meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, February 1st, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 1 February 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Perl.com / SpamCop Domain Issues; libgcrypt vulnerability; Fingerprinting QUIC

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, February 1st, 2021 edition of the Santernate Storm Center's Stormcast.

0:08.2

My name is Johannes Ulrich.

0:09.7

And I'm recording from Jacksonville, Florida.

0:13.7

Let's start out today with a quick lesson on domain registrar security.

0:20.3

We have two different events here that sort of fit

0:24.3

that pattern in different ways. First of all, pearl.perl.com, the domain, apparently the register

0:32.7

account for the people behind, pearl.com was compromised, and as a result, pearl.com was compromised and as a result pearl.com was redirected to a parking

0:43.1

page and then ultimately offered for sale. This is still ongoing last I checked it just

0:50.4

returned an empty page so maybe the good folks behind Pearl are getting control back slowly.

0:58.1

But this can be a lengthy and very disruptive process.

1:03.2

Only good part here, the actual domain that is used for a lot of the Pearl tools and such

1:08.9

is Pearl.org, not dot com. So a Pearl

1:14.1

downloads and such should not really be affected by this, but shows somewhat that probably

1:20.7

they didn't do as well as they should in maintaining their credentials. The second domain is spamcop.net.

1:30.3

That domain is now operated by Cisco,

1:34.3

and of course a lot of spam filters are relying on updates

1:38.3

from spamcop.net.

1:41.3

Problem here was not a hijack of the domain, but instead Cisco just forgot to renew the domain,

1:49.1

so it expired and then was briefly not reachable over the weekend until someone at Cisco got their

1:57.9

credit card out and re-registered the domain. Typically, when you forget to

2:04.0

renew a domain, there is sort of a grace period, so it's not necessarily easy for an attacker

2:09.8

to quickly take over the domain, but nevertheless, of course, name resolution for your domain tends to cease.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.