meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, February 26th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 26 February 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Taxslavyer vs. FTC: Fix Credential Stuffing Now; OMG Bot; Blackholing Advertising with Pi-Hole

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, February 26, 2018 edition of the Santered Storm Service Stormcast. My name is

0:08.5

Johannes Ulrich. I'm recording from Jacksonville, Florida. First, a couple of quick notes about

0:15.0

diaries from this weekend. Did he wrote about a slightly better, simpler way to download malware via Tor.

0:23.6

He had a diary about this a few weeks ago, but this new method makes things a little bit

0:29.8

easier. Secondly, Guy wrote about black hole advertising sites with pie hole. Now, pie hole

0:36.9

is sort of a sinkhole that you can install in your network, and then you can redirect black hole sites to this sinkhole. Of course, Guy had something like this with his DNS black hole. This is something that you would use to collect data from outbound connections.

0:56.8

So it's not your honeypot that collects inbound connections, but instead you're trying to

1:02.1

figure out what potentially malicious sites your users are connecting to and what data they

1:08.7

would be sending to these malicious sites.

1:11.6

I usually try to stay a little bit away from legal issues and the like, but there is an interesting

1:19.0

settlement that was reached between a tax layer, a tax preparation company and the Federal Trade

1:25.9

Commission, the FTC.

1:30.8

The problem here was credential stuffing.

1:36.6

Now, that term is a little bit new and it's really sort of a variation of a password prude force attack in that that hacker instead of just randomly guessing passwords is

1:42.5

using not just using some and passwords but other identifying

1:46.5

information that was leaked in breaches at other companies.

1:52.4

So the problem here is how do I protect my own site from an attacker that gained access

2:00.6

to my user's username and password via a third-party

2:05.3

side that I don't control.

2:08.4

Well, the FTC apparently is the opinion you should do something about it.

2:13.5

Now, I haven't had access to the full text of the settlement.

2:18.5

I'm just linking in the show notes to a summary.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.