4.9 • 696 Ratings
🗓️ 23 January 2023
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Monday, January 23rd, 2023 edition of the Sands and its Storms Centers, Stormcast. |
0:09.3 | My name is Johannes Ulrich, and I am recording from Jacksonville, Florida. |
0:14.7 | Friday we got a diary by Boyan. |
0:17.1 | Boyan does a ton of pen tests and is summarizing some of the lessons that he learned from |
0:24.5 | these pen tests. One critical one being that you must configure proper signing in your Windows |
0:31.7 | of the occasion. Otherwise, you will be vulnerable to relaying attacks. And he's sort of going over a couple of ways how you can figure out easily if you have signing enabled in your environment. |
0:47.4 | Starting with EnMAP, which will help you doing that. |
0:51.4 | But then also for HTTP and for the Active Directory Certificate |
0:57.4 | Services Server, how you make sure that the HTTP headers are configured correctly. |
1:04.5 | It's a brief post, but still extremely useful, and like I said, that's something that he |
1:10.6 | runs into all the time as part of his |
1:12.7 | pentesting practice. |
1:14.8 | So this is a very common configuration weakness, not really always that easy to fix throughout |
1:21.7 | a larger network. |
1:25.3 | MailChimp, a company that is maintaining mailing lists for various organizations was breached last week, |
1:32.2 | and I didn't cover this. |
1:33.7 | Usually I don't really cover breaches here unless there's sort of a wider lesson here. |
1:39.4 | And well, that wider lesson now comes into play when it comes to MailChimp because Fandual online sports |
1:47.9 | betting website has disclosed that as part of the Mailchimp breach, one of its mailing lists |
1:55.2 | was breached. |
1:56.3 | Now the information isn't really all that super critical, it's email addresses and names, no |
2:03.2 | passwords or anything like this. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.