meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, January 24th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 24 January 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Wininet.dll Feature; Excel "Real Estate" attack; F5 Patches; McAfee Vuln;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, January 24th, 2020 edition of the Sands and the Storms

0:06.6

and it's Storms on a stormcast.

0:08.0

My name is Johannes Ulrich.

0:09.5

And today I'm recording from Jacksonville, Florida.

0:13.6

I keep seeing this about network traffic, but the same is also true about systems.

0:19.3

If you look at systems or network traffic at a time of an incident, well, it's kind

0:25.6

of too late to figure out what's normal.

0:28.2

And that can be very important to know as you need to identify if a certain artifact

0:33.9

that you're seeing is just, well, the way the system is supposed to behave or maybe something that's related to the attack.

0:42.0

Where this came up was in an incident that Boyan was working on, and this was a list of domain

0:49.3

names that the victim found in Wynet.dll.

0:54.4

Now, Wynet.t.dl is one of those basic Windows libraries

0:58.9

that deals with network connections,

1:02.4

and it had a very long and extensive list of domains here,

1:07.8

some of them relatively obscure.

1:10.7

Well, it turned out that this was perfectly normal.

1:12.6

Modern operating systems, modern browsers are supporting a feature referred to as strict transport security,

1:19.6

where a website may indicate that it's only accessible via HDPS.

1:25.6

Well, as part of this feature, there's also a preload capability where you can add your website to a list of websites that are automatically being flagged as HTTP only by the operating system or the browser.

1:42.2

And turns out that wheninet.dl contains exactly that list.

1:48.0

So this is a list of websites that registered himself as being HDPS only.

1:54.1

And the list, of course, well, the only common denominator here is that these websites are listed.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.