meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, January 2nd, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 2 January 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. GOV Domain SPF/DMARC Use; ksmbd vuln; netgear patch; PyTorch dependency polution

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Monday, January 2nd, 2023 edition of the Sandtonet Storm Center's Stormcast.

0:09.3

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:15.1

With one week of no podcasts, we do have a couple of diaries to catch up on, so I just want to do this

0:22.3

relatively quickly here. Jan looked at the SPF and DMR records in country-level government

0:30.3

domains. So most countries have country-level domain like dot UK or dot DE, and then they have a subdomain here for

0:40.5

government entities like Gov.uk, I believe it is, for the UK top-level domain. Jan looked at

0:49.6

how these domains are then configured with respect to SPF and DMAR.

0:55.0

This is, of course, rather complex because usually these domains cover the entire

1:00.3

country's government, so there's a wide range of different government organizations.

1:05.5

One thing I want to point out that the Yans of ended as a little end note here that eight of the second level

1:12.4

gov domains have actually these blocking records and that's something that you

1:17.1

should definitely consider for a domain that does not send any email SPF and

1:22.2

demarc records basically just state hey we are not sending any emails.

1:29.0

Other diaries we have are about, well, setting up a custom D-Shield listener in your honeypot.

1:37.0

Also, how to use a PowerShell to parse JSON from Amazon and from firewalls,

1:44.6

and then also how to set up the shield sensor

1:47.2

in Microsoft's Asia Cloud.

1:49.9

So check with the respective diaries for additional details.

1:56.3

And then just a quick follow-up

1:57.8

and a little bit more detail on the KSMBD vulnerability. This vulnerability

2:03.4

was made public just before the holiday week and, of course, lots of concern about that.

2:09.2

Luckily, my initial assessment that isn't quite as big of a deal as one may think has come

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.