meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, July 8th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 8 July 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. DoH Or Not? Cisco Exploit, Magento Exploit, Malicious XSL Files

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, July 8, 2019 edition of the Sansonet Storm Center's Stormcast.

0:08.2

My name is Johannes Ulrich.

0:09.9

And today I'm recording from London, England.

0:14.2

DNS over HGPS is in the news again or not depending on how you interpret an analysis done by Chihu 360 or NetLab

0:24.4

360 of a recent godlua Linux Trojan. One of the special features of this particular piece of malware

0:34.3

is that it has a number of redundant command and control channels.

0:40.0

Now, one thing that it does according to the NetLab 360 analysis is it uses DNS over

0:46.8

HTTP to retrieve a text record with the particular command control server's name.

0:54.2

Now, Curl co-developer Daniel Sternberg actually noted that the protocol being used here is not actual DNS over HTTP.

1:04.3

Instead, it's more sort of a homemade protocol that's unique to this particular malware.

1:10.3

It does send a request to a website over

1:14.3

HTTP and then in return you do get the host name of the command control server. It's

1:21.5

supposed to connect to but it does not use any of the public DNS over HDPS servers,

1:28.8

and also the protocol being used here would not be compatible with any of these servers.

1:34.9

For Defender, this is an important distinction,

1:38.0

because if the attacker would use DNS over HDPS,

1:43.8

then you could use any defensive techniques that you

1:47.4

typically use for DNS over HDPS, like the blacklists that John Bambenek published last week

1:54.8

and that I mentioned.

1:57.1

This looks more like a standard command control channel over HDPS, so these techniques wouldn't work,

2:05.1

and you would just have to look for standard HDPS analysis techniques.

2:11.0

In the show notes, I will link to two articles here.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.