4.9 • 696 Ratings
🗓️ 19 June 2017
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Monday, June 19th, 2017 edition of the Santernat Storm Center's Stormcast. |
0:07.9 | My name is Johannes Ulrich, and today I'm reporting from Minneapolis, Minnesota. |
0:13.6 | Lorna noticed on Friday an uptick in Port 83 scans. |
0:19.9 | Now, there isn't any obvious service assigned to port 83 we set up some honeypots on |
0:27.1 | port 83 and really got a variety of different packets some TCP packets that after |
0:34.0 | complete handshake we get something in binary, not obviously matching a particular |
0:40.5 | protocol, some HTTP over UDP, and then also some of the Universal Plug-in-Play. |
0:48.8 | Now, Universal Plug-Nplay does look like HTTP, but when I say HTTP traffic over UDP, that actually |
0:57.0 | was not universal plug-and-play. |
1:00.5 | Instead, it did look exactly like what you would expect for HTTP. |
1:06.4 | Now, a couple options here, the quick protocol that Google is using, it uses UDP and essentially does |
1:13.9 | HTTP over UDP, but it has its own special structure, so this does not look like quick. |
1:22.1 | Now according to Shodan, the most common server found on Port 83, happens to be HTTP, and well, it makes |
1:29.5 | out of sense that 83 is used as an alternative port for 80. The next in the list is FTP. Not sure |
1:39.2 | why people run FTP on Port 83, but sure, why not? |
1:47.4 | So if you got any insight, please share it with us. |
1:55.2 | There are samples in Lorna's diary about the traffic that she saw on Port 83. |
2:04.3 | And last week, FortyNet did release details about denial of service vulnerability in the WINS service after Microsoft stated that they will not fix this vulnerability. |
2:10.1 | All you have to do is establish three replication sessions with a WINS server and it will |
2:16.4 | essentially hang. Now the problem of course with WINS server and it will essentially hang. |
2:18.3 | Now the problem of course with WINS is that Microsoft has clearly labeled it as a legacy service. |
2:25.3 | You shouldn't really be running WINS. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.