meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, June 21st, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 21 June 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Azure Network Monitoring #2; Google Open Redirects; NIST RDS Hahes; iOS Wifi Bug; NSA VoIP Security Guide

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, June 21st, 2021 edition of the Sand Center at Storm Center's

0:06.8

Stormcast. My name is Johannes Ulrich. And then I'm recording from Jacksonville, Florida.

0:13.9

Got a couple of nice diaries this weekend. First of all, Daniel wrote the second part of his network

0:19.8

forensics on your VM's diary.

0:23.7

The second part covers your monitor insights, which actually allows you to combine and link

0:30.1

network traffic to processes running within the virtual machine.

0:35.0

That's actually a quite common problem where you're trying

0:38.4

to figure out which particular process is responsible for particular network traffic.

0:45.2

In a second diary on Friday, Daniel wrote about two open redirects within Google's ecosystem

0:52.8

that are currently actively being exploited for fishing.

0:57.6

First one, meet.govil.com and the second one, Hangouts.com.

1:04.0

These two URLs can be used to redirect an unsuspecting victim to any website.

1:11.6

Of course, when they're clicking on the link, they'll see the Google URL and likely

1:16.6

trust it, for example, with their Google credentials.

1:20.6

And because these URLs are so popular, it's really hard kind of to rein them in and to, for example, block them or filter

1:30.4

for them in emails because, yes, they're sadly also used legitimately.

1:37.7

Never wondered for a good set of non-malicious software hashes.

1:43.4

Well, that always existed. The reference data set published by NIST.

1:48.0

Access to it hasn't been difficult, but usually with artwork you had to download entire ISO files

1:54.0

with these hashes.

1:56.0

Circle the Luxembourg cert is now making these hashes available as a DNS service, so that should make it a lot easier to look them up.

2:07.0

You can also look them up via a simple HTTP service.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.