4.9 • 696 Ratings
🗓️ 15 May 2023
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Monday, May 15, 2023 edition of the Sands and at Storm Center's Stormcast. |
0:08.8 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
0:14.7 | Almost 10 years ago, Google was approved for the use of the generic top-level domain.sip as well as dot-M-O-V. |
0:27.1 | Google hasn't really used those two top-level domains since then, but started actually allowing |
0:33.7 | registrations of these domain names about a month ago. |
0:38.7 | Now, initially, there was sort of a limited release. |
0:41.2 | You had to pay, basically, an extra early registration fee starting last week. |
0:47.4 | Anybody for the standard fee of as low as $15 a year was able to register these domain names. |
0:56.5 | Now, there still appears to be sort of some variation in the exact price of the domain name, |
1:00.7 | some more popular, like based in English words and such, appear to be more expensive. |
1:06.5 | But what happened was that basically announced that this little bit of a gold rush started |
1:12.6 | of people registering domain names ending in dot zip and dot MOV. |
1:18.5 | The reason this is significant is that these are of course standard file extensions. |
1:24.5 | So some of the domain names being registered are, for example, office update.zip, |
1:30.6 | update.zip, installer.zip, and similar domain names that really are reminiscent of file names. |
1:38.9 | This, of course, could first of all lead to fishing attacks that confuse the user about whether or not they're |
1:46.9 | actually opening a local file or a remote URL. |
1:50.7 | The other risk here is that many tools like email readers and such may convert zip file names |
1:57.0 | into URLs. |
1:58.2 | And then when you're sort of hovering over that link to that external site now, |
2:04.6 | well, you're actually doing a DNS lookup, or maybe a user may, by mistake, click on it, |
2:10.1 | which then will leak the name of that zip file. Sip file names are usually nothing sort of |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.