meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, May 22nd 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 22 May 2017

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Typosquatting (again);

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, May 22nd, 2017 edition of the Sandton and Storm Center's Stormcast. My name is Johannes Ulrich, Enterdam, recording from Jacksonville, Florida.

0:13.0

Well, typo squatting is nothing really fundamentally new. Xavier has a nice recent example here that makes a good awareness piece for DHL.

0:24.8

DHL, the packet delivery service, of course, is often the subject of malicious fishing attempts

0:31.4

where they are trying to make you open a shipping receipt.

0:36.3

In this particular case, they used DHL with www.com.

0:42.5

Now, by the time, Xavier looked at the domain, DHL had already taken it over.

0:47.9

But of course, it's just a matter of time for someone to come up with another variation,

0:53.1

replacing else with ones and the like.

0:56.0

Saville is also talking about a neat tool that you can use to find typo-squadding domains.

1:03.0

DNS Twist.

1:04.0

DNS Twist will not only try sort of look-alike domains, it will also then tell you what is the name server for them so you can find

1:13.3

possible typo squatting lookalike domains that are trying to impersonate your brand.

1:19.9

And then of course, what do you do with these typo squatting domains? Well, you probably shouldn't

1:25.6

ask Xavier pointed out, put it just to a DNS parking site,

1:30.3

but instead use it to educate users that this is not the correct spelling for your company name,

1:36.3

and to be careful with typos like that.

1:40.3

And since you're not going to use this domain for any legitimate outbound email, you can

1:45.5

then also set up SPF settings identifying this domain as a domain that will not be used

1:51.8

for any outbound email, which will make it easier for others to then filter email that's

1:57.3

trying to impersonate or use this particular domain.

2:02.1

And Netgear about a week ago released a new firmware, something you should definitely

2:07.4

consider applying given that of course it fixes like always a number of serious bugs.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.