meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, November 1st, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 1 November 2021

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. RDP Scans; Sysmon Update; Chrome Updates; Android Rooting Malware

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, November 1st, 2021 edition of the Sansonet Storm Center's

0:07.0

Stormcast. My name is Johannes Orich, and today I'm recording from Jacksonville, Florida.

0:14.0

This weekend, we got a post from Guy discussing some of the scans that he's seeing for RDP against his honeypot.

0:24.6

Note that not just the default port is being scanned, 3389, but other ports are being scanned as well.

0:32.8

According to Shodan, there are about 4.9 million IPs that have 3389 exposed and another 4 million

0:41.5

roughly that have RDP listening on other ports, but mainly that's just changing it by one,

0:48.4

so 3388. Among the users being attempted here, Ncrack kind of sticks out.

0:57.1

That's, of course, a tool that comes with NMAP.

0:59.8

I think looking at the list of users that one of the main things here is that they're actually looking if RDP is exposed.

1:10.0

If I know Gies Honeypot correctly, it actually doesn't have an RDP server listening there.

1:16.2

So that's why we may not actually see then the Prude Force attempts that are likely going to follow.

1:22.8

Remember, RDP, it's so often exposed, but it's also very often an entry point for ransomware.

1:31.0

It's really one of the protocols that you need to get a handle on and need to block

1:36.6

random access to exposed RDP servers or, well, not expose them at all if you can.

1:43.8

So only access from legitimate administrator IP address should be granted,

1:48.9

and if you're working from home, you may still be able to limit it, like, to your ISP

1:54.7

or such, if you have a dynamic IP address.

1:59.1

And we also got an update for Sysmon and Auto Runs, mostly fixing bugs and certain crash

2:06.8

conditions.

2:07.9

Don't really see any significant new features there.

2:11.2

Also, remember with Windows 11 now being out for a couple of weeks, many of these tools,

2:17.4

I think power utilities, for example, have been updated for Windows 11 now.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.