meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Monday, October 26th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 26 October 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Censys vs Shodan; Sooty; ML Attacks; #Samsung #S20 RCE; #VMWare Patches

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, October 26, 2020 edition of the Sandcent, Center Storm Center's Stormcast.

0:08.2

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.0

Probably the most popular site to find systems that are exposed to the internet.

0:19.0

That tends to be Shodan.

0:21.0

Shodan of course builds itself sort of as the search engine for the internet of things

0:27.3

and regularly scans the internet for systems that are exposed.

0:32.6

In a diary from this weekend, Guy reminds us that Shodan is not alone.

0:39.3

There are other sites in particular census is a site that Guy introduces here with some links

0:47.3

and examples and how to use the site.

0:50.3

Somewhat similar to Shodan in this approach, they are essentially port scanning the internet

0:56.6

in regular intervals and then publish information

1:00.2

about certificates and banners.

1:03.9

Personally, I found census in particular useful

1:07.5

to look for certificates.

1:10.1

Also, of course, things like shared certificates among different

1:14.2

sites. And the second diary from this weekend was also tool-oriented. Of course, Russ is always good

1:21.5

in introducing new and interesting tool. This time it's about SUDY. SUDE was written for SOC analysts in order to have a

1:32.1

quick and simple command line tool to research IP addresses, domain names, and the like.

1:39.3

Pretty neat tool, pretty simple. And that's really the goal here to make it simple and fast.

1:46.0

And of course, attacks against machine learning is one of the up-and-coming trends these days,

1:54.0

and Microsoft, MITR, IBM, and a number of other companies got together to essentially create something like the

2:02.8

Miter Attack Matrix for machine learning. One of the risks, of course, of machine learning is that

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.