meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Sunday, June 30th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 30 June 2019

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Domain Wide Virustotal Search; Mozilla TLS Guide; SKS Attack; QR Code Phishing

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Monday, July 1st, 2019 edition of the Sansonet Storms, Stormcast.

0:07.4

My name is Johannes Ulrich.

0:08.9

And today I'm recording from Riyadh, Saudi Arabia.

0:14.1

Rob had more power shell goodness for all of you.

0:18.1

And the latest diary that he published this weekend explains how to collect

0:23.6

the hashes from running processes across an entire domain and then verify them via

0:30.1

Virus Total. Now before you go ahead then quickly implement this, he also points out that

0:36.4

if you just have the free public API key

0:40.1

for virus total, you're limited to four requests a minute or 5,760 requests per day. In general,

0:48.4

this shouldn't really actually be all that bad given that even across a large network,

0:53.4

probably many hosts are running the

0:55.3

same configuration, the same software, so you should get an awful lot of duplicate

1:01.3

hashes as you are acquiring them.

1:05.1

And really what you're probably interested in are soft of one-offs, the new processes, so

1:10.0

you should be able to narrow it down to a few

1:13.2

interesting hatches that you are then checking on VirusTotal.

1:19.6

And Mozilla released the latest, greatest version, version five of its TLS server configuration

1:26.2

guide.

1:26.8

One of the interesting features about this guide is that it's also available in JSON format and can easily be used then to automate the configuration of TLS services. Of course, this really focuses on web servers. Now, before you go out and quickly implement it, be aware that it comes

1:47.9

in various levels, most notably an intermediate and modern configuration. Be a little bit careful

1:55.7

with the modern configuration. It really assumes that you are using essentially the latest and greatest

2:02.3

browser versions. For example, it does recommend TLS 1.3 as the only TLS version. The

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.