4.9 • 696 Ratings
🗓️ 14 April 2022
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Thursday, April 14th, 2020 edition of the Sands and at Storm Center's |
0:08.1 | Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida. |
0:14.9 | I've got a quick diary today by Jan. He compared the number of web servers in Ukrainian IP address space before and after a Russian invasion. |
0:28.6 | Now, the decrease is actually notable, but probably less than most would have expected. |
0:35.1 | Only about 12% of the pre-war total web servers are no longer reachable, |
0:42.6 | which given the large physical destruction and, of course, some of the distributed denial of service attacks and such, |
0:51.0 | is actually a rather small number. |
0:55.0 | Comparatively speaking, the Russian Internet actually lost more web servers. |
1:01.7 | However, that is not so much, of course, the result of physical attacks or denial of service attacks, |
1:09.9 | but likely more the result of some of the |
1:13.2 | political effects like sanctions and also some of the deep hearing that has happened either |
1:19.2 | from Western or Russian ISPs. And this decrease in connectivity probably doesn't account |
1:26.2 | for the effect of Starlink, which has been deployed in parts of Ukraine, because Starlink typically uses Nat and can't easily be used to expose web servers. |
1:39.6 | And of course, they probably wouldn't show up as part of the Ukrainian IP address space. |
1:46.7 | And then just a quick follow up on yesterday's Microsoft Patch Tuesday, the big vulnerability |
1:53.3 | here that everybody's talking about is CVE 2022-26809. |
1:59.6 | That's the RPC vulnerability. No exploit yet. A lot of chatter on Twitter |
2:06.5 | about people working on exploits, but having difficulties actually coming up with a working |
2:13.3 | exploit. I'm totally guessing here, but I think we probably have till sometime next week before |
2:21.6 | an exploit is released. I highly recommend you're applying this patch, and I'm talking about |
2:27.1 | the entire patch for the month before the weekend. It'll likely significantly improve your chances of having a quiet weekend. |
2:38.5 | And the reason I say, just apply the entire patch. Don't just focus on this RPC patch. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.