meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, August 11th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 11 August 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. DNS Attacks; Defaultinator; Zimbra Compromise; vRealize Vuln; Snort/O365 false pos;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, August 11, 2020 edition of the Sandsenet Storm Center's Stormcast.

0:08.7

My name is Johannes Ulrich, and today I'm recording from Jackstall, Florida.

0:14.5

I wrote a brief piece today about reflective, distributed denial of service attacks, and now

0:19.7

this is an oldie but goody in some ways.

0:22.9

The attacks are taking advantage of DNS.

0:25.3

And the reason I wrote about them isn't because they're new and exciting, but

0:28.9

well, because they're still happening after all these years, one of our honeypots used to be

0:35.0

a reflective amplifier and it continues to be heavily used

0:38.5

along after it stopped responding to any kind of DNS requests.

0:44.2

And while it's not running a DNS server right now, because it would really be useless

0:48.1

as a DNS server, still given all the traffic it receives.

0:52.8

I also use the opportunity to summarize some simple best practices when it comes to DNS.

0:59.5

Not complete, but issues I often see people having problems with.

1:04.0

And let me know if there's anything I should cover in more detail in that respect.

1:10.1

With Blackhead and DefCon happening this week, we do have some announcements of new attacks and

1:16.0

tools during these events.

1:18.8

One interesting tool announced today by Rapid 7 is Defaultinator.

1:24.2

Defaultinator attempts to address a problem that is probably even older than reflective DNS attacks. Defaultinator. Defaultinator attempts to address a problem that is probably even older than reflective DNS attacks default passwords. But for auditors and pen testers, it's sometimes difficult to sort of get a definite list of default passwords. There are several out there that are not complete, that are not well organized.

1:46.9

So defaultinator is trying to fix that.

1:52.0

It's a free service and tool that Rapid 7 makes available now.

1:57.7

Looks like so far they have over 8,000 passwords in their database,

2:03.4

and Kurt Bernhardt with Rapid 7 states that there still needs to be a bit of cleanup happening.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.