ISC StormCast for Thursday, December 3rd 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 3 December 2020
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, December 3, 2020 edition of the Sandsenet Stormsenders Stormcast. |
| 0:07.7 | My name is Johannes Ulrich, and the time I'm recording from Jacksonville, Florida. |
| 0:13.2 | To start out with today, we have a new paper looking at the prevalence of DNS spoofing. |
| 0:20.8 | Now, the paper was done by Lon Way and John |
| 0:25.7 | Heideman, and it's based on six years' worth of data. Now, one thing they found is that, |
| 0:32.3 | first of all, DNS spoofing is not very common. 1.7% of observations that they collected did indicate DNS spoofing, |
| 0:43.6 | but they also say it doubled over the six years in which they actually collected data. |
| 0:50.8 | Now, just to clarify, when they're talking about DNS spoofing, they're not necessarily talking |
| 0:55.6 | about sort of passively spoofing DNS responses, but for pretty much the most part, they're |
| 1:03.6 | talking about people playing machine in the middle, intercepting DNS requests, and then instead |
| 1:09.6 | of outright forwarding them to a legitimate |
| 1:12.6 | authoritative name server, these DNS resolvers will then alter the response. |
| 1:20.6 | You probably have seen things like this, for example, for captive portals, but also |
| 1:25.6 | sometimes ISPs use systems like this in order to, for example, |
| 1:31.7 | redirect users to internal search pages if they try to request a domain that does not exist. |
| 1:39.5 | So in this case, an annex domain response from a valid DNS server would be turned into a record that |
| 1:49.1 | points to that internal search page. |
| 1:51.7 | There are numerous motivations for doing things like this. |
| 1:55.6 | It could be as simple as trying to help out the user, but more likely there's some kind of financial gain here |
| 2:02.9 | in redirecting users to internal websites that of course then are monetized via advertisement |
| 2:11.5 | and user tracking. |
| 2:13.8 | The countermeasure that's being offered here is, of course, DNSSEC. However, you have to be a little bit careful here that you're not asking DNSSEC to do more than it really can do. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

