meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, December 7th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 7 December 2023

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Research Scan Attribution; MLFlow and Atlasian Vulns; AWS STS; #holidayhack

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, December 7, 2020, edition of the Sansonet Stormontas Stormcast.

0:07.9

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.6

Jan today wrote a big diary about an interesting new RFC that was just released last week, RFC-911, and it deals with a problem that I've mentioned a few times

0:25.6

and we have data for on the United Storm Center website and that's researchers scanning the internet.

0:33.7

I think we have now something like 30 groups that we are tracking based on our data because

0:39.3

they often show up as some of the top attackers.

0:43.6

And the problem, of course, is that these researchers themselves create quite a bit of sort

0:48.9

of background noise.

0:50.4

And it's often important to figure out if a particular scan that you're seeing in your network is just some researchers,

0:58.0

so you may just want to block them, or something more malicious, or maybe even some false positives or such.

1:06.4

Well, RFC 9511 suggests that a web server on the IP address doing the probing is providing essentially

1:16.5

a little file in the well-known directory called probing.text that provides additional information

1:23.5

about the origin of these scans. It would be interesting to see if this takes off. There is, of course,

1:30.3

a risk that bad guys will claim that they're researchers, but they already do that to some

1:36.4

extent. There's nothing to prevent an attacker from just setting up a webpage on a scanning IP.

1:43.4

I'm claiming that this is part of a research organization.

1:47.2

I think where this will really help is it will give you a little bit more background as to who is actually behind the scan.

1:53.5

And then you can check that particular organization's webpage, for example, to cooperate the information that is provided via that probing.

2:03.6

Text file.

2:04.8

Interesting approach.

2:05.9

We'll see if it takes off, but I would suggest if you're planning to scan the Internet for something,

2:11.8

well, check if someone is already doing that and just share data with them.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.