meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, February 16th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 16 February 2017

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. #RSAC2017; Collecting WiFi Client History; XAgent; Conference Phone

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, February 16th, 2017 edition of the Santernet Storm Center's

0:06.3

Stormcast. My name is Johannes Ulrich, and the day I'm recording from San Francisco, California.

0:12.1

In case you missed the RSA keynote panel today with at Mike Allen and myself, there is a summary

0:19.9

on the Sands website with what we talked about.

0:24.7

Also, RSA will have a follow-up webcast within about a month. The exact date hasn't been set yet.

0:32.4

We got, I think, far over 100 questions, so only got through a couple of them and hopefully will be able

0:40.0

to answer some of the remaining question during that follow-on webcast.

0:46.0

But with that, Xavier also had a great diary today with preferred network lists.

0:51.6

That's a problem that you have in a lot of wireless clients where

0:55.4

they remember the last few Wi-Fi networks they connected to and then try to

1:01.5

reconnect to them when they come online now if you sniff for that and that's what

1:06.2

Xavier goes through here you will be able to enumerate the SSIDs they're trying to connect to.

1:13.6

And then with public services, you'll be able to geolocate them.

1:17.6

Of course, once the client connects to your Wi-Fi network, you may get additional information,

1:22.6

particular iOS and OS10 devices, of a sort of the device name, which is usually, or at least

1:29.2

the default configuration, the name of the owner of the device.

1:33.3

So by combining those two datasets, you essentially know who the owner is of the device and

1:39.4

can then check what prior networks that owner connected to.

1:44.6

And that's essentially what Xavier is talking about here.

1:47.1

Not really a new problem.

1:48.7

These preferred network lists are very well known,

1:52.3

but Xavier sort of walks you through the process

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.