ISC StormCast for Thursday, February 1st, 2024
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 1 February 2024
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, February 1st, 2020, edition of the Sandsenet Storms anders Stormcast. |
| 0:08.2 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
| 0:14.2 | Wrote a quick diary today about the Dot internal domain I briefly mentioned yesterday. |
| 0:20.5 | The main reason I wrote this up was to go a little bit into the details or advantages, |
| 0:26.6 | disadvantages of using the dot internal top level domain. |
| 0:31.7 | Can be convenient for some people to have a top level domain like this, |
| 0:35.5 | but ultimately you're probably better of registering a normal |
| 0:40.8 | domain for internal use. By having an officially registered domain, you now are able to get TLS certificates. |
| 0:49.2 | You also don't have to be afraid that down the road someone else is adopting the same scheme that |
| 0:56.9 | you're using in your network, in their network, and then if you have some merger happening or |
| 1:02.0 | some VPN between the networks, you have conflicts, similar to when you're using RFC-1918 IP addresses. |
| 1:10.7 | So ultimately, I do recommend you go with the publicly registered domain. |
| 1:16.7 | Now, it's not a top-level domain. |
| 1:18.3 | You're only going to get a normal domain, |
| 1:21.1 | but that's really sufficient, I think. |
| 1:24.1 | I'm not really aware of any use case that would absolutely require you to have a top level domain. |
| 1:29.9 | If someone is aware of a use case, please let me know. |
| 1:35.3 | And Yvanti not going anywhere as far as vulnerability goes. |
| 1:41.2 | First of all, the good news, we do now have patches for two of the |
| 1:45.5 | vulnerabilities that were disclosed earlier in january c vene 2023 46805 and |
| 1:52.8 | 2024 21887 these vulnerabilities have been exploited at least since January 11th, and at this point, |
| 2:02.9 | Yvante has had a configuration that mitigated some of these vulnerabilities, but now you start |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

