meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, January 20th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 20 January 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. 0.0.0.0 and Emotet; WebKit Patch; acer Care Center; Serv-U Patch;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, January 20th, 2002 edition of the Sands and the Stormsendors Stormcast. My name is Johannes Ulrich. And today I'm recording from Jacksonville, Florida. Brad today took a look at a specific artifact of Emothead traffic. Emot head spam bots are sending, of course, a lot of email,

0:23.0

and they are spoofing the 0.0.0.0.0 IP address in some of that traffic. Of course, you

0:31.8

won't see actual traffic to that IP address. That IP address is not routable, but it, for example,

0:40.4

shows up in the Hello header and is then, of course, copied into received headers by

0:47.0

email servers receiving that email. And of course, once you have it show up in an argument to a hello request or in a received header,

0:57.7

then you will also see DNS lockups for various spam block lists, and that then usually

1:05.6

starts with the 0.0.0.0.0. IP address, followed by whatever host name at the particular list uses.

1:13.2

Safe to say, whenever you see that IP address, it's at least spam and more likely malicious.

1:20.9

Other botnets may use that as well, but Pratt specifically sees that with Emotet, so you can use it as one indicator that you're probably dealing with email that was generated by an Emotet infected host.

1:36.0

Another suggestion here was also that this may actually be deliberate attempt to figure out if the receiving mail server does have any kind of spam filtering,

1:46.2

which of course may make it less suitable for spreading malicious,

1:51.2

word documents or other office macros as what Emotette usually does.

1:57.9

Now just a little postscript here to that Cereslas 8 network. It is an unused network according to the traditional RFCs. However, Linux in the last couple of years has made an effort to actually reclaim some of this IP address space.

2:18.5

There is a Linux kernel patch available that makes zero slash eight routable.

2:25.1

Of course, the idea here is to get back some of that IP address space that was originally

2:33.8

not usable because of the old glassful addressing,

2:38.0

which hasn't been in use for, well, 20 plus years.

2:43.0

And currently we still have the unfortunate issue that Safari and with that really WebKit is leaking database names cross origin report about

2:55.8

this earlier this week I believe or was it Friday forgot but anyway there is a patch

3:01.1

available now for WebKit of course this doesn't do you much good because well

3:06.8

it would require that you essentially compile the browse and the operating system for iOS and also Safari for Mac OS yourself.

3:18.2

So yes, a patch is available, still waiting for Apple to actually roll it out into Safari and iOS iPad OS.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.