ISC StormCast for Thursday, January 24th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 24 January 2019
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Thursday, January 24th, 2019 edition of the Sands and its Storm Center's |
| 0:07.2 | Stormcast. My name is Johannes Ulrich. And today I'm recording from Jacksonville, Florida. |
| 0:14.3 | It looks like I just can't let go of DNS. The Department of Homeland Security has issued an emergency directive today, requesting |
| 0:24.4 | that government agencies are double-checking their DNS settings. Now, this sounds along the |
| 0:31.9 | lines of something that I talked about a couple weeks ago. I mentioned that there was an attack in the Middle East |
| 0:38.8 | where DNS settings for domains were altered and as a result, users were redirected to malicious |
| 0:46.9 | sites. So what DHS is warning about actually sounds quite similar. They're talking about |
| 0:53.5 | credentials to DNS administrative |
| 0:56.4 | consoles being compromised and then used to modify DNS settings in particular for the mail |
| 1:03.8 | server and of course the name server. Like I mentioned back then, that's something you should |
| 1:08.5 | definitely pay attention to and something |
| 1:11.0 | you should have some monitoring in place in order to detect if anybody is tampering with |
| 1:16.7 | your domains. The tricky part to detect often is if someone added a new host name, that |
| 1:23.3 | can often be used for fishing, like someone adding login.mid.mydomain.com in order to then use this |
| 1:30.8 | in a more targeted fishing attack. Now, one of the more challenging aspects of now firewalling |
| 1:39.3 | is to properly restrict outbound traffic from clients. |
| 1:45.0 | And this hasn't gotten easier, of course, |
| 1:47.5 | with everybody moving to cloud services |
| 1:50.1 | and cloud services not necessarily using a fixed set |
| 1:53.7 | of IP addresses. |
| 1:55.4 | So a lot of organizations are whitelisting certain domains. |
| 2:00.5 | Well, it turns out that this may not be the safest thing to do. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

