ISC StormCast for Thursday, June 29th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 29 June 2023
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, June 29, 2003 edition of the Sands and its Storms |
| 0:06.6 | Center's Stormcast. |
| 0:08.1 | My name is Johannes Ulrich and I am recording from Stockholm, Germany. |
| 0:14.2 | Jan today wrote up a quick survey based on Shodan data looking at what web servers are still |
| 0:20.7 | running, SSL version 2 and |
| 0:23.1 | well where they are running, which actually turned out to be quite interesting. |
| 0:27.2 | SSL version 2 was pretty much shown to be vulnerable and should no longer be used in late 90s, |
| 0:34.3 | so 99, and since has steadily been removed even from some TLS implementations. |
| 0:42.6 | What Jan found was, first of all, the not so surprising part. It's a lot of IoT devices, |
| 0:48.8 | the Go Ahead Web Server in particular. That's a web server that you often find sort of on |
| 0:53.2 | embedded devices, |
| 0:55.4 | but geographically it was very much concentrated in Kazakhstan. First I thought it maybe somewhat |
| 1:03.8 | politically related. Kazakhstan has had some interesting ideas like, for example, forcing everybody |
| 1:10.4 | to install a government-controlled |
| 1:12.2 | certificate authority to make a machine-in-middle attacks easier. But in this case, it appears |
| 1:18.7 | that one particular ISP, the largest ISP in Kassaslan, is deploying endpoint devices that use a web |
| 1:26.9 | server that only supports SSL version 2. |
| 1:30.8 | So these modems really are responsible for this big spike in SL version 2 devices in |
| 1:38.8 | Kazakhstan. |
| 1:39.8 | And then we got more trouble around NPM packages. Darcy Clark, who used to be associated with the NPM project, has published a blog post showing |
| 1:50.7 | how the NPM packages or the manifest files can be abused. |
| 1:57.5 | The problem is that these manifest files are never really verified or compared to the content |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

