meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, March 1st 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 1 March 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. More Memcache; Trustico TLS Issues; Flash is Out But So is DNSSEC?

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, March 1st, 2018 edition of the Sansonet Stormsendors Stormcast.

0:07.6

My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:12.2

Let's start today with a couple updates regarding the Memcash, the Denial of Service Attacks.

0:18.5

First of all, on Tuesday, MemcashD released a new version

0:23.6

1.5.6 and this version now disables UDP by default, so you have to specifically enable it.

0:32.4

Secondly, Kevin put together a little post with some tips on how to secure MAMCash.

0:38.9

It's actually by default reasonably secure in that it does only listen on Lubek.

0:45.7

A reader also left a comment with a little bit of more questionable way to defend yourself

0:52.1

against these denial of service attacks in that, well, what's attacking

0:57.2

you here are Memcash servers that are likely listening for commands from anybody, and these

1:04.4

commands can include the shutdown or flush all command, which will essentially stop the attack against you. Of course, doing so

1:13.6

may have legal and ethical implications. And then sadly, we got another and kind of odd

1:21.2

certificate authority issue. Now, this case is about Trustico. Trustico is a reseller for DigiCert.

1:29.3

And apparently at the beginning of February, Trustico did ask DigiCert to mass revoke certificates

1:37.3

that were issued by Trustico.

1:39.3

The problem here was that Trustico was a reseller.

1:43.3

And typically, the owner of the certificate

1:45.9

has to ask for the revocation, which is really the customer of Trustico in this case.

1:52.1

So if you ordered a certificate from Trustico, then you have to ask Trustico to revoke it.

1:59.0

And Trustico should be able to revoke them on their own.

2:02.5

But for whatever reason, they asked Digisert to do it.

2:06.5

Digisert didn't really feel comfortable doing so without really Trastico being the actual

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.