meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, March 5th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 5 March 2020

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. MSFT Subdomain Takeover; Not 0-Day Homoglyphs; Cornavirus Phish @JCyberSec

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, March 5th, 2020 edition of the Santernut Storm Center's Stormcast.

0:07.3

My name is Johannes Ulrich.

0:08.8

And I'm recording from Jacksonville, Florida.

0:12.8

Well, we got some abandoned subdomains in the news again.

0:15.8

This time it was security researchers, Newman Oudzdeemir and Odzan Akdibi, that found about 700 of these

0:25.6

or 800, depending on how you count linked to Microsoft. The tricky part here is that what

0:33.8

Microsoft is doing, and that's what a lot of companies are doing, that they're setting

0:38.5

up a new subdomain for some project, and then they're using a DNSC name to essentially

0:44.5

redirect that subdomain to a particular Asia host in the case of Microsoft, of course.

0:51.5

The same would probably work with most cloud providers.

0:56.0

After they're done with that particular subdomain, the project is discontinued.

1:01.1

They are removing the website, but the DNS entry remains.

1:06.5

So what can happen now is that someone is coming in, is setting up a website on that particular

1:13.9

cloud provider with the same name that the original company like here, Microsoft, choose

1:21.0

for the site.

1:22.3

Since the CName lookup still exists in Microsoft's DNS.

1:28.0

Visitors are now redirected, for example, for something like identityhelp.

1:32.9

Microsoft.com or myprouser.microsoft.com to the hacker's website.

1:40.2

And given that companies like Let's Encrypt will give you a TLS certificate, even if you are just able to put up a website with that host name.

1:50.9

So that could potentially here lead to a pretty good fishing website.

1:57.9

So what these researchers did was essentially write a script to look for abandoned websites,

2:03.8

abandoned subdomains.microsoft.com. Then next they looked up, hey, is there a C name that

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.