meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, October 27th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 27 October 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Catfeeder Spy; OpenSSL Patch Preannouncement; Ventura Bug; VMWare Vulnerability

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Thursday, October 27, 2020 edition of the Sands and Storm Centers.

0:08.7

Stormcast, my name is Johannes Ulrich, and today I'm recording from Augusta, Georgia.

0:15.5

Today I wrote up a quick, a little bit fun observation of an IoT device I recently connected to my home network.

0:23.2

The device is a cat food dispenser and as many modern devices, well, it usually comes with

0:29.9

Wi-Fi connectivity and an app to control it.

0:33.7

Now, what drew my attention first was the fact that the dispenser calls out to Baidu, the Chinese search engine, every five minutes.

0:42.6

At least there is a DNS lookup for Baidu.

0:46.2

So far, I haven't actually seen the DNS feeder connect to the IP address that's being returned here.

0:53.9

The DNS lookup for BaidO. I've seen it in

0:56.1

similar devices before is typically linked to a library. I've seen them in Python. I've seen

1:03.4

them in JavaScript that check if internet connectivity is present. So I assume that's what's going on here.

1:13.3

These libraries are often, of course, written in China,

1:17.3

which means that Baidu is sort of the logical choice there.

1:21.7

Connecting to sites like Google may not work, first of all,

1:25.2

if the country-level censorship is blocking access

1:28.5

and may actually get people into trouble, which is also one reason why they may stick to

1:36.7

Baidu. In addition, the device suffers from a flaw that's actually sadly a little bit common

1:43.5

in IoT devices like this, and that it doesn't

1:47.0

randomize the query IDs for its DNS queries, doesn't even increment them, it just keeps

1:54.2

reusing the same query ID, which in this case is two, have seen it, use also query ID 3, which of course would make it trivial to spoof a response.

2:07.5

It also has an open telnet server.

2:09.2

So far, I haven't figured out using them in password.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.