meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Thursday, September 1st, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 1 September 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. QNAME Minimization; iOS 12 Update; Translate Miner; Geode and Foxit PDF Reader Updates

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Thursday, September 1st, 2022 edition of the Sands and at Storm Center's Stormcast.

0:08.7

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.3

I wrote a brief diary earlier today about a little bit newer DNS feature QName minimization.

0:23.1

Typically, when one thinks about recursive DNS servers,

0:26.2

and that's probably what I sort of learned in school,

0:28.2

they will first send a query for the host name.

0:31.6

They're trying to resolve to the root or top-level domain servers,

0:36.3

but, well, these servers do not really need the full host name.

0:40.3

In 2016, RFC 7816 was introduced and last year we got an update for it, RFC 956.

0:50.3

The process described by these RFCs is called DNS query name or short Q name minimizations.

0:57.0

DNS servers will no longer send the entire host name to the higher up name service.

1:02.7

Instead, they're sending the name in part only and are replacing the host name with an underscore.

1:09.0

Underscores, of course, have often been sort of used as a placeholder, more or less,

1:13.8

because they're not actually valid in host names.

1:17.7

This obscures the full name from these root and top-level DNS servers.

1:24.2

In the past, we have had cases where ISPs and such operating these name servers did collect data in front of in particular some of the root name servers, also security companies and such.

1:38.8

I've seen Bind use this for a bit now.

1:43.1

It also helps with some caching efficiency. Other DNS servers

1:48.0

are possibly implementing it too, so if you see these queries, they're perfectly normal. Let me

1:53.9

know what name servers you do see implementing this. And Apple today released iOS 1256. iOS 12 is the latest version of iOS

2:06.1

supported by iPhones 6 and older, as well as iPads of the same generation. This update fixes

2:14.7

the already exploited WebKit vulnerability, CVE 2022-894.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.