ISC StormCast for Tuesday, December 20th 2016
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 December 2016
⏱️ 4 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, December 20th, 2016 edition of the Sands and it's Storm Center's Stormcast. |
| 0:07.0 | My name is Johannes Ulrich and the day I'm recording from Jacksonville, Florida. |
| 0:12.0 | For about a week now we have seen an increase in scans for port 6,789. |
| 0:19.0 | Now the suspicion here was always, it's something Marai related, just based on the |
| 0:24.2 | frequency of the scans and the kind of hosts that are doing the scanning. Well, look today my honeypot, |
| 0:31.4 | and on this port we are seeing inbound traffic that appears to enable the Telnet server on port 19,058. At this point, I haven't |
| 0:42.4 | really seen any incoming connections on port 19,058 yet, but it's possible that this first wave |
| 0:50.4 | just sets up the back door and it will have a second wave later trying to connect to that backdoor. |
| 0:58.0 | An open SSH released version 7.4 of the client and server and it is following current standard practice in removing support for old protocol versions. The server will no longer |
| 1:14.4 | support version one of the SSH protocol and in August 2017, SISH version one support will also be |
| 1:24.4 | removed from the client. Now SZH version 1 has been shown to be insecure for |
| 1:30.8 | many years now. Not exactly sure when this came out, but at least 10 years, I would think. It's about |
| 1:36.2 | time to disable it. Of course, it's always unfortunate if you do still have some old devices |
| 1:41.6 | around that do not support SH version 2, and in some cases you |
| 1:46.4 | may then actually have to use TELNET instead to still access those devices. |
| 1:52.1 | I don't think it will be a big problem for S-H-Version 1, but it also removes small RSA keys. |
| 1:58.7 | The smallest accepted size is now 1,024 bits and it will make some |
| 2:04.6 | hardening techniques like Pro-H separation mandatory so it will no longer run without it. |
| 2:11.6 | This version also features a number of security fixes, so as you apply this patch, double check your configurations |
| 2:18.7 | and make sure that you are already |
| 2:21.4 | running in the recommended |
| 2:23.2 | configuration with |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

