meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, December 22nd 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 22 December 2020

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. OpenPortStats.com; Dell Wyse Vuln; More Solarwinds

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, December 22nd, 2020 edition of the Sansanet Storm Center's Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida.

0:13.5

Today on the Storm Center, we got a quick diary by Rick regarding openportstats.com.

0:21.0

That domain claims to be part of a research organization scanning the internet for open port,

0:27.1

and of course, we do have a number of similar organizations, probably most prominently

0:31.9

Chodan, Sinsic and the like.

0:34.7

What differentiates this particular organization somewhat is that their port scans

0:41.3

can be rather aggressive and as Rick has observed earlier this year, they can pretty much amount

0:48.1

to a denial of service attack. To make things worse, the email addresses listed on their web page are not working.

0:57.5

They're just bouncing with a server not available error.

1:03.0

Now on the internet Storm Center as a part of our API, we do have lists of IP addresses

1:09.6

used by researchers to scan the internet.

1:12.6

Open port stats is included in that list.

1:16.2

So if you would like to block them, you could consider using that list.

1:21.0

Or you could also consider blocking the AS used by this group, 202,425. Of course, there may be some collateral damage here if you're

1:32.9

blocking the entire ASN. And Dell today released patches for the Dell-Wise thin OS clients.

1:43.3

These are thin clients that are often used in healthcare in order

1:48.8

to provide access to cloud-based applications. Security company CyberMDX that deals in the healthcare

1:56.8

space has identified vulnerabilities that could lead to a compromise of these clients.

2:03.6

Now, of course, sadly, they're sort of advertised as secure terminals because there's really

2:09.7

very little kind of going on on the actual terminal.

2:12.9

The applications are all hosted in the cloud, but of course, taking over the terminal still provides

2:20.2

an attacker with access potentially to these cloud-based applications.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.