ISC StormCast for Tuesday, December 3rd 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 3 December 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, December 3rd, 2019 edition of the Sandsenet Storm Center's Stormcast. My name's |
| 0:08.3 | Johannes Ulrich, and then I'm recording from San Francisco, California. In the last few weeks, we have spotted a |
| 0:16.4 | significant increase in scans on Port 26, and well well we're honestly just wondering what were |
| 0:23.6 | people looking for here. Nothing typically listening on Port 26 but of course sometimes |
| 0:29.6 | users get a bit crafty and run systems on different ports. When you're looking at |
| 0:36.1 | Shodan the top listener on Port 26 tends to be a mail server. |
| 0:42.7 | Exim is one that sort of stands out here. |
| 0:45.5 | And Exim had a number of well-documented vulnerabilities recently. |
| 0:51.3 | So our first guess was, well, people probably just run XM on Port 26 to avoid some of the |
| 0:58.1 | blocking that a lot of ISPs do on Port 25. And now someone figured this out and is starting to scan |
| 1:05.1 | for XM vulnerabilities. So we set up Honeypot to listen on Port 26, but so far we haven't really seen any XM attacks. |
| 1:17.1 | Instead, it looks like the only thing that attackers are really looking for on Port 26 is, well, yet more Telnet prud forcing. |
| 1:27.4 | So they're essentially looking for users that run Telnet on Port 26. |
| 1:33.3 | Not sure how successful this is, Shodan does not show a significant number of Telnet servers on Port 26, |
| 1:42.3 | but maybe someone discovered here something that Shodan missed. |
| 1:47.1 | On the other hand, it wouldn't be the first time that some attacker sort of has some |
| 1:51.1 | wild idea like this and is just sending a bot net after a port without really having any |
| 1:57.7 | success. |
| 2:00.0 | And on Monday, Pr Brad received an email with a malicious attachment, so well, he couldn't |
| 2:06.6 | help himself, but to take a closer look at it, it was one of those encrypted zip files. |
| 2:12.8 | The password for it was 777. |
| 2:16.4 | Well, and no big surprise, it included malicious vert document. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

