ISC StormCast for Tuesday, January 26th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 26 January 2021
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Tuesday, January 26, 2021 edition of the Sandton and Storm Center's Stormcast. |
| 0:08.3 | My name is Johannes Ulrich. |
| 0:09.9 | And then I'm recording from Jacksonville, Florida. |
| 0:14.2 | Rob today is writing about an NMAP NSE script that allows you to look for DNS over HDPS endpoints. About a week ago, |
| 0:24.8 | Guy did report about seeing scans for DNS over HDPS endpoints. And of course, the reason behind |
| 0:31.9 | these scans is that people set up their own private DNS over HDPS servers. |
| 0:38.3 | And in your corporate environment, |
| 0:40.3 | you probably want to make sure that if you have any servers like that, |
| 0:45.3 | that they are authorized. |
| 0:47.3 | And of course, just like when you're passively looking at DNS over HDPS |
| 0:52.3 | traffic, if you're scanning for these servers, well, they respond |
| 0:56.5 | just like any other HDPS server. |
| 0:59.6 | What Rob is doing here is sending an actual DNS over HGPS request to the most common |
| 1:06.6 | URLs used by these servers DNS dash query and then looking for an appropriate response. |
| 1:15.2 | DNS over HPS requests could either be sent in binary or JSON. |
| 1:19.9 | Common DNS over HPS servers do process both. |
| 1:25.0 | So for simplicity, Rob here is using the JSON variant of the queries. So this |
| 1:32.0 | should find anybody using standard off-the-shelf software to implement DNS over a GPS server. |
| 1:37.8 | But of course, attackers or malicious insiders for that matter could always set up a custom server that does not necessarily |
| 1:48.2 | follow these conventions. And software security company Sonatape got lucky again, and I guess |
| 1:56.6 | with that, also a number of Node.js developers got lucky by Sonathepe identifying three |
| 2:05.0 | different packages that contained additional malicious code. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

