meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, January 31st, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 31 January 2023

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. DoH Scans; GitHub Replaces Signing Cert; GitHub ZIP Algo Changes;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, January 31st, 2021, 2023 edition of the Sansonet Storms, Stormcast.

0:09.6

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:15.5

I put up a quick diary today with some of these sort of DNS over HTTP or HTTP requests that I've

0:23.7

been observing lately. It looks like there is a group out there that is still trying to

0:30.5

enumerate the DNS over HTTP servers. You of course all know the big ones like your Googles and

0:37.3

Cloudflarelares and such offering

0:38.8

the service, but what I suspect here is that there are individuals who are trying to get

0:45.6

a trusted DNS service going and who don't have access due to some counterfeit block lists

0:53.6

and such to the well-known DNS

0:56.1

over-Htips services. So I think that's why I'm seeing that. So far, pretty much all of the

1:03.0

lookups are for bidu.com. If you do run DNS over-HtPS service that's accessible to the public.

1:11.7

Maybe you set it up for friends and family and didn't really bother or weren't quite able,

1:17.1

based on dynamic IPs and such, to lock it down.

1:20.4

I don't think that's something you have to be too worried about.

1:23.8

I suspect that all they're really after is sort of an anonymizing DNS service, so probably

1:30.6

not going to cause too much harm other than maybe some resource exhaustion there if the requests

1:37.2

become too many and then some rate limiting may help there. I started sending back some valid answers myself just to see what else is coming,

1:47.3

but after a day so far, not much other than just some simple broaps. If anybody has any other

1:54.1

ideas, well, let me know and maybe there is more to it. And we've got two news items actually related to GitHub.

2:03.9

The first one, probably the more severe one here is that GitHub detected beginning of

2:09.5

December an unauthorized access to a repository for the development of its GitHub desktop

2:17.0

and atom products.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.