4.9 • 696 Ratings
🗓️ 14 June 2022
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Tuesday, June 14th, 2020 edition of the Sansonet Storm Center's Stormcast. |
0:08.2 | My name is Johannes Ulrich, and then I'm recording from Jacksonville, Florida. |
0:13.9 | DNS command control channels and covert channels in general over DNS remain popular because, well, first of all, |
0:22.3 | DNS usually works even through firewalls and such via recursive resolvers and also often |
0:29.5 | does height sort of in all the DNS traffic, so not always that easy to spot. |
0:35.8 | We have a recent example with the Saitama backdoor, |
0:41.0 | a backdoor that's commonly attributed to the Iranian-backed group APT-34. |
0:48.8 | What's sort of special about this particular DNS command control channel |
0:52.9 | is that as typical, we sort of have an |
0:56.6 | artificial looking and the fairly kind of obvious host name that's being looked up, but it just |
1:04.3 | looks up an A record. And a lot of covert channels, you have like text records, but here it just |
1:10.3 | looks up an A record. So all you get |
1:11.9 | back is an IPV4 address or multiple IPV4 addresses, and then the backdoor basically decodes |
1:19.8 | these addresses to actual the command that's supposed to be executed. In today's diary, Renato is |
1:27.4 | going over how this encoding scheme works, and he also does |
1:31.7 | have a decoder for you in case you're running into this kind of traffic, you're |
1:37.1 | then able to decode the traffic easily. |
1:42.1 | And users of the freight here of Travis CI, the continuous integration platform, |
1:48.4 | should be aware that logs are not only easily accessible via the API without authentication, |
1:56.8 | but also that these logs may contain credentials, |
2:00.9 | like, for example, access tokens that you're using |
2:04.3 | for sites like GitHub. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.