meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, March 29th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 29 March 2022

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Twitter BGP Hijack; Ukraine DDoS; Sophos Patches; Sonicwall Update; opnsense CARP bug

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, March 29th, 2020 edition of the Sansonet Storm Center's Stormcast.

0:08.8

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:14.3

We got a couple Ukraine-related items to start out with.

0:18.9

First one is a BGYP hijack of a Twitter prefix by RTcom.

0:25.7

The prefix in question is 104, 244-442 slash 24, and that happens to be, of course, the prefix that

0:37.1

Twitter.com resolves to.

0:39.8

Now, the hijacking was somewhat unsuccessful, at least outside of Russia, in part because of

0:48.0

the implementation of RPKI.

0:50.0

That is a more modern, secure addition to BGP that allows ISPs that implement this extension to BGP to actually validate some of these updates and with that avoid some of these hijacking attacks.

1:08.0

And that's probably why we didn't really see any widespread complaints about

1:12.7

Twitter outages, unlike back about 14 years ago in 2008, when YouTube's prefix got hijacked

1:22.1

by Pakistan, and that sort of caused widespread outages for YouTube.

1:28.2

So the good news here is that BGP is actually improving and it is making a difference.

1:34.5

If you want to test if your ISPP is using RPKI, is BGPS safe yet.com is a website Cloudflare set up to actually test your ISP.

1:49.0

I did get a bad response from it earlier today, but currently it seems to be working again.

1:55.7

If your ISP is subject to BGP hijacking, of course, there isn't really much that you sort of as an end user can do about it,

2:04.0

but TLS is your second layer here.

2:08.3

You should see TLS errors, so just don't click OK if you get a bad certificate from a site like Twitter.

2:17.3

And related to that are a number of distributed denial of service attacks against

2:22.8

sites related to the war in Ukraine and sites located in Ukraine.

2:29.1

The attacks, according to a story-in-pleaping computer, appear to originate from many compromised

2:36.6

verb-press sites that have JavaScript included in them.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.