meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, March 2nd, 2021

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 2 March 2021

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. DNS over TLS; Gootloader; AOL Phishing; Spectre in the Wild;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, March 2, 2021 edition of the Sandcent Storm Center's Stormcast. My name is Johannes Ulrich,

0:10.2

and I'm recording from Jacksonville, Florida. I'll also be notifying the winners of the February

0:18.1

Raspberry Pi Challenge within the next 24 hours.

0:22.2

So watch your email and respond so I'm able to ship them.

0:28.5

For March, I'll continue the same challenge as we had in February.

0:33.0

You either report an error that I made during the podcast or fill out the quick survey that we have on the podcast show notes page.

0:46.0

DNS over HTTP, DNS over TLS. These are two protocols that still gather a lot of interest.

0:55.3

And Rob today focused on the second one, DNS over TLS.

1:01.0

Not quite as popular, I think, as DNS over HTTP,

1:05.0

because first of all, it's relatively easy to block.

1:08.6

And secondly, it's not built into browsers as a DNS over

1:14.2

HTTP but on the other hand it's easy to install on for example a little router and

1:19.9

provide anonymize the DNS services for a particular network what eroded here is demonstrate some tools that help you find DNS over TLS endpoints

1:33.6

in your network, and then also how you test and query those endpoints.

1:39.2

There is a nice tool as part of NOT DNS, which is an alternative DNS server, KDick, that comes with

1:48.7

DNS over TLS build-in, so you don't need anything special, any other tools in order to probe

1:56.4

DNS over TLS server. And well, have you ever Googled for a question that you had, whether it's IT related or not?

2:06.8

I know I probably did that at least a dozen times just today.

2:10.8

And looks like the good loader malware, according to a write-up by Softus, is taking advantage of that.

2:19.3

Apparently, the group behind this malware is operating around 400 compromised servers

2:25.3

and using them for a good old Black Hat search engine optimization.

2:31.3

Now, in the past, this has often been used for a fairly simple, popular search

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.