meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, March 5th, 2024

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 5 March 2024

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. TAPs at Home; TeamCity Vuln; GitHub Push Protections; Android Update; Linksys Bug

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, March 5, 2020, edition of the Santernet Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:13.4

In today's diary, we have sort of an old topic renewed, and that's how you are capturing packets in Home Labs.

0:22.4

One of the quick and dirty ways to do that is a little passive tab, which has the advantage

0:28.3

that, well, first of all, it's cheap, it's simple.

0:31.0

You can even make them yourself as shown in this diary.

0:35.4

However, these simple tabs also come with some significant drawbacks, most notably

0:42.2

that they're limited to 100 megabit. So even many home internet connections probably will be

0:50.1

slowed down if you add a tap like this. My own sort of preferred solutions these days,

0:56.0

if you are on the budget, is a simple five port. Switch, there are now a number of switches

1:02.8

in the sort of $20 to $50 price range that offer a monitor port or a span port that works quite well in a setup like this.

1:14.3

A tab for a home network, typically doesn't have to be perfect, and you're certainly willing to

1:19.1

drop a couple packets here and there for a much lower price. eBay also always a great source

1:25.7

for some sort of more professional equipment, but that comes

1:30.1

with other disadvantages, like for example that it's usually quite noisy and sometimes

1:36.1

not easy to operate or requires special licenses.

1:41.0

Let me have more bad news for Team City users.

1:46.1

That's the JetBrains product.

1:49.2

It's had a couple of vulnerabilities earlier this year, and now we have three more

1:55.0

vulnerabilities that are allowing an unauthenticated attacker to access the Team City server as an administrator.

2:04.9

A patch was released by JetBrains today.

2:08.6

There is an update available that you can apply.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.