meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, November 15th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 15 November 2022

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. CONNECT Scans; Windows Kerberos Bug; Cookies vs MFA;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Tuesday, November 15th, 2020 edition of the Sands and its Storms anders Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida.

0:14.8

Jesse posted a quick diary with a Python script that he actually wrote to analyze some Connect attempts for his

0:25.1

Honeypot. Now, the Connect HP method is typically used by proxies in order to forward and

0:33.2

requests to a different web servers. And proxies are always sort of a hot target for these

0:39.9

internet-wide scans that we typically see in our honeypots. Now often they don't actually

0:46.1

bother with the connect method. Many proxies, often called transparent proxies, will forward

0:52.4

requests just based on the host name. But what Jesse saw is

0:57.1

he saw a significant increase in the number of connect requests. And summarized some of this

1:05.5

activity. Now, why are attackers looking for proxies? Some of it is sort of innocent in the sense that the attacker is just looking for some way to, for example, access a video platform that's blocked in their country.

1:21.6

I see a lot of requests like that, for example, in our DeShield data.

1:25.8

But at least one request that Jesse sort of pointed out

1:30.5

in his diary was looking for a Booter. A Booter is commonly referred to as a denial of service

1:37.8

platform, and of course they sometimes may need proxies in order to hide the true identity of their attacks.

1:47.5

So a lot of the times it's what I would consider sort of lower level or low skilled attackers

1:51.8

that are looking for proxies, but ever so often you may also run into an APT player or a more

1:58.2

advanced attacker who is really just sort of building up a platform in order

2:03.2

to attack other networks from.

2:07.2

It looks like there is one significant issue that multiple users reported with this month's

2:14.3

Microsoft update.

2:16.4

Bleeping computer has a good summary of it,

2:18.4

and apparently the problem here is that Kerberos sign-on

2:22.3

is no longer working if you are using an on-premise active directory server.

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.