ISC StormCast for Tuesday, November 1st, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 1 November 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, November 1st, 2020 edition of the Sands and Storms anders Stormcast. |
| 0:08.7 | My name is Johannes Ulrich and I'm recording from Jacksonville, Florida. |
| 0:14.7 | Rob today wrote about NMAP without NMAP, always a popular topic. |
| 0:20.2 | In this particular case, Rob looked at a built-in PowerShell command. |
| 0:26.0 | It's part of the NetTCP IP module and its test net connection or short TNC. |
| 0:33.7 | This tool pretty much is meant to debug connection. |
| 0:36.3 | So with that, you're able to check if a port is |
| 0:40.5 | listening or not essentially one of the key features of nmap now one thing raw points out it's actually |
| 0:48.1 | pretty slow in order to do sort of a port scan of multiple ports but it also has even a trace route feature built-in. |
| 0:58.1 | A couple more tricks from Rob as part of his post, including how to improve the speed a little bit |
| 1:04.6 | for port scan, but still not really its strong point, but in a pinch if all you have is power shell and a couple |
| 1:15.0 | ports that need to be scanned it's probably a valid tool of course the big thing on tuesday will |
| 1:22.5 | be the open ssl update that's supposed to become available sometime in the morning East Coast time. |
| 1:30.2 | Now, we don't have really any details at all other than it will affect OpenSSL 3.0, which |
| 1:38.1 | was released about a year ago. |
| 1:41.2 | So any operating system that receives a major update within the last year |
| 1:47.3 | is likely vulnerable if it does include OpenSSL. OpenSL 1.1.1.1 is not affected. It will also |
| 1:56.4 | receive a patch, but it will not be a security patch. Well, as soon as we have more details on |
| 2:04.5 | Tuesday, we'll certainly try to dissect what it means and publish a post about it. And talking |
| 2:13.6 | about critical vulnerabilities connect-wise on Friday, |
| 2:18.6 | release an update for its recover and R1 soft server backup products |
| 2:24.7 | which suffer from a critical vulnerability |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

