ISC StormCast for Tuesday, November 8th, 2022
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 8 November 2022
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, November 8, 2020 edition of the Sands and its Storm Center's Stormcast. |
| 0:08.4 | My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida. |
| 0:14.1 | Quick diary actually from yesterday from DDE about converting different representations of IP addresses, something scammers like to do, |
| 0:23.5 | in particular in spam and such, in order to obfuscate the actual address a user is connecting |
| 0:30.6 | to, well, IPV4 addresses can be represented many different ways, and browsers are quite |
| 0:37.3 | forgiving in what users may enter. |
| 0:40.4 | There's Octal. |
| 0:41.5 | There's just the long integer form, |
| 0:44.4 | and then, of course, host names in various variations. |
| 0:47.2 | So DDA is showing how to de-obfuscate some of these representations in Cybershift. |
| 0:55.6 | And Microsoft announced that it made the preview for Asia Active Directory authentication |
| 1:01.6 | with a certificate, so certificate-based authentication, available to pretty much everybody at this |
| 1:08.1 | point. |
| 1:08.8 | So if you're using Azure Active Directory, |
| 1:12.2 | give it a try, see how it works for you. |
| 1:14.5 | Essentially, it uses a certificate stored on Ubiki as your credential, |
| 1:21.1 | and then you can authenticate using your mobile device. |
| 1:25.7 | This is supposed to support iOS as well as Android on the mobile end, |
| 1:31.5 | and is supposed to be fishing resistant, which means that the machine, the mobile phone here |
| 1:38.2 | likely, decides how to authenticate based on certificates presented by the site. So this way the user doesn't really have |
| 1:47.1 | an option to enter their credentials into the wrong site. Not all two-factor authentication is |
| 1:53.8 | necessarily a phishing resistant, like for example, these one-time password codes like Google |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

