meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Tuesday, October 22nd 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 22 October 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. DNS over TLS Scans; North/Thor/Viking/VPN Compromises;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Tuesday, October 22nd, 2019 edition of the Santernut Storms, Stormcast. My name is Johannes Ulrich.

0:09.3

Entertainment recording from Santa Monica, California.

0:13.9

Actually, just earlier today, I gave a talk here that in part covered DNS over TLS.

0:20.4

So very fitting that Jim took a look at recent scans against Port TCP 853.

0:29.1

Port 853, of course, is the DNS over TLS port, usually using UDP, not so much TCP,

0:36.6

but still this could be an attempt for attackers

0:40.3

to enumerate possible DNS over TLS resolvers, possibly for denial of service attacks.

0:49.3

Now what isn't really clear is if these servers could be used similar to normal DNS recursive

0:56.5

resolvers because typically in order to use DNS over TLS, you first need to establish the

1:02.7

TLS connection, which does require a couple of packets going forth and back, so spoofing

1:09.2

isn't really as trivial as in your standard

1:12.4

UDP-based DNS without TLS.

1:16.3

So it's a little bit open-ended here, not sure what's happening with these scans, whether

1:22.0

it's just curiosity or researchers.

1:24.3

If you have any insight, please let us know.

1:29.2

And then today we have a couple of stories actually that relate to issues in security vulnerabilities,

1:35.3

in security tools. First, a couple of VPN providers apparently got breached. First of all, NordVPN, but in addition to

1:47.1

NordVPN, also Thorgard and possibly Viking VPN, were compromised according to a number

1:55.3

of tweets and posts to 8chan.

1:58.9

The evidence that was presented here are mostly TLS secret keys that were apparently

2:05.8

collected from these affected services.

2:10.4

NordVPN did issue a statement confirming the attack, stating that this was due to an insecure server administration tool

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.