4.9 • 696 Ratings
🗓️ 2 August 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, August 2, 2023 edition of the Sansonet Stormer's Stormcast. |
0:07.7 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
0:13.7 | Today I wrote up some of the queries that we are seeing against our web application Honeypot. |
0:20.5 | These queries are looking for |
0:22.7 | DNS over HTTP resolvers. DNS over HTTP has become quite popular given that all the browsers |
0:30.6 | are supporting it and is of course one of the features that not just attackers are looking for, |
0:36.9 | but also people who pretty much |
0:38.9 | just want some privacy. |
0:41.5 | Now, many networks are blocking well-known DNS over HTTP resolvers, which leaves these |
0:49.0 | individuals then up to essentially hunting for open resolvers. |
0:54.4 | They may find the setup and configured by third parties |
0:58.7 | that are not necessarily sort of well-known in databases. |
1:03.1 | And that's, I believe, what we are seeing here in some of the data. |
1:07.8 | Now, some of it may also be companies that are probably assembling blocklists |
1:12.9 | to block these DNS over HTTP resolvers. Sadly, I think our data here is still a little bit |
1:20.1 | limited. I configured a couple of honeypots to actually implement DNS over HTTP and to resolve |
1:27.4 | these queries, |
1:28.3 | but haven't really seen anything in these honeypots |
1:31.4 | beyond just simple sort of fingerprinting, |
1:35.4 | like we see against the random web server honeypots too, |
1:40.1 | which don't actually implement the DNS over HDPS protocol. |
1:46.4 | Kasperski published a report with details regarding a tool that they found deployed in |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.