meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, December 23rd 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 23 December 2020

⏱️ 4 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Wifi Geolocation Malware; New Treck IP Stack Vulns; Detecting Treck IP Stack

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, December 23rd, 2020 edition of the Sands and it storms on us

0:07.5

Stormcast. My name is Johannes Ulrich, and today I'm recording from Jacksonville, Florida.

0:14.9

Savi did I put together an interesting diary looking at malware that actually uses the Wi-Fi network the user is connected to

0:23.3

in order to do geolocation. Now a lot of operating systems of course have sort of

0:28.8

build-in APIs that are using for example the PSSID of the local Wi-Fi network in

0:36.8

order to geolocation but often the user will be alerted

0:40.9

if this API is used. Instead here, it just essentially grabs the Mac address of the default gateway

0:49.3

and uses a website Milnikov.org, which is, looks like a hobby run website by Alexander Milnikov.

1:00.2

That's sort of where the name also comes from.

1:04.4

And the one thing that Xavier suggests is that you probably should kind of look out for hits to this particular host name

1:14.3

if this becomes more popular with Malder.

1:18.5

Of course, this could also be used to detect sandboxes and such,

1:23.1

where then the geolocation of the public IP address and the geolocation of the local Wi-Fi

1:31.3

network or network they're connected to are not matching up.

1:37.4

And back in June, we talked about the Trek IP stack, which is, well, one of those piece

1:43.9

of software that nobody

1:45.3

heard about, but everybody is using. This is an IP stack that you often find in embedded

1:52.3

devices, and there were a large number, about 30 different wall-on-a-lease that were found

1:58.4

in track IP. Well, once news like this comes out, of course, others start looking and we now have four different

2:08.6

new vulnerabilities that track patched in its IP stack.

2:12.6

The first one is actually not so many basic TCP IP protocol, but in the HTTP server component

2:19.5

that is included with Trekk, and this could cause a denial of service. Then two more

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.