meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 18th 2017

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 17 January 2017

⏱️ 5 minutes

🧾️ Download transcript

Summary

Daily 5 min infosec news summary. News, patches, vulnerabilities and trends in information security. Efficient Whois Lookups; Dovecot Passes Audit; Secrets in Mobile Apps

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, January 18th, 2017 edition of the Sands Internet Storm Center's Stormcast.

0:08.0

My name is Johannes Ulrich.

0:09.3

And today I'm recording from Brussels, Belgium.

0:12.8

Mark Bagot wrote up a new script that he released that allows you to relatively efficiently look up who is information for domains.

0:22.2

The main feature here is that it will whitelist domains

0:25.9

that are, for example, part of the top Alexa domains

0:29.7

and only pull who is information if the domain is not listed.

0:35.6

It then particularly checks the created date in order to figure out if the

0:40.9

domain was recently created and if it was created within the last 90 days, the script will consider

0:48.6

the domain as new and with that somewhat suspicious. So the idea here is to have a relatively small number

0:56.2

of domains that will actually have to be looked up via Whois because Who Is is slow. Also can get

1:01.5

you placlisted if you're looking up too many domains and at the same time you will get a list

1:07.5

of new domains which of course are often involved in malicious activity.

1:13.5

And then you have a vulnerability disclosure for remote code execution vulnerabilities

1:19.0

in Sychcel and billion routers.

1:22.6

Now, these routers are not vulnerable by default, but Thai ISP true online does install custom

1:31.5

firmer on these devices which does introduce several remote code execution flaws, some

1:38.5

of which do not require authentication.

1:42.0

There are a few million customers of this particular ISP affected.

1:46.7

Not clear if other ISPs may use similar firmware, but this particular problem appears

1:53.3

to be limited to modems that are distributed by this particular ISP.

1:59.7

But then we also have some good news to report. The German penetration

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.