ISC StormCast for Wednesday, January 20th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 January 2021
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, January 20th, 2021 edition of the Santernut Storm Center's Stormcast. My name is Johannes Ulrich. |
| 0:10.5 | And the time recording from Jacksonville, Florida. |
| 0:15.2 | And looks like one after one, the hacker groups are coming back from vacation after we had Hank Gator last week. |
| 0:25.4 | This week, Brad is talking about quagbot. |
| 0:29.4 | Quagbot has not been seen since a few days before Christmas. |
| 0:35.1 | And well, on Tuesday, it came back with the latest wave of malicious spam. |
| 0:42.8 | The spam is typically a sip attachment. If you open this latest wave, you'll get an Excel |
| 0:49.9 | file that claims to be a docu sign document and then it tricks you into enabling macros by |
| 0:56.6 | telling you, well, in order to sign the document, you need to enable macros. By enabling |
| 1:02.8 | macros, it will then download a DLL that will load additional malware via HDPS. |
| 1:12.4 | As usual with Pratt's diary, you'll find all the evidence packet captures linked in the diary. |
| 1:22.2 | And researchers at the JSOF research lab found a number of vulnerabilities in DNS Mask. Dinesk Mask is a very popular |
| 1:33.3 | DNS forwarder. You often find it in small firewalls and routers, typically Linux or BSD-based |
| 1:43.0 | devices. And all it typically does is it will take DNS queries from a network and then forward it to either |
| 1:53.0 | a specific name server or just act as a recursive resolver. |
| 1:59.0 | The vulnerabilities discovered here are really falling into two categories. |
| 2:04.1 | There are a couple of issues that make it easy to spoof responses. |
| 2:09.5 | For example, the source port is not really randomized. |
| 2:14.5 | Only 64 different source ports are being used by DNS mask, leading to essentially |
| 2:21.5 | the well-known Kaminsky attack from a few years back. |
| 2:26.7 | In addition, Resolver is supposed to verify that a response, not just the query ID matches, |
| 2:33.9 | but also the query included in the response |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

