4.9 • 696 Ratings
🗓️ 3 January 2024
⏱️ 9 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Wednesday, January 3rd, 2004 edition of the Sans and at Storm Center's Stormcast. |
0:08.3 | My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
0:14.4 | Wrote a quick diary today about Azage identification strings. |
0:19.5 | These are essentially these banners that are being sent as |
0:22.9 | S-H clients are connecting to S-S-S-H servers. Both sites will send a banner. It's mandated, |
0:31.2 | actually, in the standard that there must be a banner and how it's formatted. But aside from the S-H version beginning, |
0:39.9 | it's pretty much up to the implementer, |
0:43.4 | what exact string to use. |
0:45.3 | So I looked at our Anipods to see what |
0:48.0 | as-H banners are being sent there. |
0:50.6 | Well, LipsH is sort of by far the most popular one. That's the standard Unix |
0:56.8 | S.H library followed by Go. And Go is sort of interesting here. Go is not what I would |
1:04.0 | call a super popular language, certainly quite popular. And one thing where it's really sort of |
1:09.9 | excels at is these multi-threaded |
1:12.6 | clients and servers, which of course makes it a great language to write little scanning tools and |
1:18.6 | such, which is why we see it so much here with SSH. But the real lesson I want to get across here |
1:25.0 | is that you should track these SSH identification strings, |
1:30.7 | in particular as far as they exit your network. |
1:34.7 | Not too much that you can do about those that scan your network, and sure you have a ton of |
1:40.1 | Mirai in similar bots doing it, but if you take a look at what's exiting your network, |
1:46.8 | you may see, for example, some odd backdoor |
1:50.8 | or Trojan communicating or maybe just an out-of-date version of a tool |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.