meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, January 4th, 2023

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News, Technology

4.9696 Ratings

🗓️ 4 January 2023

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. NTP Fingerprinting; Misc Car Vulnerabilities; Flipper Zero Phish; Trend Micro Patch;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, January 4th, 2020 edition of the Sansonet Storm Center's Stormcast.

0:09.0

My name is Johannes Ulrich and I'm recording from Jacksonville, Florida.

0:14.0

Well, in Diaries today, I wrote up a little bit about profiling hosts or fingerprinting them using NTPD network

0:23.8

time protocol.

0:25.3

There are some well-known artifacts, like for example, the different host names that different

0:32.0

operating systems use in order to synchronize their time.

0:37.1

Like for example, time.microsoft.com or time.com,

0:42.3

but also within the pool.nTP.org domain, you have a couple of subdomains that are used by

0:49.2

specific vendors. What's not so well documented, something that I sort of took a quick step on here is

0:57.0

artifacts within the NPP payload itself. In order to make this more reproducible, what I did is I

1:05.0

basically collected the first NPP packet that comes from an operating system after it's being booted.

1:12.6

And there were a number of different artifacts, like for example, some of the older

1:16.6

NTP clients send packets from port 123 to 123.

1:22.6

The newer ones tend to use high ports.

1:25.6

Also, what polling interval is being used, changes a little bit

1:29.3

between different clients, and then also the client as part of its request is sending its own

1:38.0

timestamp. Well, some of the clients actually are randomizing this timestamp sort of as an

1:43.8

additional security feature.

1:45.5

If you're interested, well, take a look at the diary and if you have any input to this,

1:51.3

if you observe anything different here, then please let me know.

1:55.9

But note that some of these things, like, for example, whether or not the clock is synchronized

2:00.1

or not, or some of these flags, or things like the polling interval, they may change as the

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2025.