meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, March 18th 2020

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 18 March 2020

⏱️ 8 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. DDoS Summary; Trickbot Update; Is Cryptojacking Dead? Adobe Patches

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, March 18th, 2020 edition of the Sansanet Storms,

0:06.3

and I'm a recording from Jacksonville, Florida.

0:11.8

Over the last couple of weeks, I took a closer look at some reflective DNS denial of service attacks.

0:21.8

And while these attacks are not anything new, they are certainly not going away.

0:27.7

And I just want to get a feel for where these attacks are at currently.

0:32.1

Now, one thing that keeps popping up with these attacks is that the DNS records being used to amplify these attacks

0:39.7

are quite often.gov domains. Actually, in the sample here, and admittedly, this is a little bit

0:47.1

of random sample. It may be somewhat biased, but the number one domain by far being used here is access dashboard.gov.

0:57.2

We had before, for example, PeaceCorp.gov being used in this manner.

1:02.8

And part of the reason for this is not just that.gov domains, of course, are typically sort of considered trusted and not usually blocked.

1:13.7

The real problem here is that all.gov domains typically use DNSSEC.

1:19.7

And DNSSEC actually works in the favor of these denial of service attacks.

1:25.9

It does actually make them somewhat worse.

1:28.3

Because like in this case, this domain really only has one A record that's being returned

1:33.3

here, but they're also returning all of these DNSSEC records, all of the keys and the signatures,

1:40.3

and that increases the size of the response here to about 2 kilobytes.

1:47.1

Second domain, or second, I should say, record that was being requested as part of these denial of service attacks,

1:55.1

was also the name servers for the root zone.

1:58.8

Now, this priming response, as it's sometimes called, is often enabled on

2:04.8

Windows name servers. So that's why this is kind of a popular query, not quite as bad as some of these

2:13.9

dot-gov records, but still, you get 823 bytes in this response.

2:20.7

Now, the targets IRC servers, you know, again, sort of something that's not really going

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.