4.9 • 696 Ratings
🗓️ 29 March 2023
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Wednesday, March 29th, 2003 edition of the Sansonet Storm Center's Stormcast. My name is Johannes Ulrich and today I'm recording from Jacksonville, Florida. |
0:14.3 | Jesse today wrote about how to collect the packet captures in a home lab network and what the different options are |
0:23.6 | and what sort of the different traffic you're seeing based on where you are placing your sensors. |
0:30.6 | The nice thing here is he used sort of a fairly cheap netgear switch with a span port in order to collect packets. |
0:38.3 | It's actually not a bad option for sort of a home network like this. |
0:42.5 | Not great in the sense that the tab is probably better, |
0:47.0 | but then again, those switches are significantly cheaper |
0:50.9 | and do the job quite well with the traffic level that you typically have in a lab network |
0:58.9 | like this. So interesting post here also he's comparing some of the different sensor types |
1:04.3 | that he's using and what type of traffic he's seeing in each. And Microsoft really wants you to patch your exchange servers, in particular if you're |
1:16.2 | hosting them in Microsoft's cloud. |
1:19.7 | The way they're now putting sort of additional pressure on administrators of out-of-date and |
1:26.4 | unpatched and vulnerable exchange servers is by throttling email from those known vulnerable servers to exchange online. |
1:36.3 | As Microsoft put it, if your exchange server is vulnerable, it's potentially exploited, and email can't really be trusted from |
1:46.7 | this exchange server. |
1:48.6 | There's sort of a warning phase of 30 days where you'll just see in your dashboard that |
1:54.2 | the mail server is out of date and needs to be updated. |
2:00.2 | Then there's an incremental increasement sort of every 10 |
2:03.4 | days where they start actually blocking email. And then after 90 days, if you're still not patched, |
2:10.6 | well, they will block all of your email. You have the option to sort of remove that block, |
2:16.6 | but only for 90 days per year. |
2:20.7 | The only other option is, well, to get your exchange server up to date. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.