4.9 • 696 Ratings
🗓️ 31 March 2021
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello, welcome to the Wednesday, March 31st, 2021 edition of the Sands and the Storm Center's Stormcast. |
0:08.6 | My name is Johannes Ulrich, and the I'm recording from Jacksonville, Florida. |
0:14.2 | Jan today took a quick look at Shodan to see what TLS versions are used out there in the wild. And well, the surprising finding here was |
0:24.6 | that there is still a significant number of outdated servers running, for example, SSL version |
0:32.6 | 3. That was about 7% of servers that showed Ann catalogeded are running SL version 3, and another 1.6% are running SL version 2. |
0:45.9 | And, well, the latest greatest version of TLS, TLS 1.3 is operating on about a quarter of the servers, according to Shodan. |
0:56.1 | Now, one thing to keep in mind here is that Shodan does not take into account how popular |
1:01.9 | these services are. |
1:04.5 | Shodan actually sort of builds itself a little bit as the search engine for the Internet of |
1:09.7 | Things. |
1:10.0 | So a lot of these systems that Shodan discovered here are probably IoT-style devices. |
1:17.5 | And yes, they tend to be behind the curve on things like SSL, if they even support and have |
1:23.7 | properly configured SSL in the first place. |
1:26.8 | But this also kind of spells trouble as browsers are removing these old versions of SSL from their libraries, |
1:36.9 | because as a result now, users of these devices are no longer able to easily connect to these devices via SSL, typically forcing them to downgrade |
1:47.3 | to clear text. |
1:49.9 | And yesterday I mentioned that the NPM Netmask library has issues, how it's handling |
1:55.9 | octal IP addresses, and that this could lead to security vulnerabilities. Well, no surprise, other languages |
2:04.2 | have similar issues. A blog post published today looks at the best programming language ever. |
2:12.4 | Pearl and how its various IP address modules are dealing with this particular problem. And they found a |
2:21.5 | couple of them, for example, NetNet Mask, NetSider Lite, Net, NetIntyre Util, and others that |
2:29.4 | are affected by essentially the same problem. In particular, as these libraries are providing simple shortcut |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.