meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, May 22nd 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 21 May 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Shodan Monitoring; Smartphone Fingerprinting; Docker Password Issues; #bluekeep #suricata sigs;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, May 22nd, 2019 edition of the Sandsenet Storm Center's Stormcast. My name is Johannes Ulrich.

0:09.5

And today I'm recording from Jacksonville, Florida.

0:13.4

Quick diary today from Tom about how to use Shodan's monitoring feature. Now, this is a for-pay feature, I believe you have to be at least a member which is pretty

0:24.4

cheap or then sign up for their more expensive small business plans if you do want all the

0:31.8

features of it.

0:33.5

But even the basic features do essentially allow you to set up alerts whenever Shodan

0:40.3

discovers a new system inside your network.

0:45.3

As Tom points out, you can do the same thing with a simple NMap scan from outside your network,

0:51.3

but getting Shodan's view and getting the alerts maybe a nice little addition

0:57.8

to some regular external vulnerability scans.

1:01.8

And then we got yet another way to identify smartphones in particular iOS devices before iOS 12.2.

1:13.5

The trick here is that all of these devices do have motion sensors or gyroscopes that

1:20.6

are accessible via JavaScript and have a unique bias as to how these sensors are oriented.

1:30.3

By subtracting any motion that device experience at a time it's being used when it's, for example,

1:36.3

being carried in a bag, these researchers were able to then extract this essentially

1:43.3

calibration data from the gyroscope and identify

1:48.0

individual devices.

1:50.0

Apple in iOS 12.2 started to add some random noise to the output in order to defeat this technique.

2:00.0

And apparently this technique may have been used in the wild out of Alexa's top 100,000 websites,

2:08.9

about 2,600 did access motion sensor data.

2:14.7

Not really clear, of course, if this was done in order to identify the devices.

2:19.2

A lot of user trackers and tools like this, but also just check if your gyroscope is accessible

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.