4.9 • 696 Ratings
🗓️ 25 May 2016
⏱️ 5 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, May 25th, 2016 edition of the Sansonet Storm Center's |
| 0:06.4 | Stormcast. My name is Johannes Ulrich, and today I'm recording from Seattle, Washington. |
| 0:12.8 | The US cert and very sign are warning again not to use your own internal top-level domain for things like WPAD, the protocol that automatically |
| 0:25.4 | assigns proxy servers. |
| 0:28.3 | This warning was released after VeriSign observed a large number of queries for some soon-to-be |
| 0:36.0 | assigned generic top-level domains to its global DNS servers. |
| 0:42.3 | Currently if this domain is not assigned, then of course you just get a failure in DNS lookup. |
| 0:49.3 | But once someone actually owns this top level domain they potentially could feed you |
| 0:56.0 | malicious proxy configurations the top one that very sign detected is dot global |
| 1:05.0 | but there are others like dot group dot death dot office prod, probably short for production, the number of other |
| 1:14.2 | top level domain names that people essentially just took for internal use and that maybe |
| 1:21.9 | then assigned as a new generic top level domain. |
| 1:25.6 | Now, theoretically, these queries should never really leave your network in the first place, |
| 1:30.3 | because your internal DNS server is supposed to resolve this if you sort of took over |
| 1:36.3 | that top-level domain. |
| 1:38.2 | But then again, mobile devices, laptops and like may leave your network. |
| 1:43.1 | The configuration remains intact |
| 1:45.5 | and then they will issue these queries to random external DNS servers. |
| 1:52.1 | At this point there are about 1,200 generic top level domains that have been issued. |
| 1:58.7 | Not all of them are actually in active use but they have essentially |
| 2:02.9 | been set up and they could be used at any point and sticking with DNS for a |
| 2:08.8 | moment here a new RFC was released 78 58 that proposes the use of DNS over TLS. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.