meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, May 30th 2018

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

News, Tech News

4.9754 Ratings

🗓️ 29 May 2018

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. New DNS Features; Apple Updates; EOS Scans; NPM isn't a Teapot; SQL As Covert Channel

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, May 30th, 2018 edition of the Sansonet Storms, Stormcast. My name is

0:07.5

Johannes Ulrich and I'm recording from Jacksonville, Florida. Recently, I have been seeing more and more

0:14.1

talk about two different DNS features. So I wrote them up with a little bit of real packet captures in case someone is interested in them.

0:23.6

First feature is DNS cookies.

0:26.6

That's supposed to replace or at least augment DNS sec somewhat.

0:32.6

DNS sec, of course, is not all that easy to set up DNS cookies, set themselves up pretty much

0:40.5

automatically.

0:42.3

So the hope is that it's safe enough and a lot easier to deploy than DNSSEC.

0:48.8

Now Ubuntu 18.04 LTS, which was just released, has this feature enabled by running the latest version

0:59.4

of Bind. The other issue DNS over TLS has gotten a real big boost recently with Cloud

1:07.5

Flair supporting it on their Quad quad one DNS servers that data deployed.

1:13.6

Another issue that probably helps with DNS over TLS is that the very popular DNS forwarder

1:21.6

Unbound supports it. Unbound is pre-installed in many Linux and BSD-based firewalls.

1:29.6

So if you have one of them, it may be possible to enable it on your firewall.

1:35.4

The advantage of DNS over TLS is privacy.

1:39.4

It doesn't really protect anybody from reflective attacks or from spoofing, but it does protect

1:46.7

the connection from the client to the respective recursive name server, which of course

1:51.9

in this case would probably be Cloudflare's name server.

1:56.3

But well, enough about DNS, let's take a look at other news.

2:00.6

Apple today released an update for iOS and

2:03.9

watchOS as well as for iTunes and TV OS. Notably missing here is Mac OS. The main focus here

2:14.1

was a set of new features around iOS. Now, the problem is that these patches,

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.