ISC StormCast for Wednesday, October 14th 2020
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 October 2020
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, October 14th, 2020 edition of the Sansonet Stormeners Stormcast. |
| 0:08.4 | My name is Johannes Ulrich, and the day I'm recording from Jacksonville, Florida. |
| 0:14.6 | Today, of course, Microsoft's Patch Tuesday, and with that we got patches for 87 vulnerabilities, 12 of which are rated critical |
| 0:25.7 | and 6 have been previously disclosed, but according to Microsoft, none of these vulnerabilities |
| 0:32.4 | have been exploited so far. Now the one vulnerability that sticks out because of its high CWS score of 9.8 is a remote |
| 0:43.6 | code execution vulnerability in the Windows TCP IP stack that can be triggered by an ICMP |
| 0:50.6 | V6 router advertisement packet. |
| 0:53.9 | So IPV6 is of course one of my favorite topics. |
| 0:57.0 | Just finished teaching the IPV6 section of SEC 503 |
| 1:01.0 | earlier today here in an online class. |
| 1:06.0 | Router advertisements are sent out by IPV6 routers |
| 1:10.0 | in regular instances or in response to a host |
| 1:14.1 | that just booted up and is looking for a router via a router solicitation. |
| 1:19.6 | Now there are a couple things that you usually find in these router advertisements. |
| 1:24.8 | You do find the hop limit that a router would like you to use to start |
| 1:29.2 | out with, the MTO of the network, and then you may find one or more prefixes that are used on |
| 1:36.4 | the network, and that can then be used by the host to come up with a routable IPV6 address. |
| 1:44.4 | The one feature that may actually matter here is that there is an option in IPV6 |
| 1:51.6 | to advertise DNS servers via these router advertisements. |
| 1:56.9 | And one of the workarounds mentioned here is that you should disable the recursive DNS server feature in ICMPB6. |
| 2:06.1 | So that's basically a hint that this feature may be to blame for what's going wrong here. |
| 2:14.2 | It's a little bit newer feature and not really all that widely used necessarily, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

