ISC StormCast for Wednesday, October 20th, 2021
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 20 October 2021
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, October 20th, 2021 edition of the Sansonet Storm Center's Stormcast. |
| 0:08.8 | My name is Johannes Ulrich, and the time recording from Riyadh, Saudi Arabia. |
| 0:14.6 | Well, you probably have heard of the great Chinese firewall and its ability to block certain keywords for users within China. |
| 0:24.6 | Occasionally here suggestions that it's possible to simply block mail connections with that, |
| 0:30.6 | a lot of spam and also just simple scanning by returning some of these keywords to anybody connecting to your mail server. |
| 0:42.5 | So this last couple of weeks, I ran a little experiment where I first basically left my |
| 0:46.8 | mail server alone, then later set up a mail server banner that included some of these |
| 0:53.4 | keywords to see whether or not this will |
| 0:56.9 | reduce the number of connections from China. Didn't look like it really made a difference. It |
| 1:02.4 | went from 11% to 9% of the IP addresses connecting to the mail server. We're from China. This is |
| 1:10.2 | really sort of within the error of the measurement. |
| 1:14.1 | So I really think that experiment has been somewhat inconclusive or if at all proving that |
| 1:19.9 | these simple keywords probably don't make enough of a difference. |
| 1:24.9 | We'll leave it running for a while and see if maybe over time there is a |
| 1:29.6 | change, but looks like at least just simply returning them as a banner doesn't make a difference |
| 1:35.8 | and, well, also probably should try a couple different keywords because there is no real sort of |
| 1:40.7 | official list of blocked keywords. |
| 1:50.7 | And the FBI released a public service announcement regarding a number of websites that are impersonating government assistance websites in an attempt to steal users' personal data. |
| 1:58.3 | Essentially, fishing these websites are using some look-alike domain names, usually |
| 2:04.9 | at least the list that the FBI published. They use the dot XYC top-level domain, and well, |
| 2:13.1 | then they are asking users for personal information under the pretense of signing up for some form |
| 2:21.0 | of unemployment or other assistance. Given that October is the Cybersecurity Awareness Month, |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

