ISC StormCast for Wednesday, October 5th 2016
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 5 October 2016
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Wednesday, October 5th, 2016 edition of the Sand Center and Storm Center's Stormcast. |
| 0:07.0 | My name is Johannes Orich, and the day I'm recording from Honolulu, Hawaii. |
| 0:12.0 | Now, always like it when users share a little log snippets with us that they find interesting and exciting and new and different. |
| 0:21.8 | We had a couple of them today that weren't exactly new, but there's still something that keeps |
| 0:26.7 | popping up. |
| 0:27.4 | So I decided to write it up as a diary. |
| 0:32.2 | In this case, it is an SSL client connecting to a non-SSSL web server. |
| 0:38.3 | This sort of leaves a fairly characteristic pattern in your weblogs |
| 0:44.3 | because your web server essentially interprets that SSL client hello request |
| 0:49.3 | as a request to the web server. |
| 0:53.3 | The connection of course will fail. You'll see for |
| 0:55.3 | example 400 errors in return that isn't really an attack against your web |
| 1:01.3 | server. It's really someone just probing web servers trying to find |
| 1:05.5 | web servers that happen to support SSL. Typically you'll see this if you have an web server that's listening |
| 1:13.1 | on a port other than 80, like 8,000, 80, and the like. Those web servers sometimes do indeed |
| 1:19.5 | respond to SSL requests and that's why you see these scans coming in. It is an attack, |
| 1:25.1 | but it's nothing really that's usually going to harm your |
| 1:29.3 | non-susel web server. So keep those logs coming. Certainly always appreciate to see what |
| 1:35.3 | other people are seeing in their web server logs or any logs for that matter. |
| 1:40.3 | And today Animus, the maker of the One Touch insulin pump and Rapid 7, did release joint |
| 1:47.4 | advisories on vulnerabilities in this insulin pump. |
| 1:51.9 | The research was done by Jay Ratcliffe, who has done research into insulin pumps for |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

