meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, September 28th, 2022

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 28 September 2022

⏱️ 7 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. DNS Option 15; YARI for YARA; HTTP Archive Almanac

Transcript

Click on a timestamp to play from that location

0:00.0

Hello and welcome to the Wednesday, September 28, 2022 edition of the Sandstone Storm Center's Stormcast.

0:09.2

My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida.

0:15.1

Already this week, I was playing with self-hosting a domain that supports DNS sec.

0:21.1

Usually I leave this up to Google or whatever registrar, but in this case, I want to

0:27.9

flexibility to do it myself, so while setting up the domain, enabling the new DNS features

0:33.6

and bind and adding the respective DS records to the registrar.

0:39.3

Well, I unsurprisingly ran into some problems.

0:43.3

I wrote a little bit about what the problems were and some of the DNS intricacies in the diary.

0:50.3

But here I just want to sort of highlight the key point and that's a nice find about a new DNS

0:58.1

feature that is at least supported by Cloudflare's DNS servers, maybe others, not sure

1:06.6

who exactly is using it, but I noticed it with a cloud flare.

1:12.7

Now, if something goes wrong with DNS, you usually get a server fail error, but there are

1:18.7

many different reasons why you may get that error.

1:21.8

So in itself, getting the error just tells you something is wrong.

1:25.3

It doesn't tell you what is wrong or why that

1:28.8

name server wasn't able to resolve that particular record. Well, RFC 8914, it's about two years old now,

1:39.5

introduces a new DNS option to help with that option 15. This option is added a response when you're

1:47.3

getting the server fail error and includes a code that tells you a little bit more about

1:53.6

what the exact failure is and then also a little bit of ASCII text that will explain you

2:00.5

why you're seeing that particular error.

2:04.2

In my case, well, it was pretty clear. I got the code 10, which means there were no signature

2:09.7

records in my zone. Now, the text actually still helped very much. I didn't find the text

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.