4.9 • 696 Ratings
🗓️ 10 February 2025
⏱️ 7 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Monday, February 10th, |
0:03.0 | 2025 edition of the Sands and its Storm Center's Stormcast. |
0:08.0 | My name is Johannes Ulrich, |
0:09.7 | and I'm recording from Jacksonville, Florida. |
0:13.0 | Today, as I'm recording this, |
0:14.3 | it's also the 16th anniversary of this podcast. |
0:19.1 | Started all February 9th, 2005. Didn't actually realize it's already that long |
0:25.8 | running. Hope also enjoyed. Actually, thanks for some of the feedback that I've gotten based |
0:31.5 | on my request on Friday. But well, it's not just the podcast that's having its birthday today. So does SSL version 2 and Jan on |
0:43.0 | Friday took a closer look at how many SSL version 2 servers are still connected to the internet. |
0:49.6 | The absolute number may surprise people. It's 423,000 IP addresses, according to Shodan. |
0:59.2 | Well, however, it is really only a very minuscule percentage of all the HEP servers exposed to |
1:06.0 | internet in total. So I think this 400,000 number sounds a bit more scary than actually is. |
1:13.6 | However, one thing that John points out is if you are finding a web server that still supports |
1:20.3 | SSL version 2 in your environment, we're talking about SL version 2, not SSL version 3, |
1:27.4 | chances are that this web server is overall running very out-of-date software. |
1:34.2 | The protocol SL version 3 started to be deprecated 14 years ago in 2011. |
1:41.3 | So that essentially means that this particular device, this particular software, has not really |
1:47.5 | received any major updates for at least a decade. With that in mind, if you do find any of |
1:55.8 | these devices, let me actually know what you find. I have to take a closer look at the |
2:00.5 | showdown data. I suspect a lot a closer look at the Showdown data. |
2:01.5 | I suspect a lot of things like webcams and such |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.