4.9 • 696 Ratings
🗓️ 28 July 2025
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Monday, July 28, 2025 edition of the Sands and then at Stormsendors, Stormcast. |
0:07.8 | My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
0:12.3 | And this episode is brought you by the Sands.edu credit certificate program in cloud security. |
0:19.4 | In diaries this weekend, we have one by Xavier looking into, well, |
0:23.9 | we'll need Linux feature, and Xavier looks at it from sort of a reverse analysis point |
0:29.8 | of view, but it's really very applicable for a number of different security tasks, |
0:35.9 | and that's Linux namespaces. Essentially, each process in Linux |
0:40.7 | may have sort of its own namespace, its own view of the environment. And in this particular |
0:47.7 | case, Xavier looked at networking, where first of all, you are able to just simply turn off networking capabilities for a particular process with the pseudo-unshare dash-net bash command. |
1:02.1 | That basically gives you a bash shell without networking. |
1:06.2 | And now if you try to analyze some malware, well, that malware can no longer communicate outbound. |
1:12.8 | But it goes more fine crane than that. |
1:15.4 | You can also just set up a different routing table for this particular process. |
1:21.8 | And for example, redirect traffic to sinkholes and the like. |
1:25.2 | Quite often when you're analyzing malware, you don't want to turn off networking altogether |
1:29.3 | because the malware will not run if it can't download second stage and such. |
1:34.0 | But you just want to capture, like, what is that second stage? |
1:36.9 | It's downloading and then send the request to a sinkhole where you're just recording the HTTP requests. And that's sort of, you know, |
1:46.5 | where this feature is really helpful. But like I said, net namespaces in Linux can do a lot more |
1:52.4 | things. There's for file systems and mounts, so similar features that you have available as you |
1:58.0 | have for networking. And I think it's a little bit an overlooked sort of security feature in general when it comes to a Linux. |
2:04.4 | A lot of even experienced Linux administrators often haven't really heard of namespaces and how they can be used. |
... |
Transcript will be available on the free plan in 6 days. Upgrade to see the full transcript now.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.