SANS Stormcast Thursday, September 11th, 2025: BASE64 in DNS; Google Chrome, Ivantii and Sophos Patches; Apple Memory Integrity Feature
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 11 September 2025
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Thursday, September 11th, |
| 0:07.7 | 2020-5 edition of the Sands Internet Storm Center's Stormcast. |
| 0:12.8 | My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:18.1 | And this episode is brought you by the sands.edu graduate certificate program in |
| 0:23.1 | penetration testing and ethical hacking. Well, today's diary was inspired by a story I covered |
| 0:29.8 | last week about botnet that used DNS for remote command and control, but they encoded the commands using base 64. |
| 0:41.0 | Did he today notice, well, hey, base 64 actually contains a couple characters like the slash |
| 0:47.4 | and the equal symbol that must not show up in DNS host names. |
| 0:53.3 | So how did they actually do it? Well, it turns out as so often |
| 0:57.3 | that sometimes things that aren't supposed to work still work under certain circumstances. |
| 1:03.6 | And what did he found out is that, for example, NS Lookup. If some of these odd characters |
| 1:09.2 | are being returned, well, it works just fine with NS lookup. |
| 1:13.6 | This is actually an important lesson that I often cover when I'm talking about web application security, |
| 1:19.5 | that you can't really trust that protocols like DNS only return valid content. |
| 1:26.6 | I think it was a few years ago I've written about this and maybe I have to write about |
| 1:32.2 | it again because I'm not sure where it ended up. |
| 1:35.7 | But for example, it is certainly possible to do things like SQL injection and cross-site |
| 1:41.6 | scripting over DNS. |
| 1:43.8 | If you're not careful in cleaning up and validating responses, |
| 1:48.1 | you're getting back via DNS, very famously, who is, of course. |
| 1:51.7 | Now, that's just plain text. |
| 1:53.1 | There are a number of who is entries that have existed in the past with exploits in |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

