SANS Stormcast Wednesday, January 21st, 2026: Punycode Hunting; telnetd vuln; 6 day Certs and IP Certs; Oracle Patches
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 21 January 2026
⏱️ 7 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Wednesday, January 21st, 2006 edition of the Sands Internet Storm Center's Stormcast. |
| 0:12.4 | My name is Johannes Ulrich, recording today from Jacksonville, Florida. |
| 0:17.6 | And this episode is brought to you by the sands, create your certificate program in penetration testing and ethical hacking. |
| 0:25.3 | A good reminder today from Xavier to, well, don't forget to look for international domain names in your DNS logs. |
| 0:33.8 | There are some legitimate international domain names, and of course, how many of them |
| 0:39.3 | you'll see depends somewhat on your users, which websites they frequent, but international domain |
| 0:46.0 | names also have the unfortunate ability to impersonate the more commonly used ASCII domain names. |
| 0:54.7 | And, well, that's exactly what Xavier is looking for here. |
| 0:59.2 | If you have a non-ASCII domain name, the label starts with XN dash-dash. |
| 1:06.1 | So that's one thing to look for. |
| 1:08.4 | In particular, if the top-level domain name is not an international top-level domain, |
| 1:14.3 | but a standard ASQ domain, that's often a hint that something fishy is going on here, |
| 1:19.3 | as in someone attempting to impersonate a particular website. |
| 1:23.3 | So take a look at that. |
| 1:24.7 | However, how effective this particular attack is also very much depends on the browser your users are using. |
| 1:31.4 | Safari tends to be a little bit more vulnerable here in that it's more likely to actually display those non-asky characters. |
| 1:40.3 | While a lot of other browsers, like, well, really a lot, or Chrome, |
| 1:44.6 | so the big other browser is typically showing the puny code, |
| 1:49.3 | which means the domain is then displayed with the XN-Dash-Dash prefix, |
| 1:53.9 | and no non-asky characters are being displayed. |
| 1:58.3 | So take a look at domain names or domain logs and see if you find anything interesting. |
| 2:04.4 | And always kind of like these warn abilities in old software that have been around for decades. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

