Handler on Duty: Johannes Ullrich
Threat Level: green
Podcast Detail
If you are not able to play the podcast using the player below: Use this direct link to the audio file: https://chrt.fm/track/2748D7/https://traffic.libsyn.com/securitypodcast/3503.mp3
My Next Class
Application Security: Securing Web Apps, APIs, and Microservices | Denver | Oct 2nd - Oct 7th 2024 |
Network Monitoring and Threat Detection In-Depth | Singapore | Nov 18th - Nov 23rd 2024 |
Interested in Internet Storm Center stickers? Check here if there are still some available for today.
NYTimes/Twitter Compromise
https://isc.sans.edu/forums/diary/NY+Times+DNS+Compromised/16451
MSFT Refreshed Patches
https://isc.sans.edu/forums/diary/Microsoft+Releases+Revisions+to+4+Existing+Updates/16448
NIST SP800-40 Document about Patch Management
http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r3.pdf
HTTP Nowhere
http://threatpost.com/firefox-extension-http-nowhere-allows-users-to-browse-in-encrypted-only-mode/102108
https://isc.sans.edu/forums/diary/NY+Times+DNS+Compromised/16451
MSFT Refreshed Patches
https://isc.sans.edu/forums/diary/Microsoft+Releases+Revisions+to+4+Existing+Updates/16448
NIST SP800-40 Document about Patch Management
http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r3.pdf
HTTP Nowhere
http://threatpost.com/firefox-extension-http-nowhere-allows-users-to-browse-in-encrypted-only-mode/102108
Discussion
What about the Domain Lock feature offered by Registrars? As I understand it, additional credentials are required to change a DNS record. Would that have thwarted the attack since only the login credentials were compromised and leveraged to facilitate the attack?
Posted by LawsonPoling on Thu Aug 29 2013, 13:58
Are there any utilities available to easily monitor your DNS zones for changes?
New Discussions closed for all Podcasts older than two(2) weeks
Please send your comments to our Contact Form
Application Security: Securing Web Apps, APIs, and Microservices | Denver | Oct 2nd - Oct 7th 2024 |
Network Monitoring and Threat Detection In-Depth | Singapore | Nov 18th - Nov 23rd 2024 |
Application Security: Securing Web Apps, APIs, and Microservices | Washington | Dec 13th - Dec 18th 2024 |
Application Security: Securing Web Apps, APIs, and Microservices | Online | US Eastern | Jan 27th - Feb 1st 2025 |