
ISC StormCast for Wednesday, April 26th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
00:00
The Problem With the Service Location Protocol
Johannes Ulrich: I ran an experiment with chat GPT. The goal here is for vendors like Apple that have these very brief vulnerability descriptions. This time it's the service location protocol which shouldn't really be used anymore. There are actually 54,000 SLP speaking devices connected to the public internet. It uses port 427 and by connecting to a vulnerable device an attacker is able to receive a list of services running within that local network.
Transcript
Play full episode