Light

Episode #837 Quiz

Cobalt Strike
Date: 2021-09-21 | Length: 1.75 hrs | Episode page at twit.tv

About this episode

The episode covers a prolonged ransom DDoS campaign against VoIP.ms, where attackers first crippled DNS and then targeted direct IP access, forcing hosts-file workarounds and Cloudflare migration. It also details Microsoft and Chrome patching multiple zero-days, Android permission auto-reset backporting, and Cobalt Strike’s Beacon, a covert post-exploitation agent abused for remote control.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What specific service did VoIP.ms tell customers to edit locally in order to bypass DNS resolution during the attack?
Question 2: According to the episode, what was the main reason Steve said traditional web DDoS protections were not applicable to the VoIP.ms attack?
Question 3: What change did VoIP.ms make to mitigate the impact once attackers began targeting the domain name and then the direct IP address?
Question 4: Which two Chrome zero-day vulnerabilities did Google patch in the release discussed in the episode?
Question 5: What did Proofpoint say about the proportion of identified Cobalt Strike campaigns attributed to known threat actors after 2019, compared with 2016 through 2018?
Cancel