
SANS Stormcast Wednesday, March 18th, 2026: IPv4 mapped IPv6; KVM Vulnerabilities; AWS Bedrock DNS Covert Channel (#)
About this episode
Get every episode summarized
Each time SANS Internet Storm Center's Daily Network Security News Podcast publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
Transcript ready
66 searchable segments. Every word is indexed and playable.
Full transcript
SANS Internet Storm Center's Daily Network Security News Podcast — SANS Stormcast Wednesday, March 18th, 2026: IPv4 mapped IPv6; KVM Vulnerabilities; AWS Bedrock DNS Covert Channel (#). Machine-transcribed; use the interactive transcript above to jump the player to any line.
Hello and welcome to the Wednesday March 18th, 2026 edition of the Sands and then its storm centers. Stormcast, my name is Johannes Ulrich, recording today from Jacksville, Florida. And this episode is brought to you by the Sands.edu, Creative Certificate Program in Meditation Testing and Ethical Hacking. Today I took a little bit closer look at the IPv4 mapped IPv6 addresses that something that came up yesterday when I looked at these proxy requests in our honey pot and just to see a little bit how they work and how they're being used. Now, really these addresses should never be seen on the network. They're really sort of more an internal operating system construct to allow essentially IPv6 only software to still communicate via IPv4. But yes, they are still somewhat usable.
Now I did a quick test here with ping6, ping6 does not work because well even if it would convert it to IPv4 as it should, ping6 only sends IPv6 packets and that of course will not work. But other tools like for example WGET or your browser will happily accept these mapped addresses. They'll translate them to IPv4 and basically then communicate over the network just using the IPv4 address. Let's check this. What is sort of a security problem here with this? It could be abused for some kind of obfuscation like you often see people use odd IP addresses like octal formats or just the long integer format in order to obfuscate IPv6 addresses. This is really just another way to sort of encode an IP address as a string in that sense and probably doesn't really add any additional threat yet another reminder that you probably
shouldn't deal with IP addresses just as a string. Well look at the nature of the IP addresses if it's IPv4 it must be a 32 bit unsigned integer so treat them like that and that usually gets you out of trouble. And Paul Asadorian as well as Ronaldo was Cascarsia did publish a blog post for Eclipse him outlining some of the vulnerabilities they found in these cheap low end IP KVM systems. We talked about them before these are sort of these know anywhere between sort of 25 and $100 IP KVM systems that have become quite popular in the past and I wrote in the past also about how to better secure them. I was actually a little bit almost surprised the positive side that they didn't for the most part find any sort of you know huge vulnerabilities. There's one vendor that is labeled here where they had a remote code execution vulnerability.
That vendor is also in so far problematic as there appear to be no patches forthcoming to address these vulnerabilities. The other vendors there were some one which should be fixed like for example brute force prevention was missing for some of them. That's of course a problem with devices like this that are pretty much secured with username and password and also something that's not that terribly hard to do for a device that really only has sort of one real user. But the other vendors are coming up with patches if they haven't already been released. So in so far that part of market doesn't seem to be as desolate in some ways as the rest of the IoT device market. The one problem that's coming up with the recent craze about AI agents is the problem that well how do you allow an agent to securely execute code that they created.
One solution of course is sandboxing and AWS does offer the betrock agent core interpreter. That's a sandbox will be the interpreter to code that the agent wrote and then well basically run it. Now this sandbox is supposed to be isolated with that limit sort of the exposure to the outside world and any attacks well turns out this is not quite true beyond trust found that the agent inside a sandbox is still able to send and receive DNS traffic. So this way DNS can be used as the good old cover channel that's really sort of what in some cases are almost feel DNS was intended to be and with that you now gain access to the sandbox and also outbound from the sandbox that isn't supposed to happen that sort of why you originally used the sandbox they have reported this to AWS and AWS has deployed
respective fixes but yet another example where you have to be careful and in general the idea of sandboxing agents is still sort of I think at least under development in the sense that it's really hard to have a useful agent and not give it access to anything. So the sandboxes even if you pre-populate them with data or so you want the agent to act on are usually somewhat limited in their functionality well and that's all we have time for today so thanks for listening thanks for liking thanks for subscribing and as always special thanks for leading dot comments in your favorite podcast platform and talk to you again tomorrow bye.
More episodes
More from SANS Internet Storm Center's Daily Network Security News Podcast

SANS Stormcast Friday, March 20th, 2026: Cowrie Strings; MSFT Intune Hardening;...
SANS Internet Storm Center's Daily Network Security News Podcast

SANS Stormcast Thursday, March 19th, 2026: Adminer Scans; Apple WebKit Patch; an...
SANS Internet Storm Center's Daily Network Security News Podcast

SANS Stormcast Tuesday, March 17th, 2026: Proxy URLs; Local Network Address Rest...
SANS Internet Storm Center's Daily Network Security News Podcast

SANS Stormcast Monday, March 16th, 2026: SmartApeSG and Remcos RAT; React Based...
SANS Internet Storm Center's Daily Network Security News Podcast