[00:00.000 --> 00:01.080] I can launch the missiles. [00:01.240 --> 00:02.280] They're all written like that. [00:02.440 --> 00:07.500] They're written with these really vague, any, you know, any use can be potentially illegal. [00:07.680 --> 00:09.040] And it scares me. [00:09.160 --> 00:10.040] It should scare you guys. [00:11.580 --> 00:12.820] I'm going to give some lessons. [00:12.860 --> 00:19.280] And the biggest rule I want to say is it's really hard to tell the criminals, the people we want to stop. [00:19.480 --> 00:21.480] We want to hold them aside and say they're bad. [00:21.620 --> 00:24.080] And people that do, well, what we do. [00:24.420 --> 00:31.880] You know, if you're researching security, if you are helping, you know, helping your corporate clients. [00:32.500 --> 00:34.880] And I decided to be a little cheesy. [00:35.120 --> 00:37.440] So it's really hard to tell the criminals apart from the good guys. [00:37.760 --> 00:40.100] So we have a freelance security researcher. [00:40.660 --> 00:43.340] Now, evil computer criminal. [00:43.420 --> 00:44.780] Can anyone tell the difference here? [00:46.600 --> 00:50.300] And the friendly guy at the help desk, you know, who's trying to fix your stuff. [00:51.620 --> 00:52.080] Okay. [00:54.400 --> 00:57.720] Lesson number one, just because you can do it doesn't make it doesn't make it legal. [00:58.640 --> 01:02.840] Think of usual business business practices for defending your stuff or doing research. [01:04.420 --> 01:09.960] It's fairly normal to go and rifle through, you know, huh, something's acting wacky on my network. [01:10.500 --> 01:12.400] One user is doing something odd. [01:12.560 --> 01:19.440] I should go and basically poke around their system to figure out who they are and if they're up to no good or if they're just being, you know, weird or clumsy. [01:21.120 --> 01:26.080] And I give an example of a recent case out of North Dakota. [01:26.680 --> 01:30.340] This guy, David Ritz, it's kind of a pain in the ass. [01:30.520 --> 01:36.380] But he basically suspects Sierra of doing something wrong. [01:36.720 --> 01:39.300] I'm not sure what, because I've only read the court documents. [01:39.360 --> 01:40.800] He never actually says what he's doing. [01:40.980 --> 01:45.360] But he basically gets, does his own transfer on Sierra's DNS servers. [01:45.540 --> 01:47.160] What are all the machines you've got? [01:47.380 --> 01:47.740] Okay. [01:48.840 --> 01:57.620] And from an IT point of view, if you didn't want to give up that information, you wouldn't allow, you wouldn't allow the DNS server to give you his own transfer, right? [01:57.820 --> 02:02.520] You know, like, it's sort of like, if you did you didn't want me in this room, you should have locked the door. [02:05.160 --> 02:09.580] Unfortunately, Sierra seems to have a better lawyer than Ritz does. [02:09.680 --> 02:13.160] And they successfully argue, we didn't grant you permission. [02:13.500 --> 02:19.080] We didn't grant you permission to go run host dash L on our system. [02:19.260 --> 02:25.460] And you have obtained important data about our company. [02:25.780 --> 02:28.780] Now he's on the hook for and now it's only civil charges. [02:28.780 --> 02:29.720] It's not criminal charges. [02:29.720 --> 02:37.020] But he, if the DA had the same thought, would have been, sorry, that's five years, up to five years in prison for computer hacking. [02:37.240 --> 02:40.040] For doing something that, it's one line. [02:40.220 --> 02:41.100] It's not elite. [02:42.180 --> 02:52.280] And I give the analogy to some people that, you know, downstairs there's this place where they have all this stuff that's useful, like, you know, beverages and snacks and whatnot. [02:52.480 --> 02:53.780] And I can just take it and walk out. [02:53.880 --> 02:54.820] It's a convenience store. [02:55.620 --> 02:58.820] Just because you can take it and walk out doesn't mean it's not illegal. [02:59.900 --> 03:01.360] Okay, where is this going? [03:01.900 --> 03:03.360] Possible does not equal eagle. [03:04.640 --> 03:12.640] Also, when you, with these nice, vague, gooey laws, a prosecutor who's got a bone to pick can make them hurt people. [03:13.280 --> 03:19.680] Now, a lot of times we want, you know, there's this old rule in the law called hard cases make bad law. [03:20.300 --> 03:21.500] Someone is bad. [03:21.500 --> 03:22.780] We want to punish them. [03:22.860 --> 03:25.320] We want to find some way of making them pay. [03:26.140 --> 03:28.080] Lori Drew, great example. [03:28.320 --> 03:29.700] Lori Drew is something of a shit bag. [03:30.000 --> 03:33.680] You know, we've all heard of her because it's the Megan Meyer MySpace suicide case. [03:34.480 --> 03:36.740] You know, adults should not do that to teenagers. [03:37.500 --> 03:53.620] But she's been charged with, among other things, two counts of unauthorized access to MySpace's servers because she went in, created a username, and used the login to get information about Megan Meyer. [03:56.500 --> 04:01.880] Normally, in the old days, you know, prior to this year, that would have been, at most, a contract violation. [04:02.000 --> 04:06.880] If MySpace had a desire to actually sue her for whatever, it would have been in civil charges. [04:06.880 --> 04:09.860] Now, it's up to five years. [04:09.860 --> 04:14.080] Now, it's up to five years in prison for something that normally we thought was just normal griefing. [04:16.200 --> 04:23.800] And the others, in other scary cases, Citron, which allows retroactive unauthorized access. [04:24.180 --> 04:29.820] You have been given, he basically deleted files on his work laptop while he worked for a company. [04:30.540 --> 04:37.260] And they retroactively charged him because, at the time, he was planning to leave the company, even though he still was an employee. [04:37.720 --> 04:41.440] He had a company laptop and deleted files on it. [04:41.840 --> 04:52.740] The IAC went after him, not for breach of contract, not for unfair competition, but for a violation of the Computer Fraud and Abuse Act. [04:53.560 --> 05:01.300] If a prosecutor was convinced, he would be looking at up to ten years in prison for deleting files on his work laptop. [05:02.960 --> 05:05.240] Presumably, you're authorized to do that, you know? [05:05.440 --> 05:12.560] You don't want to have to ask your boss, Boss, I have all these image files that I downloaded for personal use. [05:12.720 --> 05:13.440] Can I delete them? [05:17.200 --> 05:19.740] Okay, so permission is now getting fluid. [05:19.920 --> 05:22.560] People are using it in a weird, weird way. [05:23.100 --> 05:24.740] Okay, where am I going with this? [05:25.840 --> 05:26.960] Don't be unlikable. [05:27.560 --> 05:36.720] And unfortunately, most of the people in this room, most of the people who are interested in security, most of the people who are interested in hacking, are not particularly likable from mainstream. [05:37.020 --> 05:40.140] We look funny, we talk funny, we're interested in funny things. [05:40.140 --> 05:46.600] And it's unsafe to be outside of the mainstream with these very, very broad, very vague laws. [05:47.880 --> 05:53.720] Okay, now this is a chunk of something that every time you use Yahoo, you agree to. [05:54.300 --> 05:56.880] If you violate any of this, it's now criminal. [05:58.220 --> 06:01.900] So you've all read the terms of service of every webpage you've ever gone to, right? [06:02.380 --> 06:03.560] And you understood it. [06:05.060 --> 06:07.220] Just to say that there's dangerous stuff out there. [06:07.460 --> 06:08.900] Okay, is that enough FUD? [06:11.200 --> 06:16.000] Okay, there are four basic laws that affect botnet researchers and botnet defenders. [06:16.680 --> 06:25.700] The Wiretap Act, which prevents you from intercepting electronic, among other communications, while in transmission. [06:27.140 --> 06:31.660] And it explicitly protects the contents of the communication. [06:31.660 --> 06:36.180] Stuff like headers, metadata about it, is safe. [06:36.440 --> 06:37.680] That's a different law. [06:37.820 --> 06:41.800] It gives a lot more deference to people who are sniffing packets. [06:42.320 --> 06:48.220] There's a broad prohibition against interception, except for a couple exceptions we'll get into in a second. [06:49.380 --> 06:51.260] The contemporaneous is important. [06:52.900 --> 06:55.820] Pulling stuff off of disk is not interception. [06:56.140 --> 06:58.320] Pulling stuff off the wire is. [07:00.360 --> 07:01.760] It does two things. [07:01.960 --> 07:09.700] It criminalizes the interception, and it criminalizes the disclosure if you know that it was illegally intercepted. [07:11.820 --> 07:16.040] Now, there are a couple exceptions which many of you will fall into, hopefully. [07:17.120 --> 07:20.340] Valid Wiretap Warrant are, well, I put FISA in there. [07:21.160 --> 07:25.040] I really don't want to get asked about FISA because all I'll do is start screaming profanities. [07:25.420 --> 07:29.500] And while that might be an interesting part of performance art, it's not really helpful. [07:30.900 --> 07:34.260] More importantly, though, prior permission of a party to the communication. [07:34.700 --> 07:40.140] Under federal law, any one party to a communication can say, yes, you can intercept my data. [07:40.320 --> 07:41.200] Yes, you can intercept. [07:41.200 --> 07:44.040] You can wiretap, you can listen to my conversation if I allow it. [07:44.380 --> 07:47.500] Some states require all parties to approve. [07:47.680 --> 07:49.800] But under federal law, all you have to do is have one. [07:51.420 --> 07:54.220] You can also use it to identify a source of electronic interference. [07:55.140 --> 07:58.840] The way this is written, it looks like radio interference, but it doesn't say that. [07:59.040 --> 08:06.920] So it's a potential defense if you are somehow arguing that a, say, a denial of service attack against you. [08:06.920 --> 08:08.460] Well, that's electronic. [08:08.700 --> 08:10.200] It's interfering with my stuff. [08:10.380 --> 08:14.020] I'm allowed to find, I'm allowed to sniff those packets to determine where it's coming from. [08:15.680 --> 08:16.640] And provider. [08:17.800 --> 08:20.080] Provider is very, it's very broadly written. [08:20.260 --> 08:30.780] If you are offering a service either to other people or, well, to other people, either employees or customers, you are providing an electronic communications service. [08:30.780 --> 08:34.140] It doesn't say ISP, but it clearly includes ISPs. [08:34.360 --> 08:41.560] If you run a corporate LAN, you run an educational LAN, you are clearly a provider under the Wiretap Act. [08:41.720 --> 08:53.640] And you are allowed to sniff packets to your heart's content, provided it's necessary to render service, or you're using it to protect the rights or property of the provider. [08:56.500 --> 09:01.320] It's also allowed for fraud against a phone company. [09:02.400 --> 09:04.220] Not using the phone company. [09:04.400 --> 09:15.260] If A is using the telco to defraud B, the telephone company, C, cannot sniff the packets for that purpose. [09:15.500 --> 09:19.320] If they're using it to defraud the phone company, they are allowed to sniff the packets. [09:21.180 --> 09:24.060] There are exceptions to the prohibition on distribution. [09:24.320 --> 09:42.320] Once you've pulled packets to actually give the contents of that transmission to another party, you are barred unless you either did not know it was obtained illegally, or you have permission of one of the parties involved. [09:42.600 --> 09:46.800] Now, this is the explicit contents of the communication, not metadata. [09:46.800 --> 09:53.580] If you are, say you're doing research on botnets, and you say, you know, here are the types of packets we get. [09:53.680 --> 09:54.440] Here are the amounts. [09:54.660 --> 09:55.740] Here are the characteristics. [09:56.240 --> 09:59.480] If you're not giving specific information about them, you're safe. [09:59.720 --> 10:01.880] Like an actual, you know, the content of. [10:04.880 --> 10:05.720] Trap and trace. [10:05.820 --> 10:07.800] This allows the capture of metadata. [10:08.640 --> 10:12.580] Where it's going, where it came from, time, size. [10:13.220 --> 10:19.140] It has also been used to gather from, to, and subject lines on emails. [10:19.540 --> 10:20.460] It's still fluid. [10:20.580 --> 10:22.380] We haven't yet figured out everything it covers. [10:22.720 --> 10:30.740] So, if it's about the communication, it likely falls under trap and trace, which allows, basically, testing, maintenance, billing. [10:31.020 --> 10:33.160] You have a much greater protection under the provider. [10:33.940 --> 10:35.140] The provider example. [10:35.300 --> 10:40.100] You, as a recipient, may also just accept, like, I'm allowed to broadcast this information. [10:40.220 --> 10:41.160] I'm allowed to capture it. [10:43.720 --> 10:45.180] One last important law. [10:45.340 --> 10:46.440] Stored Communications Act. [10:46.560 --> 10:48.760] This is for pulling data from disk. [10:49.960 --> 10:52.500] Or, actually, any storage, no matter how temporary. [10:52.500 --> 10:55.960] This has been used to define data. [10:56.180 --> 11:00.320] Say, for example, a packet while it's resonant in the memory of a router is in storage. [11:00.360 --> 11:01.820] No matter how incidental. [11:02.340 --> 11:04.460] As long as it's not on the wire. [11:05.160 --> 11:08.600] Now, I've read one case where they talked about pulling data off of a router. [11:08.820 --> 11:14.520] But it's completely, you know, I wouldn't guarantee that that's a safe place to sniff packets. [11:15.120 --> 11:16.780] Unless you have something else to protect. [11:19.040 --> 11:20.960] But, it's still a protection there. [11:21.660 --> 11:26.080] The provider protection under the Stored Communications Act is very, very broad. [11:26.300 --> 11:30.480] You're allowed, if you hold the data, if the data is on your system, you're allowed to read it. [11:30.640 --> 11:31.800] For any reason. [11:33.180 --> 11:41.400] So, unless there's some other guarantee of privacy, your mail server, whoever owns it, can read your email. [11:44.200 --> 11:47.840] There's maybe a slight wrinkle in some states that don't permit this. [11:47.840 --> 11:50.280] But, under federal law, you're generally protected. [11:52.500 --> 11:53.540] And, the fun one. [11:53.660 --> 11:54.840] Computer Fraud and Abuse Act. [11:54.940 --> 11:56.800] This has not been really used in a couple of years. [11:57.220 --> 12:00.000] It hasn't changed in a couple of years until very, very recently. [12:00.180 --> 12:04.100] Where people realize... or prosecutors are realizing it's nicely, broadly written. [12:04.420 --> 12:09.060] So, you can get... you can kind of figure out all sorts of neat attacks against people you don't like. [12:11.140 --> 12:14.160] Makes the following unauthorized access illegal. [12:14.680 --> 12:31.460] If you obtain... if you either unauthorized... you know, without authorization, access another system, and obtain financial, medical, federal interest, namely state secrets, atomic energy stuff, or financial information, that's a violation. [12:31.680 --> 12:32.700] Up to ten years in prison. [12:32.700 --> 12:46.300] If you have a fraudulent intent with your access, and it causes $5,000 in damage, and that $5,000 can be calculated as, it cost us $5,000 to clean it up. [12:46.520 --> 12:48.580] We had to hire a forensics guy. [12:49.220 --> 12:51.900] And, when he answered the phone, he billed us five grand. [12:54.540 --> 12:59.060] To find out what happened, that gets calculated in. [12:59.060 --> 13:01.920] So, it's really, really easy to hit $5,000. [13:03.840 --> 13:06.480] Recklessly causing damage without permission. [13:06.860 --> 13:08.380] So, you don't have to have the intent. [13:08.560 --> 13:18.740] But, if you say, for example, write a worm that travels across the Internet, and your name is Robert Morris, that was the first use of 18 U.S.C. [13:18.820 --> 13:19.260] 1030. [13:19.480 --> 13:30.080] So, if you recklessly cause damage by committing an act on the Internet, by transmitting information, you can get caught up under this. [13:32.760 --> 13:33.320] Okay. [13:33.620 --> 13:35.720] We have state laws that affect this stuff. [13:35.900 --> 13:40.120] If you're in an individual state, you get affected by the state laws as well. [13:40.420 --> 13:45.780] They often mirror federal laws because, basically, legislators are lazy. [13:46.840 --> 13:48.800] They've already written at the federal level. [13:48.940 --> 13:50.360] Why should we rewrite it? [13:50.540 --> 13:51.460] We'll just crib. [13:53.940 --> 13:55.940] Wiretap law is the one big exception. [13:56.460 --> 14:04.160] Some states are what we like to call two-party states, or all parties involved in a communication have to give permission. [14:05.560 --> 14:13.120] And the other thing that will affect, I foresee seeing affecting botnet researchers, is common law torts. [14:14.500 --> 14:23.440] Nuisance, which is, if I operate my property in such a way that it affects your property, you can sue me for the damages I've caused. [14:24.840 --> 14:26.040] Slander and libel. [14:26.200 --> 14:38.480] If I say a negative, untrue fact about you to other people, either in print, libel, spoken, slander, I am liable for your losses. [14:39.500 --> 14:44.700] And some states still allow a privacy tort named intrusion into seclusion. [14:44.880 --> 14:52.440] If I broadcast true but private facts about you, I may be liable for your emotional losses. [14:52.920 --> 14:56.240] Where do these come into play against a botnet researcher or mitigator? [14:57.300 --> 14:57.640] Okay. [14:59.080 --> 14:59.680] Capture. [14:59.920 --> 15:02.960] You want to start with, well, I want to see how a bot works. [15:02.960 --> 15:05.660] I want to go capture the raw executable. [15:06.700 --> 15:08.220] So, a couple different ways you can do it. [15:08.320 --> 15:09.220] You can actively do it. [15:09.420 --> 15:09.660] Huh. [15:09.940 --> 15:11.940] I think I've heard there's a malware site. [15:12.140 --> 15:13.740] So, you know, Russian hosted site. [15:13.900 --> 15:22.340] I can download the, you know, the latest version of, of some new, some new exploit and the code that makes it happen with a nice, you know, click and drool. [15:22.960 --> 15:25.400] You know, exploit, you know, exploit this box. [15:25.520 --> 15:26.020] Click here. [15:28.320 --> 15:32.100] Now, you can actively go out by FTPing it. [15:32.100 --> 15:41.080] You can actively go out by using a vulnerable browser or application that another exploit, another, you know, executable will attack. [15:41.320 --> 15:45.600] Say, for example, a vulnerable web browser, say like Internet Explorer. [15:45.740 --> 15:48.400] And I want to find attacks that attack that browser. [15:48.640 --> 15:57.840] I just basically, you know, go to thought and believed bad sites with my vulnerable browser and hopefully I pick up some malware that I can later analyze. [15:58.480 --> 15:59.760] Or you can simulate it. [15:59.820 --> 16:01.740] You can use a honey client to go out and get it. [16:02.260 --> 16:02.540] Okay. [16:03.100 --> 16:03.900] Fairly straightforward. [16:04.820 --> 16:06.540] You're going out trying to get this. [16:06.680 --> 16:07.840] And then you have the passive stuff. [16:07.960 --> 16:11.980] You can build a honey potter net that's basically sitting there going, hey, attack me. [16:12.100 --> 16:12.480] Come on. [16:13.020 --> 16:13.640] Where are you? [16:14.020 --> 16:14.880] Oh, hi. [16:15.020 --> 16:16.840] Hi, mister, you know, nasty executable. [16:17.020 --> 16:17.800] Come on in. [16:17.900 --> 16:19.480] And you save a copy and there you go. [16:20.120 --> 16:25.880] Or you can, you know, actually collect it from end users who have said, hey, my box has been exploited. [16:26.080 --> 16:27.240] Oh, there's some interesting code here. [16:27.340 --> 16:28.280] Let me go play with that. [16:28.540 --> 16:31.380] So, those are the methods to go get malware. [16:32.440 --> 16:40.640] What's possible that you can screw up that you can go get arrested or sued in a civil action for that work? [16:42.020 --> 16:42.540] Okay. [16:42.940 --> 16:46.580] And I've actually talked to someone who had this, who did this. [16:46.580 --> 16:50.080] They misconfigured a tool to go out and check for vulnerabilities. [16:51.520 --> 16:52.700] It was broken. [16:52.880 --> 17:02.940] It basically DOSed some guy in the UK and it activated a script that sent SMS messages to all of his... [17:02.940 --> 17:06.240] He ran like a heating, ventilation, air conditioning company. [17:07.320 --> 17:13.300] The guy who was attacked had SMS messages going to their cell phones saying, like, you know... [17:13.300 --> 17:17.280] And it was kind of like an idea to say, like, go to this address and go fix their stuff. [17:18.400 --> 17:23.300] And they had a really nice little web script or a script on their web server that would allow you... [17:23.300 --> 17:27.080] The guy who was running the company to kind of click and say, you know, go here, do this. [17:28.360 --> 17:30.800] Unfortunately, the guy who went to me and asked... [17:30.800 --> 17:32.980] He wasn't really my client because I wasn't practicing law yet. [17:33.740 --> 17:36.280] He wrote this script to go out and find vulnerabilities. [17:36.280 --> 17:46.480] Well, it basically hammered this Scottish guy's server and he sent several thousand SMSs to all of his workers. [17:47.020 --> 17:48.400] So, you know, every... [17:48.400 --> 17:51.840] And I think they were charging like 10 pence per. [17:52.120 --> 17:55.140] So, the guy gets like, you know, several thousand dollar cell phone bill. [17:56.500 --> 18:03.380] And, you know, traces it back to my guy who's like, there's this guy in Scotland who's f*cking pissed. [18:05.100 --> 18:05.540] You know. [18:06.140 --> 18:07.300] And I'm like, well, why? [18:07.440 --> 18:07.860] What happened? [18:07.920 --> 18:09.060] He's like, well, I wrote this like... [18:09.060 --> 18:10.900] So, you're going out looking for vulnerabilities. [18:11.180 --> 18:11.960] Like, you wrote a... [18:11.960 --> 18:15.540] It's like, yeah, it seemed to be it broke his server interestingly. [18:16.680 --> 18:17.240] Like, okay. [18:19.280 --> 18:19.800] Am I... [18:19.800 --> 18:20.300] And he's like, oh. [18:20.420 --> 18:21.400] And I'm like, yeah, that sucks. [18:21.540 --> 18:22.680] He's like, no, no, you're a lawyer. [18:23.900 --> 18:24.180] Yeah. [18:24.420 --> 18:25.620] And like, can you sue me? [18:25.680 --> 18:28.180] I'm like, eh. [18:28.600 --> 18:30.580] And I'm kind of doing this, holding a beer for like five minutes. [18:30.700 --> 18:31.400] Like, that's not good. [18:31.500 --> 18:32.260] I'm like, okay, how about this? [18:32.300 --> 18:33.080] I'll call you tomorrow. [18:33.580 --> 18:35.000] And eventually figure out, like, look. [18:35.260 --> 18:36.960] Offer him a hundred bucks and say, I'm sorry. [18:37.640 --> 18:39.040] And that's what worked. [18:39.240 --> 18:46.660] But imagine instead if you did that to someone who was angrier than, you know, than the Scottish guy. [18:46.720 --> 18:49.840] Because the Scottish guy can't really, you know, come to the United States and sue him. [18:50.440 --> 18:56.580] And, you know, like, we're not going to see, you know, Mr. McHaggis flying over going, I want justice! [18:57.620 --> 18:59.540] It's just funnier because it's a Scottish accent. [18:59.580 --> 19:01.020] I can't really do that that well. [19:01.860 --> 19:07.800] But imagine if it's instead you do that to, oh, a mid-sized company. [19:08.040 --> 19:13.500] And you just pound the shit out of one of their boxes because your honey client is just misconfigured. [19:13.580 --> 19:18.040] You're like, oh, it should hit a random site 60 times a second. [19:18.320 --> 19:24.520] And instead you just basically have it, you know, have your thousands of honey clients all pound their server. [19:24.520 --> 19:25.060] Boom! [19:25.320 --> 19:25.860] They go down. [19:26.260 --> 19:26.500] Oops! [19:26.660 --> 19:29.620] You've inadvertently done a denial of service attack that you weren't intending to do. [19:29.980 --> 19:30.800] It's possible. [19:31.140 --> 19:34.500] So if you negligently, and the negligence is the important word. [19:34.660 --> 19:38.900] If you intentionally do it, you've now committed a criminal act. [19:38.900 --> 19:41.220] But if you negligently, you just, oops! [19:42.620 --> 19:46.360] I used the sample config file as opposed to writing my own. [19:47.220 --> 19:54.220] Is it bad if we just basically pipe everything a T3 can do to, you know, Bob's plumbing supply? [19:54.820 --> 19:55.420] Oops! [19:55.960 --> 19:57.520] I think Bob's going to be pissed. [19:58.640 --> 20:00.640] That was sort of the big hypo. [20:02.080 --> 20:08.200] You could also potentially get a nuisance tort as you used your property in such a way that it screwed with my property. [20:09.320 --> 20:16.320] I haven't read of any of these cases yet, but it's, but a lot of computer geek lawyers are like, this is, this is going to be. [20:16.420 --> 20:18.280] Someone's going to sue under this and eventually win. [20:20.500 --> 20:21.820] Okay, what about this? [20:22.100 --> 20:23.780] Downloading from a malware repository. [20:25.560 --> 20:32.020] And I wrote a paper about, well I half wrote a paper about this, because I keep on like looking at it and going, I have other work to do. [20:32.300 --> 20:36.920] But the hypothetical is, you can have a malware repository because you're Symantec. [20:37.520 --> 20:43.320] You can have a malware repository because you're, you know, leet dude 94 who likes putting virus code on the web. [20:43.540 --> 20:44.780] They're both malware repositories. [20:45.620 --> 20:50.180] If you illegally download from Symantec, Symantec is going to come after you. [20:50.180 --> 20:54.220] Because it's like, you should buy a subscription if you want to do research from our stuff. [20:54.700 --> 21:00.620] Versus leet dude is, you know, in his basement working at, you know, working at Kinko's. [21:01.500 --> 21:07.460] He's not going to be able to come after you for, you know, faking a login and going and taking his stuff. [21:07.720 --> 21:11.260] But it's potentially a violation of contract. [21:11.260 --> 21:22.160] And with the changes in the interpretation of 1030, it may actually be a criminal act to spoof a user name, go in and download someone's malware. [21:22.620 --> 21:25.860] The chances you're going to get sued by an actual criminal is zero. [21:26.080 --> 21:26.960] Because it's really hard. [21:27.080 --> 21:31.440] It's like, you know, people calling up 911 going, dude, we got ripped off on this Coke deal. [21:31.440 --> 21:42.540] I mean, it still happens, but it's really unlikely that, yeah, we run a where server and a virus malware coding site. [21:42.780 --> 21:45.140] And this dude downloaded a bunch of stuff. [21:45.760 --> 21:48.300] And, you know, we have spammers to serve, man. [21:48.480 --> 21:49.340] We're starving here. [21:49.460 --> 21:51.220] You know, I'm sure it's not going to happen. [21:51.340 --> 21:55.280] But if you're some, if you're an actual, you know, no, we're not, we're not hackers. [21:55.280 --> 21:56.760] We're security researchers. [21:57.560 --> 22:04.980] Those people might actually go and hire someone like me to go and, you know, right behind me, RIAA going, do you have any stuff left? [22:05.680 --> 22:07.060] You know, we'll take that. [22:09.540 --> 22:11.680] Okay, passive capture legal issues. [22:13.120 --> 22:21.240] If you've configured your honeypot or net correctly, it's possibly nuisance if you used actual live machines. [22:21.240 --> 22:30.220] Instead of, you, instead of building like a true emulated honeynet where it's, you know, like I have a Linux box playing like it's a bunch of unpatched Windows 98 boxes. [22:31.260 --> 22:37.640] But if you actually had, you know, like, hey, you know, I got a bunch of unpatched 98 boxes as my honeynet. [22:37.800 --> 22:44.940] If a, if it gets compromised and is used to attack someone else, it's potentially a nuisance claim. [22:45.580 --> 22:47.400] I'm going to give the FUD alert now. [22:47.840 --> 22:53.420] It's not actually, well, okay, no one's actually been sued for it, but it's just, it should be out there. [22:53.700 --> 23:02.300] So if you can just, you should monitor any honeynet, honeypot that you're running to make sure it's not actually, you know, f*cking with other people. [23:04.440 --> 23:06.380] And the final one, end user collection. [23:07.300 --> 23:11.420] If it's without permission, and I'm trying to think like how you would do this without permission. [23:11.420 --> 23:17.580] Like, oh, I'm, you know, I'm going to go and hacks her into a box that's already been infected. [23:18.200 --> 23:24.420] And yank out the, you know, yank out the bot and, you know, patch the system. [23:24.600 --> 23:27.640] And I've talked to people like, oh, I've got this great data, it's going to be a white bot. [23:27.760 --> 23:33.800] It's going to go out and look for bad bots and delete, you know, delete the bad bot and patch the system so it doesn't happen again. [23:33.800 --> 23:39.220] And I thought, that works, that would be, that would be cool, except it violates federal law. [23:39.360 --> 23:40.840] And what if you get it wrong? [23:41.180 --> 23:46.840] What if there's a vulnerability in your own code and you basically go and unpatch thousands of systems? [23:47.220 --> 23:50.240] You're, you're going to be really, you're going to be Mr. Popular. [23:52.640 --> 24:00.260] So, if you, the unlawful access, if you're capturing live packets, I don't know how you do that with an end user collection. [24:00.260 --> 24:03.780] Unless you're maybe, you know, I'm going to capture without permission. [24:03.900 --> 24:04.680] Now, if you get permission. [24:05.120 --> 24:14.360] If you're, if you either, you're the IT guy at installation, you just say, I'm going to go, I'm going to go pull code off your box. [24:14.580 --> 24:16.760] Or, you could just say, it's, it's our box. [24:16.940 --> 24:20.760] You know, it's the company's computer, we're allowed to do whatever we like to it. [24:21.100 --> 24:27.660] So, it's really for this hypothetical, I'm going to go out and download code off of your machine without you ever knowing about it. [24:29.900 --> 24:30.340] Okay. [24:32.080 --> 24:39.740] This is also the hypothetical, the reverse engineering code, like, could, could a malware manufacturer sue you under the Digital Millennium Copyright Act? [24:39.980 --> 24:44.140] And I thought, that's the most masturbatory question I've come up with today. [24:44.680 --> 24:52.180] You know, it's like, no, that's, that's more like, dude, we were doing a drug deal, you know, calling up 911, we're doing a drug deal, and I shot this guy. [24:53.420 --> 24:57.740] And the Coke's bad, like, you've double, it's like double whammy, like, it's not really going to happen. [24:57.900 --> 25:03.330] But I thought of, um, what about Gator? [25:03.960 --> 25:08.460] Remember, you know, the, the, I'm going to trick you into downloading my malware. [25:08.840 --> 25:20.400] Well, potentially, that's a company that might sue you for doing a reverse, reverse engineering on their code, if you, if they have some, some form of encryption to protect you from, well, reverse engineering the code to figure out what it does. [25:21.200 --> 25:24.760] And I thought, like, if that happens, it will be interesting to watch. [25:24.960 --> 25:25.960] I don't know yet. [25:26.600 --> 25:30.900] It's potent, it's out there, but that's like, you should worry about that about as much as a meteor. [25:31.760 --> 25:33.240] Like, that level of fear. [25:33.360 --> 25:34.380] Like, yeah, that would be bad. [25:35.060 --> 25:36.000] That, about that likely. [25:37.260 --> 25:43.480] Um, going back to the idea, if you're running a sandbox, you inadvertently compromise other systems with your sandbox. [25:44.300 --> 25:44.640] Bad. [25:48.180 --> 25:48.580] Publication. [25:48.580 --> 25:51.820] The biggest one you're going to run into is libel and slander. [25:52.020 --> 25:53.240] This has been used. [25:53.440 --> 25:53.880] Gator. [25:54.420 --> 26:01.520] Where, you, say you pull a piece of malware off, you reverse engineer it, and you say, this is malware. [26:02.300 --> 26:09.080] This is the worst piece of software, and I wholeheartedly say that, you know, Microsoft Office is malware. [26:09.460 --> 26:15.820] Um, you're going to get a phone call from Microsoft, because you have slandered their product by calling it malware. [26:15.820 --> 26:20.760] Um, you would have to then defend by saying, geez, it's, it is malware. [26:21.060 --> 26:24.000] But, you really don't want to ever get into litigation with Microsoft. [26:24.560 --> 26:27.980] Um, just cause it'll just, you know, like, wow, we won! [26:28.200 --> 26:30.540] We spent eight million dollars to defend this! [26:30.720 --> 26:31.220] I'm broke! [26:31.420 --> 26:31.700] Great! [26:32.180 --> 26:37.440] Um, but, libel and slander requires a negative, untrue statement of fact. [26:38.060 --> 26:40.480] Um, and it has to be a statement of fact. [26:40.480 --> 26:46.560] It cannot, it, you know, it, you know, if it's mere opinion, it's, you know, you are a bad person. [26:46.720 --> 26:47.020] Great! [26:47.660 --> 26:49.160] Um, it's, it's a statement of opinion. [26:49.480 --> 26:51.260] You are a dishonest person. [26:51.760 --> 26:52.960] That alleges fact. [26:53.220 --> 27:03.220] So, you could potentially look at a lawsuit if you describe something from a, from a legitimate company as, this is malware. [27:03.640 --> 27:05.800] So, you want to make sure you got all your ducks in a line. [27:05.800 --> 27:07.640] You want to, like, back it up with facts. [27:08.600 --> 27:09.820] Um, trade secret. [27:10.040 --> 27:15.380] If a vendor has given you controlled secrets, stuff that we say, you have to sign an NDA. [27:15.640 --> 27:17.200] You can't show this to anyone else. [27:17.320 --> 27:24.300] If you divulge that information in your botnet research, I don't know how that would happen, but it, it, it should just be in the back of your minds. [27:24.440 --> 27:33.420] If somehow you're, like, playing with someone else's code, um, that, like, how is this, you know, how would this be attacked by bots? [27:33.420 --> 27:36.660] Like, you know, Microsoft's doing their next generation of an operating system. [27:36.860 --> 27:40.080] Uh, yeah. [27:43.000 --> 27:44.520] Okay, it, it, it's a fantasy. [27:44.680 --> 27:49.320] Maybe Cisco, because I know people have gotten in trouble for divulging Cisco trade secrets. [27:49.920 --> 27:52.220] Um, and the divulgement. [27:52.300 --> 27:55.800] If you illegally intercept packets, you are not a provider. [27:55.800 --> 27:59.940] You, instead, you are just, uh, uh, you know, Joe researcher. [28:00.240 --> 28:10.620] And you're sniffing packets from, um, between a botnet herder and, um, an individually compromised PC. [28:10.620 --> 28:14.760] If you're also sniffing packets that they're using legitimately. [28:15.200 --> 28:17.800] Say, for example, it's my, you know, my laptop's compromised. [28:17.800 --> 28:21.980] I'm sending an email to my wife while the botnet herder is sending transmissions. [28:22.360 --> 28:28.820] Um, if you broadcast my stuff, you may have illegally, you know, you have, you have violated my rights. [28:28.820 --> 28:30.440] I may have a lawsuit against you. [28:32.760 --> 28:33.280] Okay. [28:34.080 --> 28:35.120] Um, next step. [28:35.240 --> 28:36.680] Talking about monitoring of herders. [28:36.900 --> 28:47.160] Um, you can either, um, sniff packets between the IRC channel that's running the botnet, or, um, actively. [28:47.400 --> 28:49.960] You know, log in and be, you know, act like a bot. [28:50.500 --> 28:54.800] Um, the biggest problem is what I like to call the mixed server. [28:54.980 --> 28:59.520] If, if a botnet herder is using a, a legitimate server. [28:59.560 --> 29:02.880] As in, it has other non-bot related traffic. [29:03.920 --> 29:07.480] Um, you may possibly run into a 2511 violation. [29:07.520 --> 29:09.560] Because you're sniffing packets that you're not supposed to. [29:09.820 --> 29:13.100] Now, you have a defense by saying, these weren't intended. [29:13.100 --> 29:14.360] This, these were published. [29:14.600 --> 29:16.600] Like, anyone can log into this IRC channel. [29:16.820 --> 29:18.600] So, they are broadcast. [29:18.960 --> 29:20.440] I'm not sniffing packets. [29:20.580 --> 29:21.420] I'm receiving them. [29:22.000 --> 29:23.280] And that's in a valid defense. [29:23.380 --> 29:29.660] But, you're now in a gray area where you might have to go and actually have to raise that defense as opposed to saying, like, look, you can't charge me at all. [29:31.660 --> 29:36.820] Um, I drew a little schematic here, just to show where you might be doing sniffing. [29:36.820 --> 29:41.940] So, we have an infected box and, uh, okay. [29:42.220 --> 29:44.260] Infected box, an IRC server, and a herder. [29:45.560 --> 29:49.460] Infected box says, hide the IRC channel, IRC server. [29:49.880 --> 29:51.880] Then, you know, that gets transmitted through to the herder. [29:52.040 --> 29:54.140] Herder sends commands back to the infected box. [29:54.500 --> 29:54.980] Okay. [29:54.980 --> 29:56.920] We have a researcher who wants to sniff all that. [29:57.520 --> 29:58.480] That's interception. [29:58.480 --> 30:08.500] Now, of course, it might be, it's, there's a low chance of getting actually in trouble for it because the bot herder is not going to raise the stink legally. [30:08.860 --> 30:12.040] They may do other things, but they're not going to actually try to raise a legal stink. [30:13.100 --> 30:20.040] Um, sniffing there may actually violate it if that IRC box is also used for legitimate traffic. [30:21.460 --> 30:26.660] And that's also sniffing traffic, but chances are that the infected guy is not going to complain. [30:26.660 --> 30:30.440] But, we have neutral one and two. [30:30.600 --> 30:32.440] They're also in that IRC box. [30:32.740 --> 30:34.220] So, they're talking. [30:34.460 --> 30:50.660] The researcher sniffs in, still violated the wiretap act, but because they've done it to a neutral, who can go to the cops and say, look, this guy, and I don't care if he works for Carnegie Mellon, is sniffing my traffic. [30:50.820 --> 30:51.700] He's violated the law. [30:51.860 --> 30:52.400] Punish him. [30:56.700 --> 30:58.640] Now, this is something I've been curious about. [30:58.640 --> 31:01.960] Now, can you sniff a live infection? [31:03.260 --> 31:11.480] And I thought, if you can somehow sort out the packets to make sure that all you're doing is that, as opposed to legitimate traffic, I think you might be okay. [31:16.120 --> 31:16.560] Okay. [31:17.460 --> 31:18.660] Um, issues of standing. [31:18.800 --> 31:20.760] This is, can criminals sue you? [31:20.860 --> 31:24.580] And chances are, the answer is no, for, you know, reasons I've stated before. [31:25.800 --> 31:31.000] However, but innocent traffic, innocent users can complain saying, you had no right to do that. [31:31.220 --> 31:35.300] You're allowed to go, you know, screw with the evil doers, but I'm not the evil doer. [31:38.510 --> 31:39.290] Evil doers. [31:39.730 --> 31:40.770] Um, okay. [31:41.830 --> 31:49.670] A big problem is that it's really kind of hard to determine if a site is truly, if you're sniffing traffic from it, are they legitimate or not? [31:49.810 --> 31:52.090] Because there are going to be sites that you can't tell. [31:52.530 --> 31:55.330] You know, they're not going to have like a little flag like, hi, you know, we're criminals. [31:57.850 --> 31:58.250] Okay. [31:58.870 --> 31:59.270] Hypothetical. [31:59.630 --> 32:04.190] A researcher implements a honey net, assumes all incoming and outgoing traffic is illicit. [32:04.330 --> 32:06.950] Because there's nothing should be routed here that's legitimate. [32:07.150 --> 32:10.950] So the only stuff that's going to come in are people trying to attack it or misrouted traffic. [32:12.090 --> 32:13.970] gets misrouted innocent traffic. [32:14.110 --> 32:16.090] For some reason, someone mistyped something. [32:17.250 --> 32:20.690] Um, are they going to get in trouble for sniffing those packets? [32:22.470 --> 32:27.270] Um, I believe they're safe because they are a party to the transmission. [32:28.110 --> 32:30.530] The botnet, the person who's running the honey net. [32:32.110 --> 32:36.350] Now, if they make the traffic content available, I think they're still safe. [32:37.010 --> 32:42.570] Because they were an intended recipient, even though it wasn't the actual intention. [32:42.730 --> 32:46.990] It was like, they can say, it was misrouted to us through no fault of our own. [32:47.150 --> 32:48.870] It was fault of the sender, we're safe. [32:51.290 --> 32:54.510] Um, inadvertent acquisition is not wiretapping. [32:55.250 --> 32:57.250] Uh, but you have to, it's an affirmative offense. [32:57.330 --> 32:58.910] You raise that after you've been charged. [32:59.170 --> 33:02.490] So you have to basically say, yeah, we did all that, but. [33:03.030 --> 33:07.290] So if you're, if they don't buy your defense, well, now, you know, now you're in trouble. [33:07.870 --> 33:14.850] Um, the problem is, is that as a honey net operator, you cannot use the provider defense. [33:15.550 --> 33:17.910] Because you aren't, what service are you providing? [33:18.390 --> 33:21.490] You aren't using this to, well, I was using this to protect my network. [33:21.690 --> 33:22.630] You're running a honey net. [33:23.210 --> 33:24.450] Like, what's the defense? [33:24.990 --> 33:26.590] You know, you, you put those out there. [33:26.730 --> 33:30.990] You know, you're like the National Geographic crew going, the goat has been staked. [33:30.990 --> 33:33.150] The puma is staring at it. [33:33.270 --> 33:35.050] You know, like, we were protecting the goat. [33:35.170 --> 33:35.770] No, you weren't. [33:37.310 --> 33:39.910] You had film cameras to show that you weren't protecting the goat. [33:40.590 --> 33:43.470] Um, I believe though, what about consent? [33:43.690 --> 33:45.810] Receiver granted consent, so the feds are okay. [33:46.150 --> 33:48.950] But a state, if they, if they're a two-party state, can get interested. [33:50.490 --> 33:54.590] Um, as an example, PA law is, is strange on this. [33:54.850 --> 33:56.950] All the parties have to agree in writing. [33:56.950 --> 34:01.570] I haven't actually seen this enforced yet, but, and it has to be verified by the AG. [34:01.870 --> 34:06.230] Like, you send the, like, man, like, you can't do a private wiretap. [34:06.330 --> 34:09.350] Unless you get a terms of service that's signed. [34:09.550 --> 34:13.930] So, PA based ISPs will just generally, you know, they'll put that in the terms of service. [34:14.170 --> 34:17.470] And by your using it, and they may send a copy to the terms of service of the AG. [34:19.030 --> 34:19.390] Okay. [34:20.830 --> 34:21.190] Defense. [34:21.830 --> 34:24.850] For everyone that's not doing research, you're just going, dude, we're getting hammered. [34:24.910 --> 34:25.910] What do we do to protect it? [34:26.490 --> 34:28.730] Um, passive monitoring, defenses. [34:29.050 --> 34:32.730] Basically, like, you put, hang out an IDS to figure out, like, what's going on. [34:33.250 --> 34:38.890] Um, or say, example, you're instead of being a, instead of defending your own system, you're defending someone else's. [34:38.890 --> 34:39.550] You're a consultant. [34:39.990 --> 34:41.530] With the permission and within scope. [34:41.690 --> 34:42.350] That's important. [34:42.350 --> 34:49.110] You are allowed to sniff packets for a provider, if you're an employee, if it is within the scope of your employment. [34:49.850 --> 34:50.770] This is important. [34:51.330 --> 34:56.070] If you are, and just because you're, I'm an IT worker, is not good enough. [34:56.170 --> 34:58.270] It actually has to be explicitly in there. [34:59.430 --> 35:02.050] Um, and it's best to have that in your employment. [35:02.050 --> 35:04.950] If you're running a sniffer, get it in there. [35:05.030 --> 35:06.310] I'm allowed to run a sniffer. [35:06.690 --> 35:08.250] This is when I'm allowed to run a sniffer. [35:08.250 --> 35:11.990] So that way, when you do run the sniffer, you are not violating 25.11. [35:12.090 --> 35:12.850] You have that defense. [35:15.430 --> 35:17.810] Um, if you discover a control server. [35:17.950 --> 35:26.610] Say, for example, one of your boxes has been compromised and someone is using it as an IRC server to run a botnet. [35:27.130 --> 35:34.350] Um, I believe you're safe in intercepting that traffic because it's your box. [35:34.350 --> 35:36.390] You are a recipient of that data. [35:38.590 --> 35:38.730] Okay. [35:39.630 --> 35:42.550] Um, taking down disruption of an attacking botnet. [35:43.750 --> 35:44.610] Pulling the plug. [35:44.770 --> 35:46.370] If it's your box, you're allowed to. [35:46.510 --> 35:48.250] If it's on your network, you're allowed to. [35:48.310 --> 35:55.170] If you're an ISP and one of your customer's boxes is either spewing packets, you are allowed to yank it. [35:56.710 --> 35:58.150] Null routing it, whatever. [35:59.230 --> 36:03.150] If it's yours, you have permission, and there is actual permission. [36:03.330 --> 36:05.610] Hey, Bob, we're gonna, you know, your box is hosed. [36:05.750 --> 36:06.430] We're taking it offline. [36:06.670 --> 36:07.130] Thank you. [36:07.810 --> 36:09.350] Um, our constructive permission. [36:09.930 --> 36:13.490] Um, say for example, um, you have it in the terms of service. [36:13.650 --> 36:16.670] If your, if your box starts spewing crap, it's offline. [36:17.070 --> 36:19.350] Um, DNS poisoning. [36:19.350 --> 36:36.050] The, the only thing that might get you there is if you, um, um, in your contract between the DNS hoster and the, if whoever's being, uh, uh, attacked, um, you may want to have some clause in there that says, you know, we will do whatever we have to do to protect our, [36:36.270 --> 36:37.330] protect the systems. [36:37.590 --> 36:39.990] Up to, and you might want to explicitly write that in. [36:40.050 --> 36:44.670] I wouldn't, because then if you, if, if the next generation, we find out something else. [36:44.790 --> 36:47.710] You do like, you know, some weird new magic with packet routing. [36:48.990 --> 36:51.410] Um, one thing I want to talk about is macho responses. [36:51.670 --> 36:57.170] Every time someone, you know, usually after four or five drinks will start, it's like, dude, no, we need to take it to them. [36:57.590 --> 37:04.170] And, you know, I, you know, like, we'll build a bot army of white bots that will, that will DDOS them. [37:04.470 --> 37:08.030] It's like, okay, uh, one, put down the whiskey. [37:09.010 --> 37:13.550] Um, you know, whiskey, well, whiskey is the source of all sorts of good and bad ideas. [37:14.810 --> 37:17.690] Um, you know, last night, whiskey almost had us storing our money. [37:17.710 --> 37:19.610] We're going to put our motorcycles on this floor. [37:20.710 --> 37:26.890] Uh, uh, Dr. Schomer was thinking like, dude, if we're late, ride up the middle lane and just say traffic was off. [37:26.970 --> 37:29.050] I'm like, no, I'm sober. [37:29.590 --> 37:31.550] Give me some whiskey, that may happen. [37:31.730 --> 37:33.970] But for now, 10 in the morning, I should be sober. [37:37.010 --> 37:38.290] According to the terms of my probation. [37:41.950 --> 37:42.350] Um... [37:42.350 --> 37:48.050] So, the whole counterattack, and I've, I've read papers written by lawyers about self-defense. [37:48.410 --> 38:00.170] I think the risk, uh, if you do something really dumb and macho, like, um, denial of service, if you figure out, like, you know, look at the network map and go like, ah, if I take that router out, I get a reprieve. [38:00.170 --> 38:04.670] And that router happens to be innocent and you drop that and you take out other traffic. [38:06.230 --> 38:10.490] Uh, it's, this is not, you know, it's the same way as, like, firearm self-defense. [38:10.730 --> 38:11.570] I was justified. [38:11.650 --> 38:12.010] Right. [38:12.190 --> 38:12.730] And guess what? [38:12.830 --> 38:17.390] We're going to tear, you know, we're going to, we're going to examine your life for the next year and a half. [38:17.590 --> 38:18.730] And that's not fun. [38:19.030 --> 38:20.250] No one has fun in court. [38:21.870 --> 38:23.370] Okay, people like me have fun in court. [38:23.370 --> 38:25.290] But there are two advantages. [38:25.550 --> 38:26.930] One, we're getting paid. [38:27.170 --> 38:28.770] Secondly, we go home. [38:32.350 --> 38:36.210] Okay, I want to kind of run through this, uh, um, defender hypothetical. [38:36.750 --> 38:41.990] Um, you're an end user, you know, you're a sysadmin, a network admin, or an IT security guy. [38:42.450 --> 38:44.630] Um, you get unfriendly traffic from a botnet. [38:44.850 --> 38:47.770] You can active, you're actively monitoring it and you get the upstream divider. [38:47.930 --> 38:52.310] Like, dude, all the traffic from these, this bank of IPs, drop it. [38:52.430 --> 38:53.310] Just drop it at the router. [38:54.150 --> 38:55.370] That's okay, I think. [38:56.190 --> 39:08.650] Um, if you're an ISP, uh, and you're routing traffic, you get, you're noticing an attack, like either one of your boxes is compromised and spewing bad packets, or someone's attacking some of the boxes that are on your network. [39:09.110 --> 39:14.970] Um, actively monitoring the incoming and outgoing traffic, I think you're okay, because you've got the provider thing. [39:15.190 --> 39:19.590] You've got the provider protection saying, I am using this to prevent fraud on my network. [39:20.050 --> 39:21.690] Or to protect my assets. [39:22.730 --> 39:29.190] Um, so, end user defender in this case, they have permission to monitor their own traffic. [39:29.670 --> 39:36.270] You can, more, more, you know, much more detail, put that in employee contracts, or the, those handbooks. [39:36.750 --> 39:45.550] Uh, if it's instead you're like a small ISP, um, are your, your, you don't have a direct contract with your end user, say for example, your university. [39:46.030 --> 39:52.350] You might want to just have, in the terms of service, by using our systems, we reserve the right to sniff packets to defend the network. [39:52.570 --> 39:54.650] Just so you've got, it's the belt and suspenders approach. [39:54.810 --> 39:58.390] You can't come to us, you have more protections than just what federal law allows. [39:59.490 --> 39:59.790] Okay. [40:01.510 --> 40:02.650] Uh, ISP defender. [40:02.650 --> 40:09.790] You may have permission to monitor your own traffic on your networks, because it's either in the terms of service, or it's the prevent fraud clause in 2511. [40:11.530 --> 40:12.330] Dumping traffic. [40:12.670 --> 40:18.710] There's no federal law that prevents you from dumping traffic on your own network, because it says you're not allowed to intercept it. [40:18.710 --> 40:20.950] It doesn't say you're, you have to route it. [40:22.670 --> 40:24.350] Interception is, I'm looking at it. [40:24.530 --> 40:34.070] If, you know, if, if, you know, for example, you know, this packet goes by, if I look at the contents, I'm committing a 2511 violation. [40:34.090 --> 40:37.530] If I look at it and go, I haven't read it. [40:37.570 --> 40:38.170] I haven't intercepted it. [40:38.250 --> 40:38.850] I just dumped it. [40:38.990 --> 40:39.530] I'm safe. [40:42.230 --> 40:42.690] Okay. [40:42.930 --> 40:43.750] Some dumb takeaways. [40:44.230 --> 40:48.250] Um, protect yourself, protect your, protect your organization. [40:49.010 --> 40:54.490] Have monitoring clauses in contracts with clients, end users, whoever else. [40:54.810 --> 40:55.690] And it's simple. [40:55.790 --> 41:00.570] You can just have this as one little clause in, you know, the big terms of service. [41:00.690 --> 41:03.010] By using us, you get, you know, we get to do this. [41:04.770 --> 41:07.010] Seek to avoid monitoring innocent traffic. [41:07.830 --> 41:18.830] I love writing one line that's so infinitely complex, because, you know, at least the last time I checked in TCP/IP, or TCP, there is no flag for innocent. [41:19.590 --> 41:22.370] And I'm sure someone will eventually publish that. [41:22.570 --> 41:24.350] And it'll be, you know, April fools. [41:25.130 --> 41:28.510] Um, actually, no, didn't someone, someone did write like the evil bit? [41:28.750 --> 41:29.630] I was thinking like that. [41:29.730 --> 41:31.330] Like, let's, let's activate that, you know? [41:31.870 --> 41:35.690] And just ask that if you're a bot her, you just, you know, evil bit equals one. [41:36.190 --> 41:36.710] Thank you. [41:36.910 --> 41:37.310] That's great. [41:37.910 --> 41:42.150] Um, and if that happens, it'll be perfectly safe, because then you could monitor those. [41:42.490 --> 41:42.870] Um, yeah. [41:43.850 --> 41:48.110] Um, routing metadata is less protected than the contents. [41:48.310 --> 41:54.270] So, if you can figure out some way of sniffing just that, you're better protected. [41:54.530 --> 42:05.270] If you can figure out some metrics by which you can determine, um, bad packets by doing that, you're in a safer place than you are if you actually have to do content analysis. [42:05.270 --> 42:13.350] And I'm also willing to bet that you have some advantages if you, by just, you know, pulling the metadata, pulling the headers, you have less to analyze. [42:14.050 --> 42:16.830] So, it's actually one of those, huh, I can actually do this faster. [42:16.870 --> 42:19.570] So, it might actually be both legally and technically easier. [42:20.730 --> 42:22.690] Of course, you know, I'm not going to write that. [42:22.810 --> 42:23.870] I'm not that good of a coder. [42:24.530 --> 42:27.310] Um, stored communications are protected differently. [42:27.590 --> 42:37.910] I think that's less important for what most botnet defenders would deal with, because you're not actually pulling, you know, there aren't going to be that many stored emails on a box that you're hitting. [42:38.770 --> 42:40.190] Um, but it may happen. [42:41.510 --> 42:45.390] Uh, the biggest takeaway is counterattacks are stupid. [42:46.090 --> 42:47.270] Um, don't get macho. [42:47.510 --> 42:55.390] It's, it's, because my biggest fear is, like, you know, the guy who came to me two years ago and said, I'm pissing off the Scots. [42:56.010 --> 43:03.750] Imagine if you, you know, counterattack, you know, you do your counterattack against, I think this is a botnet. [43:03.910 --> 43:13.230] Instead, they, they, you know, either you'd make a mistake, or they did something neat with, you know, IP spoofing, and you drop, oh, I don't know, Department of Defense website. [43:14.190 --> 43:17.690] You know, on the list of bad things, that's on the top of them. [43:17.790 --> 43:23.350] You know, you could, you could inadvertently, or, you know, stupidly, really increase your problems. [43:23.650 --> 43:27.270] It's like firing wildly in a subway, to defend yourself against a mugger. [43:27.490 --> 43:32.170] There may be easier ways of defending yourself, that don't get you in more trouble than when you started. [43:33.090 --> 43:35.390] Um, wow. [43:38.880 --> 43:39.600] Any questions? [43:40.620 --> 43:40.820] You [43:53.340 --> 43:58.540] know, a man, as long as his castle, what did his, a man's computer, his castle, in terms of, uh, self-defense? [43:58.820 --> 44:02.100] A second point, uh, I'd give about imminent threat. [44:02.460 --> 44:05.660] Uh, so if your neighbor's house is on fire, you should be able to put it out. [44:06.040 --> 44:07.700] Um, the fire's headed your way. [44:08.380 --> 44:10.920] Uh, aren't botnets like the wildfires of the Internet? [44:11.300 --> 44:16.840] And the third question is, um, uh, good Samaritan laws, and also how that would apply in this situation. [44:17.040 --> 44:22.960] Um, all three of those would be good defenses, if you're charged with, you've done something you shouldn't have. [44:23.420 --> 44:27.400] However, the problem is, is that no one's effectively raised those defenses. [44:28.180 --> 44:39.120] And, um, one, one piece of advice is that, that's what we call precedent making, which sounds really cool, you, that means that you get to have your name in an opinion. [44:40.680 --> 44:41.400] That's bad. [44:42.860 --> 44:44.080] For, for one problem. [44:44.700 --> 44:46.340] Half the time, you'll lose them that. [44:46.860 --> 44:58.460] And, you know, like, oh, according to the, you know, you know, according to the Bob Doctrine, and, well, Bob, you know, got to spend obscene sums of money to get it up to the appellate courts to make it an opinion that will follow. [44:58.460 --> 45:01.580] So, um, you're right, that they are potential defenses. [45:02.040 --> 45:04.840] I think the Castle Doctrine would be valid. [45:05.120 --> 45:13.800] I think, um, I don't know about how the Good Samaritan approach would work, because you're a third party, you're completely out of it. [45:15.340 --> 45:22.000] Um, but, yeah, to sum up, they are defenses, I don't know how safe they are. [45:22.000 --> 45:25.440] And I, I wholeheartedly recommend don't try them. [45:25.760 --> 45:26.620] Let someone else do that. [45:27.040 --> 45:28.640] It's like testing minefields. [45:28.780 --> 45:29.960] You go ahead, Bob. [45:30.720 --> 45:31.600] I'll wait here. [45:34.530 --> 45:35.290] Anything else? [45:41.490 --> 45:42.150] Oh, okay. [45:55.790 --> 45:59.390] Sorry, you're right in the light, so it's, it's like that scene from Poltergeist. [46:13.020 --> 46:14.640] Uh, one stupid question. [46:17.660 --> 46:34.120] Is there any way that we can get, quote unquote, deputized, so that we have some kind of a, almost like a private investigator, or a, uh, uh, greater than legal right to investigate, quote unquote? [46:34.600 --> 46:36.280] Yeah, work for law enforcement. [46:36.480 --> 46:37.640] You can contract for them. [46:41.200 --> 46:44.640] No, I mean, if you're, if you have greater protection under a warrant. [46:45.000 --> 46:52.880] If you can get someone to issue a warrant, and you're like, you know, you know, Officer Bob can't, you know, doesn't know how to network, how to, how to do this packet sniffing, but I can, yeah. [46:53.320 --> 46:57.320] You, if you can get, if you can get a court order to order this, you're safe. [46:58.300 --> 47:00.060] It's, it's not, you won't have a badge. [47:00.460 --> 47:02.160] It's not like a, you know, a free range. [47:02.340 --> 47:05.720] It would be instead a, you know, one time only. [47:06.000 --> 47:06.320] Gun? [47:08.300 --> 47:09.120] Come on. [47:09.640 --> 47:11.200] Packet sniffer, firearm. [47:11.460 --> 47:13.380] Any bozo can use a firearm. [47:15.200 --> 47:16.300] I'm from the south. [47:16.460 --> 47:17.320] I ain't no damn bozo. [47:17.960 --> 47:18.800] Second question. [47:19.220 --> 47:32.740] Um, how do shadow server and, uh, botnets.linux, uh, uh, box.org, uh, how do they get a, how do they avoid things like liability, um, uh, uh, uh, I'm sorry. [47:34.180 --> 47:43.080] Um, how do they avoid lawsuits in terms of, uh, uh, libel or defamation? [47:43.080 --> 47:45.640] No one sued them yet, from what I understand. [47:46.680 --> 47:49.020] I mean, a lot of this is, like, fairly new. [47:49.400 --> 47:53.080] I'm, I'm, you know, I don't see any lawsuits related to botnets this year. [47:53.420 --> 47:57.140] In five years it will be, oh, wow, no one thought of that. [47:57.320 --> 47:58.300] No one thought of suing them yet. [47:59.680 --> 48:01.780] But these people are all from another country. [48:01.960 --> 48:04.120] How the heck, how the heck can American law apply? [48:04.540 --> 48:06.120] Is 2511 part of the DMCA? [48:06.320 --> 48:07.120] I kind of missed it. [48:07.380 --> 48:07.620] No, no. [48:07.900 --> 48:14.740] 25, but, um, anything that affects an American, or an American system, we have a long reach, unfortunately. [48:15.980 --> 48:16.720] How are we on time? [48:16.920 --> 48:17.140] Yeah? [48:17.480 --> 48:18.040] One minute. [48:18.180 --> 48:18.720] One more question. [48:19.300 --> 48:21.560] I just sort of wanted to extend that last line of thought. [48:21.560 --> 48:31.380] I mean, this is really something that seems like something, I'm not so clear on legal tactics, but it seems like something that would almost be ripe for, like, class action or something like that, because botnets affect huge numbers of people. [48:31.540 --> 48:36.220] So, what kinds of tactics are available to us on, like, a really big, broad level that way? [48:36.220 --> 48:40.640] Legal attacks against botnet herders and whatnot, um, it's jurisdictional. [48:40.840 --> 48:43.860] Can you get your, can you get your hands around their neck? [48:44.420 --> 48:55.540] Um, you know, biggest problem is that most of the time, you know, the advantage of a bot, of a net is that the members of the gang that are operating it are also diffused. [48:55.640 --> 48:57.420] They're in 22 different jurisdictions. [48:57.820 --> 48:59.280] I mean, we catch the dumb ones. [48:59.380 --> 49:09.900] We catch, uh, I think it was last year, Operation Bot Roast 2, they caught, um, a University of Pennsylvania student who was running bots off of a server that he had access to. [49:10.100 --> 49:11.160] Like, dude, you're dumb. [49:12.100 --> 49:12.640] You know. [49:15.320 --> 49:15.940] Thank you. [49:38.450 --> 49:44.110] Coming up in just a minute, maintaining a lock sporting organization and breakthroughs in the community. [49:55.920 --> 49:59.240] By using this, you agreed to approve. [49:59.240 --> 50:01.120] What if you get this on system?