[00:00.000 --> 00:01.060] Too sleepy after lunch here. [00:01.680 --> 00:04.460] So, a couple of quick announcements before we get started. [00:04.800 --> 00:09.880] First thing I wanted to mention, there's a lot of activities going on right now down on the Mezzanine level. [00:10.220 --> 00:13.920] Hacker Village, lockpicking, demos, vendor tables. [00:14.200 --> 00:15.100] We have hammocks. [00:15.740 --> 00:19.080] So, after the talk, go on down to Mezzanine, check it out. [00:19.260 --> 00:19.800] Lots of stuff. [00:20.120 --> 00:21.440] Lots of good stuff happening there. [00:21.840 --> 00:26.360] Other thing I wanted to mention, Track 4 is going to be starting in the Morse room. [00:26.980 --> 00:31.680] Track 4 is open, so there are actually sign-up sheets posted outside the Morse room. [00:31.840 --> 00:38.560] So, if you guys want to give your own talk, go ahead and sign up and you can give your own talk over in the Morse room. [00:39.440 --> 00:45.260] With that said, Zeus botnets and Zeus Trojans, they're readily available. [00:45.500 --> 00:50.280] They are pretty easy to use for the technologically unsavvy. [00:50.280 --> 00:56.980] We have Peter Greco and Fabian Rothschild here to talk to us about how to code to resist botnets. [00:57.600 --> 00:57.960] John. [01:02.270 --> 01:03.270] Hey, I'm Pete. [01:04.030 --> 01:05.030] I'm Fabian. [01:05.210 --> 01:13.330] And we're here to show you techniques to mitigate against botnets, particularly focusing on postloggers. [01:14.170 --> 01:27.090] We would like to put a disclaimer that we're not intended to teach people how to use botnets and postloggers in particular, and that no criminals or web servers were harmed during our research. [01:29.370 --> 01:34.190] We're going to talk about the brief explanation of what botnets are, particularly the Zeus Trojan. [01:34.190 --> 01:41.350] We also looked at SpyEye 2, but for this talk, we're going to focus on Zeus, because it seems to be the most prevalent one. [01:41.870 --> 01:49.970] We're going to talk about the psychology behind a bot master, a little bit about HTML basics, and then we're going to show the methods of mitigation that we came up with. [01:52.310 --> 01:53.710] So, little things. [01:54.310 --> 01:58.510] In fact, 400% of all computers out there are infected with malware. [02:00.490 --> 02:02.890] Mostly porn, including this one. [02:06.010 --> 02:16.010] Zeus collects logins, passwords, cookies, view state parameters, virtually everything passed in a POST request, hence the name POSTloggers. [02:16.370 --> 02:35.910] The infected machines communicate with command and control server, which is a PHP web application, through the use of HTTP port 80 POST requests that take the POST data, compiles it into a text file, zips it up, RC4 encrypts it, and sends it over to the web server. [02:36.730 --> 02:44.810] Malicious DLLs hook the web browser, and reports are entered into an SQL database on the actual server, or text files, depending on how you set it up. [02:45.490 --> 02:53.230] The command and control center is definitely a user-friendly PHP application, so you don't need a lot of skill to know how to use it. [02:55.150 --> 03:03.830] Zeus works, the propagation methods is usually by spam and phishing, infected, cryptid, P2P wares, exploit packs. [03:04.170 --> 03:09.730] The largest one out there is Eleanor, usually followed by Fragus or Unique. [03:09.870 --> 03:16.330] They're iframe droppers, PDF, and they sometimes include flash exploits too. [03:16.330 --> 03:24.610] Social engineering is a more larger part of it, getting people to download fake codexes, software, and the other things. [03:24.930 --> 03:27.030] There's a few other mentions that we're not going to say. [03:27.470 --> 03:38.170] The way Zeus works, when it infects a machine, it injects a thread into services.exe, and it's pretty much invisible to Task Manager, the Windows one anyway. [03:38.330 --> 03:42.270] You can use like Process Explorer or something to see the thread, but for the most part invisible. [03:43.330 --> 03:48.290] The configuration files are in the Windows folder, in the System32 folder. [03:48.590 --> 03:51.970] It hides the folder using, you know, rootkit technology. [03:53.230 --> 03:56.430] And for the most part, also hard to detect. [03:56.750 --> 04:04.650] It has a very low detection rate by antivirus because of how, how many, you know, different variants there are. [04:04.650 --> 04:05.710] People write plug-ins for it. [04:05.810 --> 04:07.050] People encrypt it. [04:07.170 --> 04:09.850] They have lots of methods of obfuscation for it. [04:09.930 --> 04:13.750] And it makes it really hard for AV vendors to actually be able to keep up. [04:15.730 --> 04:19.790] Okay, basically the life cycle of Zeus first ends up with a builder. [04:20.510 --> 04:21.590] It's an executable file. [04:21.810 --> 04:24.850] You have to run it on a Windows machine, which is kind of ironic. [04:25.630 --> 04:32.610] It unzips into an actual payload generator and the PHP files that you need for your web server. [04:32.610 --> 04:41.870] From there, the generator payload usually gets sent to the machine through various web exploits, pirated softwares, as we talked to earlier. [04:42.230 --> 04:49.430] Infects the machine, posts logs, sends it back, post transmission to, back to the server, which then gets put in the database. [04:49.690 --> 04:55.410] And financial data is then harvested out of this large collection of posts. [04:56.530 --> 04:59.350] Here's an example of a Zeus control panel. [04:59.850 --> 05:02.050] It usually tells you what version it is. [05:02.050 --> 05:03.330] This is kind of an old version. [05:03.930 --> 05:06.950] It organizes the infections by country. [05:07.150 --> 05:09.170] It shows you how many are online, are offline. [05:09.190 --> 05:13.430] And the major thing that we're going to be focusing on is the report section. [05:13.670 --> 05:20.190] This is where one of the means that bot masters harvest the credentials that they need to get money. [05:20.430 --> 05:22.950] The primary tool used is search in database. [05:23.350 --> 05:25.530] If they set up in the files, they're searching files. [05:25.530 --> 05:28.150] Another interesting thing is the Jabber notifier. [05:28.370 --> 05:43.910] As we know, Jabber is an open source instant messaging system that the Zeus will actually notify the bot master when anything juicy that comes around, such as a bank login session or any of the other. [05:44.010 --> 05:50.330] There's many plugins that you can get that work with the Jabber notifier to send you that information, types of Mule software. [05:50.330 --> 05:52.790] This is a sample reports file. [05:53.050 --> 06:01.490] As we can see, you have the bot ID, the operating system, what country it's from, and the website that it visited for this. [06:01.610 --> 06:04.890] As we can see, that's a website. [06:06.210 --> 06:07.330] Sample reports file. [06:07.450 --> 06:09.970] This is the actual post log data that we can see. [06:10.150 --> 06:16.330] As you see, every single post parameter gets put into a text file or entered in the database. [06:16.330 --> 06:20.670] Here we have email, first name, last name, credit card information. [06:20.890 --> 06:25.550] Basically, everything that I can flip for about $20 on the cyber crime market. [06:27.430 --> 06:28.910] Psychology of a bot master. [06:34.210 --> 06:38.780] Basically, most bot masters, as we looked at it, were actually low in technical skill. [06:39.060 --> 06:41.460] They're very impatient with harvesting of credentials. [06:41.740 --> 06:45.160] And a lot of times, they rely on others to set up their bot nets. [06:45.160 --> 06:59.080] So there are actually people that sell services for bot net installations, which usually include an exploit kit, which they log on to whatever server they have. [06:59.300 --> 07:00.500] They install the bot net. [07:00.680 --> 07:01.880] They install the exploit kit. [07:01.940 --> 07:03.340] They set up the campaign for them. [07:03.420 --> 07:10.300] And then the bot master just sits back and uses the means of getting the campaign out there and collecting the information. [07:11.770 --> 07:17.780] This is the basic flow chart where the bot master sits on the actual crime flow. [07:18.080 --> 07:20.180] We see we have the bot master on one end. [07:20.280 --> 07:21.760] He works with the guarantor. [07:21.940 --> 07:24.900] The guarantor actually helps the bot master sell data. [07:25.020 --> 07:29.620] Sometimes the guarantor is the bot master, but a lot of times it goes over another thing. [07:30.200 --> 07:33.140] Trust is very important in the cyber crime market. [07:33.140 --> 07:41.520] From there, data gets sold to carters, extorters, pornographers, spammers, and the services go one way and money goes the other way. [07:41.840 --> 07:42.000] Okay. [07:42.180 --> 07:43.620] What does a guarantor look like? [07:43.680 --> 07:50.680] This is a typical guarantor that's being advertised on forums that is selling bot net data. [07:50.940 --> 07:51.160] Okay. [07:51.580 --> 07:53.320] And who buys bot net data? [07:53.440 --> 07:54.580] Well, this site was great. [07:56.100 --> 08:03.860] This is the actual person's... due to the economic collapse, a lot of pornographers cannot afford models. [08:04.120 --> 08:10.280] So now they're going to hacked data as a cheaper form of collecting the information. [08:11.040 --> 08:13.420] And as we know, the Internet is worldwide. [08:13.520 --> 08:18.140] We found harvested accounts on all language servers. [08:21.660 --> 08:22.980] So, HTTP basics. [08:23.520 --> 08:26.400] There's two kinds of HTTP requests that we're concerned with, really. [08:27.120 --> 08:29.640] We're going to have HTTP get requests. [08:30.860 --> 08:36.400] Normally, I guess most of you know what this is, but it's, you know, a browser asks for some data from the server. [08:37.380 --> 08:38.920] The server responds, gives you the data. [08:39.950 --> 08:43.280] You have a lot more of these than post requests. [08:44.170 --> 08:45.780] And usually there's not a lot of data in there. [08:47.780 --> 08:54.740] You know, web developers don't like putting a lot of sensitive data, like credit card numbers and things like that, in the get request. [08:54.740 --> 08:58.020] Because that'll show up in your address bar and, you know, it doesn't... [08:58.020 --> 09:02.210] If you're showing, you know, credit card numbers in the address bar, you've got bigger problems than Zeus. [09:04.940 --> 09:14.120] HTTP post request, pretty much what Zeus is designed to do is, you know, just log these post requests. [09:15.340 --> 09:24.760] So, what usually goes through here is, anytime you submit a form, goes through the post, credit card numbers, usernames, passwords, everything like that. [09:26.220 --> 09:34.480] Okay, so the important thing is that Zeus does not only logs post requests and does not log get requests. [09:34.720 --> 09:43.680] So, there's a lot of information that we can pass from the server to the client in a get request for the various methods that we're going to show you from here. [09:43.680 --> 09:46.860] We came up with four basic methods of mitigation. [09:47.100 --> 09:49.500] Now, these aren't 100% foolproof. [09:49.570 --> 09:54.980] And we weren't looking to come up with black and white ways of blocking it. [09:55.080 --> 09:57.960] If the person's good, they're going to get the data that's guaranteed. [09:57.980 --> 10:11.140] And we're focusing on what can we do from a server-side web application development process when we know that the client machine is compromised to save them from losing all their data. [10:11.380 --> 10:19.780] So, we came up with the basic method, which is methods that can be changed in the form sections of the pages that get served to the client. [10:20.620 --> 10:24.660] Medium methods introduces JavaScript methods of post-data obfuscation. [10:25.240 --> 10:31.920] Hard methods, we had elements of JavaScript and server-side sessioning, which includes Ajax requests. [10:32.450 --> 10:35.680] And then, of course, Nightmare, we show symmetric encryption method. [10:37.500 --> 10:39.640] In this, we're going to show that there's... [10:39.640 --> 10:44.450] Now, it's important as a web master that you need to focus on server load. [10:44.660 --> 10:47.580] So, throughout this presentation, we're going to show you different... [10:47.580 --> 10:53.450] And the examples that we've created, icons that show how heavy the server load is. [10:53.450 --> 11:02.380] So, basic methods of mitigation includes obfuscation of variable names and extraneous hidden post parameters. [11:03.620 --> 11:09.620] As we can see, you don't need to name your variable CC number, okay? [11:09.780 --> 11:15.260] They look through this for things, CC, number, everything. [11:15.600 --> 11:18.980] They use a...as you saw in the report section, they search through it. [11:19.100 --> 11:22.080] You can name this variable anything you want. [11:22.080 --> 11:25.340] And as long as the server-side and client-side knows, it's great. [11:26.540 --> 11:36.580] You can also...as you can see here, this is a prominent website that named their password, password, and their confirmation, confirmation. [11:36.900 --> 11:41.340] Which, as the bot master goes through the post requests, can easily find this. [11:42.680 --> 11:44.800] Of course, we all know hidden fields. [11:45.020 --> 11:49.960] You can also use this to put in false lead data, as I have listed here. [11:50.440 --> 11:56.840] And to the client, we can see that I put in two extraneous hidden post parameters of just junk data. [11:57.240 --> 12:02.240] And from the client that uses it, they see their main field being the account number. [12:02.240 --> 12:08.420] But in the actual post request, we see a whole bunch of other junk data that bloats logs. [12:08.980 --> 12:10.880] Bot masters sell logs. [12:11.180 --> 12:15.140] They sell their massive chunk data as a per megabyte basis. [12:15.440 --> 12:17.300] And trust is very important. [12:17.540 --> 12:21.620] So quality of those logs includes more money that they can make. [12:21.620 --> 12:24.860] And if their quality isn't that good, they're going to make less money. [12:24.900 --> 12:26.840] And it's going to really hurt the marketplace. [12:31.080 --> 12:46.700] Basics of...methods of mitigation medium includes all basic methods and the actual obfuscation of the data through prefixing, postfixing, parameter modification, and regex replacement using JavaScript. [12:46.700 --> 12:53.360] As we know, postloggers do not log get requests. [12:53.440 --> 12:59.700] So we can send our JavaScript functions to the client computer and they will not be recorded in the Zeus data. [12:59.940 --> 13:16.720] From there, we use hidden parameter creation from the on submit button, which then the JavaScript function takes the form input value and blanks the original one that loaded on the page and sends it back to the client, which then on the server-side code it, demangles it. [13:17.620 --> 13:21.100] Here's a simple JavaScript function for prefixing, postfixing. [13:21.260 --> 13:29.340] You can do any number of string manipulation that you want as long as you can undo it on the server-side, which whatever server-side code you're using. [13:29.860 --> 13:34.480] Here's a regex example replacing the five and two with the number of percent. [13:35.040 --> 13:38.760] From here, you can use...this is the most important thing here. [13:38.760 --> 13:48.160] You take the variables, you take the form, load it, create a hidden variable, do the data mangler, put it into the form, and this all happens on submit. [13:48.380 --> 13:52.880] And then it takes the original input value and makes it any arbitrary number. [13:53.020 --> 14:01.120] So when the bot master goes to look at those logs, they're going to see the CC number, thinking they're getting a valid one, and all they're getting is junk data. [14:01.120 --> 14:08.400] When the original one is now mangled by the JavaScript and then demangled on the server-side. [14:09.280 --> 14:10.780] Methods of mitigation hard. [14:11.360 --> 14:18.540] This we actually introduced basic for encoding and concatenation and tokenization of the values. [14:18.720 --> 14:20.860] This is a little more difficult. [14:21.220 --> 14:23.400] It's a little harder in the server-side thing. [14:23.500 --> 14:29.600] And we use Ajax posting messages to fill the data with...fill the logs with fake data. [14:31.140 --> 14:36.140] This is the basics of 64 encoding and decoding, if anybody doesn't know. [14:36.740 --> 14:44.820] Base64 is a way of sending arbitrary data over a textural-based media and can be very useful in obfuscation techniques. [14:45.320 --> 14:46.760] Okay, web server sessioning. [14:46.880 --> 14:49.640] This is very important because we can store... [14:50.910 --> 14:58.140] We can have several different JavaScript data mangling sessions, I mean, functions that we can use with the session. [14:58.140 --> 15:09.320] So, as we create a session with the client computer in the web server, we can assign it a data mangling function that goes to the client and is unique to that session. [15:09.640 --> 15:26.020] So, when the bot master then goes back a day later, a week later, a month later, and then tries to go to the site to get the actual JavaScript mangling function, it's going to be completely different and make it really hard for them to determine what is valid data and what isn't. [15:27.500 --> 15:30.420] So, this is how we do methods of mitigation hard. [15:30.540 --> 15:36.540] This is actually a little more where we actually have input fields without form tags. [15:36.800 --> 15:37.120] Okay? [15:37.420 --> 15:42.380] Then we use a regular HTML button with an on-click JavaScript function. [15:42.540 --> 15:56.840] From the on-click JavaScript function, it creates a hidden form through JavaScript, concatenates all the input tags into one long string with the deliminator, then use a hidden form field to put the concatenated value, Base64 encode it. [15:56.980 --> 16:05.320] You can also do a regex replacement of certain characters so they can't de-Base64 it, and then it sends that form as a post back to the server. [16:06.700 --> 16:17.740] As you can see here, here's an example of the concatenation function with the element creating the form and then sending it to the server from the on-submit. [16:20.400 --> 16:21.420] Here's another way. [16:21.540 --> 16:32.980] You can use Ajax to send intermittent post requests to fill the logs of useless junk data and then have the server recognize when a real post comes through. [16:33.260 --> 16:38.640] Basically, everything is loaded from the get request to the client side with the Ajax function. [16:38.840 --> 16:48.180] The Ajax function starts up as the user goes through the page, looks at it, picks out what they want, and it's sending arbitrary useless data posted back to the server. [16:48.380 --> 16:54.500] This will fill up the botnet logs and cause a lot of data that they would have to sift through to figure out what's going on. [16:54.500 --> 17:03.640] From the on-submit, there is a parameter number set by the web server that will tell that this is the real post request to pay attention to. [17:03.820 --> 17:09.840] That would be sent, then the server will then get the data and be able to do the useful functions. [17:10.200 --> 17:14.360] As we see here, this is a basic Ajax script that you can use. [17:16.300 --> 17:22.980] From here, we have a fake poster function that uses a random number function to send phone name. [17:22.980 --> 17:24.600] You know, you can send credit card data. [17:24.770 --> 17:34.510] And then, of course, you'd use the same function or create a similar function with that unique number in it that would tell the server that this is the valid post to pay attention to. [17:35.040 --> 17:35.340] Okay. [17:35.640 --> 17:36.960] Methods of mitigation nightmare. [17:37.340 --> 17:38.660] Do you want to... okay. [17:39.580 --> 17:43.720] This... we actually picked out RC4 encryption with rotating keys. [17:43.820 --> 17:49.440] As we know, RC4 encryption is not a very good encryption algorithm, preferably used by WEP. [17:49.440 --> 17:53.860] But the method that it does, it uses the same key for all transaction. [17:54.200 --> 18:12.560] But if we rotate the key through a session variable and send it and change it every time there's a post and communicate back and forth, we can then have a different key for every session that the form is in the submit, which will cause to send back encrypted data. [18:13.510 --> 18:15.840] The HTML form is pages loaded. [18:16.160 --> 18:19.960] The JavaScript with symmetrical RC4 key is sent to the client. [18:20.220 --> 18:25.530] Now, that's sent in the get request, which is not recorded in the Zeus post logs. [18:25.700 --> 18:29.840] From there, the on submit, the RC4 encrypted post is sent to the web server. [18:30.100 --> 18:35.420] The stolen data is totally useless for the typical bot master. [18:37.160 --> 18:42.900] And as you can see, the RC4 encryption for a JavaScript function is only 10 lines. [18:43.080 --> 18:50.920] So, as a client side, looking at the JavaScript, it's a very minimal load and weight for their applications. [18:51.510 --> 18:56.800] So, these are just examples to prevent identity theft. [18:56.800 --> 18:58.200] We know they are not 100%. [18:58.730 --> 19:02.980] And we're looking at going to a generalized mitigation of a whole. [19:03.300 --> 19:08.140] And we know that there will be people out there that can bypass all of this. [19:08.380 --> 19:13.660] There are many modules that people make for Zeus specific to banks. [19:14.340 --> 19:20.060] And also through the webinjects function of Zeus, it can pretty much bypass this. [19:20.320 --> 19:25.920] And Fabian is going to demonstrate all of our demos that we have with the actual coded sessions. [19:28.300 --> 19:28.790] All right. [19:28.920 --> 19:30.060] Sorry I haven't talked very much. [19:30.220 --> 19:32.980] I'm more of a keyboard jockey than a speaker. [19:33.530 --> 19:33.960] Here we go. [19:36.740 --> 19:37.780] Let's see if this works. [19:38.760 --> 19:39.740] Oh, you have to... [19:39.740 --> 19:40.480] I don't think they can see it. [19:40.640 --> 19:40.780] Nope. [19:40.940 --> 19:41.200] Hold on. [19:41.340 --> 19:42.700] You have to minimize. [19:45.940 --> 19:46.280] Just... [19:49.600 --> 19:51.320] A little fix. [19:52.680 --> 19:53.600] Say hi to my friend. [19:53.780 --> 19:55.140] He's scary with a wireless router. [20:09.010 --> 20:09.670] There we go. [20:12.650 --> 20:13.010] There we go. [20:13.010 --> 20:13.650] So here's the demo. [20:16.630 --> 20:16.990] Normally... [20:16.990 --> 20:18.310] Let's actually do this. [20:19.670 --> 20:21.390] I'm going to set it up on HTTPS. [20:25.090 --> 20:25.930] I'm just a connection. [20:26.310 --> 20:26.410] Sorry. [20:26.570 --> 20:27.190] Self-signed certificate. [20:28.070 --> 20:28.730] Nothing visible. [20:29.710 --> 20:30.070] Nothing? [20:31.030 --> 20:31.470] All right. [20:31.590 --> 20:31.910] One second. [20:49.670 --> 20:50.450] You want to check it out? [20:50.510 --> 20:50.590] Yeah. [20:50.770 --> 20:51.090] There we go. [20:51.230 --> 20:51.590] There we go. [20:51.630 --> 20:52.310] Everybody can see that? [20:52.310 --> 20:52.870] Yeah. [20:53.270 --> 20:53.750] Sweet. [20:54.250 --> 20:54.510] All right. [20:55.090 --> 20:56.210] Let me go ahead and add this. [21:00.810 --> 21:01.190] Okay. [21:01.550 --> 21:05.210] So normally, we have the HTTPS only. [21:05.970 --> 21:14.090] And the way this works is type in your username, your password, and you hit the login button. [21:15.050 --> 21:21.310] And then what Zeus sees is username here. [21:21.470 --> 21:23.130] As you can see, I'm dumping the array. [21:23.370 --> 21:26.950] You see the username and the password right there. [21:28.850 --> 21:32.890] But let's look at the simple side here. [21:34.530 --> 21:36.370] You know, just basic thing here. [21:36.630 --> 21:37.590] Just type in your account number. [21:38.890 --> 21:55.810] And then when we do submit that, again, they're going to get some extra post parameters here with a bunch of junk data, the real stuff, and then a lot more junk data. [21:57.310 --> 21:59.030] So let's go back here. [22:01.050 --> 22:10.910] The medium, just putting in your, you know, your credit card number, your account number. [22:11.210 --> 22:18.770] And what this one does is when you hit submit, it's going to blank out the top form here with just a bunch of pluses. [22:20.230 --> 22:25.250] And what we're going to get is the CC number is going to be junk data. [22:26.530 --> 22:29.250] The other text box, we didn't put anything on there. [22:29.510 --> 22:32.170] And then the real one is going to be in here. [22:35.340 --> 22:36.200] Not for hard. [22:38.760 --> 22:43.700] So what we're doing here is in the background, it's actually doing post requests. [22:45.140 --> 22:47.120] Let's see if we can take a look at perils here. [22:50.940 --> 22:51.760] Clear this. [22:57.150 --> 22:57.550] Okay. [22:57.730 --> 22:58.630] Perils isn't cooperating. [22:58.810 --> 22:59.810] So we're going to go back over here. [23:01.650 --> 23:05.510] You see the name, the address, credit card number, expiration day, CVV. [23:06.750 --> 23:14.490] And when you submit this, what gets submitted is this long Base64. [23:14.770 --> 23:24.450] You're going to see here there's only a single parameter because it's concatenating all of the parameters into one long Base64 string. [23:24.630 --> 23:27.210] If we look over here, we can see how long that is. [23:27.290 --> 23:27.890] No, we can't. [23:28.570 --> 23:31.830] And then we can demangle it on the server. [23:32.330 --> 23:35.590] And we have all the information there. [23:35.770 --> 23:47.030] Now you can also use the regex replacement function when you Base64 to obfuscate the Base64 function of it and make it harder for them to decode it. [23:47.730 --> 23:48.130] All right. [23:48.310 --> 23:48.910] And now for nightmare. [23:50.870 --> 24:00.370] So this one is also doing the same thing except it's sending random data encrypted with a random key every few seconds on a random interval. [24:00.370 --> 24:07.530] So if you're looking at the logs, you're going to see a bunch of logs of all this data getting submitted. [24:08.750 --> 24:10.270] And you can't decrypt it. [24:10.310 --> 24:11.790] You don't know which one is the real one. [24:12.230 --> 24:14.850] And it all looks pretty much the same. [24:15.850 --> 24:20.970] So we put in our name, phone number, vessel name, number of hostages, ransom demands. [24:24.390 --> 24:28.970] And once we submit that request, here's what the post looks like. [24:29.230 --> 24:33.510] The post parameter name is actually part of the obfuscation. [24:35.050 --> 24:41.410] Every single one of those random posts has a different MD5 hash. [24:41.690 --> 24:44.650] Just some random number that gets generated on the client side. [24:45.370 --> 24:51.470] And a bunch of data in here that's just, again, random data. [24:51.470 --> 24:54.350] It doesn't mean anything to anybody. [24:54.590 --> 24:55.690] The server rejects it. [24:55.870 --> 24:57.130] But Zeus picks it up. [24:58.010 --> 25:00.710] The RC4 key, again, is an MD5 hash of a random number. [25:00.810 --> 25:05.370] But this one is the actual real key. [25:06.150 --> 25:13.630] And then here is the decrypted data on the server side, which hopefully did not get picked up by the bot masters. [25:14.670 --> 25:14.930] All right. [25:16.470 --> 25:17.890] So that's it for that. [25:18.030 --> 25:18.650] Any questions? [25:19.230 --> 25:19.710] Does anybody have any questions? [25:19.750 --> 25:20.770] One thing to mention. [25:20.770 --> 25:27.630] With Flex, Flex4 actually has AMF encoding built into it. [25:27.710 --> 25:31.310] That makes it really hard to decode it. [25:31.670 --> 25:34.870] It can be done with known programs out there. [25:34.990 --> 25:38.570] But most bot masters will skip over it because they won't know what it is. [25:38.670 --> 25:44.350] So there are new technologies with encoding and encryption being built for web applications. [25:45.190 --> 25:51.070] We are also looking to make a .NET plugin module that will do all of this for the developers. [25:51.490 --> 25:52.710] So they don't really need to do that. [25:52.830 --> 25:54.420] That is future research that we are looking for. [25:55.110 --> 25:56.510] Right now these examples are in PHP. [25:57.350 --> 26:02.030] Does anybody have any questions about botnets and or resistant coding? [26:03.330 --> 26:04.110] I can't see. [26:04.710 --> 26:05.190] I have a question. [26:05.450 --> 26:05.590] Yeah. [26:06.570 --> 26:07.390] C sharp. [26:07.750 --> 26:13.330] Most people don't bother encoding their view state information with their ASPX servers and whatnot. [26:14.550 --> 26:17.150] Does Zeus automatically decode the view state information? [26:17.270 --> 26:19.370] Because I know a whole bunch of data is still in the view state. [26:20.290 --> 26:20.770] Yeah. [26:20.890 --> 26:21.950] That's a very good question. [26:22.290 --> 26:24.330] Zeus just captures. [26:24.330 --> 26:26.090] It does not decode it. [26:26.330 --> 26:30.170] But most of the view states as we know is a simple Base64 decode. [26:30.590 --> 26:36.230] And they do look at view state and they do use view state decoders to get data out of that. [26:36.450 --> 26:45.370] That is a major thing that I have against C sharp even though I do like C sharp and do development in C sharp. [26:45.610 --> 26:52.310] But there are settings that you can do for C sharp to encode and encrypt the view state. [26:52.530 --> 26:52.750] Right. [26:52.970 --> 26:53.110] Yes. [26:54.330 --> 26:58.110] If we have any C sharp developers here, please encrypt your view states. [26:58.970 --> 26:59.410] Please. [27:01.130 --> 27:02.110] Makes my life easier. [27:02.670 --> 27:03.570] Any other questions? [27:04.970 --> 27:06.910] You can ask us questions about Trojans too. [27:07.730 --> 27:10.120] The RC4? [27:10.340 --> 27:10.660] Yes. [27:10.900 --> 27:12.240] Is that detectable at this point? [27:13.300 --> 27:15.100] It gets passed in a GET request. [27:16.200 --> 27:19.860] So specifically against Zeus, for the most part, it's not going to pick it up. [27:21.520 --> 27:25.040] I'm sure that there's ways of configuring it to maybe pick it up. [27:26.660 --> 27:29.900] But for the most part, I mean, right now there's nothing that does that. [27:29.900 --> 27:31.300] That's in general. [27:31.480 --> 27:40.000] But there are programmers out there that make plugins for Zeus that are specific to certain banking websites. [27:40.360 --> 27:47.940] So they will create a module that will grab those GET request encryption keys and will store them. [27:47.940 --> 27:53.540] I haven't really ran into this, but I have seen a lot of plugins for Zeus that do a lot of stuff. [27:53.840 --> 27:58.480] But most of the plugins for Zeus just focus on the web injects portion of it. [27:59.220 --> 28:03.920] Zeus is ignoring GET requests because they think it has no valuable data in the channel? [28:03.920 --> 28:04.840] That's correct. [28:05.200 --> 28:05.980] In general. [28:06.380 --> 28:06.700] I see. [28:06.940 --> 28:14.580] And they're not parsing credit card numbers in arbitrary fields even though they have, you know, standard forms. [28:15.400 --> 28:18.300] You know, they look like N digits and they have the checksum. [28:18.400 --> 28:21.520] Well, we can go back to actual Zeus. [28:21.520 --> 28:30.180] Well, for the most part, they only, I mean, Zeus, the public versions and the versions that we've seen, for the most part, they just grab post requests. [28:30.180 --> 28:33.640] No, I'm talking about the parsing of the results, of the post results. [28:34.260 --> 28:34.720] They don't just... [28:34.720 --> 28:35.160] Oh, going through it? [28:36.220 --> 28:38.720] Well, it depends on how much time the person has. [28:39.200 --> 28:39.600] Usually... [28:39.600 --> 28:40.540] It's a manual process? [28:40.900 --> 28:41.220] Yeah. [28:41.420 --> 28:42.560] Yeah, a manual process is 90% of it. [28:42.560 --> 28:46.120] Rather than writing a data harvester that takes anything that looks like a credit card. [28:46.700 --> 28:48.360] There are plugins that do that. [28:48.520 --> 28:55.420] They have separate programs that you load in the Zeus data and it parses all the interesting information that you're talking about. [28:55.480 --> 28:56.740] Yeah, there are stuff like that out there. [28:56.740 --> 29:05.600] I'm surprised you didn't suggest people start using Flash or Java to do these kinds of authentication and take it out of channel completely. [29:05.860 --> 29:09.000] Well, with Flex 4, it does a lot of that for you. [29:09.080 --> 29:18.600] So it's easier if you're developing applications and you're worried about data to use Flex somewhat. [29:18.600 --> 29:18.660] That's a good point. [29:19.660 --> 29:35.060] When you were saying one of your methods of mitigation was sending random information through post requests in JavaScript, you said there was some variable on submit that you could set to tell the server side that this is fake data, ignore it, or this is the real data. [29:36.140 --> 29:45.920] Since Zeus is actually logging the post data, would they not be able to, for example, find out what that, hey, this is real thing is and just sort of filter out their logs? [29:46.220 --> 29:46.760] Oh, no. [29:47.060 --> 29:53.380] That key that... the pay attention key is sent in a get request as part of the JavaScript function. [29:53.720 --> 29:54.040] Oh, okay. [29:54.100 --> 30:01.040] Because I was going to suggest why don't you just do something like in your post requests, have a get variable called like nfake equals one or something like that. [30:01.140 --> 30:02.160] That's what we do. [30:02.280 --> 30:03.320] We don't use a get variable. [30:03.420 --> 30:06.040] We send it with the JavaScript function that loads. [30:06.380 --> 30:09.280] We have the pay attention variable. [30:10.320 --> 30:11.980] I haven't given this too much thought. [30:11.980 --> 30:12.500] I just thought about it. [30:12.600 --> 30:13.020] What about... [30:13.020 --> 30:17.280] Have you used like a JSON encode and then somehow... [30:18.580 --> 30:21.460] or whatever, that string? [30:21.720 --> 30:27.640] Because then you just have to work with a post array versus like having to go through and figure out what things you put in there and that. [30:27.860 --> 30:28.900] Yeah, I mean, I haven't... [30:28.900 --> 30:30.980] I didn't use JSON because I just never have. [30:31.440 --> 30:31.700] Okay. [30:31.960 --> 30:35.720] I just took the regular post request and messed around with it and that was it. [30:35.920 --> 30:36.120] Cool. [30:36.200 --> 30:41.600] We were focusing really on the client side on methods to send over there to send it back. [30:42.260 --> 30:42.840] Right, yeah. [30:42.980 --> 30:43.340] So, yeah. [30:43.600 --> 30:47.360] Yeah, but you can create that string from the whole post array... [30:47.360 --> 30:47.400] Yeah. [30:47.920 --> 30:49.160] ...on the client side and then send it. [30:49.280 --> 30:50.620] So you usually do like Ajax requests and stuff. [30:50.640 --> 30:51.020] It's the same thing. [30:54.820 --> 30:55.180] Hi. [30:55.480 --> 31:01.960] Speaking of the client side, do you know if running as a Windows restricted user prevents the Zeus infection in the first place? [31:03.000 --> 31:13.940] I've seen it infect limited users, but I mean, I'm not sure that that would prevent it at all. [31:14.000 --> 31:16.960] Because usually it's an exploit, so... [31:17.620 --> 31:22.840] A lot of the infections get there through users saying yes. [31:23.300 --> 31:24.960] Through some sort of... [31:24.960 --> 31:25.340] Social engineering. [31:25.340 --> 31:25.680] Yeah. [31:26.020 --> 31:30.020] 90% of it that we've run into is some form of social engineering. [31:30.280 --> 31:34.580] And so a person purposely installs it without really knowing. [31:34.780 --> 31:37.500] But that's part of the point of being a restricted user is you can't install anything. [31:38.200 --> 31:41.380] It's not that simple, but that's the theory at least. [31:41.460 --> 31:41.720] Yeah. [31:42.280 --> 31:45.020] We really haven't explored that too much, but what we've seen... [31:45.020 --> 31:46.700] I know nobody ever runs as a restricted user. [31:46.960 --> 31:47.140] Yeah. [31:47.340 --> 31:47.580] Yeah. [31:47.740 --> 31:53.560] But the infected machines we've seen on botnets has been... [31:55.440 --> 31:56.860] I've seen corporate machines. [31:56.940 --> 31:59.860] I've seen cash registers. [32:00.240 --> 32:02.340] I've seen, you know, home users. [32:03.120 --> 32:09.080] We've even seen safe tokens going logged in the post request. [32:09.360 --> 32:09.920] So... [32:09.920 --> 32:13.000] You say most antivirus programs can't see it or detect it. [32:13.060 --> 32:14.000] How do you detect it? [32:14.000 --> 32:15.360] How do we detect it? [32:15.400 --> 32:15.580] Yeah. [32:16.320 --> 32:19.280] We monitor the traffic and look for... [32:19.280 --> 32:19.460] Oh, nice. [32:19.580 --> 32:24.360] ...beacons of RC4 encrypted data that goes up port 80 every half hour. [32:26.420 --> 32:27.080] Thank you. [32:30.010 --> 32:30.490] Okay. [32:30.910 --> 32:35.270] It seems like part of the issue here is not that you're trying to make it impossible to break. [32:35.410 --> 32:39.950] You're trying to make your data not worth the time because they move on to the next... [32:39.950 --> 32:40.910] Yes, exactly. [32:42.170 --> 32:42.650] Okay. [32:42.650 --> 32:51.490] You're trying to mitigate most of the botnet users by frustrating them completely and having them go on to more vulnerable sites, which there seems to be tons of. [32:51.490 --> 32:51.550] Yeah. [32:51.550 --> 32:55.690] I mean, if they really want to, they can go in and try to figure this out and write a new plugin for Zeus. [32:55.910 --> 32:58.250] But I mean, that's going to take them so much time that it's just... [32:58.250 --> 33:02.570] But if you're not a bank, as you mentioned, maybe you're a softer target that's not as worth their time. [33:02.710 --> 33:02.910] Yes. [33:02.910 --> 33:05.370] And they might, because of this gloss over you. [33:05.630 --> 33:05.910] Yes. [33:06.130 --> 33:06.250] Yes. [33:08.170 --> 33:18.950] It seems that part of your strategy here is, as you just explained, is to make the data that your modified sites generate be worth less to the bot master. [33:19.190 --> 33:19.590] Yes. [33:19.670 --> 33:21.790] That's another strategy that we look at, too. [33:21.990 --> 33:22.110] Right. [33:22.750 --> 33:28.390] Have you thought about taking it a step further, where the botnet master seems... [33:28.390 --> 33:34.110] To them, it looks like they've got real credit card data, but it's stuff that you've generated that's fake credit card data. [33:34.270 --> 33:41.010] So it gets farther up the chain in the malware market before it's finally discovered to be bad. [33:41.130 --> 33:45.410] It seems like that would push the countermeasure higher up in the strategic levels. [33:45.670 --> 33:46.450] Would that work? [33:46.450 --> 33:47.070] Yeah. [33:47.350 --> 33:48.970] Actually, it would somewhat work. [33:50.190 --> 33:57.630] Surprisingly, a lot of the low-tech bot masters can... they memorize the buildup and the makeup of what a credit card is. [33:57.830 --> 34:04.690] A lot of them can immediately look at a credit card number, tell if it's Visa, MasterCard, American Express, and generally where it comes from. [34:04.930 --> 34:09.770] But we did look into algorithms generated that does it. [34:09.890 --> 34:15.530] But there's a lot of the bot masters and carters actually have forums to do checks. [34:15.530 --> 34:26.870] So immediately when they get a list of credit card numbers, they run it through these checkers, which are third-party applications or other programs to see if it is a valid number or not. [34:27.070 --> 34:33.090] So they mitigate that pretty quickly on their end through checkers. [34:33.310 --> 34:42.570] A lot of times they use not-for-profit foundations to run a dollar donation to check the credit cards. [34:42.570 --> 34:45.330] And if the dollar donation goes through, they know the credit card is valid. [34:47.070 --> 34:53.930] I'm still a little bit disturbed that you think that obfuscation works in the real world at any practical level. [34:55.590 --> 34:58.090] Because, I mean, aren't these people agile? [34:58.330 --> 35:01.290] Aren't they motivated to actually crack this stuff? [35:01.290 --> 35:08.370] And if they see bad data coming down from a big site or some financial target, they'll just start doing the analysis. [35:08.390 --> 35:14.570] They'll start fielding to get data and supplying along with the post data. [35:14.630 --> 35:17.110] Yeah, those are the dedicated individuals that actually build the plug-ins and stuff. [35:17.250 --> 35:18.730] We're looking at it from a general population. [35:18.730 --> 35:21.310] But how agile are they, in fact, based on history? [35:23.770 --> 35:25.070] In evolving their product? [35:25.070 --> 35:26.770] What we've seen for, like, plug-ins and stuff? [35:26.790 --> 35:26.950] Yeah. [35:28.530 --> 35:29.250] I've seen... [35:30.990 --> 35:32.010] I don't know if I can talk about this. [35:32.030 --> 35:33.810] I mean, they really do move pretty quickly. [35:34.230 --> 35:34.610] Yeah. [35:34.910 --> 35:37.150] But, I mean, we're trying to play with percentages here. [35:37.310 --> 35:41.130] We're not trying to get, you know, the guy who's writing the code. [35:41.270 --> 35:43.170] We're trying to get the other guys who bought this off a forum. [35:43.410 --> 35:44.110] And, you know, they're just... [35:44.110 --> 35:44.150] Right. [35:44.710 --> 35:47.390] I'm all in favor of dirty tricks, if they work. [35:47.850 --> 35:55.390] I mean, if you can spoil one of these guys Saturday night, every Saturday night, for a year, maybe he'll go somewhere else. [35:56.330 --> 35:56.710] But... [35:58.250 --> 36:02.650] So, on the subject of dirty tricks, how well-coded is Zeus and the backend? [36:02.650 --> 36:10.530] Could you take it another step and inject something naughty into post-verial and screw up the backend, screw up the data miner, you know, own Zeus? [36:11.190 --> 36:16.030] We've actually looked into cross-site scripting of Zeus. [36:18.890 --> 36:19.690] Speak up. [36:20.070 --> 36:20.270] Yeah. [36:22.530 --> 36:24.550] Yeah, people do that. [36:24.750 --> 36:25.490] A lot. [36:25.930 --> 36:30.530] Actually, they're not all buddies. [36:30.530 --> 36:34.990] And they attack each other along with us. [36:35.290 --> 36:41.010] Yeah, so you'll get guys who are jacking bots from other nets and doing all kinds of nasty stuff to each other. [36:41.250 --> 36:57.270] Yeah, I've actually run into some really well-written code that would automatically search and take over Zeus' botnets and install their own on all their clients. [36:59.590 --> 37:02.770] Yeah, I've seen some pretty impressive PHP scripts. [37:02.970 --> 37:08.750] We will actually have some examples in this down at the Hack Miami booth. [37:09.450 --> 37:14.350] So, if any of you want to have long detailed hour discussions, we can definitely do that. [37:14.870 --> 37:15.970] Is there any other questions at all? [37:17.090 --> 37:18.610] Did I answer that enough for you? [37:18.610 --> 37:18.630] Yeah. [37:20.590 --> 37:20.890] Okay. [37:21.130 --> 37:21.590] More questions? [37:21.910 --> 37:22.230] All right. [37:22.350 --> 37:23.090] Another couple things. [37:23.590 --> 37:25.570] Tomorrow, we're going to be on Radio Styler at 9.30. [37:25.790 --> 37:30.250] If you want to go ask us more questions on IRC or call us up, whatever, we're going to be on Radio Styler. [37:30.850 --> 37:32.910] And we have a server in the Knock Knock. [37:33.690 --> 37:36.850] If you come up, I'll give you the IP address so you can go and mess around with the demo yourself. [37:36.850 --> 37:38.850] And that's it. [37:39.230 --> 37:39.650] That's it.