[00:00.000 --> 00:05.450] Michael Shearer doing his talk... Will that help? [00:06.310 --> 00:10.230] Michael Shearer, the Pres 98, doing Shodan for penetration testers. [00:13.790 --> 00:14.890] Good afternoon, everyone. [00:15.070 --> 00:16.670] My name is Michael Shearer, the Pres 98. [00:16.950 --> 00:21.230] How many people talk about a search engine called Shodan? [00:21.310 --> 00:23.770] How many people have heard of or used Shodan? [00:24.270 --> 00:25.310] Okay, a fair number. [00:25.430 --> 00:25.530] Good. [00:26.770 --> 00:33.770] I want to talk today about Shodan for penetration testers and using Shodan in ways that it was not necessarily intended. [00:35.910 --> 00:45.430] So I'm going to talk a little bit about... A lot of you may have not even heard of Shodan, so we'll talk a little bit about what it is, some basic operations. [00:45.850 --> 00:51.670] I'm going to talk a little bit about its applications for penetration testing, which were not intended by the designer. [00:52.690 --> 00:59.950] I've put together a number of case studies on Shodan and using it to find and break things. [01:01.010 --> 01:02.950] And then we'll just talk about some conclusions. [01:05.530 --> 01:12.350] So I kind of put this slide... Anytime I use the word penetration testing in my title, I put this slide in there because I want to be clear. [01:14.650 --> 01:18.310] I know what penetration testing is and isn't, and I know what all these things mean. [01:18.490 --> 01:27.930] And I could make a very long title including all these things, but I want you to know that if you do or are involved in any of these things, that the title really does apply to you. [01:28.050 --> 01:32.550] So I say penetration testing, well, I don't do penetration testing, but I do vulnerability assessment. [01:32.690 --> 01:33.470] Well, okay, that's fine. [01:34.910 --> 01:38.910] In the definition for this presentation, it's all the same thing. [01:39.010 --> 01:43.470] And I recognize that that's not necessarily true, but just go with me on that one. [01:43.950 --> 01:48.670] So if you're involved in any of these things, you may find Shodan useful for you. [01:50.170 --> 01:51.250] So what is Shodan? [01:51.350 --> 01:52.570] Shodan is a search engine. [01:52.570 --> 01:53.930] You think, wow, well, that's great. [01:54.050 --> 01:56.950] There's a whole bunch of search engines out there, Google and Bing and Yahoo and whatever. [01:59.510 --> 02:03.670] It was developed by a web developer named John Matherly who's out in San Diego. [02:04.210 --> 02:12.830] And the difference here is Shodan is not a search engine in the same way that Google or Bing searches content and then indexes it for you. [02:14.210 --> 02:21.030] Shodan, actually, typical search engines will crawl for data on a web page or data on some sort of server. [02:21.050 --> 02:24.550] And that's the content is what you're concerned about. [02:25.170 --> 02:29.790] Shodan is actually interrogates ports and grabs the banners. [02:30.170 --> 02:32.310] So you're indexing web banners. [02:32.490 --> 02:34.010] You're indexing FTP banners. [02:34.270 --> 02:37.770] You're indexing telnet banners, et cetera. [02:38.050 --> 02:40.470] So instead of looking for content, we're looking for the banners. [02:40.710 --> 02:45.210] So instead of having a search engine of content, we have a search engine of banners. [02:46.750 --> 02:48.150] So why is that different? [02:48.370 --> 02:56.190] Well, instead of finding specific content on a web page, what we're looking for is specific content in a banner. [02:56.490 --> 03:06.510] Some of you know that banners often advertise very good information about what services are running, exact versions of services that are running. [03:06.750 --> 03:14.410] As we'll see later, sometimes banners advertise default usernames and passwords which, if people don't change, are very easy to get into. [03:15.130 --> 03:17.490] So Shodan is useful for finding specific nodes. [03:19.110 --> 03:22.050] Servers, desktops, switches, printers, all sorts of things. [03:22.870 --> 03:27.590] And optimizing your search results does require a little bit of knowledge of what banners look like. [03:30.030 --> 03:33.510] So basic operations, this is what Shodan looks like. [03:33.930 --> 03:42.750] I know you can't see it, but the URL URL is www.shodanhq.com, which I'll reference later. [03:42.870 --> 03:43.770] But this is what it looks like. [03:43.870 --> 03:46.050] It's just, you know, it's got a search box up here on the top. [03:46.950 --> 03:51.870] And then there's some searches that are already some popular and safe searches on there. [03:52.350 --> 03:54.270] And I'm going to go through different parts of this web page. [03:54.430 --> 03:59.370] But there are also two Firefox add-ons for Shodan. [03:59.930 --> 04:06.450] One is a search provider which just adds a search in the top box on the top right hand corner. [04:06.630 --> 04:08.550] So you just drop down and select Shodan. [04:08.930 --> 04:12.710] And then there's a sidebar called Shodan Helper. [04:13.410 --> 04:16.130] I'm not going to talk about these other than just to mention them to you. [04:16.770 --> 04:20.410] Some people may find these useful in terms of using Shodan. [04:20.510 --> 04:21.770] I just go to the web page itself. [04:25.400 --> 04:26.620] Okay, basic operations. [04:27.080 --> 04:30.260] In some sense Shodan is just like any other search engine. [04:30.440 --> 04:32.420] You just, you put search terms into a box. [04:32.540 --> 04:34.920] But obviously, we're not searching for content on the page. [04:35.040 --> 04:36.720] We're searching for content in the web banner. [04:38.200 --> 04:41.020] You can use quotations to narrow a search just like you would. [04:41.220 --> 04:47.040] And you can use the Boolean operators plus and minus to include and exclude terms. [04:47.380 --> 04:50.300] Although plus is kind of implied so you don't really need to do it. [04:50.360 --> 04:55.020] So if you use three different terms in your search that you're implying that they're all involved. [04:55.560 --> 04:59.060] The minus is actually useful because you may want to exclude certain things. [04:59.140 --> 05:00.140] And we'll see that later on. [05:00.980 --> 05:01.380] Okay. [05:03.180 --> 05:05.080] You can use Shodan without an account. [05:05.560 --> 05:07.420] Some people don't like to create accounts. [05:07.640 --> 05:08.220] That's fine. [05:08.440 --> 05:10.460] There are some limitations to using Shodan. [05:11.420 --> 05:20.180] But if you have one of these accounts, a Google account, Twitter, Yahoo, AOL, Facebook, OpenID, you can use any of these to log into Shodan. [05:20.340 --> 05:23.320] And we'll talk about how it gives you some additional capabilities. [05:23.780 --> 05:26.160] You can also create a Shodan account as well. [05:26.880 --> 05:27.900] It's not required. [05:28.180 --> 05:34.620] But there's a number of filters such as country and net that they will not work for you if you don't log in. [05:35.620 --> 05:40.760] Also, you will not see... you'll be limited in the number of search results that you can see. [05:41.460 --> 05:47.580] There's also an export feature that allows you to export the results that you're seeing and you have to be logged in for that as well. [05:50.820 --> 05:52.580] And this is how you can log in. [05:52.640 --> 05:54.820] You can see the number of different options there to log in. [05:54.920 --> 05:56.340] Or you can just create a Shodan account. [05:59.650 --> 06:02.130] There are a number of basic filters that you can use. [06:02.930 --> 06:09.610] And the filter is actually the word that I'm showing you in bold with the colon and then whatever the filter is. [06:09.710 --> 06:20.330] So if you want to search for something and you only wanted results from a certain country, you would just use your search term and then country colon and then the two-letter country code. [06:21.550 --> 06:25.850] If you wanted specific text in a host name or domain. [06:26.090 --> 06:33.950] So I want to search for this banner but I only want it to be in the dot gov domain or the dot edu domain or dot whatever, you know. [06:35.630 --> 06:40.770] The net filter allows you to specific... filter by a specific IP range or subnet. [06:40.950 --> 06:45.210] So this could be useful if you're looking for a specific... if you're going after a specific target. [06:45.950 --> 06:48.370] The OS filter for specific operating systems. [06:48.930 --> 06:51.350] And port for specific services. [06:51.510 --> 06:53.850] Right now Shodan is primarily port 80. [06:54.050 --> 06:57.070] But there is some port 21, 22, and 23. [06:57.530 --> 06:59.850] And eventually there should be some other ports being added. [07:00.050 --> 07:03.910] But those are the... large majority of what you're looking at is going to be port 80. [07:04.110 --> 07:05.450] So mostly web banners. [07:10.350 --> 07:12.350] There's just a couple different ways to do this. [07:12.490 --> 07:16.310] You can do everything through the... through the search box. [07:17.150 --> 07:25.590] There's also a drop-down map that you can just... if you don't know the two-letter country code for a specific country or whatever, you just click on the country. [07:26.750 --> 07:32.710] And the... the color of the country kind of has to do with how many hosts in that country have been scanned. [07:32.990 --> 07:40.530] So you can see obviously the United States, China, Germany, Japan have more hosts that have been scanned than some other countries. [07:43.610 --> 07:45.370] You can also filter by port there. [07:45.550 --> 07:47.070] You see down at the bottom there. [07:47.350 --> 07:50.870] Again, you can use the check boxes or you can just use the... the search box. [07:55.410 --> 07:59.010] And if you mouse over a country, it'll turn yellow and it'll tell you how many hosts there. [07:59.130 --> 08:01.930] So the United States, you know, a lot. [08:05.010 --> 08:07.570] I talked to John who developed Shodan. [08:08.410 --> 08:11.830] He's done large portions of the Internet, but I don't know what percentage-wise. [08:12.610 --> 08:16.970] Not the entire Internet, but large portions of the Internet and he's always adding more search results. [08:17.250 --> 08:17.350] So... [08:20.390 --> 08:25.810] So I want to talk a little bit about some basic searches and... and using some of these filters. [08:26.550 --> 08:29.750] So... and I know you can't read this and I'll... but I'll... so I'll read them off to you. [08:29.890 --> 08:33.790] The search term that I used was Apache and then country colon CH. [08:34.230 --> 08:36.590] CH is a... is a two-letter country code for Switzerland. [08:36.990 --> 08:47.710] So what's that... what that's going to find me is... any banner that has the word Apache in and then where the IP range is registered to a Switzerland IP address. [08:47.970 --> 08:56.570] So that will... more or less is going to find me all the... at least what's been scanned, all the Apache servers in Switzerland. [08:57.570 --> 08:58.210] Thank you. [08:59.270 --> 09:01.910] Or all the banners that have the word Apache in them. [09:02.070 --> 09:05.810] And most banners... unless people change banners, which some people do, but most people don't. [09:06.490 --> 09:08.130] So you can see the results here. [09:08.270 --> 09:09.830] I know they're a little bit difficult to see. [09:10.430 --> 09:14.430] But the word... the search terms that the user actually will be bolded here. [09:15.410 --> 09:17.130] So this is the banner itself. [09:17.710 --> 09:21.690] And then this will actually... the IP address over here will actually link you. [09:21.830 --> 09:23.770] You can just click on it and go directly to the result. [09:24.730 --> 09:29.210] And then as well there's... if the operating system is identified, you'll see that as well over here. [09:29.530 --> 09:32.370] And then sometimes there's a nice little flag. [09:32.910 --> 09:34.870] So you can... you know... pretty cool. [09:36.710 --> 09:40.430] This next term is Apache 2.2.3. [09:40.770 --> 09:44.290] So I didn't use the country code, but I searched for a specific version of Apache. [09:44.530 --> 09:49.570] And you can see here that there are... I don't know... a million results? [09:50.130 --> 09:53.730] 1.3 million results that have the word Apache 2.2.3. [09:53.890 --> 10:01.970] So you can kind of see now, if you're looking for a certain version of software, or that you know there's a vulnerability in a certain version of software, you might be able to find something. [10:02.350 --> 10:08.130] If you don't use the country code, the top four countries that match your query will be linked to you. [10:08.310 --> 10:11.110] So you can see here, United States, Germany, France, Canada, etc. [10:15.450 --> 10:16.690] The hostname filter. [10:17.750 --> 10:22.990] So first example here, Apache hostname colon .nist.gov. [10:23.150 --> 10:26.850] So I want to find all the Apache servers in the .nist.gov domain. [10:27.030 --> 10:27.430] Okay? [10:27.690 --> 10:28.370] We can do it. [10:30.390 --> 10:35.950] IAS-5.0 hostname colon .edu. [10:36.210 --> 10:43.530] So I want to find all the IAS-5.0 servers, Windows 2000 servers running in any EDU domain. [10:43.790 --> 10:44.550] Can I find them? [10:44.630 --> 10:45.110] Absolutely. [10:49.320 --> 10:56.400] Netfilter I talked about allows you to refine searches by IP and CIDR notation, and then OS filter by operating system. [10:57.160 --> 10:58.160] And then ports. [10:58.360 --> 11:00.500] 21, 22, 23, and 80. [11:01.300 --> 11:02.320] Overwhelmingly is 80. [11:06.190 --> 11:07.450] There's a number of searches. [11:07.770 --> 11:08.730] So you log in. [11:08.810 --> 11:09.410] You create an account. [11:09.630 --> 11:11.050] You find some interesting searches. [11:11.430 --> 11:15.570] You can actually save them so that other people can view them. [11:15.750 --> 11:19.290] So there'll be save searches, popular searches, others share them with other users. [11:19.850 --> 11:26.210] It's kind of a very basic Google hacking, except showdown hacking really in terms of saving searches. [11:31.510 --> 11:32.890] There's an export feature. [11:33.050 --> 11:35.750] Allows you to export up to 1,000 results per credits. [11:37.030 --> 11:38.310] You can purchase credits. [11:39.890 --> 11:45.810] And then there's a sample file to show you what the data export file looks like. [11:46.090 --> 11:47.030] I asked John about that. [11:47.290 --> 11:52.630] By the way, I have no connection other than I found this search engine and I talked about it. [11:52.690 --> 11:54.050] So I don't get money or anything. [11:54.530 --> 11:59.730] So I talked to him about what kind of feedback he's gotten because he just recently added the feature to purchase credits. [12:00.050 --> 12:02.870] He said the feedback he's gotten has been positive. [12:03.150 --> 12:07.570] He had one person that complained to him about having to pay to export the results. [12:08.230 --> 12:08.790] I don't know. [12:08.950 --> 12:10.510] I don't have a position on it. [12:10.890 --> 12:13.070] I know everybody, a lot of people think information should be free. [12:13.510 --> 12:14.390] Somebody else did the work. [12:14.530 --> 12:17.270] He's asking you to pay if you want to do the export feature. [12:17.370 --> 12:18.250] That's up to you to decide. [12:18.430 --> 12:21.890] But I don't... I just wanted to make clear that I don't get anything out of that. [12:25.800 --> 12:30.200] So when I first talked to John about this, he said, what was your intent of showdown? [12:30.480 --> 12:32.520] And John's a software developer, a web developer. [12:32.640 --> 12:32.960] He doesn't... [12:32.960 --> 12:34.000] he's not a penetration tester. [12:34.140 --> 12:36.100] He's not involved in InfoSec initially. [12:36.460 --> 12:40.900] So he was thinking of different marketing things and all sorts of business reasons for showdown. [12:41.140 --> 12:45.700] And didn't really think... didn't really go down the idea of penetration testing. [12:46.060 --> 12:54.460] Although as you can imagine, when showdown first came out, those of us who were in penetration testing and InfoSec kind of looked at this and said, wow, there's a lot of cool things we can do with this. [12:55.420 --> 12:57.860] So that's kind of the angle that I went down. [12:58.720 --> 13:02.520] So I want to talk a little bit about ethics before I move on. [13:03.400 --> 13:09.920] Because as you can imagine, some of the things that we're going to get into, you know, they could be questionable whether or not you should actually be doing these things. [13:10.380 --> 13:12.120] And these are kind of rhetorical questions. [13:12.300 --> 13:13.400] I don't expect you to answer them. [13:13.480 --> 13:16.020] And I'm going to kind of give you what my... what I think my answers are. [13:16.520 --> 13:17.500] Yours might be different. [13:17.960 --> 13:25.940] So is it acceptable under any circumstances to view the configuration of a device that requires no authentication to view? [13:26.100 --> 13:31.460] So if I go to one of these web pages and it doesn't ask me for a username and password, there's no popup box, no nothing. [13:31.520 --> 13:32.900] It just sends me right in. [13:33.000 --> 13:33.420] No authentication. [13:33.740 --> 13:34.720] Can I view that? [13:35.720 --> 13:43.480] What about viewing the configuration of a device where maybe it gives me a username and popup and I put the default username and password in and it sends me right in? [13:43.620 --> 13:44.720] What about viewing that? [13:45.100 --> 13:49.180] What about viewing the configuration of a device using a unique username and password? [13:49.360 --> 13:53.180] Somehow I've captured the credentials and what about changing the configuration. [13:53.740 --> 13:56.480] So let's back up. [13:57.240 --> 14:03.120] If you're authorized to do a penetration test against these things, obviously these are things that you're going to be authorized to do. [14:03.300 --> 14:12.240] I'm talking about from the perspective of you go to Shodan, you go home from HOPE and you go to www.shodanhq.com and you just start looking at stuff. [14:12.380 --> 14:13.020] Because that's what I did. [14:13.120 --> 14:15.280] I wasn't authorized to do any of the stuff that I'm going to show you. [14:15.800 --> 14:16.960] So what can you do? [14:17.960 --> 14:20.760] And this is...so this is the white to black spectrum. [14:20.880 --> 14:22.460] And this is kind of where I put these things. [14:22.680 --> 14:24.060] Some people might disagree. [14:24.260 --> 14:24.720] That's fine. [14:25.820 --> 14:27.360] This is what I'm...kind of my idea. [14:27.740 --> 14:29.880] So viewing something with no authentication at all. [14:30.020 --> 14:32.200] In other words, it's just...you don't even have to log in. [14:32.360 --> 14:33.640] I can see that fairly white. [14:33.760 --> 14:36.300] I mean, I'm not changing anything. [14:36.480 --> 14:37.520] I'm just viewing the configuration. [14:37.820 --> 14:39.140] You know, I went to the web page. [14:39.240 --> 14:41.540] We will talk about a good example of this that I ran into. [14:43.160 --> 14:45.140] What about using a default username and password? [14:45.300 --> 14:46.660] Well, now you're actually logging in. [14:47.300 --> 14:52.480] Despite the fact that they're using a default username and password, there is some sort of authentication there that you're bypassing. [14:52.680 --> 14:54.660] Or that you're, you know, using. [14:54.840 --> 14:57.280] So I think that that's probably, you know, questionable. [14:58.020 --> 15:00.840] What about figuring out some unique username and password? [15:01.060 --> 15:03.380] I mean, it's...I think it's fairly cut and dry. [15:03.700 --> 15:11.440] And then certainly changing the configuration of someone's device without having any...I mean, I'm not sure you can get any further on the, you know...you know. [15:12.820 --> 15:14.760] Anybody have any major disagreements with this? [15:14.860 --> 15:17.120] I mean, do you think this is reasonable, I think? [15:18.320 --> 15:20.640] I can understand if you want to shift it a little bit here and there. [15:20.760 --> 15:22.400] I mean, that's the whole idea. [15:23.040 --> 15:25.480] Okay, so pen-testing applications of Shodan. [15:26.080 --> 15:32.880] Using Shodan for penetration testing requires you have some basic knowledge of HTTP banners and what they look like and status codes. [15:33.440 --> 15:35.200] Banners advertise service version. [15:35.360 --> 15:37.560] They advertise services and versions. [15:39.440 --> 15:41.040] People...sometimes people spoof banners. [15:41.260 --> 15:44.820] How many of you have actually spoofed a banner on devices that you own? [15:45.820 --> 15:46.860] So, some people. [15:47.040 --> 15:47.580] Not a lot. [15:48.060 --> 15:49.220] So, yes, it can be done. [15:49.340 --> 15:50.080] And some people do it. [15:50.160 --> 15:52.160] But I don't really encounter it all that much. [15:52.320 --> 15:53.240] But it does happen. [15:54.260 --> 15:58.360] So, we are...by using these banners, we're kind of assuming that people aren't spoofing banners. [15:58.540 --> 15:59.080] And they might be. [16:01.800 --> 16:03.500] So, you all know these codes anyway. [16:03.660 --> 16:06.160] But I think it's useful to just review them very quickly. [16:06.860 --> 16:09.920] Because we can make some assumptions when we see these codes in a banner. [16:10.480 --> 16:12.160] So, a 200 okay request succeeded. [16:12.320 --> 16:14.800] In other words, we can view this page without any sort of authentication. [16:16.280 --> 16:25.120] Our 301 and 302 codes will typically...in the case of Shodan, when we see a 301 or a 302, there's not going to be anything at that web page. [16:25.340 --> 16:31.060] It's either moved or...it's not in an area where we can see something. [16:32.620 --> 16:36.260] 401 is a request requires authentication. [16:36.780 --> 16:42.080] When we see a 401, we'll typically be confronted with a pop-up box asking us for a username and password. [16:42.860 --> 16:44.220] A 403 is a forbidden. [16:45.160 --> 16:46.580] It's not going to let us view the page. [16:46.760 --> 16:50.560] There may be some sort of filter or something that's preventing us from getting there. [16:50.740 --> 16:56.180] So, the ones that we are really concerned about are 200, which will allow us to go see the page right away. [16:56.480 --> 17:00.120] And then 401, which is a pop-up box, but we may be able to bypass it. [17:01.900 --> 17:07.020] So, a 200 okay banner, the page is going to load without any authentication. [17:07.460 --> 17:11.580] Now, there may be some sort of authentication built into that page where we have to go further. [17:11.580 --> 17:13.280] Well, we can at least view that page. [17:16.060 --> 17:19.440] 301, 302's typically don't have any data, so we can try to filter those out. [17:19.720 --> 17:21.700] We talked about using the minus to filter things. [17:21.840 --> 17:25.120] These are...this is where it's very good to...minus 301, minus 302. [17:25.180 --> 17:26.260] We can get those codes out. [17:28.360 --> 17:33.860] A 401 unauthorized banner usually has a line called www authenticate. [17:34.020 --> 17:36.600] And when we see those, we typically have a pop-up box. [17:37.980 --> 17:40.060] And then some banners will actually advertise the default. [17:40.140 --> 17:42.420] So, say the default username and password is XYZ. [17:43.140 --> 17:45.160] So, if people don't change them, they're kind of handing them out. [17:46.620 --> 17:50.060] So, I did a number of search...a number of case studies on Shodan. [17:50.420 --> 17:51.400] Let's see what we're doing on time. [17:51.640 --> 17:51.820] 20. [17:51.980 --> 17:52.120] Okay. [17:52.900 --> 17:55.860] The first one is...I just want to look up Cisco devices. [17:56.160 --> 17:57.700] Let's see what kind of Cisco devices are out there. [17:57.700 --> 18:00.160] And this is the first banner that I came across. [18:00.820 --> 18:03.160] So, I just...I just used the search term Cisco. [18:03.660 --> 18:08.980] So, I get an HTTP 401 unauthorized, which is the first box in red. [18:09.120 --> 18:10.020] And now it's difficult to see. [18:10.200 --> 18:15.360] And then the third line down is a www authenticate, basic realm, level 15, or view access. [18:15.780 --> 18:19.040] I can tell you immediately that this is going to be a pop-up box. [18:19.120 --> 18:21.640] It's asking me for a username and password, which I don't have. [18:24.700 --> 18:25.100] Okay. [18:25.100 --> 18:27.240] Now, here is a different Cisco device. [18:27.500 --> 18:30.960] This is a...instead of a 401, we have a 200 okay. [18:31.660 --> 18:36.900] We also have no www authenticate and we have a last modified line, which gives us a date and time. [18:37.600 --> 18:40.640] Which the date doesn't necessarily matter, but...so, what does this mean? [18:40.820 --> 18:42.220] Well, let's go a little bit further. [18:42.500 --> 18:44.300] Here's the two banners, again, side by side. [18:46.500 --> 18:53.860] When we see these...when we see the 401 and the 200 and what they contain, they're actually about 99% mutually exclusive. [18:53.860 --> 19:00.600] In other words, search a term for Cisco, 250,000, etc. [19:01.540 --> 19:07.660] What happens is, when we get a 200 okay with a Cisco result, chances are there's no authentication required. [19:08.000 --> 19:08.220] None. [19:08.560 --> 19:09.040] Nothing. [19:10.940 --> 19:18.500] And what this means is there's probably, in Shodan right now, at least 4200 Cisco devices that require no authentication at all. [19:18.700 --> 19:18.940] None. [19:18.940 --> 19:18.960] None. [19:20.020 --> 19:21.940] Like, not default username and password. [19:22.160 --> 19:23.600] Like, we log right in. [19:25.360 --> 19:25.800] Okay. [19:26.040 --> 19:29.360] So, I wanted to find a few of these examples, so I went to them. [19:30.640 --> 19:34.460] The first one, Cisco Systems, 1812, switch. [19:35.000 --> 19:35.860] There's the name of the switch. [19:36.800 --> 19:42.860] Those of you who have administered Cisco devices, you know, this is kind of the older HTML interface to the Cisco device. [19:42.860 --> 19:46.660] And then you click on the number for the level of access that you want. [19:46.800 --> 19:51.540] So, if you want, you know, 15, which is like, you know, you would just click on it. [19:51.700 --> 19:53.640] And so, obviously, you get to this point. [19:53.760 --> 19:55.700] You would figure, click on 15. [19:55.940 --> 19:57.300] Now I'm gonna get my username and password. [19:57.840 --> 19:59.660] And then it's gonna ask me to authenticate. [20:00.700 --> 20:01.500] Or it doesn't. [20:02.880 --> 20:04.140] And it just logs you right in. [20:05.060 --> 20:09.800] Now this is the old interface, so you can either just type the commands in the command box up there. [20:10.140 --> 20:14.820] Or, you know, they have the HTML links for you to just do whatever you want. [20:14.940 --> 20:16.220] So, run whatever commands you want. [20:16.960 --> 20:19.700] So, I, you know, this is the configure commands. [20:19.920 --> 20:21.140] So, can you run configure commands? [20:21.260 --> 20:21.420] Yeah. [20:21.520 --> 20:23.000] You can also run execute commands. [20:24.380 --> 20:26.360] So, I ran, you know, okay. [20:26.700 --> 20:27.600] So, let's go back. [20:28.020 --> 20:29.360] What was the first thing I talked about? [20:29.500 --> 20:33.220] Viewing the configuration of a device that you don't have, that requires no authentication at all. [20:34.240 --> 20:35.960] Now, I'm just doing show commands. [20:36.100 --> 20:37.420] So, I'm not changing anything. [20:37.600 --> 20:38.700] I'm just seeing what I can do. [20:39.240 --> 20:40.560] So, I did a show running config. [20:40.820 --> 20:42.360] And it gave me everything. [20:43.220 --> 20:44.680] I did a show CDP neighbors. [20:45.000 --> 20:49.020] And, you know, I'm not a CCNA guy or Cisco guy. [20:49.100 --> 20:50.360] But I know some basic stuff. [20:50.480 --> 20:52.060] So, I just wanted to just kind of see what's available. [20:52.060 --> 20:54.740] So, this is an example of a Cisco device. [20:55.060 --> 21:00.920] A switch that's available on the Internet that requires no authentication at all to log into. [21:01.400 --> 21:06.380] Now, are all these devices juicy targets? [21:06.760 --> 21:07.200] No. [21:07.420 --> 21:11.980] Maybe some guy is doing a CCNA class and he set up a Cisco switch to play with. [21:12.140 --> 21:13.000] And I'm sure some of them are. [21:13.200 --> 21:15.760] But there are some legitimate targets out there. [21:16.220 --> 21:17.540] Does anybody know what... [21:17.540 --> 21:18.920] I know you can't see this. [21:18.920 --> 21:25.100] On the CDP neighbors, if you look at the first line, it's CN-CN... [21:25.100 --> 21:26.720] Does anybody know what that means? [21:26.940 --> 21:27.460] China Netcom. [21:27.460 --> 21:29.100] China Netcom. [21:29.300 --> 21:29.380] Yeah. [21:29.580 --> 21:30.860] It's an ISP in China. [21:31.220 --> 21:33.920] So, CDP neighbor of this device is a... [21:34.520 --> 21:36.380] And I've actually looked into this a little bit further. [21:36.520 --> 21:37.780] It's an infrastructure device. [21:37.780 --> 21:39.020] So, I mean, yeah. [21:39.160 --> 21:40.540] There are juicy targets out there. [21:45.290 --> 21:47.430] So, I want to find a few more devices. [21:47.850 --> 21:52.030] This is a Cisco AirNet wireless access point. [21:52.490 --> 21:55.190] Now, most home users don't use Cisco. [21:55.470 --> 21:57.390] They might use Linksys or other Netgear. [21:57.470 --> 21:59.070] But they typically don't use Cisco devices. [21:59.390 --> 22:00.310] But some do. [22:01.170 --> 22:02.370] So, this is the home page. [22:03.050 --> 22:03.990] And what about... [22:03.990 --> 22:04.330] Can we view... [22:04.950 --> 22:06.030] So, this is just the home page. [22:06.130 --> 22:12.630] Surely, if we wanted to view, you know, more configuration pages, we would have to authenticate. [22:12.710 --> 22:13.530] No, we don't have to. [22:13.670 --> 22:16.790] So, you can just, you know, go through no security. [22:17.010 --> 22:18.370] I mean, do you want to add a password? [22:18.550 --> 22:19.370] I mean, if you want to. [22:19.790 --> 22:23.990] What about turning on services? [22:24.470 --> 22:25.110] Sure, why not? [22:25.270 --> 22:27.730] I mean, again, I'm just showing you the screenshots here. [22:27.790 --> 22:29.890] I didn't actually change any kind of configuration on the device. [22:30.390 --> 22:31.470] Which would not be good. [22:33.070 --> 22:35.870] What about a Catalyst 2960 switch? [22:36.190 --> 22:38.070] This one, I don't know if this is the same one. [22:38.190 --> 22:40.910] I found a switch for a... [22:40.910 --> 22:42.490] It was a realty company in New York. [22:44.190 --> 22:46.510] And what they did was the switch meant... [22:46.510 --> 22:54.370] And they were very good about labeling all their ports to what businesses on what floors had access. [22:54.570 --> 23:00.050] So, I mean, it was like, Floor 21, XYZ Corporation, you know, off. [23:00.370 --> 23:01.990] You know, do you want to turn their Internet off? [23:02.170 --> 23:02.870] I mean... [23:04.270 --> 23:06.330] And, yeah, I don't know if this is the same one. [23:07.850 --> 23:09.210] No, this isn't the exact same one. [23:09.290 --> 23:14.530] But you can see that some people are very good about turning on very descriptive about their port descriptions. [23:15.150 --> 23:17.710] You know, maybe half duplex, slow them down a little bit. [23:17.970 --> 23:19.030] Or, you know... [23:19.030 --> 23:20.090] But these things are just out there. [23:20.230 --> 23:23.950] These are legitimate Internet services that people are not... [23:23.950 --> 23:25.470] That are running with no authentication at all. [23:26.950 --> 23:28.070] It's an ISP and R. [23:31.310 --> 23:32.110] Yeah, it's... [23:32.110 --> 23:33.830] Okay, so here's the next thing. [23:33.930 --> 23:36.990] If you notice, I didn't blur out any of the IP addresses or anything. [23:37.410 --> 23:38.350] They're all out there. [23:38.450 --> 23:39.170] I mean, I'm not... [23:39.170 --> 23:42.630] I don't feel like showing you the screenshot of a device that didn't require any authentication. [23:43.270 --> 23:43.790] Whatever. [23:44.110 --> 23:44.770] I mean, if that's... [23:45.270 --> 23:48.470] I'll get into a little bit about disclosure later, but... [23:52.440 --> 23:54.780] Cisco, Security Device Manager Express. [23:55.080 --> 23:56.720] Just more devices that... [23:56.720 --> 23:57.800] No authentication at all. [24:00.540 --> 24:02.540] Just do whatever you want. [24:03.920 --> 24:05.400] Okay, so that's the Cisco one. [24:05.560 --> 24:06.760] I kind of used that as first. [24:06.880 --> 24:07.440] That's kind of cool. [24:07.740 --> 24:08.840] No authentication at all. [24:09.020 --> 24:10.020] Okay, default passwords. [24:11.080 --> 24:13.140] So, this is the easiest search that I did. [24:13.300 --> 24:15.040] It was like, instead of just searching for... [24:15.040 --> 24:16.980] I just searched for the words default password. [24:17.160 --> 24:21.520] Because sometimes banners will say the default password is whatever. [24:22.140 --> 24:25.040] And this doesn't mean that every result will use the default password. [24:25.180 --> 24:26.160] But you know that many do. [24:26.480 --> 24:27.640] Some people don't change them. [24:27.820 --> 24:29.760] So this is kind of a lowest hanging fruit attack. [24:30.040 --> 24:32.620] This is the absolute first result that I got. [24:33.360 --> 24:34.300] It's a 401. [24:35.300 --> 24:37.240] It's got a www.authenticate banner. [24:37.380 --> 24:38.760] So we know it's a pop-up box. [24:39.060 --> 24:41.120] And the default password is 1234. [24:41.560 --> 24:42.940] And if you look, it's a web port. [24:43.020 --> 24:43.720] It's a print server. [24:44.000 --> 24:45.340] So this is actually what you... [24:45.340 --> 24:47.840] It doesn't mean that they're using it, but... [24:47.840 --> 24:48.740] And there's no username. [24:48.800 --> 24:50.140] It just says the default password. [24:50.560 --> 24:56.720] So you figure it's either admin or root or just a null username. [24:58.020 --> 24:59.400] Okay, so this is what I got. [24:59.400 --> 25:02.420] And you can see that this is the default password 1234. [25:03.160 --> 25:03.880] And I... [25:03.880 --> 25:04.200] Much... [25:04.200 --> 25:06.300] So this is one of those... [25:06.300 --> 25:07.500] Should you try it? [25:12.700 --> 25:14.040] It only took one try. [25:15.000 --> 25:16.100] I think it was no... [25:16.100 --> 25:16.680] I don't think... [25:16.680 --> 25:17.660] I think it was a null username. [25:17.960 --> 25:18.820] And it was just 1234. [25:20.060 --> 25:20.460] Now... [25:22.500 --> 25:25.040] Occasionally, you get into these foreign devices or... [25:25.680 --> 25:27.780] Outside of U.S. devices where the encoding... [25:28.340 --> 25:28.840] You just... [25:28.840 --> 25:30.240] Your system's not set up to view. [25:30.240 --> 25:32.280] You can see here that some of the... [25:33.060 --> 25:33.420] Um... [25:33.420 --> 25:34.180] Text is... [25:34.180 --> 25:34.900] Doesn't show up right. [25:36.780 --> 25:37.140] Um... [25:37.760 --> 25:38.120] But... [25:38.900 --> 25:39.260] Uh... [25:39.260 --> 25:39.780] Yeah, you can... [25:39.780 --> 25:42.620] But you can go through all these different menus and do whatever you want. [25:43.060 --> 25:47.280] One of the things I found, and I'll show you this later, is that a lot of times if you can't... [25:47.280 --> 25:47.760] If... [25:47.760 --> 25:55.280] If the links are in a foreign language or something that you don't understand, typically the underlying HTTP will still be in English or something readable. [25:55.280 --> 26:02.440] So you can often just mouse over the link and then look on your status bar on the bottom and actually see what those things mean. [26:03.080 --> 26:03.340] Uh... [26:03.340 --> 26:03.520] It... [26:03.520 --> 26:04.760] It's not so clear here. [26:04.940 --> 26:05.720] It's not so obvious here. [26:05.820 --> 26:07.140] But I'll show you an example later on. [26:08.080 --> 26:08.560] Okay. [26:08.660 --> 26:09.880] Huawei IP phones. [26:11.620 --> 26:12.100] Okay. [26:12.260 --> 26:13.300] So I just wanted to find... [26:13.300 --> 26:13.700] I just wanted to... [26:13.700 --> 26:15.640] So I said Cisco, let's go with Huawei. [26:15.780 --> 26:16.440] See what's out there. [26:16.720 --> 26:20.440] And I did a Huawei search and there's a whole bunch of results. [26:22.080 --> 26:22.440] Um... [26:22.440 --> 26:24.060] And I came up with a lot of these. [26:24.400 --> 26:24.800] And I... [26:24.800 --> 26:26.420] So this is where I start using the filters. [26:27.040 --> 26:30.240] Minus 401, minus 400, minus 301, minus 302. [26:30.360 --> 26:31.520] Because I don't want these results. [26:31.720 --> 26:33.060] I just want 200s. [26:34.020 --> 26:37.360] So I just did this search and I got a whole bunch of results. [26:37.600 --> 26:38.720] Well, 280 some results. [26:38.720 --> 26:41.820] And they're almost all in the same IP block. [26:41.960 --> 26:43.580] They're in this 150, 186. [26:44.060 --> 26:47.800] And it's Huawei ET523, whatever. [26:49.920 --> 26:50.700] And it's... [26:50.700 --> 26:52.080] This is actually what the device is. [26:52.160 --> 26:54.780] It's an Echo Life IP phone. [26:55.620 --> 26:58.560] And if you look up the IP range, these are all in Venezuela. [26:58.900 --> 26:59.620] And when you go... [26:59.620 --> 27:01.140] It's some like technology corporation. [27:01.440 --> 27:05.900] And when you go to their webpage, there's like 15 pictures of Hugo Chavez smiling. [27:05.900 --> 27:07.820] And, you know, some... [27:07.820 --> 27:09.520] Some government technology corporation. [27:15.510 --> 27:16.530] And this was... [27:16.530 --> 27:20.170] So when you actually go to the IP address, this is what you're presented with. [27:21.510 --> 27:21.950] And... [27:21.950 --> 27:24.290] So again, now we go back to... [27:24.290 --> 27:27.990] I couldn't actually find the default password for this particular phone. [27:28.210 --> 27:29.470] But I found... [27:29.470 --> 27:30.230] I don't remember... [27:30.230 --> 27:31.410] And I honestly don't remember what it was. [27:31.690 --> 27:33.710] A bunch of Huawei devices all have the same. [27:33.850 --> 27:35.170] It's just password or something like that. [27:35.170 --> 27:35.970] So I tried it. [27:36.270 --> 27:36.430] And... [27:36.430 --> 27:36.770] Yeah. [27:37.070 --> 27:37.310] I know. [27:39.810 --> 27:40.530] And I... [27:40.530 --> 27:44.030] All these tabs, you can view and change whatever you want. [27:45.090 --> 27:45.450] And... [27:45.450 --> 27:47.850] I kind of just scroll down just to see all the different... [27:47.850 --> 27:48.910] You can change the ringtones. [27:49.350 --> 27:49.630] I mean... [27:50.970 --> 27:51.330] Just... [27:55.030 --> 27:55.550] What's that? [27:57.450 --> 27:57.810] Absolutely. [27:58.050 --> 27:58.290] I mean, yeah. [27:58.470 --> 27:59.330] I mean, if you think about this... [27:59.750 --> 27:59.910] Yeah. [28:00.050 --> 28:02.110] There's a lot of things here you could just kind of play around with. [28:02.110 --> 28:03.970] But you could really mess up someone's day. [28:04.290 --> 28:05.130] I mean... [28:05.890 --> 28:06.990] If you really wanted to. [28:07.310 --> 28:07.670] Now... [28:07.670 --> 28:10.190] I don't recommend that you do this unless you have authorization. [28:11.290 --> 28:11.650] But... [28:12.670 --> 28:16.110] If you don't like the Venezuelans, then... [28:16.830 --> 28:17.410] There you go. [28:19.250 --> 28:19.970] The last... [28:21.790 --> 28:22.990] Part of the case study... [28:22.990 --> 28:25.790] The last case study I'm going to talk to you about is about infrastructure exploitation. [28:27.430 --> 28:28.150] And that... [28:28.150 --> 28:30.630] When I first did this one, I was like, well, that's kind of a lame title. [28:30.630 --> 28:32.250] So, I just renamed it to... [28:33.190 --> 28:34.730] How to Pwn an ISP. [28:38.010 --> 28:40.790] Now, I will tell you in some of these slides that I did... [28:40.790 --> 28:42.330] I did blank out some stuff. [28:42.610 --> 28:43.270] And I'll... [28:43.270 --> 28:44.570] I'll get to the reasons later. [28:47.410 --> 28:48.390] And it's actually... [28:48.390 --> 28:51.270] I should have renamed it How to Pwn an ISP in like 10 minutes or less. [28:51.510 --> 28:52.670] Without really trying. [28:52.930 --> 28:54.050] Because that's about what it is. [28:54.330 --> 28:55.950] So, I was just going through these devices. [28:55.950 --> 28:56.770] You know... [28:56.770 --> 28:57.570] These Cisco devices. [28:58.070 --> 28:59.570] And I came across this one. [29:00.330 --> 29:00.910] Cisco... [29:01.530 --> 29:02.110] WS... [29:02.110 --> 29:02.670] C... [29:02.670 --> 29:03.350] 3750. [29:03.590 --> 29:04.490] It's a Cisco switch. [29:05.750 --> 29:06.710] Same thing... [29:06.710 --> 29:09.870] Same kind of screen that we've seen before with just the HTML link. [29:10.690 --> 29:11.750] Level 15. [29:12.210 --> 29:12.690] Boom! [29:12.950 --> 29:13.450] Right in there. [29:15.350 --> 29:17.990] So, I started running just IP route. [29:18.610 --> 29:19.010] I mean... [29:19.010 --> 29:20.590] Just did the different view command... [29:21.250 --> 29:21.690] Showing... [29:21.690 --> 29:22.290] Show commands. [29:22.510 --> 29:23.470] Just to see what's out there. [29:24.150 --> 29:26.390] And you can see I did wipe out some stuff here. [29:27.030 --> 29:27.890] Running configuration. [29:31.710 --> 29:32.790] Show CDP neighbors. [29:33.150 --> 29:33.270] Oh! [29:33.410 --> 29:34.090] This was the good one. [29:34.210 --> 29:36.570] Because it showed me that there's some additional switches. [29:36.910 --> 29:37.990] And then they have a Cisco router. [29:38.550 --> 29:38.990] 7606. [29:39.150 --> 29:40.050] That's their core router. [29:40.790 --> 29:43.350] And at this point, I'm looking up the IP address. [29:43.350 --> 29:44.090] And I'm like, wow. [29:44.350 --> 29:44.670] This... [29:44.670 --> 29:45.870] This shouldn't be happening. [29:49.390 --> 29:49.950] So... [29:49.950 --> 29:51.370] Without going into all of this. [29:51.490 --> 29:52.290] This is what I saw. [29:52.510 --> 29:53.950] And literally in the course of about 10 minutes. [29:54.790 --> 29:58.550] Direct access to two Cisco 3750 infrastructure switches. [29:59.010 --> 30:01.650] And direct access to their Cisco 7606 router. [30:02.650 --> 30:05.190] VLAN IDs for their internal ISP network. [30:05.850 --> 30:08.010] Hotels in the area around the ISP. [30:08.950 --> 30:09.510] Condominiums. [30:09.810 --> 30:10.370] Apartments. [30:10.710 --> 30:11.530] Convention Center. [30:12.310 --> 30:14.710] The public backbone for their whole ISP. [30:16.830 --> 30:17.630] SNMP server. [30:17.930 --> 30:18.750] I mean... [30:20.070 --> 30:23.290] So, could I go in here and route traffic from their ISP to me. [30:23.470 --> 30:24.550] And then back to their network. [30:24.750 --> 30:25.250] And then just... [30:25.250 --> 30:25.830] Yeah. [30:25.970 --> 30:26.330] Absolutely. [30:26.550 --> 30:27.610] You can do anything you want. [30:29.810 --> 30:32.430] So, I'm going to go a little bit into very... [30:32.430 --> 30:34.550] I don't want to make this into a big disclosure debate. [30:34.550 --> 30:36.470] But I am not a... [30:36.470 --> 30:37.930] I don't find bugs in software. [30:38.090 --> 30:39.170] So, I don't deal with disclosure. [30:39.710 --> 30:41.550] But I found this and I was like, wow. [30:41.910 --> 30:42.550] This is kind of... [30:43.190 --> 30:44.490] I should do something about this. [30:45.110 --> 30:46.210] So, what do you do? [30:46.490 --> 30:47.310] So, how do you... [30:47.310 --> 30:47.850] You know... [30:47.850 --> 30:49.050] We talk about disclosure. [30:49.190 --> 30:49.970] Well, there's full disclosure. [30:50.130 --> 30:51.390] Full disclosure would mean... [30:52.930 --> 30:54.530] XYZ ISP is pwned. [30:55.030 --> 30:56.050] Do whatever you want. [30:56.210 --> 30:56.550] I mean... [30:57.230 --> 30:57.630] Right. [30:57.630 --> 30:58.130] I mean... [30:58.130 --> 30:59.090] There's no exploit. [30:59.250 --> 30:59.750] But there's... [30:59.750 --> 31:01.810] It would just be like advertising it and saying... [31:01.810 --> 31:02.290] You know... [31:02.290 --> 31:03.610] Sunlight's the best disinfectant. [31:03.670 --> 31:04.190] Fix your shit. [31:04.590 --> 31:04.810] Right? [31:06.930 --> 31:07.330] Or... [31:07.330 --> 31:08.410] Or there would be like... [31:08.410 --> 31:09.850] The opposite would be like no disclosure. [31:10.050 --> 31:10.650] So, just... [31:10.650 --> 31:11.950] Don't talk about it. [31:12.110 --> 31:13.170] But I wanted to talk about it. [31:14.550 --> 31:15.350] And then... [31:15.350 --> 31:16.450] The third path which... [31:16.450 --> 31:16.690] Or the... [31:16.690 --> 31:17.930] Kind of the medium path which is... [31:17.930 --> 31:18.350] I went down. [31:18.650 --> 31:21.770] Which was a sort of responsible sort of disclosure. [31:22.150 --> 31:23.030] So, what do you do? [31:23.230 --> 31:26.630] So, I went to the IP address and I found the security contact for the... [31:26.630 --> 31:28.330] Who owns this ISP? [31:28.650 --> 31:29.890] And so, what do I say? [31:30.050 --> 31:32.630] I was hacking your router and your... [31:33.310 --> 31:33.910] No. [31:34.730 --> 31:35.330] So... [31:35.330 --> 31:38.310] And I wrote about one sentence and this is what I said. [31:38.870 --> 31:40.250] Something like... [31:40.250 --> 31:47.830] Some of the devices on your network appear to be accessible without any authentication. [31:49.190 --> 31:50.330] Something like that. [31:51.410 --> 31:52.630] Just one sentence. [31:52.830 --> 31:56.010] I didn't want to give him anything else on what I was doing. [31:56.470 --> 31:56.910] Because... [31:56.910 --> 31:59.170] I don't want to admit to doing something that... [31:59.650 --> 32:00.050] You know... [32:00.050 --> 32:00.270] Okay. [32:00.690 --> 32:02.550] Could a port scan be considered malicious? [32:02.750 --> 32:05.030] Well, somebody might consider it the wrong way. [32:05.190 --> 32:05.690] So, that's... [32:05.690 --> 32:07.390] I literally said one sentence. [32:09.270 --> 32:09.710] And... [32:09.710 --> 32:12.890] The next day, I got an email back from the guy. [32:13.110 --> 32:14.830] And he was like... [32:14.830 --> 32:15.670] He was... [32:15.670 --> 32:18.850] This was my first indication that okay, I think I did the right thing. [32:18.850 --> 32:20.310] He was very egregious. [32:20.750 --> 32:21.290] Like... [32:21.290 --> 32:21.890] Oh, my God. [32:22.170 --> 32:22.710] Thank you. [32:23.290 --> 32:23.590] You... [32:23.590 --> 32:24.690] You saved our shit. [32:25.210 --> 32:25.390] Yes. [32:26.530 --> 32:27.690] And then he's like... [32:27.690 --> 32:28.670] Can I call you? [32:29.170 --> 32:29.890] I'm like... [32:33.070 --> 32:36.070] And I told you, I don't do this disclosure stuff. [32:36.230 --> 32:36.630] So, I... [32:36.630 --> 32:36.910] You know... [32:36.910 --> 32:38.190] But I'm... [32:38.190 --> 32:40.110] I understand that... [32:40.110 --> 32:41.570] That people are interested... [32:41.570 --> 32:42.170] That, you know... [32:42.890 --> 32:43.430] People... [32:44.430 --> 32:46.170] I sensed that this was a good guy. [32:47.010 --> 32:47.810] Maybe I was wrong. [32:47.890 --> 32:48.350] You know, I don't know. [32:49.110 --> 32:49.730] So, I... [32:49.730 --> 32:50.250] So, I... [32:50.250 --> 32:52.610] We set up a time and we talked on the phone for a couple minutes. [32:52.950 --> 32:55.570] And he really just wanted to know how did I find it. [32:56.210 --> 32:58.550] And I didn't really go into the whole showdown thing. [32:58.810 --> 33:01.610] I just told him that I kind of do research on banners. [33:01.770 --> 33:02.170] Which I do. [33:02.330 --> 33:03.790] I do a lot of research on banners. [33:04.230 --> 33:07.830] And I told him that I was doing a random search. [33:07.970 --> 33:08.790] Which I really was. [33:08.910 --> 33:09.970] I wasn't targeting him. [33:10.670 --> 33:12.870] And that I came across his device. [33:12.870 --> 33:13.970] His devices. [33:14.370 --> 33:15.070] And I just... [33:15.070 --> 33:15.350] You know... [33:15.350 --> 33:20.430] And he kind of went into this story about how some new guys had put these devices up. [33:20.590 --> 33:22.370] And they didn't configure them properly. [33:22.810 --> 33:23.210] And... [33:24.150 --> 33:24.550] Okay. [33:24.810 --> 33:25.090] And... [33:25.510 --> 33:26.610] And he offered me... [33:26.610 --> 33:27.150] He said... [33:27.970 --> 33:29.050] I won't tell you how much money. [33:29.130 --> 33:29.830] But he offered me money. [33:29.950 --> 33:33.450] He said, we'd like to send you a check for finding this. [33:33.970 --> 33:35.610] Because we want to thank you for it. [33:37.190 --> 33:37.590] So... [33:37.590 --> 33:38.870] And I didn't go... [33:38.870 --> 33:40.010] I didn't demand money or anything. [33:40.070 --> 33:42.610] I didn't go in there saying, give me money or I will expose you. [33:42.610 --> 33:43.150] No, I didn't... [33:43.150 --> 33:43.650] There was nothing. [33:43.850 --> 33:44.210] I did... [33:44.210 --> 33:46.050] I was just kind of just doing the nice... [33:46.050 --> 33:47.810] I'll just be nice and tell you about it. [33:49.670 --> 33:50.570] So I sent... [33:50.570 --> 33:52.010] I sent him my address. [33:53.130 --> 33:53.530] And... [33:55.090 --> 33:56.150] I know, you know. [33:56.350 --> 33:57.970] The next thing I'm getting some like subpoena. [33:58.170 --> 33:58.490] And there's... [33:58.490 --> 33:59.250] No, there's... [33:59.250 --> 34:01.370] To be honest with you, I have not heard a peep. [34:01.650 --> 34:02.430] Nothing at all. [34:02.430 --> 34:03.530] So I think either... [34:05.510 --> 34:07.770] They just decided they didn't want to... [34:08.330 --> 34:11.010] Or maybe they did more research on me and saw that I was... [34:11.010 --> 34:13.110] I will tell you that in the... [34:13.110 --> 34:14.870] I talked about this one other occasion. [34:14.910 --> 34:16.790] And I didn't talk about the disclosure part at all. [34:16.850 --> 34:17.170] I just... [34:17.170 --> 34:18.150] I talked about... [34:18.150 --> 34:19.890] And I did not reveal any... [34:19.890 --> 34:21.410] I still have not revealed who they are. [34:21.930 --> 34:22.250] So... [34:22.250 --> 34:23.370] He may have said... [34:23.370 --> 34:25.290] He may have looked and said, Oh, they're talking about you. [34:25.790 --> 34:27.390] I still haven't said the name of their company. [34:27.570 --> 34:27.710] Whatever. [34:28.870 --> 34:29.190] So... [34:30.210 --> 34:30.530] Whatever. [34:30.750 --> 34:31.890] Maybe they decided not to pay me. [34:32.010 --> 34:32.850] So maybe... [34:32.850 --> 34:36.270] In a disclosure, when someone offers to pay you, Maybe you should get it in writing or something. [34:36.350 --> 34:36.810] I don't know. [34:37.770 --> 34:38.970] But they offered to pay me... [34:38.970 --> 34:40.270] It was $500 what they offered. [34:40.430 --> 34:40.770] I mean... [34:40.770 --> 34:41.410] But that's pretty cool. [34:41.570 --> 34:42.030] I mean... [34:42.030 --> 34:43.490] Hey, here's $500 for finding something. [34:44.330 --> 34:44.970] They didn't... [34:44.970 --> 34:46.050] They didn't send me anything. [34:46.210 --> 34:47.830] And I'm not gonna press it at this point. [34:49.870 --> 34:50.190] But... [34:53.700 --> 34:56.840] Maybe there's more ISPs out there worth some money, you know? [34:58.700 --> 35:00.720] Like I said, I don't do the disclosure thing. [35:00.840 --> 35:02.880] So this was kind of my first foray into the whole thing. [35:03.140 --> 35:04.080] But here's the thing. [35:04.240 --> 35:05.220] I mean, now... [35:06.380 --> 35:08.380] Responsible disclosure is typically... [35:08.900 --> 35:10.220] Okay, you talk to the vendor. [35:10.440 --> 35:14.000] And after a certain period of time, you know, you announce it or... [35:14.860 --> 35:20.640] To be honest with me, I have no desire to announce who this company is because it's... [35:20.640 --> 35:20.880] It's... [35:20.880 --> 35:22.340] They're a fairly small ISP. [35:23.300 --> 35:23.700] And... [35:23.700 --> 35:26.860] Me announcing it to the world does not make it... [35:26.860 --> 35:31.220] If I could announce it to their customers, sure, maybe that would work. [35:31.660 --> 35:32.680] But there's not... [35:32.680 --> 35:33.400] To me, there's no... [35:33.400 --> 35:35.020] There's no desire to make anything public. [35:35.180 --> 35:35.320] Yeah. [35:35.440 --> 35:35.920] You have a question? [35:35.920 --> 35:38.480] Have I had a chance to go back and see if they fixed it? [35:40.060 --> 35:40.420] Um... [35:40.420 --> 35:41.840] I did look a couple days later. [35:42.080 --> 35:42.900] He claimed... [35:42.900 --> 35:43.980] I haven't looked in a couple... [35:43.980 --> 35:46.000] In recently, in the past few weeks. [35:46.200 --> 35:47.860] He says they shut it down. [35:48.000 --> 35:48.420] But I... [35:48.420 --> 35:49.760] Honestly, I haven't checked recently. [35:51.180 --> 35:51.540] Um... [35:51.540 --> 35:52.340] But, uh... [35:52.340 --> 35:56.340] Yeah, I mean, it's probably worthwhile to go back and see if they really did fix it or if they just... [35:56.340 --> 35:58.340] Maybe they think they fixed it, but they didn't. [35:58.560 --> 36:00.520] You know, maybe that was what the case was in the first place. [36:02.060 --> 36:02.500] So... [36:02.500 --> 36:02.720] Yeah. [36:03.760 --> 36:04.380] So that's... [36:04.380 --> 36:09.400] You know, for those of you who don't necessarily do disclosure thing, I don't do disclosure, but I did. [36:10.520 --> 36:10.960] So... [36:10.960 --> 36:13.320] What I think is a fairly responsible manner. [36:14.840 --> 36:16.140] Couple other examples... [36:16.140 --> 36:17.260] Or just some general observations. [36:17.720 --> 36:17.900] Okay. [36:18.320 --> 36:20.260] This is just more of kind of a fun... [36:20.260 --> 36:22.040] End up the talk with a fun thing. [36:22.160 --> 36:23.500] So, IAS 5.0. [36:25.500 --> 36:25.940] Um... [36:25.940 --> 36:26.640] Windows 2000. [36:27.080 --> 36:28.960] You know there's still lots of them out there, of course. [36:29.880 --> 36:32.740] There was, you know, 362,000 out there. [36:33.180 --> 36:33.900] Now, there's more. [36:34.080 --> 36:35.440] This is just what Shodan has captured. [36:37.020 --> 36:38.520] You can see where this one's going. [36:39.980 --> 36:41.180] IAS 4.0. [36:42.880 --> 36:44.000] Almost 10,000. [36:46.970 --> 36:48.150] I mean, you're going back. [36:48.290 --> 36:49.790] This is like time travel right now. [36:50.490 --> 36:51.750] Flux capacitor, right? [36:54.370 --> 36:54.890] 381. [36:57.550 --> 37:00.750] Does anybody know what IAS 1.0 maps to? [37:01.570 --> 37:03.790] Windows NT 3.91. [37:05.090 --> 37:05.730] 3. [37:06.610 --> 37:07.250] 91? [37:07.570 --> 37:08.010] I think it's... [37:08.010 --> 37:10.190] Either way, it's way back. [37:10.350 --> 37:13.810] It's in like 94, 95-ish, somewhere in there. [37:14.950 --> 37:16.230] There's 159. [37:21.130 --> 37:27.370] I went to a couple of these webpages and it's like they set up the webpage in like 94, 95 and never touched it since. [37:27.950 --> 37:28.950] They're still out there. [37:29.050 --> 37:29.430] Thank you. [37:35.450 --> 37:50.290] Now, the bank that I used to belong to, I went into them, I went into their, I typically went online and I went into their, into one of their local places, which I'd never, and they were running NT on one of their things. [37:50.370 --> 37:51.090] I was like, whoa. [37:51.090 --> 37:52.770] So there's stuff out there. [37:52.910 --> 37:56.150] I mean, there's people that are using these older devices, you know. [37:56.890 --> 37:57.410] Wow. [37:57.730 --> 37:58.530] It's kind of scary. [38:01.610 --> 38:05.430] Now, you've all seen, you've all done Google hacking. [38:05.770 --> 38:12.850] About every six months, some local news channel rediscovers that how you can view video cameras on Google, you know. [38:15.030 --> 38:21.190] This is a Logitech wireless network camera in Japan, I think. [38:23.130 --> 38:25.870] And by the way, all those pan and tilt buttons, they work. [38:29.650 --> 38:35.630] Not at this screenshot, but I had a screen, I had an earlier time when all these, actually they are, all the ladies were sitting there at the desk. [38:35.630 --> 38:43.470] And I was like, up, down, left and right, like trying to get them to look, but they would never look. [38:48.730 --> 38:51.050] There's no Zoom actually, and I'll talk about that in a second. [38:56.350 --> 39:00.610] So, the other, there's, there's another reason I used this slide and I want to show you something else. [39:00.770 --> 39:03.230] So this is the page as viewed in Firefox. [39:03.890 --> 39:09.450] This is the page, so, and this is what, this is one of those examples of where when you mouse over, look at the task bar. [39:09.750 --> 39:15.270] So the camera button, if you don't read, I guess it's, I think, I believe it's Japanese, is a snapshot. [39:15.270 --> 39:17.350] So it takes a snapshot of that instant. [39:17.650 --> 39:21.510] And then the second button is a client, that HTML, which doesn't really give you anything. [39:21.830 --> 39:24.530] But I want you to look at this picture, which is viewing it in Firefox. [39:25.410 --> 39:28.390] And then this picture, which is viewing it in Internet Explorer. [39:28.510 --> 39:30.510] Actually, this is an IE tab, but it's Internet Explorer. [39:30.510 --> 39:33.810] And you see there's a third button there that isn't rendered in Firefox. [39:35.470 --> 39:41.650] So this is why I strongly encourage people to view, if you're looking at web pages, to view them in different, you know, browsers. [39:42.230 --> 39:45.530] And that actually comes out through setupconfig.html. [39:47.950 --> 39:51.290] Which, again, you would not see that if you were looking at it in Firefox. [39:51.290 --> 39:53.210] And I'm not an IE guy, sorry. [39:53.990 --> 39:55.210] But hey, it's out there. [39:56.010 --> 39:57.470] And this is what it would take you to. [39:59.270 --> 40:11.910] And all those, all that, all the Japanese over there is what, again, so this is one of those devices that you can do, not just view, but you could just change things left and right, whatever you want to do. [40:15.010 --> 40:16.350] Okay, so the future. [40:17.450 --> 40:19.830] I talked to John, I said, so what do you want to do with Shodan? [40:20.050 --> 40:26.290] I mean, it's, it's, I know he's, he was kind of blown away by all this penetration sensing stuff, because it's not what he really expected for it. [40:27.710 --> 40:30.230] But, so I talked to him, what are you, what are you looking at doing in the future? [40:30.290 --> 40:34.570] He's talking about an API for program interaction, integration, I'm sorry. [40:36.650 --> 40:42.470] The export option, which I did talk about, he wants to have some kind of a summary report, he wants to give people, you know, the bang for the buck. [40:42.550 --> 40:46.010] You know, he's asking money from some people, so he wants to give them their money's worth. [40:46.630 --> 40:54.510] He wants to talk, include some fingerprints, and then he's also wants to collect HTPS, may find some useful stuff in there. [40:57.610 --> 41:03.590] Okay, so could you go home right now and do this? [41:03.590 --> 41:05.170] Absolutely, you could do this. [41:06.350 --> 41:16.230] You could write a script, an end map, or something, and collect large amounts of data on the Internet, collect web banners, and make them searchable. [41:16.330 --> 41:21.410] You could do this, but someone's already done it, so that's kind of the, that's kind of the, the first point. [41:21.590 --> 41:28.370] So, we're aggregating a significant amount of information that isn't already widely available and putting it in an easy to understand format. [41:28.930 --> 41:31.570] I shouldn't say we, because I'm not doing it, I'm just reporting on it. [41:34.830 --> 41:39.310] It also allows, if you think about it, it allows for some sense of passive vulnerability analysis. [41:39.770 --> 41:55.070] Because when I go to these, IAS 5.0, or whatever, or 4.0, I, there might be a vulnerability for someone of those devices that now, without me ever touching the target, I know that the potential is that they're vulnerable. [41:55.070 --> 42:02.910] I'm searching a particular domain for a particular target of mine, and I know that they have X number of Windows 2000 servers. [42:03.550 --> 42:07.190] I haven't even touched their IP space, and I know that they might be vulnerable. [42:07.730 --> 42:10.410] So, there's a little bit of passive vulnerability analysis there. [42:12.630 --> 42:14.430] Now, is Shodan going to take over? [42:14.550 --> 42:14.770] No. [42:14.770 --> 42:22.170] This is kind of one of those tools that you put in your toolbox of, well, we've looked here, we've looked here, what about this? [42:22.330 --> 42:23.790] Can we, can this find us anything? [42:23.930 --> 42:24.370] And it might. [42:24.670 --> 42:30.530] I think this is, I think this will help to shape vulnerability assessments and penetration tests in the future. [42:30.530 --> 42:33.230] I don't, is that like in soccer, a yellow card? [42:33.550 --> 42:33.750] Okay. [42:35.550 --> 42:36.590] One more and I'm done. [42:37.230 --> 42:39.550] I'm just, I know, I'm just... [42:40.850 --> 42:43.650] At least there's no vuvuzelas, like, in the background. [42:44.770 --> 42:45.390] I know. [42:45.930 --> 42:47.110] Is that annoying or what? [42:47.430 --> 42:47.790] One more? [42:47.990 --> 42:48.390] No. [42:50.230 --> 42:53.390] So, I think this is going to help shape vulnerability assessments in the future. [42:53.570 --> 42:59.710] I think people can maybe find something in Shodan that they don't know, and it may help to give them some additional information. [43:00.750 --> 43:04.310] John Mattely, his Twitter, there's his Twitter account, Achillian. [43:05.270 --> 43:10.690] And these are the guys that developed those add-ons for Firefox. [43:10.910 --> 43:13.850] Or you could just go to Firefox add-ons and search for Shodan and you'll find them. [43:16.270 --> 43:16.550] Questions? [43:16.810 --> 43:17.910] I will save the rest of them for questions. [43:18.030 --> 43:18.270] Yes, sir. [43:18.990 --> 43:21.410] Sorry, quick, before we do that, can you repeat all the questions? [43:21.690 --> 43:22.550] Absolutely, absolutely. [43:22.850 --> 43:24.690] Taping, we don't have, like... [43:24.690 --> 43:28.910] Okay, so the, it's not really more of a question, more of a comment, just for those of the audience. [43:29.370 --> 43:35.310] It's not unusual to run across older NT systems because with virtualization these days, no one can get rid of their hardware. [43:35.990 --> 43:43.870] I've run across many situations where they throw it into a virtual server or an ID situation, and they just keep their T351 or 400. [43:44.310 --> 43:44.570] Right. [43:44.970 --> 43:47.850] His comment was that it's not uncommon to find older systems. [43:48.770 --> 43:52.090] And also because sometimes things work and people don't want to mess with them. [43:52.650 --> 43:58.990] And also I know that a lot of older, you know, SCADA systems and use older hardware and they're not compatible with newer stuff. [43:59.010 --> 44:01.310] And if it's not broken, don't fix it type of thing. [44:01.450 --> 44:03.750] So you will run across some older stuff out there. [44:04.510 --> 44:05.030] Right here. [44:05.030 --> 44:10.010] I had a question and that was, the guy who's building it said he thought there were business, you know, applications. [44:10.370 --> 44:15.190] Is he just saying in terms of like figuring out where your vulnerabilities are or does he see other applications as well? [44:15.470 --> 44:18.630] He wasn't really looking in the vulnerability part at all. [44:18.850 --> 44:22.150] He was asking about the business applications of Shodan. [44:22.350 --> 44:23.830] He was just looking for marketing. [44:25.470 --> 44:27.330] He's a developer guy, so I don't know. [44:27.330 --> 44:31.350] He wasn't looking for down the path of vulnerabilities. [44:31.650 --> 44:32.410] How does he figure marketing? [44:34.330 --> 44:35.710] I'll let him figure it out. [44:36.210 --> 44:36.590] Yes, sir. [44:36.770 --> 44:38.570] Is there any other tools in this space? [44:39.430 --> 44:40.930] Any other tools to do this? [44:41.110 --> 44:41.490] Is it pretty? [44:45.250 --> 44:46.130] I don't... [44:46.130 --> 44:50.850] He asked if there are any other tools similar to Shodan that do the same sort of thing. [44:51.190 --> 44:52.130] There's a couple... [44:52.130 --> 44:53.570] There's some projects out there. [44:53.570 --> 45:05.050] There's a project which I can't think of the name of, which is intending to search every HTTP port on the entire Internet and report the data, which is sort of the same thing. [45:05.310 --> 45:07.950] But it's kind of a worldwide port scan of port 80. [45:09.290 --> 45:12.130] I wish I had the link and I don't. [45:12.650 --> 45:14.730] But that does sort of the same thing. [45:15.010 --> 45:18.250] The second question, I assume, what they have is the bot that goes out. [45:19.730 --> 45:20.630] Yeah, John... [45:20.630 --> 45:21.910] Oh, to gather the data? [45:22.010 --> 45:22.910] I talked to John about this. [45:22.910 --> 45:27.870] He said he wrote his own script to collect the data. [45:28.830 --> 45:31.410] I don't know exactly what, if it's Python or Perl. [45:31.690 --> 45:33.010] He didn't go into details. [45:35.510 --> 45:37.310] But it's kind of a customized thing. [45:37.390 --> 45:39.610] But he said it was very easy to do, very fast. [45:39.810 --> 45:41.910] He said anybody could reasonably do the same sort of thing. [45:42.310 --> 45:43.110] In the back, sir? [45:43.710 --> 45:47.210] Did you say it doesn't work with HTTPS? [45:48.110 --> 45:52.570] He's not collecting on HTTPS yet, but he's talking about doing it in the future. [45:54.430 --> 45:57.350] The question was, is he collecting on HTTPS? [45:57.590 --> 46:00.030] He is not collecting on it yet, but he's talked about it in the future. [46:00.150 --> 46:00.750] All the way in the back, sir? [46:05.620 --> 46:08.580] It's just 80 and then 21, 22, and 23 right now. [46:09.390 --> 46:17.160] If there are other ports that you think would be useful, he has always mentioned that you can just send him a note on Twitter and say, hey, can you collect on this port? [46:17.270 --> 46:18.250] And he could easily add that. [46:18.980 --> 46:19.210] Sir? [46:19.210 --> 46:21.770] How quickly and how does he discover new machines? [46:24.080 --> 46:31.020] He just puts in, like, large blocks of... and I don't know if he has, like, a priority list of what he's looking for. [46:32.100 --> 46:36.250] He didn't go into his specific detail, but he's always adding large amounts of new data. [46:36.520 --> 46:38.250] So... but I don't know what his priorities are. [46:38.480 --> 46:42.060] His question was about adding new data and how he gets it. [46:43.160 --> 46:44.960] How often does he refresh his cache? [46:45.660 --> 46:49.210] I've seen every week or so he's adding new data. [46:49.360 --> 46:51.540] And I don't know how often he's going back to the old data. [46:52.120 --> 46:57.600] One of the things that you will typically see on the website is when it was added, the result. [46:57.860 --> 47:01.230] So you may find that, you know, that result is older. [47:01.440 --> 47:03.820] But it will typically tell you when it was... when it was added. [47:06.420 --> 47:06.900] Yes? [47:07.180 --> 47:12.420] Assuming this isn't something that I can contact him to get the script to run... [47:14.580 --> 47:15.960] You could certainly ask him. [47:16.200 --> 47:18.000] I don't know if he'll give it to you, but I mean... [47:18.000 --> 47:24.420] The question was, could you contact him to get this script to kind of do it internally for your own company or whatever? [47:24.600 --> 47:25.700] You could certainly ask him. [47:25.790 --> 47:29.750] I mean, I'm not going to stop you from asking him whether or not you could do that. [47:31.320 --> 47:32.100] Five minutes to go. [47:32.180 --> 47:32.750] Any more questions? [47:35.270 --> 47:35.600] Yes? [47:42.840 --> 47:50.520] The question was about any success in looking at SCADA systems in terms of what you can do with them, controlling valves and all sorts of things. [47:51.160 --> 47:52.500] I did not... [47:52.500 --> 47:55.480] I don't do a lot of SCADA stuff, so I don't really... [47:55.480 --> 47:57.800] To be honest with you, I'm not really sure what to look for. [47:58.340 --> 48:01.860] So I haven't really actively looked into what you could do. [48:01.860 --> 48:05.120] I suspect that you could probably find something out there that you could... [48:05.120 --> 48:12.020] I don't know that you could, you know, turn valves on and off, but you could certainly probably get into somewhere and do something. [48:13.360 --> 48:18.900] Again, from my perspective here, I'm trying to give it, you know, what could you do as opposed to what can you do? [48:19.440 --> 48:23.920] Because obviously there's a lot of malicious intent with what you could do here. [48:24.300 --> 48:29.160] So I'm just trying to, like, draw the line in the sand and say, okay, I'll do this, but I'm not going to go that far. [48:30.780 --> 48:31.560] Any other questions? [48:32.140 --> 48:36.260] I want to thank the HOPE staff for giving me the opportunity to speak. [48:36.940 --> 48:41.060] This is a great conference to come to. [48:41.400 --> 48:49.080] It's definitely more unique than most of the other conferences that we go to in the community, but it's really one of my favorites. [48:49.560 --> 48:50.660] So thank you, everybody. [48:50.860 --> 48:51.340] Thanks for coming. [48:51.440 --> 48:52.960] I'll be up here for a little bit for questions. [48:59.100 --> 48:59.820] And thank you. [49:01.600 --> 49:05.420] Just a reminder, the keynote is going to be simulcast in all three rooms. [49:06.020 --> 49:10.660] I'm not sure whether this one's going to be open to the other room, which we do sometimes, but that might be one possibility. [49:10.820 --> 49:13.000] So it might be that you want to save your seats. [49:13.290 --> 49:14.040] Maybe, maybe not. [49:14.140 --> 49:14.520] All depending. [49:14.940 --> 49:17.840] But it'll also be in Lovelace and it'll be in the big room over there.