[00:01.320 --> 00:03.260] At one o'clock, hacking the iPod. [00:03.460 --> 00:05.400] At two o'clock, why forensics sucks. [00:06.180 --> 00:08.940] At three o'clock, Python TCP/IP stack. [00:09.360 --> 00:11.760] And at four o'clock, media streaming. [00:13.600 --> 00:14.740] The other announcements. [00:16.120 --> 00:20.660] If you have... [00:22.580 --> 00:23.020] All right. [00:23.240 --> 00:25.200] If you would, please hold your questions until the end. [00:25.340 --> 00:26.840] And if you wouldn't mind, use the microphone. [00:27.040 --> 00:29.280] We're not going to point the camera at the microphone, so don't worry. [00:29.280 --> 00:37.200] But when this goes out on the archive on the web, we don't want, you know, thousands of hackers and 30 or 40 law enforcement officers straining to hear your questions. [00:37.600 --> 00:41.040] So we can get those, and everybody will hear them, and it'll be good. [00:44.410 --> 00:45.050] That's it. [00:45.510 --> 00:50.790] And without further ado, we have Laurent Odeau to speak about retaliation with Honeypots. [00:52.190 --> 00:52.810] Thank you. [00:53.590 --> 00:54.210] Hi, everybody. [00:55.490 --> 00:56.750] My name is Laurent Odeau. [00:56.910 --> 00:58.050] I'm coming from France. [00:58.050 --> 01:02.910] And I work for the French equivalent of the Department of Energy, U.S. [01:03.150 --> 01:03.690] Department of Energy. [01:04.610 --> 01:10.450] I am a member of the team called RST-ACK, where you can find everything on rstack.org. [01:10.730 --> 01:17.150] And also, I am one of the members of the steering committee of the Honeynet project, which is leaded by Lens Piesner. [01:17.990 --> 01:21.810] So today, we're going to talk about retaliation with Honeypots. [01:22.350 --> 01:23.630] So that should be funny. [01:28.050 --> 01:32.030] So, at first, we begin with a very easy question. [01:32.170 --> 01:35.290] What is a Honeypot, in case people here wouldn't know? [01:36.230 --> 01:40.830] Is there anybody here who has either deployed a Honeypot? [01:41.310 --> 01:41.730] No? [01:42.450 --> 01:43.290] Okay, cool. [01:44.250 --> 01:55.290] Then we'll be able to talk about retaliation with Honeypots, which is the core of the presentation, and with two more bonus, which is adding poison in the Honey and monitoring the trap. [01:56.970 --> 02:02.790] Well, I will show you logs, example of logs from the Honeypot. [02:03.010 --> 02:04.510] And then we'll be able to conclude. [02:05.390 --> 02:07.170] So first, what is a Honeypot? [02:08.530 --> 02:11.870] As I know, this is Sunday, and this is very early for geeks. [02:12.270 --> 02:13.690] For me, this is very early. [02:16.470 --> 02:17.250] What's that? [02:17.950 --> 02:18.930] What can you see? [02:22.320 --> 02:23.220] A truck? [02:23.400 --> 02:23.780] Yeah, okay. [02:24.960 --> 02:25.360] Okay. [02:26.120 --> 02:27.100] Those are fakes. [02:28.100 --> 02:40.140] It comes from Fortitude, which was the code name given to the deco operation mounted by the allies to deceive the Germans about the date and above all the place of the landing for the D-Day. [02:40.140 --> 02:46.080] You know, this is the birthday of the 16th birthday for that. [02:46.880 --> 02:49.960] So deception works and will work. [02:50.160 --> 02:50.760] Okay. [02:51.500 --> 02:56.380] And Honeypots are security resources that might be used to deal with attackers. [02:57.160 --> 03:09.940] If we look at the definition proposed by Lance Piesner, the leader of the Honeynet project, he said that Honeypots are computer resources whose value lies in unauthorized or elicit use of that resource. [03:10.140 --> 03:16.280] So they are built to be attacked, scanned, probed, compromised. [03:17.640 --> 03:22.100] So how can you build your own toy to play with aggressors? [03:23.500 --> 03:30.180] You have to create non-production networks and devices, systems used to delude the attackers. [03:30.480 --> 03:34.500] For example, you can build a fake company or fake association, something like that. [03:34.820 --> 03:49.940] You have to log everything, system activity, network activity, because, for example, you would like to grab the exploits of the evil attacker and the rootkits and stuff like that. [03:50.120 --> 03:51.280] And it works, really. [03:52.520 --> 04:01.780] Then, one of the cool things with Honeypots is that while the people will attack your Honeypots, they will attack your production system. [04:01.780 --> 04:07.400] So, but this is very risky, because you have to protect this specific infrastructure. [04:07.900 --> 04:18.880] For example, what would happen if the Honeypot is used to bounce, for example, on pentagon.gov or something like that, I don't know. [04:19.160 --> 04:21.180] So, you will be the source of the attack. [04:21.560 --> 04:26.180] So, this is very difficult to deal with the outbound traffic from your Honeypots. [04:26.800 --> 04:31.060] And then, you just have to wait and see and look at attackers losing time, et cetera. [04:32.280 --> 04:34.000] So, more about Honeypots. [04:35.080 --> 04:39.940] If you think about deploying Honeypots, take care of legal issues. [04:40.180 --> 04:47.040] For example, in some countries, you might have problems with entrapment, tracking, recording, privacy. [04:47.320 --> 04:58.140] For example, what if you are recording everything in your Honeypots, and that black hats decide to have discussions in your Honeypots. [04:58.320 --> 05:01.940] If you are recording this discussion, is it legal or illegal? [05:02.460 --> 05:04.740] So, just, it depends on your country. [05:04.960 --> 05:10.740] For example, you have to check on the honeynet.org website, for example. [05:11.540 --> 05:14.120] And also, I talked about that just before. [05:14.300 --> 05:16.640] What if an attacker use your Honeypot to jump elsewhere? [05:17.240 --> 05:18.600] That's the main problem. [05:19.100 --> 05:20.920] Also, we have technical issues. [05:21.220 --> 05:25.040] Like, you have to harden the network, to avoid bounces. [05:26.340 --> 05:28.400] You have to deal with stealth problems. [05:29.260 --> 05:35.080] For now, the black hat people just want to try to fingerprint your Honeypot. [05:35.420 --> 05:37.740] They want to know if this is a Honeypot. [05:37.840 --> 05:39.040] For example, is it a VMware? [05:39.460 --> 05:40.800] They will try to look at that. [05:41.180 --> 05:43.720] They will try to see if they can access the Ring Zero. [05:44.060 --> 05:49.440] They will try to look if there is traffic on the network, system activities, and stuff like that. [05:49.680 --> 05:51.900] So, that might be difficult. [05:52.240 --> 05:56.100] And also, you need time to monitor the box, and analyze intrusions. [05:56.780 --> 06:05.160] So, some managers say that Honeypot sucks, because they don't have time to look at the logs of their real production system. [06:05.700 --> 06:08.400] Why would they add something else? [06:08.960 --> 06:09.720] I don't know. [06:10.560 --> 06:17.460] From a philosophical or psychological point of view, people say, do you really want to play with aggressors? [06:17.820 --> 06:21.580] What if, for example, a black hat see that this is a Honeypot? [06:22.000 --> 06:23.940] Will he strike back or something like that? [06:24.140 --> 06:24.900] I don't know. [06:25.080 --> 06:25.460] I don't mind. [06:27.340 --> 06:32.020] If you want more information about Honeypot, just join the Alliance on honeynet.org. [06:33.180 --> 06:33.860] Okay. [06:34.520 --> 06:37.020] So, who knows? [06:37.240 --> 06:37.920] HoneyD. [06:38.760 --> 06:39.340] Nobody? [06:39.720 --> 06:40.020] Okay. [06:40.440 --> 06:46.660] HoneyD is a pretty cool open source project, which is leaded by Nis Provost, a member of the Honeynet project. [06:47.080 --> 06:59.380] And this is a unique diamond that will help you at creating thousands and thousands of fake computers and fake services on only one computer. [07:00.280 --> 07:05.580] And this is very cool because it can fool tools like Nmap and XProb. [07:06.120 --> 07:13.400] And, for example, you can build with, I don't know, a few lines of configuration. [07:13.400 --> 07:16.700] You can build, for example, a fake cluster of PlayStation 2. [07:18.080 --> 07:19.120] That's quite funny. [07:19.260 --> 07:27.760] You can imagine someone from a foreign country attacking your fake cluster and saying, oh, dude, there is a PlayStation 2 cluster. [07:27.960 --> 07:28.680] That's strange. [07:29.380 --> 07:31.080] But everything is fake. [07:31.360 --> 07:35.960] So, if the attacker send an exploit, we grab the exploit, and that's quite funny. [07:36.540 --> 07:43.040] So, this is very easy also to simulate arbitrary routing topologies and stuff like that. [07:44.360 --> 07:56.060] To show you, for example, as you might see from the network, when packets come down to HoneyD, it comes through lib pickup. [07:56.620 --> 08:00.380] And then there is a virtual IP stack that deals with packets. [08:01.280 --> 08:19.820] And depending on the type of packets, for example, if this is TCP and UDP, and if HoneyD want to simulate a fake service to delude the aggressor, then HoneyD will launch an external program that will deal with the aggressor and simulate a service. [08:20.820 --> 08:32.160] Then, when packets will go out of the Honeypot, it will go through something that is called the Personality Engine to fool, for example, tools like Nmap or Xprop. [08:32.720 --> 08:32.900] Okay? [08:35.420 --> 08:38.140] So, to configure HoneyD, this is very easy. [08:38.240 --> 08:40.240] You just have to focus on creation. [08:40.480 --> 08:41.120] Go create. [08:41.620 --> 08:46.800] Imagine what could be your own fake network and systems and just write a configuration. [08:46.800 --> 08:59.180] For example, I would like a fake box with Linux on 192.168.1.22 with fake email server and fake suite server and whatever. [08:59.180 --> 09:02.640] You just have to create, for example, create a template. [09:02.940 --> 09:07.540] Say, the personality will be a Linux kernel with this version. [09:08.080 --> 09:12.440] I would like a fake email service on port 25. [09:12.680 --> 09:16.920] So, just launch a fake sendmail.pl script, for example. [09:17.260 --> 09:18.780] I would like a fake squid. [09:18.960 --> 09:20.060] I would like a fake proxy. [09:20.720 --> 09:21.580] And whatever. [09:21.820 --> 09:23.060] You just have to create. [09:23.220 --> 09:24.100] That's very easy. [09:24.180 --> 09:24.680] You should try. [09:26.540 --> 09:28.820] So, how work the fake services? [09:30.060 --> 09:38.320] As you can see, the attacker, for example, will try to play and talk with your honeypots and say, for example, hello, site.com. [09:38.500 --> 09:39.760] I'm a f*cking spammer. [09:39.920 --> 09:43.200] And I want to send a thousand and a thousand of spam. [09:43.520 --> 09:43.640] Okay. [09:44.280 --> 09:47.460] HoneyD will say, okay, there is a spammer. [09:48.580 --> 09:53.200] There is someone who wants to talk with my fake Sendmail service. [09:54.360 --> 09:59.320] It will launch the fake external Sendmail script. [09:59.640 --> 10:04.280] And this fake external script just have to deal with input and output. [10:04.540 --> 10:08.900] For example, if I receive hello, then I will write something. [10:09.120 --> 10:11.300] If I receive a mail from, I will write something. [10:11.300 --> 10:15.980] And this is, as you might see, this is very easy to write your own fake service. [10:16.680 --> 10:20.140] Then, it will launch, for example, the answer, send the answer. [10:20.360 --> 10:35.620] And HoneyD will finally send the final answer with, in case this is needed, changes in TCP and IP, for example, headers for personality issues. [10:35.900 --> 10:41.180] And the attacker will really think that he is talking to a Sendmail script. [10:43.600 --> 10:50.060] So, this introduction was just here to help you at understanding what are honeypots. [10:50.260 --> 10:53.880] But the core of the presentation is retaliation with honeypots. [10:55.840 --> 10:59.780] So, I'm pretty happy to be here at the HOPE conference to talk about that. [10:59.960 --> 11:04.760] Because, for example, in France, we have restriction of laws. [11:05.280 --> 11:12.620] And this is not clear for now, till June, if this is legal or not to talk about stuff like that. [11:13.180 --> 11:17.820] For example, you don't have the right to get exploited on your own computers and stuff like that. [11:17.940 --> 11:19.240] But I won't talk about that here. [11:19.400 --> 11:22.180] If you want to talk, just come on that offline. [11:25.520 --> 11:35.860] So, during the last CanSecQuest in Vancouver, I made a talk which was called Towards Evil Honeypots When They Bide Back. [11:36.560 --> 11:45.760] So, this presentation will strongly use slides from what I show during CanSecQuest Core 04. [11:45.760 --> 11:56.640] So, I said that evil honeypots are computer resources that are able to counter-attack or play with an aggressor by using specific self-defense techniques. [11:56.960 --> 11:59.760] You know, active defense, counter-attack. [12:00.720 --> 12:03.080] We're not just talking about fighting off. [12:03.080 --> 12:06.480] We're also talking about fighting back. [12:07.060 --> 12:07.380] Okay? [12:08.160 --> 12:13.700] So, imagine something like the aggressor that will attack your evil honeypot. [12:14.160 --> 12:19.400] And the evil honeypot will say, okay, if you touch me, I touch you, okay? [12:19.980 --> 12:21.800] And it will hack back. [12:21.800 --> 12:24.240] I will show you an example just after that. [12:26.160 --> 12:27.340] Don't tell the facts. [12:28.460 --> 12:28.720] Okay. [12:29.100 --> 12:31.620] Why would we play with retaliation? [12:31.980 --> 12:37.520] At first, you could say that people have the right to protect themselves. [12:38.420 --> 12:38.900] Okay? [12:38.900 --> 12:42.520] And you could say that self-defense should be accepted. [12:43.280 --> 12:47.960] Of course, this is very difficult because self-defense is not something... [12:47.960 --> 12:52.560] This is only, most of the time, something for physical threats. [12:53.340 --> 12:57.560] And this is very difficult to talk about that for the digital world. [12:57.560 --> 13:13.860] And also, this is very difficult to do clean retaliation because, for example, in the U.S., you don't have the right to protect yourself if you had another solution. [13:14.160 --> 13:18.380] So, how could you prove that you had no other alternative solutions? [13:20.080 --> 13:21.260] That's very difficult. [13:21.260 --> 13:28.780] And also, your answer, your counter-attack, has to be proportional to the attack. [13:29.120 --> 13:30.240] What is proportional? [13:30.460 --> 13:35.920] For example, if you get a DOS, a denial of service, what is proportional? [13:36.180 --> 13:36.600] A DOS? [13:37.960 --> 13:38.780] Why not? [13:38.980 --> 13:40.140] But you don't know. [13:40.260 --> 13:55.560] And also, if you attack back a computer of a victim that was hacked, for example, I don't know, that could be a very big cluster playing with codes to fight, for example, human disease. [13:56.300 --> 13:59.080] You will hack back such a computer. [13:59.400 --> 14:00.900] And that's not funny. [14:01.100 --> 14:01.180] Okay? [14:01.760 --> 14:06.840] So, as you might see, retaliation is funny from a technical point of view. [14:07.280 --> 14:08.500] I am a geeky. [14:08.840 --> 14:12.140] But also, I'm aware of legal issues. [14:12.400 --> 14:15.400] So, think about that if you look at those stuff. [14:15.400 --> 14:23.580] So, the white hat community might be interesting in retaliation, for example, to stop specific kind of attacks, like worms. [14:23.900 --> 14:28.520] And also, to trust, stop, monitor by internal users or attackers. [14:28.900 --> 14:31.160] Of course, this is very interesting. [14:31.500 --> 14:39.720] But, we have to be aware that retaliation could be used by black hat people, for example, to commit automatic crime. [14:39.720 --> 14:46.760] Imagine, if you put a honeypot that will hack back any incoming client. [14:47.200 --> 14:51.920] That's something that will automatically attack clients. [14:52.260 --> 14:54.440] So, that's something very bad. [14:55.940 --> 14:58.900] Why am I talking about honeypots? [14:59.100 --> 15:01.040] Because they are non-production resources. [15:01.040 --> 15:05.860] So, incoming traffic might be considered as suspicious. [15:06.320 --> 15:08.400] And should be considered as an aggression. [15:08.660 --> 15:10.360] Because this is a non-production system. [15:10.620 --> 15:14.820] That's why this is very cool to put something like retaliation on a honeypot. [15:15.820 --> 15:19.960] Because being evil with an aggressor might be considered as self-defense. [15:20.240 --> 15:21.620] Might be also, I said. [15:21.900 --> 15:23.140] So, hacking back. [15:23.660 --> 15:26.540] The trouble is, you have to think about spoofing. [15:26.540 --> 15:29.620] Are you sure that the attackers are those you want to hack back? [15:30.720 --> 15:32.640] You might attack innocents. [15:33.280 --> 15:36.440] And, first causality of war is innocent. [15:36.920 --> 15:37.800] You remember Platoon. [15:38.520 --> 15:40.820] And, what is the real source of the aggression? [15:41.140 --> 15:42.940] Those questions are very difficult. [15:43.560 --> 15:57.260] And also, imagine, if hack back become legal, how will you be able to prove that there were an incoming aggression? [15:57.500 --> 16:02.560] For example, if you had a line in your logs saying that, yes, Pentagon.gov attacked me. [16:03.220 --> 16:04.580] That's why I hack back. [16:04.760 --> 16:05.900] That's totally stupid. [16:06.140 --> 16:06.340] Okay? [16:06.560 --> 16:07.540] And you should go in jail. [16:09.940 --> 16:14.120] So, the proof of incoming aggression will become something very difficult. [16:14.980 --> 16:19.580] And, also, imagine if everybody put something like hack back on the Internet. [16:20.300 --> 16:22.160] Automatic hack back may lead to chaos. [16:22.540 --> 16:22.620] Okay? [16:23.280 --> 16:26.660] So, think twice before playing like that. [16:28.400 --> 16:31.200] But, hack back could be used for internal problems. [16:32.260 --> 16:38.500] Of course, you have the right to pen-test your own computers in your company, most of the time. [16:38.500 --> 16:46.320] So, if you have the right to pen-test your computer, your own computers, computers that are under your legal... [16:49.980 --> 16:51.300] You see what I mean? [16:54.920 --> 16:56.500] You have the right to pen-test. [16:56.680 --> 16:59.380] So, you have the right to attack those hosts. [16:59.600 --> 17:10.020] So, you might have the right to, for example, hack back an end user, I don't know, a Zelo trainee trying to get a specific secret file in your company, for example. [17:12.120 --> 17:22.680] But, hack back might be very difficult for external problems, and you might need cooperation, for example, state between states, or companies, and stuff like that. [17:24.800 --> 17:32.580] If we talk about the risk of spoofing, everybody knows the idle scan, for example, I suppose? [17:33.120 --> 17:33.720] Yes? [17:33.900 --> 17:34.020] No? [17:34.580 --> 17:43.080] Idle scan is just an example where the aggressor will talk with the target without being known. [17:43.640 --> 17:55.640] For example, the aggressor just have to send a scene by spoofing a host called zombie, and the target will answer with a SYN/ACK or reset, for example, to the zombie. [17:56.380 --> 18:08.880] Then, the aggressor will just have to talk with the zombie with a small SYN/ACK, which is called an IPID probe, and the zombie will send a reset. [18:08.880 --> 18:29.040] And depending on the fact that the target in the phase two sent a SYN/ACK or reset, the IPID will change on the zombie for the reset response, and the aggressor will know if the pore on the target was open or not. [18:29.500 --> 18:34.480] And, as you might see, the aggressor did not talk with the target. [18:34.480 --> 18:38.420] So, this is just called idle scan. [18:38.600 --> 18:45.940] But this is an example of a funny way to attack without being seen. [18:46.220 --> 18:54.580] And the trouble with hacking back is that that might be dangerous to hack back anybody, because you are not sure of the source of aggressor. [18:55.760 --> 18:58.340] So, let's talk about retaliation with honeypots. [18:58.340 --> 19:07.380] The idea is, imagine someone which is doing something bad against your honeypot, and you want to react. [19:09.000 --> 19:19.540] First, we could try, for example, to bite back usual clients coming to, for example, your fake web server, trying to do SQL injunction or stuff like that. [19:20.480 --> 19:24.500] What if the clients used by the attacker are vulnerable or misconfigured? [19:25.340 --> 19:38.520] For example, if you look at web clients like Internet Explorers, and SSH clients, mail clients, DNS server, IRC clients, whatever, they are all vulnerable, okay? [19:38.980 --> 19:44.860] Or, at least, they are vulnerable or they have been vulnerable, and in the future, they will be vulnerable. [19:45.560 --> 19:57.560] The question is, is it possible to do something like a remote control or a remote crash to, for example, fight back someone that tried to attack you? [19:58.240 --> 20:03.780] So, I played with something just to see if it was possible. [20:06.020 --> 20:08.480] With, for example, this is very old. [20:08.620 --> 20:10.780] This is two years old stuff. [20:11.360 --> 20:13.560] It was with SSH clients. [20:13.560 --> 20:25.060] Most of the time, on distro like Linux distribution with SSH clients, it was built, the clients were built with X11 forwarding active. [20:25.660 --> 20:26.640] Do you know what it is? [20:27.160 --> 20:27.240] Yeah? [20:28.120 --> 20:28.240] Okay. [20:28.880 --> 20:55.740] So, on the honeypots, and that was very easy with HoneyD to play like that, when the display localhost 10, when someone connected to my honeypot, because he knew, for example, a real login and a real password on my honeypot, which is something that he found with another bug on my web server, [20:57.200 --> 21:03.600] the display localhost 10 was the equivalent of the remote 0. [21:03.880 --> 21:11.380] So, the localhost on my honeypot port 6010 is automatically forwarded in the SSH station. [21:11.580 --> 21:35.430] And at that time, I could play with something like XWD or XPy, because by attacking the remote TCP port 6000 was very easy, because by attacking the local port forwarded by SSH, your attack was automatically forwarded to the attacker. [21:36.150 --> 21:45.950] So, with that, you could get, for example, you had a ciphered attack against the attacker. [21:46.630 --> 21:48.230] It was a funny hack back. [21:48.530 --> 21:57.270] You could get the attacker's screens dumped on the honeypot, and also, you could get everything tied by the attacker. [21:58.070 --> 22:00.670] So, you had a kind of remote keylogger active. [22:02.030 --> 22:13.410] So, that was funny, because he saw that it was a FreeBSD, and he went on security focus and tried to find bugs. [22:13.770 --> 22:23.850] So, that's quite funny, because most of the time, you will see that the black hat will try, for example, they will get an exploit that they don't understand. [22:24.110 --> 22:27.150] They will send this exploit towards your computers. [22:27.470 --> 22:28.290] They will get a shell. [22:28.510 --> 22:35.710] And after that, they will type the very funny command, you name dash A, and say, oh, okay. [22:36.050 --> 22:37.430] Now, I want to be rude. [22:37.650 --> 22:48.330] And so, they will go on the web server with services, giving them exploits to, for example, abuse, bugs in the kernel, and stuff like that. [22:48.690 --> 22:53.870] So, that's funny, because the black hat didn't know that he was spied. [22:56.050 --> 22:56.990] Another question. [22:58.050 --> 23:01.610] This is very difficult to buy back incoming clients. [23:02.370 --> 23:05.810] Because, for example, you have two kinds of clients. [23:06.050 --> 23:11.250] You have what I have called list link clients, like mail clients, etc. [23:12.170 --> 23:15.570] This is very easy, because you have multiple times. [23:15.790 --> 23:21.010] For example, if you want to hack back a mail client, you can send multiple mails. [23:21.010 --> 23:27.830] But, most of the time, people use, for example, incoming clients, like web clients, stuff like that. [23:28.050 --> 23:30.350] And this is a one-shot operation. [23:30.930 --> 23:35.410] And sometimes, the hack back can occur during a specific phase. [23:35.610 --> 23:41.350] For example, during the negotiation of a login password on a FTP server, and something like that. [23:41.830 --> 23:48.770] And also, you need specific information to launch a dedicated attack against the client. [23:48.770 --> 23:51.510] For example, you need to know the operating system. [23:51.830 --> 23:54.210] You need to know the version, and stuff like that. [23:54.850 --> 24:00.970] At the end, this is an example of a hack back of a putty client. [24:01.310 --> 24:03.510] You know, this is SSH for Windows. [24:03.870 --> 24:05.150] That didn't work. [24:05.750 --> 24:10.990] It was trying to launch a remote exec on the client. [24:11.390 --> 24:15.310] So, that's very difficult, but that might exist. [24:16.350 --> 24:19.810] Another question is, is it possible to exploit the exploit? [24:20.710 --> 24:27.210] Imagine someone launching an exploit against you, and you get a shell on the guy, on the script key. [24:27.490 --> 24:28.070] That's funny. [24:30.110 --> 24:34.690] So, the question is, what if there is a vulnerability in the code of an exploit? [24:35.470 --> 24:37.970] You know, like a buffer flow string format. [24:37.970 --> 24:43.710] So, do you here read the code of an exploit before launching it? [24:43.970 --> 24:46.170] I'm pretty sure that the answer is no. [24:46.390 --> 24:51.570] And I'm also pretty sure that the answer is, I don't read the payload, also, most of the time. [24:51.970 --> 25:00.350] And you know, some people put funny stuff in the payload, like format the remote host, or format the local host, or something like that. [25:00.590 --> 25:05.390] So, script kiddies don't understand the sources of the exploit they use. [25:05.390 --> 25:16.490] We can see sometimes on the Internet, people coming on IRC saying, when I launched the dcomexploit.c, it did not work. [25:16.670 --> 25:17.530] What can I do? [25:17.950 --> 25:19.030] Did you compile it? [25:19.490 --> 25:20.070] Compile? [25:20.450 --> 25:21.130] What do you mean? [25:21.490 --> 25:21.710] Okay. [25:22.150 --> 25:23.070] Go away. [25:23.830 --> 25:28.090] So, I'm pretty sure that script kiddies don't understand the exploits they use. [25:28.390 --> 25:31.850] And if you look at the code, sometimes you can see exploits. [25:31.850 --> 25:35.250] But, this is like for the web client and stuff like that. [25:35.330 --> 25:36.190] This is very difficult. [25:37.530 --> 25:44.450] If you look at automatic tools used to launch remote attacks, or audit, they are written properly. [25:44.690 --> 25:57.550] For example, if you look at Nessus, they created something which is called NESL, to get something like a small sandbox, while launching security probes. [25:57.550 --> 26:02.270] And also, for Core Impact, which is a very cool tool, this is written in Python. [26:02.830 --> 26:09.570] And also, they have something like, a use of small privilege, and some kind of sandbox. [26:10.090 --> 26:14.490] And they probably did that because they know that there is a risk. [26:14.990 --> 26:16.750] So, that might exist also. [26:17.350 --> 26:18.410] What about scanners? [26:18.950 --> 26:25.510] There are many kinds of scanners that are used in the wild, like network layers, banners, security tests. [26:25.510 --> 26:29.590] And some of them are poorly designed from a security point of view. [26:29.790 --> 26:31.390] And might lead to insecurity. [26:32.650 --> 26:38.410] We saw, my friend, we saw buffer the flow possible, and for my strings, against scanners. [26:38.590 --> 26:40.370] For example, we saw scan... [26:40.370 --> 26:45.630] I won't give the name, because of the MCA restriction and stuff like that. [26:45.810 --> 27:01.710] But we saw scanners, for example, trying to get... to grab your banner of your FTP server, and waiting for something which had 1,024 bytes. [27:02.010 --> 27:02.110] Okay? [27:02.750 --> 27:09.170] And if your FTP server had a very big banner, you know... [27:09.170 --> 27:12.850] I am a FTP server, FTP server, FTP server, FTP server, FTP server, FTP server. [27:13.790 --> 27:16.430] And... which was too big. [27:16.430 --> 27:21.950] You had a possibility to make a buffer overflow on the client, on the scanner. [27:22.210 --> 27:28.670] So that's quite funny, because this is a reverse of this usual game on the Internet. [27:28.970 --> 27:33.450] And also, we saw some reports badly generated. [27:33.870 --> 27:39.590] For example, with HTML, including banners grab on the target without checking data. [27:39.590 --> 27:46.650] So you could put, for example, a banner from your FTP server, with a JavaScript code inside of it. [27:47.430 --> 27:57.950] And when the evil script kiddie was trying to look at the security reports, you could launch code on his computer. [27:58.630 --> 27:59.870] And that's quite funny. [28:00.670 --> 28:03.490] So, for scanners, that might be possible. [28:04.030 --> 28:06.250] What about clients of Triana Horses? [28:06.750 --> 28:10.230] What if there is a vulnerability in the code of a Triana Horses client? [28:10.850 --> 28:18.410] How many times here, administrators, did you get an incoming prompt for Triana ports toward your internal network? [28:18.650 --> 28:22.550] For me, that's every day, every day, every day, every hour. [28:23.110 --> 28:25.070] We have so many probes. [28:25.070 --> 28:36.190] So, imagine an evil honeypot that would be able to answer to the client and say, Yes, I am a Triana Horses server. [28:36.350 --> 28:37.750] I'm waiting for your orders. [28:38.530 --> 28:39.810] What should I do? [28:41.130 --> 28:43.430] Then a counter-attack might be possible. [28:43.990 --> 28:47.090] Here is an example, a technical example with HoneyD. [28:47.330 --> 28:49.530] That's why I showed you HoneyD at the beginning. [28:50.150 --> 29:03.630] By adding a very easy line of configuration, which is add-template-tc-people-12345, launch the fake Netbus Perl script, which is in the back. [29:04.310 --> 29:07.890] You add a Netbus service on your fake computer. [29:08.590 --> 29:18.890] And here is the code of a fake remote Netbus server that will answer to the client. [29:19.190 --> 29:25.090] And as you can see, when the client connects, he just says, Yes, I am a Netbus server 1.6. [29:25.690 --> 29:27.090] Which means, what should I do? [29:27.310 --> 29:32.050] And if the client, for example, clicks on the button, I choose Get Info. [29:32.190 --> 29:34.090] But I could do it for every button. [29:36.610 --> 29:49.610] Then, the fake Netbus server sent, for example, 100,000 A, and was waiting for the answer of the client. [29:49.950 --> 29:52.110] And here is what happened. [29:52.750 --> 29:55.310] So, first, the Netbus client is connected. [29:55.310 --> 29:58.610] So, you can imagine the script kitty. [29:58.770 --> 29:59.110] Hey, yeah. [29:59.610 --> 30:00.350] Yeah, okay. [30:00.470 --> 30:01.290] I got one. [30:01.450 --> 30:02.210] I got a new one. [30:02.690 --> 30:04.950] I found a Netbus server on the Internet. [30:05.250 --> 30:14.150] Then, by clicking on the Get Info, as you can see on the picture number 2, the CPU went, increased to 100%. [30:14.150 --> 30:21.950] And then, few seconds after that, as you might see, this is an undefined state for the Netbus client. [30:22.390 --> 30:22.970] Okay? [30:23.450 --> 30:27.170] So, this is not something like, you get a shell on the attacker. [30:27.550 --> 30:32.130] But, you killed the application that tried to attack, for example, your company. [30:32.570 --> 30:38.890] So, I don't know if this can be called proportional answer. [30:39.110 --> 30:41.610] But that's very interesting from a technical point of view. [30:42.070 --> 30:46.650] I think that the script kitty was afraid when he saw that. [30:48.710 --> 30:52.830] So, another question is, is it possible to fight back worms? [30:53.150 --> 30:58.930] For example, imagine, in your company, on your internal network, you have a very big problem like a worm. [31:00.390 --> 31:09.290] Remember, sadly, summer last year, we've decom exploit and the MS Blast worm. [31:10.010 --> 31:15.010] It was very horrible for many companies in the world. [31:15.010 --> 31:18.550] So, the question is, is it possible to fight back worms? [31:18.910 --> 31:21.710] So, this is something I wrote in Security Focus. [31:21.970 --> 31:23.490] You can find it. [31:23.650 --> 31:29.350] I wrote a paper on securityfocus.com, which was called Fighting Internet Worms with Honeypots. [31:29.530 --> 31:35.190] And also, I made a presentation during the Black Hat in Asia, Singapore, on that subject. [31:35.430 --> 31:40.970] But, to show it very fastly, here is a theory. [31:41.590 --> 31:46.230] Imagine, we have a worm called W, that comes... [31:46.690 --> 31:47.870] W is for worm. [31:48.130 --> 31:49.290] It's not for something else. [31:49.990 --> 31:52.110] I'm not talking about political things. [31:52.110 --> 31:52.390] Okay? [31:52.990 --> 31:59.490] So, a worm called W comes from a host called A to a host called H. [31:59.670 --> 32:01.090] H because this is a honeypot. [32:01.250 --> 32:04.010] I say that for people who are sleeping. [32:04.670 --> 32:04.770] Okay? [32:06.170 --> 32:09.430] So, A is infected by W. [32:09.790 --> 32:10.110] Okay? [32:10.630 --> 32:17.430] Because A is trying, for example, to propagate itself to H. [32:17.650 --> 32:17.950] Okay? [32:18.670 --> 32:24.490] So, A is, or was, it might depend, vulnerable to the attack used by the worm. [32:25.370 --> 32:27.750] So, A may still be vulnerable. [32:29.090 --> 32:33.910] What if H, the honeypot, attacks A through this vulnerability? [32:34.910 --> 32:41.310] It means that the honeypot can take control of the host that is infected by the worm. [32:41.610 --> 32:54.070] So, what if the honeypot takes control of the host infected by the worm by using this vulnerability and try to clean the host, to patch the host, and to harden the host and, for example, to reboot. [32:54.370 --> 33:00.690] Then, only with one honeypot, you can clean thousands and thousands of computers. [33:01.030 --> 33:05.630] The trouble is, as I said, is it's legal. [33:06.450 --> 33:15.610] We can say that, for example, when I wrote that, I was also Slashdotted because of that. [33:17.050 --> 33:19.990] People said, this is forbidden to hack back. [33:20.270 --> 33:27.650] I said, yes, this might be forbidden, but on your legal, on internal network, you can play with that. [33:27.850 --> 33:34.010] And you can save hours and hours by just a few lines of code. [33:34.550 --> 33:48.430] For example, those are lines of code with HoneyD to... this is a proof of concept that show... that shows how to file off, and even file back, an MS Blast worm on a network. [33:48.930 --> 33:49.990] That's very easy. [33:50.730 --> 34:00.090] You just have to say, I want to launch this script when a worm is trying to... when MS Blast is trying to come on my computer, my honeypot. [34:00.310 --> 34:02.270] And then, here is the code. [34:02.350 --> 34:17.830] The code is just, okay, send a naval exploit towards the incoming worm infected computer, and then you have a shell, and then you try to... this is for XP, Windows XP. [34:18.050 --> 34:22.170] You try, for example, to task kill the MS Blast.exe process. [34:22.610 --> 34:25.470] Then you try to delete the file of the worm. [34:25.770 --> 34:31.150] Then you try to clean the registry, then you try to reboot the host, and stuff like that. [34:31.370 --> 34:33.450] So as you might see, this is very easy, okay? [34:34.890 --> 34:36.890] You can do very, very cool thing like that. [34:37.110 --> 34:39.350] What about the wireless threat? [34:41.670 --> 34:44.230] I wrote a paper about wireless honeypot. [34:44.550 --> 34:48.030] It was called Wireless Honeypot Trickery on securityfocus.com. [34:48.210 --> 34:53.990] And I talk about the fact that there are evil honeypots in the wireless world. [34:54.170 --> 34:54.790] Yes. [34:56.150 --> 35:00.390] Sometimes you can see, for example, an official access point with resources. [35:00.950 --> 35:17.970] For example, here, if someone launched something with an SSID, which is HOPE-05, I think, on channel 3, for example, with a very big signal, what will happen, for example? [35:19.090 --> 35:24.030] Some people might think that this is a real network, but it might be a fake one. [35:24.350 --> 35:33.690] So sometimes we can see rogue access points, which are used in the way to attack, to automatically attack clients. [35:34.250 --> 35:44.630] Because the problem, for example, if you take a train, you are a manager, you open your laptop, you don't know that you have a wireless card, for example, in your computer. [35:45.210 --> 35:53.310] And while you are traveling, an evil guy in the train, for example, will launch a fake access point. [35:53.490 --> 36:04.010] And your computer, Windows XP, which is so kind with you, will automatically connect itself to the fake access point and say, I want an IP address. [36:04.210 --> 36:07.810] So the fake access point, we just have, here is your IP address. [36:08.170 --> 36:16.630] And imagine what will happen if, for example, this manager doesn't have a personal firewall on this computer. [36:19.690 --> 36:25.270] Something like LSSS or DCOM exploit and stuff like that will probably work. [36:25.610 --> 36:35.090] And by traveling in only one hour or two hours, all his sensitive data will be taken out from the computer. [36:36.530 --> 36:52.470] And also, we can see in the wireless world, stuff like, wire drivers trying to open access points and stuff, and playing, and trying to create tunneling, and to go, to freely go out on the Internet. [36:53.210 --> 36:59.010] So, there is an example of tool, who knows the tool called NSTX? [36:59.370 --> 36:59.750] Yeah, okay. [37:00.290 --> 37:04.370] And this cool, this is very cool, I don't know how you find it. [37:04.550 --> 37:13.450] This is a very cool tool that allows you to surf, and to use the Internet, with stupid access points without paying. [37:15.310 --> 37:24.450] The idea is, most of the time, on some access points, you have the right to do DNS queries. [37:25.110 --> 37:32.090] What if you query your own DNS server somewhere on the Internet? [37:33.470 --> 37:46.490] And use not really real questions of DNS, but specific DNS questions, which are, in fact, IP over DNS. [37:47.410 --> 37:48.690] And it exists. [37:48.990 --> 37:50.430] This is called NSTX. [37:50.650 --> 37:52.770] And this is very easy to use. [37:52.970 --> 38:08.430] So, when we looked on that, with my friends from the team, RST-ACK, we found that this server could be crashed remotely, with a AVL on ePort, with something like, only one line of per. [38:09.450 --> 38:10.650] So, that's very easy. [38:11.050 --> 38:14.870] It was for the first version of NSTX. [38:15.390 --> 38:19.290] This is just to show you that there is a threat, or there was a threat. [38:19.290 --> 38:22.970] The threat was, what if people use something like NSTX? [38:23.390 --> 38:34.650] And by working on the tools used by your enemy, you can find vulnerabilities, and easily create your own possibilities to fight off. [38:37.650 --> 38:41.630] So, now, let's look at what can be done in the Honeypot. [38:41.870 --> 38:46.250] For example, sometimes, people try to steal files in your Honeypot. [38:46.950 --> 38:47.630] Okay? [38:48.490 --> 38:51.630] So, what if the GIFs are trapped? [38:51.810 --> 38:58.630] For example, what if an attacker will download, read, and launch, for example, tools from your Honeypot? [38:58.810 --> 39:01.910] Like, evil .exe, or evil .doc files? [39:02.630 --> 39:27.550] So, imagine, if you put something like, I don't know, Brittany.mp3, or Brittany.exe, or something like that, if this is a young attacker, he will probably take the file and bring it back to home to show, and to look at it with his friends on Saturday night. [39:27.790 --> 39:30.310] Hey, look, I got a Brittany.exe file. [39:30.470 --> 39:31.390] That might be cool. [39:31.730 --> 39:32.350] Yeah, that's cool. [39:32.430 --> 39:32.850] Launch it. [39:35.650 --> 39:51.890] And there is a pattern, technology, which is coming from a commercial product, which is called Spectre 7, that would add markers on the attacking host for potential trial. [39:52.070 --> 39:53.670] But I've never tested it. [39:54.090 --> 39:56.910] So, we could imagine something like... [39:56.910 --> 40:00.950] This is an exploit written by someone from my team. [40:02.470 --> 40:12.630] He wrote an exploit that allows you to get a remote shell on someone looking at a Word document that you gave him. [40:13.250 --> 40:27.490] So, imagine, you create something called superclassify.doc file in a .secret directory, and you just have to wait that the script kiddie take it and read it at home. [40:28.430 --> 40:29.210] That's funny. [40:29.550 --> 40:31.670] You can get a shell on the guy. [40:32.570 --> 40:37.450] So, some people talk about the possibility for the RAA Honeypot. [40:40.810 --> 40:47.310] Okay, I won't comment it, because I don't want to have a problem. [40:48.810 --> 40:54.650] As you can see on the Internet, on securityfocus.com, there is something written by Goebbels. [40:54.810 --> 41:00.510] They said, we focus on creating very warm hybrids to infect and spread over P2P nets. [41:02.470 --> 41:06.990] So, the question is, steal this album, does it mean, be compromised? [41:07.330 --> 41:07.990] We don't know. [41:09.630 --> 41:20.930] This might be something... I mean, Honeypot to fight back might be something that will be used by people that want to fight P2P clients and stuff like that. [41:21.190 --> 41:25.070] So, I won't say this is wrong or this is not wrong. [41:25.330 --> 41:29.470] I'm not here for political discussion, but just technical discussion. [41:30.510 --> 41:34.490] So, let's talk about monitoring the trap, and we're going to have fun. [41:37.450 --> 41:45.690] So, something that might be very useful for you is trying to do... to trust back the attacker. [41:46.030 --> 41:49.190] So, you want to gather extended information about the attacker. [41:50.650 --> 41:53.570] This might be very useful on local network. [41:53.810 --> 42:16.870] If there is not too much filtering on your internal network, sometimes, if you see a ZLO trainee or someone on your network, for example, by just requesting or just asking questions to remote service, you will be able to find extended information about the attacker or the guy who is trying to play on a network. [42:17.230 --> 42:21.070] For example, you can use stuff like finger users identity. [42:21.070 --> 42:28.330] Here is an example with HoneyD, a smaller industry to query a remote identity. [42:28.690 --> 42:35.470] You can ask, for example, a NetBIOS server who is connected to this computer and stuff like that. [42:35.630 --> 42:37.790] But that's very easy, that's very simple. [42:38.630 --> 42:41.290] But there are also some other possibilities. [42:42.370 --> 42:51.710] If you try to look at network possibilities, you will see that you can do advanced backtracking. [42:52.030 --> 42:55.710] For example, you can do active or passive fingerprinting with Honeypot. [42:56.050 --> 43:02.750] Most of the time, people talk about passive operating system fingerprints. [43:02.750 --> 43:09.170] For example, with tools like HoneyD, like Puff, or Nevo, which is a commercial tool, very useful. [43:09.890 --> 43:11.750] Or tools like Cronores, etc. [43:12.150 --> 43:17.470] You can do what is called, for example, sometimes passive operating system fingerprints. [43:17.750 --> 43:21.350] Because you want to gather the more information you can on the attacker. [43:22.030 --> 43:22.170] Okay. [43:23.630 --> 43:31.330] So, here is a very easy example of innovative active fingerprints, but that's very easy. [43:31.330 --> 43:36.770] You just have to play with what is called the close weight fingerprint, HoneyD fingerprint. [43:37.110 --> 43:39.910] And this is an example with HoneyD, how to do that. [43:40.450 --> 43:41.930] I don't have so much time. [43:42.630 --> 43:44.270] I will let you look at the slides. [43:44.470 --> 43:48.630] The slides will be available online on my website, rstck.org. [43:50.650 --> 43:53.750] So, to finish with a funny story. [43:53.970 --> 43:56.150] Here is the Truman Show Honeypot. [43:56.630 --> 43:59.590] So, the elite are inside the Honeypot. [44:01.430 --> 44:04.170] So, sometimes people want to talk with strangers. [44:04.770 --> 44:11.670] Like, you know, we are always saying, know your enemy, you know, like Tsun Tzu book. [44:11.910 --> 44:16.390] So, if you want to know your enemy, one of the best ways is to talk with the enemy. [44:17.790 --> 44:24.210] Just go to the show of Kevin and listen to playing with deception with people and that's going to be fun. [44:25.030 --> 44:28.270] Usually, Black Hat get access, play and go away on your host. [44:28.530 --> 44:31.090] You don't have any opportunity to interact with them. [44:31.330 --> 44:32.950] But you would like to talk with them. [44:33.190 --> 44:33.890] So, what can you do? [44:34.170 --> 44:34.850] That's funny. [44:35.090 --> 44:37.090] You can initiate discussion with the attackers. [44:37.650 --> 44:40.170] For example, to do human technical fingerprint. [44:40.550 --> 44:41.550] Get more proofs. [44:41.750 --> 44:42.850] Profile the attacker. [44:43.410 --> 44:44.150] Get the location. [44:44.850 --> 44:45.590] Do exchanges. [44:46.250 --> 44:46.850] Have fun. [44:47.070 --> 44:47.250] Whatever. [44:47.250 --> 44:52.370] So, you can use classical tools like write, talk, IRC, ICQ and stuff like that. [44:52.730 --> 44:55.650] But, on the honeypot, this might be very easy. [44:56.050 --> 44:57.390] For example, you want... [44:57.390 --> 45:04.350] If you want to play with social engineering, with human aggressors, you can fool the attackers on your own computer. [45:04.750 --> 45:08.850] You can come and talk with the intruders and say, Hi kid, I hacked this box too. [45:09.270 --> 45:10.150] I want to share stuff. [45:10.430 --> 45:13.110] I have root access everywhere and stuff like that. [45:13.910 --> 45:16.770] The intruder will try to guess where you are from. [45:17.090 --> 45:17.170] Okay? [45:17.930 --> 45:28.210] And if the discussion is on the honeypot, the intruders will play with tools like Netstat, Who, W, PS, stuff like that. [45:28.630 --> 45:28.790] Okay? [45:29.310 --> 45:33.310] But, as this is your honeypot, you control the honeypot. [45:33.470 --> 45:34.290] This is your show. [45:34.630 --> 45:34.730] Okay? [45:34.730 --> 45:36.850] So, you can change everything. [45:37.130 --> 45:42.810] Everything like the incoming IP address of your computer coming to your honeypot. [45:44.170 --> 45:51.510] So, you just have to, for example, put a filtering computer that will change your incoming IP address with Net. [45:52.110 --> 45:57.570] And you can change it to spoof and to say that you come from a local LAN. [45:58.470 --> 46:04.810] While coming from a local LAN, you can look like being coming from a .cn, .eru, whatever. [46:05.210 --> 46:05.310] Okay? [46:06.170 --> 46:07.310] So, this is very easy. [46:07.470 --> 46:09.490] On your gateway, you just have to use Net. [46:09.710 --> 46:15.430] And say, on the gateway, you just have to change your IP address, incoming IP address. [46:15.650 --> 46:19.050] And you can say, claim that you come from wherever you want. [46:19.050 --> 46:28.510] If you want to say that you come from, I don't know, wildeyes.gov, you can change the IP address, and the guy will think that you are really coming from that. [46:28.850 --> 46:37.690] Here is a small script from the French Honeynet project, which is part of the Honeynet Alliance, which is a Truman Show Honeypot Proof of Concept. [46:38.170 --> 46:41.490] As you might see, this is just with IP tables to change the IP source. [46:41.490 --> 46:42.530] This is very easy. [46:42.670 --> 46:47.410] And here are logs coming from one of our Honeypots. [46:48.030 --> 47:00.610] So, the Black Hat that came on our Honeypot installed a small bot, IRC bot, to bounce to an IRC private server of themselves. [47:01.150 --> 47:13.030] And we went from the Honeypot on their IRC server and initiated a discussion and say, Hello. [47:13.850 --> 47:14.630] And I said, Hi. [47:14.810 --> 47:16.830] I found this computer before you. [47:17.990 --> 47:19.650] The guy said, I know. [47:19.970 --> 47:20.730] I said, How? [47:21.010 --> 47:23.730] And he said, I did it faster than you. [47:24.230 --> 47:26.630] I said, Okay, let's try where I am from. [47:27.090 --> 47:28.370] You know, that's the trick. [47:28.810 --> 47:30.950] He said, France, because the Honeypot is in France. [47:31.210 --> 47:32.150] And I said, No. [47:32.150 --> 47:39.870] So, the intruder, very skilled, launched a netstat-n to see who was really there. [47:40.090 --> 47:40.430] Okay? [47:40.930 --> 47:45.830] And he got my fake IP address changed by the NAT. [47:46.230 --> 47:48.710] And saw that it was coming from Singapore. [47:49.090 --> 47:50.250] And he said, Singapore. [47:50.590 --> 47:51.950] I said, Of course. [47:52.210 --> 47:55.250] Which means, welcome, in the Truman Show, Honeypot. [47:55.490 --> 47:56.050] Okay? [47:56.050 --> 48:04.330] And it was quite funny because after a few minutes of discussion, I knew that they had fingerprinted that it was a VMware. [48:05.430 --> 48:10.410] And I knew that they were trying to crash the hard drive on my Hominypot. [48:10.630 --> 48:21.390] And also, I understand very easily that they were trying to, for example, abuse of this read on my system and stuff like that. [48:21.390 --> 48:24.250] So, that might be very funny to play like that. [48:25.250 --> 48:26.110] Here is a conclusion. [48:26.950 --> 48:29.970] There are other fields of interest, but we don't have so much time. [48:30.210 --> 48:34.150] Some people try to do something which is called boomerang effect. [48:34.390 --> 48:39.650] You proxy the aggression of the attacker back to the aggressor, which might be funny, and stuff like that. [48:39.790 --> 48:41.190] Audit the auditor and stuff like that. [48:41.750 --> 48:41.930] Okay. [48:42.790 --> 48:50.610] In brief, Honeypot might play a role for retaliation, counter-attack or play with an aggressor by using specific self-defense techniques. [48:51.270 --> 48:55.290] We talk about active defense, counter-misor, counter-attack, stuff like that. [48:56.050 --> 48:58.010] Sometimes, you can get a remote control. [48:58.310 --> 49:00.570] You can trap the attacker with poison gift. [49:00.730 --> 49:02.270] You can gather more information. [49:02.630 --> 49:04.870] You can crush the tools used by the attackers. [49:05.470 --> 49:07.730] For white hats, when this is legal, okay? [49:08.070 --> 49:08.310] I said. [49:08.970 --> 49:11.970] This might be useful to buy back aggressors. [49:13.510 --> 49:16.030] For example, on your own land, I said. [49:16.250 --> 49:18.870] That might be very useful. [49:18.870 --> 49:26.690] For black hats, I must agree that this might be a new way to passively attack incoming visitors. [49:27.250 --> 49:34.190] And I know that guys from East Europe use my techniques to fight off MS blasts. [49:34.350 --> 49:39.290] In order to get thousands and thousands of shells in August, last August. [49:39.290 --> 49:39.910] Okay? [49:40.570 --> 49:49.950] But something which is something like, biting back the aggressor could be called the 69 attack. [49:50.410 --> 49:50.970] Okay? [49:52.010 --> 49:58.610] And as you might know, don't play 69 with someone you don't know, okay? [49:59.930 --> 50:02.050] So, is it a future technology? [50:02.230 --> 50:02.570] I don't know. [50:02.850 --> 50:04.810] Will we have future law for that? [50:04.810 --> 50:07.670] Or will it be integrated in our culture? [50:07.890 --> 50:08.330] I don't know. [50:08.770 --> 50:09.370] We might see. [50:10.130 --> 50:10.650] So... [50:10.650 --> 50:11.010] Okay. [50:11.250 --> 50:12.190] Thank you very much. [50:12.790 --> 50:13.310] And... [50:13.870 --> 50:15.450] Thanks for your attention. [50:17.130 --> 50:24.670] I would like to thank Dragos, because he let me show that, and it's coming from my previous conference. [50:25.210 --> 50:27.330] If you have any questions, just come on. [50:37.920 --> 50:38.480] Yes? [50:38.780 --> 50:45.240] Are there any distributions already set for a Honeypot on your website or anywhere on the Internet? [50:45.500 --> 50:45.760] Yes. [50:45.820 --> 50:54.860] The question is, because you should talk in the mic, are there ready distribution to play with Honeypot? [50:55.080 --> 50:55.420] Yes. [50:55.540 --> 50:56.220] The answer is yes. [50:56.700 --> 51:10.180] Just come on the website, www.honeynet.org, and there is a new CD-ROM that will help you at creating very easily Honeypot just with one CD-ROM. [51:10.820 --> 51:15.060] With this CD-ROM, you will be able to create Honeypot in your company very easily. [51:15.520 --> 51:20.260] So, just download it, launch it, you have the documentation, and that's very easy. [51:25.160 --> 51:25.680] Okay. [51:26.620 --> 51:27.540] Another question? [51:28.560 --> 51:44.580] If you, for example, if you want to talk about that with me, just write down my email address, or ask the organizers, they will give my address, and it will be a great pleasure for me to share my ideas. [51:44.840 --> 51:47.100] This is why I came here to share my ideas. [51:48.740 --> 51:49.260] So... [51:49.260 --> 51:49.860] Okay. [51:50.520 --> 51:51.040] Okay. [51:51.300 --> 51:52.000] Thank you very much. [51:52.140 --> 51:52.700] Have fun.