[00:00.000 --> 00:03.740] What we do, they all have, basically, weaknesses that you can exploit. [00:04.360 --> 00:08.400] And when I say a weakness, it doesn't necessarily mean that there's some, like, server they have that you can break into. [00:09.020 --> 00:12.520] It means that, like, there are certain ways to detect phishing before it ever happens. [00:12.600 --> 00:16.260] There's certain ways to, you know, prevent mirroring of your website, things like this. [00:16.320 --> 00:20.900] And we have a whole box full of, like, these TrackSploits and we can only have so much time to put somebody in this. [00:21.720 --> 00:23.960] So what we're gonna do is we're gonna TrackSploit their weaknesses. [00:24.120 --> 00:25.080] We're gonna give you some case studies. [00:25.080 --> 00:30.300] A lot of TrackSploit techniques, when you're thinking about it, you really have to think of this is not a perfect solution. [00:30.460 --> 00:31.380] It's defense in depth. [00:31.620 --> 00:40.040] Defense in depth is basically, you know, something, for instance, you're looking at all, you know, pieces from cradle to grave to an attack point or an online threat. [00:40.160 --> 00:43.480] And you're saying, are there weaknesses within each piece of the threat? [00:44.160 --> 00:51.560] Any technique that they're using that we could use to, basically, come up with some way to detect certain things or track them or prevent them from doing certain things. [00:52.240 --> 00:53.700] The review of phishing techniques. [00:54.900 --> 00:56.740] How many people actually know what phishing is here? [00:56.920 --> 00:57.520] Raise your hand. [00:57.760 --> 01:00.880] Has everybody got an email from me that says that there's an eBay scam? [01:01.080 --> 01:01.920] I mean, it wasn't for me. [01:02.600 --> 01:04.480] Is there anybody that doesn't know what phishing is? [01:04.600 --> 01:05.020] Raise your hand. [01:05.560 --> 01:06.020] You do. [01:06.060 --> 01:06.520] That's what I thought. [01:06.720 --> 01:06.860] Okay. [01:07.000 --> 01:08.020] But I bet you still fall for it. [01:10.040 --> 01:13.140] So, basically, there's four types of phishing. [01:13.360 --> 01:18.820] And phishing, I group the malware nowadays as phishers because it is still the same individuals that are doing phishing that are also using this malware. [01:19.420 --> 01:22.140] There's an imitate, which is basically you mirror the entire site. [01:22.300 --> 01:23.780] You put it up just like it is. [01:24.120 --> 01:27.860] There's the forward, which means that you're basically putting... you see this with Amazon and eBay. [01:27.960 --> 01:29.440] You see it where it's the actual submit. [01:29.680 --> 01:31.400] The logins are inside the email. [01:32.280 --> 01:34.560] There's the pop-up, which was the best looking thing in the world. [01:34.980 --> 01:39.340] Basically, what happens is the real bank is in the back of the... you know, basically in the browser. [01:39.540 --> 01:43.680] So, it'll say www.somebank.com and then the front is a hostile pop-up. [01:43.780 --> 01:46.800] This is a very good attack due to the fact that it looks very genuine. [01:46.800 --> 01:49.640] And then there's key logging slash form grabbing it. [01:49.720 --> 01:50.840] The real term is form grabbing. [01:51.100 --> 01:53.300] People call it key logging, but we'll get into that. [01:54.540 --> 01:58.380] So, I'm going to kind of skip ahead this one since everybody knows what phishing is, right? [01:59.440 --> 02:03.800] So, basically, we're going to include malware in here as well. [02:03.960 --> 02:13.720] So, I'm going to read the bottom part just to the fact that the main focus we're doing is the website, however, is bogus, hostile, and set up to steal the user's information when they're luring up sites and stuff. [02:13.720 --> 02:17.400] These sites may also contain client-side exploits in conjunction with Trojans. [02:17.920 --> 02:20.640] This also includes new PowerPoint stuff that we're seeing. [02:20.840 --> 02:26.400] The zero-day PowerPoint stuff is used quite predominantly for phishing attacks. [02:27.420 --> 02:29.920] And usually with TrojanSpot and it's another malware. [02:30.320 --> 02:30.660] Oh, my. [02:31.160 --> 02:33.000] So, nice picture there. [02:33.740 --> 02:34.600] Malware analysis. [02:34.760 --> 02:35.620] We're going to go through this real quick. [02:36.300 --> 02:38.280] So, we're basically looking at phishing malware. [02:38.660 --> 02:41.760] I spend a good portion of my days examining this stuff. [02:43.040 --> 02:45.280] Today's phishing groups are pretty scalable. [02:45.880 --> 02:48.060] We're seeing a lot of phishing attacks that have botnets. [02:48.240 --> 02:52.400] They're actually... some of the phishing sites are actually hosted on people's cable modems all over the world. [02:53.600 --> 02:58.100] But the main key element that we're looking at is we were looking at what are the weaknesses that all of these... [02:58.100 --> 03:00.480] What is the same pattern that all of these Trojans are doing? [03:00.600 --> 03:02.380] Well, they're sending it off to a blind drop somewhere. [03:02.380 --> 03:06.900] So, they're stealing this data and they're sending it to somewhere that's, you know, out there in the midst of something. [03:07.140 --> 03:13.160] So, what we do is we spend our days tracking these blind drops and getting all this data back, which we'll kind of go into how to do that. [03:13.520 --> 03:24.140] And our average size of phishing group data that they steal per day for one group is about between 100 and sometimes we see up to 250 megabytes a day. [03:24.700 --> 03:28.840] On average, that's about 16,000 logins per day that are stolen from one phishing group. [03:29.520 --> 03:32.660] On average, it's about 5,000 credit cards that are in that batch. [03:33.960 --> 03:39.600] Since January 2006, Secure Science Corporation has recovered over 2 million cards just from malware. [03:40.440 --> 03:49.080] At $500 on average in California where we are based out of, the FBI has a statutory cost of, you know, the potential loss is $500. [03:49.540 --> 03:51.960] Now, a bank usually puts it at $1,200 to $1,500. [03:52.340 --> 03:54.080] We're going to say $500 according to the FBI. [03:54.080 --> 04:00.720] So, if you look at 2 million cards being stolen from, you know, since the beginning of the year, that's a $1 billion problem collectively. [04:01.560 --> 04:02.980] And that's just what we're capturing. [04:03.360 --> 04:07.140] There's a lot of, you know, malware out there that, you know, we might not see or something like that. [04:07.260 --> 04:09.600] I'm not saying that we don't catch everything, but we don't. [04:10.260 --> 04:10.620] So... [04:10.620 --> 04:12.040] Here's a nice little graph. [04:12.580 --> 04:15.780] This is just a sample of one group and their potential. [04:16.420 --> 04:21.140] So, what we have is a system that basically monitors the blind drops and stuff. [04:21.140 --> 04:23.720] And so, what we've done is basically get a stat. [04:23.880 --> 04:26.820] We don't have a circulation numbers from these banks because they don't talk about that. [04:27.060 --> 04:31.140] But what we have here is basically what we started from was March to June. [04:31.440 --> 04:34.120] We started monitoring blind drops and fishing groups. [04:34.280 --> 04:35.600] And basically, this is one group. [04:35.720 --> 04:36.280] It's a carding group. [04:37.240 --> 04:43.560] And you can see that basically these are the top banks that basically get, you know, the top targeted cards that are getting hit. [04:43.800 --> 04:45.040] So, we started sorting these cards. [04:45.100 --> 04:48.940] And as you can see, there's a very good exponential growth, especially between April and May. [04:49.060 --> 04:50.340] It's almost about a 50% growth. [04:51.240 --> 04:56.720] And it basically, the cards estimated over four months was 47,760 stolen cards. [04:57.760 --> 05:01.780] So, over four months, that's a loss of 23,880,000. [05:03.300 --> 05:07.520] So, it's... you can see that one fishing group makes about approximately 5.5 million a month. [05:09.140 --> 05:10.760] I know we're in the wrong business, I tell you. [05:12.000 --> 05:13.320] So, how the heck do we know this? [05:13.420 --> 05:18.080] So, I kind of explained it a little bit, but we're going to kind of go through one of the most popular rootkits out there. [05:18.420 --> 05:19.440] It's written in assembly. [05:19.580 --> 05:20.520] It's called Hackstore. [05:20.980 --> 05:23.460] It's also... real name is actually A311 Death. [05:23.680 --> 05:24.360] And it's by Corpse. [05:24.740 --> 05:26.780] Real name we actually know, but we can't say publicly. [05:28.540 --> 05:30.540] So, basically, it's a rootkit. [05:30.980 --> 05:31.940] It's a Trojan. [05:32.140 --> 05:33.440] It utilizes farming. [05:33.560 --> 05:37.480] We're seeing the newer advanced versions, 4.8 and above, are using farming techniques. [05:37.660 --> 05:40.360] So, they're even defeating SSL, such things like that. [05:40.800 --> 05:45.540] And they're also doing form grabbing, which if anybody doesn't know what form grabbing is, we're going to go into that. [05:45.740 --> 05:46.920] And so, just be patient. [05:47.120 --> 05:48.780] But, it's kind of like key logging. [05:49.240 --> 05:50.900] To steal user data from client machines. [05:51.180 --> 05:52.960] It's very popular by Russian Fishers. [05:53.140 --> 05:56.680] It's sold actually for about... I think it was $250. [05:56.880 --> 05:59.220] And then he has another version that's actually sold for $2,500. [06:00.180 --> 06:00.540] Okay. [06:00.700 --> 06:02.160] So, this is what the Fishers are seeing. [06:03.060 --> 06:06.140] This is basically... this is an older version, but he has a demo version. [06:06.140 --> 06:07.800] So, people can try it out and play with it. [06:08.420 --> 06:09.820] And it's a Trojan creation kit. [06:09.980 --> 06:16.880] So, they can actually get licenses of 5 or 10 permutations by just hitting save and putting their blind drop in and hitting save and go. [06:17.080 --> 06:20.360] And then basically, you know, it will permutate every time with a new FSG packing. [06:20.860 --> 06:22.040] So, we'll go into that. [06:22.200 --> 06:24.040] So, basically, you can see all the possibilities here. [06:24.200 --> 06:28.400] And the newer versions out there have even a lot more capabilities than this. [06:28.520 --> 06:33.640] But this is kind of like... it looks like the... you know, Back Orifices and the NetBuses and stuff like that. [06:33.740 --> 06:35.080] But the actual Trojan is very good. [06:35.180 --> 06:36.380] It hides itself from processes. [06:36.380 --> 06:38.340] It does a very typical rootkit stuff. [06:39.200 --> 06:39.560] Okay. [06:40.000 --> 06:42.640] So, they're basically sending it off to some site. [06:42.780 --> 06:45.100] Now, we get kind of lucky sometimes and they'll have an open directory. [06:45.460 --> 06:48.480] And so, this is an older one that was a lot smaller. [06:48.640 --> 06:49.840] This is actually back in 05. [06:50.040 --> 06:51.580] I believe... no, it's early 06. [06:51.940 --> 06:58.260] And so, what... what this was is basically... you can see log 12 dot text, log 13, log 14, log 15 dot text. [06:58.440 --> 07:01.920] A lot of times when they close their... you know, a lot of them have their closed directory. [07:02.100 --> 07:04.520] We still... you have a Perl script that basically can do inference. [07:04.520 --> 07:09.660] And so, we'll actually grab this data, you know, through inference by just... you know, searching through all the dates. [07:09.660 --> 07:10.860] Because it's associated by date. [07:12.620 --> 07:12.980] Okay. [07:13.160 --> 07:14.300] So, tricks for autoanalysis. [07:14.440 --> 07:17.000] So, when we get Hackstore, which... since it's so popular... [07:17.000 --> 07:19.520] and there's different variants of this all the time. [07:19.620 --> 07:21.380] The code base and stuff is not much different. [07:21.380 --> 07:27.820] But the packing and the permutation, it doesn't get... every time one's released, a virus company has to know about this binary to basically make a signature. [07:28.400 --> 07:36.480] So, you know, we actually have a system in place that can get a blind drop recovery within 30 seconds when we receive the malware or your meal is free. [07:37.540 --> 07:40.960] So, what we do... and we want to show you guys how to do it so that you don't have to sit there. [07:41.020 --> 07:43.460] Because we've done all the reverse engineering of the actual malware. [07:43.740 --> 07:47.100] And we're saying, okay, how can people in incident response or people want to do this? [07:47.280 --> 07:50.000] So, what we recommend is having a VMware set up, of course. [07:50.200 --> 07:56.340] And what we do is because of the way it actually hooks into IE, browser helper objects... this one's not a browser helper object. [07:56.340 --> 08:01.160] It's actually a COM object and it's a Win INET.DLL, Win32 API injection. [08:01.520 --> 08:08.580] But any of that stuff, basically, if you take IE HTTP headers, which is a free tool for IE, it's just to basically... it's kind of like live HTTP headers. [08:08.940 --> 08:12.080] So, basically, what will happen is you can see all the headers going by. [08:12.820 --> 08:18.860] The actual rootkit actually uses IE as the agent to actually send it because it uses HTTP send request A function. [08:19.120 --> 08:27.540] So, what happens is that we just sit there, we basically infect ourself, we open up IE and the first thing it does is in it to the blind drop and we see it in the headers. [08:28.380 --> 08:34.780] So, all the encryption in the world that they have built into their malware doesn't really stop anybody and we don't have to use ethereal or anything like that. [08:35.240 --> 08:38.020] So, we basically, within 30 seconds, can locate the blind drop. [08:38.160 --> 08:43.040] We can monitor it and mirror it and mitigate this because what we'll do is send it to banks, you know, and send them their data. [08:44.260 --> 08:46.740] So, in this result, we basically get dead on arrival. [08:46.820 --> 08:52.940] The minute they're sending it out because the average phishing group that does this kind of malware takes about two weeks before they start using this data. [08:53.320 --> 08:57.740] They usually do a set of, like, about a few infections, send it the same blind drops. [08:57.840 --> 08:59.160] We're monitoring it, stuff like that. [08:59.380 --> 09:01.900] We return it to, you know, banks and customers and such. [09:02.080 --> 09:13.280] And so, what happens is they're, you know, not... this is way before they're actually using and stealing this data, so it's more preemptive instead of the fraud scoring where you're waiting for, you know, some activity to occur. [09:13.820 --> 09:18.200] So, in this case, we're actually dealing with real-time fraud mitigation, RTFM. [09:20.960 --> 09:24.040] So, basically, now we're gonna look at the actual malware a little bit. [09:24.740 --> 09:28.260] What we saw in our auto-analysis is that we know it's packed with FSG. [09:28.420 --> 09:29.560] Fast, simple, good. [09:30.860 --> 09:35.440] The question that we have is how many non-malicious executables are packed with FSG? [09:35.720 --> 09:45.360] I'd say probably 0.01% possibly due to the fact that I've never seen something that is non-malicious that's packed with that, but I can't assume that I've seen every binary in the world. [09:45.840 --> 09:49.420] But, in this case, so what we did is we know that it's packed with FSG. [09:49.540 --> 09:51.380] It talks to images.data.php. [09:51.620 --> 09:54.120] Some versions talk to dat7.php and bserve. [09:54.760 --> 10:02.420] A lot of the, you know, if we're looking at a certain group, a lot of them will call it msys.exe, msys.exe, and it's based off of certain exploits because these are exploit kits. [10:03.980 --> 10:07.180] And, basically, what we did was made some bleeding-edge Snort rules. [10:07.600 --> 10:11.340] And what it does is we're actually, we actually made a bunch of them. [10:11.720 --> 10:14.560] But this, we're just, these are the main two ones that are kind of important. [10:14.820 --> 10:18.880] Because what we do is basically we do for in and out, we look for FSG. [10:19.620 --> 10:24.680] And so what this did was we actually tried it on one of our partner ISPs, which is a huge ISP. [10:24.840 --> 10:29.220] And not only did it pick up Hackstore all over the place, within five minutes it got stuff from Brazil. [10:29.420 --> 10:35.960] And no false positives on this because all of the things they picked up were packed with FSG and they all ended up being malware. [10:36.220 --> 10:40.580] So on that network it turned about to basically pick up about 20% of the malware found on that network. [10:42.900 --> 10:47.460] So in the preemptive attack, we basically know how to recover the data. [10:47.560 --> 10:49.420] But how do we actually prevent future form grabbing? [10:50.420 --> 10:53.820] You know, such users get infected, you know, they log in and stuff. [10:53.920 --> 10:56.940] What if we don't ever see this, you know, the binary? [10:57.220 --> 10:59.220] And so, you know, we can't save everybody. [10:59.380 --> 11:00.800] So how do you actually prevent this in the future? [11:01.020 --> 11:03.420] One of our TrackSploits was, what's a weakness that we can do? [11:03.420 --> 11:06.560] What we did was what, you know, Sun Tzu and the Art of War does. [11:06.780 --> 11:07.880] Where we take it to higher ground. [11:08.340 --> 11:10.400] And so instead of basically doing... [11:10.400 --> 11:12.540] Okay, so in form grabbing, just explain this real quick. [11:12.640 --> 11:15.140] Form grabbing is not logging your keystrokes. [11:15.240 --> 11:17.560] It's unscalable for most malware to even try to log your keystrokes. [11:18.400 --> 11:20.840] I've seen maybe about 99% that actually do form grabbing. [11:21.020 --> 11:27.900] And what that is, is when you hit submit in a login, your HTTP header post request is sent to the blind drop. [11:28.200 --> 11:30.920] So all that data is within that post. [11:30.920 --> 11:35.180] So, you know, as you know, scramble pads and all that stuff don't really stop that. [11:35.360 --> 11:38.160] Due to the fact that it's going to still piece it as a proper post. [11:38.400 --> 11:45.320] And so what we do is we set up a thing where basically we exchange a key, ECC key basically to the browser. [11:45.460 --> 11:46.660] The user doesn't even know about it. [11:46.860 --> 11:48.940] And what happens is we encrypt it at the HTML layer. [11:49.080 --> 11:56.220] So if you can see closely at the bottom here where you see this long string, the data still gets to the bad guy, but it's encrypted to him. [11:56.220 --> 11:57.480] So basically to them it's garbage. [11:57.700 --> 11:59.160] So that's one technique we look at. [11:59.280 --> 12:01.500] Okay, all of this malware basically does all this form grabbing. [12:01.680 --> 12:05.160] So we can eradicate the form grabbing problem rather quickly and force them to evolve. [12:05.340 --> 12:06.260] Which usually takes a good while. [12:08.320 --> 12:09.200] So, anyway. [12:09.460 --> 12:11.360] Now we're going to go into some hot log stuff. [12:12.080 --> 12:15.820] A lot of malware that's out there and phishing stuff. [12:15.940 --> 12:20.900] It uses hotlog.ru to actually keep track of the people that are connecting and getting infected. [12:21.500 --> 12:24.660] And so we saw Russian groups using hotlog.ru. [12:24.960 --> 12:29.400] And if you go to hotlog.ru, you can see an examples, you know, view stats page. [12:29.640 --> 12:31.900] It would be like view stats slash ID 23052. [12:32.260 --> 12:32.660] Okay. [12:32.800 --> 12:36.820] And it just says, you know, it shows you some bogus stats and everything like that. [12:37.060 --> 12:41.380] The funny part is, is that we have the IDs that are inside the malware or inside the phishing sites. [12:41.520 --> 12:52.120] And so for some reason, even though they have logins and passwords, if I put in the ID that actually is the bad guy's ID, it doesn't ask me for a password and gives me the full stats for that. [12:52.640 --> 12:57.740] So basically in this case, we had actually a case, one of the first phishing targets that ever came out back in 03. [12:58.860 --> 13:02.080] On our banking scam revealed, which is on the security focus site. [13:02.740 --> 13:06.760] That basically we were able to track down preemptively the tester a week earlier. [13:07.520 --> 13:10.960] Due to the fact that you can go back and you can look at all the basically the access. [13:11.180 --> 13:13.880] And so what will happen is you'll see 50 like hits. [13:14.240 --> 13:16.920] You know, how many times is one user going to get infected by this? [13:16.920 --> 13:22.140] Probably once, you know, and we're seeing 50 hits and then the IP address happens to be from Ukraine or something. [13:22.480 --> 13:24.080] You know, most likely that's the testers. [13:24.360 --> 13:27.800] So basically what's happening is we're capturing victim zero using hot logs. [13:27.920 --> 13:29.960] So we can actually track, you know, the phisher. [13:30.100 --> 13:42.500] And in the scam that was doing, in the banking scam revealed article we wrote, we were able to track a week earlier some, the scam kit developer who was in type outs corner Delaware and she sold it to these Russians. [13:42.880 --> 13:46.840] And scam kit developers, actually a lot of them are in the United States because there is no risk for them. [13:46.840 --> 13:50.940] And they sell it overseas because it's not technically illegal for them to make a scam kit. [13:51.060 --> 13:53.240] It's only illegal for them to actually use it in a fraud. [13:54.580 --> 13:56.060] So basically we are able to find that. [13:56.140 --> 13:58.880] We can also track the referrers, see who's connected, all this stuff. [13:58.980 --> 14:00.440] So we get a lot of stats with this stuff. [14:00.680 --> 14:02.500] And so we can read the bad guy's stats as well. [14:03.200 --> 14:03.920] Fun with IRC. [14:03.920 --> 14:03.940] All right. [14:04.240 --> 14:07.320] I'm not going to mention the IRC server that's involved in this, but it's been a couple. [14:08.380 --> 14:09.760] You guys ever heard of Daphonic crew? [14:10.120 --> 14:11.700] Raise your hand if you've heard of the Daphonic crew. [14:12.540 --> 14:13.100] Okay, they were the guys... [14:13.100 --> 14:13.800] Paris Hilton hack. [14:14.000 --> 14:14.660] Paris Hilton. [14:14.820 --> 14:15.380] Did you hear about anybody? [14:15.580 --> 14:16.900] Raise your hand if you've heard of the Paris Hilton hack. [14:16.920 --> 14:17.240] There we go. [14:17.340 --> 14:18.840] How about the LexisNexis hack? [14:19.320 --> 14:19.800] Raise your hand. [14:20.280 --> 14:20.520] Okay. [14:20.620 --> 14:22.340] So we accidentally discovered these guys. [14:22.500 --> 14:24.640] We were actually tracking a virus distributor. [14:25.360 --> 14:31.120] We ended up going to irc.daphonic.net in their pound main channel, which happened to be the Daphonic crew, also known as local root. [14:31.520 --> 14:34.640] And so basically what happened is they had cloaking encryption. [14:34.820 --> 14:38.400] Basically, you would see a user at some, you know, this output here. [14:38.720 --> 14:44.240] If you look at the output right here, you'd see, you know, some hexadecimal stuff and dot, and then an X, which is just a labeler. [14:44.920 --> 14:55.340] So what happened here was we were looking at this and we're like, okay, now they're hiding their IP addresses so that they're on IRC, which makes it very difficult if they own the IRC server, because you can't really subpoena them because they're not going to respond. [14:55.540 --> 15:00.260] So basically, you know, so what we did was we looked at the algorithm that was involved in this. [15:00.500 --> 15:03.860] And basically what it was is it's kind of a CRC 32 variant algorithm. [15:04.440 --> 15:05.220] So it's linear. [15:05.580 --> 15:07.000] It was a 96-bit key. [15:07.160 --> 15:17.380] So basically function worked, whereas your input was basically a 96-bit key, which was basically three sets of 32-bit words and then the INET address to encrypt, okay? [15:17.540 --> 15:20.940] And the output looked like 2AA, C9, C3E, such and stuff. [15:20.940 --> 15:22.700] So can we track split this? [15:22.840 --> 15:25.620] So looking at the code, here's some irony that was kind of neat about it. [15:26.500 --> 15:35.360] We went in and looked at the code and we saw an area where basically they had a comment that says it had a double XOR going on and it said to stop, you know, crackers. [15:36.120 --> 15:38.880] Now everybody knows what happens when a double XOR occurs. [15:39.180 --> 15:40.940] You basically reverse the operation. [15:41.780 --> 15:43.840] So basically they gave us a 64-bit key to deal with. [15:43.840 --> 15:51.520] And so basically after that, we did a related key and a divide and conquer attack against this, which, you know, you can talk to me after how we did it. [15:51.560 --> 15:52.260] We have a paper on it. [15:52.680 --> 15:57.500] And so basically what we did was basically then reduce the key search space to 0230 time. [15:57.700 --> 15:59.220] Actually, that came out bad on the PowerPoint. [15:59.400 --> 15:59.740] Sorry about that. [16:01.140 --> 16:08.860] And so basically the reduction of search time by a factor of 266, which means that we could break the key within five seconds on an AMD 64. [16:09.580 --> 16:15.240] So now we're looking at the same address and it's now 82.54.152.179. [16:15.520 --> 16:21.540] So that's kind of handy because then we handed that algorithm to the secret service and two weeks later suddenly there's raids on the news. [16:22.500 --> 16:26.000] So I don't know if we had anything to do with that, but they were thankful for the algorithm. [16:26.720 --> 16:28.180] So now IM. [16:28.400 --> 16:32.480] We see a lot of Russians, phishers using Trillion because they think it's secure. [16:32.640 --> 16:34.080] Because it has a secure IM feature. [16:34.800 --> 16:41.160] And Trillion advertised this a while back as 128-bit industry standard encryption. [16:41.920 --> 16:45.280] And so we looked into this without reverse engineering it. [16:45.480 --> 16:46.600] We just looked at the protocol. [16:47.080 --> 16:48.600] And we saw this stuff going by. [16:48.700 --> 16:51.400] And we saw that, you know, they were actually using 128-bit Trillion. [16:51.640 --> 16:54.080] 128-bit primes in Diffie-Hellman. [16:54.820 --> 16:56.300] Does anybody know what Diffie-Hellman is? [16:56.660 --> 16:56.860] Here's your hand. [16:58.160 --> 17:02.680] Does anybody know what the number, the size of the prime should at least start with? [17:03.740 --> 17:04.680] So, okay. [17:04.840 --> 17:07.720] So basically, the standard is group 2, which is 1536-bits. [17:08.260 --> 17:08.320] Okay? [17:08.800 --> 17:11.660] 128-bit prime is vulnerable to a lot of things. [17:11.840 --> 17:16.980] Basically, the way they set their primes up, they did it Sophie Germain. [17:17.100 --> 17:20.380] They were using SSLEA library, which automatically does Sophie Germain prime generation. [17:20.840 --> 17:25.160] But basically, when you have 128-bit space of primes, that's not that big of a space for primes. [17:25.280 --> 17:26.820] Because primes, you know, you don't have every number. [17:26.880 --> 17:27.480] You have prime numbers. [17:28.320 --> 17:29.780] One, you can do a cook prime attack. [17:30.220 --> 17:34.740] 128-bit, it's not hard to solve, like, you know, these keys and make, you know, basically, start generating. [17:34.920 --> 17:39.240] It still takes a long time, but the NSA's probably got a list of the 128-bit, you know, keys. [17:39.400 --> 17:39.860] That's an assumption. [17:39.860 --> 17:41.260] I'm not speaking on behalf of the NSA. [17:42.280 --> 17:53.640] And then the second attack that you can do is basically an index calculus attack, which is basically, you take a linear sieve, and basically, you make, you know, you do prime minus one divided by two, and then you basically make all primes to that, make a matrix, [17:53.780 --> 17:59.020] and then you calculate smooth relations, and you can actually solve the key, you know, keys for that possible prime set. [18:00.680 --> 18:04.000] So, and the good thing about this is many phishing groups use Trillion Secure IM. [18:04.200 --> 18:11.280] Another attack we didn't mention here is, obviously, the man-in-the-middle attack, because they don't actually do any kind of authentication or verification on their signatures when they communicate. [18:11.860 --> 18:14.700] So, there's, you know, that's been broken for a little bit, actually. [18:15.080 --> 18:18.580] But, so we have fun with that as well, so it actually is happy. [18:18.580 --> 18:20.720] So, I'm gonna let Josh go now. [18:20.960 --> 18:21.960] He's gonna talk about some botnet. [18:24.600 --> 18:31.760] Let me just start off by saying that you can tell how tired we are, because Lance is talking at about half speed, if anybody actually knows him. [18:32.640 --> 18:37.400] And, uh, and I can't seem to keep the water from going all over the place. [18:37.560 --> 18:39.260] So, I apologize for the future speakers. [18:39.260 --> 18:39.340] We're a red-eye talk. [18:39.600 --> 18:41.340] Yeah, this is definitely a red-eye talk. [18:42.140 --> 18:43.340] So, moving on. [18:44.120 --> 18:44.560] Botnets. [18:44.560 --> 18:49.680] Now, phishers, they tend to not be the most talented hackers in the world. [18:49.840 --> 18:54.840] If they had the skills, they would probably be, well, hacking and making some real money or selling secrets or something else. [18:54.960 --> 18:55.860] They're criminals on computers. [18:56.040 --> 18:56.900] Yeah, basically. [18:57.220 --> 19:02.560] So, you know, once they go through all the effort to compromise the host, well, why not get the most bang for your buck? [19:02.700 --> 19:04.520] So, they set up, they set up the phish. [19:04.620 --> 19:07.240] They set up a little email, mass email for PHP. [19:07.620 --> 19:09.360] And, usually, they set up botnets. [19:09.560 --> 19:17.160] And botnets work hand-in-hand really well with phishing, because then you can set up a dynamically changing website that's a lot harder to take down. [19:17.920 --> 19:24.740] So, often times, though, because they're not very smart and they're not very good attackers, they leave their toolkits lying around. [19:25.320 --> 19:27.560] And we're finding botnets are becoming more and more prevalent. [19:28.020 --> 19:29.880] So, they're creating compromised hosts for phishing. [19:30.400 --> 19:32.320] Eggdrop seems to be one of the most famous. [19:32.520 --> 19:37.020] It's just a standard IRC bot that they've simply configured for malicious purposes. [19:37.760 --> 19:45.360] IR offers another one, too, used more predominantly by where's groups, because phishers tend to not trade that much data on their phish sites. [19:45.560 --> 19:47.300] Higher profile, more bandwidth usage. [19:47.460 --> 19:49.640] There's more likely that they're going to get noticed and taken down sooner. [19:50.340 --> 19:54.760] The cool thing about them leaving their configuration files is it tells us so much. [19:55.080 --> 19:56.840] You look at the language that it's got going in there. [19:56.960 --> 19:58.980] Okay, now we know where on the planet they are. [19:59.680 --> 20:07.860] Now we know which language dictionary list we should use, because typically the password hashes, if not the password in plain text, are also in the configuration file. [20:08.560 --> 20:12.640] Just increasing your odds as a white hat of actually getting somewhere. [20:13.480 --> 20:16.880] So here we've got an example of a bot configuration file. [20:17.020 --> 20:21.240] This is greatly, greatly trimmed down for brevity, but here you see a couple things. [20:21.400 --> 20:22.660] You've got the admin password hash. [20:23.380 --> 20:31.400] We've got some usernames and some various French cable addresses that are permitted, excuse me, to take over and take control of the bot network. [20:31.400 --> 20:38.940] And towards the bottom you'll notice that the last three screen names that are considered to be admins are just at any host. [20:39.100 --> 20:43.940] They're at wildcard host, which seemed kind of silly to me, because you see we've got Mal, who's in here three times. [20:44.720 --> 20:51.460] He was very specific that he wanted to be the proxed network, but then he was also saying, but, you know what, why not just make it any network as well? [20:51.720 --> 20:55.720] So, you know, kind of sloppy, but we move along. [20:55.900 --> 21:00.640] And this is the actual bot that that configuration file came through. [21:00.640 --> 21:04.200] Ran it through a password cracker using a French dictionary list. [21:04.400 --> 21:05.260] Found it in seconds. [21:05.960 --> 21:09.960] We were able to then log into the bot, and it gave us all this awesome useful information. [21:10.160 --> 21:16.140] Which network we could find them on, which time of day they tend to be around, what type of system they've actually infected. [21:16.340 --> 21:19.740] So we're looking at probably a Windows NT or a Windows 2000 based system. [21:20.720 --> 21:25.040] Blue Team is a French wares team that is also involved in some phishing. [21:25.460 --> 21:32.060] In this case, they were long since defunct, or at least when we went to the channel that's listed here, Blue Team, they were nowhere to be found. [21:32.600 --> 21:37.680] But, you know, a little Googling, a little research, we found out that they were like Blue Team X or something like that. [21:37.760 --> 21:39.400] They didn't try very hard to move. [21:39.540 --> 21:42.260] Maybe the heat got on and they thought, well, let's throw an X in there. [21:42.340 --> 21:43.800] Like I said, they're not that smart. [21:44.620 --> 21:53.300] So we were able to manipulate the bot to find out a little bit more about it, because we weren't exactly certain what type of executables or malware had infected this bot. [21:53.300 --> 21:57.280] This wasn't a typical Linux-based egg drop system. [21:59.020 --> 22:05.720] But, through manipulating the bot network, we were able to actually change the directories that it was looking for files to share. [22:05.900 --> 22:08.580] And we got to include the directory that the bot was installed in. [22:08.680 --> 22:10.960] So now you can see we've got some sigwin files in here. [22:11.180 --> 22:12.740] We've got various batch files. [22:12.900 --> 22:23.420] And if you look at the dates on the logs, 2005, I had to chop off quite a bit, but this host had been owned since about 2003 and was still online, unfortunately. [22:23.840 --> 22:30.280] So, you know, the more people that get online, the more likely they are to not be the dumbest people on the Internet. [22:32.720 --> 22:35.180] I'm gonna move on a little bit, talk about Google hacking. [22:35.920 --> 22:38.120] Anybody here that doesn't know what Google hacking is? [22:38.460 --> 22:39.060] Raise your hand. [22:39.180 --> 22:45.040] I'm not talking about actually hacking into Google, more using Google to find vulnerable hosts quickly. [22:45.320 --> 22:57.440] And what we're seeing is an emerging trend based on Apache log forensics, is that these guys are finding the latest vulnerability of the day, coming up with a Google query, and bam, they've got, you know, a thousand sites that are vulnerable. [22:57.640 --> 22:59.580] It's a quick ROI, get in, get out. [23:00.680 --> 23:04.600] Johnny Long, a good friend of mine, runs a website, johnny.ihackstuff.com. [23:04.680 --> 23:06.940] It's actually where I spend most of my days. [23:07.500 --> 23:14.560] I should preface this by saying that johnny.ihackstuff.com is in no way a black hat site, and we do our best to try to dissuade that image. [23:14.580 --> 23:15.720] It's more about raising awareness. [23:16.120 --> 23:20.080] However, if you raise awareness to the good guys, you raise awareness to the bad guys. [23:20.460 --> 23:25.400] At the time of this writing, there's nearly 2,000 vulnerable dorks, as we call them, Google dorks. [23:26.260 --> 23:29.300] So there's quite a bit of things to choose from. [23:29.660 --> 23:35.400] This is an actual example of a query that we found in an Apache log refer that was very, very helpful. [23:35.960 --> 23:41.980] All in title, image view gallery, which basically means everything in the title bar, the whole thing's got to be included. [23:42.180 --> 23:46.680] And this actually happened to be from a, I think it was like a year and a half old vulnerability for image view. [23:46.820 --> 23:48.620] It was still wide open. [23:49.480 --> 23:52.520] As you can see, we still got 1050 vulnerable hosts. [23:53.160 --> 23:54.140] The cool thing... [23:54.140 --> 23:55.400] Yeah, that was as of this morning. [23:57.160 --> 24:01.340] So, the cool thing about this is that, number one, we can assume that fishers are lazy. [24:01.500 --> 24:02.360] That's why they're fishers. [24:02.540 --> 24:08.340] So odds are pretty good that the most sites, the sites that are going to be attacked the most, will very likely be within the first couple pages. [24:08.700 --> 24:15.920] This is cool because then we can scan through them, and then we can be semi-aware of which sites might be infected in the future so we can take... [24:15.920 --> 24:17.020] be a little bit more proactive. [24:17.440 --> 24:23.280] Unfortunately, we don't have the time or the resources to track down all 1050 of these people and make sure they lock down their boxes. [24:23.280 --> 24:26.240] But at least we have a pretty good idea of where we need to start looking. [24:27.180 --> 24:27.760] Let's see. [24:30.160 --> 24:30.800] Scam kits. [24:31.120 --> 24:33.200] You can tell I don't think very much of fishers. [24:33.800 --> 24:35.020] These are their toolkits. [24:35.080 --> 24:35.600] Scam kits. [24:36.580 --> 24:39.800] When they create their fish, they usually do it beforehand. [24:39.820 --> 24:40.840] They rip the site. [24:41.020 --> 24:41.520] They have everything. [24:41.680 --> 24:43.180] They package it all up nice and pretty. [24:43.320 --> 24:44.540] They make their PHP files. [24:44.680 --> 24:45.980] And then they zip the whole thing up. [24:46.400 --> 24:47.400] And they upload it somewhere. [24:47.620 --> 24:47.760] Bam. [24:47.920 --> 24:48.240] Get in. [24:48.380 --> 24:48.740] Unzip. [24:48.900 --> 24:49.220] Get out. [24:49.780 --> 24:52.480] Usually they don't delete them though, for whatever reason. [24:52.860 --> 25:01.640] The good thing about this is, since they don't delete the zip file, even though we don't have access to see the raw PHP source in most times, you can still see the email address and the archived copies. [25:01.840 --> 25:05.080] And it's only one file to download instead of 20, which is pretty convenient. [25:05.540 --> 25:06.060] Let's see. [25:06.060 --> 25:10.800] So the fish scam kit, I kind of talked about this, is the meat and potatoes of the fish. [25:10.880 --> 25:14.360] This is pretty much where all the action happens, outside of the exploitation. [25:15.320 --> 25:18.060] They're often traded on IRC and more popular channels. [25:18.060 --> 25:26.940] And you'll see people like MIRCboy, who just makes thousands of these kits and just trades them out for whatever he thinks that he's leaked because he's making HTML page. [25:27.100 --> 25:28.140] You know, welcome to 1992. [25:29.280 --> 25:32.780] Anyway, so they're generally traded by the kitties that have no real skill. [25:32.780 --> 25:37.400] However, some of the more organized fishing groups have their own brand. [25:37.540 --> 25:38.440] They don't go to IRC. [25:38.640 --> 25:39.480] They make their own. [25:39.620 --> 25:40.440] They write it from scratch. [25:40.660 --> 25:55.440] And the cool thing about this is, is that aside from the 10,000 or whoever that are getting them from MIRCboy, we can develop fingerprints, attack patterns based on maybe the way they work their PHP, the way they punctuate it or the structure it. [25:55.440 --> 25:58.000] In some cases, this is kind of funny. [25:58.420 --> 26:01.420] The scam kits, if you load them in Notepad, they look fine. [26:01.920 --> 26:12.620] But if you scroll all the way over to the right side of the screen, you'll see about 14 or 15 more mail statements in PHP of every person who would pass the file pass-through wants their email. [26:12.800 --> 26:15.140] Okay, as soon as this file is accessed, send me the email too. [26:15.260 --> 26:16.200] Send me the email too. [26:16.380 --> 26:21.080] So the phishers don't realize that they're getting phished by every other phisher who had the file before them. [26:22.200 --> 26:22.880] Let's see. [26:23.720 --> 26:25.820] Scam kits reveal the data logging process. [26:26.120 --> 26:28.220] Typically, it's just a PHP mail statement. [26:28.480 --> 26:32.180] Mail to, you know, zerocool at gmail.com. [26:32.800 --> 26:41.560] But oftentimes, they'll also include raw logging statements, which is really, really handy because then not only do we know who's doing it, but also who the victims were. [26:41.740 --> 26:46.620] And that makes it a lot easier to remediate the vulnerabilities and make sure that the damage is limited. [26:47.620 --> 26:48.300] Let's see. [26:48.380 --> 26:49.280] I think I covered that. [26:49.660 --> 26:50.180] Okay. [26:51.700 --> 26:53.600] But some are unique. [26:53.980 --> 26:56.640] Although the ones that are on IRC are pretty much ready to go. [26:56.820 --> 26:57.600] Just add water. [26:58.120 --> 26:58.700] Let's see. [26:59.040 --> 27:00.120] I kind of covered that. [27:00.440 --> 27:00.960] Email drop. [27:01.400 --> 27:06.900] The email addresses and the blind drops are often reused, which is really silly. [27:07.120 --> 27:08.640] But phishers are creatures of habit. [27:08.780 --> 27:11.860] So they're not going to change their techniques unless they have to. [27:11.960 --> 27:15.960] Unless Yahoo shuts down the email address or unless it's just getting too much spam. [27:16.440 --> 27:17.320] That's kind of funny. [27:18.600 --> 27:22.760] So here we've got an example of a typical PHP processing engine. [27:22.920 --> 27:24.320] This is usually processing.php. [27:25.160 --> 27:26.440] You know, pretty generic. [27:26.640 --> 27:28.600] This group looks like it was from Mexico. [27:29.460 --> 27:30.780] And then you've got a couple... [27:30.780 --> 27:32.480] They're emailing it to a couple different places. [27:32.700 --> 27:36.600] This is what I mean by when they put the covert mail to statements in here. [27:36.740 --> 27:39.980] This is probably just a small team that are sharing email addresses. [27:39.980 --> 27:45.320] And then once they capture your passwords, they redirect you to the actual bank. [27:47.400 --> 27:47.840] Okay. [27:48.560 --> 27:49.800] This is what I'm talking about. [27:50.000 --> 27:52.800] So they reuse their email addresses and their handles all the time. [27:52.900 --> 27:54.300] They'll put them right in their code. [27:54.540 --> 27:58.620] So, you know, first thing you do when you get these things is throw them into Google. [27:58.820 --> 28:04.340] I throw them into Google, throw them into Google image search, and you would not believe how often things come up. [28:05.000 --> 28:06.740] Stankdawg gave an awesome presentation. [28:06.940 --> 28:09.240] I think it was Friday, Saturday? [28:09.240 --> 28:10.380] I haven't slept in a while. [28:10.500 --> 28:10.980] I'm not certain. [28:11.600 --> 28:20.520] It was really good talk, talking about screenshots and going into what type of information you can infer about the person whose computer you're looking at based on subtle clues. [28:21.700 --> 28:31.460] But here we have an example of one Fisher who was just so darn proud of his handle and his skills and his leateness that he posted his friggin' handle on his DeviantArt page. [28:32.900 --> 28:34.640] And then we got a screenshot. [28:35.300 --> 28:37.040] Well, that's kind of interesting, kind of hard to see. [28:37.120 --> 28:38.420] Well, what happens when we zoom in? [28:38.420 --> 28:39.280] Uh-oh! [28:40.260 --> 28:43.420] Now we see who his friends are, who he's chatting with. [28:43.680 --> 28:50.980] I don't know if you can see it down there, but there's quite a few exploits listed in his shell on his freaking DeviantArt page. [28:50.980 --> 28:53.080] We've got the IRC channels that he hangs out. [28:53.200 --> 28:56.300] This gentleman happened to be Romanian, happened to be pretty good at Gentoo. [28:57.320 --> 28:58.460] Still not that smart. [28:58.660 --> 28:59.000] It's kind of weird. [28:59.320 --> 29:03.320] I'm just assuming that they fear that they have no sort of repercussions to worry about. [29:03.320 --> 29:04.520] So they just don't even care. [29:06.160 --> 29:06.940] But they do. [29:07.240 --> 29:09.200] And then there's Myspace. [29:10.260 --> 29:15.500] I swear to whatever DE is that you like that yeah, we've actually seen these. [29:15.760 --> 29:22.760] People, they post their handles on their Myspace with pictures of them, with pictures of their family, what city they live in, how old they are. [29:22.840 --> 29:24.720] They are dropping docs left and right. [29:25.860 --> 29:30.240] You know, high school, where they live, who their other co-conspirators are. [29:30.920 --> 29:31.360] Myspace. [29:31.680 --> 29:36.780] How difficult is it to change your number, to add a friggin' digit in there and Google won't pull this up. [29:37.100 --> 29:38.220] But I digress. [29:39.820 --> 29:43.760] And I'm going to turn this one back over to Lance since the legal stuff is more his forte. [29:44.600 --> 29:44.880] Not really. [29:45.120 --> 29:46.120] I just break the law. [29:46.260 --> 29:46.520] Just kidding. [29:48.600 --> 29:52.740] So, you guys, who's involved in implementing IDS in this room? [29:54.280 --> 29:55.120] Okay, thanks. [29:55.240 --> 29:55.700] Which companies? [29:55.880 --> 29:56.200] Just kidding. [29:58.840 --> 30:08.880] So, as you guys might know, in some states, IDS, before you can implement it, you have to have, if you're in a corporate environment, you have to have the employees sign off that they are aware that they are being monitored, the networks are being monitored. [30:09.160 --> 30:10.240] This is reason one. [30:10.420 --> 30:16.340] There was a California lawsuit about assumption of privacy, even in a corporation, even though it's on your own machines, your own networks. [30:16.580 --> 30:23.980] There's an assumption of privacy that goes along with this, using an IDS and the user just wanting to be, checking his Hotmail and things like this. [30:24.800 --> 30:30.040] Now, ISPs also use Snort and other IDS and different detection tools. [30:30.880 --> 30:35.500] And so, we're going to talk a little bit about Title 18, USC 1030. [30:36.300 --> 30:51.860] This basically, like, the cool thing about civilians, compared to it, and I know that everybody is sensitive about wiretapping, and this doesn't mean go around just wiretapping everybody, but in the world of forensics, if you're an ISP, and you've got someone doing stuff that's very suspicious on your network, [30:52.080 --> 31:01.100] you obviously want to run your IDS, and then you want to start maybe, you know, keeping an eye on it by running tcpdump every night or something, and just seeing what's going on, so that you know if you want to kick them off your ISP or not. [31:01.940 --> 31:06.980] Now, the only way ISPs are allowed to do this is they have to have a terms of service, or, you know, an AUP. [31:07.600 --> 31:17.120] And it basically has to let the user know, hey, if I'm committing, if you're committing fraud, we have every right to monitor you, and we're going to do anything in our power to basically chase you down. [31:17.320 --> 31:23.960] And the cool thing about this is that, as a company, we basically can end up, you know, requesting these ISPs and saying, hey, can you send us the hard drives? [31:24.120 --> 31:25.740] And we don't have to get a subpoena. [31:26.220 --> 31:37.620] We actually have more, you know, playing power than a lot of the times the FBI, or the Secret Service in this case, we don't have to run through the red tape, because they've already got their lawyers basically setting up an AUP that's very diligent to Title 18, [31:37.700 --> 31:45.440] because Title 18 is basically, you're allowed to monitor your networks, wiretap your own networks, as long as you are doing it for the defense of your networks. [31:46.060 --> 31:58.620] So, basically, what's happening here is we'll basically talk to a, you know, certain ISP and say, hey, there's this Russian forum that's trading cards, or there's a, you know, you know, selling exploits on your ISP, and they'll send us PCAP dumps every night, [31:58.660 --> 32:00.200] so that we can investigate this stuff. [32:00.360 --> 32:09.100] And so, we're actually working with a lot of ISPs and building this up, so that one, we can recover data for, you know, for the customers, and the banks, and the, you know, people, the targets that are involved. [32:09.940 --> 32:11.600] We can do fraud monitoring for them. [32:11.600 --> 32:13.420] It's like a Title III for the civilian. [32:14.100 --> 32:16.160] It enables us to have a strong intelligence. [32:16.380 --> 32:21.940] For instance, you guys remember, anybody heard of Burbu, or Webscob, or Patador, or Patanoc, anybody? [32:22.640 --> 32:26.380] It was a Trojan back in 04, written by the hang-up team. [32:27.240 --> 32:34.820] And, basically, that was, you know, there was a few sites, like Karlmarks.ru, that would send these blind drops, and they'd have sites. [32:34.820 --> 32:48.500] And we actually ended up finding their actual base camps, as well, which means the base camp for Fisher is basically, kind of their little hidden, dedicated server that, you know, they sort all their data from, and they have their scripts in there, and they basically do their business. [32:49.300 --> 32:56.700] The cool thing about this is, Fisher's like to log everything, even their ICQ conversations, and they put that in there, because they were doing business, and I think that they report to someone. [32:57.040 --> 33:08.760] So, basically, in this case, we were, you know, almost every Burbu blind drop that was out there, we were able to work with ISPs, and get every single hard drive, and they stole 113 gigabytes of data in 04. [33:10.240 --> 33:12.480] So, basically, it's defending your network. [33:12.740 --> 33:13.920] IDS falls under this law. [33:14.060 --> 33:26.340] If you are an ISP, I recommend and highly, you know, urge you to basically start getting on board with having a terms of service that is very applicable to this, due to the fact that it will help you, and have forensic researchers be, have easier access to assisting you, [33:27.720 --> 33:29.720] in, you know, getting these problems mitigated. [33:29.880 --> 33:35.780] And if you don't include that, then there might be some form of an implication of privacy amongst that network. [33:35.940 --> 33:40.420] So, if you don't have this there, then you're actually breaking the law by trying to monitor that communication. [33:41.060 --> 33:43.560] It would be an illegal Title III. [33:46.000 --> 33:47.260] So, coming soon. [33:48.140 --> 33:48.980] Thanks to Josh. [33:49.820 --> 33:51.420] Scam Scan 0.1. [33:51.680 --> 33:53.380] We're hoping it's going to be out in a couple weeks, hopefully. [33:53.600 --> 33:55.100] Let me just interject real fast. [33:55.300 --> 33:56.880] My code really, really sucks. [33:57.640 --> 33:59.160] This was helped... [33:59.700 --> 34:04.540] Another moderator of Johnny.ihackstuff.com is a gentleman out of Amsterdam, or the Netherlands, named Murphy. [34:04.720 --> 34:06.160] And Murphy's such a great guy. [34:06.280 --> 34:07.440] He helped me from start to finish. [34:07.540 --> 34:15.220] He held my hand, and tucked me into bed at night, and basically, took the project in my mind, and threw it into code, and basically, taught me some stuff along the way. [34:15.580 --> 34:15.760] So... [34:15.760 --> 34:23.400] So, the idea of Scam Scan is, we have a lot of future ideas, and then we have the basic thing that we're using it now, and it's actually been pretty successful in some of our investigations. [34:23.900 --> 34:25.540] It's a configuration file basically. [34:25.780 --> 34:27.860] It's, you know, Perl script, pretty much. [34:28.060 --> 34:36.940] And it has a configuration file that you couldn't basically put in, known scam kits, So, as you're investigating out there, and you find a scam kit list, or things like that, you can start adding those in. [34:37.140 --> 34:44.900] Like, if you're doing IRC monitoring, like you're just having your own dag drop bot, and you're just watching some forum, you know, on IRC, or whatever, you're listening in the channel. [34:45.160 --> 34:46.380] You can basically, you know... [34:46.380 --> 34:51.220] Sometimes, if you monitor URLs, you'll basically see, here's a list of like, sudden bank scam am... [34:51.220 --> 34:52.860] Scam kits on a website. [34:52.860 --> 34:56.160] So we end up putting it in our config file. [34:56.560 --> 35:08.040] And so when we start seeing an eBay scam or something like that, like that's actually live, we run scam scan on it and then it suddenly infers, it does basically rapid enumeration of basically certain characteristics. [35:08.520 --> 35:16.700] It ends up finding log files, like if there's a certain phishing group, it'll look for like log.txt, emp.txt, logger.txt... [35:16.700 --> 35:17.800] Think Nick2 for phishing. [35:17.940 --> 35:20.880] Yeah, it's basically, we were gonna call it fic2, but... [35:20.880 --> 35:21.700] But Lance hated the name. [35:21.700 --> 35:22.400] I hated the name. [35:22.880 --> 35:24.700] So, scam scans, so much more commercial. [35:26.180 --> 35:29.020] But it's gonna be a free tool, it's not something where, it's a GPL. [35:31.060 --> 35:34.240] But basically, the cool thing is that we're gonna be working on future releases. [35:34.800 --> 35:45.720] We're looking into doing it to a honey client so that like, you know, web attacker and a lot of the exploits that we're seeing against the IE attacks and things like that on the web, we're able to basically... [35:45.720 --> 35:48.080] Thanks for the music, does that mean I have to get off the stage now? [35:48.180 --> 35:48.980] It's like the Academy Awards. [35:50.280 --> 35:51.980] So, yes, it's your time. [35:52.160 --> 35:52.260] Go. [35:52.740 --> 36:06.820] So, but basically, we wanna do it where we can actually use that also to automate and basically mirror in and pick up, you know, we can put in patterns for like, you know, IE604.CGI and the HTML looking for exploits within the, you know, the actual sites. [36:07.260 --> 36:12.460] But basically, we pick up a lot of scam kits along the way which gives us the actual email addresses and the drops and things like that. [36:13.540 --> 36:15.900] The parsing of HTML to learn of new directories. [36:16.000 --> 36:17.000] So, we're gonna have that in the future. [36:17.560 --> 36:20.760] We're gonna do automatic mirroring of PHP source code through PHP web shells. [36:21.140 --> 36:24.100] The great thing about like a lot of this is there's a lot of... [36:24.100 --> 36:28.360] We're seeing a few phishing attacks basically. [36:28.560 --> 36:33.480] And what they're doing is setting up the Russian C99 and R57 web command shells. [36:33.680 --> 36:34.760] These are back doors basically. [36:35.020 --> 36:42.040] And it lets them just, you know, not really have to have root but they can basically whatever directory they're in, they can control the box and go around with just staying on the web. [36:42.480 --> 36:55.840] And so, we're gonna be building a system that basically can go through there and grab the web logs, grab those things and do it automatically and grab all the PHP source code to their phishing information so we can find blind drops, things like that, and kind of mitigate the risk. [36:56.980 --> 36:57.620] Shameless plug. [37:00.000 --> 37:02.900] I and Secure Science wrote a book called Phishing Exposed. [37:03.120 --> 37:04.740] It's pretty much everywhere. [37:04.760 --> 37:06.080] Amazon, Barnes and Noble, blah, blah, blah. [37:07.680 --> 37:09.300] It's just a shameless plug. [37:10.880 --> 37:11.480] Thank you. [37:11.740 --> 37:12.380] Any questions? [37:23.270 --> 37:24.130] Oh, good morning. [37:24.330 --> 37:24.710] Good morning. [37:24.790 --> 37:25.030] How are you? [37:25.070 --> 37:25.610] Good morning. [37:25.990 --> 37:26.590] I'm great. [37:26.730 --> 37:27.070] How are you? [37:27.370 --> 37:27.770] Unbelievable. [37:28.050 --> 37:28.550] Thanks for asking. [37:28.730 --> 37:29.210] I mean, awesome. [37:30.150 --> 37:30.970] Oh, aren't we all? [37:31.670 --> 37:38.090] One of the things that I've been working on, I don't know if you've run across this, is blog spam, wiki vandalism. [37:39.950 --> 37:42.810] Do they tend to use the same types of software? [37:43.070 --> 37:44.130] Are they using different tools? [37:44.510 --> 37:49.490] Or have you seen anything that might be useful in stopping them? [37:51.410 --> 37:51.850] Yeah. [37:52.510 --> 37:53.070] Which one? [37:53.210 --> 37:54.310] Is this log spam you're talking about? [37:54.410 --> 37:56.150] Blog spam and wiki vandalism. [37:56.150 --> 37:56.850] Oh, the blog spam. [37:56.990 --> 37:57.070] Yeah. [37:57.750 --> 38:02.130] A lot of the times if you look at the web blogs, you'll see certain characters. [38:02.270 --> 38:03.790] It's pretty much a scanner doing this stuff. [38:03.790 --> 38:05.270] It's basically automated tools. [38:05.770 --> 38:05.950] Oh, yeah. [38:05.950 --> 38:11.650] And so far from what we have seen globally right now, it seems to be the same tool for most of that stuff. [38:11.790 --> 38:13.790] But there's a few different tools out there for blog spam. [38:14.010 --> 38:15.210] It's like bulk mailers, right? [38:15.290 --> 38:19.990] You've got SendSafe, you've got Darkmailer, you've got DMS2. [38:20.290 --> 38:21.290] So there's a few kits. [38:21.410 --> 38:23.890] There's not a lot yet for blog spam, but it's definitely something. [38:24.010 --> 38:28.190] And a lot of the bulk mailers that are standard out there are starting to support blog spam. [38:28.190 --> 38:33.130] So it's, you know, go to like darkmailer.org, I think, or com or something like that. [38:33.230 --> 38:35.490] And I think they even added blog spam features. [38:35.730 --> 38:37.630] So they tend to just keep doing it. [38:38.310 --> 38:45.810] My other question was, once you track one of these guys down, they wind up being in Romania or Poland or Belarus, Russia. [38:46.130 --> 38:47.230] What do you do with them? [38:47.230 --> 38:48.310] We jump on a plane. [38:48.710 --> 38:50.270] And kick their ass. [38:50.410 --> 38:50.610] Yeah. [38:51.390 --> 38:55.110] No, actually, honestly, I'm only allowed to say one thing about this. [38:55.110 --> 39:00.330] Our company in the last six months has been credited to 30 arrests, 28 of them out of the country. [39:01.070 --> 39:01.550] So... [39:01.550 --> 39:02.910] The other two are my family. [39:05.010 --> 39:12.190] Real quick, in addition to the bulk mailers that we're seeing use the standard executable versions, one thing that they're doing is a lot of PHP attacks. [39:12.490 --> 39:15.910] So there's this one that seems to be the most common called off.php. [39:15.970 --> 39:23.110] And it's just a simple, no frills, generics, sometimes SQL-driven, otherwise flat text-driven email mailer. [39:23.110 --> 39:33.290] And, um, another thing is, in addition to, um, the WordPress spamming that you might see, more often what we're finding is that it's just generally they seem to favor weak PHP applications. [39:33.850 --> 39:37.950] Or they stay on top of the vulnerabilities better than some of the people who develop it. [39:38.050 --> 39:38.350] Microsoft! [39:40.070 --> 39:41.530] Does Microsoft develop PHP? [39:41.750 --> 39:43.270] No, they develop, uh, zero data. [39:43.550 --> 39:46.090] I mean, PowerPoint and other things. [39:46.850 --> 39:49.170] The whole point is that they definitely don't keep track. [39:49.370 --> 39:49.510] Right. [39:50.250 --> 39:57.050] Um, well, actually, one of the things that, actually, that Josh was saying about the PHP bulk mailers, which is a very high, it's a big popular thing in Romania. [39:57.470 --> 40:00.290] And more than, there's two types of fishing group sectors that we kind of do. [40:00.470 --> 40:02.330] There is the organized crime groups. [40:02.550 --> 40:05.490] You know, that's technically Ukraine, Russia, and Estonia. [40:05.690 --> 40:07.190] They tend to work together a lot, okay? [40:07.250 --> 40:08.210] And Latvia, Lithuania. [40:08.670 --> 40:12.010] Then there's the chaotic groups, basically a Romanian, and they're barter trade. [40:12.150 --> 40:15.510] They're pretty much kids that are kind of like, don't really know each other, but they trade back and forth. [40:15.510 --> 40:16.930] Mexico, Indonesia. [40:17.230 --> 40:19.330] Yeah, no rippers welcome, you know, that kind of stuff. [40:19.510 --> 40:27.990] And they do carding, and they, you know, the Romanians basically were carders gone fishing, whereas the Russians went fishing, you know, and now they're doing carding, because it's obviously, you know, the track two stuff. [40:28.270 --> 40:38.970] But, the thing that we saw, like, recently, a couple weeks ago, was that the PHP bulk mailer tools, to keep them anonymous, instead of breaking into systems, they did a cross-site bulk mailing trick. [40:38.970 --> 40:45.850] So, what they did was, they take PHP, and the fopen command actually lets you do the HTTP, you know, URL stuff, right? [40:46.030 --> 40:50.010] So, they make a text file that's a PHP bulk mailer, and they basically execute it on that machine. [40:50.450 --> 40:58.170] So, then, of course, the IP address comes in from that web, you know, server, and, you know, unless the guy's looking in his web logs, he's not going to see stuff like that at all. [40:58.330 --> 41:03.470] Just a quick add-on to that, you know, sometimes I'm down more in the trenches than you are when you're taking care of all the money. [41:03.890 --> 41:06.450] I've actually seen this since at least January. [41:07.170 --> 41:10.230] Just standard cross-site inclusions. [41:10.690 --> 41:14.950] And everything from full-on bulk mailers to, in some cases, actual backdoors. [41:15.250 --> 41:16.730] And they just include the PHP. [41:16.930 --> 41:22.510] They'll host it on Geocities' account, where it's flat text, it doesn't get interpreted, and then it gets pushed over to the other site. [41:23.490 --> 41:27.590] Yeah, he's been seeing that, because he works for the ETAT, and he monitors that stuff. [41:27.770 --> 41:32.050] And I saw it, I was looking through, and I was checking his work, and then suddenly I had that number, you know. [41:32.570 --> 41:32.970] So... [41:32.970 --> 41:36.910] Don't you wish you had a boss that didn't look at your work for six months, and just left you alone? [41:37.070 --> 41:37.810] I love it. [41:38.510 --> 41:39.310] It's called trust. [41:39.610 --> 41:39.650] Yeah. [41:41.450 --> 41:42.690] I came a little late. [41:42.950 --> 41:45.030] What does PHP stand for? [41:45.630 --> 41:46.510] That's a good question. [41:48.150 --> 41:50.050] PHP Hypertext Pre-Processor, am I right? [41:50.370 --> 41:51.110] Recursive acronym? [41:52.290 --> 41:52.570] I'm sorry? [41:53.010 --> 41:53.870] Well, that was good. [41:54.070 --> 41:56.230] Poopy hyper... I don't know. [41:57.170 --> 41:57.790] What is it? [41:58.130 --> 41:58.730] Did we get it right? [41:58.950 --> 42:00.750] PHP Hypertext Pre-Processor? [42:03.830 --> 42:09.120] It's an anomaly. [42:10.260 --> 42:13.640] Yeah, basically, it's rumored to be those two. [42:14.740 --> 42:22.880] I get about two dozen Nigerian scam and lottery type email every day. [42:23.180 --> 42:26.560] By the way, I sometimes wonder if I don't miss on something. [42:26.740 --> 42:30.880] Somebody is promising me $2 million in every email. [42:30.880 --> 42:32.140] I recommend getting the $2 million. [42:32.360 --> 42:32.660] Just kidding. [42:33.280 --> 42:35.280] Every time I want to quit work because I want the lottery. [42:35.660 --> 42:41.780] Are these things related somewhat with what you are describing, the bulk emails? [42:41.780 --> 42:42.580] I got this one. [42:42.640 --> 42:43.140] That's funny. [42:43.480 --> 42:43.560] Okay. [42:44.500 --> 42:48.880] One of the things that I did in my book was specifically not cover 419s and I said I wasn't going to do 419s. [42:49.480 --> 42:51.680] The Ponzi scam has been going on since 1982. [42:52.120 --> 42:52.360] Okay? [42:52.580 --> 42:56.280] And basically, it's been doing it with faxes, normal mail, things like that. [42:56.380 --> 42:58.960] Now, obviously, email being the fastest way to get people going. [42:59.420 --> 43:00.700] It's a totally different scam. [43:00.840 --> 43:02.640] It's basically a stack-based fee scam. [43:03.200 --> 43:08.860] And basically, they get you to basically send out money before you get access to their money, but you never really see their money. [43:08.920 --> 43:15.020] They just keep getting you to spend, oh, all these bank account fees and all this, like, you know, export fees and things like that. [43:15.120 --> 43:16.960] And they just keep going and then they want to invite you over. [43:16.960 --> 43:23.880] And there's actually, it's a very dangerous scam because there's been cases, I think, in 1998, there was actually a kidnapping involved in this. [43:23.980 --> 43:28.560] And the guy never actually returned, you know, no one's ever found him, so he's probably not alive. [43:29.360 --> 43:33.840] So, but we haven't really watched those as much in the sense of phishing because, you know. [43:34.040 --> 43:46.400] But one thing we are seeing, though, is because we look at malware data, the actual, like, the logs that are going on, we do see a lot of Nigerians getting infected by phishers doing money transfers at, like, certain banks. [43:46.800 --> 43:50.520] So we see all these Nigerian IPs and then we'll look the IPs up and we're like, lottery winner. [43:50.880 --> 43:54.600] Because these guys don't seem to, like, you know, care about hiding their IP address at all. [43:54.760 --> 43:55.840] You know, and they reuse it constantly. [43:56.060 --> 43:59.360] You can get those guys to send you pictures of themselves holding up the newspaper. [43:59.520 --> 44:01.340] Yeah, I'll send you the money, but you got to send me a picture. [44:01.560 --> 44:04.380] But there is a 419 site and I can't, it's like... [44:04.380 --> 44:05.060] 419 Eaters? [44:05.260 --> 44:09.260] Yeah, 419 Eaters that's more involved in specific 419 scams. [44:09.660 --> 44:13.560] If you get a 419 scam, the rule is that you're supposed to contact the Secret Service about it. [44:14.300 --> 44:19.500] But, you know, they're a black box most of the time for, you know, because, you know, telephone only has so many 419 scams, right? [44:19.960 --> 44:20.160] Okay. [44:20.800 --> 44:40.800] I have a question about when you were initially starting with Secure Science or when, for other people that are not, don't have a corporate backing or some type of a large-scale backing, where you could say, we stumble across a blind drop or we're doing something with Malware Collector or one of the associates and we find some undiscovered malware, [44:41.460 --> 44:43.380] we reverse engineer, we find a blind drop. [44:43.920 --> 44:48.580] How do we report that and not be a target for a large company to say, oh, well... [44:48.580 --> 44:52.700] Yeah, we had the same problem, actually, because we're not like the largest company in the world and stuff. [44:52.800 --> 44:55.120] And it took a couple of years for us to get trusted with this. [44:55.640 --> 44:58.660] I actually got kicked off with the anti-phishing working group because of this. [44:58.660 --> 44:59.760] They thought we were phishers. [44:59.900 --> 45:01.100] We had so much data. [45:01.240 --> 45:01.980] Yeah, we had so much... [45:01.980 --> 45:03.920] We have three terabytes of stolen data now. [45:04.660 --> 45:09.260] So, the thing with this is that now companies are being more aware that, you know, this is happening. [45:09.360 --> 45:13.240] Because we were monitoring Malware since 2003 that was doing phishing. [45:13.840 --> 45:17.800] And basically what happened is we were returning it to banks and they thought we were trying to extort them. [45:17.920 --> 45:19.240] We're like, dude, you don't have to pay for this. [45:19.300 --> 45:21.320] We obligate giving this to you. [45:21.440 --> 45:22.640] And they didn't understand how we got it. [45:22.720 --> 45:25.120] They'd call the FBI, are these guys hacking into something, you know? [45:25.480 --> 45:28.340] And so, but a lot of the companies now aren't understanding that. [45:28.340 --> 45:32.460] But the best way to go about reporting it to them is one, send it to us. [45:32.660 --> 45:33.760] No, but seriously. [45:34.380 --> 45:38.900] Two is basically just write up an article on how you, you know, the process that you took. [45:39.340 --> 45:45.440] And basically try to contact someone who's technical at the bank, ISS, you know, like the, you know, the information security department. [45:45.560 --> 45:47.820] So that they can have an understanding of that process. [45:48.240 --> 45:54.480] If you don't have the technical skill set, you know, to do that, we would gladly assist you in basically putting that together. [45:54.620 --> 45:56.620] Getting the right contacts that are not afraid of that. [45:56.620 --> 45:58.800] Because we're on the right mailing list that they understand what we're doing. [45:59.020 --> 45:59.980] So, so that's pretty good. [46:00.180 --> 46:00.960] Yeah, because it's scary. [46:01.120 --> 46:06.240] I read a lot about whistleblowers and corporations, especially a couple years back where, you know, they're in the corporations. [46:06.520 --> 46:08.020] And they're trying to expose something that's going on. [46:08.140 --> 46:11.340] And they're getting, you know, shipped off, fired, you know, even worse. [46:11.340 --> 46:16.140] Yeah, we've had actually companies that we've send them their data and they want to just go like this. [46:16.240 --> 46:16.980] I don't want to see it. [46:17.020 --> 46:17.660] I don't want to hear it. [46:17.840 --> 46:20.920] And it's because of the SOX compliances that they have to deal with. [46:21.120 --> 46:23.560] They don't want to have to basically, you know, and they don't understand. [46:23.660 --> 46:25.340] It's actually customer compromises. [46:26.060 --> 46:31.780] But some of the way that they interpret, depending on their facilities in the bank and the procedures, you know, they feel that they would have to report this. [46:31.780 --> 46:34.180] So sometimes they want to lead a blind eye on some of this. [46:34.300 --> 46:38.800] And it's, it's, it's a very, it was a very rough start for us when we started doing this for returning this stuff. [46:38.940 --> 46:43.540] And now it's gotten, we've found the formula to kind of make it easier for the banks to understand it. [46:45.020 --> 46:45.380] Hi. [46:45.500 --> 46:50.180] In the three years you guys have been doing this, how often do you come across malware or code in a foreign language? [46:50.560 --> 46:54.160] And do you have any linguists or anybody that can help you kind of understand that kind of stuff? [46:54.240 --> 47:00.120] We actually recently was, we were reverse engineering a Unicode Chinese malware. [47:00.520 --> 47:03.040] And we had to have Unicode windows and compatibility. [47:03.560 --> 47:07.460] We do have access to, we have contractors that we access through. [47:07.900 --> 47:10.920] We don't have them on staff all the time because it's, you know, we don't come into it as popular. [47:10.960 --> 47:11.920] So the demand is not high enough. [47:12.060 --> 47:21.940] But we do get, you know, a lot of Russian, you know, language because the Russian ones that are, the guys that are writing that malware will write a lot of Russian comments, things like that. [47:22.060 --> 47:26.340] And the Chinese ones, it's sometimes it won't run on a non Unicode machine anyways. [47:26.340 --> 47:30.980] So it's obviously China, attacking China or something like that. [47:31.220 --> 47:34.200] Or Unicode machine at least, maybe Japan or, you know, whatever. [47:34.840 --> 47:40.000] So, but we do have, I actually have a few, you know, contacts for Chinese. [47:40.280 --> 47:43.060] We have access to Arabic, things like that. [47:43.240 --> 47:49.780] So, you know, plus we're on certain lists that are basically have access to a lot of people that do have someone that does that. [47:49.780 --> 47:50.800] So, you know, it's available. [47:51.120 --> 47:53.960] As a side note, a huge influx lately of Indonesian fishers. [47:54.600 --> 47:57.500] Their tools aren't nearly as advanced or as good as any of the other guys. [47:57.740 --> 47:59.100] They leave all sorts of code. [47:59.220 --> 48:00.400] They leave their IRC channels. [48:00.520 --> 48:01.860] They leave shouts to their homeboys. [48:02.240 --> 48:02.640] Everybody. [48:03.020 --> 48:06.760] And we go surf right into the IRC channels and they're not making any effort to hide it. [48:07.500 --> 48:09.780] Unfortunately, Google Translator doesn't have Indonesian. [48:10.920 --> 48:15.960] So the turnaround isn't as quick as it would normally with Cyrillic or with Russian or with any of the other commonly supported languages. [48:16.580 --> 48:16.900] Yeah. [48:19.360 --> 48:20.400] I had a question about... [48:20.400 --> 48:24.960] Before you're talking about the setting up the terms of service if you work for an ISP to allow you to... [48:24.960 --> 48:30.100] They're allowed a company to easily legally give information to you guys and let you, you know, investigate. [48:30.420 --> 48:31.020] But what... [48:31.020 --> 48:34.200] I mean, did you have a lot of trouble getting ISPs to agree to something like that? [48:34.280 --> 48:35.360] I mean, if you guys... [48:35.360 --> 48:39.340] If I ran an ISP and you just called me up and said, send me your hard drives, we think something's going on. [48:39.440 --> 48:40.300] I mean, why would they do that? [48:40.460 --> 48:40.660] Okay. [48:40.780 --> 48:45.280] So what we did was we had a private project working with ISPs called Fish Proofing Your ISP. [48:45.280 --> 48:46.040] And it was free. [48:46.220 --> 48:50.300] So in bartered trade, we would say, we're going to do the forensics reports for you. [48:50.400 --> 48:52.400] We're going to basically do the investigations for you. [48:52.480 --> 48:56.760] We have references to law enforcement, so it's not like, hey, who the heck are you guys? [48:57.560 --> 48:59.080] So we, you know... [48:59.080 --> 49:03.240] So, you know, and some of these ISPs come to us and say, hey, do you guys want this data? [49:03.480 --> 49:05.800] You know, you know, I don't understand it or this or that. [49:05.800 --> 49:06.660] Just don't have the manpower. [49:06.660 --> 49:07.980] Yeah, they don't have the manpower of the resources. [49:08.400 --> 49:13.120] So we've just diligently, you know, kind of sided with the ISPs, work with them because they're the source of the... [49:13.120 --> 49:16.300] You know, not in a bad way that they're source of the problem, but they are what's going to get hit. [49:16.680 --> 49:18.420] And then that's where the traffic's going to start. [49:20.000 --> 49:24.180] So a lot of the times we just, you know, some of them don't play well at all. [49:24.340 --> 49:25.360] No, I'm sorry, you need a subpoena. [49:25.540 --> 49:26.440] You know, that kind of thing. [49:26.560 --> 49:27.400] And that's understandable. [49:27.480 --> 49:30.900] And we try to push the law enforcement to go, hey, this is an important case. [49:30.900 --> 49:35.420] See if you can do something with this, you know, and we will write a report for, like, law enforcement. [49:35.740 --> 49:38.100] But in most cases, we've had some pretty good luck. [49:39.740 --> 49:44.760] And it's just a lot of it's just networking, getting to know them, working with them, and basically helping them. [49:44.920 --> 49:49.500] You know, we'll write Snort signatures that'll help pick up certain type of activity and stuff like that. [49:49.620 --> 49:50.240] And so it's free to them. [49:50.340 --> 49:51.220] It's a service they get. [49:51.300 --> 49:51.360] Right. [49:51.560 --> 49:55.840] And in exchange, they send us the information so that we can help, you know, get the problem solved. [49:55.980 --> 49:56.140] Okay. [49:56.240 --> 49:57.160] But now if they... [49:57.740 --> 49:59.000] I mean, I guess that makes sense. [49:59.000 --> 50:01.700] Like, do you get anybody that really actually refuses? [50:02.060 --> 50:02.760] Yeah, we have. [50:02.820 --> 50:04.980] Because, I mean, you obviously don't actually have... [50:04.980 --> 50:06.620] They actually don't have to comply with you guys. [50:06.620 --> 50:07.080] No, not at all. [50:07.180 --> 50:09.580] No, it's more of a voluntary thing, and it makes it legal. [50:09.780 --> 50:11.380] But we get a ton that refuse. [50:11.540 --> 50:13.380] Some of the really huge ones refuse. [50:13.380 --> 50:14.920] I figure some of them might just not care. [50:14.920 --> 50:16.400] I mean, if it's not really their problem. [50:16.640 --> 50:17.460] I mean, they feel like... [50:17.460 --> 50:21.240] Yeah, I'm resisting the urge to even mention certain ones that don't care. [50:21.360 --> 50:25.320] But, yeah, there are definitely ones that definitely refuse. [50:25.400 --> 50:27.680] And we've even had them basically denying the problem. [50:27.680 --> 50:28.080] Okay. [50:28.220 --> 50:29.260] You know, like we've seen... [50:29.260 --> 50:32.820] Like there was one that I'm not going to say out of just protection of their end. [50:32.980 --> 50:35.880] But we were founding router hijacking. [50:36.780 --> 50:47.760] You know, basically what they were doing is these hackers were basically able to make new ARP tables and then basically add IP addresses and stuff and pick ones that are dead and basically have dark IP space. [50:47.980 --> 50:50.980] And they were sending spam on their dark IP space. [50:50.980 --> 50:55.240] And so we would get like the actual IP address would say DOD that's dead. [50:55.460 --> 50:56.120] You know, some dead thing. [50:56.220 --> 50:57.960] Or Yuba Proving Grounds or something like that. [50:58.180 --> 50:59.760] And it's because the routers were misconfigured. [50:59.940 --> 51:01.920] We told them, haha, we laughed at you when you said that. [51:02.040 --> 51:03.500] And I'm like, why don't you take a look at these headers? [51:03.800 --> 51:03.980] You know? [51:04.120 --> 51:04.600] It's like... [51:04.600 --> 51:05.540] It's pretty legit. [51:05.720 --> 51:07.260] And then you guys are the last hop on that. [51:07.440 --> 51:07.580] You know? [51:07.720 --> 51:08.220] So it's... [51:08.220 --> 51:09.580] So it's... [51:10.020 --> 51:12.340] It's an ego thing too for some people. [51:12.480 --> 51:13.240] You know how security is. [51:13.660 --> 51:14.320] It's kind of crazy. [51:14.320 --> 51:17.940] And a lot of times, you know, even if the ISP doesn't necessarily agree with us. [51:18.060 --> 51:20.160] But we've got, you know, say for example, just Yahoo. [51:20.360 --> 51:21.160] We're working with Yahoo. [51:21.440 --> 51:23.800] And they're getting attacked pretty heavily. [51:23.960 --> 51:25.260] And their customers are in danger. [51:25.520 --> 51:30.620] Well, then they can turn around to their lawyers and say, now listen, the evidence that you have is detrimental. [51:30.620 --> 51:32.040] It's legally ours, et cetera. [51:32.280 --> 51:34.720] And then we may have a partnership with them. [51:34.760 --> 51:39.720] And then it helps them see the ISP see that, you know, it's in everybody's best interest to cooperate. [51:39.980 --> 51:40.200] But... [51:40.200 --> 51:41.200] Yeah, they're customers included. [51:41.400 --> 51:41.740] Absolutely. [51:42.040 --> 51:43.640] Yeah, and one more thing on that. [51:43.640 --> 51:45.340] So, for instance, say I'm a bank. [51:45.800 --> 51:47.520] And I'm contacting you as an ISP. [51:47.660 --> 51:49.140] And I say, hey, will you help us get this data? [51:49.320 --> 51:52.180] A lot of the ISPs will say, no, no, no, that's our, you know, customer's data. [51:52.280 --> 51:54.640] But it's not because also there's data of their customers. [51:54.860 --> 52:00.560] So it's this like really interesting argument that goes back and forth between lawyers a lot of the times because they're trying to protect their customers. [52:00.680 --> 52:07.280] But we're not asking for customer information or credit cards that were logged in because, you know, that only goes to, you know, law enforcement. [52:07.520 --> 52:11.680] But we are asking for, hey, if there was customer information, can you give us that information back, you know? [52:12.140 --> 52:12.600] Thank you.