[00:35.020 --> 00:35.420] Testing? [00:35.680 --> 00:36.600] Okay, there we go. [00:38.360 --> 00:38.900] All right. [00:39.400 --> 00:39.500] Okay. [00:39.640 --> 00:40.560] Hi, I'm Black Ratchet. [00:41.280 --> 00:51.420] We're trying to talk about ghetto ideas and honeypots for the home user, which, you know, ghetto is just sort of a term I decided to really toss in there because it's not anything professional. [00:51.600 --> 00:53.740] We're not going to be deploying top layer on our homeland. [00:53.980 --> 00:57.420] But anyway, I like this. [00:57.540 --> 00:58.880] This is my favorite XKCD comic. [00:58.980 --> 01:00.220] It's printed out on my cube at work. [01:01.220 --> 01:08.240] And I just love to have this where they have all, like, you know, a giant virtual LAN of Windows machines, and you can tell them how they get infected. [01:08.460 --> 01:11.820] And it's a lot of very Hollywood, but yeah, it's never going to happen. [01:12.020 --> 01:13.400] And technically, I can't tell you how to do it here. [01:13.440 --> 01:14.480] So let's go move on. [01:15.260 --> 01:16.980] What are we going to talk about? [01:17.440 --> 01:20.000] What exactly happens on the end of your Internet connection? [01:20.640 --> 01:27.040] Open source tools that will set up your own honeypot and IDS and tie them together so you can actually tell what the heck's going on? [01:27.660 --> 01:31.960] And what you will likely see and what it means and how to respond. [01:33.340 --> 01:33.980] Who am I? [01:34.080 --> 01:35.300] Just another phone phreak from Boston. [01:35.460 --> 01:36.180] I talked at HOPE Number Six, DEFCON, and other conferences. [01:37.780 --> 01:40.900] I've been using these tools since about 2002 or so. [01:41.840 --> 01:45.200] First time I got exposed to them was a capture the flag contest, so they are battle tested. [01:46.360 --> 01:49.720] GCIA, so obviously these letters mean that I know more than all of you. [01:51.480 --> 01:52.240] Really nice guy. [01:52.420 --> 01:55.380] Talk your ear off these things if you donate alcoholic beverages to him. [01:56.920 --> 01:57.940] Why am I using PowerPoint? [01:58.140 --> 01:59.240] You saw that I was using PowerPoint. [01:59.240 --> 02:04.920] Last year, two years ago at the last HOPE, I decided to be cool, use Linux, use OpenOffice, open source. [02:05.080 --> 02:05.480] It's wonderful. [02:06.080 --> 02:07.580] Plug it in right before my presentation. [02:07.740 --> 02:08.980] Wouldn't actually work with the projector. [02:09.580 --> 02:14.300] So I didn't want to expose you to that again, so I bit the bullet and decided to use Windows. [02:15.980 --> 02:18.640] Anyway, let's actually get to the meat of the subject. [02:18.920 --> 02:20.020] This is your Internet connection. [02:20.140 --> 02:21.180] This is what everyone thinks it is. [02:21.300 --> 02:22.500] Information superhighway. [02:22.620 --> 02:26.240] You know, got all these little flags down here showing all the different countries you can get to. [02:27.020 --> 02:30.840] And, you know, you've got your highway and it's fast, it's wonderful, you know, no one's on it. [02:30.920 --> 02:33.540] You're going to go scream through and get to all these faraway places. [02:33.960 --> 02:35.380] This is what your reality is. [02:38.020 --> 02:42.060] Do you realize how hard it is to go search or on Google Images for riot pictures? [02:42.200 --> 02:42.580] There's none. [02:42.740 --> 02:43.620] There's like three of them. [02:43.760 --> 02:44.920] And they just keep on showing up. [02:45.040 --> 02:46.040] But I found this on Flickr. [02:46.440 --> 02:46.600] No. [02:46.720 --> 02:47.500] Courier of Commons. [02:47.680 --> 02:48.440] No attribution. [02:48.600 --> 02:50.000] So I used it. [02:52.300 --> 02:56.240] We want to actually trap these people trying to smash into our information superhighway Internet blog. [02:57.140 --> 02:59.440] So they're actually going to use honeypots. [02:59.700 --> 03:01.520] Now, what exactly is a honeypot? [03:02.260 --> 03:13.200] A honeypot is a system that, while you're actually trying to convince the attacker, it's this high value, you know, full of shock, wonderful information, social security numbers, credit card numbers, all kinds of wonderful things. [03:14.220 --> 03:15.700] It's a horribly secure device. [03:15.700 --> 03:21.240] But in reality, it's something that you are watching like a hawk and monitoring every move that they try to make. [03:22.140 --> 03:35.120] The first time that I actually really ever ran into this, and I think it's the first time... I've seen it referenced a couple of times as the first real honeypot, was an evening with Burford with Bill Cheswick and about three other authors. [03:35.300 --> 03:41.160] He was the AT&T Internet connection back in... or managed the Internet connection back in 1991. [03:41.960 --> 03:43.260] And he got attacked. [03:44.000 --> 03:48.260] And he set up a... on his real system, he set up a fake system so this attacker could log in. [03:48.660 --> 03:53.480] And they traced him all the way back down to, I don't know, Norway, Netherlands, somewhere along there. [03:53.960 --> 03:55.100] A really fun story. [03:55.260 --> 03:58.000] It's publicly available on the Internet. [03:58.620 --> 04:01.860] And also it's a part of his practical firewalls. [04:01.900 --> 04:02.820] I believe that's what it's called. [04:04.780 --> 04:06.960] There are two main types of honeypots. [04:07.420 --> 04:09.220] High interaction and low interaction. [04:09.560 --> 04:18.600] High interaction is what you probably are all expecting a honeypot to be, you know, a real actual system that you're plugging in and plugging out on the Internet, be it physical or virtualized. [04:20.040 --> 04:29.080] And now the issue with a high interaction honeypot with a real computer plugged into your connection, obviously it's going to get hacked because... Oh, if it doesn't get hacked, please tell me who your ISP is. [04:30.700 --> 04:35.300] And it's with a real computer getting hacked, you're actually going to run into real threats and more problems. [04:35.440 --> 04:45.420] Because when this person actually attempts to attack your computer and compromises it, he's actually going to probably do something bad with it that you don't want to happen on your interconnection. [04:45.680 --> 04:46.800] You want to be in charge of that. [04:47.740 --> 04:51.460] The other type of honeypot is a low interaction honeypot. [04:52.360 --> 04:56.180] There are two main ones that are in use today. [04:56.360 --> 04:57.200] One is called Nepenthes. [04:57.360 --> 04:59.680] And I'm probably mispronouncing that because it's some... [04:59.680 --> 04:59.760] Hmm? [05:01.020 --> 05:01.380] Nepenthes. [05:01.680 --> 05:02.180] Okay, thank you. [05:03.160 --> 05:05.060] I'm going to have to tell all my co-workers that. [05:05.720 --> 05:07.400] Or another thing called HoneyD. [05:07.920 --> 05:11.700] What it is is it provides an attacker with what I call a movie set computer. [05:12.420 --> 05:13.260] You think you're... [05:13.260 --> 05:20.140] You know, you look at all these movie lots in Hollywood and wherever, and it's, you know, Main Street USA or it's, you know, some French village. [05:20.680 --> 05:25.540] And you look at it and it looks great from the front, but if you actually peer around behind, it's actually nothing behind it. [05:26.340 --> 05:34.940] Actually, another thing that I came up with while I was listening to cover presentation, it's sort of like one of those non-player characters from, like, Final Fantasy I, where if you say two or three things to him, that's about it. [05:35.320 --> 05:37.000] You know, I'm looking for my pet dog. [05:38.340 --> 05:39.320] It's a fake computer. [05:39.760 --> 05:42.540] It's not actually going to get compromised, or hopefully not. [05:43.020 --> 05:44.840] Therefore, it's less threats and less problems. [05:44.980 --> 05:50.120] You're not actually going to be hosting all these horrible, mean, nasty, ugly things, and attacking other computers. [05:51.480 --> 05:52.780] High Interaction Honeypots. [05:53.000 --> 05:54.740] You really don't want to be running these. [05:55.220 --> 05:56.480] You can if you want to. [05:56.540 --> 06:02.560] I'm not going to tell you you can't, but it's a lot of headaches, and you have to be on top of it at all times. [06:03.440 --> 06:09.760] You can basically use a real computer, or a physical virtual computer with actual vulnerabilities, be it VM... [06:09.760 --> 06:19.180] You can run it on top of VMware, you can run it on top of Xen, user mode Linux, or if you want, just, you know, find your old, you know, Pentium 266 and toss that on your Internet connection there. [06:19.900 --> 06:21.060] Like I said, real problems. [06:21.180 --> 06:35.860] Attackers can and will use your Honeypot to attack other systems, because normally what you see is you see someone coming in, breaking into your computer, dropping his little, you know, botnet client, you know, DDoS client, something else, and then giving it commands to scan for other, [06:36.000 --> 06:38.580] well, scan for other computers, be it Honeypots or not. [06:40.400 --> 06:50.200] There's a program out there called Snort Inline, which uses IP, FW, IP tables, and all that stuff, and Snort to see, okay, I have outbound traffic. [06:50.400 --> 06:51.220] Okay, is it bad? [06:51.420 --> 06:51.780] Yes. [06:51.960 --> 06:52.980] Okay, I'm not going to send it. [06:53.180 --> 06:53.920] Is it not bad? [06:54.100 --> 06:54.320] No. [06:54.520 --> 06:55.440] Okay, I can send it. [06:55.940 --> 07:07.300] What that will allow the attacker to do is, you know, grab his toolkit, grab, you know, do whatever he actually wants to, to your box, but not actually go out to the Internet and attack other boxes. [07:08.580 --> 07:09.860] It will protect you. [07:10.060 --> 07:11.060] However, it is Snort. [07:11.160 --> 07:11.940] It's signature-based. [07:12.260 --> 07:20.420] It's not going to... unless you keep really on top of it with all your latest IDS definitions, you are going to, you know, you might have something that sneaks through. [07:22.080 --> 07:23.740] You always need to keep on top of it. [07:23.860 --> 07:26.700] And as they always say, lots of risk, but lots of reward. [07:26.840 --> 07:36.460] Because with an actual computer, with people downloading stuff to it and attacking other systems, you are going to get the best picture available of what these people are doing to computers out on the Internet. [07:37.020 --> 07:42.000] And you can do, you know, if you want to see, if you want to research into that, this is exactly what you want to do. [07:43.740 --> 07:44.900] Low-interactive honeypots. [07:44.940 --> 07:46.320] Like I said, they're a fake computer. [07:46.520 --> 07:50.780] It's either a spoof device or a physical or a virtual device that spoofs vulnerabilities. [07:52.140 --> 07:54.420] Very much less of an attack profile. [07:55.000 --> 08:02.300] It's not actually a real computer, and so it's only kind of faking a real computer with fake vulnerabilities on it. [08:03.120 --> 08:04.060] Less of a threat. [08:04.180 --> 08:10.940] However, you're really going to start running into issues when they start attacking it and trying to get predicted responses off it. [08:11.040 --> 08:23.180] And if they start seeing, hey, you know, this is not exactly responding the way I expect it to, they're either going to think it's a busted system and they're not going to attack it anymore, or they're going to start, you know, looking at it closer and they're going to find out, [08:23.300 --> 08:24.160] you know, jigs up. [08:25.400 --> 08:29.040] Not as realistic as high-interaction, like I said, but it will save you many headaches. [08:30.040 --> 08:38.960] If I was actually running this, running a high-interaction honeypot off my Internet connection, I have to probably, you know, re-wipe it and reinstall it every week at least. [08:39.740 --> 08:47.420] It will save you many a headache from doing that with a low-interaction honeypot because you won't have to be doing that because hopefully we'll never get compromised. [08:48.820 --> 08:53.180] So let's talk about high-interaction honeypots, because I think this slide is actually out of a thing. [08:54.920 --> 08:56.480] How high-interaction honeypots works. [08:56.520 --> 08:59.160] We have our evil attacker, and you can tell he's evil because he's wearing an eyepatch. [08:59.780 --> 09:01.760] And he is attacking the honeypot server. [09:01.880 --> 09:07.300] Now, the honeypot server is a real computer, and he's going to compromise it and do evil things to it. [09:07.460 --> 09:12.940] But what he doesn't know, and hopefully he won't find out, is that it's actually relaying everything he's doing over to a monitoring server. [09:13.280 --> 09:22.720] Now, the monitoring server can be doing, like, you know, it can be running Snort, it can be running an IDS, it can be running, you know, all kinds of things that will sniff packets and track them. [09:22.920 --> 09:32.320] However, if, for example, he sets up Secure Shell and he starts running encryption, that's going to really start to become an issue, because you won't be able to see exactly what he's doing, unless you start doing forensics on the box. [09:32.460 --> 09:36.340] There is a program out there called Sebek, S-E-B-E-K. [09:37.200 --> 09:39.140] I completely forget where the website is. [09:39.140 --> 09:51.600] What it will allow you to do is it will allow you to monitor... it will allow you to see exactly what he's doing at the console and replay it back as if you're staring at it, which is what Dudley Do-Right is doing. [09:53.840 --> 09:54.240] Setup. [09:54.240 --> 10:01.620] Your two main choices are Linux and Windows, because 90% of what people are going to compromise are these two operating systems. [10:02.620 --> 10:17.040] Linux, you'll see a lot more... technically, Windows, you'll see a lot more automated things, like, you know, Slammer, Sasser, you know, all these little viruses you've seen over the past six years, but people haven't been patching their systems, so they're still out there. [10:17.680 --> 10:24.280] Linux, you'll start running into more of, you know, botnet clients, which you will see on Windows to a lesser extent, automated-wise. [10:24.420 --> 10:29.960] A lot of the botnet clients for Windows are client-side attacks, you know. [10:29.960 --> 10:35.000] Aunt Mary goes to some random website, which is then compromised, and they download it onto our system. [10:35.700 --> 10:46.620] Linux, you're seeing a lot of stuff where people are running automated scripts to put their botnet clients directly on the computer via a vulnerability of some sort, and then just compromising like that, and then forgetting about it. [10:47.640 --> 10:55.080] Hardware-wise, nowadays, I mean, I guess, you know, back in the days, you'd be into, you know, they want to have more and more hardware, more and more hard processing cycles. [10:55.400 --> 10:56.620] You really don't see that nowadays. [10:58.740 --> 11:00.480] Bandwidth, that's the only thing they're interested in. [11:00.620 --> 11:06.240] If they can have, you know, a nice fat pipe to download their, you know, wares, porn, and MP3s, they're going to be happy. [11:08.500 --> 11:10.280] But sometimes you just don't even see that. [11:12.660 --> 11:13.020] Virtualization. [11:13.140 --> 11:14.580] Everyone says, oh, okay, I'll be cool. [11:14.740 --> 11:15.900] I'll run virtualization. [11:16.200 --> 11:24.060] I'll be able to have my honeypot, and I'll be able to keep my real server on at the same time without having to do any kind of, you know, technical tomfoolery with my firewall rules. [11:25.100 --> 11:26.400] Yeah, you don't want to do that. [11:26.520 --> 11:29.420] I've heard that, you know, two or three times, so I'm just going to toss it out here. [11:30.840 --> 11:35.200] You're never going to be 100% sure that there's not going to be something in the hypervisor that they're going to be able to see. [11:35.580 --> 11:36.500] They're going to break out. [11:36.620 --> 11:38.400] They're going to, you know, compromise your entire box. [11:39.440 --> 11:41.600] You're never going to be 100% sure they're not going to notice. [11:41.900 --> 11:46.340] VMware, for example, is very easy to detect if you're running on top of it. [11:46.920 --> 11:53.000] But user mode Linux, there's a couple of patches that will allow you to jail it and cheroot it. [11:53.660 --> 11:59.100] That will save you on the breakout side, but there are ways to tell that you're running within a virtualized system. [12:00.700 --> 12:06.240] And you hear people about running this on their local homeland, on their local server, with all their important documents. [12:06.920 --> 12:07.140] No. [12:10.250 --> 12:14.950] With high-attraction honeypot, stopping attacks, like I said, you need to monitor it like a hawk. [12:14.970 --> 12:16.250] You need to do it 24-7. [12:16.370 --> 12:27.910] And as soon as you know you're compromised, you need to make sure of, you know, you have the ability to be there to physically unplug that system and, you know, disconnect from the Internet so you're not attacking anybody. [12:29.570 --> 12:33.270] The hard part with this is actually making the determination of when the attacker is done. [12:33.630 --> 12:43.470] A lot of times it's easy when you're actually just dealing with someone who's, you know, spraying and praying exploits, you know, trying to comprehend... scanning an entire netblock hoping he'll net one or two boxes. [12:45.790 --> 12:56.410] Sometimes, although rarely, you'll actually run to someone where it'll be a physical human on the other side of the keyboard, where you're never exactly sure when he's done, you know, is he done putting his stuff up there? [12:56.470 --> 12:57.450] Is he gonna come back later? [12:57.770 --> 12:59.410] Do we want to keep this box up and running? [12:59.890 --> 13:01.350] It's going to be a judgment call. [13:01.630 --> 13:08.990] And, you know, I don't want to make that judgment call because, quite frankly, I don't want my system ever touching someone else's system where I get sued. [13:11.210 --> 13:12.930] You need to pull the plug immediately. [13:13.350 --> 13:14.730] Like I said, no really now. [13:15.370 --> 13:19.030] A lot of people are like, oh, well, you know, I'll give it another week or so. [13:19.170 --> 13:25.290] And what they're not knowing is they're not watching it close enough and they're not realizing that they're scanning, you know, half China, which is bad. [13:25.890 --> 13:33.210] Like I said, Snort-in-line, Snort-based utility that uses IP tables or IPFW to drop malicious backup, not 100% protective, like I said, signatures. [13:34.230 --> 13:35.570] Low-interaction honeypots. [13:35.690 --> 13:39.390] Now, I enjoy this picture because it's exactly what we want to present to the attacker. [13:39.590 --> 13:40.070] Look at that. [13:40.090 --> 13:40.790] It's a wonderful pool. [13:40.870 --> 13:41.530] There's waterfalls. [13:41.650 --> 13:42.430] It's going to come right in. [13:42.510 --> 13:44.930] And what in reality you don't really realize is that it's a chalk drawing. [13:45.030 --> 13:47.270] Anything below the stairs is all chalk. [13:50.130 --> 13:52.010] Three low-interaction honeypots. [13:53.350 --> 13:57.910] Nepenthees emulates fake vulnerabilities on a physical computer to collect exploits. [13:58.550 --> 14:07.850] It runs a... basically it binds to a bunch of ports where, you know, Samba or Windows file sharings or I think it also does Apache. [14:07.990 --> 14:08.890] We can get into more of that later. [14:09.310 --> 14:10.350] The second one is HoneyD. [14:10.610 --> 14:16.690] What HoneyD more or less does is it emulates fake computers on your network in which you can, you know, send scanned responses. [14:16.870 --> 14:19.730] This is more or less exactly what the NPC analogy is. [14:20.630 --> 14:22.930] There's another utility out there called HoneyTrap. [14:23.210 --> 14:30.870] What HoneyTrap does is it waits for anything to connect to your computer, binds a port to that, and then just tries to capture whatever is sent to it. [14:32.930 --> 14:33.330] Nepenthes. [14:33.690 --> 14:35.470] You need a physical computer to set it up. [14:36.470 --> 14:38.610] It'll, like I said, it'll bind to a bunch of ports. [14:39.210 --> 14:45.010] It'll, you know, I think it does FTP, Samba, Apache. [14:45.390 --> 14:49.430] It emulates a ton of exploits or exploitable services. [14:49.630 --> 14:54.650] So when, you know, you see someone running an automated exploits, it says, oh, okay, yeah, I'm attackable. [14:54.710 --> 14:55.230] Please attack me. [14:56.190 --> 15:03.690] And what it then does is it, you know, waits for the person to send whatever they're going to do and collects whatever they're sending to you. [15:04.510 --> 15:06.390] And I have wonderful two-act play. [15:07.170 --> 15:08.870] The attacker there sends an exploit. [15:08.870 --> 15:11.690] The Nepenthes server says, oh, geez, I'm vulnerable to that. [15:11.790 --> 15:13.270] You know, just give me whatever you're sending me, whatever. [15:13.730 --> 15:17.470] And it sends its evil bits of code to compromise your computer. [15:17.470 --> 15:22.870] And then it promptly stops and captures it and seals it all up for a nice little box for you to look at later. [15:23.270 --> 15:23.850] Good question. [15:23.970 --> 15:25.370] You say Linux all the time. [15:25.470 --> 15:26.310] What about Solaris? [15:26.370 --> 15:27.190] Is that involved too? [15:27.730 --> 15:29.830] You can, well, we can get into that at HoneyD. [15:30.830 --> 15:32.970] Solaris, I've never actually used in a Honeypot environment. [15:32.970 --> 15:41.930] But with a high interaction Honeypot, you want to run Solaris, you want to run HP UX, you want to run, you know, Windows 3.1, anything... Hmm? [15:42.530 --> 15:43.450] Oh, yeah. [15:43.970 --> 15:46.650] With a high interaction Honeypot, you can choose whatever operating system you did. [15:46.750 --> 15:49.910] I choose Windows and Linux because they're the most commonly exploited ones out there. [15:51.770 --> 16:00.330] Occasionally, when you're going through your Snort logs, you'll see, you know, either a sadmind or what's the other one they always thought about, the Solaris Telnet exploit. [16:02.210 --> 16:05.590] Very rarely do you see stuff that's specifically tailored to Solaris. [16:05.590 --> 16:11.050] But if you want to toss an old Solaris box out there and really make them wonder what the heck's going on, go right ahead. [16:13.050 --> 16:17.350] And so we have Dudley Do-Right, who has captured the evil Trojan and the attacker is saying curses. [16:18.710 --> 16:21.950] Nepenthes, pros, it can be used on any existing server. [16:22.130 --> 16:34.850] So, for example, if you have on your home DS broadband connection a web server that you're using to share photos or an FTP server that you're sharing with friends, you can disable those modules so that Nepenthes won't listen on those ports and run on everything else. [16:36.050 --> 16:42.350] And you will be able to collect exploits and, you know, do whatever you want with them and still run your home server. [16:42.650 --> 16:46.870] Again, this goes back to that whole, you know, are you comfortable with this running on your home server? [16:48.830 --> 16:53.270] Because with, as with any program, as in the last point, since it's listening on a port, it can get compromised. [16:53.690 --> 16:58.690] I don't think I've ever actually seen a security bug with Nepenthes, but I'm sure they exist. [17:00.530 --> 17:15.790] There was actually something that they were talking about on their weblog where the botnet herders were getting wise and what Nepenthes will do is say, for example, you know, I'm compromised and I'm sitting behind my NAT firewall and I have a 192.168 address and my, [17:15.810 --> 17:28.610] you know, compromised computer is saying, oh, you know, I'm scanning everybody, but when they say, okay, grab my file via TFTP, I'm on 192.168, Nepenthes are smart enough to actually say, okay, let me go try with the IP address it connected me to and maybe we'll get lucky. [17:29.070 --> 17:41.010] What the botnet herders were doing were was sending with a 192.168 address and seeing if anyone connected back to them when they were doing their scans and making a more or less a real-time black hole list in the Nepenthes nodes. [17:41.250 --> 17:44.710] So they changed the default configuration to not do that. [17:46.770 --> 17:51.870] The pros with the Nepenthes is that if you ever want to collect Windows exploits, Nepenthes is your program. [17:52.110 --> 17:58.210] It will do all kinds of wonderful, you know, Sasser, Blaster, keeps track of Slammer. [17:59.990 --> 18:08.650] And there's like a giant list of exploits or automatic virus exploits that will try to connect and allow you to monitor. [18:09.290 --> 18:11.750] The cons with the Nepenthes is that somewhat difficult to set up. [18:14.490 --> 18:19.350] I, you know, you want to run it on a binary if you have the chance, because compiling it from scratch is rather difficult. [18:19.930 --> 18:24.950] Like, I almost pulled my hair out and I consider myself fairly, fairly okay in setting up software. [18:26.650 --> 18:28.970] Its knowledge of exploits is kind of limited. [18:29.210 --> 18:36.030] Like, for example, I was actually running it, this happened a couple of months ago, where there was something running rampant on the network. [18:36.130 --> 18:37.510] We didn't know what exactly it was. [18:37.650 --> 18:41.490] It was connecting to our Nepenthes blocks and it was saying, unknown exploit, I'm not going to do anything. [18:41.930 --> 18:46.630] So, which is really annoying when you're trying to figure out exactly what the hell is going on. [18:47.490 --> 18:48.430] Logging is a bear. [18:48.690 --> 18:50.530] The logs are horrid in it. [18:52.110 --> 18:59.850] It's not going to be very tell you exactly what's going on and actually trying to configure it to do verbose logging is very painful in itself. [19:00.270 --> 19:05.670] You can tell that it was done more or less as a hack, where it's sort of like, oh, shoot, we should really log this. [19:07.550 --> 19:10.270] Like I said, since it's listening on a port, it can get compromised. [19:11.810 --> 19:15.030] Honey Trap, what it is, is sort of like Nepenthes diet. [19:16.210 --> 19:19.870] It basically listens for any type of connection to any port on the system. [19:20.670 --> 19:23.050] And then it opens up, oh, you know, I'm listening on that port. [19:23.150 --> 19:24.490] Please send me whatever you're trying to send me. [19:26.490 --> 19:29.370] It also, you know, it's Windows, Linux, it doesn't really matter. [19:30.290 --> 19:36.330] It can be installed on existing machines, much like Nepenthes. [19:36.550 --> 19:39.790] And this is very much a homeless man's honey pod, which is even below poor man. [19:42.070 --> 19:45.610] How honey trap works, you send your exploit and it goes, no, no, no, no, no. [19:50.290 --> 19:51.350] That's all it does. [19:51.490 --> 19:55.750] It just, you know, whatever you pack, whatever this, you know, packet is, it just sits there and go, yeah, keep on sending it. [19:56.130 --> 19:56.690] I'm cool. [19:58.330 --> 20:00.090] Honey Trap is that it's dead simple. [20:00.270 --> 20:01.170] It's very easy. [20:01.210 --> 20:02.470] It's very easy to set up. [20:02.610 --> 20:04.610] It's kind of, I wouldn't say very easy. [20:04.690 --> 20:05.890] It's easier to set up in Nepenthes. [20:06.870 --> 20:08.250] Very limited interactivity. [20:08.430 --> 20:17.550] I think there's a couple of things out there where people are actually trying to make it run scripts and actually say, okay, this is, you know, you connected me on port 21. [20:17.750 --> 20:18.610] I'm an FTP server. [20:18.730 --> 20:19.910] Please give me your username and password. [20:20.530 --> 20:29.990] But as for, you know, Nepenthes, it does a very good job, it does a very good job running on, you know, CIFS and Samba and, you know, Windows file sharing. [20:30.410 --> 20:31.510] Honey Trap doesn't do that. [20:31.510 --> 20:32.910] Technically, HoneyD doesn't do it either. [20:34.810 --> 20:38.910] Honey Trap does keep logs, which are slightly better than Nepenthes, but that's sort of like being the tallest midget. [20:42.670 --> 20:45.930] HoneyD, hey, I'm just saying like it is. [20:46.510 --> 20:49.150] HoneyD, HoneyD was developed by Niels Provost. [20:49.270 --> 20:50.850] He now works for Google, so you know he's really smart. [20:52.530 --> 20:54.370] Emulates, it's a really nice program. [20:54.570 --> 20:59.430] It emulates hosts on a network that either run programs or scripts specified in the configuration file. [21:00.210 --> 21:10.470] If you have, you know, a slash 24 sitting around on your network, which I'm sure you all do, you can tell it, you know, HoneyD, listen for every type of connection to this class C network that I'm going to give you. [21:10.850 --> 21:14.310] And you have to, you know, do some ARP issues if you're on Ethernet. [21:15.850 --> 21:24.870] Listen for anything and, you know, here's a bunch of addresses, you know, you're running a web server on this port, you're running a Windows box on, you know, this port, running an IES emulator. [21:25.610 --> 21:27.450] And you can have it, you know, configured down. [21:27.690 --> 21:35.070] When I first ran into this, I was just, I was on a capture the flag contest and we had a class C network that we could, you know, hack around on where everyone else was sitting. [21:35.430 --> 21:36.670] So there were eight boxes. [21:36.810 --> 21:39.970] And I said, okay, well, how can I actually make this very annoying for everyone else? [21:40.050 --> 21:43.670] So I started up HoneyD and I had it listed on every other possible IP address space. [21:43.870 --> 21:46.610] So eight boxes suddenly blossomed into 253. [21:47.210 --> 21:48.910] I wasn't very popular that weekend. [21:50.790 --> 21:53.170] It's got a very good amount of IP trickery. [21:53.310 --> 21:55.650] Like, for example, I mean, class Cs are just the beginning of it. [21:55.910 --> 22:01.090] I've heard people running, you know, more or less entire... you can say, okay, here's your class C. [22:01.210 --> 22:03.250] Okay, but you're also connected to this class C over there. [22:03.370 --> 22:08.790] But if, when you're responding on it, emulate yourself over a 64 kilobit link, and it will do it. [22:08.890 --> 22:18.290] And you can say, okay, you know, this link that you're entering, you know, this class C, when you respond to it, pretend you have a very latent connection, like, you know, 100 millisecond ping, you know, it's nothing. [22:18.430 --> 22:20.090] You want to do it, like, you know, 1,000 milliseconds. [22:20.710 --> 22:30.930] And it does a very good job trying to convince people that, you know, oh, you know, I'm an actual... you know, in reality, you're a Linux box running on some type of IP, but, you know, you'll respond back, oh, I'm Solaris. [22:31.750 --> 22:43.510] And, you know, it'll completely fool Nmap, because what Nmap... what HoneyD does is take Nmap's, you know, I don't know what exactly they call it, the file they use to determine whether or not what operating system you're running... fingerprinting system, [22:43.630 --> 22:43.910] thank you. [22:45.290 --> 22:50.210] And it uses that to spoof its responses back, so... whoops. [22:50.490 --> 22:52.070] Anyway, so we have Dudley Do-Right again. [22:53.190 --> 22:56.670] What this is, is the attacker then connects to something called Ghost. [22:56.930 --> 22:59.410] I don't know... that's not the official term, that's something I came up with. [22:59.530 --> 23:01.750] I don't exactly know what they call the spoofed computers. [23:01.910 --> 23:03.550] Maybe they just call them spoofed computers for all I know. [23:04.870 --> 23:15.250] The attacker comes in and connects to one of the ghosts, at which point HoneyD then replies, spoofs reply back from... with the IP that the attacker connected to saying, you know, it says sin. [23:15.470 --> 23:17.570] Okay, I'm this IP, SYN/ACK, what do you want? [23:19.470 --> 23:32.870] Now, the interesting part of this is that with the Honey Pot server, or the HoneyD server, you can actually have these ghosts inside of a demilitarized zone, and the HoneyD server can be sitting on your, you know, non-connected to the Internet, but listening to that demilitarized zone, [23:32.910 --> 23:34.930] so people can't actually attack it. [23:35.350 --> 23:39.130] So while, for example... and actually, I think this is covered in cons. [23:39.750 --> 23:46.770] They can attack those Honey Pot ghosts, and if they ever crash the HoneyD daemon, all those ghosts will just suddenly disappear. [23:46.950 --> 23:49.170] You won't... you probably will not get compromised. [23:51.750 --> 24:00.850] You probably... you know, probably is not a very good, you know, odds in network security, but it's safer than running into Pentas, which is actually running a server on a box on a physical hardware. [24:01.710 --> 24:02.690] HoneyD services. [24:03.110 --> 24:08.810] You can forward... what you do is when you set up a HoneyD ghost, you say, okay, ghost, you're listening on this IP. [24:09.110 --> 24:12.130] You are, you know, running, you know, HP-UX 9. [24:13.670 --> 24:16.610] And you're actually... you're running a, you know, web server on port 80. [24:16.730 --> 24:18.230] You're running a telnet port 23. [24:18.370 --> 24:20.070] You're running an FTP on port 21. [24:20.910 --> 24:28.570] What these services, when you're saying you're running FTP web and something, you have to tell it either you want to run a certain script, and there's a bunch of canned scripts out there. [24:28.650 --> 24:29.350] We'll get into that later. [24:30.610 --> 24:35.390] You can actually also forward these ports back to hosts, you know, hosted somewhere else. [24:36.410 --> 24:46.970] These are dangerous because if you're actually running a vulnerable host somewhere else that is actually being used for these HoneyD services, if they exploit that host, that host will get compromised. [24:47.350 --> 24:54.830] So you want to make sure that that's, you know, host is in its, you know, little padded cell so it can't get anywhere, except for your HoneyD server. [24:56.610 --> 24:59.910] Scripts, I actually started writing something called the Script Kitty Annoyance Toolkit. [25:01.270 --> 25:13.850] It's, you know, IMAP Daemon, Telnet Daemon, I think I did, you know, World Wide Web, and basically all it does is it just logs exactly what it runs and then it's, you know, returns a spoofed response, which is normally for, like, you know, an Apache server, [25:13.970 --> 25:16.130] it says 400 or 404. [25:16.250 --> 25:18.410] 400 meaning I have no idea what you're trying to tell me. [25:19.550 --> 25:21.530] There's also scripts available on the HoneyD website. [25:21.530 --> 25:27.150] There's a nice little program called IAS EMU, which is an IAS emulator. [25:27.310 --> 25:30.130] It'll emulate IAS 5 and it's done a really good job. [25:30.930 --> 25:33.530] They did a really good job spoofing a default IAS server. [25:34.470 --> 25:45.590] Another thing that you can do with HoneyD is you can just set up tarp bits where, you know, they'll be scanning and they'll, you know, same thing with Libria is that they, you know, just, it sends a SYN/ACK and then it sets a window size down to zero, where if you're scanning, [25:45.690 --> 25:46.230] they're hosed. [25:48.610 --> 25:50.670] HoneyD is that it's very lightweight. [25:51.510 --> 25:52.970] The pros are very lightweight. [25:53.590 --> 25:57.250] It can emulate very numerous, you know, links, devices, computers. [25:58.330 --> 26:03.530] The, basically, if Nmap, if Nmap can identify it, HoneyD can more or less spoof it. [26:05.270 --> 26:06.490] These ghosts can run everything. [26:06.630 --> 26:10.970] You can actually have a, you know, responding back as a Linux box, but you can have all your ports forwarded to a Windows box. [26:11.130 --> 26:12.370] Really, you screw up those people. [26:13.750 --> 26:15.270] It's somewhat harder to compromise. [26:15.490 --> 26:19.050] Technically, anything that ever interacts with a network can be compromised. [26:19.510 --> 26:25.610] HoneyD just gives you a little bit of abstraction there where it's going to be a touch more difficult if you have your firewall rules set up. [26:26.850 --> 26:29.770] The cons is that it requires a separate IP for each host. [26:29.890 --> 26:40.170] For example, if you're going to try to set this up on your broadband connection and you have a DMZ, but there's a host already in that DMZ, you need to get rid of that host, otherwise HoneyD won't work. [26:42.090 --> 26:43.350] Good for monitoring. [26:44.290 --> 26:47.850] Very bad to try to figure out what they're trying to do with advanced attacks. [26:48.290 --> 26:54.310] For example, you know, HoneyD does not do a good job of, you know, there's no way to really script Samba. [26:55.350 --> 27:01.470] You just really can't do it because of the way the protocols are set up and just it's... [27:01.470 --> 27:03.590] HoneyD wasn't designed for that on the scripting side. [27:04.170 --> 27:10.970] You can, you know, forward that to another Samba server where that gets back to that original point where you want to have that incredibly padded from somewhere else. [27:12.390 --> 27:13.930] Now, you have all these Honey Pots set up. [27:14.030 --> 27:19.270] You want to monitor them because, you know, what happens if you're, you know, mucking along when you're not actually looking at them? [27:19.750 --> 27:20.290] Bad things. [27:20.690 --> 27:22.810] Why are you actually investing your time to do it in the first place? [27:25.070 --> 27:25.470] Snort. [27:25.470 --> 27:26.350] Snort, enough set. [27:26.710 --> 27:29.050] It's, you know, everyone uses it for an IDS. [27:29.150 --> 27:30.350] Technically, you can use any IDS. [27:30.450 --> 27:37.350] If you have, you know, yourself, you know, a $10,000 IDS sitting underneath your bed, you can use this to monitor your Honey Pot. [27:37.590 --> 27:42.830] For the rest of us, Snort, developed by Marty Roesch back in 1998, is a lightweight IDS. [27:43.170 --> 27:44.390] Lord knows it isn't that now. [27:45.170 --> 27:47.970] It's more or less the gold standard in open source IDS systems. [27:49.010 --> 27:50.830] He's really... he's made it into his own little company. [27:50.970 --> 27:52.030] Everyone seems to be using it. [27:53.510 --> 27:59.750] There's a couple of contenders out there that may develop in the next couple of years that may provide competition, but we'll see. [28:00.610 --> 28:03.670] Snort, and one of the major complaints that everyone has about it, is that it's signature-based. [28:03.810 --> 28:04.910] It's a lot like your antivirus updates. [28:04.990 --> 28:08.290] If you're not keeping those signatures up to date, you're not going to be able to catch anything. [28:10.050 --> 28:12.730] There's a couple of utilities to monitor Snort. [28:13.550 --> 28:24.830] Snort provides this wonderful little alerts file where, you know, if you want to have it up in a console window entailing it, that's very easy to do, but if you want to try to catch up to it, you know, come back in the morning and you see, oh, hey, I had 200 attacks last night. [28:24.930 --> 28:28.130] It's going to be rather difficult to actually make... see what actually was going on. [28:28.430 --> 28:29.830] So they made utilities for it. [28:31.350 --> 28:33.050] I'm going to horribly mispronounce this. [28:33.330 --> 28:33.650] Squeal? [28:34.430 --> 28:34.750] Squeal? [28:34.890 --> 28:35.230] I don't know. [28:35.870 --> 28:38.530] It's a... it's an acronym for something. [28:38.790 --> 28:54.130] It's basically... it's a very nice tickle-based monitor where you feed it an alerts file, and it will then, you know, make it all out to nice parsing, and you can tell exactly what was going on and say, okay, you know, this IP attacked me 1500 times last night. [28:54.250 --> 28:55.090] I should actually look at that. [28:55.690 --> 28:58.910] The other one is... that came out is Base. [28:59.750 --> 29:04.850] Came out... there was a wonderful product called Acid, which is the Analysis Console for Intrusion Detection. [29:05.290 --> 29:08.970] Acid stopped being worked on about a while ago. [29:09.110 --> 29:09.750] Very long time. [29:11.110 --> 29:15.070] And so what someone did is they saw Acid and they said, oh, wow, this is a really nice program. [29:15.190 --> 29:16.190] Too bad it hasn't kept up to date. [29:16.350 --> 29:18.570] So they decided to keep it up to date themselves, and they came up with Base. [29:18.830 --> 29:19.590] Acid Base. [29:20.610 --> 29:22.510] I know. [29:22.890 --> 29:23.250] Yeah. [29:24.530 --> 29:27.010] And Base stands for Basic Analysis and Security Engine. [29:27.150 --> 29:28.670] You can't tell that was backernamed, can't you? [29:29.350 --> 29:30.850] Base.Security is .NET. [29:31.350 --> 29:33.130] Squeal is Squeal.SourceForge.NET. [29:33.530 --> 29:37.810] There's a very, very, very lightweight program called SnortSnarf. [29:38.030 --> 29:39.710] SnortSnarf, what it does is it takes alert file. [29:39.850 --> 29:42.810] It actually isn't under... it's not under being maintained anymore. [29:43.090 --> 29:55.370] But you take an alert file, you read it into SnortSnarf, or you take a Snort alert file, you read it into SnortSnarf, it creates all kinds of wonderful, beautiful HTML files where you can put it on a static web page and not have to worry about PHP or, [29:55.410 --> 29:59.650] you know, SQL, or, you know, just toss it into Internet Explorer if you really want to. [29:59.750 --> 30:00.410] It'll work fine. [30:01.930 --> 30:07.450] Base requires a SQL backend, and it requires the Snort to be configured to feed into that SQL backend. [30:08.110 --> 30:08.810] Simple to do. [30:09.630 --> 30:11.750] Snort's very good with that with its Barnyard plugin. [30:16.930 --> 30:17.570] Pardon me. [30:18.110 --> 30:18.870] TCP dump. [30:19.330 --> 30:21.410] The Swiss Army chainsaw of packet sniffing. [30:21.490 --> 30:24.190] I'm sure most people have either heard of it or have seen it before. [30:25.130 --> 30:26.990] If you haven't... wow, that cave musty. [30:27.070 --> 30:27.590] Very musty. [30:29.070 --> 30:31.330] TCP dump, you can use it to monitor everything. [30:32.270 --> 30:37.690] Basically, you can say, TCP dump just capture every packet you see ever and write it to a file. [30:38.990 --> 30:42.310] If you run... if you run TCP dump, there's something called a SnapLin. [30:42.830 --> 30:50.430] TCP pump by default will only capture X amount of bytes, and if you're monitoring, say, an Ethernet segment, your packets can be up to 1500 bytes. [30:50.590 --> 30:55.170] So it's only going to capture that first X amount of bytes for what the SnapLin is configured for. [30:55.330 --> 31:02.590] So if you're using it to monitor your intrusion detection, you want to get a best picture of what's going on, you want to have it to set as your maximum transmittable unit. [31:03.170 --> 31:04.750] I learned that the hard way, as you can tell. [31:06.930 --> 31:10.690] It's very handy to piece together new attacks or see stuff that Snort missed. [31:10.690 --> 31:12.490] Snort, like I said, is signature-based. [31:13.070 --> 31:14.590] It's not going to capture everything. [31:15.470 --> 31:28.510] So what you want to do is you want to have TCP dump to capture everything that Snort is missing, and if Snort, for example, has some type of... if Snort doesn't have a zero-day exploit for its signature yet that just came out not even three hours ago, [31:28.850 --> 31:39.290] TCP dump will allow you to see what the heck's going on, and if, you know, someone at Snort is asleep at the wheel, you can actually configure your own Snort rule for that. [31:41.010 --> 31:52.670] A lot of the times with Internet Storm Center, if, you know, people actually go visit it, they call... if they see a new exploit come out, they ask for people to capture TCP dump, and you can say, ha-ha, I can do that. [31:52.690 --> 31:53.390] I can mail that to you. [31:54.970 --> 31:57.130] What it is is there's a PCAP format. [31:57.270 --> 32:05.950] PCAP is a pretty standard way of... that TCP dump writes its files, and you can import that into Snort, Wireshark, Network Rep, NGrep. [32:06.670 --> 32:12.650] It's a very standard... almost any type of packet dumping or packet-stiffing utility will support it. [32:15.710 --> 32:25.730] Warning, if you are using TCP dump, and I'm sure that no one here is doing anything illegal off their Internet connection, you are monitoring your network. [32:25.890 --> 32:32.570] If you are going to monitor your network, and this also comes out for Snort, you may record traffic that you may not want recorded. [32:32.950 --> 32:36.190] You know, going to, you know, PersianKitty.com or something. [32:37.710 --> 32:47.110] Go, you know, make sure that your tcpdump, Snort, whatever you're using to monitor your network is only picking up the package you want it to, and not to say, you know, your console where you're trading on Pirate Bay. [32:47.490 --> 32:51.670] So if you get a knock on the door, you're not having a wonderful, here, have my libpcap file. [32:51.750 --> 32:52.910] You know, you can use that with Wireshark. [32:56.710 --> 32:57.950] Monitoring HoneyD and Nepenthes. [32:58.290 --> 33:03.110] Now, HoneyD and Nepenthes, HoneyD has a very arcane file structure for its logs. [33:03.610 --> 33:04.870] Nepenthes, like I said, it's a hack. [33:04.990 --> 33:07.830] They kind of like said, oh, geez, we really need to write a logging feature on this. [33:09.610 --> 33:12.610] It's Nepenthes, the HoneyD logs are very arcane. [33:12.750 --> 33:21.490] Like, it's sort of like, you know, host IP space, your destination IP space, port number, and then it's like, you know, four or five different type of file lines you can get from that. [33:23.870 --> 33:27.650] Thankfully, I came across this wonderful utility that not a lot of people are using, called Prelude. [33:27.850 --> 33:31.110] It's called Prelude IDS, which is stupid because it's not an IDS. [33:31.250 --> 33:35.290] They're like, oh, geez, we'll go create an IDS that will compete with Snort. [33:35.390 --> 33:38.070] And then they realize, wait, Snort doesn't really suck that bad now, does it? [33:39.330 --> 33:43.450] It's very much a way to correlate indications and warnings. [33:45.790 --> 33:53.690] You don't need to use it, but it has a pretty web-based console, so you can show it off to your supervisor, significant other, or whatever you want, whoever wants to actually see it. [33:55.330 --> 33:56.110] It's very nice. [33:56.250 --> 33:58.930] It has a great program, horrible documentation. [33:59.210 --> 34:04.210] Like, they, like, you know, just toss some things up on their website, and they're like, oh, it's documented. [34:04.270 --> 34:04.770] We're all set. [34:04.970 --> 34:07.590] We would really like some other people to write our documentation for us. [34:07.830 --> 34:08.430] Yeah, no shit. [34:10.210 --> 34:11.090] It's really bad. [34:11.250 --> 34:11.770] I'm not kidding. [34:12.370 --> 34:13.470] It's disgusting. [34:13.710 --> 34:16.210] Like, it's like eight lines of, like, here's how to set up the web interface. [34:17.030 --> 34:19.570] Please, you know, attach Slot A to Tab B, okay? [34:19.870 --> 34:20.310] There you go. [34:20.390 --> 34:20.770] You're all set. [34:20.910 --> 34:21.170] Wait a minute. [34:21.250 --> 34:21.730] It's not working. [34:22.090 --> 34:22.550] Too bad. [34:23.390 --> 34:26.490] It's open source, but it's not really open source. [34:26.630 --> 34:32.490] It's released under a GPL, but if you ever want to create a patch for it, you have to sign over your patch to the maintainers so that they own it. [34:34.310 --> 34:35.470] Asterisk does the same exact thing. [34:35.570 --> 34:43.230] I've never been comfortable with it, so I just, whenever I create a patch, I just release it under my own little license, and I don't let them incorporate it into their source tree. [34:43.450 --> 34:43.850] Forget you. [34:45.130 --> 34:46.250] How Prelude works. [34:46.890 --> 34:48.390] Well, so, for example, like, can we see it actually? [34:48.550 --> 34:52.130] So the two files down at the bottom are, say, like, a HoneyD file and a Nepenthes file. [34:52.670 --> 34:56.050] That gets read into something called a Prelude LML. [34:56.290 --> 35:00.290] Now, the LML stands for a Lackey Log... Lackey Log... Lackey Manager... [35:00.290 --> 35:01.610] Lackey... Log Manager Lackey. [35:01.690 --> 35:01.990] I don't know. [35:02.330 --> 35:04.330] They thought it was something cute, but I can never remember what it's called. [35:06.190 --> 35:14.430] That, Prelude LML, and these, like, say, for example, you have a Snort installation running, that can both be fed into something called a Prelude Manager. [35:14.590 --> 35:19.290] That actually does all the correlation and will log it into one giant database. [35:19.790 --> 35:24.970] And then, from there, you can actually, you know, look at the database raw if you're using PreWiCA, which is what it's up on the top there. [35:25.090 --> 35:26.250] I'll get a better screenshot later. [35:27.630 --> 35:28.650] You can monitor it. [35:29.510 --> 35:32.970] A lot of... and then it's not just HoneyD and it's not just Nepenthes. [35:33.050 --> 35:42.070] If you're using a... you know, it is support... Prelude LML uses a... can support a lot of different log file managers... or log formats. [35:42.670 --> 35:44.710] You know, Apache, your system logs. [35:44.950 --> 35:48.450] So, for example, if you're running a high-interaction Honeypot, you can actually use Prelude LML. [35:48.730 --> 35:54.950] Of course, you know, if someone... if some attacker actually sees this, they'll start to wonder what exactly is going on, and likely they'll kill it immediately. [35:56.750 --> 35:59.150] And here's a sort of close-up PreWiCA. [35:59.670 --> 36:01.550] This is just some of the stuff that it saw. [36:01.690 --> 36:03.190] This is a screenshot right off their web page. [36:04.830 --> 36:06.590] So, for example, I'm not sure if anyone can see it. [36:06.630 --> 36:09.330] The first line says, you know, web misc, robot text access. [36:09.490 --> 36:10.150] That's a snort alert. [36:11.030 --> 36:19.010] And then it says, you know, two TCP packets dropped, which was coming in through Prelude LML, which is actually something from the internal firewall. [36:21.090 --> 36:22.070] TCP packet dropped. [36:22.230 --> 36:25.950] And then toward the bottom, you notice how everything is nice and orange up on the top and how we got down to red. [36:26.090 --> 36:27.510] We know it's bad because it is red. [36:28.210 --> 36:30.790] It says, like, you know, Back Orifice traffic detected. [36:31.510 --> 36:31.930] TFTPF. [36:32.110 --> 36:32.490] Get it. [36:32.570 --> 36:35.890] And that's all both Prelude LML alerts and snort alerts. [36:36.030 --> 36:41.910] But what it actually has done, and you really can't see it from here, is that it's all correlated to a single time frame from a single IP. [36:42.130 --> 36:45.870] So this 82 dots whatever character is doing something very nasty. [36:46.610 --> 36:48.270] So it's something that you actually want to look at. [36:49.430 --> 36:50.410] Now response. [36:50.950 --> 36:53.130] Now we're running this wonderful little snort impact. [36:53.350 --> 36:57.010] We're running this wonderful little snort in our honeypot. [36:57.530 --> 36:59.030] What exactly are we going to do with it? [37:00.030 --> 37:02.090] And this is exactly... Don't we all want to do this? [37:02.190 --> 37:03.030] Just find whoever's doing it. [37:03.110 --> 37:03.790] Just hit him real hard. [37:05.170 --> 37:06.010] Okay, so you got attacked. [37:06.110 --> 37:06.390] Now what? [37:06.490 --> 37:08.350] Now there's three real options you can take. [37:08.450 --> 37:11.490] You can do nothing, you can attack back, or you can take down the server. [37:12.730 --> 37:13.330] Do nothing. [37:14.270 --> 37:14.970] Easiest thing to do. [37:15.050 --> 37:15.950] Oh, look, I got attacked. [37:19.680 --> 37:22.080] Saves your time, effort, and inevitable frustration. [37:22.270 --> 37:22.790] Trust me, I know. [37:23.390 --> 37:26.580] Cons is that you're actually not being a good neighbor and you're not actually accomplishing anything. [37:27.980 --> 37:29.160] Your choice is yours. [37:29.850 --> 37:30.480] Attacking back. [37:31.330 --> 37:32.480] Yeah, bad idea. [37:35.430 --> 37:35.870] Cons. [37:36.080 --> 37:39.890] I'm sure none of... and I'm sure no one here has ever even thought about doing this. [37:40.750 --> 37:41.180] Illegal. [37:42.040 --> 37:43.660] Are you really attacking the attacker? [37:43.830 --> 37:48.390] A lot of the times, you'll actually see coming... do we have a question there? [37:49.120 --> 37:51.520] Have you ever heard of like a botnet herder? [37:51.520 --> 37:58.730] Maybe he's propagating his botnet and another herder having a honeypot to capture that and then using that as attacking back? [37:58.930 --> 37:59.370] Does that occur? [38:00.040 --> 38:00.730] Um, yes. [38:00.930 --> 38:08.790] I actually haven't heard of the honeypot, but actually the shadow server project used to have publicly accessible all of its, um, statistics on honeypots. [38:08.930 --> 38:10.100] I'm sorry, on botnets. [38:10.330 --> 38:18.460] And what they were actually seeing, and they actually had to remove a lot of people's access from this, is that botnet herders were going around saying, oh, here's a really big botnet. [38:18.750 --> 38:19.870] I want that. [38:20.410 --> 38:21.950] And they were attacking the computer. [38:22.080 --> 38:28.430] They, you know, somehow compromised the botnet where they either came in and they saw, okay, all these computers are attacking... are attached to this botnet. [38:28.580 --> 38:31.660] They obviously must be vulnerable to some type of vulnerability. [38:31.830 --> 38:35.080] Let me just attack these computers rather than scanning entire Class A. [38:35.270 --> 38:46.910] So what they were seeing is, you know, these computers, you know, someone was connecting up to an IRC server, seeing the computer... the infected computers, attacking those infected computers, making them part of their botnet rather than the, you know, [38:46.910 --> 38:48.310] You know, other bad person. [38:50.180 --> 38:52.750] And so they actually had to remove that. [38:52.980 --> 39:04.580] I'm sure honeypots are actually being used by the people who we don't want using them, but I've never heard of anything actually... I've never heard any hard evidence of it, but it's definitely within the realm of possibility. [39:05.580 --> 39:06.700] So as I said, illegal. [39:06.930 --> 39:07.870] I'm sure we all know that. [39:08.480 --> 39:10.120] Are you really attacking the attacker? [39:10.290 --> 39:20.930] A lot of the times you'll just be attacking a, you know, some helpless grandma in, you know, northern New Jersey who, you know, downloaded this thing off the web trying to get Bonzi Buddy, but... [39:24.020 --> 39:26.370] And the other question is, what exactly are you attacking? [39:26.560 --> 39:27.700] What exactly are you accomplishing? [39:27.980 --> 39:30.500] All right, so you, you know, hacked all these computers. [39:32.390 --> 39:32.790] Congratulations. [39:33.230 --> 39:37.870] You know, you remove the evil botnet client. [39:38.120 --> 39:39.640] These computers are still going to get attacked. [39:39.810 --> 39:48.410] They're still going to get compromised, because unless you're going out and being, you know, Robin Hood and patching these systems, which is a nice little legal loophole, I guess. [39:48.820 --> 39:50.520] Oh, I was just trying to help people. [39:50.890 --> 39:51.700] No, it ain't going to fly. [39:51.870 --> 39:53.270] You're going to get, you know... [39:53.270 --> 39:58.600] The last yesterday at 10 a.m., they had a wonderful issue about researching botnets and legal issues. [39:59.640 --> 40:02.350] Wow, I was kind of afraid of some of the stuff that I was doing. [40:02.640 --> 40:04.410] I thought it was, you know, solid, tight. [40:04.540 --> 40:06.700] You know, I wasn't actually attacking anybody. [40:06.700 --> 40:10.370] I was just, you know, I will show you an example of some of the things you can do afterwards. [40:11.680 --> 40:16.660] But some of the stuff where I just try to take down servers where I say, you know, if these servers are compromised, please remove them. [40:17.060 --> 40:19.700] Now I'm not sure if that's 100% legal or not. [40:20.270 --> 40:21.060] There are no pros. [40:21.160 --> 40:22.020] You are part of the problem. [40:24.350 --> 40:24.700] Takedowns. [40:24.810 --> 40:27.520] Now, you know, takedown has a bad name, because we all know about the mitten movie. [40:28.350 --> 40:32.560] This is not, you know, you're not going to be punching, you know, whoever that was, Shimomura. [40:35.020 --> 40:39.200] Pros with takedowns is that they're legal, effective, and they actually remove the immediate problem. [40:40.380 --> 40:43.450] What it is, as we'll show you later, is, you know, okay, I got attacked. [40:43.700 --> 40:45.370] All right, let me go contact that ISP. [40:45.540 --> 40:50.750] You know, talk to Bob, who's, you know, the first tier help desk support, and try to get that removed. [40:52.100 --> 40:53.750] Normally, doesn't even know what the hell you're talking about. [40:54.430 --> 41:01.000] This is very much a whack-a-mole, because despite you trying to remove this computer, there are going to be two or three definitely set up. [41:01.100 --> 41:02.540] And like I said, inevitable frustration. [41:02.790 --> 41:04.200] This is exactly what I'm talking about. [41:04.800 --> 41:12.040] It's a lot of effort, and you can keep on some of these ISPs for like weeks at a time, and not have this attacking computer removed. [41:12.310 --> 41:19.000] They'll be like, well, geez, we contacted the person, but he didn't actually, you know, leave us a valid email address, and his phone number's changed, and... [41:19.500 --> 41:20.390] Just take it off. [41:20.500 --> 41:21.270] Unplug the damn thing. [41:22.870 --> 41:25.020] So we're actually going to go through a web takedown. [41:25.500 --> 41:27.060] And this is exactly what I love to do. [41:27.160 --> 41:28.730] Just takedown the hard way. [41:29.800 --> 41:32.120] So, this happened actually last week. [41:32.480 --> 41:34.600] I got... three of my honeypots got probed. [41:36.180 --> 41:38.870] Web and Snort was... there was a forecast vulnerability. [41:39.120 --> 41:40.660] I had no idea what the hell forecast was. [41:40.770 --> 41:42.850] Sounded like some type of porn thing. [41:44.660 --> 41:45.020] Yeah. [41:45.230 --> 41:46.770] And this is exactly how I feel down the bottom. [41:46.950 --> 41:52.250] You know, I figured, you know, Edgar Allan Poe, I have my cigar and my bottle of Kondak, and I'm, you know, here and wrapping on my door. [41:53.770 --> 41:54.790] I looked a bit closer. [41:55.370 --> 41:55.960] Oh, pardon me. [41:55.960 --> 41:55.980] Okay. [41:58.290 --> 41:58.750] Let's see. [41:58.870 --> 41:59.330] I just saw... [41:59.330 --> 41:59.410] Okay. [41:59.500 --> 42:00.140] It was from Snort. [42:00.180 --> 42:04.500] It was at, you know, at 3 o'clock in the morning. [42:04.700 --> 42:06.850] I wasn't up then, so it definitely wasn't something I was doing. [42:08.370 --> 42:08.730] It's... [42:08.730 --> 42:13.250] The SnortAlert was a WebMisc four-task remote code execution attempt. [42:14.850 --> 42:16.980] And, you know, you see all the stuff coming in from Snort. [42:17.080 --> 42:23.430] Snort actually has this really nice plug-in called IDMEF, which is the intrusion detection message chain format. [42:23.430 --> 42:25.080] A couple of months... [42:25.080 --> 42:27.600] Actually, probably six months ago at this point, it became an RFC. [42:27.640 --> 42:36.100] So it actually is a valid, you know, XML format for...that other vendors hopefully will start supporting soon. [42:36.100 --> 42:46.040] So you can actually have your other IDSs and firewalls start reporting into your Prelude server, or you might actually find something that actually has better documentation than Prelude, so you can move to that. [42:47.040 --> 42:52.410] It has a little Snort-specific stuff down at the bottom, like, you know, your vendor-specific, your CVE, your bug track ID... [42:53.240 --> 42:54.790] I'm sorry, your vendor-specific Snort ID. [42:56.720 --> 43:00.830] So going further down the line, we actually...this is further down the page, same page. [43:01.560 --> 43:02.700] Here's all the stuff from Snort. [43:02.950 --> 43:04.580] And we saw, okay, it's a git attempt. [43:06.140 --> 43:07.790] It's, you know, you just look down way in the bottom. [43:07.910 --> 43:09.890] Calendar tool, send reminders, and it's... [43:09.890 --> 43:10.520] Could you stop thinking? [43:10.810 --> 43:13.250] Just really... [43:13.250 --> 43:13.640] Oh. [43:15.400 --> 43:18.450] All my...my presentation will be up on my website later. [43:20.830 --> 43:22.830] So it was trying to do a remote file include attempt. [43:23.370 --> 43:27.750] If you look at the bug track ID and the CVE, you'll actually see what exactly the bug is. [43:28.210 --> 43:33.270] Remote file inclusion, I sanitized it off the website because this is exactly the point I was trying to make. [43:33.270 --> 43:36.040] If you say, okay, this person attacked me, this is an IP. [43:36.330 --> 43:41.730] This...the IP that I didn't print out, that's the actual person probably attacking me because it's Russian Federation. [43:42.190 --> 43:51.190] However, this IP that they gave us that I did blur out is that it's a...not...it's a completely innocent third party, which we will find out later. [43:51.820 --> 43:52.920] So another word of warning. [43:53.120 --> 43:55.500] I just added this the other day after hearing all about my legal things. [43:55.580 --> 43:56.460] I didn't do any of this. [43:56.540 --> 43:57.320] My friend Bob did. [43:58.000 --> 43:58.460] I did. [43:58.520 --> 43:59.270] He just said...I know. [43:59.320 --> 43:59.920] I gave him the IP. [44:00.040 --> 44:01.640] I said, you know, if you really want to look at this, go right ahead. [44:03.560 --> 44:05.380] This is an interesting thing. [44:05.840 --> 44:08.100] It's like...I always knew it was kind of a hazy gray area. [44:08.300 --> 44:12.540] And now I know even more it's a hazy gray area with that presentation yesterday. [44:13.460 --> 44:17.580] Whether or not...what exactly you're doing is a question of whether or not it's actually illegal or not. [44:17.580 --> 44:23.900] You can say, I'm a researcher, but, you know, try saying that to the FBI knocking on your door at 4am. [44:24.960 --> 44:26.840] So anyway, we saw this file. [44:27.140 --> 44:29.040] It's slash temp slash one dot GIF. [44:29.140 --> 44:30.300] That's a file they're trying to feed us. [44:31.920 --> 44:33.170] We decided to grab it. [44:33.230 --> 44:34.300] Notice how I use Torify. [44:34.480 --> 44:35.710] So it's going through an anonymous proxy. [44:35.900 --> 44:38.540] Even if it isn't illegal, do you really want this to come back to you? [44:38.620 --> 44:41.420] Or, you know, you might wake up to a nice denial of service on your hands. [44:42.400 --> 44:44.860] Believe me, it's happened to me. [44:46.480 --> 44:49.300] Anyway, so this one dot GIF, it's an awfully small file. [44:49.460 --> 44:50.460] It's only 104 bytes. [44:51.250 --> 44:52.580] Oh, Morpheus hacked me. [44:53.290 --> 44:53.900] That's strange. [44:54.000 --> 44:54.710] Where have I heard this before? [44:54.820 --> 44:57.560] Now, if we go back to the snort, it actually... [44:58.000 --> 45:04.580] If you go look down really close and you have really good eyes, you'll see user agent Morpheus effing a scanner. [45:04.790 --> 45:05.820] And it's not sanitized. [45:07.660 --> 45:08.620] Oh, wrong way. [45:11.440 --> 45:12.210] So, okay. [45:12.440 --> 45:14.060] Obviously, it's a one dot GIF. [45:14.190 --> 45:15.440] It's not actually a GIF file. [45:15.560 --> 45:15.880] All right. [45:16.020 --> 45:17.480] So I know it's actually a hostile attempt. [45:17.580 --> 45:21.730] It's not someone accidentally misconfiguring their server who's trying to probe my server. [45:22.170 --> 45:23.270] Stranger things have happened. [45:24.360 --> 45:25.460] So what I had... [45:25.460 --> 45:28.620] Actually, this is where it starts getting even more questionable. [45:28.770 --> 45:31.340] Do you actually really want to see what's further on this server? [45:31.520 --> 45:33.290] You can actually look up Torify and the links. [45:33.380 --> 45:37.340] You don't actually want to use a real web server because what happens if it's all kinds of nasty exploits sitting there? [45:39.190 --> 45:40.060] But, okay. [45:40.480 --> 45:41.640] Apache 2051. [45:41.960 --> 45:42.800] That's kind of old. [45:43.860 --> 45:45.190] Is this actually the attacker? [45:45.380 --> 45:46.270] No, probably not. [45:46.880 --> 45:55.670] If this actually was an open directory and we saw, like, you know, Microsoft Office 2007.iso, chances are this isn't non-pop. [45:56.360 --> 45:58.060] If we go to the actual website... [45:58.060 --> 46:01.000] It's all blurred out because hopefully no one will be able to see exactly what it is. [46:02.140 --> 46:03.210] It's an actual website. [46:03.340 --> 46:04.440] It had a nice little front page. [46:04.580 --> 46:08.080] It said, oh, you know, we're doing this wonderful service for people. [46:08.230 --> 46:13.440] And I was like, I really don't think this is actually some type of person trying to attack me. [46:13.440 --> 46:16.480] I think it's probably either a third-party computer or someone trying to compromise me. [46:16.840 --> 46:21.000] However, looking upon the IP address, I found it was hosted in the United States. [46:21.250 --> 46:25.210] If you ever want to do a takedown, United States people are the most cooperative. [46:25.620 --> 46:26.540] That's not saying much. [46:26.670 --> 46:27.440] Again, tall smidgen. [46:28.240 --> 46:30.840] If you're trying to take something down in Russia, good luck. [46:31.210 --> 46:33.360] If you're trying to take something down in China, again, good luck. [46:35.600 --> 46:36.560] This is what I wrote up. [46:37.400 --> 46:39.540] Takedowns are a wonderful exercise in social engineering. [46:40.600 --> 46:46.840] I created... I was like, oh, geez, I would really like to actually start doing this and actually, you know, try to do the good neighbor on the Internet thing. [46:47.060 --> 46:48.940] So I created my own little third-party entity. [46:49.060 --> 46:50.270] I called it Mehamic Labs. [46:50.840 --> 46:53.800] You know, started my own little website, put all kinds of cute little things up. [46:53.860 --> 46:55.860] And now I'm an official security researcher, aren't I? [46:55.860 --> 46:58.340] So I wrote this wonderful little letter to the hosting company. [46:58.420 --> 47:04.360] Dear sir, and whom it may concern, Mehamic Lab, an independent security research group, has found tools being used to attack systems stored on the website you host. [47:04.480 --> 47:08.560] You're receiving this message because you are listed in the contact section of the netblocks WHOIS information. [47:08.840 --> 47:11.100] In order to get this actually address, I was sending it in. [47:11.170 --> 47:12.140] I actually didn't go over this. [47:12.230 --> 47:14.000] I did a WHOIS on the IP address. [47:14.190 --> 47:16.800] And it will give you an abuse email address. [47:16.940 --> 47:17.940] This is who you want to email. [47:18.290 --> 47:23.690] You include the URLs that are hosting the malicious code. [47:23.690 --> 47:30.980] And I did find a second malicious URL, which I'm not going to talk about because it had all kinds of other nastiness in there, which I'm still trying to repress. [47:33.220 --> 47:36.300] Anyway, they were both .GIF files. [47:36.460 --> 47:39.440] So I said, you know, these tools are .ph files despite the .GIF extension. [47:39.750 --> 47:43.460] The website you host seems to have compromised by third party and using it to probe systems. [47:43.940 --> 47:46.690] If you're responsible for the security of IP, please take it down. [47:46.860 --> 47:48.800] And you've put caps so you really want to get this across. [47:48.800 --> 47:52.460] Your prompt attention is vital to admit the process of number of victims. [47:52.620 --> 47:54.730] And they usually understand that that's important. [47:55.020 --> 47:56.580] They usually just delete it anyway. [47:56.640 --> 47:57.040] Pardon? [47:57.320 --> 47:58.770] They probably just delete it most of the time. [47:59.080 --> 48:03.500] A lot of the times you do find where they just delete it and like, I'm all set. [48:04.190 --> 48:04.500] And... [48:06.270 --> 48:06.710] Yeah. [48:06.940 --> 48:07.690] A lot of the time... [48:07.690 --> 48:09.750] Well, you run into three or four different responses. [48:09.960 --> 48:14.770] I don't know exactly what occurred here, but a little while layer, it was 404. [48:14.770 --> 48:16.790] So, I'm all set. [48:17.120 --> 48:23.480] Whether or not they deleted that file and then just sent the user on their merry little way, I don't know. [48:23.640 --> 48:25.620] Is there an actual exploit somewhere in the site? [48:25.730 --> 48:26.300] Yeah, probably. [48:26.520 --> 48:27.460] I don't know if they fixed it. [48:28.710 --> 48:32.380] A lot of the times you'll see a wonderful little thing where your server is not responding anymore. [48:32.600 --> 48:34.960] Or you'll see this website has been suspended. [48:35.100 --> 48:36.040] Please contact your... [48:36.040 --> 48:37.800] If you're the owner, please contact the support. [48:40.460 --> 48:42.380] So, this is actually a good thing. [48:42.560 --> 48:45.300] Sometimes you have to send out repeated emails to the people. [48:45.440 --> 48:47.580] Sometimes you have to, you know, include more caps lock. [48:47.920 --> 48:55.380] Sometimes you have to get involved with the upstream network provider saying, you have this ISP and he's doing evil, nasty, ugly things and he's not responding to me. [48:55.580 --> 49:00.750] And a lot of times with level three, I know a couple of people who know people in level three and they can say... [49:00.750 --> 49:05.400] They can make the phone call to the person paying the bill saying, if you want your network connection still up, you need to fix this. [49:06.140 --> 49:07.900] Because they are somewhat cooperative. [49:10.180 --> 49:12.920] So, now that we have all this stuff, where do we go from here? [49:13.380 --> 49:16.320] These are ideas that I have that I have absolutely no time to implement. [49:16.520 --> 49:17.900] So, have fun. [49:19.020 --> 49:28.480] I would really like to have a little embedded box that I can put on my parents' DSL connection, reporting into a central server, have their own little mini honeypot set up, because Lord knows mom isn't using her DMZ for anything. [49:30.340 --> 49:32.420] And actually have it distributed across there. [49:32.420 --> 49:44.790] Have something where it's more or less turnkey and just, you know, have something where if you have Aunt Edna in Fargo, North Dakota, saying, please Aunt Edna, I'd really love you to plug this box on your interconnection and just turn it on and it will be all set and it will pour it into... [49:44.790 --> 49:46.500] Well, you won't tell it, it will pour into my server. [49:46.710 --> 49:52.980] But you'll see this wonderful little thing on your prelude saying, you now have this client sitting in this, you know, Fargo, North Dakota IP. [49:53.620 --> 50:03.860] And you can get very good geographically distributed information that is on many different networks, so you can get a really good idea of what actually is going on in the global interwebs. [50:04.540 --> 50:17.270] Another thing is that a nice little way of, you know, if you're running a honeypot, set up a prelude server someplace and have people feeding their IDMEF packets into your prelude server so you can get a good idea there too. [50:19.500 --> 50:22.520] Real-time intelligent gathering system to know what's probing what. [50:22.750 --> 50:23.800] We have all this information. [50:24.020 --> 50:27.840] Let's go try to make some type of list of, okay, these are the naughty IPs. [50:27.840 --> 50:30.790] Let's go find out what exactly they're doing and try to take them down. [50:31.580 --> 50:34.710] I mean, they're good ideas, but who knows? [50:34.840 --> 50:35.600] I don't have time to know. [50:35.770 --> 50:36.320] I don't know what it is. [50:37.190 --> 50:37.900] Some links. [50:39.040 --> 50:42.520] Honey.org, Nepenthes.mw.collect.org. [50:42.690 --> 50:45.380] Nepenthes and Honey Trap are made by the same group of people. [50:45.980 --> 50:51.920] Prelude IDS and SCAT will be released sometime next week when I actually have a breather after the conference. [50:55.160 --> 50:57.540] StankDawg, NotTheory, and the rest of the DDP who are sitting right there. [50:58.320 --> 51:02.270] Binrev.com forum, Boston 2600, and I guess I didn't save that. [51:02.340 --> 51:04.230] Quine, Beaker, and everyone else from Beanstack. [51:04.770 --> 51:10.290] And Scott, who's my inspiration, and he's just a wonderful kind of person, and he has a beer or something, I don't know. [51:11.960 --> 51:12.670] So, questions? [51:15.400 --> 51:15.770] Yes? [51:16.670 --> 51:17.790] Come up to the mic, I think. [51:17.860 --> 51:18.730] Everyone's been asking that. [51:21.910 --> 51:23.310] Wow, I actually did get under an hour. [51:24.150 --> 51:24.830] Two questions. [51:25.670 --> 51:27.530] Have you seen that ISP... [51:28.650 --> 51:28.990] Oh. [51:32.090 --> 51:32.850] Okay, there we go. [51:33.430 --> 51:39.190] Have you seen that ISPs don't want to cut off paying customers, and so they just kind of ignore you because of that? [51:39.230 --> 51:40.310] Yes, that's exactly what you're saying. [51:40.390 --> 51:41.730] They're like, oh, you know, it's a paying customer. [51:41.870 --> 51:43.190] We don't want to disconnect him. [51:43.230 --> 51:45.410] We tried to contact him, but he isn't answering his phone. [51:45.590 --> 51:49.430] He's in this, you know, Tahiti Beach House enjoying his Web 2.0 funds. [51:49.870 --> 51:59.630] And then for the other question, for your first idea, would a plug-in for the open source Linksys software work so that your little Linksys router is running as a honeypot? [52:00.750 --> 52:04.610] Linksys router is actually more or less what I was picturing, but I'm not sure... [52:04.610 --> 52:10.530] I think they were trying to port Nepenthes over to UCLib for all that... [52:10.530 --> 52:11.410] How much time do I have left? [52:11.590 --> 52:11.970] Oh, good. [52:13.270 --> 52:17.090] Trying to do it for Linksys box, but I don't think they actually got as far as they wanted to. [52:17.710 --> 52:20.970] You know, I'm sure there are some brilliant minds in here that actually do that for them. [52:22.230 --> 52:23.010] Another person there? [52:23.830 --> 52:31.130] Yeah, in terms of the snort log analysis, how does the smooth wall snort analysis compare with something, say, like Prelude? [52:31.410 --> 52:31.970] I don't know. [52:32.090 --> 52:33.390] I've never used smooth wall. [52:34.690 --> 52:35.250] Find out. [52:35.350 --> 52:35.590] Tell me. [52:36.330 --> 52:37.530] Well, it's fantastic. [52:37.970 --> 52:38.990] I've heard good things about it. [52:39.030 --> 52:40.410] I've never actually used it in practice, though. [52:42.210 --> 52:46.250] I'm actually curious as to whether or not smooth wall will have an IDM EF plug-in. [52:46.450 --> 52:52.210] If they have that, they can feed already, you know, normalized reports over to Prelude, which I'm sure will happily accept them. [52:53.510 --> 52:58.730] I was going to ask a question that the previous guy asked about using a Linksys box as an IDS box. [52:58.890 --> 52:59.810] It sounds like a good idea. [53:00.630 --> 53:01.430] I have no idea... [53:01.430 --> 53:05.910] I mean, if you can put Prelude LML, it supports a variety of log formats. [53:05.910 --> 53:08.490] So they may have something for smooth wall already in there. [53:08.670 --> 53:16.130] There's like, in their definitions, they have like, you know, somewhere on the range of like 20 to 30 files, just in some things that I've never even heard of before. [53:16.370 --> 53:17.890] And then another question. [53:18.750 --> 53:25.290] How much trouble, if any, have you had with people accusing you of being a spammer for giving them these automated warnings? [53:25.550 --> 53:26.350] The only... [53:26.350 --> 53:26.630] Well, no. [53:26.690 --> 53:30.330] I've never actually gotten stuff from the people I'm contacting. [53:30.870 --> 53:34.170] I did get a report from my ISP because I found a... [53:34.170 --> 53:34.650] the only... [53:34.650 --> 53:35.970] This actually really isn't related to this. [53:36.110 --> 53:37.990] I found a bug in a software program. [53:38.190 --> 53:39.370] I sent it to the person. [53:39.550 --> 53:40.170] He patched it. [53:40.310 --> 53:44.470] He thanked me in his, you know, daily, you know, oh, a new version is out. [53:44.690 --> 53:45.670] Please download it. [53:46.950 --> 53:48.910] And thanks to Mayhemic Labs for finding this. [53:49.130 --> 53:50.670] And they gave me a link to their website. [53:50.830 --> 53:54.970] I then got a report from my ISP saying, someone reported you as advertising and spam. [53:55.830 --> 53:56.190] What? [53:57.130 --> 53:58.010] No, it's not me. [53:58.130 --> 53:58.510] No, no. [53:58.650 --> 53:59.490] Look at the actual message. [53:59.830 --> 54:00.170] Come on. [54:00.870 --> 54:02.330] My ISP isn't the best thing in the world. [54:03.290 --> 54:04.550] Do we have enough of somebody else? [54:04.770 --> 54:05.030] Oh, geez. [54:05.370 --> 54:05.470] Hi. [54:05.910 --> 54:06.230] Hi. [54:06.330 --> 54:06.690] I'm sorry. [54:08.890 --> 54:10.150] So, the links... [54:10.150 --> 54:11.630] Are these going to be available on your webpage? [54:11.830 --> 54:13.150] Did you mention what your webpage is? [54:13.370 --> 54:13.890] Actually, yeah. [54:13.950 --> 54:14.910] I have my contact information. [54:15.070 --> 54:15.850] I thought I had that after that. [54:16.930 --> 54:17.650] BlackRatchet.org. [54:17.950 --> 54:18.770] BlackRatchet.org. [54:19.150 --> 54:20.590] And my Twitter name is Inesmir. [54:21.390 --> 54:22.690] I missed the links page. [54:22.690 --> 54:25.990] Was that PersianKittens.net or Persian... [54:25.990 --> 54:27.350] PersianKitty.com. [54:27.450 --> 54:27.830] PersianKitty.com. [54:28.210 --> 54:30.110] I have no idea what it actually redirects you. [54:30.170 --> 54:30.950] Go there at your own risk. [54:31.650 --> 54:32.850] I'm on the wrong page. [54:33.730 --> 54:34.330] Thank you. [54:34.610 --> 54:34.930] All right. [54:35.070 --> 54:36.370] So, I think we'll go over here next. [54:38.390 --> 54:39.350] Do we have some... [54:39.350 --> 54:40.370] I was just going to ask. [54:40.470 --> 54:48.630] Do you know of any sources for things like statistics about average time to resolution after an infection or a source of attack has been reported to a hosting company? [54:48.630 --> 54:49.210] No. [54:49.550 --> 54:50.190] I have no idea. [54:50.510 --> 54:52.610] And it can vary so much from company to company. [54:52.830 --> 54:53.350] Who knows? [54:53.670 --> 54:55.990] I actually had to talk with my honeypot. [54:56.150 --> 54:58.110] I got repeated SQL slammer attempts. [54:58.250 --> 55:00.710] That is the number one thing you'll be seeing on your store if you're running on a honeypot. [55:00.910 --> 55:01.930] SQL slammer requests. [55:02.050 --> 55:04.030] Like, I literally get about 20 to 30 per day. [55:04.730 --> 55:06.390] I got something from the Ford Corporation. [55:06.710 --> 55:07.450] Called their... [55:07.450 --> 55:08.470] Sent an email. [55:08.630 --> 55:09.130] No response. [55:09.490 --> 55:10.130] Called them up. [55:10.370 --> 55:11.690] Said, you know, you have SQL slammer. [55:11.910 --> 55:12.730] That's not us. [55:13.270 --> 55:13.990] It's your IP. [55:14.350 --> 55:15.450] I don't care if it's UDP. [55:15.590 --> 55:16.390] It's a SQL slammer. [55:16.450 --> 55:17.270] They don't spoof IPs. [55:17.270 --> 55:19.330] But they eventually got rid of it. [55:19.470 --> 55:22.070] And actually, when I started actually looking at the IP, it was a VPN account. [55:22.710 --> 55:24.530] I guess they don't consider that their problem. [55:25.270 --> 55:25.750] Over there? [55:26.290 --> 55:26.650] Yes. [55:26.810 --> 55:28.270] Earlier, you showed that letter. [55:28.670 --> 55:29.030] Mm-hmm. [55:29.030 --> 55:31.090] And you said it made a big impact. [55:31.230 --> 55:34.010] I think that will make that even more of an impact. [55:34.210 --> 55:38.150] Because you send it in the language of the country that is hosting the ISP. [55:38.150 --> 55:38.790] Yeah, I only do... [55:38.790 --> 55:41.710] I don't speak any other language, so I don't know how to translate it. [55:41.810 --> 55:45.990] Then you find a translator and you get them to translate, because that's the only way you're going to really get an effect from those guys. [55:45.990 --> 55:49.550] And I'm sure if I really wanted to, I could take it to my wife and she could translate it into Portuguese. [55:49.790 --> 55:49.890] Thank you. [55:49.890 --> 55:52.050] But not really too many Portuguese IPs I'm running into. [55:54.610 --> 55:55.110] Go ahead. [55:56.470 --> 56:06.850] Since obviously we can't run a botnet, is there anybody that is putting together any sort of central clearinghouse to organize honeypots in any way so that they can all report to a central place? [56:06.870 --> 56:08.970] There is the Honeynet project... [56:10.090 --> 56:11.670] I forgot what their website is. [56:12.650 --> 56:14.510] They're more of a research perspective. [56:14.510 --> 56:21.210] I'm not sure how they're actually going to take the bunch of crazy hacker dudes coming out and saying, hey, we want to run honeypots. [56:21.570 --> 56:24.650] A lot of times you'll see high interaction honeypots from them. [56:24.890 --> 56:29.010] They actually have this wonderful little bootable CD called Honeywall, which will... [56:29.830 --> 56:34.390] has that in there where it will transfer stuff to your console and will run a vulnerable computer. [56:34.950 --> 56:36.790] I completely forgot to put that link in anyway. [56:37.790 --> 56:42.310] But I'm not sure if there's anything like that for, you know, end user connections. [56:42.850 --> 56:45.690] So basically we're just working on individual responses. [56:45.930 --> 56:47.290] Working on individual responses. [56:48.330 --> 56:49.430] I don't know... [56:49.430 --> 56:51.230] I can't say how long do I have. [56:51.330 --> 56:52.350] Was that zero or... [56:52.830 --> 56:53.630] I've got to stop. [56:53.950 --> 56:54.190] Okay. [56:54.330 --> 56:56.110] If anyone has any questions, I'll be out in the hallway. [56:57.250 --> 56:58.210] Alcohol accepted. [56:59.290 --> 56:59.970] Thank you.