[00:04.460 --> 00:05.040] So you ready? [00:07.320 --> 00:07.680] Yeah? [00:07.940 --> 00:08.300] You sure? [00:21.520 --> 00:22.600] You ready to film it? [00:23.500 --> 00:24.620] You want to enter the assessment? [00:38.310 --> 00:39.470] So I'm in a steamroller? [00:42.290 --> 00:43.730] So I want to let them get on the charger? [00:44.190 --> 00:45.630] Yeah, so somebody left the charger. [00:45.790 --> 00:46.570] Thank you for coming. [00:46.890 --> 00:47.830] Can everyone hear me? [00:48.730 --> 00:49.250] Yes? [00:49.950 --> 00:51.270] Can everyone hear me now? [00:51.870 --> 00:52.390] No? [00:53.370 --> 00:53.490] Okay. [00:54.530 --> 00:54.910] All right. [00:59.220 --> 01:00.340] My name is Blake. [01:00.660 --> 01:01.500] This is Jeremy. [01:02.420 --> 01:02.980] Thank you, Jeremy. [01:04.080 --> 01:09.420] And the talk that we are having today is autonomously bypassing VoIP filters with asterisk. [01:20.330 --> 01:24.810] As you can tell, for the next 55 minutes, we'll be discussing a few of these topics right here. [01:24.950 --> 01:28.290] Some in detail, some a glazed overview. [01:31.870 --> 01:33.090] Can everyone see the screen? [01:34.450 --> 01:34.850] Yeah? [01:35.010 --> 01:35.690] Can everyone see the screen? [01:35.930 --> 01:35.970] Everyone? [01:38.370 --> 01:39.130] Excuse me a minute. [02:02.240 --> 02:03.060] A little better there? [02:03.980 --> 02:04.480] All right. [02:06.640 --> 02:09.920] So, quintessentially, I promised myself I wouldn't say that word. [02:10.340 --> 02:11.000] All right. [02:11.400 --> 02:14.420] So we're going to talk about VoIP censorship in the past. [02:14.440 --> 02:17.880] We're going to talk about VoIP censorship in the present. [02:17.880 --> 02:37.360] And we're going to be discussing how the technical evasions that someone utilizing Asterisk can use to provide and or guarantee VoIP services and how someone in a foreign country or highly secured network can access an external VoIP server. [02:38.500 --> 02:39.300] Make sense, right? [02:39.560 --> 02:39.940] Want anything? [02:41.020 --> 02:41.320] No? [02:41.680 --> 02:42.020] All right. [02:46.350 --> 02:47.510] I'm just going to read this verbatim. [02:47.610 --> 02:48.870] I hope you guys don't mind. [02:50.170 --> 02:55.270] There has been a trend for foreign governments to censor... That's a little cheesy, sorry. [02:56.370 --> 02:59.190] To censor their populace from information exchanges. [03:00.050 --> 03:01.650] Some effects are quite obvious. [03:01.650 --> 03:05.350] The primary example being a dead Internet telephone. [03:05.850 --> 03:07.430] Does anyone know how that feels? [03:07.430 --> 03:07.530] Anyone else? [03:07.990 --> 03:08.770] No audio. [03:08.910 --> 03:09.410] Hmm? [03:10.430 --> 03:11.410] No audio. [03:11.970 --> 03:12.610] Oh, yeah. [03:15.750 --> 03:22.430] There have been scant reports that over 15 countries in this world proactively block VoIP. [03:23.410 --> 03:24.670] I think that's a shame. [03:25.350 --> 03:25.810] Do you think it's a shame? [03:27.490 --> 03:29.350] Does anyone else think that's a shame? [03:29.710 --> 03:30.050] I do. [03:31.970 --> 03:32.790] That's great. [03:38.770 --> 03:39.950] Specifically in China. [03:43.210 --> 03:50.150] It's hard to confirm or deny some information about China for the primary reason that I've never set foot in the country. [03:50.710 --> 03:54.590] So it's hit or miss with what's the information you get off the Internet. [03:54.750 --> 03:58.150] But this is what I was able to determine with relative accuracy. [03:58.970 --> 04:08.170] That from 2006 till sometime in 2008, potentially even today, China is proactively blocking SIP traffic. [04:08.170 --> 04:10.950] Which is a type of voice signaling protocol. [04:12.890 --> 04:17.990] They've also shown signs of requiring some type of vetting process for VoIP providers. [04:18.210 --> 04:23.650] Which you'd have to register with their government to provide VoIP services. [04:36.520 --> 04:40.780] A very interesting aspect to this. [04:40.960 --> 04:46.760] As far as consumerism and globalization goes, having a policy like this is detrimental. [04:47.380 --> 04:54.740] Especially for the business traveler who goes to China, uses their Vonage phone to call their family, and they can't. [04:56.860 --> 04:57.820] Sounds about right. [04:59.260 --> 05:01.200] Does that happen to anyone? [05:01.200 --> 05:04.660] Has anyone ever gone to China and not been able to call their family? [05:05.740 --> 05:06.180] No? [05:06.500 --> 05:07.680] Or their friends or whatever? [05:08.620 --> 05:09.640] Has anyone ever been to China? [05:11.120 --> 05:12.100] Like two people? [05:14.200 --> 05:15.120] She can't call you? [05:15.780 --> 05:16.220] Skype? [05:16.740 --> 05:16.960] SIP? [05:17.900 --> 05:18.340] Skype? [05:20.460 --> 05:20.900] Sorry. [05:26.760 --> 05:29.860] It's mostly just firewalls and ACLs, which is what we're talking about. [05:33.640 --> 05:35.900] So I'm going to quote a couple of press releases. [05:40.040 --> 05:50.800] There have been news reports that there have been dissident groups within the United States that proactively spam software to people within China so that they could use to bypass firewalls and access control lists. [05:53.120 --> 05:55.720] The tool I'm going to be releasing off of a site. [05:55.720 --> 05:57.500] I'm going to have it on there later in the evening. [05:58.560 --> 05:59.700] It could be integrated. [06:00.000 --> 06:07.240] The techniques can be integrated into that software so that people can make voice phone calls as well as search the unfiltered Google. [06:14.420 --> 06:14.900] Google. [06:14.900 --> 06:20.800] And if anyone wants a copy of this, I'm going to put it on a website that's on the last slide and you guys can access it. [06:23.160 --> 06:24.040] So Google. [06:24.720 --> 06:29.680] They were in the press recently for censoring Chinese citizens. [06:30.960 --> 06:31.440] Boo! [06:32.280 --> 06:33.160] That's right. [06:35.500 --> 06:38.340] So, online search engine leader Google Inc. [06:38.600 --> 06:47.480] has agreed to censor its results in China, adhering to the country's free speech restrictions in return for better access to the Internet's fastest growing market. [06:47.700 --> 06:50.200] I understand why Google agreed to do this. [06:50.480 --> 06:54.100] It doesn't mean I necessarily agree with that they did it. [06:54.100 --> 06:55.380] That's just me. [07:04.150 --> 07:08.890] If you notice, January 25, 2006, China censoring. [07:09.390 --> 07:16.770] January 27, 2006, China in front of politicians getting yelled at. [07:17.270 --> 07:23.670] I think that's a very good move for our government to not approve of those types of activities. [07:30.260 --> 07:31.860] Does anyone have any questions so far? [07:31.980 --> 07:32.080] No? [07:32.640 --> 07:32.840] Yes? [07:33.200 --> 07:33.280] Maybe? [07:33.660 --> 07:33.780] No? [07:34.980 --> 07:35.260] No? [07:35.720 --> 07:35.860] Alright. [07:44.190 --> 07:46.570] So, I termed this very specifically. [07:47.050 --> 07:52.590] Would you believe, would you believe, that Google took an ethical stance? [07:53.450 --> 07:55.870] After getting their asses handed to them, of course. [07:58.990 --> 08:07.070] Once relatively indifferent, the government affairs, Google Inc., is seeking help inside the beltway to fight the rise of web censorship worldwide. [08:11.190 --> 08:12.450] So, why am I here? [08:12.590 --> 08:13.450] And why is Jeremy here? [08:13.710 --> 08:14.410] Do you know why you're here? [08:14.750 --> 08:15.210] I don't know why. [08:16.370 --> 08:16.710] Sweet. [08:18.550 --> 08:19.770] What could be done about this? [08:21.230 --> 08:22.730] In my eyes, there are two routes. [08:23.710 --> 08:25.390] Legislation and the reason why I'm here. [08:27.210 --> 08:28.390] Notice I didn't answer that question. [08:32.910 --> 08:39.230] I ran across a bill presented by a congressman, Chris Smith, from New Jersey. [08:40.510 --> 08:43.430] And that bill is called the Global Online Freedom Act. [08:44.190 --> 08:50.310] It may have some loopholes in it, but for the most part, the reason why I was created, I can agree with the reason why I was created. [08:54.420 --> 09:07.860] To promote freedom of expression on the Internet, to protect United States businesses from coercion, to participate in repression by authoritarian foreign governments, and for other purposes. [09:09.500 --> 09:13.320] So, this one snippet of the bill, I figured you guys would appreciate. [09:14.020 --> 09:15.500] I'm just going to read the bold parts. [09:16.260 --> 09:17.140] The right of... [09:17.140 --> 09:19.560] It shall be the policy of the United States, yada, yada, yada. [09:19.940 --> 09:23.380] The right of every individual to freedom of opinion and expression. [09:25.440 --> 09:29.140] Promote the free flow of information, specifically the Internet. [09:30.360 --> 09:32.080] And to deter any U.S. [09:32.240 --> 09:33.560] businesses from cooperating. [09:35.360 --> 09:36.800] Can anyone disagree with those? [09:37.660 --> 09:39.180] And if so, I'd like to hear why. [09:39.640 --> 09:41.200] No one's disagreed with those points. [09:44.420 --> 09:44.900] Question. [09:45.400 --> 09:46.160] Question, please. [09:46.860 --> 09:52.000] Now, when senators are people overseas, but we do the same thing here. [09:52.920 --> 09:53.960] Well, it could happen here. [09:54.620 --> 09:55.820] I could, it does. [09:57.120 --> 09:57.820] How so? [09:58.720 --> 10:02.120] Package shaping, stopping the Internet traffic. [10:02.260 --> 10:02.640] The U.S. [10:02.700 --> 10:02.940] government. [10:03.860 --> 10:06.900] So, you get that insurance side of the particular network. [10:07.060 --> 10:08.260] And then they would stop it. [10:08.960 --> 10:10.360] I understand what they left. [10:10.600 --> 10:12.180] Time Warner Cable does that? [10:13.080 --> 10:14.240] Time Warner Cable does that? [10:14.380 --> 10:14.840] Time Warner Cable does that? [10:14.840 --> 10:15.260] Time Warner Cable does that? [10:17.460 --> 10:18.720] You guys serious? [10:20.700 --> 10:21.960] Who's starting a petition? [10:24.280 --> 10:24.800] No? [10:24.960 --> 10:25.460] It's too scary. [10:30.180 --> 10:31.760] What reason to use IAX? [10:32.220 --> 10:33.540] What reason to use IAX? [10:34.120 --> 10:40.320] Oh, it's another reason to use Asterisk in the inter-Asterisk exchange protocol, which we'll get into here in a minute. [10:40.620 --> 10:50.100] If they are blocking SIP, you know, that's a known protocol that they can, firewalls can identify with, you know, simple packet inspection methods. [10:50.100 --> 10:57.540] And Blake will get in, and then I'll get into the reason why Asterisk and specifically the IAX protocol can get around some of these things. [10:58.120 --> 10:58.560] Beautiful. [11:00.580 --> 11:01.980] Does that give you guys some hope? [11:02.640 --> 11:02.820] Yeah. [11:02.980 --> 11:03.840] Pun intended? [11:04.440 --> 11:04.500] No? [11:08.430 --> 11:09.570] All right. [11:10.470 --> 11:11.230] Keywords here. [11:13.370 --> 11:14.930] Simple and guarantee. [11:15.350 --> 11:20.110] You can simply guarantee connectivity through a few little simple methods. [11:21.770 --> 11:26.910] Remember, and there's actually been arguments on how this sentence should be termed by multiple people. [11:26.910 --> 11:28.630] But I put it in here like this. [11:29.130 --> 11:32.510] Remember, those who have the best tools wins. [11:34.610 --> 11:36.090] I'm a firm believer in that. [11:37.070 --> 11:39.450] Especially, you know, software tools. [11:41.630 --> 11:53.790] As I alluded to before, I'm going to be releasing a Perl script that, on a basic level, allows a user the ability to determine if VoIP filtering, specifically IAX, is in effect. [11:53.790 --> 11:58.650] It could also help you find a way out, amongst other things. [12:01.510 --> 12:06.850] A technical overview of basic filters we will be discussing as far as evading. [12:08.890 --> 12:11.350] Firewalls, which usually sits on layer four. [12:11.990 --> 12:14.790] And access control list, which sits on layer three. [12:15.030 --> 12:19.710] So it blocks your ports, and it blocks who you could talk to. [12:21.910 --> 12:22.690] Isn't that right? [12:27.030 --> 12:28.290] You want to do this one? [12:30.090 --> 12:30.930] All right. [12:31.170 --> 12:32.390] SIP versus IAX. [12:33.430 --> 12:40.030] The SIP, or the Session Initiation Protocol, is an IETF standard that has, you know, been ratified. [12:40.030 --> 12:46.270] And most VoIP carriers and solution providers will support SIP now. [12:47.530 --> 12:55.610] Whereas IAX is not necessarily proprietary, but it's proprietary to Asterisk, being that there's only one major implementation of IAX. [12:56.370 --> 12:59.990] There's a few other ones out there, but it's not widely accepted. [13:00.170 --> 13:02.290] There is an IETF draft, but it expired. [13:03.050 --> 13:12.610] So, but SIP, in general, uses UDP or TCP port 5060, and then a bunch of UDP ports. [13:13.270 --> 13:18.150] And they're randomly selected, which is very easily for a firewall to detect. [13:18.150 --> 13:19.750] You can detect the related connections. [13:20.010 --> 13:35.550] And then SIP being SMTP-like or text-based, you can easily inspect the known parts of the header and easily block or just simply don't open the necessary paths to get through your NAT or through your firewall. [13:35.550 --> 13:41.910] Whereas IAX is a single UDP port for both in- and outbound audios. [13:42.270 --> 13:47.750] They've multiplexed the audio in the same UDP transport. [13:47.750 --> 13:52.630] So you don't have to worry about, you know, anything being detected. [13:52.630 --> 13:54.830] And it can run on any UDP port. [13:55.030 --> 13:59.610] Normally Asterisk only listens on, you know, UDP port 4569. [14:00.310 --> 14:01.870] Blake will show us here in a second. [14:02.110 --> 14:12.310] There's a way that you can make a particular Asterisk box listed on any UDP port in case some government or somebody decides to start blocking UDP port 4569. [14:12.710 --> 14:16.250] Almost like how some of the torrents get around the blocking by changing their ports. [14:16.630 --> 14:22.430] We have a way here with using Asterisk to do that same sort of effect, if you will. [14:23.810 --> 14:27.290] So, you know, basically, which would be easier to block? [14:27.290 --> 14:34.730] Not, you know, UDP and a bunch of other ports or just one port, you know? [14:35.230 --> 14:35.970] Makes sense. [14:36.070 --> 14:36.250] Yeah. [14:36.890 --> 14:37.950] Seems obvious enough. [14:40.230 --> 14:42.830] Ten thousand ports or one port, what's easier to block? [14:48.730 --> 14:49.350] Alright. [14:49.350 --> 14:59.870] Now, in the IAX2, IAX or the IAX version 2 is what that 2 means, but there's a control packet called IAX poke. [15:00.350 --> 15:03.990] And it's sort of like an application layer ping, if you will. [15:04.230 --> 15:13.350] We can send a request to an Asterisk system and asking for a response or it's sort of like a qualifier as well. [15:13.350 --> 15:15.030] Is the endpoint still out there? [15:15.210 --> 15:22.470] You know, kind of a, you know, to make, to keep either the NAT traversal path open or just to know if your peer is still out there or not. [15:22.930 --> 15:36.990] And then, once the connection is available, all you would really need, once you know that someone's running an Asterisk, IAX instance, all you would really need to authenticate, if there is even authentication, is just a username and password. [15:37.830 --> 15:51.670] So, there may be discrete systems you could set up that wouldn't even need authentication if it was like in a semi-trusted environment or if you're just testing to see if your IAX services or ports are blocked. [15:51.930 --> 16:01.350] You could have just a test box set up somewhere outside in a known non-firewalled area or ACL to see if you're being blocked or not. [16:06.170 --> 16:07.490] There's a double click slide. [16:07.690 --> 16:08.650] I don't think so. [16:09.210 --> 16:09.950] There we go. [16:11.590 --> 16:18.150] Now, as we said before, Asterisk generally only runs IAX protocol on a single UDP port. [16:18.250 --> 16:22.670] It only listens or binds to the one UDP port. [16:23.090 --> 16:28.290] And as well, I just want to make this point Asterisk, and the configuration will only run on one port. [16:28.290 --> 16:30.350] Yeah, you can't specify a range or nothing yet. [16:30.950 --> 16:31.230] Yeah. [16:32.050 --> 16:32.290] Yet. [16:33.150 --> 16:40.690] Now, the trick here is, is you can take using IP tables or your favorite firewall configuration script. [16:40.790 --> 16:41.570] Linux box. [16:41.750 --> 16:42.030] Yeah. [16:42.290 --> 16:44.230] Linux box or anything you want. [16:44.930 --> 16:52.850] And NAT those, all those UDP ports into the UDP 4569 that Asterisk is listening, looking on. [16:52.970 --> 17:02.950] So you can effectively, using the underlying UNIX system tools, route any UDP traffic, maybe other than like port 53 if you want DNS to work on the box or something. [17:03.530 --> 17:08.670] But generally, you can forward everything into the Asterisk box and then Asterisk won't even know there's any difference. [17:08.930 --> 17:11.970] And it'll respond just as it was coming out on 4569. [17:12.290 --> 17:21.690] So we can do some sort of internal tricks to the system that Asterisk running on to give it a little bit more flexibility in case they are blocking port 4569. [17:23.350 --> 17:26.370] And now this is Blake's nice little script he wrote. [17:27.670 --> 17:29.290] I'm going to just show you guys some examples. [17:29.470 --> 17:33.250] Notice, you'll notice that all the examples are off the loopback interface. [17:34.450 --> 17:39.470] I didn't necessarily do it for legal reasons, but just because I like attacking myself. [17:41.210 --> 17:41.990] Go figure. [17:43.170 --> 17:43.690] Alright. [17:44.410 --> 17:45.650] So, the basic scan. [17:45.670 --> 17:47.350] I've called it the IAX ping poker. [17:47.530 --> 17:49.010] I figure it was catchy enough. [17:49.010 --> 17:49.870] It makes sense. [17:49.870 --> 17:52.350] It kind of explains what it is. [17:52.950 --> 17:54.770] So, if you execute this command. [17:55.090 --> 17:55.650] Host. [17:55.950 --> 17:56.870] Loopback interface. [17:57.430 --> 17:57.970] Start port. [17:58.750 --> 17:59.470] End port. [17:59.950 --> 18:00.710] Actually, that's a typo. [18:00.790 --> 18:01.330] It should be EP. [18:01.670 --> 18:02.550] My apologies. [18:03.330 --> 18:04.370] I'm sure you guys could figure it out. [18:05.390 --> 18:10.070] This will scan the 127001 from port 1 to 1024. [18:11.410 --> 18:12.970] How useful could that be? [18:12.970 --> 18:18.900] If you want to see if an IP address is running Asterisk on 53 or 80 or... [18:20.000 --> 18:22.840] Any other popular port. [18:23.320 --> 18:28.260] Specifically, administrative type ports. [18:28.420 --> 18:29.640] Required services. [18:29.940 --> 18:31.220] Like DNS, specifically. [18:32.620 --> 18:34.720] Does anyone have any questions about this? [18:38.130 --> 18:41.050] It's an IAX poke scan. [18:41.730 --> 18:42.550] Only. [18:42.890 --> 18:44.110] There are... [18:44.110 --> 18:47.570] Unfortunately, there are no other protocols supported in this. [18:48.250 --> 18:49.910] Say for SIP, for example. [18:50.110 --> 18:51.750] You could put a SIP option in there. [18:52.790 --> 18:54.210] And Dundee as well. [18:54.970 --> 18:58.050] And I guess if we have time, we'll talk about Dundee later. [18:59.550 --> 19:00.450] Any other questions? [19:08.110 --> 19:09.630] This is an IP range scan. [19:10.590 --> 19:12.370] It understands CIDR addressing. [19:13.710 --> 19:16.730] I wouldn't recommend scanning the entire Internet with one command. [19:16.910 --> 19:21.430] Because it's going to be passing a reference to a ginormous array. [19:21.630 --> 19:22.510] And your computer is going to crash. [19:22.630 --> 19:23.890] Especially this tiny little PC. [19:24.130 --> 19:24.850] It couldn't handle it. [19:24.950 --> 19:25.170] I tried. [19:26.590 --> 19:27.690] It didn't work out too well. [19:27.690 --> 19:33.870] So this will pretty much scan entire non-routable Internet range. [19:34.010 --> 19:34.750] Entire subnet. [19:35.010 --> 19:37.130] On the default port of 4569. [19:37.810 --> 19:40.670] And you can combine any of these with any of them. [19:40.910 --> 19:40.990] Alright. [19:41.690 --> 19:42.190] Any questions? [19:42.390 --> 19:42.430] No? [19:47.350 --> 19:48.090] Oh, yes. [19:48.170 --> 19:49.550] But it doesn't stop with that, does it? [19:50.990 --> 19:53.410] There's something that I happen to notice. [19:54.410 --> 19:57.910] Luckily for everyone who doesn't have Astro servers running. [19:58.950 --> 20:01.830] There is a denial of service potential with this script. [20:03.590 --> 20:13.250] Over the loopback interface, executing this command will put the script into an infinite loop of transmitting UDP packets and not listening for them. [20:14.110 --> 20:18.830] So if I was running this, I actually tested this with the exact command over the loopback interface. [20:19.310 --> 20:22.610] And I noticed that the script was taking up roughly 10%. [20:23.210 --> 20:26.110] While asterisk was taking up roughly 90%. [20:26.110 --> 20:31.590] So a 1 to 9 ratio per cycle seemed kind of interesting to me. [20:37.050 --> 20:41.620] And to make it worse, the default logging level does not log pokes. [20:41.750 --> 20:48.990] So if someone is getting dosed by an IAX poke packet or a whole lot of them, there's going to be no logs for it. [20:49.440 --> 20:50.360] No logs. [20:51.470 --> 20:53.010] You had something interesting to say maybe? [20:55.510 --> 20:56.230] Oh yeah. [20:56.970 --> 21:02.920] Well, I'm a pretty active member in the Asterisk developer areas. [21:03.290 --> 21:15.070] And I mentioned it when Blake showed me his discovery of this, I mentioned it to Russell and Tillman, two of the main Asterisk project managers, I guess their titles are. [21:15.070 --> 21:20.530] And they have an optimization for this that's going to make it into the 1-6 version of Asterisk eventually. [21:20.860 --> 21:27.090] That will do away with effectively the unauthenticated or the unknown poke. [21:27.090 --> 21:38.310] They have a way to know if you should be poking them as the protocol level, instead of just being some third party sending an unrequested packet. [21:38.770 --> 21:42.590] So eventually this will get fixed, but as of right now this is the problem in Asterisk. [21:43.200 --> 21:46.310] And I've told Digium, but they didn't seem really interested. [21:46.680 --> 21:47.160] Oh well. [21:47.470 --> 21:48.050] Oh well, yeah. [21:48.050 --> 21:48.090] Yeah. [21:48.490 --> 21:49.790] Mention the . [21:49.790 --> 21:50.900] Do you have a . [21:53.880 --> 21:55.120] It's in the script. [21:55.320 --> 21:55.720] I have it. [21:55.920 --> 22:00.200] There's an inject function and you can see how I line up the data. [22:00.540 --> 22:11.320] So what I'm getting at, I'm just kind of curious, so is Asterisk setting up some, allocating some set of resources for every poke it gets regardless of what goes on and then that's really the issue, right? [22:11.420 --> 22:12.460] Is the allocation set up? [22:13.340 --> 22:22.120] Yeah, basically Asterisk is wasting time setting up a call ID and all the other underlying functions for the IEX protocol itself. [22:22.920 --> 22:33.120] And then when you don't complete, when you don't set a new call or whatever, it just Asterisk will eventually kill those resources via garbage collected thread type of situation. [22:33.640 --> 22:48.160] But yeah, if you do it in a multi-threaded situation or even in a multi-IP like a distributed environment, what we were getting ready to try before I had to fly out here was we were going to use the Amazon EC2, the Elastic Computing Cloud resources for this. [22:48.160 --> 22:54.220] We're just going to fire up, you know, a handful of instances at a targeted box with permission, I guess. [22:55.040 --> 22:55.520] Maybe. [22:55.700 --> 22:56.080] Hopefully. [22:56.380 --> 22:56.900] Yeah, hopefully. [22:57.080 --> 22:57.380] Hopefully. [22:57.500 --> 23:01.120] And see if we can actually bring a system down distributed-wise. [23:01.320 --> 23:11.900] But, you know, based on the simple testing we've done here, there is a resource utilization going on that probably shouldn't be and hopefully will get fixed in the newer versions of Asterisk. [23:11.900 --> 23:14.320] But, like I said, it's not fixed today. [23:14.760 --> 23:15.240] Essentially, [23:18.350 --> 23:18.610] I poke. [23:18.930 --> 23:19.950] Can you say that again? [23:20.070 --> 23:20.210] I'm sorry? [23:20.530 --> 23:26.530] I was going to say, essentially, I ax means, but it's effectively the same cookie kind of mechanism for the initial poke. [23:26.690 --> 23:41.850] Yeah, it means some sort of authentication, maybe not the right word, but some sort of, yeah, protections in place so you can't get an unrequested poke, you know, without having some other protocol layer interaction. [23:42.330 --> 23:42.730] I don't know. [23:42.730 --> 23:43.810] Such as authentication. [23:44.350 --> 23:45.530] Yeah, such as authentication. [23:47.390 --> 23:48.550] Any more questions? [23:52.960 --> 23:53.800] What are we doing all the time? [23:55.780 --> 23:57.020] Oh, we're cruising. [23:59.380 --> 24:00.160] All right. [24:01.040 --> 24:05.320] As well, there is an injection potential. [24:05.600 --> 24:08.100] I've set the script up so it could attack itself. [24:09.100 --> 24:23.420] If you include the inject flag, and I also didn't give it the necessary functionality that is required for person A to attack victim B, you guys can add that in yourselves if you so please. [24:23.840 --> 24:30.540] But the function is there for the fake response, the forged response. [24:33.280 --> 24:44.000] running this against myself, the script that I'm actively using the scan, it will produce false positives. [24:44.840 --> 24:59.360] So, say the example being you're in China, and you're scanning, and a network administrator at a Chinese ISP notices that you're looking for a VoIP server to maybe make some malicious phone call. [24:59.960 --> 25:03.020] Because phone calls are really malicious nowadays, you know. [25:03.660 --> 25:04.900] And they notice this. [25:05.040 --> 25:14.760] They could simply line up the proper settings and attack your script, give you false positives to say, well, this is valid, but it really isn't. [25:14.920 --> 25:21.260] Or you can even potentially steer someone in a specific direction through some vague social engineering. [25:22.020 --> 25:22.880] Is that right? [25:23.280 --> 25:24.360] Yeah, like a honeypot. [25:24.800 --> 25:24.920] Yeah. [25:26.380 --> 25:27.720] Or like a honeypot. [25:29.160 --> 25:31.060] Does anyone have any questions about that? [25:35.360 --> 25:41.720] You know, I've preferred the analogy of planting the seed. [25:41.820 --> 25:44.820] Us being here is so we could plant a seed. [25:45.400 --> 26:01.620] Currently, unfortunately, or fortunately I guess we could say, between the two of us and I haven't been able to confirm nor deny that foreign governments are proactively blocking IAX right now. [26:05.370 --> 26:08.110] Whether it's a good thing or a bad thing, if I found out or not. [26:09.230 --> 26:16.530] Whether that changes in the future, someone can simply use this script and I won't mean a lick of difference. [26:18.130 --> 26:20.130] I figure it could be useful to a few. [26:24.060 --> 26:24.780] Anything you want to say? [26:25.320 --> 26:25.560] No? [26:27.200 --> 26:27.640] All right. [26:28.100 --> 26:30.120] Before I got the Q&A, we kind of cruised through this. [26:30.180 --> 26:31.220] I thought it would take much longer. [26:33.480 --> 26:35.500] This is the New York 55 minute right here, guys. [26:36.560 --> 26:37.000] All right. [26:37.800 --> 26:40.060] I guess I'll fire up the script and toss a couple commands at it. [26:40.080 --> 26:40.600] What do you guys think? [26:42.000 --> 26:42.300] Go. [26:44.880 --> 26:47.520] How do you guys like my generic open office template? [26:47.820 --> 26:48.400] You guys like that? [26:50.500 --> 26:51.220] All right. [26:51.360 --> 26:52.440] Any sensitive information? [26:52.780 --> 26:53.100] All right. [26:55.040 --> 26:55.960] Let's just do that. [26:56.080 --> 26:56.660] A lot of fun. [26:57.040 --> 26:57.380] All right. [27:00.020 --> 27:03.360] And the last slide that I'll bring back up, it has a website. [27:03.920 --> 27:05.440] I'm not going to really talk about the website. [27:05.460 --> 27:06.680] It's just a website I threw together. [27:07.440 --> 27:08.360] We'll get back to that too. [27:09.080 --> 27:10.500] So this is the basic command. [27:10.720 --> 27:12.680] Notice I have a hope release version. [27:14.040 --> 27:19.400] By default, it sends it to the loopback interface and the default port of 4569. [27:20.480 --> 27:20.760] Boop. [27:21.480 --> 27:23.260] There's a VoIP server there. [27:24.640 --> 27:25.720] Pretty obvious, right? [27:29.420 --> 27:31.120] I should look at the next one. [27:34.020 --> 27:36.760] Does anyone have an Azure server they want me to poke right now? [27:37.200 --> 27:37.520] No? [27:38.900 --> 27:40.000] Are everyone scared? [27:40.120 --> 27:41.680] You think I'm going to put that little DOS flag on it? [27:44.940 --> 27:46.200] Sip.sensoryresearch.net. [27:46.760 --> 27:47.080] Sip. [27:47.380 --> 27:47.840] Hold on. [27:51.460 --> 27:52.100] Sip dot... [27:52.100 --> 27:53.940] Do you have a business card with this domain on it, should I ask? [27:56.380 --> 27:57.880] S-E-N... [27:58.300 --> 27:58.920] Help me out. [27:59.100 --> 28:00.800] S-E-N-S-O-R-Y... [28:00.800 --> 28:01.740] S-O-R-Y... [28:01.740 --> 28:02.900] S-O-R-Y... [28:02.900 --> 28:03.380] R-E-S-O-R-Y... [28:03.380 --> 28:03.440] R-E-S-O-R-Y... [28:03.440 --> 28:03.520] R-E-S-O-R-Y... [28:03.520 --> 28:04.300] R-E-S-O-R-Y... [28:06.480 --> 28:08.100] R-E-S-O-R-Y... [28:09.780 --> 28:12.180] Whoa, what was that? [28:13.760 --> 28:15.380] You know what, I'm actually not even on the Internet. [28:15.560 --> 28:16.520] Of course that didn't work. [28:23.420 --> 28:25.300] I do not trust it, no offense. [28:30.700 --> 28:31.480] The wire. [28:33.500 --> 28:34.420] Say that again, I'm sorry? [28:38.870 --> 28:40.330] No, there's no RTP data. [28:40.950 --> 28:43.550] No, Asterisk is not encapsulating the audio in RTP. [28:43.550 --> 28:58.070] It's just layering it in the media stream as the audio itself with just enough IP information hex-wise in the first, you know, however many bytes to identify where it needs to go. [28:58.470 --> 29:03.230] So there's no layering of that, which is not detectable, you know, as easily. [29:03.430 --> 29:09.530] You know, someone's going to have to find a footprint for IAX, whereas SIP uses RTP, which has a defined footprint. [29:18.540 --> 29:19.580] I'm going to reset my network. [29:19.700 --> 29:21.080] I'm going to turn the screen off for a second, guys. [29:21.160 --> 29:21.540] Excuse me. [29:22.620 --> 29:22.840] Okay. [29:23.060 --> 29:23.700] Well, you're lying. [29:23.820 --> 29:24.100] There we go. [29:24.260 --> 29:24.420] All right. [29:28.800 --> 29:30.000] Can I ask you a question, Jeremy? [29:30.240 --> 29:31.160] You want to tell everyone the answer? [29:32.260 --> 29:37.760] What could we do if someone comes up with a protocol signature and applies it to a deep packet inspection? [29:38.700 --> 29:42.980] Well, we could add random situations to the IAX protocol. [29:43.640 --> 29:52.420] We could set up a... since Asterisk is open-source, we could easily set up a randomization aspect in many ways. [29:52.420 --> 30:06.700] We could add random bits of data at known points in the front and back of each packet to effectively make a signature change for each and every packet, which would be real hard to guess unless someone figures out our randomization technique, I guess. [30:06.900 --> 30:07.960] But it would be open-source. [30:09.380 --> 30:10.460] Yeah, that's difficult. [30:10.460 --> 30:15.800] Eventually, the IAX packet should resemble some structure, right? [30:15.960 --> 30:24.840] So the packet shape was to be able to catch that structure and be able to detect the IAX communication and drop the header. [30:24.980 --> 30:32.520] Well, that's where you'd polymorphically randomize the headers and then just have shared hashes on each end, which is pretty much what you alluded to. [30:33.580 --> 30:35.500] Does that kind of... [30:35.500 --> 30:36.540] All right. [30:47.770 --> 30:48.510] Whatever, right? [30:48.510 --> 30:51.110] And when they fix that, you just figure out something else. [30:51.350 --> 30:53.690] I mean, whoever's got the best tool wins or... [30:53.690 --> 30:54.870] Just got to one-up each other. [30:55.010 --> 30:56.970] It's kind of like little kids on a pork, you know? [30:58.550 --> 30:58.950] So... [30:59.550 --> 31:01.810] I figure it's a proper analogy. [31:07.470 --> 31:10.310] I'm not having much luck with the Internet right now. [31:14.100 --> 31:15.580] Do that, do that, do that, do that, do. [31:20.510 --> 31:21.210] Dead line. [31:21.870 --> 31:22.270] Yeah. [31:22.670 --> 31:25.030] I don't think the Internet is working out of this cable. [31:31.720 --> 31:33.740] Is there anything we missed that we can talk about real quick? [31:34.000 --> 31:34.060] No? [31:34.820 --> 31:35.500] On the site. [31:35.840 --> 31:35.980] Yes. [31:36.260 --> 31:36.420] No? [31:36.620 --> 31:38.520] All right. [31:38.680 --> 31:39.480] Internet's not working. [31:40.420 --> 31:42.380] The gentleman over there, you can see me later. [31:42.380 --> 31:43.420] We could doss your site. [31:44.180 --> 31:44.620] Off... [31:44.620 --> 31:45.260] Off... [31:45.260 --> 31:45.720] Offline. [31:48.780 --> 31:49.580] All right. [31:53.500 --> 31:54.760] Just give me another second, guys. [31:54.880 --> 31:55.260] Excuse me. [32:38.700 --> 32:39.420] One more. [32:39.820 --> 32:40.380] One more. [32:43.020 --> 32:43.560] All right. [32:44.860 --> 32:45.480] There we go. [32:46.300 --> 32:48.400] So I'm just going to run this scan real quick. [32:48.540 --> 32:49.640] I'm going to attack myself. [32:49.940 --> 32:50.680] I hope you guys enjoy. [32:50.680 --> 32:55.600] I'm going to scan my loopback interface from port 1 to 1000. [32:58.180 --> 33:00.400] And as well, in shell number 2. [33:01.180 --> 33:02.660] What's behind shell number 2? [33:03.500 --> 33:05.000] I'm going to inject it. [33:05.180 --> 33:07.280] And real quick, I'm going to hit enter and switch back. [33:09.140 --> 33:10.240] Hopefully, we'll get it. [33:11.500 --> 33:12.840] Oh, what's that? [33:13.260 --> 33:14.200] Holy cow. [33:14.960 --> 33:18.560] I didn't know there could be so many asterisk servers on a single IP address. [33:20.120 --> 33:29.900] So as far as proof of compset goes, this kind of confirms for me that planting the seed of miscontempt and just having fun. [33:33.860 --> 33:36.520] Does anyone have any questions about any specifics? [33:37.280 --> 33:39.400] Are you going to release the code script? [33:39.700 --> 33:40.000] Yes. [33:40.400 --> 33:40.840] Oh. [33:41.340 --> 33:42.260] Thank you, sir. [33:42.500 --> 33:44.140] I almost didn't go to my last slide. [33:44.980 --> 33:45.820] All right. [33:53.440 --> 33:54.320] All right. [33:54.520 --> 33:55.300] Everyone write this down. [33:56.920 --> 33:57.800] Securitiescraper.com. [33:57.860 --> 34:03.400] It's a simple site I set up that harvests records every 15 minutes from 180 different sites and puts it all on one page. [34:03.580 --> 34:05.120] It harvests about 500 records a day. [34:05.200 --> 34:05.540] I use it. [34:05.620 --> 34:06.140] It saves me time. [34:06.140 --> 34:07.500] If you want to use it, please feel free. [34:08.260 --> 34:10.630] I'm going to provide a link on the top. [34:11.920 --> 34:13.500] I told you a brief overview, right? [34:13.630 --> 34:14.020] I mean, jeez. [34:15.860 --> 34:17.090] I'm going to put a link up top. [34:17.090 --> 34:18.090] It's not up there yet. [34:18.900 --> 34:19.880] I'm going to do it tonight. [34:20.740 --> 34:24.040] Probably with some type of beer or German energy drink in my hand. [34:25.360 --> 34:27.320] As well, I'll have a link to the presentation. [34:27.740 --> 34:29.050] You guys can download it. [34:29.090 --> 34:29.900] Have fun with it. [34:30.050 --> 34:32.590] If anyone wants to make improvements to it. [34:33.170 --> 34:34.340] Did anyone see that? [34:34.400 --> 34:35.460] I stressed the word improvements. [34:37.020 --> 34:43.300] Any type of community activity, I'd be more than willing to host and support or this, that, and the other. [34:43.300 --> 34:45.500] I'd like to see this be implemented in a lot of tools. [34:46.650 --> 34:47.520] Let freedom ring. [34:49.880 --> 34:52.800] If you want us to take down your asterisk box, let us know. [34:53.020 --> 34:53.360] Yes. [34:53.590 --> 34:56.920] We will definitely stress test your servers. [35:00.960 --> 35:01.460] All right. [35:01.520 --> 35:03.130] They want us to make a couple of announcements here. [35:03.550 --> 35:05.760] There's lots to see and do in the pavilion. [35:06.760 --> 35:08.400] And then use restraint. [35:08.630 --> 35:09.920] Please don't mess with the hotel. [35:10.630 --> 35:12.840] Leave the hotel, then mess with whatever's there. [35:12.840 --> 35:14.300] I actually don't do that either. [35:14.630 --> 35:18.900] DVD sales of all talks are in the vendor area on the 18th floor. [35:19.760 --> 35:21.040] Which is right around the corner. [35:21.360 --> 35:21.500] Yep. [35:22.540 --> 35:23.210] Let's read them all. [35:23.300 --> 35:24.280] Let's read a couple more. [35:24.340 --> 35:24.540] Yeah. [35:24.880 --> 35:30.440] Robert Steele's books are on sale at the DVD store until his talks by improved.