[00:00.000 --> 00:01.880] DEFCON, it's been expanded. [00:02.400 --> 00:07.240] So some of you guys have already seen some of this material. [00:07.520 --> 00:09.360] I'm going to go ahead and go through it all again. [00:09.700 --> 00:17.460] I'm probably going to breeze through some of it just because there's a lot more out on the Internet about it now than there was when I first presented it. [00:17.560 --> 00:19.220] So you guys can find out more. [00:22.360 --> 00:22.900] What's that? [00:23.540 --> 00:24.960] Speak up. [00:25.180 --> 00:25.720] Yes, I can. [00:26.500 --> 00:26.920] All right. [00:27.180 --> 00:27.820] Who am I? [00:28.340 --> 00:29.600] My name is Tom Wilhelm. [00:30.180 --> 00:40.660] I think it's important for you guys to understand who I am and where my background is, mostly because that way you can understand why this project came about. [00:41.280 --> 00:43.300] I've got a bunch of letters after my name. [00:43.760 --> 00:50.220] Unfortunately, I'm in an environment where that's pretty much required to get past any sort of HR filters or anything like that. [00:50.500 --> 00:51.560] You shouldn't be impressed. [00:51.800 --> 00:53.720] Like I said, it's just to get in the door. [00:53.860 --> 00:54.560] So I got those. [00:54.560 --> 00:58.000] I also got a couple of master's degree, one in computer science, one in management. [00:59.260 --> 01:03.420] I have a bachelor's degree in history as well, which is actually pretty fascinating. [01:03.700 --> 01:12.760] I encourage everybody to start expanding their ideas of what is an acceptable education in this environment, because a history degree has helped me out tremendously. [01:13.900 --> 01:15.060] I used to be in the army. [01:15.540 --> 01:17.240] I was a Russian linguist. [01:17.680 --> 01:18.120] Okay. [01:19.360 --> 01:19.800] Unusual. [01:19.960 --> 01:21.000] I usually don't get that. [01:21.000 --> 01:24.400] I was a signal analyst and a crypt analyst. [01:24.620 --> 01:26.080] And I did that for about eight years. [01:26.760 --> 01:32.420] So I have a... and I've been basically in information security for about 18 years now. [01:34.140 --> 01:36.240] Currently, I work for a Fortune 50 company. [01:36.400 --> 01:38.420] I do penetration testing and risk assessments. [01:38.840 --> 01:44.400] I get to do all the things that people aren't supposed to do, and I get paid to do it. [01:44.400 --> 01:47.480] I do internal and external penetration testing. [01:47.720 --> 01:50.780] During the risk assessments, there's usually a pen-test component. [01:51.460 --> 02:02.380] And, you know, basically they want to know, since their systems typically face the Internet, they want to know exactly what you guys, or worse than you guys, can actually do. [02:02.400 --> 02:06.060] So we actually have to do the bad things, which is cool. [02:06.800 --> 02:09.920] It's kind of a... the Fortune 50... we're actually in the teens. [02:10.180 --> 02:15.120] I just wanted to... that was a good number to throw up there instead of actually saying a 14-whatever number. [02:15.520 --> 02:17.040] I'm also a PhD student. [02:18.260 --> 02:19.980] I'm also an adjunct professor. [02:21.460 --> 02:28.760] That's going to be important as we go through this, because you'll understand why this is so critical, this project. [02:29.780 --> 02:32.100] I'm also an author. [02:32.240 --> 02:34.860] I've been published in a few books and a magazine as well. [02:36.060 --> 02:41.100] Strangely enough, this is one of these... this project has been written in a couple of these books as well as the magazine. [02:41.640 --> 02:46.920] Very few people actually know about the de-ice.net pen-test live CDs. [02:47.220 --> 02:52.280] Who's actually... just out of curiosity, how many people have actually downloaded one of the discs and ran through it? [02:52.520 --> 02:54.880] One, two, three, four... ten. [02:55.140 --> 02:55.540] Maybe ten. [02:56.200 --> 02:59.060] But it's been out for a year and a half, and like I said, it's been written up in books. [02:59.060 --> 03:05.240] And that's why I'm actually out here on the East Coast, is trying to get a little bit more recognition... [03:05.240 --> 03:08.520] or not necessarily recognition, but at least get you guys familiar with what's out there. [03:08.660 --> 03:10.040] I mean, this is, I think, cool. [03:10.280 --> 03:12.420] It's obviously been written up, so it's not that bad. [03:14.640 --> 03:16.540] A little bit of history about myself. [03:17.340 --> 03:21.500] I told you that I was in information security for the last 18 years. [03:21.500 --> 03:23.260] Well, I've always been on the defensive side. [03:23.840 --> 03:26.040] It makes sense, military and things like that. [03:26.240 --> 03:29.360] I was a system administrator, security administrator, all that stuff. [03:29.540 --> 03:31.400] So, I was always on the defensive side. [03:31.500 --> 03:36.440] Well, the company I was in, currently, went through a reorg not too long ago, a few years ago. [03:36.860 --> 03:48.160] And I got caught up in that reorg, and they moved me into, from doing, basically, exception policies for security, moved into the penetration testing group. [03:49.120 --> 03:53.400] Well, like I said, I understood what the bad guys did. [03:53.700 --> 03:59.760] And I understood, you know, on a theoretical perspective, of what the bad things could be on my system. [03:59.780 --> 04:03.280] Well, I've never actually really done those things. [04:03.560 --> 04:05.000] I knew about them, didn't do them. [04:06.780 --> 04:12.920] So, I had to figure out what my job was, and I had to figure it out, basically, at a full run. [04:12.920 --> 04:20.040] Now, one of the things that you have to understand is that the company that I was in, they had pen-testers. [04:20.160 --> 04:24.600] And they had been really hammering these systems, these Internet-facing systems. [04:25.300 --> 04:27.800] So, here I am, basically a newbie, in a way. [04:28.600 --> 04:32.420] I understand the concepts, but I didn't know the actual techniques and the tools. [04:32.420 --> 04:39.920] And so, here I am, I'm supposed to do this, and I don't really have the hands-on experience. [04:40.300 --> 04:46.560] So, I go up and I try to actually do some hacking on some of our servers, and nowhere near. [04:46.660 --> 04:52.780] Because the level of skill set was much higher than what I was starting out at. [04:52.780 --> 04:55.860] So, I knew that I had to ramp up as quickly as possible. [04:56.220 --> 05:00.980] And so, you hit the Internet, and you try to find out what are the suggestions on how to do this. [05:01.060 --> 05:01.900] And I had to do it quickly. [05:02.800 --> 05:09.520] So, the first thing, there are some Internet sites that allow you to do some SQL injections. [05:09.940 --> 05:11.280] And, you know, it's all web-based stuff. [05:11.460 --> 05:11.760] Cool. [05:12.500 --> 05:13.240] You need to know that. [05:13.620 --> 05:17.220] That's not a whole lot of what we ended up actually doing for real life. [05:18.540 --> 05:20.820] The scenarios, but that's typically it. [05:20.820 --> 05:29.580] There's nothing out there that teaches you, other than just reading, how to do an attack using Netcat, or Scapy, or any of that other stuff. [05:30.600 --> 05:32.760] You've got to basically throw up your own lab. [05:32.920 --> 05:34.200] So, next one, build a lab. [05:34.340 --> 05:34.920] Build a lab. [05:36.640 --> 05:40.120] They tell you, okay, get an OS that's compromised. [05:40.360 --> 05:41.700] You can compromise pretty easy. [05:41.920 --> 05:42.540] Oh, yeah, okay. [05:42.680 --> 05:44.180] Windows 2000. [05:44.580 --> 05:44.860] Good. [05:45.460 --> 05:47.260] Then you start learning to hack on that. [05:47.400 --> 05:47.580] All right. [05:47.700 --> 05:49.100] So, you get up Metasploit. [05:49.180 --> 05:50.200] You spin that up. [05:50.860 --> 05:52.280] You click a couple buttons. [05:52.620 --> 05:53.980] You click another button. [05:54.120 --> 05:55.120] The next thing you know, you got root. [05:55.820 --> 05:56.900] That didn't teach me anything. [05:57.080 --> 05:57.240] Nothing. [05:57.760 --> 06:04.200] So, the next thing is, is that, you know, the other alternatives is that you start hacking over the Internet. [06:04.380 --> 06:08.500] There are certain things that are available out there, unfortunately, that they're not secure. [06:09.400 --> 06:11.140] Well, I like to keep my job. [06:11.260 --> 06:12.620] So, I couldn't do that. [06:12.920 --> 06:23.160] So, what I ended up having to do is I just had to go, you know, read everything I can and actually bang my head as hard as I could against these systems so I could actually learn how to do this. [06:23.200 --> 06:25.400] It was extremely painful and extremely difficult. [06:32.390 --> 06:36.250] So, we're going to talk about a little bit of why you actually need a Pentest Lab. [06:36.250 --> 06:42.630] I just said that Pentest Labs, it wasn't really a good experience because, you know, you throw up something, it's easy to compromise. [06:42.890 --> 06:52.430] The alternative is you throw up something that's difficult, a newer version of the Red Hat or Black, you know, Red Hat or whatever you have gone to. [06:52.690 --> 06:53.670] Try banging your head. [06:53.790 --> 06:53.850] No. [06:53.950 --> 07:05.270] You got to be able to understand how to do reverse engineering and stuff like that in order to be successful because you're not... all the holes have already been patched. [07:05.370 --> 07:06.490] It's a new operating system. [07:06.630 --> 07:07.130] Good luck. [07:08.330 --> 07:13.270] So, you really need to have a lab because hacking on the Internet doesn't work. [07:13.330 --> 07:14.430] And here's some of the reasons why. [07:14.530 --> 07:15.570] We've got two people up here. [07:16.290 --> 07:21.190] These aren't the best examples because they were a little bit malicious in their intent. [07:22.990 --> 07:31.390] However, one of the things that you want to notice down here is that it did not compromise any of the confidential or proprietary information. [07:31.570 --> 07:34.870] This last individual was mostly doing it for joyriding. [07:35.390 --> 07:36.630] Unfortunately, he got busted. [07:37.090 --> 07:40.870] It didn't matter what his motives are, what his intentions were. [07:40.990 --> 07:43.090] It could have been, you know, pure as the virgin snow. [07:43.110 --> 07:46.330] But the problem was the law didn't care. [07:46.570 --> 07:49.730] He got busted, 12 months, a lot of money. [07:50.690 --> 07:52.470] So, you really need to focus on a lab. [07:53.290 --> 07:55.190] So, you're going to end up banging your head. [07:55.330 --> 07:56.210] It doesn't make sense. [07:56.410 --> 07:58.170] So, we're going to talk a little bit more. [07:59.410 --> 08:03.770] There's also some other problems as in to why you need lab. [08:03.890 --> 08:10.910] Even if you've got a buddy to set up a server on the Internet, you've got problems with brute force attacks, aggressive scanning. [08:11.170 --> 08:12.550] There's denial of service attacks. [08:12.750 --> 08:18.330] There's all these other things that you've got to deal with or you have to do in order to learn some of these techniques. [08:18.650 --> 08:21.930] And unfortunately, the intrusion detection systems will identify it. [08:22.550 --> 08:25.670] Your Internet service provider will also notice these things. [08:25.670 --> 08:27.850] So, it's not necessarily a good thing to do. [08:30.130 --> 08:31.890] Plus, you also have some time constraints. [08:32.050 --> 08:34.370] Your buddy might set up a server and you want to hack. [08:34.730 --> 08:38.110] Well, unfortunately, somebody else tells that buddy or that buddy tells somebody else. [08:38.230 --> 08:39.910] And next thing you know, there's 20 people hitting it. [08:40.530 --> 08:42.890] Also, next thing you know, his server goes down. [08:43.330 --> 08:44.050] He's at work. [08:44.190 --> 08:44.910] You can't do it. [08:44.910 --> 08:46.070] You've got to wait until he gets back. [08:46.470 --> 08:47.890] It's really crazy. [08:48.190 --> 08:48.990] Code of ethics. [08:49.030 --> 08:51.030] That's another reason why I need a lab. [08:51.350 --> 08:54.570] And like I said, I get paid well enough that I don't want to jeopardize that. [08:56.230 --> 09:01.210] So, that's the disadvantages of the hacking over the Internet and the advantages of having a lab. [09:01.310 --> 09:03.750] So, let's talk about what are the disadvantages of a lab. [09:04.730 --> 09:06.290] It's expensive and expansive. [09:07.210 --> 09:08.790] There's electrical costs. [09:08.950 --> 09:09.910] There's equipment costs. [09:10.190 --> 09:11.350] There's limited rack space. [09:11.350 --> 09:15.510] My wife gets really ticked off every time I bring in a new shiny, blinky box. [09:15.850 --> 09:20.530] And, I mean, my bedroom right now is probably about 20 degrees warmer than the rest of the house. [09:22.530 --> 09:23.910] Living space becomes uncomfortable. [09:24.430 --> 09:25.930] So it is living with your wife. [09:27.290 --> 09:28.210] Diversity is up to you. [09:28.290 --> 09:36.110] You've got to find the equipment that you want to hack and bring it into your lab and hook it up and get familiar with it and all the other stuff. [09:36.110 --> 09:44.990] It would be really convenient if you wanted to learn Oracle's or you wanted to learn the Slayer's hacks to just be able to touch that system rather than go out and buy it. [09:45.090 --> 09:46.970] That's one of the disadvantages of the lab. [09:49.810 --> 09:56.590] Here's the big one, and this is one of the reasons why I ended up doing these disks, is how do you make a real world challenge? [09:57.710 --> 10:00.710] I talked about ramping up a Windows 2000 box. [10:00.810 --> 10:01.970] Let's just go through that. [10:02.090 --> 10:09.290] I throw on some patches and I set up some weak services that are nowhere weak, but everything else is tight. [10:09.550 --> 10:13.990] Well, I already know what the vulnerabilities are and I know how to exploit it. [10:13.990 --> 10:16.350] You can't create...it's a chicken and egg problem. [10:16.510 --> 10:21.830] How do you get something that's a challenge if you already know how it's set up? [10:23.310 --> 10:24.030] You can't. [10:25.870 --> 10:26.990] So I began to think. [10:27.210 --> 10:34.270] After a couple years of banging my head and getting up to speed, I started reflecting on what I experienced and I really didn't enjoy it. [10:34.390 --> 10:41.650] And so I was thinking, how can I do this in a way that people coming up behind me don't go through this headache? [10:42.490 --> 10:44.330] Well, it had some criteria. [10:44.530 --> 10:45.230] It needed to be easy. [10:45.690 --> 10:47.830] It needed to be challenging enough. [10:48.870 --> 10:52.050] It really had to simulate real world situations. [10:52.410 --> 11:00.810] A lot of times, you know, like you do the web-based hacking and, you know, you go through the HTML page and you look for the password on the HTML page. [11:00.910 --> 11:02.110] That's very beginner stuff. [11:02.550 --> 11:03.450] Who does that? [11:03.570 --> 11:03.830] Nobody. [11:04.110 --> 11:06.570] So it can't be this fictitious. [11:06.690 --> 11:08.610] It has to be based on real world experience. [11:08.610 --> 11:14.010] Now, at this point, I had already, you know, like I said, banged my head and I was getting that real world experience. [11:14.150 --> 11:19.530] I was knowing, I was learning what those vulnerabilities really were in the real world. [11:20.070 --> 11:23.170] So I could take those and apply this to these disks. [11:23.430 --> 11:26.890] It had to be portable and it had to be nerdy enough to be cool. [11:27.770 --> 11:28.270] All right. [11:28.390 --> 11:30.710] Something nerdy would be live CDs. [11:31.650 --> 11:32.410] And they're cool. [11:35.410 --> 11:37.470] Everybody here has dealt with a live CD. [11:37.610 --> 11:38.490] I mean, Backtrack, right? [11:38.790 --> 11:39.090] Right. [11:39.310 --> 11:39.430] Okay. [11:39.570 --> 11:43.630] Who has Backtrack on their system, loaded on their hard drive? [11:44.670 --> 11:45.150] Yeah. [11:45.450 --> 11:45.890] Okay. [11:46.150 --> 11:49.190] Who only runs it from the live CD? [11:50.450 --> 11:50.930] Really? [11:51.210 --> 11:52.390] I'm pretty impressed. [11:52.610 --> 11:55.190] So you don't mount up the hard drives or anything like that. [11:55.330 --> 11:56.450] So, okay. [11:56.610 --> 11:58.030] Let's talk about speed. [11:58.030 --> 12:09.410] If you're doing like a Hydra attack where basically you're doing a brute force over the net to try to get passwords, what's the IO speed between your disk? [12:09.950 --> 12:10.390] Yeah. [12:10.670 --> 12:11.510] It's questionable. [12:11.730 --> 12:12.850] You really want that speed. [12:14.490 --> 12:17.190] Unfortunately, what most people do is they take that disk. [12:17.310 --> 12:18.090] Really cool idea. [12:18.530 --> 12:19.630] Keeps it really secure. [12:19.730 --> 12:20.850] You can't hack the disk. [12:21.330 --> 12:22.590] And they put it on their hard drive. [12:22.670 --> 12:23.150] I do it. [12:23.230 --> 12:24.970] I do it because of that speed problem. [12:24.970 --> 12:29.690] I've done distros, you know, Ubuntu comes with the ability to run it as a live CD. [12:30.330 --> 12:31.330] I don't do that. [12:31.510 --> 12:32.050] I install it. [12:32.510 --> 12:39.510] So, live CDs, my experience with live CDs was you take it, you burn it, you know, you burn it, you throw it on the disk, and you drop it to the drive. [12:41.670 --> 12:47.610] So, live CDs were basically cool, but I haven't really seen a real good reason to use them. [12:47.710 --> 12:50.070] But then it clicked for me on this one. [12:52.310 --> 12:54.190] There's some advantages to using a live CD. [12:54.350 --> 12:55.490] First of all, there's cost advantage. [12:55.770 --> 12:58.450] I cannot have an entire server run up on a disk. [12:58.650 --> 12:59.830] I don't have to have... [12:59.830 --> 13:03.850] If I want to do multiple scenarios, I can just VM it on one system. [13:04.030 --> 13:04.590] I'm done. [13:06.170 --> 13:07.230] It's portable and compact. [13:07.350 --> 13:07.810] I got a disk. [13:07.950 --> 13:08.690] I got a disk. [13:08.810 --> 13:09.510] I can give it to you guys. [13:09.770 --> 13:10.610] Well, I got one disk. [13:10.690 --> 13:11.550] I can give it to one person. [13:12.930 --> 13:14.070] It's quick and easy to use. [13:14.190 --> 13:15.790] I screw up the server. [13:16.830 --> 13:17.730] I reboot it. [13:17.830 --> 13:18.330] That's it. [13:18.330 --> 13:21.170] I don't have to go through building it up and everything like that. [13:21.470 --> 13:22.610] There are some other... [13:22.610 --> 13:23.470] I'm going to inject right now. [13:23.550 --> 13:29.790] There are some other scenarios, some practice labs basically. [13:30.390 --> 13:32.050] Anybody heard of the Hack Me series? [13:33.150 --> 13:34.090] Yeah, there's a few. [13:34.370 --> 13:36.870] The Hack Me series is basically... [13:36.870 --> 13:39.750] It's like 99% web-based attacks. [13:40.550 --> 13:41.150] Excuse me. [13:41.950 --> 13:44.370] But what you've got to do is you've got to take a server. [13:44.370 --> 13:47.010] You've got to put .NET on there. [13:47.130 --> 13:50.250] You've got to put Windows SQL Server on there. [13:50.430 --> 13:52.850] You've got to do all these things Microsoft proprietary. [13:53.150 --> 13:55.490] I screwed that up when I did that one time. [13:56.510 --> 13:58.050] I had to rebuild that. [13:58.130 --> 14:00.470] Everybody knows rebuilding a server is a pain. [14:00.670 --> 14:04.050] So, one of the advantages of the YCD is I just reboot. [14:04.270 --> 14:04.730] That's it. [14:06.550 --> 14:10.690] Now, the other thing to point out here is they are real servers with real services. [14:11.910 --> 14:15.950] There's a little bit of confusion when people first get introduced to these live CDs. [14:16.270 --> 14:20.730] And the understanding is that they take what they already know. [14:21.130 --> 14:23.810] Things like damn vulnerable Linux and things like that. [14:23.930 --> 14:27.450] And try to take these discs and put that in that mold. [14:27.570 --> 14:29.590] I'm going to explain why that's not the case. [14:29.710 --> 14:30.710] And you shouldn't think it that way. [14:31.070 --> 14:32.450] But I'll get that in a second. [14:35.290 --> 14:36.690] Okay, disadvantages of live CDs. [14:36.850 --> 14:37.990] There's always got to be a disadvantage. [14:38.970 --> 14:42.770] If you're actually learning or wanting to learn pen-tests, these live CDs are great. [14:42.890 --> 14:45.970] If you're wanting to learn how to be a system administrator, this is a bad idea. [14:46.170 --> 14:47.810] Because I've set up the entire servers for you. [14:48.870 --> 14:50.770] There's a difference between modules and packages. [14:51.790 --> 14:56.690] The modules are basically put together and then put on the disc. [14:56.890 --> 14:58.450] And then the disc runs it. [14:59.150 --> 15:02.130] Normally what you do with the server, you want a package, you just install the package. [15:02.390 --> 15:04.890] It's a lot more difficult to do things in a live CD. [15:05.990 --> 15:08.590] And also you've got to deal with proprietary operating systems. [15:09.690 --> 15:13.470] I can't make a live CD legally using Microsoft. [15:13.470 --> 15:14.350] I cannot. [15:14.770 --> 15:19.230] So unfortunately, these scenarios are strictly Linux-based. [15:19.450 --> 15:20.730] It's a problem. [15:21.130 --> 15:23.870] A lot of people out there would be more interested in the Windows stuff. [15:23.890 --> 15:24.650] I understand that. [15:24.790 --> 15:31.090] But these discs are actually good for getting your feet wet and understanding how the process works on penetration testing. [15:31.090 --> 15:33.090] And then you can move on to something else. [15:34.450 --> 15:35.050] All right. [15:38.450 --> 15:39.130] What do you... [15:39.130 --> 15:39.950] I needed some standards. [15:40.210 --> 15:43.250] I wanted to use slacks because I was familiar with backtracking. [15:43.390 --> 15:43.930] I like backtracking. [15:44.190 --> 15:44.550] Backtrack? [15:45.650 --> 15:46.390] Hardware router. [15:46.610 --> 15:47.690] This is what's recorded alive. [15:47.750 --> 15:51.150] And you have to have two blazing-fast machines like what we've demonstrated here. [15:51.630 --> 15:54.170] A target system and an attack system. [15:54.630 --> 15:59.290] One to actually hold your live CD and then another one to load up on backtrack. [16:02.500 --> 16:02.900] All right. [16:03.100 --> 16:03.700] Some more standards. [16:04.300 --> 16:04.940] Target machine. [16:05.100 --> 16:07.980] I decided originally I was going to do DHCP for all these discs. [16:08.280 --> 16:08.880] This is... [16:09.220 --> 16:11.740] You know, a lot of you guys are probably going to start falling asleep for earlier in a minute. [16:11.820 --> 16:12.860] But this was just kind of... [16:13.240 --> 16:16.520] I'll let you understand what the ideas behind this is. [16:16.520 --> 16:20.680] So when you actually see a disc 1.100 or 2.100, you'll know what it is. [16:20.960 --> 16:21.580] What it means. [16:22.800 --> 16:24.840] I figured originally I was going to go DHCP. [16:26.240 --> 16:29.380] DHCP was going to be a real problem if I wanted to do man-in-the-middle attack scenarios. [16:29.380 --> 16:32.700] So what I decided to do is do a numbering scenario. [16:33.200 --> 16:37.480] A .192.168.1.whatever is a level 1 disc. [16:37.980 --> 16:39.560] 2.whatever is a level 2 disc. [16:40.000 --> 16:41.640] There's going to be a level 3 disc out soon. [16:42.380 --> 16:43.600] And so it'll be 3.whatever. [16:44.780 --> 16:48.060] The attack machine can be a dynamic DHCP basically. [16:49.040 --> 16:50.320] Router needs to provide DHCP. [16:50.420 --> 16:52.380] And also I wanted to push methodologies. [16:53.380 --> 16:54.900] I mean, you're going to learn penetration testing. [16:54.900 --> 16:56.680] You might as well have a methodology behind you. [16:56.680 --> 16:58.340] I push ISSAF now. [16:58.740 --> 17:03.860] OSSTMM turned out to be 2 of a high level for people who are really interested in getting at a level 1 disc. [17:04.160 --> 17:04.440] So... [17:09.510 --> 17:12.730] I eliminate... it does not eliminate the need for specialized services. [17:12.870 --> 17:16.350] If you want to hack a PIX firewall, you still got to hack a PIX firewall. [17:16.570 --> 17:18.210] I can't virtualize that. [17:18.870 --> 17:19.890] Juniper equipment, whatever. [17:20.450 --> 17:22.270] You also need to understand basic routing. [17:22.630 --> 17:28.110] At this point, if you're trying to learn how to do penetration testing before you know how to set your IP address, there's a problem. [17:30.790 --> 17:32.390] I'm going to blaze over this real quick. [17:32.910 --> 17:36.670] SLACs, you can just throw in some modules that basically they're pre-built. [17:36.950 --> 17:38.290] You drop them in there and you go. [17:38.550 --> 17:42.210] And one of the... some of the... and they also have some pre-built ISOs. [17:42.850 --> 17:44.970] And they have services running online as well. [17:45.070 --> 17:47.690] You can get a really small one under the new license. [17:48.330 --> 17:49.390] Not very user friendly. [17:50.630 --> 17:51.610] You can build your own. [17:53.130 --> 17:54.390] Here's the basic file structure. [17:54.710 --> 17:58.390] Real quick, the root copy directory is where I put everything. [17:58.570 --> 18:00.830] So if you actually want to see what I did on the disk, look in there. [18:00.990 --> 18:02.770] Usually what you're supposed to do is you modulize everything. [18:02.910 --> 18:04.910] Put it in one big pretty package and stick it on there. [18:05.090 --> 18:06.190] I left everything open. [18:06.190 --> 18:10.750] So once you guys actually hack the disk and you want to know how I set it up, you can go back and look at it. [18:10.810 --> 18:13.870] I don't want any... you know, I want you guys to know everything about it. [18:15.450 --> 18:15.770] More. [18:15.770 --> 18:15.790] More. [18:16.990 --> 18:18.390] You can put IP tables. [18:19.590 --> 18:22.750] There's different ideas behind the different levels. [18:23.690 --> 18:24.610] Pretty straightforward. [18:24.790 --> 18:25.210] It makes sense. [18:27.130 --> 18:28.950] Real world scenarios. [18:29.170 --> 18:31.050] These are some of the things that I picked up along the way. [18:31.310 --> 18:33.750] They should be pretty familiar with a lot of you people. [18:34.210 --> 18:35.750] Especially if you've done any of this stuff. [18:37.430 --> 18:37.890] Okay. [18:41.430 --> 18:46.730] I mentioned that people are familiar with certain things like Damn Vulnerable Linux or there's a couple other ones. [18:47.250 --> 18:51.990] And what they usually do is when I get these emails and they get posted up on the board as well. [18:52.750 --> 18:55.750] They down... somebody downloads the disk and says, hey, I can't log into the system. [18:56.530 --> 19:02.530] Well, the problem is is that what you're doing is you're setting up a server that you're supposed to have no idea about. [19:03.030 --> 19:06.250] And it is supposed to be your challenge. [19:07.010 --> 19:09.390] You're not supposed to know the password. [19:09.590 --> 19:11.290] And I explained that and they say, yeah, okay, I got it. [19:11.350 --> 19:12.190] So what's the password? [19:12.290 --> 19:14.230] I can't log in to do the actual hacking. [19:14.230 --> 19:16.190] Well, I understand that. [19:16.330 --> 19:18.610] It's because you're not supposed to know that. [19:18.750 --> 19:21.570] Well, then how am I supposed to do this disk if I don't know the password? [19:21.810 --> 19:24.770] Well, you're supposed to do all this other stuff on the other side. [19:24.970 --> 19:27.070] It is a server. [19:27.230 --> 19:29.650] Just pretend that you can't even see it. [19:29.750 --> 19:33.330] You know, you see it boot up and it's like, hey, yeah, okay, I'm good to go. [19:34.130 --> 19:38.430] Problem is is that you got to think that you, your router is the Internet. [19:38.430 --> 19:41.030] And you're not supposed to even being able to see this disk. [19:41.310 --> 19:44.430] So you got to go through the entire thing like the discovery. [19:44.770 --> 19:46.690] And you have to start doing scans. [19:46.930 --> 19:49.190] And you have to do all those things that you normally would do. [19:49.430 --> 19:52.010] The objective is to get that root password. [19:52.210 --> 19:55.510] The objective is to find those hidden documents in these disks. [19:56.470 --> 19:58.110] You're not supposed to know that at the get-go. [19:58.110 --> 20:04.930] So think of it actually as a real-world scenario, as if you're hacking somebody's server. [20:05.790 --> 20:06.270] All right? [20:06.730 --> 20:08.430] You don't even know the people's names. [20:08.790 --> 20:09.150] Seriously. [20:10.470 --> 20:12.090] So here's a configuration. [20:12.490 --> 20:13.490] You got your backtrack CD. [20:13.650 --> 20:14.290] You got your router. [20:14.470 --> 20:15.570] And then you got your disk. [20:18.910 --> 20:21.830] I'm going to go over the scenario of the 1.100 disk. [20:22.010 --> 20:25.610] If there was a lot more people in here that had actually gone through it, I would have breezed through a little bit better. [20:25.610 --> 20:31.310] But this will hopefully give a bit of a flush out on what these disks are about. [20:31.490 --> 20:35.850] So the scenario is that your CEO is pressured by the board of directors to have penetration testing done. [20:36.310 --> 20:40.350] Small companies, this is very, you know, people read the trading magazines. [20:40.530 --> 20:42.110] Oh, we got to have this. [20:42.270 --> 20:43.490] Got to do a penetration test. [20:43.690 --> 20:44.890] I don't want to lose my job. [20:45.070 --> 20:47.490] And so the CEO is like, yeah, whatever. [20:47.650 --> 20:48.530] I don't want to spend the money. [20:49.050 --> 20:50.970] So he thinks it's a huge waste of money. [20:52.530 --> 20:55.830] He's already had a company scan their network for vulnerabilities. [20:56.270 --> 21:03.890] You know, you buy the $200 service, which is somebody scans it and sends you this big long report. [21:04.330 --> 21:09.650] And it sits on front of the network manager's desk and is filed. [21:09.850 --> 21:10.890] And nobody does anything. [21:11.170 --> 21:13.370] That's what typically people have. [21:13.490 --> 21:16.010] I know this for a fact from my previous experience. [21:16.010 --> 21:17.890] This is what really happens. [21:17.890 --> 21:19.230] So real world scenario. [21:20.550 --> 21:21.290] All right. [21:21.510 --> 21:22.610] So you get hired. [21:22.730 --> 21:24.510] You guys are the penetration testers. [21:24.630 --> 21:26.670] You get hired to do the hack. [21:28.970 --> 21:34.570] I included, because this is a level one disk, I included some hints. [21:35.010 --> 21:40.150] If you guys get stuck and it happens, there's just hints. [21:40.290 --> 21:44.270] And basically what it is is it's white letters on white background. [21:44.270 --> 21:46.890] You know, you've got to highlight to figure out what the next step is. [21:47.630 --> 21:50.770] You can't just stumble on it, so it won't ruin the party for you. [21:51.990 --> 21:54.430] But you can go through without doing that. [21:54.590 --> 21:58.050] And you can go through without hitting the forms, which have complete spoilers as well. [21:58.790 --> 22:01.630] But the objective for this is to actually learn how to process... [22:01.630 --> 22:03.370] Learn how to do penetration testing. [22:03.630 --> 22:07.350] Learn the process of penetration testing, which is why I mentioned the ISSAF. [22:08.830 --> 22:10.630] And then use the tools. [22:10.790 --> 22:11.950] Learn how to use the tools. [22:13.370 --> 22:15.330] That's going to be important to remember in a second. [22:15.430 --> 22:15.970] Learn the tools. [22:18.490 --> 22:19.010] All right. [22:19.090 --> 22:21.690] Some of the tools required for the disk 1.100. [22:22.350 --> 22:25.190] Nmap, Firefox, SSH, Hydra, John the Ripper. [22:25.450 --> 22:27.750] These are very typical tools. [22:27.970 --> 22:30.450] Everybody should be familiar with these at this point. [22:31.470 --> 22:35.590] And for those that aren't, this is a perfect opportunity to learn those. [22:36.230 --> 22:38.970] And to actually, you know, like try the brute force stuff. [22:39.130 --> 22:40.930] And try the denial of service stuff. [22:41.130 --> 22:42.930] You can do this here. [22:43.810 --> 22:44.770] Tools that are not required. [22:44.870 --> 22:45.970] Nessus and Metasploit. [22:46.270 --> 22:46.390] Okay. [22:47.050 --> 22:47.730] Great tools. [22:47.910 --> 22:48.990] I will not deny that. [22:49.070 --> 22:53.190] As far as the Nessus one, we use that in the corporation all the time. [22:53.250 --> 22:53.990] That's our baseline. [22:54.030 --> 22:57.490] When we actually ramp up a pen-test, that's the first thing we grab. [22:57.730 --> 22:59.730] Cannot deny that Nessus is not a good tool. [22:59.730 --> 23:00.750] It is a great tool. [23:00.890 --> 23:03.630] The problem is, is it does a lot for you. [23:03.830 --> 23:05.970] It tells you what the vulnerabilities are. [23:06.150 --> 23:07.930] It tells you where to go and look for these things. [23:09.070 --> 23:12.290] That's not going to help you in the real world learning penetration test. [23:12.590 --> 23:14.110] So I don't want you guys clicking. [23:14.110 --> 23:16.570] I want you guys to actually do some work. [23:18.390 --> 23:18.910] All right. [23:19.230 --> 23:19.830] Nmap scan. [23:20.090 --> 23:22.170] I'm going to just kind of go through what people would see. [23:22.950 --> 23:24.690] They see that there's some services open. [23:24.830 --> 23:26.430] FTP, SSH, SMTP. [23:26.690 --> 23:26.910] Okay. [23:27.050 --> 23:28.570] There's a lot of places to start. [23:31.030 --> 23:32.670] I intentionally broke FTP. [23:34.210 --> 23:36.570] Basically to get some people banging on that for a while. [23:38.350 --> 23:38.790] Yeah. [23:39.110 --> 23:39.610] I know. [23:39.790 --> 23:40.390] I hear chuckles. [23:40.990 --> 23:43.030] There are no Nessus vulnerabilities actually. [23:43.310 --> 23:44.590] Well, at this point there are. [23:44.770 --> 23:48.570] But when I originally wrote this a couple years ago, there were not any vulnerabilities. [23:49.410 --> 23:51.190] I basically had the newer stuff. [23:51.330 --> 23:52.650] There's some stuff that's out there. [23:52.790 --> 23:58.950] But nothing that would allow you to make a quick trip on this disk. [23:59.130 --> 24:01.490] You can't just hack it right away with clicking. [24:03.630 --> 24:04.110] Okay. [24:04.310 --> 24:05.030] Just out of curiosity. [24:05.250 --> 24:07.250] You know, there's some things out here. [24:07.390 --> 24:08.850] How many people would actually... [24:09.490 --> 24:11.870] I mean, we've got FTP, SSH, SMTP. [24:12.330 --> 24:22.010] Just out of curiosity, how many people would actually start probing the HTTP service after they found this? [24:22.350 --> 24:23.670] We've got one, two people. [24:23.810 --> 24:24.270] Three people? [24:24.630 --> 24:25.010] Three people. [24:25.390 --> 24:25.670] Okay. [24:25.670 --> 24:27.150] I know a lot of people don't raise their hands. [24:27.530 --> 24:27.890] All right. [24:28.470 --> 24:31.890] There's a lot of opportunities out there that people skip. [24:32.070 --> 24:40.670] And unfortunately, this is one of the ones that I see a lot of people do in the real world is HTTP is usually easy. [24:41.350 --> 24:42.510] Everybody gets familiar with it. [24:42.550 --> 24:44.870] It's just something that people tend to shy away from. [24:44.930 --> 24:46.050] They want to go for the juicy stuff. [24:47.150 --> 24:49.390] Unfortunately, you've got to do the entire system. [24:49.510 --> 24:51.610] You've got to understand all the working parts. [24:52.350 --> 24:57.110] So if you do go to the HTTP info, you find out that there are some system administrators. [24:58.910 --> 25:00.010] Good place to start. [25:00.290 --> 25:01.450] You don't know any names. [25:01.530 --> 25:02.530] You don't know any logins. [25:03.270 --> 25:08.510] Turns out that they actually posted some names, no logins, up on their web server. [25:08.610 --> 25:09.090] It happens. [25:09.630 --> 25:11.070] That's not unusual. [25:11.290 --> 25:15.790] And it's not something that, as a security engineer, I'm even really worried about. [25:15.790 --> 25:21.330] But what that allows you to do as a penetration tester is actually start somewhere. [25:21.650 --> 25:24.370] Now, so you've got to start creating usernames. [25:24.930 --> 25:25.850] There's a whole bunch. [25:25.950 --> 25:28.690] Has anybody actually done a Hydroscan? [25:28.770 --> 25:28.930] Yes. [25:29.470 --> 25:29.770] All right. [25:29.850 --> 25:31.550] You know that there's two things. [25:31.670 --> 25:33.510] You need the password list and you need a user list. [25:33.650 --> 25:36.490] User lists really slow down the system. [25:36.590 --> 25:41.970] It's got to go through every name and got to go through the dictionary for each one of those. [25:41.970 --> 25:43.410] It's really a massive headache. [25:43.570 --> 25:46.670] So you've got to try to figure out how to slim that down. [25:49.860 --> 26:00.080] With Hydra, basically, what we did is we just did some simple flags on Hydra to find out that the intern is an actual idiot. [26:00.380 --> 26:03.260] He uses his login name and his password is the same. [26:03.360 --> 26:06.120] Well, unfortunately, you find this out. [26:06.260 --> 26:08.860] But the fact of the matter is that you can't use this account. [26:09.060 --> 26:10.900] I know I'm spoiling it a little bit. [26:10.900 --> 26:13.180] But you can't use this account to actually do anything. [26:13.320 --> 26:16.180] But at least now you know the way they do their names. [26:16.500 --> 26:17.980] All right. [26:18.900 --> 26:19.500] Keep going. [26:20.040 --> 26:25.900] You actually find out that Adams, the guy who's running it, has a password that you can actually hack. [26:27.000 --> 26:27.480] All right. [26:27.540 --> 26:28.040] So what's next? [26:28.160 --> 26:28.600] John the Ripper. [26:29.180 --> 26:36.720] You can actually try to find out the rest of the passwords and you need to actually be able to get root in this case. [26:36.880 --> 26:38.060] So you've got to do some things. [26:38.160 --> 26:39.940] You've also got to get familiar with OpenSSL. [26:39.940 --> 26:41.700] I'm going to leave the rest of this to work. [26:41.800 --> 26:43.500] There's actually three disks out there. [26:43.680 --> 26:44.720] Actually, there's more than that. [26:45.400 --> 26:47.900] But only three of them are available right now to you guys. [26:49.660 --> 26:53.180] And the hint for the 1.100 disk is to find the CEO bank account. [26:53.380 --> 26:58.640] If you're familiar with hacking and this is old hat to you, you should knock this out in half an hour. [26:58.640 --> 27:02.040] Level 2 disk, the best time is two weeks. [27:02.780 --> 27:07.020] So, you know, there are some step-ups as far as challenges are concerned. [27:08.140 --> 27:08.880] Yeah, so. [27:09.640 --> 27:16.280] Oh, and the guy who did it in two weeks, he was actually on vacation and that kind of pretty much consumed all of his time. [27:16.660 --> 27:22.420] I apologize to him for that because I'm sure his wife was a little disappointed and that's how he spent his holiday. [27:22.420 --> 27:23.580] But anyway. [27:25.040 --> 27:25.600] Okay. [27:27.120 --> 27:31.180] I am at the end of basically the first part of this lecture. [27:31.920 --> 27:35.880] At this point, when I was at DEFCON, I had a plea for action. [27:36.500 --> 27:43.420] I would like people to do these disks themselves, to actually create their own disks. [27:43.420 --> 27:47.560] I am not the smartest guy in the world. [27:47.800 --> 27:51.980] I know that there are people out there that are a lot better than I am. [27:52.760 --> 27:56.140] And unfortunately, it's hard to get them to share their knowledge. [27:56.280 --> 28:05.720] If they were to actually create one of these, it might actually open a little window into their world so I can actually see what it would be like to be even cooler. [28:07.940 --> 28:11.520] There are, like I said, penetration tests have many facets. [28:11.520 --> 28:14.320] My particular is to tech services. [28:14.660 --> 28:18.680] I'm a big Linux guy, heavy into Solaris. [28:18.940 --> 28:19.820] That's my expertise. [28:20.080 --> 28:22.620] I'm not really that good at things like web-based. [28:22.720 --> 28:23.320] I don't like it. [28:23.460 --> 28:24.000] Never did. [28:25.100 --> 28:29.000] I'm not that good at network hacks as well. [28:30.640 --> 28:32.120] I'm learning, trying to learn that. [28:32.320 --> 28:38.240] So if there are people out there that have those skill sets, I would encourage you to develop these disks on your own. [28:38.320 --> 28:39.220] It's really simple. [28:39.360 --> 28:40.380] It's not that difficult to do. [28:40.380 --> 28:41.800] And then share the wealth. [28:42.020 --> 28:42.140] Okay. [28:42.560 --> 28:48.600] So that's the plea I was basically making at DEFCON about a year ago. [28:50.460 --> 28:52.300] Problem is, nobody did it. [28:53.320 --> 28:54.640] Here's some contact information. [28:54.800 --> 28:56.020] It's going to come up again here in a minute. [28:59.400 --> 29:00.300] Not what I wanted. [29:02.380 --> 29:02.860] Okay. [29:04.320 --> 29:06.060] So like I said, nobody really... [29:06.060 --> 29:15.080] There's one guy who actually put together a disk that was not scenario-based, but it required you to put together exploits from milw0rm. [29:15.360 --> 29:15.720] Cool. [29:16.080 --> 29:19.900] And I praise him for that, and it was really a good idea to do stuff like that. [29:19.900 --> 29:22.260] I wanted to do that for a level three disk. [29:22.660 --> 29:25.300] I'm actually going to postpone that because he's already come out with it. [29:28.420 --> 29:30.360] But I found that as a... [29:30.360 --> 29:35.340] I'm going to jump down back to the slides because I'm going to just ramble on here in a second. [29:35.340 --> 29:42.700] It says, there's some deficiencies in learning that I've experienced in the last year and a half, two years, doing these disks and stuff. [29:43.740 --> 29:47.660] One of the problems is that people only know what the basics of the tools are. [29:48.180 --> 29:50.280] They are unfamiliar with the actual flags. [29:50.940 --> 29:52.060] I kind of... [29:52.060 --> 29:53.600] I got a little story. [29:53.720 --> 29:59.980] I was at college and came out into the parking lot, and there was this girl. [30:00.100 --> 30:04.700] She had the hood of her vehicle open, and she had a metal rod. [30:04.700 --> 30:09.780] And she was banging this rod inside the engine as hard as she could. [30:10.080 --> 30:11.700] I mean, just hammering away. [30:12.000 --> 30:14.060] And it's, you know, it's like 11 o'clock at night. [30:14.240 --> 30:15.780] And it's like, you okay? [30:15.780 --> 30:16.460] What's going on? [30:16.500 --> 30:18.360] She says, well, my car won't start. [30:19.440 --> 30:25.100] So I'm trying to figure out how beating the living crap out of the engine is going to start the car. [30:25.560 --> 30:29.660] Well, so, you know, I asked the question, so what are you doing? [30:29.660 --> 30:37.100] Well, my boyfriend says that I just need to hit this thing down here, and it'll start up. [30:37.680 --> 30:41.520] He told her to tap the solenoid if it doesn't start. [30:42.020 --> 30:46.320] Well, she took that as she could bang the living crap out of it. [30:46.500 --> 30:49.120] And wires were shredded, and it was just crazy. [30:49.460 --> 30:50.700] She couldn't get anywhere. [30:50.700 --> 31:00.200] Well, I equate that to the same thing as these disks, is that people understand what it's supposed to do. [31:00.900 --> 31:03.140] Like Hydra is supposed to break passwords. [31:04.380 --> 31:07.500] But, unfortunately, people don't know how to use those tools. [31:07.680 --> 31:10.860] They bang as hard as they can, and then they miss things. [31:11.700 --> 31:18.540] Perfect scenario is in Hydra, how many guys know that you can, like, the default passwords? [31:18.540 --> 31:19.860] The banter banter. [31:20.100 --> 31:22.540] Does anybody know what those flags are off the top of their head? [31:22.700 --> 31:28.240] To look for empty passwords, or password is the same as the login. [31:28.480 --> 31:30.000] How many people have actually done that? [31:30.560 --> 31:33.700] Not very, yeah, not very, people just assume that things are going to be tight. [31:33.940 --> 31:35.440] They're not familiar with it enough. [31:36.040 --> 31:37.260] Scapy is a huge problem. [31:37.420 --> 31:39.400] A lot of times it comes back to documentation. [31:41.280 --> 31:42.500] Documentation is not out there enough. [31:42.660 --> 31:49.240] And then, also, when you do a search on the Internet, you search for Netcat, and you see the same examples over and over again. [31:49.440 --> 31:56.020] Because everybody has all of a sudden discovered Netcat, and the three commands that are out there, and they blog it. [31:56.120 --> 31:57.960] And say, oh yeah, this is awesome, this is what you want to do. [31:58.100 --> 32:01.320] Like, you know, all of a sudden they're expanding the knowledge base when they're not really. [32:01.480 --> 32:06.720] So you're littered with, you know, 3,000 searches, and they're all the same commands. [32:07.020 --> 32:09.860] Unfortunately, the information isn't getting dispersed right. [32:11.320 --> 32:12.860] Okay, so books and websites. [32:13.620 --> 32:14.700] Sorry I keep rambling. [32:15.060 --> 32:15.880] Deficiencies in learning. [32:15.960 --> 32:16.580] Books and websites. [32:16.760 --> 32:18.200] There are typos in books. [32:18.400 --> 32:20.320] There are typos in blogs. [32:20.500 --> 32:22.660] There are typos in man pages. [32:23.640 --> 32:35.300] And a lot of times, even when you do get it right, it worked for the person who wrote it, but you don't actually have the same system as they do, and so you cannot replicate it. [32:35.300 --> 32:43.500] It bugs me to no end when I'm trying to learn reverse engineering, and they give these examples, and they say, hey, go get the file, and it doesn't match. [32:44.460 --> 32:45.180] Very frustrating. [32:46.620 --> 32:59.060] And as a professor, there's a couple things that I have to deal with all the time, and it's just part of the nature, in a way, of the profession is that it's repetitious. [32:59.380 --> 33:04.060] Every semester I've got a new batch of kids, and I've got to go through the same thing again. [33:04.940 --> 33:07.880] And it's also, I'm only one person, limited time. [33:08.300 --> 33:24.420] I work with a security club as well, and I was horrified when somebody mentioned, yeah, how, you know, it's like he mentioned that the president of the club mentioned that it would be great to have me around because when the new kids come in, I can teach them as well. [33:25.120 --> 33:33.500] I was like, okay, I was hoping to teach you guys so you could do that, but I realized that they graduate, so I will be doing this. [33:34.220 --> 33:36.820] Not fun, but, you know, it's a necessity. [33:37.040 --> 33:37.960] Well, maybe not. [33:39.820 --> 33:50.360] For those who were lucky enough to actually bring their laptops, I have what I'm about to talk about up on an access point right now. [33:50.360 --> 33:50.840] Now it's open. [33:51.800 --> 33:53.440] LiveCD is the name of the access point. [33:53.960 --> 34:08.720] If you navigate to 192.168.1.123, you will see a system up, and you can browse to the, you know, bring up a browser and navigate to that site, and you'll find out that there's a wiki up there. [34:09.260 --> 34:09.840] All right. [34:10.720 --> 34:20.720] So what I did after all those negatives, all those things that I was going to have to do, the repetition and all that other stuff, I decided... [34:21.340 --> 34:39.040] Oh, and also the fact that people aren't familiar with the tools that much, and also that nobody really has been trying to develop these live CDs, I decided that what needed to be done was I needed to provide a situation where not only do they actually learn how to do penetration tests, [34:39.220 --> 34:40.640] they also learn the tools. [34:41.780 --> 34:48.220] And so what I did is I also created a live CD that basically allows you to practice those tools. [34:49.220 --> 34:51.820] And the first one that I came out with is Netcat. [34:52.040 --> 34:54.200] I wrote... I mentioned that I was an author. [34:54.400 --> 34:57.840] I wrote a couple chapters in the Netcat book, and the one that I had... [34:57.840 --> 35:04.520] the chapter I had the most fun with was the dark side of Netcat, and all the nasty things you can do with Netcat. [35:04.520 --> 35:17.600] So I tried to incorporate some of those things into this disk, so you guys can actually do those evil things in a pen-test lab and not have to worry about repercussions. [35:18.280 --> 35:18.920] All right. [35:20.600 --> 35:21.280] Excuse me. [35:23.680 --> 35:26.120] So we have a wiki-based instruction on this disk. [35:26.680 --> 35:28.040] We have hackable servers. [35:28.120 --> 35:32.060] In fact, I opened up as many services as I could possibly get. [35:32.060 --> 35:33.100] It's huge. [35:33.400 --> 35:34.500] I mean, even Echo in there. [35:34.720 --> 35:37.220] And so, yeah, just everything. [35:39.220 --> 35:41.500] Because it's a hackable server, there's no need to rebuild it. [35:41.600 --> 35:44.600] You can just drop it in as a live CD and run with it. [35:45.560 --> 35:46.480] It's self-contained. [35:46.560 --> 35:48.840] You don't actually need backtrack. [35:49.140 --> 35:50.820] You remember the other previous one I had? [35:50.940 --> 35:57.620] You got your attack disk, and you got your router, and you got your... the disk that you're attacking, your target. [35:57.620 --> 35:59.340] You don't have to do that. [35:59.420 --> 36:03.860] I would not encourage you to just learn all of it straight from the live CD. [36:04.060 --> 36:11.240] I would actually encourage you to set up a lab, go through that pain, actually learn how to configure those things. [36:11.580 --> 36:14.780] If you guys are already familiar with doing that, change it up. [36:14.900 --> 36:16.620] Do you use OSPF or something like that? [36:16.740 --> 36:21.800] Just, you know, get... that lab is there more than just to learn a tool or something like that. [36:21.800 --> 36:27.080] But you can do everything that I'm going to talk about just using a live CD. [36:27.180 --> 36:27.820] How are we doing on time? [36:30.000 --> 36:30.960] Okay, I'm breezing through. [36:31.060 --> 36:31.120] Good. [36:34.050 --> 36:37.850] So, like I said, the first disk I wanted to do was Netcat. [36:39.710 --> 36:42.070] I actually included some basic skills. [36:42.090 --> 36:46.150] I mean, very simple stuff, client stuff, then some server stuff. [36:46.190 --> 36:48.410] I also did some intermediate stuff as well. [36:48.750 --> 36:50.170] I included examples. [36:50.170 --> 36:52.210] It's almost like you're reading a book. [36:52.510 --> 36:55.570] And then I included hands-on exercises as well. [36:55.950 --> 36:59.450] And I also threw in some RFCs to bore the living daylights out of you guys. [37:00.650 --> 37:03.970] So, let's talk about the hands-on exercises real quick. [37:04.570 --> 37:09.050] What I did is, you know, like I said, so there's typos out there. [37:09.230 --> 37:11.610] You can't replicate the system exactly. [37:12.530 --> 37:19.310] So, what I did is I actually did the exercises, copied and pasted, and threw them in the wiki. [37:19.310 --> 37:21.550] So, what you see is exactly what I did. [37:21.710 --> 37:24.130] It's not like I was telling you what you could do. [37:24.250 --> 37:29.130] So, there's... if it broke, I would know instantly that it was not the right way. [37:29.250 --> 37:31.330] So, I grabbed it and threw it on. [37:34.360 --> 37:38.580] Here's a snapshot of the front page, just part of the front page. [37:38.860 --> 37:41.980] Here's some of the lessons that I included in the disks. [37:42.740 --> 37:48.240] We have the basics and we have some basically risks to your networks, some man pages. [37:48.460 --> 37:50.520] Then we use the... using Netcat as a client. [37:50.640 --> 37:51.880] It walks you through doing that. [37:52.140 --> 37:52.620] Server. [37:53.460 --> 38:01.240] And then the one that most people don't get an opportunity to do is actually attacking actual services on a network. [38:01.400 --> 38:02.100] Like Echo. [38:02.200 --> 38:04.920] What does Echo look like when you use Netcat against it? [38:06.040 --> 38:06.800] Things like that. [38:07.740 --> 38:08.100] SMTP. [38:09.440 --> 38:11.280] Then I also threw in some tricks and traps. [38:11.520 --> 38:12.520] How to create a back door. [38:12.660 --> 38:16.420] You actually can create a back door on this live CD. [38:16.900 --> 38:18.740] Some of you guys have done it for real. [38:19.720 --> 38:21.420] There's also some other things that you can do. [38:21.540 --> 38:26.720] Like when you take the... when you go and you read some of these books and things like that and you find out how to use it as a pivot system. [38:26.720 --> 38:28.960] You can do those things on this disk. [38:29.800 --> 38:33.120] How to set up an SSH tunnel just using Netcat. [38:33.240 --> 38:34.780] You can do those things on this disk. [38:35.180 --> 38:40.440] Things that you may not have an opportunity to do or you would have to spend a lot of time setting up a server to do. [38:41.240 --> 38:43.520] You can also use Netcat as a chat client. [38:43.660 --> 38:45.480] I threw all these little examples in there. [38:46.100 --> 38:49.160] And as time goes on, I will continue to throw more in there. [38:49.600 --> 38:56.560] I'm gonna... I've already... we're already working on a Hydra one so you can actually learn all the neat little tricks and flags and stuff available in Hydra. [38:57.140 --> 38:58.460] Scampi is one I'd love to do. [38:58.620 --> 39:01.260] It's gonna be a pretty... pretty hefty thing to do though. [39:02.660 --> 39:09.740] But anyway, the idea was is that you guys would have a platform where you could, if you needed to, as a refresher, let's say. [39:10.120 --> 39:11.220] How do I do that? [39:11.620 --> 39:13.880] Throw into this disk, you can relearn it. [39:16.180 --> 39:18.720] Here's a snapshot of the actual hands-on example. [39:18.900 --> 39:20.040] This is one from the SMTP. [39:21.000 --> 39:24.400] I'm not gonna go through this because, first of all, it's on the disk. [39:24.400 --> 39:32.820] Second of all, you know, it's very small and I know that most of you guys' eyes are bleeding right now and just trying to stay awake anyway. [39:34.900 --> 39:37.620] Alright, so who's the intended audience for these disks? [39:38.200 --> 39:42.180] For the Netcat disks and for these tutorial disks, it's for everybody. [39:42.540 --> 39:52.020] Not only is it for beginners who need to learn the concept and actually go through some hands-on exercises, there's also some more advanced techniques for the intermediate user, things that you may not be familiar with. [39:53.020 --> 40:02.800] It also provides the intermediate user a sandbox in which to actually practice some of the techniques that they've learned about, including denial of service attack. [40:02.920 --> 40:13.400] One guy, I was in the computer lab, and this was kind of funny, I thoroughly enjoyed this, is that I was on a network that was all done through a hub. [40:13.400 --> 40:19.080] Well, if you know about hubs, the problem is that we're talking about some serious packet crashes. [40:19.300 --> 40:21.060] I mean, they ram into each other. [40:21.400 --> 40:25.400] So I had about ten people in the class, and I was going through this disk. [40:26.700 --> 40:31.420] And I was talking about how to connect to a service. [40:33.140 --> 40:37.540] And what one guy did, he says, well, let's figure out how much this thing can handle. [40:37.740 --> 40:47.420] So the next thing I know, he basically does a cat on the entire, on all the files on the server, on this backtrack disk. [40:48.340 --> 40:48.940] All of them. [40:49.120 --> 40:54.980] And pipes it into the server, into, through Netcat, onto the target system. [40:55.100 --> 40:57.060] The next thing I know, he's doing an denial of service attack. [40:57.060 --> 40:59.360] Everybody else cannot access the disk. [40:59.600 --> 41:00.560] Well, that was perfect. [41:00.740 --> 41:13.740] And the reason why it was perfect is because, since any other opportunity that he would have had to do this, would have either been on the computer at the college, which they would have frowned upon. [41:14.160 --> 41:18.440] Or he would have had to basically set up his lab at home. [41:18.600 --> 41:24.700] And what he basically provided is, for the entire class, a demonstration of how to do a denial of service, especially over hubs. [41:24.700 --> 41:31.420] I mean, everybody started learning about why a hub isn't necessarily a good thing when you've got ten people plugged into the same network. [41:31.700 --> 41:35.640] So, it was a learning experience and it was cool to see. [41:36.120 --> 41:42.400] Like I said, it's a sandbox for you to try unusual protocols and also to try things that you shouldn't do under normal circumstances. [41:43.500 --> 41:55.100] Also, it provides an opportunity for people to, like I mentioned before, those that have skills that are way beyond me, to take those and develop them into a platform where people can actually learn. [41:55.620 --> 42:04.340] Now, unlike the disks, the Pentest Live CDs disks that I talked about, where you're not supposed to know anything, this disk, you can have complete access. [42:04.480 --> 42:06.740] I even tell you the root login and everything. [42:06.880 --> 42:07.400] It's root and tor. [42:07.660 --> 42:08.220] Very simple. [42:08.880 --> 42:12.480] The reason why is because maybe you want to see what's happening in the server side. [42:13.020 --> 42:13.880] Things like that. [42:15.280 --> 42:15.860] All right. [42:16.160 --> 42:22.820] Before I get into questions or anything else like that, one thing I wanted to ask right now is, some people have probably already plugged into it. [42:25.020 --> 42:26.200] Is anybody... Okay. [42:26.360 --> 42:26.820] Quick hands. [42:26.980 --> 42:29.320] Who's actually logged onto the service? [42:30.000 --> 42:30.360] Okay. [42:30.660 --> 42:31.180] Two people. [42:31.520 --> 42:32.000] Okay. [42:32.940 --> 42:37.660] You guys mounted the hard drive yet? [42:37.960 --> 42:39.100] You guys start probing? [42:39.260 --> 42:39.540] Okay. [42:39.660 --> 42:40.200] I'm disappointed. [42:40.200 --> 42:45.040] I figured that by now is going to have to redo the entire system. [42:45.220 --> 42:45.960] That... I will anyway. [42:46.280 --> 42:49.720] But I figured that hopefully you guys would have had an opportunity to hack my box. [42:49.880 --> 42:51.200] There's a new user on there. [42:51.540 --> 42:52.420] There's a new user? [42:53.580 --> 42:55.240] Your sample may not be the same. [42:56.200 --> 42:56.820] That's fine. [42:57.240 --> 42:57.380] Okay. [43:00.660 --> 43:02.580] Here's some emails. [43:02.780 --> 43:03.580] You can contact me. [43:03.740 --> 43:06.520] I am available anytime, anytime. [43:06.920 --> 43:08.290] I don't sleep much, so... [43:09.390 --> 43:11.730] You guys send me an email at 2 o'clock in the morning. [43:12.030 --> 43:14.590] I'm just waking up, so I'm raring to go. [43:15.030 --> 43:17.950] Send me an email if you've got any questions about anything that I've talked about here. [43:18.510 --> 43:21.470] You can actually get, right now, the only people that can get this disc... [43:21.470 --> 43:26.570] I didn't even give it to the computer security group at the college. [43:26.570 --> 43:28.550] I let them test it, and then I walked away with the disc. [43:28.550 --> 43:30.490] You guys are the only ones that can get it right now. [43:30.770 --> 43:36.390] If you go to deice.hackerdemia.com, you can download the ISO. [43:36.770 --> 43:41.970] I'm going to leave it only for you guys until late Monday, and then I'm going to open it up to everybody else. [43:42.890 --> 43:49.290] And then also that will take you to the ability to download the pen-test live CDs as well. [43:50.090 --> 43:53.450] And then let me know what you think about these things. [43:53.650 --> 43:55.530] I'm constantly looking for ways to improve it. [43:55.710 --> 43:58.890] This is going to help me a lot with those kids at the security club. [43:58.930 --> 44:02.470] It's also going to help a lot with people who are advanced users as well. [44:02.830 --> 44:05.890] And more feedback and questions, please. [44:06.450 --> 44:08.270] What license are they any more license? [44:09.590 --> 44:10.910] The new license. [44:11.030 --> 44:13.330] Everything is under the GNU license. [44:14.190 --> 44:15.430] I've got everything copyright. [44:15.630 --> 44:19.930] Actually, the stuff, the wiki stuff is my copyright, but it's all copy left. [44:20.110 --> 44:22.030] Please use it as much as you want. [44:22.730 --> 44:29.090] I've had requests to use live CDs in colleges, you know, and they worry about licenses as well. [44:29.970 --> 44:31.250] By all means, use it. [44:31.390 --> 44:32.270] That's what it's there for. [44:32.930 --> 44:34.550] There's no restrictions on downloading. [44:35.150 --> 44:42.110] Originally, it was a... you could only log into the... you had to actually get a user account to get the live CDs. [44:42.290 --> 44:43.470] That was because of a bandwidth problem. [44:43.690 --> 44:47.730] I've actually gone to a hosted service, so use the pipe. [44:47.890 --> 44:48.210] It's there. [44:48.530 --> 44:50.170] Suck as much of it down. [44:50.610 --> 44:51.150] Downloads free. [44:51.370 --> 44:53.950] I don't have any restrictions on how you use it or anything like that. [44:54.130 --> 44:55.490] You can quote me as much as you want. [44:55.550 --> 44:57.190] You can plagiarize me as much as you want. [44:57.430 --> 44:59.610] You can pretend that you wrote it. [44:59.650 --> 45:00.250] I don't care. [45:00.390 --> 45:02.070] Just as long as that information gets out there. [45:02.070 --> 45:03.890] So, is that good? [45:04.250 --> 45:04.650] Okay. [45:04.770 --> 45:05.010] Yes, please. [45:14.610 --> 45:15.010] Okay. [45:15.310 --> 45:16.170] I'm going to have to apologize. [45:16.750 --> 45:20.890] When I was in the army, I was too close to too many generators and too many computers. [45:21.490 --> 45:22.810] There's a mic set up in the back. [45:22.930 --> 45:26.210] I have a really problem hearing sometimes, so I apologize. [45:26.210 --> 45:28.610] If we could use the mic, that would be really helpful for me. [45:30.310 --> 45:30.750] Hi. [45:31.490 --> 45:40.370] In your professional work, how much of fantastic work have you done on Linux and Linux boxes and how much of the windows? [45:41.810 --> 45:46.850] Most of the systems that we play with are actually Linux-based. [45:46.850 --> 45:50.850] There's been a huge effort to try to get away from cost. [45:51.530 --> 45:52.590] Yes, thank you for attending, everybody. [45:53.370 --> 45:57.770] There's been a huge problem as far as cost, so they're trying to find other platforms. [45:58.530 --> 46:07.090] I would say the predominant system that's out there is AS/400s in our organization, but we are not allowed to touch those because those are... I mean, it's an automatic... [46:07.090 --> 46:08.410] We touch it, it crashes. [46:08.410 --> 46:11.410] So we know that it's vulnerable from the get-go. [46:11.610 --> 46:20.850] But as far as Linux systems, I would say probably most of my effort originally was probably about 80% UNIX or Linux or Solaris-based. [46:21.110 --> 46:22.610] A lot of Solaris-based systems. [46:23.230 --> 46:26.370] It's not Linux, you know, branches off BSD. [46:26.530 --> 46:28.490] Anyway, but it's the same kind of flavor. [46:30.190 --> 46:34.830] Now, recently we've been doing a lot of huge shifts towards network stuff. [46:34.830 --> 46:40.050] But to answer your particular question, we do a lot of UNIX penetration testing. [46:40.170 --> 46:45.990] If you went on and watching 50 companies, they have more or a lot of Solaris-based systems. [46:46.190 --> 46:47.050] Yes, yes. [46:47.190 --> 46:50.950] But that's not to say that the trend's not shifting dramatically. [46:50.950 --> 46:53.290] It is shifting very dramatically. [46:53.290 --> 47:08.070] There was that whole period of time when people were so uncomfortable with Linux that they weren't willing to put their assets, basically their services, which generate them millions of dollars a month or a day on these boxes while they're doing that now. [47:08.770 --> 47:09.690] Okay, one last comment. [47:10.550 --> 47:19.510] On Windows, just like, you know, Linux Live Series or Linux Live Series, you can create a bar PD, basically. [47:19.610 --> 47:19.790] Yes. [47:19.890 --> 47:28.390] And you probably cannot give it out to people like you can give out the Linux Live Series because of licensing issues. [47:28.530 --> 47:28.670] Right. [47:28.670 --> 47:32.190] But you can probably save up on your box and a lot of people to... [47:32.190 --> 47:32.810] Yes. [47:33.570 --> 47:36.610] I've gone through the idea of the BART PE as well. [47:36.930 --> 47:44.790] One of the things that the problem with the BART PE is, for those that aren't familiar with it, is they've designed an operating system that looks and feels like Windows XP. [47:45.070 --> 47:48.170] The problem with it is that they had to generate the code themselves. [47:48.350 --> 47:52.830] So when you see an exploit for Windows, it doesn't mean that BART PE is exploitable. [47:52.830 --> 47:59.110] And so basically what they've done is they've done basically a reverse engineering, look at the man pages, see what it's supposed to do. [47:59.510 --> 48:07.470] Same kind of thing that Torvald did when he was dealing with Linux, is, you know, what is a service supposed to do and then generate it according like that. [48:07.750 --> 48:11.510] So BART PE is a good tool to use as far as learning Windows and stuff like that. [48:11.650 --> 48:16.570] As far as learning how to penetration test Windows, it might be a little questionable. [48:17.810 --> 48:18.610] Thank you. [48:19.370 --> 48:20.390] Any other questions, please? [48:22.090 --> 48:23.410] Okay, I will be available. [48:23.730 --> 48:26.710] I've got a plane at 4, so I've got a couple hours to kick around. [48:26.710 --> 48:29.910] And if you guys have any questions, please don't hesitate. [48:29.910 --> 48:32.310] I can talk about what I just covered here. [48:32.450 --> 48:35.810] I can talk about penetration testing in general. [48:35.810 --> 48:37.850] I can talk about some cool stuff. [48:37.910 --> 48:39.490] So I'd like to thank my... [48:40.250 --> 48:41.970] I'm going to throw out a real thank you real quick. [48:42.010 --> 48:44.290] I'd like to thank my wife for all the support she's given me. [48:44.590 --> 48:46.610] I'm embarrassing her dramatically here. [48:46.610 --> 48:49.070] And I also want to say hello to my little girl. [48:49.110 --> 48:49.830] She's eight years old. [48:50.030 --> 48:55.090] She's trying to introduce her into the hacker world as early as possible so she can get indoctrinated. [48:55.650 --> 48:56.830] So thank you very much.