Difference between revisions of "Summerschool Aachen 2004/Building Attacks Lab"

From C4 Wiki
Jump to: navigation, search
m (Removed protection from "Summerschool Aachen 2004/Building Attacks Lab")
 
(36 intermediate revisions by 24 users not shown)
Line 1: Line 1:
= Notes on Presentations =
+
= Notes on Lab Session =
== Network Basics ==
 
  
The slides can be found [http://www.mmweg.rwth-aachen.de/~thorsten.holz/network-basics.pdf here]
+
== Google and special characters ==
  
The second lecture today will cover the basics of network programming. Here are a few links that could help you during the lab session:
+
The star * and the full stop . do not work as wildcards.
  
* [http://www.evolt.org/article/Socket_Programming_in_Perl/17/60108/ Socket Programming in Perl]
+
--[[Alexander Becher]]
* [http://www.evolt.org/article/Socket_Programming_in_Python/17/60276/ Socket Programming in Python]
 
* [http://www.fortunecity.com/skyscraper/arpanet/6/cc.htm A Crash Course in UNIX TCP/IP Socket Programming in C]
 
* [http://www.uwo.ca/its/doc/courses/notes/socket/ An Introduction to Socket Programming in C]
 
* [http://www.packetfactory.net/libnet/docs/ Libnet Packet Construction Library Developer Documentation for libnet 1.1.x], [http://www.security-labs.org/index.php3?page=libnetng Doku from Fred]
 
* [http://www.cet.nau.edu/~mc8/Socket/Contents.html Socket Tutorial in C]
 
* [http://www.unpbook.com/ UNIX Network Programming with many examples]
 
* [http://www.ecst.csuchico.edu/~beej/guide/net/ Beej's Guide to Network Programming]
 
* [http://www.developerweb.net/forum/ Unix Socket FAQ]
 
 
 
* [http://twistedmatrix.com/  Twisted, an event-driven networking framework written in Python], [http://www.zoteca.com/information/wp/twistedusenix.pdf pdf-file]
 
* [http://poe.perl.org POE - Perl Object Enviroment, really simple Servers]
 
* [http://lib.ru/PERL/perlprac/perl15.html Simple webserver in perl]
 
* [http://pylibpcap.sourceforge.net/ python module for libpcap]
 
* [http://www.tcpdump.org/pcap.htm Programming with pcap in C]
 
* [http://www.cet.nau.edu/~mc8/Socket/Tutorials/section1.html Packet Capture With libpcap and other Low Level Network Tricks]
 
* [http://aspn.activestate.com/ASPN/CodeDoc/Net-RawIP/RawIP/libpcap.html Documentation to Net::RawIP]
 
* [http://www.goto.info.waseda.ac.jp/~fukusima/ruby/pcap-e.html Ruby/Pcap extension library]
 
* [http://libnet.sourceforge.net/libnet.html Libnet documentation]
 
* [http://www.rfc-editor.org/rfcsearch.html Search for RFCs]
 
  
 
== Linux clock timings ==
 
== Linux clock timings ==
Line 38: Line 18:
  
 
-- [[Steven Murdoch]]
 
-- [[Steven Murdoch]]
 +
 +
A comment from the NetBSD 1.6.2 Kernel, file src/sys/kern/kern_microtime.c:
 +
/*
 +
  * Ordinarily, the current clock time is guaranteed to be later
 +
  * by at least one microsecond than the last time the clock was
 +
  * read.  However, this rule applies only if the current time is
 +
  * within one second of the last time.  Otherwise, the clock wil
 +
  * (shudder) be set backward.  The clock adjustment daemon or
 +
  * human equivalent is presumed to be correctly implemented and
 +
  * to set the clock backward only upon unavoidable crisis.
 +
  */
 +
 +
  
 
== A mathematical theory of communication ==
 
== A mathematical theory of communication ==
Line 49: Line 42:
  
 
[http://home.student.utwente.nl/g.v.berg/btk/ a python lib that allows you to make raw sockets.]
 
[http://home.student.utwente.nl/g.v.berg/btk/ a python lib that allows you to make raw sockets.]
 
= Notes on Lab Session =
 
  
 
== Google Search String Competition ==
 
== Google Search String Competition ==
Line 57: Line 48:
  
 
* [http://www.google.de/search?hl=en&ie=UTF-8&as_qdr=all&q=inurl%3A%22robots.txt%22+Disallow+secret&btnG=Search inurl:"robots.txt" Disallow secret]
 
* [http://www.google.de/search?hl=en&ie=UTF-8&as_qdr=all&q=inurl%3A%22robots.txt%22+Disallow+secret&btnG=Search inurl:"robots.txt" Disallow secret]
 +
* [http://www.google.com/search?q=inurl:%22robots.txt%22+Disallow+(secret%7Cadmin%7Cstat%7Cstats%7Cconfig%7Cconf%7Cinc%7Cinclude%7Cintern%7Cinterneal)&ie=UTF-8&oe=UTF-8 inurl:"robots.txt" Disallow (secret|admin|stat|stats|config|conf|inc|include|intern|interneal)]
 
* [http://www.google.de/search?hl=en&ie=UTF-8&q=%22phpScheduleIt+v1.0.0+RC1%22&btnG=Google+Search "phpScheduleIt v1.0.0 RC1"] - Get a free homepage (see bug report [http://www.securityfocus.com/bid/11080 Bugtraq 11080])
 
* [http://www.google.de/search?hl=en&ie=UTF-8&q=%22phpScheduleIt+v1.0.0+RC1%22&btnG=Google+Search "phpScheduleIt v1.0.0 RC1"] - Get a free homepage (see bug report [http://www.securityfocus.com/bid/11080 Bugtraq 11080])
  
Line 96: Line 88:
 
    
 
    
 
     } else if ((*svc)->probe_state == PROBESTATE_FINISHED_SOFTMATCHED) {
 
     } else if ((*svc)->probe_state == PROBESTATE_FINISHED_SOFTMATCHED) {
       (*svc)->port->setServiceProbeResults((*svc)->probe_state,  
+
       (*svc)->port->setServiceProbeResults((*svc)->probe_state,
 
 
  
 +
--[[User:Mario Manno|MM]] 17:12, 5 Oct 2004 (CEST)
  
 
== Making a fingerprinter ==  
 
== Making a fingerprinter ==  
Line 104: Line 96:
 
Yesterday I decided to make a (ring) fingerprinting tool in the labsession. the full description of this fingerprinting method is described in: [http://www.intranode.com/fr/doc/ring-full-paper.pdf http://www.intranode.com/fr/doc/ring-full-paper.pdf] It took a bit more work then I had planned (I'd also planned to play a little with the metasploit framework, but there was no time left) but eventually I got a perlscript which looks ok and which the perl interpreter seems to like.  
 
Yesterday I decided to make a (ring) fingerprinting tool in the labsession. the full description of this fingerprinting method is described in: [http://www.intranode.com/fr/doc/ring-full-paper.pdf http://www.intranode.com/fr/doc/ring-full-paper.pdf] It took a bit more work then I had planned (I'd also planned to play a little with the metasploit framework, but there was no time left) but eventually I got a perlscript which looks ok and which the perl interpreter seems to like.  
 
I haven't tested it yet (when the code was finished it was already around 8 or so), but I'll try to test it today or tomorrow.  
 
I haven't tested it yet (when the code was finished it was already around 8 or so), but I'll try to test it today or tomorrow.  
 +
 +
-- Ilja van Sprundel
  
 
== Tunnelling IP over DNS ==
 
== Tunnelling IP over DNS ==
Line 111: Line 105:
 
-- [[Stephen Lewis]]
 
-- [[Stephen Lewis]]
  
 +
== Tunneling information through ICMP ==
 +
 +
I've written a small perl script, which uses Net::RawIP to open a pcap listener and looks for ICMP packets with a special combination of type and code. If it sees such a packet, it interprets the payload as a command. Currently, it is possible to send it a "get file" command, which the scripts responds to by splitting the file into 32 bit chunks, sending them back to the requestor. The chunks are being encoded in the ID and sequence fields in the ICMP header.
 +
I have not implemented some kind of flow control yet. This should be done for real world use...
 +
 +
--[[User:Cpunkt|Cpunkt]] 09:58, 27 Sep 2004 (CEST)
  
 
[[Category:Summerschools]]
 
[[Category:Summerschools]]
[[Category:Events]]
 
 
[[Category:Hacks]]
 
[[Category:Hacks]]

Latest revision as of 22:23, 24 September 2018

Notes on Lab Session

Google and special characters

The star * and the full stop . do not work as wildcards.

--Alexander Becher

Linux clock timings

These show some measurements I have take on the Linux 2.4 kernel clock using gettimeofday(). This returns results with microsecond precision, so I wanted to make sure that this precision was significant. These graphs show that both the millisecond and microsecond parts give fairly uniform results.

Milliseconds
http://www.cl.cam.ac.uk/users/sjm217/volatile/timing_msec.png

Microseconds
http://www.cl.cam.ac.uk/users/sjm217/volatile/timing_usec.png

-- Steven Murdoch

A comment from the NetBSD 1.6.2 Kernel, file src/sys/kern/kern_microtime.c:

/*
 * Ordinarily, the current clock time is guaranteed to be later
 * by at least one microsecond than the last time the clock was
 * read.  However, this rule applies only if the current time is
 * within one second of the last time.  Otherwise, the clock wil
 * (shudder) be set backward.  The clock adjustment daemon or
 * human equivalent is presumed to be correctly implemented and
 * to set the clock backward only upon unavoidable crisis.
 */


A mathematical theory of communication

I've uploaded this famous paper by C.E. Shannon to http://berlin.ccc.de/~cc/shannon-a_mathematical_theory_of_communication.pdf.
You may download it, if you're interested.

--Cpunkt 12:21, 23 Sep 2004 (CEST)

Billy the kid

a python lib that allows you to make raw sockets.

Google Search String Competition

Insert here your Favorite (novel) search strings:

nmap - always print fingerprint bad bad idea

diff -Nau nmap-3.70/output.cc nmap-3.70.mm/output.cc
--- nmap-3.70/output.cc	2004-08-29 11:12:03.000000000 +0200
+++ nmap-3.70.mm/output.cc	2004-09-23 19:14:13.000000000 +0200
@@ -353,7 +353,8 @@
	snprintf(portinfo, sizeof(portinfo), "%d/%s", current->portno, protocol);
	state = statenum2str(current->state);
	current->getServiceDeductions(&sd);
-	if (sd.service_fp && saved_servicefps.size() <= 8)
+    // always print the fingerprint
+	if (sd.service_fp)
	  saved_servicefps.push_back(sd.service_fp);

	if (o.rpcscan) {
diff -Nau nmap-3.70/service_scan.cc nmap-3.70.mm/service_scan.cc
--- nmap-3.70/service_scan.cc	2004-08-29 11:12:03.000000000 +0200
+++ nmap-3.70.mm/service_scan.cc	2004-09-23 19:20:57.000000000 +0200
@@ -1825,6 +1825,9 @@
 
     if (MD && MD->serviceName) {
       // WOO HOO!!!!!!  MATCHED!  But might be soft
+      // mm: print a fingerprint everytime
+        svc->addToServiceFingerprint(MD->serviceName, readstr, readstrlen);
+
       if (MD->isSoft && svc->probe_matched) {
 	if (strcmp(svc->probe_matched, MD->serviceName) != 0)
 	  error("WARNING:  service %s:%hi had allready soft-matched %s, but now soft-matched %s; ignoring second value\n", svc->target->NameIP(), svc->portno, svc->probe_matched, MD->serviceName);
@@ -1967,7 +1970,8 @@
 					  *(*svc)->product_matched? (*svc)->product_matched : NULL, 
 					  *(*svc)->version_matched? (*svc)->version_matched : NULL, 
 					  *(*svc)->extrainfo_matched? (*svc)->extrainfo_matched : NULL, 
-					  NULL);
+                      (*svc)->getServiceFingerprint(NULL));
+					  //NULL); // always pass the fingerprint
 
    } else if ((*svc)->probe_state == PROBESTATE_FINISHED_SOFTMATCHED) {
     (*svc)->port->setServiceProbeResults((*svc)->probe_state,

--MM 17:12, 5 Oct 2004 (CEST)

Making a fingerprinter

Yesterday I decided to make a (ring) fingerprinting tool in the labsession. the full description of this fingerprinting method is described in: http://www.intranode.com/fr/doc/ring-full-paper.pdf It took a bit more work then I had planned (I'd also planned to play a little with the metasploit framework, but there was no time left) but eventually I got a perlscript which looks ok and which the perl interpreter seems to like. I haven't tested it yet (when the code was finished it was already around 8 or so), but I'll try to test it today or tomorrow.

-- Ilja van Sprundel

Tunnelling IP over DNS

Although there are already tools available to do this (cf. [NSTX ] and [DeNiSe]), I decided it would be an interesting project to try during the afteroon. Working on OpenBSD, I started to write the client part of the code using libnet and libpcap (taking 'inspiration' from various places, including nos-tun). It took quite a while to work out simple things like the correct ioctls for the tun interface, but I've made enough progress that I think it might be nice to continue with this on the project day. I'll try to add some code to this entry once there's enough to be worth looking at!

-- Stephen Lewis

Tunneling information through ICMP

I've written a small perl script, which uses Net::RawIP to open a pcap listener and looks for ICMP packets with a special combination of type and code. If it sees such a packet, it interprets the payload as a command. Currently, it is possible to send it a "get file" command, which the scripts responds to by splitting the file into 32 bit chunks, sending them back to the requestor. The chunks are being encoded in the ID and sequence fields in the ICMP header. I have not implemented some kind of flow control yet. This should be done for real world use...

--Cpunkt 09:58, 27 Sep 2004 (CEST)