Idle Speculation Eventually Stops Being Idle

Mods to VNC, Olivetti-nee-AT&T’s elegant system for remote desktops, have been around for years. UltraVNC is probably the best of them, with its device-driver level support on the Windows side. Or at least, it was before MetaVNC came along:

MetaVNC pursues a remote desktop environment that users can control applications on different hosts seamlessly. MetaVNC is a window aware VNC. MetaVNC merges windows of multiple remote desktops into a single desktop screen. MetaVNC also comes with its own task bar and application menu, which makes it easy to control applications or windows on different hosts (Java viewer only).

Furthermore, the Win32 version and linux version of MetaVNC viewer merges remote desktops with local desktops. It enables Linux and Windows remote desktops and local desktops to co-exist seamlessly!

If you use MS-Windows as a main desktop and connect remote Linux desktops through VNC, you must love it!

#define HOTHOTHOT METAVNC

Read the full entry »

Not-MD5 Imagery

Wow, I need a better CMS. Thinking of Drupal, though apparently Mambo is fairly cool as well. I’m open to suggestions, and I might be willing to throw Pizza/Tequila/Defcon passes out at someone who gets this monkey off my back. Actually, the big risk of having good content management is that you’ll find yourself coding less and whinging about other people’s code more. So somehow I’ll need to enforce some sort of ratio system…something like a minimum LoC/LoW ratio. Maybe I can even synthesize a graphical representation of said ratio…

Anyway, lots of people have been asking for pictures I’ve taken of them. So I’ll go ahead and push a few links out, thus satisfying my site admin who’s horrified that I haven’t been maintaining my Gooooooooooooooogle Rank…

Read the full entry »

MD5 Imagery

Just because we don’t have access to Wang’s attack on MD5 doesn’t mean we can’t seek out new and amusing ways to reverse engineer it…some interesting pictures, as Wang’s payloads propagate through an MD5 hash in a bit-visualized environment:

The last line is the bit-representation of the final MD5 hash. This is trivially inspired by Greg Rose et al’s musing on MD5 (very fine paper). Some others which have crossed my email:

Read the full entry »

MD5 To Be Considered Harmful Someday

I’ve been doing some analysis on MD5 collision announced by Wang et al. Short version: Yes, Virginia, there is no such thing as a safe hash collision — at least in a function that’s specified to be cryptographically secure. The full details may be acquired at the following link:

http://s3.amazonaws.com/dmk/md5_someday.pdf

A tool, Stripwire, has been assembled to demonstrate some of the attacks described in the paper. It may be acquired at the following address:

http://s3.amazonaws.com/dmk/stripwire-1.1.tar.gz

Incidentally, the expectations management is by no means accidental — the paper’s titled “MD5 To Be Considered Harmful Someday” for a reason. Some people have said there’s no applied implications to Joux and Wang’s research. They’re wrong; arbitrary payloads can be successfully integrated into a hash collision. But the attacks are not wildly practical, and in most cases exposure remains thankfully limited, for now. But the risks are real enough that responsible engineers should take note: This is not merely an academic threat, systems designed with MD5 now need to take far more care than they would if they were employing an unbroken hashing algorithm, and the problems are only going to get worse.

Some highlights from the paper:

Read the rest of this entry »

It's Alive

So Wired News has picked up on Marshall Bedoe’s genuinely interesting work on applying Bioinformatics to network protocol analysis. (I’m actually quoted in the article!) I saw Marshall talk at Toorcon, and it’s some fantastic work. As I told him — you actually found a protocol more complex than SMB, and it is us… 🙂 Seriously though, I’ve been talking about the “Medical Ghetto” for code for quite some time. Here’s a few packages I’ve been raving about that really nobody ends up using:

  • Large Graph Layout: Graphs — collections of interconnections — are actually alot of fun to play with. Graphviz is generally considered the standard tool for graph layout (in the sense that you just describe what links to what, and it puts everything together in some visually meaningful way) but it doesn’t scale past a few thousand links. What if you’ve got more to work with — say, a network the size of the Internet? Enter LGL, from some brilliant guys over at the University of Texas. Since protein interrelationships are extraordinarily complex, tools to visualize them are necessarily scalable. Of course, the tool is easily generic enough to visualize all sorts of non-biologically derived data…
  • PRAAT. Ostensibly a tool for analyzing human speech through a large number of algorithms, this absurdly portable, scriptable, and object oriented program is probably the most complete toolkit for deep audio analysis you can get — and it’s quite free. I was working on a project some time ago to swap melodies between two female vocalists, using the PSOLA manipulation interface. Certainly not what they had in mind at the Institute of Phonetic Sciences, but it worked pretty well.
  • Volsuite. People keep asking me what I used to create the scenes from the Angel project, my on-again-off-again attempt to do something neat and artistic. (Pretty pictures are cool, and as we saw with Phentropy, occasionally really useful at imparting useful information). Volsuite is a fast, full color, portable, open source volumetric renderer of three dimensional data, normally used for scientific and medical data but noticably applicable to so much more…

So that’s what I think is cool. Please mail me if you have any other thoughts 🙂 And yes, I miss Sweetcode…

Read the full entry »

Emergency C Infusion

Perl’s actually a surprisingly cool language — CPAN makes it astonishingly easy to not only acquire near-arbitrary functionality but, through more documentation than exists anywhere else in the Open Source community, actually *gasp* understand what you’re doing. Fun.

That being said, I’ll always be a C hacker…and thanks to my good friend and former build engineer, Jason Spence, I’ll have some new toys to play with once I return to the blissful land of raw packetdom (which are so much faster than even generic UDP sockets it’s not even funny). Check it out:

  • Next Generation Debug: Include this preprocessor include in your C code and get error messages that reference the file and codeline that spawned the error. It does depend on actually having non-brain-dead error handling, though.
  • Stack-Aware Memcpy: Use this version of memcpy and get array bounds checking (or at least, an inability for many buffer overflows to succeed). Vaguely reminiscent of Libsafe.

Cool stuff!

Read the full entry »

Help Wanted

The problem with packet slinging is that it’s just far too entertaining. Every time I sit down to hack on something, I have this list of genuinely amusing projects to spend cycles on. (Real world — its not that there aren’t plenty of “gruntwork” tasks that simply must be accomplished, just that it’s hard to use the hacker energy to execute them.)

Autoconf is not amusing. Neither is content management. At least to me. And, yikes, both are suffering over here at Doxpara.

So here’s the deal — Paketto needs someone to take over making the code build on modern systems. There’s some underlying code to patch; I’ll manage that, no problem. But this complex build tree I have now isn’t easily scaling to new distros, and that’s really limiting what are actually some genuinely useful tools. You an Autoconf junkie? Got some interesting stuff on Sourceforge? Want to flat out move Paketto into Sourceforge? Mail me.

Then there’s this place. Dave Weekly, my preternaturally insightful former roommate, assembled this particular XML and PHP based site design, and I’m much appreciative. But it’s 2004, and I need the ability to update things more flexibily and more often. I know enough about web work to know it’s far more difficult than it gets credit for, at least if you want something with a shred of technical class. There’s a huge amount of work I’ve done that isn’t showing up on these pages — my Slashdot and Metafilter stuff, the semi-secret but rather popular Apps Page (if Internet Explorer has to be insecure, we can at least make it useful), and even the Angel Project w/ Volsuite is nowhere to be found.

It’s getting kind of ridiculous 🙂 So, want to help contribute to my calvacade of amusing hacks, but aren’t yet up to par when it comes to the obscure advantages to (say) disabling the authoritative bit in an experimental DNS server? White Hacker Needs Web Help Badly! Mail me too.

Read the full entry »

Quick Summary: What's New?

OK, let me repeat.

Throwing arbitrary data in DNS — NOT a big deal.

Even doing network tunneling over DNS — ALSO not that big a deal; NSTX has been doing this for a while. (That being said — SSH over DNS adds strong cryptography and major cross platform compatibility that didn’t exist before.)

DNS radio is new. By segmenting audio into small chunks, we actually get universal caching of the streaming signal — a functionality we’ve never really had before. Generally, audio broadcast over the Internet falls apart after a few thousand users. Based on this ring-buffer-into-BIND architecture, combined with the utterly minimal bandwidth load of Speex, we should be able to host audio for a much greater number of listeners.

The entire suite of incoming attacks to firewalls are also new. DNS trusts the hierarchy to tell it the next hop to its target name; since I can acquire second level domains in the hierarchy for minimal cost, it’s trivial for me to insert arbitrary destinations along the DNS route path. In technical terms, whenever a recursing resolver comes to my name server to resolve a name, rather than providing an answer, I can redirect that request to another, supposedly authoritative server. That server can be at any address — even one I cannot IP route to — but if the resolver communicating with me can route to that address (say 10.0.1.11) my communication will reach that host. If there’s an SSH over DNS daemon running on 10.0.1.11, I’ve now achieved incoming connectivity to the network of my choice, completely bypassing firewalls and a trojan’s need to poll.

Recursion on dual hosted interfaces is not even necessary. There are large numbers of applications that, upon receiving untrusted traffic, execute DNS name lookups. Most commonly, they are reverse PTR lookups, but occasionally there are other types (MX from mail servers, most notably) that can be easily induced. When they are induced, the hierarchy is followed. When the hierarchy is followed, the attacks previously discussed start working. In practice, this means an IDS triggers the DNS server to start proxying traffic between an external attacker host and an internal trojaned machine. Nasty.

Read the rest of this entry »

Release!

It is done (well, for various definitions of the word “done”). Here, at the Black Hat Briefings, I’ve finally assembled and packaged my collection of DNS manipulation tools…and, as I’ve been known to do, rewrote much of of my slides (major changes — deep discussion of DNS Source Routing). Here’s the summary conclusions from the end of the talk:

1. DNS is globally deployed — you use it as a client, you probably depend on it as a server. 2. As the rest of IP networking has become progressively more and more filtered, DNS’s level of interconnectivity has (for important functionality reasons) remained constant, and in some ways outstrips the services offered by a completely unfirewalled host. 3. This connectivity can be used to offer a range of services, from encrypted VPN-style linkage, to a completely silent but remotely addressable trojan horse, to an unexpectedly useful distributed caching audio system. 4. DNS should not be disabled, re-engineered, blocked, or heavily interfered with at this time — but perhaps we can start paying closer attention to its traffic.

Without delay:

Read the full entry »

Small Update

Prepping for Black Hat and Defcon goes well … DNS radio is such an amusing hack 🙂 Speex is very impressive. A small public note — I’m looking for deployment experiences with Scanrand, as I shine it up and patch it for another Black Hat release. If there are any features you’ve added or needed, or if you’ve deployed Scanrand across some absurdly large network, let me know. I’ve written up my own experiences here, but would absolutely appreciate external input. Thanks!

Read the full entry »