Just because it's not a good idea…

…doesn’t mean it’s not a good idea 🙂 So people are digging through the horror that is that PPT not meant to be published, and they’re asking…”So what’s actually new?” Hmm. Lesse.

Q: How are you doing large scale DNS data distribution? A: It’s really simple, actually. Individual DNS servers are pretty slow, but there’s quite a few of them out there — over 140,000 on one class A alone. So even if you can only get ~20k off a single server in a reasonable amount of time, when you’re talking to 35,000 servers, 1k/s per server suddenly gets alot more powerful.

Q: When can I get the code? A: OK, the public blogging was premature. Send me an email with “beta” to get on the early distro list.

Read the full entry »

What's Miname?

Hmmm. That’s interesting.

Soooo, that totally wasn’t supposed to happen — the code’s all coming out in a couple weeks, and it was going to be this really cool event with papers and implementations and all that. What do we have now? Freaking Powerpoint. Joy!

For those wondering what I’m working on, here’s my LayerOne slides on what’s sort of a new topic for me: DNS. (PDF version here!) Here’s the summary for Defcon (maybe Blackhat too, we’ll see?):

Continuing the research done in previous years on advanced protocol manipulation and the high speed evaluation of large network characteristics, this year’s Black Ops of TCP/IP goes into new territory with a deep analysis of the Domain Name System. A core element of the TCP/IP application suite, it is everywhere — and there is unexpected power contained within.

* Interesting Facets of the Global DNS Architecture: A high speed scanner for DNS servers, modeled after my TCP scanner “scanrand”, recently executed several Internet-scale sweeps of the net. Surprising results, with direct implications for computer forensics operations, will be discussed and analyzed.

* Distributed, High Speed, Large File Dissemination via DNS, A.K.A. “Reinventing the Square Wheel.” Although there have been previous attempts to serve files over the DNS architecture, none have been even remotely usable. I will discuss a new approach that, through its significant performance improvement, is indeed remotely usable.

* One-To-Many Streaming Data Dissemination over DNS: The previous system maximizes speed at the expense of making streaming impossible. We will discuss an interesting alternate approach that almost usefully distributes streaming audio data to endpoints via their DNS queries.

* SSH over DNS: I will demonstrate a cross-platform, userspace mechanism for moving SSH data over DNS queries. This has implications for captive wireless portals, which often allow bidirectional DNS traffic.

To complete this work, some enormously complex data needed to be understood, and tools were worked with and written towards that end. Experimental 3D information visualization mechanisms and tools are thus available to be demonstrated, extending from using a 3D renderer usually used for MRI medical data as a generic static 3D canvas to using a custom OpenGL particle plotter to dynamically plot multidimensional factors of incoming data streams. A number of other topics will be raised as well, including:

* Uses and abuses of remotely visible incrementers and decrementers (such as the IPID field in many TCP/IP stacks, and initial TTL values on arbitrary DNS queries)

* Uses of generic packet race conditions, whereby useful information can be gleaned from which packet of a relatively large set effects the state change

* Protocol transliteration between TCP and UDP, allowing unreliable communication over what appears to be a TCP session, and allowing reliable data to be transmitted, with zero data expansion, over a UDP link.

* Potential solutions to the SSH bastion host security problem, whereby the invocation of remote ssh binaries at a firewall or “bastion host” opens up a single point of major failure for a server infrastructure.

OK, maybe I’m working on one or two things besides DNS. But, to be clear: DNS games aren’t anything new, I’m just throwing my hat into the ring regarding more advanced iterations (faster, larger scale) of what’s essentially vulnerabilities in the core design of a central Internet protocol.

More later.

Read the full entry »

Where's Dan?

Not dead, not unemployed. Just been in stealth mode for a little while. The big news is — I’m working for Avaya now, and have been for a couple months. Yeah. Like I wasn’t travelling enough, I had to go and join a massive company with a consulting practice that spans the country 🙂 Not that I’m complaining. These guys are looking at security in ways I had only imagined…convergence is alot bigger than I had thought.

That being said…yes, Paketto lives on, and come Black Hat 2003, a major new release will hit the streets. I’ll hold onto the details a little longer, but here’s the abstract from Stack Black Ops (my BH talk):

What can your network do? You might be surprised. Layer by layer, this talk will examine previously undocumented and unrealized potential within modern data networks. We will discuss aspects of the newest versions of scanrand, a very high speed port scanner, and the rest of the Paketto Keiretsu. Interesting new techniques will also discussed, including:

  • Bandwidth Brokering – a technique that allows market-based load balancing across administrative boundries using existing TCP protocols
  • DHCP-less Bootstrapping – a sub-optimal but effective strategy for bootstrapping network access for hosts that cannot directly acquire a DHCP lease
  • State Reconstruction – a design model that allows stateless network scanners (such as scanrand) to acquire deep knowledge about scanned hosts
  • Multihomed Node Detection – a simple set of techniques that expose firewalled hosts with alternate paths to an unfirewalled network link.
  • Generic ActiveX Encapsulation – a step-by-step methodology for safely launching arbitrary win32 tools (such as putty or a Cygwin OpenSSH environment) from a web page

We will also be discussing significant advances in data visualization, made necessary by the sometimes daunting amount of raw information these sorts of tools can expose one to.

Between you and me…this is going to be a wild talk 🙂 And yes, that’s a new book. Maybe now I can forget Swordfish.

Read the full entry »

ZapMail Redux: A Response

It’s funny. For quite some time, people have been saying 1984 has come upon us.

It took Clay Shirky — whose reputation is astonishingly well deserved — to prove people were right. 1984 is upon us — for in the year 1984, ZapMail, by FedEx, was brought unto the world. The basic idea was that you’d FedEx your document, only they wouldn’t actually send it — they’d buy a fax machine, and fax it for you. Delivery time would go from 24 hours to 2. Profit!

FedEx lost hundreds of millions of dollars before realizing businesses were just buying their own fax machines and abandoning the per-use charge(not to mention the rather tremendous inefficiencies of having somebody physically transport a document so that it may eventually be electronically transported!)

It is 2003. Instead of fax, we have WiFi. The stakes are larger.

But little has changed.

I hope, perhaps expect — I rather lack the right to demand — that Clay Shirky’s recent article “Customer-Owned Networks and ZapMail” be distributed at business schools across the world, if only for its sheer grasp of historical perspective. Clay gets it.

Read the rest of this entry »

Paketto Keiretsu 1.10 Released!

A little present for the little hacker in all of us 🙂 New in this release:

  • OpenBSD Support
  • Solaris (and Big-Endian) Support
  • “Distco” mode to Scanrand, for quickly discovering the distance to an arbitrary host. Fast RSTs don’t reset the TTL, so RST TTL / 2 = average distance. We use a barren segment of the TTL range to detect and evaluate TTL reflection.
  • Many, many bug fixes
  • Merry Christmas! Happy Holidays!

Paketto now has a permanent page on doxpara.com; further information is posted there. Or, if you’d rather just grab the code immediately, go right ahead!

Now if you’ll excuse me, I’ll be spending the next couple of days with my family; we’re heading out to Reno where there are much more interesting things to do than check one’s email 🙂 But I’ll post stories — and photos of Ireland — when I get back.

Read the full entry »

RFID Security

I put some research into a post some time ago; recently decided to archive the work for future reference. Regarding RFID:

RFID stands for Radio Frequency Identification, and is essentially a Tesla-esque hack to allow contactless, bidirectional storage of small amounts of data on trivial circuits powered by the reader infrastructure itself. It’s most commonly deployed nowadays as a replacement for magnetic-swipe oriented systems, as the lack of an exposed data surface and the absence of contact during scanning make RFID astonishingly reliable. The functionality is quite compelling, as Gilette’s mass purchase shows — what if you never needed to do inventory? What if you could just have a few sensors throughout your warehouse do a “mass ping” and acquire from the mass of replies precisely what needs to be restocked?

What if indeed. The rest is available here.

Read the full entry »

Paketto Simplified (1.0)

SCANRAND ========

Really, really fast port scanner, that can also trace network paths. Port scanning is simply the act of asking a machine if you can start up a conversation with a certain port of its, and marking down “yes” or “no” depending on the response. Normally, there’s lots of overhead as you keep track of who you sent requests to and thus who you’re expected responses from. Overhead, or “state”, makes things slow. So scanrand is stateless — right when you start up, it splits in two. One half asks everyone, “Heh! What are you hosting!” The other half picks up responses, “Hmmm, some guy just said he has a web server.”

Now, there’s a problem: If someone knows I’m not keeping track of who I’m scanning, they can just throw fake responses back at me. But TCP lets me embed a little signature with every connection request — the “Sequence Number”. This number will be returned to me when I get a valid response from a host that I scanned. So I take the IP and the port of the machine I scan, encrypt it into the sequence, and send off the request. When I get the response back, I look at the ACKnowledgement, compare it to the IP and port of the machine that’s talking to me, and immediately know whether I ever scanned this guy in the first place.

So, that’s why I get to scan really fast. Mind you, it’s the least impressive part of Paketto in raw technical terms — but it’s definitely useful as hell.

MINEWT

======

Read the rest of this entry »