introduction to mirai
play

Introduction to Mirai Luis Espinoza lespinoz@akamai.com Hardcoded - PowerPoint PPT Presentation

Introduction to Mirai Luis Espinoza lespinoz@akamai.com Hardcoded list of user/pass used by Mirai https://krebsonsecurity.com/wp-content/uploads/2016/10/IoTbadpass-Sheet1.pdf loader/src/headers/includes.h loader/src/headers/binary.h


  1. Introduction to Mirai Luis Espinoza lespinoz@akamai.com

  2. Hardcoded list of user/pass used by Mirai https://krebsonsecurity.com/wp-content/uploads/2016/10/IoTbadpass-Sheet1.pdf

  3. loader/src/headers/includes.h

  4. loader/src/headers/binary.h

  5. mirai/bot/ Bot in device

  6. dlr

  7. resolv.c

  8. main.c

  9. scanner.c Static user/pass

  10. scanner.c IP exceptions

  11. mirai/cnc/ Command-&-Control

  12. admin.go

  13. attack.go • Attack Name: “udp”, “vse”, “dns”, “syn”, “ack”, “stomp”, “greip”, “greeth”, “udpplain”, “http” • Attack targets: “Comma delimited list of target prefixes Ex: 192.168.0.1 Ex: 10.0.0.0/8 Ex: 8.8.8.8,127.0.0.0/29” • Attack Duration: “Duration must be between 0 and 3600 seconds” • Flags: “len”, “rand”, “tos”, “ident”, “sport”, “dport”, “domain” …

  14. main.go

  15. mirai/tools/scanListen.go Bot scan report

  16. Problem of volume • The “Internet of Things” is exploding. It is made up of billions of “smart” devices—from miniscule chips to mammoth machines—that use wireless technology to talk to each other (and to us). Our IoT world is growing at a breathtaking pace, from 2 billion objects in 2006 to a projected 200 billion by 2020 . 1 That will be around 26 smart objects for every human being on Earth! 1 IDC, Intel, United Nations. • * http://www.intel.com/content/www/us/en/internet-of-things/infographics/guide-to-iot.html

  17. Comments? Thank you!

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend