W HY T HE P ARASITE ? Many organizations filter outgoing traffic - - PowerPoint PPT Presentation

w hy t he p arasite
SMART_READER_LITE
LIVE PREVIEW

W HY T HE P ARASITE ? Many organizations filter outgoing traffic - - PowerPoint PPT Presentation

Introducing T HE P ARASITE Coming Soon to a Network Near You! Tsagkarakis Nikos { ntsag at census-labs.com } Census, Inc. Athcon 2011, Athens I NTRODUCING THE P ARASITE :: A THCON 2011 :: C ENSUS , I NC . O VERVIEW I NTRODUCTION C ONSTRUCTION P


slide-1
SLIDE 1

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

Introducing

THE PARASITE

Coming Soon to a Network Near You!

Tsagkarakis Nikos

{ ntsag at census-labs.com }

Census, Inc. Athcon 2011, Athens

slide-2
SLIDE 2

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

OVERVIEW

INTRODUCTION CONSTRUCTION PLAYING WITH PARASITE FUTURE OF PARASITE CONCLUSIONS

slide-3
SLIDE 3

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

INTRODUCTION

slide-4
SLIDE 4

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

WHY THE PARASITE?

◮ Many organizations

◮ filter outgoing traffic ◮ host networks that are not connected to the internet

◮ Need for a simple way to gain and retain access in

the above situations

slide-5
SLIDE 5

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

WHY THE PARASITE?

◮ An attack vector of low profile and high risk ◮ “We have strong physical security” ◮ “We will arrest a person using the plug next to a

printer”

◮ “What if I construct a device, plug it into the target

infrastructure and then go home?”

slide-6
SLIDE 6

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

RELATED WORK

◮ NeoPwn ◮ Weaponizing N900 ◮ Plug Computers for penetration testing ◮ All of the above connect back through the target

infrastructure

◮ Ineffective when there is no connection to the Internet

slide-7
SLIDE 7

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

PROTOTYPE

slide-8
SLIDE 8

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

PROTOTYPE

◮ The idea is to produce a small device that can easilly

be hidden in the target infrastructure

◮ A device that can be built by anyone

slide-9
SLIDE 9

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

IT IS AN OLD STORY

◮ Bugs ◮ Microcameras ◮ Q’s gadgets

slide-10
SLIDE 10

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

WHAT ALLOWS FOR THE USE OF PARASITE?

◮ Really messy datacenters ◮ The huge amount of cabling in a building ◮ The administrators are usually too busy to notice (or

understaffed)

◮ Noone pays attention to small changes in the

inventory of a datacenter or infrastructure

slide-11
SLIDE 11

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

CONSTRUCTION

slide-12
SLIDE 12

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

CONCEPT

slide-13
SLIDE 13

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

CHALLENGE

Build a device that is

◮ Small ◮ of Low Energy Consumption ◮ Autonomous

slide-14
SLIDE 14

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

MATERIALS FOR PROTOTYPE

◮ N900 ◮ USB Ethernet Device ◮ Cables ◮ Batteries

slide-15
SLIDE 15

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

COST

◮ N900 - 400 euro ◮ USB Ethernet Device - 15-30 euro ◮ Cables - 5 euro ◮ Batteries - 20-10000 euro ◮ 3G Connection Cost - 1 euro/day

slide-16
SLIDE 16

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

NETWORK INTERFACES

◮ GSM Interface ◮ Ethernet ◮ Wifi

slide-17
SLIDE 17

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

CONNECT BACK

◮ OpenVPN ◮ SSH

slide-18
SLIDE 18

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

BATTERY

◮ Extra battery ◮ Power over ethernet

slide-19
SLIDE 19

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

POE

slide-20
SLIDE 20

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

POE

slide-21
SLIDE 21

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

TIME TO LIVE

◮ Simple Nokia battery 40 hours ◮ Enchanced Nokia Battery PoE 60-70 hours ◮ Enchanced Nokia Battery 80 hours

slide-22
SLIDE 22

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

SELF-DESTRUCT MECHANISM

◮ Magnesium ◮ Thermistors ◮ Electric Ignitor ◮ On memory card

slide-23
SLIDE 23

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

SELF-DESTRUCT MECHANISM

slide-24
SLIDE 24

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

PLAYING WITH PARASITE

slide-25
SLIDE 25

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

USES OF PARASITE

◮ Security Testing

◮ Penetration Testing ◮ Physical Security Testing

◮ Spying

slide-26
SLIDE 26

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

SOCIAL ENGINEERS

slide-27
SLIDE 27

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

SOCIAL ENGINEERS

slide-28
SLIDE 28

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

SOCIAL ENGINEERS

slide-29
SLIDE 29

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

MANY WAYS TO PLANT THE PARASITE

slide-30
SLIDE 30

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

MANY WAYS TO PLANT THE PARASITE

slide-31
SLIDE 31

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

MANY WAYS TO PLANT THE PARASITE

slide-32
SLIDE 32

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

SOME USES OF PARASITE

nmap

slide-33
SLIDE 33

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

SOME USES OF PARASITE

sniffing

slide-34
SLIDE 34

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

SOME USES OF PARASITE

metasploit

slide-35
SLIDE 35

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

FUTURE OF PARASITE

slide-36
SLIDE 36

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

MINI COMPUTERS

◮ Use of mini computers to build Parasites ◮ An independent build of such a device

slide-37
SLIDE 37

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

MINI COMPUTERS

slide-38
SLIDE 38

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

OPENBTS

◮ Use of OpenBTS for connecting back through an

alternate GSM network

slide-39
SLIDE 39

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

CONCLUSIONS

A small device that can be planted everywhere and work for some time

slide-40
SLIDE 40

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

CAN WE BE PROTECTED?

◮ Yes, but it requires a fair amount of effort! ◮ Employ physical security measures ◮ Monitor any changes in the inventory of an

infrastructure (however small)

◮ Monitor the security of internal networks even if they

are not connected to the Internet

slide-41
SLIDE 41

INTRODUCING THE PARASITE :: ATHCON 2011 :: CENSUS, INC.

QUESTIONS?