




版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
Setiri:AdvancesinTrojanTechnologyRoelofTemminghHaroonMeerBlackHatUSA2002Setiri:AdvancesinTrojanTec1
ScheduleIntroductionWhyTrojans?BriefHistoryofTrojans&CovertChannelsTheHybridmodelSetiri:AdvancesinTrojanTechnologyDemonstrationTakingitfurtherPossiblefixesScheduleIntroduction2
IntroductionSensePostThespeakersObjectiveofpresentationIntroduction3
WhyTrojans?ProfileofTrojanusersRealcriminals……don’twritebufferoverflowsTheweirdnessoftheindustryExamplesWhyTrojans?4BriefHistoryofTrojans&CovertTunnelsTrojansFromQuickThinkingGreeks…toQuickThinkingGeeksTunnelsCovertChannelsBriefHistoryofTrojans&Cov5Trojans..
ValidIP–NoFiltersValidIP–StatelessFiltersPrivateAddresses–StatefulFiltersPrivate+Stateful+IDS+PersonalFirewalls+ContentChecking+…Trojans..ValidIP–NoFilter6
Trojans..
(ValidIP–NoFilters)“getreal..”Trojans..
(ValidIP–NoFi7
Trojans..
(ValidIP–StatelessFilter)
DialHomeTrojansRandomPorts/OpenPorts/HighPorts[cDc]ACKTunneling[ArneVidstrom]Trojans..
(ValidIP–State8
Trojans..
(StatefulFilters)BackOrifice-
GbotRattlerTrojans..
(StatefulFilters9
BriefHistoryofTrojans&CovertTunnelsTrojansFromQuickThinkingGreeks…toQuickThinkingGeeksTunnelsCovertChannelsBriefHistoryofTrojans&10
Tunnels&CovertChannelsTunnels&CovertChannels11
ConventionalTrojans&howtheyfailStatefulfirewall&IDSDirectmodelDirectmodelwithnetworktricksICMPtunnelingACKtunnelingProperlyconfiguredstatefulfirewallIRCagents+AuthenticationproxyHTTPtunnel++Personalfirewall&AdvancedProxyHTTPtunnelwithAuthentication+++ConventionalTrojans&how12
Hybridmodel:“GatSlag”CombinationbetweencovertTunnelandTrojanDefensesmechanismstoday:Packetfilters(stateful)/NATAuthenticationProxiesIntrusiondetectionsystemsPersonalfirewallsContent/protocolcheckingBiometrics/TokenPads/OnetimepasswordsEncryptionHybridmodel:“GatSlag”13AtypicalnetworkAtypicalnetwork14HowGatSlagworkedReverseconnectionHTTPcoverttunnelMicrosoftInternetExplorerastransportControlsIEviaOLEEncapsulateinIE,notHTTPReceivecommandsintitleofwebpageReceiveencodeddataasplaintextinbodyofwebpageSenddatawithPOSTrequestSendalivesignalswithGETrequestHowGatSlagworked15
WhyGatSlagworkedIntegrationofclientwithMSProxyNTLMauthenticationSSLcapableRegistrychangesPersonalfirewallsJustanotherbrowserPlatformindependentIEoneverydesktopSpecifyControllerViapublicwebpage–theMASTERsiteWhyGatSlagworkedIntegratio16
HowGatSlagworkedIICreatesinvisiblebrowserFindcontrolleratMASTERSendrequesttoControllerIfnoController&&retry>7,gotoMASTERReceivereplyParsereply:+Uploadfile()+Downloadfile+ExecutecommandLoopHowGatSlagworkedII17
WhydefensesfailFirewalls(stateful/NAT)ConfiguredtoallowuserorproxyoutContentlevel&IDSLookslikevalidHTTPrequests&repliesFilesdownloadedastextinwebpagesNodataorportstolockontoSSLprovidesencryptionPersonalfirewallsIEvalidapplicationConfiguredtoallowbrowsingAuthenticationproxiesUsersurfthewebWhydefensesfail18
ProblemswithGatslagTheController’sIPcanbeobtained!HandlingofmultipleinstancesGUIsupportControllerneededtobeonlineBatchcommandsCommandhistoryMultiplecontrollersUploadfacilitynotefficientPlatformsupportStabilitySessionleveltunnelingProblemswithGatslag19
Setiri:AdvancesinTrojanTechnologyDesignnotes:WebsitecontainsinstructionsCGIstocreatenewinstructionController’sinterface:EXEC(DOScommands)TX(Fileupload)RX(Filedownload)Directorystructure–eachinstanceTrojan“surfs”towebsite–justanormaluserwouldSetiri:AdvancesinTrojanTe20
Setiri:AdvancesinTrojanTechnologyIIAnonymityProblemswithnormalproxiesAlreadyusingaproxyProxylogs“Cleaners”provideanonymity“Inbrowserproxy”–AnonymizerTrojan->Cleaner:SSLCleaner->Controller:SSLChallenges:BrowserhistoryTemporaryfilesSetiri:AdvancesinTrojanTe21
22
23
24
DemonstrationDemonstration25
TakingitfurtherSessionleveltunnelingTakingitfurther26FlowcontrolchallengesHowthisisdifferentfromHTTPtunnelingAbrowserisnotasocketNoselectonbrowserTrainmodelTheControllersideCannot“send”BufferingofdataatControllerTheTrojansideMulti-partPOSTsMultipleconnections(HTTP)TruenetworkleveltunnelingFlowcontrolchallenges27
SolvingthedilemmaDeliveryWhitelistingUsereducationAV,personalfirewallsShouldyoualloweveryonetosurfthe‘net?Solvingthedilemma28
ConclusionAwarenessOurmotivationConclusion29演讲完毕,谢谢观看!演讲完毕,谢谢观看!30Setiri:AdvancesinTrojanTechnologyRoelofTemminghHaroonMeerBlackHatUSA2002Setiri:AdvancesinTrojanTec31
ScheduleIntroductionWhyTrojans?BriefHistoryofTrojans&CovertChannelsTheHybridmodelSetiri:AdvancesinTrojanTechnologyDemonstrationTakingitfurtherPossiblefixesScheduleIntroduction32
IntroductionSensePostThespeakersObjectiveofpresentationIntroduction33
WhyTrojans?ProfileofTrojanusersRealcriminals……don’twritebufferoverflowsTheweirdnessoftheindustryExamplesWhyTrojans?34BriefHistoryofTrojans&CovertTunnelsTrojansFromQuickThinkingGreeks…toQuickThinkingGeeksTunnelsCovertChannelsBriefHistoryofTrojans&Cov35Trojans..
ValidIP–NoFiltersValidIP–StatelessFiltersPrivateAddresses–StatefulFiltersPrivate+Stateful+IDS+PersonalFirewalls+ContentChecking+…Trojans..ValidIP–NoFilter36
Trojans..
(ValidIP–NoFilters)“getreal..”Trojans..
(ValidIP–NoFi37
Trojans..
(ValidIP–StatelessFilter)
DialHomeTrojansRandomPorts/OpenPorts/HighPorts[cDc]ACKTunneling[ArneVidstrom]Trojans..
(ValidIP–State38
Trojans..
(StatefulFilters)BackOrifice-
GbotRattlerTrojans..
(StatefulFilters39
BriefHistoryofTrojans&CovertTunnelsTrojansFromQuickThinkingGreeks…toQuickThinkingGeeksTunnelsCovertChannelsBriefHistoryofTrojans&40
Tunnels&CovertChannelsTunnels&CovertChannels41
ConventionalTrojans&howtheyfailStatefulfirewall&IDSDirectmodelDirectmodelwithnetworktricksICMPtunnelingACKtunnelingProperlyconfiguredstatefulfirewallIRCagents+AuthenticationproxyHTTPtunnel++Personalfirewall&AdvancedProxyHTTPtunnelwithAuthentication+++ConventionalTrojans&how42
Hybridmodel:“GatSlag”CombinationbetweencovertTunnelandTrojanDefensesmechanismstoday:Packetfilters(stateful)/NATAuthenticationProxiesIntrusiondetectionsystemsPersonalfirewallsContent/protocolcheckingBiometrics/TokenPads/OnetimepasswordsEncryptionHybridmodel:“GatSlag”43AtypicalnetworkAtypicalnetwork44HowGatSlagworkedReverseconnectionHTTPcoverttunnelMicrosoftInternetExplorerastransportControlsIEviaOLEEncapsulateinIE,notHTTPReceivecommandsintitleofwebpageReceiveencodeddataasplaintextinbodyofwebpageSenddatawithPOSTrequestSendalivesignalswithGETrequestHowGatSlagworked45
WhyGatSlagworkedIntegrationofclientwithMSProxyNTLMauthenticationSSLcapableRegistrychangesPersonalfirewallsJustanotherbrowserPlatformindependentIEoneverydesktopSpecifyControllerViapublicwebpage–theMASTERsiteWhyGatSlagworkedIntegratio46
HowGatSlagworkedIICreatesinvisiblebrowserFindcontrolleratMASTERSendrequesttoControllerIfnoController&&retry>7,gotoMASTERReceivereplyParsereply:+Uploadfile()+Downloadfile+ExecutecommandLoopHowGatSlagworkedII47
WhydefensesfailFirewalls(stateful/NAT)ConfiguredtoallowuserorproxyoutContentlevel&IDSLookslikevalidHTTPrequests&repliesFilesdownloadedastextinwebpagesNodataorportstolockontoSSLprovidesencryptionPersonalfirewallsIEvalidapplicationConfiguredtoallowbrowsingAuthenticationproxiesUsersurfthewebWhydefensesfail48
ProblemswithGatslagTheController’sIPcanbeobtained!HandlingofmultipleinstancesGUIsupportControllerneededtobeonlineBatchcommandsCommandhistoryMultiplecontrollersUploadfacilitynotefficientPlatformsupportStabilitySessionleveltunnelingProblemswithGatslag49
Setiri:AdvancesinTrojanTechnologyDesignnotes:WebsitecontainsinstructionsCGIstocreatenewinstructionController’sinterface:EXEC(DOScommands)TX(Fileupload)RX(Filedownload)Directorystructure–eachinstanceTrojan“surfs”towebsite–justanormaluserwo
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 消费品零售渠道变革-全面剖析
- 深度学习在图像识别中的应用-第11篇-全面剖析
- 智能电网控制技术-全面剖析
- 研究iOS9下AR交互方式的创新-全面剖析
- 丽水龙泉市属国有企业招聘真题2024
- 智能调试算法研究-全面剖析
- 数据隐私与隐私保护的社会影响-全面剖析
- 多源数据融合在监控中的应用-全面剖析
- 2025年期货从业资格考试法律法规与期货市场监管法规修订试题试卷
- 书法教师书法教育资源整合2025年测试卷:资源选择与共享策略试题
- 湖南省常德市2025届高三下学期模拟考试(二模)物理试卷(含答案)
- 人教版初一下学期生物实验报告册
- 《月是故乡明》定稿 优秀奖 教学课件
- 高铁站装饰装修施工方案
- 防台防汛管理制度
- 消防器材(灭火器)检查及记录表
- 2012小小科学家高年级试题生物
- 广电运通研究报告:数字人民币促产业升级-AI+城市助业务转型
- 移动式脚手架安全操作规程
- 永辉超市企业文化ppt课件
- 多肉生石花图谱_版
评论
0/150
提交评论