· 9 years ago · Jun 20, 2017, 04:54 PM
1The
2Hacker’s
3Handbook
4The Strategy behind Breaking
5into and
6Defending Networks
7© 2004 by CRC Press LLC
8The ABCs of IP Addressing
9Gilbert Held
10ISBN: 0-8493-1144-6
11The ABCs of LDAP
12Reinhard Voglmaier
13ISBN: 0-8493-1346-5
14The ABCs of TCP/IP
15Gilbert Held
16ISBN: 0-8493-1463-1
17Building an Information Security
18Awareness Program
19Mark B. Desman
20ISBN: 0-8493-0116-5
21Building a Wireless Office
22Gilbert Held
23ISBN: 0-8493-1271-X
24The Complete Book of Middleware
25Judith Myerson
26ISBN: 0-8493-1272-8
27Computer Telephony Integration,
282nd Edition
29William A. Yarberry, Jr.
30ISBN: 0-8493-1438-0
31Electronic Bill Presentment and Payment
32Kornel Terplan
33ISBN: 0-8493-1452-6
34Information Security Architecture
35Jan Killmeyer Tudor
36ISBN: 0-8493-9988-2
37Information Security Management
38Handbook, 4th Edition, Volume 1
39Harold F. Tipton and Micki Krause, Editors
40ISBN: 0-8493-9829-0
41Information Security Management
42Handbook, 4th Edition, Volume 2
43Harold F. Tipton and Micki Krause, Editors
44ISBN: 0-8493-0800-3
45Information Security Management
46Handbook, 4th Edition, Volume 3
47Harold F. Tipton and Micki Krause, Editors
48ISBN: 0-8493-1127-6
49Information Security Management
50Handbook, 4th Edition, Volume 4
51Harold F. Tipton and Micki Krause, Editors
52ISBN: 0-8493-1518-2
53Information Security Policies,
54Procedures, and Standards:
55Guidelines for Effective Information
56Security Management
57Thomas R. Peltier
58ISBN: 0-8493-1137-3
59Information Security Risk Analysis
60Thomas R. Peltier
61ISBN: 0-8493-0880-1
62Interpreting the CMMI: A Process
63Improvement Approach
64Margaret Kulpa and Kurt Johnson
65ISBN: 0-8493-1654-5
66IS Management Handbook,
678th Edition
68Carol V. Brown and Heikki Topi
69ISBN: 0-8493-1595-6
70Managing a Network Vulnerability
71Assessment
72Thomas R. Peltier and Justin Peltier
73ISBN: 0-8493-1270-1
74A Practical Guide to Security Engineering
75and Information Assurance
76Debra Herrmann
77ISBN: 0-8493-1163-2
78The Privacy Papers:
79Managing Technology and Consumers,
80Employee, and Legislative Action
81Rebecca Herold
82ISBN: 0-8493-1248-5
83Securing and Controlling Cisco Routers
84Peter T. Davis
85ISBN: 0-8493-1290-6
86Six Sigma Software Development
87Christine B. Tayntor
88ISBN: 0-8493-1193-4
89Software Engineering Measurement
90John Munson
91ISBN: 0-8493-1502-6
92A Technical Guide to IPSec Virtual Private
93Networks
94James S. Tiller
95ISBN: 0-8493-0876-3
96Telecommunications Cost Management
97Brian DiMarsico, Thomas Phelps IV,
98and William A. Yarberry, Jr.
99ISBN: 0-8493-1101-2
100AUERBACH PUBLICATIONS
101www.auerbach-publications.com
102To Order Call: 1-800-272-7737 • Fax: 1-800-374-3401
103E-mail: orders@crcpress.com
104OTHER AUERBACH PUBLICATIONS
105© 2004 by CRC Press LLC
106AUERBACH PUBLICATIONS
107A CRC Press Company
108Boca Raton London New York Washington, D.C.
109The
110Hacker’s
111Handbook
112SUSAN YOUNG AND DAVE AITEL
113The Strategy behind Breaking
114into and
115Defending Networks
116© 2004 by CRC Press LLC
117This book contains information obtained from authentic and highly regarded sources. Reprinted material
118is quoted with permission, and sources are indicated. A wide variety of references are listed. Reasonable
119efforts have been made to publish reliable data and information, but the authors and the publisher cannot
120assume responsibility for the validity of all materials or for the consequences of their use.
121Neither this book nor any part may be reproduced or transmitted in any form or by any means, electronic
122or mechanical, including photocopying, microfilming, and recording, or by any information storage or
123retrieval system, without prior permission in writing from the publisher.
124All rights reserved. Authorization to photocopy items for internal or personal use, or the personal or
125internal use of specific clients, may be granted by CRC Press LLC, provided that $1.50 per page
126photocopied is paid directly to Copyright Clearance Center, 222 Rosewood Drive, Danvers, MA 01923
127USA. The fee code for users of the Transactional Reporting Service is ISBN 0-8493-0888-7/04/$0.00+$1.50.
128The fee is subject to change without notice. For organizations that have been granted a photocopy license
129by the CCC, a separate system of payment has been arranged.
130The consent of CRC Press LLC does not extend to copying for general distribution, for promotion, for
131creating new works, or for resale. Specific permission must be obtained in writing from CRC Press LLC
132for such copying.
133Direct all inquiries to CRC Press LLC, 2000 N.W. Corporate Blvd., Boca Raton, Florida 33431.
134Trademark Notice:
135Product or corporate names may be trademarks or registered trademarks, and are
136used only for identification and explanation, without intent to infringe.
137Visit the Auerbach Publications Web site at www.auerbach-publications.com
138© 2004 by CRC Press LLC
139Auerbach is an imprint of CRC Press LLC
140No claim to original U.S. Government works
141International Standard Book Number 0-8493-0888-7
142Library of Congress Card Number 2003055391
143Printed in the United States of America 1 2 3 4 5 6 7 8 9 0
144Printed on acid-free paper
145Library of Congress Cataloging-in-Publication Data
146Young, Susan (Susan Elizabeth), 1968–
147The hacker’s handbook : the strategy behind breaking into and defending Networks /
148Susan Young, Dave Aitel.
149p. cm.
150Includes bibliographical references and index.
151ISBN 0-8493-0888-7 (alk. paper)
1521. Computer networks—Security measures. 2. Computer networks—Access control. 3.
153Computer hackers. I. Aitel, Dave. II. Title.
154TK5105.59.Y68 2003
155005.8—dc22 2003055391
156CIP
157© 2004 by CRC Press LLC
158v
159Acknowledgments
160Every book, as they say, has a story. This book’s history has been a long
161and varied one. Along the way, numerous individuals have contributed
162their time, focus, energy, technical acumen, or moral support to seeing
163The
164Hacker’s Handbook
165through to its conclusion.
166The authors would like to thank the following individuals for their con-
167tributions and support:
168• Rich O’Hanley and the production staff at Auerbach Press for their
169tireless support of this book, in spite of its long (and somewhat
170nefarious) history.
171• Our contributing authors — Felix Lindner, Jim Barrett, Scott Brown,
172and John Zuena — for taking the time and care to write several
173excellent chapters on the hacking community, malware, directory
174services, and network hardware that contain some truly unique and
175interesting material.
176• Our technical reviewers, including Jim Tiller, Anton Chuvakin, Sean
177Cemm, Ben Rothke, and Ted Shagory, for their insights and for
178dedicating their time and energy to helping to shape a better book.
179We are confident that this review process will continue as this text
180goes to publication, and want — in advance — to thank our readers
181and reviewers for their attention to the ongoing quality of this book.
182In addition, Dave Aitel would like to thank Justine Bone for her support
183and encouragement and Susan Young would like to thank the following indi-
184viduals: the Darklord (Thomas McGinn) for keeping his personal commit-
185ment to support the effort that went into this book in spite of many months
186of spent deadlines, missed weekends, and fatigue (thanks, T2B); Trevor
187Young, for lending his genuine talent, enthusiasm, time, and care to crafting
188the illustrations throughout this book; Gemma Young, and her parents,
189Sylvia and Neil, for their interest, support, and advice through two years of
190long distance phone calls; and International Network Services (and parti-
191cularly Steven Marandola, Bob Breingan, and Shaun Meaney) for making
192available time and support for the completion of this book.
193© 2004 by CRC Press LLC
194Authors
195Dave Aitel
196is the founder of Immunity, Inc. (www.immunitysec.com), with
197prior experience at both private industry security consulting companies and
198the National Security Agency. His tools, SPIKE and SPIKE Proxy, are widely
199regarded as the best black box application assessment tools available.
200Susan Young
201has worked in the security field for the past seven years, four
202of which have been spent in the security consulting arena, helping clients
203design and implement secure networks, training on security technologies,
204and conducting security assessments and penetration tests of client system
205or network defenses (so-called ethical hacking). Her experience has
206included consulting work in the defense sector and the financial industry, as
207well as time spent evaluating and deconstructing various security products.
208She currently works as a senior security consultant in the Boston area secu-
209rity practice of International Network Services (INS).
210© 2004 by CRC Press LLC
211Contributors
212Jim Barrett
213(CISA, CISSP, MCSE, CCNP) is a principal consultant for the
214Boston office of International Network Services (INS). He currently serves
215as the national Microsoft practice leader for INS and has been working with
216Microsoft technologies for longer than he can remember. Prior to INS, Jim
217spent several years as a member of the information systems audit and
218security practice of Ernst & Young LLP, where he co-authored the firm’s
219audit methodology for Novell NetWare 4.1 and was an instructor at the
220Ernst & Young National Education Center. His areas of expertise
221include network operating systems and information systems security.
222Scott Brown
223(CISSP, GCIA, GCIH) is a senior security consultant for Interna-
224tional Network Services, with more than 13 years experience in the infor-
225mation technologies field. He is a Certified Information Systems Security
226Professional (CISSP), and holds both SANS GCIA and GCIH certifications.
227Scott is also a private pilot with a rating in single engine aircraft.
228John Zuena
229(CISSP, CCNA, CCDA, NNCSE) is a senior consultant for Inter-
230national Network Services, with more than 14 years experience in the infor-
231mation technologies field. He is a Certified Information Systems Security
232Professional (CISSP) and holds both Cisco and Nortel internetworking cer-
233tifications. He is also a private pilot with ratings in both single engine air-
234planes and helicopters.
235© 2004 by CRC Press LLC
236viii
237Illustrator
238Trevor Young
239has been drawing, painting, creating, and generally exercis-
240ing his artistic imagination for a very long time.
241Young attended Camberwell College of Art in London, studying graphic
242design and illustration, and has gone on to a successful career in the film
243special effects industry in London, first working for the Film Factory and
244currently as a digital compositor for Hypnosis VFX Ltd. You will find him in
245the IMDb at http://us.imdb.com/Name?Young,+Trevor. He has continued to
246work in illustration from time to time and generously contributed his time
247to create a set of illustrations for this book that have become truly integral
248to the book and the subject matter.
249© 2004 by CRC Press LLC
250List of Abbreviations
251ACK
252Acknowledge
253ARIN
254American Registry for Internet Numbers
255ASCII
256ASCII Character Set (ASCII)
257ASN
258Autonomous System Number
259ASP
260Active Server Pages or Application Service Provider
261BSDI
262Berkeley Software Design (BSD) Operating System Internet
263Server Edition
264CANVAS
265Immunity Security’s CANVAS Vulnerability Scanner
266CAST
267Computer Aided Software Testing
268CDE
269Common Desktop Environment
270CHAM
271Common Hacking Attack Methods
272CIFS
273Common Internet File Sharing
274CPAN
275Comprehensive Perl Archive Network
276CRC
277Cyclic Redundancy Check
278CVE
279Common Vulnerabilities and Exposures (List)
280CVS
281Concurrent Versions System Source Code Control System
282DDoS
283Distributed Denial-of-Service
284DID
285Direct Inward Dialing
286DIT
287Directory Information Tree
288DNS
289Domain Name System
290DNSSEC
291Domain Name System Security
292DoS
293Denial-of-Service
294DSA
295Digital Signature Algorithm
296EFS
297Encrypting File System (Microsoft)
298EIGRP
299Enhanced Interior Gateway Routing Protocol
300EIP
301Extended Instruction Pointer
302ESMTP
303Extended Simple Mail Transfer (Protocol)
304EVT
305Event (Microsoft)
306FIFO
307First In First Out is an approach to handling queue or stack
308requests where the oldest requests are prioritized
309FX
310Handle for Felix Lindner
311GCC
312GNU C Compiler
313GCIA
314GIAC Certified Intrusion Analyst
315GCIH
316GIAC Certified Incident Handler
317© 2004 by CRC Press LLC
318THE STRATEGY BEHIND BREAKING INTO AND DEFENDING NETWORKS
319GDB
320GNU Project Debugger
321GID
322Group ID (Access Control Lists)
323GINA
324Graphical Identification and Authentication (Dynamic Link
325Library, Microsoft)
326GNOME
327GNU Free Desktop Environment
328GNU
329GNU Software Foundation
330HIDS
331Host Intrusion Detection System
332HKEY
333Microsoft Registry Key Designation (Hive Key)
334HMAC
335Keyed Hashing Message Authentication
336HQ
337Headquarters
338HTTPS
339Secure Hypertext Transmission Protocol
340HUMINT
341Human Intelligence
342ICQ
343ICQ Protocol
344IDS
345Intrusion Detection System
346IKE
347Internet Key Exchange (Protocol)
348IMDb
349Internet Movie Database
350IPO
351Initial Public Offering
352IPSec
353IP Security (Protocol)
354IRIX
355Silicon Graphics IRIX Operating System (IRIX)
356ISAKMP
357Internet Security Association and Key Management Protocol
358ISS
359Internet Security Systems
360IUSR
361Internet User (i.e., IUSR_name) is an anonymous user desig-
362nation used by Microsoft’s Internet Information Server (IIS)
363KB
364Kilobytes or Knowledgebase
365KDE
366K Desktop Environment
367KSL
368Keystroke Logger
369LKM
370Loadable Kernel Modules
371LM
372Lan Manager (Microsoft Authentication Service)
373LT2P
374Layer 2 Tunneling Protocol
375MIB
376Management Information Base
377MSDE
378Microsoft Data Engine
379MSDN
380Microsoft Developer Network
381MSRPC
382Microsoft Remote Procedure Call
383MUA
384Mail User Agent
385MVS
386Multiple Virtual Storage (MVS) Operating System
387MX
388Mail Exchange (Record, DNS)
389NASL
390Nessus Attack Scripting Language (Nessus Security Scanner)
391NIDS
392Network Intrusion Detection System
393NMAP
394Network Mapper (Nmap)
395NMS
396Network Management Station
397NTFS
398NT File System
399NTFS5
400NT File System 5
401NTLM
402NT LanMan (Authentication)
403OU
404Organizational Unit
405PCX
406.pcx files created with MS Paintbrush tool
407© 2004 by CRC Press LLC
408PHP
409Hypertext Preprocessor
410PID
411Process Identifier
412PUT
413PUT (FTP)
414RCS
415Revision Control System
416RDS
417Remote Data Service
418RIP
419Routing Information Protocol
420RSA
421RSA Security, Inc.
422SAM
423Security Accounts Manager (Microsoft)
424SANS
425Sysadmin, Audit, Network, Security (SANS Institute)
426SASL
427Simple Authentication and Security Layer
428SATAN
429Security Administrator Tool for Analyzing Networks
430SID Security Identifier (Microsoft)
431SIGINT Signal Intelligence
432SMB Server Message Block (Protocol)
433SOCKS Sockets Protocol (Firewall)
434SRV Service Record (DNS)
435SUID Set User ID (bit) utilized in UNIX Operating Systems to
436impose File System Access Control Lists
437SYN Synchronize (TCP SYN)
438SYN-ACK Synchronize-Acknowledge (TCP SYN ACK)
439USB Universal Serial Bus
440VB Visual Basic
441VM Virtual Machine
442VMS VMS (Operating System)
443VNC AT&T Virtual Network Computing (Software)
444XDMCPD X Display Manager Control Protocol
445XOR Exclusive OR
446© 2004 by CRC Press LLC
447Contents
4481 Introduction: The Chess Game
449Book Structure
450Chapter 2. Case Study in Subversion
451Chapter 3. Know Your Opponent
452Chapter 4. Anatomy of an Attack
453Chapter 5. Your Defensive Arsenal
454Chapter 6. Programming
455Chapter 7. IP and Layer 2 Protocols
456Chapter 8. The Protocols
457Chapter 9. Domain Name System (DNS)
458Chapter 10. Directory Services
459Chapter 11. Simple Mail Transfer Protocol (SMTP)
460Chapter 12. Hypertext Transfer Protocol (HTTP)
461Chapter 13. Database Hacking
462Chapter 14. Malware and Viruses
463Chapter 15. Network Hardware
464Chapter 16. Consolidating Gains
465Chapter 17. After the Fall
466Chapter 18. Conclusion
467PART I FOUNDATION MATERIAL
4682 Case Study in Subversion
469Dalmedica
470The Dilemma
471The Investigation
472Notes
4733 Know Your Opponent
474Terminology
475Script Kiddy
476Cracker
477White Hat Hacker
478Black Hat Hacker
479Hacktivism
480Professional Attackers
481© 2004 by CRC Press LLC
482History
483Computer Industry and Campus
484System Administration
485Home Computers
486Home Computers: Commercial Software
487Home Computers: The BBS
488Phone Systems
489Ethics and Full Disclosure
490Opponents Inside
491The Hostile Insider
492Corporate Politics
493Conclusion
494Notes
4954 Anatomy of an Attack
496Overview
497Reconnaissance
498Social Engineering and Site Reconnaissance
499Internet Reconnaissance
500Internet Search Engines and Usenet Tools
501Financial Search Tools, Directories, Yellow Pages,
502and Other Sources
503IP and Network Reconnaissance
504Registrar and whois Searches
505Network Registrar Searches (ARIN)
506DNS Reconnaissance
507Mapping Targets
508War Dialing
509Network Mapping (ICMP)
510ICMP Queries
511TCP Pings: An Alternative to ICMP
512Traceroute
513Additional Network Mapping Tools
514Port Scanning
515TCP and UDP Scanning
516Banner Grabbing
517Packet Fragmentation Options
518Decoy Scanning Capabilities
519Ident Scanning
520FTP Bounce Scanning
521Source Port Scanning
522Stack Fingerprinting Techniques
523Vulnerability Scanning (Network-Based OS
524and Application Interrogation)
525Researching and Probing Vulnerabilities
526System/Network Penetration
527© 2004 by CRC Press LLC
528Account (Password) Cracking
529Application Attacks
530Cache Exploits
531File System Hacking
532Hostile and Self-Replicating Code
533Programming Tactics
534Process Manipulation
535Shell Hacking
536Session Hijacking
537Spoofing
538State-Based Attacks
539Traffic Capture (Sniffing)
540Trust Relationship Exploitation
541Denial-of-Service
542Consolidation
543Security
544Notes
545References
546Texts
547Web References
5485 Your Defensive Arsenal
549The Defensive Arsenal
550Access Controls
551Network Access Controls (Firewalls)
552State Management Attacks on Firewalls
553Firewall Ruleset and Packet Filter Reconnaissance
554IP Spoofing to Circumvent Network Access Controls
555Denial-of-Service
556Packet Fragmentation Attacks
557Application Level Attacks
558System Access Controls
559Host-Based Firewalls
560Operating System Access Controls
561and Privilege Management
562Authentication
563IP Authentication
564Password Authentication
565Account/Password Cracking
566Eavesdropping Attacks
567Password Guessing Attacks
568Token-Based Authentication
569Session Authentication
570Session Authentication Scheme Cracking
571Generation of Counterfeit Session Auth Credentials
572Session ID Brute-Forcing
573© 2004 by CRC Press LLC
574Session Auth Eavesdropping
575Session Auth/ID Stealing or “Hijackingâ€
576Client Session/ID Theft
577Cryptographic (Key-Based) Authentication
578Key Transfer and Key Management Vulnerabilities
579Key Transfer Vulnerabilities
580Key Management Vulnerabilities
581(Public Key Infrastructure)
582Key Binding and Impersonation Vulnerabilities
583Dictionary and Brute-Force Attacks
584against Weak Secrets
585Centralized Authentication Servers
586RADIUS
587TACACS
588Kerberos
589Human Authentication (Biometrics)
590Resource Controls
591Nonrepudiation
592Digital Signatures (and Digital Certificates)
593Privacy
594Virtual Private Network (VPN)
595Session and Protocol Encryption
596Secure Sockets Layer (SSL)
597Certificate and Impersonation Attacks (SSL)
598Cryptographic Weaknesses (SSL)
599Attacks against the Handshake Protocol (SSL)
600SSL Man-in-the-Middle Attacks
601Man-in-the-Middle Attack Version Rollback (SSL)
602Viruses, Worms, and other Application Issues (SSL)
603Secure Shell (SSH)
604File System Encryption
605Intrusion Detection
606Network-Based and Host-Based IDS
607Anomaly-Based (Behavior-Based) IDS
608Signature-Based (Knowledge-Based) IDS
609IDS Hacking Exploits
610Address Spoofing or Proxying
611Attacking the IDS
612Denial-of-Service
613Instigating Active Events
614Nondefault Evasion and Pattern Change Evasion
615Packet Fragmentation and “Session Splicingâ€
616Port Scan Evasion
617TCP Session Synchronization Attacks
618© 2004 by CRC Press LLC
619URL Encoding (Unicode and Hex Attacks)
620Web Evasion Techniques
621File System Integrity Checkers
622Security Information Management
623Data Integrity
624Application Proxies
625Content Assurance (Antivirus, Content Scanning)
626Notes
627References
628Texts
629Web References
6306 Programming
631Languages
632Speed and Security Trade-Offs
633Native Compiled Code: C/C++/Assembly
634Bytecode/Just in Time Compiled Code
635(“Managed†Code): C#/Java
636Interpreted (Usually Compiled into Byte Codes
637at Runtime): Perl, Python (Scripting Languages),
638PHP, Visual Basic, .ASP, Lisp, JSP (Web Languages)
639Language-Specific Flaws and Strategic Ways to Protect
640against Them
641The Basics of Buffer Overflows and Other Memory
642Allocation Errors
643History
644Basic Stack Overflows
645Options for the Hacker after a Stack Overflow
646So What Is a Stack Canary?
647Heap Overflows
648Format String Bugs
649Integer Overflows
650Signal Races on UNIX
651What Is Shellcode?
652Interpreter Bugs
653File Name Canonicalization
654Logic Error War Stories
655Platform-Specific Programming Security Issues
656Windows NT Compared to UNIX
657Types of Applications
658Web Applications
659Cross-Site Scripting Vulnerabilities
660Java J2EE
661Traditional ASP
662© 2004 by CRC Press LLC
663.Net
664LAMP
665Remote Procedure Calling
666Creating an RPC Program
667Special Cases
668Setuid Applications on UNIX
669DCOM Services
670Auditing Techniques
671Tools That Aid Source Auditing
672Tools That Aid Reverse Engineering
673Fuzzing Audit Tools
674Web Security Audit Tools
675General Security Tools
676Encryption and Authentication
677Layered Defenses
678Platform-Specific Defenses (Security through Security
679and Security through Obscurity)
680Nonexecutable Stack
681Using a Different Platform Than Expected
682File System User Access Controls
683Process Logging
684The Insider Problem, Backdoors, and Logic Bombs
685Buying an Application Assessment
686Conclusion
687References
6887 IP and Layer 2 Protocols
689Layer 2 Protocols
690Address Resolution Protocol (ARP)
691Protocol
692Hacking Exploits
693Security (Mapping ARP Exploits to ARP Defenses)
694Static ARP Entries on Internet Gateways
695and Firewalls
696Network Management
697ARP Monitoring
698Port-Level Security
699Reverse Address Resolution Protocol (RARP)
700Protocol
701Hacking Exploits
702Security (Defenses for RARP-Related Attacks:
703DHCP, BOOTP)
704Assignment of Static IP Addresses to Clients
705Use of DHCP/BOOTP MAC Controls
706ARP Monitoring
707© 2004 by CRC Press LLC
708Port-Level Security
709Layer 3 Protocols
710IP Protocol
711Protocol
712Hacking Exploits
713IP Eavesdropping (Packet Sniffing)
714IP Spoofing
715IP Session Hijacking (Man-in-the-Middle Attacks)
716IP Packet Fragmentation Attacks
717ICMP-Based Fragmentation Attacks
718Tiny Fragment Attacks
719Overlapping Fragment Attacks
720IP Covert Tunneling
721Security (Mapping IP Exploits to IP Defenses)
722Tools and Techniques to Detect Promiscuous
723Mode Packet Sniffers
724System Audits to Identify NICs
725in Promiscuous Mode
726System Hardening Procedures
727to Inhibit Sniffer Installation
728Inspection of Systems for Signs
729of Rootkit Compromise
730Institution of Switched Network
731Institution of ARP Monitoring
732Institution of Traffic Encryption
733Implementation of Strong Authentication
734Institution of Spoof Protection at Firewalls
735and Access Control Devices
736Patch TCP/IP Implementations
737Deny Source Routing at Gateways and Firewalls
738Deny ICMP Redirects at Gateways and Firewalls
739Deter the Use of IP Addresses for Authentication
740or Construction of Trust Relationships
741Implement ARP Controls
742Monitor Network Traffic Using Network
743and Host-based IDS
744Restrict ICMP Traffic into and out of
745a Protected Network
746Patch Firewalls and Intrusion Detection Systems
747against Packet Fragmentation Attacks
748Notes
749References
750Texts
751Request for Comments (RFCs)
752White Papers and Web References
753© 2004 by CRC Press LLC
7548 The Protocols
755Layer 3 Protocols
756Internet Control Message Protocol (ICMP)
757Protocol
758Hacking Exploits
759ICMP-Based Denial-of-Service
760ICMP Network Reconnaissance
761ICMP Time Exceeded
762ICMP Access Control Enumeration
763ICMP Stack Fingerprinting
764ICMP Covert Tunneling
765Security
766Deny ICMP Broadcasts
767Network Controls against ICMP Packet Flooding
768IP Spoofing Defenses
769Patch TCP/IP Implementations against
770ICMP Denial-of-Service and ICMP Typing
771Monitor Network Traffic Using Network and
772Host-Based Intrusion Detection Systems (IDSs)
773Restriction of Specific ICMP Message Types
774Monitor ICMP Activity at Firewalls
775and Intrusion Detection Systems
776Layer 4 Protocols
777Transmission Control Protocol (TCP)
778Protocol
779Hacking Exploits
780Covert TCP
781TCP Denial-of-Service
782TCP Sequence Number Prediction
783(TCP Spoofing and Session Hijacking)
784TCP Stack Fingerprinting
785TCP State-Based Attacks
786Security
787Network Controls against TCP Packet Flooding
788IP Spoofing Defenses
789Patch TCP/IP Implementations against TCP
790Denial-of-Service, TCP Stack Fingerprinting,
791and TCP Sequence Number Prediction
792Monitor Network Traffic Using Network
793and Host-Based IDS Systems
794Activation of SYN Flood Protection on Firewalls
795and Perimeter Gateways
796Implement Stateful Firewalling
797User Datagram Protocol (UDP)
798Protocol
799© 2004 by CRC Press LLC
800Hacking Exploits
801Covert UDP
802UDP Denial-of-Service
803UDP Packet Inspection Vulnerabilities
804Security
805Disable Unnecessary UDP Services
806Network Controls against UDP Packet Flooding
807IP Spoofing Defenses
808Patch TCP/IP Implementations against UDP
809Denial-of-Service
810Monitor Network Traffic Using Network-
811and Host-Based IDS Systems
812Implement Stateful Firewalling
813Notes
814References
815Texts
816Request for Comments (RFCs)
817White Papers and Web References
818PART II SYSTEM AND NETWORK PENETRATION
8199 Domain Name System (DNS)
820The DNS Protocol
821DNS Protocol and Packet Constructs
822(Packet Data Hacking)
823DNS Vulnerabilities
824DNS Exploits and DNS Hacking
825Protocol-Based Hacking
826Reconnaissance
827DNS Registration Information
828Name Server Information
829IP Address and Network Topology Data
830Information on Key Application Servers
831Protocol-Based Denial-of-Service
832Dynamic DNS (DDNS) Hacking
833Application-Based Attacks
834Buffer Overflows (Privileged Server Access,
835Denial-of-Service)
836Exploiting the DNS Trust Model
837DNS Registration Attacks
838DNS Spoofing
839Cache Poisoning
840DNS Hijacking
841DNS Security and Controls
842Mapping Exploits to Defenses
843Defensive Strategy
844© 2004 by CRC Press LLC
845Configuration Audit and Verification Tools
846DDNS Security
847Name Server Redundancy
848DNSSEC: Authentication and Encryption of DNS Data
849Name Server Software Upgrade(s)
850Network and Name Server Monitoring
851and Intrusion Detection
852Berkeley Internet Name Daemon (BIND)
853Logging Controls
854Microsoft Windows 2000 DNS Logging Controls
855Patches and Service Packs
856Server-Side Access Controls
857Split-Level DNS Topologies (and DNS Proxying)
858Split-Level DNS Topology
859System and Service Hardening
860Notes
861References
862Texts
863Request for Comments (RFCs)
864Mailing Lists and Newsgroups
865Web References
86610 Directory Services
867What Is a Directory Service?
868Components of a Directory
869Schema
870Leaf Object
871Container Object
872Namespace
873Directory Information Tree
874Directory Information Base (DIB)
875Directory Features
876Directory Security
877Single Sign On
878Uses for Directory Systems
879Directory-Enabled Networking
880Linked Provisioning
881Global Directory
882Public Key Infrastructure
883Directory Models
884Physical vs. Logical
885Flat vs. Hierarchical
886X.500 Directory
887X.500 Schema
888X.500 Partitions
889X.500 Objects and Naming
890© 2004 by CRC Press LLC
891A Word about Aliases
892X.500 Back-End Processes
893Directory Information Tree
894Directory Information Base
895Replication
896Agents and Protocols
897X.500 Directory Access
898X.500 Security
899Authentication
900Simple Authentication
901Strong Authentication
902Access Control
903Rights
904Summary
905Lightweight Directory Access Protocol (LDAP)
906LDAP Schema
907LDAP Partitions
908LDAP Objects and Naming
909LDAP Queries
910LDAP Data Interchange Format (LDIF)
911LDAP Security
912Authentication
913Anonymous Access
914Simple Authentication
915Simple Authentication with Secure Sockets
916Layer (SSL)/Transport Layer Security (TLS)
917Simple Authentication and Security Layer (SASL)
918Access Control
919Summary
920Active Directory
921Windows NT
922Windows 2000 Schema
923Windows 2000 Partitions
924Windows 2000 Objects and Naming
925The Domain
926The Tree
927The Forest
928The Forest Root Domain
929Naming Standards and Resolution in Windows 2000
930Active Directory Back-End Processes
931The Directory Information Base (DIB)
932Replication
933The Global Catalog
934Windows 2000 Security
935Authentication
936© 2004 by CRC Press LLC
937Kerberos
938NTLM
939Access Control
940Exploiting LDAP
941Sun ONE Directory Server 5.1
942Microsoft Active Directory
943Summary
944Future Directions
945Further Reading
94611 Simple Mail Transfer Protocol (SMTP)
947The SMTP Protocol
948SMTP Protocol and Packet Constructs
949(Packet Data Hacking)
950SMTP Vulnerabilities
951SMTP Protocol Commands and Protocol Extensions
952Protocol Commands
953Protocol Extensions
954SMTP Exploits and SMTP Hacking
955SMTP Protocol Attacks
956Account Cracking
957Eavesdropping and Reconnaissance
958ESMTP and Command Set Vulnerabilities
959Protocol-Based Denial-of-Service
960Mail Bombing
961Mail Spamming
962Man-in-the-Middle Attacks
963Application-Based Attacks
964Malicious Content (MIME Attacks)
965Buffer Overflows (Privileged Server Access)
966Worms and Automated Attack Tools
967Application-Based Denial-of-Service
968Attacks on the Mail Trust Model
969Mail Spoofing
970Identity Impersonation
971Attacks on Data Integrity
972Delivery Status Notification Manipulation
973SMTP Security and Controls
974Mapping Exploits to Defenses
975Defensive Strategy
976Antispam/Antirelay Controls
977Antivirus and Content Scanning
978Client-Side Access Controls
979Content or Code Signing
980Delivery Status Notification Controls
981Disable Vulnerable ESMTP and SMTP Commands
982© 2004 by CRC Press LLC
983Disable Vulnerable MIME Types
984Network and SMTP Server Monitoring,
985Intrusion Detection
986Patches and Service Packs
987Separation of SMTP and Intranet Account Databases
988Server-Side Access Controls
989Server Redundancy
990SMTP Header Stripping and Parsing
991SMTP Source Routing Controls
992Split SMTP Topology
993System and Service Hardening
994Transport Layer Security, Secure Socket
995Layer Security
996Notes
997References
998Texts
999Request for Comments (RFCs)
1000White Papers and Web References
100112 Hypertext Transfer Protocol (HTTP)
1002The HTTP Protocol
1003HTTP Protocol and Packet Constructs
1004(Packet Data Hacking)
1005HTTP Vulnerabilities
1006HTTP Protocol Methods (and Associated Vulnerabilities)
1007HTTP Exploits and HTTP Hacking
1008HTTP Protocol Attacks
1009Eavesdropping and Reconnaissance
1010Account Cracking
1011Basic Access Authentication
1012Digest Access Authentication
1013HTTP Method Vulnerabilities
1014Content Vulnerabilities
1015Caching Exploits
1016Cache Poisoning
1017Man-in-the-Middle Attacks
1018Unauthorized Retrieval of Cache Data
1019and Cache Monitoring
1020Denial-of-Service
1021Protocol-Based Denial-of-Service
1022Application-Based Attacks
1023Buffer Overflows (Privileged Server Access,
1024Denial-of-Service)
1025Directory Traversal Attacks
1026Application-Based Denial-of-Service
1027Attacks on the HTTP Trust Model
1028© 2004 by CRC Press LLC
1029State-Based Attacks (Session ID Hacking)
1030HTTP Spoofing/HTTP Redirection
1031Man-in-the-Middle Attacks (Session Hijacking)
1032HTTP Security and Controls
1033Mapping Exploits to Defenses
1034Defensive Strategy
1035Caching Controls and Cache Redundancy
1036Disable Vulnerable HTTP Methods
1037HTTP Header Stripping
1038Implementation of HTTP Digest
1039Access Authentication
1040Load Balancing and Server Redundancy
1041Network and HTTP Server Monitoring,
1042Intrusion Detection
1043Patches and Service Packs
1044Security for Financial Transactions
1045Server-Side Access Controls
1046System and Service Hardening
1047Transport Layer Security or Secure Socket
1048Layer Security
1049Notes
1050References
1051Texts
1052Request for Comments (RFCs)
1053Web References
105413 Database Hacking and Security
1055Introduction
1056Enumeration of Weaknesses
1057SQL Injection
1058Introduction
1059Phases of SQL Injection
1060Hacking Microsoft SQL Server
1061Overflows in Microsoft SQL Server
1062You Had Me at Hello
1063SQL Server Resolver Service Stack Overflow
1064Microsoft SQL Server Postauth Vulnerabilities
1065Microsoft SQL Server SQL Injection
1066A Note on Attacking Cold Fusion Web Applications
1067Default Accounts and Configurations
1068Hacking Oracle
1069Buffer Overflows in Oracle Servers
1070SQL Injection on Oracle
1071Default User Accounts
1072Tools and Services for Oracle Assessments
1073Other Databases
1074© 2004 by CRC Press LLC
1075Connecting Backwards
1076Demonstration and Examples
1077Phase 1. Discovery
1078Phase 2. Reverse Engineering the Vulnerable Application
1079Phase 3. Getting the Results of Arbitrary Queries
1080Conclusions
108114 Malware and Viruses
1082Ethics Again
1083Target Platforms
1084Script Malware
1085Learning Script Virus Basics with Anna Kournikova
1086Binary Viruses
1087Binary File Viruses
1088Binary Boot Viruses
1089Hybrids
1090Binary Worms
1091Worst to Come
1092Adware Infections
1093Conclusion
1094Notes
109515 Network Hardware
1096Overview
1097Network Infrastructure
1098Routers
1099Switches
1100Load-Balancing Devices
1101Remote Access Devices
1102Wireless Technologies
1103Network Infrastructure Exploits and Hacking
1104Device Policy Attacks
1105Installation Policy
1106Acceptable Use Policy
1107Access Policy
1108Configuration Storage Policy
1109Patch or Update Policy
1110Denial-of-Service
1111Device Obliteration
1112Configuration Removal or Modification
1113Sending Crafted Requests
1114Physical Device Theft
1115Environmental Control Modification
1116Resource Expenditure
1117Diagnostic Port Attack
1118Sequence (SYN) Attack
1119© 2004 by CRC Press LLC
1120Land Attack
1121Bandwidth Expenditure
1122Broadcast (Smurf) Attacks
1123Other ICMP-Related Attacks
1124Redirects
1125ICMP Router Discovery Protocol (IDRP) Attack
1126Ping O’Death
1127Squelch
1128Fragmented ICMP
1129Network Mapping Exploits
1130Ping
1131Traceroute
1132Broadcast Packets
1133Information Theft
1134Network Sniffing
1135Hijacking Attacks
1136Spoofing
1137Address Spoofing
1138TCP Sequence Attacks
1139Media Access (MAC) Address Exploits
1140Password or Configuration Exploits
1141Default Passwords or Configurations
1142No Passwords
1143Weak Passwords
1144Dictionary Password Attacks
1145Brute-Force Attacks
1146Logging Attacks
1147Log Modification
1148Log Deletion
1149Log Rerouting
1150Spoofed Event Management
1151Network Ports and Protocols Exploits and Attacks
1152Telnet
1153BOOTP
1154Finger
1155Small Services
1156Device Management Attacks
1157Authentication
1158Console Access
1159Modem Access (AUX)
1160Management Protocols
1161Web (HTTP[S])
1162Telnet
1163SSH (Version 1)
1164TFTP
1165© 2004 by CRC Press LLC
1166SNMP
1167Device Configuration Security Attacks
1168Passwords
1169Remote Loading (Network Loads)
1170Router-Specific Exploits
1171Routing Protocol Attacks
1172Authentication
1173IRDP Attacks
1174Cisco Discovery Protocol (CDP)
1175Classless Routing
1176Source Routing
1177Route Table Attacks
1178Modification
1179Poisoning
1180ARP Table Attacks
1181Modification
1182Poisoning
1183Man-in-the-Middle Attack
1184Access-Control Lists Attacks
1185Switch-Specific Exploits
1186ARP Table
1187Modification
1188Poisoning
1189Man-in-the-Middle Attack
1190Media Access (MAC) Address Exploits
1191Changing a Host’s MAC
1192Duplicate MAC Addresses
1193Load-Balancing Device — Specific Exploits
1194Remote Access Device — Specific Exploits
1195Weak User Authentication
1196Same Account and Login Multiple Devices
1197Shared Login Credentials
1198Home User System Exploitation
1199Wireless Technology — Specific Exploits
1200Interception and Monitoring
1201Jamming
1202Insertion
1203Rogue Access Points
1204Unauthorized Clients
1205Client-to-Client Attacks
1206Media Access (MAC) Address
1207Duplicate IP Address
1208Improper Access Point Configuration
1209Service Set Identifier (SSID)
1210Default SSID
1211© 2004 by CRC Press LLC
1212SSID Broadcasting
1213Wired Equivalent Privacy (WEP) Exploits
1214Network Infrastructure Security and Controls
1215Defensive Strategy
1216Routing Protocol Security Options
1217Management Security Options
1218Operating System Hardening Options
1219Protecting Running Services
1220Hardening of the Box
1221Explicitly Shut Down All Unused Interfaces
1222Limit or Disable In-Band Access (via Telnet,
1223SSH, SNMP, Etc.)
1224Reset All Default Passwords
1225Use Encrypted Passwords
1226Use Remote AAA Authentication
1227Use Access Lists to Protect Terminal, SNMP,
1228TFTP Ports
1229Remote Login (Telnet) Service
1230SNMP Service
1231Routing Services
1232Limit Use of SNMP
1233Limit Use of Internal Web Servers Used
1234for Configuration
1235Disable Cisco Discovery Protocol (CDP)
1236on Cisco Gear Outside of the Firewall
1237Do Not Leak Info in Banners
1238Keep Up-to-Date on Security Fixes for
1239Your Network Infrastructure Devices
1240DoS and Packet Flooding Controls
1241Use IP Address Spoofing Controls
1242Watch for Traffic Where the Source
1243and Destination Addresses Are the Same
1244Enforce Minimum Fragment Size to Protect
1245against Tiny Fragment Attack, Overlapping
1246Fragment Attack, and Teardrop Attack
1247Disable IP Unreachables on External Interfaces
1248Disable ICMP Redirects on External Interfaces
1249Disable Proxy ARP
1250Disable IP Directed Broadcasts (SMURF Attacks)
1251Disable Small Services (No Service Small-Servers
1252UDP and No Service Small-Servers TCP)
1253Disable IP Source Routing (No IP Source-Route)
1254Use Traffic Shaping (Committed Access Rate)
1255Tools
1256© 2004 by CRC Press LLC
1257Configuration Audit and Verification Tools
1258Wireless Network Controls
1259Notes
1260References
1261Tools
1262Request for Comments (RFCs)
1263White Paper
1264Web References
1265PART III CONSOLIDATION
126616 Consolidating Gains
1267Overview
1268Consolidation (OS and Network Facilities)
1269Account and Privilege Management Facilities
1270Account Cracking
1271SMBCapture
1272Active Directory Privilege Reconnaissance
1273and Hacking
1274Built-In/Default Accounts, Groups,
1275and Associated Privileges
1276Finger Service Reconnaissance
1277Kerberos Hacking and Account Appropriation
1278Keystroke Logging
1279LDAP Hacking and LDAP Reconnaissance
1280Polling the Account Database
1281Social Engineering
1282Trojanized Login Programs
1283File System and I/O Resources
1284File System and Object Privilege Identification
1285File System (Operating System) Hacking
1286File Sharing Exploits
1287NFS (IP) Spoofing
1288SMBRelay
1289File Handle/File Descriptor Hacking
1290File System Device and I/O Hacking
1291File System Exploitation through
1292Application Vulnerabilities
1293Application-Based File System Hacking
1294Extended File System Functionality
1295and File System Hacking
1296Service and Process Management Facilities
1297Processes, Services, and Privilege Identification
1298Starting/Stopping Services and Executing
1299with Specific Privileges
1300© 2004 by CRC Press LLC
1301API, Operating System, and Application
1302Vulnerabilities
1303Buffer Overflows, Format String,
1304and Other Application Attacks
1305Debugging Processes and Memory Manipulation
1306Inter-Process Communication (IPC), Named Pipe,
1307and Named Socket Hacking
1308Devices and Device Management Facilities
1309Devices and Device Management Hacking
1310Keystroke Logging
1311Packet Sniffing
1312Libraries and Shared Libraries
1313Library (and Shared Library) Hacking
1314Shell Access and Command Line Facilities
1315Shell Hacking
1316Registry Facilities (NT/2000)
1317Registry Hacking
1318Client Software
1319Client Software Appropriation
1320Listeners and Network Services
1321Account/Privilege Appropriation via
1322a Vulnerable Network Service
1323NetBIOS/SMB Reconnaissance
1324Network Information Service (NIS) Reconnaissance
1325NIS Hacking
1326SNMP Reconnaissance
1327Network Trust Relationships
1328Account Cracking
1329IP Spoofing
1330Token Capture and Impersonation
1331Application/Executable Environment
1332Consolidation (Foreign Code)
1333Trojans
1334Backdoors (and Trojan Backdoors)
1335Backdoor Listeners
1336Backdoor Applications
1337Rootkits
1338Kernel-Level Rootkits
1339Security
1340Mapping Exploits to Defenses
1341Notes
1342References and System Hardening References
1343Texts
1344Web References
1345© 2004 by CRC Press LLC
1346System Hardening References
1347Windows NT/2000
1348UNIX Platforms
134917 After the Fall
1350Logging, Auditing, and IDS Evasion
1351Logging and Auditing Evasion
1352Windows NT/2000 Logging/Auditing Evasion
1353IP Spoofing
1354Account Masquerading
1355Deletion/Modification of Log File Entries
1356Deletion of Log Files
1357Disabling Logging
1358Controlling What Is Logged
1359Manipulation of Audit Options
1360Deletion or Update of Audit Files
1361UNIX Platforms
1362UNIX Logging/Auditing Evasion
1363IP Spoofing
1364Account Masquerading
1365Deletion/Modification of Log File Entries
1366Deletion of Log Files
1367Disabling Log Files
1368Controlling What Is Logged
1369Manipulation of Audit and Accounting Options
1370Deletion or Update of Audit Files
1371Routers (Cisco)
1372AAA Protocols (RADIUS, TACACS)
1373Centralized Logging Solutions (Syslog)
1374IP Spoofing
1375Account Masquerading
1376Deletion/Modification of Log File Entries
1377Deletion of Log Files
1378Disabling Log Files
1379Controlling What Is Logged
1380IDS Evasion
1381Forensics Evasion
1382Environment Sanitization
1383Sanitizing History Files
1384Sanitizing Cache Files
1385File Hiding and File System Manipulation
1386Operating System File Hiding Techniques
1387Alternate Data Streams (NT/2000/XP)
1388Steganography
1389Cryptography
1390© 2004 by CRC Press LLC
1391Covert Network Activities
1392Covert TCP
1393“Normalizing†Traffic (Covert Shells)
1394ICMP Covert Tunneling
1395Investigative, Forensics, and Security Controls
1396Mapping Exploits to Defenses
1397Centralized Logging and Archival of Log File Data
1398Centralized Reporting and Data Correlation
1399Encryption of Local Log File Data
1400Establishment of Appropriate Access Controls
1401for Log Files
1402Implementation of Tools for Remote Monitoring
1403of Log Files
1404Patches and Software Updates
1405Process Monitoring for Logging Services
1406Regular File System Audits
1407Strict Management of Audit and
1408Accounting-Related Privileges
1409Traffic Encryption for Syslog Packet Data
1410Notes
1411References
1412Texts
1413Web References
141418 Conclusion
1415Conclusion: Case Study in Subversion
1416Dalmedica’s Perspective
1417Access Points
1418Bastion Hosts
1419Reconnaissance Activity
1420Target Systems
1421Conclusion (Final Thoughts)
1422References
1423Areas of Focus
1424General Hacking and Security Resources
1425Authentication Technologies
1426Cryptography
1427DNS and Directory Services
1428Network Management
1429Route/Switch Infrastructures
1430Storage Networking
1431Voice over IP
1432Wireless Networks
1433Notes
1434© 2004 by CRC Press LLC
1435Chapter 1
1436Introduction:
1437The Chess
1438Game
1439When you see a good move, look for a better one.
1440— Emanuel Lasker
1441Chess, like any creative activity, can exist only through the combined
1442efforts of those who have creative talent and those who have the ability
1443to organize their creative work.
1444— Mikhail Botvinnik
1445Good offense and good defense both begin with good development.
1446— Bruce A. Moon
1447Botvinnik tried to take the mystery out of chess, always relating it to sit-
1448uations in ordinary life. He used to call chess a typical inexact problem
1449similar to those which people are always having to solve in everyday life.
1450— Garry Kasparov
1451A chess game is a dialogue, a conversation between a player and his
1452opponent. Each move by the opponent may contain threats or be a
1453blunder, but a player cannot defend against threats or take advantage
1454of blunders if he does not first ask himself: What is my opponent plan-
1455ning after each move?
1456— Bruce A. Moon
1457© 2004 by CRC Press LLC
1458In many ways, this is almost the hardest chapter to pen in this book; in writ-
1459ing this, I am forced to relive the many occasions on which I have stood in
1460a bookstore leafing through a technical book, trying to determine its value
1461to the technical “excursion†I am currently embarked on. I generally start
1462with the preface … (sigh). For this particular book, putting together an
1463accurate, representative preface is a daunting task;
1464The Hacker’s Handbook
1465was deliberately constructed as a multifaceted text.
1466Let me try — this book is about hacking, yes, but it is also weighted
1467towards the security community. At the time when the authors started
1468framing the book (May 2001), a significant number of books on the subject
1469of digital hacking and security had already been published. In an effort to
1470make some “space†for this book, we reviewed many of them and came to
1471the conclusion that there was room for a book that adopted an analytical
1472perspective on hacking and security and attempted to inform readers
1473about the technical aspects of hacking that are, perhaps, least understood
1474by system, network, and security administrators.
1475To this end, we compiled a list of objectives that truly informed the way
1476in which this book was constructed:
1477•
1478Chapters should maintain a dichotomy between hacking and security,
1479intended to inform the reader’s understanding of both. Most
1480chapters are deliberately broken into (1)
1481technical
1482(background),
1483(2)
1484hacking
1485, and (3)
1486security
1487sections; the intent of this approach
1488is to inform the way in which administrators defend systems and
1489networks by exploring hacking exploits and defenses in the same
1490technical context.
1491•
1492Chapters should be organized around specific technical and adminis-
1493trative components
1494(e.g., specific services such as SMTP, HTTP, DNS,
1495directory services and specific administrative tasks, system harden-
1496ing, forensics investigation, etc.), to facilitate using the book as a
1497technical security reference. If you are a DNS administrator, for
1498example, you should be able to quickly locate material relevant to
1499DNS hacking and DNS security.
1500•
1501There should be an emphasis on providing a sound technical and
1502conceptual framework
1503that readers can apply throughout the book.
1504Key foundation chapters address the following:
1505– Attack anatomy (Chapter 4)
1506– Security technologies (Chapter 5)
1507– Programming (Chapter 6)
1508– Transmission Control Protocol/Internet Protocol (TCP/IP) attacks
1509(Chapters 7 and 8)
1510– Postattack consolidation (Chapters 17 and 18)
1511•
1512The book should maintain a dual perspective on theory and tools,
1513intended to provide a rounded approach to the subject matter. Each
1514© 2004 by CRC Press LLC
1515chapter is organized to provide an appropriate theoretical founda-
1516tion for the chapter material as a frame of reference for the reader.
1517Tools, exploit code, and hacking “techniques†are analyzed in this
1518context but with sufficient latitude to reinforce the fact that hacking
1519is still a “creative†activity.
1520•
1521Chapters should provide detailed reference material
1522to provide a
1523“path†for readers to continue to augment their knowledge of the
1524field and act as a guide to consolidating the sheer volume of hacking
1525and security information available through the Internet and other
1526resources. Providing this information is also intended to ensure that
1527the technical material presented in this book is enduring.
1528As indicated, the book is oriented toward systems, network, and security
1529administrators with some degree of security experience who are looking to
1530expand their knowledge of hacking techniques and exploits as a means of
1531informing their approach to systems and network security. This orienta-
1532tion makes for a fairly broad audience and is reflected in the breadth of the
1533material presented. To ensure that the book delivers on this objective,
1534each chapter contains a table mechanism and chapter section that delib-
1535erately “maps†hacking exploits to prospective defenses, and each chapter
1536ends with a treatment of prospective security defenses.
1537The only practical limitation to the book material is that the authors
1538chose to focus on the Microsoft Windows NT/2000 and UNIX platforms;
1539the volume and depth of technical material presented in the book necessi-
1540tated setting some scope constraints. The authors felt that there might be
1541value in limiting the range of platforms represented in the text to add more
1542technical depth to the application hacking material. Rather than under-
1543representing platforms such as Novell or Mainframe/Midrange, the deci-
1544sion was made to exclude them altogether.
1545To reinforce the positioning of hacking and security material in the book,
1546a “chess game†analogy has been played throughout the material (none of
1547the authors, by the way, are particularly good chess players). The dynamics
1548and strategy of chess were thought by the authors to have several parallels
1549with the subject matter presented in this book:
1550• As with many other strategic games, the success of either party in
1551the chess game depends upon that party’s ability to enhance his or
1552her skills relative to his or her opponent’s.
1553• Chess players engage, to varying extents, in an attempt to predict
1554the moves of their opponents so that they can prevail and checkmate
1555their opponents.
1556• Chess is essentially a game of move and countermove; hacking and
1557security tactics can be conceived of in the same manner.
1558• Defensive strategies exist in hacking and security, but an aggressive
1559and creative attacker can overcome them.
1560© 2004 by CRC Press LLC
1561• Offensive strategies also exist, but intelligent and vigilant defenders
1562can counter them.
1563• Poorly executed plans or rigid adherence to a plan is less effective
1564than learning and adjusting as the chess game progresses.
1565• The whole hacking vs. security “chess match†can turn upon a single
1566move.
1567Use of this analogy is also intended to credit the general hacking com-
1568munity for its resourcefulness in pursuing new types of vulnerabilities
1569and exploit code. It is not a perfect analogy (defenders generally do not
1570attack their attackers, for example), but it is pretty close. The chess game
1571theme has been reinforced in this book through the incorporation of a
1572series of illustrations (by Trevor Young) that lend some art (and humor)
1573to the subject matter.
1574Susan Young
1575March 2003
1576Book Structure
1577The Hacker’s Handbook
1578has been organized into several sections to aid the
1579reader’s understanding of the material being presented (see Exhibit 1).
1580The first part of the book (
1581Part I. Foundation Material
1582) introduces pro-
1583gramming, protocol, and attack concepts that are applied throughout the
1584book. The second part of the book (
1585Part II. System and Network Penetration
1586)
1587addresses specific subject areas (protocols, services, technologies, hack-
1588ing facilities, hostile code) that relate to system and network penetration.
1589The final part of the book (
1590Part III. Consolidation
1591) details the types of con-
1592solidation activities conducted by hackers once a system or network has
1593been successfully penetrated to establish and expand a “presence.â€
1594The following information provides a detailed breakdown on the con-
1595tent of each chapter.
1596Chapter 2. Case Study in Subversion
1597The concept behind this chapter is to present a case study that demon-
1598strates what a complex network attack looks like from an administrator’s
1599perspective. The conclusion (Chapter 18) to the book revisits the initial
1600case study material from an attacker’s perspective, leveraging the techni-
1601cal material presented throughout the book.
1602The case study adopts a couple of fictional characters (a hacker and net-
1603work administrator) and charts their moves as the attack unwinds using
1604system and device log files, screens, etc., and a fairly complex network
1605based around a reasonable security architecture.
1606© 2004 by CRC Press LLC
1607Chapter 3. Know Your Opponent
1608Chapter 3 presents a history of hacking and the different elements who
1609constitute the hacking community, providing a potential “profile†of a
1610hacker — script kiddie, hacker, cracker, competitor, political activist, cyber
1611terrorist, Gray Hat, Black Hat, etc.
1612This chapter is intended to provide some insight into hacking psychology
1613and hacking motivation.
1614Chapter 4. Anatomy of an Attack
1615Chapter 4 presents an “anatomy†of various types of attacks and a taxonomy
1616of the tools appropriated in the process. Five elements of attack strategy
1617are presented in a model that opens the chapter:
1618• Reconnaissance
1619• Mapping targets
1620• System or network penetration
1621• Denial-of-service
1622• Consolidation (consolidation tactics are discussed in detail in
1623Chapter 16)
1624Exhibit 1. Layout of
1625The Hacker’s Handbook
1626Chapter Title
1627Ch. 1 Introduction: The Chess Game
1628Part I Foundation Material
1629Ch. 2 Case Study in Subversion
1630Ch. 3 Know Your Opponent
1631Ch. 4 Anatomy of an Attack
1632Ch. 5 Your Defensive Arsenal
1633Ch. 6 Programming
1634Ch. 7 IP and Layer 2 Protocols
1635Ch. 8 The Protocols
1636Part II System and Network Penetration
1637Ch. 9 Domain Name System (DNS)
1638Ch. 10 Directory Services
1639Ch. 11 Simple Mail Transfer Protocol (SMTP)
1640Ch. 12 Hypertext Transfer Protocol (HTTP)
1641Ch. 13 Database Hacking
1642Ch. 14 Malware and Viruses
1643Ch. 15 Network Hardware
1644Part III Consolidation
1645Ch. 16 Consolidating Gains
1646Ch. 17 After the Fall
1647Ch. 18 Conclusion
1648© 2004 by CRC Press LLC
1649“Generic†types of attack are briefly overviewed in this chapter as con-
1650text for the technical chapters that follow, including account attacks,
1651buffer overflows, denial-of-service, session hijacking, spoofing, etc.
1652Each chapter segment concludes with a “Tools†section that provides a
1653table of references to applicable tools and pointers to source code and Web
1654references.
1655Chapter 5. Your Defensive Arsenal
1656This chapter dissects the tools employed by administrators to defend a
1657networked environment and examines the vulnerabilities and types of
1658exploits each are prone to.
1659The following framework is used to organize the security technologies
1660presented in the chapter:
1661• Access control
1662• Authentication
1663• Auditing and logging
1664• Resource controls
1665• Nonrepudiation
1666• Privacy
1667• Intrusion detection
1668• Data integrity
1669• Platform integrity
1670Chapter 6. Programming
1671Chapter 6 is a technical “foundation†chapter and could be considered the
1672technical complement of the “Protocols†chapters that follow. The chapter
1673addresses the programming flaws exploited by attackers in constructing
1674exploit code and the methodology and programming facilities they draw
1675upon in building a hacking exploit.
1676Written for the nonprogrammer, the chapter details various types of
1677compiled and interpreted languages and investigates the following types of
1678programming deficiencies and hacking facilities:
1679• Language-specific flaws
1680• Buffer overflows and memory allocation errors
1681• Format string bugs
1682• Interpreter bugs
1683• Canonicalization attacks
1684• Logic errors
1685• Platform-specific security issues
1686• Web application issues
1687• Remote procedure call (RPC) vulnerabilities
1688© 2004 by CRC Press LLC
1689The chapter ends by examining different programming mindsets, what
1690“pits†programmer against programmer, and tools available to software
1691programmers for validating the security of the software they develop.
1692Chapter 7. IP and Layer 2 Protocols
1693Chapter 8. The Protocols
1694The Protocols chapters focus on the TCP/IP protocols and examine some
1695of the “generic†TCP/IP exploits and denial-of-service attacks and defenses
1696against them. Specific protocol material, in some instances, is deferred to
1697later chapters. The chapters focus on the fundamental vulnerabilities in
1698TCP/IP that are exploited by hackers and some of the ongoing IP security
1699initiatives intended to address these.
1700Each protocol is examined using the OSI reference model as context:
1701• Layer 2 protocols: Address Resolution Protocol (ARP), Reverse
1702Address Resolution Protocol (RARP)
1703• Layer 3 protocols: Internet Protocol (IP), Internet Control Messaging
1704Protocol (ICMP); routing protocols such as Routing Information
1705Protocol (RIP), Open Shortest Path First (OSPF), Enhanced Interior
1706Gateway Routing Protocol (EIGRP), and Border Gateway Protocol
1707(BGP) are overviewed in the chapter “Network Hardwareâ€
1708(Ch. 15); IP
1709Security Protocol (IPSec) is detailed in “Your Defensive Arsenal†(Ch. 5)
1710• Layer 4 protocols: Transmission Control Protocol (TCP), User Data-
1711gram Protocol (UDP)
1712• Layer 5 protocols: Secure Sockets Layer (SSL) addressed in “Your
1713Defensive Arsenal†(Ch. 5)
1714• Layer 7 protocols: Each addressed in its respective chapter (DNS,
1715HTTP, Lightweight Directory Access Protocol [LDAP], Open Database
1716Connectivity [ODBC], Remote Procedure Call [RPC], SMTP, Simple
1717Network Management Protocol [SNMP], Structure Query Language
1718[SQL], etc.)
1719A great deal of material is dedicated to the IP protocol, which has some
1720fundamental security flaws that allow it to be used as a transport for net-
1721work attacks.
1722Chapter 9. Domain Name System (DNS)
1723The focus of this chapter is the Domain Name System, which is treated as
1724a critical Internet “directory†service and a fragile link in Internet secu-
1725rity. This chapter explores the significance of DNS as a target for hacking
1726activity and denial-of-service and its appropriation in the construction of
1727reconnaissance and application attacks. The following types of exploits
1728are examined in the chapter:
1729© 2004 by CRC Press LLC
1730• Reconnaissance attacks
1731• Cache poisoning
1732• Application attacks
1733• Denial-of-service
1734• Dynamic name registration hacking
1735• Client/server spoofing
1736• Name server hijacking
1737The final section of this chapter provides a set of tools for securing, sub-
1738stantiating, and monitoring a name service infrastructure and includes
1739information on split-level DNS implementations, name server redundancy,
1740dynamic client security, and the use of digital signatures to secure name
1741server content.
1742Chapter 10. Directory Services
1743This chapter provides information on the various types of directory services
1744in common use on networks and the types of hacking and reconnaissance
1745exploits to which each is prone. The following directory services and direc-
1746tory service protocols are discussed in some detail:
1747• Microsoft Active Directory
1748• LDAP
1749• X.500 directory services
1750As with prior chapters, this chapter explores some of the generic
1751types of hacking exploits leveraged against directory services and the
1752specifics of vulnerabilities in particular implementations. The chapter
1753also overviews directory security and examines directory security in
1754the context of specific applications of directory services (such as public
1755key infrastructure).
1756Chapter 11. Simple Mail Transfer Protocol (SMTP)
1757Chapter 11 analyzes the Simple Mail Transfer Protocol (SMTP) as a core
1758Internet and private network service and a significant “vector†for the propa-
1759gation of malicious code and the construction of denial-of-service attacks.
1760Key vulnerabilities in the SMTP protocol are detailed as context for the
1761hacking material, and mail hacking is explored through the dissection of a
1762variety of attacks, exploit code, and packet data, including:
1763• Mail eavesdropping and reconnaissance
1764• ESMTP hacking
1765• Denial-of-service
1766• Mail spamming and relaying
1767• Mail spoofing
1768• MIME hacking
1769© 2004 by CRC Press LLC
1770The conclusion to the chapter addresses the facilities available to
1771administrators for hardening SMTP servers and some of the SMTP security
1772initiatives intended to address specific vulnerabilities in the protocol
1773(such as Secure/Multipurpose Internet Mail Extensions [S/MIME]).
1774Chapter 12. Hypertext Transfer Protocol (HTTP)
1775The HTTP chapter addresses the significance of HTTP as a hacking target
1776in light of the advent of Internet commerce and the transport of a variety
1777of sensitive personal and commercial data via HTTP. HTTP servers are fre-
1778quently used to provide an accessible Web front-end to complex, back-end
1779database and custom applications, affording hackers a “conduit†through
1780which to mount application and data reconnaissance attacks.
1781HTTP hacking is explored through dissection of the following types of
1782attacks:
1783• Eavesdropping and reconnaissance
1784• Account cracking and authentication credential capture
1785• HTTP method exploits (POST, PUT, etc.)
1786• HTTP cache exploits
1787• Denial-of-service
1788• Directory traversal attacks
1789• Session ID hacking
1790• Man-in-the-middle attacks
1791The chapter concludes by examining HTTP security mechanisms such as
1792SSL, caching controls, digital certificate or signature security, and session ID
1793security options.
1794Chapter 13. Database Hacking
1795Database hacking and database security represent an enormous body of
1796material. This chapter focuses on vulnerabilities in specific types of data-
1797base technologies (SQL Server, Oracle, MySQL) to illustrate some basic
1798points about database hacking and data security. General themes include:
1799• SQL injection
1800• Overflows
1801• Exploitation of default accounts
1802Representative database applications and examples are drawn upon to
1803add “depth†to the material and to document the process of identifying and
1804exploiting a vulnerable database application.
1805Chapter 14. Malware and Viruses
1806This chapter addresses various forms of hostile code that can be used to
1807achieve denial-of-service, data destruction, information capture, or intrusion.
1808Definitions are provided for each type of malware for context. These include:
1809© 2004 by CRC Press LLC
1810• Viruses
1811• Worms
1812• Hoaxes
1813• Backdoors
1814• Logic bombs
1815• Spyware
1816• Adware
1817The chapter also details some of the programming and scripting lan-
1818guages and application facilities that are used to produce hostile code.
1819Chapter 15. Network Hardware
1820Chapter 15 addresses vulnerabilities in network hardware and associated
1821firmware, operating systems, and software. The chapter opens with a
1822broad discussion of the growing significance of network hardware (routers,
1823switches, etc.) as a target for hacking activity and by providing a broad
1824overview of the types of hacking exploits to which each hardware compo-
1825nent (hardware, firmware, software) is susceptible:
1826• Attacks against routing or switching infrastructures
1827• Routing protocol attacks (RIP, OSPF, etc.)
1828• Management attacks (SNMP, HTTP, etc.)
1829• Operating system/Internet operating system (OS/IOS) attacks
1830• Denial-of-service
1831• Wireless hacking
1832• Packet switching attacks
1833• Remote access attacks
1834• Attacks against redundant network components
1835The final chapter section addresses the security options in network
1836hardware, protocol, management, and operating system (OS) facilities that
1837can be leveraged to harden a network device or network, including packet
1838flooding controls, wireless network security, OS/IOS hardening, routing
1839protocol access control lists, and authentication controls.
1840Chapter 16. Consolidating Gains
1841Chapter 16 is the first of two chapters to address the tactics and tools
1842employed by attackers to consolidate their position on a system or net-
1843work — essentially, the tasks that are undertaken by attackers to ensure
1844consistent, covert access to a system or network resource or to extend
1845their privileges as they relate to that resource. It demonstrates the effec-
1846tiveness of the hacking community’s knowledge of common system
1847administration practices, standard system builds, and default application
1848configurations; the intent of this chapter is to attempt to inform the way
1849in which system and network administrators approach the management
1850of these facilities from a “counter-tactics†perspective.
1851© 2004 by CRC Press LLC
1852Consolidating Gains explores the use of standard operating systems and
1853network facilities for consolidation activities, in addition to the application
1854of “foreign†exploit code:
1855• Standard OS and network facilities
1856– Account and privilege management facilities
1857– File system and input/output (I/O) resources
1858– Service management facilities
1859– Process management facilities
1860– Devices and device management facilities
1861– Libraries and shared libraries
1862– Shell access and command line interfaces
1863– Registry facilities (NT/2000)
1864– Client software
1865– Listeners and network services
1866– Network trust relationships
1867– Application environment
1868• Foreign code
1869– Trojan horses
1870– Backdoors (including Trojan backdoors)
1871– Rootkits
1872– Kernel-level rootkits
1873The closing section of the chapter presents a collection of procedures
1874and tools that can be used to stem consolidation activities; the focus of this
1875material is cross-platform system hardening strategy.
1876Chapter 17. After the Fall
1877After the Fall addresses forensics evasion and forensics investigation.
1878From a hacking perspective, this includes the techniques and tools hack-
1879ers employ to evade audit or logging controls and intrusion detection
1880mechanisms, as well as covert techniques used to frustrate investigative
1881actions and avoid detection. For the system or network administrator, a
1882considerable amount of material on the preparations that should occur
1883prior to a security incident is presented, along with measures for protect-
1884ing audit trails and evidence.
1885The following types of hacking exploits are addressed:
1886• Logging and auditing evasion (by platform): NT/2000; UNIX; router;
1887authentication, authorization, and accounting (AAA) protocols, etc.
1888• Intrusion detection system (IDS) evasion (linked to material in
1889Chapter 5, “Your Defensive Arsenalâ€)
1890• Forensics evasion
1891– Environment sanitization
1892– File hiding (including steganography, cryptography) and file
1893system manipulation
1894– Covert network activities (including IP tunneling, traffic normali-
1895zation)
1896© 2004 by CRC Press LLC
1897The chapter closes with an examination of the types of tools and tactics
1898security administrators can leverage to improve capabilities to detect and
1899investigate security incidents, including protections for log files and audit
1900trails, IDS, data correlation solutions, forensics technologies, and incident
1901handling capabilities.
1902Chapter 18. Conclusion
1903The final chapter of
1904The Hacker’s Handbook
1905reviews the case study material
1906presented in Chapter 2 in the context of the technical material presented
1907throughout the book. The case study is examined from the attacker’s per-
1908spective and from the perspective of a network administrator investigating
1909the incident.
1910The chapter concludes with a set of references that supplement the
1911references provided at the end of each chapter:
1912• Security sites
1913• “Underground†sites
1914• Technical standards
1915• Ongoing technical “themes†in hacking and security
1916© 2004 by CRC Press LLC
1917Part I
1918Foundation
1919Material
1920© 2004 by CRC Press LLC
1921Chapter 2
1922Case Study
1923in Subversion
1924This case study — really the “chess game†at work — is unique among the
1925chapters presented in this book. The case study examines the actions of a
1926fictitious administrator, hacker, and investigator in the context of a series
1927of security events that beset a fictional company (Dalmedica). These
1928events are depicted from a “defensive†standpoint — from the standpoint
1929of the administrator and investigator trying to make sense of them — using
1930a “real†network. The network, systems, and application environment cho-
1931sen for the case study is dynamic, transitions over the course of the study
1932timeline, and is representative of a reasonably sound security design. The
1933events that occur are illustrations of hacking exploits and attacks presented
1934in the remainder of the book but are represented from a “symptomatic†per-
1935spective; later chapters illuminate and explain the types of attacks alluded
1936to in the case study.
1937This chapter is paired with the Conclusion (Chapter 18) of the book,
1938which revisits the case study material from the attacker’s perspective.
1939Dalmedica
1940Dalmedica is a (fictitious) six-year-old public corporation that develops
1941software for the medical industry. Its most recent software development
1942venture — due for release at some point over the next three months —
1943involves a product called Medicabase that assists medical researchers in
1944analyzing, correlating, and securing patient data as part of clinical trial
1945management. Dalmedica has been aggressively marketing some of the
1946concepts behind Medicabase for some time, and the software has become
1947somewhat controversial because of the “hooks†it potentially provides third
1948parties into patient clinical data. Competitors have shown interest in the
1949product from a competitive standpoint because of its technological
1950advances and have been scouting for ways to further some of the “politicalâ€
1951controversy surrounding the product in the hopes that this will negatively
1952impact sales and market share once it goes to market.
1953Dalmedica operates a medium-sized network of some 650 nodes (see
1954Exhibit 1). The company went through a significant network efficiency
1955© 2004 by CRC Press LLC
1956assessment and reorganization two years ago, and the internal network is
1957(for the most part) fully switched and organized into virtual local area net-
1958works (VLANs) that correspond with operational domains (development,
1959quality assurance [QA], finance, etc.). The security architecture consists of
1960Exhibit 1. Network Diagram
1961IDS
1962Stateful Packet Filtering
1963Firewall
1964VPN Server
1965SMTP Gateway
1966(Anti-Virus and
1967Content Filtering)
1968Web Farm
1969Web Content
1970Filtering
1971Gateway
1972Private LAN (172.30.0.0/16)
1973INTERNET
1974ISP-Managed Router
1975Internet DMZ
1976Load Balancing Device
1977IDS
1978Dial-up Server
1979Extranet DMZ
1980Partner Extranet
1981Application Proxy Firewall
1982(Primary (Public) DNS Server)
1983204.70.10.240/29 (Publicly Addressed IP Network)
1984204.70.10.208/28 (Publicly Addressed IP Network)
1985204.70.10.224/28
1986(Publicly
1987Addressed IP
1988Network)
1989204.70.10.192/28 (Publicly Addressed IP Network)
1990Partner Network Connection
1991Partner Net
1992(Router ACLs)
1993Server Network
1994(Fully Switched)
1995DNS Server(s)
1996(Primary and
1997Secondary)
1998Active Directory/
1999Domain Controller
2000(and Backup Domain
2001Controllers)
2002Corporate
2003Mail Server
2004IDS
2005Database
2006Servers
2007Corporate LAN
2008(Switched to the Desktop)
2009Clients, Printers, etc.
2010(500 nodes)
2011QA/Development LAN
2012(Fully Switched)
2013Clients
2014Development Servers
2015(UNIX/NT)
2016Syslog
2017Server
2018.246
2019.241
2020.245
2021.228, .229, .230
2022.208
2023.224
2024.193
2025.221
2026.194, .195
2027.209
2028.210 .211
2029172.30.0.1
2030© 2004 by CRC Press LLC
2031a two-tier firewall environment (stateful perimeter firewall, application-
2032level local area network [LAN] firewall), with network-based intrusion
2033detection systems (IDSs) in place at the Internet connection, on the Web
2034demilitarized zone (DMZ), and on the private LAN. Dalmedica uses a split-
2035level (public vs. private) Domain Name System (DNS) configuration
20361
2037and
2038has implemented a mail gateway and content scanning gateway that scan
2039all mail and Web content exiting or entering the main corporate LAN. Log-
2040ging is centralized via a syslog server (although local logging is still per-
2041formed on a number of systems) and a Microsoft Active Directory/Domain
2042architecture has been established to authenticate users to specific
2043resources on the network.
2044From an administrative perspective, network, systems, and application
2045administration is divided among several technical groups that fall under the
2046corporate information technology (IT) function. Security management is
2047performed by a parallel organization that consists of policy and technology
2048branches and interfaces with respective groups within IT. IT and security
2049operations are primarily integrated via the corporate incident handling
2050team, which meets on a regular basis to inspect and respond to vulnerability
2051reports and security threats. Web and operations application development
2052is considered a development function and is managed within the develop-
2053ment organization, subject to the same development and QA process as
2054product software development.
2055Dalmedica leverages consultants for specific project tasks and contracts
2056an outside security consulting firm to perform a periodic annual security
2057risk assessment and to conduct external and extranet penetration test-
2058ing, as deemed appropriate. Dalmedica security management also has the
2059ability to call in specialists, such as forensic specialists or criminal investi-
2060gators, where necessary, although the company has never had cause to
2061do this.
2062The Dilemma
2063Scott Matthews was confused by what was happening. Within the last ten
2064minutes, two critical problems had emerged on the network: no network
2065clients could get out to the Internet, and Internet users were having prob-
2066lems accessing Dalmedica’s Web servers. His first instinct was that it was
2067a connectivity problem, and so he telnet-ed to Dalmedica’s Internet
2068router, ran a series of ICMP connectivity tests to the next hop router and
2069arbitrary Internet sites, and placed a call to EnterISP, Dalmedica’s Internet
2070service provider.
2071“Hi, this is Scott Matthews, network operations manager for Dalmedica.
2072We’re seeing some Internet connectivity problems that I was wondering if
2073you could help me investigate?†The technician worked with Scott in
2074inspecting packet response times to and from Dalmedica’s Internet handoff
2075© 2004 by CRC Press LLC
2076and identified that there was some latency and congestion not just on
2077Dalmedica’s Internet link but also on associated areas of EnterISP’s network.
2078Traceroutes to Dalmedica’s Internet router revealed the following:
2079$ traceroute gw.dalmedica.com
2080tracing route to gw.dalmedica.com (204.70.10.246), 30 hops
2081max
20821 gw1.enterisp.net (211.198.12.30) 5.412ms 5.112ms 5.613ms
20832 core1.enterisp.net (211.197.22.15) 30.160ms 34.576ms
208434.180ms
20853 core2.enterisp.net (210.105.60.17) 770.433ms 890.899ms
2086920.891ms
20874 gw.Dalmedica.com (204.70.10.246) * * * Request timed out.
2088“Scott, let me examine this a little further, and I’ll get back to you,†the
2089technician responded. Scott and the technician exchanged contact informa-
2090tion and hung up. Scott sat back in his chair, paged through the messages on
2091his pager and thought for a second. Returning access to the corporate Web
2092servers was probably the highest priority — perhaps it was worthwhile
2093taking a couple of seconds to examine the firewall log files. He started a
2094session to the corporate application proxy firewall using a firewall manage-
2095ment client and inspected the current log file. What he saw startled him —
2096hundreds of DNS connection requests for domains for which the firewall
2097(Dalmedica’s primary/public DNS server) was not authoritative. “**?%~!,â€
2098he exclaimed, “a denial-of-service attack?â€
20992
2100A bevy of source addresses
2101was associated with the recursive DNS requests; Scott performed a couple
2102of DNS IP-to-hostname lookups using nslookup to try to identify some of
2103them. A portion returned hostnames:
21043
2105nslookup
2106Default server: ns1.enterisp.net
2107Address: 210.10.10.249
2108> set q = ptr
2109> 8.60.122.199.in-addr.arpa
21108.60.233.199.in-addr.arpa Name = bandit.mischevious.com
2111> 9.150.17.66.in-addr.arpa
21129.150.17.66.in-addr.arpa Name = rogue.outasitecollege.edu
2113“Oh, this looks worse and worse.†He was just considering his next move
2114(and expletive) when his manager popped his head around the door.
2115“Scott, what’s going on?†questioned Bob.
2116Scott responded with “Someone is mounting what appears to be a
2117denial-of-service against us, but I think I can stem it by turning off support
2118for Internet recursion at the firewall.
21193
2120I’ll still need to contact EnterISP to
2121© 2004 by CRC Press LLC
2122see if they can help me stem any associated packet flooding. Also, our desk-
2123tops don’t seem to be able to get out to the Internet; this may be a related
2124problem due to the link congestion.â€
2125“Well, whatever it is, we need to get to the bottom of it quickly,†stated
2126Bob, “Tom Byrd just informed me that marketing is getting ready to put out
2127a preliminary press release on Medicabase this morning, and they’ll be
2128posting a link to additional information on our Web site. Let me know if you
2129get stalled with this…â€
2130Scott visibly sank in his chair — it was days like this when he wished
2131he had abandoned a technical career and taken up something “safe†such
2132as vertical freefall skydiving. He focused, turned back to the firewall, and
2133disabled support for Internet recursion — this would have no impact on
2134Dalmedica Web site access but would prevent the attacker from being
2135able to force the firewall/name server to perform exhaustive Internet
2136lookups on behalf of anonymous hosts. Performance at the firewall
2137seemed to leap as the change was successfully written out.
2138Scott turned to his phone and called the head of the security incident
2139handling team — Mike Turner — and informed him that he thought he had a
2140security incident on his hands. “OK, keep calm,†stated Mike (in a panicked
2141voice), “I’ll contact a couple of people and we’ll start an investigation to
2142determine if this is a legitimate incident.â€
2143Dalmedica’s LAN clients were still experiencing problems accessing the
2144Internet — Scott noted that there was an absence of the general HTTP
2145“clutter†he was used to seeing in the firewall log files. He waited a minute,
2146willing the screen to start popping client HTTP requests — nothing. “Ah,
2147there’s one,†he exclaimed, as a lone entry populated the log file, “Hmmm…
2148something’s not right here...†He swung around in his seat to a server
2149sitting next to him, and started a browser session to an Internet Web site
2150(see Exhibit 2).
2151Scott was confounded. He went to the command prompt on the system,
2152fired up nslookup and tried performing DNS lookups for some well-known
2153Internet sites:
2154C:\>nslookup
2155DNS request timed out.
2156timeout was 2 seconds.
2157*** Can't find server name for address 210.10.10.249: Timed
2158out
2159*** Default servers are not available
2160Default Server: UnKnown
2161Address: 210.10.10.249
2162© 2004 by CRC Press LLC
2163> set q = any
2164> www.enterisp.net
2165Server: UnKnown
2166Address: 210.10.10.249
2167*** UnKnown can't find www.enterisp.net: No response from
2168server
2169>
2170As each successive DNS request failed, he sagged. Scott swung back to
2171the firewall, launched a command prompt, and used nslookup to perform
2172some DNS lookups. Every DNS request he issued from the firewall received
2173a successful response. Intrigued, Scott pondered the problem for a second.
2174He checked the resolver configuration on the “test†client as a sanity check
2175and concluded that it was possible that this was a separate problem from
2176the DNS denial-of-service and that it was worth inspecting the configura-
2177tion and logs on the internal DNS server. The log on the internal DNS server
2178revealed the following:
2179a.root-servers.net. 198.41.0.4 Can’t contact root NS:
2180a-root.servers.net
2181b.root-servers.net. 128.9.0.107 Can’t contact root NS:
2182b-root.servers.net
2183c.root-servers.net. 192.33.4.12 Can’t contact root NS:
2184c-root.servers.net
2185Exhibit 2. Failed Attempt to Connect
2186© 2004 by CRC Press LLC
2187Scott shook his head. What was this? Had anyone performed any recent
2188updates to the DNS server? A cursory inspection of the log didn’t reveal
2189anything. He placed a call to the group responsible for DNS and IP manage-
2190ment within IT/systems and requested some assistance in investigating the
2191problem. “Check the root name server hints file, which is located at
2192c:\winnt\system32\dns,†responded the administrator. “It should point to
2193the corporate firewall because we’re proxying DNS connections to the
2194firewall.†Scott reviewed the contents of the file.
2195“It looks like a standard root name server hints file to me,†he stated.
2196“It contains a list of all of the Internet Root name servers and their respec-
2197tive IP addresses.â€
2198The DNS administrator was perplexed. “Well, there’s your problem.
2199I don’t know who would have reverted the configuration, but you need to
2200stop the DNS server, rename that file, and replace it with a file that uses the
2201firewall’s inside interface as a root NS — that should solve the problem.â€
2202Scott accomplished the necessary changes and saw the firewall log file
2203“leap†with the familiar HTTP clutter. He breathed a sigh of relief and
2204picked up the phone to call his manager and report a successful return to
2205normal operations. At that moment, Mike Turner, the head of the security
2206incident team, appeared behind him. “So Scott, how are we doing?â€
2207“Well, we’re back to normal,†stated Scott, “…but I’d be grateful if you’d
2208work with our ISP to try to determine who was mounting the DNS denial-of-
2209service — I’m going to grab some coffee.â€
2210***
2211Later that day, as Scott was returning from a long lunch and passing the
2212development lab, he spotted a number of engineers and the development
2213lab administrator crouched around a single terminal. He swiped his badge
2214at the lab card reader and swept into the lab. “Hi guys, what’s going on?†he
2215asked cheerfully, to the pained expressions in front of him.
2216“We’re not sure yet,†replied one of the engineers. “It looks like we’re
2217having a problem with some library corruption in one of the libraries on
2218the source code server.â€
2219“Can we recover?†asked Scott.
2220“Well, we can…†the source code librarian, Neil Beck responded, “…but I’d
2221like to figure out how it happened so that we can prevent it from recurring.â€
2222Scott nodded. He exited the server room and headed to a nearby confer-
2223ence room for a management meeting to discuss the morning’s events. The
2224ISP had not been able to trace the absolute source of the denial-of-service
2225attack that occurred that morning but had gathered sufficient information
2226to indicate that the attack was well organized and executed, and that it
2227© 2004 by CRC Press LLC
2228specifically targeted Dalmedica. As the meeting’s members speculated about
2229the perpetrator(s) of the attack, one of the engineers stuck his head around
2230the door of the conference room. “Scott, can I borrow you for a second?â€
2231Things were starting to look kind of grim.
2232“Well, we didn’t think anything of the library corruption until we started
2233to uncover some evidence that other files in the file system had been
2234manipulated,†the engineer said. “Specifically, portions of our CVS-managed
2235source code have been checked out using an unauthorized account.â€
2236Scott stopped in his tracks.
2237“Neil can better explain the problem,†the engineer speculated, scuttling
2238down the hallway towards the engineering lab.
2239Neil and Scott reviewed Neil’s notes and recapped the sequence of
2240events on the Source Code Control System (SCCS) (see Exhibit 3).
2241“I stumbled across most of this while grep’ing through log files to trouble-
2242shoot the library problem,†explained Neil. “If you’re in agreement, I think
2243we should bring the security incident handling team in to investigate this
2244and this morning’s denial-of-service.†Scott concurred, as he began to con-
2245template whether it had really been wise to take such a long lunch.
2246Exhibit 3. Sequence of Events
2247System Event Description
2248Account
2249manipulation
2250Two benign-looking accounts (cvstree and cvsmanager) had been
2251created on the UNIX development server housing the Source
2252Code Control System (SCCS)
2253An account that belonged to an engineer who had recently left
2254Dalmedica had been used to log on to the system on several
2255occasions over the past two weeks; certain files in that user’s
2256home and development directories had been created or updated,
2257including files that facilitated remote access to the server
2258Process table
2259irregularities
2260Neil made regular passes at the process table on the system and
2261noted that there were a couple of additional services
2262(and network listeners) running on the system; although
2263this was not unusual (several developers had administrative
2264access to the server), it was felt that, cumulatively, this
2265required additional investigation
2266Library corruption Libraries on the SCCS had apparently been updated or created; as
2267a corollary to this, the LD_Library Path on the system had been
2268updated — something considered a highly unusual system
2269event; this activity had resulted in the replacement of some .c
2270and .o files in library directories and the resulting library
2271corruption
2272Log file gaps There appeared to be a 20-minute window in the local log file on
2273the SCCS that corresponded with the timing of the DNS denial-of-
2274service attack
2275© 2004 by CRC Press LLC
2276Examination of some of the systems that had trust relationships with the
2277SCCS revealed some alarming activity. Random scans of some of the sys-
2278tems associated with the SCCS indicated that a Windows system that was
2279used by one of Dalmedica’s administrators to Secure Shell (SSH) to the
2280SCCS and other servers had been compromised with a Trojan backdoor. In
2281addition, the .rhosts files on several associated UNIX systems had been
2282updated with specific host and user names:
2283devsys.dalmedica.com root
2284devsys.dalmedica.com bschien (an ex-developer)
2285crimson.dalmedica.com cvs
2286Examination of logs and alarms from a network-based IDS situated on
2287the corporate LAN had picked up unusual activity at several LAN systems
2288over the past several weeks; an IDS installed to the Internet DMZ had also
2289triggered over the same time period on a common gateway interface (CGI)
2290script error and attempted privilege elevation attack:
2291[**] [1:1122:1] WEB-MISC [**]
2292[Classification: Attempted Privilege Escalation]
2293[Priority: 2]
229411/05-23:01:09.761942 208.198.23.2:1438 ->
2295204.70.10.229:80
2296TCP TTL:128 TOS:0x0 ID:10349 IpLen:20 DgmLen:314 DF
2297***AP*** Seq: 0x2277A4B3 Ack: 0xED9E771D Win: 0x4470
2298TcpLen: 20
2299As this information came to light and the prospective magnitude of the
2300incident expanded, the incident handling team made a critical decision to
2301augment the investigation by bringing in an outside computer forensics
2302investigation team. It was the lead investigator on this team — Bill Freidman
2303— whom Scott sat down with the following day to review the initial findings.
2304The Investigation
2305Bill scratched his head and grimaced, “So the DMZ IDS was recently
2306installed? Have there been any other recent changes to your network?â€
2307Scott responded, “Well, it depends on what you mean by recent. There have
2308been a number of changes to our network over the past 12 months as the
2309result of security and performance assessments performed over a year ago.â€
2310“I’ll need to see an updated network diagram,†Bill replied. “The more
2311comprehensive, the better… oh… and also configuration data for your fire-
2312walls, routers, and other network access points.â€
2313Scott shuffled around some paperwork in a folder from his desk and
2314placed the diagram displayed in Exhibit 4 in front of the investigator.
2315© 2004 by CRC Press LLC
2316“We made a few significant changes to the network architecture we were
2317operating with a year ago,†stated Scott. “We dispensed with the remote
2318access/dial-up server and have converted all of our remote users over to
2319VPN. We also instituted an LDAP server that is integrated with our Active
2320Directory environment to authenticate partner users to the partner extranet,
2321Exhibit 4. Updated Network Diagram
2322IDS
2323Stateful Packet Filtering
2324Firewall
2325VPN Server
2326SMTP Gateway
2327(Anti-Virus and
2328Content Filtering)
2329Web Content
2330Filtering
2331Gateway
2332LAN (172.30.0.0/16)
2333INTERNET
2334ISP-Managed Router
2335Application Proxy Firewall
2336(Primary (Public) DNS Server)
2337Partner Network Connection
2338Partner Net
2339(Router ACLs)
2340Server Network
2341(Fully Switched)
2342DNS Server(s)
2343(Primary and
2344Secondary)
2345Active Directory/
2346Domain Controller
2347(and Backup Domain
2348Controllers)
2349Corporate
2350Mail Server
2351IDS
2352Database
2353Servers
2354Corporate LAN
2355(Switched to the Desktop)
2356Clients, Printers, etc.
2357(500 nodes)
2358QA/Development LAN
2359(Fully Switched)
2360Clients
2361Development Servers
2362(UNIX/NT)
2363Syslog
2364Server
2365IDS
2366Web Farm
2367Internet DMZ
2368Load Balancing Device
2369IDS
2370Extranet DMZ
2371Web-referenced
2372Database Servers
2373Partner Extranet
2374LDAP
2375Server
2376Web Cache
2377Content Mgt. DMZ (172.30.1.0/29)
2378.245
2379204.70.10.240/29 (Publicly Addressed IP Network)
2380.246
2381.241
2382.244
2383204.70.10.224/28
2384(Publicly
2385Addressed IP
2386Network)
2387.228, .229, .230
2388.208 .193
2389.194, .195
2390204.70.10.192/28 (Publicly Addressed IP Network)
2391.224
2392204.70.10.160/
239328 (Publicly
2394Addressed IP
2395Network)
2396.221
2397204.70.10.208/28 (Publicly Addressed IP Network)
2398.209
2399172.30.0.1
2400DB
2401Replication
2402© 2004 by CRC Press LLC
2403implemented a Web cache, and migrated our content scanning servers to
2404a DMZ off of the application proxy firewall. Finally, we established a set of
2405Web-accessible database servers on a DMZ off of the stateful firewall that
2406synchronizes with select databases on the corporate LAN.†Scott paused
2407for breath, “I think that covers everything — I’ll have to follow up with the
2408router and firewall configuration data.â€
2409An hour later, Scott delivered the requested configuration information to
2410the investigator. The Internet router configuration was reasonably hard-
2411ened with access control lists that controlled remote access; a review of the
2412firewall configuration information revealed the information in Exhibits 5
2413through 7.
2414Bill’s team was afforded access to Dalmedica’s systems and network,
2415and any resources — intrusion detection systems, firewall, system and
2416Exhibit 5. Stateful Packet Filtering Firewall (Perimeter 1)
2417Permit/
2418Deny Source Destination Protocol/Port
2419Permit Any (0.0.0.0) Internet Web servers
2420(204.70.10.228, 229, 230)
2421TCP 80 (HTTP)
2422Permit Any (0.0.0.0) Mail scanning gateway
2423(204.70.10.209)
2424a
2425TCP 25 (SMTP)
2426Permit Any (0.0.0.0) Application proxy firewall
2427(204.70.10.209)
2428TCP 53, UDP 53 (DNS)
2429Permit Partnernet
2430(192.168.10.0)
2431Extranet Web servers
2432(204.70.10.194, 195)
2433TCP 80, TCP 443
2434(HTTPS)
2435Permit Internet Web servers
2436(204.70.10.228, 229, 230)
2437Database DMZ
2438(204.70.10.160/28)
2439TCP 1433 (SQL)
2440Permit Extranet Web servers
2441(204.70.10.194, 195)
2442Database DMZ
2443(204.70.10.160/28)
2444TCP 1433 (SQL)
2445Permit Database DMZ
2446(204.70.10.160/28)
2447Corporate
2448database servers
2449(204.70.10.210, 211)
2450TCP 1433 (SQL)
2451Permit Corporate LAN
2452(204.70.10.209)
2453Internet Web servers
2454(204.70.10.228, 229, 230)
2455TCP 8080 (Web
2456development),
2457TCP 21 (FTP)
2458Permit Corporate LAN
2459(204.70.10.209)
2460Extranet Web servers
2461(204.70.10.194, 195)
2462TCP 8080
2463(Web development),
2464TCP 21 (FTP)
2465Permit Public network
2466(204.70.10.0/24)
2467Corporate syslog server
2468(204.70.10.209)
2469UDP Port 514
2470(syslog)
2471Permit Corporate LAN
2472(204.70.10.209)
2473Any (0.0.0.0) Any port
2474Deny Any (0.0.0.0) Any (0.0.0.0) Default deny
2475(logging)
2476a
2477Network Address Translation (NAT) is being performed at the application proxy firewall;
2478this is reflected in the source and destination addresses for LAN hosts on the Stateful Packet
2479Filtering firewall.
2480© 2004 by CRC Press LLC
2481device log files, system/platform inventories, etc. — that might assist them
2482in piecing together what had occurred. As additional data about the nature
2483of the security breach came to light and the scope of the investigation
2484broadened, Bill kept Scott and Dalmedica’s security incident handling team
2485informed. At the end of the first week, as the investigation unfolded, a meet-
2486ing was called to give the investigation team a chance to turn over some of
2487their initial findings.
2488***
2489Exhibit 6. Application Proxy Firewall (Perimeter 2)
2490Permit/
2491Deny Source Destination Protocol/Port
2492Permit Any (0.0.0.0) Content management DMZ
2493(172.30.1.0/29)
2494TCP 80 (HTTP),
2495TCP 25 (SMTP)
2496Permit Partner network
2497(192.168.10.0/24)
2498Corporate LAN
2499(172.30.0.0/16)
2500TCP 21 (FTP)
2501Permit Database DMZ
2502(204.70.10.160/28)
2503Corporate database
2504servers (172.30.2.210,
2505211)
2506TCP 1433 (SQL)
2507Permit Public network
2508(204.70.10.0/24)
2509Corporate syslog server
2510(172.30.2.250)
2511UDP port 514 (syslog)
2512Permit Content
2513management DMZ
2514(172.30.1.0/29)
2515Corporate syslog server
2516(172.30.2.250)
2517UDP port 514 (syslog)
2518Permit Corporate LAN
2519(172.30.0.0/16)
2520Application proxy firewall
2521(204.70.10.209,
2522172.30.2.254)
2523TCP 22 (SSH)
2524Permit Corporate LAN
2525(172.30.0.0/16)
2526Internet Web servers
2527(204.70.10.228, 229, 230)
2528TCP 8080
2529(Web development),
2530TCP 21 (FTP)
2531Permit Corporate LAN
2532(172.30.0.0/16)
2533Extranet Web servers
2534(204.70.10.194, 195)
2535TCP 8080
2536(Web development),
2537TCP 21 (FTP)
2538Permit Corporate LAN
2539(172.30.0.0/16)
2540Public network
2541(204.70.10.0/24)
2542TCP 22 (SSH),
2543TCP 69 (TFTP),
2544UDP 161, 162 (SNMP)
2545Permit Corporate LAN
2546(172.30.0.0/16)
2547Any (0.0.0.0) TCP 22 (SSH), TCP 25
2548(SMTP), TCP 80 (HTTP),
2549TCP 443, 563 (SSL),
2550TCP 20, 21 (FTP),
2551TCP 110 (POP3), TCP 21
2552(Telnet), TCP 119
2553(NNTP), TCP 53 (DNS);
2554and UDP 53 (DNS),
2555TCP 1433 (SQL)
2556Deny Any (0.0.0.0) Any (0.0.0.0) Default deny (logging)
2557© 2004 by CRC Press LLC
2558“OK, everyone, let’s get started,†Bill announced in an authoritative
2559voice. Because a select portion of Dalmedica’s upper management team
2560was present for the meeting, he had taken the time to prepare an overhead
2561presentation on their behalf — aimed at a simple explanation of a complex
2562turn of events. As he spoke, he clicked the remote and the projector
2563whirred into action. “I thought it might be useful to start by reviewing some
2564of the tools that have been employed in the investigation to date, take a
2565look at our initial technical findings, and then discuss some suggested
2566ways forward for the investigation.â€
2567“This slide (Exhibit 8) overviews some of the tools and techniques that
2568have been utilized to preserve the technical evidence we’ve uncovered,â€
2569stated Bill.
2570Exhibit 7. Application Proxy Firewall (NAT)
2571Translate Source Destination To Protocol/Port
2572Many-to-one
2573NAT Trans
2574Corporate LAN
2575(172.30.0.0/16)
2576Any (0.0.0.0) Firewall’s outside
2577interface
2578(204.70.10.209)
2579<Any>
2580Many-to-one
2581NAT Trans
2582Any (0.0.0.0) Corporate LAN
2583(172.30.0.0/16)
2584Firewall’s inside
2585interface
2586(172.30.2.254)
2587<Any>
2588Many-to-one
2589NAT Trans
2590Any (0.0.0.0) Content
2591management DMZ
2592(172.30.1.0/29)
2593Firewall’s content
2594management
2595interface
2596(172.30.1.1)
2597<Any>
2598One-to-one
2599NAT Trans
2600Any (0.0.0.0) Corporate
2601database servers
2602(204.70.10.210, 211)
2603Corporate
2604database servers
2605(172.30.2.210, 211)
2606TCP 1526
2607(Oracle/SQL)
2608One-to-one
2609NAT Trans
2610Any (0.0.0.0) Mail scanning
2611gateway
2612(204.70.10.209)
2613Mail scanning
2614gateway
2615(172.30.1.5)
2616TCP 25
2617(SMTP)
2618One-to-one
2619NAT Trans
2620Public network
2621(204.70.10.0/24)
2622Corporate syslog
2623server
2624(204.70.10.209)
2625Corporate syslog
2626server
2627(172.30.2.250)
2628UDP 514
2629(syslog)
2630• Use of external binaries to analyze systems (based on platform
2631inventory).
2632• Use of dedicated forensics workstation (for analysis and reporting).
2633• All evidence secured in a secure room and locker.
2634•
2635Tools
2636: File viewers, Unerase tools, search tools, drive imaging software,
2637forensic programs.
2638Exhibit 8. Investigative and Evidentiary Techniques
2639© 2004 by CRC Press LLC
2640“So, let’s cut to the chase — what did we find?†Bill sighed. “Well, as sus-
2641pected, files on the Source Code Control System have been tampered with,
2642and…. well, we have found evidence that other systems were involved. Let’s
2643run through this — system-by-system — and analyze the initial findings.â€
2644Bill clicked through the next series of slides (see Exhibits 9 through 13).
2645Bill wrapped his presentation, saying “In conclusion, I would strongly
2646recommend that we continue and expand the investigation, and that
2647Dalmedica give consideration to working with us in making an initial con-
2648tact with law enforcement. We believe that if we continue the investigation
2649we may find other and remote systems that were involved, which will assist
2650us in understanding the motive for the activity and, perhaps, lead to the
2651perpetrators.â€
2652• Confirmed initial findings.
2653• Working with ISP to parse through relevant log file data.
2654• Firewall log files and router log files confirm DNS denial-of-service
2655packet flooding.
2656• Evidence of connection laundering — DNS reverse lookups on source
2657addresses reveal some interesting system and domain names.
2658Exhibit 9. DNS Denial-of-Service
2659• There is evidence of code having been compiled on the system that
2660relates to two processes running on the server (.o, .c files, etc.).
2661• Server processes appear (from memory dumps, connection
2662attempts, and hex analysis) to be a custom file transfer application.
2663• Log files were excerpted using a log file editing tool found on the
2664system in a/tmp directory.
2665• Ex-employee account was implicated (judging by shell history files).
2666• The origin and purpose of the two secondary accounts are uncertain.
2667Exhibit 10. Source Code Control System
2668• Confirmed compromised by a Trojan backdoor — RWWWShell.
2669• System was likely infected via e-mail — initial inspection of Outlook
2670seems to confirm this (.pst file inspection).
2671• Working with e-mail administrator to retrieve SMTP logs and analyzing
2672e-mail header data.
2673• Continuing investigation to see if other systems are affected.
2674Exhibit 11. Windows (SCCS) Management Client
2675© 2004 by CRC Press LLC
2676Bill was interrupted — somewhere at the back of the room one of the
2677grey business heads bobbed up, “How did this happen…?â€
2678Read on…
2679Notes
26801. Refer to the “Security†section of Chapter 9 for an explanation of split-level DNS.
26812. Note that, generally, a DNS-based denial-of-service attack leverages DNS responses
2682to effect an attack against a target network, using IP spoofing in conjunction with
2683DNS lookups. Refer to Chapter 9 for reference.
26843. Internet recursion is discussed in some detail in Chapter 9.
2685• There are indications that other UNIX development systems are
2686involved.
2687• On some of these systems, .rhosts or hosts.equiv files may have
2688been updated (still under investigation).
2689• A Linux system was uncovered that has a trust relationship with the
2690SCCS server that appears to be implicated — running the same two
2691foreign processes as the SCCS server with a backdoor listener.
2692• This information was uncovered via a manual audit of the system
2693(original drive image preserved) using hex editors, string searches,
2694and forensic tools.
2695• Investigation continues.
2696Exhibit 12. UNIX Development System
2697• IDS activity revealed the following preliminary information:
2698– Internet Web servers have been probed for CGI vulnerabilities
2699using specific query strings.
2700– Database servers on the corporate LAN have also been probed.
2701– Partnernet IDS picked up some of the DNS denial-of-service activity
2702and some activity to and from the corporate LAN.
2703• IDS systems were deluged on the day of the DNS denial-of-service,
2704impacting packet capture.
2705Exhibit 13. Other Avenues of Investigation
2706© 2004 by CRC Press LLC
2707Chapter 3
2708Know Your
2709Opponent
2710Felix Lindner
2711This chapter gives you an introduction to the motivation of your opponent.
2712Because motivation is the engine that drives any action, this is the key
2713to defense.
2714The Federal Bureau of Investigation (FBI) and other advanced law
2715enforcement organizations around the world use profiling to describe and
2716categorize criminal behavior. This leads to better understanding of threats
2717and techniques, which facilitates effective defense. It is essential to know
2718what happens behind the front lines, to know where the tools and people
2719come from, and to be able to make judgments about future developments.
2720The same principles that apply in law enforcement and the military should
2721help you defend your systems. Taking the time to understand the history of
2722hacking and why your opponent is doing what he or she is doing will pay off.
2723The typical profile, fueled by the media and public opinion, is the following:
2724A young boy, with greasy blond hair, is sitting in a dark room. The room
2725is illuminated only by the luminescence of the C64’s 40-character screen.
2726Taking another long drag from his Benson and Hedges cigarette, the
2727weary system cracker telnets to the next faceless “.mil†site on his hit list.
2728“guest — guest,†“root — root,†and “system — manager†all fail. No mat-
2729ter. He has all night. He pencils the host off of his list and tiredly types in
2730the next potential victim…
27311
2732This picture was fed to the public for a long time. Now the media has
2733changed its view on “hackers,†constructing a more nefarious image, which
2734can of course be better used for exciting news, reports, and articles. But
2735the image is still a stereotype. This chapter will try to give the reader a
2736more differentiated view.
2737Terminology
2738A longstanding debate exists in the computer security field about the correct
2739terminology to use to describe an attacker. Bob Woods wrote a Newsbytes
2740editorial in 1996
27412
2742to explain why the news media uses the word hacker even
2743© 2004 by CRC Press LLC
2744though many people send them corrections every time they do it. The sum-
2745mary of this editorial is: “The public knows them as hackers — we know
2746that they are more correctly referred to as crackers.†I agree with this state-
2747ment. To circumvent the naming issues here while discussing different
2748motivations and backgrounds, this chapter will cast some light on common
2749terms first.
2750At one point in time, a hacker was someone who enjoyed learning details
2751of programming languages, computer systems, or algorithms and pre-
2752ferred the actual process of writing programs rather than planning and
2753designing them. He appreciated good hacks from other hackers and was
2754commonly known to his peers as an expert on specific topics. In short, you
2755could think of people similar to those who initially wrote the Linux kernel.
2756The New Hacker’s Dictionary
27573
2758was started in 1975 as the jargon-1 text file
2759and therefore covers ages of computer and Internet history, covering the
2760type of hackers the media refers to in the short section “Crackers, Phreaks,
2761and Lamers.†It dates this culture back to the late 1980s, when some people
2762used MS-DOS-based systems to run “pirate†bulletin boards and states that
2763the jargon is heavily influenced by skateboard lingo and underground-rock
2764slang. I would assume this describes what is in most readers’ minds when
2765they think of hackers.
2766Script Kiddy
2767People calling themselves “real hackers†invented the term script kiddy.
2768Compared to script kiddies, the inventors of this name were highly skilled
2769in the techniques of computing environments and how to use these to gain
2770unauthorized access. Script kiddies in contrast are described as people
2771who just run scripts that they obtain from hackers. This term spread very
2772fast. Today’s script kiddies spend most of their time in IRC — Internet Relay
2773Chat — and trade information and 0-day exploits. They often have no par-
2774ticular interest in the problems and challenges of computer security. The
2775targets of their attacks are not carefully selected but rather are systems
2776that happen to be vulnerable to the particular exploit they have at hand.
2777But you should not underestimate them. Script kiddies are by far the
2778biggest group of attackers you are facing. They have an internal social
2779structure and are trained in obtaining dangerous information fast. Defend-
2780ing yourself against the average script kiddy is not difficult, but you have to
2781keep in mind that script kiddies will often have access to a new exploit
2782months before you know this exploit exists.
2783Script kiddies are criminals. The problem is that they do not see them-
2784selves as such. If asked, they tell you the crime they commit is like stealing
2785chocolate in the supermarket. They feel that hacking systems is more like
2786collecting baseball cards than attacking the heart of someone else’s busi-
2787ness. The 17-year-old “Mafiaboy,†who became famous by being arrested
2788© 2004 by CRC Press LLC
2789for his distributed denial-of-service attacks on popular Web sites such as
2790Amazon.com, eBay, Yahoo, and Cable News Network (CNN), was seen by
2791his peers in IRC as a script kiddy. After he performed the attacks, he went
2792straight into IRC and told everyone what he had just done. This fact illus-
2793trates that, despite the fact that he committed a crime and his action
2794resulted in a substantial loss in money for the victims, he did not realize
2795that he had committed a crime and was at risk of prosecution. If he had
2796realized that he was now a criminal, would he go into IRC and tell everyone?
2797Probably not. Another angle to look at in this particular case is the motiva-
2798tion. Was this boy interested in blackmailing these companies? Or did he
2799work for a competitor who was interested in taking these sites down? Did
2800he promote a particular security product that prevented such attacks?
2801None of these motivations seems to fit. To the best of the public’s know-
2802ledge, he did it for fun and simply “because I could do it.†This underlines
2803the basic issue: for most script kiddies, there is no real difference between
2804killing people or monsters in the latest ego-shooter game or taking out
2805computer systems that run a company’s business.
2806Cracker
2807Most security professionals today refer to the average attacker as a
2808cracker. This became a generic term for attackers with medium-level skills
2809and no noticeable ethical boundaries. As with all of these terms, “crackerâ€
2810is not closely defined but rather changes its meaning from time to time. As
2811the reader will see in the historical background section, even the term
2812cracker once described a different type of person and had less negative
2813images connected to it.
2814One of the major differences between script kiddies and crackers is that
2815crackers actually understand some of the technology behind their doings.
2816Their tools do not have to be much more advanced than those of script kid-
2817dies, but a cracker usually knows how to use these tools and all possible
2818options. Crackers understand why a particular tool is not working in some
2819cases, and their attacks are less noisy than those of script kiddies. But
2820crackers are not limited to the tools they use. They extend the process of
2821system penetration to the degree where every bit of information is used to
2822perform the task. Once they have broken into a computer, crackers will
2823collect all data that could be useful in later attacks on other systems. This
2824includes password files with encrypted or hashed passwords that are
2825cracked on their home system or yet another computer broken into some
2826time ago. They also use social engineering techniques if they are more
2827effective against a particular target than a technical attack. In contrast,
2828script kiddies would never call the company they are attacking.
2829The cracker is interested in taking over as many systems as possible.
2830The way the attack is performed does not matter. If a simple attack is possi-
2831ble, a cracker would seldom choose another more elegant attack vector.
2832© 2004 by CRC Press LLC
2833The compromised systems are later used as a platform for new attacks, to
2834crack passwords, or as so-called zombie hosts for distributed denial-of-service
2835attacks. Crackers are aware of the fact that their doings are illegal in most
2836countries. They take care about the connection that can be seen from the
2837target system or network. Redirectors and proxies are often used to hide
2838their digital tracks. They also take care of log files and make heavy use of
2839so-called rootkits that hide the backdoors they leave behind.
2840Crackers prefer high-profile targets. Although script kiddies may not even
2841notice the purpose of the target they attack, crackers focus their target
2842selection on certain criteria. If the target seems to have a large amount of
2843processing power, it can be used for brute-force cracking. If the system has
2844a high bandwidth connection to the Internet, it is a good platform for
2845further attacks. Sometimes, targets are chosen because of their purpose.
2846For example, some cracker groups focus on high-profile Web servers and
2847deface Web pages. This increases their reputation on the cracker scene,
2848which in turn leads to more connections to other crackers. The more con-
2849nections the cracker has, the more exploit code and information he can
2850obtain. The cracking society has several parallels to mafia organizations, in
2851this sense.
2852White Hat Hacker
2853The perpetual debate about naming forced the security community to
2854invent a new system. It refers to people as Black Hat, White Hat, or Gray Hat
2855hackers. Black Hat stands for the bad guys, White Hat stands for the good
2856guys, and Gray Hat describes people sitting in between. There are many
2857speculations but no proven relations between this terminology and a Linux
2858distributor called Red Hat.
2859The source of this system is early Western movies. Good guys wore white
2860hats, whereas bad guys always had dirty black hats. This color-coded termi-
2861nology made it easy for the audience to distinguish between the good guy
2862and the bad guy. Unfortunately, the world is not black and white.
2863People referring to themselves as White Hat hackers are interested in
2864computer security for a completely different reason from those that moti-
2865vate other hackers. They think this field is interesting because it changes
2866every day. They see the need to protect the public by actively discovering
2867security holes in software and making the public aware of this issue. White
2868Hats work together with the vendors of particular software to solve the
2869issue and make the digital world more secure. Even if the vendor takes
2870several months to fix the hole, the White Hat would not publish the
2871information before the vendor does. Some White Hats see themselves as
2872knights in shiny silver armor protecting the innocent from the bad guys.
2873White Hats would never use their knowledge to break into a system they
2874are not allowed to.
2875© 2004 by CRC Press LLC
2876Despite the fact that most people think that the best protection is
2877developed by people actually breaking into systems, some of the most
2878advanced techniques for protection are developed by White Hats.
2879Because their background is often one of higher education and they are
2880aware of the additional needs a protection system has to fulfill — such as
2881stability, portability, and simplified management — White Hats are often
2882the better developers or consultants.
2883Black Hat Hacker
2884In contrast to a White Hat hacker, a Black Hat is in general put into the
2885“bad guy†corner. But Black Hats would prefer to define themselves as “not
2886White Hat†and never as “bad guys,†because from their point of view, the
2887vendors of insecure software and the script kiddies and crackers are the
2888bad guys.
2889The technical knowledge of the Black Hat is at a level comparable to that
2890of a White Hat, although the focus is a little different. Where a White Hat
2891has an interest in general software development issues and algorithms that
2892can be applied globally, the Black Hat is often a better assembly program-
2893mer and knows more about processor architecture and different target
2894systems. In general, most Black Hats seem to know a wider range of tech-
2895nologies in today’s computing environments than White Hats do, whereas
2896White Hats may have a better understanding of algorithms.
2897The Black Hat usually scorns an insecure network and the administrator
2898who is responsible for the security of that network. When he or she reports
2899security issues to a vendor, this is done in a manner that imparts information
2900sufficient for him or her to fix the problem. The Black Hat does not care if the
2901vendor cannot understand the issue according to the provided information. In
2902such a case, or if the vendor does not observe the timelines given by the Black
2903Hat, the Black Hat will disclose the information completely to the outside
2904world — including exploit code — and will not necessarily care about the
2905risks. Some Black Hats do not even care about the general policies connected
2906to full disclosure (see the section on ethics in this chapter). There is already a
2907trend in the Black Hat community to keep information rather than disclose it.
2908Hacktivism
2909The word hacktivism is a combination of hacking and activism. A hack-
2910tivist is someone who uses system penetration to propagate a political,
2911social, or religious message. The targets of such individuals are mostly
2912high profile Web server environments where as many people as possible
2913see their message.
2914The level of such a hacktivist is often that of the script kiddy. Because
2915the whole exercise is done to promote the message and not to attack the
2916system, the process of penetration itself is not of particular interest to the
2917© 2004 by CRC Press LLC
2918hacktivist. This holds true for most hacktivism. Lately, especially in the
2919conflicts between the United States and China,
29204
2921hacktivism obtained a new
2922face. Hacker groups or individuals ranging from script kiddies and crackers
2923to Black Hats started attacking and defacing Chinese Web sites. The Web
2924pages of political organizations in Afghanistan became targets for hundreds
2925of attackers after the terrorist attacks on the World Trade Center and
2926Pentagon in September, 2001. Hacktivism of this sort is likely to be per-
2927formed in a professional manner. The attackers sometimes build teams and
2928attack not only the primary target but also the perimeter devices in its net-
2929work to achieve maximum impact.
2930Although many hacker groups have released statements saying that
2931they do not support this kind of hacktivism and have asked the hacker
2932community not to use the worldwide data networks as a place of war,
2933I assume this kind of hacktivism will grow in the future. The cracker groups
2934penetrating systems nearly every day are able to outperform most system
2935administrators of propaganda Web sites, and they know it.
2936Professional Attackers
2937Conflicts such as the ones discussed above do not only interest patriotic
2938crackers. According to military sources, every nation has by now at least a
2939small military department that is tasked with information warfare. Most
2940secret services around the world have increased the number of informa-
2941tion security professionals they employ and leverage the fact that many
2942systems can be reached remotely.
2943Agencies and the military in every nation are spending money to build
2944up and train their professional attackers. Although the defense of com-
2945puter systems has been on the task list for many years now, the attack
2946strategies are relatively new. The huge difference between all other groups
2947and the professional group is the amount of money and organizational
2948back-end support that is available. These groups have laboratories and
2949everyday training. They do not have to be the most expert hackers in the
2950world (although some may be); because there is money, there is always
2951some experienced Black Hat who is willing to train them.
2952The reader will probably doubt the statements above because not much
2953is known about such groups or the action they take. But this is exactly how
2954it is supposed to work. Spy networks such as the one known as Echelon
2955have been in place for a long time now, and still nobody really knows what
2956they do and do not do. The same applies to information warfare and how
2957much of daily business operations is actually subjected to espionage of
2958one form or another. The truth is, one can only estimate from past experi-
2959ences with other groups such as the huge cryptography teams working at
2960the National Security Agency, with regard to how much energy is put into
2961the information warfare groups of the leading agencies around the world.
2962© 2004 by CRC Press LLC
2963History
2964It is very difficult to provide a historic view of hackers as a whole. Today’s
2965hackers — in the sense of Black Hats or White Hats — are the result of
2966several different groups and movements from five to thirty years ago.
2967I will describe some of the sources and give pointers to what kind of
2968groups resulted, but readers should exercise their own judgment in this
2969area. The reader must be aware of the fact that every individual has differ-
2970ent reasons and driving forces behind his or her doings. By pointing out
2971some of the sources hackers evolved from, the readers can match these
2972sources to the people they encounter in the wild and make their own deci-
2973sions. When talking about anatomies of hacks, the reader will find some of
2974this background information useful. Behavior becomes more predictable
2975when the history of the individual’s environment is taken into consider-
2976ation — and this does not require knowing the individual.
2977Sometimes when dealing with permanent attacks on systems that we are
2978supposed to protect, we have to remember that anyone who owns an IBM
2979personal computer (PC) or its successors has perhaps committed a com-
2980puter crime at least once. The crimes you have probably committed are:
2981•
2982Violation of the copyright laws that apply in your country.
2983I am sure
2984that the reader has at least one commercial software product on his
2985hard drive that is not purchased or for which he or she is not holding
2986a valid license. Are these several shareware programs with run-out
2987evaluation timeframes? Guilty.
2988•
2989Violation of data integrity laws, if applicable in your country.
2990Did you
2991ever download a crack or a patch that originated from a source other
2992than the vendor itself? Did you apply this patch? Guilty.
2993•
2994Committing the crime of document forgery.
2995The last time you down-
2996loaded a piece of software, what name did you enter in the registra-
2997tion form and what e-mail address? Not your own? Guilty.
2998I could list more of these, but I think you get the picture. Most of these
2999crimes are “normal†in our digital world, and nobody thinks about it — in
3000some countries it is the same with speed limits. All we have to remember
3001is the fact that putting someone in the Black Hat corner or allowing that
3002person to go to the White Hat corner is not dependent on whether the per-
3003son committed a crime according to the law but more or less depends on
3004one’s point of view.
3005Computer Industry and Campus
3006The term hacker itself and many references come from the computer cen-
3007ters at universities and computer industry laboratories. Many scientists,
3008assistants, system managers, teachers, and students are hackers in the
3009original meaning of the word. Many of them are also interested in computer
3010security and society issues.
3011© 2004 by CRC Press LLC
3012Dorothy E. Denning (working at Digital Equipment Corp. Systems
3013Research Center) in
3014Phreak Magazine,
3015Volume 3, Issue 32, File #3 of 12,
3016wrote on the subject of hackers and their motivations and ethics:
3017The ethic includes two key principles that were formulated in the early
3018days of the AI Lab at MIT: “Access to computers — and anything which
3019might teach you something about the way the world works — should be
3020unlimited and total,†and “All information should be free.â€
3021Beside the fact that Denning is referring to an ethic here, it is no surprise
3022that a well-known and respected name (the Massachusetts Institute of
3023Technology [MIT]) is mentioned. The skill level at such institutes is under-
3024standably high, the systems are available to students, and the general trust
3025between people is high. Every student at a technically oriented university
3026has access to at least three different operating systems. Superuser access
3027is usually granted to interested students. In the professional security
3028environment of today, the saying “like a university†refers to computer sys-
3029tems with lax security and without the most basic protection.
3030The computer industry laboratories, the information technology sections
3031of universities, and the appropriate sections of the Department of Defense
3032developed a network based on a protocol family of a Transport Control
3033Protocol, a User Datagram Protocol, and an Internet Protocol, today
3034known as the Internet. The scientific members applied their rules of trust-
3035worthy peers, and the military members applied their rules of verified
3036trustworthiness before being allowed to join. People invented and imple-
3037mented services to give out information as freely and as simply as possi-
3038ble. The results are services such as finger, Telnet, FTP, HTTP, or the World
3039Wide Web.
3040The same organizations developed operating systems such as UNIX or
3041contributed essential parts. Although VMS and UNIX introduced the concept
3042of processes that run parallel but have their own protected memory ranges,
3043the access levels for human users could not be more simple: You are the
3044superuser (your user ID is 0), or you are not. The primary goal was function-
3045ality and powerful tools. Portability was also high on the list. Every user of
3046today’s UNIX will agree that these goals were reached. Tools developed for
3047UNIX — such as the various shells, Perl or Sendmail — are all very powerful.
3048They were designed by programmers for programmers. But powerful func-
3049tionality often has the drawback of complexity, which in turn often leads to
3050bugs in software or at least unexpected behavior. Unexpected behavior is
3051all an attacker needs to gain unauthorized access. I use and love UNIX — but
3052I know what price the power of UNIX sometimes costs.
3053UNIX “wizards†often tell you that they broke into systems for various
3054reasons and refer to themselves as hackers — but they are not your daily
3055enemy. So what is the difference? The first one is that these wizards refer
3056© 2004 by CRC Press LLC
3057to themselves as hackers in the original sense of the word. The second
3058point is that the number of times they broke into systems is probably less
3059than ten. My experience is that they have done this every time for a reason-
3060able reason (such as the admin of a system being on vacation) and some-
3061times for fun.
3062The centers of intelligence and excellence of our information society are
3063part of the development that created Black Hat hackers. They gave them the
3064technology and methodology as discussed in the paragraph on hacker ethics.
3065System Administration
3066System administrators and operators did their part in the development of
3067Black Hat hackers. The reader may disagree with that statement and indeed,
3068their influence is perhaps the smallest in the whole scenario, but the overall
3069application of the security concepts mentioned above introduced the position
3070of an omnipotent person — the superuser — and many readers may agree that
3071they have misused the technical permissions they were given for their day-to-
3072day work at least once. Maybe it was the reading of someone else’s e-mail to
3073the sweet secretary on the first floor or the creation of a private Web site on
3074the company’s network. Ever killed a user’s shell? It could be a misuse of
3075permissions given. Whoever thinks that his superuser would never do such a
3076thing: take a look at the text series “The Bastard Operator from Hell.â€
30775
3078Although most system managers never become Black Hats, some do.
3079Home Computers
3080The introduction of home computers in large numbers in the 1980s was prob-
3081ably the beginning of the era of premature attackers. Computers such as the
3082Commodore C64, Amiga 500, Atari ST, and IBM PCs were introduced into the
3083bedrooms of teenagers. These computers had several advantages over other
3084toys such as game consoles: you could program them yourself, and you were
3085encouraged to do just that. But most customers bought their software at the
3086local dealer. This was mostly for the system’s game capabilities, although the
3087gaming capabilities of the IBM PC, at that time, were very limited.
3088You can spend a huge amount of time on a single computer game, but
3089at some point in time, even this is no longer interesting. Then, you either
3090buy a new game or start programming and playing around with your com-
3091puter. This generation was able to accumulate an extraordinary level of
3092knowledge due to the following:
3093•
3094The computer was at home.
3095You could come back from school or work
3096and spend your time using it until after midnight without having to
3097ask for processing time or pay anything except power, and it was in
3098your home environment. This led to an average amount of time spent
3099on these relatively simple computers that was surprisingly high.
3100© 2004 by CRC Press LLC
3101•
3102The process was reproducible.
3103Unless you were playing with the
3104frequency of your monitor or the timing of your central processing
3105unit (CPU), you could do everything over and over again until you
3106found out what you wanted to do. Things changed in random access
3107memory until you decided to turn the system off — then, everything
3108was back to square one. You do not break anything when changing
3109bytes in memory.
3110This is a powerful aspect of hacking and programming development. In
3111contrast to the real world and for example, chemistry, you can learn and
3112develop knowledge in information technology to a certain level by trial-
3113and-error methods. Do not try to learn how to create nitroglycerin the
3114same way.
3115The trial-and-error method was supported by other factors. Documenta-
3116tion was expensive and not always available. In fact, most interesting parts
3117of normal operating system design, file formats and so on, were docu-
3118mented in the UNIX environment only. The home computer vendors
3119charged for every bit of information. Some of them even tried to prevent
3120information from being known so that they could sell their development
3121packages. What these vendors failed to notice was the need for software
3122and the need for programmers.
3123Home Computers: Commercial Software
3124Commercial software was for a long time the only software available for
3125home computers — and it was expensive. The price of a computer game
3126today is still as high as it was in the beginning, and most teenagers would
3127simply not spend so much money on a game. The result: games were and
3128are copied. In contrast to the real world, you can clone data in the computer
3129world. Once this process is complete, the original data is unchanged, but
3130you have another set of data that is 100 percent identical to the first one. It
3131is hard to imagine — even for lawyers and other adults — that this is a crimi-
3132nal act. How can this be bad? Nothing is damaged, right? Nobody is hurt.
3133The question in the heads of the people who were hurt — the people
3134whose income was affected by the decreasing sales numbers — was differ-
3135ent: how can we prevent this from happening? The introduction of law
3136enforcement into the game did not help much to prevent teenagers from
3137copying software. And parents had problems in understanding what their
3138kids were doing or had the same attitude towards copyrights and prices for
3139software that the kids did. With the growing number of home computer
3140users, police could no longer check every lead about possible software
3141piracy. Therefore, the software industry introduced copy protection mech-
3142anisms. First, numbers had to be entered into the game before you could
3143play, and these numbers were on the packing or on a code table that came
3144with your game. These protections could be circumvented with publicly
3145© 2004 by CRC Press LLC
3146accessible photocopying technology — just copy the code card. Later, soft-
3147ware developers became better at the game and introduced bad-sector
3148checks, key disks, manual checks, and many exotic ways of making sure
3149the software was licensed. None of these remained uncracked.
3150The term “cracking†software refers to the process of reverse-engineer-
3151ing the software and then changing the code to disable the protection.
3152What you need is:
3153• The software and optionally one valid key.
3154• A so-called debugger, memory editor, or in-circuit emulator (ICE).
3155Although the way of doing things is completely different for each of
3156these three, the effect remains the same. You can stop the program
3157in question at any time, examine the memory (what changed — what
3158did not) or run the program step by step, where a step is one CPU
3159instruction at the time. This is the detail level on which you control
3160every tic in your computer.
3161• A certain level of knowledge about the platform you are working on,
3162your CPU, and a list of supplementary chips inside your computer.
3163• Later, as it became available, special hardware. Introduced in 1985
3164by Apple for its Apple II computer, the “Apple II Action Replay†was
3165an external hardware debugger. The “Amiga Action Replay†by Datel
3166(http://www.datel.co.uk/) was a full-blown cheat extension card for
3167the Amiga 500 and could be used for cracking as well.
3168Talented people worked alone or in groups on newly released games and
3169protection mechanisms and developed small changes for these programs
3170to disable their protection. The process of searching and finding such a
3171protection is sometimes very time-intensive and — depending on the level
3172of the programmer who created it — the protection could be very compli-
3173cated to break. Sometimes, the protection itself was protected, and the
3174game stopped working in the middle because the protection part was
3175altered and so on. The time and knowledge invested in such a change
3176(called a crack) is much more than the reader may assume. The result was
3177a program that changed the original binary executable file or a new version
3178of this executable without protection.
3179Imagine the amount of time you need to crack a game and that the
3180result is a 10-byte patch. Your achievement is not represented in an
3181appropriate way. That is where the so-called INTRO came into play. First,
3182the cracker changed some graphic or text string in the game itself to have
3183his synonym displayed as to who he is and that he cracked the game.
3184Later, the programming skill developed on the home computers was
3185applied to a DEMO — a piece of noninteractive software that looks a little
3186bit like an MTV video clip: high-end, real-time computer graphics, great
3187background artist work, and terrific sprites (moving, often layered,
3188bitmaps), fantastic music playing in the background, and 100 percent
3189© 2004 by CRC Press LLC
3190adjusted to the graphics. Now, members of a group could use all their
3191abilities to show not only how good they are at cracking software but
3192could introduce themselves in an appropriate way to the world. New
3193skills were needed: graphic artists (GFX’rs), music composers, and the
3194programmer for the engine — the software running the whole thing. New
3195software was needed as well: sound composers written by hackers were
3196for a long time the state of the art in computer music on home computers.
3197Competitions started to determine who wrote the best DEMO, and soon
3198the scene developed an independent existence with DEMOs written for
3199fun or for conventions such as the Assembly (http://www.assembly.org/).
3200The DEMO scene is still active and has moved to other operating systems
3201or is still using the Amiga but is very much separated from the cracking
3202scene now. Demo coders and artists with their work can be found at
3203http://gfxzone.planet-d.net/and http://www.scene.org/.
3204Home Computers: The BBS
3205Although there is much to tell about cracking game software, another
3206development dates back to the late 1970s. Bulletin Board Systems or BBSs —
3207sometime called mailboxes — were the first widely used data transfer points.
3208As usual, the industry found out that their need for communication could not
3209be fulfilled by normal means of communication such as snail mail. Sending out
3210software patches on tapes was not very effective and required a lot of human
3211intervention. Direct access from one computer into another was needed.
3212The solutions were serial connection methods. The range is wide and
3213includes UNIX-to-UNIX Copy (UUCP) and Serial Line Internet Protocol
3214(SLIP) applications on UNIX systems as well as XMODEM, YMODEM, and
3215ZMODEM protocols mainly used with PC clones. System operators now
3216could connect from one computer into another using a serial line. By mod-
3217ulating the signals used between these two hosts into sound, you could
3218transfer data over a phone line. The device to do this was called a modula-
3219tor/demodulator— a modem.
3220The possibility of using publicly available phone systems to connect
3221two computers introduced a new era. Although at first the connections
3222were performed system-to-system for maintenance or operation, soon cen-
3223tral points of communication came into existence. These systems had
3224more free hard drive space than others did and could therefore hold more
3225data. The BBS was born.
3226As often observed, industrial applications slowly make their way into
3227homes. First, system operators had modems at home with which to con-
3228nect to work. Then, they set up their own BBS and ran it on a secondary
3229line. When this development met with the evolution of IBM PC clones and
3230Amiga systems, private BBSs mushroomed. They were used to exchange
3231© 2004 by CRC Press LLC
3232tools, papers, and of course, cracks for games. All individuals who counted
3233themselves as part of the hacker or cracker movement had to have at least
3234one home BBS system where they spent most of their online time. Cracker
3235groups used several BBSs but had designated HQ BBS systems — some-
3236times not really belonging to them but cracked into. For a current perspec-
3237tive: think of it as a network of Web sites and their mirrors.
3238BBSs had several advantages:
3239• There was no rocket science involved in setting them up. In fact,
3240most BBS systems were simple MS-DOS-based programs taking
3241advantage of the simple OS-to-hardware situation. User authentica-
3242tion and access to different file system parts was granted by some
3243kind of proprietary implementation — often just flat files protected
3244by a username and password.
3245• They were cheap. The most expensive part of each system was the
3246modem and hard drive. The individuals running the BBS did not pay
3247the phone bill, because the caller paid (if he or she paid at all —
3248see the next section).
3249• You could get in contact with people. BBSs usually employed several
3250board systems and were later connected to each other so people
3251could swap files, software, and messages across BBS boundaries.
3252Although commercial BBSs did not really change a lot over time, private
3253systems became separated. Three groups evolved:
32541. The first group consisted of “normal†file BBSs run by private indi-
3255viduals who did not interfere with any law. They just distributed
3256freeware and shareware programs, pictures, text files, and messages.
3257They often had uplinks to the FIDO net, which still has approximately
325830,000 systems worldwide and uses direct modem connections and
3259border remailers to exchange e-mail with the TCP/IP Internet via
3260UUCP. The private boxes disappeared first when private Web pages
3261became available because their operation was very expensive and
3262work intensive compared to Web page maintenance.
32632. The second group of BBS systems consisted of semicommercial or
3264sponsored systems. The primary intent of these was to facilitate
3265chat and communication. People running these systems all over the
3266world have either moved over to Internet-based chat systems, such
3267as IRC, or decided to stay in the modem-based area a little longer.
3268Some bigger companies figured that this was a good opportunity to
3269do some marketing and started sponsoring these modem systems.
3270Pubs and clubs used the access and some old PC hardware to
3271promote them and encourage customers to use them. One example
3272is the still-existing modem system in several German cities, which
3273is sponsored primarily by Marlboro.
3274© 2004 by CRC Press LLC
32753. The third group leads us back to the history of hacking: underground
3276boxes. These were used to exchange illegal or semilegal contents.
3277Because most normal BBS sysops (system operator — the owner of
3278the BBS) banned copyrighted software from their systems to stay out
3279of jail, underground BBS dial-in numbers were kept secret to prevent
3280law enforcement from discovering them. But the boxes not only
3281served the purpose of exchanging cracks and commercial software.
3282People communicated through these boxes. Before the underground
3283boxes existed, hacking and cracking groups were limited to specific
3284geographical areas and could only communicate to each other. Open
3285BBSs were not safe enough, and public key encryption was not
3286widely known. Using underground BBS systems, groups could com-
3287municate on fairly safe systems, publish their ideas in papers, and
3288find other groups and new members. The first E-zines (electronic
3289magazines) appeared and were distributed through the HQ boxes.
3290By this time, a huge network of several thousand interconnected
3291BBSs had developed. Each BBS had automatic or manual links to
3292other BBSs and transferred files back and forth. It sometimes took
3293several days for a file to reach the last BBS, but it worked fairly well.
3294Although the traditional normal BBS did not enforce many regulations,
3295and the commercial and chat-centric systems needed only behavior rules,
3296the underground BBSs were very rigorous with their rules. Unknown hack-
3297ers did not get any information. You had to crack and hack a lot to get hold
3298of a special phone number. Then, you could log in to the system with guest
3299permissions. Only when an appropriate amount of interesting data was
3300uploaded to the system, and you contributed “cool†stuff, ideas, or know-
3301ledge to the group, was your account promoted to user level. What you had
3302to contribute depended very much on the focus and knowledge of the BBS
3303members. The most desired material was more of the technical manual
3304kind than commercial software or cracks. This changed when the Internet
3305replaced most underground BBSs — but there are still some in use.
3306Phone Systems
3307The first targets of Black Hat hacking were telephone systems. When com-
3308puter connectivity was based on the availability of phone lines, and hack-
3309ers started using these connections to access computer systems they were
3310not supposed to access, two issues arose:
3311First, the use of a phone line was traceable. Everyone knows that ways
3312to trace a connection back to its originating phone exist. Most readers will
3313remember from Hollywood movies that the phone company needs consid-
3314erable time to perform such a trace. In the late 1970s and 1980s, these
3315traces took more time than today. This means the attacker had to be con-
3316nected (or dialed-in) for this time to be traceable. But taking into account
3317© 2004 by CRC Press LLC
3318that available transfer rates were between 1200 and 2400 baud, this was
3319no protection — it took hours to perform a relatively simple task. Imagine
3320how long you have to be connected to a computer system that you are not
3321familiar with. As soon as you manage to get access to it, you have to find
3322out what it is. If you do not know it and you do not have a manual or you
3323could not even identify it, you have to use imagination, guess commands,
3324and try to find out how it works, what you can do with it, and what its pur-
3325pose is. Even if you have a manual, you have to spend a long time finding
3326the right commands and learning about the permission and access control
3327mechanisms before you can leave at least a simple backdoor — because
3328you do not want to go through the whole process of gaining access again.
3329This all adds to the issue of being traceable. Now, if you could use some-
3330one else’s line or could be simply untraceable, then you could spend a lot
3331more time hacking.
3332The second issue is a profane one: money. Usage of phone lines is
3333billed to the caller. If you wanted to hack someone’s computer and the
3334only means of access besides breaking into the person’s office was by
3335phone, you had to pay for the connection. This is traceable — but in the
3336times we are referring to here, this was not the primary issue because
3337most people did not realize they had been hacked. The issue was that you
3338(or your parents) had to pay for a lot of long distance phone connections
3339over a long time. This could easily increase a phone bill by several hun-
3340dred dollars. The only way around this was to use phone lines that were
3341not exactly given to you by the phone company: those of your neighbors
3342or unused ones.
3343These two requirements led to an interesting and still existing move-
3344ment in the hacker scene: phreaks. The name comes from “freak†but with
3345the f replaced by ph as in phone. The verb “phreaking†describes hacking
3346phone systems.
3347The desire to be untraceable and use phone lines other than yours was
3348fulfilled by phreaks. First, connections to the neighbor’s phone line were
3349made to use her line instead of yours. Because this person would often call
3350the phone company very soon after her bill arrived, and the company
3351would find the additional connection, this was not the best idea. The second
3352step was to use unassigned lines. This often worked for a long time, but
3353these lines had no phone number assigned and were not fully functional in
3354many respects. The most successful way of phreaking was to actually hack
3355the phone system core devices and configure the line you wanted to use
3356yourself. This activity was known as “blue boxing†because often these
3357lines terminated at a pirate BBS. Because the core devices could handle all
3358kinds of phone services and special settings, some groups managed to
3359have their BBS connected to a blue box that was actually accessible by a
3360toll-free number.
3361© 2004 by CRC Press LLC
3362Yet another way of more basic phreaking is probably well known. The
3363public phones used to use dual tone multifrequency (DTMF) tones to report
3364the coins inserted back to the core systems. These tones could be recorded
3365and replayed every time the phreak wanted to place a long-distance call to
3366a target computer. This is a very good example of technology that was
3367developed and implemented to meet the needs of normal users and opera-
3368tors and not with security implications in mind. No phone company would
3369use this method of payment approval today — but other methods in use
3370are not necessarily more secure.
3371The history of phreaking is very important for the general development
3372of hacking. Phreaks are required to have good knowledge of all important
3373protocols and connection types, as well as the functionality of the phone
3374system they are attacking. On top of this, a lot of information is gained by
3375social engineering, which requires the phreak to actually know the proce-
3376dures of daily business in the phone company. Phreaks have to call the
3377right people to get the information required or have them configure the
3378settings they are looking for. Phreaks have to use the right words to convince
3379the victim that they are normal college students who simply need help. All
3380these skills are not developed in one day. It takes a considerable amount of
3381time to learn and to concentrate on the task. This shows an increase in
3382dedication that was not seen before. Groups who worked together to gain
3383additional knowledge and share or trade papers on phone systems evolved
3384on pirate BBS systems. Many of the good phreaks could actually teach
3385something to a normal phone company engineer because they spend most
3386of their spare time learning the exotic behavior of the latest switchboard.
3387Ethics and Full Disclosure
3388The ethic includes two key principles that were formulated in the early days
3389of the AI Lab at MIT: “Access to computers — and anything which might
3390teach you something about the way the world works — should be unlimited
3391and total,†and “All information should be free.†In the context in which
3392these principles were formulated, the computers of interest were research
3393machines and the information was software and systems information.
3394The text Dorothy E. Denning was writing is about hackers breaking into
3395systems and the fact that several contacts with hackers changed her point
3396of view from “the bad guys†to a more differentiated angle. The reader might
3397better understand the meaning and source of the quote above after the
3398short excursion into the history of hacking presented in this chapter. But
3399what are today’s hacker ethics? This question cannot be answered easily.
3400Most White Hat hackers will tell you that their goal is to “find security
3401issues and vulnerabilities in computer and information systems and make
3402this information available to the public so everyone can protect them-
3403selves.†Their ethics prohibit the abuse of such information. White Hats
3404© 2004 by CRC Press LLC
3405would not attack a computer system with their tools and knowledge simply
3406because they do not like the person running the system. Is this an ethic?
3407The same people tend to use their knowledge for commercial purposes.
3408They found their own companies, publish their own products, or offer their
3409services as consultants. If you find a major hole in — say, the most popular
3410Web server, and you publish this information together with a detailed
3411recipe on how to exploit it, is this ethical? If you then offer your service to
3412the affected companies, is this ethical?
3413Every reader has probably seen one or more TV reports where the TV
3414people hired a “good hacker†to break into a high-profile target. The TV sta-
3415tion gains publicity and the hacker is now famous. Is that ethical? Last time
3416I was watching such a show, the hacker not only showed his ability to hack
3417an unpatched Internet Information Server at a bank but also provided
3418extensive information about the book he had just published. On top of this,
3419he offered a hot line to affected (scared) people, where he would give them
3420recommendations on how to protect themselves. Of course, this hot line
3421was not cheap. The TV reporter stressed the point that this guy could be a
3422criminal and steal thousands of dollars from the bank, but instead was
3423working with the TV channel to provide this information to the public. But
3424if he would be a criminal and actually take the money, he would have to
3425cover his tracks very carefully and make sure the money stayed in the
3426account he transferred it to. This is not as simple as breaking into an
3427unpatched Internet Information Server (IIS). And of course, being rich and
3428famous because of the TV and the free promotion is way better than being
3429rich and on the run because every law enforcement officer in the world is
3430looking for you.
3431Sometimes, Black Hats have ethics as well. These are less stable and you
3432cannot put your finger on them, but they exist. Some Black Hats would never
3433“trash†a system. Trashing refers to totally destroying a system installation
3434to make forensics more difficult. This means, for the system administrator,
3435that all data is lost and he has to recreate the whole system — hopefully
3436from backups. Other Black Hats would leave digital business cards on the
3437system to make the owner aware of the fact that the system is insecure.
3438************************
34396
3440* Y0uR 53(ur17y 5u(|<5 *
3441* g3|\|3r1(hAx0r *
3442************************
3443Of course, the Black Hat committed a crime by breaking into the system
3444in the first place, and the system owners cannot be sure that no backdoor
3445has been left open to the attacker. They do not know whether the attacker
3446used this system as the basis for new attacks or if he or she took over other
3447systems in his or her network and just left this single business card. But
3448© 2004 by CRC Press LLC
3449they are aware that their security has been broken. It is up to the company
3450to decide on the next steps — including calling law enforcement and trying
3451to track down, sue, and arrest the hacker. The business card he left does not
3452protect him. On the other hand, the company is not forced to tell the public
3453that it was hacked and can choose the consultant it feels most comfortable
3454with to help find the problems and solve them. Is that more ethical?
3455As you see, based on these two examples, the words “hacker ethicsâ€
3456no longer have any particular meaning. They more correctly describe what
3457each and every hacker considers his or her ethics.
3458Although it would deserve a chapter on its own, the debate about “full
3459disclosure†falls under the ethics discussion. Full disclosure is seen as the
3460contribution of the White Hat hacking community. Quoting from the fre-
3461quently asked questions (FAQs) of the most popular full disclosure mailing
3462list, BugTraq:
34637
34640.1.6 What is Full Disclosure?
3465Full Disclosure is a security philosophy that believes:
34661. A truly secure system must be able to withstand open review at all
3467levels (e.g., protocol, source code, etc).
34682. The details of security vulnerabilities should be available to everyone.
3469Benefits include:
34701. A large number of individuals get to review the system for security
3471weaknesses.
34722. Vendors are pressured into providing security fixes quickly.
34733. Programmers and system designers can learn from others’ mistakes.
34744. Users can identify similar vulnerabilities on systems other than the
3475original.
3476Cons include:
34771. At the same time you inform constructive people of security vulnera-
3478bilities, you also inform destructive people.
3479The first paper I got hold of several years ago that could be seen as “full
3480disclosure†was written by Dan Farmer and Wietse Venema in 1993. It is
3481called “Improving the Security of Your Site by Breaking Into Itâ€
3482(http://www.fish.com) and gives UNIX system administrators a guide for
3483simple hacking in UNIX environments. When this paper and the tool SATAN
3484were released, many people blamed the authors for giving weapons to
3485children by telling them how to hack the UNIX systems they try to protect.
3486Both authors tried to give the reader a view on the things they are protecting
3487by showing them the view of an attacker. Hacking and security texts (this one
3488included) fall into the full disclosure discussion, because they provide poten-
3489tial attackers with information about what the defenders concentrate on.
3490© 2004 by CRC Press LLC
3491Full disclosure and the process of how to publish such information are
3492discussed very often, and no consensus has yet been reached. Rain Forest
3493Puppy created a policy document that is recommended as a guideline for
3494all kinds of hackers when dealing with newly found vulnerabilities. This
3495policy — known as RFPolicy — can be found at http://www.wiretrip.net. It
3496provides timeframe recommendations and rules of behavior for hackers
3497and vendors. Many hackers observe this policy. But it is a recommendation
3498— nothing else. Mailing lists such as BugTraq assume or trust the fact that
3499hackers finding vulnerabilities will follow the line of this or a comparable
3500policy. Belief in such policies is what makes full disclosure work. But what
3501if other people do not follow the rules? What if they find vulnerabilities, are
3502able to exploit them, and keep the information to themselves?
3503A growing number of hackers think it is not a good idea to perform full
3504disclosure in the way BugTraq contributors do. They argue that two differ-
3505ent types of information are distributed through the full disclosure lists.
3506The first type is information about a potential security issue found in a
3507product. This information does not include any way to exploit the security
3508issue, yet. The person who posted this information just stumbled across
3509something he or she thought could be a security issue or was at least not
3510the way it should be. This information is useful for the system owners who
3511run such a product because now they are aware of a potential issue. This
3512information has another effect: Black Hats who develop exploits to actu-
3513ally use them now have the information that an issue exists and can look
3514into the possibility of exploiting it. Now, the innocent message about a
3515security issue leads to system administrators who know that an issue
3516exists, a vendor that probably does not take the issue too seriously
3517(because it is just theoretical), and a group of Black Hats who actually use
3518this issue to penetrate systems. It is understandable that this outcome is
3519not what was intended.
3520The second type of information going to such lists is ready-to-run
3521exploit code. This is an obvious danger because everyone — even
3522script kiddies — can take the code and penetrate systems of users reading
3523the advisory.
3524The major problem here is that in any case, the advantage is on the
3525Black Hat side. One of the issues is timing. If you are a Black Hat or a secu-
3526rity professional, you read these lists daily and you spend a lot of time with
3527the information found there and in other sources. If you are responsible for
3528your systems and also for system security, you do not spend all your time
3529reading these lists. You probably never learned assembly or C and there-
3530fore perhaps cannot actually comprehend the exploit codes. This means
3531that, even if both parties have the same information at the same time, the
3532defender has the disadvantage of a longer time needed to understand the
3533© 2004 by CRC Press LLC
3534issue. Then, the attacker just has to identify a vulnerable target and break
3535into it without having to worry about system crashes, data lost, and similar
3536problems. On the other hand, the system owner has to make sure that pro-
3537duction is not affected. He probably has to schedule downtime, talk to his
3538manager, and make sure he is allowed to apply the latest patch. He must
3539also talk to the vendor of the software running on these servers and make
3540sure the patch does not affect the functionality of application XYZ.
3541If this is not enough, look at some program code sent to the full disclo-
3542sure mailing lists. The code is sometimes developed six months before it is
3543actually posted to the list. Now, did the code hang around on the hard drive
3544of this hacker for this time or did he give it to others? Did one of his peers
3545give this code to yet another group of people? Was the code used to attack
3546systems? Some speculate that a certain amount of exploit code is released
3547only after the original developer(s) feel it does not bring any more advan-
3548tage to them. This would mean that a lot of intrusions actually use code
3549that is not published and therefore not known in the wild.
3550As you can see from the examples listed above, the spectrum of different
3551opinions has increased over time. Most hacker groups no longer follow one
3552ethic but either develop their own or just do not care. The fact that the skills
3553required to develop new attack methods or good exploits rise over time
3554makes hacker ethics even less important. People who spend their time
3555developing such skills get an omnipotent feeling and rate other people only
3556by their skills. Who needs ethics when he is the master of the game anyway?
3557Opponents Inside
3558The reader has probably heard but never believed this message: 80 percent
3559of successful attacks come from the inside. But this does not limit the
3560possible opponents inside your company to the number of people who
3561would actually attack the systems you try to protect. A company is a collec-
3562tion of several groups with different interests. One of these interests is secu-
3563rity — but it is only one. You have managers and back office staff who want
3564easy-to-use computer systems. You might have application developers who
3565would like to have open systems for easy development. There might be
3566finance people who actually care about security but will not tell you the
3567status of it because you are not supposed to know anything about the stuff
3568finance does. There are actually more threats to consistent security inside
3569a company than outside.
3570The Hostile Insider
3571Would you give an average hacker a list of important hosts of your network
3572including the Domain Name System (DNS) addresses, Primary Domain
3573Controller, internal and external Web servers, application servers, and
3574routers? Would you give him accounts on all these systems and tell him
3575© 2004 by CRC Press LLC
3576how they work? Would you provide this attacker with enough time to dis-
3577cover the ins and outs of your network and server architecture and would
3578you place his system behind the firewall so he can access all targets easily?
3579That is what a hostile insider has to start with.
3580The normal desktop system configuration contains more valuable data
3581than any attacker from the outside could probably find out in several
3582weeks. It provides the insider with all key information about your network
3583and therefore lays out the targets in front of him in a very clear way.
3584C:\>ipconfig/all
3585Windows IP Configuration
3586Host Name . . . . . . . . . . . : internal-host
3587Primary Dns Suffix. . . . . . . : localdomain.com
3588Node Type . . . . . . . . . . . : Broadcast
3589IP Routing Enabled. . . . . . . : No
3590WINS Proxy Enabled. . . . . . . : No
3591Ethernet adapter Local Area Connection:
3592Connection-specific DNS Suffix. :
3593Description . . . . . . . . . . : 3Com 3C920
3594Integrated Fast
3595Ethernet
3596Controller (3C905C-TX Compatible)
3597Physical Address. . . . . . . . : 00-08-74-9C-21-13
3598Dhcp Enabled. . . . . . . . . . : Yes
3599Dhcp Server . . . . . . . . . . : 192.168.1.230
3600IP Address. . . . . . . . . . . : 192.168.1.5
3601Subnet Mask . . . . . . . . . . : 255.255.255.0
3602Default Gateway . . . . . . . . : 192.168.1.1
3603DNS Servers . . . . . . . . . . : 192.168.1.250
3604192.168.1.251
3605The information available to the insider by just looking at this Internet
3606Protocol (IP) configuration is awesome. It contains the default gateway,
3607which is probably a router, the DHCP server address, the DNS servers, and
3608the type of NetBIOS communication. This information alone provides some
3609very interesting targets.
3610Most companies try to limit administrative overhead by using a single
3611point of authentication. This trend continues because directory services
3612© 2004 by CRC Press LLC
3613are becoming more popular. But it means that the insider, having an active
3614user account, can log into a range of systems with this account. Local priv-
3615ilege escalation is a lot simpler than attacking a system on which the
3616attacker has no account. But maybe he does not actually need to do this. It
3617very much depends on the goals of the attacker. If he is after confidential
3618data, poor file permissions might be all that are needed.
3619The insider has a lot of time at hand. Consider a person who works at
3620this company for several years. During this time, the person probably sees
3621a range of systems. If we draw some assumptions about hostile insiders,
3622the picture becomes even scarier:
3623• Insiders are aware of computer security issues to a certain degree.
3624• When insiders utilize network resources, they have an eye on the
3625security level of these and remember the softest targets.
3626• When they discover the passwords of other users, they keep track
3627of them. This might happen by looking over someone’s shoulder or
3628simply because the person called and asked for a favor.
3629• Insiders perform their information-gathering carefully and never per-
3630form any suspect activity on the company network (prior to choos-
3631ing the target and moment).
3632These assumptions match a large number of employees of an average
3633company. Insiders do not have to work in the information technology (IT)
3634department — but they often do.
3635An insider who decides to go for active attacks might go unnoticed for a
3636long time. Even if someone notices failed logins, increased security
3637warnings in the log files about refused file access, or refused connections,
3638the normal assumption is that a flawed configuration is the source of the
3639problem. When the same activities are observed at the perimeter of the
3640network, the system administrator will probably take a closer look. Most,
3641if not all, networks I have seen have several levels of protection on the
3642outside but are simple computer networks on the inside. This applies to
3643small office networks as well as worldwide corporate networks.
3644Consider the scenario in Exhibit 1. This company has several hundreds
3645of computers in a network, some servers, an outside firewall, and a demili-
3646tarized zone.
3647Malory is our hostile insider. He wants to do some harm to the company
3648without getting caught. Alice, working as firewall administrator, is con-
3649nected to the same company network. Because Alice does not want to walk
3650over to the other building where the firewalls are located, she has permit-
3651ted her PC to access the firewall.
3652The attack is pretty straightforward: Malory attacks — and successfully
3653breaks into — Alice’s PC and installs a customized Trojan horse application
3654© 2004 by CRC Press LLC
3655that supports keyboard logging. Now, he calls Alice and reports issues with
3656the firewall. Alice connects to the firewall and enters her username and
3657password into the appropriate dialog. Malory watches the process.
3658Of course Alice does not find anything, but this is not unusual. Malory con-
3659tinues to log every key Alice presses for some days and thereby collects
3660her Windows username and password as well as some other interesting
3661information. When Alice goes to lunch and locks her screen, Malory uses
3662the remote takeover functionality of his Trojan application to unlock the
3663screen, logs into both firewalls, and changes the first rule to allow any
3664inbound and outbound traffic. Then, he uses the Trojan application to
3665remove all traces of it on Alice’s PC. Now, Malory connects to the next best
3666IRC server, joins some cracker’s channel, and tells everyone that a com-
3667pany just messed with its firewall and he happened to notice that. He gives
3668out the IP address range and disconnects.
3669Now, the only place where traces of his activity could be found are
3670Alice’s and Malory’s PCs. But who would suspect Malory in the first place?
3671The result would be noticed first by customers connecting to the Web
3672server and seeing a defaced Web page. After a range of attackers from the
3673outside established a foothold in the company’s network, the responsible
3674staff would be busy for some time trying to block further incidents. If the
3675intrusions are not obvious and Malory contacted some skilled Black Hats,
3676this can go unnoticed for several days.
3677The “moral†is this: Hostile insiders are as (if not more than) dangerous
3678as the people outside of your firewall.
3679Corporate Politics
3680It may seem strange to list corporate politics as an “enemy†of good secu-
3681rity and an abettor of hacking activity, but in a good portion of corpora-
3682tions this is an accurate statement. One could ask, for example, why the
3683Exhibit 1. Company Configuration
3684LAN
3685DMZ
3686Internet
3687Firewall 1
3688Web
3689Mail
3690Firewall 2
3691Internal Network
3692Malory
3693Alice
3694© 2004 by CRC Press LLC
3695chief executive officer (CEO) of a corporation might be listed as an oppo-
3696nent of the security administrator. He is a placeholder for a more complex
3697management situation. The general issue — and most readers will know
3698this from their own experience — is that the security administrator or the
3699security officer is responsible for companywide security but does not have
3700the right to tell others how to plan, design, implement, and operate their
3701systems. This is a common dilemma and no golden way around it exists.
3702The interests of several groups are affected when security measures are
3703taken. The art of security management is to make sure the other parties
3704feel comfortable with the actions taken or required. If they can at least
3705accept them, the opponent CEO is no longer an issue.
3706A problem arises when internal company politics are used to force a
3707certain software solution or concept into production despite the security
3708manager warning about it. Security people fight external attackers every
3709day, but tend to retreat when it comes to conflicts with their own manage-
3710ment. It is not a nice situation to fight battles in your own working environ-
3711ment, but the most successful security managers and administrators do it.
3712Their goal is to have a secure network, keep it up and running, and mitigate
3713the effects of new viruses or internal attacks. If this means they get angry
3714looks at the coffee corner, they accept it. This should not be misunder-
3715stood. Readers are not encouraged to argue with each and every manage-
3716ment peer about new implementations and existing procedures until
3717everyone hates them. It is rather a warning that the reader may sometimes
3718be required to resist the desire to just agree with a dangerous solution
3719because it makes his or her life easier. It does not. In the long term — and
3720experience at many companies proves this — the dedicated security man-
3721ager or administrator will have a better reputation, even beyond the
3722boundaries of the company.
3723Conclusion
3724This chapter has attempted to draw together some “threads†in terminology
3725commonly used to describe the hacking community and its motivations and
3726objectives. Hopefully, it has also demonstrated that hacking motivations are
3727complex and difficult to quantify; some of the “profiles†and terminology
3728typically used to describe hackers and their motivations are misleading in
3729the sense that there are sometimes extremely “thin†lines that divide the
3730White Hat, Gray Hat, and Black Hat communities. This does not make the
3731terminology useless, as long as the broader spectrum and complexity of
3732the hacking community are well understood.
3733The chapter also presented some differing perspectives on the subject
3734of “ethics†and some of the controversy surrounding the “full disclosureâ€
3735movement. As with any discussion on the subject of “ethics†(and though
3736there are some reasonable ground rules for the security community) — the
3737© 2004 by CRC Press LLC
3738subject appears much more complex when viewed from the perspective of
3739the attacker. The final chapter section made some fundamental points
3740about some of the “enemies†of sound organizational security — some of
3741whom operate within the confines of your own organization.
3742The fundamental idea is to
3743draw your own conclusions.
3744The intent was to
3745stir up some debate on this subject, because ultimately any attempt to
3746strictly map out the hacking community or its motivations will fall short
3747when it comes to the examination of a specific incident or the motivations
3748of a particular individual. This is ultimately what presents the challenge in
3749analyzing the moves and countermoves of your opponent, and in improv-
3750ing your own “chess game.â€
3751Notes
37521. Dan Farmer, Wietse Venema, 1993. “Improving the Security of Your Site by Breaking
3753Into It,†(http://www.fish.com).
37542. Reference, “Hacker versus Cracker,†Bob Woods (CNN/Newsbyte).
37553. Reference,
3756The New Hacker’s Dictionary
3757, 3rd Ed., Eric S. Raymond, MIT Press.
37584. The context for this comment was the U.S. spy plane incident of 2001.
37595. See http://bofh.ntk.net.
37606. For all readers who do not know how to read this, it says: “Your security sucks,
3761generic hacker.â€
37627. Reference http://www.securityfocus.com for additional information on full disclosure.
3763© 2004 by CRC Press LLC
3764Chapter 4
3765Anatomy
3766of an Attack
3767To play chess and formulate a strategy, you have to understand the capa-
3768bilities of the pieces on the chessboard. This chapter and the following
3769chapter (“Your Defensive Arsenalâ€) detail the offensive and defensive capa-
3770bilities of the chess players in the hacking vs. security “chess game.â€
3771This chapter presents an overall anatomy of an attack and a taxonomy
3772of the tools appropriated in this process; it provides a technical profile of
3773various forms of hacking activity and serves as a frame of reference for the
3774remainder of the book. Taken as a whole, it provides a reasonable tactical
3775model for the process of sketching and constructing an attack, comple-
3776mented by a technical overview of the tools and exploits employed in this
3777process. The overall intent is to provide a framework that “hackers†(in
3778the broadest sense) can draw upon in dissecting and examining exploits
3779and attack tools and a foundation for the application and protocol mate-
3780rial presented later in this book. Detailed discussion of certain material
3781(buffer overflows, IP spoofing, etc.) is deferred to later chapters, but all
3782material is referenced in this chapter for completeness. The first section
3783of this chapter presents a literal model for navigating the material pre-
3784sented throughout the book, as an aid to understanding attack anatomy.
3785This chapter is structured around the following framework:
3786•
3787Reconnaissance.
3788This section details the techniques and tools that
3789can be used by a prospective attacker to gather information about
3790a system, server farm, or network. This includes mechanisms that
3791can be employed on a Local Area Network (LAN), behind a firewall,
3792as well as Internet-facing techniques for information gathering.
3793•
3794Mapping Targets.
3795This section documents the types of tools appro-
3796priated by attackers to map target systems, networks, and services.
3797War-dialers, network discovery tools, and port and vulnerability
3798scanners are examined in some detail, as are techniques for using
3799ICMP and TCP stack fingerprinting techniques to map IPs and services
3800to systems.
3801© 2004 by CRC Press LLC
3802•
3803System/Network Penetration.
3804Specific application and network
3805attacks are detailed in Chapters 9 through 15; this chapter section
3806introduces key terminology and overviews the mechanics of com-
3807mon application and protocol hacking techniques, such as buffer
3808overflows, account cracking, spoofing, and war dialing.
3809•
3810Denial-of-Service.
3811Denial-of-service (DoS) is treated, in parallel with
3812system/network penetration, as an objective of hacking activity;
3813denial-of-service tools are detailed, along with the types of resource
3814constraints exploited in denial-of-service attacks, such as memory,
3815disk space, CPU cycles, etc.
3816•
3817Consolidation.
3818“Consolidation†refers to the techniques employed by
3819attackers to consolidate system and network gains, evade security
3820controls, and avoid detection. The bulk of the material on consoli-
3821dation is presented in Chapter 16; aspects of consolidation are intro-
3822duced in this chapter section to complete the attack “anatomy.â€
3823•
3824Security.
3825The “Security†section of this chapter utilizes a table conven-
3826tion applied throughout the book as a tool for mapping attacks to
3827prospective defenses; the security technologies chapter that follows
3828(Chapter 5, “Your Defensive Arsenalâ€) explores defensive technologies
3829and their strengths (and limitations) in much greater detail.
3830Overview
3831Exhibit 1 illustrates the attack framework applied throughout this chapter
3832and correlates it with specific chapters that provide continuing technical
3833and supporting information.
3834This “model†is intended not so much as a literal attack framework, but
3835as a broad frame of reference for the material presented throughout this
3836book; in practice, system and network attacks can be complex and convo-
3837luted, as indicated in the case study chapter (Chapter 2). Notwithstanding,
3838the framework adopted in this chapter for the analysis of attack strategy
3839and attack tools should provide a decent strategic context for the technical
3840details explored in this and later chapters.
3841Reconnaissance
3842The term “reconnaissance†as applied to hacking activity references a
3843range of information-harvesting activities that precede any attempt to
3844launch malicious packets at a target network. The premise behind these
3845activities is to profile an organization, its operations, administrative staff,
3846and systems and network infrastructure to craft an effective attack strat-
3847egy; this is applicable whether the actual assault is formulated as a denial-
3848of-service, social engineering, application attack, or information theft. It is
3849worth noting that even in instances where the “attacker†already has con-
3850siderable organizational reconnaissance (such as when an unauthorized
3851© 2004 by CRC Press LLC
3852employee seeks to gain access to confidential data), significant technical or
3853“social†reconnaissance may still be conducted.
3854Some types of reconnaissance activity can be detected by a target
3855organization, such as certain social engineering or site reconnaissance
3856activity, but the vast majority of resources for information gathering are
3857Internet-based and therefore offer the perpetrator complete anonymity
3858and legality. To the authors’ knowledge, no
3859widely available
3860detective tech-
3861nologies allow an individual or organization to isolate Internet reconnais-
3862sance activity (such as repeated use of Internet search engines to perform
3863keyword searches). Reinforcing this is the fact that most of these activities
3864involve public information.
3865Overall, the goal of hacking-related reconnaissance is to improve the
3866probability that an attack against a target network will be successful and to
3867improve the attackers’ odds of successfully masking their identity. Using
3868the chess game analogy, we could liken this to the “mental walk-through†a
3869player might perform prior to executing a chess move.
3870Social Engineering and Site Reconnaissance
3871Social engineering, in the context of reconnaissance activity, refers to the
3872gathering of useful reconnaissance data by requesting the information
3873from an employee or contractor of the target company. Generally, this is
3874achieved by using social engineering techniques to manipulate an individ-
3875ual’s conscience or sense of social norms to persuade that person to
3876Exhibit 1. Anatomy of an Attack Overview
3877Reconnaissance
3878Social Engineering (Ch. 4)
3879Site (Physical) Reconnaissance (Ch. 4)
3880WWW Reconnaissance (Ch. 4, Ch. 12)
3881IP/Network Reconnaissance (Ch. 4,
3882Ch.7 & 8)
3883DNS Reconnaissance (Ch. 4, Ch. 9)
3884Mapping Targets
3885System/Network Penetration
3886Account/Password Cracking (Ch. 4, Ch. 5)
3887Application Attacks (Ch. 9-15)
3888Cache Exploits (Ch. 9-15)
3889File System Hacking (Ch. 16, Ch. 17)
3890Hostile Code (Ch. 14)
3891Programming Tactics (Ch. 6)
3892Process Manipulation (Ch. 16, Ch. 17)
3893Shell Hacking (Ch. 16, Ch. 17)
3894Session Hijacking (Ch. 7, Ch. 8)
3895Spoofing (Ch. 7, Ch. 8)
3896State-based Hacking (Ch. 5, 7, 12)
3897Traffic Capture (Ch. 7, Ch. 8)
3898Trust Relationship Exploitation (Ch. 16, 17)
3899Denial-of-Service
3900System-based (Ch. 4, all services)
3901Network-based (Ch. 4, Ch. 15)
3902Consolidation
3903Extending Access (OS & Network
3904Facilities) (Ch. 16)
3905Extending Access (Foreign Code)
3906(Ch. 16)
3907Trojans
3908Backdoors
3909Rootkits
3910Kernel-level Rootkits
3911Evading Security Controls (Ch. 5,
3912Ch. 17)
3913Logging, Auditing and IDS Evasion
3914(Ch. 17)
3915Forensics Evasion (Ch. 17)
3916War Dialing (Ch. 4)
3917Network Mapping (Ch. 4)
3918Port Scanning (Ch. 4)
3919Vulnerability Scanning (Ch. 4)
3920Researching and Probing
3921Vulnerabilities (Ch. 4)
3922© 2004 by CRC Press LLC
3923release information to an impostor with a probable-sounding story. Candi-
3924date stories might include everything from the telephone company
3925employee, who is really a phone “phreak†attempting to harvest useful
3926phone system data, to the new management employee, who contacts a cor-
3927porate helpdesk to request a password or token reset, but is actually a
3928remote intruder.
3929Social engineering activities are often regarded as far-fetched or ludi-
3930crous but are actively engaged in and generally represent the most imme-
3931diate way to gather information that might be used in a site, network, or
3932voice-based attack. Frequently, social engineering techniques are com-
3933bined with other types of hacking reconnaissance to construct an attack or
3934exploit; a hacker may not be able to utilize an account appropriated
3935through social engineering as part of an Internet attack, for example, but
3936may find a way to employ the account once he or she has gained a presence
3937on a target network.
3938Various types of site reconnaissance (dumpster diving, site and conver-
3939sation monitoring, and site penetration) can also be used to supplement
3940Internet information harvesting and are broadly considered types of
3941social engineering activity. Paper or media retrieval, in particular, can har-
3942vest a wealth of information about an organization’s operations, account
3943management practices, information technology infrastructure, and
3944administrative contacts.
3945Exhibit 2 indicates the types of reconnaissance data (electronic, paper,
3946and media based) that could be engineered from an organization and that
3947would be of potential interest to an intruder.
3948Sadly, social and site engineering attacks are almost always effective at
3949gathering useful reconnaissance data, particularly where an attacker is
3950able to accumulate information that can be used to spawn further recon-
3951naissance (e.g., voicemail or system accounts, points of contact, etc.).
3952Internet Reconnaissance
3953A mass of reconnaissance data (personal and organizational) can be
3954derived from the Internet; much of this reconnaissance can be useful to
3955hackers looking for business, social, or technical information to use to
3956instigate an attack.
3957The following types of general reconnaissance can be obtained from the
3958Internet:
39591
3960•
3961Employee data.
3962Employee titles, contact telephone numbers, e-mail
3963addresses, and areas of responsibility (including, perhaps, recent
3964project assignments) are often easily obtained. Much of this data
3965could be used in a social engineering attack. Telephone numbers
3966© 2004 by CRC Press LLC
3967could be appropriated for war-dialing activity. E-mail addresses pro-
3968vide clues to account conventions and can be a good starting point
3969for account harvesting activities.
3970•
3971Business partners.
3972Clues about business partners can provide a hacker
3973with other potential avenues of attack. Business partners and joint
3974ventures can provide fodder for social engineering activity; knowledge
3975of partners and potential network and applications connectivity can
3976also provide additional “routes†into the target organization.
3977Exhibit 2. Types of Reconnaissance Data of Potential Interest to an Intruder
3978Information Format or Source Hacking Utility
3979Account/password
3980information
3981Paper (Post-It notes,
3982notepads, printouts),
3983removable media
3984(diskettes, tapes,
3985compact disks [CDs]),
3986help desk or IT staff,
3987telephone lists
3988Account names can be
3989gathered from various
3990sources (e-mail lists,
3991telephone lists, etc.);
3992passwords may be socially
3993engineered from an IT or
3994corporate help desk function.
3995Telephone numbers and
3996telephone system
3997reconnaissance
3998Paper (Post-It notes,
3999notepads, printouts),
4000help desk or IT staff,
4001telephone lists
4002Telephone numbers can be
4003used to orchestrate a social
4004engineering attack (by
4005contacting key individuals
4006or functions, such as the
4007corporate help desk);
4008numbers may also be
4009appropriated for a war-
4010dialing effort
4011a
4012System reconnaissance
4013(e.g., IP addresses,
4014hostnames, services,
4015applications)
4016Paper, removable media
4017(backups), help desk
4018or IT staff, system
4019documentation,
4020system theft
4021System reconnaissance could
4022be pieced together from
4023multiple sources, but social
4024engineering might provide
4025an opportunity to gather
4026this information covertly
4027Network maps and
4028network
4029documentation (e.g.,
4030IP addresses,
4031hostnames, services,
4032applications, network
4033security controls)
4034Paper, removable media
4035(backups), help desk
4036or IT staff
4037Gathering network
4038reconnaissance on perimeter
4039devices and perimeter
4040security controls, in
4041particular, can assist an
4042attacker in planning an attack
4043Proprietary or
4044confidential data
4045Paper, removable media,
4046staff, system theft
4047Difficult to quantify; this could
4048represent any kind of
4049competitive, financial, or
4050personal data
4051a
4052See below for information on war-dialing activities; war-dialing is the practice of using a
4053software tool and modem to dial through a company’s DID or analog telephone number
4054ranges looking for a system or device with an unsecured modem.
4055© 2004 by CRC Press LLC
4056•
4057Existing technologies.
4058Certain organizations may advertise informa-
4059tion about the technologies (hardware and software) they have
4060employed in constructing their Internet or extranet infrastructure.
4061Employees may also unintentionally disclose information about
4062specific technologies through mailing lists and newsgroups. If an
4063IT employee submits a question to a newsgroup forum concerning
4064a configuration issue with an Apache Web server running on the
4065Solaris 8 operating system, that person has divulged information
4066an “eavesdropper†can use in formulating an attack.
4067•
4068Financial information.
4069Public corporations, in particular, are required
4070to disclose a great deal of financial data. Commercial organizations
4071often choose to disclose certain types of financial data on corporate
4072Web sites or specific financial forums for the benefit of investors,
4073shareholders, and employees (for example, annual reports, financial
4074news, etc.). Some of this data, such as information on subsidiaries
4075and initiatives, can provide clues about facilities a hacker might be
4076able to appropriate in crafting an attack.
4077•
4078Proprietary data.
4079The authors have worked with scientific organiza-
4080tions and pharmaceutical companies whose scientists and other
4081employees do not always appreciate the monetary or competitive
4082value of information they divulge in technical forums and the Inter-
4083net. In other words, a “hacker†engaged in industrial espionage may
4084not need to break into the target organization’s network or facilities
4085to obtain useful competitive data. The organization’s employees may
4086literally be giving the information away.
4087An audit of Internet reconnaissance material, using some of the tools
4088indicated below, will generally reveal the “state†of an organization’s immu-
4089nity to Internet-based reconnaissance gathering.
4090Tools
4091Tools that can be appropriated for Internet reconnaissance activity include
4092the following:
4093Internet Search Engines and Usenet Tools
4094Internet search engines
4095such as Lycos, AltaVista, Hotbot, Google, and Excite
4096provide facilities such as Internet directories, link crawlers, and caches
4097that increase the probability that a hacker will be able to get a “hit†on
4098information useful to perpetrating an attack against the target organiza-
4099tion. Multiple search engine sites and search engine “suites†that provide
4100the capability to search several search engines or resources in parallel can
4101produce more effective Internet searches. These tools can considerably
4102cut the amount of time it takes to harvest Internet reconnaissance in the
4103form of news postings, mailing list articles, and Web pages.
4104© 2004 by CRC Press LLC
4105Usenet newsgroup postings
4106can also contain a wealth of information for
4107hackers conducting organizational and technical reconnaissance. Individu-
4108als and employees frequently submit technical questions regarding platform
4109and application issues to newsgroups in the form of requests for technical
4110assistance. These types of postings can reveal useful information about
4111potential security vulnerabilities. Newsgroups also make excellent forums
4112for social engineering activity.
4113Mailing lists
4114and mailing list archives often contain the same kinds of
4115technical reconnaissance and can be searched using one of the search
4116engines referenced in Exhibit 3.
4117Financial Search Tools, Directories, Yellow Pages, and Other Sources
4118Numerous financial search tools for gathering reconnaissance data on spe-
4119cific companies (and publicly traded companies, in particular) are available
4120(see Exhibit 4). The types of financial and business data accessible via these
4121tools include mergers and acquisition information, information regarding
4122corporate subsidiaries and business partners, and information on key prod-
4123ucts and business or IT initiatives. “Peripheral†financial data, such as large
4124technology expenditures, new product(s), and financial news stories, can
4125also be valuable. Any or all of this information might be useful to an intruder
4126searching for a means to gain ingress into a target network or organization.
4127Business and residential phone directories and yellow pages can also be
4128useful in gathering employee reconnaissance that might assist in account
4129cracking activity. If crackers can obtain information about an individual’s
4130interests, resumé, family members, or affiliations, they may be able to more
4131accurately predict password selection or identify other forums in which an
4132employee might have disclosed reconnaissance. Significant information on
4133companies and individuals can also be obtained from online news sources,
4134industry publications, corporate Web sites, and search engines that cater
4135to the retrieval of personal information.
4136Exhibit 3. Search Engines
4137Tool Location
4138Internet Search Engines
4139AltaVista http://www.altavista.com; http://news.altavista.com
4140Excite http://www.excite.com
4141Google http://www.google.com; http://groups.google.com
4142Lycos http://www.lycos.com
4143Multi-Search Engines and Search Engine “Suitesâ€
4144Dogpile http://www.dogpile.com
4145WebFerretPRO http://www.ferretsoft.com
4146© 2004 by CRC Press LLC
4147IP and Network Reconnaissance
4148It should be intuitive, but some initial (and ongoing) IP and technical recon-
4149naissance needs to occur prior to the selection of target systems and
4150services for attack activity. From a high-level perspective, this activity can
4151be encapsulated as detailed in Exhibit 5.
4152This section addresses some of the tools at the disposal of hackers for
4153the purposes of gathering host and network IP information; the sections
4154that follow explore methods of augmenting host reconnaissance via
4155Exhibit 4. Financial Search Tools, Directories, Yellow Pages, and Other Sources
4156Tool Location
4157Financial Search Tools
4158Securities and Exchange Commission (SEC)
4159“EDGAR†database
4160http://www.sec.gov/edgar.shtml
4161NASDAQ http://www.nasdaq.com
4162New York Stock Exchange (NYSE) http://www.nyse.com
4163Hoovers http://www.hoovers.com
4164Dun & Bradstreet http://www.dunandbradstreet.com
4165Directories, Yellow Pages, and Similar Sources
4166Phone directories and yellow pages http://www.bigyellow.com
4167News and business news sources http://www.cnn.com
4168http://www.nytimes.com
4169http://www.msnbc.com
4170http://money.cnn.com
4171Industry publications and sites http://www.businessweek.com
4172http://www.forbes.com
4173http://www.i-medreview.com
4174http://www.ama-assn.org
4175People pages and search engines http://www.whowhere.com
4176http://www.ussearch.com
4177http://www.usafind.com
4178Exhibit 5. Process for Gathering IP and Network Reconaissance
4179Network Identification
4180Registrar Searches
4181whois Searches
4182ARIN Searches
4183IP (Host) Identification
4184DNS Queries and Zone Transfers
4185(next section)
4186ICMP Queries
4187Service Identification
4188Port Scans
4189Service Enumeration
4190Vulnerability Scans
4191© 2004 by CRC Press LLC
4192DNS, ICMP, and port/vulnerability scanning activity (which is used in
4193service enumeration).
4194Registrar and whois Searches
4195There are a number of Internet registrars (Network Solutions, InterAccess,
41961stDomain.net, etc.) responsible for maintaining information on Internet
4197address allocations, domain names, and associated organizations and con-
4198tacts for specific areas of the Internet DNS. This information is maintained in
4199whois databases that can be searched using command-line or Web interface
4200versions of the UNIX whois client. DNS is a sound place to start in attempting
4201to map IP addresses to target organizations because its function is to serve
4202as an Internetwide host directory for IP and service information.
4203Prior to performing any comprehensive IP or DNS reconnaissance, an
4204attacker may have little more than an organization name to begin
4205“hacking†with; by performing whois searches against a specific Internet
4206registrar, using this organization name (or any affiliated names), it is possi-
4207ble to produce a list of all DNS domains owned by the target organization
4208(see Exhibit 6).
4209The first step in this process is to identify the registrar that owns
4210registrations for a particular DNS domain. A list of the registrars respon-
4211sible for registrations for the .com, .net, and .org domains is maintained
4212by ICANN
42132
4214at http://www.icann.org/registrars/accredited-list.html
4215.
42163
4217Reg-
4218istrars for domains other than .com, .net, and .org
4219can be identified using
4220http://www.allwhois.com (domains outside of the top-level domains and
4221non-U.S. domains), or http://whois.nic.mil (U.S. military domains). Once the
4222registrar has been identified, an attacker can drill down (see Exhibit 7) to
4223Exhibit 6. Producing a List of All DNS Domains Owned by the Target
4224Organization
4225$ whois “targetorganization. “@whois.crsnic.net
4226[whois.crsnic.net]
4227Whois Server Version 1.1
4228Domain names in the.com,.net, and.org domains can now be
4229registered with many different competing registrars. Go to
4230http://www.internic.net for detailed information.
4231TARGETORGANIZATION.COM
4232TARGETORGANIZATION.NET
4233TARGETORG.COM
4234TARGETORGSUBSIDIARY.COM
4235TARGETORGSUBSIDIARY.ORG
4236© 2004 by CRC Press LLC
4237obtain additional information about the name servers that house the domain
4238zone data (these are the target organization’s master/slave name servers).
4239Exhibit 8 documents the various types of whois queries that can be
4240issued against one of the registrar whois databases.
4241The information yielded by a whois query can be used in specific types
4242of social engineering or Internet attacks; aside from the obvious value of IP,
4243network, and DNS reconnaissance, some of the data represented above
4244(such as contact names, e-mail addresses, and telephone numbers) can be
4245appropriated for account cracking or social engineering activity.
4246Tools
4247A partial list of additional whois resources is provided in Exhibit 9; some
4248of these whois sites apply to IP network registrations and would be used spe-
4249cifically to obtain IP information for a target organization.
4250Network Registrar Searches (ARIN)
4251In addition to the domain registrars indicated above, the Internet has a
4252series of network registrars who maintain whois databases that map
4253Exhibit 7. Drilling Down to Obtain Additional Information about the Name
4254Servers
4255$ whois targetorganization.com@whois.networksolutions.com
4256[whois.networksolutions.com]
4257Registrant:
4258Target Organization, Inc. (TGTORG1-DOM)
425927 Lansdowne Drive
4260Boston, MA 02109
4261Domain Name: TARGETORGANIZATION.COM
4262Administrative Contact, Technical Contact, Zone Contact:
4263Smith, Andrew [Network Operations Manager] (AS1705)
4264asmith@TARGETORGANIZATION.COM
4265617-992-7170 (FAX) 617-992-1210
4266Record last updated on 18-Mar-99.
4267Record created on 15-Jun-95.
4268Database last updated on 17-Apr-00 15:06:52 EDT.
4269Domain servers in listed order:
4270NS1.TARGETORGANIZATION.COM 1.2.3.4
4271NS2.TARGETORGANIZATION.COM 5.6.7.8
4272© 2004 by CRC Press LLC
4273organizations to IP allocations or networks; a portion of these registrars was
4274indicated in “Registrar Searches,†above. For organizations in the United
4275States, for example, ARIN (American Registry for Internet Numbers) maintains
4276information about the IP allocations assigned to particular organizations.
4277ARIN provides a Web interface for whois queries at http://www.arin.net/
4278whois/arin-whois.html, but ARIN queries can also be issued using a command-
4279line whois query:
4280$ whois “targetorganization.com. “@whois.arin.net
4281[whois.arin.net]
4282Target Organization (ASN-XXXX) XXXX 99999
4283Target Organization (NETBLK) 1.1.1.1 – 1.1.1.254
4284Tools
4285Refer to the tools section of “Registrar and whois Searches†for additional
4286information on whois sources for IP and network data.
4287Exhibit 8. whois Queries
4288Query Type Hacking Reconnaissance Query Example
4289Corporate or
4290organization
4291queries
4292Provides all data relevant to
4293a particular organizational
4294name
4295whois “name target organizationâ€
4296@whois.crsnic.net
4297Organizational
4298contacts
4299Provides contact information for
4300administrator(s) of
4301a particular domain
4302whois “name matthews, scottâ€
4303@whois.crsnic.net
4304whois “targetorg.comâ€
4305@whois.crsnic.net
4306Domain queries Provides all data relevant to
4307a particular DNS domain
4308whois “targetorg.comâ€
4309@whois.crsnic.net
4310whois “targetorg.â€
4311@whois.crsnic.net
4312whois targetorg.com
4313@whois.crsnic.net
4314Host queries Provides information about a
4315particular host (for example,
4316a name server)
4317whois “host 1.2.3.4â€
4318@whois.crsnic.net
4319NIC handles Provides data on the particular
4320object associated with the NIC
4321handle (organization, host,
4322or contact)
4323whois “handle AB1234â€
4324@whois.crsnic.net
4325IP or network
4326queries
4327Data containing network or host
4328IP assignments
4329(These types of searches
4330are conducted using the
4331appropriate network registrar
4332a
4333)
4334whois “targetorg.comâ€
4335@whois.arin.net
4336(where ARIN is the appropriate
4337network registrar)
4338a
4339See “Network Registrar Searches (ARIN),†below.
4340© 2004 by CRC Press LLC
4341DNS Reconnaissance
4342The DNS
43434
4344is an ideal vehicle to use to conduct host and IP reconnaissance
4345because it effectively delivers a distributed database of all kinds of host-
4346related information. The identification of a host resource record via a stan-
4347dard DNS query is a pretty good indication of a “live†target (or targets),
4348although a hacker conducting IP reconnaissance will generally want to ver-
4349ify this via ICMP queries or port probes.
43505
4351Client-side resolver utilities, such
4352as dig or nslookup, or DNS reconnaissance tools (for example, SolarWinds
4353or Sam Spade) can be used to harvest DNS data; the reconnaissance tools
4354generally speed the data gathering process, but essentially issue the same
4355standard DNS queries.
4356The types of information (really, resource records) listed in Exhibit 10
4357can be obtained through the interrogation of DNS servers.
4358Identifying hosts, IP addresses, and services using individual, directed
4359DNS queries can be laborious and result in the omission of specific DNS
4360resource records from the search because the attacker never gets a complete
4361picture of the DNS domain. For this reason, most attackers gathering DNS
4362reconnaissance will work from an initial DNS zone transfer and then hone this
4363reconnaissance using some of the specific DNS queries identified in Exhibit 10.
4364Zone transfers
4365are the facility provided in DNS to allow administrators to
4366configure a set of zone files (a DNS database, essentially) on a single master
4367Exhibit 9. Additional whois Servers and Tools
4368whois Servers and Tools Universal Resource Locator (URL)
4369whois Servers
4370U.S. IP allocations http://www.arin.net/whois/arin-whois.html
4371European IP allocations http://www.ripe.net
4372Asia Pacific IP allocations http://whos.apnic.net
4373U.S. government http://whos.nic.gov
4374U.S. NIC (.us domain) http://nic.us/policies/whois.html
4375.biz domain http://www.whois.biz/
4376.com, .org, .net, .edu domains http://www.crsnic.net/whois
4377Internet/whois Tools
4378NetInfo http://www.netinfo.co.il
4379Netscan tools http://www.nwspsw.com
4380Registrar whois Web interfaces e.g., http://www.netsol.com/cgi-bin/whois/whois;
4381www.arin.net/whois/arin-whois.html
4382Sam Spade http://www.samspade.org
4383WS Ping ProPack http://www.ipswitch.com
4384Xwhois http://www.oxygene.500mhz.net/whois
4385© 2004 by CRC Press LLC
4386Exhibit 10. Types of Information on DNS Servers
4387Query Type Syntax Hacking Reconnaissance
4388Name servers (NS)
4389nslookup:
4390Set q = ns
4391targetdomain.com
4392dig:
4393dig targetdomain.com ns
4394NS records identify the master
4395(primary) and slave
4396(secondary) name servers for
4397a domain; once these have
4398been identified, they can be
4399queried for specific DNS
4400records or polled for a
4401zone transfer
4402Host address
4403(A – IPv4 record)
4404(AAAA – IPv6
4405record)
4406nslookup:
4407Set q = a
4408host.targetdomain.com
4409dig:
4410dig targetdomain.com a
4411“A†records provide a host-to-IP
4412mapping for a specific host;
4413performing an “A†record
4414query should return the IP
4415address for the hostname
4416provided; an “A†record
4417lookup can provide a hacker
4418with an IP (or set of IPs) to
4419target in hacking activity
4420Reverse lookup
4421(PTR)
4422nslookup:
4423Set q = ptr
44244.3.2.1.in-addr.arpa
4425dig:
4426dig 4.3.2.1.in-addr.arpa
4427A “reverse†(PTR) record
4428lookup returns the hostname
4429for a given IP (using the in-
4430addr.arpa syntax specified in
4431the example); this may be
4432useful in instances where a
4433hacker has conducted some
4434broad ping or port scans and
4435needs to verify the identities
4436of vulnerable hosts
4437Mail server (MX)
4438nslookup:
4439Set q = mx
4440targetdomain.com
4441dig:
4442dig targetdomain.com mx
4443A mail server (MX) lookup
4444returns a list of mail servers
4445(ordered by preference value)
4446for a given target domain;
4447obtaining a list of the SMTP
4448servers for a given domain
4449can provide hackers with a set
4450of targets for mail hacking
4451a
4452Host information
4453(HINFO)
4454nslookup:
4455Set q = hinfo
4456targetdomain.com
4457dig:
4458dig targetdomain.com hinfo
4459HINFO records are generally
4460deprecated because they
4461can provide useful
4462reconnaissance on host
4463hardware or software
4464configurations; some
4465organizations still employ
4466them for Internet hosts or
4467may link “privateâ€
4468HINFO records
4469© 2004 by CRC Press LLC
4470name server but populate a set of slave name servers with the same data.
4471To achieve this, slave name servers “poll†the master for database updates
4472on a periodic basis and pull new copies of the zone data via a zone transfer,
4473as necessary. Most administrators will configure the master server so that
4474it only allows updates to a specific list of slave name servers; however, not
4475all organizations implement appropriate IP or digital signature controls for
4476zone transfers. The authors know of some sizeable Internet Service Providers
4477and Internet organizations that allow DNS zone transfers to any host.
4478To perform a manual zone transfer, a client-side resolver utility such as
4479nslookup or dig can be used in interactive mode, with the appropriate DNS
4480“xfer†options:
4481$ nslookup
4482Default Server: ns1.localdnsserver.com
4483Address: 1.1.1.1
4484First, direct nslookup to use the target’s master name server for the
4485zone transfer:
4486> server ns1.targetorganization.com
4487Default Server: [ns1.targetorganization.com]
4488Address: 1.2.3.4
4489Then, perform the zone transfer to the local file system (the targetorga-
4490nization.com.dns file), using nslookup’s “ls –d†option:
4491Exhibit 10 (continued). Types of Information on DNS Servers
4492Query Type Syntax Hacking Reconnaissance
4493TXT information
4494(TXT)
4495nslookup:
4496Set q = txt
4497targetdomain.com
4498dig:
4499dig targetdomain.com txt
4500TXT records are deprecated for
4501many of the same reasons as
4502HINFO records; they are free-
4503form text records that can
4504contain descriptive
4505information about a host
4506Services (SRV)
4507nslookup:
4508Set q = srv
4509targetdomain.com
4510dig:
4511dig targetdomain.com srv
4512SRV records map services to
4513hosts and therefore can be
4514useful to hackers in
4515identifying target services for
4516hacking activity; certain
4517services and operating
4518systems (e.g., MS Windows
45192000 Active Directory) require
4520these records
4521a
4522Note that this list will not necessarily represent all mail servers on a target’s network.
4523Because many organizations make use of mail relays and mail proxies, a portion of the
4524servers identified may be external to the target network.
4525© 2004 by CRC Press LLC
4526> set type = any
4527> ls –d targetorganization.com.
4528>>/tmp/targetorganization.com.dns
4529The output from the zone transfer (i.e., the contents of targetorganiza-
4530tion.com.dns) might look similar to the following:
4531[ns1.targetorganization.com]
4532targetorganization.com SOA
4533ns1.targetorganization.com
4534dnsadmin.targetorganization.com.(1004028738 14400 7200
4535864000 300)
4536targetorganization.com. NS ns1.targetorganization.com
4537targetorganization.com. NS ns2.targetorganization.com
4538ns1.targetorganization.com. A 1.2.3.4
4539ns2.targetorganization.com. A 5.6.7.8
4540targetorganization.com. MX 0 mail.targetorganization.com
4541mail A 7.8.9.1
4542www A 7.8.9.1
4543>
4544Tools
4545A series of operating system clients, third-party software, and Web tools
4546can be used to gather DNS information; a subset of these tools is listed in
4547Exhibit 11.
4548Exhibit 11. Tools Used to Gather DNS Information
4549Tool Location
4550adig http://nscan.hypermart.index.cgi?index = dns
4551axfr http://ftp.cdit.edu.cn/pub/linux/www.trinix.org/src/netmap/
4552axfr-x.tar.gz
4553Demon Internet http://www.demon.net/external
4554dig http://www.nwspsw.com
4555domtools http://www.domtools.com/dns/domtools.shtml
4556host Included with most UNIX variants
4557Networktools.com http://network-tools.com
4558nsbatch http://www.ntware.com/workstation/dns_tools.html
4559PCS network tools http://www.softlandmark.com/DNSLookup.htm
4560Sam Spade http://www.samspade.org
4561SolarWinds http://www.solarwinds.net
4562© 2004 by CRC Press LLC
4563Mapping Targets
4564Mapping targets involves a range of activities designed to yield information
4565about a target’s network topology, host platforms, and service environ-
4566ment. By honing the initial reconnaissance, using specific mapping and
4567profiling techniques, an attacker can begin to formulate a concrete attack
4568“plan.†This mapping and profiling is the point at which the initial reconnais-
4569sance activity first gives way to active “fingering†of a target network —
4570most of the reconnaissance techniques discussed so far are relatively anon-
4571ymous and inconspicuous. As an attacker begins to actively profile a net-
4572work and specific systems, the attacker will “lob†packets or conduct port
4573probes that have the potential to be picked up by firewalls or intrusion
4574detection systems. For the administrator, this may be the first evidence that
4575an intruder is actively searching for points of entry into the network,
4576whether these represent Internet, dial-up (SLIP/PPP), or wide area network
4577access points.
4578The premise behind this mapping/profiling activity is to bring the attack
4579to the point where the hacker is ready to strike — in other words, to the
4580point at which a vulnerable target system, port, and service have been
4581identified. This process may take anything from a few minutes to months,
4582depending upon the sensitivity and security of the target network and the
4583technical sophistication of the attacker. Mapping and profiling activity will
4584often also encompass some degree of network probing to determine the
4585characteristics of any firewall and intrusion detection technologies
4586employed on the target network; savvy attackers will monitor attack activ-
4587ity and system responses to look for indications that they may have been
4588picked up by an intrusion detection device or firewall.
45896
4590Internal “intrudersâ€
4591may have an advantage in the range of tools and types they can employ to
4592obtain system or network recon without the interference of firewalls and
4593intrusion detection systems (IDSs); they are also likely to be privy to infor-
4594mation about an organization’s security stance that may or may not be
4595available to an external intruder.
4596War Dialing
4597War dialing slots into target mapping as a means of gathering reconnais-
4598sance on unsecured (or poorly secured) modems and modem pools. War
4599dialers essentially target remote access servers and systems running
4600remote access software as a means of gaining access to a network or
4601networked system; because many organizations can have poorly secured
4602modems at some location on their network, war dialing is regarded as a
4603good means of gaining nonfirewalled access to a network.
4604A war dialer (see Exhibit 12) is a software application used to identify
4605phone numbers that can be used to establish a connection to a computer
4606modem; the war dialer dials a defined range of phone numbers and logs to
4607© 2004 by CRC Press LLC
4608a local database any numbers that indicate a successful connection to a
4609modem. Depending on the sophistication of the war dialer, it may also be
4610able to identify the operating system version and remote access software
4611versions and to conduct limited penetration testing to determine whether
4612the “listening†application is vulnerable. This may involve parsing through
4613a list of known accounts or attempting to exploit software vulnerabilities
4614on the basis of “fingerprint†information.
4615In the absence of automatic penetration testing capabilities, it is generally
4616possible to parse through the database looking for successful connections
4617and then attempt to manually crack an account associated with the remote
4618access application.
4619Phone numbers for war dialing activity may be obtained through whois
4620or public telephone directory information or by contacting the target
4621organization and conducting a social engineering attack.
4622Tools
4623A series of commercial and “freeware†war dialers are available for war
4624dialing activity (see Exhibit 13); some of these are available for platforms
4625such as personal digital assistants (PDAs).
4626Network Mapping (ICMP)
4627Having completed some initial network and IP reconnaissance using Internet
4628whois databases and the Domain Name system, the progress of an attack
4629Exhibit 12. Sandstorm Enterprises PhoneSweep War Dialer. Sandstorm
4630Enterprises PhoneSweep dialer is legitimately used in penetration testing
4631activity. Freeware dialers are generally appropriated by attackers for more
4632subversive activity.
4633© 2004 by CRC Press LLC
4634will often warrant confirming the presence of “live†IP targets (and their
4635accessibility) through ICMP port probes and ping sweeps. Using ICMP, an
4636attacker can both validate networked systems and “map†out the topology
4637of the network on which the targets reside, including any gateways, rout-
4638ers, firewalls, and intrusion detection systems; this may have a significant
4639bearing on how an attack proceeds or lead to the identification of addi-
4640tional, vulnerable targets.
4641Network mapping is generally accomplished by employing various tools
4642that use the Internet Control Message Protocol (ICMP).
46437
4644The utility of ICMP
4645for this type of activity is that it was essentially designed for the trouble-
4646shooting of routing and connectivity issues in IP networks, and therefore
4647incorporates features that make it useful for mapping purposes. ICMP mes-
4648sage types such as echo reply (0), destination unreachable (3), redirect (5),
4649and time exceeded (11) provide a great deal of information to hackers
4650about host connectivity and the hop count to a particular system.
46518
4652ICMP Queries
4653ICMP “mapping†is often conducted via a ping sweep using IP network
4654information derived from ARIN (or another network registrar) as input to
4655the “pingâ€; ping sweeps may be conducted using third-party reconnais-
4656sance software or ICMP-based attack tools, by providing a destination list
4657to a standard operating system (OS) implementation of ping, or by building
4658scripts that iterate through a set of IP network and subnet numbers,
4659recording ping responses:
4660#!/bin/sh
4661host_file = hosts
4662for host in $(cat $host_file)
4663Exhibit 13. Commercial and “Freeware†War Dialers Available
4664Tool (Author) Location
4665Verttex ModemScan http://www.verttex.com/
4666PhoneTag http://packetstormsecurity.nl/wardialers/
4667indexsize.shtml
4668Sandstorm PhoneSweep http://www.sandstorm.net
4669SecureLogix TeleSweep Secure http://www.securelogix.com
4670TBA (KingPin, @stake) www.l0pht.com/~kingpin/pilot.html
4671THC-Scan (Van Hauser, THC) http://thc.pimmel.com
4672ToneLoc (Minor Threat, Mucho Maas) http://packetstormsecurity.nl/wardialers/
4673indexsize.shtml
4674© 2004 by CRC Press LLC
4675do
4676ping $host -n 1 | grep -q '1 packets received'
4677if [ $? = 0 ]
4678then
4679echo "$host: live"
4680else
4681echo "$host: down"
4682fi
4683done
4684If the remote attacker has already gathered some reconnaissance data
4685about the target network, he or she may probe individual IPs with an ICMP
4686ping (echo request), perhaps using the organization’s DNS data as a guide.
4687In either instance, systems that respond to a “ping†packet may be targeted
4688for additional activity; it is likely that the IPs of these systems may be used
4689as input to a port scanner to identify the presence of potentially vulnerable
4690services or as the targets for other types of fingerprinting activity.
4691Evidence of repeated ICMP activity from a consistent set of source
4692IP addresses or of ICMP sweeps of sizeable IP allocations, as represented in
4693firewall or intrusion detection logs, may be the very first indication that an
4694intruder is sweeping for vulnerable systems.
4695Consequently, many organizations now block ICMP echo at Internet
4696gateways and perimeter firewalls; certain ICMP tools (such as ICMPEnum)
4697have incorporated options to probe IPs using specific ICMP message types
4698in an effort to get ICMP data through firewalls.
4699Tools
4700Exhibit 14 lists some of the ICMP discovery tools that have ping sweep
4701capabilities.
4702Exhibit 14. ICMP Discovery Tools with Ping Sweep Capabilities
4703Tool (Author) Location
4704Fping (Thomas Dzubin) http://www.fping.com
4705Hping (Salvatore Sanfilippo) http://www.hping.org
4706ICMPEnum (Simple Nomad) http://www.nmrc.org/files/sunix/index.html
4707Nmap (Fyodor) http://www.insecure.org
4708Pinger (Rhino9) ftp://ftp.technotronic.com/rhino9-products
4709Ping Plotter http://www.nessoft.com/pingplotter
4710SolarWinds http://www.solarwinds.net
4711WS_Ping ProPack http://www.ipswitch.com/Products/WS_Ping/index.html
4712© 2004 by CRC Press LLC
4713TCP Pings: An Alternative to ICMP
4714Because many organizations now block inbound pings from public net-
4715works such as the Internet (for improved security), the absence of an echo
4716reply to an ICMP ping packet does not necessarily indicate that a system is
4717inaccessible. Attackers will frequently reinforce ping activity with TCP or
4718User Datagram Protocol (UDP) connection attempts on well-known ports 9
4719(such as TCP port 80, UDP/TCP port 53, etc.) to qualify a host as a potential
4720target. For TCP services, a positive “SYN-ACK†response to an initial “SYNâ€
4721connection request on a specific port verifies the presence of a system
4722listening on the specified port and may be easier to force through a firewall
4723system than an ICMP request (see Exhibit 15).
4724This type of rudimentary port scanning activity can be automated using
4725port scanning or ping sweep tools (such as Nmap, Hping, or Nessus) or
4726utilities such as traceroute.
4727Tools
4728Exhibit 16 lists tools for TCP pings.
4729Traceroute
4730Traceroute (available in most versions of UNIX and Windows 10 ) is an
4731extremely valuable tool for mapping hosts and networks because it pro-
4732vides information about the route a packet takes between two hosts
4733(the source and destination hosts for the traceroute). Traceroute manipu-
4734lates the IP time-to-live (TTL) option in ICMP or UDP packets (depending
4735on the version of traceroute) to obtain an ICMP_TIME_EXCEEDED
4736Exhibit 15. TCP Ping Scan
4737HTTP Server (TCP/80)
4738(Simple) Packet Filtering Firewall
4739Hacker's Client
4740Rule 1: Permit Internet to access Web Server at 5.6.7.8
4741Rulebase
47425.6.7.8
4743SA: 1.2.3.4
4744DA: 5.6.7.8
4745TCP 80 (SYN)
4746Response Packet
4747DMZ Network
4748SA: 5.6.7.8
4749DA: 1.2.3.4
4750TCP 80 (SYN/ACK)
4751(1)
4752(2)
4753(3)
4754SA: 1.2.3.4
4755DA: 5.6.7.8
4756TCP 80 (RST)
4757A response from the remote system indicates that it is "live" and listening on the
4758specified port. A reset is immediately issued by the hacking client to terminate the
4759connection (with the intention of circumventing the firewall and system logfiles).
4760© 2004 by CRC Press LLC
4761message from each hop or router on the path to a destination host. By
4762default, each IP router in the path to a specific destination inspects the IP
4763header in incoming packets, decrements the TTL value in the IP header by
4764one, and then forwards the packet to its destination. Using this mecha-
4765nism ensures that a finite “hop count†can be imposed on IP packets; if and
4766when a packet reaches a TTL value of 30, 11 the final router in the route
4767path decrements the TTL to 0 and responds to the originating host with an
4768ICMP_TIME_EXCEEDED message.
4769Traceroute (see Exhibit 17) manipulates this facility by forwarding
4770packets from the source host with the TTL deliberately set to a specific
4771value; for the first packet generated, traceroute would generate a packet
4772with a TTL value of “1†(as opposed to 30). This ensures that the “end†host
4773(the first and final host in the route path) responds with an
4774ICMP_TIME_EXCEEDED. The next packet is then generated with a TTL of
4775“2†to pick up the next router in the path, and this process is repeated until
4776it delivers information about all routers on the path to the destination.
4777Exhibit 16. TCP Ping Tools
4778Tool (Author) Location
4779Firewalk (Michael Schiffman, David Goldsmith) http://www.packetfactory.net/firewalk
4780Fping (Thomas Dzubin) http://www.fping.com
4781Hping (Salvatore Sanfilippo) http://www.hping.org
4782Internet Security Scanner http://www.iss.net
4783Nessus http://www.nessus.org
4784NetScan Tools http://www.nwpsw.com
4785Nmap (Fyodor) http://www.insecure.org
4786Exhibit 17. Traceroute Operation
4787Server
47885.6.7.8
4789Firewall
4790Hacker's Client
4791Router
4792Router
4793Router
47941.2.3.4
4795NAT Rule
4796Rule 1: Map 1.2.3.4 (FW) to 5.6.7.8 (Server)
4797TTL=1
4798DA: 1.2.3.4
47996.7.8.9
4800Time Exceeded
4801(TTL=1)
4802DA: 6.7.8.9
4803Time Exceeded
4804(TTL=1)
4805DA: 6.7.8.9
4806Time Exceeded
4807(TTL=1)
4808DA: 6.7.8.9
4809TTL=2
4810DA: 1.2.3.4
4811TTL=3
4812DA: 1.2.3.4
4813© 2004 by CRC Press LLC
4814$ traceroute 1.2.3.4
4815Tracing route to 1.2.3.4 over a maximum of 30 hops:
48161 localgw (192.168.1.1) <10ms <10ms <10ms
48172 isprtr.isp.net (5.6.7.8) <30ms <30ms <40ms
4818<…>
48193. destination.domain.com (1.2.3.4) <40ms <40ms <45ms
4820Using the TTL in this way produces a hop count that provides network
4821topology reconnaissance because the source for the TIME_EXCEEDED mes-
4822sage is the “end†router. Because many firewalling devices are configured to
4823block inbound traceroute activity, it is not usually possible to make progress
4824beyond the perimeter firewall on a network, unless the attacker appropriates
4825a tool such as Firewalk to probe ports utilizing TTL exceeded (see the next
4826chapter, “Your Defensive Arsenal,†for additional information on Firewalk).
4827Certain implementations of traceroute (UNIX, for example) support
4828UDP-based traceroute. The ability to use either protocol for the traceroute
4829can be valuable in getting packets through firewalls and other packet filter-
4830ing devices (using ports such as UDP 53 [DNS], for example). Examples of
4831various implementations of traceroute, including UDP implementations,
4832are provided in Exhibit 18.
4833Additional Network Mapping Tools
4834In addition to the ICMP and traceroute facilities referenced above, a range
4835of network reconnaissance tools can be employed to document a network
4836(many of which employ standard network facilities such as ICMP [trace-
4837route], DNS, and SNMP). Some of these tools are “noisier†than others (and
4838therefore, perhaps most useful inside a network perimeter); all of these
4839tools speed the process of gathering network topology data.
4840Tools
4841Exhibit 19 lists additional network mapping tools.
4842Exhibit 18. Implementations of Traceroute
4843Tool (Author) Location
4844Hping (Salvatore Sanfilippo) http://www.hping.org
4845Ping Plotter http://www.nessoft.com/pingplotter
4846SolarWinds http://www.solarwinds.net
4847Traceroute Native to most IP-based OS platforms
4848(including Windows and UNIX)
4849Traceroute (Static UDP version)
4850(Michael Schiffman)
4851ftp://ftp.ee.lbl.gov/traceroute.tar.Z
4852WS_Ping ProPack http://www.ipswitch.com/Products/
4853WS_Ping/index.html
4854© 2004 by CRC Press LLC
4855Port Scanning
4856The last section addressed the identification of “points of access†into a
4857network through IP and network reconnaissance gathering; this section
4858addresses the identification of “points of access†into a host or set of hosts.
4859Once initial network and IP reconnaissance has been completed and an
4860attacker has identified a set of “live†target hosts, the process of homing in
4861on these targets can begin. A significant component of this is the identifica-
4862tion of vulnerable network services. Port scanning technology is generally
4863appropriated for this task.
4864The objectives of port scanning are generally to identify one or more of
4865the following:
4866• Open ports. TCP or UDP ports open on target systems (essentially
4867TCP or UDP listeners).
4868• Host operating system. Port scanners may accomplish this through
4869stack “fingerprinting†(see below). The term “fingerprinting†refers
4870to tools that can draw inferences on OS or application versions from
4871observable packet signatures and network behavior.
4872• Software or service versions. Software or service versions may be
4873identified via “banner grabbing†or application fingerprinting.
4874• Vulnerable software versions. Service or software identification may
4875aid a hacker in picking off vulnerabilities that present opportunities
4876for intrusion or denial-of-service. 12
4877Nmap, for example, is capable of producing the following type of detail
4878for a specific host:
4879Exhibit 19. Additional Network Mapping Tools
4880Tool Location Description
4881Cheops
4882(Mark Spencer)
4883http://www.marko.net/
4884cheops
4885Runs on the Linux operating system,
4886and uses ICMP and traceroute to
4887perform network discovery; also
4888performs TCP stack fingerprinting
4889(to identify system operating
4890systems) and provides a graphical
4891representation of a network
4892SolarWinds http://www.solarwinds.net Uses ICMP, DNS, and SNMP discovery
4893facilities to enumerate a network;
4894the SNMP discovery tools can
4895identify network nodes and
4896enumerate configurations using a
4897preconfigured set of SNMP
4898community strings
4899© 2004 by CRC Press LLC
4900Interesting ports on (1.2.3.4):
4901(The 1023 ports scanned but not shown below are in state:
4902filtered)
4903Port State Service
490421/tcp closed ftp
490523/tcp closed telnet
490625/tcp open smtp
490780/tcp open http
4908Remote OS guesses: AIX v4.2, AIX 4.2, AIX 4.3.2.0-4.3.3.0
4909on an IBM RS/*, IBM AIX v3.2.5 - 4, Linux 1.3.20 (X86)
4910TCP Sequence Prediction: Class = truly random
4911Difficulty = 9999999 (Good luck!)
4912Port scanning tools range in sophistication from tools that purely identify
4913ports and listeners to those that have fairly sophisticated stack finger-
4914printing and application profiling capabilities. The sections that follow detail
4915some technical capabilities of port scanners that are important to an under-
4916standing of the “logic†that supports port scanning technology and some of
4917the features supported by port scanners.
4918TCP and UDP Scanning
4919A number of TCP/IP scanning techniques are employed by port scanners to
4920gather host reconnaissance or bypass firewalls and access control devices
4921(see Exhibit 20). Many of these were pioneered in Fyodor’s Nmap scanning
4922tool (references can be found on Fyodor’s web site http://www.insecure.org).
4923Banner Grabbing
4924Banner grabbing is the process of connecting to a system on a specific port
4925and examining the banner provided by the application listening on that
4926port. Connected to an SMTP mail server on TCP port 25, we might receive
4927the following banner from the application listening on that port:
4928220 mail.targetorganization.com ESMTP Sendmail 8.8.3; Fri,
492917 Dec 00:02:53 -0500
4930From this banner we can deduce that the mail server is a Sendmail 8.8.3
4931mail server that supports Extended SMTP (ESMTP) commands. Depending
4932on the security imposed for the SMTP server, we may be able to initiate an
4933exchange by echoing specific commands to the server over the telnet ses-
4934sion, to determine the SMTP/ESMTP commands supported.
4935Port scanners exercise similar functionality to perform “banner grab-
4936bing,†using TCP port connects to obtain information about the applica-
4937tions and software versions running on a particular system. Knowing this,
4938© 2004 by CRC Press LLC
4939some system administrators alter or delete banners (where they have the
4940option to) in an attempt to disguise the listening application.
4941Packet Fragmentation Options
4942Many port scanners support packet fragmentation options to aid the process
4943of passing packets through packet filtering devices and to evade intrusion
4944detection systems. 13 Packet fragmentation techniques split the TCP (or UDP)
4945header over several packets in an attempt to make it more difficult for access
4946control devices to detect the signature of the port scan (see Exhibit 21).
4947Most current firewall and IDS implementations have the ability to assem-
4948ble the original IP packets (from packet fragments) before assessing them,
4949Exhibit 20. TCP and UDP Scanning
4950Feature (Type of Scan) Description
4951TCP connect scans TCP connect scans are comprised of a complete TCP full
4952open (SYN, SYN/ACK, ACK); TCP connect scans are
4953generally easily picked up by firewalls, intrusion detection
4954devices, and the target node
4955TCP SYN scans TCP SYN scans are “stealthier†than TCP connect scans
4956because they only issue a TCP half open (a single SYN
4957packet) to the target host; if the port being probed is open
4958on the target system, the system will respond with a
4959SYN/ACK; a RST/ACK is issued by the target host if the port
4960is closed
4961TCP FIN scans TCP FIN scans issue a single FIN packet to the target
4962host/port; if the port is closed, the target system should
4963respond with an RST
4964TCP Xmas tree scan A TCP Xmas tree scan involves sending a packet with the FIN,
4965URG, and PUSH TCP flags set to a target host/port; an RST
4966should be issued by the target system for all closed ports
4967TCP Null scan A TCP Null scan disables all flags; again, the target system
4968should issue an RST for all closed ports
4969TCP ACK Scan TCP ACK scans can be used to determine firewall rulesets
4970or to pass packets through a simple packet filtering
4971firewall; stateful firewalls will reject ACK response packets
4972that cannot be tallied with a session in the firewall’s state
4973table; simple packet filtering firewalls will pass ACK
4974connection requests
4975TCP RPC scan TCP RPC scans can be conducted against systems to identify
4976remote procedure call (RPC) ports and their associated
4977program and version numbers
4978UDP scan There are no facilities for setting specific state flags in UDP
4979scans; an ICMP port unreachable message in response to
4980the originating UDP packet indicates that the port is
4981“closedâ€; UDP scanning can be slow
4982© 2004 by CRC Press LLC
4983thwarting packet fragmentation attempts. Older firewall and IDS implemen-
4984tations often lacked this capability, so packet fragmentation interfered
4985with packet inspection.
4986Decoy Scanning Capabilities
4987Nmap and certain other port scanning tools have “decoy†capabilities that
4988allow a decoy scan (or scans) to be initiated at the same time as a directed
4989scan. This makes it much more difficult for the target organization to track
4990down the source of the scan because tools that deploy this tactic typically
4991spoof legitimate source addresses and mix packets from the decoys with
4992the “real†scan.
4993Ident Scanning
4994Ident scanning can be useful in identifying the user account bound to a
4995particular TCP connection. This is generally facilitated through communi-
4996cation with TCP port 113 (ident), which should respond with the identity of
4997the user that owns the process associated with the TCP port. This type of
4998scanning is only useful when applied to systems that implement the ident
4999service (generally UNIX systems) but can be useful in identifying services