十一届全国政协委员职务和界别情况T。。。

整理文档很辛苦,赏杯茶钱您下走!

免费阅读已结束,点击下载阅读编辑剩下 ...

阅读已结束,您可以下载文档离线阅读编辑

资源描述

Setiri:AdvancesinTrojanTechnologyRoelofTemminghHaroonMeerBlackHatUSA2002中医免费资料:AdvancesinTrojanTechnologyDemonstrationTakingitfurtherPossiblefixesIntroductionSensePostThespeakersObjectiveofpresentationWhyTrojans?ProfileofTrojanusersRealcriminals……don’twritebufferoverflowsTheweirdnessoftheindustryExamplesBriefHistoryofTrojans&CovertTunnelsTrojansFromQuickThinkingGreeks…toQuickThinkingGeeksTunnelsCovertChannelsTrojans..ValidIP–NoFiltersValidIP–StatelessFiltersPrivateAddresses–StatefulFiltersPrivate+Stateful+IDS+PersonalFirewalls+ContentChecking+…Trojans..(ValidIP–NoFilters)“getreal..”Trojans..(ValidIP–StatelessFilter)DialHomeTrojansRandomPorts/OpenPorts/HighPorts[cDc]ACKTunneling[ArneVidstrom]Trojans..(StatefulFilters)BackOrifice-…toQuickThinkingGeeksTunnelsCovertChannelsTunnels&CovertChannels1985–TSCDefinition”CovertChannels”1996–PhrackMagazine–LOKI1998–R–THC1999-HTTPTUNNEL–GNU2000-FireThru-FirethruConventionalTrojans&howtheyfailStatefulfirewall&IDSDirectmodelDirectmodelwithnetworktricksICMPtunnelingACKtunnelingProperlyconfiguredstatefulfirewallIRCagents+AuthenticationproxyHTTPtunnel++Personalfirewall&AdvancedProxyHTTPtunnelwithAuthentication+++Hybridmodel:“GatSlag”CombinationbetweencovertTunnelandTrojanDefensesmechanismstoday:Packetfilters(stateful)/NATAuthenticationProxiesIntrusiondetectionsystemsPersonalfirewallsContent/protocolcheckingBiometrics/TokenPads/OnetimepasswordsEncryptionAtypicalnetworkHowGatSlagworkedReverseconnectionHTTPcoverttunnelMicrosoftInternetExplorerastransportControlsIEviaOLEEncapsulateinIE,notHTTPReceivecommandsintitleofwebpageReceiveencodeddataasplaintextinbodyofwebpageSenddatawithPOSTrequestSendalivesignalswithGETrequestWhyGatSlagworkedIntegrationofclientwithMSProxyNTLMauthenticationSSLcapableRegistrychangesPersonalfirewallsJustanotherbrowserPlatformindependentIEoneverydesktopSpecifyControllerViapublicwebpage–theMASTERsiteHowGatSlagworkedIICreatesinvisiblebrowserFindcontrolleratMASTERSendrequesttoControllerIfnoController&&retry7,gotoMASTERReceivereplyParsereply:+Uploadfile()+Downloadfile+ExecutecommandLoopWhydefensesfailFirewalls(stateful/NAT)ConfiguredtoallowuserorproxyoutContentlevel&IDSLookslikevalidHTTPrequests&repliesFilesdownloadedastextinwebpagesNodataorportstolockontoSSLprovidesencryptionPersonalfirewallsIEvalidapplicationConfiguredtoallowbrowsingAuthenticationproxiesUsersurfthewebProblemswithGatslagTheController’sIPcanbeobtained!HandlingofmultipleinstancesGUIsupportControllerneededtobeonlineBatchcommandsCommandhistoryMultiplecontrollersUploadfacilitynotefficientPlatformsupportStabilitySessionleveltunnelingSetiri:AdvancesinTrojanTechnologyDesignnotes:WebsitecontainsinstructionsCGIstocreatenewinstructionController’sinterface:–EXEC(DOScommands)–TX(Fileupload)–RX(Filedownload)Directorystructure–eachinstanceTrojan“surfs”towebsite–justanormaluserwouldSetiri:AdvancesinTrojanTechnologyIIAnonymityProblemswithnormalproxiesAlreadyusingaproxyProxylogs“Cleaners”provideanonymity“Inbrowserproxy”–AnonymizerTrojan-Cleaner:SSLCleaner-Controller:SSLChallenges:BrowserhistoryTemporaryfilesDemonstrationTakingitfurtherSessionleveltunnelingFlowcontrolchallengesHowthisisdifferentfromHTTPtunnelingAbrowserisnotasocketNoselectonbrowserTrainmodelTheControllersideCannot“send”BufferingofdataatControllerTheTrojansideMulti-partPOSTsMultipleconnections(HTTP)TruenetworkleveltunnelingSolvingthedilemmaDeliveryWhitelistingUsereducationAV,personalfirewallsShouldyoualloweveryonetosurfthe‘net?ConclusionAwarenessOurmotivation

1 / 29
下载文档,编辑使用

©2015-2020 m.777doc.com 三七文档.

备案号:鲁ICP备2024069028号-1 客服联系 QQ:2149211541

×
保存成功