Ogenstad.net

Security Stories and Help with Network Documentation

Once upon a time this used to be my blog. For current updates head over to Networklore.

About / Stories / Contact

  • GitHub
  • LinkedIn
  • RSS
  • Twitter

Powered by Genesis

Taking the Long Way Home – Part 2

March 23, 2006 by patrick.ogenstad

Read Part 1

midfr0st was never able to sleep during the day, at least not when the sun was shining. Might as well go out and meet with some friends. midfr0st picked up a packet of cigarettes, a lighter and his none work laptop then headed for his balcony. While the laptop was booting up he lit a smoke. Only eight left, might have to leave the apartment today. He double clicked the World of Warcraft icon and inhaled some smoke while the game was loading.

At 10:15 he bid his friends farewell and closed the lid of his laptop. He was getting more tired but knew he couldn’t sleep. midfr0st had never been able to stand the smell of smoke on his fingers and washed his hands obsessively. Having been outside for a while he couldn’t help noticing the sun shining through his windows, making the dust in his apartment painfully obvious. He would love to hire a maid or cleaner but he didn’t want them to see all his computer equipment and gadgets. I need a robot, he thought dreamingly.

midfr0st powered up all his computers, fans and other things which made noise. When he called the tech support of the antispam company Gantern used, he wanted it to sound like he was in a server room. He picked up a cell phone from his rack and inserted a sim card.

Tech support: “Hello this is Donald how may I help you?”
midfr0st writes down Donald’s name in his notes.
midfr0st: “Hi Donald, I’m calling from Gantern Construction.”
Donald: “Do you have your contract number?”
midfr0st moved closer to the noise.
midfr0st: “What’s that?”
Donald: “Your contract number”
midfr0st: “Contract number haha! That’s a good one! They didn’t even tell me we were using you guys until a couple of days ago. I’ll tell you it’s mayhem down here. The domain we are using is gantern.com. Hold on.”
midfr0st pretended to be arguing to someone in the “server room”.
midfr0st: “Sorry for that.”
Donald: “No problem”
midfr0st: “The domain we are using is gantern.com, can you get it up to your screen?”
Donald: “Hang on… the computer system is very slow today.”
Why do they always say that when your calling support?
Donald: “Here I have it. Are you Richard Burne?”
midfr0st: “Hey, not even my mother calls me Richard. I’m Dick to most people and the e is silent in Burne it’s not Bernie.”
Donald: “Oh, sorry, so what can I do for you Dick?”
midfr0st: “We are changing our infrastructure and will be moving our mail servers. As we have it now you forward all email to mail.gantern.com. What I would need is to change that to an ip address, could you do that?”
Donald: “Ehm, well I guess I could, but why?”
midfr0st: “Time”
Donald: “Time?”
midfr0st: “Yes I want the change to be instantaneous, if I just change the DNS records for mail.gantern.com I have to worry about caching issues. How fast can you do the change?”
Donald: “In minutes but can’t you just lower the…”
midfr0st: “Again time. If it was up to me I would, but you know how it is with management; they tend to live in the past and everything happened yesterday including this conversation. I bet you’ve been there.”
Donald: “Do you want me to change it now?”
midfr0st: “No thanks, I don’t have time to deal with it today. Besides I have to prep the new server first. I’ll call you this time tomorrow. Thanks for your help. Bye!
Donald: “You’re welcome, bye!”

Read Part 3 

[tags]security, stories, social engineering[/tags]

Filed Under: Stories

Taking the Long Way Home – Part 1

March 20, 2006 by patrick.ogenstad

Monday 05:45. The world around him was still asleep, the only sound violating the silence was the occasional bird outside. midfr0st was unaware of this, just as he was unaware of his mp3 playlist coming to an end three hours ago. His eyes had been fixed on his computer screen for the last sixteen hours. His mind had trouble remembering why. The screen was all black except for a line of text in the upper left corner: “follow the white rabbit.”

I’m going nowhere with this, he thought as he erased the text he’d written well over an hour go. Instead midfr0st brought up the network diagram he had been creating. It wasn’t for his own network, rather a network his present client wanted to 0wn.

midfr0st had some history of doing an honest living but had found the illegal path to be more rewarding when it came to making doubloons. Besides I like being my own boss.

At the moment midfr0st was working on a job concerning communication or rather email. His current client, Dae, was so eager to read the emails from Gantern Construction that midfr0st had been paid in advance. This usually wasn’t the way midfr0st worked but his confidence had grown a lot lately and he was positive he could pull it off. After his last contact with Dae he was beginning to regret his early payment.

Dae: How’s our little expedition going?
midfr0st: It’s moving along
Dae: Where is it moving?
midfr0st: I’m still working on it
Dae: I would hope so, when can you have the package delivered?
midfr0st: I don’t know, soon enough. These things take time.
Dae: You sounded a bit cockier when we paid you.
midfr0st: I haven’t spent the money, you can have it back if you want to.
Dae: The money is not important, my faith in you is. You do not want me to loose that faith.

midfr0st wasn’t overly concerned about Dae’s threats. Dae didn’t seem to know too much about Internet security and midfr0st did his best not to leave a trace back to him. Instead midfr0st traced the IP Dae had used in the irc session. He found that the IP belonged to a company called Wiamra Group, which according to their website was into construction. The way Dae could get to midfr0st was through M3m3th who had introduced them. M3m3th was a friend, but you never knew. midfr0st was pretty sure M3m3th wouldn’t be able to track him.

06:31, the dog started to bark. For some time midfr0st had been positive that his neighbors had that freaking dog running on ntp, every morning at 06:31 it started. The walls in his apartment seemed to have been optimized to let sound pass through them unhindered. Once when it was really getting on his nerves he began feeding the times into rrdtool to get some viewable graphs. After two weeks of manually running the update script he got fed up with the manual labor and considered setting up a microphone to record the barking automatically and then feed it to the update script. In the end he decided against it and figured he had better things to do with his time. Besides, during my testing the dog had been off 25 seconds one day and even if it was on ntp it had to be a very poor implementation.

midfr0st realized the music was silent and let a fresh load of mp3s drown the sound of the dog, it was time to get back to the task at hand. He had a lot of nmap scans, information from the Gantern Construction website, he had hacked an ftp site on their DMZ but that hadn’t been of further value. There were quite a few doors into the company but midfr0st hadn’t been able to squeeze through. All the log files and notes had stopped making sense a long time ago.

At 07:05 something finally caught his eye, mail.gantern.com had port 25 open which would be common enough. However the mx records for the domain pointed elsewhere

MX = 10, mail exchanger = gantern.com.in10.antispamprovider.com
MX = 20, mail exchanger = gantern.com.in20.antispamprovider.com
MX = 30, mail exchanger = gantern.com.in30.antispamprovider.com
MX = 40, mail exchanger = gantern.com.in40.antispamprovider.com

Why didn’t I see this earlier? midfr0st began searching through his notes and after a few minutes he verified that mail.gantern.com was in fact accepting mails from the world. I hope this will work and that it’ll be enough. midfr0st checked the time 07:13, it was too early to begin.

Read Part 2

[tags]security, stories[/tags]

Filed Under: Stories

The Collector

January 10, 2006 by patrick.ogenstad

In 2004 a group of people were handing out free chocolate to anyone who would give them their passwords. It turned out that 70 % would reveal their password for a candy bar or perhaps that people are willing to lie to strangers in order to get free chocolate. Though this was some interesting statistics, it wasn’t very useful to me. What I wanted was a username to go with the password and the name of the company where the person was working. However, I didn’t want to stand alone in the subway handing out Snicker bars to people who didn’t deserve them. I’ll keep my candy treats for myself, thank you very much! Besides I wanted a something which was a tad more discreet.

Mambo server to the rescue! Well I’ve switched to Joomla after the split. Joomla is an excellent CMS system which I’ve used to create my site laugh-and-a-half.com. It’s a site where people go for a laugh; it’s crammed with funny stories, silly pictures and videos with crappy quality. Out of the goodness of my heart I provide all these services free of charge as long as people register. Some teasers are available without logging in, but most of the site members come from recommendations by their friends (at least that’s what the polls tell me) and they don’t mind registering. I don’t ask for much; Alias/Username, Real Name, Email, Password, Gender, Age and Occupation.

Some people just enter gibberish, and that’s fine, (that’s what I would do), others are proud of their titles and neatly enters the correct information in every field; “Sales Executive”, “Purchase Manager”, “Corporate Slave”. I’d like to ask for a phone number too, but I don’t feel that bold. The information would be great to have in social engineering terms, but I don’t want to make people too suspicious, plus I want valid information. Most members provide exactly that, and password reuse is practiced by most people who login to the site. It’s not really their fault, they haven’t been taught better.

When the users login I also keep records of their connecting IP addresses, from nine to five this usually can be translated to companies.

During the time when I was starting up the site there was a lot of work involved with collecting jokes and wrestling myself up in the search engines. But I can tell you the ROI has been substantial; nowadays the site has grown and more or less has a life of its own. 95 % of the content is now submitted by users. Everyone likes sharing a joke right?

No one knows that I run the site. That is, no one on irc knows, they probably haven’t even heard of the site and I’m sure as hell not going to tell them. Why should I? The site is registered to some bloke name Peter. Yep that’s me IRL. The people I do business with only know about tr0y and it would be most unfortunate if anyone connected tr0y to Peter.

While Peter runs an innocent site called laugh-and-a-half, tr0y is in it for the information. There is some work involved with sorting out bad data from good, but overtime my Perl scripts have gotten quite refined.

I get a thrill when a new company finds the site. It starts with one user, then he or she sends an email to his or her colleagues which they in turn forward. Some days I’ve gotten 20 users from the same company!

So what do I do with this information? Most of the time I trade it, if it’s from an interesting company I might be able to sell it. Otherwise I have great fun using it myself. Some times I’m able to just VPN in to a company based on the information I’ve been given from my members. To some extent I guess I just like the mining.

Lately I’ve added some more features to laugh-and-a-half. First I’ve got the face recognition software, the idea is that people upload their pictures and I tell them who they look like. Boy do people love to look like celebrities;
“Susan you look like Madonna, please tell your friends.”
Of course the software itself isn’t working very well but the upload module works excellent.

Then there’s the horoscope where the members enter more information about themselves. This is a mix of “worthless stuff” and things I wanted to know but didn’t dare ask during their registration. Members fill out a form; where they live, interests, favorite food, what they earn, what their boss is called, favorite animal etc. Based on their input I provide them with a randomized horoscope.

Another popular feature of laugh-and-a-half.com is the weekly newsletter. Every Monday the site sends out a newsletter with the jokes which have received the best votes during the previous week. Mind you it’s easy to unsubscribe. Heavens I don’t want to get accused of spamming! The newsletter is a good way to remind people of the site. But then there’s a little something called out of office replies.

“Hi this is Brent, I’m out of the office visiting customers this week…”
“Laura is on vacation this week; if you need anything call Mark at this number…”
“Hi this is Jonathan I am on vacation until 13/7…”
“Hello, Sarah will be back on Wednesday…”
“Neil is on vacation…”

These can be good to have for a bunch of reasons, but today I think I’ll ping devin…

– tr0y – you there?
– devin – hey buddy long time no see, sup?
– tr0y – know anyone in kent?
– devin – why?
– tr0y – business
– devin, business business?
– tr0y – yep business business
– devin – shoot
– tr0y – a guy named jonathan will be on vacation in Greece
– devin – the deal?
– tr0y – 6 %
– devin – I’ll get back to you
– troy – I’ll send you what you need when you do
– devin – how do you know about this anyway?
– tr0y – I ask politely

Please note this is a purely fictional story any name found here are made up. I’ve written this because I like writing, if someone reads it and enjoys it great. If they get more conscious about security, that’s a bonus too.

Related Links:

Passwords revealed by sweet deal
– http://news.bbc.co.uk/1/hi/technology/3639679.stm

Would you trade your password for chocolate?
– http://www.theregister.co.uk/2004/05/28/password_advice/

Urban Legends Reference Pages: Crime (Grand Theft Auto Reply)
– http://www.snopes.com/crime/intent/reply.htm

Passwordsafe – is a tool that allows you to have a different password for all the different programs and websites that you deal with, without actually having to remember all those usernames and passwords. Password Safe runs on PCs under Windows.
– http://passwordsafe.sourceforge.net/

Simple Formula for Strong Passwords (SFSP) Tutorial
– http://www.sans.org/rr/whitepapers/authentication/1636.php

Filed Under: Stories

  • « Previous Page
  • 1
  • …
  • 6
  • 7
  • 8