Slashdot Mirror


Black Ops of TCP/IP: Paketto Keiretsu 1.0 Release

Effugas writes "After pushing OpenSSH to perform feats of secure tunneling far beyond what I ever expected it could do, it became clear that some genuinely useful modes of network operation were simply inaccessable without either replacing or manipulating core network protocols. Since the basic infrastructure of the Internet isn't likely to change any time soon, that left...creative manipulation and reconstruction of the Lingua Reseaux: TCP/IP. Taking advantage of expectations, pitting layers against eachother, finding new uses for old options and data fields -- instead of simply unleashing the latest incarnation of some "Ping of Death", could such work unveil hidden functionality within existing networks? As I discussed at Black Hat 2002 and the inimitable Defcon X, the answer is yes. And now, proof of this is ready. BSD Licensed (in deference to the very source of TCP/IP), The Paketto Keiretsu, Version 1.0, is a collection of five interwoven "proof of concepts" that explore, extract, and expose previously untapped capacities embedded deep within networks and their stacks, at Layers 2 through 4. The five -- scanrand, minewt, lc ( linkcat ), paratrace, and the OpenQVIS cross-disciplinary-a-go-go phentropy -- demonstrate Stateless TCP Scanning, Inverse SYN Cookies, Guerrila Multicast, Parasitic Tracerouting, Ethernet Trailer Cryptography, and quite a bit more. (For details, stop by DoxPara Research or check out the latest slides. The academic paper is coming "soon".) In terms of actual usefulness, scanrand is no nmap, but it's still interesting: During an authorized test inside a multinational corporation's class B, scanrand detected 8300 web servers across 65,536 addresses. Time elapsed: approximately 4 seconds."

7 of 303 comments (clear)

  1. Ok, I'll bite by myowntrueself · · Score: 0, Offtopic

    Was that ROT13 or Dutch?

    --
    In the free world the media isn't government run; the government is media run.
  2. I am dumb by cygnus · · Score: 1, Offtopic

    What'd he say?

    What'd he say?

    time to go back to TCP/IP Network Administration to learn how to decode this Slashdot article...

    --
    Just raise the taxes on crack.
    1. Re:I am dumb by stu72 · · Score: 1, Offtopic

      > --
      > *** information wants to be two dollah! ***

      *** Information wants to be ... about treefiddy! ***

  3. Re:SHORTEST AND LONGEST BOOKS by rocketfairy · · Score: 0, Offtopic

    French gov't not nice to foreigners? Bollocks! The Vichy state was perfectly friendly to the Nazis.

  4. MOD ALL PARENTS DOWN!! by Anonymous Coward · · Score: 0, Offtopic

    Since this is thick and requires people to actually read the links to actually understand what's being discussed, of course every post within the first minutes of this thread is of the innane nature of somebody who doesn't understand what this is about. Yet, instead of filtering these clueless posters out... they get mod points for "Funny". Huh? I don't think there's anything funny in people proclaiming they know nothing in an attempt to do slightly better than just try to blurt out "First Post!" Moderators, there's a lot of Overrated (-1)'s that need to be applied up here...

  5. XBox article in disguise?! by Viewsonic · · Score: 0, Offtopic
    If you put all the words backwards and rearrange them just a little the article says "Buy an XBox" over and over. Damnit, I thought Slashdot would at least a DAY without another XBox promo..

    And in other news, METROID PRIME IS OUT !!! GameCube Platinum with Metroid bundle = $169!!

  6. Re:to much to read by Wolfrider · · Score: 0, Offtopic

    --It's "whilst" to YOU, you insensitive clod!!

    --
    .
    == WolfriderV6 == I'm willing to admit that *I just might* be wrong... Are you??