Ïðåäèñëîâèå
Áëàãîäàðíîñòè
Ââåäåíèå
Ïîëå áèòâû

ÏÐÎÅÊÒ HONEYNET
ÑÈÑÒÅÌÀ HONEYPOT
ÑÅÒÜ HONEYNET
Íàçíà÷åíèå Honeynet
Ñèñòåìà Honeypot â ñåòè Honeynet
ÐÅÇÞÌÅ

Êàê ðàáîòàåò Honeynet
ÊÎÍÒÐÎËÜ ÄÀÍÍÛÕ
ÇÀÏÈÑÜ ÄÀÍÍÛÕ
Óðîâåíü êîíòðîëÿ äîñòóïà
Ñåòåâîé óðîâåíü
Ñèñòåìíûé óðîâåíü
Àâòîíîìíûé óðîâåíü
ÑÎÖÈÎÒÅÕÍÈÊÀ
Ðèñê
ÐÅÇÞÌÅ

Ñîçäàíèå ñåòè Honeynet
ÎÁÙÀß ÀÐÕÈÒÅÊÒÓÐÀ
ÊÎÍÒÐÎËÜ ÄÀÍÍÛÕ
ÇÀÏÈÑÜ ÄÀÍÍÛÕ
ÏÎÄÄÅÐÆÀÍÈÅ HONEYNET È ÐÅÀÃÈÐÎÂÀÍÈÅ ÍÀ ÀÒÀÊÈ
ÐÅÇÞÌÅ

ÀÍÀËÈÇ
Àíàëèç äàííûõ
ÐÅÃÈÑÒÐÀÖÈÎÍÍÛÅ ÆÓÐÍÀËÛ ÁÐÀÍÄÌÀÓÝÐÀ
ÀÍÀËÈÇ IDS
ÑÈÑÒÅÌÍÛÅ ÆÓÐÍÀËÛ
ÐÅÇÞÌÅ

Àíàëèç âçëîìàííîé ñèñòåìû
ÍÀÏÀÄÅÍÈÅ
ÀÍÀËÈÇ
Âçëîì
ÏÎËÓ×ÅÍÈÅ ÄÎÑÒÓÏÀ
ÂÎÇÂÐÀÙÅÍÈÅ
ÐÅÇÓËÜÒÀÒÛ ÀÍÀËÈÇÀ
ÐÅÇÞÌÅ

Ïðîäâèíóòûé àíàëèç äàííûõ
ÏÀÑÑÈÂÍÀß ÄÀÊÒÈËÎÑÊÎÏÈß
Ñèãíàòóðû
Ïðèìåð ICMP
ÑÈÑÒÅÌÍÎÅ ÂÑÊÐÛÒÈÅ
ÐÅÇÞÌÅ

Ïðàêòèêà ñèñòåìíîãî âñêðûòèÿ
ÎÁÐÀÇÛ
ÈÍÑÒÐÓÌÅÍÒÛ THE CORONER'S TOOLKIT
ÂÐÅÌß MAC
ÓÄÀËÅÍÍÛÅ ÑÒÐÓÊÒÓÐÛ INODE
ÂÎÑÑÒÀÍÎÂËÅÍÈÅ ÄÀÍÍÛÕ
ÐÅÇÞÌÅ

ÓÃÐÎÇÀ
ÒÀÊÒÈÊÀ
ÈÍÑÒÐÓÌÅÍÒÛ
Ìîòèâû
ÌÅÍßÞÙÈÅÑß ÒÅÍÄÅÍÖÈÈ
ÐÅÇÞÌÅ

×åðâÿêè íà âîéíå
ÓÑÒÀÍÎÂÊÀ
ÏÅÐÂÛÉ ×ÅÐÂßÊ
ÂÒÎÐÎÉ ×ÅÐÂßÊ
ÍÀ ÑËÅÄÓÞÙÈÉ ÄÅÍÜ
ÐÅÇÞÌÅ

Ñâîèìè ñîáñòâåííûìè ñëîâàìè
Âçëîì

Íàøà ññûëêà ;)



Êàê êóïèòü ñóìêè ñ íîóòáóêàìè 15 äþéìîâ â Ìîñêâå ïî õîðîøåé öåíå?


ÏÅÐÂÛÉ ×ÅÐÂßÊ

Ìåíåå ÷åì ÷åðåç ñóòêè ó íàñ ïîÿâèëñÿ ïåðâûé ïîñåòèòåëü. Ñèñòåìà 216.191.92.10 (host-010.hsf.on.ca) ñêàíèðîâàëà ñåòü â ïîèñêàõ ñèñòåì íà áàçå Windows, îïðåäåëèëà íàøó è ñòàëà åå çàïðàøèâàòü. Îíà íà÷àëà ñ èìåíè ñèñòåìû è îïðåäåëåíèÿ òîãî, áûëî ëè âêëþ÷åíî ñîâìåñòíîå èñïîëüçîâàíèå; îíî áûëî âêëþ÷åíî. Çàòåì áûëî âûïîëíåíî çîíäèðîâàíèå îïðåäåëåííûõ äâîè÷íûõ ôàéëîâ íàøåé ñèñòåìû. Öåëü ñîñòîÿëà â òîì, ÷òîáû îïðåäåëèòü, áûë ëè èíñòàëëèðîâàí êîíêðåòíûé ÷åðâÿê; åñëè íåò, îíà áû åãî óñòàíîâèëà.  äàííîì ñëó÷àå ÷åðâÿê íå áûë óñòàíîâëåí. ×åðâÿê Win32.Bymer èñïîëüçóåò ìîùíîñòè öåíòðàëüíîãî ïðîöåññîðà, ÷òîáû ïîìî÷ü èíäèâèäó âûèãðàòü ñîðåâíîâàíèå distributed.net. Ïîä ýòèì íàçâàíèåì ñóùåñòâóåò ãðóïïà, êîòîðàÿ èñïîëüçóåò áåçäåéñòâóþùèå ïðîöåññîðû ðàñïðåäåëåííûõ êîìïüþòåðîâ äëÿ ðàçëè÷íûõ çàäà÷, òàêèõ êàê âçëîì øèôðà RC5-64. Åñëè ïîëüçîâàòåëè ðåøàþò çàäà÷ó, îíè íàãðàæäàþòñÿ ïðèçàìè. ×åì áîëüøå êîìïüþòåðîâ êîíòðîëèðóåò îäèí ÷åëîâåê, òåì áîëüøå øàíñîâ íà ïîáåäó.  íàøåì ñëó÷àå êòî-òî âîâëåê íàñ â ïðîåêò, óñòàíîâèâ ÷åðâÿêà â íàøåé ñèñòåìå.

Íåêèé ÷åëîâåê - íàçîâåì åãî bymer@inec.kiev.ua - ñîçäàë ñàìîâîñïðîèçâîäÿùåãîñÿ ÷åðâÿêà, êîòîðûé íàõîäèò óÿçâèìûå îïåðàöèîííûå ñèñòåìû Windows è óñòàíàâëèâàåò â íè÷åãî íå ïîäîçðåâàþùèå ñèñòåìû êëèåíòà distributed.net. Ïîñëå óñòàíîâêè è çàïóñêà ÷åðâÿê èñïîëüçóåò êîìïüþòåð, ÷òîáû ïîìî÷ü àâòîðó ïîáåäèòü â ñîðåâíîâàíèè. Òåì âðåìåíåì ÷åðâü íà÷èíàåò çîíäèðîâàòü äðóãèå ñèñòåìû â ïîèñêàõ óÿçâèìûõ ìåñò, êîòîðûå îí ìîã áû çàõâàòèòü. Öåëü ñîñòîèò â òîì, ÷òîáû êîíòðîëèðîâàòü êàê ìîæíî áîëüøå êîìïüþòåðîâ. Ìîòèâ àâòîðà î÷åíü ïðîñò: ïîáåäèòü â ñîðåâíîâàíèè distributed.net. ×åðâÿê ðàçðàáîòàí äëÿ òîãî, ÷òîáû ïîçâîëèòü ïîëüçîâàòåëþ êîíòðîëèðîâàòü êàê ìîæíî áîëüøåå êîëè÷åñòâî ñèñòåì íà áàçå Windows. Èìåííî ïîýòîìó ê ÷åðâÿêó ïðèëàãàåòñÿ ýëåêòðîííûé àäðåñ, òàê ÷òî ìîæíî áóäåò îïðåäåëèòü àâòîðà, åñëè ýòà ñèñòåìà ñóìååò âçëîìàòü øèôð â çàäà÷å distributed.net.

Òåïåðü ðàññìîòðèì íàïàäåíèå ñ ïîìîùüþ çàïèñè ïàêåòîâ ñåòåâîãî òðàôèêà, ïåðåõâà÷åííûõ IDS Snort. Äëÿ áîëåå ãëóáîêîãî àíàëèçà ïðîòîêîëà NetBIOS, âîçìîæíî, ïðèäåòñÿ îáðàòèòüñÿ ê àíàëèçàòîðó ïðîòîêîëà, íàïðèìåð ê áåñïëàòíîé óòèëèòå Ethereal (http://eee.ethereal.com).  ïðèâåäåííûõ íèæå çàïèñÿõ àíàëèçàòîðà ñèñòåìà 172.16.1.105 - ýòî IP-àäðåñ ñèñòåìû honeypot.

Ñíà÷àëà ÷åðâÿê ïðîâåðÿåò, åñòü ëè â ñèñòåìå ôàéë dnetc.ini. Ýòî ñòàíäàðòíûé ôàéë êîíôèãóðàöèè äëÿ êëèåíòà distributed.net. Îí óêàçûâàåò ãëàâíîìó ñåðâåðó, êòî äîëæåí óïðàâëÿòü âñåìè çàõâà÷åííûìè ÏÊ: ñêîðåå âñåãî, ýòî ÷åëîâåê, ñîçäàâøèé ÷åðâÿêà. Çäåñü ìû âèäèì çàïèñü ïàêåòà, â êîòîðîì óäàëåííàÿ ñèñòåìà (èìÿ NetBIOS GHUNT, ó÷åòíàÿ çàïèñü GHUNT, äîìåí HSFOPROV) êîïèðóåò ôàéë êîíôèãóðàöèè â íàøó honeypot:

11/01-15:29:18.580895 216.191.92.10:2900 -> 172.16.1.105:139
TCP TTL:112 T0S:0x0 ID:50235 IpLen:20 DgmLen:135 DF
***AP,*, Seq: 0xl2930C6 Ack: 0x66B7068 Win: 0x2185 TcpLen: 20
00 00 00 5Â FF 53 4D 42 2D 00 00 00 00 00 01 00 . ..[.SMB-
00 00 00 00 00 00 00 00 00 00 00 00 00 Ñ8 57 1Ñ W.
00 00 82 Dl OF FF 00 00 00 07 00 91 00 16 00 20
00 DC 1Ñ 00 ÇÀ 10 00 00 00 00 00 00 00 00 00 00 :
00 00 00 1À 00 5Ñ 57 49 4Å 44 4F 57 53 5Ñ 53 59 \WINDOWS\SY
53 54 45 4D 5Ñ 64 6Å 65 74 63 2Å 69 6Å 69 00 STEM\dnetc.ini.
Íèæå ïðèâîäèòñÿ ïåðåäà÷à ôàéëà êîíôèãóðàöèè dnetc.ini; òî÷êîé ñîïðèêîñíîâåíèÿ ÿâëÿåòñÿ bymer@inec.kiev.ua - ÷åëîâåê, êîòîðûé ïîëó÷àåò êîíòðîëü íàä öèêëàìè ÖÏ è êîòîðûé, ñêîðåå âñåãî, ñîçäàë íàïàâøåãî íà íàñ ÷åðâÿêà. Äîâîëüíî óìíî, íà ïðàâäà ëè?
11/01-15:29:18.729337 216.191.92.10:2900 -> 172.16.1.105:139
TCP TTL: 112 T0S:0x0 ID:50747 IpLen:20 Dgml_en:317 DF
***AP*** seq: 0x1293125 Ack: 0x66B70AD Win: 0x2140 TcpLen: 20
00 00 01 11 FF 53 4D 42 0B 00 00 00 00 00 01 00 SMB
00 00 00 00 00 00 00 00 00 00 00 00 00 C8 57 1Ñ W.
00 00 02 D2 05 00 00 E1 00 00 00 00 00 E1 00 E4
00 01 E1 00 5B 6D 69 73 63 5D 20 0D 0A 70 72 6F . . . . [misc] ..pro
6A 65 63 74 2D 70 72 69 6F 72 69 74 79 3D 4F 47 ject-priority=OG
52 2C 52 43 35 2C 43 53 43 2C 44 45 53 0D 0A 0D R, RC5, CSC, DES. . .
0A 5B 70 61 72 61 6D 65 74 65 72 73 5D 0D 0A 69 .[parameters]..!
64 3D 62 79 6D 65 72 40 69 6E 65 63 2E 6B 69 65 d=bymer®inec. kie
76 2E 75 61 0D 0A 0D 0A 5B 72 63 35 5D 0D 0A 66 v.ua [rc5]..f
65 74 63 68 2D 77 6F 72 6B 75 6E 69 74 2D 74 68 etch-workunit-th
72 65 73 68 6F 6C 64 3D 36 34 0D 0A 72 61 6E 64 reshold=64. . rand
6F 6D 70 72 65 66 69 78 3D 32 31 37 0D 0A 0D 0A omprefix=217
5B 6F 67 72 5D 0D 0A 66 65 74 63 68 2D 77 6F 72 [ogr]. . fetch-wor
6B 75 6E 69 74 2D 74 68 72 65 73 68 6F 6C 64 3D kunit-threshold=
31 36 0D 0A 0D 0A 5B 74 72 69 67 67 65 72 73 5D 16.... [triggers]
0D 0A 72 65 73 74 61 72 74 2D 6F 6E 2D 63 6F 6E . . restart-on-con
66 69 67 2D 66 69 6C 65 20 63 68 61 6E 67 65 3D fig-flie-change=
79 65 73 0D 0A yes. .

Çàòåì íåîáõîäèìî ïåðåäàòü ïðîãðàììó dnetc.exe, êëèåíòà ñåðâåðà, óñòàíîâëåííîãî íà distributed.net. Îíà çàïóñêàåòñÿ â çàõâà÷åííîé ñèñòåìå è íà÷èíàåò ðàáîòàòü. Ìû óáåäèëèñü â ýòîì, âçÿâ ñèãíàòóðó êëèåíòà MD5, îáíàðóæåííóþ íà honeypot. Çàòåì çàãðóçèëè êëèåíòà èç distributed.net è âçÿëè MD5 hash êëèåíòà dnetc.exe. Îíè îêàçàëèñü èäåíòè÷íûìè (d0fd1f93913af70178bff1a1953f5f7d), çíà÷èò, ýòîò êîä íå ÷åðâÿê, à áèíàðíûé ôàéë, êîòîðûé èñïîëüçóåò ìîùíîñòè ïðîöåññîðà äëÿ ðåøåíèÿ ÷àñòè çàäàíèÿ distributed.net (çàäà÷à çàêëþ÷àåòñÿ âî âçëîìå øèôðà ïîëíûì ïåðåáîðîì). Îäíàêî ÷åðâÿê íàìåðåâàåòñÿ èñïîëüçîâàòü ýòîò áèíàðíûé ôàéë áåç âàøåãî ðàçðåøåíèÿ èëè âåäîìà, ðàäè äîñòèæåíèÿ öåëè.

11/01-15:34:09.044822 216.191.92.10:2900 -> 172.16.1.105:139
TCP TTL:112 TOS:OxO ID:33084 IpLen:20 DgmLen:135 DF
,**AP*** Seq: 0xl29341A Ack: 0x66B71C0 Win: 0x202D TcpLen: 20
00 00 00 5B FF 53 4D 42 2D 00 00 00 00 00 01 00 ...[.SMB-
00 00 00 00 00 00 00 00 00 00 00 00 00 C8 57 1Ñ W.
00 00 04 26 OF FF 00 00 00 07 00 91 00 16 00 20 . . . &
00 FE 1D 00 ÇÀ 10 00 00 00 00 00 00 00 00 00 00 . . . . :
00 00 00 1A 00 5C 57 49 4E 44 4F 57 53 5C 53 59 \WINDOWS\SY
53 54 45 40 5C 64 6E 65 74 63 2E 65 78 65 00 STEM\dnetc.exe.

Çàòåì ìû âèäèì ïåðåäà÷ó ÷åðâÿêà â ôàéëå msil26.exe. Ýòî ñàìîâîñïðîèçâîäÿùèéñÿ ÷åðâÿê, êîòîðûé ñëó÷àéíûì îáðàçîì çîíäèðóåò óÿçâèìûå ñèñòåìû è êîïèðóåò ñåáÿ â íèõ. Êðîìå òîãî, îí íàâåðíÿêà ÿâëÿåòñÿ ïðè÷èíîé îãðîìíîãî êîëè÷åñòâà çàôèêñèðîâàííûõ íàìè ïîïûòîê ñêàíèðîâàíèÿ.

11/01-15:37:23.083643 216.191.92.10:2900 -> 172.16.1.105:139
TCP TTL:112 T0S:0x0 ID:40765 IpLen:20 DgmLen:136 DF
***AP*** seq: 0xl2C146A Ack: 0x66C248B Win: 0x20B2 TcpLen: 20
00 00 00 5C FF 53 4D 42 2D 00 00 00 00 00 01 00 . . .\.SMB-.. . .
00 00 00 00 00 00 00 00 00 00 00 00 00 C8 57 1Ñ W.
00 00 02 F3 OF FF 00 00 00 07 00 91 00 16 00 20
00 CO 1E 00 ÇÀ 10 00 00 00 00 00 00 00 00 00 00 .... :
00 00 00 1B 00 5C 57 49 4E 44 4F 57 53 5C 53 59 \WINDOWS\SY
53 54 45 4D 5C 6D 73 69 32 31 35 2E 65 78 65 00 STEM\msi216.exe.

Íàêîíåö, ÷åðâÿê èçìåíÿåò, à çàòåì çàãðóæàåò íîâûé ôàéë win.ini, òàê ÷òî ñèñòåìà áóäåò çàïóñêàòü ÷åðâÿêà ïðè ïåðåçàãðóçêå. Ïîìíèòå, ïðè óäàëåííîì çàïóñêå ôàéëà â ñèñòåìå Windows 98 ìîãóò âîçíèêíóòü ïðîáëåìû, ïîýòîìó ÷åðâÿê ïîëüçóåòñÿ òàêèì ìåòîäîì çàïóñêà. Îí âûïîëíÿåò ýòî, äîáàâèâ ñåáÿ ê ôàéëó êîíôèãóðàöèè çàïóñêà c:\windows\win.ini, ïîñëå ÷åãî â ïðîöåññå çàïóñêà áóäåò çàãðóæåí. Çàòåì âî âçëîìàííóþ ñèñòåìó çàãðóæàåòñÿ íîâûé ôàéë win.ini:

11/01-15:36:55.352810 216.191.92.10:2900 -> 172.16.1.105:139 TCP TTL:112 T0S:0x0 ID:1342 IpLen:20 DgmLen=1500 DF ***A**** seq: 0x12C6F55 Ack: 0x66C95FC Win: OxiFBF TcpLen: 20
00 00 0B 68 FF 53 4D 42 1D 00 00 00 00 00 01 00 .h.SMB
00 00 00 00 00 00 00 00 00 00 00 00 00 C8- 57 1Ñ W.
00 00 02 F9 0C 0D 00 61 19 00 00 00 00 00 00 00 a
00 00 00 00 00 00 00 00 00 2C 0B 3C 00 2D 0B 00 ,.<.-..
5B 77 69 6E 64 6F 77 73 5D 0D 0A 6C 6F 61 64 3D [windows]..load= 63 ÇÀ 5C 77 69 6E 64 6F 77 73 SC 73 79 73 74 65 c:\windows\syste 6D 5C 6D 73 69 32 31 36 2E 65 78 65 0D 0A 72 75 m\msi216.exe.. ru
6Å 3D 0D ÎÀ 4Å 75 6Ñ 6Ñ 50 6F 72 74 3D 4Å 6F 6Å n=. . NullPort=Non
65 0D ÎÀ 00 ÎÀ 5Â 44 65 73 6Â 74 6F 70 5D 0D ÎÀ å.... [Desktop]. .
57 61 6Ñ 6Ñ 70 61 70 65 72 3D 28 4Å 6F 6Å 65 29 Wallpaper=(None)
0D 0À 54 69 6Ñ 65 57 61 6Ñ 6Ñ 70 61 70 65 72 3D . .TileWallpaper=
31 0D 0À 57 61 6Ñ 6Ñ 70 61 70 65 72 53 74 79 6Ñ 1.. WallpaperStyl
65 3D 30 0D ÎÀ 0D ÎÀ 5Â 69 6Å 74 6Ñ 5D 0D ÎÀ 69 å=0. . . . [ntl]. . i

Âîò è âñå. ×åðâÿê òåïåðü ïîëíîñòüþ óñòàíîâëåí, a honeypot çàðàæåíà. Ñåé÷àñ òðåáóåòñÿ ïåðåçàãðóçèòü ñèñòåìó, è ÷åðâÿê ïðèìåòñÿ çà ðàáîòó. Ïðè ýòîì ïðîèçîéäåò íåñêîëüêî ñîáûòèé:

• íà÷íåò ðàáîòó êëèåíò distributed.net, èñïîëüçóÿ êîìïüþòåð äëÿ ñîðåâ íîâàíèÿ;
• ÷åðâÿê ïðèñòóïèò ê ïîèñêó äðóãèõ óÿçâèìûõ ñèñòåì, ÷òîáû ñêîïèðî âàòü â íèõ ñåáÿ. Èìåííî ýòî ÿâëÿåòñÿ ïðè÷èíîé âñåõ ñëó÷àåâ ñêàíèðî âàíèÿ UDP 137 è TCP 1394;
• ÷åðâÿê ìîæåò äîáàâèòü â ñèñòåìíûé ðååñòð ñëåäóþùèå êëþ÷è: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CuãrentVersion\Run\Bymer. scanner HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\Bymer.scanner Ìîæíî ïîäóìàòü, ÷òî íåîáõîäèìîñòü æäàòü ïåðåçàãðóçêè ñèñòåìû äëÿ çàïóñêà äåëàåò ìåòîä íåíàäåæíûì. Íî èìåéòå â âèäó: ÷åðâü íàöåëåí íà ñèñòåìû ñ Windows 98. Êàê ÷àñòî âû ïåðåçàãðóæàåòå Windows 98? Êðîìå òîãî, åñëè ìîæíî ïîëó÷èòü äîñòóï ê ñèñòåìå, ÷òîáû çàãðóçèòü ÷åðâÿêà, íàñêîëüêî ñëîæíî áóäåò íàïàäàþùåìó çàñòàâèòü åå ïåðåçàãðóçèòüñÿ?
Copyright (ÖÅ) Addison-Wesley