3 ms·
Heh I gave a talk at DefCon Skytalks last week on this exact exfil method and C&C structure with a live demo using code we wrote....interesting.
by devnull42 10y ago
Heh I gave a talk at DefCon Skytalks last week on this exact exfil method and C&C structure with a live demo using code we wrote....interesting.
- j_s 10y agoIs there any part of your talk available online?
- devnull42 10y agoThis is pretty much the only part. The code from the live demo. I will try and find a place to get the slides up in the next few days if there is any interest: https://github.com/coryschwartz/dns_exfiltration https://github.com/coryschwartz/dns_exfiltration
- ladzoppelin 10y agoI was at the conference but missed this talk. I would love to see the slides. Congrats on speaking at Defcon.
- b_emery 10y agoAny further comments on the need for nation-state sized budgets, based on your work?
- eugenekolo2 10y ago> Heh I gave a talk at DefCon Skytalks last week on this exact exfil method and C&C structure with a live demo using code we wrote....interesting. > Kaspersky researchers still aren't sure precisely how the USB-enabled exfiltration works. The presence of the invisible storage area doesn't in itself allow attackers to seize control of air-gapped computers. The researchers suspect the capability is used only in rare cases and requires use of a zero-day exploit that has yet to be discovered. In all, Project Sauron is made up of at least 50 modules that can be mixed and matched to suit the objectives of each individual infection. You remarkably have the exact exfil method when that's not disclosed information?
- devnull42 10y ago>The attackers used multiple interesting and unusual techniques, including: > Data exfiltration and real-time status reporting using DNS requests. Sorry to be more specific we spoke on DNS Base Exfil using base64 encoded strings in DNS Lookups and also how to use DNS records to control botnets. So not exact and only part of their method.