3 ms·
From the gist of the incredible difficult to decipher training manual there are 4 systems. Overview of network topology is here: http://i.imgur.com/gzw6nAT.png
by TheLegace 13y ago
From the gist of the incredible difficult to decipher training manual there are 4 systems. Overview of network topology is here:
http://i.imgur.com/gzw6nAT.png http://i.imgur.com/gzw6nAT.png
1) ADMF-Client & Infection GUI
These seem to be HP Compaq computers, running Windows 7 Ultimate, FinFlyISP GUI and a XMPP client(which runs over TLS and is secure).
This is a tool for LEA to use which interfaces with the ADMF backend for managing infections, selection of infection methods, realtime status info and management of all components.
2) ADMF - Central Administration Function
This is the backend which all the LEA terminals in 1 connect to. These are HP DL380 G6 Intel Xeon X5550 @ 2.67GHz servers running hardened Debian(by Dreamlab best practices). It is a core component of their infrastructure and communicates in realtime with all their other component systems. It stores the configuration and initiation of infections. Realtime exchange of info and states(target coming online, being infected, etc.) Contains RFC XMPP used for secure encrypted communications.
3) Network Data processing component (iProxy/NDP01/NDP02)
Infections are remotely activated by ADMF in 2 via the GUI. Each NDP is bridged with 10GB/s fiber bypass module. Incase of hardware/logical failures this module switches automatically to by-pass mode. Thus traffic will never be interrupted. ATTENTION this is highly dynamic bridge, do not change any configuration manually. NDP has been specially configured for his network, any changes are tightly coordinated with Dreamlab.
4) Radius Probe(RP01/RP02)
Realtime monitoring of AAA processes which include:
1. Targets coming online
2. Receiving IP Addresses
3. Changing IP Addresses
4. Going offline
Recording of RADIUS authentications and accounting dialogues. Being always up to date of target IP
RP sends info to ADMF, the ADMF provisions the NDP. Running same hardware/OS as 3. The RPs have bidirectional connection with broadband remote access server(BRAS) [1] which are what connect to the global internet from a ISPs network. BRAS aggregrates user sessions from access network. This is where ISPs can inject policy management and QOS. Aggregrates DSLAM connections from locally dispersed in an ISP area network.
Communications Visualized
The slide explains that communication of all components always is initiated towards the ADMF.
http://i.imgur.com/qOQfVYd.png http://i.imgur.com/qOQfVYd.png
Use Cases
1. GUI->ADMF [Infect a target]
2. ADMF->Radius prove [Start monitoring/set a trap on target]
3. Radius->ADMF->NDP/iProxy [Handover of IP]
4. iProxy->NDP [iProxy requests NDP to analyse datastream on IP and "interesting" traffic]
5. NDP->iProxy [Handover traffic matching request]
6. iProxy [changes traffic and modifies data by adding infection parts]
7. iProxy->NDP [iProxy sends modified traffic data to NDP]
8. NDP Reinject [NDP recalculates checksums/resequences TCP/IP packets and reinjects traffic into the stream]
9. Target infection done [Data successfully sent to target]
[1] http://en.wikipedia.org/wiki/Broadband_Remote_Access_Server http://en.wikipedia.org/wiki/Broadband_Remote_Access_Server
- dmix 13y agoWhat exactly is an "infection"?
- samstave 13y agoAssuming its whatever malware/rootkit/data-logging/remote-access trojan desired. EDIT: What we need is a menu/list of the infections available to staff
- swatkat 13y agoFinFisher wikipedia page: http://en.wikipedia.org/wiki/FinFisher http://en.wikipedia.org/wiki/FinFisher It talks about the "infection" and its "use by repressive regimes" among other things.
- INTPenis 13y agoI've worked with ISPs setting up RADIUS so that, and Debian, are really the only parts I understand here. So I interpret this as a system that needs to run in full co-operation with the ISP or the owner of the fiber cables. Since that is usually who is managing the RADIUS setup.
- stephengillie 13y agoThe Radius Probe section looks like Windows Active Directory -- servers that handle Remote Desktop Protocol connections (such as bastion servers) are routinely named RDPxx for easy identification, and AD basically runs off LDAP. Though I don't know why that cloud would be labeled "OSS"