.:[ packet storm ]:.
                             
beyond paranoid
beyond paranoid

 Section:  .. / papers / protocols  /

Page 1 of 3
<< 1 2 3 >> Files 1 - 25 of 54
Currently sorted by: Last ModifiedSort By: File Name, File Size

 ///  File Name: dns-writeup.txt
Description:
Interesting write up discussing DNS cache poisoning then and now.
Author:Monsieur Aglie
File Size:10778
Last Modified:Jul 22 20:57:32 2008
MD5 Checksum:a0d975e9261838a800c2ee206625f579

 ///  File Name: protocolhopping.txt
Description:
Whitepaper titled Protocol Hopping Covert Channels - Protocol Hopping Covert Channels (PHCC) are a way to realize covert channels that switch between different protocols while a covert channel is established. PHCCs even can use a randomized protocol order and a mixed packet order to transfer packets what makes them hard to detect.
Author:Steffen Wendzel
Homepage:http://doomed-reality.org/?sub=research&ssub=phcc_res
Related Exploit:phcct-0.1.tgz
File Size:8097
Last Modified:Nov 13 21:10:46 2007
MD5 Checksum:5d320776e626989ea1b25f67aac58b25

 ///  File Name: WAFUTFF.pdf
Description:
Whitepaper entitled "Writing a fuzzer using the Fuzzled framework". The paper includes some of the techniques used to dismantle protocols including documentation, observation and static analysis.
Author:Tim Brown
Homepage:http://www.nth-dimension.org.uk/
File Size:83733
Last Modified:Sep 5 00:45:10 2007
MD5 Checksum:add66aa7259bcf872fdab3c30ab0c06d

 ///  File Name: Insecurities_in_AoE.pdf
Description:
ATA over Ethernet (AoE) is an open standards based protocol that allows direct network access to disk drives by client hosts. This paper investigates the insecurities present in the ATA over Ethernet (AoE) protocol and presents some attacks that exploit various vulnerabilities in the protocol.
Author:Morgan Marquis-Boire
Homepage:http://www.security-assessment.com/technical/whitepapers/
File Size:2154981
Last Modified:Oct 3 19:48:10 2006
MD5 Checksum:88b59f8845764d6106e7c2427f76b9c8

 ///  File Name: SFTPtutorial.html
Description:
Whitepaper discussing the use and setup of SFTP in the business place.
Author:John K. Norden
File Size:9086
Last Modified:Mar 29 01:36:44 2005
MD5 Checksum:8126602bfbde02e90f2613928dbd6078

 ///  File Name: SlippingInTheWindow_v1.0.doc
Description:
Full whitepaper by Paul (Tony) Watson entitled Slipping in the Window: TCP Reset Attacks.
Author:Paul A. Watson
Homepage:http://www.terrorist.net/
Related File:SlippingInTheWindow_v1.0.ppt
File Size:3252736
Related CVE(s):CAN-2004-0230
Last Modified:Apr 23 19:20:53 2004
MD5 Checksum:b26f786303bd4a9d222a70a397a82501

 ///  File Name: SlippingInTheWindow_v1.0.ppt
Description:
Powerpoint presentation by Paul (Tony) Watson entitled Slipping in the Window: TCP Reset Attacks. This presentation was original given at CanSecWest 2004.
Author:Paul A. Watson
Homepage:http://www.terrorist.net/
Related File:SlippingInTheWindow_v1.0.doc
File Size:563712
Related CVE(s):CAN-2004-0230
Last Modified:Apr 23 19:19:40 2004
MD5 Checksum:a1b0b84aa9945d244882a533e78ee295

 ///  File Name: UKdnsTest.txt
Description:
Network Penetration conducted a survey at the start of 2003 to check the status of the United Kingdom's DNS infrastructure. This paper discusses the second run of what was tested, the results, some sample zone transfers, and recommendations.
Author:Ste Jones
Homepage:http://NetworkPenetration.com
File Size:7632
Last Modified:Oct 16 02:13:58 2003
MD5 Checksum:7841d7b80b30c00c25fb3d7f0498b3fb

 ///  File Name: SMB-RSVP.txt
Description:
Paper discussing how the Resource reSerVation Protocol (RSVP) is used within the Subnet Bandwidth Management protocol (RFC 2814) and is vulnerable to allowing a rogue host to hijack control of a server via the use of priority assignment.
Author:STE Jones
Homepage:http://www.networkpenetration.com
File Size:8652
Last Modified:Aug 12 21:37:00 2003
MD5 Checksum:8ba022f0018a7724e3cbbb169de22180

 ///  File Name: covert_paper.txt
Description:
Exploitation of data streams authorized by a network access control system for arbitrary data transfers: tunneling and covert channels over the HTTP protocol.
Author:Alex Dyatlov, Simon Castro
Homepage:http://www.gray-world.net
File Size:68934
Last Modified:Jun 21 18:40:30 2003
MD5 Checksum:4536af34036f3ee2b3439ad7b5e85b8b

 ///  File Name: UDPRemoteControls.txt
Description:
This paper illustrates how to control server with the UDP protocol. It covers UDP basics, how to spoof datagrams, and gives full source code with explanations. This paper can be used in conjunction with the udp-remote-final.tar.gz package.
Author:Angelo Rosiello
File Size:16544
Last Modified:Apr 5 20:59:36 2003
MD5 Checksum:2f58a7be9b71e80ca6a744a64e0a5e55

 ///  File Name: UDPRemoteControls.txt~
Description:
Unavailable.
File Size:16565
Last Modified:Apr 5 20:58:23 2003
MD5 Checksum:2f58a7be9b71e80ca6a744a64e0a5e55

 ///  Directory: / gif /
Description:
Unavailable.
Total Files:19
Last Modified:Sep 15 22:08:10 2002

 ///  File Name: newtcp.htm
Description:
Strange Attractors and TCP/IP Sequence Number Analysis - One Year Later. Includes cool 3D pictures of the sequence number distribution for several OS's and analyzes the predictability of each. Many OS's have very predictable sequence numbers, allowing non encrypted connections to be spoofed and enabling protocol attacks against encrypted connections.
Author:Michal Zalewski
Homepage:http://lcamtuf.coredump.cx/newtcp
File Size:33449
Last Modified:Sep 11 18:48:22 2002
MD5 Checksum:010445ebec5632199f8b278f617c32ce

 ///  File Name: routing.pdf
Description:
Slides for FX's talk at Defcon 2001 on attacking routing protocols.
Author:FX
Homepage:http://www.phenoelit.de
File Size:879369
Last Modified:Jul 21 00:32:20 2001
MD5 Checksum:19dd51ca67fffec971b4c19caeb2e365

 ///  File Name: ICMP_Scanning_v3.0.zip
Description:
ICMP Usage in Scanning v3.0 - This paper outlines what can be done with the ICMP protocol regarding scanning. Although it may seem harmless at first glance, this paper includes details on plain Host Detection techniques, Advanced Host Detection techniques, Inverse Mapping, Trace routing, OS fingerprinting methods with ICMP, and which ICMP traffic should be filtered on a Filtering Device.
Author:Ofir Arkin
Homepage:http://www.sys-security.com/
Changes:Version 3.0 introduces significant changes made to the text. Includes some host based security measures available with Linux based on Kernel 2.4.x and with Sun Solaris 8 and a snort rule base for dealing with the ICMP tricks illustrated within the text.
File Size:1845541
Last Modified:Jun 5 15:17:34 2001
MD5 Checksum:f60a05e7802e4364c022896d78730665

 ///  File Name: intro_to_arp_spoofing.pdf
Description:
Introduction to Arp Spoofing, a method of exploiting the interaction between IP and Ethernet protocols. Includes discussion of switched sniffing, man in the middle attacks, hijacking, cloning, poisoning and more. Describes the operation of ARPoison, Ettercap, and Parasite.
Author:Sean Whalen
File Size:29400
Last Modified:Apr 30 13:45:22 2001
MD5 Checksum:d6e4ccb58a50fb399854112178df5955

 ///  File Name: OW-003-ssh-traffic-analysis.txt
Description:
Openwall Advisory - Passive Analysis of SSH Traffic. This advisory demonstrates several weaknesses in implementations of SSH protocols. When exploited, they let the attacker obtain sensitive information by passively monitoring encrypted SSH sessions. The information can later be used to speed up brute-force attacks on passwords, including the initial login password and other passwords appearing in interactive SSH sessions, such as those used with su(1) and Cisco IOS "enable" passwords. All attacks described in this advisory require the ability to monitor (sniff) network traffic between one or more SSH servers and clients.
Author:Solar Designer
Homepage:http://www.openwall.com/linux
File Size:39118
Last Modified:Mar 19 17:46:08 2001
MD5 Checksum:a6971bfa7f65f86bca364b3a8b03a734

 ///  File Name: passive.pdf
Description:
Passive System Fingerprinting using Network Client Applications - Passive target fingerprinting involves the utilization of network traffic between two hosts by a third system to identify the types of systems being used. Because no data is sent to either system by the monitoring party, detection approaches the impossible. Methods which rely solely on the IP options present in normal traffic are limited in the accuracy about the targets. Further inspection is also needed to determine avenues of vulnerability, as well. We describe a method to rapidly identify target operating systems and version, as well as vectors of attack, based on data sent by client applications. While simplistic, it is robust. The accuracy of this method is also quite high in most cases. Four methods of fingerprinting a system are presented, with sample data provided.
Author:Jose Nazario
Homepage:http://www.crimelabs.net
File Size:223084
Last Modified:Jan 17 20:42:19 2001
MD5 Checksum:b224cd7181e63bc377c194bc105fe9c7

 ///  File Name: host-detection.doc
Description:
Advanced Host Detection - Techniques To Validate Host-Connectivity. Security Engineers spend a tireless amount of effort to block and filter packet anomalies in an internetwork connected environment. Advanced host mapping bypasses many forms of intrusion detection systems, filters, and routers, essentially enabling an attacker to map and discover previously unknown firewalled hosts. Also available in PDF and TXT form.
Author:Dethy
Homepage:http://www.synnergy.net
File Size:145920
Last Modified:Jan 15 16:21:59 2001
MD5 Checksum:938010bc0d9b99eb9b35830b0f7a13e7

 ///  File Name: host-detection.pdf
Description:
Advanced Host Detection - Techniques To Validate Host-Connectivity. (PDF) Security Engineers spend a tireless amount of effort to block and filter packet anomalies in an internetwork connected environment. Advanced host mapping bypasses many forms of intrusion detection systems, filters, and routers, essentially enabling an attacker to map and discover previously unknown firewalled hosts. Also available in TXT and DOC form.
Author:Dethy
Homepage:http://www.synnergy.net
File Size:61012
Last Modified:Jan 15 16:19:41 2001
MD5 Checksum:2866b8e06c2e023af6d2353b6ac6c628

 ///  File Name: host-detection.txt
Description:
Advanced Host Detection - Techniques To Validate Host-Connectivity. Security Engineers spend a tireless amount of effort to block and filter packet anomalies in an internetwork connected environment. Advanced host mapping bypasses many forms of intrusion detection systems, filters, and routers, essentially enabling an attacker to map and discover previously unknown firewalled hosts. Also available in PDF and DOC form.
Author:Dethy
Homepage:http://www.synnergy.net
File Size:42776
Last Modified:Jan 15 16:17:57 2001
MD5 Checksum:29e1aa57dd7594aeb700b3e563f4579a

 ///  File Name: analisis-remoto-de-sistemas.txt
Description:
Port Scanning and OS Fingerprinting - In Spanish.
Author:Honoriak
File Size:97811
Last Modified:Jan 12 19:18:26 2001
MD5 Checksum:b4d894cbc192bce67cd91bc869bb0807

 ///  File Name: portscan.pdf
Description:
Examining port scan methods - Analyzing Audible Techniques. This paper attempts to enumerate a variety of ways to discover and map internal/external networks using signature-based packet replies and known protocol responses when scanning. Specifically, this document presents all known techniques used to determine open/closed ports on a host and ways an attacker may identify the network services running on arbitrary servers. Text version available here.
Author:Dethy
Homepage:http://www.synnergy.net
File Size:67383
Last Modified:Jan 5 03:26:29 2001
MD5 Checksum:aa639e684a8e7913186faa5b0f7081b9

 ///  File Name: portscan.txt
Description:
Examining port scan methods - Analyzing Audible Techniques. This paper attempts to enumerate a variety of ways to discover and map internal/external networks using signature-based packet replies and known protocol responses when scanning. Specifically, this document presents all known techniques used to determine open/closed ports on a host and ways an attacker may identify the network services running on arbitrary servers.
Author:Dethy
Homepage:http://www.synnergy.net
File Size:32573
Last Modified:Jan 5 03:24:32 2001
MD5 Checksum:4608dc43a219fc1243b13e3e1ca6f75d