Blog talking about security, privacy, legal, and compliance topics, as well as follow-on content from the 'Brake'ing Down Security Podcast...
Showing posts with label BIND. Show all posts
Showing posts with label BIND. Show all posts
Sunday, June 12, 2016
2016-023- DNS_Sinkholing,
Picture yourself in the middle of a security incident... A malware infection, or you have hosts on your network are part of a botnet. You figured out where how the malware is communicating with the command and control servers, but if you just kill the connection, the malware stop functioning. What do you do?
In some cases, you might be able to employ a DNS #sinkhole to route traffic harmlessly to or through a honey network that can be used to further analyze things like #infection vectors, #protocols, commands, and #network movement. You can also use #DNS sinkholing to disable the malware if certain conditions are met.
Like most tools, sinkholing can be used for good, but there are legal issues if it's used incorrectly. We discuss some of the legalities. It won't disable all malware or exploit kits, but for some infections, this is another tool in your toolbox you can employ.
In a continuation from last week's show with Earl Carter about the #Angler #Exploit Kit, we discuss how Angler is able to bypass #EMET and #ASLR protections... https://www.fireeye.com/blog/threat-research/2016/06/angler_exploit_kite.html
Direct Link: http://traffic.libsyn.com/brakeingsecurity/2016-023-DNS_Sinkholes2.mp3
iTunes:
Links we used to discuss sinkholing:
Basic sinkhole app using BIND: https://isc.sans.edu/forums/diary/DNS+Sinkhole+ISO+Available+for+Download/9037/
http://resources.infosecinstitute.com/dns-sinkhole
https://www.paloaltonetworks.com/documentation/60/pan-os/newfeaturesguide/content-inspection-features/dns-sinkholing
https://www.sans.org/reading-room/whitepapers/dns/dns-sinkhole-33523
http://www.darkreading.com/partner-perspectives/general-dynamics-fidelis/principles-of-malware-sinkholing/a/d-id/1319769
Blackhole DNS servers -- http://www.malware-domains.com/ or http://www.malwaredomains.com/
http://handlers.dshield.org/gbruneau/sinkhole.htm
Malware blackhole DNS campaign (2013) - http://www.bleepingcomputer.com/forums/t/511780/dns-sinkhole-campaign-underway-for-cryptolocker/
http://www.darkreading.com/risk/microsoft-hands-off-nitol-botnet-sinkhole-operation-to-chinese-cert/d/d-id/1138455
http://someonewhocares.org/hosts// -massive dns sinkholing list
Comments, Questions, Feedback: bds.podcast@gmail.com
Support Brakeing Down Security Podcast on Patreon: https://www.patreon.com/bds_podcast
#Twitter: @brakesec @boettcherpwned @bryanbrake
#Facebook: https://www.facebook.com/BrakeingDownSec/
#Tumblr: http://brakeingdownsecurity.tumblr.com/
Player.FM : https://player.fm/series/brakeing-down-security-podcast
#Stitcher Network: http://www.stitcher.com/s?fid=80546&refid=stpr
#TuneIn Radio App: http://tunein.com/radio/Brakeing-Down-Security-Podcast-p801582/
Here is a new episode of Brakeing Down Security Podcast!
Labels:
BIND,
CISA,
CISSP,
command and control,
CPE,
DNS,
endpoint security,
Infosec,
interviews,
ISSA,
malware,
network security,
OWASP,
physical security,
podcast,
security,
web application security
Sunday, March 6, 2016
2016-010-DNS_Reconnaissance
DNS... we take it for granted... it's just there. And we only know it's broken when you boss can't get to Facebook.
This week, we discuss the Domain Naming System (DNS). We start with a bit of history, talking about the origins of DNS, some of the RFCs involved in it's creation, how it's hierarchical structure functions to allow resolution to occur, and even why your /etc/hosts is important.
We discuss some of the necessary fields in your DNS records. MX, ALIAS, CNAME, SOA, TXT, and how DNS is used for non-repudiation in email.
We also touch on how you can use DNS to enumerate an external network presence when you are the red team, and what you should know about to make it harder for bad actors to not use your external DNS in amplification attacks.
Finally, you can't have a discussion about DNS without talking about how to secure your DNS implementation. So we supply you with a few tips and best practices.
Plenty of informational links down below, including links to the actual RFCs (Request for Comment) which detail how DNS is supposed to function. Think of them as the owner's manual for your car.
Direct Download: http://traffic.libsyn.com/brakeingsecurity/2016-010-DNS_Reconnaissance.mp3
#iTunes:
Comments, Questions, Feedback: bds.podcast@gmail.com
Support Brakeing Down Security using Patreon: https://www.patreon.com/bds_podcast
RSS FEED: http://www.brakeingsecurity.com/rss
On #Twitter: @brakesec @boettcherpwned @bryanbrake
#Facebook: https://www.facebook.com/BrakeingDownSec/
#Tumblr: http://brakeingdownsecurity.tumblr.com/
Google Play Store: https://play.google.com/music/podcasts/portal/#p:id=playpodcast/series&a=100584969
Player.FM : https://player.fm/series/brakeing-down-security-podcast
Stitcher Network: http://www.stitcher.com/s?fid=
TuneIn Radio App: http://tunein.com/radio/
Podcast Links we used for information:
http://www.slideshare.net/BizuworkkJemaneh/dns-42357401
300+ million domains registered: https://www.verisign.com/en_US/internet-technology-news/verisign-press-releases/articles/index.xhtml?artLink=aHR0cDovL3ZlcmlzaWduLm13bmV3c3Jvb20uY29tL2FydGljbGUvcnNzP2lkPTIwMTIwNTI%3D
https://technet.microsoft.com/en-us/library/cc770432.aspx
http://security-musings.blogspot.com/2013/03/building-secure-dns-infrastructure.html
http://tldp.org/HOWTO/DNS-HOWTO-6.html
https://en.wikipedia.org/wiki/Domain_Name_System
https://en.wikipedia.org/wiki/DNS_spoofing
http://www.esecurityplanet.com/network-security/how-to-prevent-dns-attacks.html
http://www.firewall.cx/networking-topics/protocols/domain-name-system-dns/161-protocols-dns-response.html
http://www.thegeekstuff.com/2012/05/ettercap-tutorial/
https://isc.sans.edu/forums/diary/New+tricks+that+may+bring+DNS+spoofing+back+or+Why+you+should+enable+DNSSEC+even+if+it+is+a+pain+to+do/16859/
https://support.google.com/a/answer/48090?hl=en
http://www.ecsl.cs.sunysb.edu/tr/TR187.pdf
https://tools.ietf.org/html/rfc882
https://tools.ietf.org/html/rfc883
https://tools.ietf.org/html/rfc1034
https://tools.ietf.org/html/rfc1035
Here is a new episode of Brakeing Down Security Podcast!
Subscribe to:
Posts (Atom)