Full Disclosure mailing list archives
Re: Interesting idea for a covert channel or I just didn't research enough?
From: Kevin Wilcox <kevin () tux appstate edu>
Date: Thu, 06 Oct 2005 10:23:11 -0400
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Michael Holstein wrote:
attacker sends packets -> packets are dropped by firewall -> packets properties are captured in logs -> backdoor reads logs and finds encoded commands -> commands are executedAs a covert channel? .. no, it's a waste. Once you have the access to set that up, you could establish any number of more efficient schemes. As a way to do a "remote wake-up" though .. it might have some promise .. but it still depends on too many other variables.
SAdoor uses this general idea. device in promiscuous mode sits and listens, iptables can have all ports filtered and no services running on the machine, a particular sequence of events happens, a command gets executed. http://cmn.listprojects.darklab.org/ kw -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.6 (GNU/Linux) iD8DBQFDRTNN7XWNuvsOTiYRAqr5AKDQmgqdbBHSJrc2fuOzwx4SjekKlQCg3gFR JYDJjZo37FNF1XNjaejqamc= =8SzG -----END PGP SIGNATURE----- _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Interesting idea for a covert channel or I just didn't research enough? PASTOR ADRIAN (Oct 06)
- Re: Interesting idea for a covert channel or I justdidn't research enough? phased (Oct 06)
- Re: Interesting idea for a covert channel or I just didn't research enough? Bernhard Mueller (Oct 06)
- Re: Interesting idea for a covert channel or I just didn't research enough? Mario 'BitKoenig' Holbe (Oct 06)
- Re: Interesting idea for a covert channel or I just didn't research enough? Michael Holstein (Oct 06)
- Re: Interesting idea for a covert channel or I just didn't research enough? Kevin Wilcox (Oct 06)
- Re: Interesting idea for a covert channel or I just didn't research enough? mudge (Oct 06)
- Re: Interesting idea for a covert channel or I just didn't research enough? Jurjen Oskam (Oct 06)
- RE: Interesting idea for a covert channel or I justdidn't research enough? Aditya Deshmukh (Oct 07)
- Re: Interesting idea for a covert channel or I justdidn't research enough? Thierry Zoller (Oct 08)
- Re: Interesting idea for a covert channel or I justdidn't research enough? Jurjen Oskam (Oct 08)
- RE: Interesting idea for a covert channel or I justdidn't research enough? Aditya Deshmukh (Oct 07)
- Re: Interesting idea for a covert channel or I just didn't research enough? Michael Holstein (Oct 06)
- Re: Interesting idea for a covert channel or I just didn't research enough? Frank Knobbe (Oct 06)
(Thread continues...)