3.3. database honeypot

24
Database honeypot by design @GiftsUngiven @cyberpunkych

Upload: defconmoscow

Post on 06-Aug-2015

44 views

Category:

Internet


3 download

TRANSCRIPT

Page 1: 3.3. Database honeypot

Database honeypot by design

@GiftsUngiven@cyberpunkych

Page 2: 3.3. Database honeypot

Vote

Page 3: 3.3. Database honeypot

Vote

Page 4: 3.3. Database honeypot

Pre-history

Page 5: 3.3. Database honeypot
Page 6: 3.3. Database honeypot
Page 7: 3.3. Database honeypot
Page 8: 3.3. Database honeypot

bla bla bla

Page 9: 3.3. Database honeypot

Data analysis

Бро, не забудь надеть очки, дальше хэкерская правда

Page 10: 3.3. Database honeypot

Data analysis #1client request

LOAD DATA LOCAL INFILE "C:\\Windows\\system32\\drivers\\etc\\hosts" INTO TABLE mysql.test

Page 11: 3.3. Database honeypot

Data analysis #2server response

Page 12: 3.3. Database honeypot

Data analysis #3client answer

Page 13: 3.3. Database honeypot

Data analysis #?

What if we skip client request and just send server response to get a file for any request?

Page 14: 3.3. Database honeypot

Data analysis #?

Page 15: 3.3. Database honeypot

Data analysis #!

1 – client send ‘select’ query request2 – server send response ‘I want a file’3 – client send file content

Page 16: 3.3. Database honeypot

Profit!

- a little bit of script language to automate process

- A lot of fun

Page 17: 3.3. Database honeypot

Remember me? Now you know what to do!

Page 18: 3.3. Database honeypot

Honeypot?Want to hack my mysql? Okay… I will exchange your requests for your files.

Please, run ‘msfconsole’ under root.

Page 19: 3.3. Database honeypot

Python solves all problems

• https://github.com/Gifts/Rogue-MySql-Server

Page 20: 3.3. Database honeypot

Whhyyyyyy?

Page 21: 3.3. Database honeypot

Good guy Ares

We: MiTM?Ares: No problems!

http://intercepter.nerf.ru/http://intercepter.nerf.ru/dev.exe

Page 22: 3.3. Database honeypot

Good guy Ares

Page 23: 3.3. Database honeypot

Is it vulnerable?

Page 24: 3.3. Database honeypot

Thnx.

questions?