About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
  #1   Add Punk_Rocker_22 to your ignore list  
Old 2008-08-26, 21:26
Punk_Rocker_22 Punk_Rocker_22 is offline
Regular
 
Syracuse Send a message via AIM to Punk_Rocker_22 Send a message via Skype™ to Punk_Rocker_22
Default Pretending you're running Linux

My school requires you run their antivirus program if you have windows or OSX. They make you install a program called SafeConnect which monitors your antivirus status and sends information back to the school. There is an exception for Unix and Linux users.

Last year I could spoof my browser user agent to look like I was on a PDA, that let me access the PDA WiFi network. This year I spoofed it to look like I'm running Linux so I don't need to run their software. It seems to be working, but its only been a few minuets. What other ways can they detect my OS? and how can I spoof it?

Of course the real solution is just to install Linux, but I like my games.

Edit, yea it didn't work. Its still asking me to run their shit.

Last edited by Punk_Rocker_22; 2008-08-26 at 21:49.
Reply With Quote
  #2   Add O RLY to your ignore list  
Old 2008-08-26, 22:44
O RLY O RLY is offline
Moderator
 
Padmasana Send a message via AIM to O RLY Send a message via MSN to O RLY
Talking Re: Pretending you're running Linux

They can usually determine what basic operating system you are running by probes.
__________________
In Silence I lay for that Fateful Day. 0day.

jamato@email.itt-tech.edu <-- My Email
Reply With Quote
  #3   Add Vic Mackey to your ignore list  
Old 2008-08-26, 23:19
Vic Mackey Vic Mackey is offline
Regular
 
Washington
Default Re: Pretending you're running Linux

Get wireshark, and see what information SafeConnect is sending to your school. Shouldn't be too hard to write a script or program that would send spoofed packets I'd assume.
Reply With Quote
  #4   Add Punk_Rocker_22 to your ignore list  
Old 2008-08-27, 00:22
Punk_Rocker_22 Punk_Rocker_22 is offline
Regular
 
Syracuse Send a message via AIM to Punk_Rocker_22 Send a message via Skype™ to Punk_Rocker_22
Default Re: Pretending you're running Linux

Alright, totally off topic now, but thats fine.

I downloaded Wireshark, determined the location the program was sending the info and intercepted the packets.

When I disable my AV it sends 13 packets that tells the school that my AV is disabled. I immediately get locked out of the network.

When I enable it, it sends 9 packets and I can get back on right away.

I also assume it sends out some info every few hours, because if I disable it, I get locked a little bit later. I'm going to run Wireshark for the next few hours to determine what packets and the frequency of these packets. Though I could probably just send the 9 packets that says my AV is enabled every now and then.

My next big question is how do I resend these packets? I have the packets and I know where they are being sent, what port, what protocol, ect. I know C and Java, but I never got into network programming.

Final question is, is my packet scanning detectable if I'm not running in promiscuous mode?

Last edited by Punk_Rocker_22; 2008-08-27 at 01:02.
Reply With Quote
  #5   Add Vic Mackey to your ignore list  
Old 2008-08-27, 00:37
Vic Mackey Vic Mackey is offline
Regular
 
Washington
Default Re: Pretending you're running Linux

I am pretty sure most languages have a way to work with your network devices, whether integrated, or through a plug in. I honestly don't have a clue as to actually making a script or program, but someone in Hello World might.

And no, they shouldn't be able to tell that you are running wireshark. It is basically showing you what is already happening behind the scenes.
Reply With Quote
  #6   Add Punk_Rocker_22 to your ignore list  
Old 2008-08-27, 01:03
Punk_Rocker_22 Punk_Rocker_22 is offline
Regular
 
Syracuse Send a message via AIM to Punk_Rocker_22 Send a message via Skype™ to Punk_Rocker_22
Default Re: Pretending you're running Linux

Alright, cool

I narrowed it down to 9 packets that get sent in the same order in 20min intervals

Now to figure out how to send them on my own....

EDIT: Feck, it seems the packets being sent out are slightly different and are responding to packets sent it by the schools network

New mission is to isolate what parts of the AV it checks to make sure its running. That way I could make a fake AV to cut back on my system resources.

Last edited by Punk_Rocker_22; 2008-08-27 at 01:18.
Reply With Quote
  #7   Add Prometheum to your ignore list  
Old 2008-08-27, 01:24
Prometheum Prometheum is offline
Regular
 
01 Send a message via AIM to Prometheum Send a message via MSN to Prometheum
Default Re: Pretending you're running Linux

Write a program that emulates the program you want it to emulate. If it's as simple as it sounds, then it'll be easy.

Or you could just install Gnu.
Reply With Quote
  #8   Add Punk_Rocker_22 to your ignore list  
Old 2008-08-27, 01:28
Punk_Rocker_22 Punk_Rocker_22 is offline
Regular
 
Syracuse Send a message via AIM to Punk_Rocker_22 Send a message via Skype™ to Punk_Rocker_22
Default Re: Pretending you're running Linux

ahaha. I just renamed notepad.exe to McShield.exe (McAffe)

I ran that and it passed the check. Lol

So I'm just going to write a silly little program that hides in the taskbar and I'll name it McShield.exe

Jesus christ, I should have thought of this in the beginning. Start with the simplest solution, no matter how stupid.
Reply With Quote
  #9   Add Vic Mackey to your ignore list  
Old 2008-08-27, 03:04
Vic Mackey Vic Mackey is offline
Regular
 
Washington
Default Re: Pretending you're running Linux

Yeah, I was going to suggest something much more complicated if that didn't work. I was assuming this was a fairly well written application, and it would have some kind of signature database for lots of different anti virus programs. I guess they are just a bunch of lazy fuckers.
Reply With Quote
  #10   Add SLice_760 to your ignore list  
Old 2008-08-27, 03:21
SLice_760 SLice_760 is online now
Regular
 
....... Send a message via AIM to SLice_760
Thumbs up Re: Pretending you're running Linux

Quote:
Originally Posted by Punk_Rocker_22 View Post
ahaha. I just renamed notepad.exe to McShield.exe (McAffe)

I ran that and it passed the check. Lol

So I'm just going to write a silly little program that hides in the taskbar and I'll name it McShield.exe

Jesus christ, I should have thought of this in the beginning. Start with the simplest solution, no matter how stupid.
Hahaha that's fucking funny man. That reminds me of how I finally hacked the admin account at my school last year. I opened an old DOS window (command.com, not cmd.exe) and typed "net user admin pwned" just to see what would happen. It changed the admin password to pwned. I stared at the screen dumbfounded for like 10 minutes because this was after a few months of many failed attempts at password sniffing and hacking.
Reply With Quote
This thread continued for 2 pages in the real archive, 20 posts total - only page 1 survived here.
Reply

Thread Tools
Show Printable Version Show Printable Version
Email this Page Email this Page
Display Modes
Linear Mode Linear Mode
Hybrid Mode Switch to Hybrid Mode
Threaded Mode Switch to Threaded Mode

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics