.:: Phrack Magazine ::.
[ News ]<br>[ Issues ]<br>[ Authors ]<br>[ Archives ]<br>[ Contact ]<br>[ Search ]
[ Close ]
Enter something in the search box to see results
-->
.:: Against the System ::.
Issues :<br>[ 1 ]<br>[ 2 ]<br>[ 3 ]<br>[ 4 ]<br>[ 5 ]<br>[ 6 ]<br>[ 7 ]<br>[ 8 ]<br>[ 9 ]<br>[ 10 ]<br>[ 11 ]<br>[ 12 ]<br>[ 13 ]<br>[ 14 ]<br>[ 15 ]<br>[ 16 ]<br>[ 17 ]<br>[ 18 ]<br>[ 19 ]<br>[ 20 ]<br>[ 21 ]<br>[ 22 ]<br>[ 23 ]<br>[ 24 ]<br>[ 25 ]<br>[ 26 ]<br>[ 27 ]<br>[ 28 ]<br>[ 29 ]<br>[ 30 ]<br>[ 31 ]<br>[ 32 ]<br>[ 33 ]<br>[ 34 ]<br>[ 35 ]<br>[ 36 ]<br>[ 37 ]<br>[ 38 ]<br>[ 39 ]<br>[ 40 ]<br>[ 41 ]<br>[ 42 ]<br>[ 43 ]<br>[ 44 ]<br>[ 45 ]<br>[ 46 ]<br>[ 47 ]<br>[ 48 ]<br>[ 49 ]<br>[ 50 ]<br>[ 51 ]<br>[ 52 ]<br>[ 53 ]<br>[ 54 ]<br>[ 55 ]<br>[ 56 ]<br>[ 57 ]<br>[ 58 ]<br>[ 59 ]<br>[ 60 ]<br>[ 61 ]<br>[ 62 ]<br>[ 63 ]<br>[ 64 ]<br>[ 65 ]<br>[ 66 ]<br>[ 67 ]<br>[ 68 ]<br>[ 69 ]<br>[ 70 ]<br>[ 71 ]<br>[ 72 ]
Get tar.gz<br>Current issue : #57 | Release date : 2001-08-11 | Editor : Phrack Staff
IntroductionPhrack Staff
Phrack LoopbackPhrack Staff
Phrack Line NoisePhrack Staff
Editorial policyPhrack Staff
IA64 shellcodepapasutra
Taranis read your e-mailjwilkins
ICMP based OS fingerprintingOfir Arkin & Fyodor Yarochkin
Vudo malloc tricksMaXX
Once upon a free()anonymous author
Against the SystemMichal Zalewski
Holistic approaches to attack detectionsasha
NIDS on mass parallel processing architecturestorm
Hang on, snoopystealth
Architecture spanning shellcodeeugene
Writing ia32 alphanumeric shellcodesrix
Cupass and the netuserchangepassword problemD.Holiday
Phrack World NewsPhrack Staff
Phrack magazine extraction utilityPhrack Staff
Title : Against the System
Author : Michal Zalewski
==Phrack Inc.==
Volume 0x0b, Issue 0x39, Phile #0x0a of 0x12
|=-------------=[ Against the System: Rise of the Robots ]=--------------=|<br>|=-----------------------------------------------------------------------=|<br>|=-=[ (C)Copyright 2001 by Michal Zalewski [email protected]> ]=-=|
-- [1] Introduction -------------------------------------------------------
"[...] big difference between the web and traditional well controlled<br>collections is that there is virtually no control over what people can<br>put on the web. Couple this flexibility to publish anything with the<br>enormous influence of search engines to route traffic and companies<br>which deliberately manipulating search engines for profit become a<br>serious problem."
-- Sergey Brin, Lawrence Page (see references, [A])
Consider a remote exploit that is able to compromise a remote system<br>without sending any attack code to his victim. Consider an exploit<br>which simply creates local file to compromise thousands of computers,<br>and which does not involve any local resources in the attack. Welcome to<br>the world of zero-effort exploit techniques. Welcome to the world of<br>automation, welcome to the world of anonymous, dramatically difficult<br>to stop attacks resulting from increasing Internet complexity.
Zero-effort exploits create their 'wishlist', and leave it somewhere<br>in cyberspace - can be even its home host, in the place where others<br>can find it. Others - Internet workers (see references, [D]) - hundreds<br>of never sleeping, endlessly browsing information crawlers, intelligent<br>agents, search engines... They come to pick this information, and -<br>unknowingly - to attack victims. You can stop one of them, but can't<br>stop them all. You can find out what their orders are, but you can't<br>guess what these orders will be tomorrow, hidden somewhere in the abyss<br>of not yet explored cyberspace.
Your private army, close at hand, picking orders you left for them<br>on their way. You exploit them without having to compromise them. They<br>do what they are designed for, and they do their best to accomplish it.<br>Welcome to the new reality, where our A.I. machines can rise against us.
Consider a worm. Consider a worm which does nothing. It is carried and<br>injected by others - but not by infecting them. This worm creates a<br>wishlist - wishlist of, for example, 10,000 random addresses. And waits.<br>Intelligent agents pick this list, with their united forces they try to<br>attack all of them. Imagine they are not lucky, with 0.1% success ratio.<br>Ten new hosts infected. On every of them, the worm does extactly the<br>same - and agents come back, to infect 100 hosts. The story goes - or<br>crawls, if you prefer.
Agents work virtually invisibly, people get used to their presence<br>everywhere. And crawlers just slowly go ahead, in never-ending loop.<br>They work systematically, they do not choke with excessive data - they<br>crawl, there's no "boom" effect. Week after week after week, they try<br>new hosts, carefully, not overloading network uplinks, not generating<br>suspected traffic, recurrent exploration never ends. Can you notice<br>they carry a worm? Possibly...
-- [2] An example ---------------------------------------------------------
When this idea came to my mind, I tried to use the simpliest test, just<br>to see if I am right. I targeted, if that's the right word, general-purpose<br>web indexing crawlers. I created very short HTML document and put it<br>somewhere. And waited few weeks. And then they come. Altavista, Lycos<br>and dozens of others. They found...