Establish persistant outbound connection for covert application

From: David Siles (ctowizkid_at_gmail.com)
Date: 08/24/05

  • Next message: ricci_at_cs.ust.hk: "Re: SEIM evaluation"
    Date: Tue, 23 Aug 2005 17:17:16 -0500
    To: security-basics@securityfocus.com
    
    

    Hello all,

    I am looking for some additional ideas for an application we are
    trying to use for a law enforcement application.

    We are currently using a product that allows us to install a software
    shim on a suspect's PC and then connect into the PC at any given time
    to perform forensic analysis. While this works great, we consistently
    run into the problem of personal firewalls, NAT devices, SP2, and
    other ACLs that prevent us from connecting into the suspect machine.

    While we usually have the suspect full cooperation in the monitoring
    efforts and we can initally configure their network and/or PC
    configuration to allow this communication things get changed. Also we
    run into the problem with dynamic addressing changing on us, which can
    be a pain to keep track off unless we install some type of dyn dns
    solution.

    To tackle this problem I have been able to setup SSH tunneling and
    making the suspects computer establish the SSH connection to our
    external facing test box and then having our forensic station connect
    in and use the SSH to redirect the tunneling, but I would like to come
    up with a better method.

    I am asking if anyone has ideas on this to either reply to the list
    for benefit of all or contact me directly.

    I am looking for something that will connect outbound, preferable
    covertly as a background/hidden process (e.g. fooing a netcat/cryptcat
    connection) to awaiting connection server or service for redirection.
    SSH may be the best process here, but I don't like having to open an
    SSH tunnel for this. The application we are using is already running
    encrypted traffic, so adding another layer of encryption also slows it
    down.

    The capability to make this application call home will be of great
    benefit to many in the LEO community and if your interested in what we
    are doing, please feel free to contact me offlist.

    Thanks,

    Dave Siles


  • Next message: ricci_at_cs.ust.hk: "Re: SEIM evaluation"

    Relevant Pages

    • Re: Securing ssh tunnels.
      ... >> ie. with ssh tunneling there is very little real access control on ... >> possible with ssh tunnels. ... connection to an outside host. ...
      (SSH)
    • Re: What is The SSH?
      ... Building and Using SSH Tunnels ... What is an SSH tunnel? ... how to use it to make a connection to a server. ... You will need a working SSH client and server installation to build and test ...
      (microsoft.public.windows.server.networking)
    • Re: Problem connecting to SSH, OpenVMS7.3-2, HP TCP/IP v5.4 patched
      ... warning: Authentication failed. ... connection lost (Connection closed by remote host.). ... So, as you can see, I am trying to make an ssh connection with the ...
      (comp.os.vms)
    • Re: Keeping OpenSSH connections alive
      ... The TCP connection is timing out, not the SSH session. ... You can then, reconnect to the backgrounded screen session, upon relogin. ...
      (SSH)
    • Re: Remote Desktop Connection
      ... You can try a free two user version of SSL-Explorer to try it out. ... SSL-Explorer also supports a web based RDC and VNC access to desktop PCs on your network. ... OpenVPN is completely free like SSH. ... What if i have a linkys WiFi router, and does not have vpn feature, how could i secure the connection? ...
      (microsoft.public.windowsxp.work_remotely)

    Loading