DEF CON 25 - Jim Nitterauer - DNS: Devious Name Services Destroying Privacy & Anonymity w/o consent

Поделиться
HTML-код
  • Опубликовано: 1 авг 2024
  • You've planned this engagement for weeks. Everything's mapped out. You have tested all your proxy and VPN connections. You are confident your anonymity will be protected. You fire off the first round and begin attacking your target. Suddenly something goes south. Your access to the target site is completely blocked no matter what proxy or VPN you use. Soon, your ISP contacts you reminding you of their TOS while referencing complaints from the target of your engagement. You quickly switch MAC addresses and retry only to find that you are quickly blocked again!
    What happened? How were you betrayed? The culprit? Your dastardly DNS resolvers and more specifically, the use of certain EDNS0 options by those resolvers.
    This presentation will cover the ways in which EDNS OPT code data can divulge details about your online activity, look at methods for discovering implementation by upstream DNS providers and discuss ways in which malicious actors can abuse these features. We will also examine steps you can take to protect yourself from these invasive disclosures.
    The details covered will be only moderately technical. Having a basic understanding of RFC 6891 and general DNS processes will help in understanding. We will discuss the use of basic tools including Wireshark, Packetbeat, Graylog and Dig.
  • НаукаНаука

Комментарии • 13

  • @Radi0he4d1
    @Radi0he4d1 6 лет назад +5

    wow that guy has a concerning number of taskbar icons.

    • @ko-Daegu
      @ko-Daegu 6 лет назад

      Radi0he4d1
      Damn boooi
      🤣🤣🤣

  • @wpsecurelabs1456
    @wpsecurelabs1456 2 года назад

    Awesome

  • @ko-Daegu
    @ko-Daegu 6 лет назад

    Great CEO would love to work with him

  • @_randombob
    @_randombob 6 лет назад

    The connection needs a ground aometimes, may be why it kept dooking up.

  • @wrnrt
    @wrnrt 6 лет назад +7

    Slides issue could have been fixed in post...

    • @vuvffufg
      @vuvffufg 6 лет назад +1

      But we need the full experience of the talk. lol I would have been so pissed and walked out if I was there, just as tho I am leaving this video.. hahaha

    • @ko-Daegu
      @ko-Daegu 6 лет назад

      Werner T
      No slide problems no watch
      But yeah without the problems it’s not defocn

  • @nxxxxzn
    @nxxxxzn 5 лет назад +2

    "steve" should stop rolling his own fpga hdmi crap and buy proper stuff

  • @floridaseminole8643
    @floridaseminole8643 5 лет назад

    Fucking blinking