port scanning without sending packets - def con · port scanning without sending packets. gregory...

72
DefCon 19, Las Vegas 2011 Port Scanning Without Sending Packets

Upload: others

Post on 06-Aug-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

DefCon 19, Las Vegas 2011

Port Scanning Without Sending Packets

Page 2: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Gregory Pickett, CISSP, GCIA, GPENChicago, Illinois

[email protected]

Hellfire Security

Page 3: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Overview

How This All StartedIt’s Not A Magic TrickLoose Lips Sink ShipsCatch Me If You CanBack To The Future

Page 4: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Suppose You Have This Guy On Your Network …

Page 5: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Suppose You Have This Guy On Your Network …

Page 6: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Suppose You Have This Guy On Your Network …

Host Name?

Page 7: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Suppose You Have This Guy On Your Network …

CharacterizeProfile

Asset or IntruderRoleFunction

Determination

10.111.128.55

nbtstat

Host Name

Page 8: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Suppose You Have This Guy On Your Network …

CharacterizeProfile

Asset or IntruderRoleFunction

Determination

10.111.128.55

?

Host Name

Page 9: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

What is all this multicast?

Me!

Page 10: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

It’s Multicast DNS (mDNS)!

PurposeName Resolution (Peer-to-Peer)

HistoryAppleTalk Name Binding ProtocolZero Configuration Networking

DevelopmentMulticast DNSDNS-Service Discovery

Page 11: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Features

MessagesSame formats and operating semantics as conventional DNSBased on “local” domainShared and unique records

OperationsQueries and responses sent to 224.0.0.251Utilizes UDP port 5353 for both resolvers and responders

Page 12: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Usage

Probe

Announcement

- Startup -

- For those resource records that it desires to be unique on the local link- Proposed questions in the Authority Section as well- Any “Type” record

- All shared and unique records in answer section- Unique have their cache-flush bit set- Repeated any time should rdata change- Unsolicited response

(query)

(response)

224.0.0.251

224.0.0.251

Page 13: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Usage

Querying

Responding

- Resolution -

- One-shot queries, and continuous ongoing queries- Source port determines compliance level of the resolver- Fully compliant resolvers can receive more than one answer- Known answer suppression- Truncation is used for large known answer set

- Mutlicast or unicast response per the query parameter- Unicast queries are always treated as having the “QU” bit set- Cache-flush bit indicates an authoritative answer- No queries in any response

224.0.0.251

224.0.0.251

10.15.36.251

(multicast)

(unicast)

Or

Page 14: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Usage

Goodbye- Resolution -

- Used for changes on “Shared” records- Not needed for unique records because of the cache-flush bit

(query)

224.0.0.251

Page 15: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Implementations

AppleRendezvousBonjour

AppleWindows

AvahiLinux

Others

Page 16: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Names

“PTR” Record135.148.16.172.in-addr.arpa7.A.F.A.E.B.E.F.F.F.A.4.6.2.2.0.0.0.0.0.0.0.0.0.0.0.0.0.0.8.E.F.ip6.arpa

“A” RecordNPIBB0A88.local

“AAAA” RecordNPIBB0A88.local

Page 17: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Services

“PTR” Record_ipp._tcp.local

“SRV” RecordHP Color LaserJet 4700 [10080F]._ipp._tcp.localHP Color LaserJet 4700 [96E411]._ipp._tcp.localHP Color LaserJet 4700 [96E411]._ipp._tcp.local

Page 18: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Other

“TXT” RecordHP Color LaserJet 4700 [808EDF]._ipp._tcp.local

“HINFO” Recordtimur.locallocalhost.local

Page 19: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

DNS-Service Discovery

Works over standard and multicast DNS Fully CompliantContinuous QueryingShared “PTR” recordsUnique “SRV” and “TXT” records

Page 20: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Probe

Page 21: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Query, “A” Record

User

Page 22: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Response, “A” Record

User

UserUser User

Page 23: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Query, “PTR” Record

Page 24: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Response, “PTR” Record

Page 25: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Query, “SRV” Record

Page 26: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Response, “SRV” Record

Page 27: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Grabbing Information from an mDNS Responder

mDNSHostNameParameters (-t:Target)Reverse lookup of the IPv4 addressOperates using a unicast legacy query to UDP port 5353 of the target

mDNSLookupParameters [-t:Target] [-q:Question] [-r:Record Type]Submits the question as givenAlso operates using a unicast legacy query to UDP port 5353 of the target …

Page 28: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Demonstration

Page 29: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

But wait ...

Isn’t this just flowing to my interface on it’s own?

OK … I could do some really cool things with this!

Page 30: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

What could I do?

Me!Information Gathering

Host Thank you!

Host Thank you!

Service Thank you!

Service Thank you!

Service Thank you!

Service Thank you!

Host Thank you!

Service Thank you!

Service Thank you!

Page 31: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Requirements

Must have active responders (someone offering)Connected to same switch as other resolvers (someone asking)

Or

Join yourself (if you must) to the multicast group

Works best on a busy network … because you need hosts out there asking a lot of questions so that you can collect the most answers!

Page 32: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

First Cool thing … Host Discovery!

mDNSDiscoveryParameters [-t:Range]Reports on any host communicating to 224.0.0.251Doesn’t join the group … only picks up traffic for the multicast group that is forwarded to all ports by the switch

Page 33: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Demonstration

Page 34: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

End result?

Completely silent, passive host discovery

Network Security Guy!

Why don’t you go active so I can catch you!

Page 35: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

But wait, there’s more …

Page 36: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Second Cool thing … Port Scanning!

Legitimate hosts performing (in essence) port scans with one packetCouldn’t I perform a port scan with no packets?

Page 37: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

That’s right … two, two products in one!

Page 38: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Is it magic?

Page 39: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

It’s “Zero Configuration” Networking!

Page 40: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

So Let’s Do This …

DNS-Service Discovery occurs continuously over the networkListen for it over multicast DNS on the local linkDon’t rely on known service records … it’s too limitingWhen a host responds to a discovery request …report all the SRV record ports in it’s replies as ports open on that host

Page 41: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

So Let’s Do This …

mDNSScanParameters [-t:Range] [-p:Ports]Currently 22 services over 18 ports have been seen and identified using this methodMany more are possible based on the exhaustive list availableDoesn’t join the group either …

Page 42: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Demonstration

Page 43: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

This is what our sensors see …

Page 44: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

… in a typical active scan

Page 45: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

And what do our network sensors see …

Me!

Page 46: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

… during this passive scan

Me!

Nothing!

Page 47: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

What does this mean?

Network Security Guy!

We are still unhappy!

Completely silent, passive port scans

Page 48: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

OK, what else?

Unique ImplementationsUnique RecordsUnique SetsCould this be used to fingerprint?

Page 49: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Yes … yes, it could

Linux_services._dns-sd._udp.local Avahi_workstation._tcp.local (SRV) Linux

Apple_services._dns-sd._udp.local Bonjour_afpovertcp._tcp.local (SRV,TXT) Apple_device-info._tcp.local (TXT)

Page 50: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Yes … yes, it could

Printers _ipp._tcp.local (SRV, TXT) Printer_printer._tcp.local (SRV, TXT) Printer_pdl-datastream._tcp.local (SRV, TXT) Printer

Network Attached Storage (Seagate)_blackarmor4dinfo._udp.local (SRV,TXT) NAS, Seagate_blackarmor4dconfig._tcp.local (SRV, TXT)

IP Cameras (Axis)_axis-video._tcp.local (SRV) IP Camera, Axis

Page 51: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Profiling, “TXT” RecordsLinux

Apple

Page 52: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Profiling, “TXT” Records

Printer

User

Page 53: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Profiling, “TXT” Records

Network Attached Storage (Seagate)

Page 54: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Profiling, “TXT” Records

IP Camera (Axis)

Page 55: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Someday … mDNSFingerprint

Build database of identifying record setsCollect all incoming records and organize by hostMatch against database and extract configuration informationReturn identity and configuration information for each host

Page 56: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Limitations

MulticastRouters between the recipient and the source must be multicast enabled

mDNSQuerying (Link-Local Response Only)

Responses only accepted from local-linkResponses only sent to the local-link

Listening (Layer-2 Boundaries)Broadcast DomainVLAN containment

Page 57: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Sensors

Intrusion Detection/Prevention SystemsEtherapeNetflow/StealthWatch

Page 58: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Detect

Page 59: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Other detection possibilities

MonitoringIGMP (group membership)mDNS (responders)

Management Applications?

Page 60: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Defenses (Host)

Anti-Virus/Anti-Spyware/Anti-SpamIntrusion Prevention SystemFirewall and Port BlockingApplication ControlDevice ControlOthers

Page 61: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Do these help any?

Page 62: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Defenses (Network)

Firewalls/Access Control ListsNetwork Access ControlVLANs

Page 63: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

How about these?

Page 64: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

What can we do then?

IGMPImplement IGMP snoopingAuthenticate group membership (IGAP)Track members (Membership reports)

Page 65: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

What can we do then?

Multicast DNSLocate mDNS respondersDisable the serviceHarden the box … in particular the services that are offeredSanitize records

Page 66: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Plan of Attack

Hunt down mDNS responders with these toolsRemove them or harden themImplement any controls you have for multicast in your environment

IGMP snooping/MLDv2IGAP or IPv6 multicast authentication mechanisms

Page 67: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Other Protocols

Simple Service Discovery Protocol (SSDP)Microsoft’s Answer to “Zero Configuration”networkingHTTP-Based but also multicastedMethods: NOTIFY, M-SEARCH

Link Local Multicast Name Resolution (LLMNR)Another Microsoft solution

DNS-Based but also multicasted

Both less developed, but still in use

Page 68: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Final Thoughts

Hosts are now actively advertising their available attack surfaces to anyone listening on the network Great for passive information gatheringCan be controlled to limit your exposureBut ultimately …This is not for the enterprise

Page 69: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Demonstration

Page 70: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

ToolsmDNSHostName v1.00 for WindowsMD5: e97b2c8325a0ba3459c9a3a1d67a6306

mDNSLookup v1.00 for WindowsMD5: f489dd2a9af1606dd66a4a6f1f77c892

mDNSDiscovery v1.00 for WindowsMD5: e6c8c069989ec0f872da088edbbb1074

mDNSScan v1.00 for WindowsMD5: eb764b7f0ece697bd8abbea6275786dc

Updates http://mdnstools.sourceforge.net/

Page 71: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com

Linkshttp://www.multicastdns.org/http://www.dns-sd.org/http://www.ietf.org/id/draft-cheshire-dnsext-multicastdns-14.txthttp://www.ietf.org/id/draft-cheshire-dnsext-dns-sd-10.txthttp://www.ietf.org/id/draft-cheshire-dnsext-special-names-01.txthttp://www.rfc-editor.org/rfc/rfc3927.txthttp://www.bleepsoft.com/tyler/index.php?itemid=105http://www.dns-sd.org/ServiceTypes.htmlhttp://www.zeroconf.org/http://avahi.org/http://meetings.ripe.net/ripe-55/presentations/strotmann-mdns.pdfhttp://www.mitre.org/work/tech_papers/2010/09_5245/09_5245.pdf

Page 72: Port Scanning Without Sending Packets - DEF CON · Port Scanning Without Sending Packets. Gregory Pickett, CISSP, GCIA, GPEN Chicago, Illinois gregory.pickett@hellfiresecurity.com