maznu-naughty-step-netmcr- maznu-naughty-step-netmcr-

Enics 9 views 30 slides Oct 04, 2024
Slide 1
Slide 1 of 30
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28
Slide 29
29
Slide 30
30

About This Presentation

Naughty Step Net


Slide Content

The Naughty Step
Marek Isalski — @maznu
Faelix Limited — https://faelix.net/

ssh
SMTP
IMAP
POP
VOIP
Drupal
WordPress

That is one big
pile of shit!

The Naughty Step

The Shit Pit
The Naughty Step

PushDo
virus cover traffic sending 2kbytes with POST / HTTP/1.0
and opening connection to TCP port 25

omg wtf loadavg

– every infosec professional ever
“Security is hard.”

WWW
Cat GIF Blog
make DJT
root again!

WWW
Cat GIF Blog
make DJT
root again!
apache
logs
fail2ban

Edge Router
WWW
Cat GIF Blog
make DJT
root again!
apache
logs
fail2ban
slurry
AMQP

Edge Router
WWW
Cat GIF Blog
make DJT
root again!
apache
logs
fail2ban
slurry
spreader
AMQP

Edge Router
WWW
Cat GIF Blog
apache
logs
fail2ban
slurry
spreader
AMQP
passwords
are hard

Edge Router
WWW
Cat GIF Blog
apache
logs
fail2ban
slurry
spreader
AMQP
passwords
are hard

WWW
Cat GIF Blog
apache
logs
fail2ban
slurry
spreader
AMQP
passwords
are hard
Edge Router

Edge Router
fail2ban
slurry
spreader
AMQP
passwords
are hard

Edge Router
WWW
Cat GIF Blog
fail2ban
slurry
spreader
AMQP
passwords
are hard

Edge Router
fail2ban
slurry
spreader
AMQP
make DJT
root again!

Edge Router
fail2ban
slurry
spreader
AMQP
make DJT
root again!

DNS RBL
badips.com
VIPs

Edge Router
fail2ban
slurry
spreader
AMQP
make DJT
root again!

DNS RBL
badips.com
fastnetmon
VIPs
fastnetmon?
NetMcr #2!

Edge Router
fail2ban
slurry
spreader
AMQP
make DJT
root again!

DNS RBL
badips.com
fastnetmon
VIPs
snort?
NetMcr #???
snort

Edge Router
fail2ban
slurry
spreader
AMQP
make DJT
root again!

DNS RBL
badips.com
VIPs
IPv6
fastnetmon
snort

bots = smart
Typical day of traffic in the shitpit:
spike of traffic, bot realises, moves on.

bots = dumb
Last 90 days, showing some ongoing, persistent attackers.

Show me the code!

Show me the code!
:-(

Show me the code!
:-)
soon?

Check these out!
•fail2ban = tail log files, filter them, perform actions
•fastnetmon = am I being DDoSed? uses NetFlow/etc
•portsentry = am I being portscanned?
•mod_security + OWASP = Web Application Firewall
•snort = intrusion detection system

Check these out!
•fail2ban = tail log files, filter them, perform actions
•fastnetmon = am I being DDoSed? uses NetFlow/etc
•portsentry = am I being portscanned?
•mod_security + OWASP = Web Application Firewall
•snort = intrusion detection system
•MikroTik MUM London 2016-11-14 (Monday!)

Q?
E: [email protected]
T: @maznu
Tags