12
The BruCO”NSA” Network “How we take care of your packets”

The BruCO"NSA" Network

Embed Size (px)

DESCRIPTION

This is the lightning talk presented by @xme and @senseizeon at BruCON 0x05 about the deployed network.

Citation preview

Page 1: The BruCO"NSA" Network

The BruCO”NSA”Network

“How we take care of your packets”

Page 2: The BruCO"NSA" Network

Topology

• Radio P2P Link to theInternet

• Public VLAN

• Private VLAN (Crew,Speaker, Apps)

Page 3: The BruCO"NSA" Network

Topology

Page 4: The BruCO"NSA" Network

Our C&C

Page 5: The BruCO"NSA" Network

Numbers• 100 MBits up/down

• 11 AP’s

• 5 switches

• 60.303.633 packets captured yesterday

• Peak up to 65 Mbits/s

• Since BruCON 0x01, ~1 KM of CAT-5 cables

• ...a lot of Clubmate and 0xC0FFEE

Page 6: The BruCO"NSA" Network

Visibility“A network is like milk on a stove, you need to keep

an eye on it all the time”

Page 7: The BruCO"NSA" Network

Visibility

Page 8: The BruCO"NSA" Network

Fun VS. Legal

• BruCON is considered as an ISP from the .be law point of view

• We keep:MAC|Timestamp|SrcIP|SrcPort|DstIP|DstPort

• “Due diligence” principle

Page 9: The BruCO"NSA" Network

Wall of Sheep

Page 10: The BruCO"NSA" Network

Wall of Sheep

• 25 unique passwords sniffed (up to now!)

• Avg length: 6.8 characters

Protocols Countssnmp 2034http 82ftp 27pop 17

Page 11: The BruCO"NSA" Network

Malware Tracking

Page 12: The BruCO"NSA" Network

All your packets are belong to us...

Thank You!