Defcon 17 Tactical Fingerprinting using Foca

Loading...

Flash Player 9 (or above) is needed to view presentations.
We have detected that you do not have it on your computer. To install it, go here.

0 comments

Post a comment

    Post a comment
    Embed Video
    Edit your comment Cancel

    1 Favorite

    Defcon 17 Tactical Fingerprinting using Foca - Presentation Transcript

    1. Chema Alonso, José Palazón “Palako”
      Tactical Fingerprinting using metadata, hidden info and lost data using FOCA
    2. 2003 – a piece of history
      Irak war was about to start
      US wanted the UK to be an ally.
      US sent a document “proving” the existence of massive destruction weapons
      Tony Blair presented the document to the UK parliament.
      Parliament asked Tony Blair “Has someone modified the document?”
      He answered: No
    3. 2003 – MS Word bytes Tony Blair
    4. What kind of data can be found?
      Metadata:
      Information stored to give information about the document.
      For example: Creator, Organization, etc..
      Hidden information:
      Information internally stored by programs and not editable.
      For example: Template paths, Printers, db structure, etc…
      Lost data:
      Information which is in documents due to human mistakes or negligence, because it was not intended to be there.
      For example: Links to internal servers, data hidden by format, etc…
    5. Metadata
      Metadata Lifecycle
      Wrongmanagement
      Badformatconversion
      Unsecureoptions
      Wrongmanagement
      Badformatconversion
      Unsecureoptions
      New apps
      orprogram
      versions
      Searchengines
      Spiders
      Databases
      Embedded
      files
      Hiddeninfo
      Lost Data
      Embedded
      files
    6. Metadatacreatedby Google
    7. Lost Data
    8. Lost data everywhere
    9. Public server
    10. So… are people aware of this?
      The answer is NO.
      Almost nobody is cleaning documents.
      Companies publish thousands of documents without cleaning them before with:
      Metadata.
      Hidden Info.
      Lost data.
    11. Sample: FBI.gov
      Total: 4841 files
    12. Are theyclean?
      Total: 1075 files
    13. Howmany files is my companypublishing?
    14. Sample: Printer info found in odf files returned by Google
    15. Google Sets prediction
    16. Sample: Info found in a PDF file
    17. What files store Metadata, hidden info or lost data?
      Office documents:
      Open Office documents.
      MS Office documents.
      PDF Documents.
      XMP.
      EPS Documents.
      Graphic documents.
      EXIFF.
      XMP.
      And almost everything….
    18. Pictureswith GPS info..
      EXIFREADER
      http://www.takenet.or.jp/~ryuuji/
    19. Demo: Lookingfor EXIF information in ODF file
    20. Even Videos withusers…
      http://video.techrepublic.com.com/2422-14075_11-207247.html
    21. And of course, printedtxt
    22. What can be found?
      Users:
      Creators.
      Modifiers .
      Users in paths.
      C:Documents and settingsjfoomyfile
      /home/johnnyf
      Operating systems.
      Printers.
      Local and remote.
      Paths.
      Local and remote.
      Network info.
      Shared Printers.
      Shared Folders.
      ACLS.
      Internal Servers.
      NetBIOS Name.
      Domain Name.
      IP Address.
      Database structures.
      Table names.
      Colum names.
      Devices info.
      Mobiles.
      Photo cameras.
      Private Info.
      Personal data.
      History of use.
      Software versions.
    23. How can metadata be extracted?
      Info is in the file in raw format:
      Binary.
      ASCII .
      Therefore Hex or ASCII editors can be used:
      HexEdit.
      Notepad++.
      Bintext
      Special tools can be used:
      Exifredaer
      ExifTool
      Libextractor.
      Metagoofil.

      …or just open the file!
    24. Tools: Libextractor
    25. Tools: MetaGoofil
      • http://www.edge-security.com/metagoofil.php
    26. Yes, also Google….
    27. Your FBI user
    28. Your UN user
    29. YourScotlandYarduser
    30. YourCarabinieriuser
    31. YourWhiteHouseuser
    32. Yes, we can!
    33. Drawbacks
      These tools only extract metadata.
      Not looking for Hidden Info.
      Not looking for lost data.
      Not post-analysis.
    34. OnlyMetadata
      http://gnunet.org/libextractor/demo.php3
    35. Notverygoodwith XML files (SWX, ODF, OOXML)
    36. Google is [almost] GOD
    37. FiletypeorExtension?
    38. Foca
      Fingerprinting Organizations with Collected Archives.
      Search for documents in Google and Bing
      Automatic file downloading
      Capable of extracting Metadata, hidden info and lost data
      Cluster information
      Analyzes the info to fingerprint the network.
    39. Demo: FOCA
    40. FOCA Online
      http://www.informatica64.com/FOCA
    41. Solutions?
    42. First: Cleanallpublicdocuments
    43. Clean your documents:MSOffice 2k7
    44. Clean your documents: MSOffice 2k3 & XP
      http://www.microsoft.com/downloads/details.aspx?displaylang=en&FamilyID=144e54ed-d43e-42ca-bc7b-5446d34e5360
    45. OLE Streams
      In MS Office binaryformat files
      Storeinformationaboutthe OS
      Are notcleanedwiththese Tools
      FOCA findsthisinfo
    46. Demo: Lookingforinfo in cleaneddocument
    47. OpenOfficecleaningoptions
      Onlymetadata
      Notcleaninghiddeninfo
      Notcleaninglost data
    48. Cleaning documents
      OOMetaExtractor
      http://www.codeplex.org/oometaextractor
    49. Demo: OpenOffice “Security” Options…
    50. Are yousaferelyingonyourusers?
    51. IIS MetaShield Protector
      http://www.metashieldprotector.com
    52. Second: Beg Google todeleteallthecached files
    53. Don´t trust your users!!!
    54. Don´tcomplainaboutyourjob!!
    55. PS: Thisfilealso has metadata
    56. Thanks
      Authors
      Chema Alonso
      chema@informatica64.com
      Jose Palazón “Palako”
      palako@lateatral.com
      Enrique Rando
      Enrique.rando@juntadeandalucia.es
      Alejandro Martín
      amartin@informatica64.com
      Francisco Oca
      froca@informatica64.com
      Antonio Guzmán
      antonio.guzman@urjc.es

    + chemai64chemai64, 3 months ago

    custom

    2102 views, 1 favs, 5 embeds more stats

    Talk delivered by Chema Alonso and José Palazón " more

    More info about this document

    © All Rights Reserved

    Go to text version

    • Total Views 2102
      • 1832 on SlideShare
      • 270 from embeds
    • Comments 0
    • Favorites 1
    • Downloads 64
    Most viewed embeds
    • 241 views on http://elladodelmal.blogspot.com
    • 25 views on http://www.cyberhades.com
    • 2 views on file://
    • 1 views on http://www.newsgator.com
    • 1 views on http://74.125.79.132

    more

    All embeds
    • 241 views on http://elladodelmal.blogspot.com
    • 25 views on http://www.cyberhades.com
    • 2 views on file://
    • 1 views on http://www.newsgator.com
    • 1 views on http://74.125.79.132

    less

    Flagged as inappropriate Flag as inappropriate
    Flag as inappropriate

    Select your reason for flagging this presentation as inappropriate. If needed, use the feedback form to let us know more details.

    Cancel
    File a copyright complaint
    Having problems? Go to our helpdesk?

    Categories