Microsoft Windows Vista Community Forums - Vistaheads
FREE Anti Rootkit Software for Vista Users




Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.


Registry Mechanic - Free Scan Now

A twist in fluxnet operations. Enter Hydraflux, (Sat, Jul 19th)

Security News



Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Reply
  #1 (permalink)  
Old 07-19-2008
Steve's Avatar
Steve Steve is offline
Moderator
 
Join Date: Sep 2006
Location: Emerald Isle
Posts: 41,777
Steve is on a distinguished road
A twist in fluxnet operations. Enter Hydraflux, (Sat, Jul 19th)
William, one of the other handlers, has been working on something a bit different. Like all of the handlers he has a lot on his plate so he hasn't had a chance to write things up, here is a little taste from Williams paper on something he has dubbed Hydraflux.



Fastflux is by now a staple for many phishing sites and malware delivery. It builds a stable network which is difficult to take down. In a fastflux environment many clients communicate with a flux node which in turn communicates with the mother ship. (Many clients ---Fluxnode:80----mothership:80) If you take out the fluxnode you affect a number of clients, but if you manage to take out the mothership, then the end result is more impressive. You have now taken out a number of fluxnodes as well as the many clients connected to it. Hyrdaflux changes this.



Asmall flux net(at the time) was observed where the behavior of the fluxnodes was different. The emergence may simply be an evolution in one flux herder codebase, or it represent a new fluxnet operation altogether. The uniqueness of this particular fluxnet does not become apparent until you see what is happening on theupstream side of thefluxnode traffic that is mothership bound. HydraFlux is bestowed as a result of operational behavioral based naming. In the observed network eachfluxnode endpoint maintained a one to many mothership relationship. The nodes also communicated with the mothership on a non standard port. (Many clients ---Fluxnode:80----Multiple Mother ships:4449) This type of structure now makes it more complicated to take the network down as the fluxnode can still receive instructions from the remaining motherships. The immediate upstream mothership was identified as nginx servers andthere is no easy methodto determine if the mothership tagged is the final destination, or just a hop in a network of motherships.



HydraFlux nodes inject the actual client IPinto mothership comms similar to how Storm and Warezov flux nets do (each in their own way). HydraFlux does this by injecting a client header X-Source: $IP following the Host: header, which is also modified on the upstream journey to the mothership(s) so that this header value represents the flux node incoming bind IP address, like so...



Client Traffic to - $FLUXNODE_IP:80

GET /servlet/?portal=kljasdliqwnnd78wnsnwjnsn HTTP/1.1

Accept: image/gif, (REDACTED_FOR_BREVITY), */*q=0.5

UA-CPU: x86Accept-Encoding: gzip, deflate .NET CLR 2.0.50727)

Host: www.AAAAA.BBBBB.net

Connection: Keep-Alive



Traffic leaving fluxnode for one Mothership - aaa.bbb.vvv.ddd:4449

GET /servlet/?portal=kljasdliqwnnd78wnsnwjnsn HTTP/1.1

Accept: image/gif, (REDACTED_FOR_BREVITY), */*q=0.5

UA-CPU: x86Accept-Encoding: gzip, deflate .NET CLR 2.0.50727)

Host: $FLUXNODE_IP

X-Source: $REMOTE_CLIENT_IP

Connection: Keep-Alive
At 11 minute intervals the fluxnode endpoint communicates with the mothership. It targets each of the respectivemothershipsinvolved.The form-encoded data identifiestypical elementsrelated to the clientincluding OS version, etc but perhaps the most interesting part isthe (XOR'd 27) instruction file consistently named 'COMMON.BIN' that is delivered back to the clientas the server response to POST/forum.php data. This file contains the IP addresses of all upstream motherships for the node.



It would seem that a potentiallylarge number of mother shipscould easily become involved, or for better or worse turn this into an ugly redirector mix of fluxnode endpoints redirecting through fluxnode end points intent on annoying even the most aggressive investigator.
So as you can see the game has changed again. The above was observed back in April and May, research continues. Thanks to William for doing the research and allowing me to edit and publish the diary.
Mark H



More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Yatzy Twist 1.0 Gamer Games Feed 0 06-26-2008 19:00
Word Twist 1.0 Gamer Games Feed 0 04-28-2008 18:40
Art with a Mathematical Twist Steve General Technology News 0 02-19-2008 19:50
Article ID: 939536 Read operations or write operations on a floppy disk may be faster when you use an earlier Microsoft operating system than when you use a newer Microsoft operating system KBArticles English 0 10-22-2007 20:00
Vista Ultimate x64 Will Not Enter Sleep Mode but will Enter Hibern reductant microsoft.public.windows.vista.general 4 05-07-2007 10:41


All times are GMT +1. The time now is 11:28.


CA Desktop DNA Migrator 2008

Spam Filter for Outlook and Outlook Express

Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119