The BruCO"NSA" Network

Preview:

DESCRIPTION

This is the lightning talk presented by @xme and @senseizeon at BruCON 0x05 about the deployed network.

Citation preview

The BruCO”NSA”Network

“How we take care of your packets”

Topology

• Radio P2P Link to theInternet

• Public VLAN

• Private VLAN (Crew,Speaker, Apps)

Topology

Our C&C

Numbers• 100 MBits up/down

• 11 AP’s

• 5 switches

• 60.303.633 packets captured yesterday

• Peak up to 65 Mbits/s

• Since BruCON 0x01, ~1 KM of CAT-5 cables

• ...a lot of Clubmate and 0xC0FFEE

Visibility“A network is like milk on a stove, you need to keep

an eye on it all the time”

Visibility

Fun VS. Legal

• BruCON is considered as an ISP from the .be law point of view

• We keep:MAC|Timestamp|SrcIP|SrcPort|DstIP|DstPort

• “Due diligence” principle

Wall of Sheep

Wall of Sheep

• 25 unique passwords sniffed (up to now!)

• Avg length: 6.8 characters

Protocols Countssnmp 2034http 82ftp 27pop 17

Malware Tracking

All your packets are belong to us...

Thank You!

Recommended