50
Deanonymization and total espionage Dmitry «Bo0oM» Boomov

Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

  • Upload
    -

  • View
    13.686

  • Download
    2

Embed Size (px)

DESCRIPTION

This talk is dedicated to de-anonymizing active Internet users. We will give a hands-on demonstration of various Internet resources tracking and/or storing user data, and explain how this data can be used to find out the identity on the other side of the screen for your own (either good or evil) purposes. Доклад посвящен деанонимизации активных пользователей интернета. На практике будет показано, как различные интернет-ресурсы следят или содержат информацию о пользователях и как ее можно использовать, чтобы вычислить, кто находится по ту сторону монитора для собственных (как плохих, так и хороших) нужд.

Citation preview

Page 1: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Deanonymization and total espionage

Dmitry «Bo0oM» Boomov

Page 2: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Tits and

kittens.

Hopefully, now

you like my

report.

Page 3: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Deanonymization

Passive Active

Page 4: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Password retrieval

Page 5: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Password retrieval

Page 6: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Getting information from email

Page 7: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Getting information from email

Page 8: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Getting information from email

Page 9: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Getting information from phone. Viber

Page 10: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Getting information from phone. Whatsapp

Page 11: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Getting information from phone. Banks

Page 12: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Getting information from phone. Banks

Page 13: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Getting information from phone

Page 14: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Getting information from phone

http://numbuster.com/

Page 15: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Find friends

Page 16: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

← Anonist

Page 17: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Apps

https://developers.facebook.com/

Page 18: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Apps

https://vk.com/editapp?act=create

Page 19: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Apps

Demo: bo0om.ru/zn2014/vk/1/

Page 20: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Online users

https://letters.yandex.ru/promo

Page 21: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Clickjacking

Page 22: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Clickjacking

Demo: bo0om.ru/zn2014/vk/2/

Page 23: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Clickjacking

Demo: bo0om.ru/zn2014/vk/3/

Page 24: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

CSRF + XSS + BUGS = PROFIT

Page 25: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Click, click…

Page 26: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Click, click…

<a href='tel://1234567890'>Click me</a>

Page 27: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Callback

Page 28: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Callback

Thx @black2fan ;)

Page 29: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Social detector

Demo: bo0om.ru/zn2014/sd/

Page 30: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Вate of birth

Page 31: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Nicknames

Page 32: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Nicknames

Page 33: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Friends and relatives

Page 34: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Friends and relatives

Page 35: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Friends and relatives

Page 36: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Tinfoleak

http://vicenteaguileradiaz.com/tools/

Page 37: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Exif

Page 38: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Analytics

Page 39: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Analytics

Page 40: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)
Page 41: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Banners

Page 42: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Social buttons

Page 43: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

BIG DATA

http://bo0om.ru/zn2014/wtf/

Page 44: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

GEO

https://maps.google.com/locationhistory/

Page 45: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Cookie Matching

Specifically, when creating a new cookie, it uses the following storage mechanisms when available:

- Standard HTTP Cookies - Local Shared Objects (Flash Cookies)- Silverlight Isolated Storage - Storing cookies in RGB values of auto-generated, force-cached PNGs using HTML5 Canvas tag to read pixels (cookies) back out- Storing cookies in Web History - Storing cookies in HTTP ETags - Storing cookies in Web cache - window.name caching

- Internet Explorer userData storage- HTML5 Session Storage - HTML5 Local Storage - HTML5 Global Storage - HTML5 Database Storage via SQLite- HTML5 IndexedDB

- Java JNLP PersistenceService- Java CVE-2013-0422 exploit (applet sandbox escaping)

http://samy.pl/evercookie/

Page 46: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Js: onflash: on

Js: onflash: on

Js: onflash: on

Js: onflash: on

Js: onflash: on

Js: onflash: on

Js: offflash: off

Page 47: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Providers

http://imarker.ru/

Page 48: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Evil

Page 49: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)
Page 50: Bo0oM - Deanonymization and total espionage (ZeroNights, 2014)

Twi: @i_bo0om