SniffJoke in progress, 0.4.2 to 0.5

SniffJoke at the moment has been stabilized in the 0.4.2 release, some requirements and issue had become clear in the last months.

The first overall: require testing on the road. IDS may not so vulnerable, but sniffers surely are. simply, is difficult found someone with a law enforce sniffer that want collaborate in order to defeat him technology. At the CCC maybe I shall print out an A4 physical spam.

Portability: evilaliv3 has started a symbiotic project: Janus, in SniffJoke framework will supply all privileged operations, restrict the portability issue, and be a simple C software easy to be ported under every 4.4BSD and POSIX O.S.. With Janus, SniffJoke will run as an unprivileged single process.

Stability: IP/TCP options abuse shall not be tested only with a single destination, like sj-iptcpopt-probe (on behalf of sniffjoke-autotest) actually does. A new class is under development and will solve this issue, beside enlarge the amount of “scramble” available.

The available package for the GNU distributions with Linux kernel, are gentoo, RPM, .deb (tested under ubuntu, debian, backtrack).

Security analysis: July 2011, rfc6274.txt Security Assessment on IPv4. Require some detailed reading, also because point to an IDS improvement to avoid evasions.

Additionally, this document analyzes the security implications from
changes in the operational environment since the Internet Protocol
was designed.  For example, it analyzes how the Internet Protocol
could be exploited to evade Network Intrusion Detection Systems
(NIDSs) or to circumvent firewalls.

 

About vecna

Claudio Agosti (I, in this section) is currently working in some projects involving: steganography, anonymity, deep level networking, voip and mobile network security and online human right protection. Mix well, put a sprinkle of anti-forensic, serve cold. The worst issue in those really cool projects is that no one is financing me, thus sometime I need to work. Jobs actually include developing and few security issue to manage. Dreams ? A world where everyone has N-pseudonyms, certified by web of trust security model. I'm not "security certified" except lifeguard, I'm bored by penetration testing, and my future is painted with javascript. keywords: vecna, s0ftpj, sniffjoke, globaleaks, winston smith project, elettra.
This entry was posted in english, sniffjoke and tagged . Bookmark the permalink.

Leave a Reply

Your email address will not be published.

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>