<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>binpoint.com &#187; My Ideas</title>
	<atom:link href="http://binpoint.com/category/ideas/feed/" rel="self" type="application/rss+xml" />
	<link>http://binpoint.com</link>
	<description>A Security Blog (Stirred with Geek Life)</description>
	<lastBuildDate>Wed, 09 Jun 2010 02:02:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Minority Report Computer is Real</title>
		<link>http://binpoint.com/2008/11/minority-report-computer-is-real/</link>
		<comments>http://binpoint.com/2008/11/minority-report-computer-is-real/#comments</comments>
		<pubDate>Tue, 18 Nov 2008 08:28:42 +0000</pubDate>
		<dc:creator>tom</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[My Ideas]]></category>
		<category><![CDATA[Gestures]]></category>
		<category><![CDATA[Huge ass monitors]]></category>
		<category><![CDATA[Minority Report]]></category>

		<guid isPermaLink="false">http://binpoint.com/?p=110</guid>
		<description><![CDATA[No really. Watch here. Now they just need to finish up Jarvis from the Iron Man movie and we&#8217;re all set for RL to become obsolete. Related posts:Computer Security At Hotels Real Cost of Apple iPad vs Amazon Kindle 2 User Interfaces In Film, and the Man Who Designs Them


Related posts:<ol><li><a href='http://binpoint.com/2009/03/computer-security-at-hotels/' rel='bookmark' title='Permanent Link: Computer Security At Hotels'>Computer Security At Hotels</a></li>
<li><a href='http://binpoint.com/2010/01/real-cost-of-apple-ipad-vs-amazon-kindle-2/' rel='bookmark' title='Permanent Link: Real Cost of Apple iPad vs Amazon Kindle 2'>Real Cost of Apple iPad vs Amazon Kindle 2</a></li>
<li><a href='http://binpoint.com/2009/12/user-interfaces-in-film-and-the-man-who-designs-them/' rel='bookmark' title='Permanent Link: User Interfaces In Film, and the Man Who Designs Them'>User Interfaces In Film, and the Man Who Designs Them</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><a href="http://binpoint.com/wp-content/uploads/2008/11/minority-report-ui.jpg"><img class="alignnone size-medium wp-image-111" title="minority-report-ui" src="http://binpoint.com/wp-content/uploads/2008/11/minority-report-ui-300x200.jpg" alt="" width="300" height="200" /></a></p>
<p>No really. <a href="http://oblong.com/">Watch here</a>.</p>
<p>Now they just need to finish up Jarvis from the Iron Man movie and we&#8217;re all set for RL to become obsolete.</p>


<p>Related posts:<ol><li><a href='http://binpoint.com/2009/03/computer-security-at-hotels/' rel='bookmark' title='Permanent Link: Computer Security At Hotels'>Computer Security At Hotels</a></li>
<li><a href='http://binpoint.com/2010/01/real-cost-of-apple-ipad-vs-amazon-kindle-2/' rel='bookmark' title='Permanent Link: Real Cost of Apple iPad vs Amazon Kindle 2'>Real Cost of Apple iPad vs Amazon Kindle 2</a></li>
<li><a href='http://binpoint.com/2009/12/user-interfaces-in-film-and-the-man-who-designs-them/' rel='bookmark' title='Permanent Link: User Interfaces In Film, and the Man Who Designs Them'>User Interfaces In Film, and the Man Who Designs Them</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://binpoint.com/2008/11/minority-report-computer-is-real/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Thousands of Sacrificial Lambs</title>
		<link>http://binpoint.com/2008/06/thousands-of-sacrificial-lambs/</link>
		<comments>http://binpoint.com/2008/06/thousands-of-sacrificial-lambs/#comments</comments>
		<pubDate>Thu, 26 Jun 2008 17:41:29 +0000</pubDate>
		<dc:creator>tom</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[My Ideas]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[Silly]]></category>
		<category><![CDATA[virtual machine]]></category>

		<guid isPermaLink="false">http://binpoint.com/?p=22</guid>
		<description><![CDATA[Problem: So you say &#8216;hackers&#8217; are constantly knocking on the perimeter door to your network. You claim that they are trying to &#8216;map&#8217; your network. You insist that they will cherry pick targets based on fingerprint data, wins/dns name, or other factors. Proposition: Fill up a virtual machine host with hundreds to thousands of fake [...]


Related posts:<ol><li><a href='http://binpoint.com/2010/04/network-scanning-with-nmap/' rel='bookmark' title='Permanent Link: Network Scanning with nmap'>Network Scanning with nmap</a></li>
<li><a href='http://binpoint.com/2008/06/writing-a-dns-sniffer/' rel='bookmark' title='Permanent Link: Writing a DNS sniffer'>Writing a DNS sniffer</a></li>
<li><a href='http://binpoint.com/2009/03/computer-security-at-hotels/' rel='bookmark' title='Permanent Link: Computer Security At Hotels'>Computer Security At Hotels</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Problem:</p>
<ul>
<li>So you say &#8216;hackers&#8217; are constantly knocking on the perimeter door to your network.</li>
</ul>
<ul>
<li>You claim that they are trying to &#8216;map&#8217; your network.</li>
</ul>
<ul>
<li>You insist that they will cherry pick targets based on fingerprint data, wins/dns name, or other factors.</li>
</ul>
<p>Proposition:</p>
<ul>
<li>Fill up a virtual machine host with hundreds to thousands of fake hosts that each have random fingerprint appearance and different name. They don&#8217;t need to do anything except listen on a few ports (on a set of believable ports, to mimic a real OS), and maybe send a fake packet or two around (you know, like M$ boxes like to do because they get lonely.) A full blown app like <a href="http://www.vmware.com">vmware</a> is overkill for this purpose. A perl script on five tiny embedded systems would suffice.</li>
</ul>
<p>Just think of the possibilities.</p>
<ol>
<li>Each would dilute any reconnaissance tool with bogus hosts</li>
<li>Each is indistinguishable from real hosts without attempting to check the function of each service for each address.</li>
<li>Each could also be setup to send alerts to your InfoSec dept when anyone attempts to connect to them; (only two categories of connectors: 1) misconfigured friendlies, and 2) bad guys.)</li>
<li>Every second the scanner spends poking around in these fake hosts, your real ones aren&#8217;t touched.</li>
<li>You can brag about how many &#8216;hosts&#8217; are on the network you manage.</li>
<li>If &#8216;fancy&#8217; is your middle name, you could write a script that would forward connection attempts to a honeypot and attempt to grab a fresh piece of badware.</li>
</ol>
<p>Thoughts?</p>
<p>P.S. I admit I partly stole this idea from Tom Liston&#8217;s <a href="http://labrea.sourceforge.net/">LaBrea tarpit</a>.</p>


<p>Related posts:<ol><li><a href='http://binpoint.com/2010/04/network-scanning-with-nmap/' rel='bookmark' title='Permanent Link: Network Scanning with nmap'>Network Scanning with nmap</a></li>
<li><a href='http://binpoint.com/2008/06/writing-a-dns-sniffer/' rel='bookmark' title='Permanent Link: Writing a DNS sniffer'>Writing a DNS sniffer</a></li>
<li><a href='http://binpoint.com/2009/03/computer-security-at-hotels/' rel='bookmark' title='Permanent Link: Computer Security At Hotels'>Computer Security At Hotels</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://binpoint.com/2008/06/thousands-of-sacrificial-lambs/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Why freeways should be conveyor belts</title>
		<link>http://binpoint.com/2008/06/why-freeways-should-be-conveyor-belts/</link>
		<comments>http://binpoint.com/2008/06/why-freeways-should-be-conveyor-belts/#comments</comments>
		<pubDate>Wed, 25 Jun 2008 22:53:35 +0000</pubDate>
		<dc:creator>tom</dc:creator>
				<category><![CDATA[My Ideas]]></category>
		<category><![CDATA[Silly]]></category>
		<category><![CDATA[car]]></category>
		<category><![CDATA[commute]]></category>
		<category><![CDATA[idea]]></category>

		<guid isPermaLink="false">http://binpoint.com/?p=50</guid>
		<description><![CDATA[I drive a pretty sizable distance every day to commute to work. I drive on a freeway most of the distance. Freeways were poorly named. Congested freeways are anything but free of cars. They house traffic &#8216;trends&#8217; such as &#8216;packs&#8217; or &#8216;squadrons&#8217; as well as &#8216;stop and go&#8217; sections or often just convenient &#8216;parking lot&#8217; [...]


Related posts:<ol><li><a href='http://binpoint.com/2008/06/writing-a-dns-sniffer/' rel='bookmark' title='Permanent Link: Writing a DNS sniffer'>Writing a DNS sniffer</a></li>
<li><a href='http://binpoint.com/2008/07/alltop/' rel='bookmark' title='Permanent Link: alltop'>alltop</a></li>
<li><a href='http://binpoint.com/2008/06/detectin-bad-tcp-sessions/' rel='bookmark' title='Permanent Link: Detecting bad TCP sessions'>Detecting bad TCP sessions</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft size-full wp-image-51" title="car-belt-freeway" src="http://binpoint.com/wp-content/uploads/2008/06/car-belt-freeway.png" alt="" width="400" height="300" /></p>
<p>I drive a pretty sizable distance every day to commute to work. I drive on a freeway most of the distance.</p>
<p>Freeways were poorly named. Congested freeways are anything but free of cars. They house traffic &#8216;trends&#8217; such as &#8216;packs&#8217; or &#8216;squadrons&#8217; as well as &#8216;stop and go&#8217; sections or often just convenient &#8216;parking lot&#8217; areas while you attempt to get home before dark.<br />
In an attempt to optimize this sad state of affairs affecting those of us in urban life, I have come up with the solution (which as I&#8217;m sure you&#8217;ve guessed by now since you read the title) is that all freeways should be replaced with conveyor belts.</p>
<p>Now, I don&#8217;t mean the rubber &amp; pulley wheel variety, I have in mind something more like the catapult system found on the flight decks of American super carriers. It seems so simple it just may work!</p>
<p>Each car would hook up to one of these at speed and &#8220;lock in&#8221; to a spot on the freeway &#8216;belt.&#8217; That way, the belt is always moving at a constant speed, no one is able to weave in and out of lanes, it&#8217;s impossible to have a fender bender, people can&#8217;t use the margins on the side of the road as &#8216;temp passing lanes,&#8217; maximum fuel efficiency for all cars is enforced and no one can speed!</p>
<p>It&#8217;s a perfect solution! I just solved the top 5 highway issues with one ginormously expensive and implausible invention that everyone would hate.</p>
<p>I dare you to poke holes in my logic&#8230;</p>


<p>Related posts:<ol><li><a href='http://binpoint.com/2008/06/writing-a-dns-sniffer/' rel='bookmark' title='Permanent Link: Writing a DNS sniffer'>Writing a DNS sniffer</a></li>
<li><a href='http://binpoint.com/2008/07/alltop/' rel='bookmark' title='Permanent Link: alltop'>alltop</a></li>
<li><a href='http://binpoint.com/2008/06/detectin-bad-tcp-sessions/' rel='bookmark' title='Permanent Link: Detecting bad TCP sessions'>Detecting bad TCP sessions</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://binpoint.com/2008/06/why-freeways-should-be-conveyor-belts/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Writing a DNS sniffer</title>
		<link>http://binpoint.com/2008/06/writing-a-dns-sniffer/</link>
		<comments>http://binpoint.com/2008/06/writing-a-dns-sniffer/#comments</comments>
		<pubDate>Tue, 24 Jun 2008 23:37:50 +0000</pubDate>
		<dc:creator>tom</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[My Ideas]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[libpcap]]></category>
		<category><![CDATA[sniffer]]></category>

		<guid isPermaLink="false">http://binpoint.com/?p=42</guid>
		<description><![CDATA[Programming project: construct a program that can listen to perimeter traffic and construct http proxy-like logs. The weapon of choice? libpcap! The app will need to listen for both DNS (udp port 53) and HTTP (tcp port 80) traffic to accomplish this. First up is determining where all the interesting bits in each layer of [...]


Related posts:<ol><li><a href='http://binpoint.com/2008/06/thousands-of-sacrificial-lambs/' rel='bookmark' title='Permanent Link: Thousands of Sacrificial Lambs'>Thousands of Sacrificial Lambs</a></li>
<li><a href='http://binpoint.com/2010/04/network-scanning-with-nmap/' rel='bookmark' title='Permanent Link: Network Scanning with nmap'>Network Scanning with nmap</a></li>
<li><a href='http://binpoint.com/2008/06/detectin-bad-tcp-sessions/' rel='bookmark' title='Permanent Link: Detecting bad TCP sessions'>Detecting bad TCP sessions</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Programming project: construct a program that can listen to perimeter traffic and construct http proxy-like logs. The weapon of choice? <a href="http://www.tcpdump.org/">libpcap</a>! The app will need to listen for both DNS (udp port 53) and HTTP (tcp port 80) traffic to accomplish this.</p>
<p>First up is determining where all the interesting bits in each layer of the OSI stack are located within each packet. In logical order:</p>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Ethernet#Ethernet_frame_types_and_the_EtherType_field">Ethernet Headers &amp; Packet Structure</a></li>
</ul>
<ul>
<li><a href="http://en.wikipedia.org/wiki/IPv4#Packet_structure">IP Headers &amp; Packet Structure</a></li>
</ul>
<ul>
<li><a href="http://en.wikipedia.org/wiki/User_Datagram_Protocol#Packet_structure">UDP Headers &amp; Packet Structure</a></li>
</ul>
<ul>
<li><a href="http://en.wikipedia.org/wiki/Domain_Name_System#Types_of_DNS_records">DNS Records</a> and <a href="http://www.faqs.org/rfcs/rfc1035.html">DNS Headers</a> (about half way down)</li>
</ul>
<p><img class="size-medium wp-image-43" title="tcpdump-source" src="http://binpoint.com/wp-content/uploads/2008/06/tcpdump-source-300x170.png" alt="" width="300" height="170" /></p>
<p>With all that reference material, you might think this is a lot of reading! Okay, fine how about a copy and paste job? <a href="http://sourceforge.net/projects/tcpdump/">Tcpdump</a> is the perfect place to exercise your mouse wheel click skillz to get all the data structures and defines you&#8217;ll need.</p>
<p><img class="alignnone size-medium wp-image-44" title="wireshark" src="http://binpoint.com/wp-content/uploads/2008/06/wireshark.png" alt="" width="232" height="177" /></p>
<p>One last useful tool that should be in every network programmers tool belt is of course, Wiershark (aka ethereal). In this case, it comes in handy to double check your program is disassembling the packets the same as Wireshark.</p>
<p>A BPF is used to speed up the filtering of interesting packets from useless ones and is passed in to the program as follows:</p>
<blockquote><p>dns_sniffer &#8220;udp port 53&#8243;</p></blockquote>
<p>When writing any network aware application, the best place to start for documentation is always going to be the <a href="http://www.faqs.org/rfcs/rfc1035.html">applicable RFC</a> for whatever protocol you plan to speak.</p>
<p>When figuring out what bitmasks were needed to mask out specific bits (namely the first two bits for parsing DNS compression) <a href="http://www.ascii.cl/conversion.htm">Conversion Table</a> came in handy. I also found this <a href="http://www.cprogramming.com/tutorial/bitwise_operators.html">handy page</a> if you need to brush up on bitwise operations (I sure did, since I hardly use them.) And don&#8217;t forget your <a href="http://www.asciitable.com/">ASCII-Table</a>!</p>
<p>Have you ever wondered how your lonely little-endian wintel laptop / desktop is able to communicate over the same IP network to a big-endian speaking SPARC system? It certainly kept me up at night! See for yourself <a href="http://beej.us/guide/bgnet/output/html/multipage/htonsman.html">how it is able to work</a>.</p>
<p>More to follow&#8230; (you know, like source code)</p>


<p>Related posts:<ol><li><a href='http://binpoint.com/2008/06/thousands-of-sacrificial-lambs/' rel='bookmark' title='Permanent Link: Thousands of Sacrificial Lambs'>Thousands of Sacrificial Lambs</a></li>
<li><a href='http://binpoint.com/2010/04/network-scanning-with-nmap/' rel='bookmark' title='Permanent Link: Network Scanning with nmap'>Network Scanning with nmap</a></li>
<li><a href='http://binpoint.com/2008/06/detectin-bad-tcp-sessions/' rel='bookmark' title='Permanent Link: Detecting bad TCP sessions'>Detecting bad TCP sessions</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://binpoint.com/2008/06/writing-a-dns-sniffer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Detecting bad TCP sessions</title>
		<link>http://binpoint.com/2008/06/detectin-bad-tcp-sessions/</link>
		<comments>http://binpoint.com/2008/06/detectin-bad-tcp-sessions/#comments</comments>
		<pubDate>Fri, 13 Jun 2008 05:03:44 +0000</pubDate>
		<dc:creator>tom</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[My Ideas]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[bad]]></category>
		<category><![CDATA[idea]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[tcp]]></category>
		<category><![CDATA[traffic]]></category>

		<guid isPermaLink="false">http://binpoint.com/?p=25</guid>
		<description><![CDATA[Here&#8217;s an idea: Why not develop a feature into personal firewalls that tracks active tcp sessions (via netstat) but with some intelligence. The idea behind intelligence is to not spam the poor user every single time an application wants to talk on the NIC. How would that work? Well, it could associate keystrokes / clicks [...]


Related posts:<ol><li><a href='http://binpoint.com/2008/06/writing-a-dns-sniffer/' rel='bookmark' title='Permanent Link: Writing a DNS sniffer'>Writing a DNS sniffer</a></li>
<li><a href='http://binpoint.com/2010/04/network-scanning-with-nmap/' rel='bookmark' title='Permanent Link: Network Scanning with nmap'>Network Scanning with nmap</a></li>
<li><a href='http://binpoint.com/2008/06/thousands-of-sacrificial-lambs/' rel='bookmark' title='Permanent Link: Thousands of Sacrificial Lambs'>Thousands of Sacrificial Lambs</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s an idea:</p>
<p>Why not develop a feature into personal firewalls that tracks active tcp sessions (via netstat) but with some intelligence. The idea behind intelligence is to not spam the poor user every single time an application wants to talk on the NIC. How would that work?</p>
<p>Well, it could associate keystrokes / clicks with network events. If there is a new tcp session established or new listening local port, challenge the user with the application name associated with said session or listening port.</p>
<p>It sounds so simple it just might work. Do you see any false-positive scenarios?</p>


<p>Related posts:<ol><li><a href='http://binpoint.com/2008/06/writing-a-dns-sniffer/' rel='bookmark' title='Permanent Link: Writing a DNS sniffer'>Writing a DNS sniffer</a></li>
<li><a href='http://binpoint.com/2010/04/network-scanning-with-nmap/' rel='bookmark' title='Permanent Link: Network Scanning with nmap'>Network Scanning with nmap</a></li>
<li><a href='http://binpoint.com/2008/06/thousands-of-sacrificial-lambs/' rel='bookmark' title='Permanent Link: Thousands of Sacrificial Lambs'>Thousands of Sacrificial Lambs</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://binpoint.com/2008/06/detectin-bad-tcp-sessions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hello Earth!</title>
		<link>http://binpoint.com/2008/05/hello-earth/</link>
		<comments>http://binpoint.com/2008/05/hello-earth/#comments</comments>
		<pubDate>Sun, 04 May 2008 09:12:52 +0000</pubDate>
		<dc:creator>tom</dc:creator>
				<category><![CDATA[My Ideas]]></category>
		<category><![CDATA[hello world]]></category>
		<category><![CDATA[new]]></category>

		<guid isPermaLink="false">http://binpoint.com/?p=4</guid>
		<description><![CDATA[In true compsci tradition, all technical writings start with the now detested &#8220;Hello World&#8221; example. Related posts:User Interfaces In Film, and the Man Who Designs Them


Related posts:<ol><li><a href='http://binpoint.com/2009/12/user-interfaces-in-film-and-the-man-who-designs-them/' rel='bookmark' title='Permanent Link: User Interfaces In Film, and the Man Who Designs Them'>User Interfaces In Film, and the Man Who Designs Them</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>In true compsci tradition, all technical writings start with the now detested &#8220;<a title="ha ha" href="http://lists.freebsd.org/pipermail/freebsd-chat/2004-March/002208.html">Hello World</a>&#8221; example.</p>
<pre></pre>


<p>Related posts:<ol><li><a href='http://binpoint.com/2009/12/user-interfaces-in-film-and-the-man-who-designs-them/' rel='bookmark' title='Permanent Link: User Interfaces In Film, and the Man Who Designs Them'>User Interfaces In Film, and the Man Who Designs Them</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://binpoint.com/2008/05/hello-earth/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
