LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-08-2012, 11:53 PM   #1
expcodersrrg
LQ Newbie
 
Registered: Aug 2012
Posts: 9

Rep: Reputation: Disabled
Akamai Issue, undesired connections, speed down, ...


Amazing Akamai Issue have a really smart technology to jump firewall restriction. I have make a white list for may firewall it mean nothing get out. This solution stop Akamai for some days, but now it is connected again jumping the firewall white list. Akamai install a new process server on my computer and send info to Akamai server using different ip to my computer assigned ip to jump firewall. Akamai Issue have a proved advanced technologies to jump firewall.
I will try upload image proves

More references:
http://www.matveev.se/net/akamai.htm

http://www.linuxquestions.org/questi...laints-831481/

http://ubuntuforums.org/showthread.p...ghlight=akamai


//Images as posted in http://ubuntuforums.org/showthread.php?t=2039515:
http://ubuntuforums.org/attachment.p...1&d=1344490930
http://ubuntuforums.org/attachment.p...2&d=1344490930
http://ubuntuforums.org/attachment.p...3&d=1344490930

Last edited by unSpawn; 08-10-2012 at 03:02 PM. Reason: //Add image links from other forum post
 
Old 08-10-2012, 03:56 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
See what AS Number the IP address is in and black list the, in this case 2 C class, networks? Note black listing whole ASN's may prevent other sites or applications using .deploy.akamaitechnologies.com from working properly so maybe white listing allowed addresses may be more efficient and less restrictive. Blocking AS Numbers here doesn't automagically mean blocking in the firewall (and if you do don't put it in the filter table INPUT chain as matveev.se suggests but use an OUTPUT chain NEW state filter as it's your machine that requests the connection) but it probably could be done way more efficient using a persistent-caching local name server like Pdnsd, again because it's your machine that has to resolve the host name before making any requests. As this isn't a Linux Security question I'll move this thread to the Linux Networking forum.
 
Old 08-10-2012, 05:45 PM   #3
expcodersrrg
LQ Newbie
 
Registered: Aug 2012
Posts: 9

Original Poster
Rep: Reputation: Disabled
Akamai servers are also used by faceboock, gnome-pannel and a lot of other common used app. Clouds services tend to be confused with intrusions often, for example my gnome-pannel try to use akamai clouds to get weather info. Also I have verify, a normal behavior in clouds is asap as it receive a request, try to find open ports in host, reverse dns.

It works at this way:

gnome-panel weather software or other akamai based softwares try connect to clouds jumping firewall if possible asap as connection to Internet detected on system. Then cloud akamai services detect host requests, call dns-rollback and begin try open connection from akamai to host searching open ports in ranges not commonly used 452620 … 452670 for example. This is a normal pattern in cloud services, I have see the same in other cloud services. But this patter is the same as a Trojan intrusion.

In my case I don't care what they see or monitor, but slow down the Internet speed with unrequested connections.

---------- Post added 08-10-12 at 06:46 PM ----------

For example one of there gnome-panel weather software:

Tcpdump >>>

0x0000: 0000 0200 0000 0000 0000 0000 0000 0800 ................
0x0010: 4500 01b7 4250 0000 3a11 76a9 c837 8003 E...BP..:.v..7..
0x0020: c837 b5ca 0035 a983 01a3 70ed 94c9 8180 .7...5....p.....
0x0030: 0001 0004 0008 0008 0777 6561 7468 6572 .........weather
0x0040: 046e 6f61 6103 676f 7600 0001 0001 c00c .noaa.gov.......
0x0050: 0005 0001 0000 0384 0020 0777 6561 7468 ...........weath
0x0060: 6572 046e 6f61 6103 676f 7609 6564 6765 er.noaa.gov.edge
0x0070: 7375 6974 6503 6e65 7400 c02e 0005 0001 suite.net.......
0x0080: 0000 3735 0011 0561 3137 3131 0167 0661 ..75...a1711.g.a
0x0090: 6b61 6d61 69c0 49c0 5a00 0100 0100 0000 kamai.I.Z.......
0x00a0: 1400 0417 43f3 19c0 5a00 0100 0100 0000 ....C...Z.......
0x00b0: 1400 0417 43f3 12c0 6000 0200 0100 002f ....C...`....../
0x00c0: 2f00 0603 6e30 67c0 62c0 6000 0200 0100 /...n0g.b.`.....
0x00d0: 002f 2f00 0603 6e36 67c0 62c0 6000 0200 .//...n6g.b.`...
0x00e0: 0100 002f 2f00 0603 6e33 67c0 62c0 6000 ...//...n3g.b.`.
0x00f0: 0200 0100 002f 2f00 0603 6e34 67c0 62c0 .....//...n4g.b.
0x0100: 6000 0200 0100 002f 2f00 0603 6e32 67c0 `......//...n2g.
0x0110: 62c0 6000 0200 0100 002f 2f00 0603 6e35 b.`......//...n5
0x0120: 67c0 62c0 6000 0200 0100 002f 2f00 0603 g.b.`......//...
0x0130: 6e37 67c0 62c0 6000 0200 0100 002f 2f00 n7g.b.`......//.
0x0140: 0603 6e31 67c0 62c0 cd00 0100 0100 0006 ..n1g.b.........
0x0150: ff00 04cc 02f1 acc0 bb00 0100 0100 0031 ...............1
0x0160: 3200 04cc 02f1 adc0 9700 0100 0100 0031 2..............1
0x0170: 3200 04c8 3e2c 23c0 f100 0100 0100 0085 2...>,#.........
0x0180: 8e00 04cc 02f1 aec0 df00 0100 0100 0085 ................
0x0190: 8e00 04c1 6c58 c3c1 0300 0100 0100 0006 ....lX..........
0x01a0: ff00 04cc 02f1 a5c0 a900 0100 0100 0031 ...............1
0x01b0: 3200 04cc 02f1 aec1 1500 0100 0100 0006 2...............
0x01c0: ff00 04cc 02f1 af .......



0x0000: 0000 0200 0000 0000 0000 0000 0000 0800 ................
0x0010: 4500 01b7 e113 0000 3a11 d7e5 c837 8003 E.......:....7..
0x0020: c837 b5ca 0035 828e 01a3 1b20 118c 8180 .7...5..........
0x0030: 0001 0004 0008 0008 0777 6561 7468 6572 .........weather
0x0040: 046e 6f61 6103 676f 7600 0001 0001 c00c .noaa.gov.......
0x0050: 0005 0001 0000 0384 0020 0777 6561 7468 ...........weath
0x0060: 6572 046e 6f61 6103 676f 7609 6564 6765 er.noaa.gov.edge
0x0070: 7375 6974 6503 6e65 7400 c02e 0005 0001 suite.net.......
0x0080: 0000 3735 0011 0561 3137 3131 0167 0661 ..75...a1711.g.a
0x0090: 6b61 6d61 69c0 49c0 5a00 0100 0100 0000 kamai.I.Z.......
0x00a0: 1400 0417 43f3 19c0 5a00 0100 0100 0000 ....C...Z.......
0x00b0: 1400 0417 43f3 12c0 6000 0200 0100 002f ....C...`....../
0x00c0: 2f00 0603 6e35 67c0 62c0 6000 0200 0100 /...n5g.b.`.....
0x00d0: 002f 2f00 0603 6e31 67c0 62c0 6000 0200 .//...n1g.b.`...
0x00e0: 0100 002f 2f00 0603 6e32 67c0 62c0 6000 ...//...n2g.b.`.
0x00f0: 0200 0100 002f 2f00 0603 6e30 67c0 62c0 .....//...n0g.b.
0x0100: 6000 0200 0100 002f 2f00 0603 6e33 67c0 `......//...n3g.
0x0110: 62c0 6000 0200 0100 002f 2f00 0603 6e36 b.`......//...n6
0x0120: 67c0 62c0 6000 0200 0100 002f 2f00 0603 g.b.`......//...
0x0130: 6e37 67c0 62c0 6000 0200 0100 002f 2f00 n7g.b.`......//.
0x0140: 0603 6e34 67c0 62c1 1500 0100 0100 0006 ..n4g.b.........
0x0150: ff00 04cc 02f1 acc0 df00 0100 0100 0031 ...............1
0x0160: 3200 04cc 02f1 adc0 cd00 0100 0100 0031 2..............1
0x0170: 3200 04c8 3e2c 23c0 9700 0100 0100 0085 2...>,#.........
0x0180: 8e00 04cc 02f1 aec0 bb00 0100 0100 0085 ................
0x0190: 8e00 04c1 6c58 c3c1 0300 0100 0100 0006 ....lX..........
0x01a0: ff00 04cc 02f1 a5c0 f100 0100 0100 0031 ...............1
0x01b0: 3200 04cc 02f1 aec0 a900 0100 0100 0006 2...............
0x01c0: ff00 04cc 02f1 af .......
 
Old 08-10-2012, 08:10 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Instead of posting that kind of explanation of things (Akamai first and foremost is known for CDN and not "cloud akamai services" and I've never heard of "dns-rollback") and ASCII representations of traffic (nobody who analyzes pcaps reads it in this way) please host a packet capture we can download that supports what you say. If you need to obfuscate your machines public IP address see tcprewrite.
 
Old 08-10-2012, 09:12 PM   #5
expcodersrrg
LQ Newbie
 
Registered: Aug 2012
Posts: 9

Original Poster
Rep: Reputation: Disabled
sorry for my explanations, it is not dns-rollback is some type of web usually called dns-reverse or some similar I do not remember the exact name. I think clouds can use this to select most near and fast speed available to customer PC.
 
Old 08-10-2012, 09:18 PM   #6
expcodersrrg
LQ Newbie
 
Registered: Aug 2012
Posts: 9

Original Poster
Rep: Reputation: Disabled
Anyone know a good firewall with rules per softwares application in ubuntu?

This way I can allow only firefox connect to internet and solve the issue. I know windows have this by default since XP.

---------- Post added 08-10-12 at 10:18 PM ----------

Anyone know a good firewall with rules per softwares application in ubuntu?

This way I can allow only firefox connect to internet and solve the issue. I know windows have this by default since XP.
 
Old 08-10-2012, 09:50 PM   #7
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Before you talk about firewall circumvention, comparing Content Delivery Network traffic with "Trojan intrusions" or misinterpreting what CDN does as "unrequested connections", maybe you should first find out how a Content Delivery Network actually works?..
 
Old 08-10-2012, 10:31 PM   #8
expcodersrrg
LQ Newbie
 
Registered: Aug 2012
Posts: 9

Original Poster
Rep: Reputation: Disabled
ok think this, how you difference someone using CDN for his Trojans or a not risk apps like Facebook?

I have read other people reporting similar situations in the web.

Anyway in my case I only what speed up Internet, using a firewall to block undesired software apps.
 
Old 08-11-2012, 04:45 AM   #9
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by expcodersrrg View Post
I only what speed up Internet
Blocking (groups of) addresses from being resolved, persistently caching DNS queries, limiting the maximum amount of new outbound connections, limiting the maximum amount of connections per class network, lowering network related sysctls and caching page contents may help.


Quote:
Originally Posted by expcodersrrg View Post
using a firewall to block
I already answered that.


Quote:
Originally Posted by expcodersrrg View Post
undesired software apps.
If you think applications are "undesired" then simply don't run them.
 
Old 08-11-2012, 05:50 AM   #10
expcodersrrg
LQ Newbie
 
Registered: Aug 2012
Posts: 9

Original Poster
Rep: Reputation: Disabled
But for example i will like to use the gnome-panel time but it not have config to disallow get weather info.

The solution provided remove entirely akamai but as a CDN it could be useful, that is the reason a firewall per application could be better.
For example I will like use youtube from firefox, but not allow other softwares to connect (like unknown process displayed in images attached).

http://ubuntuforums.org/attachment.p...3&d=1344490930
http://ubuntuforums.org/attachment.p...3&d=1344490930

You can see gnome-panel and unknown process using Akamai CDN.
 
Old 08-11-2012, 06:34 AM   #11
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by expcodersrrg View Post
But for example i will like to use the gnome-panel time but it not have config to disallow get weather info.
Ah, finally a specific question. Running something like 'gconftool-2 --makefile-uninstall-rule /etc/gconf/schemas/gweather.schemas' should remove any GNOME panel weather applet information (else see your gconftool-2 mnual pages). If that's too much, or if it causes errors, unset or change individual /schemas/apps/gweather/prefs/ settings like auto_update, enable_radar_map, location*, coordinates, use_custom_radar_url and radar.


Quote:
Originally Posted by expcodersrrg View Post
a firewall per application could be better. (..) For example I will like use youtube from firefox, but not allow other softwares to connect
Program Guard was an application level firewall for GNU/Linux as were FireFlier and TuxGuardian. They've all gone. The only remaining one AFAIK is LeopardFlower. I won't comment on them (apart from taking obsolescence as an indication of lack of actual use) and I've never needed to use them. Maybe they work for you.
 
Old 08-11-2012, 07:55 AM   #12
expcodersrrg
LQ Newbie
 
Registered: Aug 2012
Posts: 9

Original Poster
Rep: Reputation: Disabled
Thanks unSpawn, this is what i was looking for.

But is important note this ===>>

Lets use some maths:

All the Ubuntu gnome-panel users have the clock be default and use weather services. Let suppose 2 million peoples uses Ubuntu with gnome-panel in the entire word right now. Every time a single user is connected gnome-panel weather send request to CDN and paid a small fraction of cost for CDN services. Let suppose that one user in an entire year using gnome-panel weather services request to CDN cost only 1$.

2 million users X 1$ per year = 2 million dollars of costs per year.

…..????

gnome-panel clock waste 2 million dollars per year at minimum paying to Akamai CDN.
We should really thanks the service free for us.

Ummmm.... It sound logic, I will do the same if one day have 2 millions dollars.
 
Old 08-14-2012, 06:03 PM   #13
expcodersrrg
LQ Newbie
 
Registered: Aug 2012
Posts: 9

Original Poster
Rep: Reputation: Disabled
A propose to global monitoring network:

CDN and other Clouds based services are often used in all the places I guess at least 90 % of Internet user access every day one or two of the main providers.

Solution:

Store user IP, user-dns, time and session information of facebook, weather services, gmail, yahoo, hotmail, … and any other services that uses Clouds. This will provide a digital identity for one person.

Handle huge volume of data will be important, and some optimizations will be useful.

Use case, how monitor a single user (concrete example):

Suppose Ronald login on facebook, Akamai CDN will store:

Ronald digital ID, stored on Cloud:
+++++++++++++++++++++++++++++++++++++++++++++++++++++++
IP: 152.10.27.175
user-dns: var15.ppp9.ispprovider.es
time: 11/27/2012 15:03:25
facebook session id: jhfs3fd345dfsdf9898948rf767udst73shf74wr8
+++++++++++++++++++++++++++++++++++++++++++++++++++++++

Now is important know the same user continue online with the same session at least.
So we should made a trick and with small frequency verify session id and update digital ID.

Trick solutions:
1) Leave a thread on browser requesting service to akamai or cloud posting session ID.
2) In client software app(chat messengers) is more easy, just send periodically session data.

Now we can know about Roland user:

Start connection day 11/27/2012 15:03:25 with IP 152.10.27.175 and remains online 2 hours. One day latter get connected again 11/28/2012 11:22:20 with IP 12.107.27.17.

But we have more about Roland: Facebook name, email address, other facebook and emails and accounts used, ….

Suppose Roland is a bad person and we have rights to track it, as soon we detect it is online we can now request to Roland ISP capture all info.
 
Old 08-14-2012, 08:22 PM   #14
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by expcodersrrg View Post
Solution:
You can post "solutions" all you want (though I'd rather see you use your LQ web log for posts like these) but I'm still unsure what problem you're trying to (or being asked to?) solve.
 
Old 08-14-2012, 08:49 PM   #15
expcodersrrg
LQ Newbie
 
Registered: Aug 2012
Posts: 9

Original Poster
Rep: Reputation: Disabled
In my case the only problem is connection speed down, because a lot of softwares app, try connect hidden, and if possible jump firewall, .. to access CDN Clouds like akamai. The solution in this case is use a firewall per application to avoid an unknown app get connected.

After research a little I have seen webs like :
http://www.matveev.se/net/akamai.htm
that reveal current privacy problems in our days.

In my case I don't care what others see, I can post my desktop Image you will see now weather services working with genome-panel.

But for example you are from Spain, are you fine knowing other country or private organization can be right now monitor all your citizen activity for unknown objectives?

I do not said this is some bad, It could be used for good objectives like propose make.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Blacklist ipv6 to speed up internet connections. Mol_Bolom Linux - Networking 5 10-05-2009 07:26 PM
how do i limit all connections on my server so a set speed? steve51184 Linux - Server 9 09-14-2009 12:24 AM
Question involving kermit connections and line speed EnderX Linux - Software 1 11-04-2008 12:44 PM
View network speed on all connections Quantum0726 Linux - Networking 1 07-11-2005 02:26 AM
Very slow speed even in LAN connections Adony Linux - Networking 5 11-09-2004 06:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:56 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration