LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-30-2005, 08:52 AM   #1
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 474

Rep: Reputation: 30
covert channels


Hi there,
I found out with great interest about covert channels and covert communication some time ago I thought I must add this type of information to my INFOSEC knowledge.
So if someone wants to talk about covert channels from a theoretical and practical but educational perspective he/she is welcomed.

Any thoughts, links, books, tools etc ....

Until now I've studied about steganography and little about hiding info in network traffic (tcp, udp , icmp etc.)

I liked steghide (linux and windows version) and stegdetect for hiding/finding info in images and audio files.
Interesting is also hyden which embeds info in any binary file.

Covert Channel Tunnelling Testing (cctt) should also be mentioned.


I am waiting for you comments on this subject.



all the best,
ddaas
 
Old 11-01-2005, 02:40 AM   #2
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 474

Original Poster
Rep: Reputation: 30
I thought this would be an interesting discussion...
No Feedback?
 
Old 11-01-2005, 07:48 AM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
I thought this would be an interesting discussion...
No Feedback?


Maybe then you could break the ice with some examples and links? Maybe pose a question that has the potential to lead to a discussion? Maybe narrow the scope a bit as well. Covert channels is quite a wide topic.
 
Old 11-03-2005, 01:20 AM   #4
primo
Member
 
Registered: Jun 2005
Posts: 542

Rep: Reputation: 34
http://gray-world.net/
There's a great deal of papers & software on the subject.
 
Old 11-03-2005, 02:09 AM   #5
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 474

Original Poster
Rep: Reputation: 30
1) cctt (covert channel tunnelling tool) seems also a great tool for making arbitrary tcp/udp tunnels and for passing firewall rules.
2) I found out very interesting how hyden uses steganography and hides data in binary files. Your /bin/ls cound carry a text file and it is guarateed from the author (I I've tested it) that the file size doesn't change a bit after the other file is embedded. The algorithm works based on the redundant instruction set of the x86. An inconvenient is that this redundant instructions are limited and the data hidden rate is only 1/110 comparing with steganography in images which has a rate of 1/17 - hidded data/cover data
3) A nice book is http://www.syngress.com/catalog/?pid=3140 It is not very technical and is like a story, but in the end you find out how much you have learnt.
4) Other links:
http://www.sarc-wv.com/
http://www.jjtc.com/pub/r2026.pdf
http://www.fbi.gov/hq/lab/fsc/backis...research01.htm
 
Old 11-03-2005, 02:36 AM   #6
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 474

Original Poster
Rep: Reputation: 30
Very interesting is how a secret message could be hidden in a inocent text (or not so inocent).
http://www.spammimic.com

What other tools for creating null ciphers do you know?
 
Old 11-03-2005, 03:15 AM   #7
ddaas
Member
 
Registered: Oct 2004
Location: Romania
Distribution: Ubuntu server, FreeBsd
Posts: 474

Original Poster
Rep: Reputation: 30
Quote:
I found out very interesting how hyden uses steganography
Sorry, is hydan not hyden - http://www.crazyboy.com/hydan/
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] covert the 14 cd iso to DVD iso? djkarl Debian 3 10-09-2005 08:19 AM
how to covert int to string/char type? nelnel Programming 2 08-23-2005 11:46 PM
Is it possible to covert PHP into C? linuxfond Programming 5 09-03-2003 02:34 AM
java covert double into string iceman47 Programming 10 05-28-2003 10:51 PM
Covert Bitrate of MP3's DiZASTiX Linux - Software 5 05-19-2003 06:24 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:39 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration