Top Banner
TOR, I2P, FREENET… FOR WHAT?
31

The End of Anonymity on Anonymous Networks

Apr 14, 2017

Download

Technology

Denis Makrushin
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: The End of Anonymity on Anonymous Networks

TOR, I2P, FREENET… FOR WHAT?

Page 2: The End of Anonymity on Anonymous Networks

DEANONYMIZATOR… THE END OF ANONYMITY ON ANONYMOUS NETWORKS

Denis Makrushin (@difezza), Maria GarnaevaGlobal Research and Analysis Team

Page 3: The End of Anonymity on Anonymous Networks

«I KNOW WHAT YOU DID LAST SUMMER»

Page 4: The End of Anonymity on Anonymous Networks

… BUT HOW?!

Page 5: The End of Anonymity on Anonymous Networks

EXPLOITS, FINGERPRINTING… YEP-YEP.

Page 6: The End of Anonymity on Anonymous Networks

FLASH, HTML5, ENTRY-NODE DETECTION… YEP-YEP.

Page 7: The End of Anonymity on Anonymous Networks

BUT HOW …

… did they found my mega-private-0day-forum?!

… did the found me?!

Page 8: The End of Anonymity on Anonymous Networks

PASSIVE DATA COLLECTION SYSTEM… OR HOW DID THE FOUND MY MEGA-PRIVATE-0DAY-FORUM?!

Page 9: The End of Anonymity on Anonymous Networks

>> EXITPOLICY ACCEPT *:*

Page 10: The End of Anonymity on Anonymous Networks

>>TSHARK –I 1 –W DUMP.PCAP

Page 11: The End of Anonymity on Anonymous Networks

TOR-USER’S PSYCHOLOGICAL PORTRAIT

Page 12: The End of Anonymity on Anonymous Networks

PSYCHOLOGICAL PORTRAIT. PART TWO.

Page 13: The End of Anonymity on Anonymous Networks

BlackMarket; 14.32

DDoS-campaign; 3.03

Finan-cialServices; 2.82

Dark-netHoste

r; 1.86

Russian; 1.70

Leaks&Services;

1.70

Pe-dophile;

1.65

Asian; 0.85

Pornographie; 0.85

Hacker&Malicious; 0.80 Search Engines; 0.64Gambling; 0.53Arabic; 0.11

Other19%

Common59%

No Content22%

Page 14: The End of Anonymity on Anonymous Networks

ACTIVE DATA COLLECTION SYSTEM… OR KNOCK-KNOCK, DUDE!

Page 15: The End of Anonymity on Anonymous Networks

TRAFFIC INJECTION… YEP-YEP.

Page 16: The End of Anonymity on Anonymous Networks

TELL ME, WHO ARE YOU?

Page 17: The End of Anonymity on Anonymous Networks

SO DIFFERENT COOKIES

Page 18: The End of Anonymity on Anonymous Networks
Page 19: The End of Anonymity on Anonymous Networks

MEANWHILE, IN TOR BROWSER

Page 20: The End of Anonymity on Anonymous Networks

LET ME MEASURE YOUR TEXT

Page 21: The End of Anonymity on Anonymous Networks

GETBOUNDINGCLIENTRECT()

FONT VALUE

Impact 3409372Georgia 3344049Courier New 3430809Consolas 3392005MS Gothic 3383290

Page 22: The End of Anonymity on Anonymous Networks

“YEP-YEP, WE KNOW” – TOR PROJECT

Page 23: The End of Anonymity on Anonymous Networks

PROOF-OF-CONCEPT: PREPARING PATIENT

Page 24: The End of Anonymity on Anonymous Networks

PROOF-OF-CONCEPT: INJECT IT!

Page 25: The End of Anonymity on Anonymous Networks

PROOF-OF-CONCEPT: ANALYZE IT!

Page 26: The End of Anonymity on Anonymous Networks

XSS IS A PAIN OF ONION

Page 27: The End of Anonymity on Anonymous Networks

VECTOR OF ATTACK

Page 28: The End of Anonymity on Anonymous Networks

I KNOW YOU BY THE FONTS

Page 29: The End of Anonymity on Anonymous Networks
Page 30: The End of Anonymity on Anonymous Networks
Page 31: The End of Anonymity on Anonymous Networks

THANK YOU! [email protected]@kaspersky.comhttp://twitter.com/difezza