RE: Hackers 2 - Operation Takedown 04-17-2018, 01:39 AM
#17
(04-16-2018, 09:41 PM)mothered Wrote:(04-16-2018, 04:49 PM)hacxx Wrote: The ISP provide devices that were connected and they ping to check if the ip was alive (This means that a internet connection was established).
1) Scan ISP subnet for all ips
2) Ping them to check who is alive
The problem with that scene, was they said "anyway of tracing"- with "tracing" being the operative word.
Establishing a connection Is one thing, tracing It's origin Is something else.
Actually.....there are some fun attacks you can do with that. They should very easily translate to the networking stack. Take a look at how KASLR slides are leaked through TLB caches. It uses a quasi-brute force "does it exist and is it active" methodology paired with a bunch of invalid accesses and compares the errors to each other in order to "triangulate" a specific symbol in a random space. Of course, the second stage of that attack would require something different for TCP, but the idea is still the same.



























![[+]](https://sinister.li/images/modern/collapse_collapsed.png)