Re: [SLUG] at-home cops, evading the

From: Derek Glidden (dglidden@illusionary.com)
Date: Tue Sep 25 2001 - 15:08:55 EDT


Bill wrote:
>
> Since I can not find a way to do this openly, I am looking for a way to
> evade their detection software. It seems I should be able to coax Apache
> into listening on a high port and passing that port address around the
> family. Maybe someone knows of a different method or can tell me why this
> one won't work?

That's one way of doing it, but you'll run into difficulties if you run
the web server on a port that wouldn't normally be open on firewalls. A
lot of "enterprise" networks keep outbound ports closed except for
commonly used ones, like port 80 for http. (Not realizing that most
viruses and trojans will just pass data around on port 80 anymore, and
that trying to restrict down outbound ports accomplishes very little
because of that, apparently...) Be extra sneaky and run it on port 139,
so it looks like Windows NetBIOS traffic. :)

If you have access to another server someplace, you could set up an
IPSEC tunnel, or some other form of VPN back to your home computer and
feed the data up through that. Alternatively, set up squid or Apache
doing forward-proxying and just relay everything through the other
machine. Of course, if you had access to another machine, you wouldn't
be so concerned about how to serve data off your home PC...

Aren't at-home in danger of bankruptcy at the moment anyway?

-- 
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
#!/usr/bin/perl -w
$_='while(read+STDIN,$_,2048){$a=29;$b=73;$c=142;$t=255;@t=map
{$_%16or$t^=$c^=($m=(11,10,116,100,11,122,20,100)[$_/16%8])&110;
$t^=(72,@z=(64,72,$a^=12*($_%16-2?0:$m&17)),$b^=$_%64?12:0,@z)
[$_%8]}(16..271);if((@a=unx"C*",$_)[20]&48){$h=5;$_=unxb24,join
"",@b=map{xB8,unxb8,chr($_^$a[--$h+84])}@ARGV;s/...$/1$&/;$d=
unxV,xb25,$_;$e=256|(ord$b[4])<<9|ord$b[3];$d=$d>>8^($f=$t&($d
>>12^$d>>4^$d^$d/8))<<17,$e=$e>>8^($t&($g=($q=$e>>14&7^$e)^$q*
8^$q<<6))<<9,$_=$t[$_]^(($h>>=8)+=$f+(~$g&$t))for@a[128..$#a]}
print+x"C*",@a}';s/x/pack+/g;eval 

usage: qrpff 153 2 8 105 225 < /mnt/dvd/VOB_FILENAME \ | extract_mpeg2 | mpeg2dec -

http://www.eff.org/ http://www.opendvd.org/ http://www.cs.cmu.edu/~dst/DeCSS/Gallery/



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 20:05:11 EDT