View by:

Break through the university firewall Internet Redirection, Hide data in photos with Steganography and answers to your Virtualization questions!

Tuesday, May 5th, 2009 – running time 28:45
Want to bypass those nasty restrictions imposed by your corporate or university firewalls? Darren has just the trick with Internet Redirection. Ever wanted to hide secret data inside a photo? Shannon's show us a neat steganography app. Plus Matt answers your virtualization questions!

Corporate and university firewalls can be a particular PITA -- especially if you're a gamer. And while SSH tunneling (even over DNS)or VPN technologies are often preferred, it is quite possible to "bounce" your traffic off an Internet Redirection server. Like a fancy proxy, rinetd allows you to specify incoming and outgoing IP and port. It features basic client access rules based on IP and even supports logging. In my segment I demonstrate accepting traffic on port 80 and transmitting it to an IRC server on port 6667.

Granted this isn't going to fool your more complex firewalls that actually inspect packets -- but if you're just looking to get traffic through an open port I highly recommend giving rinetd a try.

Highlights
open source ( 3:58, 3:58 ) technolust ( 1:33, 1:33 ) open source ( 3:58, 3:58 ) technolust ( 1:33, 1:33 )

Automatically Generated Transcript(may not be 100% accurate) ( more )

" Wow. This week on the show and Internet traffic with the TCP redirect encrypting secret documents and hiding them inside images. And answers to your questions about virtualization. All that and more on that episode of Hak5. This episode of Hak5 is brought to you by godaddy -- like square space and viewers like you."

" Lo -- in the heart five million Darren Kitchen I'm -- let's not mention once."

" And there's. This is your weekly -- In the old farm. It. So it's guys let's -- Out. Own up and is. That we will be holding auditions and we blew -- off the island. -- Is that. It just jump on the theory that. Used to always. Today although these days. From yeah technolust wise -- you guys get through these like. Like sneakers mentally call the balance the signal that's -- it's not yet again -- on that."

" Yeah I'm gonna be talking about. The third part of our virtualization. -- it's a series. You take a break from the how to her you know planning and stuff like that. And a bunch of questions that people and allow asks me so -- gonna do real quick rundown of you know some of the things people are wondering. Things like that we before we actually get into the house."

" Like bureaucrats when it and you're playing with with what step in on earth see. And I and ultimately I guess it's just go right into it so it's eggnog -- Understanding about. It's basically a lake and bedding and -- into image is into you music files. Any kind of file that you once it's also involves like. Back in the day. There's the story about this guy -- shave the head of the -- it and wrote tattooed message onto his head -- waited to the hair grow back and then let go. Let him go -- so he can share the information somebody else. The thing about stand on her feet compared to cryptography. Is that photography it's. It's obvious that there's essence there you just can't really you have to figure out the code. To find out ways that's right -- expect under -- you hide it inside is something that looks so are all. Nobody is -- to -- to take the time to figure out what's in there because they don't think it isn't it's just an image so it's just."

" Hiding something in plain sight. Yeah so so cool we could we could put something in Kate and nobody would you like the proverbial. What is it like -- violent side of the cake. --"

" There's also this really cool story about how there's but supposedly there -- these terrorist -- out more stuff like that and they would. Hide it inside is avatar images like cats and things. So they were able to send messages to each other just in kind of get an avatar files. He's cheeseburgers me the attackers. While there's little you never had so many -- cool -- it can't live in and out about this really cool program it's just -- Stay right. There's tons of different programs out out there all of them work habits. So you -- the one that you like house for me extend tied. Rates that is open source planet what's that I'd that's what it is -- head yes -- dot SourceForge dot net it's available they have. When there's great documentation for use you can figure out how to do it yourself. At the dam expert -- next here as well as well and as I think. -- Well if you can run now if you you could run on Mac and yes I'll libraries and it's that some show you really quick do you and he downloads of obviously. I have this original picture of all all the -- Poehler yeah yeah. Oh -- Steve. It looks so. I have this original picture if -- hold as properties you can see that right now the bites aren't 68000. Ends and by way. Keep that in mind it's gonna change after I changed. So I -- that this version become part and added I just copy Beers on. About before I actually added this when it was the same -- so. 68 so what can we wouldn't sign this file you better text. This for me and attacks. There's all sorts of things and and you can also it is it just like that it's usually had to do it okay so you open your command propped. -- just get it."

" Okay so I'm gonna open up state had -- EXE. This is the RB information on how to you first about in bed -- information and then extract your information. So first I'm going to embed this really small little text document that says the -- Hak5 stores opening this week check out -- dot. -- It's here image against spammers for that. Wired -- in one registered and say you're seeing my little text that's not an important but maybe only talents and some secret and it. I got it you know news file -- an embedded. Analyses type pad. And it. Acts he. And then pictures called Paul. Edited dot JPEG. Dash. TXT. And it's gonna ask me and make -- for its okay well Leo like pa camera guys -- camera."

" So I'm betting T shirts and holiday -- dot com stock. So signaling that the difference now between news files you have the original. Yes you have -- is -- you know that's still. 68000. -- 60007. We got a pot headed -- now. And this kind of weird because it compressed and just a little bit more. Added that little itty bitty text documents and now it's 59529. Bytes right. On the instigate Agassi lost C I mean you can view compression on the image so if you have the original image and then you have this one nice thing maybe -- okay. If you know and you can just look at the bites and see if there's."

" And that it -- It's that gets us right into what's called -- analysis which we should do follow up segment we -- actually show you how to. In -- process and images and see if maybe there's something hidden in the cake."

" Wish it. Race so I'm I'm the person that's getting this file I don't actually captured -- TXT aside just deleted it rate since -- and the person."

" Artists and your person that's downloaded this and you can guessing and she runs take I."

" I'd stack had again on the new and we think humans and can put in here with Mimi Ito is a difference in the size is so windows -- on an -- edited. I wonder if it was edited mean. It's just stay intact -- had extract dash SF -- Center asked me before pass phrase so hopefully I'll Saint Paul Cameron or would brute force it. Okay it's that it -- extracted."

" Wow. This week on the show and Internet traffic with the TCP redirect encrypting secret documents and hiding them inside images. And answers to your questions about virtualization. All that and more on that episode of Hak5. This episode of Hak5 is brought to you by godaddy -- like square space and viewers like you."

" Lo -- in the heart five million Darren Kitchen I'm -- let's not mention once."

" And there's. This is your weekly -- In the old farm. It. So it's guys let's -- Out. Own up and is. That we will be holding auditions and we blew -- off the island. -- Is that. It just jump on the theory that. Used to always. Today although these days. From yeah technolust wise -- you guys get through these like. Like sneakers mentally call the balance the signal that's -- it's not yet again -- on that."

" Yeah I'm gonna be talking about. The third part of our virtualization. -- it's a series. You take a break from the how to her you know planning and stuff like that. And a bunch of questions that people and allow asks me so -- gonna do real quick rundown of you know some of the things people are wondering. Things like that we before we actually get into the house."

" Like bureaucrats when it and you're playing with with what step in on earth see. And I and ultimately I guess it's just go right into it so it's eggnog -- Understanding about. It's basically a lake and bedding and -- into image is into you music files. Any kind of file that you once it's also involves like. Back in the day. There's the story about this guy -- shave the head of the -- it and wrote tattooed message onto his head -- waited to the hair grow back and then let go. Let him go -- so he can share the information somebody else. The thing about stand on her feet compared to cryptography. Is that photography it's. It's obvious that there's essence there you just can't really you have to figure out the code. To find out ways that's right -- expect under -- you hide it inside is something that looks so are all. Nobody is -- to -- to take the time to figure out what's in there because they don't think it isn't it's just an image so it's just."

" Hiding something in plain sight. Yeah so so cool we could we could put something in Kate and nobody would you like the proverbial. What is it like -- violent side of the cake. --"

" There's also this really cool story about how there's but supposedly there -- these terrorist -- out more stuff like that and they would. Hide it inside is avatar images like cats and things. So they were able to send messages to each other just in kind of get an avatar files. He's cheeseburgers me the attackers. While there's little you never had so many -- cool -- it can't live in and out about this really cool program it's just -- Stay right. There's tons of different programs out out there all of them work habits. So you -- the one that you like house for me extend tied. Rates that is open source planet what's that I'd that's what it is -- head yes -- dot SourceForge dot net it's available they have. When there's great documentation for use you can figure out how to do it yourself. At the dam expert -- next here as well as well and as I think. -- Well if you can run now if you you could run on Mac and yes I'll libraries and it's that some show you really quick do you and he downloads of obviously. I have this original picture of all all the -- Poehler yeah yeah. Oh -- Steve. It looks so. I have this original picture if -- hold as properties you can see that right now the bites aren't 68000. Ends and by way. Keep that in mind it's gonna change after I changed. So I -- that this version become part and added I just copy Beers on. About before I actually added this when it was the same -- so. 68 so what can we wouldn't sign this file you better text. This for me and attacks. There's all sorts of things and and you can also it is it just like that it's usually had to do it okay so you open your command propped. -- just get it."

" Okay so I'm gonna open up state had -- EXE. This is the RB information on how to you first about in bed -- information and then extract your information. So first I'm going to embed this really small little text document that says the -- Hak5 stores opening this week check out -- dot. -- It's here image against spammers for that. Wired -- in one registered and say you're seeing my little text that's not an important but maybe only talents and some secret and it. I got it you know news file -- an embedded. Analyses type pad. And it. Acts he. And then pictures called Paul. Edited dot JPEG. Dash. TXT. And it's gonna ask me and make -- for its okay well Leo like pa camera guys -- camera."

" So I'm betting T shirts and holiday -- dot com stock. So signaling that the difference now between news files you have the original. Yes you have -- is -- you know that's still. 68000. -- 60007. We got a pot headed -- now. And this kind of weird because it compressed and just a little bit more. Added that little itty bitty text documents and now it's 59529. Bytes right. On the instigate Agassi lost C I mean you can view compression on the image so if you have the original image and then you have this one nice thing maybe -- okay. If you know and you can just look at the bites and see if there's."

" And that it -- It's that gets us right into what's called -- analysis which we should do follow up segment we -- actually show you how to. In -- process and images and see if maybe there's something hidden in the cake."

" Wish it. Race so I'm I'm the person that's getting this file I don't actually captured -- TXT aside just deleted it rate since -- and the person."

" Artists and your person that's downloaded this and you can guessing and she runs take I."

" I'd stack had again on the new and we think humans and can put in here with Mimi Ito is a difference in the size is so windows -- on an -- edited. I wonder if it was edited mean. It's just stay intact -- had extract dash SF -- Center asked me before pass phrase so hopefully I'll Saint Paul Cameron or would brute force it. Okay it's that it -- extracted."

mari1ee

Started discussion: May 6, 2009 @ 9:11am GMT

Episode 512 - Break through the university firewall Internet Redirection, Hide data in photos with Steganography and answers to your Virtualization questions! [Discussion]

Want to bypass those nasty restrictions imposed by your corporate or university firewalls? Darren has just the trick with Internet Redirection. Ever wanted to hide secret data inside a photo? Shannon's show us a neat steganography app. Plus Matt answers your virtualization questions!

Watch or download now!

computoman
7 months ago
Interesting show again. I wonder if rinetd or socat would run on one of the free firmwares (i.e. openwrt), I have one router left that I have not redboot to install a new firmware. You could see it in Darren's eyes about wanting to use rinetd to reroute requests on a man in the middle device. if you did not have a router, an ancient computer with linux/bsd would be perfect for rinetd. an old thin client using x86 version of openwrt on flash might be an interesting experiment.
hdibani
7 months ago

camouflage

Great show as usual :)
i used this windows program called camouflage around 8 years ago, to do exactly the same. instead of using the command line, camouflage comes with a gui (right click > camouflage/right click > uncamouflage).

check it out here:
http://camouflage.unfiction.com/
Guytheninja
7 months ago
I enjoyed this episode. I especially liked the stenography part. I did some stenography in one of my programming classes in college. :D

Also, Matt seemed to be in a better mood.
masterevilace
7 months ago
Matt mentioned that he bought a house.. maybe that's why he was in such a bad mood in the previous episode. Makes sense to me.

I definitely enjoy the virtualization segments.. while I'm not planning on doing it or anything, it's definitely nice to know how big servers are setup and run
zorgul
7 months ago
For the Steganography part.

Does the added data is stored in the jpg data (picture) or it is appended to the files? It would have been nice to have a little more info on how it works.

Great show!
Guytheninja
7 months ago
In reply to zorgul:
For the Steganography part.

Does the added data is stored in the jpg data (picture) or it is appended to the files? It would have been nice to have a little more info on how it works.

Great show!


http://www.garykessler.net/library/steganography.html looks like a good place to start.

When I used stenography in my CS class; I didn't use a key. I just took the last bit of each R value (of the RGB bitmap file) and swapped it with a bit of my hidden message. Obviously, thats the easiest (and most easily uncovered) method of stenography.

The cool thing is that you really cannot tell the difference between the two images by the naked eye.
zorgul
7 months ago
thanks for the link
View all 7 comments