Preflight Checklist: Defcon Pineapple Crew


The Pineapple crew is bound by this: we carry our drinks in Pineapples. No über-133t mania, we just have pineapples and all have a big room. That stated, Defcon is a wiley experience- stick close to your crew...
So once we arrived in Vegas, met up with our Seattle crew, and had eaten, there were things to do to setup:
1) Liquor run, stock the bar...
Between 9 of us, we made out pretty nicely with liquor funds.
2) Setup a LAN router
Bruno brought a Soekris board, ike loaded it up with PfSense, and our lan was online. No wireless, a 10/100 switch and fistfulls of patch cables fit the bill, avoiding a ton of threats and annoyances.
3) Figure out and secure outside internet connectivity
Defcon is notorious for creating the most hostile network in the world, for three days a year, in the desert. What do I mean? Well, this year there were just under 7000 attendees, (that's seven-thousand). That stated, can you imagine a wireless lan where there are 50-100 people running various forms man-in-the-middle attacks, all on top of each other? How about people testing out carefully crafted TCP reset packets using pseudo-broadcast methods? (packet nukes), what about having 20-30 different spoofed DNS servers? Or what about phishing content-caches of popular sites?
End of the day, if you blow it on this network and do something stupid, you could easily have one of the following happen to you:
a) Have your mail, etc... servers all be attacked in various ways by hordes of script kiddies with something to prove.
b) Have people testing out whatever they just saw in the last lecture, ON YOU.
c) Be embarrassed and shamed by your friends for many years to come, possibly loose your job (if you work in some high-profile security arena or your company is compromised)
So yeah, it's kindof juvenile, but also really quite a fun and unique enviornment.
That stated, the wired lan securely keeps things simple for the occasional file-sharing, and a nat/firewall can be managed in real time for the wan uplink.
For the actual WAN uplink, we had a few options:
WIFI) rip the Atheros wireless mini-pci card out of George's laptop, put it in the soekris, pay for hotel-net crapola.
Downside: That network is likely to be owned, and more than being insecure, it'd could prove to become quite useless under attack at scale.
GPRS) Use my cingular phone as modem tether, to my laptop which feeds the router.
Downside: It's like 1500BAUD, (seriously), and it only works when I'm in the room (with my phone). This is what we used in the end, very minimal network use from us- too much to do, too many friends and drinks!


0 Comments:
Post a Comment
<< Home