• Aucun résultat trouvé

CODE REVIEW Tuesday, 3:19 a.m

Dans le document Dissecting the Hack (Page 106-116)

Leon wanted to stay awake. He had enjoyed watching Hannah work as she parsed through the code they had captured from 3DNF. He sat in an uncomfortable hotel chair between Bob and Hannah as they worked. Hannah’s hands moved across the keyboard with the fl air of a pianist. After each command was completed, there was a certain virtuoso quality to the way she fi nished off the strike on the “Enter” key.

As Leon watched his two companions, every blink of his eyes took a little longer to open. His breathing slowed and his body relaxed slightly. One deep breath and—

“What!?” Bob had punched Leon on the shoulder.

“I told you they were Feds!”

“What?” Leon still couldn’t command any more words.

“I told you they were Feds!” Bob tried again.

“We don’t know that,” Leon responded and then yawned. “That’s just what Dobbs said in his Twitter (p. 287). Did you fi nd anything in the code?”

Hannah jumped in. “Whatever you guys caught, it wasn’t amateur. I found refer-ences to IPs that tie back to Germany, Russia, Switzerland, and China. There’s no way to know where the command and control for this is. I tried looking at these IPs and they are all black holes. They either don’t exist or they have some good source fi ltering” .

“What does the code do?” Leon asked.

“We can’t tell. But there is more about where the code was going when you caught this copy. You guys were too quick looking at the packet capture. Here,” Hannah pointed at the display on her laptop. “—the fi le was going to 10.24.53.192.”

“Yeah, we knew that,” Leon said. He turned to Bob and wondered aloud to Bob brooding in his chair, “Since when are you so quiet?”

“But did you see this?” Hannah continued scrolling down a couple of screens worth of captured data and pointed again. “Whoever was on the wireless network with you was also talking to 10.43.84.143.”

82 CHAPTER S3V3N

“Okay, so they hopped to another private network,” Bob responded. Leon noted the slight annoyance in Bob’s tone.

“What were they doing?” Leon turned back to Hannah.

“Well, it’s a different subnet. So I’d sure like to know if it just hopped through a switch, or if it is going through a router to an internal segment, or DMZ, or out to another extranet. We just can’t tell if this is in the same general network or not.

Since the person you were eavesdropping on went straight to the fi rst IP, they knew what they wanted.” Hannah turned to Bob. “You didn’t see any scanning before you started this capture, did you?”

“No—this is the only interesting part of the traffi c we saw,” Bob responded.

Hannah continued, “I bet if they are good guys or bad, they were placing some kind of command and control on at least one box, maybe two.”

“Feds!” Bob loudly concluded.

“We don’t know that,” Leon pointed out trying to break Bob out of his funk.

“They’ve got my dad!” Bob responded, his voice close to cracking.

“What?” Hannah turned to Leon. “That’s more than the code review I signed on for.”

Leon didn’t want to lose the new help. “Listen, we think—but we don’t know—

the people who were on the network were Feds.”

“Of course, they were—you guys saw Dobbs’s DM when they went to his shop.”

Bob was getting his voice back. He turned to Hannah. “Max, I had a camera in my lab.

It was tied to a motion sensor and sent a video fi le to a remote server I use. We pulled down the fi le and saw three people in my lab with my dad. They had a gun on him and one of them shot out my camera. None of my stuff is live on the web anymore.”

“That doesn’t sound like the Feds,” Hannah responded.

Bob looked almost wounded with her answer, but he didn’t stop. “Dobbs. He’s from 2600, he—wait a minute—you were lurking at the meeting last month, weren’t you!”

“I was watching,” Hannah confessed defi antly.

“Where?” Leon jumped in.

“I was hanging out close enough to listen to what was going on. I knew if I sat down and started talking, I’d probably get pulled in and then I’d have to come up with some complicated real-world story.”

Bob shook his head, a little mad at himself for not connecting the dots before now. “Anyway, two Feds showed up at Dobbs’s shop yesterday. They were asking about me!”

Hannah started to ask a question, but Bob cut her off.

“And get this—one of the Feds has been going to 2600!”

“Who?” Hannah asked.

“Jeb—the kicker. He was in a suit at Dobbs’s place. They’ve been watching us all along!”

“Listen, if they are Feds, they won’t get you for anything more than listening to an unsecured wireless. I’ve looked at the logs and you don’t have anything other than a radio broadcast someone was dumb enough to not encrypt properly. But, if these guys are bad—you don’t know how far they will go. If they have your dad, I say go to the Feds now and take your chances.”

83 Code Review

Bob was shaking his head in disagreement before Hannah even fi nished. Leon was a little slower to come to a conclusion. Everyone had exhausted his or her arguments. They sat in silence with each looking at a different random object in the room. After a few sighs and shifts in a seat, Leon tentatively broke the silence.

“I think Hannah’s right. We need someone on our side and I think it’s worth tak-ing the chance.” Leon paused, expecttak-ing the push back from Bob, but it didn’t come.

Instead, he just looked expectantly at Leon to see if he had more. Leon continued his thought.

“If Jeb—or whatever his name is—has been watching us, then at least he knows we aren’t that bad. If he’s been paying attention in the 2600 meetings, we don’t teach people to do evil.” Leon paused for a breath and Bob let him continue.

“Let’s set up a meet at some neutral place. Maybe they can help.”

Bob sat and considered the idea. He knew his friends were right, he just had to break the momentum of his own distrust of anyone in a position of authority.

“Okay, let’s send a text to Jeb. I’ve got his cell number from Dobbs.”

“Don’t use your phone,” Hannah volunteered.

Bob gave her an incredulous look. “Of course, not. I don’t carry a phone—and I’m not going to use Leon’s and give them a way to trace us. I’ll use a VMware browser appliance through TOR to a Web site that sends texts” ( p. 305). Bob turned and reached for his laptop, balanced it on his knees, and started typing.

Hannah looked a little embarrassed at the answer and leaned back in her chair while Bob worked. Leon leaned over Bob’s shoulder as he typed.

I hear you are asking around about us. Meet at Galleria parking garage, where we exit from 2600 meetings at 17:30 today. Don’t bring goons. Bob.

“I don’t think ‘goons’ is a way to make a friend,” Leon suggested.

“Tough. I don’t want any extras,” Bob answered still agitated with no tangible target to lash out at, then he clicked the “Send” button on the screen. “Now, we need a different car. The Mini works for wardriving, but we may need to blend into the crowd now. Max, do you have a car?”

“Uh, yeah. But I don’t want every cop on the street looking for it.” Max said taken aback at the abrupt transition.

“What do you have?” Bob asked, ignoring Hannah’s concern.

“It’s a Ford Taurus my dad gave me after he wore it out driving to work for years.”

“Perfect. We’ll need you to drive to the meet by yourself and be our way out. We will need to ditch the Mini. If the Feds have been talking to Rudy, then they probably know we have his car,” Bob deduced.

“I’m not sure. I don’t think Rudy would tell them,” Leon suggested.

“We can’t take that chance—Rudy has more to lose than we do. We’ve got to assume the Mini isn’t safe. Besides, we left the wagon in the parking lot, remember?”

Leon nodded in agreement, but Hannah wasn’t satisfi ed with her part.

“I just said I don’t want to have cops looking for—”

84 CHAPTER S3V3N

“Max, we don’t have a choice. We need to get out of there and you are the only way,” Bob responded. “Besides, we won’t be followed. They won’t ever see us get into your car—that’s why we picked the location.”

Hannah still wasn’t convinced. She looked at Bob and started to speak. Just as she took a breath, Leon cut her off.

“Hannah, please,” was all he said quietly. She looked at Leon and her expression softened just slightly.

“We arrive at different times, and I don’t park anywhere near you.”

“Deal,” was all Bob said.

Leon smiled slightly at Hannah and nodded his head. “Okay, now we are a team.”

He turned back to Bob. “So what do we need for the meet?”

“Let’s see…” Bob leaned back in his chair and stared at the ceiling with his hands behind his head. “We’ll need my iPaq to check for heat, my laptop with the code, and, uh, and that’s probably it.” I don’t want to take more and risk losing it.”

Two hours later, Leon and Bob pulled into the Galleria parking garage slowly.

Leon started up the ramp while watching the environment for threats. Bob had his iPaq running WiFiFoFum. The software gave him a radar-like display of wireless access points in the area .

“We’re clear so far—no cops in this part of the garage.” Bob leaned over and showed the display to Leon. A single dot appeared near the edge of the screen.

Leon understood. The display showed sources of wireless network signals and estimated their distance. The Houston police department, like a few others around the country, had begun using wireless signals between their squad cars and repeater stations set on traffi c signals. The resulting network gave them a high-speed data link back to their headquarters, so they could retrieve datalike lookups on license plates or pull up videos on certain public area surveillance cameras. The problem with the system was that they hadn’t considered how easy it was to detect the wireless signal.

Even though it was encrypted, it still warned of their presence. Even when they went on silent runs, they were emitting a Wi-Fi networking signal ( pp. 400–401).

Leon turned back to watching the cars slowly pass as they drove up the ramp.

Just as they made the turn passed the second-level stairwell entrance, neither of them noticed the man step out of the door. As Leon and Bob proceeded up the ramp, Andrei strode calmly across the ramp and over to an older-model sedan. He needed something that wouldn’t have an alarm. The well-practice move was only visible to someone directly in front of Andrei. He slipped the tool between the window and the rubber gasket of the door and with a deft move, caught the lock and pulled. The door was open and Andrei quickly went to work on the ignition.

Mark and Chris were already standing by their car on the third level. As agreed, in the texts they received, they were positioned on the opposite end of the level from the stairwell. Neither spoke as they watched the full parking lot. There was a lull in foot traffi c, but they could hear the sound of cars and people on the other levels.

Chris caught the motion fi rst and tapped Mark’s arm as she turned.

Leon pulled the Mini Cooper up the ramp and continued around up to the fourth level.

Chris followed the movement of the car while Mark watched where it came from.

85 Code Review

“Is that our contact?” Chris asked as she tracked the movement.

“Yeah. Watch for them to walk in. They’ll either come from behind us or that stairwell,” Mark motioned across the parking garage to the metal door that had no window. They stood scanning the area for only a couple of quiet minutes before the door to the stairwell opened slowly. Two college-age kids walked out. The shorter leaned forward slightly to compensate for the weight of the backpack he carried.

“We don’t need to worry about them running,” Chris noted.

Leon paused for a moment, but Bob never broke stride. Both of them were scan-ning the area. Bob went straight to the fi rst space between a parked car behind him and an SUV in front. Leon was close behind. From their position, they could see the door to the stairwell, were a few paces from the ramp up to the next level, and had a clear line of sight to the two “Feds” who were the objective of the day. The hood of the SUV gave more protection from their biggest threat.

“Dobbs was right—that’s Jeb from the 2600 meetings,” Bob observed. He could see both of Mark’s hands, but the lady stood with her side facing them. Her left hand was visible resting on the hood of a car, but her right arm was held close to her side, hiding her hand. “I think she has a gun,” Bob noted while trying to deny the reality at the same time. Leon nodded half in agreement but didn’t speak.

“Bob. What were you guys doing at 3DNF Saturday night?” Mark started the conversation.

Bob didn’t give Leon a chance to speak. “I’d rather know what you guys were doing there!”

“Bob, we weren’t there. We got a call that they found a CyberBob icon fi le on one of their servers. That sounds like you were planting stuff for the Capture the Flag.”

“You were there!” Bob retorted without answering Mark’s question. “We were minding our own business at a convenience store and detected you guys planting a Trojan on their network!” Bob yelled accusingly.

Leon winced and gave Bob a look since he had just confessed to eavesdropping on a network to a federal agent. However, “Dude, shut up!” was all that came out.

“Bob, I don’t know what you are talking about. We weren’t there.”

“We have proof you were dropping fi les on a private company’s network!” Bob took a breath and decided to play his only card. “I’ll give all that up if you will just let my dad go! He had nothing to do with it and didn’t know where I was!”

There was a pause while Mark and Chris exchanged confused looks.

“Bob, let’s go somewhere to fi nish this conversation in private. I think you don’t understand—”

Mark stopped talking as a car pulled behind Bob and Leon’s position. It was com-ing up from the lower level and passed in front of the stairwell entrance. Leon caught the motion and turned. Chris saw the car, and then saw the taller of the two kids move rather quickly.

In the same moment, Andrei pulled behind Bob and Leon. He smoothly raised his gun up from the passenger’s seat, where it was laying with his hand on the grip.

Leon felt the fi rst shot more than he heard it. The sound of a gunshot inside the parking garage reverberated and then a ringing sound began to grow inside his head.

86 CHAPTER S3V3N

Before he could decide if he was hit, he saw Bob go down. The bullet hit Bob directly in the middle of his backpack. The impact slammed him forward and his face caught the passenger’s side mirror on a Chevy Tahoe as he fell. For a half-count, Leon saw Bob hit the ground and saw the back of his backpack stained a dark color, looking like it was wet. Leon yelled for his friend and ducked low at the side of the SUV and tried to get to Bob.

From there, the experiences of the two friends diverged. For Leon, he was sud-denly amazed to fi nd Bob struggling to get back up and begin barking orders at him. For Bob, the gunshot impact, the face-plant into the SUV, and Leon’s shouting blurred into a surreal world of soldiers and gunfi re.

“What are you looking at?!” Bob barked with a voice of authority. Before Leon could process the fact that his friend was standing, more orders followed.

“Cover my left while I fi nd where they’re coming from!” Bob crouched down, opened the Velcro cover on the case attached to his belt and pulled out his PDA. Leon saw Bob’s WiFiFoFum wireless scanner. But it was clear that Bob saw something different.

By now, Andrei had continued in the car up the ramp to the next level. As soon as his fi rst shot hit, he tried two more that Leon never heard. Both shots missed. They traveled passed Bob and Leon towards Mark and Chris. From Chris’s position, the fi re appeared to come from the kids. Mark was down behind the engine block of their car while Chris stayed up just high enough to return fi re. She did little more than infl ict even more damage on the Tahoe protecting Bob and Leon.

“What are you doing!?” Mark yelled at Chris.

“One of your geeks is shooting at us!”

“That’s not them—do you think they know anything about—” Mark stopped talk-ing as he followed the motion of Andrei’s car around the curve to the next level.

Andrei had kept his gun pointed out the driver’s side window as he pulled away from Bob and Leon. As he saw Chris duck fi rst, he fi red again. Andrei needed to keep them pinned down as he drove by. Mark wasn’t as quick to react. He had his weapon out by this time, but he hadn’t fi red. The moment of decision had already passed and he had not acted. Chris was already moving. As she went down behind the car, she reached with her left hand and grabbed Mark’s jacket. Her momentum pulled Mark down in just enough time for Andrei’s shots to miss.

“I’ve been here for less than a week and you already owe me!” Chris yelled as she turned to follow the motion of Andrei’s car up the ramp. There was no angle for a shot.

“We’ve got two in the area, but we should make it to the LZ. Cover the left and stay low!” Bob was just starting to get his feet under him when Leon grabbed his

“We’ve got two in the area, but we should make it to the LZ. Cover the left and stay low!” Bob was just starting to get his feet under him when Leon grabbed his

Dans le document Dissecting the Hack (Page 106-116)