I did a killclient which would send back a malformed packet to any ssh handshake and kill the connecting client. This made the pentesters mad. Sending them spoilers will just make the sad, and not so mad.
Is that a feature or was that a hack. Did the same packet kill multiple clients? More info?
It was a hack, I was getting a nice regular supply of probes from Brazillian addresses, connect to port 22, try 5 different passwords on several different ids ad naseum. So I hacked the openssh server to start mutating the response packets. (very trivial genetic programming where the 'fitness' function value was time to respond between calls, longer = better) That went on for a while until the mutated response was somewhere around 10K bytes and then the call would just stop. A couple of weeks after that I got DDOS'd from a Brazilian botnet. Fail2ban cleaned that up but in practical terms it was easier to just use fail2ban on all of that.
That sounds extremely interesting, do you have a write up or source code somewhere?
I'd be interested to hear about more applications of adaptive/genetic code to network security.
I think it sounds more complicated than it is, think of it as response fuzzing. It is exactly like trying to find vulnerabilities in servers by sending them fuzzed packets except in this case you're trying to find vulnerabilities in clients by returning a fuzzed packet.
It will make your pentesters sad. We like movies.
No, just good humor :)
Somewhat tangentially related: a long time ago, certain scanning tools would crash or otherwise not react well to getting a stream of /dev/urandom. You could consider this the more human version.
And then someone uses you in an DoS amplification attack instead of going after you directly.
Nope. Good fun but not good security. Better to just refuse the connection.
It depends if you want to annoy human pentesters to give you the finger.