CIA Targeting Linux Users With OutlawCountry Network Traffic Re-Routing Tool
hothardware.com
hothardware.com
iptables contains five tables:
raw is used only for configuring packets so that they are exempt from connection tracking.
filter is the default table, and is where all the actions typically associated with a firewall take place.
nat is used for network address translation (e.g. port forwarding).
mangle is used for specialized packet alterations.
security is used for Mandatory Access Control networking rules (e.g. SELinux -- see this article for more details).
My opinion: this is simple but pretty smart at the same time, therefore the perfect hacker tool. I can't even imagine a single sysadmin who searched for additional iptables tables before this leak.To the dismissive people here: as a hacker you don't want complex attacking tools, they can be found much easier, because all the tools look for complex attacks (e.g. modified system files).
Hiding this well in plain sight in a place where no one and no tool ever looks is genius.
iptables contains five tables:
raw is used only for configuring packets so that they are exempt from connection tracking.
filter is the default table, and is where all the actions typically associated with a firewall take place.
nat is used for network address translation (e.g. port forwarding).
mangle is used for specialized packet alterations.
security is used for Mandatory Access Control networking rules (e.g. SELinux -- see this article for more details).
And that tbh doesn't seem very reliable, see what happened on a laptop which does not use iptables:
$ cat /proc/net/ip_tables_names
cat: /proc/net/ip_tables_names: No such file or directory
$ iptables -L
[...]
$ cat /proc/net/ip_tables_names
filter
$ iptables -t nat -L
[...]
$ cat /proc/net/ip_tables_names
nat
filter
This seems to only show loaded/active iptables tables. Which means that a table may exist but unless it is loaded you will not see it. But of course in our scenario the CIA would have activated some rules, so this table should appear there. Unless the CIA was also able to hide the table from that file, which may well be possible, since the table was added via a root kernel module...The post further down there says that additional tables can only be created via the kernel, so if you're really creating additional tables could you please share your commands for doing so?
From what's shown in the article it's likely only usable on RedHat-derivatives (because of the binary-only kernel module). There are already "amateur" rootkits out there, with what's almost certainly a better feature set.
I am particularly unimpressed with the documentation's suggestion to rm the module afterwards, as the systems in question are extremely likely to have the shred command installed (which first overwrites the file contents in-place) which would make it impossible for a quick examiner to simply undelete the module for analysis.
I think this was some agent's idea of a PoC more than something they expected to use.
As for RH-only, what makes us think that there aren't also Debian and other similar attacks?
MS-Word is also "somewhat unimpressive," as it's only usable on Windows.
$ cat /etc/gemrc
# --user-install is used to install to $HOME/.gem/ by default since we want to separate
# pacman installed gems and gem installed gems
gem: --user-installMy understanding is that ufw uses iptables under the hood. I use ufw, yet my laptop (casual user) has iptables; don't know whether it was installed as a result of installing ufw, or if it's there by default.
Regardless of using iptables or ufw, these are both for manipulating the lower level kernel network firewall. And the article shows using iptables to load an nf kernel module. (I think) it's the module that's important, and iptables is just the convenience function to get it done.
Anyone who has root access could easily install and uninstall iptables, or use some other method of module installation.
I think.
https://access.redhat.com/documentation/en-US/Red_Hat_Enterp...
Though, I am not sure how vulnerable the key infrastructure is to the CIA.