begood Posted July 16, 2010 Report Posted July 16, 2010 Hello fd-list folks.I recently demonstrated at Athcon, a new security conference taking placein Athens - Greece, a new stealthy port scanning attack that is madepossible by abusing XMPP. The technique uses a "zombie" host (that can beanyone in your [most probably fake] friend/contact list) and some timingcalculations in order to conduct a portscan through that proxy to anytarget. The IP address is never revealed to the scanned victim, the sameway the famous idle/zombie scan, discovered by antirez, works.The idea, a proof of concept pidgin patch and a detailed analysis can beread in the paper.You can find the whitepaper here:http://sock-raw.org/papers/abusing_network_protocolsand the presentation slides:http://sock-raw.org/papers/anp_presentation.pdfIt is interesting to see how protocols like seemingly "innocent" protocolslike XMPP can still be abused to do things like the above attack.Regards,ithilgoreFull Disclosure: A new zombie port scanning attack-- http://sock-raw.orgithilgore (ithilgore) on Twitter Quote