COLIN O’HANLON & NICK CIGANKO Sam Spade: Network Query Tool
What it does Used to identify malicious sites Operates on multiple platforms Basic network query Ping for service Finger Tracert Whois Reporting abuse DNS diagnostics
Why? Block unwanted network contact Spam mail origins Adversary working from a specific IP Malicious host General network curiosity
Other Features Scanning addresses Crawling for info Browsing Source Blacklist Check Timezone check
Ping Contact a host (local or networked) Number of pings Types to ping IP Ping URL Ping
Finger Retrieves IP address Works on sites, mail hosts
Tracert Network hub diagnostics GUI focus
Whois Network Diagnostics Address Registration Admins
Abuse Reporting Site’s abuse department Finds associtaed complaint center and provides address Usually ” format
How does this help me now? Scenario: You have a malicious website that wants to access your computer but you cannot exit the browser window, ect. Finger the URL for the IP As Windows Admin: Start>Control Panel>System and Security>Windows Firewall>Advanced Settings Select the INBOUND RULES, then single click the NEW RULE on the right panel Custom Rule>All Programs>Next> Add (enter the IP as a These remote IP address) > BLOCK CONNECTION > Next>Next>Finish DEMO
Questions or Concerns?