Foca 2 5
This presentation is the property of its rightful owner.
Sponsored Links
1 / 45

FOCA 2.5 PowerPoint PPT Presentation


  • 114 Views
  • Uploaded on
  • Presentation posted in: General

FOCA 2.5. Chema Alonso. What’s a FOCA?. FOCA on Linux?. FOCA + Wine. Previously on FOCA…. FOCA 0.X. FOCA: File types supported. Office documents: Open Office documents. MS Office documents. PDF Documents. XMP. EPS Documents. Graphic documents. EXIFF. XMP.

Download Presentation

FOCA 2.5

An Image/Link below is provided (as is) to download presentation

Download Policy: Content on the Website is provided to you AS IS for your information and personal use and may not be sold / licensed / shared on other websites without getting consent from its author.While downloading, if for some reason you are not able to download a presentation, the publisher may have deleted the file from their server.


- - - - - - - - - - - - - - - - - - - - - - - - - - E N D - - - - - - - - - - - - - - - - - - - - - - - - - -

Presentation Transcript


Foca 2 5

FOCA 2.5

Chema Alonso


What s a foca

What’s a FOCA?


Foca on linux

FOCA on Linux?


Foca wine

FOCA + Wine


Foca 2 5

Previously on

FOCA….


Foca 0 x

FOCA 0.X


Foca file types supported

FOCA: File types supported

  • Office documents:

    • Open Office documents.

    • MS Office documents.

    • PDF Documents.

      • XMP.

    • EPS Documents.

    • Graphic documents.

      • EXIFF.

      • XMP.

    • Adobe Indesign, SVG, SVGZ (NEW)


What can be found

What can be found?

  • Users:

    • Creators.

    • Modifiers .

    • Users in paths.

      • C:\Documents and settings\jfoo\myfile

      • /home/johnnyf

  • Operating systems.

  • Printers.

    • Local and remote.

  • Paths.

    • Local and remote.

  • Network info.

    • Shared Printers.

    • Shared Folders.

    • ACLS.

  • Internal Servers.

    • NetBIOS Name.

    • Domain Name.

    • IP Address.

  • Database structures.

    • Table names.

    • Colum names.

  • Devices info.

    • Mobiles.

    • Photo cameras.

  • Private Info.

    • Personal data.

  • History of use.

  • Software versions.


Pictures with gps info

Pictureswith GPS info..


Foca 2 5

Demo:

Single files


Sample fbi gov

Sample: FBI.gov

Total: 4841 files


Are they cleaned

Are theycleaned?


Foca 1 v rc3

FOCA 1 v. RC3

  • Fingerprinting Organizations with Collected Archives

    • Search for documents in Google and Bing

    • Automatic file downloading

    • Capable of extracting Metadata, hidden info and lost data

    • Cluster information

    • Analyzes the info to fingerprint the network.


Sample printer info found in odf files returned by google

Sample: Printer info found in odf files returned by Google


Types of engineers

Types of Engineers


Dns prediction

DNS Prediction


Google sets prediction

Google Sets Prediction


Foca 2 5

Demo:

Mda.mil


Foca 2 0

FOCA 2.0


What s new in foca 2 5

What’s new in FOCA 2.5?

  • Network Discovery

  • Recursivealgorithm

  • InformationGathering

  • SwRecognition

  • DNS Cache Snooping

  • ReportingTool


Foca 2 5 exalead

FOCA 2.5: Exalead


Ptr scannig

PTR Scannig


Bing ip

Bing IP


Foca 2 5 shodan

FOCA 2.5 & Shodan


Network discovery algorithm

Network DiscoveryAlgorithm

http://apple1.sub.domain.com/~chema/dir/fil.doc

  • http -> Web server

  • GET Banner HTTP

  • domain.com is a domain

  • Search NS, MX, SPF records for domain.com

  • sub.domain.com is a subdomain

  • Search NS, MX, SPF records for sub.domain.com

  • Try allthe non verified servers onall new domains

    • server01.domain.com

    • server01.sub.domain.com

  • Apple1.sub.domain.com is a hostname

  • Try DNS Prediction (apple1) onalldomains

  • Try Google Sets(apple1) onalldomains


Network discovery algorithm1

Network DiscoveryAlgorithm

http://apple1.sub.domain.com/~chema/dir/fil.doc

11) Resolve IP Address

12) GetCertificate in https://IP

13) Searchfordomainnames in it

14) Get HTTP Banner of http://IP

15) Use Bing Ip:IPtofindalldomainssharingit

16) Repeatforevery new domain

17) Connecttotheinternal NS (1 orall)

18) Perform a PTR Scansearchingforinternal servers

19) Forevery new IP discovered try Bing IP recursively

20) ~chema-> chemaisprobably a user


Network discovery algorithm2

Network DiscoveryAlgorithm

http://apple1.sub.domain.com/~chema/dir/fil.doc

21) / , /~chema/ and /~chema/dir/ are paths

22) Try directorylisting in allthepaths

23) Searchfor PUT, DELETE, TRACE methods in everypath

24) Fingerprint software from 404 error messages

25) Fingerprint software fromapplication error messages

26) Try commonnamesonalldomains (dictionary)

27) Try Zone Transfer onall NS

28) Searchforany URL indexedby web enginesrelatedtothehostname

29) Downloadthe file

30) Extractthemetadata, hiddeninfo and lost data

31) Sortallthisinformationand presentitnicely

32) Forevery new IP/URL startoveragain


Foca 2 5 url analysis

FOCA 2.5 URL Analysis


Foca 2 5 url analysis1

FOCA 2.5 URL Analysis


Foca 2 5

Demo: fbi.gov

whitehouse.gov


Customizable search

CustomizableSearch


Foca spidering

FOCA + Spidering


Foca spidering1

FOCA + Spidering


Dns cache snooping

DNS Cache Snooping


Dns cache snooping1

DNS Cache Snooping


Dns cache snooping2

DNS Cache Snooping

  • DNS Cache Snooping + Evilgrade

  • DNS Cache Snooping + AV bypassing


Foca reporting module

FOCA Reporting Module


Foca reporting module1

FOCA Reporting Module


Foca 2 5

Demo: DNS

Cache Snooping


Foca online

FOCA Online

http://www.informatica64.com/FOCA


Cleaning documents

Cleaning documents

  • OOMetaExtractor

http://www.codeplex.org/oometaextractor


Iis metashield protector

IIS MetaShield Protector

http://www.metashieldprotector.com


Questions at q a room 113

Questionsat Q&A room 113

  • Chema Alonso

    • [email protected]

    • http://www.informatica64.com

    • http://www.elladodelmal.com

    • http://twitter.com/chemaalonso

  • Workingon FOCA:

    • Chema Alonso

    • Alejandro Martín

    • Francisco Oca

    • Manuel Fernández «The Sur»

    • Daniel Romero

    • Enrique Rando

    • Pedro Laguna

    • SpecialThanksto: John Matherly [Shodan]


  • Login