2016-007-FingerprinTLS profiling application with Lee Brotherston - a podcast by Bryan Brake, Amanda Berlin, Brian Boettcher

from 2016-02-14T04:38:35

:: ::

We first heard about FingerprinTLS from our friend Lee Brotherston at DerbyCon last September. Very intrigued by how he was able to fingerprint client applications being used, we finally were able to get him on to discuss this. 


We do a bit of history about #TLS, and the versions from 1.0 to 1.2


Lee gives us some examples on how FingerprintTLS might be used by red teamers or pentest agents to see what applications a client has on their system, or if you're a blue team that has specific application limitations, you can find out if someone has installed an unauthorized product, or you could even block unknown applications using this method by sensing the application and then creating an IPS rule from the fingerprint.


Finally, something a bit special... we have a demo on our Youtube site that you can view his application in action! 


Video demo: https://youtu.be/im6un0cB3Ns


 


 


https://upload.wikimedia.org/wikipedia/commons/thumb/4/46/Diffie-Hellman_Key_Exchange.svg/2000px-Diffie-Hellman_Key_Exchange.svg.png


http://blog.squarelemon.com/tls-fingerprinting/


https://github.com/LeeBrotherston/tls-fingerprinting


http://www.slideshare.net/LeeBrotherston/tls-fingerprinting-sectorca-edition


https://www.youtube.com/watch?v=XX0FRAy2Mec


http://2015.video.sector.ca/video/144175700


Cisco blog on malware using TLS... http://blogs.cisco.com/security/malwares-use-of-tls-and-encryption


 


Stitcher Network: http://www.stitcher.com/s?fid=80546&refid=stpr


TuneIn Radio App: http://tunein.com/radio/Brakeing-Down-Security-Podcast-p801582/


BrakeSec Podcast Twitter: http://www.twitter.com/brakesec


Bryan's Twitter: http://www.twitter.com/bryanbrake


Brian's Twitter: http://www.twitter.com/boettcherpwned


Join our Patreon!: https://www.patreon.com/bds_podcast


Tumblr: http://brakeingdownsecurity.tumblr.com/


RSS FEED: http://www.brakeingsecurity.com/rss


Comments, Questions, Feedback: bds.podcast@gmail.com


**NEW** Google Play Store: https://play.google.com/music/podcasts/portal/#p:id=playpodcast/series&a=100584969


**NEW** Listen to us on Player.FM!! : https://player.fm/series/brakeing-down-security-podcast


iTunes: https://itunes.apple.com/us/podcast/2016-007-fingerprintls-profiling/id799131292?i=362885277&mt=2


Direct Download: http://traffic.libsyn.com/brakeingsecurity/2016-007-FingerprinTLS_with_Lee_Brotherston.mp3

Further episodes of BrakeSec Education Podcast

Further podcasts by Bryan Brake, Amanda Berlin, Brian Boettcher

Website of Bryan Brake, Amanda Berlin, Brian Boettcher