<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Footprinting &#8211; @Forensicxs</title>
	<atom:link href="https://www.forensicxs.com/tag/footprinting/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.forensicxs.com</link>
	<description>Ethical Hacking &#124; Cybersecurity</description>
	<lastBuildDate>Sun, 27 Nov 2022 22:01:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>Belarus and the Web</title>
		<link>https://www.forensicxs.com/belarus-and-the-web/</link>
					<comments>https://www.forensicxs.com/belarus-and-the-web/#respond</comments>
		
		<dc:creator><![CDATA[Forensicxs]]></dc:creator>
		<pubDate>Sun, 27 Nov 2022 22:01:44 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[beCloud]]></category>
		<category><![CDATA[Belarus]]></category>
		<category><![CDATA[Footprinting]]></category>
		<category><![CDATA[Operational and Analytical Center]]></category>
		<guid isPermaLink="false">https://www.forensicxs.com/?p=2968</guid>

					<description><![CDATA[In this article, I will scratch the surface of the Belarus web infrastructure, using some basic footprinting techniques Belarus is a country in Eastern Europe. It is bordered by Russia to the east and northeast, Ukraine to the south, Poland to the west, and Lithuania and Latvia to the northwest. It has a population of &#8230; <p class="link-more"><a href="https://www.forensicxs.com/belarus-and-the-web/" class="more-link">Continue reading<span class="screen-reader-text"> "Belarus and the Web"</span></a></p>]]></description>
										<content:encoded><![CDATA[
<p> </p>



<p>In this article, I will scratch the surface of the Belarus web infrastructure, using some basic <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">footprinting</mark></strong> techniques</p>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Belarus</mark></strong> is a country in Eastern Europe. It is bordered by Russia to the east and northeast, Ukraine to the south, Poland to the west, and Lithuania and Latvia to the northwest. It has a population of <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">9.5 million</mark></strong>. Minsk is the capital and largest city</p>



<figure class="wp-block-image size-full is-resized"><img fetchpriority="high" decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image.png" alt="" class="wp-image-2970" width="505" height="336" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image.png 683w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-300x199.png 300w" sizes="(max-width: 505px) 100vw, 505px" /></figure>



<p>Belarus had a complex history in the last century, changing hands at various times, to the  Grand Duchy of Lithuania, the Polish–Lithuanian Commonwealth, and the Russian Empire. In the aftermath of the Russian Revolution in 1917, the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Byelorussian SSR</mark></strong> (Soviet Socialist Republic) became a founding constituent republic of the Soviet Union in 1922</p>



<p>After the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Polish-Soviet War</mark></strong>, Belarus lost almost half of its territory to Poland. Much of the borders of Belarus took their modern shape in 1939, when some lands of the Second Polish Republic were reintegrated into it after the Soviet invasion of Poland</p>



<p>During <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">World War II</mark></strong>, military operations devastated Belarus, which lost about a quarter of its population and half of its economic resources</p>



<p>The parliament of the republic proclaimed the sovereignty of Belarus in July 1990, and during the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">dissolution of the Soviet Union</mark></strong>, Belarus declared independence in August 1991. However, Belarus kept strong ties with Russia</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-2.png" alt="" class="wp-image-2973" width="384" height="385" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-2.png 752w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-2-298x300.png 298w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-2-150x150.png 150w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-2-100x100.png 100w" sizes="(max-width: 384px) 100vw, 384px" /></figure>



<p>Following the adoption of a new constitution in 1994, <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Alexander Lukashenko</mark></strong> was elected Belarus&#8217;s first president in the country&#8217;s first and only free election post-independence, serving as president ever since. Lukashenko heads an authoritarian government with a poor human rights record due to widespread abuses</p>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Internet infrastructure</mark></strong></p>



<p>Let&#8217;s start a quick review about <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Internet cables</mark></strong> providing the Internet to Belarus</p>



<p>The first one is the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Transit Europe Asia (TEA)</mark></strong> network, which is an international transit fiber-optic cable line passing trough Russia, and linking European countries with Asia. TEA has transmission routes on <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Rostelecom</mark></strong> (Russian National Telecommunication Company : <a rel="noreferrer noopener" href="https://bit.ly/3Vwy4Vy" target="_blank">https://bit.ly/3Vwy4Vy</a>) core networks, with extensions to Belarus</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-11.png" alt="" class="wp-image-2985" width="511" height="300" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-11.png 711w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-11-300x176.png 300w" sizes="(max-width: 511px) 100vw, 511px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3fWHHME" target="_blank" rel="noreferrer noopener">https://bit.ly/3fWHHME</a></figcaption></figure>



<p>A second one is <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">TransTeleCom (TTK)</mark></strong>, which is one of the leading Telecom operators in Russia. TTK has a partnership with the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Russian Railways</mark></strong> (<a rel="noreferrer noopener" href="https://bit.ly/3EHJv6I" target="_blank">https://bit.ly/3EHJv6I</a>)</p>



<p>TTK is operating a large fiber-optic backbone digital communication network, which is laid along the railways of Russia and has many access points in all densely populated regions of the country, connecting the eastern and western borders of the Russian Federation</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-12.png" alt="" class="wp-image-2987" width="505" height="259" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-12.png 1006w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-12-300x154.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-12-768x393.png 768w" sizes="(max-width: 505px) 100vw, 505px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3fWHHME" target="_blank" rel="noreferrer noopener">https://bit.ly/3fWHHME</a></figcaption></figure>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">TTK Eurasia Highway</mark></strong> has connections with communication networks of all neighboring countries with Russia, including Belarus, and is an optimal route between Europe and Asia</p>



<p>Belarus has its own local companies able to install underground cables and expand the Internet network. One of these is <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Minskkabel</mark></strong> which is specialized in the manufacture of optical cables for an interconnected communication network between Belarus, Russia, and other neighbouring countries</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-13.png" alt="" class="wp-image-2988" width="386" height="129" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-13.png 948w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-13-300x101.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-13-768x259.png 768w" sizes="(max-width: 386px) 100vw, 386px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3T9QadI" target="_blank" rel="noreferrer noopener">https://bit.ly/3T9QadI</a></figcaption></figure>



<p>Now, let&#8217;s look at the Belarus country code <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">ccTLD &#8211; Top Level Domain</mark></strong> and corresponding <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">DNS &#8211; Domain Name Server</mark></strong> <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">root zone</mark></strong></p>



<p>IANA is responsible to assign the operators of top-level domains, such as&nbsp;.com, and maintain their technical and administrative details</p>



<p>We can find the Belarus ccTLD on the IANA website with the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">.by country code</mark></strong></p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-8.png" alt="" class="wp-image-2981" width="451" height="494" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-8.png 790w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-8-274x300.png 274w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-8-768x842.png 768w" sizes="(max-width: 451px) 100vw, 451px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3ezLKOW" target="_blank" rel="noreferrer noopener">https://bit.ly/3ezLKOW</a></figcaption></figure>



<p>IANA is responsible for determining an appropriate <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">trustee</mark></strong> for each ccTLD. Administration and control are then delegated to that trustee, which is responsible for the policies and operation of the domain</p>



<p>In the case of Belarus, it is <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Belarusian Cloud Technologies LLC</mark></strong> <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">(beCloud)</mark></strong>. According to their website, they describe themselves as the first infrastructure operator in Belarus. Here are some key services <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">operated</mark></strong> by beCloud :</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-21.png" alt="" class="wp-image-3007" width="573" height="124" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-21.png 963w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-21-300x65.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-21-768x167.png 768w" sizes="(max-width: 573px) 100vw, 573px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3rZ8Scy" target="_blank" rel="noreferrer noopener">https://bit.ly/3rZ8Scy</a></figcaption></figure>



<p>In the last years, Belarus has been building a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">sovereign Cloud</mark></strong> ecosystem, mostly with the help of major European, US and Asian companies, such as the ones below. The <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">international sanctions</mark></strong> on Belarus and Russia are mainly targeted to specific individuals, and do not block necessarily these partnerships and exchange of technology</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-22.png" alt="" class="wp-image-3008" width="372" height="458" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-22.png 664w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-22-244x300.png 244w" sizes="(max-width: 372px) 100vw, 372px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3rWkb5h" target="_blank" rel="noreferrer noopener">https://bit.ly/3rWkb5h</a></figcaption></figure>



<p>Taking into account the capital cost of construction of a network and the limited population of Belarus, it was decided to create <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">one single infrastructure operator</mark></strong>. beCloud operates several <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">datacenters</mark></strong> and has a wide <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">network</mark></strong> inside Belarus, and sells the bandwidth to other operators</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-23.png" alt="" class="wp-image-3009" width="389" height="316" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-23.png 829w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-23-300x244.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-23-768x623.png 768w" sizes="(max-width: 389px) 100vw, 389px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3S4ehK6" target="_blank" rel="noreferrer noopener">https://bit.ly/3S4ehK6</a></figcaption></figure>



<p>The chief inspector of the Belarus TLD is the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">OAC &#8211; Operational and Analytical Center</mark></strong></p>



<figure class="wp-block-image size-large is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-9-1024x617.png" alt="" class="wp-image-2982" width="497" height="299" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-9-1024x617.png 1024w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-9-300x181.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-9-768x463.png 768w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-9.png 1109w" sizes="(max-width: 497px) 100vw, 497px" /><figcaption class="wp-element-caption"><a href="https://oac.gov.by/" target="_blank" rel="noreferrer noopener">https://oac.gov.by/</a></figcaption></figure>



<p>There is much <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">controversy</mark></strong> about this agency. A son of Lukashenko had been appointed director some years ago</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-24.png" alt="" class="wp-image-3011" width="364" height="187" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-24.png 812w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-24-300x154.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-24-768x395.png 768w" sizes="(max-width: 364px) 100vw, 364px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3TrX9zc" target="_blank" rel="noreferrer noopener">https://bit.ly/3TrX9zc</a></figcaption></figure>



<p>Here are the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">main tasks</mark></strong> of the OAC</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-25.png" alt="" class="wp-image-3013" width="483" height="215" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-25.png 921w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-25-300x134.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-25-768x344.png 768w" sizes="(max-width: 483px) 100vw, 483px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3yIqpd4" target="_blank" rel="noreferrer noopener">https://bit.ly/3yIqpd4</a></figcaption></figure>



<p>Several agencies are subordinated to the OAC, such as the important <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">National Traffic Exchange Center (NTEC)</mark></strong></p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-28.png" alt="" class="wp-image-3026" width="361" height="180" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-28.png 816w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-28-300x150.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-28-768x383.png 768w" sizes="(max-width: 361px) 100vw, 361px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3s1rEjK" target="_blank" rel="noreferrer noopener">https://bit.ly/3s1rEjK</a></figcaption></figure>



<p>The Ministry of Telecommunications <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">controls all telecommunications</mark></strong> originating within the country through its carrier unitary enterprise, <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Beltelecom</mark></strong></p>



<p>The statistics on <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Shodan</mark></strong> show us the importance of Beltelecom as the main operator of routers and switches accross Belarus</p>



<figure class="wp-block-image size-large is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-15-1024x558.png" alt="" class="wp-image-2992" width="538" height="293" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-15-1024x558.png 1024w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-15-300x164.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-15-768x419.png 768w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-15.png 1223w" sizes="(max-width: 538px) 100vw, 538px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3EqtMZG" target="_blank" rel="noreferrer noopener">https://bit.ly/3EqtMZG</a></figcaption></figure>



<p>Beltelecom owns all the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">backbone channels</mark></strong> that link to external networks such as the one from Rostelecom in Russia</p>



<figure class="wp-block-image size-large is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-26-1024x761.png" alt="" class="wp-image-3014" width="536" height="397" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-26-1024x761.png 1024w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-26-300x223.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-26.png 1083w" sizes="(max-width: 536px) 100vw, 536px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3eAt29S" target="_blank" rel="noreferrer noopener">https://bit.ly/3eAt29S</a></figcaption></figure>



<p>While Beltelecom is in charge of the infrastructure, <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">NTEC</mark></strong> is responsible for allowing the access to the international Internet, and grants this service for a fee that is paid by Telecom operators</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-30.png" alt="" class="wp-image-3028" width="507" height="84" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-30.png 798w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-30-300x50.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-30-768x128.png 768w" sizes="(max-width: 507px) 100vw, 507px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3CWZ20b" target="_blank" rel="noreferrer noopener">https://bit.ly/3CWZ20b</a></figcaption></figure>



<p>The Belarus authorities can <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">block the internet</mark></strong> as they did in August 2020 during the elections turmoil, as you can see on the chart below</p>



<figure class="wp-block-image size-large is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-19-1024x554.png" alt="" class="wp-image-2996" width="534" height="288" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-19-1024x554.png 1024w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-19-300x162.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-19-768x416.png 768w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-19.png 1461w" sizes="(max-width: 534px) 100vw, 534px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3rVh0Lk" target="_blank" rel="noreferrer noopener">https://bit.ly/3rVh0Lk</a></figcaption></figure>



<p>In fact, the American IT company, <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Sandvine (Procera)</mark></strong>, had supplied filtering equipment for normal network operations (such as traffic optimization, congestion management, cost efficiency, anti malware&#8230;) using a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Deep Packet Inspection (DPI)</mark></strong> process, with the help of <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">resident engineers</mark></strong></p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/Capture2.png" alt="" class="wp-image-2999" width="394" height="365" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/Capture2.png 582w, https://www.forensicxs.com/wp-content/uploads/2022/10/Capture2-300x278.png 300w" sizes="(max-width: 394px) 100vw, 394px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3T5yiRo" target="_blank" rel="noreferrer noopener">https://bit.ly/3T5yiRo</a></figcaption></figure>



<p>The Sandvine equipement had been used by Belarus authorities to block legitimate traffic and <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">switch off</mark></strong> the Internet</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-27.png" alt="" class="wp-image-3015" width="477" height="148" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-27.png 771w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-27-300x93.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-27-768x239.png 768w" sizes="(max-width: 477px) 100vw, 477px" /></figure>



<p>Further to this, Sandvine decided to <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">terminate the contract</mark></strong> with Belarus : <a href="https://bit.ly/3VxIfcg" target="_blank" rel="noreferrer noopener">https://bit.ly/3VxIfcg</a></p>



<p>In Belarus, the state body <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">BelGIE</mark></strong> is responsible to manage the list of restricted IPs and traffic : <a href="https://belgie.by/en/home">https://belgie.by/en/home</a></p>



<p>Let&#8217;s check the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Name Servers</mark></strong> provided for the .by Belarus ccTLD (remind that a lot of domains in the world have multiple nameservers to increase reliability)</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th>Name Server</th><th>IP</th><th>Identity</th><th>Location</th><th>Traceroute</th></tr></thead><tbody><tr><td>dns1.tld.becloudby.com</td><td>93.125.25.72</td><td>beCloud</td><td>Belarus</td><td>UTG<br>RETN<br>NTEC<br>beCloud</td></tr><tr><td>dns2.tld.becloudby.com</td><td>93.125.25.73</td><td>beCloud</td><td>Belarus</td><td>UTG<br>RETN<br>NTEC<br>beCloud</td></tr><tr><td>dns3.tld.becloudby.com</td><td>185.98.83.4</td><td>Dataline</td><td>Russia</td><td>UTG<br>RETN<br>Dataline</td></tr><tr><td>dns4.tld.becloudby.com</td><td>184.72.17.94</td><td>Amazon AWS</td><td>USA</td><td>AWS</td></tr><tr><td>dns5.tld.becloudby.com</td><td>54.180.35.203</td><td>Amazon Technologies</td><td>USA</td><td>AWS</td></tr></tbody></table><figcaption class="wp-element-caption"><a href="https://bit.ly/2wAB2B5" target="_blank" rel="noreferrer noopener">https://bit.ly/2wAB2B5</a></figcaption></figure>



<p>The main Name Servers n°1 and n°2 are hosted by <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">beCloud</mark></strong> in Belarus</p>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Ukrainian Telecommunications Group (UTG)</mark></strong> is a major Ukrainian operator, enabling some part of the traffic towards Belarus.  <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">RETN </mark></strong>is a major international network operator headquartered in UK and managing Eurasian cables going through Ukraine and Russia</p>



<p>The <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">National Traffic Exchange Center (NTEC)</mark></strong> has been seen above already, and we can confirm that the NTEC is at the center of the Internet communication from abroad Belarus</p>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Dataline</mark></strong> is an IT company located in Russia with cloud capabilities. It&#8217;s interesting to see that some backup Belarus Name Servers are hosted in <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Russia (Dataline)</mark></strong> and <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">USA (AWS)</mark></strong></p>



<p>Here below are the main <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">ISP</mark></strong> (Internet Service Providers) of Belarus :</p>



<figure class="wp-block-image size-large is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-10-1024x606.png" alt="" class="wp-image-2984" width="486" height="286"/><figcaption class="wp-element-caption"><a href="https://bit.ly/3T5TNS3" target="_blank" rel="noreferrer noopener">https://bit.ly/3T5TNS3</a></figcaption></figure>



<p>Internet usage in Belarus is about <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">82%</mark></strong>, as we can find here : <a rel="noreferrer noopener" href="https://bit.ly/3CjOKqz" target="_blank">https://bit.ly/3CjOKqz</a>. It is similar as the one of France</p>



<p>The mobile networks <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">2G/3G/4G</mark></strong> are quite widespread, with a stronger concentration of these networks around major cities</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-6.png" alt="" class="wp-image-2978" width="446" height="320" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-6.png 878w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-6-300x216.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-6-768x553.png 768w" sizes="(max-width: 446px) 100vw, 446px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3RFEQVO" target="_blank" rel="noreferrer noopener">https://bit.ly/3RFEQVO</a></figcaption></figure>



<p>The mobile network <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">5G</mark></strong> is not yet deployed, but activities are on-going to implement this latest standard</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-7.png" alt="" class="wp-image-2979" width="450" height="347" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-7.png 660w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-7-300x231.png 300w" sizes="(max-width: 450px) 100vw, 450px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3Eq7APc" target="_blank" rel="noreferrer noopener">https://bit.ly/3Eq7APc</a></figcaption></figure>



<p>The overall <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">efficiency</mark></strong> of the Belarus network is not that great, probably due to a lower coverage in rural areas</p>



<figure class="wp-block-image size-large is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-18-1024x568.png" alt="" class="wp-image-2995" width="455" height="251" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-18-1024x568.png 1024w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-18-300x166.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-18-768x426.png 768w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-18.png 1147w" sizes="(max-width: 455px) 100vw, 455px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3CGAzNA" target="_blank" rel="noreferrer noopener">https://bit.ly/3CGAzNA</a></figcaption></figure>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Operational and Analytical Center</mark></strong></p>



<p>Let&#8217;s go deeper on the OAC &#8211; chief inspector of the Belarus TLD &#8211; that we have seen above : <a rel="noreferrer noopener" href="https://bit.ly/3gVNzGH" target="_blank">https://bit.ly/3gVNzGH</a></p>



<p>First of all, you shall know that the OAC is entitled by Law to restrict internet, in case of threats to National Security : <a href="https://bit.ly/3TrZaei" target="_blank" rel="noreferrer noopener">https://bit.ly/3TrZaei</a></p>



<p>We can use several <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">footprinting</mark></strong> and <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">recon</mark></strong> tools for that. Let&#8217;s go through the findings using some of these tools</p>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-red-color">urlscan.io</mark></strong> : <a href="https://bit.ly/3sG0S0m" target="_blank" rel="noreferrer noopener">https://bit.ly/3sG0S0m</a></p>



<p>The main IP is 195.50.4.123, located in Minsk, and belongs to BCTBY-AS, which is Belarusian Cloud Technologies, as seen above. The site takes advantage of the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Google web tracking</mark></strong> technologies, helping the webmaster to perform <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">analytics</mark></strong></p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-31.png" alt="" class="wp-image-3033" width="397" height="238" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-31.png 536w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-31-300x180.png 300w" sizes="(max-width: 397px) 100vw, 397px" /></figure>



<p>Google Tag Manager (GTM) has been interesting for hackers, as JavaScript can be embedded inside GTM containers and is executed when a browser loads the link to a container : <a href="https://bit.ly/3Nihfd4" target="_blank" rel="noreferrer noopener">https://bit.ly/3Nihfd4</a></p>



<p>Doubleclick (<a rel="noreferrer noopener" href="https://bit.ly/3sGfQn9" target="_blank">https://bit.ly/3sGfQn9</a>) now belongs to Google and is part of the Google Marketing tools</p>



<p>With all these Google technology embedded inside their website, the admin have a good way to <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">track user</mark></strong> navigation on their website</p>



<p>We can read the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Javascript global variables</mark></strong>, here below</p>



<figure class="wp-block-image size-large is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-33-1024x186.png" alt="" class="wp-image-3038" width="698" height="126" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-33-1024x186.png 1024w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-33-300x54.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-33-768x139.png 768w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-33.png 1131w" sizes="(max-width: 698px) 100vw, 698px" /></figure>



<p>Apart from usual Javascript events, we can confirm the Google analytics and tag manager, already mentioned above. In addition, we find the NS_CSM, which are <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Citrix</mark></strong> variables standing for <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Client Side Measurement</mark></strong></p>



<p>The CSM is the console included in the Citrix WAF (Web Application Firewall), allowing the Admin to monitor any security events. Here a sample screenshot of the interface</p>



<figure class="wp-block-image size-full"><img decoding="async" width="982" height="549" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-32.png" alt="" class="wp-image-3037" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-32.png 982w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-32-300x168.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-32-768x429.png 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3NmBIgN" target="_blank" rel="noreferrer noopener">https://bit.ly/3NmBIgN</a></figcaption></figure>



<p>Basically, the Citrix WAF works as follows</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-37.png" alt="" class="wp-image-3042" width="372" height="452" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-37.png 670w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-37-247x300.png 247w" sizes="(max-width: 372px) 100vw, 372px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3DHGjXP" target="_blank" rel="noreferrer noopener">https://bit.ly/3DHGjXP</a></figcaption></figure>



<p>The Citrix WAF is based upon a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">cookie</mark></strong> derived from the web client session : <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">citrix_ns_id</mark></strong></p>



<p>In fact, to maintain the state of the session, the Citrix Web App Firewall generates its own session cookie, and passes it only between the web browser and the Citrix Web Application Firewall, and <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">not to the web server</mark></strong></p>



<p>This will ensure that if any hacker tries to modify the session cookie, the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">WAF will drop</mark></strong> the current session, and the WAF will <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">keep the information</mark></strong> of the URLs and forms visited by the client</p>



<p>Here further details about how this Citrix WAF is working : <a href="https://bit.ly/3UeJ4p7" target="_blank" rel="noreferrer noopener">https://bit.ly/3UeJ4p7</a></p>



<p>Here below <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">all cookies</mark></strong> generated by the website :</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="759" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-34-1024x759.png" alt="" class="wp-image-3039" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-34-1024x759.png 1024w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-34-300x222.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-34-768x569.png 768w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-34.png 1069w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></figure>



<p>Beyond the citrix_ns_id, we find the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">citrix_bot_id cookie</mark></strong>. This allows the Admin to implement <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Bot management policies</mark></strong>, to block malicious bots : <a href="https://bit.ly/3U62hd3" target="_blank" rel="noreferrer noopener">https://bit.ly/3U62hd3</a></p>



<p>We also see the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">XSRF token</mark></strong> (see here a definition : <a rel="noreferrer noopener" href="https://bit.ly/3DIOz9Y" target="_blank">https://bit.ly/3DIOz9Y</a>), which will help protect against <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">web sites forgeries</mark></strong></p>



<p>Beyond these cookies, we can see some basic <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">web hacking protections</mark></strong></p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-35.png" alt="" class="wp-image-3040" width="534" height="77" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-35.png 852w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-35-300x44.png 300w" sizes="(max-width: 534px) 100vw, 534px" /></figure>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">nosniff</mark></strong> will help protect against MIME sniffing</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-38.png" alt="" class="wp-image-3043" width="433" height="165" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-38.png 626w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-38-300x114.png 300w" sizes="(max-width: 433px) 100vw, 433px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3Ud9Wpc" target="_blank" rel="noreferrer noopener">https://bit.ly/3Ud9Wpc</a></figcaption></figure>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">SAMEORIGIN</mark></strong> will block iframe inclusions that are not from the same web site origin</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-39.png" alt="" class="wp-image-3044" width="407" height="184" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-39.png 615w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-39-300x136.png 300w" sizes="(max-width: 407px) 100vw, 407px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3U84Hav" target="_blank" rel="noreferrer noopener">https://bit.ly/3U84Hav</a></figcaption></figure>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">1; mode=block</mark></strong> will prevent XSS attacks</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-40.png" alt="" class="wp-image-3045" width="438" height="243" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-40.png 768w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-40-300x167.png 300w" sizes="(max-width: 438px) 100vw, 438px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/2GWk0zR" target="_blank" rel="noreferrer noopener">https://bit.ly/2GWk0zR</a></figcaption></figure>



<p>Created for browsers equipped with XSS filters, this non-standard header was intended as a way to control the filtering functionality. Since modern browsers no longer use XSS filtering, this header is now <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">deprecated</mark></strong></p>



<p>We can see that the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">server is an nginx</mark></strong> dealing http requests on the port 443 (as expected)</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-41.png" alt="" class="wp-image-3046" width="316" height="285" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-41.png 615w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-41-300x270.png 300w" sizes="(max-width: 316px) 100vw, 316px" /></figure>



<p>The website is protected by <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">TLS1.3</mark></strong> and AES256</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-42.png" alt="" class="wp-image-3047" width="283" height="154" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-42.png 518w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-42-300x163.png 300w" sizes="(max-width: 283px) 100vw, 283px" /></figure>



<p>The website has an encryption certificate delivered by <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Let&#8217;s Encrypt</mark></strong></p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/10/image-46.png" alt="" class="wp-image-3051" width="481" height="274" srcset="https://www.forensicxs.com/wp-content/uploads/2022/10/image-46.png 624w, https://www.forensicxs.com/wp-content/uploads/2022/10/image-46-300x171.png 300w" sizes="(max-width: 481px) 100vw, 481px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3SOxYpK" target="_blank" rel="noreferrer noopener">https://bit.ly/3SOxYpK</a></figcaption></figure>



<p>Some people have <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">criticized</mark></strong> the fact that Let&#8217;s Encrypt provides CERT services to Belarus. But in fact, they validate only that the server has the proven control over the domain name you are visiting. And beyond that, blocking US CERT would probably push Belarus to implement <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Russian government Certificate of Authority</mark></strong>, with all potential risks for the end users : <a rel="noreferrer noopener" href="https://bit.ly/3U8wA2i" target="_blank">https://bit.ly/3U8wA2i</a></p>



<p>For the following analysis, check this reminder about <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">DNS</mark></strong> here : <a rel="noreferrer noopener" href="https://bit.ly/3E0FmtV" target="_blank">https://bit.ly/3E0FmtV</a>, and also here : <a rel="noreferrer noopener" href="https://bit.ly/3FOpETN" target="_blank">https://bit.ly/3FOpETN</a></p>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-red-color">BuiltWith Technology Profiler</mark></strong> : <a href="https://bit.ly/3hB2JBy" target="_blank" rel="noreferrer noopener">https://bit.ly/3hB2JBy</a></p>



<p>We can find more details about the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">front-end</mark></strong>, mainly the use of <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Javascript Framework</mark></strong></p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-13.png" alt="" class="wp-image-3074" width="557" height="162" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-13.png 700w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-13-300x87.png 300w" sizes="(max-width: 557px) 100vw, 557px" /></figure>



<p>We can also find more details about the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">back-end</mark></strong> server</p>



<p>It seems that the server is <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">probably</mark></strong> built using <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">PHP</mark></strong> version 7 or above (but this has not been detected since 2021 so it may have been replaced by another)</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-11.png" alt="" class="wp-image-3072" width="572" height="71" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-11.png 723w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-11-300x38.png 300w" sizes="(max-width: 572px) 100vw, 572px" /></figure>



<p>The server has a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Sender Policy Framework (SPF)</mark></strong>, which enables receiving mail servers to authenticate whether an email message was sent from an authorized mail server (spam and spoofing protection)</p>



<p>The server is based upon <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Nginx</mark></strong>. Previously, it was based upon<strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color"> Apache</mark></strong> (year 2019), and the OS was <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Debian</mark></strong> (year 2017)</p>



<p>We will see below that it&#8217;s now <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">probably</mark></strong> running <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">FreeBSD</mark></strong> (<a rel="noreferrer noopener" href="https://bit.ly/3AbZqaf" target="_blank">https://bit.ly/3AbZqaf</a>)</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-12.png" alt="" class="wp-image-3073" width="573" height="248" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-12.png 704w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-12-300x130.png 300w" sizes="(max-width: 573px) 100vw, 573px" /></figure>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-red-color">whois</mark></strong></p>



<p>Let&#8217;s run a whois against the IP address 195.50.4.123</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-7.png" alt="" class="wp-image-3066" width="524" height="563" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-7.png 744w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-7-279x300.png 279w" sizes="(max-width: 524px) 100vw, 524px" /></figure>



<p>We confirm that the IP is owned by Belarusian Cloud Technologies LLC, as seen above. There are two contact people, that we can cross check on social networks. We find the Linkedin profile of Andrey Chepikov, which states an experience at &#8220;protection of networks <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">against external influences</mark></strong>&#8220;</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-8.png" alt="" class="wp-image-3067" width="406" height="312" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-8.png 846w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-8-300x231.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-8-768x592.png 768w" sizes="(max-width: 406px) 100vw, 406px" /></figure>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-red-color">dnsrecon</mark></strong> : <a rel="noreferrer noopener" href="https://bit.ly/3sN1txp" target="_blank">https://bit.ly/3sN1txp</a></p>



<p>This tool does a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">DNS enumeration</mark></strong>. We find the basic informations about the domain oac.gov.by (MX : Mail Server, A : IP address, TXT : Text record). The Sender Policy Framework (SPF) is configured (v=spf1 -all) , so that only this server can send emails on behalf of the domain</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image.png" alt="" class="wp-image-3055" width="615" height="135" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image.png 782w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-300x66.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-768x169.png 768w" sizes="(max-width: 615px) 100vw, 615px" /></figure>



<p>To use Google Analytics, you need to prove that you own the domain. That&#8217;s why the Admin added a TXT record to prove this, with <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">google-site-verification</mark></strong>. Here is how you can confirm your domain ownership : <a rel="noreferrer noopener" href="https://bit.ly/3NE66DR" target="_blank">https://bit.ly/3NE66DR</a></p>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-red-color">dig</mark></strong> : <a href="https://bit.ly/3FTE3hT" target="_blank" rel="noreferrer noopener">https://bit.ly/3FTE3hT</a></p>



<p>We can check if the domain has <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">DNSSEC</mark></strong> implemented. In this case, it is <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">not enabled</mark></strong></p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-9.png" alt="" class="wp-image-3068" width="496" height="290" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-9.png 636w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-9-300x175.png 300w" sizes="(max-width: 496px) 100vw, 496px" /></figure>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-red-color">dnshistory</mark></strong> : <a rel="noreferrer noopener" href="https://bit.ly/3SPbxkc" target="_blank">https://bit.ly/3SPbxkc</a></p>



<p>We can see that the domain has historical records dating from <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">December 2012</mark></strong></p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-2.png" alt="" class="wp-image-3058" width="525" height="499" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-2.png 920w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-2-300x286.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-2-768x731.png 768w" sizes="(max-width: 525px) 100vw, 525px" /></figure>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-red-color">Linkedin</mark></strong></p>



<p>We can find some interesting informations on this social network, such as technologies that the OAC may be actively using :</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-10.png" alt="" class="wp-image-3071" width="519" height="419" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-10.png 814w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-10-300x243.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-10-768x622.png 768w" sizes="(max-width: 519px) 100vw, 519px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3G6xrMW" target="_blank" rel="noreferrer noopener">https://bit.ly/3G6xrMW</a></figcaption></figure>



<p>We can therefore correlate some technical evidences we had found in the previous sections, which increases the probability that the OAC actually uses these technologies</p>



<p>We can therefore assume the following architecture :</p>



<ul class="wp-block-list">
<li>Javascript <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Vue.js</mark></strong> Frameworks for the Front-End</li>



<li><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">PHP Laravel</mark></strong>, Node.js, React.js Frameworks for the Back-End</li>



<li><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">PostgreSQL</mark></strong>, <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">MongoDB</mark></strong> for the database management</li>
</ul>



<p>The softwares and services are <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">probably</mark></strong> based upon a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Cloud Native</mark></strong>  architecture :</p>



<ul class="wp-block-list">
<li><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">VMware</mark></strong> (Virtual Machines)</li>



<li><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Kubernetes</mark></strong> k8s (to manage containerized applications across multiple hosts)</li>



<li><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Gitlab CI</mark></strong> (Continuous Integration) </li>



<li><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">CEPH</mark></strong> as a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">distributed storage system</mark></strong> (<a rel="noreferrer noopener" href="https://bit.ly/3Emillf" target="_blank">https://bit.ly/3Emillf</a>)</li>
</ul>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-red-color">p0f</mark></strong> : <a href="https://bit.ly/3AbaEMb" target="_blank" rel="noreferrer noopener">https://bit.ly/3AbaEMb</a></p>



<p>p0f &#8211; <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">passive operating system fingerprinting</mark></strong> &#8211; can be used to detect the server Operating System (OS). It will detect how the OS implements the TCP/IP stack</p>



<p>In our case, I find that the server machine is based upon <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Windows XP</mark></strong></p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-14.png" alt="" class="wp-image-3077" width="432" height="205" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-14.png 588w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-14-300x142.png 300w" sizes="(max-width: 432px) 100vw, 432px" /></figure>



<p>Is it weird to find such an outdated version of Windows ? Not quite. Some organizations are still using XP nowadays. For example, the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Belarus railway system is using Windows XP</mark></strong>, as it was shown to the world during the invasion of Russia into Ukraine (<a rel="noreferrer noopener" href="https://bit.ly/3GbVrhG" target="_blank">https://bit.ly/3GbVrhG</a>)</p>



<p>In addition, Microsoft has decided to <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">block new Windows licence</mark></strong> to Belarus and Russia (<a rel="noreferrer noopener" href="https://bit.ly/3Trb5Ja" target="_blank">https://bit.ly/3Trb5Ja</a>), this will not help Belarus to move to more recent versions</p>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-red-color">Zenmap</mark></strong></p>



<p>We are going to find additional informations with Zenmap (in fact, it is a GUI version of <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">nmap</mark></strong> : <a rel="noreferrer noopener" href="https://bit.ly/2Hlfc7P" target="_blank">https://bit.ly/2Hlfc7P</a>)</p>



<p>The first one is the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">TCP Sequence Prediction </mark></strong>(difficulty = 251 in our case), which is a measure of the risk that a TCP connection can be hijacked by an attacker, predicting the sequence number and preparing a faked packet (you can learn more about sequence number here <a rel="noreferrer noopener" href="https://bit.ly/3G9JPMb" target="_blank">https://bit.ly/3G9JPMb</a> and also here <a rel="noreferrer noopener" href="https://bit.ly/3EsStUZ" target="_blank">https://bit.ly/3EsStUZ</a>)</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-19.png" alt="" class="wp-image-3084" width="400" height="28" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-19.png 458w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-19-300x21.png 300w" sizes="(max-width: 400px) 100vw, 400px" /></figure>



<p>We find the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">open Ports</mark></strong> and more technical informations about hardware used</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-17.png" alt="" class="wp-image-3082" width="651" height="80" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-17.png 816w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-17-300x37.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-17-768x95.png 768w" sizes="(max-width: 651px) 100vw, 651px" /></figure>



<p>The open Ports <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">80</mark></strong> (HTTP) and <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">443</mark></strong> (HTTPS) are typical for a Web Server</p>



<p>We find a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Citrix NetScaler, </mark></strong>which is an Application Delivery Controller (<strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">ADC</mark></strong>) created to optimize, manage, and secure network traffic : <a rel="noreferrer noopener" href="https://bit.ly/3X1Coww" target="_blank">https://bit.ly/3X1Coww</a>. This includes the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Citrix WAF</mark></strong> we have seen earlier</p>



<p>It is also <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">probable</mark></strong> that this ADC is acting as a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Citrix VPX Load Balancer</mark></strong>. A typical network topology would be as follows (VIP = virtual server IP), with internal machines hidden behind the Citrix ADC :</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-22.png" alt="" class="wp-image-3092" width="398" height="254" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-22.png 815w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-22-300x192.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-22-768x492.png 768w" sizes="(max-width: 398px) 100vw, 398px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3Ac5n7n" target="_blank" rel="noreferrer noopener">https://bit.ly/3Ac5n7n</a></figcaption></figure>



<p>Zenmap provides <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">probable</mark></strong> <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">infrastructure</mark></strong> informations (with % of probability) :</p>



<ul class="wp-block-list">
<li>Citrix NetScaler VPX load balancer (89%) : as seen above</li>



<li>Linksys BEFSR41 EtherFast router (86%) : it&#8217;s a basic network <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">router</mark></strong></li>



<li>AVtech Room Alert 26W environmental monitor (86%)  : server room real time <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">monitoring</mark></strong> of temperature, humidity,&#8230;</li>



<li>FreeBSD 6.2-Release (85%) : it&#8217;s <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">probable</mark></strong> that the server is based upon <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">FreeBSD 6.2</mark></strong>. If true, this is quite an outdated version. We can check the version 6.3 release notes to get an overview of the bugs in 6.2 : <a href="https://bit.ly/3UQUhMH" target="_blank" rel="noreferrer noopener">https://bit.ly/3UQUhMH</a></li>
</ul>



<p>Let&#8217;s compare with a direct OS discover using <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">nmap</mark></strong></p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-21.png" alt="" class="wp-image-3091" width="550" height="144" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-21.png 695w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-21-300x79.png 300w" sizes="(max-width: 550px) 100vw, 550px" /></figure>



<p>nmap provides us with a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">probable</mark></strong> guess, that FreeBSD 6.2 is based upon the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Virtual Machine Oracle Virtualbox</mark></strong></p>



<figure class="wp-block-image size-full"><img decoding="async" width="917" height="100" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-20.png" alt="" class="wp-image-3090" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-20.png 917w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-20-300x33.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-20-768x84.png 768w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></figure>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-red-color">Web security</mark></strong></p>



<p>We can dig a bit deeper if the web site is well protected, using a vulnerability scanner, such as <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Wapiti</mark></strong> : <a rel="noreferrer noopener" href="https://bit.ly/3VxDZss" target="_blank">https://bit.ly/3VxDZss</a></p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="181" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-23-1024x181.png" alt="" class="wp-image-3097" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-23-1024x181.png 1024w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-23-300x53.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-23-768x135.png 768w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-23-1536x271.png 1536w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-23.png 1667w" sizes="(max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 543px, 580px" /></figure>



<p>We get the following report :</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-24.png" alt="" class="wp-image-3098" width="510" height="635" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-24.png 582w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-24-241x300.png 241w" sizes="(max-width: 510px) 100vw, 510px" /></figure>



<p>Let&#8217;s go through the results :</p>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-25.png" alt="" class="wp-image-3099" width="487" height="149" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-25.png 1024w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-25-300x92.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-25-768x236.png 768w" sizes="(max-width: 487px) 100vw, 487px" /></figure>



<p>The <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Content Security Policy header (CSP)</mark></strong> lets you precisely control permitted content sources and many other content parameters, and is a recommended way to protect your websites and applications against XSS attacks. A basic CSP header to allow only assets from the local origin is :</p>



<pre class="wp-block-code"><code>Content-Security-Policy: default-src 'self'</code></pre>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-29.png" alt="" class="wp-image-3105" width="497" height="153" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-29.png 755w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-29-300x93.png 300w" sizes="(max-width: 497px) 100vw, 497px" /><figcaption class="wp-element-caption"><a href="https://bit.ly/3XNY002" target="_blank" rel="noreferrer noopener">https://bit.ly/3XNY002</a></figcaption></figure>



<figure class="wp-block-image size-full is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-26.png" alt="" class="wp-image-3100" width="485" height="138" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-26.png 1024w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-26-300x86.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-26-768x220.png 768w" sizes="(max-width: 485px) 100vw, 485px" /></figure>



<p>When enabled on the server, the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">HTTP Strict Transport Security header (HSTS)</mark></strong> enforces the use of encrypted HTTPS connections instead of plain-text HTTP communication. A typical HSTS header might look like this:</p>



<pre class="wp-block-code"><code>Strict-Transport-Security: max-age=63072000; includeSubDomains; preload</code></pre>



<p>This informs any visiting web browser that the site and all its subdomains uses only SSL/TLS communication, and that the browser should default to accessing it over <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">HTTPS</mark></strong> for the next two years (the <code>max-age</code> value in seconds)</p>



<p>The <code>preload</code> directive indicates that the site is present on a global list of HTTPS-only sites. The purpose of preloading is to speed up page loads and eliminate the risk of <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">man-in-the-middle (MITM)</mark></strong> attacks when a site is visited for the first time</p>



<figure class="wp-block-image size-large is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-27-1024x781.png" alt="" class="wp-image-3101" width="484" height="369" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-27-1024x781.png 1024w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-27-300x229.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-27-768x585.png 768w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-27.png 1039w" sizes="(max-width: 484px) 100vw, 484px" /></figure>



<p>An <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">HttpOnly Cookie</mark></strong> is a tag added to a browser cookie, that prevents client-side scripts from accessing data. Using the HttpOnly tag when generating a cookie helps mitigate the risk of client-side scripts accessing the protected cookie, thus making these cookies more secure.</p>



<p>The example below shows the syntax used within the HTTP response header :</p>



<p>Set-Cookie: <code>=“[; “=“]</code> <code>[; expires=“][; domain=“]</code> <code>[; path=“][; secure][; HttpOnly]</code></p>



<p>If the HttpOnly flag is included in the HTTP response header, the cookie cannot be accessed through the client-side script. As a result, even if a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">cross-site scripting (XSS) flaw</mark></strong> exists, and a user accidentally accesses a link that exploits the flaw, the browser will not reveal the cookie to the third-party</p>



<figure class="wp-block-image size-large is-resized"><img decoding="async" src="https://www.forensicxs.com/wp-content/uploads/2022/11/image-28-1024x806.png" alt="" class="wp-image-3102" width="486" height="382" srcset="https://www.forensicxs.com/wp-content/uploads/2022/11/image-28-1024x806.png 1024w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-28-300x236.png 300w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-28-768x604.png 768w, https://www.forensicxs.com/wp-content/uploads/2022/11/image-28.png 1042w" sizes="(max-width: 486px) 100vw, 486px" /></figure>



<p>The <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Secure flag</mark></strong> is used to declare that the cookie may only be transmitted using a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">secure connection</mark></strong> (SSL/HTTPS). If this cookie is set, the browser will never send the cookie if the connection is HTTP. This flag prevents cookie theft via <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">man-in-the-middle attacks</mark></strong></p>



<p>It would be good practice to enable the above <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">security flags</mark></strong>, thus complying with the OWASP recommendations. However, I assume that the OAC is not so concerned, as the website does not include many rich content, and a powerfull <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">WAF</mark></strong> is already implemented</p>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Belarus web infrastructure in summary</mark></strong></p>



<p>Let&#8217;s summarize the infrastructure that we have seen above</p>



<figure class="wp-block-table"><table><thead><tr><th>Entity</th><th>Key observation</th><th>Comment</th></tr></thead><tbody><tr><td>Belarus TLD</td><td>Name Servers are hosted in several countries</td><td>Belarus (beCloud), Russia (Dataline), USA (AWS)</td></tr><tr><td>beCloud</td><td>Sovereign Cloud and Internet infrastructure</td><td>Built with the support of many international corporations</td></tr><tr><td>oac.gov.by</td><td>IP owned by Belarusian Cloud Technologies</td><td>State owned Beltelecom has control over most of the Internet infrastructure</td></tr><tr><td>oac.gov.by</td><td>Chief inspector of the Belarus TLD</td><td>Entitled by Law to restrict internet, in case of threats to National Security</td></tr><tr><td>BelGIE</td><td>Responsible to optimize the traffic and filter IP addresses as per the need</td><td>DPI (Deep Packet Inspection) as per the need. Got support from Sandvine in the past for traffic optimization (including filtering)</td></tr><tr><td>oac.gov.by</td><td>Performs analytics using Google web tracking</td><td>Google Tag Manager, Doubleclick</td></tr><tr><td>oac.gov.by</td><td>WAF and Load Balancer implemented using Citrix</td><td>Citrix NetScaler<br>Citrix VPX Load Balancer</td></tr><tr><td>oac.gov.by</td><td>Encryption of the website using TLS1.3 and AES256</td><td>Certificate issued by Let&#8217;s Encrypt</td></tr><tr><td>oac.gov.by</td><td>Web server machine</td><td>The web server may use a Windows XP machine, with an nginx server</td></tr><tr><td><br>oac.gov.by</td><td>Web server OS</td><td>Managed by a FreeBSD controller, built upon an Oracle VM Virtual Box</td></tr><tr><td>oac.gov.by</td><td>Web security</td><td>Some usual basic security flags are missing, but the website is protected using a WAF</td></tr></tbody></table></figure>



<p><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">Conclusion</mark></strong></p>



<p>In this short preview of the Belarus web infrastructure, we have seen the following items, using <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">footprinting</mark></strong> methods :</p>



<ul class="wp-block-list">
<li>Belarus has built a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">sovereign cloud</mark></strong> to manage its web infrastructure, with the help of <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">international corporations</mark></strong> (US, Europe, Asia,..)</li>



<li>The Belarus Name Server is backed-up by <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">AWS</mark></strong> (USA) and <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Dataline</mark></strong> (Russia)</li>



<li>The Belarus authorities have a <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">strong degree of control</mark></strong> over access points and can block any IP traffic if necessary (such as during the August 2020 elections turmoil)</li>



<li>The Operational and Analytical Center (OAC) is the <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">chief inspector</mark></strong> of the Belarus Top Level Domain (TLD)</li>



<li>The OAC website performs analytics using <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Google web tracking</mark></strong> technology</li>



<li>The OAC website is protected with the use of <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Citrix</mark></strong> technology (WAF, Load Balancer), and its root certificate is issued by <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Let&#8217;s Encrypt</mark></strong></li>



<li>The OAC web server <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-vivid-cyan-blue-color">may</mark></strong> be based upon an <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">obsolete version of Windows (XP)</mark></strong> and does not comply with all the basic <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">OWASP</mark></strong> recommendations</li>



<li>The <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">restrictions applied to Belarus</mark></strong> by some US corporations such as <strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Microsoft</mark></strong> will limit their ability to implement security patches and updates</li>



<li><strong><mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-luminous-vivid-orange-color">Linkedin profiles</mark></strong> are always a good way to learn more about the technologies used by a target</li>
</ul>



<p><br></p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.forensicxs.com/belarus-and-the-web/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Database Caching 3/48 queries in 0.033 seconds using Disk

Served from: www.forensicxs.com @ 2025-12-25 09:24:56 by W3 Total Cache
-->