Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label Chrome/Chromium. Show all posts
Showing posts with label Chrome/Chromium. Show all posts

Sunday, April 28, 2013

Browsers Browsers Everywhere!

Posted on 2:03 PM by Unknown

…and in browser news and trends, things are getting pretty interesting…

Firefox/Mozilla

  • Firefox turns 20—version 20, that is - Ars Technica
  • Firefox 20.0: Find out what is new - GHacks.net
  • New In Firefox 20: Private Window, Improved Download Manager & More - AddictiveTips blog
  • Download Manager Tweak - Firefox Extension Guru's Blog. I actually like the new Download Manager feature a lot, still haven’t yet shed my Download Statusbar Add-on in Firefox. But I probably could and likely will.
  • Download Manager Tweak - Firefox Extension Guru's Blog
  • Samsung teams up with Mozilla to build browser engine for multicore machines - Ars Technica
  • Mozilla and Samsung team up to kill Chrome mobile - BetaNews
  • Newsfox: 1.0.8.4.2 - RSS reader Add-on for Firefox just got some updates. Release notes 
  • Firefox Stub Installer on Beta Channel - Firefox Extension Guru's Blog. As The Guru points out, newer versions of Mozilla Beta/nightly releases download a small “stub” and than then downloads and installs the main binary sets over the wire. This does keep initial download sizes low, but also can wreak havoc on controlling custom deployments of some of these packages. Chrome does the same thing and they also “hide” their Chromium Dev download sources very well so now I have ended up dropping over to PortableApps.com: Google Chrome Portable/Additional Versions at SourceForge.net to snag and apply my portable Dev builds. Not impressed…especially now that Mozilla is rolling that direction as well. More info here on the Mozilla nightly stub-installer background if you are curious: Mozilla Adds Chrome-Like Downloader to Streamline Firefox Installs - TheNextWeb & Stub Installer in Firefox Nightly – Try it out, Give feedback, and Test it! - QMO – quality.mozilla.org
  • Firefox prefetching: what you need to know - Firefox Extension Guru's Blog - Great tweaking tips from The Guru.

…meanwhile over at the other hot-rod shop…

  • Google going its own way, forking WebKit rendering engine - Ars Technica
  • Blink: A rendering engine for the Chromium project - Chromium Blog
  • Does WebKit face a troubled future now that Google is gone? - Ars Technica
  • Blink - The Chromium Projects

Sadly, I remain terribly frustrated that Chrome developers just will not add a “sidebar” feature for bookmark management to Chrome like Mozilla has. This is a soapbox I just can’t seem to climb down from with Chrome. Again I say, if it were not for this one missing feature, I might jump to using Chrome/Chromium as my primary browser and relegate Firefox to the #2 slot.

The closest “solution” I have found are tree-style tab organizers…but the drawback of them is having to leave the tabs open.  Something I don’t like doing.

Sigh.

  • Get A Tree Style View Of Chrome Tabs; Group & Hibernate Them - AddictiveTips blog. 
  • Sidewise Tree Style Tabs - Chrome Web Store
  • Tabs Outliner: the ultimate Chrome tab management extension? - GHacks blog
  • Tabs Outliner - Chrome Web Store

Finally…it’s a bit older post, but I really found this post by Alex Limi very fascinating from a power user’s standpoint in using a browser. I don’t at all like the idea of removing control and configuration settings from access. That said, as a sysadmin, you can certain spend many frustrating hours troubleshooting a user’s web-experience problems before finding a buried browser setting that was causing the issue.

  • Checkboxes that kill your product — Alex Limi

Cheers,

--Claus Valca

Read More
Posted in browsers, Chrome/Chromium, Firefox | No comments

Saturday, January 12, 2013

Thoughts on Chrome(ium) Privacy Attainment

Posted on 12:31 PM by Unknown

It is no secret to GSD blog fans that I’m a heavy supporter/user of Firefox browser. It remains my primary workhorse for web surfing. Updates come pretty steadily and performance and stability issues haven’t been an issue for me. Plus the specialized add-ons I use make it super-handy.

That said, the Google Chrome -- specifically Chromium Dev build -- is the browser I launch when I want to do mindless web surfing, or leave a full-screen web-page up while I am monitoring something specific.

When I help a friend/family-member set up a new system, I always install and give a walkthrough of Chrome. More times than not they quickly come to prefer it over Internet Explorer.

In fact, one of the only reasons I don’t use Chrome(ium) more is the continued (and probably “forever”) lack of a bookmark-sidebar option that Firefox has.  With my personal bookmarking/blogging habits, that feature is a “must-have.” Lacking that, hard-core regular usage of Chrome remains an exercise in frustration.  More on my attempts to overcome this in a follow-up post.

On my system I have kept two (portable) build versions of Chrome; Chromium (Dev) and SRWare Iron.

I use and prefer Chromium builds because they are updated quite frequently. I have been a long user of SRWare Iron because the developer has offered out a list of specific privacy feature enhancements under the hood that you don’t get with Chrome versions.

Additionally, there is Comodo Dragon Web Browser also based on Chrome and providing some additional security/privacy features. However I don’t use this version.

Chrome Flavors - Full Install versions

These versions will install a “full” version directly onto your Windows system

  • Chrome Browser - Download current Chrome browser release version
  • Chromium - The Chromium Projects (overview)
  • Download Chromium - Download current Chromium browser release version
  • SRWare Iron - Download a “privacy-enhanced” version build of Chromium
  • Dragon Internet Browser - Download a “privacy-enhanced” version build of Chromium; includes “Domain Validation” feature from Comodo, cookie/web-tracking & browser download tracking for privacy.

Chrome Flavors - Portable versions

These “no-install” versions allow you to take your Chrome-browser with you on a USB stick…or if you just want to run it locally without installing onto your Windows system.

  • Google Chrome Portable - PortableApps.com.  The main version level is right there at the top. This is the “mainstream” Chrome version. Scroll down a bit on the page and you will find  additional download links for portable versions of Chromium (Dev) and Beta release versions. This is the source of the Portable Chromium (Dev) package I use/update.
  • Chromium Portable - This is another portable Chromium (Dev) package another group maintains.
  • Iron Portable - Download the PortableApps.com version of SRWare Iron
  • SRWare Iron - Look carefully and there is portable version (zip) offered on the developer’s download page.
  • Comodo Dragon Portable - Basically this forum tip says to just download the regular version and pay attention to choose the “portable” version install option while doing so.
  • Sandcat Browser - Syhunt. This is a specialized portable penetration-testing oriented web-browser based on the Chromium browser. Supports live HTTP Headers, request editor, fuzzer, JavaScript Executor, Lua executor, PageInfo extension, HTTP brute-force, CGI scanner scripts, and much more

Updating Challenges

I also have a bit of an OCD app updating problem. If there is a newer version out -- particularly important with browsers and browser-plugins for security reasons -- I download and apply.

This is a challenge for both my portable Chromium and portable SRWare Iron builds as they don’t have/support in-app updating. So I have to watch the webs/feeds for signals a new version is released then manually update them.

As of this post date, Chromium Dev is at 25.0.1364.29. SRWare Iron is at 23.0.1300.0.

So to remedy the issue I keep an eye open of the Chrome Release blog (via my RSS feed reader). Then I pop over and check the direct download page for the source of the particular portable version I use and snag it when it appears..usually just a few days later.

  • Chrome Releases - Chrome release notice blog
  • Google Chrome PortableApps / Additional Versions - SourceForge.net file repository downloads
  • Chromium Portable - SourceForge.net file repository downloads
  • SRWare.net • View forum - SRWare Iron Support (English) - New version releases noted at the top.

Rolling your own Privacy Build of Chrome - Overview

So, what I want to have is all the privacy enhancements of SRWare Iron but in the “current” level of Chromium (Dev) and on a regular basis. Could I manually tweak-out a Chromium installation to achieve the same (or similar) privacy gains? 

One of the nice things of SRWare Iron is that the developer does all this work for you under the hood. But if like me you are comfortable making lots of browser configuration changes manually, and don’t mind doing some research, maybe you can get to the point of having an up-to-date Chrome-based browser with most/all of the features the SRWare Iron version has.

Aside: This isn’t really meant to be a discussion on creating an “ultra-secure/private” web-browsing experience in Chrome. I’m not seeking a completely “stealth” web-browsing experience. I’m not interested in setting up proxy/TOR sessions to try to bypass network/ISP tracking, nor is it to discuss the merits of “in private” mode browsing and all that. Who really knows what/how-much deep-packet inspection and logging at ISP’s may be going on. Rather, this attempt is to reasonably minimize the number of tracking features normally encountered in standard web browsing sessions. Yes, those “features” can be used by ISP/web-sites/content-providers to “enhance” your browsing experience in serving customized web-content, advertisements, and search-results specific to your browsing habits. That may be a good thing or not depending on you perspective. I personally to prefer to pour my coffee black and then add cream/sugar/etc depending on my mood. Same with my browser.

I started looking at the list of primary feature comparisons provided by SRWare; Chrome vs Iron.

Once I was familiar with these items, I started hitting Google to see how I could make each change manually. I soon found what I was looking for.

My plan was to post a link to explain how to achieve each setting.

But then as I dug just a bit deeper, I started finding some interesting discussions about recommended security and policy settings for Chrome builds; as well as some updated comments on the relevancy of the items targeted in SRWare Iron.

So instead, I’m posting links to those as I think this approach will allow someone to better (and more easily) create a customized privacy/browsing configuration for their own Chrome usage needs.

  • Google Chrome Privacy Whitepaper - Provided by Chrome, this excellent web-page outlines just about all the most critical features in Chrome/Dev that interface with Google and/or third-party services and sites including,
    • “Ominibox” predictions - how to enable/disable
    • “Chrome Instant” - search results and in-line prediction serving/logging
    • Google search locale
    • Phishing/malware protections - how to enable/disable
    • Navigation error tips - enable/disable
    • Google Update - (and those component ID tags)
    • Installation tokens, Promotional tags/tokens
    • Usage stats and crash reports - enable/disable
  • SRWare Iron Browser - A Private Alternative To Chrome? - InsanityBit - I found this post to be very helpful in understanding the benefits that I was seeking to have in SRWare Iron. It is pretty clear the writer takes a position against SRWare Iron’s advertised benefits over stock Chrome/Chromium builds. After reading you can do additional research and come to your own conclusions. I found it very helpful and it led me to personally drop using SRWare Iron and just stick with my own tweaked-out version of Chromium.
  • Chrome vs Iron (Privacy Comparison) with Poll for Chrome users - MalwareTips forum - This discussion thread contains discussion (and content) based on the previous link. It also touches on the Dragon build version, and has some screen shots of privacy features options in Dragon.
  • Google Chrome Security Settings and Configuration Guide for Enterprise - Root777 - Ajit Gaddam has a really super post that outlines recommendations for a more secure enterprise deployment of Chrome. Even if you aren’t deploying it in an organization, I found the discussion and points super-helpful. Lots of background information. Some changes are made in Group Policy Editor, but there are tips that can be followed for manual configurations.
  • Policy List - The Chromium Projects - List of policies that Chrome refers to and uses. Note that Chrome and Chromium policy settings will have different locations in the Registry depending on build.

Rolling your own Privacy Build of Chrome - Assistive Tools and Tips

If you don’t like the idea of making a lot of manual setting and configuration changes, then there are a number of excellent utilities and Chrome extensions that can assist you with the process.

In fact, these may be the only tools and tips most average privacy tweakers of Chrome need.

  • How to remove Google Chrome installation ID for anonymous surfing? - TechTrickz - These are two older tools that remove the unique “client_id” for your chrome browser. I can’t find a direct link to Abelssoft’s UnChrome tool any longer but some download sites still have it. Chrome Privacy Protector from Aquila is still around Chrome Privacy Protector. I don’t know if these will work with “portable” versions of Chrome or not.  In fact, according to this post Chrome to ditch unique ID, sort of via The Download Blog back in 2010, this feature should now be ditched.
  • Privacy manager - Chrome Web Store - I really like this Chrome add on. It provides awesome granular control over primary privacy settings, cookie handling, and some network behavior. I can’t believe I haven’t been using this tool from the very beginning! For a deeper review, see this AddictiveTips blog post: Privacy Manager: Chrome Security Settings & Junk Data Cleaning.
  • Privacyfix by Privacychoice - Chrome Web Store - this Chrome add-on allows you to make specialized privacy setting tweaks to your Chrome browser. It is really easy to follow and does a great job explaining the options and makes it easy to change/restore the settings depending on what you need to accomplish.
  • Adblock Plus - Chrome Web Store - Block most ads in Chrome and the tacking stuff that comes with them.
  • FlashBlock - Chrome Web Store - Block Flash media from auto-launching without your permission.
  • Google Analytics Opt-out Add-on (by Google) - Chrome Web Store - Use to instruct Google Analytics JavaScript to not sent any info about the website you are on to Google Analytics. More tips and background on this particular privacy subject here: Keep Google From Tracking Your Every Move Online - How-To Geek
  • How to Optimize Google Chrome for Maximum Privacy - How-To Geek - Additional tips and info on tweaking Chrome for privacy.
  • How to Set your Google Chrome for Maximum Privacy|Set google for privacy - Hack How - Additional tips and info on tweaking Chrome for privacy.

Cheers

--Claus V.

Read More
Posted in browsers, Chrome/Chromium, Google | No comments

Saturday, September 8, 2012

Java does a “Jack and Jill”

Posted on 9:35 AM by Unknown

CC attribution: illustration "Jack and Jill" by "perpetualplum" on flickr.
Jack n Jill Mod

So here is the way I saw the Java drama roll downhill like Jack and Jill over the last two weeks from security standpoint.

So we started out safely headed up the hill to fetch our water shod with Oracle’s Java 1.7 update 6.

08/27/2012 - Starting up the hill…

  • Quick Bits about Today's Java 0-Day - ISC Diary
  • Research & Analysis of Zero-Day & Advanced Targeted Threats:Zero-Day Season is Not Over Yet - Malware Intelligence Lab from FireEye
  • Java 7 0-Day vulnerability information and mitigation - DeepEnd Research
  • Attackers Pounce on Zero-Day Java Exploit - Krebs on Security
  • Researchers: Java Zero-Day Leveraged Two Flaws - Krebs on Security

Oh noes! Jack has stumbled!

(It wasn’t really clear at first, but Java 1.6.34 was also vulnerable.)

08/30/2012 - Java Jack Recovers

Fortunately Java Jack just had a stumble, the pail and his crown are still safe after catching himself.

  • Oracle Releases Java Security Updates - ISC Diary
  • Vulnerability Note VU#636312 - Oracle Java JRE 1.7 Expression.execute() and SunToolkit.getField() fail to restrict access to privileged code - US-CERT
  • Alert for CVE-2012-4681 - Oracle
  • Java SE 7u7 AND SE 6u35 Released - F-Secure Weblog : News from the Lab
  • Oracle patches critical Java bugs used to commandeer computers -  Ars Technica

So we all rush out and download Java 1.7.7 and/or Java 1.6.35.

Whew! That was close.

08/31/2012 - Java Jack Takes a Dive bringing Jill with him

Jack…Stop looking at that frisky rabbit and getting ideas and pay attention dude! You’re about to step into some of its…

Oh snap! You did and you slipped in it.

  • Not so fast: Java 7 Update 7 critical vulnerability discovered in less than 24 hours - ISC Diary
  • Critical bug in newest Java gives attackers complete control of PCs - Ars Technica
  • Latest Java sandbox is still vulnerable - The H Security: News and Features
  • Blackhole targeting Java vulnerability via fake Microsoft Services Agreement email phish - ISC Diary

Seriously Jack. Really?

You should have been paying better attention to your hill-climbing technique; or at the very least dear Jill and not the rabbit.

Now you’ve taken Jill out in your folly and broken your crown; again.

Still Want That Water?

So where does that leave us now that we are holding the pail to safely quench our thirst?

Here is some sound advice.

  • 6 ways to protect against the new actively exploited Java vulnerability - Security - InfoWorld
  • You don't need Java - BetaNews
  • Tips For Java Junkies - F-Secure Weblog : News from the Lab

Me? I just disabled my Java browser plugins for IE/Chrome/Firefox and run NoScript in Firefox. However I didn’t uninstall my Java applications (1.6.35/1.7.6) as I do use a handful of true Java applications on my system.

I figure that will have to do for now until the next round of updates rolls.

No word when Jack will be out of the ER yet. Jill remains pouty.

Other Java-related tools you might be interested in while you wait…

  • JavaRa - SingularLabs - great third-party freeware utility to manage your Java RE build installations. More here at ghacks.net.
  • Jarfix - Johann N. Löfflmann’s tiny app to fix Java “JAR” file associations on Windows after a Java update borks them.
  • Java SE Downloads - Oracle - Java SE (Standard Edition) 7u7 JRE (Java Runtime Environment) and Java SE 6 update 35 JRE download links available from this link. When new updates are available you should be able to get them here.

Oh, did I mention that we just completed a massive rollout of Java 1.6.31 a few weeks ago across our enterprise to bring us to a new operational standard?

I lovingly refer to it as Project Maginot Line.

à revoir! from the bunker,

--Claus V.

Read More
Posted in browsers, Chrome/Chromium, Firefox, Internet Explorer, security, utilities, viruses | No comments

Sunday, August 12, 2012

Weekend Linkfest

Posted on 1:35 PM by Unknown

The Mars lander has been a fantastic success this week and the brainz has been on NASA overload. Couple that with some Perseid watching out back with Alvis last night and things are super fun.

Here is a fresh linkage roundup this week.  I recommend a slice of Key-Lime pie with it.

New Microsoft videos and Miscellaneous presentations

  • "Defrag Tools" - a new Channel 9 series (that will talk a lot about Sysinternals utilities) - Aaron Margosis' "Non-Admin" and App-Compat WebLog
    • Defrag Tools - Microsoft Channel 9 - neat source for fresh reviews of MS tools and techniques.
      • Defrag Tools: #1 - Building your USB thumbdrive
      • Defrag Tools: #2 - Process Explorer
  • Black Hat USA 2012 Presentation – Targeted Intrusion Remediation: Lessons from the Front Lines - Mandiant M-unition blog. I highly recommend viewing Jim Aldridge’s presentation slide-show (PDF) along side the excellent whitepaper (PDF) for the best experience.
  • Black Hat USA 2012 - Briefings - Great collection of materials over a wide-range of topics.

Network Bits

  • Troubleshoot Network Issues with Netalyzr - CyberNet News - review of helpful site for network troubleshooting.
  • Where did the Capture Filter go in Wireshark 1.8 (by Tony Fortunato) - LoveMyTool blog
  • SoftPerfect Network Scanner - Updated to version 5.4.5 this week.

Tool and Utility Roundup

  • DOWNLOAD: SysInternals Suite (Updated August 3, 2012) - Kurt Shintaku's Blog - Notice that Microsoft Sysinternals has updated their “package” suite of tools. Sysinternals Suite
  • KLS SOFT - WSCC - Windows System Control Center - Neat handy program that organizes and manages both the tools from Sysinternals as well as from NirSoft. Great way to access as well as update these tools in a collective manner.
  • ToolTip: FindUninstallString - Anything about IT blog - Handy tool to do a reg search for references to uninstall strings. FindUninstallString
  • Windows Disco - Hexacorn blog. New free tool to walk “…through all processes and their windows and takes a screenshot of each window, then saves it to a temporary PNG file in a current subfolder (named disco); you may review all these files either in an application itself, or in an Explorer, IrfanView or other image viewer.” Good illustration of technique for hunting spy/key-logger apps that utilize a “hidden” window with their process.
  • Detect Usermode Hooks with NoVirusThanks Ring3 Hook Scanner - NoVirusThanks new tool to help with malware analysis
  • MMC has detected an error in a snap-in and will unload it - Ask the Performance Team - Hotfixes for this post July 2012 update issue (if it happens) are linked in the post.
  • How To Build Your Own Image System with ImageX - Windows7hacker  - Old hat to me now but this guide is nice guide to the process with lots of images to help clarify the process.
  • Do copy acceleration utilities actually lower file transfer speeds? Our tests say yes -freewaregenius.com - Confusing post title, but bottom line is that copy-helper apps may not result in quite as peak transfer rates as you would think. caveat emptor
  • SRWare.net - New Iron-Version: 21.0.1200.0 Stable for Windows

Windows Live Essentials Updates

I was surprised to see news that Windows Essentials 2012 got some updating this week. The primary focus seems to be in Movie Maker and Photo Gallery. I thought most of it was to re-brand and distance from the “Live” naming, but there were some pretty big enhancements.

When I applied the Windows Essentials updater, I noted that many other Essentials apps also got an updating, including my fav Windows Writer. Unfortunately, trying to find a useful change-log for the updates is next to impossible, so your guess (at this time) is as good as mine as to what actually the upgrade enhances.

Introducing the New Windows Photo Gallery and Movie Maker_2012-08-07_20-28-51

  • Introducing the New Windows Photo Gallery and Movie Maker - Windows Experience Blog
  • List of all new features in Windows Photo Gallery and Movie Maker 2012 - LiveSide.net
  • Microsoft's Essentials 2012 drops Live branding, Vista support and pumps up Windows 8 - Betanews
  • New Windows Photo Gallery & Movie Maker Add Auto Collage, Panorama & Enhanced Narration - AddictiveTips blog

The Web-Life

  • How to Remove or Hide a Last Name from a Windows Live Profile - Windows Live Unplugged
  • Google Adds Personal Gmail Results Into Search - Liz Gannes - AllThingsD - Creepy.
  • Google quietly launches 'Account chooser' for easier multiple account login - The Verge
  • Advanced sign-in security for your Google account - Official Google Blog
  • How it works - Accounts Help (Getting started with 2-step verification) - Google Help
  • One Factor, Two Factor, Three Factor, More - SpiderLabs Anterior

Just saying….

Security and Patching Watch

  • Microsoft to close critical holes in August Patch Tuesday - The H Security
  • Microsoft Security Bulletin Advance Notification for August 2012 - Microsoft
  • APSB12-16 - Prenotification Security Advisory for Adobe Reader and Acrobat - Adobe Security Bulletins
  • Adobe warns of critical holes in Reader, Acrobat - ZDNet
  • An even more secure Flash Player for our Windows users - Google Chrome blog
  • The road to safer, more stable, and flashier Flash - Chromium blog

Forensics

  • Windows Incident Response: RegRipper Updates - Windows Incident Response blog
  • Dropbox Forensics - Champlain College Computer & Digital Forensics report by Jake Viens

Cheers.

--Claus V.

Read More
Posted in boot-cd's, Chrome/Chromium, forensics, Gmail, Google, Link Fest, malware tools, Microsoft, networking, security, utilities | No comments

Sunday, August 5, 2012

Browser Options

Posted on 12:42 PM by Unknown

There are so many different alternative Windows web-browsers out there, I won’t event begin to attempt to capture them all.

Instead, this post is my reference list of alternative web browsers I would be most likely to use in regular browsing sessions.

Each have their own benefits and drawbacks.  Just depends what the need is.

Which Firefox is right for you -- 14, 15, 16 or 17? - BetaNews - Nick Peers rounds up differences in the current release, beta, alpha, and nightly builds.

Mozilla Firefox, Portable Edition - At this moment, I’ve pulled back a bit from my usage of the “nightly” builds and am back on the main current release level. This is a portable version great for running on your system directly or off a flash-drive.

Comodo IceDragon ver. 13.0 - This is Comodo’s security-designed take on Mozilla’s Firefox. Has some additional features such as Comodo Secure DNS and Site Inspector. More in this WindowsClub post.

Private Browsing - PortableApps.com - Take your standard release-level portable Firefox build, tweak the settings, add in a Flash blocker, disable plugins and local extensions, cram in a privacy-enhancer block-list, a separate profile, and a custom icon to remind you this isn’t your regular firefox, and you have a browser with your privacy in mind. Not this isn’t a “Tor” proxy supported build, though you could add that in if you wanted. It’s more to prevent tracks from being left behind on systems you use it on as well as keeping your browsing a little more directed-ad free. If you want a Tor-based browsing solution, check out the Tor Browser Bundle for one solution.

I hesitate to mention, but will anyway, there are also custom-builds of Firefox for x64 bit operation. I’ve used variants of these in the past, generally with no issues, but these are pretty much hard-core enthusiast builds; so don’t come crying to me if you break something or take your eye out with them; Waterfox and The Pale Moon Project. Check out these great posts about Waterfox to get some background if you are still interesting in running with scissors.

  • Waterfox a 64-Bit Windows “Firefox” - Firefox Extension Guru's Blog
  • WaterFox: A 64-bit Performance-Focused Version of Firefox - CyberNet News

Google Chrome Portable - PortableApps.com. Main release level public build…portable.

Iron Portable - PortableApps.com - Portable version of SRWare Iron browser. This is based on Chromium and removes some of the default “usage tracking” bits that could be a concern for users of the Chrome browser. Although I use Firefox for my primary web-browser, I use Iron Portable now for my general web-surfing; particularly when I am on media-rich/enhanced websites, YouTube, etc. More in this WindowsClub post.

Dragon Internet Browser – This is Comodo’s security modded version of the Chrome browser. Tweaks to offer additional privacy for Chrome users, verifies Domains and alerts on differences in SSL certificates, blocks some cookies and web-trackers, monitors and blocks browser downloading tacking for privacy.

Opera, Portable Edition - Opera. Portable. Enough said.

Maxthon Portable - PortableApps.com. This interesting build uses both the Trident and the Webkit rendering engines to ensure maximum single browser compatibility with web pages.

Sandcat Browser - Syhunt. This is a very interesting portable penetration-testing oriented web-browser. Supports live HTTP Headers, request editor, fuzzer, JavaScript Executor, Lua executor, PageInfo extension, HTTP brute-force, CGI scanner scripts, and much more. Built on the Chromium browser.

--Claus V.

Read More
Posted in browsers, Chrome/Chromium, Firefox, Google, Internet Explorer, security | No comments

Sunday, July 8, 2012

GSD Linkfest - a little bit of everything today

Posted on 2:35 PM by Unknown

Quick collection of links gathered in this week.

  • Data recovery tutorial - As discovered and described by TinyApps.org. Very nice guide covering a number of Linux-based tools and techniques. DataRecovery - Community Ubuntu Documentation
  • Copy files from failing devices - Another great tippage from TinyApps bloggist. Check out safecopy
  • Create a system recovery partition - Great finds from TinyApps must come in “threes” as a link to Steve Si’s Create a system recovery partition post is found. It’s a detailed walkthough on setting up a Windows system-restore partition…just in case bad things ever strike.
  • Add to the file carving kit - TinyApps bonus links to POC for “Smart Carving” methods. Drop into the project’s SourceForge Documentation page to get the details.
  • FreeRecover - Free file recovery app for NTFS drives. It’s pretty fast. You can select options to get file paths as well as check “file integrity” to evaluate recovery value.  At this moment you cannot seem to sort results by column headings. It’s a good start.
  • Redo Backup and Recovery - BootCD format ISO file to handle system backups, recovery, partition editing, file recovery, and may more additional tools.
  • | Free Security & Utilities software downloads at SourceForge.net
  • The Case of the Veeerrry Slow Logons - Mark's Blog - Great post by the Windows Master Mark Russinovich. Covers a number of angles as well as the Windows login process in detail (and how it can be hampered). Good reading.
  • Google Chrome Bookmarks Menu Extension - CybernetNews found a really refined and polished  Google Chrome Bookmarks Menu Extension. I had been using Atomic Bookmarks but this one is much better IMHO.
  • Ads Are Coming to Google Chrome Extensions - TheNextWeb blog. Choose your extensions wisely now, my friends…
  • Release: NewsFox 1.0.8.4 - My favorite in-Firefox RSS feed add-on has a new release. newsfox: NEWEST
  • Filelist Creator - Free mini-app to create great lists of files/directories for indexing documentation. I have a few of these and this one is very, very nicely done. It’s been added to my carry-list.  Spotted and reviewed over at this Create Detailed File Lists In Various Formats With Filelist Creator AddictiveTips post.  Check out the big collection of other great utilities over at Stefan Trost Media. I grabbed more than a few!
  • TED V3.0 : The TEDinator - New update to the super-duper “TED Downloaded”.  I really appreciate the detail and help this tools brings in allowing me to download a local file of favorite “TED” talks. See also the new TED Radio Hour : NPR.
  • HexDive 0.3 - Hexacorn has just released a new version of HexDive which helps look for key strings in possible malware and other executable files. It’s CLI so it is really fast.
  • Forensic Artifacts blog has been releasing a large list of posts detailing forensic-worthy artifact bits left over from many applications. I found the PsTools Artifacts post extra interesting since it is used by a lot of us SysAdmins.
  • NTFS Tools collection - reboot.pro. Joakim Schicht has just announced an updated collection of NTFS tools he has been grinding away on.  After you read the overview on the first link, hop over to his Google Project hosting page mft2csv to check out:
    • NTFS File Extractor which extracts systemfiles (metafiles) off an NTFS volume.
    • mft2csv which takes a $MFT file and rip info from all the records and dump to CSV file.
    • MFTRCRD is a cli file dumper to pull all info mft2csv can decode. can also dump the $MFT record of a specific file to console and detailed run information.
    • SetMACE which is a timestamp fiddling tool.

      Note, Joakim doesn’t have them all bundled up in a single archive package so look at the Downloads page carefully to pick out the most recent versions of each of them. It isn’t hard but does take a moment to make sure you are grabbing the right file. Also be aware that these are compiled in “AutoIt” script. It’s very flexible and powerful but some AV apps might complain…  Joakim has done a great job with his documentation on each tool. Check out the Wiki for more details on each one.

Have fun!

--Claus V.

Read More
Posted in anti-virus software, boot-cd's, browsers, Chrome/Chromium, command-line interface, Firefox, forensics, Google, Link Fest, Linux, malware tools, NewsFox, RSS, utilities | No comments

Friday, June 15, 2012

RSS Feed Reader Upgrade - Hope through the storm (+more)

Posted on 5:19 PM by Unknown

Over the last few weeks a perfect storm apparently conspired to take out productivity on my personal laptop.

First, I had woken up on a Saturday morning to find my smokin-hot laptop “Tatiana” would no longer boot. Four beeps of death and no BIOS boot screen. Coupled with that was a failing internet connection. Oh yeah, the cable-DVR box refused to output video signal.

Bad Things™ were afoot! Bad, man.

Between sporadic and brief periods of Nettage I was able to manage a download of Dell’s Studio 1558 Support doc with beep codes. Four beeps = RAM read/write failure. I breathed better after I had tried pulling out the two (new) Crucial 4GB Dimm sticks (total 8 GB RAM) and dropped back in the x2 2 GB OEM (Kingston) RAM that shipped with the system and it booted up normally again. Based on a super-kind investment from little-bro after I walked him through some dicey system issues a while back, I had upgraded Tatiana’s memory with two sweet 4 GB sticks of RAM from Crucial. With 8 GB on board, the system chews up the VM’s I’m running.

Through trial and error I was eventually able to locate which of the two Crucial sticks went bad. I left the good 4 GB Dimm stick in and supplemented it with a 2 GB Kingston stick to limp by with 6 GB.

Good news is that the Crucial gang have a generous warranty policy on their RAM and a week after I went through the RMA process, the replacement Dimm arrived today and is waiting installation. Yea Crucial! The entire process was a piece of cake and communications to me by Crucial were spot on! Customer service done right and one reason I return to them time-after-time for my RAM upgrades.

The spotty Intertubes issue was another thing. Due credit to my ISP help desk, they never gave me a hassle during the troubleshooting process (do you have lights on your modem?) and let me jump right to the gist when I identified myself as network dude (sure, let me do a signal test like you suggest and BTW here’s the packet data results we are seeing…). The first time I called they couldn’t test down to the router as their entire system was down also (bummer). The second time they reported lots of packet loss and sent an updated config file to it. That helped a bit, for a day. Then back to spotty connectivity. I had already done extensive troubleshooting on the Cat-6 hard-wiring between the cable modem and my WiFi modem; it was fine as was my WiFi modem connection itself. Another call, another confirmation of packet issues, another day of a working network before regular outages began. “Sir, do you have splitter in the modem’s line?” “Yes, your last tech put it there himself. We’ve been good for over two years since.”  They offered to send a line tech but I didn’t feel like taking a day off work just yet.

So last week after work I pulled my Dremel, put a wire polishing brush on the tip and from the outside of the house inward, unscrewed every coax connection, polished the threads and copper center wire, and reassembled…all the way back and including the cable modem box.  An hour or more later everything was bright/shiny and tight. And the connection was rock-solid again. Hurrah!

The DVR cable box was a surprising issue.  It is Cisco RNG200 HD-DVR box and I use an HDMI cable to output signal to the TV. First check was the cable itself. Attaching it to the (now working again) Tatiana resulted in great video signal display to the TV. Not the cable.

Maybe the box itself was failing?  For the past month we had noticed a trend where the video signal would go black suddenly for a few seconds before restoring again. Related perhaps?

After finally getting a cheery cable-tech on the line from our provider, he listened patiently as I explained all the troubleshooting work I had done already and the growing video output signal dropouts. Immediately he sent a major re-programming order to the system (not your normal box reauthorization signal mind you). About forty minutes later the software had been digested, applied, and assimilated. The box sprang to life and signal was restored again. And all our recorded shows were still on the drive! Since then, we haven’t had any issues with video dropout either. Not sure what happened, but I’m guessing the software/firmware refresh cleared it up.

Claus? What has this to do with RSS feeding?

I’m getting to that.

Amongst all this drama spread over a week or two getting resolved, Firefox 13 dropped, a significant Flash update dropped, and my Firefox/NewsFox combo for reading my almost 250 RSS feeds ground to a horrible stop.

See, I found that every time I attempted to use NewsFox to pull my RSS feeds, it would inevitably hit one that had some kind of Flash/Java/script something and lock Firefox up completely. I could get it going again by waiting forever for a “script stopped responding” dialog to appear which might eventually allow me to continue on. However I found just killing the plugin-container sub-process with Process Explorer did the trick faster. To compound issues, I wasn’t seeing the Flash Player sub-processes kick off underneath the "plugin-container”.

fkswe35k.x31

Something bad was happening and only by killing the plugin-container process could I get control back of Firefox.

I had previously experimented with dedicated client-based RSS feed readers, but have been a die-hard proponent of having my RSS feeds directly in my web-browser and NewsFox fit the need perfectly.

So I started the search to see if there was a client-based RSS feed reader that would allow me to break out of my browser for RSS feed reading in the meantime, but still be compatible with the process to support my blogging work.

After looking through the options on my (very) old post RSS Reader Roundup…Valca Style, checking out some newer apps, (including the slick new Mishra and Voyage readers) and picking though a ton of Google search results on the subject, I settled on two possible candidates; Feedreader and Omea Reader.

Feedreader was very nice and has become quite polished since I last toyed with it. I was able to import my sizeable OMPL list from NewsFox and with a few tweaks had a nicely sorted/displayed 3-column view. The text view is beautiful for the articles and the feed information and article link presented at the top of each displayed article header was stunningly perfect. Feed updating was fast and stable. It was almost a perfect match. Except that despite all my attempts, the process of getting the link out and into Firefox just didn’t quite work smoothly. Since I bookmark interesting links during the week until blogging time rolls around this was a real problem. I don’t use IE regularly, but still prefer to leave it as my default system browser. So clicking a link opened up IE, which I then had to copy the link and paste it into Firefox and then reload the page and then save my bookmark. The total package is beautiful and simple.

tymsuhoy.emm

Omea Reader was brilliant and I’m using it full time now for my RSS needs.  Out of the box (as I posted originally back in 2008) it is very over-the-top feature rich. I was able to turn off features/tabs for contact management, favorites, HTML plugin, News plugin, Notes plugin, and pictures plugin.  Once disabled, all that I left running was the RSS plugin. I easily imported my OPML file and it raced through the feed updating rocket-fast.  It supports complex feed-view filtering as well as categorizations. I can set a ton of special filters and highlighting based on key-words.  The article text-view is nice (though not quite as polished as Feedreader). Some feed/links that NewsFox had issue with were no issue for Omea. It doesn’t have a launch at startup option (nor launch minimized) that I can tell, however I set it to launch as a scheduled task 5 minutes after login and that seems OK.  While running it seems to kill my Windows screen saver. Haven’t figured that out yet. In fact, my only complaint seems to be that the RSS article feed link is displayed at the very bottom of each post, rather than up in the header section like Feedreader. (Omea Team? Any tips to get the article link displayed in the header section?)  This means sometimes I need to scroll to the very bottom to open the link in a browser. Speaking of that, Omea is cool in that if I have Firefox running in the background and click a RSS feed link to view the full article in the browser, it sends it to Firefox as a new tab. From there I just deposit the page in my bookmark sidebar. That’s a Texas two-step dance I can live with. Sweet!

iwnp00tc.ucd

I’ve not given up yet on NewsFox and may return to it since I (below) sorted out the Firefox lockup issue I was plagued with, but I’ve clearly reached the tipping point.  The speed and feature set that Omea Reader bring me as a full featured, and semi-autonomous RSS reader have convinced me this was a wise way to go. I can update my feeds in the background without locking up my Firefox browsing.

Now, soon after I had started getting used to Omea Reader, I had to turn my attention back to the constant lockup issues with Firefox. I was super close to jumping to Chrome full time. The only thing that saved me was the (continued) lack of a bookmarks sidebar in Chrome like Firefox has.

The lockup issue ended up not being NewsFox add-on extension specific. It directly hurt the most because NewsFox was always open in the background and it seemed that anytime it or me hit a feed that had something going on triggering the event, Firefox would lock up.

I disabled NoScript. I disabled AdBlock. No fix. Eventually I was able to find some web-pages (outside of NewsFox) that would cause the page load to lock up Firefox but not IE or Chrome. I had material to work with and it was clearly outside of being just a NewsFox problem

Long story short, I eventually found through lengthy troubleshooting that the issue (in my case) was the Flash/Adobe/Shockwave plugins I had in my portable Firefox plugin folder; Mozilla Firefox, Portable Edition Support | Installing Plugins. Basically, Firefox Portable (which I use) has a FirefoxPortable\Data\plugins directory where you can keep your plugin files if you run the app on a system that lacks them.

These here:

m0zm2qw0.u1d

+ This

fkswe35k.x31

= Firefox lockups and no Flash sub-process execution!

Instead:

Nothing here:

nfdd0c40.tfk

+ This

lyxzhyj3.t0x

= No Firefox lockup and the expected Flash sub-process executions!

Firefox 13 tamed.

Go figure.

Despite the fact that the files I had in here were the same ones from where they are also “installed” on my system, emptying out the files in this folder solved the lockup issue I was experiencing. 

Don’t know why that was an issue, but it was. With the portable plugin repository empty again, no more lockups since and Firefox seems just fine finding the appropriate browser plugins from their main installation location on my system.

So it was with interest today that I found the following in my RSS feeds.

  • Firefox 13 tripped up by Flash patch -The H Security: News and Features.

    Quoting from that post:

A further option for remedying the problem is to deactivate Protected Mode. Under Windows 7 or Vista, this requires the addition of the line ProtectedMode=0 to the configuration file mms.cfg. Since Protected Mode is not used under Windows XP, this step is not necessary on that platform. In 64-bit editions of Windows 7 and Vista, mms.cfg is located in <%windir%\syswow64\macromed\flash>; in 32-bit versions the file is located in <%windir%\system32\macromed\flash>. Administrator privileges are required to modify these files. Detailed instructions can be found in Adobe's Protected Mode FAQ.

Some users have traced some of their crashes back to the fact that Firefox's out-of-process plugin protection has been disabled. A support article on the Mozilla web site explains how to reverse this change.

Adobe has gone even further and released instructions for downgrading Flash Player to a previous version. Users should on no account downgrade to build 11.2, however, as it is known to contain critical security vulnerabilities which are currently being actively exploited. Instead, users should install Flash Player 10.3, in which the vulnerabilities in question have been fixed in a similar way to version 11.3 since Adobe is continuing to supply enterprise customers with security patches for Flash 10.

I had considered that the new sandboxing features might have been causing the issue, but since I had been able to replicate the issue in a parallel run of Firefox 12 I ruled the Firefox version 13 itself as being the source of my particular issue.

I’m now turning my attention to picking through this detailed technical post in hopes it might help be understand what was going on:

  • Inside Flash Player Protected Mode for Firefox - Adobe Secure Software Engineering Team (ASSET) Blog

All is well in my case, and having weathered a perfect storm of technology problems, I’m pleased to say Firefox 13 is running strong, I have a new “high-end” RSS feed reader that is increasing both my performance and feed consuming hunger brilliantly, the cable box video output is good as new, and thanks to Crucial, I’m back to 8 GB system RAM on my notebook again.

There is peace and harmony in the Valca home again.

Hopefully somewhere, something in all these travails and victories might help someone.

Cheers!

--Claus V.

Read More
Posted in browsers, Chrome/Chromium, Firefox, Link Fest, RSS, troubleshooting | No comments

Sunday, May 20, 2012

So Many Links…So Little Time!

Posted on 3:04 PM by Unknown

Busy day today. Chores to do inside the house and out. And links galore spilling out of my Firefox sidebar, ripe for posting.

Critical Updates

  • Adobe: Critical security holes in Shockwave, Photoshop, Illustrator - ZDNet ZeroDay blog
  • Adobe - Security Bulletins: APSB12-13 -Security update available for Adobe Shockwave Player.
  • Adobe - Web Players - Links to download Adobe Flash Player and Adobe Shockwave.
  • QuickTime for Windows update plugs security holes - The H Security: News and Features - And then when you are done with Adobe, go grab the latest QuickTime player update.

New Place to Report Fake Tech Support Scam Calls

As if the usual bane of telemarketers isn’t enough to wade through almost every day and night, now we are seeing a renewed push of the fake-tech-support calls. Enterprise IT shops are even having to now send notices across their employee-base to remind them that they haven’t been outsourced to these callers and that employees should always make sure they are talking to the right IT guys and gals. Some places are event starting to black-list some of these third-party remote control sites to clamp-down the borders against these calls.

Troy Hunt has a series of great posts that tell you just about everything you need to know about these scams. I’ve posted them before but Troy’s writings are so good, they need another mention.

  • Anatomy of a virus call centre scam - Troy Hunt’s blog
  • Scamming the scammers – catching the virus call centre scammers red-handed - Troy Hunt’s blog
  • “Type www.” – “Ok, w-w-w-d-o-t”; antagonising call centre scammers - Troy Hunt’s blog

The guys and gals over at SANS have gotten into the game as well.

  • Who's tracking phone calls that target your computer? Stay Tuned to the ISC - ISC Diary

They have opened up two (same) locations for you to report any fake-tech-support calls you may get for intel-gathering purposes. Knowledge is power!

  • (Red Theme) - Report Fake Tech Support Calls - SANS Internet Storm Center; Cooperative Network Security Community
  • (Green Theme) - Report Fake Tech Support Calls - DShield; Cooperative Network Security Community

For the SysAdmins in the Audience

Kyle Beckman has written an outstanding series of posts at 4Sysops blog on folder redirection in Windows. Definitely worth taking some notes from.

  • Folder Redirection – Part 1: Introduction - 4sysops
  • Folder Redirection – Part 2: Setting up your file server - 4sysops
  • Folder Redirection – Part 3: Explanation of folder permissions - 4sysops
  • Folder Redirection – Part 4: Group Policy configuration - 4sysops
  • Folder Redirection – Part 5: Best practices - 4sysops

In other news…

FREE: Veeam ONE Free Edition – Real-time Hyper-V and VMware monitoring - 4sysops

"Could not reconnect all network drives" - TinyApps.Org. Great tip and trick for delaying (slightly) the mapping of network drives until the network is fully available after login.

Windows Error Lookup Tool Portable 3.0.4 (get details on Windows error codes) Released - PortableApps.com

Batch-Convert XLSX To XLS Without MS Excel Or An Online Converter - New tool reviewed by AddictiveTips.  Get the tool here from the author.

Jarfix - free tool to fix broken “jar” file associations in Windows.  I needed this after the last Java Runtime update I applied to my system. After installation, I could no longer run the Java-based Software Protection Initiative - Encryption Wizard tool as I had before. I tried several times to update the file-associations but no dice. Then I found this tool, and once executed…problem solved!

Likewise, a few months ago I had re-installed Google Earth but for some reason, lost all indications on how to launch it…no icon on the desktop. None in my “Start” list. Nada. Uninstalled/reinstalled. Still the launcher icon was no-where to be found.  Finally found this link: Google Earth icon has disappeared from my PC : Fix my problem - Google Earth Help  Downloaded the Google Earth Icon Restorer and ran it. Again, problem solved!

Mirekusoft Install Monitor -freeware Installation management software. (Note site down at time of posting) - I have a number of system change monitor/detectors I rely on to monitor how and where a software install impacts a system. Each one takes slightly different approaches. So I read with interest about this new installation monitor/logger. It runs as a service so it catches all installations and documents where in the file-system and registry the bits go. Drawbacks? Maybe a bit unstable and if a program was already installed prior to installing this tool, it doesn’t well-catch the updated installation bits. All that said, it might be worth looking into…particularly in a lab/test-bench setting where you need to document where install bits go before deploying them.  See this CSArchive.Net Mirekusoft Install Monitor post for some screenshots while the main site is down. Alternative programs to consider: Total Uninstaller by martau.com (free-trial/$) or Revo Uninstaller Freeware.

Leelu Soft: Watch 4 Folder 2.3 and Track Folder Changes are two other utilities you may want to check out.

I’m not sure why I’m on this theme this week, but the freeware app GeekUninstaller came to my attention this week also. Free and available in both installable and portable versions, helps remove installed applications.  For a few more details and screen-caps, see this AddictiveTIps post: Geek Uninstaller Lets You Completely Wipe Off Any Application From PC

VMware Workstation Player 4.0.3 released / Workstation 8.0.3 - Born and Windows IT Blog - My own recent experience using VMWare Player 4.0.3 for a Win 8 CP run was outstanding. Definitely worth getting these updated bits. VMware Player 4.0

Group Policy Central - new blog to me about Group Policy topics, including some Win 8 items and findings. Doesn’t appear to be updated quite as frequently as I would like, but since it is new, I’ll probably find more than enough material here to keep me busy until the next post comes out.

Network Nuggets of Gold!

NetBScanner - New tool from NirSoft - NetBIOS scanner. Provide a IP range and get IP addresses, WS Names, Workgroup membership as well as MAC address. Super nice GUI. Add this right now to your network toolbox!  Reminds me of the CLI tools (work good for me) NBTScan and the similarly named nbtscan. More info on NetBScanner at this AddictiveTips review. 

wpic v1.0.0 - woanware - A “simple console web page capture tool based on Chromium project that captures an entire web-page. Reminded me of IECapt which is an IE based web-page capture tool that I use daily for some data archiving.

NETRESEC CapLoader - Not free - interesting tool to process large network PCAP files and filter flows of interest. See this CapLoader Demo - YouTube for more info.

Curiously, there was this related post The Adventures of Packet Tracy, PI over at wirewatcher blog on parsing down large PCAP sets for URLs of interest.

HolisticInfoSec: toolsmith: Buster Sandbox Anayzer - Detailed information and walkthrough regarding a new release of Buster Sandbox Analyzer back in April.

In a GSD post On the Hunt… I detailed a quite involved process in hunting down/validating network connections and mapping them to specific switch ports. Over at LoveMyTool blog, Tony Fortunato posted a short video on how to find out which switch port the client is connected to. Pretty standard stuff.  However, I’m always putting a sharp eye on these just in case I find a new or better technique. And I did! For whatever reason (Cisco IOS updates?) we’ve seriously lost our ability to search for MAC addresses in the Cisco Network Assistant product. We are not alone as others are encountering issues as well. Anyway, we have some workarounds in the GUI but they are a bit time intensive looking through many, many switch port connections.  So like Tony, I find it (generally) faster to just telnet to each switch, run a “show mac address-table” and list the MAC/Port associations and look for the target MAC. On 48-port switches, that is a lot of searching. Tony’s video taught me the following trick; “show mac address-table |include <mac address>”  Including the pipe-include lets me pop just the single MAC I want. Sweet!

More here: Cisco IOS "include" filter.  And for the full list of powerful Cisco CLI options, check out this Cisco IOS Terminal Services Configuration Guide, Release 12.2 - Regular Expressions  [Cisco IOS Software Releases 12.2 Mainline] at Cisco Systems . Note your Cisco IOS version may render some of these commands a bit different, if supported at all. You probably also want to tuck away this Regular Expressions (PDF) for reference as well.

Finally, over at Anything About IT blog, Alex Verboon posted this Script for finding Executables that are command-line programs via a free utility IsCommandLineApp by Helge Klein. Might be useful in incident-response.

For the ForSec crewmates

In my recent Forensically Sound: Quick Post #3 I posted a number of links touching on early forensic surveys of Windows 8 “release” builds. I warned that none of these observations are 100% guaranteed to be present and accounted for in the final baked version, but they are good starting points. Troy Larson wisely commented on that post “Regarding Windows 8 forensics: I would be careful of relying too much on the public preview versions for detailed forensic analysis. Offsets and formats can still change.” Noted! So with Troy’s perspective firmly fixed in mind, here are a few more links touching on early (very early) Win 8 forensic notes and observations.

  • Windows 8 Forensics Part 3 -Post by Ethan Fleisher on file history saving.
  • Digital Forensics Stream: Windows 8 TypedURLsTime by Jason Hale at the Digital Forensics Stream blog
  • Random Thoughts of Forensics: Windows 8 - Refresh Excerpt - Random Thoughts of Forensics - Kenneth Johnson touches on “Windows 8 Refresh points” impact as well as “System Recovery”

Portable Agents to QuickScans: Tips on Using the Latest Version of Redline - Mandiant M-unition blog

SANS DFIR Wall Poster Preview - SANS

File Formats ZOO - Hexacorn blog - file sector header information for common file formats.

File Formats ZOO – Installers - Hexacorn blog - likewise for software installer files.

The Curious Case of the Forensic Artifact - Hexacorn blog - in which the process of solving a curiosity is illuminated.

RegRipper: Update, Road Map, How not to get p0wned by RR v2.5, and Approximating Program Execution via VSC Analysis with RegRipper - Windows Incident Response blog -- my o my how RegRipper has grown!

More About Volume Shadow Copies - Journey Into Incident Response:  Corey Harrell dishes more on VSCs.

Related…VSC Toolset Update: Browsing Shadow Copies - Digital Forensics Stream post by Jason Hale with interesting comment thread follow up.

TypedURLs (Part 1) and TypedURLs (Part 2) - Crucial Security Forensics Blog posts by Paul Nichols.

Addressing Malware Issues from an Operational Perspective - Crucial Security Forensics Blog post by Michael Robinson. Great quick read on malware in the organization and changes that may be needed in operations.

Resurrecting “Dead” Images for Live Analysis - Crucial Security Forensics Blog post by Mark A. Wade.

Old Servers never die – unfortunately - Forensics from the sausage factory. Great “how-to” tips and results on imaging a server/system over the network, when you must…

Digital Forensics with Open Source Tools (Amazon link) - New book by Cory Altheide, Harlan Carvey. It’s a book after my own heart! Open Source/freeware (closed-source) tools for for/secs.

Windows Live Messenger – MessengerCache folder  Forensics from the sausage factory. This post was very interesting as it took a fresh look at what may be a commonly used application on some Windows systems.

“You Can’t See Me”…(my bad…I guess you can…)

A recent round of migrating users into a new AD domain (and some folder rcopy/redirection work on the side) has left a few users with missing data post-migration. I have tons and tons of tools to recover deleted data from a drive. The sysadmin I was working with reached for a new one to me in our troubleshooting work together, FreeUndelete over at OfficeRecovery.com. Did the job nicely and the customer had their files restored in no time. I offered my own recommendations in thank-you. In doing so I spotted that Kickass Undelete recently got bumped up to 1.3 beta version. Others I like include Recuva. I also learned (via this AddictiveTips blog post) about Orion File Recover Software Free. I also saw this review at AddictiveTips blog for Wise Data Recovery freeware software. For even more tools, check out this GSD post File Recovery Extravaganza.

PhotoGrok / Java

PhotoGrok: EXIF-Based Image & File Viewer With Metadata Filters - AddictiveTips blog. I have more than enough EXIF-data/File-Viewer apps than I really need, but I’m a sucker for a new utility so I went ahead and downloaded the PhotoGrok tool and was quite pleased with the effort. It’s a nice tool. However, when I went to try to uninstall it, it wasn’t listed in my Add/Remove program (errr, make that Programs and Features) list. Nor could I find a link to an uninstaller in my program file list.

Checking the desktop shortcut target location led me to

“C:\Windows\SysWOW64\javaws.exe -localfile -J-Djnlp.application.href=http://www.haplessgenius.com/photogrok/launch.jnlp "C:\Users\profilename\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\3b46d1a5-79989755"”

Now how do we uninstall this?  Unfortunately, the otherwise well-written FAQ didn’t seem to spell out the method. Yikes. Time for some deeper digging.

Turns out PhotoGrok is a Java WebStart application.

To remove you can follow the principle outlined in this post: How to Clear the Java Web Start Cache as explained by a different software vendor. This post Clearing the Java WebStart Cache by NGS has some better screen-captures (although they may be outdated a bit if you have a more recent Java build on your system…it should work well enough to get you what you need to know). Still not sure? See this final set of screen-caps for a newer Java build: Java Web Start 1.6 beta2 Review courtesy of UCWare.com.

See, no need to panic! Easy-peasy if you want to strike it from your system.

Reset that Windows Password! (or crack it with a new release of Ophcrack…)

So last week--a tech was having some issues having a pushed application install on their system. Turns out their domain account didn’t have admin group membership and was causing the bomb-out. No problem, let’s just add you to the…hmm…for some reason all the admin account passwords are different from our standard and the “fail-safe” account is disabled. Oh snap. I hear the drumbeats of a system reload! Can you say “too-bad, doo-dad?”

Luckily, I had a backup plan.  Booted the system in my custom WinPE, used the embedded tools to off-line authenticate to the whole-disk encrypted system drive, then used NTPWEdit 0.3 to update the Admin password accordingly. Reboot. On the local system admin account now, added tech to the admin group. enabled the disabled account, good to go.

See also Password Renew at sala source (which I understand doesn’t play well under WinPE).

Related: DistroWatch.com: Ophcrack LiveCD updated May 15th. More news about this build here: Distribution Release: Ophcrack LiveCD 3.4.0

"This new live CD includes the latest version of ophcrack 3.4.0. It is built on Slitaz GNU/Linux 4.0, the latest version of this great live CD. Christophe Lincoln from Slitaz helped us to enhance the scripts for partitions and tables detection. A new ncurses interface is also available to help users look for tables on other drives or interact with ophcrack. Finally a live CD without tables has been released as well for users that already downloaded or bought tables. The directory containing the table files must be placed inside another directory called tables in order for ophcrack to find them automatically."

More Ophcrack release news here: news page

Now where’s my mop?

Cheers!

--Claus V.

Read More
Posted in boot-cd's, Chrome/Chromium, command-line interface, forensics, graphics, Internet Explorer, Link Fest, Linux, Microsoft, networking, NFAT, security, troubleshooting, tutorials, utilities, Windows 8 | No comments

Sunday, April 1, 2012

Forensic Linkfest - microwave-ready meals

Posted on 1:26 PM by Unknown

My “For-Sec” to-be-blogged pile is bustin out at the seams.

Unfortunately, I still haven’t been able to find the time to toss the meat on grill in a way that gives it justice…so as of now, that material is still slow-smoking.

In the meantime maybe you will find something noteworthy in the following links-of-note prepared for quick consumption.

NetWitness - Investigator Freeware - Version 9.7.5.4 released 03/16/12. I’ve used this NFAT tool successfully in the past, but had stopped looking for updated versions. So the other day when my one-year’s registration period had expired and I had to “re-enlist” I was advised an update was available. There are a number of free NFAT tools, and each provides its own slant. NetWitness Investigator Freeware version is a must-have tool for your assessment collection. Get the update!

MIR-ROR - This incident response toolset has now been updated to version 2.0: HolisticInfoSec: MIR-ROR 2.0 released. Sure you have to dump a few of the ingredients in the provided bowl before you bake, but it’s, well, a piece of cake. The result is a collection of tools that can speed up your assessment and information collection on a suspect system.

65 Open Source Replacements for Security Software - Datamation’s Cynthia Harvey has composed a knock-out list of great Open Source tools. I’m confident that anybody who regularly reads this blog will find something new or interesting in this list.

NAFT Release - Didier Stevens has released his Network Appliance Forensic Toolkit than can handle network appliances but also supports memory dumps of OS’s like Windows. Basically (for now) it extracts network packets from memory dumps or other devices via pattern recognition.

The Latest Version of Redline Finds Indicators of Compromise and More - Mandiant’s Redline tool has now been updated.

Brett Shavers has a number of new posts about progress in the WinFE building and toolsets.

  • Colin’s Write Protect Application- Windows Forensic Environment Blog
  • WinFE Script Updated - Windows Forensic Environment Blog

The Girl, Unallocated forensic blog has been a great source of how-to’s and advice on approaching investigations. This latest series is quite interesting.

  • Case Experience #2 - IP Theft Investigation Thought Process
  • Case Experience #2.1 - More About IP Theft Thought Process
  • Case Experience #2.2 - Let the Digging Begin
  • Case Experience #2.3 - Digging Into the Registry

Prefetch analysis posts are quite plentiful.

  • Prefetch Analysis, Revisited...Again... - Windows Incident Response blog
  • Second Look at Prefetch Files - Journey Into Incident Response blog

Corey Harrell also has a great in-depth timeline study based on Volume Shadow Copy data. Sharpen your Saw on this one!

  • Volume Shadow Copy Timeline- Journey Into Incident Response blog

We are all learning more and more as Chrome gains in popularity. SANS Computer Forensics and Incident Response blog’s “johnmmccash” has a great roundup of material in his Forensically mining new nuggets of Google Chrome post.

Finally, Security Ripcord blog’s Don C. Weber has a technical post on Hard Drive Acquisition Information Using faidds and makes some interesting observations in the process.

Cheers!

--Claus V.

Read More
Posted in Chrome/Chromium, forensics, Link Fest, malware tools, NFAT, security, software, utilities | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile