Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label NFAT. Show all posts
Showing posts with label NFAT. Show all posts

Saturday, November 2, 2013

ForSec Linkfest - 2013 DST Fallback Edition

Posted on 1:23 PM by Unknown

FYI…tomorrow morning at 2 AM here in the United States of America it will be time to “fall back” from DST. One more hour of sleep and then it’s weeks of trying to get the body’s timeclock to readjust.

So as you get ready to find all the clocks you need to manually adjust (don’t forget the vehicles!), here is some linkage to distract you from that task. Please note I’ve also sprinkled in some networking items as well to keep you on your toes!

  • Wireshark 1.10.3 and 1.8.11 Released - Wireshark website
  • Wireshark - Official site Download
  • Reviewing Wireshark's Capture Pane (by Tony Fortunato) - LoveMyTool blog
  • Using PowerShell to Automate Tracing - MessageAnalyzer blog
  • Nmap cheat sheet - HelpNet Security blog - From the notice:
    • Counter Hack founder and SANS instructor Ed Skoudis and his team created a helpful cheat sheet for Nmap, which includes notable scripts of the Nmap Scripting Engine, script categories, instructions for scan types, probing options, and more.
  • How A Wireless Issue Looks Like a Wired Issue (by Tony Fortunato) - LoveMyTool blog
  • NAFT: The Movie - Didier Stevens
  • New utility to quickly set the DNS servers of your Internet connection - QuickSetDNS utility from Nir Sofer's workbench.
  • On getting Pineappled at Web Directions South - Troy Hunt’s blog
  • Disassembling the privacy implications of LinkedIn Intro - Troy Hunt’s blog
  • Command-line Forensics of hacked PHP.net - NETRESEC Blog
  • iOS apps can be hijacked to show fraudulent content and intercept data - Ars Technica
  • Your iPhone knows where you’ve been, puts it on a map - Chron.com’s TechBlog
  • What's New in the Prefetch for Windows 8?? - Invoke-IR blog
  • Re-Introducing the Vulnerability Search - Journey Into Incident Response blog
  • Links - Windows Incident Response blog
  • Incident Response Teams are the New (Security) Black - Speaking of Security - The RSA Blog and Podcast
  • Red Alert: 10 Computer Security Blogs You Should Follow Today - MakeUseOf blog
  • New Security Intelligence Report, new data, new perspectives - Microsoft Malware Protection Center blog
  • Meet “badBIOS,” the mysterious Mac and PC malware that jumps airgaps - Ars Technica
  • Hacking a Reporter: Writing Malware For Fun and Profit (Part 1 of 3) - SpiderLabs Anterior
  • Treasure Hunting with FTK, EnCase, and SQLite Databases - Computer & Digital Forensics at Champlain blog
  • Add the CAINE ISO to your E2B drive - RMPrepUSB, Easy2Boot and USB booting

Cheers,

Claus Valca

Read More
Posted in boot-cd's, cheat sheets, forensics, iOS, Link Fest, networking, NFAT, PowerShell, security, utilities | No comments

Saturday, October 19, 2013

Micro Network News linkfest

Posted on 9:27 PM by Unknown

Just a small collection of network-minded links of interest this week.

Free Network Sniffers, Analyzers and Stumbers - WindowsNetworking.com - I saw some oldies-but-goodies in the list, some new ones (to me), most I was familiar with, and surprisingly missing from the list, Microsoft Message Analyzer. A lot more of the micro-sniffers/NFAT tools out there also got left off but the list seems a bit short to me and misses quite a few more worthy contenders.

Remote Capture with Message Analyzer and Windows 8.1 - MessageAnalyzer blog. Speaking of Message Analyzer, you now can remotely capture traffic with this tool (on supported target systems) without even needing a copy of Message Analyzer installed on them. Neat!  For more info see Using the Network Tracing Features over at TechNet.

Tweaking Wireshark Columns and Decodes - Packet Foo blog

We’re switching to Qt. - Sniff free or die - A development version of Wireshark 1.11.0 has been released that opens the door to using Qt for the user interface library.  The development version has some basic things working, but much of what you love about Wireshark does not. It’s a quick and interesting read.

D-Link Router backdoor vulnerability discovered - TechGeek

D-Link Router Backdoor - Schneier on Security blog

Old D-Link routers with coded backdoor - ISC Diary post

Oh my.

--Claus Valca

Read More
Posted in Link Fest, Microsoft, networking, NFAT, security | No comments

Saturday, September 14, 2013

iPhone Traffic - ZAP’ed, Security, and Network Tap Tap Tapping

Posted on 9:59 AM by Unknown

This week brought in a very interesting post from web security/developer Troy Hunt.

 Unearthing the hidden shortcomings in Aussie mobile app security - Troy Hunt’s blog

Please go read then come back.

Interesting isn’t it?

I know most GSD readers probably wouldn’t be surprised to find some of their favorite mobile-apps leak user ids and passwords in plain-text, but for those who don’t know, some do.

Case in point (that has now been reported as fixed!):  Zscaler Research: Mobile App Wall of Shame: ESPN ScoreCenter

Naturally that got me thinking about a common mantras in the For/Sec world; “know your tools” & “verify, verify, verify”.

What I want to do is some benchmarking and analysis of the mobile apps I use on my own iPhone to have a better understanding on what is happening with their network traffic. This would be valuable information to know for general usage, and critical knowledge in case you unknowingly encounter a Wi-Fi Pineapple in the wild or a more complex man-in-the-middle Wi-Fi attack and get your network traffic captured.

One super-easy (and lazy) way I have found is to use ZAP - Zscaler Application Profiler.  From the “About” page link:

About ZAP

Zscaler Application Profiler (ZAP) is web based tool designed to streamline the capture and analysis of HTTP(S) traffic from mobile applications. ZAP is capable of analyzing traffic from both iOS and Android applications and includes the following functionality:

  • Search: View summarized historical results for past scans.
  • Scan: Proxy traffic from a mobile device through the ZAP proxy and the mobile app traffic will be automatically captured and analyzed
  • iPCU: Upload your iOS device configuration file(.deviceinfo) to check risk score of installed application. It will give you overall risk score of your device. The information provided is based on out knowledge base.

ZAP classifies traffic into the following buckets and calculates an overall risk score for the application:

  • Authentication: Username/password sent in clear text or using weak encoding methods.
  • Device Metadata Leakage: Data that can identify an individual device, such as the Unique Device Identifier (UDID).
  • Personally Identifiable Information Leakage: Data that can identify an individual user, such as an email address, phone number or mailing address.
  • Exposed content: Communication with third parties such as advertising or analytics sites.

Zscaler also has a detailed video on this service on their blog: Zscaler Research: Introducing ZAP.

So you can either check their historical report data on apps already researched, you can connect your device to their proxy to do a scan on a new app/version not already captured historically, or even upload your own iOS device config file.

Wow.  Bookmark this resource link now!

However, there may be cases you want to do your own local network traffic capture and analysis…because you like pain and frustration (and hands-on learning perhaps).

Part I - In Which Hardware TAP Options are narrowed down

At work (when & where authorized) we can set up network packet captures either on a specific system or on the LAN using port-SPAN.

At home, I don’t have a managed switch (or dumb hub) that can do that.  I suppose I could buy a USB-NIC (so I can have two wired network ports on my laptop) and then capture traffic temporarily though one of these messy devices (home-built or purchased) but that isn’t quite as elegant as I would prefer.

Or (as the TinyApps bloggist kindly just reminded me) use Cain & Abel.

  • Capturing Packets on a Broadcom Card - The Flying Frank
  • Configuration - OXID.I

Instead I decided I'll pick up a specialized device that support a network TAP.  This way I can just hook it in line between my Wi-Fi router and the cable modem and capture everything that passes though. It may not be 100% on packet captures, but I think it will be good enough for my home testing.

So the next question is what device?

I’ve settled on the following options:

  • Dualcomm DCSW-1005 USB Powered 5-Port 10/100 Fast Ethernet Switch TAP (Port Mirroring) - Amazon.com link
    • Dualcomm DCSW-1000/1005PT - Dualcomm product page
  • Dualcomm DCGS-2005L 5-Port 10/100/1000 Gigabit Ethernet Switch Network TAP (Plastic Case) - Amazon.com link
  • Dualcomm DCGS-2005 5-Port 10/100/1000 Gigabit Ethernet Switch Network TAP (USB Powered, Port Mirroring, PoE Pass-Through) - Amazon.com link
    • Dualcomm DCGS-2005/DCGS-2005L - Dualcomm product page

The DCSW-1005 model is an attractive basic option. It supports port-mirroring, is USB powered, and has 5-ports. (note only port #1 is mirrored to port #5).  The price is good.  The only “drawback” I see is that it only supports 10/100 speed on the network.  While I seriously doubt I would ever approach over 100 Mbps and cause a bottleneck on my home network…most all my other network equipment is 1000 Mbps capable.  So thinking forward, this could be slightly limiting down the road, or if I am asked by family/friends/associates to do some network troubleshooting on a “true” 1000 Mbps network, or tapping in between two network devices actually running at 1000 Mbps.  So there is that. Also, the buffer memory used by the device in the mirroring process is 256 KB. So if that gets saturated, there is the possibility of dropped packet captures.

The only difference between the DCGS-2005/2005L seems to be the “L” model has a metal cabinet while the other doesn’t. Of course, that option comes with a $20 markup as well.  I’m pretty sure the plastic cabinet would be just fine, but the vanity in me just likes the metal cabinet appearance a bit more. Probably just a bit more durable when tossed around in a go-bag and maybe it might dissipate heat a bit better? This model does support up to 1000 Mbps so there is that benefit since it is (at least $100 more expensive) but the buffer memory is just 104 KB. Hmmm. 

Should I be concerned about overloading either of the devices’ memory buffer when capturing home-network traffic? Probably not but what say you pros?

I did find these pretty basic and older reviews, including one from the guru of network security Richard Bejtlich.  I really didn’t find any more recent reviews of the device so if/when I get my hands on one, you can be assured I’ll have a write-up review.

  • DualComm Port Mirroring Switch - TaoSecurity - (Sept. 2010)
  • Review of Dualcomm 5-Port Pass-Through Port Mirroring Switch - LoveMyTool - Betty DuBois - (April 2010)
  • Network Security Monitoring with Dualcomm DCSW-1005PT - CyberArms - D.Dieterle - (Nov. 2010)

Part II - In Which Other Alternatives are discovered

So let’s assume that you are already comfortable with network packet captures, installing network software, and making network configuration changes to Wi-Fi devices.

Are there any options to capture iPhone network traffic without going to the trouble and expense of picking up TAP hardware just for that task?

Yep.

First option is a tool called Paros. It is Java based (I know, I know..) and can assess web application vulnerabilities. The link has a Windows binary that appears back from August 2008.

Here is a nice walkthough on using Paros Sniff Your iPhone's Network Traffic by Jerod Santofrom to give you some introduction to it.

There was a comment on the Paros page providing information to a very current “fork” of Paros: ZAP

(Note: Not to be confused with the Zscaler ZAP service)

OWASP Zed Attack Proxy Project - OWASP - OWASP.org

There are tons of information on that page on this tool:

  • Screenshots
  • wiki videos page
  • project pamphlet - a very quick intro
  • project presentation - longer presentation

And here are some quick links on ZAP usage:

  • Owasp ZAP - InfoSec Institute post
  • Debugging SSL on Both iOS Devices and Simulators with Man-in-the-middle Proxies - CodeProject
  • Intercepting iPhone traffic with your MacBook - Shaun Zinck’s blog

Next up, we have Fiddler, a free web debugging proxy from Telerik

  • Capturing HTTP traffic on an iPhone with Fiddler - Scott Wojan’s DotRant blog
  • Configuring Fiddler to Capture Web Traffic from an iPhone/iPad Device - ESRI Support Services blog
  • How To Sniff iPhone Network Traffic - Matt McClure’s blog

Finally, if you are hard-core, just go use Wireshark.

  • iPhone Meets Wireshark – Capture Wireless Network Traffic from Mobile Devices - EtherLook

Part III - Resources, References, & Pineapples

Here are some additional links related to all of the above discussions including the Dualcomm products, SPAN/TAP considerations, and the next network device I’m interested in picking up to play with; the Wi-Fi Pineapple.

SPAN Out of the Box (PDF Link) - John He’s Dualcomm Technology PowerPoint presentation at SharkFest 2010. Goes into details about SPAN/TAP considerations and specifics on what DualComm feels makes their product super special. SPAN out of the Box (Blip video)

B-7 (Battaglia) TAPS Demystified (PPT Link) - Samuel Battaglia’s Network Critical PowerPoint presentation at SharkFest 2010.

SPAN Port vs TAP (Video) - Betty DuBois- SharkFest 2009 presentation. PowerPoint presentation here (ZIP).

SPAN Port or TAP? CSO Beware - LoveMyTool blog - Tim O’Neill

Network Monitoring Madness: Poor Man’s Resource Linkfest - GSD blog post from 2010.

Let’s Get For/Sec-Motivated! - GSD blog post from 2011.

The beginners guide to breaking website security with nothing more than a Pineapple - Troy Hunt’s blog.

Your Mac, iPhone or iPad may have left the Apple store with a serious security risk - Troy Hunt’s blog.

Pineapple Surprise! Mixing trusting devices with sneaky Wi-Fi at #wdc13 - Troy Hunt’s blog.

Netgear DS104 4-Port 10/100 Dual Speed Hub with Uplink Button (Amazon link) - recommended to look into as well by TinyApps bloggist who reports he had good experience with it.

CaptureSetup/Ethernet - The Wireshark Wiki

CaptureSetup/WLAN - The Wireshark Wiki

Cheers!

--Claus Valca

Read More
Posted in Apple, forensics, iOS, iPhone, networking, NFAT, security, troubleshooting, tutorials, utilities, video | No comments

Monday, September 2, 2013

ForSec Labor Day Blow-out Linkfest

Posted on 6:15 PM by Unknown

Final link push for the GSD blog before shutting down for the night.

I hope all you ForSec guys and gals have had a restful Labor Day before heading back into the trenches tomorrow.

Here are some links of note to review this week that I picked out.

Richard Bejtlich on His Latest Book, “The Practice of Network Security Monitoring” - M-unition blog

Did It Execute? - M-unition blog post by Mary Singh on incident response.

Anatomy of an ongoing Drive-by-Download campaign - ZScaler ThreatLabZ blog post

Browser Related":

Psst. Your Browser Knows All Your Secrets. - SANS ISC Diary guest post by Sally Vandeven on pulling the crypto keys in a browser.

Cookie Cadger to Identify Cookie Leakage from Applications over An Insecure HTTP Request - Next of Windows

Cookie Cadger - project homepage. From the link:

“Cookie Cadger helps identify information leakage from applications that utilize insecure HTTP GET requests.

“Web providers have started stepping up to the plate since Firesheep was released in 2010. Today, most major websites can provide SSL/TLS during all transactions, preventing cookie data from leaking over wired Ethernet or insecure Wi-Fi. But the fact remains that Firesheep was more of a toy than a tool. Cookie Cadger is the first open-source pen-testing tool ever made for intercepting and replaying specific insecure HTTP GET requests into a browser.

“Cookie Cadger is a graphical utility which harnesses the power of the Wireshark suite and Java to provide a fully cross-platform, entirely open-source utility which can monitor wired Ethernet, insecure Wi-Fi, or load a packet capture file for offline analysis.”

Book stuff - Windows Forensic Environment - Brett Shavers teases us again with brief news he continues to develop a standalone WinPE/FE “one-push” builder. Also he has released an early Kindle version of his X-Ways Forensics Practitioner’s Guide. Finally Brett gives recommendations for some other great ForSec reference books in his post.

Sadly, I am embarrassed to confess that I have just rediscovered the SANS Institute: Reading Room.

It appears their Latest 25 Papers RSS link to the page may have some issues as though I can load it in Firefox, trying to use it in a dedicated RSS reader generates an error that it cannot find actual RSS data on the page. Hmm.

Anyhows…since I just found it (again) there are gazillion (or slightly less) new whitepapers for review and reading.

Here are the ones I picked out that looked interesting to my desk operations:

  • 60 Seconds on the Wire: A Look at Malicious Traffic - (direct PDF Link) - SANS Reading Room whitepaper by Kiel Wadner - August 22, 2013.
  • Live Response Using PowerShell - (direct PDF Link) - SANS Reading Room whitepaper by Sajeev Nair - August 20, 2013.
  • Event Monitoring and Incident Response - (direct PDF Link) - SANS Reading Room whitepaper by Ryan Boyle - May 15, 2013.
  • Detecting Security Incidents Using Windows Workstation Event Logs - (direct PDF Link) - SANS Reading Room whitepaper by Russ Anthony  - August 22, 2013.
  • Windows Logon Forensics - (direct PDF Link) - SANS Reading Room whitepaper by Sunil Gupta - March 15, 2013.
  • Custom Full Packet Capture System - (direct PDF Link) - SANS Reading Room whitepaper by Derek Banks - April 16, 2013.
  • Security Best Practices for IT Project Managers - (direct PDF Link) - SANS Reading Room whitepaper by Michelle Pruitt - June 24, 2013.
  • Get Out of Your Own Head: Mindful Listening for Project Managers - (direct PDF Link) - SANS Reading Room whitepaper by Charlie Scott - December 20, 2010.
  • The Death of Leadership in Management - (direct PDF Link) - SANS Reading Room whitepaper by Dana Hudnall - September 12, 2013.

That last link reminded me of the following particular motivational leadership links I keep handy on my blog sidebar:

  • Getting the Job Done - TaoSecurity blog’s Richard Bejtlich.
  • AFOATS Training Manual - 2004 edition via Google Docs
  • Five Qualities of Real Leadership - TaoSecurity blog’s Richard Bejtlich.
  • What I've Learned - USNI Blog post by Alexander Martin

Cheers,

--Claus Valca

Read More
Posted in browsers, forensics, Kindle, Link Fest, networking, NFAT, security, Win FE | No comments

Network News & Goodies - Labor Day Edition

Posted on 5:14 PM by Unknown

Linkfest post on Labor Day. Lots of network goodies here for the GSD fans!

Presented in no particular order…just how they came of the bench tonight.

Viewpoints: OSI Model and APSTNDP - Microsoft’s MessageAnalyzer blog

Wireshark Tutorial Series #2. Tips and tricks used by insiders and veterans - Sniff free or die Wireshark blog

Tools - The Wireshark Wiki - great Super-List of tools and supporting material for Wireshark.

I’ve posted recently quite a gushing rant on TraceWrangler. It is a free (still-Alpha release) no-install tool to help with sanitizing and anonymizing packet trace files. Pretty wicked cool. Jasper Bongertz posted an intro here and touched on some of the issues current tools of this kind have.

I mention it because the Wireshark Wiki Tools page does contain a list of capture file anonymization tools and (sadly) TraceWrangler isn’t on it yet. Somebody with a connection needs to send the Wiki editors some memos…just saying.

TraceWrangler (change log) - now at version Alpha 0.1.3 build 308.

Microsoft Security Advisory (2861855): Updates to Improve Remote Desktop Protocol Network-level Authentication - Microsoft Security TechCenter

Sequence Match View: Identifying Interesting Network Patterns - Microsoft’s MessageAnalyzer blog

How Secure Is Your Smartphone - Check the Packets (by Tony Fortunato) - LoveMyTool blog

The Do's and Do NOT's of using SPAN Ports (by Darragh Delaney) - LoveMyTool blog

NetFort SPAN Port Configurator - freeware - GUI Utility to set Span Ports on Cisco switches…because as you know, using the free Cisco Network Assistant to do so is such a pain.

ZMAP 1.02 released - SANS ISC Diary

ZMap · The Internet Scanner. From the home page:

“ZMap is an open-source network scanner that enables researchers to easily perform Internet-wide network studies. With a single machine and a well provisioned network uplink, ZMap is capable of performing a complete scan of the IPv4 address space in under 45 minutes, approaching the theoretical limit of gigabit Ethernet.

“While ZMap is a powerful tool for researchers, please keep in mind that by running ZMap, you are potentially scanning the ENTIRE IPv4 address space and some users may not appreciate your scanning. We encourage ZMap users to respect requests to stop scanning and to exclude these networks from ongoing scanning.”

“We suggest that users coordinate with local network administrators before performing any scans and we have developed a set of scanning best practices, which we encourage researchers to consider. It should go without saying that researchers should refrain from exploiting vulnerabilities or accessing protected resources, and should comply with any special legal requirements in their jurisdictions.”

While you may not break the Internet as handily as Jen does, you might do bad things to your own. Be sure you are well familiar with the tool before experimenting!

INMAP 6.40 Released - SANS ISC Diary

Nmap Change Log - nmap.org

Download the Free Nmap Security Scanner for Linux/MAC/UNIX or Windows - nmap.org

SoftPerfect WiFi Guard - version release to 1.0.3 (Change log)

NetworkTrafficView - NirSoft - version release to 1.76:

  • Added 'Maximum Packet Size' column. For TCP connections that transfers significant amount of data, the value under this column represents the actual MTU.

Wireless Network Watcher - NirSoft - version release to 1.67

  • Updated the internal MAC addresses database.

KiTTY - update to current version release of 0.63.0.2

60 Seconds on the Wire: A Look at Malicious Traffic (direct PDF Link) - SANS Reading Room whitepaper by Kiel Wadner - August 22, 2013.

Custom Full Packet Capture System - (direct PDF Link) - SANS Reading Room whitepaper by Derek Banks - April 16, 2013.

Updated from another recent GSD post because they seemed apropos here in this as well:

Psst. Your Browser Knows All Your Secrets. - SANS ISC Diary guest post by Sally Vandeven on pulling the crypto keys in a browser.

Cookie Cadger to Identify Cookie Leakage from Applications over An Insecure HTTP Request - Next of Windows

Cookie Cadger - project homepage. From the link:

“Cookie Cadger helps identify information leakage from applications that utilize insecure HTTP GET requests.

“Web providers have started stepping up to the plate since Firesheep was released in 2010. Today, most major websites can provide SSL/TLS during all transactions, preventing cookie data from leaking over wired Ethernet or insecure Wi-Fi. But the fact remains that Firesheep was more of a toy than a tool. Cookie Cadger is the first open-source pen-testing tool ever made for intercepting and replaying specific insecure HTTP GET requests into a browser.

“Cookie Cadger is a graphical utility which harnesses the power of the Wireshark suite and Java to provide a fully cross-platform, entirely open-source utility which can monitor wired Ethernet, insecure Wi-Fi, or load a packet capture file for offline analysis.”

Cheers.

--Claus Valca

Read More
Posted in forensics, Link Fest, Microsoft, networking, NFAT, Remote Support, tutorials, utilities | No comments

Sunday, August 11, 2013

Network & Network Security Quickpost - Last call NFAT edition

Posted on 8:22 PM by Unknown

I just couldn’t wrap up the weekend without sharing these links. I’m so going to be nodding off in my training class tomorrow. Must bring Thermos of extra coffee with me! Don’t want to make the teacher unhappy!

So many network tools, tricks, and nuggets came out last week I’m still exciting thinking about how to use them all!

Security Advisory: Two Vulnerabilities in NetworkMiner - NETRESEC Blog - Don’t let the boring post title fool you! Based on this, Erik Hjelmvik has released a new version of NetworkMiner! Now sparkling at version 1.5 (free/pro editions)

NetworkMiner packet analyzer - Download NetworkMiner version 1.5 (free) here.

While I was doing some super-fast (but apparently productive) beta testing for Erik on some Windows 7 and Windows 8/8.1 systems, I noticed I wasn’t getting great results from my test captures made with and being processed in NetworkMiner. My “doh”. Erik kindly reminded me of his post NETRESEC RawCap - A raw socket sniffer for Windows where he pointed out that using Windows raw socket sniffing has some problems. I had forgotten I didn’t yet install Wireshark/WinPcap on these particular test systems. From Erick’s post:

Microsoft's newer operating systems (later than WinXP) have limitations associated with raw socket sniffing of external interfaces, i.e. everything that isn't localhost. Known limitations in Windows Vista and Win7 are:

  • Windows 7 - Can't capture incoming packets
  • Windows Vista - Can't capture outgoing packets
Due to these limitations in the raw sockets implementations of Microsoft's current operating systems we suggest running RawCap on Windows XP if you need to capture from external interfaces.

Baselining Dropbox With Wireshark (by Tony Fortunato) - LoveMyTool blog video presentation.

Editing Tracefiles With TraceWrangler (by Tony Fortunato) - LoveMyTool blog video presentation. This short video presentation on a new (Alpha release) tool, TraceWranger blew me away. There are methods of sanitizing trace files for sharing/training but they are fraught with challenges for mere mortals. This new tool is amazing and I really hope the developer Jasper Bongertz gets the support needed to encourage his continued refinement and development of this valuable tool for analysts.

  • TraceWrangler - (alpha software) - currently at build version 0.1.3. Standalone application. No installation needed. Unzip and go. Written by Jasper Bongertz.
  • TraceWrangler Documentation - This is Must Read material if you are interested in using this tool properly
    •  Starting TraceWrangler - the basics
    • Anonymization Tasks - details for the options
  • Trace File Sanitization NG - SEC-04_Trace-File-Sanitization-NG_Jasper-Bongertz (PDF) - Link to his presentation of the tool at Sharkfest 2013.
  • Sharkfest 2013 - Trace File Sanitization (Jasper Bongertz) - YouTube. While PDF versions of presentations are nice, on a whim I decided to see if Jasper’s presentation was actually up on YouTube for viewing. It was!
  • Trace file sanitization for network analysts - Packet Foo - Jasper’s blog post with additional details on his tool in case you missed the presentation.
  • The notorious Wireshark “Out of Memory” problem - Packet Foo. Oh how this has hobbled me over the years! So much so that CLI based captures became my dearest friend!
  • Packet Foo RSS - Yeah. It’s that good. Feed yourself on it!

Nmap - Now at version 6.40 - Free Security Scanner For Network Exploration & Security Audits.

  • Nmap Change Log
  • Download Nmap Security Scanner - for Linux/MAC/UNIX or Windows

Message Analyzer Beta3 Refresh has Been Released (Build 6215) - MessageAnalyzer - Lost in all the news was a quiet announcement of the next generation of Microsoft’s own network traffic analysis tool MessageAnalyzer getting a Beta 3 refresh release. The interface is very different (to me) from Wireshark, but since I used NetMon a ton to supplement my Wireshark work, it is taking some getting used to.

HolisticInfoSec: toolsmith: C3CM Part 1 – Nfsight with Nfdump and Nfsen - HolisticInfoSec blog - Russ McRee’s post rocks on so many levels. Well worth the read and review.

Firefox Developer Tool Features for Firefox 23 - Mozilla Hacks – the Web developer blog. In case you missed it, Firefox 23 was released last week. Included in it (besides the new app icon update) was a new network tool called “Network Monitor.” 

I so love this! “F12” is the new “must know” hotkey in these modern browsers!

If only Mozilla (or Chrome or IE 10) were “approved” web-browsers in our enterprise. This feature alone would so help with network and web-app diagnostics and troubleshooting from the end-user desktops.

What’s that you say? One single element of your cloud-based web-application seems to time out in IE 8, crashing your session? The network is fine, site bandwidth is fine. Your PC is fine. Seems like it could be a server-side application issue. Let me make a ticket for your issue and send it up. (Response often comes back, “There is no problem…must be a client-side issue…check the PC and bandwidth, follow our response template and let us know…”) (Sigh…)

  • Network Monitor, now in Firefox Beta - Mozilla Hacks – the Web developer blog - More details on the feature.
  • A look at Firefox's new Network Monitor - Ghacks - Martin Brinkmann does an outstanding job introducing it as well.

Turns out Chrome web browser can do this trick as well

  • Evaluating network performance - Chrome DevTools — Google Developers
  • Performance profiling with the Timeline - Chrome DevTools — Google Developers
  • Chrome Dev Tools: Networking and the Console - Nettuts+
  • Google Chrome Dev Tools: Network Panel - TechRepublic

Turns out that Internet Explorer (IE9, IE10, IE11) also have a “F12” feature for network analysis in the browser.

  • Introduction to F12 Developer Tools (Windows) - IE Dev Center
  • Navigating the F12 Developer Tools Interface (Internet Explorer) - IE Dev Center
  • Internet Explorer's F12 Developers Tools: A feature walk-through - TechRepublic
  • A Peek at Internet Explorer’s Developer Tools - Nettuts+
  • Network Traffic Capturing with IE9 Developer Tools - LINQED.NET

And in IE11, it’s about to bring the house down on the competition!

Debugging and Tuning Web Sites and Apps with F12 Developer Tools in IE11- IEBlog. OMG!!! I am so crushing on the new “F12” profiling and responsiveness tool interface in IE 11! Please tell me this is going to be backwards compatible with Win 7. (Why yes, Virginia, it is…)

3ohix43s.dfg

Anyway, back to more Firefox 23 release news and details.

  • Firefox 23 lands with a new logo and mixed content blocking - Ars Technica
  • Firefox Notes - Desktop - Mozilla.org
  • Firefox 23 enables mixed content blocking, consolidates search settings - BetaNews
  • A Look At What's New In Firefox 23 - Addictive Tips blog

Troubleshooting TCP/IP Connectivity Issues with This Command-Line Utility Portqry.exe - Next of Windows. Been using portqry.exe from the command line along with the PortQueryUI GUI fro some time. Dead helpful in a pinch!

PuTTY: a free telnet/ssh client - just released at version beta 0.63 for you console fans! See the extensive Changes page for all the details

  • PuTTY Portable 0.63 - PortableApps.com build version as well is available and updated.

KiTTY - let’s not forget about this fork version of PuTTY that has some additional bells-and-whistles!

  • News - latest KiTTY news is update 0.62.2.3 minor update in late May 2013.
  • Recent changes - tracking site-changes at KiTTY’s house
  • KiTTY Portable - why “yes” there is a PortableApps.com build version as well for KiTTY fans.

Finally, at home I run Mozilla Firefox, Portable Edition and Google Chrome Portable rather than installing them directly on my system. However I was trying to use some of NirSoft’s Browser Tools to explore and check my Google Chrome(ium) cache and wasn’t finding anything at all.

Strange.  Bug in the tool?

Turns out the answer was “of course not dummy” it’s the dummy’s bug.

Where is the Google Chrome Portable cache folder? - PortableApps.com. Bruce Pascoe kindly puts it like this:

Chrome Portable, like FFP, doesn't save the cache by default.

Note that unlike Firefox however, there's no way to turn the cache off completely in Chrome, so while it's running the cache is stored in the local temp directory (%TEMP%), but then it's immediately deleted when you exit Chrome.

So anyway, yeah, no surprise that you couldn't find it.

and cleared up a bit by “The MAZZTer”

The cache folder is saved in %TEMP%\GoogleChromePortable.

Where the %TEMP% is the user’s temporary file location under their profile.

04i5mjur.uan

This is interesting as it explains why the NirSoft tool ChromeCacheView wasn’t finding anything while pointing to the default user profile location in my Portable Apps application structure that ChromeHistoryView didn’t seem to have any issue with parsing. So even though the files were removed when the program terminated, it most likely did not “secure” delete them, so (depending on overwrite activity of the file system/free-space scrubber utilities) it might be possible to carve and recover them from a system that the portable-apps version of Chrome was used on. And that sounds like a challenge for another day…

Cheers!

--Claus Valca

Read More
Posted in browsers, Firefox, forensics, Google, Internet Explorer, Link Fest, Microsoft, networking, NFAT, security, troubleshooting, utilities | No comments

Sunday, July 28, 2013

ForSec “Value Package” Linkfest - No coupons required!

Posted on 5:00 PM by Unknown

One last Linkfest from a now exhausted GSD blogger this weekend.

Cleaning out the “to-be-blogged” hopper is always rewarding, but I tend to get very behind on the weekend chores. My saving grace this weekend has been frequent scattered showers and an equally tired Lavie who hasn’t been interested in going out for shopping, groceries, or dining out. The kitchen has been cleaned. The laundry has been done for the week.

Next stop, a few hours of rest, post-blogging, then a wind-down with Endeavour on PBS Masterpiece.

Too Funny Not To Miss

Bloody galah scammers still not getting the message - Troy Hunt’s blog. Security guru Troy Hunt has had his fair share of “this is (not) Microsoft cold calling you…your PC is infected…let me remote control it” scams and has picked them all apart to the bone.

This time he takes a new angle…in a way that only an Aussie could pull off!  This is a classic! Troy, please offer us some of those sound files or link to where we can get them!  I need to put together a Texan sound-effect package for similar fun with unwanted callers. Brilliant!

Microsoft Security News

Microsoft Releases New Mitigation Guidance for Active Directory - Microsoft Security Blog

Overview of Microsoft`s "Best Practices for Securing Active Directory" - SANS Computer Forensics and Incident Response blog’s Mike Pilkington does a great summary and takeaway of the new AD mitigation guidance.

Security Awareness Training: Your First Line of Defense (Part 4) - WindowSecurity.com’s Deb Shinder discusses evaluating training effectiveness short and long-term.

See also these previous series posts:

  • Security Awareness Training: Your First Line of Defense (Part 1)
  • Security Awareness Training: Your First Line of Defense (Part 2)
  • Security Awareness Training: Your First Line of Defense (Part 3)

Network Security, News and Techniques

Wireshark 1.8.9 and 1.10.1 Security Update - ISC Diary

  • Wireshark 1.10.1 - Release Notes
  • Wireshark 1.8.9 - Release Notes
  • Wireshark - Downloads

Next up are some great and detailed video presentations from Sharkfest 2013

  • Sharkfest 2013 - Wireshark Network Forensics (by Laura Chappell)
  • Sharkfest 2013 - Trace File Sanitization NG (by Jasper Bongertz)
  • Sharkfest 2013 - Attack Trends and Techniques (by Steve Riley)
  • Sharkfest 2013 - Capture Limit of a Laptop, When does it Drop Packets? (by Chris Greer)

Recent Forensically Focused Posts

  • HowTos - Windows Incident Response blog
  • HowTo: Malware Detection, pt I - Windows Incident Response blog
  • HowTo: Data Exfiltration - Windows Incident Response blog
  • HowTo: Add Intelligence to Analysis Processes - Windows Incident Response blog
  • HowTo: Determine/Detect the use of Anti-Forensics Techniques - Windows Incident Response blog
  • HowTo: Investigate an Online Banking Fraud Incident - Windows Incident Response blog
  • Finding an Injected iframe - Journey Into Incident Response blog
  • MS Excel and BIFF Metadata: Last Opened By - Digital Forensics Stream blog

Physical (In)Security?

Duplicate house keys online - Keys Duplicated - This is either freaking amazing or super-scary. I just can’t decide! According to their Security page, precautions are taken.

The Keys Duplicated Blog - A couple really cool and technical posts on the behind the scenes things that make their keys pretty good.

…as spotted on Lifehacker’s post: Shloosl Copies Your House Keys Using a Smartphone Photograph

When 'Smart Homes' Get Hacked: I Haunted A Complete Stranger's House Via The Internet - Forbes

ForSec LiveCD Distro News

  • More on WinFE and Autopsy - Windows Forensic Environment blog
  • DEFT Linux 8 stable with DART 2 is out! - DEFT Linux - Computer Forensics live cd
  • Kali Linux Summer Update Release 1.0.4 - Kali Linux
  • Pass the Hash toolkit, Winexe - Kali Linux
  • Downloads - Kali Linux

AV/AM Bits

Microsoft Security Essentials quietly released version 4.3.216.0 engine update for their free antivirus scanning program. If you use MSSE, you should get it via the automatic updates…if you have them turned on…you do have them turned on right?

Download Microsoft Security Essentials - Microsoft Download Center - Like most things MSSE, trying to figure out just what got updated is next to impossible so let’s just say for now that this one must be better than the previous version and move on.

I’m still using MSSE around the Valca home on all our home systems. I also continue to recommend it to friends and family (generally everyone non-work-related) who I provide friendly IT support to. I find it is pretty non-threatening to the non-technical users I know and though it loves to alert on many of my security programs (potentially unwanted programs) since they can also be used for 3vil, it seems to do a more than adequate job security the systems.

For my Windows 8 systems, I’m instead relying on Bitdefender Antivirus Free. In some ways it’s a bit different model in that you need to sign up with an email address to set up your account. Then you can download the client to the system. What is nice is that if you manage multiple systems in your home, you can log into your account at their site and then get a console feedback on the status of those systems. That’s something that I do at work with another vendor’s enterprise AV client health/status management console. That’s super cool for a free product. I’m seriously leaning to expanding it’s coverage to my main Windows 7 laptop at home. Performance has been outstanding on my Windows 8 systems.

Kaspersky tops real world protection test - BetaNews - this post does point out that Bitdefender tied Kaspersky with a 99.9 % protection level in AV-Comparatives Independent Tests of Anti-Virus Software for July 2013. While Microsoft Security Essentials rated a 92.5 % protection level. There are some additional disclaimers so read the short BetaNews article carefully. Then head over to AV-Comparatives to dig deeper and see the full findings.

  • AV-Comparatives Real-World Protection Test March-June 2013 - AV-Comparatives
  • AV-Comparatives Real-World Protection Tests - AV-Comparatives

Finally, we wrap up this segment with this interesting discussion:

The evolution of Ronvix: Private TCP/IP stacks - Microsoft Malware Protection Center

It’s a bootkit infection that has its own private TCP/IP stack. By doing so it can be extra stealthy and bypass personal firewall hooks and can lurk unseen in standard tools and utilities (such as nbtstat). Doing so, depending on packet/network monitor off the infected machine may be ineffective. However, it still must talk ON the network, so an independent network monitoring and forensics analysis approach using a network monitoring appliance or span port capture may detect the traffic. This may be why comparing outside network traffic captures from a system on the network to network traffic captured on the system may be a useful exercise for incident response and monitoring purposes.

Legally Focused

I’ve been reading a wider range of subjects, and a small part of those touch on our legal system. Mainly they apply to digital law and crime but some are more general. I’m just tossing them out there for the interested or curious. Generally they tend to analysis of current events or provide a more detailed lawyer’s review than the talking/shouting legal heads we encounter on mass-media “news-like” entertainment outlets these days.

  • CYB3RCRIM3 - Susan Brenner’s blog on cybercrime and cyberconflicts in technology and law.
  • Popehat - group blog with a mostly legal focus (though topics can range far afield!)
  • Le·gal In·sur·rec·tion - group blog with mostly legal and law-in-today’s-culture focus. Pretty vibrant opinions. Alignments may vary.
  • Lowering the Bar - Sometimes lighthearted (though always serious at the core) look at some of the nonsense the legal system contains, or foists on others from time to time. Great site.
  • Massad Ayoob - legal, cultural, and educational postings primarily dealing with legal private firearm ownership issues. Also analysis of public media trends and news stories.

Have a great week!

--Claus Valca

Read More
Posted in Active Directory, anti-virus software, boot-cd's, cheat sheets, firewalls, forensics, humor, Link Fest, malware tools, Microsoft, networking, NFAT, security, troubleshooting, tutorials, utilities, video, viruses, Win FE | No comments

Sunday, April 28, 2013

ForSec News Roundup

Posted on 4:04 PM by Unknown

Final GSD post of the weekend. 

Strategies of a world-class computer security incident response team - Help Net Security - Carson Zimmerman presents “…ten fundamental qualities of an effective CSIRT that cut across elements of people, process, and technology.” Run-time is just over 33 min.

ProcDOT - Visual Malware Analysis - SANS Computer Forensics and Incident Response blog. Christian Wojner introduces it thusly…“It correlates Procmon logfiles and PCAPs to an interactively investigateable graph. Besides that ProcDOT is now also capable of animating the whole infection evolution based on a timeline of activities. This feature lets you even quickly find out which server or which requests were responsible that specific data/code got on the underlying system, by which process it was written, how often, who injected what, which autostart registry key was set, what happened when, and so forth ...” Get it via ProcDOT - CERT.at

From the ProcDOT project page:

Screenshot

3crmye3k.ddd

Instruction-Media

The User Interface
Tutorial-Video 1: The User Interface
Tutorial-Video 2: The Graph
Tutorial-Video 3: Analysis (Part 1)
Tutorial-Video 4: Analysis (Part 2): The Timeline

Over at the ISC Diary blog, Mark Baggett has been posting a great series of articles examining the tug-and-pull between those in IT/Sec who advocate a full OS wipe/reload after a malware infection and those who say “save-time-and-clean-it” by removing the malware infection, but not reimage the system. There still seems to be some kind of mysterious desire by staff to possibly prove what a clever IT person we are by digging an infection out of a system rather than just recovering the user’s data, wiping the system, then restoring it from a clean image and putting the data back. Maybe we all want to be a hero. However, as Mark’s posts show, if not done properly and effectively, the malware may remain persistently hidden but functional and you may be back before you know it (and the rest of your data secrets lifted or network exploited). These posts are a good guide and gut-check for how challenging these threats can play hide-and-seek. Familiarity with these techniques might be your last line of defense if your shop doesn’t have a fast-n-hard policy of recover/wipe/restore remediation.

  • Wipe the drive! Stealthy Malware Persistence Mechanism - Part 1 - ISC Diary blog
  • Wipe the drive! Stealthy Malware Persistence - Part 2 - ISC Diary blog
  • Wipe the drive! Stealthy Malware Persistence - Part 3 - ISC Diary blog
  • Wipe the drive! Stealthy Malware Persistence - Part 4 - ISC Diary blog

Tracking Down Persistence Mechanisms - Journey Into Incident Response blog - Not to be outdone, Corey Harrell does a great companion-piece to the ISC Diary blog posts above.  Corey details how he uses Microsoft Autoruns utility in that process.

From one of the comments there, we jump over to Finding Evil: Automating Autoruns Analysis post over in the trustedsignal blog from Dave Hull.

And then in spot-on timing within the ForSec community, Mark Woan at woanware releases a new utility called autorunner. 

“Autorunner is based upon the AutoRuns tool by the Sysinternals/Microsoft gurus. It is designed to perform automated Authenticode.aspx) checking for binaries designed to auto-start on a host. Its primary purpose is to aid forensic investigations.

“…autorunner is designed to work around all of these issues. It will check against all user profiles associated with the host. It will parse out LNK files to the actual binary (one level down). It allows the user to specify multiple drive mappings, so that if the forensic image contains multiple partitions you can map the original drives to mounted drives on the forensic workstation.

“The application should be used against a forensic image that has been mounted using whatever method you desire.”

Securely wiping an SSD - TinyApps blog - Getting back to the drive-wiping thought, this quick-post reminds us of some of the hazards of attempting to sanitize a SSD device. Some might think using a SSD device to hold image captures might be a good idea but if you do, be sure it is one you can truly “zero-out” and sanitize before porting your image over to it! Does anyone use SSD devices yet for that purpose? What other challenges (cost aside) would this present. Are there any benefits to a SSD over a HDD for storing or capturing disk images?

Placing the Suspect Behind the Keyboard – NEW BOOK! - Windows Forensic Environment - Congratulations to Brett Shavers for his new book! It’s been added to my Amazon.com wish-list queue for triggering once my next Amazon.com gift certificate ship comes into port.

Tool Time - The Hacker Factor Blog - A great post in the theme of “know your tools” before you trust the results they provide. One of the gem finds in Dr. Neal Krawetz’s post is his link to the National Institute of Standards and Technologies (NIST) and National Institute of Justice (NIJ) 2012 Computer Forensics Tool Testing Handbook from their computer forensic tool testing program. It’s got 173 pages of goodness to review. The latest publications can be found on this Topical Collection: Computer Forensic Tool Testing Publication Database | National Institute of Justice.

4:mag Issue #1 - Forensic 4cast. A very nice and slick digital publication debuts. This edition covers topics in iOS device/application data & malware, starting out in the digital forensics field, and hard-drive secrets.

The students over at the Champlain College Computer & Digital Forensics department have been busy working on papers addressing Private Browsing. Expect more in this series:

  • Private Browsing Forensics: Introduction - (PDF Link) Private Browsing Forensics: Introduction
  • Private Browsing Part 2 - (PDF Link) Private Browsing Part 2

RegRipper Ripper (3R) and the list of reg keys covered by RR plugins - hexacorn bog.

RegRipper Consolidation - Windows Incident Response blog. Harlan and crew have been super-busy trying to clean house and tie up some loose ends in the RegRipper landscape. This new effort should help make “one-stop-shopping” and development support for RegRipper and plug-ins much easier. Additionally, Harlan has been working hard on the blog to post additional background information on some of myriad (Cory referred to 280+ in his post) RegRipper plug-ins.

Forensic 4cast Awards 2013 – Meet the Nominees - Forensic 4cast. Voting is now open. You can place your votes here.

Encrypted Disk Detector Version 2 - SANS Computer Forensics and Incident Response blog - Chad Tilbury announces and introduces a new version that is out. Get it here over at Magnet Forensics.

What is "up to date anti-virus software"? - ISC Diary.Great post and great discussions in the comments.

Case Leads: LivingSocial Hack, New Cyber Warriors, analyzeMFT update and more... - SANS Computer Forensics and Incident Response blog

Cheers!

--Claus Valca.

Read More
Posted in anti-virus software, books, forensics, iOS, Link Fest, malware tools, networking, NFAT, security, utilities, viruses, Win FE | No comments

ForSec LiveCD bits

Posted on 2:37 PM by Unknown

Things have been fairly quiet in the ForSec LiveCD world since the Kali Linux distro dropped.

They dropped a minor update last week for Kali Linux Accessibility Improvements for blind or visually impaired users. That was a nice touch.

  • CAINE 4.0 and NBCaine 4.0 codename "Pulsar" released! - CAINE. Main features include the 3.2.0-38 kernel & GuyMager 0.7.1, additions of LibreOffice 4.0.1, Squliteman, Remote Filesystem Mounter, adparm, netdiscover, and fixes to netcat works and GHex.  On the windows side of the CD, NirLauncher with FTK Imager and Sysinternals tools packed in as well. Lots of neat improvements here so go download your ISO!
  • New Release of REMnux Linux Distro for Malware Analysis - Lenny Zeltser on Information Security announces Version 4 of the REMunx Linix Distro.
  • Installing the REMnux Virtual Appliance for Malware Analysis - SANS Computer Forensics and Incident Blog has a great walkthough post from Lenny Zelter.
  • ISC Handler Lenny Zeltser's REMnux v4 Reviewed on Hak5 - ISC Diary. Review picks up at the top by Hak5’s host Shannon Morse.
  • REMnux: A Linux Distribution for Reverse-Engineering Malware - Home page and download links
  • WinFE and UEFI Secure Boot! - Windows Forensic Environment blog. Brett Shavers has some notes of interest on some of the technical challenges facing WinFE users with UEFI secure booting.
  • WinFE CTIN 2013 Presentation - Windows Forensic Environment blog. Brett Shavers has graciously shared his WinFE presentation: WinFE CTIN (PDF file link).

--Claus V.

Read More
Posted in boot-cd's, forensics, Link Fest, Linux, malware tools, NFAT, security, utilities, Win FE | No comments

Network fun and news

Posted on 12:36 PM by Unknown

And here is a roundup of tips, news, tools and techniques in the world of networking…

  • Troy Hunt: The beginners guide to breaking website security with nothing more than a Pineapple - Troy Hunt - If you use or support WiFi stop what you are doing right now and read this. And be terrified. and then make sure you go back and audit/configure your WiFi router and browser and system as securely as you can. Crap. Now, where did I put those 50’ Cat-6 patch cords from Cables-to-Go?
  • Detecting TOR Communication in Network Traffic - NETRESEC Blog
  • NetFort Span Port Configurator (by Tony Fortunato) - LoveMyTool blog
  • ColaSoft nChronos Intro and Troubleshooting (by Tony Fortunato) - LoveMyTool blog
  • The Importance of Watching the Wire - Packet Life
  • NetConnectChoose - New NirSoft utility - Set the default Internet connection and view general connection information. More information in this NirBlog post - New utility to select the default Internet connection and to view Internet/network connection information
  • TcpLogView - New NirSoft utility - Creates TCP connections log. More information in this NirBlog post - New utility that displays TCP connections log
  • LDWin: Link Discovery for Windows - What the.....? blog - new Windows utility to discover link information for devices connected to devices that support the Link Layer Discovery Protocol (LLDP) as well as Cisco Discovery Protocol (CDP). Free!  See also the developer’s super handy for troubleshooting tool WinCDP
  • How to install the loopback adapter in Windows 8 - 4sysops

Cheers.

--Claus V.

Read More
Posted in Link Fest, networking, NFAT, security, utilities | No comments

Ubuntu 13.04 (Raring Ringtail) Upgrade..a bit faster this time

Posted on 11:51 AM by Unknown

Yesterday turned out to be a deluge of epic proportions.  A moisture-saturated atmosphere dumped an unexpectedly large amount of water across the upper Gulf Coast. The Houston area had to deal with waves of hail, flooded freeways littered with floating and abandoned cars, high-water rescues, and general misery. What the local forecasters said on Friday would be a 10-30% chance of scattered showers became a 100% certainty of something floating in backyards everywhere. 

So it was the perfect day to settle in with my visiting father-in-law as the girls swam around town and watch home-improvement shows on cable and perform an upgrade to by VirtualBox session of Ubuntu.

  1. Find in RSS feeds that my Ubuntu 12.10 Quantal Quetzal install has a 13.04 Raring Ringtail upgrade available.
    ●  Ubuntu 13.04 is ready to deploy - Ubuntu
    ●  Ubuntu 13.04 boosts graphics performance to prepare for phones, tablets - Ars Technica
    ●  Ubuntu 13:04 Raring Ringtail published: The most important features at a glance - Caschys Blog (GTranslated)
    ●  New Ubuntu version hits today! - Boing Boing
    ●  Ubuntu 13.04 'Raring Ringtail' gives some, takes some - BetaNews
    ●  Hands-On With The New Features In Ubuntu 13.04 Raring Ringtail - AddictiveTips
  2. Begin making plans to do an in-place upgrade of my VirtualBox Ubuntu build…forgetting I had recently updated VirtualBox to 4.2.12 and it didn’t hurt my Windows VM systems…so why should I care about Ubuntu impact.
    ●  Downloads – Oracle VM
    ●  Changelog – Oracle VM VirtualBox
  3. Launched my VirtualBox Ubuntu build and logged in normally…and got a blank desktop. I did this several times. I could launch the VM and get the expected account login window for Ubuntu 12.10 just fine, but the desktop would never load. Hmmm. Wonder if that recent VirtualBox update had anything to do with it? Probably.
  4. Did some research and found some posts regarding VMWare upgrades screwing with Ubuntu in the past and they had tips about disabling 3D acceleration in the VM machine settings. VirtualBox has a similar feature (that was enabled) so I disabled it, relaunched the Ubuntu VM and now was able to load the desktop! Lesson learned; after upgrading VirtualBox, disable 3D acceleration on first-boot.

    hk3ijk2t.dbz
    ●  Latest Ubuntu update broke cinnamon · Issue #1763 · linuxmint/Cinnamon - GitHub
    ●  Later remember I also had 3D headaches last Ubuntu upgrade that I had to power-through.
  5. At that point I was able to install/upgrade to the latest VirtualBox Extension pack within Ubuntu proper. It ran slow as molasses but got the job done. Shut down the VM when done, re-enabled 3D acceleration in the VM machine settings, and was able to log back into the Ubuntu desktop with no issues and it was super-fast again. Yea! Looks like my former fixes from that post are still sticking:
        ● Ubuntu 12.10 – VirtualBox Guest Additions not Working -Complete, Concrete, Concise
        ● #10901 (vboxvideo fails to auto-load on Ubuntu 12.10 Guest) – Oracle VM VirtualBox
        ● virtualbox.org • View topic - Ubuntu 12.10 "virtually" unusable
        Edited “/etc/modules” file to include “vboxvideo” line as suggested above. Shut down.
        ● [ubuntu] newbie question on editing as root - Ubuntu Forums
        Edited “/etc/modules” file to include “vboxvideo” line as suggested above. Shut down.
        ● [ubuntu] newbie question on editing as root - Ubuntu Forums
  6. Used Daniel Benny Simanjuntak’s tip in the last Ubuntu post comments I did to run the following command from the terminal to start the upgrade process: Piece of Cake (and it wasn’t a lie)!
         …through terminal one can upgrade as well using the command:
          sudo do-release-upgrade -d
  7. Let it run forever…do a few reboots…
  8. When it is all settled down, I log in and kick the tires a bit, and change the desktop to the snazzy Raring Ringtail image.

    52rur2va.rbu
  9. Check “Upgrade to Raring Ringtail” off my to-do list.

I keep this particular Ubuntu build around mostly for working with the super-cool NFAT Xplico. However it is good for testing additional specialized software utilities and just trying to get more familiar with the Ubuntu environment in general.

This particular virtual HDD is just 8 GB so free space is a premium. I could expand it to at least 10 GB but HDD space on my laptop is at a premium so for now I’m trying to keep it thin.

After I got the upgrade done, I uninstalled some extra programs that had come in the default Ubuntu build to make room. I also ran through a few of the tips in this older Mike's Software Development Blog: Freeing hard disk space in Ubuntu Linux post. There may be more tips for freeing up space I haven’t found yet. I’m open for new tips and tricks!

Finally, the super awesome and brilliant Ubuntucat must be living here on the Gulf Coast as well as she has found a bunch of free time (homebound due to biblical-portioned rainstorms perhaps?) and is ripping out tons of posts on Ubuntu 13.04 over the last two days! Thank you, Thank you, Thank you Ubuntucat!

  • Installing Ubuntu 13.04 - Ubuntucat
  • Installing software in Ubuntu 13.04 - Ubuntucat
  • Tweaking Privacy Settings in Ubuntu 13.04 - Ubuntucat
  • Installing proprietary drivers on Ubuntu 13.04 - Ubuntucat
  • Pure Ubuntu 13.04 - Ubuntucat
  • Pure Kubuntu 13.04 - Ubuntucat (see Kubuntu | Friendly Computing for more info on this build)
  • Pure Xubuntu 13.04 - Ubuntucat (see Xubuntu for more info on this build)
  • Pure Lubuntu 13.04 - Ubuntucat (see lubuntu | lightweight, fast, easier for more info on this build)

--Claus V.

Read More
Posted in Linux, NFAT, tutorials, virtualization, Xplico | No comments

Monday, February 18, 2013

ForSec/Sysadmin Super Linkfest

Posted on 3:47 PM by Unknown

Yes indeed. I have been super-busy at home and work of late. Though the material keeps rolling in daily, my ability to get it out has been hampered a bit with “real-life” commitments.

So I’m taking advantage of a lull in the storm to dump my link hopper for your enjoyment and my reference.

Grab some snacks, make sure your wireless mouse is fed up on batteries and cheese, and settle in for some serious linkage dumping.

The Java/Flash Patch Cycle

In a sign of just how long it has been since I posted (and the activity that has transpired since mid-January) I submit the following. Note sarcasm attached.

  • Java 0-Day patched as Java 7 U 11 released - ISC Diary
  • Oracle patches widespread Java zero-day bug in just three (days, that is) - Ars Technica (Java 7.11). Hurray! Patched & Secure!
  • Security experts on Java: Fixing zero-day exploit could take 'two years' - ZDNet. Umm. So I’m not patched after patching?
  • Critical Java vulnerabilities confirmed in latest version - Ars Technica. Snap.
  • Java’s new “very high” security mode can’t protect you from malware - Ars Technica. So the point is, what exactly, Oracle? 
  • Another day, another Java security failure - Ed Bott.
  • Oracle releases emergency patches for Java - The H Security: News and Features - Yea! See it didn’t take Oracle ‘two-years’ to patch Java after all! Hurray!
  • Mozilla pulling plug on auto-running nearly all plugins - The H Security: News and Features.
  • Firefox will block by default nearly all plugins - HelpNet Security. Umm. Mozilla? Do you know something the rest of us don’t on those patched plugins?
  • Zero-Day Vulnerabilities Found in Adobe Flash Player - TrendLabs Security Intelligence Blog.  And not be left outdone in publicity, Adobe Flash steps up with new vulnerabilities. Time to patch.
  • Adobe issues emergency Flash update for attacks on Windows, Mac users - Ars Technica
  • Research & Analysis of Zero-Day & Advanced Targeted Threats: LadyBoyle comes to town with a new exploit - Malware Intelligence Lab from FireEye - Flash exploit in action.
  • Thanks, Adobe. Protection for critical zero-day exploit not on by default - Ars Technica - Now what? For crying-out-loud Adobe, I’ve got to enable some exploit protections manually? How the friggin’ are non-tech users to know and keep up with this? Sheesh.
  • Mitigate the Adobe Reader/Acrobat XI Vulnerability - F-Secure Weblog : News from the Lab
  • Adobe Acrobat and Reader Security Update Planed this Week - ISC Diary.  Really? Is this another one I need to manually activate or will you activate it for me this time?
  • Java Archive Downloads - Java SE 7 - get your Java 7 SE downloads in all their prior versions
  • Java Downloads for All Operating Systems - Java SE 7 - get your latest version here (currently 7.13).
  • Java Runtime Environment 6 Downloads - Java SE 6 - Get your latest version for Java 6 here (currently 6.39).
  • JavaFX Download for JDK6 - You may or may not need this. But if you do need JavaFX you can get the latest here.
  • Where can I get the latest version of Java 6? - Java. Umm. So Oracle seems to be saying they are pulling public download support for future versions of Java 6. Other sites will mirror older versions, but the pickings are about to get thin. Hopefully if you are running Java SE, you can jump to 7 if you haven’t already done so.
Java SE 6 End of Public Updates
After February 2013, Oracle will no longer post updates of Java SE 6 to its public download sites. Existing Java SE 6 downloads already posted as of February 2013 will remain accessible in the Java Archive on Oracle Technology Network. Developers and end-users are encouraged to update to more recent Java SE versions that remain available for public download
  • Adobe Flash Player Distribution - Adobe. Get your latest exe/msi version downloads here.
  • Shockwave Player Distribution Downloads - Adobe. Get your latest exe version downloads here.

So where does that leave us?

Remove Java? I doubt it. - Malware Analysis Blog. I did!

I actually have decided to remove Java SE from our home systems. I do like to run some Java apps but that is pretty rare so I will install, run, de-install Java as needed. Small price for system security.

In a bit of irony, shortly before drafting this blog-post statement, Lavie brought me her iPhone and iPod and told me she sent me a link to a band she follows. As a hard-core fan, she was treated to a free download of some tracks from the artist’s portfolio. She needed these added to her devices. When I followed the link to download the tracks on our system, I was presented with a dialog box to install Java SE. Turns out their download manager app uses Java SE. Nice.  Install, download files, de-install Java again. I did notice it linked to the Java 7.13 bits. That’s something.

Sadly, I can’t get away with doing the same at work. We run a non-current release version of Java 6 “standard” at work. If you are running Java 7 automated auditing reports tattle on you and you either have to justify your use of Java 7 or it will be auto-uninstalled and roll-back to the standard level of Java 6.

Sweet baby Jebus.

For home users who are non-technical (or are and just don’t have the time to follow the web-browser plugin patching game) I recommend popping in once a week to the Qualys BrowserCheck on each of their installed web-browsers. Maybe that way you can catch and patch dated versions fairly easily.

Why the Patching Fuss?

Failure to patch and run current versions of Java/Flash/<insert plugin-here> (not to mention your OS) could lead the following headaches and pubic shame and liability.

  • Facebook engineers compromised by Java zero-day - The H Security: News and Features
  • Facebook computers compromised by zero-day Java exploit - Ars Technica
  • Facebook Hacked, Mobile Dev Watering Holes, and Mac Malware - F-Secure Weblog : News from the Lab
  • Employees targeted with fake DocuSign "confidential message" - Help Net Security
  • Chinese Hackers Infiltrate New York Times Computers - NYTimes.com

And you thought having someone guess your Yahoo password and use it to send spam was a headache.

Not software-based, but Amazon users are exploited also…

Saw these links this past week. Fascinating.

  • Chasing an active Social Engineering Fraud at Amazon Kindle - Scott Hanselman
  • Two-for-one: Amazon.com’s Socially Engineered Replacement Order Scam - HTMList.com, A Web Development Blog by Synapse Studios

For the ForSec Crew

OMG! What an amazing number of posts and material from our ForSec experts! Especially timely after all these latest Java patching dramas we have been enjoying lately.

  • Java, Timelines, and Training - Windows Incident Response Blog
  • BinMode: Parsing Java *.idx files, pt trios - Windows Incident Response Blog
  • Why "BinMode"? BinMode: Parsing Java *.idx files, pt. deux - Windows Incident Response Blog
  • BinMode: Parsing Java *.idx files - Windows Incident Response Blog
  • BinMode - Windows Incident Response Blog
  • Java IDX Sample Files from Java Spearphishing Attack from SANS FOR508 - SANS Computer Forensics and Incident Response blog.
  • Extracting ZeroAccess from NTFS Extended Attributes - Journey Into Incident Response blog
  • Detecting Extended Attributes (ZeroAccess) and other Frankenstein’s Monsters with HMFT - hexacorn blog
  • Beyond good ol’ Run key, Part 3 - hexacorn blog
  • Links for Toolz - Journey Into Incident Response blog
  • Deobfuscating Potentially Malicious URLs - Part 1- Open Security Research blog
  • Attributing Potentially Malicious URLs - Part 2 - Open Security Research blog
  • Evaluating Potentially Malicious URLs - Part 3 - Open Security Research blog
  • Interesting Malware in Email Attempt - URL Scanner Links - If the OSR links above wet your appetite, this GSD post has some additional related resources you might be interested in.
  • Tips on Malware Analysis from Jake Williams - Lenny Zeltser On Information Security blog. Link to three posts regarding malware analysis.
  • There Are Four Lights: The Forensic Scanner - Windows Incident Response Blog
  • What is PALADIN Forensic Software? - Sumuri - the free forensic liveCD is now released at version 4.0.
  • CAINE 4.0 codename "Pulsar" is cooking. It’s not hear yet but the CAINE liveCD distro is in works now as well
  • Apple Hates Forensicators - Forensic 4cast
  • Got a PC problem? Try OSForensics 2.0 - Betanews - Nice review on OSForenics. I find it helpful for sysadmin support duties as well. OSForensics - Download

We pause for a PSA…

  • Yes, that PC cleanup app you saw on TV at 3am is a waste - Ars Technica

Network News of Late

  • CapLoader 1.1 Released - NETRESEC Blog
  • Analyzing 85 GB of PCAP in 2 hours - NETRESEC Blog
  • Extracting Metadata from PcapNG files - NETRESEC Blog
  • Wireshark releases v1.8.5 and 1.6.13 - ISC Diary
  • Wireshark - Download
  • Wireshark - Wireshark 1.8.5 Release Notes
  • Connect OpenVPN - OpenVPN for iOS
  • URL Snooper - Mouser Software at DonationCoder.com
  • WAN Circuit Topologies - Packet Life
  • Security alert for D-Link routers - The H Security: News and Features
  • More Wi-Fi devices with security holes - The H Security: News and Features
  • Microsoft Message Analyzer Beta 2 is released (build 5950)! - MessageAnalyzer blog

Tools, Utilities and Treats for the SysAdmins

  • Undelete Navigator Is A File Recovery Tool With Better Browsing - AddictiveTIps blog
  • Kickass Undelete - a free, open source file recovery tool for Windows - Version 1.3 beta
  • FreeRecover - SourceForge.net
  • Recuva v1.45 - Piriform
  • Comodo Rescue Disk for Windows - Download Rescue Disk Software
  • COMODO Rescue Disk (CRD) v2.0.261647.1 is formally released - Comodo
  • COMODO Rescue Disk 2.0 combats even deeply embedded malware - BetaNews
  • LSoft Technologies - Freeware products
  • RKill terminates malware processes - BetaNews
  • RKill Download - bleepingcomputer
  • Remove malware from an already-infected PC with Malwarebytes Chameleon - Softwarecrew
  • Chameleon - Malwarebytes
  • Updates: Pendmoves v1.2, Process Explorer v15.3, Sigcheck v1.91, Zoomit v4.42 - Sysinternals
  • Updates: Autoruns v11.41, Handle v3.51, Movefile v1.01, Procdump v5.13, Sigcheck v1.9 - Sysinternals
  • Update: Autoruns v11.42 - Sysinternals
  • DISM GUI 3.5 Released - Mike's Blog
  • JavaRa 2.1 - SingularLabs - Tool to assist with removal of Java from Windows systems.
  • MemTest86 now maintained by PassMark Software - BetaNews
  • Outlook 2013 deprecated features and components - Outlook Blog
  • WSUS Offline Update - Update Microsoft Windows and Office without an Internet connection

Bits and Pieces

  • Information about ComboFix being infected and what you should do - Bleeping Computer. From time to time I have recommended or posted links to ComboFix tool to remove certain malware infections. It appears a particular release version of ComboFix was compromised. the latest version is clean but I thought it would be good to note this thread for the curious or concerned.
  • Universal Plug and Pray - F-Secure Weblog : News from the Lab
  • Exposed UPNP Devices - ISC Diary
  • ScanNow for Universal Plug and Play (UPnP) - Rapid7. Download and install this tool to check your network for potential UPnP issues. Only be aware it does require Java SE installation as a pre-requisite…so that may bring it’s own issues to the table. If in doubt, install Java SE and this tool. Run both to audit/assess. Make your notes….then uninstall.
  • Universal Plug and Play Check by Rapid7 - online version of the tool to check your router for issues. Limited features.
  • Comodo - free security products for home users.
  • Search & Browse The History Of All Web Browsers On A PC From One Place - AddictiveTips
  • My Computer Tweaker: Massive Collection Of Windows Registry Tweaks  - AddictiveTips
  • Control Panel - My Computer Tweake - by ~KeybrdCowboy on deviantART
  • New: UNetbootin Portable 583 (create bootable Linux USB drives) Released - PortableApps.com
  • New: Smart Deblur Portable 1.27 (sharpen out of focus and blurry images) Released - PortableApps.com
  • Spybot - Search & Destroy: The Simple, Yet Effective Route For Cleaning Your PC Of Malware - MakeUseOf blog review.
  • Spybot - Search & Destroy Portable - PortableApps.com

Enjoy.

-- Claus Valca

Read More
Posted in anti-virus software, boot-cd's, forensics, Link Fest, malware tools, Microsoft, networking, NFAT, security, software, utilities | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile