Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label Win FE. Show all posts
Showing posts with label Win FE. Show all posts

Sunday, October 20, 2013

Forensic News Flashes - New Projects and learning opportunities galore!

Posted on 9:11 PM by Unknown

It’s late and has been a super-long weekend.

Lavie isn’t too impressed I’m still sitting at my desk working on posts.

In the meantime, I’m commited to getting this last bit of ForSec linkage collected over the past few weeks out the door so you can have fun reviewing it this week.

Those young and crazy pups over at the Computer & Digital Forensics at Champlain program have clearly caught their dean napping. In an interesting series of posts, they attempt to wreak havoc on different hard-drives and then try to put humpty-dumpty back together again.

  • Destructed Data Forensics- Part 3
  • Data Destruction Forensics- Part 2
  • Data Destruction Forensics

MantaRay Forensics - anTech Triage & Analysis System. As far as I can tell, this is the first time I have posted any mention of MantaRay Forensics here at GSD.  Spotted in this C&DF@C post Swimming with MantaRay Forensics

MantaRay was designed to automate processing forensic images, directories and individual files with open source tools. With support for numerous image formats, this tool provides a scalable base to utilize open source and custom exploitation tools. MantaRay was developed by two forensic analysts, Doug Koster and Kevin Murphy.

ForGe Forensic test image generator v1.1 - Git Hub project page. from the Overview description:

ForGe is a tool designed to build computer forensic test images. It was done as a MSc project for the University of Westminster. Its main features include:

  • Web browser user interface
  • Rapid batch image creation (only NTFS supported)
  • Possibility to define a scenario including trivial and hidden items on images
  • Variance between images. For example, if ForGe was told to put 10-20 picture files to a directory /holiday and create 10 images, all these images would have random pictures pulled from repository.
  • Variance in timestamps. Each trivial and hidden file can be timestamped to a specific time. Each scenario is given a time variance parameter in weeks. If this is set to 0, every image receives an identical timeline. If nonzero, a random amount of weeks up to the maximum set is added to each file on each image
  • Can modify timestamps to simulate certain disk actions (move, copy, rename, delete)
  • Implements several data hiding methods: Alternate data streams, extension change, file deletion, concatenation of files and file slack space.
  • New data hiding methods can be easily implemented. Adding a new file system is also documented.

Developer Hannu Visti goes shares a great post over the features and background of this tool over at Forensic Focus. ForGe – Computer Forensic Test Image Generator.  This could be a really fresh and innovative tool to help with both simulating forensic images for training and drill purposes. Very interesting and well worth the time to check out. It’s beyond my skill set to review and comment on but if any of the ForSec pros out there have any thoughts or comments, please feel free to drop them in the comments here for our community education.

Linkz 4 Free Infosec and IT Training - Journey Into Incident Response - Corey Harrell goes above and beyond with an outstanding listing of trainings, exercises, and learning resources that are ForSec focused and absolutely-friggin-free for the taking!  Corey promises to keep the listing updated so bookmark the page and check back often. I’m particularly interested in the CSIRT-like topics and materials listed like those in the ENISA CERT linkage. I’ve downloaded most all of the PDF versions already to review this week as time allows!

Many of these trainings have supplemental videos and VM’s for download too!

Other specific courses from Corey’s post I’m listing below so I can find them quickly…

  • Incident management guide - ENISA CERT
  • Tools - ENISA CERT - OMG what a detailed and categorized listing.
  • Certified Information Systems Security Professional (CISSP)® Common Body of Knowledge (CBK)® Review - via Open Security Training
  • Flow Analysis & Network Hunting - via Open Security Training
  • Introduction to Vulnerability Assessment - via Open Security Training
  • Introduction to Network Forensics - via Open Security Training
  • Offensive, Defensive, and Forensic Techniques for Determining Web User Identity - via Open Security Training
  • Utilizing SysInternals Tools for IT Pros course - Microsoft Virtual Academy - Note I think I have already posted this one earlier!

What 'tier 2' & 'tier 3' tools do you load on your forensic workstation(s)? - ForensicKB blog - Lance Mueller has a great list of Tier 2 and Tier 3 apps he considers. I’m pleased to find more than a few in my toolkit already. Note that not all of the software listed here is necessarily free or open-source. More than a few are commercial applications. That’s not at all a bad thing, but just something to be aware of.

 Windows Incident Response: Shell Item Artifacts, Reloaded - Harlan Carvey undertakes some very methodical validation exercises on Windows shell item artifacts. Definitely worth reading.

Meanwhile, from another ForSec guy who appears to never sleep… Brett Shavers has been in a posing frenzy over at his Windows Forensic Environment blog site.

Best publicly available testing of WinFE I’ve seen to date - Windows Forensic Environment (Note post info is good but link in it has been superseded by one found in post below.

Updated link on the Mistype project - Windows Forensic Environment

WinFE - direct link to the article mentioned. I agree, it is a truly fascinating read for WinFE aficionados. I’m coming back to read this one carefully this week.

Mini-WinFE - Windows Forensic Environment - This post has tons and tons of screenshots to illustrate the new Mini-WinFE project as well as an introduction that goes over the project features. Very basically, this specific project (1 of 3 promised for alternative WinFE building) allows you to roll your own WinFE boot disk in a “minimal” configuration with FAU utilities, FTK Imager and support for X-Ways Forensics. Total build time is estimated at 10 minutes from start to media in your hand.

Mini-WinFE is out of beta! - Windows Forensic Environment - See you waited too long! The first link was requesting Beta testers. Now it is released!  Direct project link here via Reboot.pro and extensive Mini-WinFE project documentation from Misty is linked here.

Quick video on building a Mini-WinFE - Windows Forensic Environment - a very short (3:33 min) YouTube video is available on this post page for those who want to check out the building process.

Since we are on a WinFE bender, let’s shift gears slightly and use that excuse to post a link on the WinFE’s kissable cousin for sysadmins who aren’t quite as focused on disk read-only preservation, WinPE.

How to Customize Windows PE Boot Images to Use in Configuration Manager - Chris Nackers Blog. Chris links to this Microsoft TechNet resource How to Customize Windows PE Boot Images to Use in Configuration Manager

New website and project roadmap - DEFT Linux - Computer Forensics live CD - The DEFT development team has put some fresh paint on their website as well as outlined where they plan to head in the coming months. Congratulations to DEFTA President Stefano Fratepietro and all the community and project contributors who have worked hard to make DEFT Linux a premiere Forensic live CD resource! From that post..

Here follows the forthcoming milestones concerning the new versions of DEFT 8, Virtual Appliance and User Manual.

  • DEFT Linux 8.1 with relevant news for Mobile Forensics – November 2013
  • DEFT 8 VMware Virtual Appliance – late November 2013
  • Roadmap of projects supported by donations – December 2013
  • DEFT 8 User Manual – February 2014
  • Third Italian National Conference DEFTCON 2014  – Polytechnic of Milano, April 11, 2014

Installing VMware Tools on Kali Linux and Some Debugging Basics - SpiderLabs Anterior - Christophe De La Fuente goes to the mat to show some advanced debugging skills in getting VMware Tools onto Kali Linux. As is pointed out in the comments, there are easier ways to do it, but the experience shared of the road taken makes us all a bit wiser. Which this post then led me to discover and add to my RSS feed pile…

Computer Howto's by Lewis Encarnacion - Lewis’s posts are great. Covering not just Windows 7 topics, but also some of the finer points in using and getting comfortable in Kali Linux.

FAU -version 1.3.0.2464 - Speaking of the Forensic Acquisition Utilities (FAU) it seems a new version came out in August 2013. I don’t think I caught that release. The link has a “what’s new” jump as well as the new binary set download link but for the lazy…from that source:

  • Volume_dump and DD now recognize drives with BusTypeSata as devices supporting the ATA feature set.  ATA specific attributes are reported for these drives.
  • Fixed a problem with the DD --verify option when writing an image to certain to certain drives.  Under certain circumstances the DD --verify option reported a spurious failure even though the reimaging of the target drive succeeded and the cryptographic checksum of the destination drive was in fact identical to the cryptographic checksum source image file or drive.  This problem did not affect the accuracy of the reimaged drive but required that the user to validate the target drive after the imaging process was complete.  Thanks to Suman Beros for reporting this problem.
  • When acquiring a physical drive DD now drops the block size down to the device block size when approaching the putative end of the source drive.  Hard drives often misreport their capacity either by over estimating or under estimating the true size.  The only reliable way to image a hard drive is to attempt to acquire beyond the purported end of the drive and see if valid data is returned.  However, we have encountered a few drives that freeze or hang the imaging process if you attempt to read beyond the end of the drive with a block size that is greater than the device block size.  Needless to say, this can be disconcerting when you have already read 1 TiB of data only to have the whole process hang on the last few sectors.  Dropping down to the device block size when approaching the end of a drive should produce more reliable acquisitions.  A disadvantage is that drive acquisition will be slower at the end of the drive.
  • Examples have been added to the DD help text which show how to acquire a physical drive.

That’s all for tonight!

Cheers my friends.

Claus Valca

Read More
Posted in boot-cd's, cheat sheets, Education, forensics, Learning, Link Fest, Linux, security, software, tutorials, utilities, Win FE, Win PE | No comments

Monday, September 2, 2013

ForSec Labor Day Blow-out Linkfest

Posted on 6:15 PM by Unknown

Final link push for the GSD blog before shutting down for the night.

I hope all you ForSec guys and gals have had a restful Labor Day before heading back into the trenches tomorrow.

Here are some links of note to review this week that I picked out.

Richard Bejtlich on His Latest Book, “The Practice of Network Security Monitoring” - M-unition blog

Did It Execute? - M-unition blog post by Mary Singh on incident response.

Anatomy of an ongoing Drive-by-Download campaign - ZScaler ThreatLabZ blog post

Browser Related":

Psst. Your Browser Knows All Your Secrets. - SANS ISC Diary guest post by Sally Vandeven on pulling the crypto keys in a browser.

Cookie Cadger to Identify Cookie Leakage from Applications over An Insecure HTTP Request - Next of Windows

Cookie Cadger - project homepage. From the link:

“Cookie Cadger helps identify information leakage from applications that utilize insecure HTTP GET requests.

“Web providers have started stepping up to the plate since Firesheep was released in 2010. Today, most major websites can provide SSL/TLS during all transactions, preventing cookie data from leaking over wired Ethernet or insecure Wi-Fi. But the fact remains that Firesheep was more of a toy than a tool. Cookie Cadger is the first open-source pen-testing tool ever made for intercepting and replaying specific insecure HTTP GET requests into a browser.

“Cookie Cadger is a graphical utility which harnesses the power of the Wireshark suite and Java to provide a fully cross-platform, entirely open-source utility which can monitor wired Ethernet, insecure Wi-Fi, or load a packet capture file for offline analysis.”

Book stuff - Windows Forensic Environment - Brett Shavers teases us again with brief news he continues to develop a standalone WinPE/FE “one-push” builder. Also he has released an early Kindle version of his X-Ways Forensics Practitioner’s Guide. Finally Brett gives recommendations for some other great ForSec reference books in his post.

Sadly, I am embarrassed to confess that I have just rediscovered the SANS Institute: Reading Room.

It appears their Latest 25 Papers RSS link to the page may have some issues as though I can load it in Firefox, trying to use it in a dedicated RSS reader generates an error that it cannot find actual RSS data on the page. Hmm.

Anyhows…since I just found it (again) there are gazillion (or slightly less) new whitepapers for review and reading.

Here are the ones I picked out that looked interesting to my desk operations:

  • 60 Seconds on the Wire: A Look at Malicious Traffic - (direct PDF Link) - SANS Reading Room whitepaper by Kiel Wadner - August 22, 2013.
  • Live Response Using PowerShell - (direct PDF Link) - SANS Reading Room whitepaper by Sajeev Nair - August 20, 2013.
  • Event Monitoring and Incident Response - (direct PDF Link) - SANS Reading Room whitepaper by Ryan Boyle - May 15, 2013.
  • Detecting Security Incidents Using Windows Workstation Event Logs - (direct PDF Link) - SANS Reading Room whitepaper by Russ Anthony  - August 22, 2013.
  • Windows Logon Forensics - (direct PDF Link) - SANS Reading Room whitepaper by Sunil Gupta - March 15, 2013.
  • Custom Full Packet Capture System - (direct PDF Link) - SANS Reading Room whitepaper by Derek Banks - April 16, 2013.
  • Security Best Practices for IT Project Managers - (direct PDF Link) - SANS Reading Room whitepaper by Michelle Pruitt - June 24, 2013.
  • Get Out of Your Own Head: Mindful Listening for Project Managers - (direct PDF Link) - SANS Reading Room whitepaper by Charlie Scott - December 20, 2010.
  • The Death of Leadership in Management - (direct PDF Link) - SANS Reading Room whitepaper by Dana Hudnall - September 12, 2013.

That last link reminded me of the following particular motivational leadership links I keep handy on my blog sidebar:

  • Getting the Job Done - TaoSecurity blog’s Richard Bejtlich.
  • AFOATS Training Manual - 2004 edition via Google Docs
  • Five Qualities of Real Leadership - TaoSecurity blog’s Richard Bejtlich.
  • What I've Learned - USNI Blog post by Alexander Martin

Cheers,

--Claus Valca

Read More
Posted in browsers, forensics, Kindle, Link Fest, networking, NFAT, security, Win FE | No comments

Sunday, August 11, 2013

Security-minded - QuickPost

Posted on 6:51 PM by Unknown

And now for a change of pace, these caught my eye this week.

Presented in no known order.

  • Everything you wanted to know about SQL injection (but were afraid to ask) - Troy Hunt’s blog
  • Kali Linux - Penetration Testing Platform - Kali Linux
  • Pass-The-Hash: Protect Your Windows Computers! (Part 1) :: Viruses, trojans and other malware - WindowSecurity.com
  • Pass the Hash and Other Credential Theft and Reuse: Preventing Lateral Movement and Privilege Escalation - TechEd North America 2013 | Channel 9
  • Techniques malware authors use to evade detection - Help Net Security post.
  • ZeroAcces rootkit dominates, adds new persistence techniques - Help Net Security post.

My kind friend the TinyApps bloggist tipped me to these super-juicy fruits.

  • Sprites mods - Hard disk hacking - Intro - SpritesMods.com
  • Hard drive hack provides root access, even after reinstall | Hacker News
  • Researchers demo exploits that bypass Windows 8 Secure Boot | ITworld

Which led to a fun correspondence, from which I then jumped and found this great resource:

  • Hard Drive Circuit Board Replacement Guide or How To Swap HDD PCB - Donor Drives

Moving on we also have…

  • Quickpost: Rovnix PCAP - Didier Stevens. Didier graciously provided a PCAP file for download and analysis of this clever litter bugger. So you don’t have to risk your system. For more info on the nasty; The evolution of Rovnix: Private TCP/IP stacks - Microsoft Malware Protection Center.

The RSA Blog has some great material here for incident responders:

  • Responding When the Attacker has a Foothold - Part 1 - Speaking of Security - The RSA Blog
  • Analysis Techniques: Responding When the Attacker has a Foothold – Part II - Speaking of Security - The RSA Blog
  • Analysis Techniques: The Attacker Has a Foothold – Part III, Assessing Scope - Speaking of Security - The RSA Blog 

Finally,

  • List of keys parsed by RegRipper Plugins /Generated by 3R - RegRipper Ripper v0.2/ - Hexacorn blog - Amazing resource for you RegRipper fans!  Spotted via this 3R update post.
  • Making the build even easier - Windows Forensic Environment - The always WinFE restless guru Brett Shavers is teasing us with news of a WinBuilder project to create a standalone “push-button” WinFE build project. Sweet!

Constant Vigilance!

--Claus Valca

Read More
Posted in boot-cd's, forensics, Link Fest, security, Win FE | No comments

Sunday, July 28, 2013

ForSec “Value Package” Linkfest - No coupons required!

Posted on 5:00 PM by Unknown

One last Linkfest from a now exhausted GSD blogger this weekend.

Cleaning out the “to-be-blogged” hopper is always rewarding, but I tend to get very behind on the weekend chores. My saving grace this weekend has been frequent scattered showers and an equally tired Lavie who hasn’t been interested in going out for shopping, groceries, or dining out. The kitchen has been cleaned. The laundry has been done for the week.

Next stop, a few hours of rest, post-blogging, then a wind-down with Endeavour on PBS Masterpiece.

Too Funny Not To Miss

Bloody galah scammers still not getting the message - Troy Hunt’s blog. Security guru Troy Hunt has had his fair share of “this is (not) Microsoft cold calling you…your PC is infected…let me remote control it” scams and has picked them all apart to the bone.

This time he takes a new angle…in a way that only an Aussie could pull off!  This is a classic! Troy, please offer us some of those sound files or link to where we can get them!  I need to put together a Texan sound-effect package for similar fun with unwanted callers. Brilliant!

Microsoft Security News

Microsoft Releases New Mitigation Guidance for Active Directory - Microsoft Security Blog

Overview of Microsoft`s "Best Practices for Securing Active Directory" - SANS Computer Forensics and Incident Response blog’s Mike Pilkington does a great summary and takeaway of the new AD mitigation guidance.

Security Awareness Training: Your First Line of Defense (Part 4) - WindowSecurity.com’s Deb Shinder discusses evaluating training effectiveness short and long-term.

See also these previous series posts:

  • Security Awareness Training: Your First Line of Defense (Part 1)
  • Security Awareness Training: Your First Line of Defense (Part 2)
  • Security Awareness Training: Your First Line of Defense (Part 3)

Network Security, News and Techniques

Wireshark 1.8.9 and 1.10.1 Security Update - ISC Diary

  • Wireshark 1.10.1 - Release Notes
  • Wireshark 1.8.9 - Release Notes
  • Wireshark - Downloads

Next up are some great and detailed video presentations from Sharkfest 2013

  • Sharkfest 2013 - Wireshark Network Forensics (by Laura Chappell)
  • Sharkfest 2013 - Trace File Sanitization NG (by Jasper Bongertz)
  • Sharkfest 2013 - Attack Trends and Techniques (by Steve Riley)
  • Sharkfest 2013 - Capture Limit of a Laptop, When does it Drop Packets? (by Chris Greer)

Recent Forensically Focused Posts

  • HowTos - Windows Incident Response blog
  • HowTo: Malware Detection, pt I - Windows Incident Response blog
  • HowTo: Data Exfiltration - Windows Incident Response blog
  • HowTo: Add Intelligence to Analysis Processes - Windows Incident Response blog
  • HowTo: Determine/Detect the use of Anti-Forensics Techniques - Windows Incident Response blog
  • HowTo: Investigate an Online Banking Fraud Incident - Windows Incident Response blog
  • Finding an Injected iframe - Journey Into Incident Response blog
  • MS Excel and BIFF Metadata: Last Opened By - Digital Forensics Stream blog

Physical (In)Security?

Duplicate house keys online - Keys Duplicated - This is either freaking amazing or super-scary. I just can’t decide! According to their Security page, precautions are taken.

The Keys Duplicated Blog - A couple really cool and technical posts on the behind the scenes things that make their keys pretty good.

…as spotted on Lifehacker’s post: Shloosl Copies Your House Keys Using a Smartphone Photograph

When 'Smart Homes' Get Hacked: I Haunted A Complete Stranger's House Via The Internet - Forbes

ForSec LiveCD Distro News

  • More on WinFE and Autopsy - Windows Forensic Environment blog
  • DEFT Linux 8 stable with DART 2 is out! - DEFT Linux - Computer Forensics live cd
  • Kali Linux Summer Update Release 1.0.4 - Kali Linux
  • Pass the Hash toolkit, Winexe - Kali Linux
  • Downloads - Kali Linux

AV/AM Bits

Microsoft Security Essentials quietly released version 4.3.216.0 engine update for their free antivirus scanning program. If you use MSSE, you should get it via the automatic updates…if you have them turned on…you do have them turned on right?

Download Microsoft Security Essentials - Microsoft Download Center - Like most things MSSE, trying to figure out just what got updated is next to impossible so let’s just say for now that this one must be better than the previous version and move on.

I’m still using MSSE around the Valca home on all our home systems. I also continue to recommend it to friends and family (generally everyone non-work-related) who I provide friendly IT support to. I find it is pretty non-threatening to the non-technical users I know and though it loves to alert on many of my security programs (potentially unwanted programs) since they can also be used for 3vil, it seems to do a more than adequate job security the systems.

For my Windows 8 systems, I’m instead relying on Bitdefender Antivirus Free. In some ways it’s a bit different model in that you need to sign up with an email address to set up your account. Then you can download the client to the system. What is nice is that if you manage multiple systems in your home, you can log into your account at their site and then get a console feedback on the status of those systems. That’s something that I do at work with another vendor’s enterprise AV client health/status management console. That’s super cool for a free product. I’m seriously leaning to expanding it’s coverage to my main Windows 7 laptop at home. Performance has been outstanding on my Windows 8 systems.

Kaspersky tops real world protection test - BetaNews - this post does point out that Bitdefender tied Kaspersky with a 99.9 % protection level in AV-Comparatives Independent Tests of Anti-Virus Software for July 2013. While Microsoft Security Essentials rated a 92.5 % protection level. There are some additional disclaimers so read the short BetaNews article carefully. Then head over to AV-Comparatives to dig deeper and see the full findings.

  • AV-Comparatives Real-World Protection Test March-June 2013 - AV-Comparatives
  • AV-Comparatives Real-World Protection Tests - AV-Comparatives

Finally, we wrap up this segment with this interesting discussion:

The evolution of Ronvix: Private TCP/IP stacks - Microsoft Malware Protection Center

It’s a bootkit infection that has its own private TCP/IP stack. By doing so it can be extra stealthy and bypass personal firewall hooks and can lurk unseen in standard tools and utilities (such as nbtstat). Doing so, depending on packet/network monitor off the infected machine may be ineffective. However, it still must talk ON the network, so an independent network monitoring and forensics analysis approach using a network monitoring appliance or span port capture may detect the traffic. This may be why comparing outside network traffic captures from a system on the network to network traffic captured on the system may be a useful exercise for incident response and monitoring purposes.

Legally Focused

I’ve been reading a wider range of subjects, and a small part of those touch on our legal system. Mainly they apply to digital law and crime but some are more general. I’m just tossing them out there for the interested or curious. Generally they tend to analysis of current events or provide a more detailed lawyer’s review than the talking/shouting legal heads we encounter on mass-media “news-like” entertainment outlets these days.

  • CYB3RCRIM3 - Susan Brenner’s blog on cybercrime and cyberconflicts in technology and law.
  • Popehat - group blog with a mostly legal focus (though topics can range far afield!)
  • Le·gal In·sur·rec·tion - group blog with mostly legal and law-in-today’s-culture focus. Pretty vibrant opinions. Alignments may vary.
  • Lowering the Bar - Sometimes lighthearted (though always serious at the core) look at some of the nonsense the legal system contains, or foists on others from time to time. Great site.
  • Massad Ayoob - legal, cultural, and educational postings primarily dealing with legal private firearm ownership issues. Also analysis of public media trends and news stories.

Have a great week!

--Claus Valca

Read More
Posted in Active Directory, anti-virus software, boot-cd's, cheat sheets, firewalls, forensics, humor, Link Fest, malware tools, Microsoft, networking, NFAT, security, troubleshooting, tutorials, utilities, video, viruses, Win FE | No comments

Sunday, July 14, 2013

ForSec briefs - Low Post Consumer Waste version

Posted on 5:17 PM by Unknown

Forensic LiveCD News

  • DEFT Linux 8 public beta & DART 2 stable ready for download DEFT Linux - Computer Forensics live cd
  • Running Autopsy 3 Digital Forensics Platform on WinFE Lite for Triage Forensics -Windows Forensic Environment blog

EMET 4.0 Related

  • toolsmith: EMET 4.0 - These Aren’t the Exploits You’re Looking For - HolisticInfoSec blog
  • Windows Security 101: EMET 4.0 — Krebs on Security
  • Threat Mitigation with EMET 4.0 - Microsoft Security TechCenter
  • Microsoft's EMET v 4.0 Released … in case you missed it - GrandStreamDreams blog

Fundamentals are Everything

Windows Incident Response Blog’s Harlan Carvey is running a great series of “How To” posts

  • HowTo: Determine Users on the System
  • HowTo: Correlate Files To An Application
  • HowTo: Determine Program Execution
  • HowTo: Determine User Access To Files
  • HowTo: Track Lateral Movement
  • HowTo: Correlate an Attached Device to a User
  • Finding Malware Like Iron Man Slide Decks - Corey Harrell - Journey Into Incident Response

Updates! Get Yer Updates!

  • Second batch of Windows 8.1 updates improve application compatibility - BetaNews
  • Adobe, Microsoft Release Critical Updates — Krebs on Security

Cheers.

--Claus V.

Read More
Posted in anti-virus software, boot-cd's, forensics, Link Fest, Linux, malware tools, Microsoft, software, Win FE | No comments

Sunday, June 30, 2013

Forensic News and Blog Update Link Fest

Posted on 3:25 PM by Unknown

Here is a mini-roundup of some great forensic posts over the past few weeks I bookmarked.

  • There Are Four Lights: Incident Response - Windows Incident Response blog - I’m always on the lookout to be humbled (and schooled) in better incident response methodologies.
  • There Are Four Lights: LNK Parsing tools - WIndows Incident Response blog
  • Crossing Streams - WIndows Incident Response blog
  • RegRipper Updates - WIndows Incident Response blog
  • The Tool Validation "Myth-odology" - WIndows Incident Response blog -file under “know your tools”.
  • Good Reading, Tools - WIndows Incident Response blog
  • Unleashing auto_rip  - Journey into Incident Response blog - nice new tool walkthough that leverages “RegRipper” for doing some pre-assessment of a potentially compromised system.
  • Is WinFE still being used? - Windows Forensic Environment blog. Uh, Hell Yeah it is! This post has some excellent links on how WinFE is being used, and ways to build your own. Of course Brett Shavers’ WinFE blog is littered with links, tools, and tips on how to do that if you didn’t already realize it!
  • A Windows Live CD plugin for my UserAssist utility - Didier Stevens - (updated)
  • Control Panel Forensics: Evidence of Time Manipulation and More - Cool stuff from Chad Tilbury over on the SANS Computer Forensics and Incident Response blog.

Meanwhile, in the world of digital forensics, our dear friend Dr. Neal Krawetz has had his hands full between teaching us the nuances of digital image forensics and fighting the noble fight against clarity, objectivity, and transparency in the world of digital news photography and photography contests. You go Dr. Krawetz!

  • Unbelievable - The Hacker Factor Blog
  • Angry Mob - The Hacker Factor Blog
  • Deep Dive - The Hacker Factor Blog

When I grow up I want to be gothic physical/digital forensic examiner…just like Abby Sciuto!

Seriously…

(IN)SECURE Magazine - June 2013 edition (PDF download) covers a number of great topics this month including:

    • Becoming a computer forensic examiner
    • UEFI secure boot: Next generation booting or a controversial debate
    • How to detect malicious network behavior
    • DNS attacks on the rise: Rethink your security posture
    • IT security jobs: What's in demand and how to meet it
    • Remote support and security: What you don’t know can hurt you

Cheers!

--Claus V.

Read More
Posted in boot-cd's, forensics, Link Fest, security, tutorials, utilities, Win FE | No comments

Sunday, April 28, 2013

ForSec News Roundup

Posted on 4:04 PM by Unknown

Final GSD post of the weekend. 

Strategies of a world-class computer security incident response team - Help Net Security - Carson Zimmerman presents “…ten fundamental qualities of an effective CSIRT that cut across elements of people, process, and technology.” Run-time is just over 33 min.

ProcDOT - Visual Malware Analysis - SANS Computer Forensics and Incident Response blog. Christian Wojner introduces it thusly…“It correlates Procmon logfiles and PCAPs to an interactively investigateable graph. Besides that ProcDOT is now also capable of animating the whole infection evolution based on a timeline of activities. This feature lets you even quickly find out which server or which requests were responsible that specific data/code got on the underlying system, by which process it was written, how often, who injected what, which autostart registry key was set, what happened when, and so forth ...” Get it via ProcDOT - CERT.at

From the ProcDOT project page:

Screenshot

3crmye3k.ddd

Instruction-Media

The User Interface
Tutorial-Video 1: The User Interface
Tutorial-Video 2: The Graph
Tutorial-Video 3: Analysis (Part 1)
Tutorial-Video 4: Analysis (Part 2): The Timeline

Over at the ISC Diary blog, Mark Baggett has been posting a great series of articles examining the tug-and-pull between those in IT/Sec who advocate a full OS wipe/reload after a malware infection and those who say “save-time-and-clean-it” by removing the malware infection, but not reimage the system. There still seems to be some kind of mysterious desire by staff to possibly prove what a clever IT person we are by digging an infection out of a system rather than just recovering the user’s data, wiping the system, then restoring it from a clean image and putting the data back. Maybe we all want to be a hero. However, as Mark’s posts show, if not done properly and effectively, the malware may remain persistently hidden but functional and you may be back before you know it (and the rest of your data secrets lifted or network exploited). These posts are a good guide and gut-check for how challenging these threats can play hide-and-seek. Familiarity with these techniques might be your last line of defense if your shop doesn’t have a fast-n-hard policy of recover/wipe/restore remediation.

  • Wipe the drive! Stealthy Malware Persistence Mechanism - Part 1 - ISC Diary blog
  • Wipe the drive! Stealthy Malware Persistence - Part 2 - ISC Diary blog
  • Wipe the drive! Stealthy Malware Persistence - Part 3 - ISC Diary blog
  • Wipe the drive! Stealthy Malware Persistence - Part 4 - ISC Diary blog

Tracking Down Persistence Mechanisms - Journey Into Incident Response blog - Not to be outdone, Corey Harrell does a great companion-piece to the ISC Diary blog posts above.  Corey details how he uses Microsoft Autoruns utility in that process.

From one of the comments there, we jump over to Finding Evil: Automating Autoruns Analysis post over in the trustedsignal blog from Dave Hull.

And then in spot-on timing within the ForSec community, Mark Woan at woanware releases a new utility called autorunner. 

“Autorunner is based upon the AutoRuns tool by the Sysinternals/Microsoft gurus. It is designed to perform automated Authenticode.aspx) checking for binaries designed to auto-start on a host. Its primary purpose is to aid forensic investigations.

“…autorunner is designed to work around all of these issues. It will check against all user profiles associated with the host. It will parse out LNK files to the actual binary (one level down). It allows the user to specify multiple drive mappings, so that if the forensic image contains multiple partitions you can map the original drives to mounted drives on the forensic workstation.

“The application should be used against a forensic image that has been mounted using whatever method you desire.”

Securely wiping an SSD - TinyApps blog - Getting back to the drive-wiping thought, this quick-post reminds us of some of the hazards of attempting to sanitize a SSD device. Some might think using a SSD device to hold image captures might be a good idea but if you do, be sure it is one you can truly “zero-out” and sanitize before porting your image over to it! Does anyone use SSD devices yet for that purpose? What other challenges (cost aside) would this present. Are there any benefits to a SSD over a HDD for storing or capturing disk images?

Placing the Suspect Behind the Keyboard – NEW BOOK! - Windows Forensic Environment - Congratulations to Brett Shavers for his new book! It’s been added to my Amazon.com wish-list queue for triggering once my next Amazon.com gift certificate ship comes into port.

Tool Time - The Hacker Factor Blog - A great post in the theme of “know your tools” before you trust the results they provide. One of the gem finds in Dr. Neal Krawetz’s post is his link to the National Institute of Standards and Technologies (NIST) and National Institute of Justice (NIJ) 2012 Computer Forensics Tool Testing Handbook from their computer forensic tool testing program. It’s got 173 pages of goodness to review. The latest publications can be found on this Topical Collection: Computer Forensic Tool Testing Publication Database | National Institute of Justice.

4:mag Issue #1 - Forensic 4cast. A very nice and slick digital publication debuts. This edition covers topics in iOS device/application data & malware, starting out in the digital forensics field, and hard-drive secrets.

The students over at the Champlain College Computer & Digital Forensics department have been busy working on papers addressing Private Browsing. Expect more in this series:

  • Private Browsing Forensics: Introduction - (PDF Link) Private Browsing Forensics: Introduction
  • Private Browsing Part 2 - (PDF Link) Private Browsing Part 2

RegRipper Ripper (3R) and the list of reg keys covered by RR plugins - hexacorn bog.

RegRipper Consolidation - Windows Incident Response blog. Harlan and crew have been super-busy trying to clean house and tie up some loose ends in the RegRipper landscape. This new effort should help make “one-stop-shopping” and development support for RegRipper and plug-ins much easier. Additionally, Harlan has been working hard on the blog to post additional background information on some of myriad (Cory referred to 280+ in his post) RegRipper plug-ins.

Forensic 4cast Awards 2013 – Meet the Nominees - Forensic 4cast. Voting is now open. You can place your votes here.

Encrypted Disk Detector Version 2 - SANS Computer Forensics and Incident Response blog - Chad Tilbury announces and introduces a new version that is out. Get it here over at Magnet Forensics.

What is "up to date anti-virus software"? - ISC Diary.Great post and great discussions in the comments.

Case Leads: LivingSocial Hack, New Cyber Warriors, analyzeMFT update and more... - SANS Computer Forensics and Incident Response blog

Cheers!

--Claus Valca.

Read More
Posted in anti-virus software, books, forensics, iOS, Link Fest, malware tools, networking, NFAT, security, utilities, viruses, Win FE | No comments

ForSec LiveCD bits

Posted on 2:37 PM by Unknown

Things have been fairly quiet in the ForSec LiveCD world since the Kali Linux distro dropped.

They dropped a minor update last week for Kali Linux Accessibility Improvements for blind or visually impaired users. That was a nice touch.

  • CAINE 4.0 and NBCaine 4.0 codename "Pulsar" released! - CAINE. Main features include the 3.2.0-38 kernel & GuyMager 0.7.1, additions of LibreOffice 4.0.1, Squliteman, Remote Filesystem Mounter, adparm, netdiscover, and fixes to netcat works and GHex.  On the windows side of the CD, NirLauncher with FTK Imager and Sysinternals tools packed in as well. Lots of neat improvements here so go download your ISO!
  • New Release of REMnux Linux Distro for Malware Analysis - Lenny Zeltser on Information Security announces Version 4 of the REMunx Linix Distro.
  • Installing the REMnux Virtual Appliance for Malware Analysis - SANS Computer Forensics and Incident Blog has a great walkthough post from Lenny Zelter.
  • ISC Handler Lenny Zeltser's REMnux v4 Reviewed on Hak5 - ISC Diary. Review picks up at the top by Hak5’s host Shannon Morse.
  • REMnux: A Linux Distribution for Reverse-Engineering Malware - Home page and download links
  • WinFE and UEFI Secure Boot! - Windows Forensic Environment blog. Brett Shavers has some notes of interest on some of the technical challenges facing WinFE users with UEFI secure booting.
  • WinFE CTIN 2013 Presentation - Windows Forensic Environment blog. Brett Shavers has graciously shared his WinFE presentation: WinFE CTIN (PDF file link).

--Claus V.

Read More
Posted in boot-cd's, forensics, Link Fest, Linux, malware tools, NFAT, security, utilities, Win FE | No comments

Saturday, August 25, 2012

Power Pile of Links

Posted on 6:35 PM by Unknown

Chain links _ Flickr - Photo Sharing!_2012-08-25_17-32-04CC attribution: "Chain links" by HowardLake on flickr.

Got to go into the office tomorrow for one of those rare (for me) weekend special project rotations.

So I’m afraid a have just a bit less time that usual to spend on the blogging front.

Today’s offering is a large mix that covers LiveCD’s, some WinPE stuff, virtualization, new utility “how to” videos, third-party plugin updates, browser bits, networking, admin tips, password hint leakage, forsec, and a bit of graphical goodies.

ForSec LiveCD’s 

PALADIN 3.0.1 Forensic Software - Paladin just released version 3.0 of their LiveCD. You must have set up a free user account first and log in to access the PALADIN Download page. Changes in 3.0 & 3.0.1 are:

Version 3.0 New Features -

-- PALADIN Toolbox has been ported to Ubuntu 12.04

-- Network Share Icon has been added to the desktop to access network volumes that have been added via the MOUNT Tab

-- Boot support for current Intel Macs (including the newer MacBook Airs)

Release Notes

3.0.1 - Fixed issue where Unallocated Image function was producing 0 byte files.

Road to DEFT 7.2 and more DEFT Linux - Computer Forensics live cd - Deft 7.2 is scheduled for release in September 2012 and will mark a milestone of sorts. It will be the last x32-bit system release. Starting with 8.0 builds, they are going for x64 system support builds only. Shouldn’t be a deal-breaker, just keep a 7.x version handy as well.

DEFT 7 Cyber Forensic Tool Overview (by Casey Mullis) - LoveMyTool blog. Since we were speaking of DEFT, Casey Mullis gives a nice walkabout of DEFT 7 with nice screenshots if you are interested.

ESSPEE - Penetration Testing & Forensics - SourceForge.net - Updated to “R1 x86”. This is a new distro to me and is based on BackTrack 5 for pentest/for/sec work. Uses the “Unity” desktop interface.

Back|Track 5 R3 - new release. More details BackTrack 5 R3 Released!, BackTrack 5 R3! — PenTestIT, and from this H Security: News and Features post, BackTrack 5 R3 adds tools for Arduino and Teensy attacks. Choose your path carefully! Available in both KDE or Gnome flavors, with x32 or x64 platforms. In case you can’t decide, you may want to first look at this general KDE and Gnome Comparison post by ubuntucat.

WinPE Stuff

The few of you who regularly read this humble blog may have seen some recent activity in the comments sidebar. Turns out we had a recent celebrity visitor "Steve” from RMPrepUSB who posts a crazy-number of posts and tips on WinPE and USB booting in general.

Steve left a tip regarding use of the imagex.exe argument “/norpfix” switch when capturing images…specifically as it applies to junctions when the image is applied to a differently-named volume.

What is /norpfix switch, and what does it do? - Blogs from Zhou, Minxiao

In case you are interested, RMPrepUSB is a super cool tool to format and create bootable USB media. Lots of bells and whistles here and extreme tippage and tutorials for you WinPE fans.

  • Create Bootable Windows or Linux USB with RMPrepUSB - ghacks.net
  • RMPrepUSB (and USB booting) - RMPrepUSB blog

If I’m not careful I can loose hours at a time gong though Steve’s extensive tutorials. Here are justa few you might find interesting:

  • 16 - How to boot to different WinPE versions using a single boot.wim that contains multiple images
  • 83 - Download ImageX, BCDBoot and other WAIK tools - RMPrepUSB
  • 53 - Windows 8 To Go (boot Windows 8 from a USB drive!) - RMPrepUSB

Windows 8 and WinFE - Windows Forensic Environment blog. Brett Shavers tips us to a cmd script from Troy Larson (The WinFE dude) that allows creation of a WinFE build from Windows 8 RTM. New to WinFE building? Well then, see also:

  • Build questions - Windows Forensic Environment blog.
  • WinBuilder - Windows Forensic Environment blog.
  • Colin’s Final Version of his write protect application - Windows Forensic Environment blog.
  • Winbuilder Tutorial - Windows Forensic Environment blog.
  • Windows Forensic Environment - Colin Ramsden’s site for WinFE Lite building.

How to sync time in Windows PE - WindowsNetworking.com

VirtualBox and VMware Player updates

Pretty good synchronization getting these updates out guys!

First up, VirtualBox 4.1.20 is out.

  • Oracle releases VirtualBox 4.1.20 - BetaNews review by Nick Peers.
  • Download VirtualBox 4.1.20.80170 - FileHippo.com - (sometimes faster)
  • Oracle VM VirtualBox - Download from Oracle
  • Changelog – Oracle VM VirtualBox

Next, VMwarePlayer is rolled up to v5.0 with some significant changes.

  • Download VMware Player 5.0 - Get it from VMware direct, or..
  • Download VMware Player 5.0.0 - FileHippo.com
  • VMware Player 5 Release Notes
  • VMware releases Workstation 9, Fusion 5 and Player 5 - BetaNews
  • VMware Player angetestet 5 - Borns IT & Windows Blog (Google Translated)

For VirtualBox, be sure you download and upgrade your Oracle VM VirtualBox Extension Pack at the same time. Likewise VMware users should also be sure to install the latest VMware Tools in your VMware hosted virtualized client OS for peak performance.

Defrag Tools Video

Defrag Tools - Microsoft Channel 9 - neat source for fresh reviews of MS tools and techniques now has two more quality videos up.

  • Defrag Tools: #3 - Process Monitor
  • Defrag Tools: #4 - Process Monitor - Examples

Update those Browser Plugins!

I’m thinking I’ve put in close to three hours this past week updating our home systems as well as Dad’s system to ensure they have the latest Flash/Java/etc. updates.

Adobe closes numerous critical holes in Reader and Acrobat - Update - The H Security: News and Features

There are lots of places and ways to download and get the updates; inside app updaters, direct from the software builder’s site, or from third-party locations like filehippo or majorgeeks.

I generally tend to just rock over to filehippo and pull them down. I suppose there is a risk they could have been corrupted or “seeded” with unwanted bits, but so far I’ve not had any problems and their Plugins Downloads page makes nice “one-stop” shopping.

At work it is hard keeping up with what “build” version we need to upgrade these to as for Flash there are both 11.3.x and 11.4.x versions which may cause problems for certain in-house software applications if compatibility is not verified first. However, most home-users should probably be on the 11.4.x run right now.

Likewise there are both Java 1.6.x builds and 1.7.x build branches. Again, most home-users should probably be on the 1.7.x builds.

  • Download Shockwave Player 11.6.6.636 - FileHippo.com
  • Shockwave Player - Adobe.com
  • Download Flash Player 11.3.300.271 (IE) - FileHippo.com
  • Download Flash Player 11.3.300.271 (Non-IE) - FileHippo.com
  • Download and install the latest Flash Player version - Adobe.com
  • Web Player Download for All Operating Systems - Adobe.com
  • Download Java Runtime Environment 1.7.0.6 - FileHippo.com
  • Java Downloads for All Operating Systems Version 6 Update 34 - Java.com
  • Java Downloads for All Operating Systems Version 7 Update 6 - Java.com

Regardless, once you are done with your patching, hop your Windows IE, Mozilla Firefox, and Google Chrome browser(s) over to Qualys BrowserCheck and run a quick free check to make sure they are sufficiently patched.

Additional Browser Notes

In my recent post Greased Monkey Business I celebrated the joy of finally finding a custom Grease Monkey script I could use that would justify adding it to my Firefox browser; Removing UTM data from URLs automatically for cleaner bookmarks. It has been a lifesaver to my blogging work.

So this past week I gave a second banana to the Monkey; Scrub Google Redirect Links for Greasemonkey from “ping”.

Check out this MakeUseOf post that goes into the details: How To Copy Crap-Free URLs From Google’s Search Results

Comodo IceDragon 14.0 released -- get it NOW! - BetaNews notice of the Comodo tweaked Firefox 14 browser release. (actually it is version 14.0.3). Direct download is available from this Comodo forums link: Comodo IceDragon ver. 14.0.3 is now available for download!!

BrowsingHistoryView - Nirsoft - Version 1.0 new utility release to view browsing history of all your web browsers. Nir Sofer has been offering browser-specific utilities to view browsing history, but this gem covers the four major ones at once; Internet Explorer, Mozilla Firefox, Google Chrome, and Safari. New Web browser history viewer - NirBlog

Network Fun

NetworkMiner 1.4 Released - NETRESEC Blog - New release improves handling of fragmented IPv4 packets. Hurray! Also no longer checks for pcap extension; works as long as it is a valid libpcap file, DHCP options are extracted, new parser for a particular protocol. There are also some nice GUI improvements.

Trace File Case Files - Sharkfest 2012 (by Jasper Bongertz) - video presentation of using Wireshark to trace out real-world problems and solve them.

Wireshark Security Update - ISC Diary. Wireshark builds got updated to squash bugs and patch vulnerabilities. Go get busy…Wireshark · Download

Notes for the Sysadmins

Simple but Extremely Useful Windows Tricks - Open Security Research - Nice list of handy Windows tips.

Why The Size of My Partition is Maxed Out at 2 Terabyte and How to Get Over it - Windows7hacker. Just guided Dad though adding a second internal HDD to his Vista system. He’s getting into digital photography and while he has lots of room left on his OEM primary HDD, adding a 2nd drive gives him an exclusive place to drop the files. I guess we could have gone with a external USB drive, but the internal was faster in the long run for large file transfers. Talked him into a 7200 RMP 1TB SATA drive. With some guidance got him to get it successfully installed. Then via a quick remote-control session, got it formatted, labeled, and added to the OS fine. Considered going for a 2+TB drive for a few more bucks, but this was easy enough. Next time I will have to follow the link tippage and set up a GPT disk if the conditions warrant.

Microsoft updated SkyDrive.com - Borns IT & WIndows Blog (Google Translated) - Nice review of the new SkyDrive updates.

RegKeyFixer - reboot.pro - sweet little tool by Joakim similar to Sysinternal’s RegDelNull. Related: Reghide

ForSec Links

Password hints easily extracted from Windows 7, 8 - Ars Technica

All Your Password Hints Are Belong to Us - SpiderLabs Anterior

A Fistful of Dongles: AFoD Interview with Eric Zimmerman - A Fistful of Dongles - Eric Huber interviews F.B.I Special Agent Eric Zimmerman. Great article (and Eric wears a mean flat-top to boot!). Many years ago I had applied to the F.B.I. hoping for a career there following in the steps of my grandfather who was a former Special Agent under Hoover. Alas…it was a path not to be.

ShellBag Analysis - Windows Incident Response Blog

SetRegTime - Windows Incident Response Blog

Linkz for Tools - Journey Into Incident Response Blog - Corey Harrell has some info on this post, particularly those tipping us time-challenged guys to the Time Zone Converter – Time Difference Calculator and Time Zone Map. Also valuable is the final section “Process, Process, Process” which strikes home the critical value of knowing in advance HOW you are going to do exactly WHAT it is you want to accomplish; supporting examples include links to the Forensic Process Lifecycle (PDF) from Lance Mueller at ForensicKB, the previously GSD blogged SANS DFIR Poster 2012 (PDF) download, and Corey’s own Journey into IR Methodology scratchpad.

Man versus AntiVirus Scanner - Journey Into Incident Response Blog - Corey shows of the value of having skillz and technique and a rock-solid process in a John Henry’esqe dance against an anti-malware scanner. Really a great tutorial and exercise.

Registry Decoder 1.4 Released and Updated Registry Decoder Live - New versions are available. I noticed that in the past separate downloads were available for x32 and x64 however I don’t see that in this release. I’ve not followed up yet to see if the newer version handles both automatically or not.

Generating computer forensic supertimelines under Linux: A comprehensive guide for Windows-based disk images - Forensic Focus. ForenicsRichard has also released the Shell (Bash) and C Source code as well.

Finding Smoking Gun and going beyond that – Helpful Forensic Artifacts - Hexacorn blog - another strong article supporting previously mentioned themes of having a process to use in looking for clues which here are referred to has HFA’s (Helpful Forensic Artifacts) to guide the overall investigative and analysis journey and discovery.

HexDive 0.4 - New update at Hexacorn to a tool which extracts strings from a file/sample for additional review. Corey recommends using BinText or Strings to further review the output.

The “Hikit” Rootkit: Advanced and Persistent Attack Techniques (Part 1) - Mandiant M-unition blog

The “Hikit” Rootkit: Advanced and Persistent Attack Techniques (Part 2) - Mandiant M-unition blog

Grab Bag

Change the Windows Logon Screen Background - CybernetNews tips us to Luke Payne Software » Logon Screen Rotator. While I do rotate my Win 7 desktop login picture periodically, (right now it it Tardis based), generally I keep it stable. This is a cool tool however for those who like a bit more variety.

Organize & Manage Huge Photo & Video Databases Using Snaps - AddictiveTips reviews the Snaps - Photo management application.

Microsoft Reimagines Paint - Next at Microsoft - New “version” of the perennial “Paint” app. (Win 8 only).

Tip o' the Week #133 - The Art of Cut n' Paste - The Electric Wand

Cheers!

--Claus V.

Read More
Posted in boot-cd's, browsers, Firefox, forensics, imagex, Internet Explorer, Link Fest, Microsoft, networking, NFAT, Opera, security, troubleshooting, tutorials, utilities, virtualization, Win FE, Win PE | No comments

Sunday, August 5, 2012

Stormy Sunday Linkfest

Posted on 2:58 PM by Unknown

Here is a roundup of a LOT of Sysadmin/For-Sec linkage I’ve tucked away over the past couple of weeks.

It stormy outside, dry inside, and the Olympics churn on on the tele. Perfect time for a super-fast linkfest dump.

Noteworthy For the SysAdmin

  • Case of the Domain Join Failure - chentiangemalc - Because it really is frustrating when you can’t join a workstation to the domain!
  • LeapFrog Connect: Can’t install Adobe Flash on Windows 7 x64? - Kurt Shintaku's Blog - Why was I not surprised it was a Flash version issue?
  • Some Facts About Windows Low Disk Space Warning Balloon - Windows7hacker
  • Windows 7 Tip: How To Log Which Drivers Get Loaded During System Boot - Windows7hacker
  • Resolving USB Speed Issues, “This Device Can Perform Faster” Error - MakeUseOf blog - this bugs me to no end! Grrr! At least thanks to Chriss Hoffman’s excellent post, I have a better understanding of some root-cause issues.
  • Cjwdev | Free Software For IT Professionals - A number of awesome free Active Directory support utilities. Man I love this stuff!
    • NTFS Permissions Reporter - “A tool for producing reports on NTFS permissions across multiple directories and servers.”
    • AD Info - “Query your Active Directory domain for information on several different types of objects (Users, Computers, Groups, Printers etc) using this flexible and user friendly Active Directory reporting tool.“
    • AD Tidy - “Clean up your Active Directory domain by identifying user and computer accounts that are no longer in use. Any accounts that match your search criteria can have a number of actions performed on them, including: Disable, Move, Remove From All Groups, Export To CSV and many more.”
    • Fast Software Audit - “Quickly audit multiple remote computers to find out what software is installed on them and retrieve Windows product key and product ID.” New to me. Was dead-on helpful surveying a series of systems to see if our software upgrade push worked on a sample of domain-joined systems. So Cool!
    • Managed Service Accounts GUI - “Managed Service Accounts are a useful new feature introduced in Server 2008 R2 but they can only be created and managed with Powershell, so this tool was created to provide a simple user friendly GUI that will let you create, edit and install them.”  More details in this 4sysops post: Managed Service Accounts GUI
  • How to partially remove the SkyDrive option in Office 2013 using Group Policy - Anything about IT
  • 8/2/2012 - Flash Player 11.3 Update  - Adobe Forums - This update (11.3.300.270) is only for specific cases for Windows systems and the Adobe ActiveX plugin only. It’s almost the same as 11.3.300.268 except for a fix where that version was crashing the Adobe Flash Player Update Service.
  • Source Sans Pro: Adobe’s first open source type family - Typblography. Nice new free font form Adobe.
  • Beta 1 released VirtualBox 2.4 - Born’s IT & Windows Blog (Google Translated).

For the Network Watchers

  • Rack Unit Measuring Tape - Packet Life - Cool but a bit expensive.
  • WPAD Man in the Middle - NETRESEC Blog - Great breakdown.
  • A better way of Analyzing HTTP Packet Captures from Cloudshark (by: Jason Walls) - LoveMyTool blog
  • Secrets of Vulnerability Scanning: Nessus, Nmap, and More (by Ron Bowes) - LoveMyTool blog
  • Penetration testing tool masquerades as surge protector - HelpNet Security & Power strip or network hacking tool? It’s both, actually - Ars Technica . One more thing to keep a watchful eye out for at work. Great.
  • Wireshark - Download for the latest stable release (1.8.1). More details see this Wireshark 1.8.1 Release Notes.

ForSec Focused

  • “Remote” Collections with WinFE, a neat trick - Windows Forensic Environment - I’m wondering if Devio: Remote drive access and acquisition might be another alternative.
  • A little reminder about ‘write protection’ - Windows Forensic Environment - Good reminder from Brett Shavers.
  • Colin’s Final Version of his write protect application - Windows Forensic Environment. See link below for project details
  • Windows Forensic Environment - Great WinFE project building site by Colin Ramsden.
  • New plugins have been coming in - RegRipper
  • regdecoderR99.zip - registrydecoder - 1.3 Minor Bug Fix - Automated Acquisition, Analysis, and Reporting of Registry Contents - Google Project Hosting
  • Combining Techniques - Journey Into Incident Response blog takes some fresh look at how malware and fraud investigation techniques compliment each other.
  • Parallels hard drive image converting for analysis - Forensic Focus blog - How to approach Parallels virtual drive analysis.
  • UserAssist Windows 2000 Thru Windows 8 - Didier Stevens - updated to version 2.6.0
  • Redline version 1.6 - Mandiant’s tool received an update back on July 11.
  • New Open Source Tool: Audit Parser - Mandiant’s community spirit continues with another tool to help sort and manage XML data output into tab-delimited text format for CSV/Excel work.
  • Looking at Mutex Objects for Malware Discovery and Indicators of Compromise - Lenny Zeltser posts at SANS Computer Forensics and Incident Response blog.
  • Beyond good ol’ Run key - Hexacorn blog - Additional tricks and tips to be on the watch for regarding auto-launch techniques you may see deployed. 
  • Cuckoo Sandbox  - Updated to version 0.4 back on July 24th.
  • Adding Value to Timelines - Windows Incident Response blog - Great perspective on timelines and their usefulness, when taken in larger context.
  • Malware Root Cause Analysis - Journey Into Incident Response - Excellent review on how to approach an analysis, including use of timelines and artifacts. Love the report diagram as well. Very concise and presentable to non-techies.
  • Attack Surface Analyzer 1.0 Released - The Security Development Lifecycle - interesting tool to baseline a system before a software change, then re-run to examine impact to security the installation may have caused.
  • Links and Updates - Windows Incident Response blog - Nice walkabout looking at some new sites, tools, and forsec posts.

USB Imaging

  • A Simple USB Thumb Drive Duplicator on the Cheap - Open Security Research - Interesting post on a do-it-yourself technique for replicating an USB drive image when you don’t have the $$ for a hardware-based specialty appliance.
  • ImageUSB - Write an image to multiple USB Flash Drives - OSForensics - Software based USB duplication tool.
  • USB Image Tool - alex's coding playground - my own preference for capturing and duplicating a USB drive image to additional drives.

Utilities and Miscellanea

  • From TechEd: Legacy Web App Issues, Sysinternals Gems, webcast with Mark Russinovich - Aaron Margosis' "Non-Admin" and App-Compat WebLog - great video links.
  • TSSessions utility - Aaron Margosis' "Non-Admin" and App-Compat WebLog
  • Updates: Handle v3.5, Process Explorer v15.22, Process Monitor v3.03, RAMMap v1.21, ZoomIt v4.3 - Sysinternals Site Discussion
  • Updates: AccessChk v5.1, Autoruns v.11.33, Coreinfo v3.05, Whois v1.1 - Sysinternals Site Discussion
  • quarkspwdump - Windows credentials extraction - Google Project Hosting - recently updated to version 0.2b on July 16th.
  • MultiMonitorTool - NirSoft - New tool release to help manage multiple display setups.
  • Peppermint OS - Interesting “light” (under 512 MB) LiveCD distro built on MintLinux.
  • NoVirusThanks Process Dumper - NoVirusThanks. CLI tool for dumping “…all commited regions of a process’ virtual memory to a .dmp file that can be later analyzed.”  More details in this company blog post: Dump Processes with NoVirusThanks Process Dumper.  Compare with Sysinternal’s ProcDump.
  • CCEnhancer -SingularLabs  - Updated to version 3.5. Great easy-to-use tool to simply upgrade the fantastic Piriform product CCleaner with a whole lot more scrubbing power. Take a peak also at SingularLab’s System Ninja system optimizer and cleaner app.
  • Directory Monitor - Brutal Developer - Updated to version 1.1.2.12. Available in x32, x64, and portable versions. Sweet!
  • GeekUninstaller - Nice freeware app to not only uninstall apps from Windows systems, but also do some advanced system scanning and program super-cleaning of the bits and pieces that get left behind.  More in this CyberNet News post; Cleanly Uninstall Windows Applications and Remove Leftover Files.

Cheers!

--Claus V.

Read More
Posted in Active Directory, boot-cd's, forensics, Link Fest, Linux, networking, NFAT, security, utilities, Win FE, Win PE | No comments

Sunday, July 1, 2012

Material Roundup: Linkfest

Posted on 6:00 PM by Unknown

Been a semi-relaxing weekend.

Read with interest this TaoSecurity blog post Bejtlich's Thoughts on "Why Our Best Officers Are Leaving" as well as this one Whither United States Air Force Academy? both by Richard Bejtlich. I also noted that the USAFA was evacuated this week as cadets were heading in due to the area fires. These things still catch my attention as I had started the process to become a USAFA candidate my senior year of high-school before removing myself from the process for family reasons (my choice…no excuses). Still, I will always wonder about the path not taken.

Also, while IANAL, I was left scratching my head and heartbroken just a bit by the recent SCOTUS decision. The USNI blog had a post that resonated with my own feelings: The U.S. Supreme Court just diminished the significances of Military Valor [opinion].

Little bro was in town so he brought some pizza’s over, I grabbed some super-good local micro-brewed root beers and we had a party catching up, comparing life notes, and watching Act of Valor on this pre-July 4th weekend.

I wrapped things up yesterday with a viewing of Cave of Forgotten Dreams (Wikipedia) which covers the Chauvet Cave (Wikipedia). Very interesting and well filmed documentary. The cave-art is really fascinating…I just wish we could have learned more about the people behind it.

I guess if there was a theme it was reflecting on the importance of what remains of us, of our efforts, of the world around us.

Back to the shallows…

Sometimes I feel a bit guilty just dumping a super-post like this that is heavy-laden with linkage.

Some weeks are busier than others, however, and while I have more than a few posts still pending in the hopper that are deeper collections of “how-to”, personal reviews, or troubleshooting sessions, I hope that some find value in these “linkfests”.  Primarily they serve to help me quickly search and find material, tools, and techniques that I believe will either be useful, or are useful, when I am away from my desk and my USB dongle is at home rather than in hand. It’s challenging finding that right software or tip and maybe something here will be useful to others or pique their interest and send them in the right direction.

Security Bits

  • Adobe updates Flash Player 11.3 to fix Firefox crashing problem - The H Security - Adobe issued a new Flash (non-IE only) version 11.3.300.262 to address some issues in Firefox 13. Get your update.
  • Analysis of drive-by attack sample set  - ISC Diary - I always value posts like these that teach and show how “drive-by” vectors work. I’ve cleaned more than a few systems that fell victim to a drive-by because Java/Flash/OS/etc. wasn’t correctly patched.
  • Firefox thumbnails could expose private data; fix 'coming soon' - ZDNet. I hadn’t thought of it as an issue since I am use to Chrome doing the same thing, but the thumbnails are larger in Firefox and I could make out some detail to the webmail pages I saw as compared to how they render in Chrome.
  • Stop Firefox 13 Speed Dial Thumbnails From Showing Secure Content - AddictiveTips
  • How to turn off Firefox’s New Tab Page Completely - ghacks.net blog.
  • Our password hashing has no clothes - Troy Hunt’s Blog - Troy lays out an excellent (developer level) case for the new challenges of password hashing and salting. This was excellent reading and I really took a lot out of it in terms of password security in general.
  • John the Ripper password cracker - speaking of which Jon the Ripper “jumbo” edition just got released at version 1.7.9-jumbo-6 for Unit. WIndows binaries seem to be at 1.7.9-jumbo-5. Announcement here.
  • oxid.it - Cain & Abel - seems worth mentioning…
  • Free Computer Security - Personal Software Inspector (PSI) - Secunia. New Version 3.0 released with even more awesomeness!
  • Third edition of vulnerability spotter Secunia PSI - The H Security. More breakdowns.
  • Secunia PSI 3.0 released - HelpNet Security - more details here regarding this release version.
  • Free Online Computer Scan - Online Software Inspector (OSI) - Secunia. If the “installed” client isn’t your thing, the on-line scan is still super awesome and helpful.
  • Qualys BrowserCheck - Related - don’t browse the web in your browser without checking it for patch and plugin update availability!
  • Detect & Remove Fake Antivirus Scams From Your Windows PC - AddictiveTips post for a new MicroTrend tool to help with fake-av infection removal. See below.
  • Removing Fake Antivirus (FakeAV) - TrendMicro. Comes in both CLI and GUI downloads.
  • Remove 50 Known Fake Antivirus Software From Windows - AddictiveTips related post on another fake-av removal tool
  • Remove Fake Antivirus 1.86 - download tool as offered by free of virus & comptuer tips blog.
  • Security Center reports Virus Protection is On - ever handy tip from TinyApps blog.

For Sec News

  • Registry Decoder 1.3 released! - Digital Forensics Solutions. Bug fixes and some new plugins.
  • More good stuff - RegRipper - new plugins from Elizabeth Schweinsberg coming soon.
  • SANS Digital Forensics and Incident Response Poster Released - Handy! SANS
  • Training, and Learning - Windows Incident Response blog
  • When was a file accessed? - Windows Incident Response blog (How many times does this question get asked?)
  • Investigator's Tool-kit: Timeline - ISC Diary. Quite detailed overview and issues post
  • Win7 HomeGroup Reg Particulars - Forensic Artifacts
  • WinFE “Lite” - Windows Forensic Environment
  • Build questions -Windows Forensic Environment
  • HexDive 0.2 - Hexacorn Blog

Network Resources

  • Wireshark 1.8.0 can capture from multiple interfaces at once - The H Security
  • Wireshark · Wireshark 1.8.0 Release Notes - new Wireshark release in the waters…if you didn’t figure it out.
  • Wireshark · Download links
  • SoftPerfect Network Scanner - freeware - release 5.4.4 now out. Changelog Comes in both x32 and x64 flavors. My favorite stand-alone IP scanner (out of more than many I carry).
  • Chatter on the Wire: OS Fingerprinting - Satori was recently updated and now supports many more network fingerprints.
  • http://kitty.9bis.com - Never heard of KiTTY before but it is a fork of .62 PuTTY telnet client with some extra features.
  • New: KiTTY Portable 0.62.1.2 (telnet and SSH with added features) Released - PortableApps.com has a portable version.
  • PuTTY: a free telnet/ssh client - For the purists.
  • Announcing TightVNC Version 2.5.2 -TightVNC - New version just released. Love this app.
  • TightVNC: VNC-Compatible Free Remote Control / Remote Desktop Software - Download TightVNC here.
  • Announcing TightVNC Java Viewer - Yeah, the Java version rocks the beans as well. Super easy to use, compatible with standard VNC, TightVNC, UltraVNC, x11vnc, Apple Remote Desktop in Mac OS X, Xen/HVM, VMWare, Qemu etc. The link/page says 2.1 but there is a download link present for TightVNC Java Viewer version 2.5.2 so be sure you grab the latest version!

Tools and Utilities of Note

  • Updates: Autoruns v11.32, Process Explorer v15.21, Process Monitor v3.02 - Sysinternals. Stop, Drop, and Download now; the holy trinity of software tools just got updated again!
  • Monitor Any Folder Or Disk Drive For Changes In Real-Time, Even Across Networks - AddictiveTips blog post review of new NirSoft tool.
  • FolderChangesView - Monitor folder/drive changes - NirSoft
  • ExtremeCopy: Probably The Fastest File/Folder Move & Copy Utility - AddictiveTips blog review.
  • ExtremeCopy - Easersoft. I’m a dedicated TeraCopy fan but this one sounds intriguing. Will need to put it through the paces soon.
  • Remove Items from the Windows Explorer and IE Context Menus - CyberNet News.
  • MenuMaid - SD Software - software utility link
  • 4 Better Windows Console Tools Alternatives to Windows Built In Command Prompt -Windows7hacker - Kent has a really nice roundup. While the good-ole cmd.exe will do the job, I must say these “replacements” are quite nice. I’ve used “Console2” quite a bit and like the tab format and transparency/font/color tweaking options. PowerCMD surprised me with its feature set and I really can see myself using it more regularly. Check out the others as well.
  • GetFoldersize - Michael Thummerer Software Design - Super nice freeware tool to locate and understand just what is taking up space on your hard-drive. Was recently updated to version 2.5.10. I really like this tool.
  • SizeOnDisk Folder Size - new to me freeware tool found on CodePlex.  Another nice tool to find file/folder size hogs.
  • Folder Size - another freeware file/folder size tool.
  • SpaceSniffer - Uderzo Software - freeware tool that is amazingly fast and amazingly fun to use. While the previously mentioned tools excel at a tabular report, this one provides a super easy visual layout presentation of your space usage. You can drill down very easily. It gives you a easy-to-grasp picture on what is using up your hard-drive space..
  • SequoiaView - I keep this one around just because it is so beautiful. It does a great job even though it hasn’t been updated in quite a long time. It may have been one of the first to present space on disk usage in a “squarified” treemap format.
  • FolderSize - tiny little app (174 kb) from developer Jan Horn that is standalone and gives you a basic what-you-need-to-know report on drive/folder space usage.
  • DirectorySlicer - With giant (and cheap) USB sticks and network connections aplenty, splitting files and folders to specific sizes is become a rarified task. That said this CodePlex project is worth snagging in that it splits files of a folder into partitions of a specified size. So that super-folder you are trying to burn to CD doesn’t fit? Directory Slicer takes the work out of guessing by allowing you to set the size (or use a preset) then it divvies it up accordingly! Clever.
  • Unlock & Delete Empty Folders via Wildcard-Based Rules - AddictiveTips post review of…
  • Empty Folder Cleaner - 4dots Software
  • Reminded me of a previously GSD mentioned Empty Folder Nuker by Simon Wai.


For the Admins: Mostly from Microsoft

  • Rights Protected Folder Explorer 1.0 - Bink.nu blog. “Rights Protected Folder Explorer is a Windows based application that allows you to work with Rights Protected Folders. A Rights Protected Folder is similar to a file folder in that it contains files and folders. However, a Rights Protected Folder controls access to the files that it contains, no matter where the Rights Protected Folder is located.” Also Download Rights Protected Folder Explorer from Microsoft info from TheWindowsClub blog. Get it here Download: RPF Explorer - Microsoft Download Center(Download Details).
  • The Group Policy Setting “Verbose vs normal status messages” has a new name in Windows 8 - Anything about IT  blog
  • Comprehensive Linux course - TinyApps bloggist shares an amazing resource find for us Linux wannabe-better’s offered by Paul Cobbaut. Although it is claims to be Linux basics, it covers a wide range of topics and material.  This is a great find! Check back to the site often as the material is getting frequent updates.
  • Microsoft Outlook Configuration Analyzer Tool 2.0 - Bink.nu blog - “The Outlook Configuration Analyzer Tool 2.0 provides a detailed report of your current Outlook profile and mailbox. This report includes many parameters about your profile, and it highlights any known problems that are found in your profile or mailbox. For any problems that are listed in the report, you are provided a link to a Microsoft Knowledge Base (KB) article that describes a possible fix for the problem.” Go get the Download OCAT_Setup.zip over at the Microsoft Download Center’s Download Details page
  • FREE: Service Credential Manager – Search Windows services - 4sysops post on a new tool Service Credential Manager to help check all scheduled services and tasks based on a specific user account across your domain. Nice! In free/$ flavors.
  • FREE: ADREPLSTATUS – Active Directory Replication Status Tool - 4sysops blog post on a new Microsoft tool with a snazzy GUI to check for AD replication issues. Has export ability for reporting. Download: ADREPLSTATUS at the Microsoft Download Center (Download Details).

Cheers and happy pre-July 4th State-side well wishes to all.

Claus V.

Read More
Posted in Active Directory, anti-virus software, boot-cd's, cheat sheets, command-line interface, forensics, Link Fest, Linux, malware tools, Microsoft, networking, NFAT, security, utilities, viruses, Win FE | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile