Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label Xplico. Show all posts
Showing posts with label Xplico. Show all posts

Sunday, April 28, 2013

Ubuntu 13.04 (Raring Ringtail) Upgrade..a bit faster this time

Posted on 11:51 AM by Unknown

Yesterday turned out to be a deluge of epic proportions.  A moisture-saturated atmosphere dumped an unexpectedly large amount of water across the upper Gulf Coast. The Houston area had to deal with waves of hail, flooded freeways littered with floating and abandoned cars, high-water rescues, and general misery. What the local forecasters said on Friday would be a 10-30% chance of scattered showers became a 100% certainty of something floating in backyards everywhere. 

So it was the perfect day to settle in with my visiting father-in-law as the girls swam around town and watch home-improvement shows on cable and perform an upgrade to by VirtualBox session of Ubuntu.

  1. Find in RSS feeds that my Ubuntu 12.10 Quantal Quetzal install has a 13.04 Raring Ringtail upgrade available.
    ●  Ubuntu 13.04 is ready to deploy - Ubuntu
    ●  Ubuntu 13.04 boosts graphics performance to prepare for phones, tablets - Ars Technica
    ●  Ubuntu 13:04 Raring Ringtail published: The most important features at a glance - Caschys Blog (GTranslated)
    ●  New Ubuntu version hits today! - Boing Boing
    ●  Ubuntu 13.04 'Raring Ringtail' gives some, takes some - BetaNews
    ●  Hands-On With The New Features In Ubuntu 13.04 Raring Ringtail - AddictiveTips
  2. Begin making plans to do an in-place upgrade of my VirtualBox Ubuntu build…forgetting I had recently updated VirtualBox to 4.2.12 and it didn’t hurt my Windows VM systems…so why should I care about Ubuntu impact.
    ●  Downloads – Oracle VM
    ●  Changelog – Oracle VM VirtualBox
  3. Launched my VirtualBox Ubuntu build and logged in normally…and got a blank desktop. I did this several times. I could launch the VM and get the expected account login window for Ubuntu 12.10 just fine, but the desktop would never load. Hmmm. Wonder if that recent VirtualBox update had anything to do with it? Probably.
  4. Did some research and found some posts regarding VMWare upgrades screwing with Ubuntu in the past and they had tips about disabling 3D acceleration in the VM machine settings. VirtualBox has a similar feature (that was enabled) so I disabled it, relaunched the Ubuntu VM and now was able to load the desktop! Lesson learned; after upgrading VirtualBox, disable 3D acceleration on first-boot.

    hk3ijk2t.dbz
    ●  Latest Ubuntu update broke cinnamon · Issue #1763 · linuxmint/Cinnamon - GitHub
    ●  Later remember I also had 3D headaches last Ubuntu upgrade that I had to power-through.
  5. At that point I was able to install/upgrade to the latest VirtualBox Extension pack within Ubuntu proper. It ran slow as molasses but got the job done. Shut down the VM when done, re-enabled 3D acceleration in the VM machine settings, and was able to log back into the Ubuntu desktop with no issues and it was super-fast again. Yea! Looks like my former fixes from that post are still sticking:
        ● Ubuntu 12.10 – VirtualBox Guest Additions not Working -Complete, Concrete, Concise
        ● #10901 (vboxvideo fails to auto-load on Ubuntu 12.10 Guest) – Oracle VM VirtualBox
        ● virtualbox.org • View topic - Ubuntu 12.10 "virtually" unusable
        Edited “/etc/modules” file to include “vboxvideo” line as suggested above. Shut down.
        ● [ubuntu] newbie question on editing as root - Ubuntu Forums
        Edited “/etc/modules” file to include “vboxvideo” line as suggested above. Shut down.
        ● [ubuntu] newbie question on editing as root - Ubuntu Forums
  6. Used Daniel Benny Simanjuntak’s tip in the last Ubuntu post comments I did to run the following command from the terminal to start the upgrade process: Piece of Cake (and it wasn’t a lie)!
         …through terminal one can upgrade as well using the command:
          sudo do-release-upgrade -d
  7. Let it run forever…do a few reboots…
  8. When it is all settled down, I log in and kick the tires a bit, and change the desktop to the snazzy Raring Ringtail image.

    52rur2va.rbu
  9. Check “Upgrade to Raring Ringtail” off my to-do list.

I keep this particular Ubuntu build around mostly for working with the super-cool NFAT Xplico. However it is good for testing additional specialized software utilities and just trying to get more familiar with the Ubuntu environment in general.

This particular virtual HDD is just 8 GB so free space is a premium. I could expand it to at least 10 GB but HDD space on my laptop is at a premium so for now I’m trying to keep it thin.

After I got the upgrade done, I uninstalled some extra programs that had come in the default Ubuntu build to make room. I also ran through a few of the tips in this older Mike's Software Development Blog: Freeing hard disk space in Ubuntu Linux post. There may be more tips for freeing up space I haven’t found yet. I’m open for new tips and tricks!

Finally, the super awesome and brilliant Ubuntucat must be living here on the Gulf Coast as well as she has found a bunch of free time (homebound due to biblical-portioned rainstorms perhaps?) and is ripping out tons of posts on Ubuntu 13.04 over the last two days! Thank you, Thank you, Thank you Ubuntucat!

  • Installing Ubuntu 13.04 - Ubuntucat
  • Installing software in Ubuntu 13.04 - Ubuntucat
  • Tweaking Privacy Settings in Ubuntu 13.04 - Ubuntucat
  • Installing proprietary drivers on Ubuntu 13.04 - Ubuntucat
  • Pure Ubuntu 13.04 - Ubuntucat
  • Pure Kubuntu 13.04 - Ubuntucat (see Kubuntu | Friendly Computing for more info on this build)
  • Pure Xubuntu 13.04 - Ubuntucat (see Xubuntu for more info on this build)
  • Pure Lubuntu 13.04 - Ubuntucat (see lubuntu | lightweight, fast, easier for more info on this build)

--Claus V.

Read More
Posted in Linux, NFAT, tutorials, virtualization, Xplico | No comments

Sunday, October 28, 2012

For-Sec & Utility Jumble Linkfest

Posted on 6:52 PM by Unknown

Wordle_2012-10-28_10-49-54

The short weekend is done. The “Sandy Watch” is on for what could be -- for our northeastern friends -- a storm event to be remembered for many years to come. So comes a pile of security/forensic and utility-minded links spill out below for the curious and information hungry.

Forensics and Security

Girl, Unallocated: Be Very Quiet... I'm Tracking Emails Through Headers - Girl, Unallocated Blog. The Girl has a great post looking at email headers and their bits and perils. One gem is a report (PDF) from Stroz Friedberg and a particular focus on email headers. The report as a whole is a great read and again provides a lesson in technical report writing and presentation as well as some forensics pushback on anti-forensics techniques. At 102 pages, it isn’t a brief, but well worth the time to download and study.

The Girl’s post reminded me of another great publicly-available report that addressed emails in a forensic investigation.  In my GSD post Interesting Malware in Email Attempt - URL Scanner Links, I wrote the following bits at the end:

A recent Digital Forensics Case Leads post has mention of a super-fantastic investigation/forensic report involving anonymous emails. This is must-read material, not just in terms of the investigative methodology but also the way the report was composed and presented. Very clearly done!  I’m keeping a saved copy of the report for future reference; both technically and as a report template. From the post via the link above:

“University of Illinois recently released a detailed investigation report (PDF) regarding anonymous emails allegedly sent by its Chief of Staff to the University's Senates Conference. The report is an interesting read, and also serves as a potentially useful model for those looking for report samples and templates.”

How a Google Headhunter's E-Mail Unraveled a Massive Net Security Hole - Threat Level @ Wired.com.  I almost overlooked Kim Zetter’s post on how Mathematician Zach Harris -- as an exercise -- discovered a flaw in some providers user of a weak DKIM key to sign emails originating from them. Fascinating and short read.

DEFT 7.2 and DEFT english manual, ready for download! DEFT Linux - Computer Forensics live cd . New DEFT version out. Last one in x32 bits. Future versions will be strictly x64 flavored.

Xplico – Xplico 1.0.1 - Xplico new version release just dropped. From the brief post:

ChangeLog:

  • nDPI integration
  • performace improved
  • FTP dissector improved
  • Added the prism dissector
  • CLI execution bug fixed
  • PCAP-over-IP SSL encryption
  • IRC dissector improved
  • File reconstruction from Fragmented Payloads improved
  • FaceBook Chat updated
  • FaceBook Message (partial)
  • HTTP without initial packets (packets lost)
  • RTP dissector improved
  • PCAP2WAV, RTP2WAV interface added

And don’t forget! Now you can update/get via apt-get! for Ubuntu 11.04 and higher.  Sweet!

sudo bash -c 'echo "deb http://repo.xplico.org/ $(lsb_release -s -c) main" >> /etc/apt/sources.list'
sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 791C25CE
sudo apt-get update
sudo apt-get install xplico

LastActivityView - Nirsoft brand new utility! - Use this new tool to view the latest computer activity in Windows operating system. Nir Softer has some more details on his NirBlog: New utility that shows general computer activity. Could be useful for incident response and analysis and other “quick peeks” for key system activity indicators to narrow down the search.

FileAlyzer Portable 2.0.5.57 (detailed file analyzer) Released -PortableApps.com

Hacking KeyLoggers - Open Security Research has a great post that not only identified a USB keylogging device, but takes it to the next level in hacking it to determine the impact of the device and when it might have been dropped. Clever stuff.

Attacking TrueCrypt - The H Security: News and Features. Another interesting post that almost slipped by me. Interesting by itself but also shows the benefit of using “cascaded algorithms” in TrueCrypt to thwart current attacks…for now.

Restoration of defocused and blurred images - Yuzhikov.com. This is super cool.  Vladimir Yuzhikov hasn’t just done a proof of concept for de-fuzzing blurred imaged (either out of focus or those blurred with a mathematical algorithm), no, he has actually released a free Windows app to demonstrate the possibilities. Besides images, text that is out of focus can be unblurred as well. This is very fascinating and could assist investigators facing images and other digital files with blurred faces or content. It’s not exactly easy or guaranteed to work, but it is very promising start and Vladimir notes he is continuing development and refinement. Read his work please and snag the download.

Google Drive opens backdoor to Google accounts - The H Security: News and Features . Quoting from the post, “The Windows and Mac OS X desktop clients for Google's Drive file storage and synchronisation service open a backdoor to users' Google accounts which could allow the curious to access a Drive user's email, contacts and calendar entries.”  read the post for more info. As usual it seems to be a convenience versus security trade-off again. Choose your cake wisely. I stick with using only the web interfaces and pass on the client versions of these cloud-based storages services…for now.

Virtualization

The TinyApps bloggist has been hard at work digging out great tips and techniques for importing the virtualized “Windows XP Mode” into popular virtualization software. As always, the posts are impeccable with lots of details and supporting source documentation for additional study and research.

  • Import Windows XP Mode into VMWare Player - TinyApps.org blog
  • Import Windows XP Mode into VirtualBox - TinyApps.org blog
  • Must-have tool for VirtualBox users - TinyApps.org blog.

Oracle VM VirtualBox - Version 4.2.4 just dropped…by the way. I almost missed it were it not for my RSS feed filters. See the changelog for more details.  And be sure to grab the 4.2.4 VM VirtualBox Extension Pack as well.

Miles’ posts reminded me of an earlier GSD summer post Virtual Solutions and his great post comment guiding me to getting MS’s IE VirtualPC images running in Virtual Box.

How to run Microsoft’s IE VPC images in VirtualBox
http://tumblr.jonthornton.com/post/11405634980/how-to-run-microsofts-ie-vpc-images-in-virtualbox

ievms - Automated installation of the Microsoft IE App Compat virtual machines
https://github.com/xdissent/ievms

Browser Plugin Update Time…Again.

Yes dear readers, it is “Jack and Jill” time again. Bother.

Adobe Shockwave got updated, as of this post, the newest (Windows) version of Adobe Shockwave is currently 11.6.8.638.

  • Adobe - Adobe Shockwave Player - direct download
  • Adobe - Security Bulletin: APSB12-23 - Security updates available for Adobe Shockwave Player - Adobe
  • Adobe patches 6 critical security flaws in Shockwave - ZDNet
  • Adobe fixes critical Shockwave vulnerabilities - The H Security: News and Features

Adobe Flash was updated as well. Newest (Windows) version is currently 11.4.402.287.

  • Adobe - Flash Player - version information
  • Adobe releases 25 critical Flash patches - The H Security: News and Features
  • Adobe - Security Bulletins: APSB12-22 - Security updates available for Adobe Flash Player - Adobe

Java also got a quick update to both build versions. Windows Java updates are available in 1.6.0_36 and 1.7.0_09.

  • Java SE 6 Update Release Notes - Oracle
  • Java SE 7 Update Release Notes - Oracle
  • Java SE Downloads - Direct download

Trying to figure out if all your browser plug-ins are current can be a super-pain for the inexperienced and geekless.

My go-to recommendation remains to pop over to Qualys BrowserCheck in each of your installed web-browsers, be it Chrome, Windows IE, or Firefox. Alas, Opera, Safari, and other browsers are not currently supported, however a check in one of the supported browsers may quite likely uncover a outdated plug in, patching it may fix the others in the process.  For a backup check, hope over next to The Secunia Online Software Inspector for a second opinion.

If you want a good all-in-one location to manually download your plugs, check out Browsers and Plugins Downloads over at FileHippo.com.

Utility and SysAdmin Finds of the Week

Defrag Tools: #13 - WinDbg - Defrag Tools @ Channel 9. New video on Sysinternals tool usage; specifically integrating Debugging Tools for Windows.

Case of the CertUtil Import Refusing The Correct Password - chentiangemalc. Great practicum post on troubleshooting a strange password error where the password was correct but not being taken.

SpeedyFox - Boost Firefox,Skype,Chrome,Thunderbird in a Single Click! - CRYSTALIDEA Software . It has been forever…like dinosaurs roaming the earth eras ago…since I last saw any post anywhere on speeding up a pokey Firefox browser by “optimizing” the JSON databases. This is a dead-simple process to improve launch-time for a well-used Firefox browser. It’s been months since I last optimized mine. When I went to run SpeedyFox, my favorite tool to do so, I wondered if there had been an updated release. My version was at least a year old.  Happily I found there was a newer version, and that it now supports optimizing Chrome-based browsers as well. It remains available as a free edition. Current version is 2.0.3 but while I was sleeping, the developers have been adding support for Skype, Chrome (including SRWare Iron and Pale Moon), Mozilla Thunderbird, and Firefox (including Epic Browser). There is a Mac version (Firefox only) also.

If you use Firefox/Chrome/Thunderbird, stop, drop and run right now!  Did I mention it supports custom paths to your browser profiles so you can optimize portable versions on your drive/disks? Sweet baby Jebus!

CR2 Converter - I shot a lot of photos for Lavie and her family last weekend with the Canon 5D Mark II.  Pops asked for copies and when I was getting ready to pass them off, I realized I had not changed the setting from “RAW” only to RAW+JPEG. So I had over 300 digital images in RAW .cr2 format that his computer cannot read and that are not really a practical format for him anyway to use. Sure, I could batch-convert them in Lightroom/Photoshop, but I really just needed to get them quickly on a CD for him.  I have more than a few RAW freeware tools for tweaking individual RAW file images but that was too time-consuming to use. Luckily, with just a bit of Google diving, I found the freeware Canon RAW Image Converter “CR2 Converter”.   It supports batch-conversion and did an acceptable job for this task. My i7 x64 8 GB RAM system chewed through converting the files in no-time.  To my eyes the resulting images were a bit lightly purple-tinted…not bad or unpleasant but definitely noticeable when compared to the RAW file. Nothing that some simple color correction can’t fix if really important. For Pops it wasn’t but YMMV.  I wouldn’t use it everyday for batch processing but for quick-n-dirty RAW .cr2 to JPEG/JPG/GIF/BMP/PNG/TIFF conversions it is a super time-saver. Tuck it away for when needed in a pinch.

Cheers and hopes and prayers for the very best across the north-east seaboard as Sandy rolls in.

--Claus V.

Read More
Posted in browsers, Firefox, forensics, Google, graphics, hurricanes, Internet Explorer, Link Fest, Microsoft, networking, NFAT, security, troubleshooting, utilities, video, Virtual PC, virtualization, Windows 7, XP, Xplico | No comments

Sunday, May 6, 2012

Oldies But Goodies - Linkfest

Posted on 1:50 PM by Unknown

Progress is being made on several piles of links I’ve come across but haven’t posted yet. It is actually turning out to be a good thing culling them down like these.

The links below were in a For/Sec/Net folder I was using to hold blog material under that subject until it got too full and too old for me to continue dropping items in there. Some went back to late 2011!

Yesterday I decided to do some Spring cleaning and deal with it.  I dumped a LOT of links that seemed either dated or just not as important now as they seemed to be back then.

What remains below are links that I still wanted to document for research/reference. I did update/supplement some of them with some new material if applications the original links I captured have been updated.

Anyway, here you go if you are interested.

Watching the Networks

  • Using Wireshark to Support the Application (by Tim Poth) - LoveMyTool blog - video presentation on Wireshark techniques for troubleshooting network issues.
  • Network Mystery #2 (by Betty DuBois) - LoveMyTool blog - video presentation on analysis of a slow network performance situation.
  • Wireshark in the Large Enterprise (by Hansang Bae) - LoveMyTool blog - video presentation on the role Wireshark can play in a large network environment.
  • Using Wireshark's Editcap to Reduce Your Trace File Size (by Tony Fortunato) - LoveMyTool blog - short (7m) video on splitting capture files to make capture file more manageable.
  • Ostinato: Craft and Play Packets (by Joke Snelders) - LoveMyTool blog - Overview of the packet crafter and traffic generator application Ostinato.
  • PDD - Packet Dump Decode (by Joke Snelders) - LoveMyTool blog - packet/hexcode dumping/conversion too.
  • NetworkMiner 1.3 Released - NETRESEC blog - old news for a great program.
  • Security Onion includes NetworkMiner - NETRESEC Blog
  • No more Wine - NetworkMiner in Linux with Mono - NETRESEC Blog - I just followed these steps and got NetworkMiner running perfectly in Ubuntu 12.04 this weekend. Sweet.
  • Passive OS Fingerprinting - NETRESEC Blog
  • NBTScan. NetBIOS Name Network Scanner. - I use this CLI tool each week. Works great. Mark Woan recommended this version as an alternate: nbtscan - NETBIOS nameserver scanner
  • Magic Tree from Gremwell - Interesting tool to help manage network scan data. Works with nmap.
  • Home of 0x4553-Intercepter and 0x4553-NAT or Intercepter-NG - very interesting pen-test/sniffing tool that can parse out quite a lot of items.

Tips, Tricks,and other Material

  • Facebook Forensics - Help Net Security - Points to paper published by Valkyrie-X Security Research Group on Google Docs or download it in PDF format.
  • How we found the file that was used to Hack RSA - F-Secure Weblog : News from the Lab
  • Bypass Vulnerabilities in Squid and McAfee Web Access Gateway - SpiderLabs Anterior blog.
  • Quickpost: Blocking and Detecting a Teensy Dropper - Didier Stevens
  • Plug and Prey: Malicious USB Devices - IronGeek reference material
  • Lost a Windows Registry key? Yaru can recover it - BetaNews blog - review of  (YARU) Yet Another Registry Utility tool.
  • Carving Symantec VBN Files - Security Braindump - guide on using QExtract to remove SAV quarantined files for incident analysis. However it has limitations and Bugbear provides some tips on an alternative method of extraction.
  • CSI:Internet - Controlled from the beyond - The H Security: News and Features
  • Purchase information such as your e-mail address and name of iTunes song removed - Caschys Blog (GTranslated) - I’ve been meaning to post this for a while. Caschy illustrates how if you buy songs via iTunes the file gets embedded with the purchaser name/email address. I thought this might have some possible use when looking forensically at a system/files.
  • (IN)SECURE Magazine
    • DOWNLOAD ISSUE 33 HERE  - PDF Link
    • DOWNLOAD ISSUE 32 HERE - PDF Link
  • Proceedings of The 9th Australian Digital Forensics Conference - I may have posted this before, but it contained a lot of great presentations and whitepapers I had to relink.

Scan it & Dump it!

  • rootrepeal - Beta rootkit detector
  • GMER - Rootkit Detector and Remover
  • Live Memory Forensic Analysis - SANS Computer Forensics and Incident Response blog
  • MoonSols DumpIt goes mainstream ! - MoonSols - ISC Diary | MoonSols Dumpit released...for free!
  • Volatility: Advanced Memory Forensics - Released to version 2.0 back in August 2011.
  • Hexacorn Application Monitor - Hexacorn Blog. Related blog post: How to use HAM?

Tools and Utilities

  • TrID - Marc Pontello - Utility to ID files from their binary signature. Def database gets updated often so keep it fresh!
  • FileMind Pro Beta 0.6 - Metability Software - Super cool tool to find/review/manage file metadata.
  • FileMind QuickFix - Metability Software - and a free tool to scrub metadata from files.
  • Know Your Files - Metability Software blog. Not updated recently but still good info.
  • TZWorks LLC Prototype Downloads for Forensic tools - TZWorks list of lots of super-cool freeware utilities.
  • Registry Decoder - from the project page -- “Registry Decoder provides a single tool in which to perform browsing, searching, analysis, and reporting of registry hive contents. All functionality is exposed through an intuitive GUI interface and accommodates even novice investigators.“
  • Free Computer Forensic Software downloads and Secuirty Tools - Forensic Computing Ltd. - Great list of tools.
  • DarkComet RAT - Official - tool to extract information from browser history

Live ForSec CD’s

  • CAINE Live CD - computer forensics digital forensics - “SuperNova” version 2.5.1 has been out.
  • DEFT 7.1 ready for download - Released April 2nd with more than a few updated packages and fixes.
  • Ubuntu - Now at 12.04 release version. I prefer to use this for my own self-installations of Xplico and Network Miner packages.
  • Ubuntu 12.04 and VirtualBox Image - Xplico team has released a VirtualBox image built on Ubuntu 12.04 which includes their Xplico 1.0.0 version (if you don’t want to build it yourself!).
  • ubuntu [Xplico Wiki] - Now you can use the Xplico Repository or one of several terminal scripts to easily (and I mean REALLY EASILY) get the Xplico NFAT application going! Super sweet.

Maltego

I first learned about Maltego when I read this fun post Using Maltego CaseFile to map The Spy Hunter at the wirewatcher blog.

Basically this tool lets you organize your intelligence and forensic investigation information in new and graphical manners to better show relationship between elements. Check out the bottom of this page for some screenshots and links to more presentations.

It comes in both a commercial and community edition.

  • Maltego 3.1.1 Community edition released - Maltego Blog - info on the latest version release.
  • Maltego Blog - Latest news
  • Maltego Blog: Maltego CaseFile Beta released - has 10min video on an earlier version with links to the beta version 1.0 downloads.
  • Maltego 3 > Community Edition - registration page. Registration is required to use the community edition.

Note: I’m still playing with the version 1.0 beta version and haven’t upgraded yet to the version 3.1.1 community edition.  The version 1.0 so far has been meeting my basic “play and learn” needs, FWIW.

Whew!

I feel better now.

Next up…new material fresh out of the bakery ovens.

Cheers!

--Claus V.

Read More
Posted in boot-cd's, forensics, Link Fest, Linux, malware tools, networking, NFAT, security, tutorials, utilities, Xplico | No comments

Monday, July 4, 2011

For/Sec Linkfest: Revolutionary Edition

Posted on 1:20 PM by Unknown

image

cc attrib: The US Army on flickr, DoD photo by Air Force Tech. Sgt. Jacob N. Bailey

This season’s July 4th finds Lavie and I quietly resting at home watching “classic” revolutionary period movies on TCM. Alvis has flow the coop to a week-long church-youth camp. Firework sales and use have been banned by all the area counties and municipalities due to the record-busting Texas drought and heat.  We will probably have to suffice with watching celebratory events in HDTV-mode again tonight.

The weekend has been pretty light on tech-support calls. Dad wanted to give his father-in-law’s old cobbled-together “antique” PC system a refresh so I picked out a nice basic-home-user-grade Dell Inspiron 570 model that will be way sufficient for his pretty-much email-only PC needs.  Dad and little-bro set it up yesterday and did most of the pre-installation setup and file-transfer.  I’ll do some remote-support work this afternoon to lock it down and recover some account passwords and such off the old system and get them going on the new one.   And then yesterday I stripped-down the keyboard off Lavie’s laptop.  Seems a week or so ago, Lavie fell asleep with both a small tumbler of sweet tea and her laptop on her chest.  A very small portion of the tea ended up in the keyboard. Oops. (very) Fortunately the keyboard tray caught all of the spillage. (un) Fortunately, it was sweet (sugared) tea, so let’s just say the keys were less than responsive with spring-back action.  That restoration job took about three hours. Disassembly and cleaning was pretty straight-forward. However getting the scissor-action two-piece key travel parts re-mounted was very delicate work as I didn’t want to break any of them. It took me about twenty minutes to get the mating and mounting technique down before my pace picked up.  All is well now and Lavie is clickity-clicking again happily.

Offered here today is a forensic and security slanted linkfest.  This folder has been very, very full for a very long time.  What survives below are the best of the best as the blogging room floor is littered with editing cuts and discarded linkage that didn’t age well.

In the Reading Room

(IN)SECURE Magazine is a great source of security and network issues. I keep several of these PDF files on both my laptop and Kindle for go-to reading when things are slow. (IN)SECURE Magazine issue 29 and (IN)SECURE Magazine issue 30 are the most current. However, pop onto the Archive page to look for past issues that may have some gems.  For example, this early ISSUE 4 (PDF link) has a great article “Structured Traffic Analysis” on pg 6 written by network sec guru Richard Bejtlich. While the article could probably be updated with the newer network analysis tools made available since Oct 2005, the framework Richard lays out still works very well.

InfoSec Resources has lots of great articles to read and study. Check out their article archives for a really wide range of for-sec articles and whitepapers.

CERT Societe Generale - IRM (Incident Response Methodologies) as some good incident handling guides to review or keep filed within reach.

Dashboard | SANS Internet Storm Center - Security “dashboards” look cool and can communicate valuable information. I’ve got several I keep an eye on from time to time.  SANS has recently updated theirs.

Girl, Unallocated - Newly added forensics blog to my RSS feed list.  Fresh perspectives are always welcome at GSD!

VRT: A Close Look at Rogue Antivirus Programs - Post by Alain Zidouemba that contains PDF of the slides presented on his talk "A Close Look at Rogue Antivirus Programs" given at Hack in Paris conference.  I’ve lately been paying closer attention to articles on malware (particularly rogue-securityware) vectors.

Security Aegis has some great posts Real OSINT and OSINT, because knowing is half the battle on “open-source intelligence” work.  This is good stuff as when you are doing network traffic analysis, being able to attempt to track down and understand the names/handles seen in the traffic may provide additional clues in your incident response analysis.

The posts over at Malware Intelligence don’t come fast-enough for me, but when they do, they are golden. JAVA Drive-by [infection] On Demand actually got their hands on a “drive-by” generator and pick it apart. Neat.

Network Traffic: News and Reports

Lots and lots of goodies here!

The folks at Packet Life have posted some good material recently: Proving the Network is Not the Problem With iperf and Long-Term Traffic Capture With Wireshark offer great tips and techniques for you network jockeys.

Out of comments from those posts came a jump to the NetStress Network Benchmarking Tool and NetSurveyor Network Discovery Tool -- both of which are offered for free by Performance WiFi.

LoveMyTool blog has the following juicy fruits: Microsoft Network Monitor 3.4: Search the Description Column (by Joke Snelders) and A Deeper Look into Your Network - Cool Tool (by Vivek Rajagopalan)

That second one points us to Trisul Network Metering and Forensics tool.  If you just need “near-time” network traffic reporting and analysis, then the Free rolling 3 day window version looks hard to beat.

TinyApps.Org Blog : Setup a virtual network lab brings to our attention the free Marionnet.org project for networking practice and study.  It is a very cool project.

The Case of the Great Router Robbery over at InfoSec Resources poses some deep thoughts about the importance of physically securing your routers.  It’s not just because many of they are outright high-dollar items to begin with, but the configuration data on them is golden for pen-attack reconnaissance and enablement. It closes with some good thoughts about securing your device if it is stolen and what you should do if loss does occur.

Network Mystery #1 (by Betty DuBois) at LoveMyTool has both a recorded presentation as well as slide-show PDF from Sharkfest 2011. It is appx 1:26 long so it isn’t a fast-view.  That said, Betty offers some great guided material for you network tracers.

" ... In this session, Detective Betty DuBois will review one of the elusive network cases she has solved using Wireshark and Pilot. There will be plenty of forensics evidence provided, and lots of practical information to help you solve your own network mysteries. This session will be a deep dive into the "Case of the Slow Network". Betty will walk the attendees through how the data was captured (tshark & AirPcap), the methods used to isolate the problem (SMTP relay infection), and which users were infected ... "

Network Traffic: Tools and Techniques

Solution to the Nitroba case - Erik Hjelmvik (Network Miner) on the NETRESC blog posts some great network forensics tips specific to the “Nitroba Case” exercise. I was fortunate enough to read the first-post version before some elements were modified. Regardless it is a great example of how NetworkMiner can be used to analyze and dissect network traces in investigatory work.

Tools for modeling the user-traffic - superlist of network traffic analysis tools over at comlab.uni-rostock.de.  Bookmarkable.

RawCap sniffer for Windows released - NETRESEC Blog. I’m sure I’ve posted this here. Erik released a CLI tool for raw-socket network captures. It’s a slim single-exe file and is pretty cool. No installation required. Definitely worth keeping on a USB stick.  I like that I could download it to a local (remote) system and run a targeted trace of that system’s network traffic without needing to install a larger app like Wireshark. Likewise, as Erik suggests in the post, one could “…use the Sysinternals tool PsExec to inject RawCap.exe onto the [remote system] and sniff the packets.”

Split or filter your PCAP files with SplitCap - NETRESEC Blog. Not a new tool, but an update to v1.6. This CLI tool can slice-n-dice very large PCAP files into smaller sets based on IP addresses or sessions. Sure, you can do filtering work in Wireshark and NetMon as well, but this is a very fast tool and makes bulk PCAP file splitting/filtering very easy.

York::Log all network traffic - The SZ Development.  Interesting network sniffing/logging tool.  Certainly not for Wireshark/NetMon pros; however the GUI and basic logging/websession monitoring features might make it more user-friendly for folks getting their feet wet.

NMTopProtocols Expert Released - Network Monitor Blog

Using Wireshark's editcap to Remove Duplicate Packets Packets (by Tony Fortunato) - LoveMyTool guided post.

Bittwiste: pcap Capture File Editor (by Joke Snelders) - LoveMyTool - review and thoughts on how to use the Bit-Twist program for packet manipulation.

So Many Tools…So Little Time!

Windows Incident Response: Using RegRipper - WindowsIR blog. Harlan provides us an updated guide on how to effectively use his amazing RegRipper tool. See also the New Plugins from Harlan.

Kissin-Kousin of RegRipper is Woanware’s RegExtract.  I believe they complement each other nicely. Keeping up with the active updates to RegExtract can be challenging. Focusing on the most recent may cause you to overlook other features that have previously snuck in! See these: RegExtract v1.1.3, RegExtract v1.1.4, RegExtract v1.1.5, RegExtract v1.1.6, and the latest, RegExtract v1.1.7.

Also recently updated in the Woanware factory:

  • ChromeForensics v1.0.4
  • USBDeviceForensics v1.0.6
  • PrefetchForensics v1.0.4

Dropbox Reader - by CyberMarshal. CLI tool collection for investigating DropBox cloud-storage software indicators.

DumpStrings.1sc - Didier Stevens shares a script that dumps ASCII and UNICODE strings found in a file. To be used with 010 Editor.

P2 Shuttle Free - Paraben Corporation - Free multi-tool to remotely mount disks, do live-system process reconnoiter, memory capture, machine searching, active file browsing of email, chant and IE history, and open a disk without mounting. This version does have some limitations so understand before relying on it too much.

P2 eXplorer Free - Paraben Corporation - Free utility to mount forensic disk images of many different formats.

Meanwhile the folks at Mandiant have been busy making material as well:

  • MANDIANT Intelligent Response 2.0. See this MIR 2.0 Released post for more info. (not free)
  • MANDIANT Redline - (free) - “Redline is a free utility from MANDIANT that accelerates the process of triaging hosts suspected of being compromised or infected while supporting in-depth live memory analysis. Designed to help find even the best-hidden malware, it analyzes and rates every running process on a system according to risk, combining Memoryze's live memory analysis with MRI (Malware Risk Index) scoring. Redline makes memory forensics accessible to any investigator without relying upon easily-defeated signature-based detection.”
  • Highlighter v1.1.2 Released

In both posts Windows Incident Response: Tools and Meetup, Tools and other stuff  - Harlan offers a great listing of for-sec tools.  I especially liked the discussion of “Jump Lists”.

Complementing that discussion is the new woanware tool JumpLister v1.0.0.  “JumpLister is designed to open one or more Jump List files, parse the Compound File structure, then parse the link file streams that are contained within. It uses the LNK parser I wrote so stuff like object ID’s and MAC addresses are handled.” Sweet!

The H Security announced that Microsoft releases Security Essentials 2.1.  Despite the fact that the recent system infections I had to clean were able to overwhelm (previous versions of) Microsoft Security Essentials, I still have lots of confidence in the product for home users. In these cases, outdated Java/Flash versions left the door to the barn open and MSSE couldn’t keep up with the attack. Any a new version has been quietly released.  It’s actually been out for about a week but Windows Updates and/or MSSE internal updating didn’t pick it up. However if you want it now (recommended) download the new version directly from the product page and run. It will do an in-place upgrade with no fuss. For more info or download locations:

  • Microsoft Security Essentials 2.1.1116.0 released, Download Now - Windows Valley has the (slim) info on what this update brings.
  • Virus, Spyware & Malware Protection - Microsoft Security Essentials main product page.
  • Download Security Essentials 2.1.1116 - FileHippo.com (alt download link)
  • Download and install Offline Updates for Microsoft Security Essentials - Windows Valley has a great tip and linkage on how to “off-line upate” the DAT files for MSSE. I figured this could be done but never took the time to hunt down the source locations. Here you go!

How-To’s and Info of Note

Create a Bootable DBAN USB Pen Drive - TrishTech - Vendor dude has a contract to secure(DoD) wipe our out-of-service system HDD’s before they are returned to the lessor. Most of the time he is running a bank of bases and tossing in a Darik's Boot And Nuke (DBAN) CD and wiping away. Periodically however he would run into a system with a bad CD-ROM drive and would have to strip out the HDD and put it into another system to then run his CD.  I asked him why he didn’t just make a boot-USB version of DBAN. Brilliant, wasn’t it….  Here you go.

Security Braindump: Virtualizing Raw Disk Images - Because you know one day you will need to…

Windows Security Center: Under the Hood - Didier Stevens. Wish I had this post from Didier when I had composed this GSD post: How to Repair Windows Security Center List Items.

Tim Mugherini presents NTFS MFT Timelines and Malware Analysis - posted by John Strand at PaulDotCom.

Internet Explorer 9 Security Part 4: Protecting Consumers from Malicious Mixed Content - IEBlog.

For-Sec Live CD News

The world of “Live CD’s” is alive and healthy.

Security Onion 20110628 now available - I’ve only recently become acquainted with the tools and features of Security Onion distro. Very nice and has some great includes from Doug Burks.

PALADIN Download - Sumuri - Version 1.0 was released back in April 11. 

DEFT Linux 6.1 Computer Forensics live cd was also released back in April 11. See this new “draft” DEFT english manual if you are not already familiar with this distro.

BackTrack Linux 5.0 - Penetration Testing Distribution was released in May 11.  It’s a whopper so unless you got a big pipe, you may need to start the download when you put the cat out for the night.

As previously mentioned here on GSD, Brett Shavers the WinFE guy has been hard at work evangelizing on the WinFE distro.

  • Sharing the love with WinFE - WinFE Blog
  • How easy (or difficult) is it to build a WinFE with WinBuilder? - WinFE Blog

Offline Antivirus – How to run Microsoft Safety Scanner on Windows PE 3.0 - 4sysops

Whew!

Now this post is out of the way, I can turn attention back to an Xplico follow-up along with a collection of linkage that came out of a conversation with TinyApps on write-block hardware that has been gathering dust for quite a while.

Happy 4th!

--Claus V.

Read More
Posted in anti-virus software, boot-cd's, command-line interface, forensics, Link Fest, Linux, malware tools, Microsoft, networking, NFAT, security, software, tutorials, utilities, viruses, Win FE, Xplico | No comments

Saturday, March 5, 2011

Self-Installing Xplico in Ubuntu - Virtual Edition

Posted on 5:46 PM by Unknown

image

Above Image…the Xplico baby is delivered and working perfectly!

In my previous Xplico post, I mentioned how I had been using the VirtualBox images of Xplico.  And how suddenly they had stopped working.

Having been using this tool for a while, the sudden loss of this resource was frustrating.

In the end I sought to create my own self-built version so I could have a running version in my own VirtualBox session/image.

Plan A - Good Theory, Difficult Implementation

My original plan was quite simple.  (Warning: Linux-noobie stumblings ahead!)

  1. Create a  8 GB dynamic VirtualBox vmdk file.
  2. Find a Debian-based LiveCD that included a local installer.
  3. Load the vmdk file using the LiveCD to boot it.
  4. Install the Debian OS.
  5. Install Xplico
  6. Celebrate.

In theory this should have worked fine.

I had no challenges making the vmdk file.

I picked out PureOS and Linux Mint Debian LiveCD’s as my platform sources. Downloaded both and went with Mint.

I booted the vmdk file and installed Mint. No issues besides having to do some gparted work on the volume and some formatting of the partition. No biggie.

Then I set about doing the Xplico installation.  The Xplico developers have done a great job with providing the documentation on their Xplico-Wiki:

Install Xplico

  • Building: Building and Installing Xplico

  • Interface: Installing Xplico Interface (XI)

  • Tutorial: Step by step installation

  • doing a DEB package: Instructions to generate a DEB package from source code.

So it should have been a piece of cake. Right?

Unfortunately, despite all my Step by Step attempts, I couldn’t apt-get a version of libmysqlclient16-dev.  And even though I continued on bravely anyway, stuff just started falling apart.

So after a few hours of work last night struggling through--and at least another hour of research--I found an alternative Xplico-installation method offered and decided to get some zzz’s and start fresh in the morning.

Plan B - Can it be this easy?

My new plan was realistically simple.

  1. Create a  8 GB dynamic VirtualBox vmdk file.
  2. Download Ubuntu Desktop Version 10.10 (it has a local installer).
  3. Load the vmdk file using the LiveCD to boot it.
  4. Install Ubuntu.
  5. Install Xplico via a pre-crafted script I had discovered in a forum.
  6. Celebrate.

And it worked!

The GSD Xplico Recipe

Here’s the Haps!

After much research from the night before, and realizing that the “official” Xplico VirtualBox images were based on Ubuntu, that seemed the way to go rather than my first choices.

Note this assumes some moderate familiarity with VirtualBox and Linux.  I’m leaving some of the details out that seem straight-forward (to me)…YMMV.

  1. Download VirtualBox if you haven’t already done so.  At the time of this post I used 4.0.4. Install accordingly.
  2. Launch and create a new virtual machine using the wizard.  Give it a  name, for the OS type pick “Linux” and for version pick “Ubuntu”. Pick your base memory size.  For my host system I’ve got lots of RAM so I went with 1024MB but you could use the default 512MB.  I kept the Boot Hard Disk option checked and allowed it to create a new hard disk at 8 GB. Since space is still a premium, even with a 500GB local hard drive, I went with the Dynamically expanding storage disk option. I took the default location, confirmed the size and hit “Finish”.  Done.
  3. Next I downloaded Download Ubuntu Desktop Edition 10.10 x32 bit version of the LiveCD.
  4. Once done I modified by virtual machine storage settings for the CD to point to the ISO I just downloaded and then launched the virtual machine.
  5. Once Ubuntu booted I just clicked the large “Install Ubuntu” button offered.
  6. I decided to go with all the defaults, including downloading of updates while installing as well as installing all third-party software packages offered. I took the default to let the installer erase and use the entire disk automatically (look ma! No manual gparted work!).
  7. While the installation went on in the background I continued with the localization setup and profile setup.  I decided to name my build GSD-Xplico and use “xplico” for both the name and password (to mirror the default account in the Xplico app) for simplicity.
  8. Hang out and chill for a while (or get started make an Old Bay Gulf-Coast pot-boil for dinner) as the installation/updating process completes. Yummers.
  9. When done, reboot as requested by the installer (don’t forget to disassociate the attached ISO LiveCD/Installer first!).
  10. Log in using the credentials you created in step 7.
  11. Optional but recommended.  Go ahead and install the VirtualBox Guest Additions.  I’m assuming most folks still here should be able to handle knowing how to do that. This will help a number of things but most of all will allow you a few more screen resolution size options.
  12. Optional but recommended. When prompted by the Update Manager, go ahead and install all available updates offered. At the time of this post, I found 275 updates offered.
  13. When done, reboot.
  14. Log in again and open up Firefox.
  15. Now for the secret sauce.
  16. Browse to http://5ff1cwepqm.tal.ki/20101216/wicd-xplico-261923/
  17. In that GnackTrack forum, commenter blaksark posted the following Xplico Script installation by Nsark.  All honor and credit ascribed accordingly.

    sudo apt-get update && sudo apt-get install -y gdebi sed && wget http://sourceforge.net/projects/xplico/files/Xplico%20versions/version%200.6.1/xplico_0.6.1_i386.deb && sudo gdebi -n xplico* && sudo find /etc/php5/apache2/php.ini -exec sed -i.bak 's/post_max_size = 8M/post_max_size = 800M/g; s/upload_max_filesize = 2M/upload_max_filesize = 400M/g' {} \; && sudo service apache2 restart && sudo service xplico restart && firefox localhost:9876
  18. Copy that script to the clipboard.
  19. Open “Applications” --> “Terminal” from the top menu bar.
  20. Paste the copied script.
  21. Press “Enter”
  22. Provide the prompt your password.
  23. Watch Nsark’s magic run for a bit. Basically it is getting all the dependencies, all the packages, installing them, then adjusting the apache settings to allow for larger PCAP file size uploads, restarting apache and the xplico service, and finally launching Firefox to the Xplico web-page.  Brilliant!
  24. When completed, close the terminal window.
  25. Behold, a wonderfully installed version of Xplico!
  26. You may want to set the Xplico Web Interface page as your Firefox homepage.  http://localhost:9876/users/login
  27. Default Username = xplico
  28. Default Password = xplico
  29. Admin Username = admin
  30. Admin Password = xplico
  31. Tips…you will want to use the default sets above for general PCAP work and Analysis. Use the Admin account to change some variables, user accounts, and configuration settings.  Most mere mortals probably won’t need to fiddle with these at all. 
  32. Adjust Ubuntu theme/wallpaper accordingly for attitude and coolness factor as needed.  I personally kept the default “Ambiance” theme but changed the wallpaper to the included orange feather on the grey background.  Seemed to match the Xplico Web-page interface colors nicely.  If you have already resized the virtual screen size to as large as you can but still feel a bit jammed up in the Xplico web-interface, you can also adjust the zoom size in Firefox to be a bit smaller to get more on without having to fiddle with the scroll bars.

That’s pretty much it!  You’ve just built your own lab for processing PCAP files.  Sure it doesn’t have all the extra cool pen/sec/for tools and apps that DEFT LiveCD comes with, but hey! it works and you built it yourself! And with some more work, you can download additional network/security packages as needed.

If you can’t wait, download, unpack, and upload Sample captures from the Xplico Wiki site.

I’ll go into more detail on those and the wonders of Xplico PCAP session reassembly in the next post.

Please also note…if you shut down Xplico and the Ubuntu system, then before you re-launch Xplico the next time you need to run the following command in a terminal session before launching Firefox and logging into the Xplico web interface:

sudo /etc/init.d/xplico start

I suspect in the DEFT 6 LiveCD, that when you run the Xplico icon and the terminal window opens but doesn’t close out it is trying to do the following but failing for some reason.

sudo /etc/init.d/xplico start http://localhost:9876/users/login

I haven’t had time to see if a manual-launch of Xplico in the DEFT 6 Live CD will work better that way.  Xplico appears to work but fails on uploading of PCAP files in my experience.

Post Script #1 - Useful Xplico-building Resources

Before I eventually dug up blaksark’s Nsark script, I did uncover a few more installation recipes from other Xplico tinkerers.

I'm listing them below as together they provide a great overview of other installation techniques on a few other platforms.  They might be found helpful by others all assembled in one place:

  • Step by Step Xplico 0.6.1, 0.6.0, 0.5.8, 0.5.7 and 0.5.6 Installation - [Xplico Wiki]
  • xplico - [Xplico Wiki] - All kinds of official documentation!
  • Securityfu - Installing Xplico on Ubuntu 9.10 64bit style
  • Xplico : Quick Setup Debian - YauB shares some Wi-Fi tips for Xplico.
  • Xplico: An intro - SOLDIERX.COM. EverestX shares some guides on getting it going on Backtrack4 and then has a very basic overview if you can’t wait to start playing.
  • [How-To] Xplico:Network Forensic Analysis Tool - by ClsHack.
  • Compiling xplico - backtrack-linux forums - Another “all-in-one” auto-script by vvpalin for Backtrack distros.

Post Script #2 - Pre-Loaded Xplico Distros (Installable)

For whatever reason, to the best of my knowledge, the DEFT builders haven’t included an installer for the LiveCD to allow installation directly onto a local drive (real or virtual).

Only after all this exercise, and some leads in the resources mentioned above I’ve found (so far) two LiveCD distros that do include “pre-built” versions of Xplico in them, and can be fully installed in a real/virtual system.  This may be another option for folks who don’t want to cook your own version as I’ve shown earlier.

  • GnackTrack - Gnome Based Penetration Distro - This is a really cool pen/sec/for distro I’ve not seen before.  It is quite mature and very polished and includes Xplico.
  • BackTrack Linux – Penetration Testing Distribution - Probably one of the Godfathers of all pen/sec/for LiveCD distros.  Now including Xplico. Install BackTrack to Disk - BackTrack Linux.
  • Security Onion - LiveDVD - For “…installing, configuring, and testing Intrusion Detection Systems. It is based on Xubuntu 10.04 and contains Snort, Suricata, Sguil, Squert, Xplico, nmap, metasploit, Armitage, scapy, hping, netcat, tcpreplay, and many other security tools.”

If you are aware of any other LiveCD’s (with installer support) that include pre-added builds of Xplico, please drop the information in the comments and I’ll keep this post updated.

updated 03/06/2011 to include Security Onion LiveDVD suggested by Doug Berks.

Hope someone finds this useful.

Next stop…putting Xplico through the paces on PCAP processing and traffic reassembly.

Cheers!

Claus V.

Read More
Posted in boot-cd's, Firefox, forensics, networking, NFAT, security, tutorials, virtualization, Xplico | No comments

Xplico & VirtualBox Headaches - Part II

Posted on 9:35 AM by Unknown

Yes.  I know.  I really know.

I’ve promised a post on the wondermous Network Forensic Analysis Tool (NFAT) Xplico.

When it’s working, it is an outstanding tool, particularly when you have to take some of your PCAP files from the analysis bench into the boardroom and present findings in a way decision makers can relate to after an incident or network analysis review.

I started out cutting my teeth by using the 0.5.x builds directly in the DEFT Linux LiveCD builds.  Then I started playing around with the Xplico-provided VirtualBox Image builds including the new 0.6.x versions.

I was all set to start writing a post…when I was surprised at work to suddenly be getting no-boot errors on the VirtualBox vmdk drives I had some cases going on on my XP system.  Attempts to reload VirtualBox (from the 3.2.x version to the latest 4.0 versions) and/or redownload and deploy the various Xplico-provided vmdk images were unsuccessful…despite all the MD5 download hashes matching…even on different XP systems.

Fortunately, I was still going strong on my home system’s VirtualBox vmdk images for Xplico where I had some community-provided PCAP files to use for the post.

Only last weekend, when I launched them, they too experienced the same error.

image

Above: The killer-diller error.  Brand new, first-launch of Xplico’s latest VirtualBox 0.6.1 image/appliance.  Note that right after setting the system clock and activating the swap file fsck does a forced check saying the drive hasn’t been checked in over 249 days… Same thing in both VirtualBox 3.2.x builds as well as the latest 4.0.x releases; XP/Win7..doesn’t matter.

image

Above: After the original error, the damage has been done and now I get this every Xplico VirtualBox Image boot.

So now I was left with trying to use Xplico directly off the DEFT LiveCD builds.  Only the previous version of Xplico in the DEFT 5 was an older version and didn’t seem to render the images in the rebuilt web-page sessions, nor Xplico in DEFT 6 which seems to run, but for some reason all attempts to upload PCAPS failed (I think it is an apache issue as the terminal window never closes like it does on the DEFT 5 LiveCD build).

Double Bummer!  Particularly after feeling a bit better having overcome this DEFT 6 and VirtualBox: Maybe it’s just me? issue a few months ago.

Now, while I got started in the early days of LiveCD building by hand-building custom Knoppix (Damn Small Linux) boot CD’s, I’m just a few levels above “noobie” when it comes to Linux building, working, and troubleshooting.

As the images presented earlier capture, the whole issue seems to be that when I ran any of the VirtualBox vdmk images, during the boot process a diskcheck (fsck) was/is triggered due to some kind of date/clock-time stamp.  It claims I haven’t used these in over 258 days…thus triggering the fsck.  Only if I do run a manual fsck as suggested, it claims to find a bunch of stuff “bad” and “fixes” it all.  Only upon reboot the system is hosed.

I know there are ways to Skip or Bypass a Fsck but despite my best attempts, I couldn’t get grub to cooperate with me.

So now I was really frustrated.  I was/am still unable to get the (really nice when running) VirtualBox images directly from Xplico working.  And the versions in the LiveCd’s from DEFT, while nice, aren’t really a convenient environment for real and persistent NFA case work.  Based on previous work with Xplico I know that it can deliver and deliver very well…only I felt like I was running lame with any of these current solutions.

So that meant I had one last possibility (at least as far as I knew at the time)…roll my own “installed” Linux build on a fresh vmdk file in VirtualBox, and then manually install Xplico into it.

I’m cool with that, I needed a fully working Xplico build, and maybe it would be a good exercise before going into Xplico proper.  How hard could it be?

The answer?

Really, really frustrating…then stupidly simple.  Seriously simple.  Even Alvis could do it.

image

Above Image…the Xplico baby is delivered and working perfectly!

It can be done, and now I have a fully functional Xplico application running in an installed/hdd based configuration (still virtualized in a VirtualBox vmdk file) so I can save and revisit all my PCAP uploads.  Sweet Success!

So that post is coming up next…maybe even later today.  I now need to reproduce/test it on my work XP system…just to be 100% certain the process works.

In the meantime, this humble Linux padawan would deeply value any feedback from the Linux/VirtualBox Jedi Masters on why out of the blue the fsck started complaining about the time since last boot right after setting the system clock (certainly not 249 days!) on these vmdk images…and any solutions for fixing this issue. Now that I can roll my own I’m not really going back, however other users/testers might be curious and run into the same thing. 

From the Google work I was able to do, there may be an issue with the way the VirtualBox BIOS is reporting the actual time/date (or that it can’t get it from the hardware system) to pass on correctly to the virtual system.  Am I the only person running into this issue with the Xplico VirtualBox images?  Surely not as it replicated on different XP hardware systems as well as (finally) my Windows 7 system as well…and despite many installs/uninstalls/reinstalls/fresh-system installs, I have since been unable to get one running again.

I believe that by default, fsck is set to run automatically after x/days or y/boots.  However, I’m curious why that now always appears, even after a fresh reimport of either Xplico VB appliance.

Cheers!

Claus V.

Read More
Posted in boot-cd's, forensics, Linux, networking, NFAT, troubleshooting, tutorials, virtualization, Xplico | No comments

Thursday, January 27, 2011

DEFT 6 and VirtualBox: Maybe it’s just me?

Posted on 5:27 PM by Unknown

 

Just a quick-post.

Recently, the DEFT gang released DEFT Linux 6.  This is the next iteration of the DEFT LiveCD for forensics work.

(I’m continuing to make notes for my promised write-up of Xplico and was hoping to work with the latest LiveCD which includes the updated version of Xplico as well for my post, anyway…)

For some reason, when I downloaded the ISO file and attempted to boot it in the latest 4.0 version releases of VirtualBox on my Windows 7, x64 (Home Premium) system, I only got a black screen.

I checked the MD5 for the ISO and it matched perfectly.  The “burned” CD of the same ISO file would work just fine to boot a physical system…so I was at a loss as to why it wouldn’t work in VirtualBox.

I had allocated 1024MB for the virtual machine, and bumped the video RAM allocated up to 16 MB.

Nothing.

My host system is a Dell Studio 15 (1558) with 4GB RAM and an i7 processor.  Should be able to handle things.

For kicks I tried booting my DEFT 5.1 ISO in the same “ISO Loader” VirutalBox machine and had no issues.  It loaded and ran just fine.  Back to using the DEFT 6 ISO file and nothing.

After a couple of days pondering things, I decided to try disabling “VT-x/AMD-V” & “Nested Paging” under the “Acceleration” tab just for kicks n grins.

image

Guess what?

The DEFT 6 ISO now loaded and was executed just fine by VirtualBox.

image

Probably just an issue with my particular host system but just in case anyone else is scratching their head getting a non-boot of the DEFT 6 ISO in VirtualBox, it might not hurt to try.

I can enable those settings on other virtual machines in VirtualBox and don’t have any issues so maybe it’s just DEFT 6 specific…

Cheers…

Claus V.

Read More
Posted in boot-cd's, forensics, Linux, NFAT, virtualization, Xplico | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile