Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label graphics. Show all posts
Showing posts with label graphics. Show all posts

Sunday, March 17, 2013

ForSec News Linkfest

Posted on 9:26 PM by Unknown

I am super-behind on my blog posting of Forensics/Security news of note.

Here is a rapid-fire linkfest dump.

Some is old news and some is hot-off-the-press.

Cross-pollination is to be expected.

Enjoy!

Mostly “For”

  • CaseLeads: China Cyber Espionage Exposed, Account Issues with Twitter and Plenty of Great How-To's - SANS Computer Forensics and Incident Response Blog
  • Hiding Data in Hard-Drive's Service Areas (PDF Link) - Ariel Berkman - Recover Information Technologies LTD
  • Intro to Report Writing for Digital Forensics - Brad Garnett - Part I - SANS Computer Forensics and Incident Response Blog
  • Report Writing for Digital Forensics: Part II - Brad Garnett - Part I - SANS Computer Forensics and Incident Response Blog
  • HolisticInfoSec: toolsmith: Redline, APT1, and you – we’re all owned - Holistic Info blog
  • Open Source Forensics for Windows, MacOS, and Linux - LoveMyTool blog. Casey Mullis outlines a forensic tool, the Digital Forensics Framework. Available directly or pre-packaged in Debian, Backtrack, DEFT, the SANS SIFT kit, and CERT.org package repository.
  • Location Data within JPGs - Forensics from the Sausage Factory blog
  • High Watermark - The Hacker Factor Blog - I am SO digging into Dr. Neal Krawetz’s awesome blog that covers all manner of things, but primarily photo/image forensics. Jump over and prepare to get lost and overload your favorites/bookmark folder in the process!
  • (IN)SECURE Magazine - Issue 37 “Becoming a malware analyst edition” - now available for free PDF format download.
  • Clean Windows Registry of USB Drives - GetUSB.info
  • 3RPG - Rapid RegRipper Plugin Generator v0.3 - Hexacorn
  • 3RPG – 4 RegRipper Plugins in 15 minutes - Hexacorn
  • 3RPG – Rapid RegRipper Plugin Development - Hexacorn
  • BinMode: IE Index.dat - Windows Incident Response blog

Supplemented with some “Sec”

  • Another Forensics Blog: Finding and Reverse Engineering Deleted SMS Messages
  • In-Depth Look: APT Tools of the Trade - TrendLabs Security Intelligence Blog
  • The strange case of Gamarue propagation - Microsoft Malware Protection Center
  • Research & Analysis of Zero-Day & Advanced Targeted Threats:YAJ0: Yet Another Java Zero-Day - Malware Intelligence Lab from FireEye
  • UAC Impact on Malware - Journey into Incident Response blog
  • Static analysis tool for examining binaries - Help Net Security
  • Update: PDFiD Version 0.1.0 - Didier Stevens
  • Update: pdf-parser Version 0.4.1 - Didier Stevens
  • OS Image Wrangling - SpiderLabs Anterior
  • Windows 8: Tracking Opened Photos - Digital Forensics Stream blog
  • Wow6432Node: Registry Redirection - Windows Incident Response blog
  • Houston We’ve Had a Problem – Wow64 - Journey into Incident Response blog
  • Wipe the drive! Stealthy Malware Persistence Mechanism - Part 1 - SANS ISC Diary blog
  • Wipe the drive! Stealthy Malware Persistence - Part 2 - SANS ISC Diary blog

Please correct me I I am wrong but I am now seeing the terms “YAJ0” and “YAJU” pretty often in blog posts and titles.  YAJ0 seems to mean “Yet Another Java Zero-Day” and YAJU probably means “Yet Another Java Update”.  That both of these are now come in text-worthy shorthand forms is no LOL-ROLFLMAO matter.

And a final object lesson…

Be careful in your watchfulness to not overlook the obvious hiding in plain sight.

  • A Smuggling Trick - Daniel Miessler

Cheers!

Claus Valca

Read More
Posted in forensics, graphics, Link Fest, security, utilities | No comments

Sunday, October 28, 2012

For-Sec & Utility Jumble Linkfest

Posted on 6:52 PM by Unknown

Wordle_2012-10-28_10-49-54

The short weekend is done. The “Sandy Watch” is on for what could be -- for our northeastern friends -- a storm event to be remembered for many years to come. So comes a pile of security/forensic and utility-minded links spill out below for the curious and information hungry.

Forensics and Security

Girl, Unallocated: Be Very Quiet... I'm Tracking Emails Through Headers - Girl, Unallocated Blog. The Girl has a great post looking at email headers and their bits and perils. One gem is a report (PDF) from Stroz Friedberg and a particular focus on email headers. The report as a whole is a great read and again provides a lesson in technical report writing and presentation as well as some forensics pushback on anti-forensics techniques. At 102 pages, it isn’t a brief, but well worth the time to download and study.

The Girl’s post reminded me of another great publicly-available report that addressed emails in a forensic investigation.  In my GSD post Interesting Malware in Email Attempt - URL Scanner Links, I wrote the following bits at the end:

A recent Digital Forensics Case Leads post has mention of a super-fantastic investigation/forensic report involving anonymous emails. This is must-read material, not just in terms of the investigative methodology but also the way the report was composed and presented. Very clearly done!  I’m keeping a saved copy of the report for future reference; both technically and as a report template. From the post via the link above:

“University of Illinois recently released a detailed investigation report (PDF) regarding anonymous emails allegedly sent by its Chief of Staff to the University's Senates Conference. The report is an interesting read, and also serves as a potentially useful model for those looking for report samples and templates.”

How a Google Headhunter's E-Mail Unraveled a Massive Net Security Hole - Threat Level @ Wired.com.  I almost overlooked Kim Zetter’s post on how Mathematician Zach Harris -- as an exercise -- discovered a flaw in some providers user of a weak DKIM key to sign emails originating from them. Fascinating and short read.

DEFT 7.2 and DEFT english manual, ready for download! DEFT Linux - Computer Forensics live cd . New DEFT version out. Last one in x32 bits. Future versions will be strictly x64 flavored.

Xplico – Xplico 1.0.1 - Xplico new version release just dropped. From the brief post:

ChangeLog:

  • nDPI integration
  • performace improved
  • FTP dissector improved
  • Added the prism dissector
  • CLI execution bug fixed
  • PCAP-over-IP SSL encryption
  • IRC dissector improved
  • File reconstruction from Fragmented Payloads improved
  • FaceBook Chat updated
  • FaceBook Message (partial)
  • HTTP without initial packets (packets lost)
  • RTP dissector improved
  • PCAP2WAV, RTP2WAV interface added

And don’t forget! Now you can update/get via apt-get! for Ubuntu 11.04 and higher.  Sweet!

sudo bash -c 'echo "deb http://repo.xplico.org/ $(lsb_release -s -c) main" >> /etc/apt/sources.list'
sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 791C25CE
sudo apt-get update
sudo apt-get install xplico

LastActivityView - Nirsoft brand new utility! - Use this new tool to view the latest computer activity in Windows operating system. Nir Softer has some more details on his NirBlog: New utility that shows general computer activity. Could be useful for incident response and analysis and other “quick peeks” for key system activity indicators to narrow down the search.

FileAlyzer Portable 2.0.5.57 (detailed file analyzer) Released -PortableApps.com

Hacking KeyLoggers - Open Security Research has a great post that not only identified a USB keylogging device, but takes it to the next level in hacking it to determine the impact of the device and when it might have been dropped. Clever stuff.

Attacking TrueCrypt - The H Security: News and Features. Another interesting post that almost slipped by me. Interesting by itself but also shows the benefit of using “cascaded algorithms” in TrueCrypt to thwart current attacks…for now.

Restoration of defocused and blurred images - Yuzhikov.com. This is super cool.  Vladimir Yuzhikov hasn’t just done a proof of concept for de-fuzzing blurred imaged (either out of focus or those blurred with a mathematical algorithm), no, he has actually released a free Windows app to demonstrate the possibilities. Besides images, text that is out of focus can be unblurred as well. This is very fascinating and could assist investigators facing images and other digital files with blurred faces or content. It’s not exactly easy or guaranteed to work, but it is very promising start and Vladimir notes he is continuing development and refinement. Read his work please and snag the download.

Google Drive opens backdoor to Google accounts - The H Security: News and Features . Quoting from the post, “The Windows and Mac OS X desktop clients for Google's Drive file storage and synchronisation service open a backdoor to users' Google accounts which could allow the curious to access a Drive user's email, contacts and calendar entries.”  read the post for more info. As usual it seems to be a convenience versus security trade-off again. Choose your cake wisely. I stick with using only the web interfaces and pass on the client versions of these cloud-based storages services…for now.

Virtualization

The TinyApps bloggist has been hard at work digging out great tips and techniques for importing the virtualized “Windows XP Mode” into popular virtualization software. As always, the posts are impeccable with lots of details and supporting source documentation for additional study and research.

  • Import Windows XP Mode into VMWare Player - TinyApps.org blog
  • Import Windows XP Mode into VirtualBox - TinyApps.org blog
  • Must-have tool for VirtualBox users - TinyApps.org blog.

Oracle VM VirtualBox - Version 4.2.4 just dropped…by the way. I almost missed it were it not for my RSS feed filters. See the changelog for more details.  And be sure to grab the 4.2.4 VM VirtualBox Extension Pack as well.

Miles’ posts reminded me of an earlier GSD summer post Virtual Solutions and his great post comment guiding me to getting MS’s IE VirtualPC images running in Virtual Box.

How to run Microsoft’s IE VPC images in VirtualBox
http://tumblr.jonthornton.com/post/11405634980/how-to-run-microsofts-ie-vpc-images-in-virtualbox

ievms - Automated installation of the Microsoft IE App Compat virtual machines
https://github.com/xdissent/ievms

Browser Plugin Update Time…Again.

Yes dear readers, it is “Jack and Jill” time again. Bother.

Adobe Shockwave got updated, as of this post, the newest (Windows) version of Adobe Shockwave is currently 11.6.8.638.

  • Adobe - Adobe Shockwave Player - direct download
  • Adobe - Security Bulletin: APSB12-23 - Security updates available for Adobe Shockwave Player - Adobe
  • Adobe patches 6 critical security flaws in Shockwave - ZDNet
  • Adobe fixes critical Shockwave vulnerabilities - The H Security: News and Features

Adobe Flash was updated as well. Newest (Windows) version is currently 11.4.402.287.

  • Adobe - Flash Player - version information
  • Adobe releases 25 critical Flash patches - The H Security: News and Features
  • Adobe - Security Bulletins: APSB12-22 - Security updates available for Adobe Flash Player - Adobe

Java also got a quick update to both build versions. Windows Java updates are available in 1.6.0_36 and 1.7.0_09.

  • Java SE 6 Update Release Notes - Oracle
  • Java SE 7 Update Release Notes - Oracle
  • Java SE Downloads - Direct download

Trying to figure out if all your browser plug-ins are current can be a super-pain for the inexperienced and geekless.

My go-to recommendation remains to pop over to Qualys BrowserCheck in each of your installed web-browsers, be it Chrome, Windows IE, or Firefox. Alas, Opera, Safari, and other browsers are not currently supported, however a check in one of the supported browsers may quite likely uncover a outdated plug in, patching it may fix the others in the process.  For a backup check, hope over next to The Secunia Online Software Inspector for a second opinion.

If you want a good all-in-one location to manually download your plugs, check out Browsers and Plugins Downloads over at FileHippo.com.

Utility and SysAdmin Finds of the Week

Defrag Tools: #13 - WinDbg - Defrag Tools @ Channel 9. New video on Sysinternals tool usage; specifically integrating Debugging Tools for Windows.

Case of the CertUtil Import Refusing The Correct Password - chentiangemalc. Great practicum post on troubleshooting a strange password error where the password was correct but not being taken.

SpeedyFox - Boost Firefox,Skype,Chrome,Thunderbird in a Single Click! - CRYSTALIDEA Software . It has been forever…like dinosaurs roaming the earth eras ago…since I last saw any post anywhere on speeding up a pokey Firefox browser by “optimizing” the JSON databases. This is a dead-simple process to improve launch-time for a well-used Firefox browser. It’s been months since I last optimized mine. When I went to run SpeedyFox, my favorite tool to do so, I wondered if there had been an updated release. My version was at least a year old.  Happily I found there was a newer version, and that it now supports optimizing Chrome-based browsers as well. It remains available as a free edition. Current version is 2.0.3 but while I was sleeping, the developers have been adding support for Skype, Chrome (including SRWare Iron and Pale Moon), Mozilla Thunderbird, and Firefox (including Epic Browser). There is a Mac version (Firefox only) also.

If you use Firefox/Chrome/Thunderbird, stop, drop and run right now!  Did I mention it supports custom paths to your browser profiles so you can optimize portable versions on your drive/disks? Sweet baby Jebus!

CR2 Converter - I shot a lot of photos for Lavie and her family last weekend with the Canon 5D Mark II.  Pops asked for copies and when I was getting ready to pass them off, I realized I had not changed the setting from “RAW” only to RAW+JPEG. So I had over 300 digital images in RAW .cr2 format that his computer cannot read and that are not really a practical format for him anyway to use. Sure, I could batch-convert them in Lightroom/Photoshop, but I really just needed to get them quickly on a CD for him.  I have more than a few RAW freeware tools for tweaking individual RAW file images but that was too time-consuming to use. Luckily, with just a bit of Google diving, I found the freeware Canon RAW Image Converter “CR2 Converter”.   It supports batch-conversion and did an acceptable job for this task. My i7 x64 8 GB RAM system chewed through converting the files in no-time.  To my eyes the resulting images were a bit lightly purple-tinted…not bad or unpleasant but definitely noticeable when compared to the RAW file. Nothing that some simple color correction can’t fix if really important. For Pops it wasn’t but YMMV.  I wouldn’t use it everyday for batch processing but for quick-n-dirty RAW .cr2 to JPEG/JPG/GIF/BMP/PNG/TIFF conversions it is a super time-saver. Tuck it away for when needed in a pinch.

Cheers and hopes and prayers for the very best across the north-east seaboard as Sandy rolls in.

--Claus V.

Read More
Posted in browsers, Firefox, forensics, Google, graphics, hurricanes, Internet Explorer, Link Fest, Microsoft, networking, NFAT, security, troubleshooting, utilities, video, Virtual PC, virtualization, Windows 7, XP, Xplico | No comments

Friday, October 19, 2012

Pile ‘o Linkage

Posted on 1:53 PM by Unknown

Chain links _ Flickr - Photo Sharing!_2012-08-25_17-32-04CC attribution: "Chain links" by HowardLake on flickr.

Time to unload them…

Forensics

  • Windows 8 Forensics - A First Look - YouTube video from ForensicFocus presented by Josh Brunty. appx 40 min.
  • Digital Forensics Stream: VSC Toolset - GUI tool for executing batch files against a volume shadow copy. More details on the latest version in this VSC Toolset Update: File Recovery blog post.
  • Windows Incident Response: Forensic Scanner - Windows Incident Response blog - Harlan has recently released a super assessment tool to get a fast big-picture view report of a system being examined. It is very simple to use and provides great data for figuring out if there are any important indicators to spend more time in a closer examination of the system. Download available at forensicscanner - ASI Forensic Scanner via Google Project Hosting
  • Network Artifacts found in the Registry - Windows Incident Response blog - This is a RegRipper focused post but the previously mentioned Forensic Scanner also provides some network information; the WiFi info is quite useful on laptops to see where they have been traveling and connecting to.
  • From Malware Analysis to Portable Clam AV - Journey Into Incident Response - Corey Harrell has a fun post read on identifying a malware binary and then creating a custom AV signature in ClamAV.
  • New Archive of RegRipper Plugins - RegRipper has a new collection of current/updated plugins available if you haven’t snagged them recently.
  • Live forensics: prefetch and powershell - 8 bits blog - using PowerShell in incident response.
  • CAINE Live CD - computer forensics digital forensics - Release version 3.0 “QUASAR” is out with some updates and application additions.

Adobe Reader XI (11)

  • Announcing Adobe Reader XI - New version of Adobe Reader is out…just when you were probably getting your apps finally coded to interact with Adobe X (10).
  • Adobe Reader XI Deployment - Stealthpuppy’s Aaron Parker has some excellent as always tips on deploying it; including some customizations.
  • How to configure Group Policy for Adobe Reader XI - Group Policy Central - Not to be outdone by Aaron, Alan Burchill also has some tips for using it with GP.

Network Bits

  • Meet the successor to Microsoft Network Monitor! - MessageAnalyzer - TechNet Blogs. The successor to Microsoft’s NetMon packet trace tool is out in beta. I believe it is only supported on Win7/8. I’ve played with it a bit and NetMon users should quickly feed comfortable in it, although the GUI is significantly different in many ways. Testing captures on a Win8 RC virtual machine have gone pretty well. I’ve had a few crashes so more work does need to be done before final release in mid-2013. Definitely worth checking out though not likely to replace Wireshark or your other favorite network packet capture tools quite yet.
  • New Release: Cisco Discovery for Windows v1.3 -What the.....? blog. - I’ve posted before of various ways you can trace down what switch port is connected to, all usually multi-stepped. If you have a Cisco based switched network, this new-to-me tool in a single executable might save a whole lot of frustration if kept handy on a USB stick.  Run it, pick your interface, get your CDP data…switch/port will be magically revealed. Sweet! Get the WinCDP tool here.
  • WinsockServicesView - NirSoft - is a New utility to view, disable, and enable the installed Winsock service providers. Nir does it again with a super easy-to-use and helpful tool to catalog Winsock service providers on a system.
  • Install NetworkMiner with apt-get - NETRESEC Blog. Yeah. It’s now that easy. Not like before in a previous GSD post: Network Miner Updating on Ubuntu 12.04
  • Wireshark Tutorial Series. Tips and tricks used by insiders and veterans - Sniff free or die blog details a new Hands on with Wireshark YouTube video (11 min) by RiverbedTechnology that covers some basic usage tips.

For the SysAdmins

  • How to find latest Microsoft Knowledge Base articles for Windows 8 and Server 2012 - Anything about IT
  • FREE: Group Policy Search – Find Group Policy settings - 4sysops - Via this MSDN site: Group Policy Search
  • DOWNLOAD: Group Policy Settings Reference for Windows (8) and Windows Server (2012) - Kurt Shintaku's Blog - See also: Group Policy Settings Reference Spreadsheet - Group Policy Team Blog
  • Crash Course in Active Directory Organizational Unit Design - Windows Networking site.
  • Case of the Domain Join Failure followed by Case of the Domain Join Failure II–Object Already Exists - chentiangemalc
  • Enterprise Wireless Security – An overview - 4sysops
  • Get Files Out of a Running Virtual Machine - Ben Armstrong Virtual PC Guy Blog
  • How to diagnose Windows sleep problems - Tenniswood Blog
  • 7 Cool Useful Command Prompt Tips You May Not Know - Windows7hacker
  • Beyond good ol’ Run key, Part 2 - Hexacorn blog
  • Windows PowerShell 3.0 download - Bink.nu summary of the new features in PS 3.0
  • Download: WMF 3.0 - Microsoft Download Center
  • PowerShell 3.0 - 4sysops - Krishna Kumar offers a overview of some of those newest features.
  • PowerShell 3.0 overview – Part 2 - 4sysops - the review continues….

Utilities

  • Updates: Autoruns v11.34, ProcDump v5.0, Sigcheck v1.8, VMMap v3.11 - Sysinternals Site blog
  • Process Explorer v15.23 - Sysinternals
  • PsPing - Sysinternals new CLI tool to measure network performance including bandwidth available between systems. Also can generate histograms of results.
  • Rapid Environment Editor - Most folks won’t have any need to ever edit their Windows environment variables. But if you are a tweaker or geek or sysadmin, you might need to. This looks to be the tool for you! in addition it provides Error checking to highlight any problems with the entries. I had two “abandoned” items in my system I cleaned up with it. Really a nice portable tool to keep handy.
  • MetroTextual 1.1 - SingularLabs - Minor update to a Win8’ish style notepad tool. I posted quite a bit about it earlier MetroTextual - Spirit of the notepad known as Bend...  This new version has some fixes and feature enhancements. However I noticed on my Win7 x64 system that while v1.0 seemed OK, version 1.1 garbles selected text. I like the newest feature adds but it remains a work in progress…which raises the same question Scott Hanselman of ComputerZen pondered: A Bug Report is a Gift.  What is the best way to report it to the developers…from within the app?

    before text selection…
    z2q0i14a.klx

    after text selection…
    ajp20ovk.jktCurious…
  • HexDive 0.5 – Adding a bit of a context… & HexDive 0.6 – new strings and more -Context… - Hexacorn continues to make great leaps of improvement in the free and super-useful HexDive tool to look for interesting string patterns in files. Check it out!
  • PeStudio 4.10 - Winitor - Speaking of binary analysis, PeStudio is a new-to-me tool to aid in application binary analysis. Cool!

New “Defrag” Tools Videos (and others also)

Microsoft/Sysinternals and their Channel9 team have really scored a home-run with their “Defrag Tools” video series. Each week (or sooner) a new quality video comes out..with clear file download links/formats…that reviews or expands an in-depth review of Sysinternals tools and usage.  I’ve already posted links for Episodes 1-6 and now we have 7-12 out.  I download these at home and tuck them away for replay on rainy days or presidential debates. Even when I consider myself very comfortable using a particular Sysinternals utility, walkthroughs such as these always leave me with a new tip/trick/configuration tweak that I didn’t have before.

  • Defrag Tools: #7 - VMMap
  • Defrag Tools: #8 - Mark Russinovich
  • Defrag Tools: #9 - ProcDump
  • Defrag Tools: #10 - ProcDump - Triggers
  • Defrag Tools: #11 - ProcDump - Windows 8 & Process Monitor
  • Defrag Tools: #12 - TaskMgr and ResMon

A great supplemental Channel 9 is The Defrag Show

See also this WEBCAST: Maximizing Windows 7 Performance: Troubleshooting Tips (1hr 1min) as found by Kurt Shintaku and add it to your video bag as well.

Google Fonts

Font geek? Me too!

I frequently hit the following sites looking for new and impactful free-use fonts for maximum impact on presentations and documents where having just the right font can add a punch of enhancement.

  • 1001 Free Fonts
  • Font Squirrel
  • dafont.com
  • Font Freak

So I got really excited when I found that Google has a web font collection (500+) under the Open Font License.

  • Google Web Fonts - Google
  • Google Fonts directory - Google
  • Download and Install Google Fonts on your Computer - Digital Inspiration
  • Download Reference Posters for Google Web Fonts- Digital Inspiration

Now this is really cool!.

Cheers!

--Claus V.

Read More
Posted in Active Directory, boot-cd's, cheat sheets, forensics, Google, graphics, Link Fest, malware tools, Microsoft, networking, NFAT, utilities, video, Windows 7, Windows 8 | No comments

Friday, September 7, 2012

A Little Bit All Over the Place

Posted on 8:17 PM by Unknown

I’ve run into a few IT-related challenges over the past two weeks.

Fortunately, I’ve not only been able to overcome them, but walked away with a number of amazing software finds in the process.

Those posts are currently pending due to the awesomeness (to me) of getting things organized for public consumption as my mental and lab process notes leave much to be desired.

So since my brain is mush right now here are some appetizers to hold you over.

Last month, Microsoft released a number of updates to their Windows Essentials bundle. The public focus were a host of changes touted in the Photo Gallery and Movie Maker components.  However, they were sneaky and made an update to the Live Writer application.  What updates? Your guess is as good as mine as asking for provision of a “change log” is likely to bring a beating.

  • Windows Live Writer 2012 Released – Nothing is new or fixed. - LEHSYS
  • Windows Live Writer 2012: Anyone happen to notice this? - LEHSYS Side Notes

LEHSYS’s Larry Henry seems to like WLW and be just as frustrated as me lately.

One thing I have noticed with this new release is that I can make it “fake-crash” very easily while composing.

Untitled - Windows Live Writer_2012-09-07_18-13-21

What do I do?  Simply make the mistake of hitting the delete key too many times and sucking an existing  hyperlink into the delete vortex. Bam! Crash window.

Only it’s a fake-crash. The first time I encountered it I freaked as I had composed a long post and was in fear of loosing my material--well up the the last save point. However I soon learned that it didn’t matter if I clicked the red “X” or “Close program” button, WLW would keep on trucking. No loss occurred and despite the warning, Windows did not attempt to close Windows Live Writer.

I didn’t have this issue before the “upgrade”.  I wish I could somehow roll back to the previous version. Anyone figure out how to “off-line install” older versions of Windows Essentials/Windows Live Writer?

GSD Sidebar:

I did finally find links to the full “off-line” installer for the Windows Essential packages!

  • How do I install Windows Essentials while offline? - Install offline - Microsoft Essentials
  • Windows Live Essentials 2011 deployment options using offline installer - TechNet - Has lots of command-line arguments for installation help!
  • Offline installer for Windows Live Essentials - WLSetup-All.exe - Scott Hanselman
  • Deploying Windows Live Essentials 2011 - The Angry Technician
  • Install Windows Live Essentials 2012 offline - morganjayp

What I find interesting is that the “wlsetup-all.exe” from the MS site is 131 MB in size and is served from http://g.live.com/1rewlive5-all/en/wlsetup-all.exe but the one linked in Scott’s original post near the bottom is 134 MB and served from http://g.live.com/1rewlive3/en/wlsetup-all.exe.

So these are different “off-line” WL setup binaries.  In fact, if you look at the path, you can see a “pattern”. On a whim I tried http://g.live.com/1rewlive4-all/en/wlsetup-all.exe and got a good download as well.

Googling that URL template, I found this very helpful post Windows Live Downloads « The Field Guide which details these indicate which “wave” release it was.

  • Wave5 = Microsoft Essentials 2012
  • Wave4 = Windows Live Essentials 2011
  • Wave3 = Windows Live Essentials 2009

I’ll play with these and likely roll-back to the Wave4 WLW version to see how things go.

(The text in the fake blog post above came from the awesome Samuel L Ipsum site. It is one of a number of fantastic alternative Lorem Ipsum generators listed in this post: 30 Alternatives to Lorem Ipsum found by Splashnology. Zombie Ipsum has to be a close second.)

I’ve been taking a lot more digital photos lately since getting a Canon S95. This has led to a new issue which is managing my growing photo library. It is a super joy to shoot with and handles low-light/no-flash captures wonderfully. I haven’t scratched the surface of it’s capabilities but the small format really lends itself to being kept on my person for random shots (examples of photos I took with the S95 around town below no post-process done).

IMG_0505IMG_0739

IMG_0735IMG_0287

This will probably multiply now that my dear brother has lent me use of his “old” EOS 5D and a super cool set of lenses and Speedlight. I’m a bit overwhelmed with it all. We are planning some nature stalking as we have found we feed off each other when photo-walking together.

He uses Adobe Photoshop Lightroom 4 which is very high end. Then again he does some amazing photography work and has amassed a tremendous digital library over the years. He is also a Photoshop wiz so it works for him quite well. Dad is making the transition from a old-school 35-mm SLR format guy to the new DSLR world. As such, he is focusing on the transition and uses ACDsee.

I’ve got a pretty large collection of photo editing and management apps I have been using for some time (that’s another post to list them all!). Primarily I use FastStone Image Viewer which has borne the brunt of my digital image management and basic manipulation work. It’s great but I think I need something a bit more beefy.

I do have Adobe Bridge, although it is a CS4 version. I may just need to learn it. Got a few books on it already in my home library. It is really fast on my system and fairly intuitive. XnView works well and I am learning it also. Of course, I do have Microsoft Essentials Photo Gallery. It is a fairly nice interface and has some nice features, but it doesn’t seem as “serious” as Adobe Bridge or other tools for some reason to me.

Before FastStone’s tool, I had used ImageWalker which was cool as it contained a amazing collection of photo-effects to apply. I eventually turned to PhotoFiltre for that task.

So it was with excitement I stumbled on the updated ImageWalker replacement Diffractor. It is super slick and has just enough editing tools to be handy to use.  I love the interface and while the menu/navigation system takes a while to get used to, once learned it is really fun to use. It even includes a timeline generator view! Definitely recommended for use!

Picasa from Google is pretty neat. It is very fast and operates smoothly. I didn’t feel like installing it (yet) and found (like many Google products) the installation exe could be extracted with 7-Zip. I’m going to spend some time with this application as well.

I quickly found a super-neat photo workflow application called darktable. The problem was that while I could install it pretty easily into my Ubuntu 12.04 build, all my photos were in my Windows OS and while I use Ubuntu and can work in it comfortably, this wasn’t quite how I wanted to do things smoothly. Alas, there is no Windows build (yet?). See this Noupe post Darktable: The free Alternative to Photoshop Lightroom goes Mac OS X for more info.

I found the Open Source photo management application digiKam. Supported platforms include Linux, FreeBSD, Mac OSX and Windows. The screenshots and features look very promising. It does seen to be a bit “crash-y” on my Win7 x64 system…so the search goes on.

Other Canon stuff I probably shouldn’t mess with just yet but am tempted to:

  • MagicLantern.fm - Home - software to modify the camera controls and features for Canon EOS cameras
  • CHDK - Canon Hack Development Kit to add additional controls and features to select PowerShot cameras

Moving on to another topic, I had recently was banging my fist on a USB flash drive that was presenting some issues. In the process of troubleshooting, I found a few of my favorite USB tools had been updated fairly recently.

  • Dev Eject - v. 1.0.24 - lists removable media, allows ejection of devices, and shows files that are open and preventing ejection.
  • HotSwap! - v. 6.1.0.0 - Helps with USB device removal..and a whole lot more!
  • USB Disk Ejector - v. 1.3.0.3 - Helps with USB device removal in a pleasant GUI/system tray.

Some cool Windows Tweaking utilities I found this past week are:

  • Librarian - a powerful libraries manager for Windows 7 and Windows 8.
  • Taskbar Pinner - a universal pinner software for your taskbar. Pin a file, a folder, a shell object, or a library to your Windows task bar.

There are a whole lot more tweaking tools for Win7/Win8 over at WinAero. Check out their downloads/software page for more.

I still use Jumplist-Launcher over at Hedgehog's Blog as well. It hasn’t been updated for a long time but still does a great job. Between the jumplist I made with this tool and Winstep Nexus Dock everything I need is pretty much in quick access reach on my Win 7 systems.

Finally, I’m playing with Baralga to get use to trying to better document and track the time I spend working on various projects. It’s a Java-based app so it is quite portable and flexible. I checked out a long list of time-tracking apps and this seemed to fit my needs the closest.

Cheers

Claus V.

Read More
Posted in graphics, Microsoft, photography, software, troubleshooting, utilities, Windows Live Writer | No comments

Sunday, May 20, 2012

So Many Links…So Little Time!

Posted on 3:04 PM by Unknown

Busy day today. Chores to do inside the house and out. And links galore spilling out of my Firefox sidebar, ripe for posting.

Critical Updates

  • Adobe: Critical security holes in Shockwave, Photoshop, Illustrator - ZDNet ZeroDay blog
  • Adobe - Security Bulletins: APSB12-13 -Security update available for Adobe Shockwave Player.
  • Adobe - Web Players - Links to download Adobe Flash Player and Adobe Shockwave.
  • QuickTime for Windows update plugs security holes - The H Security: News and Features - And then when you are done with Adobe, go grab the latest QuickTime player update.

New Place to Report Fake Tech Support Scam Calls

As if the usual bane of telemarketers isn’t enough to wade through almost every day and night, now we are seeing a renewed push of the fake-tech-support calls. Enterprise IT shops are even having to now send notices across their employee-base to remind them that they haven’t been outsourced to these callers and that employees should always make sure they are talking to the right IT guys and gals. Some places are event starting to black-list some of these third-party remote control sites to clamp-down the borders against these calls.

Troy Hunt has a series of great posts that tell you just about everything you need to know about these scams. I’ve posted them before but Troy’s writings are so good, they need another mention.

  • Anatomy of a virus call centre scam - Troy Hunt’s blog
  • Scamming the scammers – catching the virus call centre scammers red-handed - Troy Hunt’s blog
  • “Type www.” – “Ok, w-w-w-d-o-t”; antagonising call centre scammers - Troy Hunt’s blog

The guys and gals over at SANS have gotten into the game as well.

  • Who's tracking phone calls that target your computer? Stay Tuned to the ISC - ISC Diary

They have opened up two (same) locations for you to report any fake-tech-support calls you may get for intel-gathering purposes. Knowledge is power!

  • (Red Theme) - Report Fake Tech Support Calls - SANS Internet Storm Center; Cooperative Network Security Community
  • (Green Theme) - Report Fake Tech Support Calls - DShield; Cooperative Network Security Community

For the SysAdmins in the Audience

Kyle Beckman has written an outstanding series of posts at 4Sysops blog on folder redirection in Windows. Definitely worth taking some notes from.

  • Folder Redirection – Part 1: Introduction - 4sysops
  • Folder Redirection – Part 2: Setting up your file server - 4sysops
  • Folder Redirection – Part 3: Explanation of folder permissions - 4sysops
  • Folder Redirection – Part 4: Group Policy configuration - 4sysops
  • Folder Redirection – Part 5: Best practices - 4sysops

In other news…

FREE: Veeam ONE Free Edition – Real-time Hyper-V and VMware monitoring - 4sysops

"Could not reconnect all network drives" - TinyApps.Org. Great tip and trick for delaying (slightly) the mapping of network drives until the network is fully available after login.

Windows Error Lookup Tool Portable 3.0.4 (get details on Windows error codes) Released - PortableApps.com

Batch-Convert XLSX To XLS Without MS Excel Or An Online Converter - New tool reviewed by AddictiveTips.  Get the tool here from the author.

Jarfix - free tool to fix broken “jar” file associations in Windows.  I needed this after the last Java Runtime update I applied to my system. After installation, I could no longer run the Java-based Software Protection Initiative - Encryption Wizard tool as I had before. I tried several times to update the file-associations but no dice. Then I found this tool, and once executed…problem solved!

Likewise, a few months ago I had re-installed Google Earth but for some reason, lost all indications on how to launch it…no icon on the desktop. None in my “Start” list. Nada. Uninstalled/reinstalled. Still the launcher icon was no-where to be found.  Finally found this link: Google Earth icon has disappeared from my PC : Fix my problem - Google Earth Help  Downloaded the Google Earth Icon Restorer and ran it. Again, problem solved!

Mirekusoft Install Monitor -freeware Installation management software. (Note site down at time of posting) - I have a number of system change monitor/detectors I rely on to monitor how and where a software install impacts a system. Each one takes slightly different approaches. So I read with interest about this new installation monitor/logger. It runs as a service so it catches all installations and documents where in the file-system and registry the bits go. Drawbacks? Maybe a bit unstable and if a program was already installed prior to installing this tool, it doesn’t well-catch the updated installation bits. All that said, it might be worth looking into…particularly in a lab/test-bench setting where you need to document where install bits go before deploying them.  See this CSArchive.Net Mirekusoft Install Monitor post for some screenshots while the main site is down. Alternative programs to consider: Total Uninstaller by martau.com (free-trial/$) or Revo Uninstaller Freeware.

Leelu Soft: Watch 4 Folder 2.3 and Track Folder Changes are two other utilities you may want to check out.

I’m not sure why I’m on this theme this week, but the freeware app GeekUninstaller came to my attention this week also. Free and available in both installable and portable versions, helps remove installed applications.  For a few more details and screen-caps, see this AddictiveTIps post: Geek Uninstaller Lets You Completely Wipe Off Any Application From PC

VMware Workstation Player 4.0.3 released / Workstation 8.0.3 - Born and Windows IT Blog - My own recent experience using VMWare Player 4.0.3 for a Win 8 CP run was outstanding. Definitely worth getting these updated bits. VMware Player 4.0

Group Policy Central - new blog to me about Group Policy topics, including some Win 8 items and findings. Doesn’t appear to be updated quite as frequently as I would like, but since it is new, I’ll probably find more than enough material here to keep me busy until the next post comes out.

Network Nuggets of Gold!

NetBScanner - New tool from NirSoft - NetBIOS scanner. Provide a IP range and get IP addresses, WS Names, Workgroup membership as well as MAC address. Super nice GUI. Add this right now to your network toolbox!  Reminds me of the CLI tools (work good for me) NBTScan and the similarly named nbtscan. More info on NetBScanner at this AddictiveTips review. 

wpic v1.0.0 - woanware - A “simple console web page capture tool based on Chromium project that captures an entire web-page. Reminded me of IECapt which is an IE based web-page capture tool that I use daily for some data archiving.

NETRESEC CapLoader - Not free - interesting tool to process large network PCAP files and filter flows of interest. See this CapLoader Demo - YouTube for more info.

Curiously, there was this related post The Adventures of Packet Tracy, PI over at wirewatcher blog on parsing down large PCAP sets for URLs of interest.

HolisticInfoSec: toolsmith: Buster Sandbox Anayzer - Detailed information and walkthrough regarding a new release of Buster Sandbox Analyzer back in April.

In a GSD post On the Hunt… I detailed a quite involved process in hunting down/validating network connections and mapping them to specific switch ports. Over at LoveMyTool blog, Tony Fortunato posted a short video on how to find out which switch port the client is connected to. Pretty standard stuff.  However, I’m always putting a sharp eye on these just in case I find a new or better technique. And I did! For whatever reason (Cisco IOS updates?) we’ve seriously lost our ability to search for MAC addresses in the Cisco Network Assistant product. We are not alone as others are encountering issues as well. Anyway, we have some workarounds in the GUI but they are a bit time intensive looking through many, many switch port connections.  So like Tony, I find it (generally) faster to just telnet to each switch, run a “show mac address-table” and list the MAC/Port associations and look for the target MAC. On 48-port switches, that is a lot of searching. Tony’s video taught me the following trick; “show mac address-table |include <mac address>”  Including the pipe-include lets me pop just the single MAC I want. Sweet!

More here: Cisco IOS "include" filter.  And for the full list of powerful Cisco CLI options, check out this Cisco IOS Terminal Services Configuration Guide, Release 12.2 - Regular Expressions  [Cisco IOS Software Releases 12.2 Mainline] at Cisco Systems . Note your Cisco IOS version may render some of these commands a bit different, if supported at all. You probably also want to tuck away this Regular Expressions (PDF) for reference as well.

Finally, over at Anything About IT blog, Alex Verboon posted this Script for finding Executables that are command-line programs via a free utility IsCommandLineApp by Helge Klein. Might be useful in incident-response.

For the ForSec crewmates

In my recent Forensically Sound: Quick Post #3 I posted a number of links touching on early forensic surveys of Windows 8 “release” builds. I warned that none of these observations are 100% guaranteed to be present and accounted for in the final baked version, but they are good starting points. Troy Larson wisely commented on that post “Regarding Windows 8 forensics: I would be careful of relying too much on the public preview versions for detailed forensic analysis. Offsets and formats can still change.” Noted! So with Troy’s perspective firmly fixed in mind, here are a few more links touching on early (very early) Win 8 forensic notes and observations.

  • Windows 8 Forensics Part 3 -Post by Ethan Fleisher on file history saving.
  • Digital Forensics Stream: Windows 8 TypedURLsTime by Jason Hale at the Digital Forensics Stream blog
  • Random Thoughts of Forensics: Windows 8 - Refresh Excerpt - Random Thoughts of Forensics - Kenneth Johnson touches on “Windows 8 Refresh points” impact as well as “System Recovery”

Portable Agents to QuickScans: Tips on Using the Latest Version of Redline - Mandiant M-unition blog

SANS DFIR Wall Poster Preview - SANS

File Formats ZOO - Hexacorn blog - file sector header information for common file formats.

File Formats ZOO – Installers - Hexacorn blog - likewise for software installer files.

The Curious Case of the Forensic Artifact - Hexacorn blog - in which the process of solving a curiosity is illuminated.

RegRipper: Update, Road Map, How not to get p0wned by RR v2.5, and Approximating Program Execution via VSC Analysis with RegRipper - Windows Incident Response blog -- my o my how RegRipper has grown!

More About Volume Shadow Copies - Journey Into Incident Response:  Corey Harrell dishes more on VSCs.

Related…VSC Toolset Update: Browsing Shadow Copies - Digital Forensics Stream post by Jason Hale with interesting comment thread follow up.

TypedURLs (Part 1) and TypedURLs (Part 2) - Crucial Security Forensics Blog posts by Paul Nichols.

Addressing Malware Issues from an Operational Perspective - Crucial Security Forensics Blog post by Michael Robinson. Great quick read on malware in the organization and changes that may be needed in operations.

Resurrecting “Dead” Images for Live Analysis - Crucial Security Forensics Blog post by Mark A. Wade.

Old Servers never die – unfortunately - Forensics from the sausage factory. Great “how-to” tips and results on imaging a server/system over the network, when you must…

Digital Forensics with Open Source Tools (Amazon link) - New book by Cory Altheide, Harlan Carvey. It’s a book after my own heart! Open Source/freeware (closed-source) tools for for/secs.

Windows Live Messenger – MessengerCache folder  Forensics from the sausage factory. This post was very interesting as it took a fresh look at what may be a commonly used application on some Windows systems.

“You Can’t See Me”…(my bad…I guess you can…)

A recent round of migrating users into a new AD domain (and some folder rcopy/redirection work on the side) has left a few users with missing data post-migration. I have tons and tons of tools to recover deleted data from a drive. The sysadmin I was working with reached for a new one to me in our troubleshooting work together, FreeUndelete over at OfficeRecovery.com. Did the job nicely and the customer had their files restored in no time. I offered my own recommendations in thank-you. In doing so I spotted that Kickass Undelete recently got bumped up to 1.3 beta version. Others I like include Recuva. I also learned (via this AddictiveTips blog post) about Orion File Recover Software Free. I also saw this review at AddictiveTips blog for Wise Data Recovery freeware software. For even more tools, check out this GSD post File Recovery Extravaganza.

PhotoGrok / Java

PhotoGrok: EXIF-Based Image & File Viewer With Metadata Filters - AddictiveTips blog. I have more than enough EXIF-data/File-Viewer apps than I really need, but I’m a sucker for a new utility so I went ahead and downloaded the PhotoGrok tool and was quite pleased with the effort. It’s a nice tool. However, when I went to try to uninstall it, it wasn’t listed in my Add/Remove program (errr, make that Programs and Features) list. Nor could I find a link to an uninstaller in my program file list.

Checking the desktop shortcut target location led me to

“C:\Windows\SysWOW64\javaws.exe -localfile -J-Djnlp.application.href=http://www.haplessgenius.com/photogrok/launch.jnlp "C:\Users\profilename\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37\3b46d1a5-79989755"”

Now how do we uninstall this?  Unfortunately, the otherwise well-written FAQ didn’t seem to spell out the method. Yikes. Time for some deeper digging.

Turns out PhotoGrok is a Java WebStart application.

To remove you can follow the principle outlined in this post: How to Clear the Java Web Start Cache as explained by a different software vendor. This post Clearing the Java WebStart Cache by NGS has some better screen-captures (although they may be outdated a bit if you have a more recent Java build on your system…it should work well enough to get you what you need to know). Still not sure? See this final set of screen-caps for a newer Java build: Java Web Start 1.6 beta2 Review courtesy of UCWare.com.

See, no need to panic! Easy-peasy if you want to strike it from your system.

Reset that Windows Password! (or crack it with a new release of Ophcrack…)

So last week--a tech was having some issues having a pushed application install on their system. Turns out their domain account didn’t have admin group membership and was causing the bomb-out. No problem, let’s just add you to the…hmm…for some reason all the admin account passwords are different from our standard and the “fail-safe” account is disabled. Oh snap. I hear the drumbeats of a system reload! Can you say “too-bad, doo-dad?”

Luckily, I had a backup plan.  Booted the system in my custom WinPE, used the embedded tools to off-line authenticate to the whole-disk encrypted system drive, then used NTPWEdit 0.3 to update the Admin password accordingly. Reboot. On the local system admin account now, added tech to the admin group. enabled the disabled account, good to go.

See also Password Renew at sala source (which I understand doesn’t play well under WinPE).

Related: DistroWatch.com: Ophcrack LiveCD updated May 15th. More news about this build here: Distribution Release: Ophcrack LiveCD 3.4.0

"This new live CD includes the latest version of ophcrack 3.4.0. It is built on Slitaz GNU/Linux 4.0, the latest version of this great live CD. Christophe Lincoln from Slitaz helped us to enhance the scripts for partitions and tables detection. A new ncurses interface is also available to help users look for tables on other drives or interact with ophcrack. Finally a live CD without tables has been released as well for users that already downloaded or bought tables. The directory containing the table files must be placed inside another directory called tables in order for ophcrack to find them automatically."

More Ophcrack release news here: news page

Now where’s my mop?

Cheers!

--Claus V.

Read More
Posted in boot-cd's, Chrome/Chromium, command-line interface, forensics, graphics, Internet Explorer, Link Fest, Linux, Microsoft, networking, NFAT, security, troubleshooting, tutorials, utilities, Windows 8 | No comments

Saturday, April 7, 2012

Tools, Tips, and Reverse-Image Searches

Posted on 4:22 PM by Unknown

Last week must have been pretty quiet as folks prepared for the Easter weekend. I didn’t collect near as much material as usual.

That’s a good thing seeing as I’m still digging out the piles of linkage I’ve been buried under.

Submitted for your edification:

NoVirusThanks - Funny name, great tools and freeware utilities for sysadmins and incident responders alike.  I have a few other "elite go-to” sources that offer a spectacular range of utilities for my prime toolsets and I’ve had to add NoVirusThanks to my list.

  • Sysinternals Utilities - Microsoft SysInternals.
  • Nirsoft - Nir Sofer’s amazing collection of freeware tools and utilities.
  • woanware - Mark Woan’s collection of forensics and network security utilities.

There are lots of other great producers of quality freeware Windows tools and utilities both for system administration, incident response, and forensics, but these sites seem to pack the best of them into a single place.

Wireshark · Wireshark 1.6.7 Released - Mostly bugfixes but check out the full 1.6.7 release notes if you care. Then go download the latest version of Wireshark in your favorite flavor.

Just when I thought I covered the series in my last post, Girl, Unallocated slips in a new installment, #2.4 with some timeline/SIFT work.

  • Case Experience #2 - IP Theft Investigation Thought Process
  • Case Experience #2.1 - More About IP Theft Thought Process
  • Case Experience #2.2 - Let the Digging Begin
  • Case Experience #2.3 - Digging Into the Registry
  • Case Experience #2.4 - Exposing Kilroy with Log2Timeline

David Kravets from Wired’s Threat Level authored the post How Forensics Claims Facebook Ownership Contract Is 'Forged' that offers some certainly interesting items out of a forensic examination. I find value in reading publically released incident response and forensic analysis reports to pick up tips as well try to understand both the good, the great and especially the less than stellar (to then be avoided) in techniques used.

New Tools, Registry Findings - Windows Incident Response blog - Harlan Carvey passes on some new tips, tools, and registry bits of his own, one of which is the super-handy RegRipper Plugins maintenance tool from the super-cool Cheeky4n6Monkey. Read both Halan’s and Cheeky’s posts to get some idea if this tool would helpful.

Get out the Vote!

The Forensic 4cast Awards hosted by Forensic 4cast is open for voting through June 17th.

Take a look at the stellar nominees for each category and pass some love and kindness in support of the hard work these oft-unrecognized forensicators do day-in and day-out. Everybody likes some props now and then and here’s a way to show your appreciation for the top-shelf work done in the forensic community. Go and Meet the 2012 Nominees then cast a vote.

The humble GSD blog treads far below these giants but it was cool to see a kind link-back over in a recent SANS Digital Forensics Case Leads blog post. That’s some mighty fine company to be sandwiched amongst. I’m encouraged that some of these posts are as helpful to others as they are rewarding for me to share. Semper paratus, my friends.

Where’s That Image?

And here is how Claus finds new tools/techniques. Scary.

I was ripping though my RSS feed pile this past week and came across this post over at Boing Boing! That piqued my interest: Moon boxes and mystery men. I’m a sucker for old black-n-white techy photos of stuff from bygone era’s. Stuff like old space program photos, crazy industrial equipment, even the ads over at Phil Are Go!

Anyway.

While the question posed by Frank Munger was interesting, I was more curious if/where the photo had previously appeared on the WWW.

So I downloaded the “original” image, popped over to Google Images, clicked on the tiny blue camera in the search bar, uploaded the image I had downloaded and…bingo got the results. Of course, looking down a bit more on the page I found that Frank Munger had since found the answer he was seeking Y-12's moon-box mystery solved, although the Boing Boing didn’t update their story. That particular itch was now considered scratched, but that did lead me to look around for more reverse-image search tools.

There may be times when you find an image on a system or drive and want some more information about it. You could do a search on the file-name but those can be renamed. While you may not be able to draw many conclusions from an image search, it might give you some additional context for understanding.

Since the last time I went blogging about reverse-image-lookup tools on the web was quite a while ago, there are some new ones worth bookmarking.

Google Images - Check out these related links for more information on how to use this Google search feature: Search by Image · Inside Google Search and Search by Image - Google Images Help.

TinEye Reverse Image Search - One of the originals and still quite good. TinEye also offers some Plugins for major web-browsers.

Bing Images - While Bing does some great image searches based on terms, it doesn’t (yet) seem to support reverse-image searching.

Anyone know of any other reverse image search sites and/or tools worth recommending?

Cheers!

--Claus V.

Read More
Posted in forensics, graphics, Link Fest, security, utilities | No comments

Saturday, March 10, 2012

Rain-Delay Linkfest

Posted on 10:14 AM by Unknown

After an exceptional season of drought here in Texas, it looks like things are starting to change. We are facing at least five days of rain; heavy downpours mixed with long periods of light grey drizzles.

Planned yard-work long since abandoned.

Perfect weather for emptying the “to-be-blogged” hopper.

System Security

Time for new Flash updates. These are for the mainstream 11.1.x line of Flash builds. If you are running the 11.2.x line of beta Flash, I figure you are keeping up with those already.

Flash vulnerability exploited to deliver malware - Help Net Security has some good details about a threat that was patched as well as how it was flagged and described by security researcher Mila Parkour. While this Adobe rushes out critical Flash update post over at Ars Technica has some more details about “…the vulnerability, discovered by Tavis Ormandy and Fermin Serna of Google's security team, affects Flash players on Windows, Mac OS X, Linux, and Solaris operating systems, as well as Google Chrome and Android.”

I use these links from File Hippo for my Flash updating needs. Whatever source you prefer to use go get’em.

  • Download Flash Player 11.1.102.63 (IE) - FileHippo.com
  • Download Flash Player 11.1.102.63 (Non-IE) - FileHippo.com

PSI 3.0 Beta Launch -Secunia is rebuilding their Personal Software Inspector tool to now not only find and notify you about missing security updates and patches needed for applications and plug-ins on your system, but also make it easier to apply those found patches and updates in-application rather than hunting them out yourself. It is still a work in progress but should provide a good tool to help in the process.

Microsoft Security Bulletin Advance Notification for March 2012 - Microsoft Security TechCenter. MS Windows updates coming soon to a system near you!

Getting Inside the evil

I’ve really been enjoying Troy Hunt’s writings, both current and browsing through the archive material. These two posts were exceptionally eye-opening. Troy does an excellent job showing the process by which these scams work. Get out the notepad.

  • Scamming the scammers – catching the virus call centre scammers red-handed - Troy Hunt
  • Anatomy of a virus call centre scam - Troy Hunt

Introducing Adobe SWF Investigator - Adobe Developer Connection. New beta tool making the rounds on various security sites. Based on the Adobe AIR platform, it will help with SWF analysis from both static and dynamic angles.

Examining VSCs with GUI Tools - Journey Into Incident Response blog. Corey Harrell does a great job in showing methods to work with Volume Shadow Copies containers.

Browser Things

Password Generation - The Chromium Projects. We’ve touched on passwords here at GSD quite recently. This new component of Chrome development is pretty interesting. Having the built-in-browser ability to quickly and easily generate complex passwords is pretty cool. I hope some form of this feature matures into the mainstream builds.

Speaking of Chrome, for the longest time I have been using a portable build of Chromium (DEV builds)coupled with an updater application from Caschys Blog. Once a week or so I hit the updater and it finds and downloads/installs the newest version available from the source repositories. Unfortunately I wasn’t paying attention to what (or what not) was actually happening. When I recently saw the latest DEV build level in a RSS feed, I finally went back and checked what my Chrome DEV build was and it was WAY behind. Seriously WAY WAY behind. Bother. So now I am using this Google Chrome Portable page and scrolling down the the portable DEV build link. Updating is just a matter of downloading the file, and pointing it to the exiting location and overwriting it. If you are porting over your profile and extensions over from a previous portable version, the location they go into turned out to be quite different from the earlier portable DEV build I had been using.

It is now located in this folder location: “ …\GoogleChromePortableDev\Data\profile\Default”

Once I had my Chrome profile ported out of the old DEV version and into the new one, the difference in the builds was significant.

Mozilla’s Collusion tells who’s tracking you - Mozilla Links. Worth a look.

2-step verification - Google Apps Help. Google has a optional 2-step verification option to enhance the security of your account login process. FYI.

Freeware of Note

usboblivion - Google Project Hosting. Anti-forensics-like tool to purge USB history of USB-connected drives from Windows registry. Question: does use of the tool leave any tracks of its own behind? Spotted via this Addictive Tips blog post: Delete Record Of Previously Connected USB Devices Using USBOblivion

Rufus - Create bootable USB drives - Really neat and slick bootable USB creator tool. More details on these reboot.pro pages: Rufus and Rufus (introduction topic).

NTFS Permissions Reporter - Cjwdev - offered in both free and $ versions. Windows already has built-in methods to look at NTFS permissions but this is a nice GUI tool that some might find more useful at providing a wider-view on the permissions. Spotted via this Addictive Tips blog post: NTFS Permissions Reporter: View Access Permissions Applied On Folders.

regshot - Via SourceForge. Another tool to do before and after registry diff’ing. More details at this CybernetNews post: Monitor Registry Changes in Windows.

File Extension Monitor - NoVirusThanks - free/portable tool that allows real-time monitoring and logging of files created in the system. Great to run during setup files or to trace droppers/activity. Spotted via this Addictive Tips blog post: Monitor File Creation Activity Across Disk Volumes With File Extension Monitor.

HijackThis was my #1 go-to malware busting tool in the very early days of my IT career. I would use it slice-n-dice auto-run entries and bring back law-and-order to a malware-hijacked system. Over the years as my knowledge and skillset grew and tools matured, I’ve come to rely much more now on the Sysinternals Utilities. A one-two punch with Autoruns and Process Explorer coupled with the all-seeing-eye of Process Monitor typically provides me the hammer needed to bust into a hijacked system. So it was with fondness that I read this HijackThis now open source post at The H Security. I really hope that this move now gives new life and capability to this classic tool.

Peeking at NAFT - Didier Stevens is going crazy teasing us with a new project; a new forensic toolkit he is developing the “Network Appliance Forensic Toolkit (NAFT)”. Ooohhh!

Ezvid - Free Movie Maker and Slideshow Creator For YouTube. Spotted via this Addictive Tips blog post: Create Image & Video Slideshows With Narration Using ezvid.

Microsoft Research Cliplets - Neat project from MS Research that takes a digital video short, and allows you to isolate just a section of the motion. When exported the result is a static image with a section of movement. It’s a cool effect.

Multi-Image Fusion - This Microsoft Research project appears to be aiming as the next generation of Microsoft Image Composite Editor, or ICE. They have a 305-image composite on the page as a teaser. I love ICE but sometimes when I have a complex series of images and try to drag/drop them into ICE, it cannot stich non-sequential images into a composite. Related: Hugin - Panorama photo stitcher

For Sysadmins

BETA: PowerShell v3 Technical Guide (CTP2) - Kurt Shintaku's Blog

Service overview and network port requirements for the Windows Server system - Microsoft Support Article ID 832017.

[Review] God's Jury: The Inquisition, IT & Privacy - ReadWriteWeb. Curt Hopkins has a book review. What is really fascinating to me is how new technology can make the evils of dark history past relevant and accessible again with the dizzying pace (again) of information aggregation. Amazon has a Kindle version that will soon be making an appearance here in the Valca home.

Network Stuff

Nmap 5.61TEST5 released with 43 new scripts,improved OS & version detection, and more available for download - ISC Diary

Wireshark and Pcap-ng - Wireshark blog - news that Wireshark 1.8.0 will have two new features: concurrent capture from multiple interfaces and packet annotation. These changes appear to rely on pcap-ng file formats. Hopefully applications that rely on the pcap format will adjust and add compatibility for the pcap-ng format but if not, be sure you save your captures in a format that can be imported (or exported into) a file format compatible with your NFA tools.

Detecting sniffers with HSD - Hexacorn blog. Free tools and techniques for detecting the presence of network sniffing activity.

Tony Fortunato over at the LoveMyTool community blog has a video showing Using Pathtest for Performance Measurement. PathTest is a free tool to test network bandwidth capacity between two endpoints using packet-flooding techniques. This is a serious tool so use carefully and during non-production hours unless you (and your customers) really, really know what you are doing and why you need to do so. Cool tool!

Cheers!

--Claus V.

Read More
Posted in anti-virus software, books, boot-cd's, browsers, Chrome/Chromium, Firefox, forensics, Gmail, Google, graphics, Link Fest, malware tools, Microsoft, networking, NFAT, security, utilities | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile