Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg
Showing posts with label networking. Show all posts
Showing posts with label networking. Show all posts

Saturday, November 2, 2013

ForSec Linkfest - 2013 DST Fallback Edition

Posted on 1:23 PM by Unknown

FYI…tomorrow morning at 2 AM here in the United States of America it will be time to “fall back” from DST. One more hour of sleep and then it’s weeks of trying to get the body’s timeclock to readjust.

So as you get ready to find all the clocks you need to manually adjust (don’t forget the vehicles!), here is some linkage to distract you from that task. Please note I’ve also sprinkled in some networking items as well to keep you on your toes!

  • Wireshark 1.10.3 and 1.8.11 Released - Wireshark website
  • Wireshark - Official site Download
  • Reviewing Wireshark's Capture Pane (by Tony Fortunato) - LoveMyTool blog
  • Using PowerShell to Automate Tracing - MessageAnalyzer blog
  • Nmap cheat sheet - HelpNet Security blog - From the notice:
    • Counter Hack founder and SANS instructor Ed Skoudis and his team created a helpful cheat sheet for Nmap, which includes notable scripts of the Nmap Scripting Engine, script categories, instructions for scan types, probing options, and more.
  • How A Wireless Issue Looks Like a Wired Issue (by Tony Fortunato) - LoveMyTool blog
  • NAFT: The Movie - Didier Stevens
  • New utility to quickly set the DNS servers of your Internet connection - QuickSetDNS utility from Nir Sofer's workbench.
  • On getting Pineappled at Web Directions South - Troy Hunt’s blog
  • Disassembling the privacy implications of LinkedIn Intro - Troy Hunt’s blog
  • Command-line Forensics of hacked PHP.net - NETRESEC Blog
  • iOS apps can be hijacked to show fraudulent content and intercept data - Ars Technica
  • Your iPhone knows where you’ve been, puts it on a map - Chron.com’s TechBlog
  • What's New in the Prefetch for Windows 8?? - Invoke-IR blog
  • Re-Introducing the Vulnerability Search - Journey Into Incident Response blog
  • Links - Windows Incident Response blog
  • Incident Response Teams are the New (Security) Black - Speaking of Security - The RSA Blog and Podcast
  • Red Alert: 10 Computer Security Blogs You Should Follow Today - MakeUseOf blog
  • New Security Intelligence Report, new data, new perspectives - Microsoft Malware Protection Center blog
  • Meet “badBIOS,” the mysterious Mac and PC malware that jumps airgaps - Ars Technica
  • Hacking a Reporter: Writing Malware For Fun and Profit (Part 1 of 3) - SpiderLabs Anterior
  • Treasure Hunting with FTK, EnCase, and SQLite Databases - Computer & Digital Forensics at Champlain blog
  • Add the CAINE ISO to your E2B drive - RMPrepUSB, Easy2Boot and USB booting

Cheers,

Claus Valca

Read More
Posted in boot-cd's, cheat sheets, forensics, iOS, Link Fest, networking, NFAT, PowerShell, security, utilities | No comments

Saturday, October 19, 2013

Micro Network News linkfest

Posted on 9:27 PM by Unknown

Just a small collection of network-minded links of interest this week.

Free Network Sniffers, Analyzers and Stumbers - WindowsNetworking.com - I saw some oldies-but-goodies in the list, some new ones (to me), most I was familiar with, and surprisingly missing from the list, Microsoft Message Analyzer. A lot more of the micro-sniffers/NFAT tools out there also got left off but the list seems a bit short to me and misses quite a few more worthy contenders.

Remote Capture with Message Analyzer and Windows 8.1 - MessageAnalyzer blog. Speaking of Message Analyzer, you now can remotely capture traffic with this tool (on supported target systems) without even needing a copy of Message Analyzer installed on them. Neat!  For more info see Using the Network Tracing Features over at TechNet.

Tweaking Wireshark Columns and Decodes - Packet Foo blog

We’re switching to Qt. - Sniff free or die - A development version of Wireshark 1.11.0 has been released that opens the door to using Qt for the user interface library.  The development version has some basic things working, but much of what you love about Wireshark does not. It’s a quick and interesting read.

D-Link Router backdoor vulnerability discovered - TechGeek

D-Link Router Backdoor - Schneier on Security blog

Old D-Link routers with coded backdoor - ISC Diary post

Oh my.

--Claus Valca

Read More
Posted in Link Fest, Microsoft, networking, NFAT, security | No comments

Sunday, September 29, 2013

Links of the Week

Posted on 2:04 PM by Unknown

Here is a hodge-podge of links that stood out this week.

Tr3Secure Data Collection Script Reloaded - Journey Into Incident Response blog - Corey Harrell has new news and updated on the Tr3Secure Volatile Data Collection Script he developed some time ago.

Tr3Secure Data Collection Script Reloaded - Journey Into Incident Response blog - Corey then follows up with a “real-world” walkthough of the Tr3Secure Volatile Data Collection Script after purposefully a lab pc for the sake of the discussion. It’s one thing to read about what a tool and process can do, it is a real treat to have the author lead a guided walkthough of the tool in action. As always, don’t forget to follow up with a comments reading as well.

plaso - super timeline - from the website “Plaso (plaso langar að safna öllu) is the Python based back-end engine used by tools such as log2timeline for automatic creation of a super timelines. The goal of log2timeline (and thus plaso) is to provide a single tool that can parse various log files and forensic artifacts from computers and related systems, such as network equipment to produce a single correlated timeline. This timeline can then be easily analysed by forensic investigators/analysts, speeding up investigations by correlating the vast amount of information found on an average computer system.”  Spotted via this CDF at Champlain post.

Microsoft Security Essentials: Aiming low? - ZDNet - Larry Seltzer offers some thoughts on Microsoft’s free AV solution. He really doesn’t thrash MSE but does point out that there are many other free alternatives that tend to perform higher. It seems like a pretty reasonable perspective.  FYI, I have been debating making a change from Microsoft Security Essentials to Bitdefender Antivirus Free. Yesterday I uninstalled MSE and replaced it with BAF. The changeover went very smooth. The deciding factor for me was the ongoing poor post-boot performance of my system.  While I don’t have a SSD drive in my laptop, I is running an Intel i7 CPU with 8 GB RAM. After boot, MSE scans on the post boot environment seem to be leading to slower post-boot launch of a number of my applications for a while as processes and files get scanned. Now that I am on BAF, I don’t see those post-boot application hangs. That said, I will continue to primarily recommend MSE to family and friends unless repeated infections indicate a need for the advance protection BAF may provide.

Before moving on from Microsoft Secuirty Essentials and Windows Defender (for Win 8), I thought this post Windows Defender and context menu for file check? (GTranslated) at Borns IT and Windows Blog was very insightful.  Some time ago I posted a number of Windows Defender tweaking tips Advanced Tips for Windows Defender with Windows 8, one of which was how to add a scan with Windows Defender to the context menu list in Win 8.  Born’s acknowledges that is a popular request and go though how it is accomplished. However, as he points out, the way Windows Defender operates, when a file is accessed via the (File) Explorer, Windows Defender already scans it before allowing access. If it is infected then you don’t get to fiddle with it.  Same thing with downloaded files; again pre-scanned by Windows Defender.  So, you can manually scan them again if you want, but know that if you do use Windows Defender in Win 8, it has already scanned the file.

Message Analyzer has Released – A New Beginning and Message Analyzer: Why so different from Network Monitor? - MessageAnalyzer Blog - Final release now public for Microsoft’s network capture analysis tool. I’m not sure it will replace Wireshark, but the approach is a step up from their older Network Monitor capture tool and is at the very minimum a great supplemental network capture tool for packet analysis.

Plugin Activation in Firefox - Mozilla Add-ons Blog - basically in a future version of Firefox, all plugins (except Flash) will become “click-to-activate”. This may or may not be a great thing depending on your security versus convenience perspective.

Wendel's Small Hacking Tricks - Killing Processes from the Microsoft Windows Command Line interface - SpiderLabs Anterior - I’m always looking to find a way to do something without a third-party tool so this is handy information to be familiar with.

Universal USB Installer (also YUMI) USB Flash drive does not boot on EeePC - RMPrepUSB, Easy2Boot and USB booting... blog - This is a pretty esoteric technical post for most folks, however if you are into USB-based system booting, it is interesting.

When setting up Windows 8.1, Microsoft appears to do all it can to shove you to create/use an on-line Microsoft account rather than a local one.  For some folks that might be fine but others (particularly the old-school crowd) will find this process similar to a cattle chute. If you are a thinking cow, it probably isn’t a very pleasant experience. Fortunately, there seem to be a number of outs if you know the game ahead of time.

  • How To Install Windows 8.1 Without Microsoft Account - Into Windows
  • Use Windows 8.1 with a local account instead of a Microsoft account - 4sysops
  • How to setup local account in Windows 8.1 - DeDoimedo.com
  • Windows 8.1 How To Convert Windows Live Account To Local Account - Next of Windows

Group Policy Search Engine Gets Updated - Group Policy Central blog - From that post by Alan Burchill:

“The Group Policy Search Engine is a great web site that has all the different version of Microsoft Group Policy ADMX files that allows you to easily and quickly search for the policy setting. This site is one I use very frequently especially and is a must have bookmark for any Group Policy Administrator.

“Well, Stephanus from Microsoft who maintains the web site has just loaded the Windows 8.1 and Windows Server 2012 R2 policy setting meaning you can now look up all the new policy setting in the latest version of Windows. “

Group Policy Search - site homepage.

Google Static Map Maker: Static Maps on Steroids - noupe - Nice tool to create linkable custom static Google maps rather than using a screen-shot image or a embedded and modifiable one.

Google Static Map Maker - site homepage by Katy Decorah.

Cheers!

--Claus Valca

Read More
Posted in Active Directory, browsers, Firefox, forensics, Google, Internet Explorer, Link Fest, malware tools, Microsoft, networking, security, Windows 8 | No comments

Saturday, September 14, 2013

GSD Saturday Linkfest: IT Crowd and ForSec Folks welcome

Posted on 4:31 PM by Unknown

News and Links For the ForSec Crowd

Kali Linux 1.0.5 and Software Defined Radio - Kali Linux - new build released with updates and some bells-and-whistles to boot!

Windows 8 / Server 2012 Memory Forensics - Forensic Methods

Inside Windows Rootkits - Forensic Methods

Links - Windows Incident Response blog - Lots of great fresh material here!

Forensic Perspective - Windows Incident Response blog

Tools to Grab Locked Files - Journey Into Incident Response blog - Cory Harrell has a simply amazing post full of tremendous resources worth taking a look into for using to grab locked files.

DOWNLOAD: Microsoft Security Intelligence Report, Volume 14 Windows Application & PDF - Kurt Shintaku's Blog - This is too good to pass up! From Kurt’s post.

The Microsoft Security Intelligence Report Windows application analyzes the threat landscape of exploits, vulnerabilities, and malware using the latest data from hundreds of millions of systems around the world and some of the Internet’s busiest online services.

Readers will find the data, insights, and guidance provided in this report useful in helping them protect their organizations, software, and users.  

Key features of the application include:

  • All content, in one convenient place – includes all 800+ pages of content from Volume 14 of our latest report and is fully searchable.
  • High fidelity charts – Many customers have asked us if they can obtain high resolution versions of the charts. We’ve delivered that in the application and have even included the “save as” functionality so that customers may use them in other applications, such as PowerPoint.
  • Reader friendly – We’ve designed the application with you, the reader in mind. One example of this is the integration of our glossary into the body of a page which appear as mouse-over tool-tips.

Security Intelligence Report (SIR) vol.14 (Windows Application) - Microsoft.com - The installable application has 800+ pages of content while the PDF version checks in at 120 pages. Pick you medicine and pucker up.

Other useful Microsoft security and threat response links:

  • Microsoft Malware Protection Center
  • Microsoft Security Response Center
  • Computer Security Tools & Downloads – TechNet Security
  • Microsoft Security Intelligence Report

Microsoft Security Essentials Prerelease - Microsoft Download Center - new pre-release version 4.4.207.0 for interested users of MSSE. Released on 09.09.13 so it is very fresh.

(IN)SECURE Magazine issue 39 released - HelpNet Security - Download directly here (PDF link).

News and Links For the IT Crowd

I enjoy the technical and scientific articles I get in my RSS feeds over from the IEEE Spectrum website. It has great material and is terribly technical. Some sadly interesting IT news I’ve seen over there recently tag state IT departments.

  • IT Hiccups of the Week: A Bad Week for U.S. State Government IT - IEEE Spectrum
  • Is There a U.S. IT Worker Shortage? - IEEE Spectrum
  • IT Hiccups of the Week: U.S. State Government IT System Meltdowns Galore - IEEE Spectrum

A new find this week has been the Microsoft Office Configuration Analyzer Tool

The Microsoft Office Configuration Analyzer Tool (OffCAT) is a program that provides a detailed report of your installed Office programs. This report includes many parameters about your Office program configuration and highlights known problems found when OffCAT scans your computer. For any problems that are listed in the report, you are provided with a link to a public-facing article (usually a Microsoft Knowledge Base article) on the issue so you can read about possible fixes for the problem. If you are a Help Desk professional, you can also save the report to file so that the report can be viewed in the Office Configuration Analyzer Tool on another client where the tool is installed. The Office Configuration Analyzer Tool 1.1 also includes a command-line version that can be used to collect an OffCAT scan without user intervention.

I’ve been playing with it for a while and am amazed at the depth of information and assistance it provides, particularly for many very obscure items.

Spotted over at this 4sysops post FREE: Microsoft OffCAT – Office Configuration Analyzer Tool 1.1

MBSA 2.3 Preview Release Available - Anything about IT - News about a new preview release version of Microsoft Baseline Security Analyzer (note link is to public version 2.2) that supports MS OS’s between XP and Windows 8.1

Windows 8.1 Command Prompt or PowerShell - Anything about IT

PowerShell 4.0 – A first look - 4sysops

How to Know When an Object Was Created and Changed in Active Directory - WindowsNetworking.com

When was the Last Password Changed for a User Account in Active Directory - WindowsNetworking.com

Office 365 for Nonprofits Organizations - Microsoft.com - Microsoft recently announced that they are offering Office 365 for non-profits (including eligible churches). This could be a big deal for many, learn more here.

SysInternals Tools, Windows 8 Training - Microsoft Virtual Academy - Seven video training modules and supporting materials to assist with learning the latest in core SysInternals tools. Check it out! Hat tip to Kurt Shintaku.

Kyle Beckman has posted a great series about Folder Redirection over at 4sysops that I (re)discovered. Lots of good information and tips here.

  • Folder Redirection – Part 1: Introduction - 4sysops
  • Folder Redirection – Part 2: Setting up your file server
  • Folder Redirection – Part 3: Explanation of folder permissions
  • Folder Redirection – Part 4: Group Policy configuration
  • Folder Redirection – Part 5: Best practices
  • How to disable Folder Redirection

Create a new Windows Service

Moon Point Support Weblog had a helpful post: Creating a Service for a Windows System

It caught my eye as we are working with a system down in the coal-mines that requires running the core features as applications rather than services which makes security and log-in/account management more than a little bit challenging. Alas, this won’t solve those headaches but it is worth bookmarking and knowing.

How To Create a User-Defined Service - Microsoft Support

How to create a Windows service by using Sc.exe - Microsoft Support

NSSM - the Non-Sucking Service Manager

Virtualization Software Updates

Download VMware Player 6.0 - VMware

VMware woos power users and IT pros with Fusion and Workstation upgrades - Ars Technica

VMware Player 6 Released with Full Windows 8.1 Support - Next of Windows

Oracle VM VirtualBox - Version 4.2.18 released - Oracle

General Application and Utility Updates of Note

UltraVNC VNC - version release 1.1.93 now out.

PeStudio - version release 7.45 now out.

Speccy v1.23 - Piriform - new release.

HWiNFO Portable - version 4.24-2000 - PortableApps.com - in what begs another GSD LinkList post, HWiNFO is yet another system hardware info-gathering resource I’ve been playing with. I’ve got more than a few I call up from the bullpen and this one has been added to the pitching stable.

IOBit Driver Booster Free - I confess I was very skeptical when I saw this new application appear. I have a few trusted driver apps to catalog and/or back up existing drivers on a system, and some vendor-specific driver update scanning applications used to update my systems. However, I have generally distained apps that claim to scan for driver updates on Windows systems and tell me what I need. Driver updating can be a dangerous and system-harmful thing if the wrong one is applied. So when I tried with trepidation this application, I found the UI was super clean and easy to navigate, the scan was immediate and dead-on fast, it seemed very accurate (finding only one out of date driver), provides a detailed and comprehensive list of drivers checked and their status, and creates a Restore point before every driver update is installed. It’s so easy I’d recommend it to my non-techy friends and family who I support. Great job IOBit! I’ll be running this one weekly!

SoftPerfect Network Scanner - updated to version 5.5. See Changelog for details.

Wireshark - updated to Stable version 1.10.2 and Old Stable version 1.8.10.

  • Wireshark 1.10.2 - Release notes
  • Wireshark 1.8.10 - Release notes

For you crazy WinPE building fans who use WinBuilder, a new version has been released that is much different from the previous version you may be familiar with. At the time of this blog-posting, the Winbuilder.net site seems to be temporarily down, but here were the applicable links you need to check out. I suspect fans of WinBuilder will fall one one side of the fence or the other; love it or hate it. Particularly with the Java building components.

  • WinBuilder - Development - reboot.pro
  • WinBuilder - reboot.pro
  • without imbedded Java RTEs - download version.

lessmsi (aka Less Msiérables) · ActiveScott at GitHub - now at version 1.1.3 The download link is a bit hard to find on the page if you aren’t used to GitHub. Look for “1 release" at the top bar just above the purple band and click it to find the compiled binaries in lessmsi-v1.1.3.zip.

d7 v10 Just Released! - Computer Technician - Foolish IT LLC.the updated change list is too expansive for me to try to list here. Check it out.

SoundVolumeView - new NirSoft utility - View/change sound levels & save/load sound level profiles on Windows Vista/7/8/2008 - More details in this NirSoft blog post.

Whew!  That post tired me out…or maybe it was the A&M/Alabama game live-streaming on my second monitor.

--Claus Valca

Read More
Posted in Active Directory, anti-virus software, boot-cd's, forensics, Link Fest, Linux, malware tools, Microsoft, networking, PowerShell, security, software, tutorials, utilities, virtualization, viruses | No comments

iPhone Traffic - ZAP’ed, Security, and Network Tap Tap Tapping

Posted on 9:59 AM by Unknown

This week brought in a very interesting post from web security/developer Troy Hunt.

 Unearthing the hidden shortcomings in Aussie mobile app security - Troy Hunt’s blog

Please go read then come back.

Interesting isn’t it?

I know most GSD readers probably wouldn’t be surprised to find some of their favorite mobile-apps leak user ids and passwords in plain-text, but for those who don’t know, some do.

Case in point (that has now been reported as fixed!):  Zscaler Research: Mobile App Wall of Shame: ESPN ScoreCenter

Naturally that got me thinking about a common mantras in the For/Sec world; “know your tools” & “verify, verify, verify”.

What I want to do is some benchmarking and analysis of the mobile apps I use on my own iPhone to have a better understanding on what is happening with their network traffic. This would be valuable information to know for general usage, and critical knowledge in case you unknowingly encounter a Wi-Fi Pineapple in the wild or a more complex man-in-the-middle Wi-Fi attack and get your network traffic captured.

One super-easy (and lazy) way I have found is to use ZAP - Zscaler Application Profiler.  From the “About” page link:

About ZAP

Zscaler Application Profiler (ZAP) is web based tool designed to streamline the capture and analysis of HTTP(S) traffic from mobile applications. ZAP is capable of analyzing traffic from both iOS and Android applications and includes the following functionality:

  • Search: View summarized historical results for past scans.
  • Scan: Proxy traffic from a mobile device through the ZAP proxy and the mobile app traffic will be automatically captured and analyzed
  • iPCU: Upload your iOS device configuration file(.deviceinfo) to check risk score of installed application. It will give you overall risk score of your device. The information provided is based on out knowledge base.

ZAP classifies traffic into the following buckets and calculates an overall risk score for the application:

  • Authentication: Username/password sent in clear text or using weak encoding methods.
  • Device Metadata Leakage: Data that can identify an individual device, such as the Unique Device Identifier (UDID).
  • Personally Identifiable Information Leakage: Data that can identify an individual user, such as an email address, phone number or mailing address.
  • Exposed content: Communication with third parties such as advertising or analytics sites.

Zscaler also has a detailed video on this service on their blog: Zscaler Research: Introducing ZAP.

So you can either check their historical report data on apps already researched, you can connect your device to their proxy to do a scan on a new app/version not already captured historically, or even upload your own iOS device config file.

Wow.  Bookmark this resource link now!

However, there may be cases you want to do your own local network traffic capture and analysis…because you like pain and frustration (and hands-on learning perhaps).

Part I - In Which Hardware TAP Options are narrowed down

At work (when & where authorized) we can set up network packet captures either on a specific system or on the LAN using port-SPAN.

At home, I don’t have a managed switch (or dumb hub) that can do that.  I suppose I could buy a USB-NIC (so I can have two wired network ports on my laptop) and then capture traffic temporarily though one of these messy devices (home-built or purchased) but that isn’t quite as elegant as I would prefer.

Or (as the TinyApps bloggist kindly just reminded me) use Cain & Abel.

  • Capturing Packets on a Broadcom Card - The Flying Frank
  • Configuration - OXID.I

Instead I decided I'll pick up a specialized device that support a network TAP.  This way I can just hook it in line between my Wi-Fi router and the cable modem and capture everything that passes though. It may not be 100% on packet captures, but I think it will be good enough for my home testing.

So the next question is what device?

I’ve settled on the following options:

  • Dualcomm DCSW-1005 USB Powered 5-Port 10/100 Fast Ethernet Switch TAP (Port Mirroring) - Amazon.com link
    • Dualcomm DCSW-1000/1005PT - Dualcomm product page
  • Dualcomm DCGS-2005L 5-Port 10/100/1000 Gigabit Ethernet Switch Network TAP (Plastic Case) - Amazon.com link
  • Dualcomm DCGS-2005 5-Port 10/100/1000 Gigabit Ethernet Switch Network TAP (USB Powered, Port Mirroring, PoE Pass-Through) - Amazon.com link
    • Dualcomm DCGS-2005/DCGS-2005L - Dualcomm product page

The DCSW-1005 model is an attractive basic option. It supports port-mirroring, is USB powered, and has 5-ports. (note only port #1 is mirrored to port #5).  The price is good.  The only “drawback” I see is that it only supports 10/100 speed on the network.  While I seriously doubt I would ever approach over 100 Mbps and cause a bottleneck on my home network…most all my other network equipment is 1000 Mbps capable.  So thinking forward, this could be slightly limiting down the road, or if I am asked by family/friends/associates to do some network troubleshooting on a “true” 1000 Mbps network, or tapping in between two network devices actually running at 1000 Mbps.  So there is that. Also, the buffer memory used by the device in the mirroring process is 256 KB. So if that gets saturated, there is the possibility of dropped packet captures.

The only difference between the DCGS-2005/2005L seems to be the “L” model has a metal cabinet while the other doesn’t. Of course, that option comes with a $20 markup as well.  I’m pretty sure the plastic cabinet would be just fine, but the vanity in me just likes the metal cabinet appearance a bit more. Probably just a bit more durable when tossed around in a go-bag and maybe it might dissipate heat a bit better? This model does support up to 1000 Mbps so there is that benefit since it is (at least $100 more expensive) but the buffer memory is just 104 KB. Hmmm. 

Should I be concerned about overloading either of the devices’ memory buffer when capturing home-network traffic? Probably not but what say you pros?

I did find these pretty basic and older reviews, including one from the guru of network security Richard Bejtlich.  I really didn’t find any more recent reviews of the device so if/when I get my hands on one, you can be assured I’ll have a write-up review.

  • DualComm Port Mirroring Switch - TaoSecurity - (Sept. 2010)
  • Review of Dualcomm 5-Port Pass-Through Port Mirroring Switch - LoveMyTool - Betty DuBois - (April 2010)
  • Network Security Monitoring with Dualcomm DCSW-1005PT - CyberArms - D.Dieterle - (Nov. 2010)

Part II - In Which Other Alternatives are discovered

So let’s assume that you are already comfortable with network packet captures, installing network software, and making network configuration changes to Wi-Fi devices.

Are there any options to capture iPhone network traffic without going to the trouble and expense of picking up TAP hardware just for that task?

Yep.

First option is a tool called Paros. It is Java based (I know, I know..) and can assess web application vulnerabilities. The link has a Windows binary that appears back from August 2008.

Here is a nice walkthough on using Paros Sniff Your iPhone's Network Traffic by Jerod Santofrom to give you some introduction to it.

There was a comment on the Paros page providing information to a very current “fork” of Paros: ZAP

(Note: Not to be confused with the Zscaler ZAP service)

OWASP Zed Attack Proxy Project - OWASP - OWASP.org

There are tons of information on that page on this tool:

  • Screenshots
  • wiki videos page
  • project pamphlet - a very quick intro
  • project presentation - longer presentation

And here are some quick links on ZAP usage:

  • Owasp ZAP - InfoSec Institute post
  • Debugging SSL on Both iOS Devices and Simulators with Man-in-the-middle Proxies - CodeProject
  • Intercepting iPhone traffic with your MacBook - Shaun Zinck’s blog

Next up, we have Fiddler, a free web debugging proxy from Telerik

  • Capturing HTTP traffic on an iPhone with Fiddler - Scott Wojan’s DotRant blog
  • Configuring Fiddler to Capture Web Traffic from an iPhone/iPad Device - ESRI Support Services blog
  • How To Sniff iPhone Network Traffic - Matt McClure’s blog

Finally, if you are hard-core, just go use Wireshark.

  • iPhone Meets Wireshark – Capture Wireless Network Traffic from Mobile Devices - EtherLook

Part III - Resources, References, & Pineapples

Here are some additional links related to all of the above discussions including the Dualcomm products, SPAN/TAP considerations, and the next network device I’m interested in picking up to play with; the Wi-Fi Pineapple.

SPAN Out of the Box (PDF Link) - John He’s Dualcomm Technology PowerPoint presentation at SharkFest 2010. Goes into details about SPAN/TAP considerations and specifics on what DualComm feels makes their product super special. SPAN out of the Box (Blip video)

B-7 (Battaglia) TAPS Demystified (PPT Link) - Samuel Battaglia’s Network Critical PowerPoint presentation at SharkFest 2010.

SPAN Port vs TAP (Video) - Betty DuBois- SharkFest 2009 presentation. PowerPoint presentation here (ZIP).

SPAN Port or TAP? CSO Beware - LoveMyTool blog - Tim O’Neill

Network Monitoring Madness: Poor Man’s Resource Linkfest - GSD blog post from 2010.

Let’s Get For/Sec-Motivated! - GSD blog post from 2011.

The beginners guide to breaking website security with nothing more than a Pineapple - Troy Hunt’s blog.

Your Mac, iPhone or iPad may have left the Apple store with a serious security risk - Troy Hunt’s blog.

Pineapple Surprise! Mixing trusting devices with sneaky Wi-Fi at #wdc13 - Troy Hunt’s blog.

Netgear DS104 4-Port 10/100 Dual Speed Hub with Uplink Button (Amazon link) - recommended to look into as well by TinyApps bloggist who reports he had good experience with it.

CaptureSetup/Ethernet - The Wireshark Wiki

CaptureSetup/WLAN - The Wireshark Wiki

Cheers!

--Claus Valca

Read More
Posted in Apple, forensics, iOS, iPhone, networking, NFAT, security, troubleshooting, tutorials, utilities, video | No comments

Monday, September 2, 2013

ForSec Labor Day Blow-out Linkfest

Posted on 6:15 PM by Unknown

Final link push for the GSD blog before shutting down for the night.

I hope all you ForSec guys and gals have had a restful Labor Day before heading back into the trenches tomorrow.

Here are some links of note to review this week that I picked out.

Richard Bejtlich on His Latest Book, “The Practice of Network Security Monitoring” - M-unition blog

Did It Execute? - M-unition blog post by Mary Singh on incident response.

Anatomy of an ongoing Drive-by-Download campaign - ZScaler ThreatLabZ blog post

Browser Related":

Psst. Your Browser Knows All Your Secrets. - SANS ISC Diary guest post by Sally Vandeven on pulling the crypto keys in a browser.

Cookie Cadger to Identify Cookie Leakage from Applications over An Insecure HTTP Request - Next of Windows

Cookie Cadger - project homepage. From the link:

“Cookie Cadger helps identify information leakage from applications that utilize insecure HTTP GET requests.

“Web providers have started stepping up to the plate since Firesheep was released in 2010. Today, most major websites can provide SSL/TLS during all transactions, preventing cookie data from leaking over wired Ethernet or insecure Wi-Fi. But the fact remains that Firesheep was more of a toy than a tool. Cookie Cadger is the first open-source pen-testing tool ever made for intercepting and replaying specific insecure HTTP GET requests into a browser.

“Cookie Cadger is a graphical utility which harnesses the power of the Wireshark suite and Java to provide a fully cross-platform, entirely open-source utility which can monitor wired Ethernet, insecure Wi-Fi, or load a packet capture file for offline analysis.”

Book stuff - Windows Forensic Environment - Brett Shavers teases us again with brief news he continues to develop a standalone WinPE/FE “one-push” builder. Also he has released an early Kindle version of his X-Ways Forensics Practitioner’s Guide. Finally Brett gives recommendations for some other great ForSec reference books in his post.

Sadly, I am embarrassed to confess that I have just rediscovered the SANS Institute: Reading Room.

It appears their Latest 25 Papers RSS link to the page may have some issues as though I can load it in Firefox, trying to use it in a dedicated RSS reader generates an error that it cannot find actual RSS data on the page. Hmm.

Anyhows…since I just found it (again) there are gazillion (or slightly less) new whitepapers for review and reading.

Here are the ones I picked out that looked interesting to my desk operations:

  • 60 Seconds on the Wire: A Look at Malicious Traffic - (direct PDF Link) - SANS Reading Room whitepaper by Kiel Wadner - August 22, 2013.
  • Live Response Using PowerShell - (direct PDF Link) - SANS Reading Room whitepaper by Sajeev Nair - August 20, 2013.
  • Event Monitoring and Incident Response - (direct PDF Link) - SANS Reading Room whitepaper by Ryan Boyle - May 15, 2013.
  • Detecting Security Incidents Using Windows Workstation Event Logs - (direct PDF Link) - SANS Reading Room whitepaper by Russ Anthony  - August 22, 2013.
  • Windows Logon Forensics - (direct PDF Link) - SANS Reading Room whitepaper by Sunil Gupta - March 15, 2013.
  • Custom Full Packet Capture System - (direct PDF Link) - SANS Reading Room whitepaper by Derek Banks - April 16, 2013.
  • Security Best Practices for IT Project Managers - (direct PDF Link) - SANS Reading Room whitepaper by Michelle Pruitt - June 24, 2013.
  • Get Out of Your Own Head: Mindful Listening for Project Managers - (direct PDF Link) - SANS Reading Room whitepaper by Charlie Scott - December 20, 2010.
  • The Death of Leadership in Management - (direct PDF Link) - SANS Reading Room whitepaper by Dana Hudnall - September 12, 2013.

That last link reminded me of the following particular motivational leadership links I keep handy on my blog sidebar:

  • Getting the Job Done - TaoSecurity blog’s Richard Bejtlich.
  • AFOATS Training Manual - 2004 edition via Google Docs
  • Five Qualities of Real Leadership - TaoSecurity blog’s Richard Bejtlich.
  • What I've Learned - USNI Blog post by Alexander Martin

Cheers,

--Claus Valca

Read More
Posted in browsers, forensics, Kindle, Link Fest, networking, NFAT, security, Win FE | No comments

Network News & Goodies - Labor Day Edition

Posted on 5:14 PM by Unknown

Linkfest post on Labor Day. Lots of network goodies here for the GSD fans!

Presented in no particular order…just how they came of the bench tonight.

Viewpoints: OSI Model and APSTNDP - Microsoft’s MessageAnalyzer blog

Wireshark Tutorial Series #2. Tips and tricks used by insiders and veterans - Sniff free or die Wireshark blog

Tools - The Wireshark Wiki - great Super-List of tools and supporting material for Wireshark.

I’ve posted recently quite a gushing rant on TraceWrangler. It is a free (still-Alpha release) no-install tool to help with sanitizing and anonymizing packet trace files. Pretty wicked cool. Jasper Bongertz posted an intro here and touched on some of the issues current tools of this kind have.

I mention it because the Wireshark Wiki Tools page does contain a list of capture file anonymization tools and (sadly) TraceWrangler isn’t on it yet. Somebody with a connection needs to send the Wiki editors some memos…just saying.

TraceWrangler (change log) - now at version Alpha 0.1.3 build 308.

Microsoft Security Advisory (2861855): Updates to Improve Remote Desktop Protocol Network-level Authentication - Microsoft Security TechCenter

Sequence Match View: Identifying Interesting Network Patterns - Microsoft’s MessageAnalyzer blog

How Secure Is Your Smartphone - Check the Packets (by Tony Fortunato) - LoveMyTool blog

The Do's and Do NOT's of using SPAN Ports (by Darragh Delaney) - LoveMyTool blog

NetFort SPAN Port Configurator - freeware - GUI Utility to set Span Ports on Cisco switches…because as you know, using the free Cisco Network Assistant to do so is such a pain.

ZMAP 1.02 released - SANS ISC Diary

ZMap · The Internet Scanner. From the home page:

“ZMap is an open-source network scanner that enables researchers to easily perform Internet-wide network studies. With a single machine and a well provisioned network uplink, ZMap is capable of performing a complete scan of the IPv4 address space in under 45 minutes, approaching the theoretical limit of gigabit Ethernet.

“While ZMap is a powerful tool for researchers, please keep in mind that by running ZMap, you are potentially scanning the ENTIRE IPv4 address space and some users may not appreciate your scanning. We encourage ZMap users to respect requests to stop scanning and to exclude these networks from ongoing scanning.”

“We suggest that users coordinate with local network administrators before performing any scans and we have developed a set of scanning best practices, which we encourage researchers to consider. It should go without saying that researchers should refrain from exploiting vulnerabilities or accessing protected resources, and should comply with any special legal requirements in their jurisdictions.”

While you may not break the Internet as handily as Jen does, you might do bad things to your own. Be sure you are well familiar with the tool before experimenting!

INMAP 6.40 Released - SANS ISC Diary

Nmap Change Log - nmap.org

Download the Free Nmap Security Scanner for Linux/MAC/UNIX or Windows - nmap.org

SoftPerfect WiFi Guard - version release to 1.0.3 (Change log)

NetworkTrafficView - NirSoft - version release to 1.76:

  • Added 'Maximum Packet Size' column. For TCP connections that transfers significant amount of data, the value under this column represents the actual MTU.

Wireless Network Watcher - NirSoft - version release to 1.67

  • Updated the internal MAC addresses database.

KiTTY - update to current version release of 0.63.0.2

60 Seconds on the Wire: A Look at Malicious Traffic (direct PDF Link) - SANS Reading Room whitepaper by Kiel Wadner - August 22, 2013.

Custom Full Packet Capture System - (direct PDF Link) - SANS Reading Room whitepaper by Derek Banks - April 16, 2013.

Updated from another recent GSD post because they seemed apropos here in this as well:

Psst. Your Browser Knows All Your Secrets. - SANS ISC Diary guest post by Sally Vandeven on pulling the crypto keys in a browser.

Cookie Cadger to Identify Cookie Leakage from Applications over An Insecure HTTP Request - Next of Windows

Cookie Cadger - project homepage. From the link:

“Cookie Cadger helps identify information leakage from applications that utilize insecure HTTP GET requests.

“Web providers have started stepping up to the plate since Firesheep was released in 2010. Today, most major websites can provide SSL/TLS during all transactions, preventing cookie data from leaking over wired Ethernet or insecure Wi-Fi. But the fact remains that Firesheep was more of a toy than a tool. Cookie Cadger is the first open-source pen-testing tool ever made for intercepting and replaying specific insecure HTTP GET requests into a browser.

“Cookie Cadger is a graphical utility which harnesses the power of the Wireshark suite and Java to provide a fully cross-platform, entirely open-source utility which can monitor wired Ethernet, insecure Wi-Fi, or load a packet capture file for offline analysis.”

Cheers.

--Claus Valca

Read More
Posted in forensics, Link Fest, Microsoft, networking, NFAT, Remote Support, tutorials, utilities | No comments

Sunday, August 11, 2013

Network & Network Security Quickpost - Last call NFAT edition

Posted on 8:22 PM by Unknown

I just couldn’t wrap up the weekend without sharing these links. I’m so going to be nodding off in my training class tomorrow. Must bring Thermos of extra coffee with me! Don’t want to make the teacher unhappy!

So many network tools, tricks, and nuggets came out last week I’m still exciting thinking about how to use them all!

Security Advisory: Two Vulnerabilities in NetworkMiner - NETRESEC Blog - Don’t let the boring post title fool you! Based on this, Erik Hjelmvik has released a new version of NetworkMiner! Now sparkling at version 1.5 (free/pro editions)

NetworkMiner packet analyzer - Download NetworkMiner version 1.5 (free) here.

While I was doing some super-fast (but apparently productive) beta testing for Erik on some Windows 7 and Windows 8/8.1 systems, I noticed I wasn’t getting great results from my test captures made with and being processed in NetworkMiner. My “doh”. Erik kindly reminded me of his post NETRESEC RawCap - A raw socket sniffer for Windows where he pointed out that using Windows raw socket sniffing has some problems. I had forgotten I didn’t yet install Wireshark/WinPcap on these particular test systems. From Erick’s post:

Microsoft's newer operating systems (later than WinXP) have limitations associated with raw socket sniffing of external interfaces, i.e. everything that isn't localhost. Known limitations in Windows Vista and Win7 are:

  • Windows 7 - Can't capture incoming packets
  • Windows Vista - Can't capture outgoing packets
Due to these limitations in the raw sockets implementations of Microsoft's current operating systems we suggest running RawCap on Windows XP if you need to capture from external interfaces.

Baselining Dropbox With Wireshark (by Tony Fortunato) - LoveMyTool blog video presentation.

Editing Tracefiles With TraceWrangler (by Tony Fortunato) - LoveMyTool blog video presentation. This short video presentation on a new (Alpha release) tool, TraceWranger blew me away. There are methods of sanitizing trace files for sharing/training but they are fraught with challenges for mere mortals. This new tool is amazing and I really hope the developer Jasper Bongertz gets the support needed to encourage his continued refinement and development of this valuable tool for analysts.

  • TraceWrangler - (alpha software) - currently at build version 0.1.3. Standalone application. No installation needed. Unzip and go. Written by Jasper Bongertz.
  • TraceWrangler Documentation - This is Must Read material if you are interested in using this tool properly
    •  Starting TraceWrangler - the basics
    • Anonymization Tasks - details for the options
  • Trace File Sanitization NG - SEC-04_Trace-File-Sanitization-NG_Jasper-Bongertz (PDF) - Link to his presentation of the tool at Sharkfest 2013.
  • Sharkfest 2013 - Trace File Sanitization (Jasper Bongertz) - YouTube. While PDF versions of presentations are nice, on a whim I decided to see if Jasper’s presentation was actually up on YouTube for viewing. It was!
  • Trace file sanitization for network analysts - Packet Foo - Jasper’s blog post with additional details on his tool in case you missed the presentation.
  • The notorious Wireshark “Out of Memory” problem - Packet Foo. Oh how this has hobbled me over the years! So much so that CLI based captures became my dearest friend!
  • Packet Foo RSS - Yeah. It’s that good. Feed yourself on it!

Nmap - Now at version 6.40 - Free Security Scanner For Network Exploration & Security Audits.

  • Nmap Change Log
  • Download Nmap Security Scanner - for Linux/MAC/UNIX or Windows

Message Analyzer Beta3 Refresh has Been Released (Build 6215) - MessageAnalyzer - Lost in all the news was a quiet announcement of the next generation of Microsoft’s own network traffic analysis tool MessageAnalyzer getting a Beta 3 refresh release. The interface is very different (to me) from Wireshark, but since I used NetMon a ton to supplement my Wireshark work, it is taking some getting used to.

HolisticInfoSec: toolsmith: C3CM Part 1 – Nfsight with Nfdump and Nfsen - HolisticInfoSec blog - Russ McRee’s post rocks on so many levels. Well worth the read and review.

Firefox Developer Tool Features for Firefox 23 - Mozilla Hacks – the Web developer blog. In case you missed it, Firefox 23 was released last week. Included in it (besides the new app icon update) was a new network tool called “Network Monitor.” 

I so love this! “F12” is the new “must know” hotkey in these modern browsers!

If only Mozilla (or Chrome or IE 10) were “approved” web-browsers in our enterprise. This feature alone would so help with network and web-app diagnostics and troubleshooting from the end-user desktops.

What’s that you say? One single element of your cloud-based web-application seems to time out in IE 8, crashing your session? The network is fine, site bandwidth is fine. Your PC is fine. Seems like it could be a server-side application issue. Let me make a ticket for your issue and send it up. (Response often comes back, “There is no problem…must be a client-side issue…check the PC and bandwidth, follow our response template and let us know…”) (Sigh…)

  • Network Monitor, now in Firefox Beta - Mozilla Hacks – the Web developer blog - More details on the feature.
  • A look at Firefox's new Network Monitor - Ghacks - Martin Brinkmann does an outstanding job introducing it as well.

Turns out Chrome web browser can do this trick as well

  • Evaluating network performance - Chrome DevTools — Google Developers
  • Performance profiling with the Timeline - Chrome DevTools — Google Developers
  • Chrome Dev Tools: Networking and the Console - Nettuts+
  • Google Chrome Dev Tools: Network Panel - TechRepublic

Turns out that Internet Explorer (IE9, IE10, IE11) also have a “F12” feature for network analysis in the browser.

  • Introduction to F12 Developer Tools (Windows) - IE Dev Center
  • Navigating the F12 Developer Tools Interface (Internet Explorer) - IE Dev Center
  • Internet Explorer's F12 Developers Tools: A feature walk-through - TechRepublic
  • A Peek at Internet Explorer’s Developer Tools - Nettuts+
  • Network Traffic Capturing with IE9 Developer Tools - LINQED.NET

And in IE11, it’s about to bring the house down on the competition!

Debugging and Tuning Web Sites and Apps with F12 Developer Tools in IE11- IEBlog. OMG!!! I am so crushing on the new “F12” profiling and responsiveness tool interface in IE 11! Please tell me this is going to be backwards compatible with Win 7. (Why yes, Virginia, it is…)

3ohix43s.dfg

Anyway, back to more Firefox 23 release news and details.

  • Firefox 23 lands with a new logo and mixed content blocking - Ars Technica
  • Firefox Notes - Desktop - Mozilla.org
  • Firefox 23 enables mixed content blocking, consolidates search settings - BetaNews
  • A Look At What's New In Firefox 23 - Addictive Tips blog

Troubleshooting TCP/IP Connectivity Issues with This Command-Line Utility Portqry.exe - Next of Windows. Been using portqry.exe from the command line along with the PortQueryUI GUI fro some time. Dead helpful in a pinch!

PuTTY: a free telnet/ssh client - just released at version beta 0.63 for you console fans! See the extensive Changes page for all the details

  • PuTTY Portable 0.63 - PortableApps.com build version as well is available and updated.

KiTTY - let’s not forget about this fork version of PuTTY that has some additional bells-and-whistles!

  • News - latest KiTTY news is update 0.62.2.3 minor update in late May 2013.
  • Recent changes - tracking site-changes at KiTTY’s house
  • KiTTY Portable - why “yes” there is a PortableApps.com build version as well for KiTTY fans.

Finally, at home I run Mozilla Firefox, Portable Edition and Google Chrome Portable rather than installing them directly on my system. However I was trying to use some of NirSoft’s Browser Tools to explore and check my Google Chrome(ium) cache and wasn’t finding anything at all.

Strange.  Bug in the tool?

Turns out the answer was “of course not dummy” it’s the dummy’s bug.

Where is the Google Chrome Portable cache folder? - PortableApps.com. Bruce Pascoe kindly puts it like this:

Chrome Portable, like FFP, doesn't save the cache by default.

Note that unlike Firefox however, there's no way to turn the cache off completely in Chrome, so while it's running the cache is stored in the local temp directory (%TEMP%), but then it's immediately deleted when you exit Chrome.

So anyway, yeah, no surprise that you couldn't find it.

and cleared up a bit by “The MAZZTer”

The cache folder is saved in %TEMP%\GoogleChromePortable.

Where the %TEMP% is the user’s temporary file location under their profile.

04i5mjur.uan

This is interesting as it explains why the NirSoft tool ChromeCacheView wasn’t finding anything while pointing to the default user profile location in my Portable Apps application structure that ChromeHistoryView didn’t seem to have any issue with parsing. So even though the files were removed when the program terminated, it most likely did not “secure” delete them, so (depending on overwrite activity of the file system/free-space scrubber utilities) it might be possible to carve and recover them from a system that the portable-apps version of Chrome was used on. And that sounds like a challenge for another day…

Cheers!

--Claus Valca

Read More
Posted in browsers, Firefox, forensics, Google, Internet Explorer, Link Fest, Microsoft, networking, NFAT, security, troubleshooting, utilities | No comments

Sunday, July 28, 2013

ForSec “Value Package” Linkfest - No coupons required!

Posted on 5:00 PM by Unknown

One last Linkfest from a now exhausted GSD blogger this weekend.

Cleaning out the “to-be-blogged” hopper is always rewarding, but I tend to get very behind on the weekend chores. My saving grace this weekend has been frequent scattered showers and an equally tired Lavie who hasn’t been interested in going out for shopping, groceries, or dining out. The kitchen has been cleaned. The laundry has been done for the week.

Next stop, a few hours of rest, post-blogging, then a wind-down with Endeavour on PBS Masterpiece.

Too Funny Not To Miss

Bloody galah scammers still not getting the message - Troy Hunt’s blog. Security guru Troy Hunt has had his fair share of “this is (not) Microsoft cold calling you…your PC is infected…let me remote control it” scams and has picked them all apart to the bone.

This time he takes a new angle…in a way that only an Aussie could pull off!  This is a classic! Troy, please offer us some of those sound files or link to where we can get them!  I need to put together a Texan sound-effect package for similar fun with unwanted callers. Brilliant!

Microsoft Security News

Microsoft Releases New Mitigation Guidance for Active Directory - Microsoft Security Blog

Overview of Microsoft`s "Best Practices for Securing Active Directory" - SANS Computer Forensics and Incident Response blog’s Mike Pilkington does a great summary and takeaway of the new AD mitigation guidance.

Security Awareness Training: Your First Line of Defense (Part 4) - WindowSecurity.com’s Deb Shinder discusses evaluating training effectiveness short and long-term.

See also these previous series posts:

  • Security Awareness Training: Your First Line of Defense (Part 1)
  • Security Awareness Training: Your First Line of Defense (Part 2)
  • Security Awareness Training: Your First Line of Defense (Part 3)

Network Security, News and Techniques

Wireshark 1.8.9 and 1.10.1 Security Update - ISC Diary

  • Wireshark 1.10.1 - Release Notes
  • Wireshark 1.8.9 - Release Notes
  • Wireshark - Downloads

Next up are some great and detailed video presentations from Sharkfest 2013

  • Sharkfest 2013 - Wireshark Network Forensics (by Laura Chappell)
  • Sharkfest 2013 - Trace File Sanitization NG (by Jasper Bongertz)
  • Sharkfest 2013 - Attack Trends and Techniques (by Steve Riley)
  • Sharkfest 2013 - Capture Limit of a Laptop, When does it Drop Packets? (by Chris Greer)

Recent Forensically Focused Posts

  • HowTos - Windows Incident Response blog
  • HowTo: Malware Detection, pt I - Windows Incident Response blog
  • HowTo: Data Exfiltration - Windows Incident Response blog
  • HowTo: Add Intelligence to Analysis Processes - Windows Incident Response blog
  • HowTo: Determine/Detect the use of Anti-Forensics Techniques - Windows Incident Response blog
  • HowTo: Investigate an Online Banking Fraud Incident - Windows Incident Response blog
  • Finding an Injected iframe - Journey Into Incident Response blog
  • MS Excel and BIFF Metadata: Last Opened By - Digital Forensics Stream blog

Physical (In)Security?

Duplicate house keys online - Keys Duplicated - This is either freaking amazing or super-scary. I just can’t decide! According to their Security page, precautions are taken.

The Keys Duplicated Blog - A couple really cool and technical posts on the behind the scenes things that make their keys pretty good.

…as spotted on Lifehacker’s post: Shloosl Copies Your House Keys Using a Smartphone Photograph

When 'Smart Homes' Get Hacked: I Haunted A Complete Stranger's House Via The Internet - Forbes

ForSec LiveCD Distro News

  • More on WinFE and Autopsy - Windows Forensic Environment blog
  • DEFT Linux 8 stable with DART 2 is out! - DEFT Linux - Computer Forensics live cd
  • Kali Linux Summer Update Release 1.0.4 - Kali Linux
  • Pass the Hash toolkit, Winexe - Kali Linux
  • Downloads - Kali Linux

AV/AM Bits

Microsoft Security Essentials quietly released version 4.3.216.0 engine update for their free antivirus scanning program. If you use MSSE, you should get it via the automatic updates…if you have them turned on…you do have them turned on right?

Download Microsoft Security Essentials - Microsoft Download Center - Like most things MSSE, trying to figure out just what got updated is next to impossible so let’s just say for now that this one must be better than the previous version and move on.

I’m still using MSSE around the Valca home on all our home systems. I also continue to recommend it to friends and family (generally everyone non-work-related) who I provide friendly IT support to. I find it is pretty non-threatening to the non-technical users I know and though it loves to alert on many of my security programs (potentially unwanted programs) since they can also be used for 3vil, it seems to do a more than adequate job security the systems.

For my Windows 8 systems, I’m instead relying on Bitdefender Antivirus Free. In some ways it’s a bit different model in that you need to sign up with an email address to set up your account. Then you can download the client to the system. What is nice is that if you manage multiple systems in your home, you can log into your account at their site and then get a console feedback on the status of those systems. That’s something that I do at work with another vendor’s enterprise AV client health/status management console. That’s super cool for a free product. I’m seriously leaning to expanding it’s coverage to my main Windows 7 laptop at home. Performance has been outstanding on my Windows 8 systems.

Kaspersky tops real world protection test - BetaNews - this post does point out that Bitdefender tied Kaspersky with a 99.9 % protection level in AV-Comparatives Independent Tests of Anti-Virus Software for July 2013. While Microsoft Security Essentials rated a 92.5 % protection level. There are some additional disclaimers so read the short BetaNews article carefully. Then head over to AV-Comparatives to dig deeper and see the full findings.

  • AV-Comparatives Real-World Protection Test March-June 2013 - AV-Comparatives
  • AV-Comparatives Real-World Protection Tests - AV-Comparatives

Finally, we wrap up this segment with this interesting discussion:

The evolution of Ronvix: Private TCP/IP stacks - Microsoft Malware Protection Center

It’s a bootkit infection that has its own private TCP/IP stack. By doing so it can be extra stealthy and bypass personal firewall hooks and can lurk unseen in standard tools and utilities (such as nbtstat). Doing so, depending on packet/network monitor off the infected machine may be ineffective. However, it still must talk ON the network, so an independent network monitoring and forensics analysis approach using a network monitoring appliance or span port capture may detect the traffic. This may be why comparing outside network traffic captures from a system on the network to network traffic captured on the system may be a useful exercise for incident response and monitoring purposes.

Legally Focused

I’ve been reading a wider range of subjects, and a small part of those touch on our legal system. Mainly they apply to digital law and crime but some are more general. I’m just tossing them out there for the interested or curious. Generally they tend to analysis of current events or provide a more detailed lawyer’s review than the talking/shouting legal heads we encounter on mass-media “news-like” entertainment outlets these days.

  • CYB3RCRIM3 - Susan Brenner’s blog on cybercrime and cyberconflicts in technology and law.
  • Popehat - group blog with a mostly legal focus (though topics can range far afield!)
  • Le·gal In·sur·rec·tion - group blog with mostly legal and law-in-today’s-culture focus. Pretty vibrant opinions. Alignments may vary.
  • Lowering the Bar - Sometimes lighthearted (though always serious at the core) look at some of the nonsense the legal system contains, or foists on others from time to time. Great site.
  • Massad Ayoob - legal, cultural, and educational postings primarily dealing with legal private firearm ownership issues. Also analysis of public media trends and news stories.

Have a great week!

--Claus Valca

Read More
Posted in Active Directory, anti-virus software, boot-cd's, cheat sheets, firewalls, forensics, humor, Link Fest, malware tools, Microsoft, networking, NFAT, security, troubleshooting, tutorials, utilities, video, viruses, Win FE | No comments

New Apps and Utility Updates

Posted on 1:30 PM by Unknown

Submitted here for your frustration is a jumble of new and updated software applications I’ve collected over the past couple of weeks.

Think of it like the “pot-luck” box where everything is free for the taking after the week-long garage sale has concluded.

Only you might really want something in this mix.

MetroTextual 1.5 - SingularLabs - slick notepad replacement has some new improvements in this edition. Including Transformers (Plugins).

SpeedyFox - CRYSTALIDEA Software - Some time back got bumped to version 2.0.4. I run this regularly to clean up my Firefox/Chrome/Thunderbird databases. It really helps with launch speed. See also SpeedyFox Portable - PortableApps.com

CPU Meter Pro - Microsys - The GUI is very nice though the level of detail might be a bit less than some sysadmins might prefer.

DLL UnInjector - NoVirusThanks - unload DLLs within a selected process. More at this Unload loaded DLLs with DLL UnInjector post.

Download Backup Thunderbird - free tool to back up Thunderbird email clients spotted in this AddictiveTips post Easily Backup & Restore Your Mozilla Thunderbird Accounts & Their Data. I personally have always relied on MozBackup.

NetworkLatencyView - Nirsoft - New tool that calculates the network latency. Some details in this NirBlog post: New utility that calculates the network latency of every TCP connection. Looks pretty cool for you network troubleshooting and monitoring geeks.

TightVNC version 2.7.10. - What's New in TightVNC

LibreOffice 4.1 is here! - LibreOffice.org

LibreOffice - Home

LibreOffice Productivity Suite Download - LibreOffice

LibreOffice 4.1.0 Portable - PortableApps.com

Opera Next 16 hints at new features - BetaNews. I don’t really follow Opera web-browser development very closely any longer. Most of my time is focusing on Firefox/Chrome/Chromium/Internet Explorer. Hover there are some detail here that might be worth noting.

Network monitor debuts in latest Firefox beta - Mozilla Links. I really, REALLY like this addition…browser-bloat or not.

SMF v 5.0 – Search my Files - funk.eu - I’ve got more than many Windows file finders, searchers, and file indexing apps that I can summon at will. However funk’s SMF and NirSoft’s SearchMyFiles tools are my go-to file finders without peer. They both have been recently updated with loads new features and rather than see them as competitors, I see them as complimentary utilities depending on the search need at hand.

Intel® Driver Update Utility - Back while I was working on my “What is this “PC-Doctor Module” you speak of?” post, I noted Lavie’s system had the Dell Support Center software installed and how it can help with keeping OEM drivers updated. I checked my own system and the software wasn’t there. Maybe I uninstalled it? Anyway, this Java based application from Intel will do a scan of your system and report if any Intel-based hardware components are present and if a newer driver is available. Sometimes the OEM-branded driver will be preferred, however in most all cases, I have found the Intel driver is much, much fresher and more improved than the OEM version. Yesterday it told me my IntelProNic/WiFi network driver was way old so I updated it to the latest Intel driver version. No issues.

View DELL Service Tag and Express Service Code From Linux and Windows - The Geek Stuff.  Because sometimes it’s a hassle to flip your Dell laptop/desktop around to look for the codes:

1. Get DELL Service Tag on remote Windows system

Login to the Windows remote-host using VNC or remote desktop connection. Use WMIC on Windows to get service tag as shown below.

C:\>wmic bios get serialnumber
SerialNumber
ABCDEF1

Following WMIC command will give make and model number along with service tag.

C:\>wmic csproduct get vendor,name,identifyingnumber
IdentifyingNumber Name Vendor
ABCDEF1 PowerEdge 2950 Dell Inc.

If VNC or remote desktop connection to the remote-host is not available,  execute the following from the local-host to get the service tag of the remote-host.

C:\>wmic /user:administrator /node:remote-host bios get serialnumber
SerialNumber
ABCDEF1
[Note: Replace remote-host with the machine name of your remote-host.]

PeStudio 7.26 - winitor - (updated) - “PeStudio is a free tool to perform static analysis and investigation of any Windows executable file. A file being analyzed with PeStudio is never launched. Therefore, you can evaluate unknown executable files and even malware with no risk. PeStudio runs on any Windows platform and is fully portable, no installation is required. PeStudio does not change the system or leave anything behind.”


SoftPerfect Network Scanner - version 5.4.12 - a free network scanner, tweaked and updated. It’s one of my all-time favs.


Get the Start menu back in Windows 8 and 8.1 with Classic Shell - BetaNews - Tip from Mike WIlliams that Classic Shell 3.9 beta has improved their flagship tool for reclaiming the ground lost by users everywhere in the ongoing battle for Win8 Start Menu hill against Microsoft. I really like the way this looks. Pop over to Classic Shell directly to download the beta bits if you are interested. I find that I still (for now) prefer IObit Start Menu 8 Free for my Windows 8 tweaking. One of these days I’ll get caught up and empty out my lethargic Windows 8 post-launch pile-o-links that has more than a few additional alternatives. My little brother recommends Stardock’s $ Start8 application for what it’s worth.


Cheers.


--Claus Valca

Read More
Posted in browsers, Firefox, Internet Explorer, Link Fest, malware tools, Microsoft, networking, Opera, security, utilities | No comments

RoboCopy (& a few alternatives) for network file copying

Posted on 12:00 PM by Unknown

2zytnmnl.plbGrowing up as kids in Texas, children of an manager at a local oil refinery, in a town surrounded by oil derricks, pump jacks, and refinery noises and smells, it only made sense that one of the most fun games we had to play at home was King Oil. I need to see if mom and my brother know where our game set is being stored. Hopefully we still have it around!

These days, I wonder if someone should make a game called “King Bandwidth” with the goal to successfully manage the needs of the customers, the decisions made by web-based application programmers and OS updating, video feeds and training, “soft phone” communication software, and third party facility service operators who just assume that if there is a network available, they should have the right to hook into it for their own equipment provision and administration. Oh. And you need to manage all potential security threats as well.

One of the challenges we face in our environment is that some tasks for the system administration side of operations involves shuttling very large files across the network. If we do that during primary production hours we run the risk of slowing down the network for our users and the web/cloud-based applications they depend on. If we try it during off-production hours we often get slowed down running into automated nightly infrastructure processes that get priority scheduling.

What I was hoping to do was find some alternatives to allow us to “trickle” copy files around the network that would minimize bandwidth impact.

One might think that if running out of bandwidth is the problem, then just increase the bandwidth.  But as any sys/network admin knows, that gets very complicated very quick. Besides just the raw dollar cost of adding additional capacity (standard copper circuits, coax, fiber) you often have infrastructure costs for additional cabling, upgraded routers/switches, and the like. If you over-buy capacity, your wasting money and facing irate fiscal managers, if you under-plan for capacity you are looking at wasting money and having irate end users and other IT admins. Bother. It is a delicate balancing act to be sure.

So anything we can do to live within the existing parameters, but be more efficient is a Good Thing™ .

What would be great would be to find a file-copy/transfer tool that would support some argument options that respected bandwidth so we could “slow-copy” where needed or “fast-copy” when bandwidth wasn’t an issue.

The very first tool that came to mind was Microsoft’s (Robust File Copy) tool robocopy.exe.  What made this tool particularly nice is that is is Windows-native and is on almost all our systems already.

Robocopy - TechNet Windows Server & Robocopy - Wikipedia

Aside from all the powerful and cool features it brings, the one that really interested me was the following argument: /ipg:n - specifies the inter-packet gap to free bandwidth on slow lines.

Robocopy - SS64.com - More details on the cli usage and some examples.

One potential “gotcha” with Robocopy is that it doesn’t handle open files. From the Wikipedia article:

Robocopy will not copy open files. Any process may open files for exclusive read access by withholding the FILE_SHARE_READ[4] flag during opening. Even robocopy's Backup mode will not touch those files. (Backup mode instead runs Robocopy as a "Backup Operator". This allows Robocopy to override permissions settings (specifically, NTFS ACLs).[5] [6])

The Windows Volume Shadow Copy service is used for such situations, but Robocopy does not use it. Therefore Robocopy is not useful for backing up live operating system volumes. However, one can use a separate utility, such as DiskShadow.exe[7] (included with Windows Server 2008), to create a shadow copy of a given volume, which Robocopy can then be directed to back up.

Mmkay?

Updated: the exceptionally sharp TinyApps bloggist reminds us there are some great apps to help work around the locked-file issue with RoboCopy. For a full and amazing rundown of applications that can help and solution pop over right now (or at least bookmark) the TinyApps post Copy in-use files from the command line. Great tips and resources as always!

Other points to be aware of, Windows XP doesn’t come with it native, you need to get it from the Windows Server 2003 Resource Kit Tools then add it onto an XP system.

Beginning with Windows Vista through Windows 7 and 8, it was included as part of the base Windows OS package. That’s nicer.

All that to say that depending on where you got your robocopy.exe file, it may be one of several versions…each with their own slight idiosyncrasies;

  • Copy files faster in Windows 7 with robocopy - FAQforge
  • Robocopy Appears to be Broken in Windows 8 - Microsoft Community

So robocopy.exe may just be the perfect tool our sysadmins need to use proactively when copying files across our networks to play it safe. Only there is one small hurdle to overcome.

robocopy.exe is a CLI tool.  Not a nice, sweet GUI that many (but definitely not all) of todays IT folks are used to. In my mind, that is a major plus, but for some, eyes glaze over quickly…

Fortunately there is a solution for that:

Utility Spotlight: Robocopy GUI - TechNet magazine post from November 2006.  Robocopy GUI is an unsupported GUI wrapper for robocopy.exe

And under the “Monitoring Options” is the “IPG” field to manage copy actions over the network where bandwidth concerns exist:

14aqdblx.xfq

How great is that?!

The Robocopy GUI post notes that there is now a newer tool “RichCopy” that offers improvements over Robocopy GUI:

Free Utility: RichCopy, an Advanced Alternative to RoboCopy - TechNet Magazine post from April 2009.

A careful look in the overwhelming number of options it provides shows a “Trickle” feature under the “Mode” area.

d2iavwol.yjg

Unfortunately for us, while RichCopy may be a great tool in other applications, for this particular case, application documentation (and subsequent forum crawls) report the “trickle” feature is not supported.

3sy3f5ne.khd

More details on RichCopy here: How do I ... use RichCopy for high-powered file copy and transfers? - TechRepublic

So that brings us back to robocopy.exe and/or the RoboCopy GUI wrapper and the “/IPG:N” option to control bandwidth during the copy process.

From what I have read in the forums, there is something to a black-art of trying to best calculate the impact of the correct “N” value you are looking for.

Fortunately, the awesome crew at ZEDA.nl has some great tips and tools to help dial in your range finding.

ZEDA Windows Tip: Copy files on slow links - ZEDA.nl

The delay is calculated in the formula:
[filesize] / 64KB * IPG
A 300MB file and an IPG value of 500 means a delay of:
300MB / 64KB * 500ms = 307200KB / 64KB * 0,5sec = 2400 sec = 40 min.

Example

I copy a 300MB file over a 1MBit/sec line. If all bandwidth is available this will take 40 minutes; 1Mbit/sec = 1/8MB/Sec = 300MB/2400sec = 300MB/40min

Robocopy IPG Calculator - ZEDA Tools - ZEDA.nl - This tool helps automate the estimation of how long it will take to copy a particular file using Robocopy /IPG:N when provided the filesize, the current transfer rate across the network, and the IPG rate you provide. Pretty handy and cool.

Need more examples on how to use Robocopy? Then Bob’s your Uncle! (or rather PramodK who wrote and is actively maintaining it:

Robocopy and a Few Examples - TechNet Wiki

Not satisfied with either the robocopy.exe CLI or RoboCopy GUI tool?  Want some more options or maybe a better way to save you own advanced robocopy commands for reuse?

Here are some more RoboCopy GUI tools:

Better Robocopy GUI - CodePlex - “Provide intuitive GUI for editing optional parameters of Robocopy command line. It was designed for computer literates who like Robocopy but don't use it very often, and need to review legacy commands from time to time. This program is alternative to Microsoft's Robocopy GUI.”

WinRoboCopy - UpWay2Late.com Software - Though I can’t see where the /IPG:N option can be selected and called…you can however manually add it to your cli string.

Getting off the RoboCopy trail…

Up to this point I was specifically looking at RoboCopy itself, because being a “native” Microsoft application carries some additional benefits inside our organization.

However it that isn’t a concern, there are some alternative, third-party copy applications that may have some network bandwidth conservation options as well.

Ultracopier/SuperCopier - freeware - (Teracopy, SuperCopier like), replacement for files copy dialogs. It has an option under “Default options” to set a speed limit. More overview details in this AddictiveTips post: UltraCopier - Limit Speed & Pause / Resume File Copy Operation. Get the bits here: Download. And for more options, Download all version of ultracopier including a portable version.

Advanced LAN Pump - SoftSolo - ($$) - has controls for dealing with network bandwidth usage. Previous versions were freeware. If you want the last free version (v2.32) then you can grab it from The Portable Freeware Collection - Advanced LAN Pump.

I really started thinking about a blog post on this again after TinyApps.org bloggist posted some nice tiny apps for copy actions:

  • "Access is denied" when attempting to copy green files - TinyApps.org blog
  • FastCopy and Ycopy - TinyApps.org blog

So I reached out and TinyApps bloggist kindly offered the following additional gem of an application that I hadn’t yet found in a forum:

backup - How do you limit the bandwidth for a file copy? - Server Fault - comment left by user “levitation”

I use KillCopy for this purpose. I find it very convenient.
It has separate speed and other settings profiles for local and network copy.
It is also able to resume when a transfer of a large file (or files) is interrupted in case of bad connection, or even when the computer hosting the program crashes.

KillCopy - freeware - tiny GUI app that is skinnable and has advanced LAN speed control options

Advances settings:

    • Speed limit: You can limit maximum copy transfer speed in Kbps units or change what part of current traffic used by KillCopy.

LkN -where N - number 0..10 - speed limit in kbps (see following table)
LcN -where N - number 0..10 - speed limit in bps (see following table)
LpN -where N - number 0..10 - speed limit in % (see following table)

N

kbps

%

0

16

10

1

32

20

2

128

30

3

256

40

4

512

50

5

1024

60

6

2048

70

7

4096

80

8

8192

90

9

16384

100

10

No limit

No limit

Then again, if you just don’t care about sucking all the bandwidth from your site…

…and bringing down the wrath of the end-users and management, then these alternative file copy tools may also be worth looking into. Some have been previously covered here at GSD:

  • TeraCopy - (free for personal use) – Very nice, fast and tiny.
  • Copy Handler - (freeware) – Dependable and fast file-copy activity. Updated periodically.
  • Roadkil.Net's Unstoppable Copier - (freeware) – Special-use tool to get copy files that are “damaged" like off optical media or that give other programs copy-errors.
  • FastCopy - (freeware) - New to me that some claim is the fastest file-copier tool out-there today.

Finally, since we are way off topic now,

Windows 7 native file-copy process is a big leap forward over the XP dialog windows.

And Windows 8 takes it even further.

  • Windows 8 Explorer: improved copy, delete, and conflict resolution - ExtremeTech
  • Improving our file management basics: copy, move, rename, and delete - Building Windows 8 - MSDN Blog
  • Acting on file management feedback - Building Windows 8 - MSDN Blog

Which is one feature on Lavie’s Windows 8 laptop I am envious of that my Windows 7 laptop doesn’t’ have.

Cheers and again a special thanks for TinyApps.Org bloggist helping me to track down some additional alternatives to robocopy for file copy bandwidth management over networks.

Claus Valca

Read More
Posted in Link Fest, Microsoft, networking, tutorials, utilities | No comments
Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile