Bios Password

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Saturday, August 7, 2010

PC Troubleshooting and Hack-ups.

Posted on 2:28 PM by Unknown

Sometimes you can’t trust or rely on the data at hand.  Sometimes you have to dig deeper.

Sometimes you can be diverted from purpose by focusing incorrectly.

Case in point:

Yesterday I was having bad-awful issues with Firefox.

My blogging/browsing method involves dragging/dropping tabs for subjects/posts of interest as I surf and research over to my Bookmark Sidebar.  I have various folders set up for posts-to-be.

Only the drag-n-drop action was all over the place.  Sometimes I could place them where I wanted. Other times they would end up nowhere, or in a way-incorrect location.

It got so bad I started troubleshooting the issue.  I disabled add-on extensions one by one, changed themes.  Nothing helped.

I’d had something like that happen before with a bug in Firefox so since I was recently bumped to version 3.6.8 I figured that must be the issue.

So I built a whole new, ground-up, portable package of Firefox with a earlier version.

Strangely, the problem persisted.

By now at least an hour had passed.  I was getting no-where.

So I stepped back and let my brain relax…ding…could the problem be, literally, at hand?

I disassembled my optical mouse Logitech - LX7 Cordless Optical Mouse and examined it closely.  Sure enough.  When I turned the top lid over I could see wear had occurred on both of the piano-key like “hammers” that press down on the contact switches attached to the circuit board.

I thought for a moment how I could add some fresh bulk to them…but in a way that was “slick” and thin.  Digging through the tech-closet for inspiration I saw a bulk AAA battery pack.  It was made of clear thin plastic and had several flat sections.  I carefully snipped two tiny “shims” of material and then super-glued them carefully to the worn surface of the mouse-click “hammers”.  I then cleaned all the gunk from the innards of the mouse while they dried.

Reassembly was fast and testing found my “click/drag/drop” issue had vanished.

Inspired by that success and laden with leftover plastic I then removed the bulky shell of an old USB 2GB stick I’m using for Ready Boost but that blocks the other free USB port on the laptop.  I then made a clear micro-shell with remaining AAA battery cover plastic, barely taller and wider than the USB connecter itself. More super-glue and I now had a sweet, sealed, transparent USB stick cover on to protect the circuit board.  And my other USB port is fully accessible again.

Not a bad day….

By the way, since we are talking about data analysis of sorts did you see these?

  • CIA Software Developer Goes Open Source, Instead -- Danger Room | Wired.com
  • Collaborative Analysis of Competing Hypotheses -- available soon under GPL

I’m wondering how something like this might be able to be leveraged for forensics/incident response/IT Help Desk purposes.

Can’t wait to see the public release.

--Claus V.

Read More
Posted in hardware, troubleshooting | No comments

This Week in Linkfest history…

Posted on 1:44 PM by Unknown

Somehow I’m going to do it.  Even after spending precious energy and brain cells seriously updating the GSD blog.

…and it being my turn for the weekend “on call” duty worker coverage.

I’m going to drop a ton of linkage for you peeps.

More Network News

Fresh from the overwhelming Network Monitoring Madness: Poor Man’s Resources post come a few remaining items (there shall be stragglers in the ranks).

  • Capsa Free - Network Analyzer -- (freeware) -- Just this weekend, Colasoft released a free-edition of their Network Analyzer tool.  It does have a few limitation but is yet another GUI-rich tool that can do packet capture and analysis, similar to Network Monitor, Wireshark, OmniPeek Personal, or even my new best friend, the fabulous free PRTG Traffic Grapher.
  • Using High Performance Filtering -- Network Monitor Blogs -- even more tippage on how to get maximum capture performance under high-volume packet capture deployments.

More Remote Connection Management News

As we expand our ever-growing number of network analysis systems, the need for a unified way to access/manage them remotely is paramount.

To that end I’ve been personally favoring Microsoft’s RDCMan (Remote Desktop Connection Manager).  I’ve got (and continue to add) each of the remote systems to the side bar and can launch connections to them at will.

However a recent comment brought my attention to another recommended tool that is really featured so I’m relisting them all again here for reference.

  • Microsoft’s RDCMan -- (freeware) -- My #1 pick for Windows RDP sessions.
  • Avian Waves RD Tabs -- (freeware) -- A tabbed RD management tool that adds features such as (quoting) “…favorites with advanced editing, command line scripting, connection thumbnails, encrypted passwords, detached connection windows, remote desktop screen capture, remote terminal server information/management, RDP 6.0 support, and much more!”
  • mRemote -- (freeware) -- Another muti-tab remote connection manager.
  • Terminals -- (freeware) -- “Terminals is a secure, multi tab terminal services/remote desktop client. It uses Terminal Services ActiveX Client (mstscax.dll)”
  • Royal TS -- (free/$) -- Recently updated. Free version limits number of remote connections “per file”.
  • 2X Client Portable -- (freeware).
  • chriscontrol -- (freeware) -- not really a multiple-connection manager but does provide a way to flexibly connect to remote systems in some cases.
  • Remotely Enable Remote Desktop :: IntelliAdmin - (free tool) – Get the micro-file from this link: Enable Remote Desktop – Remotely (exe download-link from IntelliAdmin).  I tend to avoid direct links but the download link from their blog-post page actually points to their full-featured application, and not the standalone tool.

More Web Browser News | Mostly Firefox

Exciting news (to me at least) in the Firefox fronts:

  • Newsfox NEWEST - version 1.0.6.1.2 is out.  Tip: download the .xpi to your local system then from Firefox, use the File menu to open/install it.  This version prepares the way for compatibility with the current 3.6.x builds as well as the 4.x builds.  Up to now, despite really enjoying the Firefox 4.0b2 – “Official” x64 Bit Editions I’ve really stayed away from regular usage as NewsFox, my RSS reader, wasn’t compatible.  So finding this new build this weekend was joyous.  Also, I’ve found that many of the NewsFox Tweaks and Tips still work so keep tweaking!
  • The only thing holding me back from seriously “full-timing” use of Firefox 4.x x64 is the ongoing lack of Flash support in x64 browsers.
  • I’m going to eventually get around loading up the TabCandy Dashboard in one of these Firefox packages I use: Tab Candy, tabbed browsing evolved (Mozilla Links), Tab Candy – A Firefox Tabs Addon You HAVE TO Get (makeuseof) both go over the highlights.
  • I’ve had two weirdnesses happen this past week in web-browsing.  Yesterday it seemed like the majority of Google “extras” didn’t work in any of our browsers…drop down menus, finding more pages in the updated Google Images format.  That eventually sorted itself out so I guess it was an issue at Google’s end.  Also we are required to calculate mileage claims only based on “shortest distance” as calculated by Rand McNally.  Only it just so happened that the day our claim forms were due, the site was acting all zonky by only loading properly for IE6.  Not for Firefox, not for IE8, not for Opera, not for Chrome. Weird. So I ended up opening a Virtual PC tester that had IE6 to get the job done.
  • In the process of working out that item I found the Utilu IE Collection - Utilu.com which is an installation package set that will load all versions of IE from 1.0 to 8.0 on your system.  Now, that said, I really don’t recommend doing so on any “production” system.  I’ve tried it out using a Virtual PC VHD I have for such things.  I’ve read around on this and some folks report uninstallation issues as well as freaky things happening with their (primary) IE browser when/after it is installed/uninstalled.  However it was so cool I couldn’t help but mention it here.  For another source of IE builds check out evolt.org’s - Browser Archive for IE platforms.
  • 10 Browser Testing Tools: Roundup for Web Designers -- Bryan Connor has a list of additional tools that can be used to compare browser engine rendering.
  • Microsoft releases final IE9 preview, beta due in September - ZDnet. also Internet Explorer 9 Test Drive.
  • If You’re on a Firefox Beta, Get a NoScript Beta - hackademix - While you can always get stable versions of NoScript to use with your stable version releases of Firefox, if you are running beta/nightly builds of Firefox, bizarre things can happen.  So it is great to see hackademix pointing the way for us to his NoScript development build instead.

More Web Browser News | Strictly Chrome

I’m still nowhere near ready to jump ship from Firefox to Chrome full time, but I do find myself using the Chromium nightly versions in a portable version much more now.  It is a delightful browser to use

Here is the latest list of “add-ons” that I have found useful to load on it.

  • Google Chrome Themes Gallery - gotta get a theme.  I prefer the more toned down Google Themes rather than the “Artist” line.
  • AdBlock - Google Chrome extension gallery.
  • Atomic Bookmarks - Google Chrome extension gallery.
  • Browser Button for AdBlock - Google Chrome extension gallery.
  • ChromeAccess - Google Chrome extension gallery.
  • FlashBlock - Google Chrome extension gallery.
  • Create Link- Google Chrome extension gallery. Tip: I add an extra %text% line for plain-text only copy formatting.
  • Print - Google Chrome extension gallery.
  • Trash Can - Google Chrome extension gallery.
  • youtube-html5-chrome - Project Hosting on Google Code.

I’m running a portable version of Chrome built by Carsten “caschy” Knobloch that includes an multi-build supported updater in his Portable Chrome package: Portable Google Chrome 4.1.249.1059 (German site).  This has the latest full portable packages for download or you can simply unpack it and copy the single exe updater file to your existing portable Chrome package and use it from there.  It automates the process to check, download, unpack, and install the latest Chrome release versions into you portable Chrome folders.  Way too cool!  See this post Neue Version des Portable Chrome Updaters (German) for additional info on the updater proper.

Finally there is a new project that can update Chromium builds -- when installed on your system (not portable) -- Chromium Updater (via Google Operating System blog) project link: Chromium Updater.  For some other options see this Chromium Updater from mulder or my previous favorite tool Dirhael’s (portable) Chromium Nightly Updater.

System Building

It’s gonna be a while before I am able to upgrade my personal PC system.  I’m almost certain to go with some kind of a desktop-replacement class notebook.

However, it is still so much fun to read the exploits of high-end “home-brew” system builds.

Scott Hanselman (Computer Zen guru) has been on a tear on his on monster system.

  • Ultimate Developer PC 2.0 - Part 3 - UPDATE on Building a WEI 7.9 and RFC for building a GOM (God's Own Machine)
  • Ultimate Developer PC 2.0 - Part 2 - UPDATE and PODCAST on Building a WEI 7.9 and RFC for building a GOM (God's Own Machine)
  • Ultimate Developer PC 2.0 - Part 1 - Building a WEI 7.9 and RFC for building a GOM (God's Own Machine)

Then Pete Brown also got working on his own Ultimate-PC build.

And even our local Dwight Silverman kicked things off in his Operation Switchback.

Tools, Utilities, and Tips

Like shells (or tar-balls) washed up on the coast, these keep rolling in with the breakers!

  • Shotty -- (freeware) -- another simple screen shot tool. Spotted via Lifehacker.
  • RBTray -- (freeware) -- Tired of some applications minimizing to the Task Bar? Put them into the system tray instead.  Spotted via CybernetNews.
  • Gridy -- (freeware) -- tool to snap open windows to an invisible grid (also in portable version).  Like AeroSnap on steroids.  Spotted via Windows7hacker.
  • Updates: TCPView v3.01, Disk2vhd v1.62, AdExplorer v1.42 - Sysinternals Site Blog.
  • Bend - A modern text editor -- (freeware) -- a positively beautiful GUI with an almost zen-like quality.  Spotted via Tenniswood Blog.  Windows 7 only.  Stunning.
  • FREE: TeraCopy – Increase copy speed - 4sysops (tip) -- I’ve use TeraCopy along with a few other speedy file-copy tools, but it never seemed as intuitive to me to use as I would like.  4sysop’s post helps get past that and get it quickly up and running.
  • Regedit as offline Registry editor - 4sysops (tip) -- I’ve been mounting REG hives “offline” for a while now.  It was a bit awkward at first getting the hang of the process.  Michael’s walkthrough is direct.  See also: Edit the registry on a mounted WIM (Off Campus blog), and this SkullSecurity post as well if you need a few goes at it.
  • lessmsi -- (freeware) -- seems to have found a new home over at Project Hosting on Google Code.  It is a great tool to unpack/examine MSI files.
  • Dependency Walker (depends) -- (freeware) -- No not that Depends! -- Neat tool to scan any x32 or x64 Windows module and build a tree diagram of all dependent modules.  Really cool.  Related: How to debug application crash/hang in production environment? - MSDN Managed Newsgroup Support Team Blog

Finally, while I was off this past Wednesday as well, I spend a good part of the day remotely cleaning Dad’s PC from a rather painful Rouge Antivirus infection.  All was well and clean when I got done.  One of the tools I used, post-cleaning, to sweep things up a bit was CCleaner.

However I saw this week that a new “add-on” super-charges this already beefy tool:

  • CCleaner Enhancer -- (site down currently).
  • CCleanerEnhancer -- mirrored by ghacks. “Update: Website seems to be temporarily down, you can download the portable program from our servers instead. CCleanerEnhancer, and the current definitions file. Simply unzip that file into the CCleaner directory winapp2. The program cannot connect to the host right now, it seems to be using the website of the developer for downloading the signature file.”
  • CCleaner Enhancer -- mirrored by How-To Geek News. “Update 2: The mirror copy won’t work either, since the site is down. What you’ll need to do is download this INI file from my test machine and put it into your CCleaner installation folder. Once you’ve restarted CCleaner, you’ll see the new items in the Applications tab.”

It seems to be simply an supercharged .ini file that the CCleaner tool supports.

  • Add programs to winapp2.ini - Piriform Community Forums
  • Winapp2.ini for CCleaner - Pastebin.com

Still cool.

Windows UAC Revisited

It’s funny, with Vista I had to do a number of things to tame UAC.  Under Windows 7, I don’t even notice it and haven’t made any adjustments to the default settings.  Looks like the work reported in TechBlog: Microsoft reworking the UAC for Windows 7 by MS paid off.

I last really commented on UAC back in fall 2008 in this Speak of the devil: Norton’s UAC Tool GSD post.

The only thing I’ve noticed with UAC in Windows 7 is that some shortcuts will launch with a UAC prompt and others will not.

There’s now a tool to tweak those shortcuts:

  • UAC Trust Shortcut 1.0 -- (freeware) -- via IT Knowledge 24.  for x86 and x64 versions of Windows 7 and Vista.

Spotted via stadt-bremerhaven blog (German) as well as Technospot blog.

That reminded me of the TweakUAC utility I used to use on Vista (and you can for Win7 as well but why?).

Which reminded me then of Norton Labs and their Project "UAC Tool" which provided “whitelisting” for UAC control in Vista.

Which I also then spotted in the Labs this Project "Security Inspector" which audits your system for recommended security settings.  However the drawback is that it requires a copy of Norton Internet Security 2009 be installed locally.  Sorry.  And it does not support NIS 2010 yet either.  So now I’m wondering why I bothered noting this at all.  Oh well.

Maybe tomorrow I can post on some for/sec items that came up this week (with some super-cool finds btw) as well as a list of freeware tools I’ve been using to do DVD conversions (for our church-house produced DVD service recordings) and specifically Flash-format focused.

Cheers!

--Claus V.

Read More
Posted in anti-virus software, Chrome/Chromium, Firefox, Google, Internet Explorer, Link Fest, Microsoft, networking, NewsFox, Remote Support, RSS, troubleshooting, utilities, Windows 7 | No comments

Blog Reboot #2

Posted on 11:12 AM by Unknown

Fresh from last night’s Blog Breathing… GSD blog updating.

I’ve had a fairly decent night of sleep and have been hard at work on the additional design changes I’ve wanted to do.

I did change the overall “light-fonts on dark background” to “darker-text on lighter background”.  This should be better on the eyes by far.

Our resident graphic artist Alvis has been popping in giving me feedback and suggestions as well.

Most of the “Links” items and sub-categories survived, however I did add more than a few new items:  see the “Tech and Security Links”, “Life in Zen”, “Things to Motivate”, “Forensic Live CD’s”, “Software Sources”, “Guilty Pleasures”, and “Photography” sections for the super-duper changes.

I also successfully added the new “GSD Watch List” blog roll.  Blogger’s own gadget seemed to do the trick.  Only issue I have is that I have some awesome Microsoft TechNet blogs that it won’t add for some reason; Mark's Blog, Sysinterals Site Blog, MS Malware Protection Center, Network Monitor Blog.  I think it’s because of the way the blog home pages are addressed in a disallowed format: http://blogs.technet.com/b/blognamehere/   I’ve been unable to figure out a workaround for now so those had to get added statically up in the “Links” section.

I’ve noticed that Blogger platform now has the option to Create Pages in Blogger (more here Pages come to Blogger In Draft).  I think this might be a great way to add some static material pages for reference but I would need to do more organization.  What would serve me (and the faithful readers) best? Pages with lists of “best of” tools/utilities, wish-list, web-browser links (fav platforms/extensions), or useful CLI examples?  Or would those be better served under the Google Sites Grand Stream Dreams project site page instead?

We’ll have to see….

Cheers.

--Claus V.

Read More
Posted in Blogger, blogging | No comments

Friday, August 6, 2010

Blog Breathing…

Posted on 6:16 PM by Unknown

I’ve just made a few updates/tweaks to the GSD blog tonight.  Didn’t really plan on it but there it is.

I’ve removed the two-column sidebar and reduced it to a singe column.

That then allowed me to expand the blog post text area but about 25%.  I feel like I can breath again when I look at the posts.  Weird.

I also changed the font.  I down-sized it just a touch, but also with a new sans-serif style which I think works a bit better on the eyes.

I haven’t yet, but I may still change the post background to a lighter one and ditch the white text.  I fiddled with it just a bit before deciding to leave it as-is for now.

I’ve replaced the “blogged by” image on the sidebar lead and rolled it back to the original GSD kids.  I like the colors and it seems “lighter” and more cheerful and image.  My real-life expression is generally more stoic in nature (except when I’m flirting…apparently all the time according to Lavie) so I think the old “new” image works better here.  Fear not, no other meaning with this change; Lavie and Alvis remain attached to my side…both in the fantasy anime as well as in real life!

My next task is to seriously update the “Claus’s Toolbox” and “Links” links.    Most of the toolbox links still stand but I’ve probably added a few more GSD posts and such that warrant addition.  It’s funny that while I still have those Tweaking XP and Vista links, I’ve not done one for Windows 7.  To be honest there are really only a very few tweaks I make under W7.  Strange…maybe they got it “righter” in the GUI/interaction this time.

I’m also self-aware of some glaring omissions to this mis-match “blog-roll” of sorts.  I’ve got some favorite blogs that aren’t listed, and other linger on though I haven’t clicked through in ages.

I think the “New Gear and Gizmos” links section is about to be retired and replaced with a Forensics one.  That probably makes sense because I am much less “hardware” focused now.  And while I am no professional “forensicator” - to use a keydet89 term – I am doing a lot of network and incident response posts and related activities on my own work-bench so I think it fits.

Finally, I’m considering adding my own (again borrowing from the keydet89’s blog sidebar style) fav BlogRoll list.  I just gotta figure out which gadget he used…hopefully it is a Blogger one to make things easy…

So I’ll be working on these as well from time to time, expect to see a few more tweaking as the weeks go by.

Cheers!

--Claus V.

Read More
Posted in Blogger, blogging | No comments

Sunday, August 1, 2010

DCCU–Power for the BIOS!

Posted on 2:29 PM by Unknown

This past week as I was prepping and arranging for the deployment of some specialized network traffic capture systems a thought suddenly struck me; what happens if the power goes out?

These are “headless” desktop systems that are deployed along side our other network servers.  We had already deployed seven or so around our service areas and had lots to go.

I suppose we could request a local site user to go in and punch the “on” button for us, but we really want to keep the systems low-key and blending in with the other items.  And yes, they are on UPS units…but sometimes those don’t last for an entire outage period….

Wouldn’t it be nicer it there was a way they could “auto-on” if power was restored?  And/or maybe enable “wake-on-LAN”?  Or even auto-power themselves on (in the event of a extended power failure/recovery) at a particular time?

Turns out they can…via BIOS settings on these Dell systems.

I thus made the changes on those that were still on my desk waiting pickup for deployment.

But what about all those that were already deployed, or the many more sitting in a shelf already boxed up for deployment?  I didn’t relish pulling them all out again, just do do BIOS tweaks.  Nor did I want to drive all over the area, making BIOS tweaks on a single system.

Wouldn’t it be nice to update the BIOS remotely?

Guess what?  Because they are Dell systems I could!

Dell Client Configuration Utility – Dell

image

The DCCU tool is offered on the Dell Tools and Utilities page. It is a free administrative tool that allows you to “build” a custom executable package of BIOS settings and/or BIOS flash updates.

It supports Dell OptiPlex, Latitude, and Precision systems.  It does require .NET be present on the administrator’s system you are installing/building the DCCU packages with.  It does not need to be on the “client” systems you choose to deploy the packages on.

You can perform complex operations in each of the following BIOS areas:

  • BIOS Update – Yep.  Upgrade (or downgrade) your BIOS remotely.
  • BIOS Inventory – Collect a survey of the BIOS settings on the machine you run the executable against. Import the results file into the DCCU to read.
  • BIOS Settings – Make your changes/tweaks accordingly!

Once you have selected your options and rolled up the package, a single EXE file is generated which is custom to your choices.  It is extremely intuitive but it helps to know a bit which BIOS options your particular hardware platform supports.  Not all Dell BIOS options are the same from system to system.

However, if you don’t know, you can even use the tool to perform a “BIOS Inventory”

BIOS Inventory: No substantial changes from the previous version. This simple option creates an executable that you can run on the client. Running the executable creates a results file (TaskResult.xml) in the same directory as the executable that you can import into the DCCU to view the current settings and their various options. The only change now is that the executable file no longer self destructs, and this change allows you to run it multiple times.

Then, in my case, I just remotely copied the custom EXE package I built to each of the remote systems needing the BIOS tweaks.  I created a “dell_BIOS” folder on the root of the systems for the file, then I ran the executable.  It will unpack a load of files and then you can reboot the system.

Once the reboot happens, the BIOS changes are made and the system comes back up.  The files are removed except for just a few and this is how you know the changes were done.

Wicked cool!

It is very easy to use and very powerful.

Here are some additional links I found to give you a sense of what to do and how to use it.

  • Dell Client Configuration Utility 3.0 - The Dell TechCenter – With screen shots.  Here is the toy utility in all its power and glory!
  • Configuring the BIOS using the Dell Client Configuration Utility (DCCU) - The Dell TechCenter – Earlier version than the current DCCU version 3.0 A00 dated 10/09/2008) but gives you an intro.
  • Enable Wake On Lan with DCCU - The Dell TechCenter – This was one (of many) tweaks I did to improve system recovery and control in the event the system shuts down due to a power failure.
  • Standardizing BIOS Settings in a Dell Shop – Windows IT Pro article contains a few deployment ideas and tips for DCCU BIOS update packages.

How cool is this!!!

Cheers!

--Claus V.

Read More
Posted in hacks, hardware, Remote Support, utilities | No comments

Saturday, July 31, 2010

Network Monitoring Madness: Poor Man’s Resource Linkfest

Posted on 1:40 PM by Unknown

image

CC image attribution: Network by Claus Rebler – flickr

I had so hoped that the recent GSD Network Linkfest had covered all the necessary bases.

Alas, that was not to be the case.

Despite parking my rear-end on a beautifully constructed office furniture set (cardboard box empties) for the past week and a half on a network infrastructure installation project while the facility remains empty of occupants and furniture, I had to remain productive in my primary duties as well; one of which seems to be enhancing network monitoring and performing utilization analysis.  Sweet.

The Setup

To recap that post I’ve been struggling to get stable long-term captures using Wireshark, but was getting awesome performance and stability under the nmcap CLI version of Network Monitor.  (I suspect it is a hardware resource issue rather than an application issue.).

From there I typically import the resulting capture file into NetworkMiner, export the data I need with SysExporter, then do analysis in Excel.  No problem right?

Well, as I noted, Network Monitor doesn’t save in a .pcap-format.  And NetworkMiner doesn’t process .cap file format.

So I needed to figure out a way (if possible) do handle the conversion, CLI preferred.  And I did.  Sort of.

Network Monitor .CAP to .PCAP format conversion

I could launch Wireshark and import the .cap file, but for some reason, a significant amount of frame information was not being displayed as expected. Not cool or useful.

However, I found the trick in this D-Fens.net LogParser page, about half-way down:

NETMON as an input type

One note about NETMON: I assume nowadays the majority of people use Wireshark (or still Ethereal as it was once called) for capturing network traffic. LogParsers input filter cannot read these captures files. You can then either tell Wireshark to save the capture files as NETMON v2.x file format or better: convert the native pcap files to NETMON later on with "editcap.exe" which comes along with the wireshark package.

editcap.exe -F netmon2 wireshark-input-capture.pcap netmon-output-capture.cap

I applied it to some of my .cap files and it worked like a charm, quickly converting 450 MB size .cap file to .pcap in less than a minute or two. Seriously.

In my case the editcap CLI looked like this.

editcap.exe –F libpcap wireshark-input-capture.cap netmon-output-capture.pcap

I was so excited it worked!

However I did find a potential “gotcha”.  While my results worked great on the capture machine I was working on, when I tried the same thing with a .cap file on my own local system, it editcap complained miserably and would not do the conversion.

Turns out that on the remote system I had installed the previous “current” version of Wireshark, 1.2.9 and the conversion worked great.

However on my local system I was running the Release Candidate version of Wireshark, 1.4.0rc2 and the conversion failed.  Something appears to be different in the editcap.exe shipping and the way they read the .cap file format of Network Monitor 3.4.

See Also’s:

  • Editcap Guide: 11 Examples To Handle Network Packet Dumps Effectively – The Geek Stuff blog
  • Network Packet Dump – The Geek Stuff blog

I also found that InGuardians has a great tool that might also support conversion of Network Monitor 3.x .cap file outputs to .pcap: <--InGuardians --> Defensive Intelligence <Tools>.

Look closely under that page for the nm2lp (NetMon to LibPcap) tool.  From that page

While the NetMon UI has powerful features for analyzing packet captures, few attack tools include the ability to natively read from the NetMon stored capture file format. In order to leverage tools such as Aircrack-ng, coWPAtty and Cain for wireless analysis, the capture file format needs to be libpcap- compatible. Some tools such as Wireshark support reading and converting NetMon Ethernet captures, but do not correctly interpret NetMon wireless captures.

Fortunately, the NetMon API allows developers to write custom applications and interpret data from NetMon stored captures. Combined with the ability to create a libpcap capture file, it is possible to convert the NetMon file to a libpcap file. nm2lp converts NetMon wireless captures to libpcap format, making them useful in these other tools.

Also be sure to follow the link to read more about nm2lp in Josh Wright's "Vista Wireless Power Tools for the Penetration Tester" (PDF link) paper.

Be aware of the following bugs noted in the utility's “readme” file:

BUGS

+ Timestamps are messed up in the output libpcap file.  This needs resolution.
+ NetMon captures can include multiple link types in a single capture file, while libpcap
  requires the link type to be consistent for a single capture file.  nm2lp assumes the
  input NetMon capture file is all of WiFi link type.

It is a good tool, though I am squirreling away a few copies (exe installer and portable version) of the Wireshark 1.2.9 version until I can be sure that future versions of editcap will support the cap to pcap conversions I depend on.  If anyone can enlighten me on this observation between the editcap versions with some more background knowledge (I’m a noobie in this area!) I would appreciate it.

Network monitoring post interlude

I want to pause for a moment and digress.

Though I have been depending on NetworkMiner for my packet reassembly work, I’ve only been able to use version 0.88 on my XP SP3 systems.  That’s because as I posted in this cry for help to hjelmvik, for all later versions, when I load a .pcap file it loads fine in the application about 1/3 to 1/2 of the way then suddenly the program quits: no lockup, no crash, nothing. Just gone. Process Monitor traces find no smoking guns. I’m waiting for a response.

I suppose I could go to the more sophisticated app NetWitness Investigator which I do have installed and use for capture file analysis, but I just feel bonded with NetworkMiner.

I also found that hjelmvik has another project SplitCap - an open source pcap file splitter which looks interesting.

And while working out the .cap to .pcap method, I somehow stumbled upon the cool network application “Satori” which fingerprints network host OS’s based on network data.   Chatter on the Wire: OS Fingerprinting and Satori.  From the Software page description where you can download the file:

(July, 2010) - Uses WinPCap (almost all testing has been done with 4.1 beta 5 recently). This program listens on the wire for all traffic and does OS Identification based on what it sees. Main things it works to identify are: Windows Machines, HP devices (that use HP Switch Protocol), Cisco devices (that do CDP packets), IP Phones (that send out Skinny packets), and a lot of DHCP related stuff recently, plus some other things. Still early on, will make many changes and will add whatever features are requested, so just send them with packet captures if possible!

Download the zipped file, unextract, run the update.exe and grab the latest files.

It also is cool as Eric Kollmann has included a built-in component updater to ensure you are then downloading just what you need.

Check it out!

Finally, I’ve bookmarked Packet Life since I’m no network analyst though I’m not being paid as such to be one lately!  Gotta get up to speed somewhere!

RE: Port Spanning/Mirroring

I’ll leave out the juicy details on how we are getting our captures, but it is no real secret that it involves a system tied to a spanned port on our network Cisco switches.

As such here are some related materials on that subject for future refrence when needed.

…But first, read and review this brief TaoSecurity post on SPANs versus Taps: TaoSecurity: Expert Commentary on SPAN and RSPAN Weaknesses

It links to two MOST Excellent articles on the issues of using spanned switch ports for collecting your network capture data, both form Tim O’Neill:

  • SPAN Port or TAP? CSO Beware (by Tim O’Neill)
  • RSPAN … Friend or Foe? (by Tim O’Neill)

OK, now the linkage on SPAN’ing

  • Catalyst Switched Port Analyzer (SPAN) Configuration Example - Cisco Systems. A definitive resource.
  • Port Mirroring on a Cisco 3550 Switch -danielmiessler.com
  • Security Wizardry - Switch Port Mirroring
  • How to Configure Local SPAN Port on Cisco Catalyst Switch - ItsyourIP.com

And my oldies but goodies favorites:

CDP - What Switch Am I Connected To? and Monitoring Traffic with Span Ports – SynJunkie.  Two really great posts out of series of ones touching on network monitoring, and Cisco switch/router configuration techniques.  I’m singling these out in particular as they are of interest to sysadmin troubleshooting on the network as well as traffic captures.

More Network Monitor Capture Tips and Tricks

I’ve really been having a fun time writing out CLI examples of nmcap. To recap (copy/paste)  from the recent GSD post on this subject:

I found out from the NetMon 3.4 blog post that high performance captures, Microsoft Network Monitor 3.4 has a CLI component that can be used for GUI-less captures.  And it is also very sophisticated.

  • NM3 Command Line Capturing with NMCap – YouTube. Awesome introduction video to the options and power of NMCap CLI. Wow.

PaulErLong, author of the above tutorial has some other great helpful videos on Network Monitor 3.x usage as well:  YouTube – PaulErLong’s Channel

As an added bonus, you can type “nmcap /examples” and get a list of pre-provided examples featuring more advanced CLI usage of the tool.

Another NMCap trick: The Quick and Easy on Using NMCap to Create Circular Network Traces Based on File Size - Microsoft Enterprise Networking Team

Anyway, if you do decide to save your nmcap file output in “chunk” forms, you might need to also know how to reassemble it from the CLI as well.

  • NMCap: the easy way to Automate Capturing - Network Monitor Blogs
  • Chained Captures and Stitching Them Back Together - Network Monitor Blogs

That second post is very useful as it includes a roll-it-yourself batch file to automate the process of assembling chained .cap files.

Nice.

  • Using Color Rules to Show Direction - Network Monitor Blogs.  Ooohhh. Pretty colors!

More Network Odd’s ‘n End’s

Two extra bits of info I found this week:

  • TaoSecurity: Time Issues in Libpcap Traces – Mind your timestamps and how your tools interpret them!
  • Web Traffic Analysis with httpry – SANS-ISC Handler’s Diary

Additional (Free) Network Monitoring Tools

While monitoring router charts and looking for indications of traffic utilization issues, then firing off a packet capture session, and then later reassembling it and analyzing it does have it’s fun, this clearly is more of a “reactive” approach.

What is the poor-man (or woman!) who is a network analyst/responder to do when the enterprise budget doesn’t support a true enterprise-class solution for real-time network monitoring?

I’m in that boat right now and think I came up with some options that are surprisingly robust and useful…even to us non-professional network guys and gals.

Here are some I have found and like a lot (note: read and respect the EULA’s here gang!).

WildPackets OmniPeek Personal

This one is an oldie, having been yanked and replaced by WildPackets commercial grade applications years ago.  However, based on the reviews I read it looked awesome powereful for a freeware (for personal use!) tool.  Amazingly so.

  • OmniPeek Personal – free network monitor, better than Wireshark - 4sysops
  • OmniPeek Personal takes on Wireshark : Introduction – Tom’s Guide Review by Davey Winder

Unfortunately, as I've noted, WildPacket's seems to have removed the package from it’s website and most download links return back to WildPackets.  However, if you do a Google Search, one of the top three or so results might net you a working download link for now.

ntop/ntop-XTRA

I had come across ntop before as a network monitoring solution with Open Source support.

It looked really cool and robust.

Only one problem…for me…was that it was provided for Windows as a binary app with limited capture support (1000 packet limit).  To get the full version you can either register for a copy or re-compile the ntop source code yourself.  Something that some wiser folks have found fraught with headaches (recompiling that is, not registering…)

However, it turns out there was an OpenXTRA project hosting an NTop-XTRA build.  Perfect for Windows out of the box.

FREE: NTop-XTRA – Shows network usage - 4sysops

Only it has been killed.

Only again, with some Google searching and tips from 4sysops readers, there is (currently) an active link where NTop_XTRA_3_18_0.exe is still “hosted”.

Snag it while you can.  Right now!

Back? Good. Read/View on..

  • How to Install NTop On Windows - eHow.com
  • How to configure NTOP for Windows – YouTube video by GigaFinVideo

It also seemed to be providing awesome stats, though with not quite the same level of eye-candy and intuitiveness that OmniPeek Personal generates.

One potential “gotcha” I ran into was trying to log into the settings.  It wanted me to provide credentials.  admin/admin seemed to work fine though I’m not sure if that is what it was or that is what I was setting it to be!

PRTG Network Solutions

Another network traffic monitoring name I kept seeing was PRTG from Paessler.

Turns out that while they do provide enterprise-class network monitoring solutions with their PRTG Network Monitor application, they also provide some fantastic free network tools, frequently updated, free for personal and commercial use!  Now that is citizenship!

  • PRTG Network Monitor – See this more info and download page for the freeware version (limited to 10 sensors) download link and PDF manual documentation.
  • PRTG Traffic Grapher – Again, see this more info and download page for the freeware version (limited to 10 sensors) download link and PDF manual documentation.

Other free tools of note from Paessler are

  • Card Packet Counter – collect stats on network packets passed by a local network card.
  • WMI Tester – measure accessibility to WMI counters on systems.
  • Site Inspector – web browser that combines IE/Mozilla browser engines into a single platform for site analysis
  • URL Recorder – find the URL/POSTDATA strings passed by user when the browse a series of URLS. Might be good for malware/web forensics.

Even MORE (Free) Network Monitoring Tools

This is turning into a post Linkfest overload but it has taken me weeks to track all these down!

Why let them go to waste?

  • Show Traffic – By Demonsten at SourceForge.net
  • ARGUS- Auditing Network Activity – and ARGUS- Auditing Network Activity - Getting Started (check out the video in action).  Argus is a really detailed tool to monitor and process packet captures and then report it back in digestable methods.  Many sites use Argus to perform network activity audits.  Or as the main page says, “The audit data that Argus generates is great for network forensics, non-repudiation, network asset and service inventory, behavioral baselining of server and client relationships, detecting very slow scans, and supporting Zero day events.”
  • ArgusEye - A GUI for Argus
  • Periscope – Network monitoring application.
  • SecViz - Security Visualization – Site to discuss and view ways reams of data can be better visualized for analysis and understanding.
  • Isis: An Infovis System for Investigating Intrusions – Concept project information.  “Isis is an infovis system for investigating intrusions. It allows network security administrators to visualize traffic using timelines and event plots in order to reconstruct the sequence of events that make up an intrusion.” Seems interesting.
  • Zenoss Open Source Server and Network Monitoring – Neat and deep reaching platform.
  • OSSIM - The OSS Correlation and Security Suite – Hosted by AlienVault this is another fan-favorite and is very sophisticated.
  • SolarWinds is one of the enterprise-class industry giants in this field. However they do offer some free free tools beyond the trial versions.  Specifically worth looking into is their SolarWinds Free Real-time NetFlow Analyzer
  • Nagios – Hunt around and then find their Nagios Core OSS edition.  There is also a Nagios Core 32bit Windows Installer to check out.

Additional Network Monitoring Resources

Here are additional links that have a ton of resources for software applications as well as methodologies.  It’s a great place to get lost in.

  • ArcaneTek from LowTek: Network Analyzers and Top Talkers for Windows – My  original starting point for much of the follow-on tools listed in this post.
  • Top 6 Traffic Monitoring Tools – SecTools.org
  • Top 100 Network Security Tools – SecTools.org
  • Network Monitoring Tools – Clearly updated with love and OCD by Les Cottrell.  I promise your head will spin with the info on this page!

In closing (if you’ve bothered to read this far, thank you!) I do want to say this.

One of the challenges many of us in the IT shop have is convincing the board-members and holders of the budget strings just how critical software like this is.  Often we are tasked with solving a complex IT problem and have little or no resources (at the onset) to support us.

That includes not just day-to-day operations, but particularly network management and incident response.

Having companies and individuals who produce tools like these, and provide them for free (or even demo/trial versions) can really make life better for us all.

By being able to deploy them in real “live-fire” situations after some testing/vetting in a lab really allows us to then go back after a while and make the case with real data and real results why investment into a commercial/enterprise professional application might be a win-win for both the organization and the poor IT shop charged with the task.

So to all the folks named and un-named above who have or do provide these tools and services, for free/trial basis, I say, “Thank you.”

And to you in the IT shops who might come across this post…I hope you find something inspirational and useful.

Cheers!

--Claus V.

Read More
Posted in browsers, command-line interface, forensics, Link Fest, Linux, networking, tutorials, utilities | No comments

Sunday, July 25, 2010

Network Linkfest

Posted on 4:29 PM by Unknown

I decided these links merited a post of their own.

  • NetWitness Investigator – is a great freeware offering helping to decode and reassemble packets as well as traffic capture conversations in a clear manner.  Now there is news that in early August 2010, version 9.5 will bring some additional power to the people; YouTube - NetWitness Visualize.  The $$ pro version has even more astounding capabilities.  Can’t wait to see this one.
  • New NMAP Version Announced, Now At 5.35DC1
  • SoftPerfect Network Scanner – freeware – now at version 4.4.8
  • Decrypting SSL traffic with Wireshark, and ways to prevent it – WireWatcher blog. 

I really like the content on wirewatcher as Alec Waters does a fantastic job showing the capabilities of network traffic analysis along side with system analysis response.  I’m just a kindergartener in network analysis but the concepts and methodologies used by the professors are top-notch introductions to key concepts.  Added to my RSS feed list.

In other news,  our ongoing peak traffic capture work is netting some interesting results.

One of the observations is that our dedicated capture systems may not be robust enough to handle the volume of traffic the spanned port is throwing at them.  We have been using the latest stable Windows version of Wireshark but even though we set captures to run in “chunks” for limited periods of times, there have been multiple occasions when we return to the systems to retrieve the .pcap sets for analysis, it turns out the Wireshark capture crashed mid-way through the run.  I’m almost certain it is a resource issue.

So it was with interest that I read this post:

  • Reducing Dropped Frames with Network Monitor 3.4 - Network Monitor Blog

Recent Network Monitor builds ship with several capture filters, one of which is a “high performance capture” filter.  So I installed NetMon 3.4 on a dedicated capture system, got the latest parser sets, and then configured a test session to run at a peak time (around lunchtime at the remote site), and let it rip.

I came back an hour later and it had captured a tremendous level of frames, with no drops found….and it was still chugging away until I ended the capture session.

Nice.  I was very impressed with the results.

Only Network Monitor saves the captures in the “.cap” format, something NetworkMiner doesn’t handle.

Wireshark does, so I imported the massive .cap file into Wireshark, intending to then convert it into ".pcap” format, which NetworkMiner does recognize.  Unfortunately, I got the oft-seen Wireshark crash do to insufficient memory resources error.  Bummer.  I’ve gotten that before assembling chunks as well and in that case had to use the command line Wireshark tool mergecap to do so without memory errors.

So firstly, I’m wondering if maybe using Wireshark’s dumpcap to do non-GUI captures might be more stable for longer capture runs.  Figure I can make up some batch files for different scenarios and fire at will. And these would be in the .pcap format.

Also, secondly, I could possibly use the command-line tool tshark or editcap to do the .cap to .pcap conversions with fewer overhead resources were I to stick with NMcap as my capture engine?  Looks like I got some experimenting to do.

  • Wireshark · UNIX® Manual Pages has lots of tips for these CLI tools for Wireshark.

I’m also going to deploy and try the Wireshark Development Release version as well to see if maybe these builds help with the memory resource crashes I’m running into in processing the .cap/.pcap files in the GUI environment.

Turning back to Network Monitor…

Likewise, I also soon found out from the NetMon 3.4 blog post that for even higher performance captures, it also has a CLI component that can be used for GUI-less captures.  And it is also very sophisticated.

  • NM3 Command Line Capturing with NMCap – YouTube. Awesome introduction video to the options and power of NMCap CLI. Wow.

PaulErLong, author of the above tutorial has some other great helpful videos on Network Monitor 3.x usage as well:  YouTube – PaulErLong’s Channel

Definitely worth bookmarking and reviewing if you are new to Network Monitor usage.

As an added bonus, you can type “nmcap /examples” and get a list of pre-provided examples featuring more advanced CLI usage of the tool.

Another NMCap trick: The Quick and Easy on Using NMCap to Create Circular Network Traces Based on File Size - Microsoft Enterprise Networking Team

  • Microsoft Network Monitor 3.4 – Download – comes in both x32 and x64 bit flavors.

And the Network Monitor parsers on CodePlex are even more updated than those shipping in the NM 3.4 download package…

  • NMParsers - Release: Microsoft Network Monitor Parsers 3.4.2371 – These come in both x32 and x64 versions, of course.

Then before you leave, snag the following “Experts” that Network Monitor 3.x supports

  • NMTopUsers - Release: Top Users 2.1 – Look carefully as they have two sets, “Top Users by Conversation” and “Top Users by Endpoint”.  Again, both are available in x32 and x64 depending on which Network Monitor build you are running.

Goodness my head is spinning now!

So much work/learning to do….

--Claus V.

Read More
Posted in command-line interface, Link Fest, networking, tutorials, utilities, video | No comments
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

Popular Posts

  • New Year’s Day - First Post 2011
    Same day I came out with my first post after a long drought, I fell upon this article Blogging Seems To Have Peaked, Says Pew Report over a...
  • Oscar watch Linkpost
    Alvis and Lavie are watching the Oscars tonight and I’m along for the ride. I wasn’t able to come even close to getting out some of the pos...
  • Finally! Time to Post! New material list
    After a recent text from my bro reminding me it has been since March since I’ve done a blog post, I was finally able to clear the schedule a...
  • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA utility found
    A few weeks ago a new release of Ubuntu came out. Naturally that meant it was update time! I have been getting pretty good at this now so ...
  • iodd : Multi-boot madness!
    Like many computer technicians and responders, I seem to always have at hand a collection of bootable media; CD’s, DVD’s, USB-HDD’s, flash m...
  • Network Capture Tools and Utilities
    At a conference this week, we had quite a section regarding network captures. The instructor was going on about how you can try to sort ou...
  • It just has to be bigger on the inside…
      Last Christmas, Lavie gifted me with a cute little Jawbone JAMBOX unit. I thought it was pretty cool. It uses a Bluetooth connection t...
  • Mostly Minor Network Notes
    Here are some minor tweaks and features, mostly of a network nature. Manual Uninstall of the Cisco VPN Client « Mobile Expertise -- becaus...
  • Windows Live Mail error 0x80041161
    Dad is working with his father-in-law who has an issue with his Suddenlink web-mail-based “forwarding” handling of messages. Seems that (an...
  • FireCAT 1.5 “Plus” Add-On Collection
    In yesterday’s GSD post I noted the following: Both of these tools brought be back to the excellent FireCAT 1.5 collection of Firefox...

Categories

  • Active Directory
  • anti-virus software
  • Apple
  • architecture
  • art
  • AVG
  • Blogger
  • blogging
  • books
  • boot-cd's
  • browsers
  • cars
  • cell-phones
  • cheat sheets
  • Chrome/Chromium
  • command-line interface
  • cooking
  • crafts
  • crazy
  • curmudgeon
  • DHC
  • Dr. Who
  • E-P1
  • Education
  • family
  • Firefox
  • firewalls
  • For the Gentleman
  • forensics
  • Gmail
  • Google
  • graphics
  • hacks
  • hardware
  • humor
  • hurricanes
  • imagex
  • Internet Explorer
  • iOS
  • iPhone
  • iPod
  • iTunes
  • Kindle
  • Learning
  • Link Fest
  • Linux
  • malware tools
  • Microsoft
  • movies
  • music
  • networking
  • NewsFox
  • NFAT
  • Nook
  • Opera
  • organization
  • PDF's
  • photography
  • politics
  • PowerShell
  • recipes
  • Remote Support
  • RSS
  • science
  • Scripting
  • search engines
  • security
  • Shuttle SFF
  • software
  • Texana
  • Thunderbird
  • troubleshooting
  • TrueCrypt
  • tutorials
  • utilities
  • VBscript
  • video
  • Virtual PC
  • virtualization
  • viruses
  • Vista
  • Vista mods
  • wallpapers
  • Win FE
  • Win PE
  • Win RE
  • Windows 7
  • Windows 8
  • Windows Home Server
  • Windows Live Writer
  • Windows Phone
  • writing
  • XP
  • XP mods
  • Xplico

Blog Archive

  • ▼  2013 (83)
    • ▼  November (8)
      • Ubuntu 13.10 Upgrade - Lessons Learned & VIDMA uti...
      • ForSec Linkfest - 2013 DST Fallback Edition
      • CryptoLocker Ransomware Info & Free Prevention Sol...
      • Linkfest for the SysAdmins
      • Microsoft Security Essentials/Defender & PowerShell
      • Miscellaneous TrueCrypt linkage
      • PowerShell 4.0 and a tiny “gotcha”
      • New Software Updates + VMware Tools Update fix
    • ►  October (8)
    • ►  September (14)
    • ►  August (6)
    • ►  July (10)
    • ►  June (10)
    • ►  April (11)
    • ►  March (6)
    • ►  February (7)
    • ►  January (3)
  • ►  2012 (96)
    • ►  December (8)
    • ►  November (4)
    • ►  October (9)
    • ►  September (8)
    • ►  August (12)
    • ►  July (4)
    • ►  June (3)
    • ►  May (7)
    • ►  April (13)
    • ►  March (3)
    • ►  February (5)
    • ►  January (20)
  • ►  2011 (41)
    • ►  December (8)
    • ►  November (7)
    • ►  September (4)
    • ►  August (4)
    • ►  July (2)
    • ►  June (6)
    • ►  March (5)
    • ►  February (1)
    • ►  January (4)
  • ►  2010 (69)
    • ►  December (1)
    • ►  October (3)
    • ►  September (2)
    • ►  August (13)
    • ►  July (17)
    • ►  June (3)
    • ►  May (3)
    • ►  April (3)
    • ►  March (11)
    • ►  February (1)
    • ►  January (12)
  • ►  2009 (177)
    • ►  December (20)
    • ►  November (11)
    • ►  October (7)
    • ►  September (7)
    • ►  August (21)
    • ►  July (17)
    • ►  June (7)
    • ►  May (18)
    • ►  April (9)
    • ►  March (17)
    • ►  February (23)
    • ►  January (20)
  • ►  2008 (35)
    • ►  December (23)
    • ►  November (12)
Powered by Blogger.

About Me

Unknown
View my complete profile