Saturday, January 14, 2006
DoD - Day 6 - The End...
The day started out early since I had to load up my junk because room checkout was around 11am when I would be in a presenation. After loading up, I headed over to Inverness Hall for breakfast and the "conference wrap-up." Nice things were said about everyone who participated and presented. Jordan and I won First Place in the Cipher Hunt challenge. Now that I think about it, I wish I had a copy of our challenges. Oh well. We received First Place medals in the DoD Cybercrime Olympics 2006 along with USB Aquariums. I received two nice certificates; a generic one for attending the conference and a very nice one for completing the 2 day Mac OS X Forensics class. Those were bonuses I wasn't expecting.
The first presentation of the day was "Identity Theft" by Kevin Mandia. Kevin is an awesome speaker. I was really impressed by his "stage presence" and comfort with the material. He went through a case study of a woman who had $50,000 stolen from her accounts which was later determined to have been accomplished by exploiting Internet Explorer on her computer and installing a keylogger. Great intro to people who don't do incident response and know the associated tools.
The second and last presenation focused on BitTorrent and forensics. It was quite and interesting topic. One of the dilemmas mentioned deals with how do investigators tracking down child porn deal with the issued of forced sharing when they are trying to download and verify potential child porn images. As soon as the investigator finishes downloading a file chunk, it is automatically shared out to others making the investigator a distributor of child porn. It raised several questions that I would like to research later on and possibly provide some help to the author and law enforcement (forensic) community.
I am now hanging out at my sister-in-law's house working on an article with a looming deadline but wanted to get in my last conference update. It was a great experience. I loved meeting all of the interesting people and look forward to keeping in touch with them. I am already anticipating next year's conference. Thanks to DoD, JTF-GNO & Technology Forums.
Thursday, January 12, 2006
DoD - Day 5 Update
The first presentation must have been specifically for law enforcement folks since it wasn't overly technical. Nothing wrong with that, but the title of "Hacking and Forensic Analysis of an iPod" made me expect more. The presentation briefly went over the partition structure of iPods, the directory structure, "hiding" files on it and using to boot Linux from an iPod. I know many others in the class got lots from it so I won't knock it. It just wasn't technical enough for me.
My second choice was a presentation by a lawyer from the JTF-GNO about the rights of system administrators to provide info to law enforcement and what info can be given. It was definitely interesting and raised a few questions I have for the university environment. Not much more that I can say about this one. I do need to review the slides as he did not go over all of them. Great information and excellent speaker.
The third presentation was by Thane Erickson who taught part of the Mac OS X forensics class I was in earlier. He was focusing specifically on Tiger things that were different and/or not covered in the previous class that was mainly on Panther. I learned about the difference in how passwords were hashed between Panther and Tiger, how to crack them, details about Spotlight and associated commandline tools and Dashboard Widgets with their associated forensic value. Excellent stuff. Thane is a good presenter and knows his stuff well. If you ever see him, make sure you tell him that LSU SUCKS!!!
Next, I went to a talk titled, "Daubert Digital Forensics." Since I am not LE, this presentation was just something I thought I might learn more about. I did take a few notes but did not find it overly interesting. Right now, I bet you are thinking, "Duh, it is legal stuff. Of course, it isn't interesting." Well, you have a point, but one day, it might be something I have to adhere to...but not yet.
After lunch with the FDLE boys, I thought "Digital Crime Scene Reconstruction" would be good with Fred Cohen. Hmmm...other people enjoyed it more than I did. His talk did a good job of validating the Daubert talk but his constant joking and goofiness turned me off. During the presentation, I ended up designing a future hacking challenge network layout for UF where I will set it up and challenge all L33T hackers at UF to penetrate. It should be fun.
My next choice was another bust. How did I keep choosing crappy presentations? It was Johnny Long presenting "Death by a 1000 Cuts." How could it be lame? Have you read "Stealing the Network: How to Own an Identity?" If yes, then don't go to this presentation. It is a rehash of one of the chapters and not very exciting. I really disappointed I chose it over Kevin Mandia's "Windows Malware Analysis" presentation. Johnny did get done 15 minutes early, so I was able to catch the last bit of Kevin's presentation which pissed me off even more that I chose the wrong presentation. I think by going to Kevin's "Identity Theft" presentation tomorrow, it will make up for it.
Finally, I caught the last hour of Bill Harback's "Examining the Windows Registry." It was FULL of windows registry information. Holy Crap! Bill went through so much in that hour, I would have had registry coming out of my ears if I had been there for both hours. Afterwards, he gave us updated copies of his presentation along with a free version of a registry tool that was recently purchased by a decently well known forensic tool company.
That's it for Thursday. The presentations I chose to attend certainly did not turn out as I hoped. Tomorrow will be better, especially since Jordan and I will be getting awards for kicking @$$ in the DoD Cybercrime Olympics. Now, I think I am going to drive over to Wing House or Hooters and work on an article for Secure Enterprise magazine that is due next week.
Wednesday, January 11, 2006
DoD - Day 4 Update
Next, I sat through two 2 hr presentations by Richard Beijtlich from Tao Security. Most people know him from from his extremely popular blog. Richard is a smart guy when it comes to network monitoring and incident response. To top things off, he is a fantastic speaker. His first presentation was on Network Incident Response and went through his standard incident response procedures. One issue he drove home with me was to not tip your hand when responding to an incident. Many times when I am incident handling, I will download the same tools that the attacker used which could easy alert them that I am tracking them if I download from a server they have compromised. There are two sides to the logic there but if there is a risk the attacker might do more damage because they know I am aware of them, they may retaliate. He also had some good ideas of how to implement a logging only server and incident response in general.
Richard's next presentation focused more specifically on forensics from a network perspective. He had some interesting thoughts on creating a ring-buffer type of full packet network logger that simply sits and records all network data in 1gb chunks and overwriting the oldest chunks. Applying the theory of computer forensics to network forensics, he reiterated several times that the key to successful investigations and prosecuting is developing a sound methodology and sticking to it every time. Most of the interesting examples and ideas can be found on his blog as he has posted them at some point in the past. I am glad I made it to both.
The fourth presentation was Xbox Forensic Analysis. No joke...it was a real presentation. Xboxes are beginning to show up more on forensic analysts' desks as they become used for more and more things. Someone playing a game online could be approaching an underage minor or they could have modded their Xbox so they can view illegal photos and videos. It was some interesting stuff. All in all, it makes me want to mod my Xbox even more. Since I have one that appears to have a bad BIOS, it needs to be replaced anyways...what better time to mod it. :-)
The last presentation was on something Jordan and I will be putting together soon at work. Creating a database and web frontend to hashsets. The idea is that known good and bad files can have hashes created and stored in a database. When investigating an incident, hashes from the filesystem can be compared to the database rule out files that are known good, identify those known bads and single out any odd ones not in either group. The whole point is data reduction so that more time can be focused on analyzing suspicious files than what is normally spent on identifying them. We think it is a rocking idea.
I was disappointed there were not many BoF (birds of a feather) sessions planned. Out of the whopping TWO, I chose the "Bring Your Foo: DoD Wireless Hacking Challenge." Come on, with a name like that, how could I resist. The only thing that I didn't consider was that I only had my 3 month old PowerBook with me and no L33T toolz. I was stuck running nmap across the network and trying to find the servers to be hacked. Dave, the Army CID dude running it, had intended on us being on hubs so we could do some passive recon to figure out what was going on within the network. Unfortunately, we were on switches and no person with an Auditor CD knew what to do with ettercap so we were a bit blind. After a hint from Dave, we knew that the servers were on an entirely different subnet. Again, I was still at a loss with only nmap and no Internet access to grab tools that I could compile on Mac OS X. So, just after I shut down my laptop, I noticed someone using Metasploit which reminded me I had downloaded it on my laptop. In a display of power rivaling that of the most L33T script kiddies, I owned two servers within minutes. Ipconfig on one of them showed it had two NICs with one on a completely different subnet from the first two. Geez. Dave put together an awesome challenge but we had limited time reserved in the room and did not get to complete the challenge. Oh well, it was fun and I have some great ideas for putting on a hacking challenge at UF's next ITSA Day.
That's it for me. I am tired, it has been another long day and I will be up early again tomorrow. Thanks for reading.
Tuesday, January 10, 2006
DoD 2006 - Days 2 & 3 Update
The last portion of the class was spent cracking the passwords. It was surprisingly simple. {I just edited this as I started to talk about a tool we used in class but realized it might be a violation since it is an internal tool for "Official Use Only."}. The passwords were pretty easy to get to and crack. I was quite surprised, but remember, this was done on Panther. The instructor said that Tiger has made some changes making it trickier...but not impossible. He will be giving a presentation in the next day or two about Tiger and specific forensic challenges such as this.
Monday evening, the expo began with a large list of vendors and some tasty food. There was a gimmick to get attendees to visit booths by giving out a list of the vendors and requiring their signature from 25 of them so you could be entered into a raffle. I finished it after listening to quite a few pitches but did talk to some interesting people. The turnout of attendees and number of vendors was quite impressive, and I walked away with some pretty darn useful tools and swag. I even got added to a mailing list, portal and magazine subscription that I probably wouldn't have access to if I wasn't here.
Day 3 - 01/10/2006: Today was the official kickoff of the conference with the keynote and headliners. Jordan and I missed the keynote because we were working on the Cipher Hunt challenge which required us to find clues all over the large Innisbrook property and solve the cipher on each one to find the next clue. With a little social engineering and good decipering skills, we kicked some but and were most likely the first team to finish it (but there may have been _1_ before us). This was also the only day they are feeding us all day according to the schedule. There was a nice breakfast, lunch and dinner in a walk_around_and_choose_what_you_want_to_eat_from_the_many_food_tables format.
Det Randy Stone gave a brief presentation about the BTK case and an intro into the forensics that helped catch the killer. It was quite impressive. Johnny Long gave a very amusing presentation on how Hollywood has portrayed hacking. It was damn funny as he went through examples from Hackers, Net Force, Swordfish and more. We were asked to choose if the portrayal was L33T or LAME. Holy Crap! We were all laughing! David Marconi spoke next about Hollywood villians. It was written up as being a talk about the future of hacking in the movies but I didn't see any of that. He was talking about having multidimensional villians and showed too many movie of these types of villians. Oh well, not great.
The evening had food, tickets for free drinks and more vendor action. At 6:30pm, they raffled all kinds of cools vendor-donated prizes. Do you think I won anything? Heck No!! Jordan won the _last_ prize to be given out...a Symantec engraved 20gb iPod Photo. After that, we had the Floppy Disk Throw as the second part of the Cybercrime Conference Olympics as a followup to the Cipher Hunt. We did a great job but there was some crappy judging, crappy distance recording, contestants who should not be eligible and shady score changes at the end. We should have been 2nd but were "bumped" to 5th. Even with that pile of crap, we should still be in the Top 3 and win some kick-butt prizes thanks to our excellent Cipher Hunt work.
It was a LONG day so I will be crashing soon. Sleep will not be coming soon enough. There is so many cool presentations tomorrow. It starts with Johnny Long at 8:30 and keeps getting better after that. I will keep you updated.
Sunday, January 08, 2006
Department of Defense Cybercrime Conference 2006
How is it so far? Well, if you haven't been to the Westin Innisbrook Golf Resort, it is a gorgeous place with lush golfing all around the resort. I have spoken here two years in a row for the FAEDS conferences and was happy to finally get to come as an attendee of conference where I can really enjoy the amenities. As for the conference, there are already quite a few feds lurking around the classes. The Mac OS X forensics class is quite good. I have enjoyed most of it and learned quite a bit already. Since the instructors are teaching from a thick book used in their two week class, they have to skim over some topics but I get to keep the book to review later on. Also, the book hasn't been updated for Tiger but the instructor has been doing a good job of pointing out any differences. One instructor is doing a Tiger-specific forensic presentation later this week so I might catch that one, too.
So, my initial thoughts...can I clone myself? There are so many presentations that I want to attend and so little time to fit them all in. About 8-12 presentations are going on simultaneously and I want to see at least 2-5 of them each hour. Luckily, I have been given the "Law Enforcement Only" CD that contains all the presentations, so whatever I don't make it to, I can look at the presentation later. Fantastic stuff. I will try to post every day what is going on and my thoughts about it all.
Monday, January 02, 2006
Performancing for Firefox
I was attempting to use the Developer Preview of Flock but it is still pretty buggy and does not compare to Performancing. If you are a blogger and use any of the supported blog software/sites, definitely check out Performancing. Thanks to Martin McKeay for mentioning it in his podcast.
Friday, December 23, 2005
Gearing up for the holidays!
Enough of my rambling...it is the Friday before Christmas and campus is dead. Time to go home and work from the comfort of my couch.
Merry Christmas!
Tuesday, December 20, 2005
Podcasts I Listen To...
I was planning on getting this list out last week but never bothered to sit in front of my desktop to look at the iTunes podcast subscriptions since I post to my blog from my PowerBook. So, here it goes. They are in alphabetical order thanks to iTunes. I will post my opinions and descriptions with each one. Note: This list and the links took quite a while to put together. I hope you find it useful. Disregard misspellings and such because it is late!
- A Day in the Life of an Information Security Investigator
- This is a fun and informative listen. It is based on the Chief's blog. The Chief, aka Security Monkey, talks about his cases as a security investigator, answers questions from his monkey (blog readers) and allows his right-hand man, Scrap, to rant. Definitely one of my favorites.
- Ancestor
- This is a podcast novel by Scott Sigler who releases a new chapter/episode every week. Another one of my top favorites. I really look forward to listening every Mon as the story unfolds. If don't mind some blood, gore and explicit language, check it out!
- Blue Box: The VoIP Security Podcast
- I had to catch up as I came into listening around the 8th episode. It is a good podcast about VoIP issues, current trends, new products and topics from the VOIPSA mailing list.
- Diggnation
- I enjoy just about every episode. I find myself laughing out loud to while walking around campus or having lunch in the breakroom. Kevin and Alex talk about the top "dug" stories from the site Digg.com. They provide adolescent humor the entire time making me wonder why I like it so much, but I think it just reinforces why I like it so darn much. The comic relief makes it one of my top favorites.
- EarthCore: A Podcast Novel
- This is the first podcast novel ever and Scott Sigler did a great job. I was always looking forward to the new episodes. It has ended and even become published because of the huge fan base. You can catch up on all the episodes as they are still online. This ranks in my top favorites. Plenty of blood, gore and explicit language.
- ITC: Security
- I keep this in my iTunes list in hopes that good stuff will come around again. There have been three really good ones that I have saved and sometimes relisten too. Most suck. The chick who runs the "security university," or whatever it is called, is a moron and conducts awful interviews. Check out the ones with Ron Gula and Dan Geer. I also have Bruce Schneier's in my list under ITC but can't remember if it was really that good.
- Martin McKeay
- Martin is a CISSP with a pretty good blog. He is focused quite a bit on the Payment Card Industry (PCI) regulations and has some good insight into it. I enjoy his blog and podcast but wish he would fix it so I could subscribe via iTunes. As he gets more into podcasting and decides more on a structure for the shows, I could see this as possibly becoming a favorite.
- Mighty Seek: WebAppSecurity
- There have only been a handful of episodes but they were pretty good regarding web application security. The host gets on his soapbox a bit but he has intelligent arguments. I hope to hear more good stuff from this one.
- Mommycast.com
- I started listening to a couple of these after I had begun downloading them for my wife. At the time, she was pregnant and I was able to use some of the things I learned from the podcast to immediately help her through the pregnancy. It has been a couple of months since I listened to any of them but keep them around for her and the chance I might be interested again.
- Network Computing | Security Channel
- I subscribed to this because it is done by a friend of mine. I have only listened to about 4-5 of them and enjoyed a couple. The ones that include interviews are usually the best ones. If you are of limited time and get bored easily, you might want to pass over this one. I do expect it to get better, but it isn't there yet.
- NotParanoia Podcasts
- I'm not sure I have made it through a full episode yet. The hosts are in Australia and England making the sound quality pretty shoddy. I keep it in my list so that one day I will go back and give it another chance. Maybe the newer ones have gotten better. YMMV.
- NPR: 7AM ET News Summary
- I am not a world news, or even a local news, nut. If the news doesn't come in a security related e-mail, I don't usually know about it. This is my weak attempt at knowing what is going on in the world.
- PaulDotCom Security Weekly
- This is a pretty decent podcast. I do get a little tired of the guys rehashing current security issues but it is fun to listen to their ideas. They tend to be goofy when referring to putting on their White/Gray/Black hats when discussing issues but I have hope that they will continue to refine their podcast.
- SABAGsecurity
- This is by two guys that work for McAfee. It is pretty good. They don't evangelize their products as much as you might think. McAfee product coverage is minimal with only talking about new releases or bugs. The rest of the time is spent on a topic of the week or month and current "notable" vulnerabilities. Not a favorite but it has potential.
- Security Catalyst
- This is a great podcast. Michael is a Lead CISSP Instructor who speaks and trains professionally. He has good insight into security topics, does not focus on current issues (thankfully) and has grand plans for his podcast. He is currently looking for a co-host and has an "editorial board" to help plan the episodes. Michael certainly puts a lot of time and effort into his podcast. I enjoy this one quite a bit and expect it to become a top favorite.
- Security Now!
- Ugh...I'm not sure why I keep this around. Steve Gibson is a smart guy but sometimes sounds like he needs to switch to decaf cause he gets talking so fast that he says the wrong thing. Now, I am sure it is simply because he is overexcited and confuses himself. But then again, maybe the fact the Leo Laporte is a computer security ID10T. Seriously, Leo is security stupid. It hurts me to listen sometimes. I don't think I have ever listened to a full episode out of boredom or disgust. I think I just keep it around for pure masochistic joy.
- Systm
- This is a video podcast that I have only watched one episode but plan on going back and watching. I have an iPod Photo so watching it requires me to sit in front of my desktop, which I don't do much anymore since thanks to my PowerBook. This one has some definite potential as long as Kevin Rose doesn't try to act too much like a "hacker."
Monday, December 19, 2005
Helix 1.7 is out!
Did you get the message? Neither did I. Helix is an awesome Linux bootable CD for incident response and forensics. On top of being a great bootable CD, it has an excellent Windows incident response side to it. Sort of a Dr Jekyll Mr Hyde type of thing. It is bizarre to me that such a nice update didn't get any fanfare. The Helix site doesn't even state that 1.7 is available. The forum mentions it and the changelog is updated but the page doesn't state the version or an updated file hash.
Some of the highlights of the update include Linux and Windows features. Some of the Linux updates include a 2.6.14 kernel, updated tools like Autopsy, Sleuthkit, Firefox, dcfldd, and new tools like the EnCase Linen Utility, tcpxtract and hfsplus for Mac drives. For Windows, a new GUI, log files saved in PDF, updated tools like WFT, FRED. and new tools such as IRCR, Forensic Server Project and FTK Imager.
Definitely check out Helix when you have time. It is worth your time if you do any sort of Incident Response or Forensics. One beef I have with Helix is the GUI under Windows. I posted a message in the forum to see if Drew would modify Helix's behavior to open a CMD prompt first and then let the user choose to run the GUI if they want. Why? The GUI loads into RAM and could potentially overwrite important evidence. I recommend going straight to a CMD, provide some scripts for imaging memory and local drives and then let users go into a GUI for more in-depth analysis...but that is just my 2 cents. Take for a spin and decide for yourself.
Friday, December 16, 2005
Knowing what's on your box...
Do you know what is running on your boxes? Really...are you sure? I was handling an incident today where a machine was compromised through a unnamed database running that was part of a terminal server application. The whole time I am investigating the compromise I was wondering if they knew the DB was running, and if so, did they think about whether or not it needed to be externally accessible and did they think that maybe it would need to be updated. Heck, maybe they thought the vendor who was using the DB would be responsible and provide updates to it. Beats me. As an incident handler, I don't always get my hands on the boxen that get 0wN3d. I get to provide the network forensic data proving it was compromised so that the system administrator can deal with it appropriately.
On a related note, the first alpha release of Metasploit was released yesterday. It is now based on the Ruby programming language which a friend of mine referred to as being as simple as writing pseudocode. I plan on checking it out as it may be applicable the the private hacking challenge I am working on. The whole point of this paragraph is that I was wondering if the release might have be why we saw the DB get exploited today. I haven't bothered checking all the new sploitz included in the the alpha release, but I can tell you that last year's big release caused a two immediate compromises of servers running the Veritas Backup Exec agent.
That's enough for now. I have to run home to get ready for a party that is an hour and a half away. I know I promised my lists of podcasts today but that will either have to wait until after the party or maybe later this weekend. TGIF!
Thursday, December 15, 2005
When to rebuild...
We have this little section in our policy that states a system must be rebuilt after it is compromised. In some situations, the rebuild will be at the discretion of the Information Security Manager. Unfortunately, system administrators like to argue about this or simply ignore it when it comes to malware. I have seen computer support technicians work on a spyware/adware infected box for THREE DAYS before finally giving up and rebuilding. Get a freaking clue people!!! The box could have been rebuilt using Ghost, Microsoft ADS or favorite imaging app in 20 to 60 minutes, yet you wasted 3 days. Holy crap! I seriously wanted to smack some of these people. There are some malware infections that are very simple to alleviate, but others are a real pain and most help desk people are not trained to deal with these types of things. I truly amazes me. I have had things handed to me that were not able to be "cleaned" by the help desk that I solved in 5-10 minutes yet spent the next 30 minutes verifying that it wasn't something more sinister. Rootkits are becoming more prevalent and more malware is using a "rootkit" driver to hide their processes so why not make it easy on yourselves. Spend some time developing a process where you can burn your systems down to a wiped disk, apply and image or slipstreamed OS/app install and be done with it.
Geez...enough ranting. I need to work on my list of updated tools to put on this site but that probably won't happen until next week. I will have my podcast listing up tomorrow.
Wednesday, December 14, 2005
Crime Scene: What to do with a running system?
Are there any forensic specialists out there that analyze a machine while it is running at the crime scene before pulling the power? Why I am asking? I was sitting in a presentation this morning by a law enforcement officer who is said to be a court certified computer forensic expert. He stated that a machine should have its power cord unplugged upon seizure. Someone asked about dumping memory and his response was that it was saved in swap space and will be intact. I don't want to get into why this is not true, but I am curious how many people do live analysis before taking down a system. There is lots of juicy info available in memory and will be lost as soon as power is gone. Of course, if you have an idiot in front of the keyboard, more harm than good can be done. For a trained forensic specialist, I think they could get important information from the live system, document EXACTLY what they did and it hold up in court. Any thoughts??
Tuesday, December 13, 2005
CISSP - To Be or Not To Be...
I am seriously considering getting the CISSP. Why? Well, I almost feel like I am missing something by not having it. One of my good friends, whom I respect as a security professional, has had it for a couple of years. There are also two podcasts that I listen to regularly and both individuals are CISSP's. The content of the podcasts are excellent. Specifically, the Security Catalyst is excellent and put on by a CISSP trainer. His insight and topics are very good, much better than most of the podcast and blogs that I read. Of course, that could be a singular instance and not an example of most CISSPs.
I was at a SANS conference last year where I was hanging out with two really sharp fellows when we weren't in the forensics class. We were having sushi and beer when the topic of CISSP came up. They were shocked that I didn't have it yet when I have more advanced certs already. They equated it to a kind of "foot-in-the-door" cert that recruiters look for when scanning applications. I shrugged it off thinking my more technical certs should outweight the CISSP but I am now reconsidering it.
This post is probably more than I want to devote to this topic for now until I talk to a few more friends in the sec biz to get their opinions. There will be a follow-up post about this later along with a post listing all the podcasts I listen to.
Monday, December 12, 2005
Easier & More Efficient Blogging...
I have been wanting to blog more often because I feel like I have lots of interesting things to add to the security world but find going to Blogger to be a small hurdle that prevents me from doing it. That is a truly lame excuse but it has been enough to cause me to search for more efficient blogging methods. I am now testing Flock, a new Open Source web browser designed to "make it easier to blog, publish your photos and share and discover things." If this is successful, you will start seeing daily blogs from me...which may lead me to my eventual goal of developing a podcast.
Wednesday, November 02, 2005
HOORAY! Mac OS X Update 10.4.3 LOVES Virtual PC 7.02 for Mac
Since I delved into the world of Apple ownership, I was frustrated by the lack of *real* support for Microsoft's Virtual PC for Mac. It could simply be that people don't use it very much...better yet, security professionals and hackers don't use it very much on Macs. That is probably true because finding solutions to problems with it is far from easy compared to VMware.
I still haven't found the solution to my problem with having full network access to the Virtual Machine while it is in "network sharing" mode (aka NAT). BUT, the update to 10.4.3 fixed the Virtual Switch!! What does this mean? Well, the Virtual Switch lets your Virtual Machine get an IP as if it were on the LAN right next to your host machine. Now, when I boot up my Virtual Machine running FreeBSD 5.4, it gets a private IP address on the UF network just like my PowerBook. This gives me the chance to connect/exploit services on the Virtual Machine and thus bypassing the "network sharing" issue. Thanks, Apple, for fixing this issue!!
Monday, October 31, 2005
Quick Book Review: "Stealing the Network : How to Own an Identity"
Friday, October 28, 2005
What is going on with me? Updates are here!
Work is great! I am really enjoying my new position on the UF Security Team within the University of Florida. Our website is a little weak right now, but we have a Public Relations person that was hired just before me, and it is one of her projects. I hope to assist and provide information on secure OS builds, incident response tools and procedures, possibly even a security blog...but that might not fly.
I have settled in pretty well with my new Apple PowerBook. It has taken some getting used to. Compiling different forensics tools has not been a problem. I did a quick test of MetaSploit Framework 2.5 and it seemed to work fine. Working within Virtual PC is limiting compared to VMware, but I am getting by OK withing snapshots. :-( I was surprised to find that I could install FreeBSD 5.4 in it.
My coworker Jordan and I are working on "Hacking: The Art of Exploitation" with some guidance from our friend Atlas we met last year at a SANS conference. Atlas was first place individual (Ronin) and third place overall in Capture the Flag (CTF) at Defcon 13. It is very cool stuff. Some of the examples work on MacOSX while the rest I have had to SSH into a SUSE 8.0 Linux box. Oddly, the examples don't work on my SUSE 9.3 box, which I think has to do with some sort of kernel setting for exec-shield, but I don't know yet. I am looking forward to getting into working on real executables...like the ones from CTF.
What else? I am DJing again this weekend at a Haunted House in Orange Park. My daughter, Gabriella Skye, is almost 5 months old. I am drinking coffee daily again, more water, less soda.
I think that is about it. I promise to start posting more technical stuff. My goal will be at least once a day during the week depending on if I am in the office of not. Have a great Halloween!!!
Thursday, September 29, 2005
My New PowerBook and MS Virtual PC vs Snapshots
Where am I going with this? Well, I love playing with malware and testing incident response techniques on virtual machines. My first love is VMware but there is no Mac version so I am forced to use MS Virtual PC. Unfortunately, it doesn't do snapshots like VMware...BUMMER! I'm not really a fan of undo disks but it maybe what I am forced to do. One idea was to use a tool like Deep Freeze or ShadowUser to lock the system so that any changes were undone with a reboot which is a bit like a costly version of undo disks. I am going to test each method and see which is the easiest and most efficient. Until I decide, I will be making duplicates of my VPC files, working on the dupe and deleting it after my test.
ADDENDUM: I have settled on Undo Disks. The additional software adds a level of unneeded complexity and that is something I definitely don't desire when doing malware analysis. One feature I found during testing is the ability to carry forward changes during reboots when using Undo Disks. Sometimes it is necessary to reboot during analysis to see how malware will react...nice feature! One thing I did not check was how this affects booting up with Helix and dd'ing the hard drive. That is one more test to check. :-)
FAEDS Presentation
Monday, September 12, 2005
Memory analysis
So, where I am going with this? The Digital Forensic Research Workshop (DFRWS.org) held their conference in Aug where they put on a forensic challenge based on memory analysis. Two entries received top showing on their website and each contained custom programmed tools to parse memory. The real question is will they be releasing these tools. Kntlist looks like it might be a commercial tool written by George M. Garner, but the more interesting tool (or possibly easier) is memparser which rips through a memory dump and pulls out process lists and detailed info about individual processes. Check out the DFRWS site and look for the memory challenge results.
