Friday, February 15, 2013

Catching up

Erik has released a new version of caploader and you can find more information here.  One of the complaints I got when I posted about 1.0 was that people wanted a demo, and guess what, there is a demo version now along with a number of enhancements.

Most of my time of late has been playing with my Raspberry Pi and looking at different options I can do with it.

My main goal years ago for releasing my linux version of satori was to put it on a little system like this.  In that vein I've started looking at rewriting Satori in python and making the code available.  This has been a goal for a long time and is not going very far very fast, but eventually I hope to have something to release!

Friday, December 7, 2012

ICMP OS Fingerprinting

Interesting, this was in draft form, not sure how long it has been here, nor where I was going, but here it is as I left it.....

Quite honestly I thought ICMP based OS Fingerprinting was dead and had been for years now that almost all OS's default to running a firewall! I was quite surprised to see that NetScanTools Pro has an option in it to still do this.

Happened to pick up an article from Laura Chappell, which had a link to this quicktime audio: http://www.screencast.com/users/laurachappell/folders/Media%20Roll/media/75047d06-2801-49b7-87d3-0e41a3abd500

I really hate installing software that installs half a dozen other pieces of software (such as C++ Redistributable, I mean I understand why, but it just drives me nuts, I miss all inclusive programs)

Stuff in the Q...

These come into my google alerts some times, but I don't always get around to them very timely.

1.  This one was from back in Oct.  Memory-Only Operating System Fingerprinting in the Cloud

Has some interesting pieces of info in it.  On my list to get back to and actually read all the way through instead of just skimming it.

Abstract for those interested:
Precise fingerprinting of an operating system (OS) is critical to
many security and virtual machine (VM) management applications
in the cloud, such as VM introspection, penetration testing, guest
OS administration (e.g., kernel update), kernel dump analysis, and
memory forensics. The existing OS fingerprinting techniques primarily
inspect network packets or CPU states, and they all fall short
in precision and usability. As the physical memory of a VM is
always present in all these applications, in this paper, we present
OS-SOMMELIER, a memory-only approach for precise and efficient
cloud guest OS fingerprinting. Given a physical memory dump
of a guest OS, the key idea of OS-SOMMELIER is to compute the
kernel code hash for the precise fingerprinting. To achieve this
goal, we face two major challenges: (1) how to differentiate the
main kernel code from the rest of code and data in the physical
memory, and (2) how to normalize the kernel code to deal with
practical issues such as address space layout randomization. We
have designed and implemented a prototype system to address these
challenges. Our experimental results with over 45 OS kernels, including
Linux, Windows, FreeBSD, OpenBSD and NetBSD, show
that our OS-SOMMELIER can precisely fingerprint all the tested
OSes without any false positives

2.  I've been sitting on since back in September, though it may have been out much longer than that.  That was when the google alert showed up.

YAF does DHCP fingerprinting.  It appears tojust use the fingerprints from packetefence based on the writing, but it is nice to see another program out there taking up dhcp fingerprinting.

By looking at the order of the DHCP options in the DHCP requests from the Operating System's DHCP client, it may be possible to identify the client's OS version. The yaf DHCP fingerprinting plugin does exactly that. For flows that yaf has labeled as DHCP, yaf will look at the DHCP options if available in the payload captured for that flow. yaf specifically looks at Option 55. Option 55 requests a list of parameters. The order in which they are requested can usually identify the OS of the requesting IP address.

Sunday, November 25, 2012

SinFP and Syn/Ack fingerprinting

With SinFP3 v1.2 they claim to do one packet OS fingerprinting

"The latest version of SinFP3 (v1.20) introduces two new cool features: the ability to perform a SYN scan and doing OS fingerprinting at the same time. The idea is to use SYN|ACK answers to the SYN scanning process to acurately identify the remote operating system nature. The second new feature is a server mode allowing third-party applications to access the SinFP3 fingerprinting engine. We also created a new output plugin to display results in a simpler manner than in previous versions of SinFP3."

 It is cool that since they are already scanning the systems and looking for open ports they've added the ability to use the Syn/Ack response and passively fingerprint the return data.  p0f had a syn/ack feature and I added it to Satori back in the day, but I know p0fv2 didn't have a very big syn/ack DB and I honestly don't know how big Satori's is as I have it all rolled into the tcp.xml file. 

I need to look at their fingerprint file and see if it is something I can incorporate into Satori.  If it appears feasible to convert what I get back into the same format, i'll have to follow up with the authors and see about adding it in.  That just means finding time to play with SinFP now!  Not sure when that will happen, but added to the list.

Friday, October 5, 2012

Network Forensics - How to get better at

Ok, I like to toy in the network forensics world, but it is hard to get any better at it when I have so little time to dedicate to it on top of everything else going on with life and work!

Lets digress a bit, I like to play a game on facebook, almost 2 years sunk into it when I have spare time, called Battle Pirates.  In trying to track down an issue way back when the game started I realized that it sent some info in the clear about what was going on.  JSON files would provide you with whose ship was going across the map, where it was going on how strong the fleet was.  They might have a simple ship as the lead ship, making it look weak, but seeing it was a lvl 40 fleet you knew it was a farce.  I also realized I could see bases under their fog of war.  At the initial time the only way to find someone was to scout, remove the fog of war and find their base, but by scanning around the map, even with the FOW there I could still see underneath it because the data was on the wire to read if you knew how.

Eventually they lifted the whole idea of the fog of war and I stopped paying much attention what I could pull until I got bored with the game and was about to quit.  I noticed that I could actually tell, based on the JSON files exactly what was on a fleet when it was launched.  Once it was on the water all I could do was get updates on where it was going, etc, but if I was "watching" when it was launched, I could get exactly what was on it.  Only problem was it was in code looking something like this:
...[["create","oid",999999,"level",7,"on","Some User","type",3,"minidata",{"hullid":30},"x",999999900,"y",58500,"fleetid",3]],"updated_at":"99999999.837","transitionid":"99999999","data":{"fleet":{"mpm":0,"ships":[{"weapons":[104,112],"hullID":30,"tacticalModules":[],"armors":[303,303],"actives":{"flt":3,"fltp":1,"hp":192,"bid":99999,"f":1,"rank":5,"id":14},"specials":[550]},{"weapons":[121,104],"hullID":30,"tacticalModules":[],"armors":[310,310],"actives":{"flt":3,"fltp":4,"hp":172,"bid":99999,"f":0,"rank":3,"id":15},"spels":[550]},{"weapons":[104,121],"hullID":30,"tacticalModules":[],"armors":[302,302],"actives":{"flt":3,"fltp":2,"hp":132,"bid":99999,"f":0,"rank":5,"id":13},"specials":[550]},{"weapons":[182,182],"hullID":45,"tacticalModules":[],"armors":[312],"actives":{"flt":3,"fltp":3,"hp":362,"bid":99999,"f":0,"rank":0,"id":27},"specials":[530]},{"weapons":[182,182],"hullID":45,"tacticalModules":[],"armors":[320],"actives":{"flt":3,"fltp":5,"hp":225,"bid":99999,"f":0,"rank":0,"id":28},"specials":[500]}],"fspd":55,"adstats":[],"fnum":1,"mcap":28613,"fid":3}}


It provided me with where it was launched from, the rank and HP on the ship, the armor, any specials, and any tact modules along with the type of ship.

Only problem was looking through what I could find to translate those numbers to actual useful info.

I never did find it in the swf file, but didn't look too hard there, instead, little by little I launched my fleets, compared what I had on them to what it reported and built out a list.

I rarely use the program except to try to spot new ships being launched that I may not have, or to identify new weapons, armor, etc and then ask the people if they are ones I know.

My latest trick was to notice that at the end of the battle you can see what was on the fleet you just battled.  With that in mind and the tweaks they made today to BP, I decided to list out what was on the new fleets.  This is subject to change, as just before this writing, most Drac fleets disappeared off the map as I believe Kixeye may be revamping them due to outcry from those that don't like today's changes, but I digress.  Here are the ones I've checked so far (had to do this manually via a packet capture and my list of numbers as it wasn't programmed into my program to disect this):

29:
1 - LightCruiser (HP:980)
specials[Sonar3,SFB1]
weapons:[D53C,D53M,D53R]
armors:[Unknown93,Unknown93]
2 - LightCruiser (HP:980)
specials:[Sonar3,AA2]
weapons:[D71N,D71L,D71A]
armors:[Unknown93,Unknown93]
3 - Battleship (HP:3188)
specials:[Sonar3,SFB2,Autoload3]
weapons:[D71N,D71L,D71A,D53C,D53M,D53R]
armors:[Unknown94,Unknown94]
4 - Battlecruiser (HP:1478)
specials:[Sonar3,Eng2,HB2]
weapons:[D33P,D33A,D33P,D33A]
armors:[Unknown92,Unknown92]
5 - LightCruiser (HP:642)
specials:[Sonar3,AA2]
weapons:[D35S,D35S]
armors:[Unknown93]


37:
1 - LightCruiser (HP:980)
specials:[Sonar3,SFB2]
weapons:[D53C,D53M,D53R]
armors:[Armor93,Armor93]
2 - Battlecruiser (HP:1732)
specials:[Sonar3,HB2]
weapons:[D33P,D33A,D33P,D33A]
armors:[Armor93,Armor93]
3 - Dreadnought (HP:8749)
specials:[Sonar3,AA3,SFB3,Laser3]
weapons:[D53C,D53M,D53R,D53C,D93M,D93R,D33P,D33X]
armors:[Armor95,Armor95,Armor95,Armor95]
4 - Battlecruiser (HP:1732)
specials:[Sonar3,HB2,Eng2]
weapons:[D33P,D33A,D33P,D33A]
armors:[Armor93,Armor93]
5 - LightCruiser (HP:642)
specials:[Sonar3,SFB2]
weapons:[D53C,D53M,D53R]
armors:[Armor93]


45:
1 - Battlecruiser (HP:2546)
specials:[Sonar3,SFB3,AA2]
weapons:[D51L,D51A,D53M,D53R]
armors:[Armor95,Armor95]
2 - Battlecruiser (HP:2586)
specials:[Sonar3,AA2,HB3]
weapons:[D71N,D71L,D71A,D33P]
armors:[Armor95,Armor95]
3 - Battleship (HP: 5220)
specials:[RA3,Eng3,HB3]
weapons:[D35S,D35S,D35S,D35X,D35X,D35X]
armors:[Armor95,Armor96,Armor95]
4 - Battleship (HP:4515)
specials:[AA3,HB3,HES3]
weapons:[D33X,D33P,D33A,D71N,D71L,D71A]
armors:[Armor96,Armor95]
5 - Battleship (HP:4874)
specials:[AA3,SFB3,Laser3]
weapons:[D53C,D53M,D53M,unknown,D71A]
armors:[Armor96,Armor96]


55:
(1) - Battleship (hp:6378)
specials[Sonar3,AA3,HES3]
weapons:D71L,D71L,D71L,D71L,D33P,D33A]
armors:[Unknown96,Unknown96,Unknown96]
(2) - Battleship (hp:6258)
specials:[Sonar3,AA3,SFB3]
weapons:[D71L,D71L,D53C,D53C,D53M,D53R]
armors:[Unknown96,Unknown96,Unknown96]
(3) - Battleship (hp:6578)
specials:[Eng3,HB3,AA3]
weapons:[D33X,D33X,D33P,D33P,D33A,D33A]
armors:[Unknown96,Unknown96,Unknown96]
(4) - Battleship (hp:6258)
specials:[Sonar3,AA3,SFB3]
weapons:D53C,D53M,D53R,D71L,D71L,D93C]
armors:[Unknown96,Unknown96,Unknown96]
(5) - Battleship (hp:6258)
specials:[HB3,Eng3,unknown],
weapons:D35L,D35L,D35S,D35S,D35X,D35X]
armors:[Unknown96,Unknown96,Unknown96]


One thing I've noticed of late is the armor on the drac fleets is different than what we as players have access to.  Also all the drac hull's, while named the same, are different ID's so they may have different specs than the ones players have.  The weapons and specials, for the most part though all seem to be the same as what we have access to except for some of the weapons and tacticals that were in the last 2 raids. 

Ok, so what does all this have to do with Network Forensics?  Only that you have to get comfortable with looking at tons of packet captures and be willing to go back over them afterwards, because you never know what you may have missed in the past!  The fact that I could see launched fleets and killed fleets was there from my packet captures a year ago, but up until recently I hadn't see it because I was filtering it down to what I thought I wanted to see and missing what I really wanted in the process!

Monday, July 23, 2012

Revenge of the PDU

Your next PDU? Taking the wall wart to the next level. I've been thrilled to see the little wall wart devices for the past 2 years or so and been saying how much fun they'd be in a Pen Test. While this one isn't one you'd want to abandon, due to the cost, it is the ultimate in stealth!

Nothing like having a PDU with a built in computer that phones home!

So many ideas, so little free time....

Thursday, July 12, 2012

DHCP dll for Satori updated

Quick note, updated the dhcp dll Satori uses.  I'm getting ~10 times faster processing for DHCP fingerprints now!

Run the updater.exe and look for the latest!

Wednesday, July 4, 2012

Satori 0.7.4 released

Short Info:
- Had a request from Randy to add a "not" feature to the filter. Added that and fixed the fact that it only filtered existing packets, not new packets. Thanks for the suggestion! Usage is: ![var] or just [var], sorry no ability to use && or || type logic.
- Also fixed a bug he noticed in the MAC Vendor not showing up in cases where it did know it.
- Last but not least packaged Satori with InstallForge (http://www.installforge.net/).

Long Winded Info:
For those that don't want to do a full blown install, nice thing is InstallForge, while making it an .exe it is actually a .zip, so it can be extracted with any zip program. You'll end up with an extra dir, but works sweet even when using unzip.

I had a request to add the ability to do a NOT in the filter. Initially it was simple, the problem came with trying to get it to do more than just what was currently on the screen, ie all those new packets coming in at the same time. While the first piece of code was about 5 mins of trial and error and some logic issues, the piece to get it to update new packets was 3-4 of pain and suffering on my part. Nothing like have 7 year old code that you barely ever look at anymore and try to figure out everything that is actually happening there!

The same person pointed out a few other issues, one of which was that Satori sometimes shows the Vendor of a MAC, other times doesn't, with no rhythm or reason he could see. Initially neither could I, until I remembered that the DNS dll will put an IP down and if you end up going there later it will add the MAC. Problem was I wasn't doing a lookup then, just an update. Simple code change later and I think it is now fixed. Thankfully that was a 10 min fix!

And the last thing he noted was that the date/time stamp of files on my web server were sometimes older than local ones from an install. This has to do with doing the install via a simple zip file and when you extract it it takes "today's" date/time instead of the file depending on the zip program and its settings. It also has to do with the way I pull time locally vs remotely and GMT, so sometimes files are off by a day. While I didn't fix this entirely, I've wanted a decent and free installer program for a long time and I found InstallForge. Works nicely for what I need and I recommend checking them out and donating to them if you find it useful!

One cool feature of InstallForge is it is really a .zip file underneath, so for those of you that don't want to install Satori, you can still just right click on the .exe and tell 7zip, or whatever your zip program of choice is to unextract it and you should be good to go!

Monday, June 11, 2012

Adventures in new machines

Ok, switching to a new machine and moving all your tools to it always sucks, but really, I mean really, it shouldn't be this hard! I've been working on getting Delphi installed on my machine for the past 4+ hours so that I could start working on Satori again (yes it is written in Delphi, I still hate C and C++ though one of these days I swear I'll learn it). Ok, I'm running an ANCIENT version of Delphi, Delphi 6, but I refuse to pay $900 to get the latest version and since I didn't upgrade over the years I can't get by on the cheaper upgrade price of $500, or whatever it was. The saga starts, install Delphi 6. Program from 2001 or so, 1 CD install flies. Launch it, Windows 7 whines, Delphi 7 isn't supported.... Huh, this is Delphi 6, click past the stupid error and it works fine. It didn't like the debugger I don't think, but oh well, it installed. Oh new machine, Borland only lets you install 3 times or so before they make you email in on a rebuild to bump your license count. On a plus side, they got back in me in under 30 mins having bumped my license limit (thanks Bryce, very impressed). Ok, go to open Satori, missing VirtualStringTree, try to install that, missing XP Theme Manager, install that. Missing this component, then this, then that. Damn I'd forgotten how many little components I'd added to Satori over the years (time to write it command line only already, more on that shortly). While I was at it, oh lets go ahead and get the latest version of XYZ, hey why doesn't this work anymore, oh yeah, I'd added my own little code into their file for the convience factor since it needed extended. ARRGGGHHHH.... 4 hours later Satori opens and compiles again! YEAH! Satori cmd line - ok, I made a linux version 3 or so years ago, cmd line only, thinking of expanding that and doing a windows/linux version that is cmd line only. Been doing a ton of Snort stuff lately and the way Snort/Barnyard2/BASE all work together makes me think I should look at doing that again. Get Satori to just write to file as fast as it can, maybe doing the fingerprinting lookup, maybe leaving that to a 2ndary piece of software that would also dump it into a DB. Then get a pretty front end to read it near real time out of the DB. All a pipe dream now, no free time to do any of this, but it is on my mind to do one of these days. If I do do that, I'll be switching it all over to Free Pascal and Lazarus most likely or maybe I'll get real bold and convert the whole thing to C++, wouldn't that be a kick (why do I hate C/C++ so much.....). Anyway, long story short, Satori can be compiled on my machine again and maybe I'll do some updates. Oh and satori is getting used a bit more, more on that in another post down the road.

Saturday, June 9, 2012

Forensics Contest #10

Well it has been awhile since they released one to the public, but the Lake Missoula Group has released a new puzzle. Besides just network this time it appears to have some HD forensics required! If time permits I hope to get to this in the near future. You have until 7/23/12 to submit your answers. Contest #10 can be found here.