Wednesday, February 25, 2009

Cool little device

Ok, nothing to do with OS Fingerprinting, but since I've been looking into Pentesting so much lately also, when I saw this post earlier today on Twitter by Hal, all I could think of was how much fun one could have with one of these!

http://www.linuxdevices.com/news/NS9634061300.html?kc=rss

These devices are getting smaller and smaller all the time and cheaper and cheaper.

I'm waiting to see one with two ethernet ports on it, basically an internal switch so that you can drop one of these behind someones desk, plug their computer feed into your device, a short cable from the device to their computer and then have this thing phone home and open some type of door for you.

As it is now that could still be done easily enough with it, but you also have to find a network port that is live. Adding the internal switch would just make things easier.

Tuesday, February 24, 2009

Insecure Magazine, os fingerprinting and xprobe2

The latest version of (in)secure was released here recently. The first article this month was on using a new version of xprobe2 to do fingerprinting. Sounds like some new features have been added and some cleanup has been done.

Looks like the next release is due out in June of xprobe

Sunday, February 22, 2009

EDHCPFingerprint & EFFormat

Both programs from enterasys have been updated again! They've been busy. Main change I know about is a repository.xml file that is generated. It looks to see what names show up across multiple .xml files (tcp, mac, dhcp, smb, etc). It was a very useful feature in cleaning up some of my files. Some of which I'm not even using yet, but that I've been adding to from time to time in the past and hope to use in the future!

I've pretty much started using EFFormat full time now in editing my fingerprint files!

As always, they can be found here at enterasys

Updated Software

Satori updated to version 0.62. Lots of new fingprints added and others updated. Took like Linux distro's and combined them where it made sense instead of having 5 fingerprints that were all the same because they were based on the same distro. Also added the packetfence fingerprint info back into my dhcp.xml file. We'll see if the packetfence project starts using the .xml file or not, it has been discussed in the past and may be being looked at again. We'll see.

With the addition of these fingerprints back into dhcp.xml I decided to give the user a few more options in parsing dhcp fingerprints. You'll find it under options. I also added a new feature for arp parsing also since it was in an 'addon' dll instead before. Now it is just an option.

Last major change was an update program. It is a stand alone program that will update the .exe, .dll, and .xml files. It is nothing fancy, but it gets the job done. It will let you keep up to date on the latest fingerprint files, dll's, etc without me having to do a full new .zip file!

Saturday, January 10, 2009

EDHCPFingerprint & EFFormat

As mentioned previously we've been busy recently on the fingerprint files. Jeff of enterasys has been quite busy on 2 programs this past month.

EDHCPFingerprint - reads in the dhcp.xml file and an exported tcpdump file of bootp packets in text format and will determine the OS based on that. It also has some other cool export features.

EFFormat - reads in all the .xml files that I have built for satori (some that I'm not even using yet) and allows you to modify them. I have a built in version in Satori that sorta did this, but nothing as nice!

Both programs can be found at Enterasys Tools page.

Due to all the recent work on these files we of course found and cleaned up a lot of old fingerprints that were inaccurate or did not provide enough info anymore. There has also been a few new fingerprints added. So the fingerprinting based on DHCP should be more accurate.

Wednesday, December 24, 2008

EDHCPFingerprint

Jeff from Enterasys has been working with me and Erik (author of NetworkMiner) on tweaks to the dhcp schema. A lot of it was changes they wanted to see done to help extend it out. I was just the middle man since I own the file! :)

These changes will come in quite useful, in different ways, to all of us and I'm glad they were made. Hopefully we've finished for now with the latest change being done earlier this morning.

In the near future, hopefully I'll start leveraging the new info included in it better. Just need time!

Anyway, check out EDHCPFingerprint if you get a chance.

Wednesday, December 17, 2008

Updated Software

NetworkMiner -
Ok, been spending a lot of time trying to crash NetworkMiner for the author. Found a nice little bug he had going and a quite a few crashes. All of those are fixed in 0.87 which was recently released. If you are using NetworkMiner I highly recommend updating to the latest version to fix the nasty little bug earlier versions had on saving files.

Satori -
also been spending a lot of time with Erik, author of NetworkMiner, and Jeff (from a private company) on updating the dhcp.xml file schema. Jeff had a lot of good recommendations and has provided a few new fingerprints. Between the 3 of us we updated the schema to a very good 1.0 version I think. I may do an overhaul of it a year or two down the road to add some other functionality into it, but we'll see. Anyway, the new version allows us to group Devices much nicer than before. For Satori it will give me the ability to group Devices across fingerprinting files (dhcp, icmp, tcp) since all 3 have been updated to the new format. Not sure when I'll add the functionality to utilize it, but it is updated along with the removal of a lot of old information in the dhcp.xml file that came from the packetfence.org project. It was nice to have at one point, but since they do not track if it is a dhcp inform/discover/request packet, it doesn't do me any good anymore, so it was removed, along with some other fingerprints I got from files around the same time and did not get everything I needed!

Always looking for new fingerprints. And on that note, I setup an account dhcpfingerprints [AT] gmail.com specifically for fingerprints, originally for dhcp ones (since that is how most people keep finding out about Satori), but will probably use it for all fingerprints.

Saturday, November 15, 2008

Twitter

Well finally decided to setup a twitter account. Long story short, someone got a hold of me mentioning my DHCP paper, he was one of the original authors from KU on it and mentioned my paper was mentioned by yet someone else on twitter. Decided it was time to check it out.

My site probably will never see postings, but who knows. I'm basically just using it to follow some other sites, which I could probably do via other means, but....

Saturday, November 8, 2008

Active AP 802.11 Fingerprinting

Toorcon recently seems to have had a presentation on Fingerprinting APs to see if they are ones you should trust. (Click on the Title to see it)

Some interesting tests by tweaking flags sent and doing clock skew tests. Looks like it may have also been presented at Blackhat and ShmooCon also this year.

The presentation material for Toorcon seems to be a little longer than the ShmooCon one, though ShmooCon's seems to have a few different slides in it. Didn't go looking for it at Blackhat.

Makes me think I should work on getting Satori to be able to use my AirPCap adapter and start working at breaking down those 802.11 packets!

Advanced application level OS fingerprinting

A short (36 pages or so) powerpoint type paper on Application Level Fingerprinting.

I found it interesting how, depending on the OS the application was running on, it would act differently depending on what was sent at it. After doing some of this for going on 10 years, I'm surprised to find that I'm surprised by it, but I was.

Anyway, seems like a nice writeup on a new way of thinking/testing a few things. If I was still big into Active Fingerprinting I may have had to try to expand on this, but for now, I have enough projects.

Check it out. And if you don't like pdf's, check out the original post at SecurityFocus and grab one of the other formats. Otherwise click on the Title up top and you should hit the pdf version of it.