Jeff updated the fingerprint editor he wrote that I utilize for .xml editing of the files Satori uses. We got the Terms of Service inputted into all of the .xml files now and the UTF-8 encoding fixed with saving of the file when the TOS is there. Some other minor fixes/updates as I believe.
Thanks for the changes!
Monday, March 26, 2012
Wednesday, March 7, 2012
Satori - update 0.7.3 and most dll's recompiled
I'm busy taking the SANS 503 IDS course, one of the things we do in that course is look at BPF style filters. Low and behold, I use these in Satori to do some prefiltering of packets before Satori hashes through them. While I have complete confidence in my coding skills (brief pause as I control the hysterical laughing fit I've found myself in), it never hurts to preprocess the packets before I get them.
History on the filters, we'll look at the TCP fingerprinting one:
Original:
'tcp'
Noticed vlan tagged traffic wasn't being picked up so, up until yesterday:
'tcp or vlan'
Yesterday first change:
'tcp or (vlan and tcp)' - decent update, meant only vlan traffic that was also tcp got sent to me, but wait, we only want TCP traffic with options, so...
'tcp[12] > 50 or (vlan and tcp[12] > 50)'
So now, instead of having to process all tcp traffic with Satori, winpcap only sends this dll tcp traffic that has tcp options!
Other protocols still read the whole tcp packet, or the whole packet for that matter, but now tcp processing should be a little quicker as I don't have to dig through the packet to see if it is tcp with options, I let winpcap do it. I still check to see if there are options on it and don't assume all is good, but I limit the initial packets that I have to process!
Ok, other updates besides BPF stuff....
Satori 0.7.3 released. Wanted a new .zip file as the last one was 0.7.1 and that was from quite awhile ago. 0.7.2 .exe was released 1.5 years ago! One thing I recently noticed with the update of the oui.txt file is that Satori reads it, but doesn't pick up any new changes in it unless I recompile the .exe. No idea why, on my list to fix some day.
Also released the SIP dll and profile. I wrote these back in 2010 and evidently never released them to the public. Which reminds me, I should probably upload the .xml file that goes with that also which means updating the .zip file that will be missing it also. Oh well, 5 more mins of my life.
Enjoy the updates, let me know if I broke anything as I haven't had a ton of testing time with the new changes as I'm supposed to be studying for SANS 503 stuff right now!
Oh last note, figured out some interesting "glitches" with the vlan tag and BPF, will try to do a different post once I verify it all and get some feed back.
History on the filters, we'll look at the TCP fingerprinting one:
Original:
'tcp'
Noticed vlan tagged traffic wasn't being picked up so, up until yesterday:
'tcp or vlan'
Yesterday first change:
'tcp or (vlan and tcp)' - decent update, meant only vlan traffic that was also tcp got sent to me, but wait, we only want TCP traffic with options, so...
'tcp[12] > 50 or (vlan and tcp[12] > 50)'
So now, instead of having to process all tcp traffic with Satori, winpcap only sends this dll tcp traffic that has tcp options!
Other protocols still read the whole tcp packet, or the whole packet for that matter, but now tcp processing should be a little quicker as I don't have to dig through the packet to see if it is tcp with options, I let winpcap do it. I still check to see if there are options on it and don't assume all is good, but I limit the initial packets that I have to process!
Ok, other updates besides BPF stuff....
Satori 0.7.3 released. Wanted a new .zip file as the last one was 0.7.1 and that was from quite awhile ago. 0.7.2 .exe was released 1.5 years ago! One thing I recently noticed with the update of the oui.txt file is that Satori reads it, but doesn't pick up any new changes in it unless I recompile the .exe. No idea why, on my list to fix some day.
Also released the SIP dll and profile. I wrote these back in 2010 and evidently never released them to the public. Which reminds me, I should probably upload the .xml file that goes with that also which means updating the .zip file that will be missing it also. Oh well, 5 more mins of my life.
Enjoy the updates, let me know if I broke anything as I haven't had a ton of testing time with the new changes as I'm supposed to be studying for SANS 503 stuff right now!
Oh last note, figured out some interesting "glitches" with the vlan tag and BPF, will try to do a different post once I verify it all and get some feed back.
Monday, February 13, 2012
p0fv3 - update
Well sat down and finally played with p0fv3...
DAMN that is fast! Reminds me how pathetically slow Satori is since I wander the .xml file EVERY packet that goes through instead of reading it in once, hashing it and doing a look up on that hash. Not sure how easy it will be, but after seeing how fast p0fv3 is (and prads in the past) just reminds me how much time I'm killing do to how I do lookups!
Anyway, back to p0fv3. Ran a 7 year old pcap file through it, there were about 7-10 devices that it didn't know. Mostly Netware 5 and 6 boxes, a few others that I don't know and would like to, and then a few XP ones that may have been because of the SP they were at or other services. Anyway, sent them on.
Very nice nice program as always mz!
DAMN that is fast! Reminds me how pathetically slow Satori is since I wander the .xml file EVERY packet that goes through instead of reading it in once, hashing it and doing a look up on that hash. Not sure how easy it will be, but after seeing how fast p0fv3 is (and prads in the past) just reminds me how much time I'm killing do to how I do lookups!
Anyway, back to p0fv3. Ran a 7 year old pcap file through it, there were about 7-10 devices that it didn't know. Mostly Netware 5 and 6 boxes, a few others that I don't know and would like to, and then a few XP ones that may have been because of the SP they were at or other services. Anyway, sent them on.
Very nice nice program as always mz!
Monday, February 6, 2012
Passive Aggressive Pwnage
15 min fire talk at Schmoocon 2012, mentions Satori in DHCP fingerprinting, which I was happy to see, missed the greater use of it, but at least it was mentioned!
Audio on this sucks, but was worth my 15 mins to listen to and get a few new ideas.
Thanks for the mention of Satori John!
Audio on this sucks, but was worth my 15 mins to listen to and get a few new ideas.
Thanks for the mention of Satori John!
Friday, January 27, 2012
NetSlueth
It was posted to the fingerbank discussion list in the past week on the Alpha version of NetSlueth. I'd tagged it to go back and look at, and unlike most of the time I tag things for follow up I did it in less than 6 months!
I guess it was just 2 days ago, wow, not sure I've ever gotten back that quick.
Anyway, partial info from the list:
"I basically used tshark for low level processing, allowing me to focus on the logic of the analysis. It needs ALOT more work, including improving my sloppy coding skills. It requires a full installation of Wireshark and .Net Framework or later on the machine. I'm going to make it fully mono compatible shortly."
By using tshark he took a lot of the headache out of coding underlying pieces that I've dealt with in Satori. Anyway, I ran some initial pcap files I had around through it and it seemed to do quite nicely on identifying the OS running on them. I didn't have any luck with a live capture, but I didn't dig around very long on trying to figure out why either!
I need to dig into it more and see what all protocols they are utilizing, but if you need another little tool, this one may be worth looking at!
I guess it was just 2 days ago, wow, not sure I've ever gotten back that quick.
Anyway, partial info from the list:
"I basically used tshark for low level processing, allowing me to focus on the logic of the analysis. It needs ALOT more work, including improving my sloppy coding skills. It requires a full installation of Wireshark and .Net Framework or later on the machine. I'm going to make it fully mono compatible shortly."
By using tshark he took a lot of the headache out of coding underlying pieces that I've dealt with in Satori. Anyway, I ran some initial pcap files I had around through it and it seemed to do quite nicely on identifying the OS running on them. I didn't have any luck with a live capture, but I didn't dig around very long on trying to figure out why either!
I need to dig into it more and see what all protocols they are utilizing, but if you need another little tool, this one may be worth looking at!
Thursday, January 12, 2012
Fingerprint Editor 1.00.08
Jeff recompiled his fingerprint editor for us with the latest .xml files from my fingerprint database!
Tuesday, January 10, 2012
p0f v3
And I though MZ gave up on p0f after no updates to v2 in years. I guess I'm proven wrong....
== What's new ==
Version 3 is a complete rewrite, bringing you much improved SYN and SYN+ACK fingerprinting capabilities, auto-calibrated uptime measurements, completely redone databases and signatures, new API design, IPv6 support (who knows, maybe it even works?), stateful traffic inspection with thorough cross-correlation of collected data, application-level fingerprinting modules (for HTTP now, more to come),
and a lot more.
----
On my list to test in the near future and provide some new fingerprints. Assuming time permits and how well it works (I have no doubts well, but...), I will look at what it is doing and see if I can incorporate new stuff/ideas into a newer tcp plugin for Satori.
== What's new ==
Version 3 is a complete rewrite, bringing you much improved SYN and SYN+ACK fingerprinting capabilities, auto-calibrated uptime measurements, completely redone databases and signatures, new API design, IPv6 support (who knows, maybe it even works?), stateful traffic inspection with thorough cross-correlation of collected data, application-level fingerprinting modules (for HTTP now, more to come),
and a lot more.
----
On my list to test in the near future and provide some new fingerprints. Assuming time permits and how well it works (I have no doubts well, but...), I will look at what it is doing and see if I can incorporate new stuff/ideas into a newer tcp plugin for Satori.
Saturday, November 5, 2011
Using Machine Learnign Techniques for Advanced Passive Operating System Fingerprinting
Ok, guess I'm about a year out on this, but....
Anytime someone mentions your work in their master thesis, it is a nice thing to mention it and post a link!
His thesis can be found here.
He covers a lot of the same ground initially I did it my paper on OS Fingerprinting, but also covers a few tools and newer techniques that were not around back in 2005 or whenever it was that I wrote my paper on this subject. This is only in regards to the start of the paper, giving a quick overview of fingerprinting techniques and tools, he then dives deeply into other things that go well beyond what I've covered previously. I guess it is a master thesis,so it better!
He does bring up a good point/issue with passive fingerprinting and ipsec. Which since I'm working on a final project for school right now discussing network security and ipsec, it may be worth me looking into this a bit more!
Anytime someone mentions your work in their master thesis, it is a nice thing to mention it and post a link!
His thesis can be found here.
He covers a lot of the same ground initially I did it my paper on OS Fingerprinting, but also covers a few tools and newer techniques that were not around back in 2005 or whenever it was that I wrote my paper on this subject. This is only in regards to the start of the paper, giving a quick overview of fingerprinting techniques and tools, he then dives deeply into other things that go well beyond what I've covered previously. I guess it is a master thesis,so it better!
He does bring up a good point/issue with passive fingerprinting and ipsec. Which since I'm working on a final project for school right now discussing network security and ipsec, it may be worth me looking into this a bit more!
DLink cloud managed solutions - offer dhcp fingerprinting in basic option
I don't have a lot of details here, I've been sitting on a lot of "Os fingerprinting" notices the past 6 months, been so busy with work and school I haven't posted much, but have some time to catch up this weekend.
Anyway, DLink has a cloud based solution that does DHCP OS Fingerprinting, more are more every day seem to finally be catching on on how to use this!
One of many articles can be found here.
Anyway, DLink has a cloud based solution that does DHCP OS Fingerprinting, more are more every day seem to finally be catching on on how to use this!
One of many articles can be found here.
OS fingerprinting with IPv6
I was sad to see they didn't go into DHCPv6 at all in this, but the author goes into IPv4 with IPv6 fingerprinting, some of what still works, some possible new stuff.
He did this for his GIAC Gold, maybe I should have used my DHCP presentation for Blackhat and got a Gold Cert on one of the many GIAC certs I hold. Oh well.
Check out the paper here.
He did this for his GIAC Gold, maybe I should have used my DHCP presentation for Blackhat and got a Gold Cert on one of the many GIAC certs I hold. Oh well.
Check out the paper here.
Subscribe to:
Posts (Atom)