Showing posts with label linux. Show all posts
Showing posts with label linux. Show all posts

Tuesday, May 15, 2012

BackTrack5 Install

I recently came into a mode of downtime for a few days and decided to finally install backtrack5 on a Lenovo X201 laptop. I burned the disk early on this semester but between my own students and my deliveribles at DSU, it sat on my desk at home collecting dust until this last weekend.

Out of the gate I hit the dreaded black screen. It took about an hour to find the right combination of grub tweaks to get it to boot and launch X. From there I will have to say that an i5 and 8GB of RAM is sheer overkill for this distribution. I did like the number of tools loaded into the live disk and the ease of use of the Ubuntu based apt installer made it easy to get the extra tools I wanted in my load. This left some testing of the tools to see if they performed any better than the windows versions.

For the most part I was pleasantly surprised at how well everything worked. I did find that the wlan0 adapter was not talking well with ssidsniff even when calling the adapter explicitly in the argument tags. Small issue really and I fully admit that in the short amount of time I did not try Kismet. I was able to quickly pull off an (on my own network of course) arp poisoning MITM attack using SSLStrip which I had seen demonstrated from the BlackHat tutorials and a few YouTube links prior. I was really impressed at how many tools were available to the user for security concerns. Nessus, OpenVAS, and  Snort were full installs with some of my more favorite tools such as Nikto and Ettercap.

I have to say that I'm sad I did not pick up this distribution earlier. BT5 is great and it would have saved me all those hours configuring my previous Ubuntu installs with tools had I just moved to this instead. I will also say that it is likely that the Lenovo hardware on this is what caused most of my issues. I will play around with it a little more this week before my summer courses get crazy and perhaps get it going in a VirtualBox environment although having real adapters in place of bridged mode NICs is always nicer.

Monday, September 26, 2011

Nikto2

I have been working on a project for my information security class. It requires me to test and gather information on a server before attempting to penetrate it. I have managed to build a good list of information on the server, but I have not managed to penetrate it yet. Of course I'm trying to do this without the use of scripts or applications designed for this server's vulnerabilities, so I'm doing it the hard way, but honestly, did anyone expect anything less of me?

So I'm working though trying to find all the tools I can use to discover all the possible vulnerabilities and I remember nikto. For those who are not familiar with Nikto, it is a web server vulnerability tool, a very vertically aligned form of metasploit (which I wish had student licenses). Nikto 2 has come along way since the last time I looked at it and seems to be very stable. The thing I like most about Nikto is the mutation capability, being able to change what I need to accomplish my goal. This goes beyond just adding parameter tags, to being able to actively get content loaded on the server. It also has a export to metasploit function which enables this to be added to a pen tester's suite of tools. Nice.

Within a few minutes and a good nmap scan I was able to determine a mostly complete range of vulnerabilities on the project server. Of course the hard part is actually utilizing these vulnerabilities and exploiting them, but then again, that what I'm being graded on. Nikto 2 is working flawlessly on my ubuntu server, my Solaris VM, and my OSX laptop (10.7 Lion).

Monday, May 30, 2011

Summer Semester: Shift in Focus

EC2...wow, just wow. As I sit here trying desperately to wade through the massive amount of material I must read and prep in 23 days, I sit in awe of how Amazon has implemented the EC2. You are probably wondering why I have sprung this topic without any sort of prelude or previous mention, well that's a funny story actually and it all revolves around being flexible.

So I registered for a seminar course this summer, INFS 890. I must take and pass six of these courses to meet the requirements for the DSc program. What I did not realize involves two things: 1. I have completed my core and 2. It's all specialization and dissertation work from here on out. INFS 890 prepares you for dissertation by allowing you to schedule time and resources for your dissertation topic. I now have a dissertation area, professor, and direction. So when discussing the needs of the course with the instructor I came to a choice, a fork in the road if you will, between network security and cloud security. Given the resources and position of my current work projects I chose cloud security, and to quote Indiana Jones, it would seem that I have chosen wisely.

I started playing with EC2 last week after reading the apology letter from Amazon regarding the recent outage. The way that the infrastructure is set up is amazing. I started creating my own instances and modifying other AMIs to meet my curiosity. Wow...30 seconds to VM creation. So many distributions and so inexpensive. Being able to set the instances in a good arrangement then setting that arrangement as a cloud formation. Wow. I loved being able to setup Ubuntu in just minutes. I doubt I will ever need a home machine to do OS testing and learning. I have been trying to get back into SuSE and instead of buying or re-purposing a machine to do this, I can now just launch a AMI, make the changes I need, and continue on my merry way.

This does leave some serious security questions though, and if the literature at this point is any indication, EC2 security is being left in the hands of the users. The literature on this is far from sparse (YAY), meaning it's a hot topic and there is no great silver bullet answer. I have seen some excellent ideas in the articles so far and I am starting to implement them myself in my own test cloud. Of course I do have to watch the cost, but that's why I applied to the AWS in Education program, perhaps with a little luck, Amazon will allow me to play and learn at a reduced cost.

Friday, May 23, 2008

Ulteo for Windows

I decided to try something new. Since I need some basic Linux functionality at my office, but I am locked in to using Windows, I was pleasantly surprised at Ulteo.

I have the need to run and cron several scripts which I wrote for SEO and SEM purposes. These are custom scripts which I really want to have running with the need (or cost) of an additional server. Normally I would just purchase a Mac and be done with the whole issue. Since the company needed to reduce the costs I decided (with a whimper in my heart) to get a XP machine.

Enter Uleto. The installation was easy, although I do recommend the machine have a good pipe to download either installer. I would also suggest that you have at least 2GB ram, as the installer runs in a virtual machine instance. It also requires you to have registered at the ulteo.com website for their web services, which I didn't mind.

Ulteo links flawlessly (so far) with the windows environment. I get my wonderful bash, python 2.4.3 (kind wished to see at least 2.5 on the install, but I will test upgrading the python core later). The really nice part is that I didn't have to purchase VMware. I like VMware, but for small business, when you need to cut corners, free is better.

Give it a look, you might like it. Here is the link for the windows environment. You want the Ulteo Virtual Desktop. A torrent file is also available although I haven't checked to see how seeded the torrent was in my bit torrent utility.

Have fun!

Wednesday, October 10, 2007

Bye Bye XP

After upsetting me for the last time, I did something I never thought I would do...I took the plunge whole-heartedly into Linux.

Mind you this is not trying the flavor of the week on some secondary machine. I backed up all my non-os data, and wiped my XP load clean off my primary PC at home (it will have to do until I get another mac).

I tried SuSE Open Source 10.3, I have to say that although it was nice, I was still left with the impression that it was missing things, mainly dual monitor support. U will write more tomorrow about my SuSE 10.3 experience, good and bad.

So Ubuntu it is...dual monitors, FireFox, Perl, Python, and CrossOver/Wine (soon). I'm not really needing much more atm. I don't have to worry about licensing, OEM crap, or corruption (scripts in place back up my home folder to a thumb drive).

It has been a while, but it is nice to be back /127.0.0.1

Wednesday, September 12, 2007

Quick Check of Google Crawl

If you are not using Google's Webmaster tools this is a quick BASH script which can check the spider rate.

type cache:your.website.here in a google search
note the return URL in the browser - save this (must have the IP)

#!/bin/bash
set -o errexit
stamp=`date`
touch temp.txt
lynx -dump -accept_all_cookies "cached.url.here" | grep 'retrieved' | cut -c 4-50>>temp.txt
cache=`catrm -rf temp.txt
echo $stamp Google $cache>>/path/to/desired/dir/file.txt

Check out the documentation on the cut command which gets the info from grep, this truncates the number of characters passed to the temp.txt, adjust to what you need to get the desired result.

this should give you a return result like this:
Fri Aug 31 14:18:05 CDT 2007 Google retrieved on Aug 30, 2007 13:49:11 GMT.
Tue Sep 4 09:10:20 CDT 2007 Google retrieved on Aug 31, 2007 14:35:14 GMT.
Wed Sep 5 07:51:55 CDT 2007 Google retrieved on Sep 2, 2007 15:52:02 GMT.
Thu Sep 6 13:01:19 CDT 2007 Google retrieved on Sep 4, 2007 22:35:39 GMT.
Fri Sep 7 07:00:00 CDT 2007 Google retrieved on Sep 5, 2007 13:25:22 GMT.
Sat Sep 8 07:00:00 CDT 2007 Google retrieved on Sep 6, 2007 13:28:59 GMT.
Sun Sep 9 07:00:00 CDT 2007 Google retrieved on Sep 8, 2007 08:19:05 GMT.
Mon Sep 10 07:00:00 CDT 2007 Google retrieved on Sep 8, 2007 08:19:05 GMT.
Tue Sep 11 07:00:00 CDT 2007 Google retrieved on Sep 10, 2007 08:54:21 GMT.
Wed Sep 12 07:00:00 CDT 2007 Google retrieved on Sep 10, 2007 23:52:44 GMT.

a quick a dirty log of when Google Crawled my site, I then just threw this to crontab to run every morning at 4am, and my browser is set to open this link upon activation.

Enjoy.