Friday, August 28, 2009

Extracting Files from a tcpdump

I'm working as consultant, pentester and sometimes still as second-level-security guy for a rather huge company.
Occasionally I have to analyze tcp-streams, and occasionally I came to a point where i had to extract files out of huge dumps. What I found during my last research about a year ago was not really usable - i hacked together a few lines of perl to extract exactly what i wanted - this didn't deliver exact files, but was enough to help me solve a problem.

Jim Clausing, one of the more practical guys over at ISC described the same problem recently and asked the readers of the ISC-Blog for software that is able to extract files from pcap-dump. People came out with a load of promising solutions:


Not all of them might do exactly what you want - but this is defintely the best overview on pcap-file-extractors I ever came across.

Tom

Thursday, August 27, 2009

Network-Cheatsheets

I'm on my way to become a friend of cheatsheets. A nice suite of network-related sheets is here: http://packetlife.net/cheatsheets/

Tom

Tuesday, August 04, 2009

How to find Elite-Security-People

Ever wondered where to find those real elite-security-people?

Maybe look for those who did their cissp-certification years ago: http://attrition.org/misc/ee/20050426-cissp.txt
~4.700 Names, employers, functions, addresses etc pp. of all those early CISSPs.


Real elite? - look for those who have an account at osvdb.org - especially check their id - the smaller the ID, the more 4337 they are. Get the (huge!) db here: https://www.metricscenter.net/amCharts/osvdb-metrics/raw/osvdb-csv.latest

Around 5.000 names here - but it reads like a who's who of those it-security-swamp. Also look here if you look for a human security-contact at some soft- or hardware-company - you find quite a few in those database.



Ever wondered how to find elite-security-guys, the leading edge security professionals?



You know other security-pro-listings? - Write a comment.

"The reason people search for themselves is that they're curious about what other people see when they search for their name," says Joe Kraus, Google's director of product management. (here)

Funny, those public databases.

tom

Sunday, August 02, 2009

How to check a site for E-Mail authentication

Working as a pentester, i often check webshops and well-established brands. I expect them to have some kind of E-Mail-Authentication in place - be it Domain-Keys or an SPF-Record.

Not because I want to make the world a spam-free-place - I believe mail-authentication a worthwile measure against phishing-scams abusing a company-brand. I a company has mail-authentication like SPF in place, almost all spam-filters are able to and will separate legitimate company-mail and newsletters from phishing-scams, that are usually sent via untrusted ip's or without proper DKIM.

I was recently asked how to check this in a realworld-scenario. SPF is fairly easy - just get TXT and SPF-record for the domain in question. DIG is your friend, or just use serversniff's dns-report.
DKIM is more complicated: You need a realworld mail from the customer - be it a newsletter or an errormessage or anything else.

But how to verify SPF-Records and Domain-Key-Sigs?

I found it the easiest to use googlemail for this task - open an email in question, press the small arrow up right (next to the upper "reply") and select "Show Original". GMail will show you the complete Mail-Headers then, including validated SPF- and DKIM-Records. These might look like this:

SPF pass: Google verified an SPF-Record for this mail.

SPF neutral: Google can't verify an SPF-Record for this mail.

SPF pass by "best guess": There is no SPF-Record, but google was able to verify that the originating machine belongs to the originating domain.

And now for different DKIM-Headers:




I'm still not sure what google's spamfilter means with these headers, but it seems to be fairly accurate with even detecting a domain in "test-mode".

I'd be happy to hear from any other solution for verifying Mail-Authentication - write a comment or drop me a mail to tom@serversniff.net.

tom

Thursday, July 30, 2009

DNS-Redirects

Nobody likes DNS-Redirects. Even IETF said recently (http://www.icann.org/en/committees/security/sac041.pdf):

The redirection and synthesizing of DNS responses by TLDs poses a clear and significant
danger to the security and stability of the domain name system. The consequences of
synthesized DNS responses range from erosion of trust relationships to the creation of
new opportunities for malicious attacks, without the ability of the affected party(ies) to mitigate these problems.


Serversniff stumbles over this shit, too. Currently the TLDs .mobi, .jobs and .asia use this - they answer every dns-request with an ip, even if a domain won't exist.

They don't dare to present a http-landing-page (like e.g. t-online.de does) - but in fact they resolve every query to an IP, misleading quite a few of serversniff's scripts. We're workin to fix this - but this takes time, for we need to fix every ip-lookup-routine.

totally useless shit.

tom

Tuesday, July 21, 2009

to be unique or not

Way back in 2004 I created serversniff
* to help myself managing and doing my pentests
* to help others checking their sites
* to help myself understanding stuff. cryptology, protocols etc
* to help others understanding stuff. cryptology, protocols etc

and finally, to create something unique and new.

Why should i reinvent the wheel, why invest time to offer services that others already offer for free?

I'm a bit puzzled about the occasional inquirys to "donate" sourcecode for somebody's public site. People are not ashamed to ask for ready-to-run code to implement serversniff's functions on their sites. And no, it's not just one or to mails coming in with such requests. Anyway, i still see serversniff as more or less academic, and primary educational stuff. I give out advice, concepts and snippets of code as long as the request is friendly and nice.

But still: It wouldn't come to my mind to ask anybody to donate code of his website so that i can implement it in any of my sites. I'm still eager to learn necessary stuff before i start coding php-scripts, i'm still committed to create unique services that aren't to be found anywhere else in this flavour or quality.

While serversniff's script use crappy php-code and the server itself is unstable like a one-legged stool i'd never try to release a service unless i'm convinced that it has something unique or does its job better than all other sites.

Maybe there's just somehting wrong with my mind.

tom

Serversniff on Twitter

We're implementing and fixing quite a lot on what we call "Serversniff 2.0", currently hosted on http://webwiki.de. Since it's plain to much to blog it all in detail, we decided to put the updates and fixes on a twitter-feed hosted at http://twitter.com/serversniff.

Follow there if you want to stay tuned about news and fixes concerning serversniff.

tom

Wednesday, July 15, 2009

Site-Analyzer: Added Page-Rank detection - http://webwiki.de/taglists/pagerank-8

Added a page-rank-detection for sites.
If a site has a page-rank, it is displayed at site-analyzer.
Page-Ranks of 5 and higher get tagged, so we'll build up a list of
sites with high-pageranks. Since the feature is brand new, there is
not really much in there right now - but you might try to list all
sites having a Google-Page-Rank of 8 here:
http://webwiki.de/taglists/pagerank-8
 
tom

Tuesday, July 14, 2009

New links in Site-Analyzer

I just implemented links to Symantec/Norton's SafeWeb-Analyzer
(https://safeweb.norton.com/), McAfee's SiteAdvisor
(https://www.siteadvisor.com/) and Googles SafeBrowsing
(http://google.com/safebrowsing/diagnostic?site=www.bayern.de).
 
If you're in doubt wether to trust a site you might check it first on
these sites.
 
Do you know any other relevant malware-checks?
 
Comment here or drop me a mail:
 
tom@serversniff.net

experiment: switched from http://thumbshots.com to http://shrinktheweb.com

we switched the site-image-hosting from thumbshots.com to
http://shrinktheweb.com
pictures are bigger and it seems faster. shrinktheweb.com has tighter
limits for the free version - we'll see if this is enough.
 
tom