Sunday, June 3, 2012

HoNe - Running Process Cyber Attack Sensor

June 3, 2012 | Robert Cazares

I found this to be noteworthy of coming back to for further investigation in using this tool.

Hone is a unique open source tool developed by Pacific Northwest National Laboratory for correlating packets to processes to bridge the HOst-NEtwork divide.It is designed to determine which applications are communicating with external network, correlate packets to the responsible processes in Linux systems. Diagnose connections by adding process information.  

Available for Linux kernels 2.6.32 and later.
Windows 7, Windows XP and a MacOS X version is planned.




Pacific Northwest National Laboratory Creates New Sensor To Stop Attackers In Their Tracks

Apr 11, 2012 | 05:06 PM

RICHLAND, Wash. - The good guys have a new, innovative tool to help them identify and understand cyber attacks.

Developed by a researcher at the Department of Energy’s Pacific Northwest National Laboratory, the new Hone cyber sensor determines how network activity on a computer is related to an application such as Internet Explorer or any running process. Finding these relationships enables cyber security experts to more quickly identify a potential problem and dissect how it works.

Full story is here: 
http://www.darkreading.com/advanced-threats/167901091/security/news/232900169/pacific-northwest-national-laboratory-creates-new-sensor-to-stop-attackers-in-their-tracks.html

HoNe project at github can be found here:
https://github.com/HoneProject/Linux-Sensor#readme

Wednesday, April 13, 2011

Blindly restoring Windows XP screen resolution

Applies to Windows XP (any version)

Have you ever changed the screen resolution of your computer to where you have saved settings that your monitor cannot display? I have, several times. It's annoying at best to to have accidentally made a change and then not be able to see what you're doing.

Here are the steps to restore your display.
Please note that you have to be logged in.
If you need to blindly login to your account, I'll save those steps for a different post.

---------------------------------------------------
Take an educated guess and place the mouse cursor someplace on the desktop where you are not hovered over any icons or the toolbar.
  1. Click the Right Mouse button.
  2. On your keyboard, press the UP ARROW once, then press the ENTER key.
  3. On your keyboard press the TAB key four times.
  4. On your keyboard, press the RIGHT ARROW key four times.
  5. On your keyboard press the TAB key once.
  6. Then press the LEFT ARROW key four or five times
  7. Then press the ENTER key.
At this point you should have a viewable display.
The Monitor Setting dialog box will begin a countdown, "Reverting in n seconds".
Save your display settings.

And that should do it!

Tuesday, March 9, 2010

There's something amiss in China - Increased daily spam

OK, so for the past few weeks I have noticed a marked increase in spam in my primary email Spam folder. I have been deleting messages willy-nilly from the folder, as I usually do, when I walk through my daily email reading and composition routine.

Yesterday, I decided to let the spam pile up for a 24 hour period and take note of how many spam messages I have received. I don't like to pick on or lean in one direction or the other without having at least some metrics to go on, but out of 98 spam messages, 24 of those messages DID NOT have Chinese characters in the subject line.


Whup, OK, as I was typing this the message count JUST jumped to 102. By way of supposition, that's approximately 80% of the spam I have received in the past 24 hour period is coming from China.


Delving a little deeper I took a random check of the email headers, and yes, unless they're totally forged headers, I have to say, they do originate someplace in China. Where in China? Not important at this time. It's notable that they come from over the China border to here, at my gmail account in the United States.


So, what's happening here? Why the sudden spike in spam to my gmail account originating in China? Is there a mechanism I can implement to block ALL email from China from reaching my email account? I don't know anyone in China. I'm not expecting any email from China. Why can't I simply block all these messages? It's annoying at the very least and it is spam. I am going to keep my eye on this for a while, compile some data, see how it goes and maybe publish my results after 30 days or so. Is it worth it? I'll keep you posted.


- Robert Cazares

Saturday, February 27, 2010

FTK 1.8 notes

FTK 1.8 notes - placeholder

Wednesday, February 10, 2010

cnbc.com - San Antonio: New Cyber City

Airtime: Wed. Feb. 10 2010 | 12:17 PM ET

Discussing why San Antonio is key to cyber security, with NBC's Janet Shamlian and Dr. Greg White, colonel for the U.S. Air Force and Fred Ramirez, CNF Technologies.

http://www.cnbc.com/id/15840232?video=1410041474&play=1


Friday, February 5, 2010

Windows 7 64-bit and 32-bit, Swiff Player, Flash 10 installation

OK, so here's a work-around for you who have not been able to play .swf files on your Windows 7 64-bit and 32-bit systems.

I have tested this on both 32-bit and 64-bit systems with instant success. However, I make no guarantees or warranties and YMMV. What I can tell you is that after after a few hours of research and banging, it works for me.

This "fix" is simple. Really, it is.

- 64-bit systems
1) Install Adobe Flash 10 (
Adobe Flash Player Standalone Installer, version 10.0.42.34) from
http://fpdownload.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_10_active_x.exe.
2) When installation is completed, navigate to C:\Windows\SysWOW64\Macromed\Flash and make a copy of Flash10d.ocx in the same directory.
3) Rename the copy of Flash10d.ocx to Flash.ocx (you will still have a copy of
Flash10d.ocx)
4) Install Swiff Player 1.5 (http://www.globfx.com/downloads/swfplayer/)
5) Run Swiff Player and load your .swf files.
6) Enjoy!

- 32-bit systems
1) Install Adobe Flash 10 (Adobe Flash Player Standalone Installer, version 10.0.42.34) from
http://fpdownload.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_10_active_x.exe.
2) When installation is completed, navigate to C:\Windows\System32\Macromed\Flash and make a copy of Flash10d.ocx in the same directory.
3) Rename the copy of Flash10d.ocx to Flash.ocx (you will still have a copy of
Flash10d.ocx)
4) Install Swiff Player 1.5 (http://www.globfx.com/downloads/swfplayer/)
5) Run Swiff Player and load your .swf files.
6) Enjoy!

Note 1: There is also a differing link to Adobe Flash 10 here:
http://get.adobe.com/flashplayer/otherversions/

Here's another link that I leaned on that helped me through this nagging issue:

Adobe Flash Player Standalone Installer?

http://social.answers.microsoft.com/Forums/en-US/InternetExplorer/thread/c8fe6d6f-ca63-4f2d-aa39-0365ca9c8b2d

- Robert

Updated Feb 5, 2010 - 1:32PM

Thursday, February 4, 2010

Control Sets and the Windows XP startup process

For our reference, we need to know which ControlSet is used for system startup.

Typically, if the system\Select\Current value is set to 0x1 (Data: 0x00000001 (1)), then CurrentControlSet is pointing to ControlSet001.


For more detailed information see the below snippets and links.
--------------------------------------------------------------
Control Sets and the Windows XP startup process
Published: November 03, 2005
http://technet.microsoft.com/en-us/library/bb457123.aspx

Startup Phases

The Windows XP Professional startup process closely resembles that of Microsoft Windows NT version 4.0, Microsoft Windows 2000, and Microsoft Windows Server™ 2003, but it significantly differs from Microsoft MS-DOS, Microsoft Windows 95, Microsoft Windows 98, and Microsoft Windows Millennium Edition (Windows Me).

--------------------------------------------------------------
Article ID: 100010 - Last Review: November 1, 2006 - Revision: 3.1
What are Control Sets? What is CurrentControlSet?
http://support.microsoft.com/kb/100010

Of importance:
ControlSet001 may be the last control set you booted with, while ControlSet002 could be what is known as the last known good control set, or the control set that last successfully booted Windows NT. The CurrentControlSet subkey is really a pointer to one of the ControlSetXXX keys. Clone is a clone of CurrentControlSet, and is created each time you boot your computer by the kernel initialization process. In order to better understand how these control sets are used, you need to be aware of another subkey, Select.

Select is also under the SYSTEM key. Select contains the following values:
Current
Default
Failed
LastKnownGood
"Each of these values contain a REG_DWORD data type and refer to specifically to a control set. For example, if the Current value is set to 0x1, then CurrentControlSet is pointing to ControlSet001. Similarly, if LastKnownGood is set to 0x2, then the last known good control set is ControlSet002. The Default value usually agrees with Current, and Failed refers to a control set that was unable to boot Windows NT successfully. "

Blog Archive