<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Information Systems Auditing</title>
	<atom:link href="http://www.jedge.com/wordpress/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://www.jedge.com/wordpress</link>
	<description>A collection of links, documents, and thoughts of a State IS auditor.</description>
	<lastBuildDate>Wed, 01 Sep 2010 00:31:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Stand-Alone Tools and Utilities</title>
		<link>http://www.jedge.com/wordpress/?p=261</link>
		<comments>http://www.jedge.com/wordpress/?p=261#comments</comments>
		<pubDate>Wed, 01 Sep 2010 00:31:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.jedge.com/wordpress/?p=261</guid>
		<description><![CDATA[A question was raised today during a presentation about what utilities you can use without installing them. There are engagements that the auditor is not allowed to use their own laptop and must use a laptop provided by the auditee. This severely limits how effective an engagement can be but it is not impossible to [...]]]></description>
			<content:encoded><![CDATA[<p>A question was raised today during a presentation about what utilities you can use without installing them.  There are engagements that the auditor is not allowed to use their own laptop and must use a laptop provided by the auditee.  This severely limits how effective an engagement can be but it is not impossible to obtain the information you need when you connect to the auditee&#8217;s network.  I&#8217;ve made changes to the <a href="http://www.jedge.com/wordpress/?page_id=72">Security Tools</a> page to highlight which tools are stand-alone and do not require installation.  Also for reference see <a href="http://www.jedge.com/wordpress/?p=82">Penetration Testing Ninjitsu</a> which I pulled from a Core Security webcast.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jedge.com/wordpress/?feed=rss2&amp;p=261</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web Security Dojo</title>
		<link>http://www.jedge.com/wordpress/?p=246</link>
		<comments>http://www.jedge.com/wordpress/?p=246#comments</comments>
		<pubDate>Sat, 17 Apr 2010 17:18:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.jedge.com/wordpress/?p=246</guid>
		<description><![CDATA[NA CACS conference hosted by ISACA (18-22 April 2010) Remote Security Testing for Web Applications Presented by David Rhoades Maven Security Consulting Attending this conference workshop session introduced me to Maven Security&#8217;s Web Security Dojo.  This is a virtual image, Ubuntu based, that includes several free and open source tools used for web application auditing.  [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.isaca.org/Template.cfm?Section=North_America_CACS&amp;CONTENTID=50896&amp;TEMPLATE=/ContentManagement/ContentDisplay.cfm&amp;utm_source=promonewsletter&amp;utm_medium=email&amp;utm_content=textlink&amp;utm_campaign=nacacs">NA CACS</a> conference hosted by <a href="http://www.isaca.org">ISACA</a> (18-22 April 2010)</p>
<p>Remote Security Testing for Web Applications<br />
Presented by David Rhoades<br />
<a href="www.mavensecurity.com">Maven Security Consulting</a></p>
<p>Attending this conference workshop session introduced me to Maven Security&#8217;s <a title="Web Security Dojo" href="http://www.mavensecurity.com/web_security_dojo/" target="_blank">Web Security Dojo</a>.  This is a virtual image, Ubuntu based, that includes several free and open source tools used for web application auditing.  The image also includes web application environments that are vulnerable to many common vulnerabilities to allow you to test and learn how to use the tools.  This pre-configured environment is perfect for educational purposes.  They also include a BASH script that will setup your own Ubuntu environment.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jedge.com/wordpress/?feed=rss2&amp;p=246</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Updated Linux Laptop configuration for Auditors</title>
		<link>http://www.jedge.com/wordpress/?p=244</link>
		<comments>http://www.jedge.com/wordpress/?p=244#comments</comments>
		<pubDate>Wed, 10 Mar 2010 16:18:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.jedge.com/wordpress/?p=244</guid>
		<description><![CDATA[I&#8217;ve created an updated configuration tutorial for setting up your Linux laptop to conduct system and network audits.  This version details how to get everything up and running on the latest Ubuntu currently at version 9.10 (Karmic Koala).  The specific brand I use is the Netbook Remix.  See the Configuration Tutorials to download the latest [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve created an updated configuration tutorial for setting up your Linux laptop to conduct system and network audits.  This version details how to get everything up and running on the latest Ubuntu currently at version 9.10 (Karmic Koala).  The specific brand I use is the Netbook Remix.  See the <a href="http://www.jedge.com/wordpress/?page_id=8">Configuration Tutorials</a> to download the latest pdf document.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jedge.com/wordpress/?feed=rss2&amp;p=244</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>John the Ripper w/ Jumbo Patch (Updated for 1.7.5)</title>
		<link>http://www.jedge.com/wordpress/?p=233</link>
		<comments>http://www.jedge.com/wordpress/?p=233#comments</comments>
		<pubDate>Mon, 16 Nov 2009 13:57:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.jedge.com/wordpress/?p=233</guid>
		<description><![CDATA[Password cracking Windows hashes on Linux using John the Ripper (JtR). If you prefer the Linux operating system JtR is the password cracking utility to use. By default JtR does not support the hashes that we are interested in cracking. See below for installation and patching instructions for JtR.   Applying the patch to JtR adds [...]]]></description>
			<content:encoded><![CDATA[<p>Password cracking Windows hashes on Linux using John the Ripper (JtR).  If you prefer the Linux operating system JtR is the password cracking utility to use.  By default JtR does not support the hashes that we are interested in cracking.  See below for installation and patching instructions for JtR.    Applying the patch to JtR adds the functionality to crack NTLM and MS-Cache passwords.  NOTE:  This install was done on Ubuntu 10.4 but should work on any Linux system since we are compiling from source.</p>
<p><kbd>$./john --format=mscash --rules --wordlist=&lt;PASSWORD_LIST&gt; &lt;CACHE_HASH_FILE&gt;<br />
$./john --format=nt --rules --wordlist==&lt;PASSWORD_LIST&gt; &lt;NTLM_HASHE_FILE&gt;</kbd></p>
<p>For additional information you can read the JtR <a href="http://www.openwall.com/john/doc/">documentation</a> and <a href="http://openwall.info/wiki/john">wiki</a> from Openwall.</p>
<p>OpenSSL is needed.  This can be installed through your package manager or may already be installed.    Remember to install the development package (libssl-dev or libssl-devel).  Instructions on download and compile are included below.</p>
<p><kbd><br />
$ wget http://www.openssl.org/source/openssl-1.0.0a.tar.gz<br />
$ tar zxvf openssl-1.0.0a.tar.gz<br />
$ cd openssl-1.0.0a<br />
$ ./config --openssldir=/usr/local<br />
$ make<br />
$ sudo make install<br />
$ wget http://www.openwall.com/john/g/john-1.7.5.tar.gz<br />
$ tar zxvf john-1.7.5tar.gz<br />
$ cd john-1.7.5/<br />
$ wget http://www.openwall.com/john/contrib/john-1.7.5-jumbo-3.diff.gz<br />
$ gzip -d john-1.7.3-jumbo-3.diff.gz<br />
$ patch -p1 &lt; john-1.7.5-jumbo-3.diff<br />
$ cd src/<br />
$ make linux-x86-sse2<br />
</kbd></p>
<p>John will be found in the run directory.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jedge.com/wordpress/?feed=rss2&amp;p=233</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Using Perl to Parse Nmap XML</title>
		<link>http://www.jedge.com/wordpress/?p=220</link>
		<comments>http://www.jedge.com/wordpress/?p=220#comments</comments>
		<pubDate>Fri, 06 Nov 2009 18:28:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.jedge.com/wordpress/?p=220</guid>
		<description><![CDATA[As an auditor I liked to quickly analyze my Nmap scan results by parsing the XML output produced and loading it into my favorite spreadsheet application. From there I could sort by host, port, service, or operating system for analysis. The parsed results are a lot easier to add to reports and workpapers. Just remember [...]]]></description>
			<content:encoded><![CDATA[<p>As an auditor I liked to quickly analyze my <a href="http://nmap.org">Nmap</a> scan results by parsing the XML output produced and loading it into my favorite spreadsheet application.<br />
From there I could sort by host, port, service, or operating system for analysis.  The parsed results are a lot easier to add to reports and workpapers.  Just remember to keep the original Nmap results.<br />
I&#8217;ve developed a LAMP <a href="http://www.jedge.com/wordpress/?page_id=62">framework</a> to parse and load Nmap results into a database for reporting and analysis.  However if you are just looking to quickly parse the results of individual scans I&#8217;ve got a Perl script for you!<br />
First a quick blurb on getting installing Perl and and Nmap-Parser module.</p>
<p><strong>Windows</strong></p>
<p>Download ActivePerl from the Active State website:  https://www.activestate.com/activeperl/downloads/<br />
Once ActivePerl is installed you will need to install the <a href="http://search.cpan.org/dist/Nmap-Parser/Parser.pm">Nmap Parser</a> written by <a href="http://anthonypersaud.com/">Anthony Persaud</a>.<br />
From the Command Prompt enter the following command:<br />
<kbd><br />
C:\&gt;ppm install nmap-parser<br />
Downloading Nmap-Parser-1.19...done<br />
Downloading XML-Twig-3.32...done<br />
Unpacking Nmap-Parser-1.19...done<br />
Unpacking XML-Twig-3.32...done<br />
Generating HTML for Nmap-Parser-1.19...done<br />
Generating HTML for XML-Twig-3.32...done<br />
Updating files in site area...done<br />
21 files installed<br />
</kbd></p>
<p><strong>Linux</strong></p>
<p>For Ubuntu/Debian you can install the package.<br />
<kbd>#apt-get install libnmap-parser-perl</kbd></p>
<p>For every Linux distro you can install the package via <a href="http://www.cpan.org/">CPAN</a>.<br />
<kbd>#perl -MCPAN -e 'install Nmap::Parser'</kbd></p>
<p>Copy the following Perl code below and save it as nmap_parse.pl.<br />
<pre><code>
use Nmap::Parser;

my $np = new Nmap::Parser;
my $infile = @ARGV[0];

$np-&amp;gt;parsefile($infile);

#GETTING SCAN INFORMATION

print &quot;Scan Information:\n&quot;;
my $si = $np-&amp;gt;get_session();
print
&#039;Number of services scanned: &#039;.$si-&amp;gt;numservices().&quot;\n&quot;,
&#039;Start Time: &#039;.$si-&amp;gt;start_str().&quot;\n&quot;,
&#039;Finish Time: &#039;.$si-&amp;gt;time_str().&quot;\n&quot;,
&#039;Scan Arguments: &#039;.$si-&amp;gt;scan_args().&quot;\n&quot;;

print &quot;Host Name,Ip Address,MAC Address,OS Name,OS Family,OS Generation,OS Accuracy,Port,Service Name,Service Product,Service Version,Service Confidence\n&quot;;
for my $host ($np-&amp;gt;all_hosts()){
&nbsp;&nbsp;for my $port ($host-&amp;gt;tcp_ports()){
&nbsp;&nbsp;&nbsp;&nbsp;my $service = $host-&amp;gt;tcp_service($port);
&nbsp;&nbsp;&nbsp;&nbsp;my $os = $host-&amp;gt;os_sig;
&nbsp;&nbsp;&nbsp;&nbsp;print $host-&amp;gt;hostname().&quot;,&quot;.$host-&amp;gt;ipv4_addr().&quot;,&quot;.$host-&amp;gt;mac_addr().&quot;,&quot;.$os-&amp;gt;name.&quot;,&quot;.$os-&amp;gt;family.&quot;,&quot;.$os-&amp;gt;osgen().&quot;,&quot;.$os-&amp;gt;name_accuracy().&quot;,&quot;.$port.&quot;,&quot;.$service-&amp;gt;name.&quot;,&quot;.$service-&amp;gt;product.&quot;,&quot;.$service-&amp;gt;version.&quot;,&quot;.$service-&amp;gt;confidence().&quot;\n&quot;;
&nbsp;&nbsp;}
}
</code></pre><br />
Save the above code and run it from the command line as follows:</p>
<p><kbd>C:\&gt;nmap_parse.pl nmap_scan_output.xml &gt;&gt; results.csv</kbd></p>
<p>Additional Information</p>
<p>ppm &#8211; Perl Package Manager, version 4</p>
<p>http://docs.activestate.com/activeperl/5.10/bin/ppm.html</p>
<p>ActiveState CPAN PPM Repository</p>
<p>http://ppm4.activestate.com/</p>
<p>Nmap Parser</p>
<p>http://search.cpan.org/dist/Nmap-Parser/Parser.pm</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jedge.com/wordpress/?feed=rss2&amp;p=220</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password Length vs. Password Strength</title>
		<link>http://www.jedge.com/wordpress/?p=197</link>
		<comments>http://www.jedge.com/wordpress/?p=197#comments</comments>
		<pubDate>Wed, 21 Oct 2009 18:45:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.jedge.com/wordpress/?p=197</guid>
		<description><![CDATA[Take this hypothetical scenario (Okay, it really wasn’t hypothetical at the time).  You recommend to your client that minimum 8 character passwords should be enforced but they want a minimum of 6 character passwords and instead they will enforce password complexity (alphanumeric and special characters). As auditors we like to have facts to back-up our [...]]]></description>
			<content:encoded><![CDATA[<p>Take this hypothetical scenario (Okay, it really wasn’t hypothetical at the time).  You recommend to your client that minimum 8 character passwords should be enforced but they want a minimum of 6 character passwords and instead they will enforce password complexity (alphanumeric and special characters).</p>
<p>As auditors we like to have facts to back-up our recommendations.  What better fact than simple math.</p>
<p>Password strength in relation to the number of guesses an attacker needs to brute force the password is represented by the number of characters available to choose from raised to the power of the length of the password.</p>
<p>N^x</p>
<p>N = number of characters available<br />
x = length of the password.</p>
<p>Lets do some simple math for six character passwords vs eight character passwords.  We will even have complex passwords for the six character password and simpler passwords requirements for the eight character password.</p>
<p>If an individual was required to have all 4 character strength requirements (uppercase and lowercase letters, numbers, and special characters) and had a six character password we can compute how many guesses you would need to crack the password.</p>
<p>Upper alpha = 26<br />
Lower alpha = 26<br />
Number = 10<br />
Special Char = 32</p>
<p>Note:  Special character support depends on the system.  In this example we are going with what Windows supports for passwords ()`~!@#$%^&amp;*-+=|\{}[]:;&#8221;&#8216;&lt;&gt;,.?/ and space.  Also of note is Windows supports 65,000 additional Unicode characters but we will keep it to symbols found on the keyboard.  Other systems do not support as many special characters as Windows.</p>
<p>94^6 = 689,869,781,056  (690 billion guesses).</p>
<p>Now we take a password with only upper and lowercase password requirements but make it an eight character minimum requirement.</p>
<p>Upper alpha = 26<br />
Lower alpha = 26</p>
<p>52^8 = 53,459,728,531,456 (53.5 trillion guesses).</p>
<p>As you can see the eight character password, with few character requirements, has 74 times more choices than a “complex” six character password.</p>
<p>How about some computational proof!  I use Cain &amp; Abel to show how long it would take to bruteforce the example above with an NTLM (local windows account) hash and a MS-Cache hash (domain windows account).  Note:  Brute force attempts also depend on the complexity of the encryption method used.  You will see that the complexity for an MS-Cache password is greater than NTLM.</p>
<p>NTLM six character, alphanumeric and special characters (<a title="Cain Screenshot" href="http://www.jedge.com/wordpress/wp-content/uploads/2009/10/six_char_NTLM.png">here</a>).<br />
NTLM eight character, alpha characters (<a title="Cain Screenshot" href="http://www.jedge.com/wordpress/wp-content/uploads/2009/10/eight_char_NTLM.png" target="_blank">here</a>).</p>
<p>MS-Cache six character, alphanumeric and special characters (<a title="Cain Screenshot" href="http://www.jedge.com/wordpress/wp-content/uploads/2009/10/six_char_MSCache.png">here</a>).<br />
MS-Cache eight character, alpha characters (<a title="Cain Screenshot" href="http://www.jedge.com/wordpress/wp-content/uploads/2009/10/eight_char_MSCache.png">here</a>).</p>
<p>You can see from the computational results from Cain &amp; Abel show that it takes about 80 times longer to brute force the less complex eight character password compared to the more complex six character password.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jedge.com/wordpress/?feed=rss2&amp;p=197</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NTBACKUP:  more than DR/BCP (Updated)</title>
		<link>http://www.jedge.com/wordpress/?p=182</link>
		<comments>http://www.jedge.com/wordpress/?p=182#comments</comments>
		<pubDate>Wed, 10 Jun 2009 17:13:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.jedge.com/wordpress/?p=182</guid>
		<description><![CDATA[An auditor&#8217;s interest in the Windows NTBACKUP Utility extends beyond examining their DR/BCP plan. Suppose you just got command prompt access to a server (example tutorial 1, 2, &#038; 3) but the host has anti-virus installed and you can&#8217;t disable it. You can&#8217;t use your trusty pwdump2 to dump the local password hashes (the same [...]]]></description>
			<content:encoded><![CDATA[<p>An auditor&#8217;s interest in the Windows NTBACKUP Utility extends beyond examining their DR/BCP plan.</p>
<p>Suppose you just got command prompt access to a server (example tutorial 1, 2, &#038; 3) but the host has anti-virus installed and you can&#8217;t disable it.  You can&#8217;t use your trusty pwdump2 to dump the local password hashes (the same utility that SQLAT and SQLNINJA use).  No problem, just use the ntbackup utility to make a current backup of the registry (including SAM and SYSTEM keys).<br />
<kbd><br />
C:\>ntbackup backup systemstate /j "Auditor Owns Your Hashes" /f "%systemroot%\temp\%Username%SysState.bkf" /a<br />
C:\>del "c:%systemroot%\temp\%Username%SysState.bkf"<br />
</kbd><br />
You don&#8217;t need the backup file you created so it can be deleted (C:\>del %systemroot%\temp\%Username%SysState.bkf).  When a backup is done of the systemstate the files in the %systemroot%\repair folder are updated.  Copy the sam, system, and security files from %systemroot%\repair.</p>
<p>Once those files are obtained you can use the command line utilities from the <a href="http://code.google.com/p/creddump/">creddump project</a> to produce the same files obtained form PWDumpX (see <a href="http://www.jedge.com/wordpress/?page_id=47">tuturial</a>).  </p>
<p>Python needs to be installed for creddump to work.  </p>
<p>Python version 2.5.4 from <a href="http://www.python.org/download/releases/2.5.4/">http://www.python.org/download/releases/2.5.4/</a><br />
Pycrypto version 2.0.1 from <a href="http://jintoreedwine.com/files_and_stuff/pycrypto-2-0-1.zip">http://jintoreedwine.com/files_and_stuff/pycrypto-2-0-1.zip</a></p>
<p><kbd>C:\creddump-0.1>pwdump.py SYSTEM SAM >> PWHashes.txt<br />
C:\creddump-0.1>lsadump.py SYSTEM SECURITY >> LSASecrets.txt<br />
C:\creddump-0.1>cachedump.py SYSTEM SECURITY >> PWCache.txt</kbd></p>
<p>Using RainbowCrack and the <a href="http://rainbowtables.shmoo.com/">rainbowtables</a> obtained from <a href="http://www.shmoo.com/">The Schmoo Group</a> you will be able to obtain the passwords to any local account with a password 14 characters or less from PWHashes.txt.</p>
<p>See this <a href="http://www.jedge.com/wordpress/?page_id=47">tuturial</a> on how to dictionary attack the passwords obtained from the PWCache.txt file.</p>
<p>You can review the LSASecrets.txt file to obtain plain text passwords for Windows service accounts.  Often these accounts are also Domain accounts with the same password or even Domain Administrator accounts.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jedge.com/wordpress/?feed=rss2&amp;p=182</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SQLNINJA:  SQL Injection</title>
		<link>http://www.jedge.com/wordpress/?p=173</link>
		<comments>http://www.jedge.com/wordpress/?p=173#comments</comments>
		<pubDate>Thu, 04 Jun 2009 13:54:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.jedge.com/wordpress/?p=173</guid>
		<description><![CDATA[On a recent pentest I was able to use SQLNINJA to exploit a SQL Injection vulnerability I had identified.  I documented the steps I took so that future auditors can take advantage of this tool.  Check out the tutorial here.]]></description>
			<content:encoded><![CDATA[<p>On a recent pentest I was able to use SQLNINJA to exploit a SQL Injection vulnerability I had identified.  I documented the steps I took so that future auditors can take advantage of this tool.  Check out the tutorial <a title="SQLNINJA Tutorial" href="http://www.jedge.com/wordpress/?page_id=140">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jedge.com/wordpress/?feed=rss2&amp;p=173</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Updated Configuration Tutorial</title>
		<link>http://www.jedge.com/wordpress/?p=169</link>
		<comments>http://www.jedge.com/wordpress/?p=169#comments</comments>
		<pubDate>Thu, 04 Jun 2009 10:59:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.jedge.com/wordpress/?p=169</guid>
		<description><![CDATA[I have created an updated configuration document for my Motion Computing m1300 wireless tablet. This document details getting Ubuntu 8.04 LTS Hardy Heron up and running on the tablet. Included in the documentation are the steps to get Kismet, Aircrack-ng, and Karmasploit up and running. Those steps will be helpful no matter what hardware you [...]]]></description>
			<content:encoded><![CDATA[<p>I have created an updated <a title="Ubuntu on Motion Computing m1300" href="http://www.jedge.com/docs/Wireless%20Hacking%20Tablet%20-%20Ubuntu%20Hardy%20Heron.pdf">configuration document</a> for my Motion Computing m1300 wireless tablet.  This document details getting Ubuntu 8.04 LTS Hardy Heron up and running on the tablet.  Included in the documentation are the steps to get Kismet, Aircrack-ng, and Karmasploit up and running.  Those steps will be helpful no matter what hardware you install Ubuntu on.</p>
<p>I have also created an <a href="http://www.jedge.com/docs/Linux%20Penetration%20Testing%20Laptop%20Setup%20v2.pdf">updated configuration</a> document for the setup of my Linux laptop that I use for penetration testing.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.jedge.com/wordpress/?feed=rss2&amp;p=169</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Auditing Remote Services from the Command Line</title>
		<link>http://www.jedge.com/wordpress/?p=89</link>
		<comments>http://www.jedge.com/wordpress/?p=89#comments</comments>
		<pubDate>Fri, 06 Mar 2009 14:06:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.jedge.com/wordpress/?p=89</guid>
		<description><![CDATA[During an audit I had to determine whether a particular remote control service was installed on the Domain workstations and servers. It was determined during the interview process that no remote control software was in use.  I decided to obtain the evidence to the contrary.  I had already compromised a Domain Administrator account so I [...]]]></description>
			<content:encoded><![CDATA[<p>During an audit I had to determine whether a particular remote control service was installed on the Domain workstations and servers.  It was determined during the interview process that no remote control software was in use.  I decided to obtain the evidence to the contrary.  I had already compromised a Domain Administrator account so I had the appropriate permissions.</p>
<p>Get a list of servers and workstations.<br />
<kbd>C:\&gt;net view /domain<br />
C:\&gt;net view /domain:&lt;domain_name&gt; &gt;&gt; host_list.txt</kbd></p>
<p>The host_list.txt will need to be edited as descriptions of the workstations and servers will show up to the right of the host name.  You can quickly edit it in Excel (text to columns).  Of course if this was Linux and /or you had awk you could pipe it and choose the first column (| awk &#8216;{print $1}&#8217;)</p>
<p>The command we will be using to query remote services is called Service Control (sc) from the Windows Resource Kit.  For more information on the command see this <a title="SC - Service Control" href="http://www.ss64.com/nt/sc.html" target="_blank">site</a>.</p>
<p><kbd>C:\&gt;for /f %i in (host_list.txt) do @echo %i &gt;&gt; results.txt &amp;&amp; sc %i query &lt;Service_Name&gt;</kbd></p>
<p>In addition to the service results I would like to have the fully qualified domain name and ip address of the server or workstation I am querying.  A quick addition of the nslookup command you and you get this:</p>
<p><kbd>C:\&gt;if /f %i in (host_list.txt) do @nslookup %i &gt;&gt; results.txt &amp;&amp; sc %i query &lt;Service_Name&gt; &gt;&gt; results.txt</kbd></p>
<p>Finally, I would like to know, with reasonable assurance, the user of that workstation.  For that we will be using a command line tool from the <a title="pstools download" href="http://technet.microsoft.com/en-us/sysinternals/bb896649.aspx">pstools</a> tool kit called psloggedin.  Once that tool is installed on your auditor workstation/laptop you can add it to our command.</p>
<p><kbd>C:\&gt;if /f %i in (host_list.txt) do @nslookup %i &gt;&gt; results.txt &amp;&amp; sc %i query &lt;Service_Name &gt;&gt; results.txt &amp;&amp; psloggedin -l -x %i &gt;&gt; results.txt</kbd></p>
<p>I wrote a quick script to parse the output of the above command so it can be sorted and analyzed in your preferred spreadsheet application.<br />
<pre><code>
#!/usr/bin/perl

$numArgs = $#ARGV +1;
if($numArgs &amp;lt; 1){
&nbsp;&nbsp;print &quot;Invalid Number of Arguments\n&quot;;
&nbsp;&nbsp;print &quot;serviceparse.pl \n\n&quot;;
&nbsp;&nbsp;exit;
}

#open the file
$infile = &quot;$ARGV[0]&quot;;
open(DAT, $infile) || die(&quot;Something did not work.&nbsp;&nbsp;You figure it out.&quot;);

#save file contents into an array
@raw_data=;
close(DAT);

#Cycle through the entire array
for($count=0;$count&amp;lt;=$#raw_data;$count++){

&nbsp;&nbsp;#get fully qualified domain name
&nbsp;&nbsp;if(@raw_data[$count] =~ /Name:/){
&nbsp;&nbsp;&nbsp;&nbsp;@array = split(/:/, @raw_data[$count]);
&nbsp;&nbsp;&nbsp;&nbsp;$host = @array[1];
&nbsp;&nbsp;&nbsp;&nbsp;$host =~ s/^s+//;
&nbsp;&nbsp;&nbsp;&nbsp;$host =~ s/s+$//;

&nbsp;&nbsp;&nbsp;&nbsp;#get ip address
&nbsp;&nbsp;&nbsp;&nbsp;@array = split(/:/, @raw_data[$count+1]);
&nbsp;&nbsp;&nbsp;&nbsp;$ip = @array[1];
&nbsp;&nbsp;&nbsp;&nbsp;$ip =~ s/^s+//;
&nbsp;&nbsp;&nbsp;&nbsp;$ip =~ s/s+$//;

&nbsp;&nbsp;&nbsp;&nbsp;$service = &quot;&quot;;
&nbsp;&nbsp;&nbsp;&nbsp;$user = &quot;&quot;;
&nbsp;&nbsp;&nbsp;&nbsp;for($c=$count+1;$c&amp;lt;=$#raw_data;$c++){

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if(@raw_data[$c] =~ /RUNNING/){
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$service = &quot;Installed and Running&quot;;
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if(@raw_data[$c] =~ /STOPPED/){
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$service = &quot;Installed and Stopped&quot;;
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if(@raw_data[$c] =~ /FAILED 1722/){
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$service = @raw_data[$c+2];
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$service =~ s/^s+//;
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$service =~ s/s+$//;
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if(@raw_data[$c] =~ /FAILED 1060/){
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$service = @raw_data[$c+2];
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$service =~ s/^s+//;
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$service =~ s/s+$//;
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if(@raw_data[$c] =~ /locally:/){
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;@array = split(//, @raw_data[$c+3]);
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$user = @array[1];
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$user =~ s/^s+//;
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;$user =~ s/s+$//;
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;}else {if(@raw_data[$c] =~ /Error opening HKEY_USERS/){$user = &quot;&quot;;}}

&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;if(@raw_data[$c] =~ /Server:/){print &quot;$host,$ip,$service,$user\n&quot;;last;}
&nbsp;&nbsp;&nbsp;&nbsp;}
&nbsp;&nbsp;}
}

</code></pre><br />
Run this script from the command line and pipe it to save the output.</p>
<p><kbd>$perl serviceparse.pl results.txt &gt; parseresults.csv</kbd></p>
]]></content:encoded>
			<wfw:commentRss>http://www.jedge.com/wordpress/?feed=rss2&amp;p=89</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
