<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Norwegian Honeynet Project &#187; Tips &amp; Tricks</title>
	<atom:link href="http://www.honeynor.no/category/tips-tricks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.honeynor.no</link>
	<description>A chapter of the Honeynet Project</description>
	<lastBuildDate>Mon, 06 Sep 2010 12:05:49 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Firefox prefetch</title>
		<link>http://www.honeynor.no/2010/05/18/firefox-prefetch/</link>
		<comments>http://www.honeynor.no/2010/05/18/firefox-prefetch/#comments</comments>
		<pubDate>Tue, 18 May 2010 22:47:10 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[config]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[precrime]]></category>
		<category><![CDATA[prefetch]]></category>
		<category><![CDATA[search]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=435</guid>
		<description><![CDATA[Are you aware of the effects of the network-prefetch-next preference in Firefox? It&#8217;s actually quite an old feature (according to this site it was introduced way back in 2003), but I&#8217;m pretty sure not everyone know the possibly scary side effect of this smart(tm) feature. It tries to make the browser being one step ahead [...]]]></description>
			<content:encoded><![CDATA[<p>Are you aware of the effects of the network-prefetch-next preference in Firefox? It&#8217;s actually quite an old feature (according to <a href="http://kb.mozillazine.org/Network.prefetch-next">this</a> site it was introduced way back in 2003), but I&#8217;m pretty sure not everyone know the possibly scary side effect of this smart(tm) feature. It tries to make the browser being one step ahead of its user, by prefetching sites it assumes the user will click on next.</p>
<p>This is what&#8217;s being logged on honeynor.no when I (84.215.x.y) google the word &#8220;<a href="http://www.google.com/#hl=en&#038;q=honeynor">honeynor</a>&#8220;.</p>
<p><code>84.215.x.y - - [18/May/2010:23:42:55 +0200] "GET / HTTP/1.1" 200 17832 "http://www.google.com/ \<br />
search?hl=en&#038;source=hp&#038;q=honeynor&#038;aq=f&#038;aqi=g-s1g-sx7&#038;aql=&#038;oq=&#038;gs_rfai=&#038;fp=64bbd6d9727d98e0" \<br />
"Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.3) Gecko/20100423 Ubuntu/10.04 (lucid) \<br />
Firefox/3.6.3"</code></p>
<p>I haven&#8217;t left google yet!, but my very intelligent browser thinks I might click on the first link (www.honeynor.no) so it goes ahead and access the site, way before my puny brain has had any chance on processing the search output. In true <a href="http://en.wikipedia.org/wiki/Philip_K._Dick">PKD</a>-style, I hereby accuse firefox of a precrime!</p>
<p>Why is this action bad? Let me answer the question with a question; Do you always want to access the sites presented to you when you search the web? I can think of several cases where I&#8217;m not keen on letting some third party know of my interest in them; either that&#8217;s during an analysis or in case of possible repercussions against me for accessing a site in an unexpected or socially engineered manner.</p>
<p>It seems google is in cahoots with firefox on this one, because I&#8217;m unable to reproduce the same result using bing, yahoo or alltheweb. Only on google is the prefetch mechanism activated.</p>
<p>So, how can you disable this feature? Luckily it very easy; go to <strong>about:config</strong> in your firefox/mozilla browser and set the parameter <strong>network.prefetch-next</strong> to <strong>false</strong>. That&#8217;s it! </p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2010/05/18/firefox-prefetch/" type="text/javascript" charset="utf-8"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2010/05/18/firefox-prefetch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox 3.6.x and vmrc</title>
		<link>http://www.honeynor.no/2010/05/04/firefox-3-6-x-and-vmrc/</link>
		<comments>http://www.honeynor.no/2010/05/04/firefox-3-6-x-and-vmrc/#comments</comments>
		<pubDate>Tue, 04 May 2010 21:11:51 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[console]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[plugin]]></category>
		<category><![CDATA[remote]]></category>
		<category><![CDATA[server]]></category>
		<category><![CDATA[vmrc]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=424</guid>
		<description><![CDATA[Recently I upgraded to the 3.6 series of Firefox (3.6.3 to be exact), and suddenly my VMware Remote Console (vmrc) was broken. We use VMware Server 2.0.1, but upgrading to the latest 2.0.2, didn&#8217;t help. At closer inspection, the problem was not with the server nor with vmrc itself, but rather with the integration of [...]]]></description>
			<content:encoded><![CDATA[<p>Recently I upgraded to the 3.6 series of Firefox (3.6.3 to be exact), and suddenly my VMware Remote Console (vmrc) was broken. We use VMware Server 2.0.1, but upgrading to the latest 2.0.2, didn&#8217;t help. At closer inspection, the problem was not with the server nor with vmrc itself, but rather with the integration of the plugin used with Firefox 3.6 (I&#8217;m using VMware Remote Console Plug-in 2.5.0.122581). Whether the problem is related to the plug-in or FF 3.6&#8242;s plug-in framework (or a combination of the two), I do not know. What I do know though, is that you don&#8217;t have to downgrade to FF 3.5.x if you use the following workaround.</p>
<p>On your vmware server, go to the following directory:<br />
<code style="font-size: 1.4em;">/usr/lib/vmware/webAccess/tomcat/ \<br />
apache-tomcat-6.0.16/webapps/ui/plugin/</code></p>
<p>Copy the appropriate vmrc plugin for your client platform (mine was a 32 bit Ubuntu 10.04 Desktop, so I grabbed vmware-vmrc-linux-x86.xpi).</p>
<p>On your client, unzip the xpi-file:</p>
<p><code style="font-size: 1.4em;">$ unzip vmware-vmrc-linux-x86.xpi</code></p>
<p>Run the vmrc executable (it&#8217;s actually just a wrapper script) manually by specifying the absolute path (I extracted the contents to /tmp):</p>
<p><code style="font-size: 1.4em;">$ /tmp/vmrc/plugins/vmware-vmrc</code></p>
<p>The vmrc UI starts, and you can connect to your vmware server by either specifying it&#8217;s hostname or it&#8217;s IP-address, together with your username and password (I also had to specify the port, e.g. &lt;IP&gt;:8333). When a connection has been established with the server, you will be presented with a selection of virtual machines you may connect to.</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2010/05/04/firefox-3-6-x-and-vmrc/" type="text/javascript" charset="utf-8"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2010/05/04/firefox-3-6-x-and-vmrc/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using Nmap to scan for Conficker</title>
		<link>http://www.honeynor.no/2009/03/31/using-nmap-to-scan-for-conficker/</link>
		<comments>http://www.honeynor.no/2009/03/31/using-nmap-to-scan-for-conficker/#comments</comments>
		<pubDate>Tue, 31 Mar 2009 20:24:05 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Nmap]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=136</guid>
		<description><![CDATA[As a result of the latest KYE paper (Containing Conficker), many of the scanner tools out there have implemented (or are in the process of doing so) the method presented in chapter 5 of the paper, which explains basically how you may remotely scan a machine, and have the machine tell you whether or not [...]]]></description>
			<content:encoded><![CDATA[<p>As a result of the latest <a href="https://www.honeynet.org/papers/conficker/">KYE paper (Containing Conficker)</a>, many of the scanner tools out there have implemented (or are in the process of doing so) the method presented in chapter 5 of the paper, which explains basically how you may remotely scan a machine, and have the machine tell you whether or not Conficker has compromised the system. The method works for all current Conficker variants and is indiscriminate of the infection vector!</p>
<p><a href="http://nmap.org/">Nmap</a> was one of the first tools to implement this. Lets try it out!</p>
<p>Download the latest development release from <a href="http://download.insecure.org/nmap-dist/">http://download.insecure.org/nmap-dist/</a> (at the time of writing: <a href="http://nmap.ucsd.edu/nmap/dist/nmap-4.85BETA6.tar.bz2">4.85BETA6</a>) and the usual configure, make, sudo make install should to the trick, but in case you run into compile- or run-time errors you may want to check out <a href="http://nmap.org/book/inst-source.html">this page</a>. (If you face run-time complaints about openssl, you should follow <a href="http://www.skullsecurity.org/blog/?p=209">this link</a>). There&#8217;s also binaries available for <a href="http://nmap.ucsd.edu/nmap/dist/nmap-4.85BETA6-setup.exe">Windows</a> and <a href="http://nmap.ucsd.edu/nmap/dist/nmap-4.85BETA6.dmg">OSX</a>.</p>
<p>The following is an example of a basic scan for conficker</p>
<p><code style="font-size:1.4em;">nmap -sC -PN -d -p445 --script=smb-check-vulns \<br />
--script-args=safe=1 192.168.1.1</code></p>
<p>For large-scale scans, you may invoke nmap with some optimisations parameters as <a href="http://seclists.org/nmap-dev/2009/q1/0869.html">recommended here</a>.</p>
<p><code style="font-size:1.4em;">nmap -sC -PN -d -p445 -n -T4 --min-hostgroup 256 \<br />
--min-parallelism 64 --script=smb-check-vulns \<br />
--script-args=safe=1 10.0.0.0/8</code></p>
<p>In addition to the no-ping (PN) and port specific scan (p) we added no-dns-resolution (n), more aggressive timing controls (T) and parallel scanning with group of 256 hosts (with at least 64 simultaneously). The two latter parameters may be tuned even further for increased performance. <a href="http://seclists.org/nmap-dev/2009/q1/0869.html">The recommendation</a> is to maintain a 4:1 ratio between the two values, and keep the upper limit to 4096/1024.</p>
<p>Using safe=1 as an argument sent to the script, the <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx">MS08-067 vulnerability</a> is not really checked. Using unsafe=1 and it will be checked, however be aware of a possibility that the vulnerable server service may crash.</p>
<p>Here are some examples of the output from the script smb-check-vulns (with MS08-067 check enabled):</p>
<pre>|  MS08-067: LIKELY VULNERABLE (host stopped responding)
|  Conficker: Likely INFECTED

|  MS08-067: FIXED
|  Conficker: Likely CLEAN</pre>
<p>&#8230;So, scan your network now, while it&#8217;s still possible.</p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2009/03/31/using-nmap-to-scan-for-conficker/" type="text/javascript" charset="utf-8"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2009/03/31/using-nmap-to-scan-for-conficker/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Daemonlogger Patch</title>
		<link>http://www.honeynor.no/2008/08/01/daemonlogger-patch/</link>
		<comments>http://www.honeynor.no/2008/08/01/daemonlogger-patch/#comments</comments>
		<pubDate>Fri, 01 Aug 2008 22:33:52 +0000</pubDate>
		<dc:creator>Tor Inge Skaar</dc:creator>
				<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[packet capture]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[trace]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=31</guid>
		<description><![CDATA[I&#8217;ve been using Daemonlogger now for some time, and really like this compact yet highly functional packet capture tool from Marty Roesch (mr. Snort himself). It&#8217;s libpcap based and has some nice features like log-&#038;-replay, log rotation and ring-buffer. Features that are missing in the tcpdump implementation I used prior to Daemonlogger. In many situations [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.honeynor.no/img/daemonlogger.png" alt="A demonic log..." style="margin: 5px" align="right" />I&#8217;ve been using <a href="http://www.snort.org/users/roesch/Site/Daemonlogger/Daemonlogger.html">Daemonlogger</a> now for some time, and really like this compact yet highly functional packet capture tool from Marty Roesch (mr. Snort himself). It&#8217;s libpcap based and has some nice features like log-&#038;-replay, log rotation and ring-buffer. Features that are missing in the tcpdump implementation I used prior to Daemonlogger.</p>
<p>In many situations I like to use the <span style="font-family:monospace; font-size:1.3em;">-t</span> option to partition the log files based on time, e.g. <span style="font-family:monospace; font-size:1.3em;">-t 1h</span> to get one pcap file each hour (aligned on the hour). Also, I usually create a dedicated disk partition for pcap storage. In these situations I think Daemonlogger doesn&#8217;t quite &#8220;cut the mustard&#8221;. It&#8217;s missing an easy way to have it utilize most of the dedicated disk space and rotating the pcap files based on time intervals whilst maintaining an active ring-buffer. Of course, you may use the <span style="font-family:monospace; font-size:1.3em;">-s</span> option to rotate based on the size of the log file (in bytes) and also set a count limit with <span style="font-family:monospace; font-size:1.3em;">-m</span>. But, as I mentioned, I&#8217;m more of a time guy.</p>
<p>This is why I made a small patch to Daemonlogger which implements the missing feature. The added option (<span style="font-family:monospace; font-size:1.3em; font-weight:bold;">-x</span>) lets you specify the amount of free space you want to have on the disk where the pcap files are stored.</p>
<p><code>daemonlogger -i eth0 -d -l /var/log/pcap -S 0 -t 1h <span style="color:red;">-x 500</span> -r</code></p>
<p>In the above example, daemonlogger sniffs on eth0 interface, runs in daemon mode, logs to <span style="font-family:monospace; font-size:1.3em;">/var/log/pcap</span> with a max snap length and creates a new file every hour on the hour. When there is less than 500 MiB of free space on the disk device that holds <span style="font-family:monospace; font-size:1.3em;">/var/log/pcap</span>, the ring-buffer will activate and delete the oldest file in that directory.</p>
<p><strong>Download file: <a href="http://www.honeynor.no/tools/daemonlogger.honeynor.patch">daemonlogger.honeynor.patch</a></strong></p>
<p>Disclamer: <em>I&#8217;m by no means an experienced C-programmer, so you&#8217;re on your own pal if you apply this patch :)</em></p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2008/08/01/daemonlogger-patch/" type="text/javascript" charset="utf-8"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2008/08/01/daemonlogger-patch/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Deobfuscating JavaScripts</title>
		<link>http://www.honeynor.no/2008/04/01/deobfuscating-javascripts/</link>
		<comments>http://www.honeynor.no/2008/04/01/deobfuscating-javascripts/#comments</comments>
		<pubDate>Tue, 01 Apr 2008 14:47:19 +0000</pubDate>
		<dc:creator>mkrakvik</dc:creator>
				<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[neosploit]]></category>
		<category><![CDATA[spidermonkey]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/?p=17</guid>
		<description><![CDATA[With the recent update of the Neosploit exploit pack, I thought I&#8217;d share a small tip on how to deobfuscate these kind of attacks. Here&#8217;s a short video demonstrating a generic method of deobfuscating JavaScripts, using the SpiderMonkey JavaScript interpreter and overriding the eval()-function. Hope you&#8217;ll find it useful! Get the Flash Player to see [...]]]></description>
			<content:encoded><![CDATA[<p>With the recent update of the <a title="Neosploit Updated with Exploit" href="http://www.symantec.com/enterprise/security_response/weblog/2008/03/neosploit_updated_with_exploit.html" target="_self">Neosploit</a> exploit pack, I thought I&#8217;d share a small tip on how to deobfuscate these kind of attacks. Here&#8217;s a short video demonstrating a generic method of deobfuscating JavaScripts, using the <a title="SpiderMonkey (JavaScript-C) Engine" href="http://www.mozilla.org/js/spidermonkey/" target="_self">SpiderMonkey</a> JavaScript interpreter and overriding the eval()-function. Hope you&#8217;ll find it useful!</p>
<div id="container" style="position: relative; left: -9px;"><a href="http://www.macromedia.com/go/getflashplayer">Get the Flash Player</a> to see this player.<br />
<script src="http://www.honeynor.no/~mkrakvik/movies/swfobject.js" type="text/javascript"></script><br />
 <script type="text/javascript"><!--
        var s1 = new SWFObject("/flvplayer/mediaplayer.swf","mediaplayer","416","307","7");
        s1.addParam("allowfullscreen","true");
        s1.addVariable("width","416");
        s1.addVariable("height","300");
        s1.addVariable("file","http://www.honeynor.no/~mkrakvik/movies/neosploit/neosploit.flv");
        s1.addVariable("image","http://www.honeynor.no/~mkrakvik/movies/neosploit/neosploit.png");
        s1.write("container");
// -->
</script></div>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2008/04/01/deobfuscating-javascripts/" type="text/javascript" charset="utf-8"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2008/04/01/deobfuscating-javascripts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Malware unpacking in OllyDbg</title>
		<link>http://www.honeynor.no/2008/03/26/malware-unpacking-in-ollydbg/</link>
		<comments>http://www.honeynor.no/2008/03/26/malware-unpacking-in-ollydbg/#comments</comments>
		<pubDate>Wed, 26 Mar 2008 11:48:20 +0000</pubDate>
		<dc:creator>mkrakvik</dc:creator>
				<category><![CDATA[Tips & Tricks]]></category>
		<category><![CDATA[Videos]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[ollydbg]]></category>
		<category><![CDATA[unpacking]]></category>

		<guid isPermaLink="false">http://www.honeynor.no/index.php/2008/03/26/malware-unpacking-in-ollydbg/</guid>
		<description><![CDATA[From time to time, we come across malware that is more interesting than others. A couple of months ago we saw a trojan bot with MSN spreading capabilities. And as usual, the malware was packed. However, I was not able to identify the packer being used (using PEiD, and similar tools). So I tried unpacking [...]]]></description>
			<content:encoded><![CDATA[<p>From time to time, we come across malware that is more interesting than others. A couple of months ago we saw a trojan bot with MSN spreading capabilities. And as usual, the malware was packed. However, I was not able to identify the packer being used (using PEiD, and similar tools). So I tried unpacking this sample manually in OllyDbg, and discovered that it was actually using threads to unpack itself, something I haven&#8217;t seen before.</p>
<p>Below you can find my very first screencast, showing how this sample was unpacked. Enjoy! :)</p>
<p><a href="http://www.honeynor.no/~mkrakvik/movies/msnbot/index.html" title="Malware unpacking in OllyDbg" target="_blank"><img src="http://honeynor.no/~mkrakvik/movies/msnbot/msnbot.png" alt="Unpacking in OllyDbg" height="240" width="320" /></a></p>
<p><em> (will open in new window)</em></p>
<div id="flaresmith" class="feedflare"><script src="http://feeds.feedburner.com/~s/honeynor?i=http://www.honeynor.no/2008/03/26/malware-unpacking-in-ollydbg/" type="text/javascript" charset="utf-8"></script></div>]]></content:encoded>
			<wfw:commentRss>http://www.honeynor.no/2008/03/26/malware-unpacking-in-ollydbg/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
