Rabu, 09 Juni 2004

Sguil 0.4.0, Snort 2.1.3, Barnyard 0.2.0 Installation Guide Published

I just published a new guide for installing Sguil 0.4.0 with Snort 2.1.3 and Barnyard 0.2.0. This guide contains sections for each Sguil component, namely the sensor, database, server, and client. The dependency listings should help users deploy Sguil in a distributed manner, rather than running all components on a single platform. Please email sguil at taosecurity dot com if you have any comments on this guide.

Senin, 07 Juni 2004

Review of Anti-Spam Tool Kit Posted

Amazon.com just published my four star review of Anti-Spam Tool Kit. From the review:


"I've never been interested in viruses, worms, or spam. All three represent the lowest end of malware, with spam occupying a particularly disdainful place in the computer security hierarchy. I wasn't very excited when a review copy of "Anti-Spam Tool Kit" (ASTK) arrived in the mail, but I found myself drawn in by the value of the content and tools it described. I highly recommend anyone tasked with fighting spam read ASTK."

Update: Paul Wolfe sent a nice email regarding my review. I recommend if you have comments on ASTK you visit the ASTK book site at www.vorpalmedia.com. Tell him what you'd like to see in a second edition or comments on the first edition.

Jumat, 04 Juni 2004

Report on Compatible Devices in FreeBSD

Sometimes it helps to know what hardware is compatible with non-Windows operating systems like FreeBSD. I wanted to buy a CompactFlash card and reader to work with my Soekris net4801 platform. I used the list at the flashdist site to guide my product purchase. I bought a SanDisk ImageMate 8 in 1 Reader/Writer, model SDDR-88-A15, pictured at above left. I also bought a 256 MB Type 1 CompactFlash card (product ID SDCFB-256-A10). Although the reader supports USB 2.0, my laptop natively only supports USB 1.1. I do own an Adaptec DuoConnect adapter, but only the FireWire port works. I have not had any luck with FreeBSD 5.2.1 REL and the ehci. driver.

Here is what dmesg reports when I attach the CF reader (with CF card inserted) to the USB port on my laptop:
umass0: SanDisk ImageMate 8 in 1, rev 2.00/91.39, addr 2

GEOM: create disk da0 dp=0xc3a81450

da0 at umass-sim0 bus 0 target 0 lun 0

da0: Removable Direct Access SCSI-0 device

da0: 1.000MB/s transfers

da0: 245MB (501760 512 byte sectors: 64H 32S/T 245C)

GEOM: create disk da1 dp=0xc3ab2850

da1 at umass-sim0 bus 0 target 0 lun 1

da1: Removable Direct Access SCSI-0 device

da1: 1.000MB/s transfers

da1: Attempt to query device size failed: NOT READY, Medium not present

...truncated...


You see the CF card is present on device da0, but devices da1 and up aren't ready as there's nothing inserted in those slots.


Using the device for storage is simple:


orr:/home/richard$ sudo mount -t msdos /dev/da0s1 /floppy

orr:/home/richard$ ls /floppy/

orr:/home/richard$ df -h

Filesystem Size Used Avail Capacity Mounted on

/dev/ad0s2a 5.8G 3.3G 2.0G 62% /

devfs 1.0K 1.0K 0B 100% /dev

/dev/ad0s2d 1.9G 1.2G 589M 68% /home

/dev/ad0s2f 739M 17M 662M 3% /tmp

/dev/ad0s2e 4.4G 135M 3.9G 3% /var

linprocfs 4.0K 4.0K 0B 100% /usr/compat/linux/proc

neely:/usr/ports 12G 8.1G 2.5G 76% /usr/ports

/dev/da0s1 244M 8.0K 244M 0% /floppy


I tried the CF reader in a machine with ehci support compiled in to the kernel, since it has USB 2.0 ports built-in. I got errors saying "usb3: unrecoverable error, controller".
As I mentioned the Adaptec DuoConnect earlier, here is how it appears in dmesg when attached:


cardbus1: Resource not specified in CIS: id=10, size=800

cardbus1: Resource not specified in CIS: id=14, size=4000

fwohci0: mem 0x88000000-0x88003fff,0x88004000-0x88 0047ff irq 11 at device 0.0 on cardbus1

fwohci0: OHCI version 1.10 (ROM=1)

fwohci0: No. of Isochronous channel is 4.

fwohci0: EUI64 08:00:28:56:02:00:49:8a

fwohci0: Phy 1394a available S400, 3 ports.

fwohci0: Link S400, max_rec 2048 bytes.

firewire0: on fwohci0

fwe0: on firewire0

if_fwe0: Fake Ethernet address: 0a:00:28:00:49:8a

sbp0: on firewire0

fwohci0: Initiate bus reset

fwohci0: BUS reset

fwohci0: node_id=0xc000ffc0, gen=1, CYCLEMASTER mode

firewire0: 1 nodes, maxhop <= 0, cable IRM = 0 (me)

firewire0: bus manager 0 (me)

cardbus1: Resource not specified in CIS: id=10, size=1000

ohci0: mem 0x88000000-0x88000fff irq 11 at device 0.4 on cardbus1

usb1: OHCI version 0.0

usb1: unsupported OHCI revision

ohci0: USB init failed

device_probe_and_attach: ohci0 attach returned 5

cardbus1: Resource not specified in CIS: id=10, size=1000

ohci0: mem 0x88000000-0x88000fff irq 11 at device 0.5 on cardbus1

usb1: OHCI version 15.15, legacy support

usb1: unsupported OHCI revision

ohci0: USB init failed

device_probe_and_attach: ohci0 attach returned 5

cardbus1: Resource not specified in CIS: id=10, size=100

cardbus1: at device 0.6 (no driver attached)

Although USB 2.0 doesn't work with this adapter, FireWire appears to be supported. I'm not the only person who has experience with this NEC chipset and USB 2.0 (see this thread.) I bought a Plextor 708UF external DVD burner, which offers USB 2.0 and FireWire support. Here is how it appears when connected to the Adaptec DuoConnect:


fwohci0: BUS reset

fwohci0: node_id=0xc000ffc1, gen=3, CYCLEMASTER mode

firewire0: 2 nodes, maxhop <= 1, cable IRM = 1 (me)

firewire0: bus manager 1 (me)

fwohci0: BUS reset

fwohci0: node_id=0xc000ffc1, gen=4, CYCLEMASTER mode

firewire0: 2 nodes, maxhop <= 1, cable IRM = 1 (me)

firewire0: bus manager 1 (me)

firewire0: New S400 device ID:00d0a910023005cd

GEOM: create disk cd0 dp=0xc4220e00

cd0 at sbp0 bus 0 target 0 lun 0

cd0: Removable CD-ROM SCSI-0 device

cd0: 50.000MB/s transfers

cd0: Attempt to query device size failed: NOT READY, Medium not present - tray closed


Notice the "1.06" in the output. That is the drive's firmware version. If I need to update it, I can use PXUpdate, as explained here.

Since this DuoConnect supports FireWire so well, maybe I should have bought a SanDisk Ultra Firewire ImageMate Reader (CDW sells them for $42). If I only wanted to use the CF card with my laptop, I could have also purchased a SanDisk PC Card Adapter .

I'm making this blog entry using a USB 200M 10/100 NIC. While I can't boot with it attached, once I insert it into my USB port it appears like this to dmesg:



axe0: Linksys product 0x2226, rev 2.00/0.01, addr 2

axe0: Ethernet address: 00:10:60:25:a4:1a

miibus1: on axe0

rlphy0: on miibus1

rlphy0: 10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, auto


It's easy to configure it:


orr:/home/richard$ sudo ifconfig axe0 inet 192.168.2.5 netmask 255.255.255.0 up

orr:/home/richard$ sudo route add default 192.168.2.1

add net default: gateway 192.168.2.1

orr:/home/richard$ ping www.google.com

PING www.google.akadns.net (216.239.39.104): 56 data bytes

64 bytes from 216.239.39.104: icmp_seq=0 ttl=240 time=23.568 ms

^C


Since USB 1.1 "Full speed" supports 12 Mbps, I can't make full utilization of a 100 Mbps link. Since this NIC connects to a wireless 802.11b bridge, which eventually connects to a cable modem, the NIC isn't the bottleneck. USB 2.0 "High speed" supports 480 Mbps, and IEEE 1394a ("FireWire 400") supports 400 Mbps.

Kamis, 03 Juni 2004

Fixing Troublesome Port Upgrades

Today while trying to run portupgrade on my FreeBSD 5.2.1 REL system, I ran into this error:

drury# portupgrade -varp

---> Upgrade of devel/libbonobo started at: Thu, 03 Jun 2004 15:43:31 -0400
---> Upgrading 'libbonobo-2.6.0' to 'libbonobo-2.6.2' (devel/libbonobo)
---> Build of devel/libbonobo started at: Thu, 03 Jun 2004 15:43:31 -0400
---> Building '/usr/ports/devel/libbonobo'
===> Cleaning for libiconv-1.9.1_3
===> Cleaning for ORBit2-2.10.2
...edited...
===> Configuring for libbonobo-2.6.2
checking for a BSD-compatible install... /usr/bin/install -c -o root -g wheel
checking whether build environment is sane... yes
checking for gawk... no
checking for mawk... no
checking for nawk... nawk
checking whether gmake sets $(MAKE)... yes
checking whether to enable maintainer-specific portions of Makefiles... no
checking for perl... /usr/bin/perl
configure: error: XML::Parser perl module is required for intltool
===> Script "configure" failed unexpectedly.
Please report the problem to gnome@FreeBSD.org [maintainer]
and attach
the "/usr/ports/devel/libbonobo/work/libbonobo-2.6.2/config.log" including
the output of the failure of your make command. Also, it might be
a good idea to provide an overview of all packages installed on your
system (e.g. an `ls /var/db/pkg`).
*** Error code 1

Stop in /usr/ports/devel/libbonobo.

I found a thread with a similar problem. I also found an error, so I tried the following solution. I told portupgrade to upgrade the p5-XML-Parser port, which intltool complained about above. By using the -f switch I forced the reinstallation of the p5-XML-Parser port, and the -r switch told portupgrade to upgrade ports depending on p5-XML-Parser. This resulted in reinstallation of intltool and

drury# portupgrade -r -f p5-XML-Parser
---> Reinstalling 'p5-XML-Parser-2.34_1' (textproc/p5-XML-Parser)
---> Building '/usr/ports/textproc/p5-XML-Parser'
===> Cleaning for perl-5.8.4
...edited...
tar: lib/perl5/site_perl/5.6.1/mach/XML/Parser/LWPExternEnt.pl:
Cannot stat: No such file or directory
tar: Error exit delayed from previous errors
pkg_create: make_dist: tar command failed with code 512
---> Uninstalling the old version
---> Deinstalling 'p5-XML-Parser-2.34_1'
pkg_delete: package 'p5-XML-Parser-2.34_1' is
required by these other packages and may not be deinstalled
(but I'll delete it anyway):
eel2-2.6.1
gedit2-2.6.1
gtksourceview-1.0.1
intltool-0.30_1
libbonoboui-2.6.1
libgnome-2.6.1.1
libgnomeui-2.6.1.1
scrollkeeper-0.3.14_1,1
pkg_delete: file '/usr/local/lib/perl5/5.6.1/man/man3/XML::Parser.3.gz'
doesn't
really exist
pkg_delete: file '/usr/local/lib/perl5/5.6.1/man/man3/XML::Parser::Expat.3.gz'
doesn't really exist
pkg_delete: file '/usr/local/lib/perl5/5.6.1/man/man3/XML::Parser::Style::Debug.
3.gz'
doesn't really exist
...edited...
Installing /usr/local/lib/perl5/5.8.4/man/man3/XML::Parser::Style::Stream.3
Writing /usr/local/lib/perl5/site_perl/5.8.4/mach/auto/XML/Parser/.packlist
===> Compressing manual pages for p5-XML-Parser-2.34_1
===> Registering installation for p5-XML-Parser-2.34_1
===> Cleaning for perl-5.8.4
===> Cleaning for expat-1.95.7
===> Cleaning for p5-XML-Parser-2.34_1
---> Cleaning out obsolete shared libraries
[Updating the pkgdb in /var/db/pkg ... - 196 packages found
(-0 +1) . done]
---> Reinstalling 'intltool-0.30_1' (textproc/intltool)
---> Building '/usr/ports/textproc/intltool'
===> Cleaning for libiconv-1.9.1_3
...truncated...

When this was done I upgraded libbonobo independently:

drury# portupgrade -v libbonobo
---> Session started at: Thu, 03 Jun 2004 16:31:27 -0400
---> Upgrade of devel/libbonobo started at: Thu, 03 Jun 2004 16:31:28 -0400
---> Upgrading 'libbonobo-2.6.0' to 'libbonobo-2.6.2' (devel/libbonobo)
---> Build of devel/libbonobo started at: Thu, 03 Jun 2004 16:31:28 -0400
---> Building '/usr/ports/devel/libbonobo'
===> Cleaning for libiconv-1.9.1_3
===> Cleaning for ORBit2-2.10.2
===> Cleaning for bison-1.75_2
===> Cleaning for gettext-0.13.1_1
===> Cleaning for glib-2.4.1_1
===> Cleaning for gmake-3.80_2
===> Cleaning for libIDL-0.8.3_2
===> Cleaning for m4-1.4_1
===> Cleaning for pkgconfig-0.15.0_1
===> Cleaning for popt-1.6.4_2
===> Cleaning for perl-5.8.4
===> Cleaning for python-2.3.4
===> Cleaning for intltool-0.30_1
===> Cleaning for libxml2-2.6.9
===> Cleaning for p5-XML-Parser-2.34_1
===> Cleaning for libbonobo-2.6.2
===> Extracting for libbonobo-2.6.2

That took care of the earlier problems and updated the port.

Review of Anti-Hacker Tool Kit, 2nd Ed Posted

Amazon.com just published my four star review of Anti-Hacker Tool Kit, 2nd Ed. From the review:


"I reviewed the first edition "Anti-Hacker Tool Kit" (AHT:1E) in August 2002. This second edition (AHT:2E) follows only 18 months after the original was published. I don't believe enough time has passed to warrant an update, even though tools can evolve quickly. In certain aspects the book suffers from a lack of updates from AHT:1E author Keith Jones, who found the publisher's demands onerous. Nevertheless, AHT:2E is a must-buy if you didn't read AHT:1E."

Rabu, 02 Juni 2004

Good News from Snort Land

I have two good pieces of news from the Snort development team. First, Snort 2.1.3 has been released. The big deal with this new release is multi event logging via event queue. This feature lets Snort generate multiple alerts per packet or stream, rather than alerting once and then moving on to the next packet or stream. It was introduced to address what H.D. Moore calls event masking.

The second good piece of news is the appearance of Sguil in several publications and presentations. First, Marty Roesch's AUSCERT 204 presentation (.pdf) includes Sguil along with ACID as two consoles for Snort. Sguil also appears in two new books, Syngress' Snort 2.1 and O'Reilly's Network Security Hacks. Both books spend most of their time explaining how to install older versions of Sguil, but it's the thought that counts.

Now that Snort 2.1.3 has been released, I plan to upgrade my Sguil for FreeBSD installation guide to use the new Snort, plus Barnyard 0.2.0, Sguil 0.4.0, MySQL 4.0.20, and other updated supporting applications.

Review of Hacking Exposed: Windows 2003 Posted

Amazon.com just posted my four star review of Hacking Exposed: Windows Server 2003. From the review:


"HE:W03 is still the best book available if you want to learn how to assess and compromise Windows servers using publicly available tools. It will not teach original exploitation techniques like coding exploits, although this is usually unnecessary when admins deploy stock servers with blank administrator passwords. The authors are experts when it comes to performing pen tests of Windows targets, even though they are unapologetic Windows fans. (Page 195 bears the quote "command-line brain damage of Linux.") Their bias is also apparent as they question the applicability of the word "monopoly" to Microsoft (a legal fact); this isn't surprising given the authors' employers. Their bias also colors their judgment in the introduction, where they propose that security is a zero sum game between security and usability. Attitudes like that can no longer cover for Microsoft's security lapses."