Showing posts with label networking. Show all posts
Showing posts with label networking. Show all posts

Friday, September 21, 2012

One of the ones I didn't like

So I mentioned in the Plan for IA240 blog post, I had some other ideas. Ones that I decided to not go with for various reasons.

One to those ideas that I rejected:

Using a tablet, with my cell phone as a tether. I tried using my cellphone in class the first night. It didn't work too well. It was rather slow Googling questions the professor was asking.

I also didn't like the idea for a hand full of reasons. I could be wrong, because I don't understand all the tech.

First the tethering. I have a rooted (running cyanogen mod) cell phone, but every time I tried, I get messages saying the network I have for service is blocking it.

I'm still creating a wireless network that someone could try attacking. Other people wanting to connect. Not saying people would, but hacking wifi isn't that hard, and if they're willing to go after a laptop, why not go easier with a wifi connection.

I've only used Shark for Root sparingly. As I understand it, it can do 3g packet captures. I'm not sure if that's only for the phone it's on, or if it can grab any 3g signal. I also haven't found much documentation on it. I also don't have the equipment to test it properly at this time. Maybe we can set something like that up to EMU's IA Club, where we can play around with it and see what it does.

Just one of the ideas, I tossed to the side. I'll talk about another one some other time.


Saturday, September 15, 2012

Plan for IA-240 at Eastern Mi.

** This has been updated:

So one of the classes I'm taking this term is required for my degree. And I have to worry about protecting my computer in it.

The course:
IA 240. The main point of the class, that I took away from the first night, is to learn how to write Analyst reports. The over all goal is to give us the skills required to go work for a government agency. (The program has a lot of students leave and get jobs in the public sector).

The Final:
The professor will assign us something to do an analysis report on at the end of the semester. To teach us on Operational Security, we have to protect our final project from our class mates. He gives extra credit for each student we got information from.

The Problem:
The professor has already said we are required to bring laptops to class, and class mates, as in the past, will try hacking that computer to get your final project. **Update-1: This was said in a warning, not in a you will be hacking each other in this class.

Over all, knowing the above, one really wants to get your hacks in early, get a back door, and be able to come in to the classmates boxes at will. Lots of way to do that. But I'm about not being an easy target. In fact I don't want my system compromised.

Options to protect me:
- Change operating systems every class, either local install, from USB, or DVD / CD.
- Run Backtrack, and use that as the the desktop (not meant for that).
- Run TAILS
- buy dedicated machine, and use nothing on it, doing forensics on it at the end of the semester, and keep nothing on it.
- Be really evil... (run vm or a dedicated box with a sticky honeypot).

The Plan:
I don't have the money for the dedicated machines.

I thought about putting my money where my mouth is and installing Backtrack, on an old hard drive, then harden it. This would fit in with my Linux Hardening applied to BackTrack talk. However don't like the idea of swapping the hardware that often. Trying to hack my class mates would be un-ethical in my eyes anyway.

I don't have an interest in hacking my class mates. Just not being hacked.

So, I've already got Full Disk Encryption, I'm going run with The Amnesic Incognito Live System (TAILS). I'll take an energy hit, the main hard drive won't be touched.

The only thing I have to worry about is saving my work from class (not that I type much in class, I'm more about pen and paper). But if there is something I need to save, I have things for that. I'm using Google's two factor authentication. I also could look into doing File System over SSH. Not sure if I'll have to go that far.



*Update-1: the professor was not giving permission. he was giving a warning.








Sunday, July 10, 2011

some days

Last night / this morning was a maintenance window at work. Lots of stuff to do. One call had about 30 people on it.

Now I'm the junior most member on my team. There are still things I don't know how to or can't do. Not that I don't know how. I mean I know how did them at my last job. Just don't know how we do them at this job. Can't because I don't have the needed access. Some of it I'm figuring out how to do work's way.

Anyway. there was an issue with an SSL cert. Really looks like someone sent us the wrong information in the turn up requests, since the same typo was in all of it (DNS and SSL). Anyway that got fixes late last night, but the people who were complaining didn't bother to test it. Ended paging everyone on my team. The one that fixed it asked why I didn't test it. Which I was in the process of doing when the other people said to start making the pages. Really those should come from me, not other people. Anywho. The other guy on my team was able to take care of the DNS stuff. But man was he ranting (and rightfully so).

Then at the very end, I got a huge win. Something wasn't working. Looks like another case of bad info. I was able to fix it. Before I started looking at it I had no clue what to even do. I vaguely knew the problem was related to NAT and Routing.

But I really found the problem falling back on one of my older skills that I love to use. Its kind of funny really because I was mentioning on a forum yesterday how great that skill was.

The skill - Being able to set up, and read a packet capture (sniffing) with TCPDump in real time. Once I found out what the problem was, I fixed it. with about 60 seconds to go in the maintenance window. :)

Saturday, August 8, 2009

Fun with grep

I got a copy of the Grep Pocket Reference back in early July via PDF format (from O'Reilly's Safari Bookshelf). I read through it but didn't really learn that much.

Last week the hard copy version arrived (2 weeks after I ordered it from Amazon). I've been reading it the last week. The parts I'm going through right now talks about Regular Expressions (regex). I've read about regex more times than I can count, in classes, in shell scripting books, on the web. This time it made sense.

My firewall log parsing for ip addresses has really improved. For example. I'd usually do "grep '< my ip address >' /external/logs/firewall1". The problem my address at work is .18, but it would pull .181 - .189 also. The first thing I did was back slash the . (dots) in the ip address. It cleaned up some stuff from the logs but not much. It's nicer to know that's not looking for any character and only matching what I want it too.

Which was a problem I was having when I wrote failed a few years ago.

Yesterday I read about word boundaries. I tested it this morning with my work IP address, and no longer am I getting the .181 - .189 addresses. Which is fun. It'll make looking for some things easier in the logs at work.

-------

Just for fun, here is what the finished version of Failed looked like (modified slightly):

#! /bin/sh
# checks for /var/log/auth.log for login failures.
# version 0.2
# < my email address removed >

# prints failed invalid users
echo "Failed Invalid User Attempts"
sudo grep "Failed" /var/log/auth.log | grep -i 'invalid' | grep -v '< work login id removed >' | awk '{print $1,$2,$3,$13,$11}' | sort -u

echo ' '
#prints failed vailid users, except for me.
echo "Failed Valid User Attempts"
sudo grep "Failed" /var/log/auth.log | grep -vi 'invalid' | grep -v '< work login id removed >' | grep -v '< home login id removed >' | awk '{print $1,$2,$3,$11,$9}' | sort -u
echo ' '

------

I sudo the 2 lines, because I need to be root to access that log file. I didn't want to setuid the script to run, nor did I want to be root when I ran it. It also requires me to type my password to run it, since sudo only remembers my password for 5 minutes.

To make this work on Redhat based systems, change auth.log to secure.log

Saturday, August 1, 2009

I'm jumping on the band wagon...

...I'm just late that's all.

So I'm thinking about passwords lately. With Black Hat and Defcon this week, the report that some big name Infosec people had their accounts broke into, a friend's tweet on getting 400 followers, and me having to change my FB password today, I thought I'd share how I come up with passwords.

Now for fun the other night, driving back from Tang Soo Do on a long and lonesome highway east of Omaha... I came up with about 15 or so passwords based off a tv show I liked. They were between 8 to 10 characters each.

So there are a few ways I do it. There are 2 examples in each.

Method One:
I'll take a phrase, the longer the better, and modify it.
The quick red fox jumps over the lazy brown dog (a well known pangram , ie uses all the characters in the English language) or I'm here to chew bubble gum and kick arse and I'm all out of bubble gum (mainly because I'm fond of quotes).
I'll take the phrase, and use camel case (mixed case), with numbers, special characters (anything over the number keys), and letters. I'll then mix them up like below:

Th3Qu!ckBrownF0xJump3s_Over_the_L2zy_red_dog

I'm_h3r3_2ch3w_BubbleGum&kick@rse.&I'm@ll0ut_ofBubbleGum

I can mix them other ways too. For example, I swapped brown and red, just to make it a little different.

Method Two:
I'll take a song lyric or a line from a movie, tv show, or whatever and I'll modify it by using just the first letter of each word, and the some of the other steps above. Examples I'll uses are Seger's Turn the Page, and a line from Cool Hand Luke.

"On an long and lonesome highway east of Omaha" becomes:

0@L&lh3oO!

"What we've got here is... failure to communicate. Some men you just can't reach. So you get what we had here last week, which is the way he wants it... well, he gets it"

Wwgh!F2c.SmUjcr=SugWwhHlw,W!twhWi_whg!! (to be honest, I'd modify it a little more, and weighing in around 30 characters, I'd use that for a pass phrase for my encrypted hard drive).

There are some other rules I use, if you notice, I have 2 characters side by side, 1 will be cap, 1 will not be. I tend to use the 2 interchangeably at home and at work, so we have phrase on some boxes, and the vegitable soup on others.

Lastly Method 3, which I only use on rare occasions is:
pwgen (password generator) from the linux command line. I'll add options like at least 1 special character, 1 upper case, 1 number and set it to be 10 to 12 characters long.

and finally...
I tend to use password safes, with things divided in them. Keepass and Password Safe.

I have had a few users complain when I give them a 10 to 12 character password based on something they said in the conversation. 1 about being long, and 2 about being so random, but when I tell them I use 24 to 26 character passwords regularly they tend to think it's not that bad and they seem to remember what they got fairly well.

There are other ways to make passwords too, and if you google them, I suggest googling site:lifehacker.com

Have fun, be safe online and for extra credit, figure out why I think this is a bad password. BwDn$b! (there are 2 reasons I don't like it).

Wednesday, June 24, 2009

Pidgin, Yahoo, and Debian Testing

So like lots of people, I've been having problems with Pidgin and Yahoo, after the upgrade. I followed several "work arounds". However every couple days it stopped working again.

If you followed the blog at all, you know I run Debian Testing right now. Currently, testing doesn't have the latest version of Pidgin that fixes the issue.

Instead of waiting, or changing my source lists, I went to the Debian Package pages and found the files I needed to get it to work.

If someone else wants to use DPKG to install just the files they need, here are the ones I needed:

libpurple0_2.5.7-1_i386.deb
libzephyr4_3.0~beta.2483-2_i386.deb
pidgin-data_2.5.7-1_all.deb
pidgin_2.5.7-1_i386.deb

Libpurple0 and pidgin-data were needed for pidgin. Libzephyr4 was needed for libpurple to install.

Wednesday, May 20, 2009

AT&T blocking port 25

I've noticed a few trends in my visitor lists. One is people looking for information about AT&T U-verse blocking port 25.

Yes they, like many ISPs are blocking out bound port 25 for non-business customers. This is in an attempt to cut down on spam. I think it's a failed attempt, because the zombies still spam like mad, but meh.

I was able to get my U-verse connection un-blocked by calling tech support. I also have a static IP address block. If you're trying to find out a way to get around the block good luck. If you have a reason that you need out bound port 25, and are not a spammer, you'll need to call Customer Support.

Monday, April 13, 2009

I love finding new tools

TCPview, and netactview. They do the same thing, but one does it in Windows, the other does it in Linux.

Going through firewall logs Friday I found a box trying to hit Akamai Technologies' servers faster than once a second. Like 2 or 3 a second. The box lives on a part of the network with restricted outside access.

There was so much chatter in the logs I was looking at, it looked like it was the only box. The reason it caught my eye to start with was they all had Deny statements with them. Not knowing what the box was doing, we pulled it off the network. There have been infected user boxes before, from surfing sites that were a no no.

The other Network Engineer / Windows Admin today tossed TCPview on the box, it's basically a gui for netstat. Constantly updates in the window, and uses color codes too. However the box had been swept, put back on the network and updated.

I looked at the logs, thinking maybe the issue was a software update (as far as we know the sweep came back clean, the person who did the the sweep is off today), I saw several other boxes. Joking the other guy and I walked back to the area saying it's probably Adobe. Toss TCPview on it, and low, it is adobe updater.

I liked the tool. So I looked, turns out that netactview does the same thing in Linux. Very Nice.

I could do the same thing with netstat, but I hate watching text scroll by.

Friday, March 6, 2009

AT&T U-Verse Did something right.

*Edit: If you found this page on a search engine while looking for info on AT&T blocking port 25 go to this post

I know the title surprises me too. Even more since this was going to start off as a huge rant about them.

As it says on the side bar, I work as a Network Engineer. I won't say where, but I'm the senior technical resource in the department. Security, design, repair, etc all fall under my position. That includes fixing misconfigured servers and trouble shooing problems (so we can know what needs to be fixed).

Yesterday we (the system administrators) got an email from someone not able to send us email. From what we could tell it looks like their problem, is on their stuff. Not ours. While looking into that problem, I saw another one. The company's email servers were listed on some Real Time Black Lists (RTBL). Which are used to block emails from spammers.

Looking into why we were on the list, one of our mail servers were listed as an open relay which means that spammers could send mail through our mail servers. The easiest and fastest way to check, is to login to the servers via telnet and see if they will send the mail. So, I bounce to my box at home (from work via ssh), and try to telnet to port 25 on the mail server. Not working. Can't telnet to port 25 anywhere else either. Luckily a friend was able to let me use his linux box to trouble shoot the problem, and it wasn't blocked from there. We fixed the configuration on our mail server this morning.

But I still couldn't get to the server on port 25 to re-test remotely. So I took note, and after confirming stuff was fixed, I started to look into why I couldn't telnet from home. My budy doesn't have a problem leaving my account on his box, but that doesn't mean I want to have to rely on his box being up.

After hunting around, it turns out to try and cut down on spam, ISPs are blocking port 25 outbound. It is, what it is. And I think it's a bad idea, to a point. People like me, who need to test are the smaller subset of people that need to use the port, while the spammers are the bigger group. Blocking it from everyone does prevent zombies and spammers from using the port to send spam. But it also prevents us from being able to fix our systems. The better idea would be to start blocking the mail servers that are found to be open relays. Although blocking port 25 prevents finding open relays that haven't been blocked yet. It also cuts down on some traffic (the hunting of open ports).

So I started looking into AT&T and the blocking of the port. The article I found, on their help site, said that they're blocking port 25 for Dial up and Dynamic High Speed internet customers, and doesn't affect people with static ip address, or dedicated connections (Frame Relay, T1, T3).

But wait, I pay 15.00 a month for 8 static ip addresses. So I called ready to raise hell. I fought my way through the automated system, it took several tries and they had to remotely "test" my connection, before transferring me to a live person. I told her the deal, I'm a network engineer, I need to test my mail servers at work remotely, and port 25 is being blocked. She couldn't unblock it. So off to tier 2 I go. The guy there was a lot of help. Re-explained the situation, he looked up my account, confirmed I do have a static ip address (although he read the read column the first time), and unblocked the port for me. he noted the account that I requested it unblocked and why.

Seriously I was expecting to jump through a bunch more hoops before getting things resolved. I wasn't happy at the start of the call, but was by the end. And now I can get to my servers at work the way I need to so I can make sure they're not open relays the next time I find us on a black list.

Is there a better way to block the spammers? Yes. Will it happen? no. I can think of several ways. The biggest is to take the profit out of it, like they did when they ended prohibition. Re-writing the standards so relaying is changed, and being and open relay can't happen. (There has been some work in this). will it be easy to fix the problem... not in today's world.

Friday, January 30, 2009

Today was just strange

This is cross posted between my LJ and My Blog

Tried to get up at 5am. Didn't work. Got up around 8:30. Went and paid rent. Then went and talked to the Coordinator, because she didn't call yesterday.

The Self Defense class is on. Next Wednesday at 7:30pm for the ladies, 8:30 for both sexes.

Leaving there, a guy whipped around a corner (we have medians with little turns in them to get into parking lots), didn't even bother trying to slow, I almost t-boned him. Then at the first light I had to turn at, a semi started fish tailing. Turned down another road and got 1/2 way to the road I needed, only to have it closed by an accident. 2 lane road, and the 2 cars took up the whole thing. Looked bad.

Ran by the post office, watched a cute break down about her package. Dropped off my Package going back to amazon for refund, and finally left for work. Get there, get told a server is down in our Louisville office. Called the Louisville tech to reboot the box, it's been flaky. Found out that the doors down there were broke. The mag locks would not disengage. So I got to spend time on the phone with him to figure out how to break into the computer room down there.

Other weird things most the day, like at lunch when I was given the wrong pager for my food, and they had to come find me, so they could give it to me. Then when I got ready to go, which takes about 15 minutes for me to do, the Help Desk Lady comes over and says the police are there.

Turn around there's a county sheriff deputy. Oo. He said they're was a 911 call and hang up from our building. He said they tried to call back, but couldn't get out of the automated system so they sent him out. We walked around, he said since he didn't hear any screaming he wasn't worried. It was either a wrong number or caused by the weather, which happens in the winter. He left, I figured I'd walk around some.

Went to carpet row first, since that's where the VPs, the Owners, the Directors and others like that sit. Saw my director was still there. Told him the cops were there because they got a 911 call. The look on his face was just pure worry would be the best way to say it. He went straight to 11. I had to calm him down quickly. We went over and talked to the Manufacturing Director and VP, then the four of us walked the building. Each person took a different area. We met back up and all was good.

So next week there will probably be a memo if you accidentally call 911, stay on the phone and tell them you got them by mistake.

So then I was getting ready to go again, and the MFG Director stops by says his guys can't get to the Manufacturing share on our network. Look, and the NAS heads crashed again. Spent the next 1.5 hours dealing with that.

Then home ward bound. Stopped to get some clothes for the Self Defense class. That and looking at toys and other things, took about an hour.

Monday, January 26, 2009

Safari Bookshelf

So I have a Safari account. It lets me have electroic copies of tech books for a fairly low price.

I was looking at a book today, and it said buy print version 35% off for subscribers. Woot. Then I looked at amazon.com. I'd pay 50 cents more at Amazon but get free shipping.

I know which one is the better deal there. Sad as it is, the 35% discount sounds nice until you actually look at final costs. Sure free shipping means waiting a few extra days but that's ok, I've already got an electronic copy.

Tuesday, January 13, 2009

And to top it all off, I need to get some blue thread.

Today sucked. Really really sucked.

I woke up sore and tired again. My back was hurting again. Not as bad as last week, but sore enough that I really really really thought about calling in sick today.

Then I get to work. Long story short there, a piece of networking equipment died, and took us off line for about 8 hours. The first 3 hours, you could reach the company websites, but that was it. At 12:30, we rebooted a piece of equipment. Before I did it, I said I didn't think it would fix the problem. I was right. It made it worse. I said worse case, we'll be dead in the water. Close enough, we didn't have any external presence on the ineternet.

In kicks the adrenaline, because shit just hit the fan, and it was my job to fix it. Trying to do 3 or 5 things at once, and making little headway on any of them. Finally I focus on one of them, get the websites back up, even if it's limping along, so the outside world could see us. About an hour later (note this is about 2 hours after the reboot), I got the system up. Changed ip address, monkeyed around with the firewall, ran cables over the floor. All while waiting for Cisco to deliver a new part to us.

Around 3:30, I ran out for comfert food. Regardless of the fact that I had steamed colliflower and broccli, 2 pergoies, and half a chicken breast for lunch at 12:15. I went and got 2 Double cheeseburgers minus onion plus bacon, large fry, large dr pepper, and a large frosty from wendy's. Got back, ate the first burger, felt like crap. After washing my face and hands, to free them of ketchup and mayo (note this around 4pm now, and the part isn't due until after 6pm) I see a car parked on the sidewalk in front of the door. I go out to the lobby, and it was Cisco's delivery team with the part. I don't think the guy thought I was authorized to sign for it, but my name was on the package too, or was supposed to be.

Opened the boxes, and the adrenaline kicked back in, as I flipped the power switches on the equipment. Meanwhile my frosty is melting. Replace the bad card, and everything comes back up... Except the web sites because of the changes I made. So I quickly run off to change the firewall, reconfig the box I changed, change DNS, and all other kinds of fun things that took me an hour to do the first time (un-did it in 15 minutes), and life was happy.

However after running on adrenaline for so long, I'm now exhausted. I was going to come home and just go to bed. Skipped Martial Arts... Of course I diddn't leave work until 6pm. Got bird out of his cage, since it's going down to around -5f tonight, I stopped to retape my bed room window. If I had the tape I'd do the other one, and I really need to get some more weather tape, and replace all the duct tape I used. But it's not as drafty in here. Still some drafts but not as bad.

In the process I cut a line in my blue blanet on my bed. Stupid razor knife. I know it was my own fault. I didn't see the cut (and I looked at the time) until I got in bed. I hope it doesn't get worse between now and the weekend, so I can get some thread and sew it back up. Yes I know how to sew. Which does surprise people. Nothing fancy, but I can make small repairs, and put patches on clothes, I did all the patches on my martial arts uniforms myself. Although next time, I'm going to pay someone.

I was going to skip ETK tonight. but I wanted something to make me feel better than I when I was getting ready to go to bed.

Warm up: 10 minutes.
10x wall squat
10x halo (16kg, 5 to the right, 5 to the left)
10x pumps
Total: 4 sets, could have done more, but I stopped to get the kettlebell off my bookshelf, take off my sweat pants, change my shirts, get my water from the kitchen, etc.

Workout: 24kg, 5 minutes
5 left, 5 right Turkish Get Up.

Had enough time to do a 6th one on the left, but decided against it.

Monday, November 24, 2008

It shouldn't be THAT easy

I've sold my manager, and director on Encrypted IM... We're running a small test right now, in the IT group (the IT people, we'll fold the rest of the IS people in later (the developers, dbas and etc).

We're using Pidgin, with Pidgin-encryption. Really easy to set up. Install Pidgin. Install Pidgin-encryption. Works with all major IM servers, and Operating Systems.

After installing, set your user accounts (don't have to, but that is the way I like to do it), then go and turn on the plugin for pidgin-encryption under options>plugins.

When you turn it on, by selecting the check box, it creates rsa keys for all accounts in the client. Click on configure plugin button, and go to the second tab. Highlight the account, press regenerate key. Change the key size to 2048. The bigger the key the harder it is to break. I have mine set at 4096 (the largest size supported by the client at this time).

Then when you IM a someone, you'll notice somewhere in the text window (here at work it's on the top of the window) a little lock. Click it, and it turns on the encryption. If the person on the other side has the plugin installed, you'll get their key. You should have 2 locks at that point. with arrows pointing to each other. You're encrypted and good to roll. If you're sending an im to someone without encryption, just turn off the crypto, by hitting that little green lock.

So what does encryption do again? It makes it so no one else can read your messages, unless they are supposed to. Encrypted IM rocks. This is really fast, easy to set up, and simple to use. You don't have to worry about someone, like Google (if using Google talk), storing your IMs and giving them to the cops. Because It's encrypted. However, the cops can make you give up your key, at least in the United States. But, if you're transferring Intellectual Property (YOUR OWN, or YOUR EMPLOYER'S) you don't have to worry about the competitor getting your data.

So what shouldn't be that easy? Getting upper management to buy in on this. I've been trying for 2 years. They both said yes today. The director said to bring it up at the next team meeting, and we'll work it out.

Wednesday, November 12, 2008

cisco load balancer

So I have a content switch module in one of my switches. It's used for Load Balancing of services across multiple servers. Think multiple servers for 1 web page, all the servers are mirrored so you get the same content, it just spreads the pain around to 4 servers instead of having 1 server to do all the work.

So I'm renumbering 4 of the servers. We're actually upgrading some of the content to virtual servers, but leaving some stuff behind on the old server. It was a case of a new product not having a home and sharing the load on the servers, with out creating a virtual server.

Anyway like I said, renumbering servers. Set up the firewall to point the traffic to the load balancer. Set the server up to pass traffic. I already have one up and running this is the second one. I spent roughly 2 to 3 hours trying to figure out why this thing couldn't get a network connection. It could talk to the other servers on the same vlan / network, but moving across to the other vlans and networks (where the firewall comes into play) it wouldn't.

Change ip addresses, same problem. Change gateways to the DMZ instead of the LB, and it would get a net connection. Double check the firewall routing. It still didn't work.

Then I thought, ok, the only thing I haven't done is put it into a server farm yet, on the CSM. As soon as I did that, it started working. Why the LB, needs to know what server farm something belongs to before it starts passing traffic I have no idea. I think it's a bad design though. I can see why they'd do it that way. That way you don't have things pointing to the load balancer that aren't being balanced. But when you're just setting up a box, you don't want it to be balanced, you want it to work.

Meh