Tuesday, September 23, 2008

Login!

Password RESET for MacOSX (no disk needed)

Command-key + s - SETS MAC TO BOOT ON SINGLE MODE
fsck -fy
mount -uw /
launchctl load /System/Library/LaunchDaemons/com.apple.DirectoryServices.plist
dscl . -passwd /Users/

:)

Thursday, June 19, 2008

OpenBSD Syslogd Centralized Server

I setup OpenBSD 4.2 as a Central Loggin Server. with awesome results (no need for any other 3rd party logging software OpenBSD has it all)

Paranoid Fishies check this out:

my /etc/rc.conf

syslogd_flags= "-u -a "

my /etc/syslog.conf

# $OpenBSD: syslog.conf,v 1.17 2005/05/25 07:35:38 david Exp $
#

*.notice;auth,authpriv,cron,ftp,kern,lpr,mail,user.none /var/log/messages
kern.debug;syslog,user.info /var/log/messages
auth.info /var/log/authlog
authpriv.debug /var/log/secure
cron.info /var/cron/log
daemon.info /var/log/daemon
ftp.info /var/log/xferlog
lpr.debug /var/log/lpd-errs
mail.info /var/log/maillog
local7.debug //
#uucp.info /var/log/uucp

# Uncomment this line to send "important" messages to the system
# console: be aware that this could create lots of output.
#*.err;auth.notice;authpriv.none;kern.debug;mail.crit /dev/console

# Uncomment this to have all messages of notice level and higher
# as well as all authentication messages sent to root.
#*.notice;auth.debug root

# Everyone gets emergency messages.
*.emerg *

# Uncomment to log to a central host named "loghost". You need to run
# syslogd with the -u option on the remote host if you are using this.
# (This is also required to log info from things like routers and
# ISDN-equipment). If you run -u, you are vulnerable to syslog bombing,
# and should consider blocking external syslog packets.
#*.notice;auth,authpriv,cron,ftp,kern,lpr,mail,user.none @loghost
#auth,daemon,syslog,user.info;authpriv,kern.debug @loghost

# Uncomment to log messages from sudo(8) and chat(8) to their own
# respective log files. Matches are done based on the program name.
# Program-specific logs:
#!sudo
#*.* /var/log/sudo
#!chat
#*.* /var/log/chat


touch filename.log
chmod 644 filename.log


now for the Device Part:

Cisco Router: 7200Series

conf te
service timestamps log datetime
logging host transport udp port 514
logging facility local7
logging trap debugging
logging on

Monday, February 11, 2008

nikto scan

i did a test using nikto today and found out a couple of "said" vulnerabilities:

---------------------------------------------------------------------------
- Nikto 2.02/2.03 - cirt.net
+ Target IP: 172.17.4.20
+ Target Hostname: 172.17.4.20
+ Target Port: 80
+ Start Time: 2008-02-12 12:53:41
---------------------------------------------------------------------------
+ Server: Apache
- Allowed HTTP Methods: GET, HEAD, OPTIONS, TRACE
+ OSVDB-877: HTTP method ('Allow' Header): 'TRACE' is typically only used for debugging and should be disabled. This message does not mean it is vulnerable to XST.
+ OSVDB-877: TRACK / : TRACK option ('TRACE' alias) appears to allow XSS or credential theft. See http://www.cgisecurity.com/whitehat-mirror/WhitePaper_screen.pdf for details
+ OSVDB-877: TRACE / : TRACE option appears to allow XSS or credential theft. See http://www.cgisecurity.com/whitehat-mirror/WhitePaper_screen.pdf for details
+ OSVDB-2117: GET / : Appears to be a default Apache install.
+ OSVDB-2799: GET -evasiondose.pl?daily&somefile.txt&|ls| : DailyDose 1.1 is vulnerable to a directory traversal attack in the 'list' parameter.
+ OSVDB-3268: GET /icons/ : Directory indexing is enabled: /icons
+ OSVDB-3233: GET /icons/README : Apache default file found.
+ 3657 items checked: 8 item(s) reported on remote host
+ End Time: 2008-02-12 13:00:33 (412 seconds)
---------------------------------------------------------------------------
+ 1 host(s) tested


enter Mod_Rewrite

RewriteEngine on
RewriteCond %{REQUEST_METHOD} !^(GET|POST|HEAD)$
RewriteRule .* - [F]

RewriteEngine on
ReWriteCond %{REQUEST_METHOD} ^(TRACE|TRACK)
ReWriteRule .* - [F]

this needs to be put on the directive. in order to take effect. fixes the issue, happy openbsd :)

Wednesday, February 6, 2008

learning curve

私輪渡り者です。

I'm getting there ...

Tuesday, January 29, 2008

hushmail a.k.a NSAmail?

I've been using hushmail for almost a year now, and I use it mostly for inter-hushmail email since It does a pretty good job on encrypting mail... but it's just scares me to know that encryption based email services on the net *might* be owned by those folks that just like watching.... say.. NSA?

Anyways either this is true or not. It's a nice read.

http://groups.google.com/group/alt.security.pgp/browse_thread/thread/5171d049f75a2bbc/7fa4d97626043295

Kinda makes you wonder how they can get away with using encryption from the US.GOVT prying eyes.

hushmail owns 1 block of ip's 65.39.178.0/24 and puts on their whoisdb

Peer 1 Network Inc. PEER1-BLK-06 (NET-65-39-128-0-1)
65.39.128.0 - 65.39.255.255
Hush Communications USA PEER1-HUSHMAIL-01 (NET-65-39-178-0-1)
65.39.178.0 - 65.39.178.255

# ARIN WHOIS database, last updated 2008-01-28 19:10

# Enter ? for additional hints on searching ARIN's WHOIS database.
and indicates that the country of origin is GB(GreatBritain)? look closely though their class is owned by a company called peer1 networks.

OrgName:    Peer 1 Network Inc.
OrgID: PER1
Address: 75 Broad Street
Address: 2nd Floor
City: New York
StateProv: NY
PostalCode: 10004
Country: US

NetRange: 65.39.128.0 - 65.39.255.255
CIDR: 65.39.128.0/17
NetName: PEER1-BLK-06
NetHandle: NET-65-39-128-0-1
Parent: NET-65-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.PEER1.NET
NameServer: NS2.PEER1.NET
Comment: ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE
RegDate: 2002-06-21
Updated: 2006-09-20

RTechHandle: ZP55-ARIN
RTechName: Peer1 Network Inc.
RTechPhone: +1-604-683-7747
RTechEmail: net-admin@peer1.net

OrgAbuseHandle: NSA-ARIN
OrgAbuseName: Peer 1 Network AUP Enforcement
OrgAbusePhone: +1-604-484-2588
OrgAbuseEmail: abuse@peer1.net

OrgTechHandle: ZP55-ARIN
OrgTechName: Peer1 Network Inc.
OrgTechPhone: +1-604-683-7747
OrgTechEmail: net-admin@peer1.net

# ARIN WHOIS database, last updated 2008-01-28 19:10

# Enter ? for additional hints on searching ARIN's WHOIS database.
US IP block you be the judge.... =D *evil grin*

Friday, November 23, 2007

OpenBSD and PPTP!

It's already been a week now since I've started fiddling my rules and i just ended up with having 1 client ONLY to successfully connect to an external pptp server. the openbsdmail-lists says that, it's pptp's fault. because it's old but i believe it's a challenge.

we'll see what happens next. anyways below are the 2 rules I've come up with. that will let pptp pass-through a PF/Carp box (OpenbSD 4.1 Tested): Just make sure you pass TCP and GRE Traffic.

given setup is (BLOCK in/out ALL)

#Rule Style 1
pass out quick on $ext_if inet proto gre all label "GRE out WAN"
pass in quick on $ext_if inet proto gre all label "GRE in WAN"
pass out quick on $int_if inet proto gre all label "GRE out LAN"
pass in quick on $int_if inet proto gre all label "GRE in LAN"
pass out quick on $int_if inet proto { tcp, udp } from any to any port 1723
pass in quick on $int_if inet proto { tcp, udp } from any to any port 1723
pass out quick on $ext_if inet proto { tcp, udp } from any to any port 1723
pass in quick on $ext_if inet proto { tcp, udp } from any to any port 1723

Rule Style 2
pass in quick on $int_if inet proto { tcp, udp } from any to any port 1723
pass in inet proto gre from any to any
pass out inet proto gre from any to any

frickin is not a good way to pass-pptp. i guess it can be done on the kernel justlike linux's ppt-passthrough.

Saturday, November 17, 2007

http://www.internetpulse.net/
http://blogs.interfacett.com/mike-storm/
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_configuration_example09186a00808d2b72.shtml
http://www.ciscoblog.com/archives/security/pix/configurations/

Monday, November 5, 2007

OpenBSD 4.2

It's already been 4 days since 4.2's initial release, I am currently running my firewalls on 4.1 pf has been good to me and without a doubt pf(4) simply.. rocks..

I'm gonna try out 4.2 on a practice machine i have in the office, it looks like xenocara will kick ass with openbsd. great documented OS with a modular type X.

Errata for 4.2

http://openbsd.org/errata42.html
http://openbsd.org

:) my os of choice.

Friday, November 2, 2007

What's in austria anyways?


Now I have a good reason to go and visit Austria...

checkout:
http://en.wikipedia.org/wiki/Fucking,_Austria

Monday, October 29, 2007

Zebra Routing on OpenBSD

Zebra Routing for OpenBSD.

Zebra Build from source will break on OpenBSD, since codes that openbsd has are sanitized, on the other hand you can apply the following patch to your zebra code and build it.

*** zebra/kernel_socket.c.orig Fri Jul 20 12:00:41 2007
--- zebra/kernel_socket.c Fri Jul 20 12:01:17 2007
***************
*** 58,65 ****
--- 58,69 ----
{RTM_REDIRECT, "RTM_REDIRECT"},
{RTM_MISS, "RTM_MISS"},
{RTM_LOCK, "RTM_LOCK"},
+ #ifdef RTM_OLDADD
{RTM_OLDADD, "RTM_OLDADD"},
+ #endif /* RTM_OLDADD */
+ #ifdef RTM_OLDDEL
{RTM_OLDDEL, "RTM_OLDDEL"},
+ #endif /* RTM_OLDDEL */
{RTM_RESOLVE, "RTM_RESOLVE"},
{RTM_NEWADDR, "RTM_NEWADDR"},
{RTM_DELADDR, "RTM_DELADDR"},

good luck :) if you need any help you can always check out http://www.zebra.org. this project is currently unmaintained if you want another forked version it's available as http://quagga.sourceforge.net

Sunday, October 21, 2007

links links links...

Here are some of my old security links

http://www.ktl.elf.stuba.sk/~zilka/
http://hellnet.perverz.hu/ebookz/
http://www.team509.com
http://files.nixp.ru/books/
http://www.ssuet.edu.pk/~amkhan/Linuxbooks/
http://www.ssuet.edu.pk/~amkhan/cisco/cisco.htm
http://www.flashdance.cx/books/
http://www.hackemate.com.ar/textos/
http://hoth.amu.edu.pl/~mmarciniak/books/
http://lotfree.next-touch.com/coding/
http://cebka.pp.ru/books/
http://ploug.eu.org/doc/
http://tutorials.thefuzzyone.co.uk/
http://lib.profi.net.ua/wersius/Adisson%20Wesley/
http://www.cnfreeos.org/Document/
http://mirrors.cn99.com/books/
http://www.eygle.com/orabk/Book/
http://pq.ozersk.ru/ftp/text/
http://www.itlibitum.ru/library/BOOK/ENGLISH/THEMES/CPP/
http://www.comms.scitech.susx.ac.uk/fft/
http://www.comp.leeds.ac.uk/Perl/ -- my favorite perl guide
http://www.metawire.org/~firewalker/docs/
http://www.woodmann.com/crackz/Tools.htm
http://www.l0t3k.org/programming/docs/shellcode/
http://www.infosyssec.net/infosyssec/tools2.htm
http://www.howtoforge.com/
http://www.geeklady.net/
http://milw0rm.com/
http://download.securelogix.com/
http://www.networksecurityarchive.org/

DEMO Hack

http://www.hackingdefined.com/index.php/Demos
http://www.onimoto.com/
http://www.ghacks.net/
http://www.kisp.org/elohimus/tutorials/
http://phreaknic.wilpig.org/

Free Magazine

http://www.insecuremag.com/

some cool links that I have.

PIX Firewall packet capture procedure:

though I haven't tried this yet, it would be awesome to try this on my 515 here.

http://www.computernetworkinghelp.com/content/view/40/1/

blink.. blink... blinkenshell.

I've been searching for free shell accounts off the internet, this helps me do initial tests of my networks from almost anywhere. This also gives me ample space to work with scripts from virtually anywhere that has an internet connection.

folks at http://www.blinkenshell.org, yes this is my new home. I have my personal page currently on the works being transfered to my new site http://pfunix.blinkenshell.org.

thanks indy for taking up a new unix bud among it's growing community.

Monday, October 15, 2007

Unix-a-holic page

I got this account at rootshell.be the stuff i put there are mostly osX based builds.

http://phenix.rootshell.be/~pfunix

Sunday, October 14, 2007

Im alive... it has been almost a year since i first created this blog without any content.. for that long 2006.. it's 07 now.. close to 08 .. dang.. it's really been a while

Tuesday, January 2, 2007

Life on 2007

2nd day of January 2007, still have the holiday season jetlag.

Sunday, December 31, 2006

First Post of the Year!

Happy New Year!!


This is my first post of the year what a nice way to start the year. I'm planning to blog all my adventures on this site. hope all is well