<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Passionate about Information Security &#187; Nmap</title>
	<atom:link href="http://blog.ismaelvalenzuela.com/tag/nmap/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.ismaelvalenzuela.com</link>
	<description>on ismaelvalenzuela.com</description>
	<lastBuildDate>Tue, 26 Jan 2010 17:58:24 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Security Onion LiveCD is now available</title>
		<link>http://blog.ismaelvalenzuela.com/2009/06/16/security-onion-livecd-is-now-available/</link>
		<comments>http://blog.ismaelvalenzuela.com/2009/06/16/security-onion-livecd-is-now-available/#comments</comments>
		<pubDate>Tue, 16 Jun 2009 19:48:01 +0000</pubDate>
		<dc:creator>Ismael Valenzuela</dc:creator>
				<category><![CDATA[Intrusion Detection Systems]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Bro]]></category>
		<category><![CDATA[Doug Burks]]></category>
		<category><![CDATA[IDS]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[LiveCD]]></category>
		<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Nmap]]></category>
		<category><![CDATA[NSMnow]]></category>
		<category><![CDATA[Security Onion]]></category>
		<category><![CDATA[Sguil]]></category>

		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=93</guid>
		<description><![CDATA[I read in Doug Burks' tweet that his Security Onion LiveCD is now available for download. Being a serious Sguil fan, I can't do anything but recommend you have a look at this new live distro.]]></description>
			<content:encoded><![CDATA[<p><img class="size-medium wp-image-91 alignright" style="border: 0pt none; margin: 2px; vertical-align: top; float: right;" title="yellow-onion1-thumb.jpg" src="http://blog.ismaelvalenzuela.com/wp-content/uploads/2009/06/yellow-onion1-thumb.jpg" alt="Security Onion ??" width="181" height="197" />I read in <a href="https://twitter.com/dougburks" target="_blank">Doug Burks&#8217; tweet</a> that his Security Onion LiveCD is now available for download. Being a serious <a href="http://sguil.sourceforge.net/" target="_blank">Sguil</a> fan, I can&#8217;t do anything but recommend you have a look at this new live distro.</p>
<p>You can download it from the following location:<br />
<a title="Security Onion LiveCD" href="http://distro.ibiblio.org/pub/linux/distributions/security-onion/" target="_blank">http://distro.ibiblio.org/pub/linux/distributions/security-onion/</a></p>
<p>The following information is extracted from Doug&#8217;s <a href="http://securityonion.blogspot.com/" target="_blank">Security Onion blog</a>:<strong></strong></p>
<blockquote><p><strong>What is it?</strong></p>
<p>The Security Onion LiveCD is a bootable CD that contains software used for installing, configuring, and testing Intrusion Detection Systems.<span id="more-93"></span></p>
<p><strong>What software does it contain? </strong></p></blockquote>
<blockquote style="clear: both"><p>The Security Onion LiveCD is based on Xubuntu 9.04 and contains Snort 2.8.4.1, Snort 3.0.0b3 (Beta), sguil, idswakeup, nmap, metasploit, scapy, hping, fragroute, fragrouter, netcat, paketto, tcpreplay, and many other security tools.</p>
<p><strong>What can it be used for?</strong></p>
<p>-The Security Onion LiveCD can be used for Intrusion Detection. Simply boot the CD and double-click either the Snort-Sguil or SnortSP-Sguil desktop shortcuts. The Snort and Sguil daemons will then start, listening on eth0 for any suspicious traffic and creating alerts in the Sguil console.</p>
<p>-The Security Onion LiveCD can be used to test an Intrusion Detection System. Simply boot the CD and use the included tools (such as nmap, metasploit, idswakeup, scapy, hping, and others) to test your existing IDS or to test the included Snort 2.8.4.1 and Snort 3.0 Beta 3.</p>
<p>-The Security Onion LiveCD can be used to install an Intrusion Detection System. Simply boot the CD and double-click the Install desktop shortcut. For more information about installation, please see the README desktop shortcut.</p></blockquote>
<p style="clear: both">I haven&#8217;t had a chance to download it yet, but I will definitely give it a try over the next few days. I&#8217;m very interested in trying out the IDS installation feature and see how it compares to other <a href="http://sguil.sourceforge.net/" target="_blank">Sguil</a> installation scripts like <a href="http://www.securixlive.com/nsmnow/" target="_blank">NSMnow</a>. I&#8217;m currently working on the deployment of a good number of <a href="http://sguil.sourceforge.net/" target="_blank">Sguil</a> servers/sensors and <a href="http://www.securixlive.com/nsmnow/" target="_blank">NSMnow</a> has reduced significantly the time needed to get them up and running. Hence, any new development on this topic is more than welcome.</p>
<p style="clear: both">I will keep posting my findings on this new exciting tool!</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ismaelvalenzuela.com/2009/06/16/security-onion-livecd-is-now-available/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Detecting Conficker: run this check now!</title>
		<link>http://blog.ismaelvalenzuela.com/2009/03/30/detecting-conficker-run-this-check-now/</link>
		<comments>http://blog.ismaelvalenzuela.com/2009/03/30/detecting-conficker-run-this-check-now/#comments</comments>
		<pubDate>Mon, 30 Mar 2009 22:31:38 +0000</pubDate>
		<dc:creator>Ismael Valenzuela</dc:creator>
				<category><![CDATA[Security Advisories]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Honeynet Project]]></category>
		<category><![CDATA[MS08-67]]></category>
		<category><![CDATA[Nessus]]></category>
		<category><![CDATA[ngrep]]></category>
		<category><![CDATA[Nmap]]></category>
		<category><![CDATA[python]]></category>
		<category><![CDATA[Snort]]></category>

		<guid isPermaLink="false">http://blog.ismaelvalenzuela.com/?p=70</guid>
		<description><![CDATA[...you have to know that the Honeynet Project has been working on a way to detect Conficker-infected machines and that they have just released a scanner for this task. The scanner is available as a python script and as a windows .exe executable, and can be used to scan a single host or a whole network range.]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re reading this blog I&#8217;m sure I don&#8217;t have to tell you what <a title="MS08-067" href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" target="_blank">MS08-67</a> or <a title="Conficker on Wikipedia" href="http://en.wikipedia.org/wiki/Conficker" target="_blank">Conficker</a> is about (despite the fact we keep seeing many unpatched machines, but that&#8217;s a different story).</p>
<p>Besides that, there are plenty of <a title="Rumors on 1st April activation on Press" href="http://www.itworld.com/security/65407/conficker-april-1st-eve-destruction-or-big-joke" target="_blank">rumours</a> about a possible<span style="color: #000000;"><span style="color: #000000;"> Conficker attack on 1st April. I know you may think it&#8217;s all hype or scaremongering, and it might well be. But, if you run a large corporate network I&#8217;m sure you don&#8217;t want to sit down and wait until 1st April to find out.<br />
</span></span></p>
<p>If that&#8217;s the case, you have to know that the <a title="Detecting Conficker on HoneyNet Project" href="https://www.honeynet.org/node/388" target="_blank">Honeynet Project</a> has been working on a way to detect Conficker-infected machines and that they have just released a <a title="Conficker scanner" href="https://www.honeynet.org/node/388" target="_blank">scanner</a> for this task. The scanner is available as a <a title="Conficker scanner" href="http://iv.cs.uni-bonn.de/uploads/media/scs.zip" target="_blank">python script</a> and as a <a title="Conficker scanner" href="http://www.doxpara.com/scs.zip" target="_blank">windows .exe executable</a>, and can be used to scan a single host or a whole network range.</p>
<p><span id="more-70"></span></p>
<p>When run it on my mac the output looked like this:</p>
<blockquote><p># ./scs.py 192.168.1.1 192.168.1.254</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Simple Conficker Scanner<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
scans selected network ranges for<br />
conficker infections<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Felix Leder, Tillmann Werner 2009<br />
{leder, werner}@cs.uni-bonn.de<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p>No resp.: 192.168.1.1:445/tcp.<br />
No resp.: 192.168.1.82:445/tcp.<br />
No resp.: 192.168.1.80:445/tcp.<br />
No resp.: 192.168.1.81:445/tcp.<br />
No resp.: 192.168.1.95:445/tcp.<br />
192.168.1.99 seems to be clean.<br />
192.168.1.101 seems to be clean.<br />
192.168.1.85 seems to be clean.<br />
192.168.1.97 seems to be clean.<br />
192.168.1.106 seems to be clean.</p></blockquote>
<p>Alternatively, popular scanners like <a title="Nmap" href="http://nmap.org" target="_blank">nmap</a>, <a title="Nessus" href="http://www.nessus.org" target="_blank">Nessus</a> and others have quickly updated their plugins to support Conficker detection. At the moment, <strong>Nmap 4.85beta5</strong> has all the scripts included, and it&#8217;s now ready for download at <a title="Nmap download" href="http://nmap.org/download.html" target="_blank">http://nmap.org/download.html</a>. If you&#8217;re are running a Unix-like system you probably want to update nmap from svn:</p>
<blockquote><p>$ svn co &#8211;username=guest &#8211;password=&#8221; svn://svn.insecure.org/nmap<br />
$ cd nmap<br />
$ ./configure &amp;&amp; make<br />
$ sudo make install</p></blockquote>
<p>Then run nmap using the new NSE script:</p>
<blockquote><p>$ nmap &#8211;script=smb-check-vulns &#8211;script-args=safe=1 -p445 -d &lt;target&gt;</p></blockquote>
<p>As of Nessus, use plugin <a title="Nessus plugin 36036" href="http://www.nessus.org/plugins/index.php?view=single&amp;id=36036" target="_blank">#36036</a> to detect any variant of Conficker.</p>
<p>The Honeynet Project has also released <a title="Snort" href="http://www.snort.org" target="_blank">Snort</a> signatures to detect Conficker.A and Conficker.B traffic. Make sure you update your IDS sensors with <a title="Snort signatures for Conficker A and B variants" href="https://www.honeynet.org/node/388" target="_blank">these signatures</a> and be ready to monitor your console over the next few days. If you don&#8217;t have any IDS technology in place (I will resist the temptation to ask you why by now) but you have access to a network span port, you can still plug any Unix-like box in and run <a title="Ngrep at Sourceforge" href="http://ngrep.sourceforge.net/" target="_blank">ngrep</a> like this:</p>
<blockquote><p>$ sudo ngrep -qd eth0 -W single -s 900 -X<br />
<em>&lt;insert shellcode string from <a title="Honeynet Project" href="https://www.honeynet.org/node/388" target="_blank">here</a>&gt;</em><br />
&#8216;tcp port 445 and dst net <em>&lt;local network range&gt;</em>&#8216;</p></blockquote>
<p>Further details about Conficker fingerprint and the detection methods and tools can be found here: <a title="University of Bonn (Germany)" href="http://iv.cs.uni-bonn.de/wg/cs/applications/containing-conficker" target="_blank">http://iv.cs.uni-bonn.de/wg/cs/applications/containing-conficker</a></p>
<p>Good luck.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.ismaelvalenzuela.com/2009/03/30/detecting-conficker-run-this-check-now/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
