Showing posts with label Forensics. Show all posts
Showing posts with label Forensics. Show all posts

Sunday, February 7, 2010

4G handset to be demonstrated this month

NTT DoCoMo is to demonstrate a prototype handset based on the high-speed wireless data technology LTE later this month, according to the Japanese mobile operator’s handset partner, NEC.

NEC said on Monday that NTT will demonstrate the handset receiving streaming high-resolution video across an LTE network at Mobile World Congress, which kicks off on 15 February in Barcelona. According to NEC, the handset uses an LTE chipset that was developed by Fujitsu, NEC, NTT DoCoMo and Panasonic, and first sampled in October.

LTE, the ‘long-term evolution of 3G’, is the successor to HSDPA and is roughly 10 times faster, providing theoretical downlink speeds of at least 100Mbps and a theoretical uplink of at least 50Mbps. The technology was designed to reduce latency in data transmission and improve the efficiency of frequency usage, making it more suitable than 3G for services such as streaming HD video, video conferencing and online gaming.

The world’s first commercial LTE mobile broadband services went live in Oslo and Stockholm in December through the Scandinavian operator TeliaSonera, which is initially offering LTE access via a mobile dongle.

Huawei announced in December that it had completed its first UK-based LTE trials, held in conjunction with O2, that reached maximum downlink throughput of 150Mbps. The trial took place in the Slough area, where O2’s headquarters are located.

NTT has said it plans to spend between ?300bn-?400bn (?2bn-?3bn) on LTE rollouts over the next five years.

source : http://www.hacking-news.com/

4G handset to be demonstrated this month

NTT DoCoMo is to demonstrate a prototype handset based on the high-speed wireless data technology LTE later this month, according to the Japanese mobile operator’s handset partner, NEC.

NEC said on Monday that NTT will demonstrate the handset receiving streaming high-resolution video across an LTE network at Mobile World Congress, which kicks off on 15 February in Barcelona. According to NEC, the handset uses an LTE chipset that was developed by Fujitsu, NEC, NTT DoCoMo and Panasonic, and first sampled in October.

LTE, the ‘long-term evolution of 3G’, is the successor to HSDPA and is roughly 10 times faster, providing theoretical downlink speeds of at least 100Mbps and a theoretical uplink of at least 50Mbps. The technology was designed to reduce latency in data transmission and improve the efficiency of frequency usage, making it more suitable than 3G for services such as streaming HD video, video conferencing and online gaming.

The world’s first commercial LTE mobile broadband services went live in Oslo and Stockholm in December through the Scandinavian operator TeliaSonera, which is initially offering LTE access via a mobile dongle.

Huawei announced in December that it had completed its first UK-based LTE trials, held in conjunction with O2, that reached maximum downlink throughput of 150Mbps. The trial took place in the Slough area, where O2’s headquarters are located.

NTT has said it plans to spend between ?300bn-?400bn (?2bn-?3bn) on LTE rollouts over the next five years.

source : http://www.hacking-news.com/

Google aims to speed up DNS requests



Google and Neustar UltraDNS have proposed a extension to try to build some geographic awareness into the Domain Name System.

The proposed extension, called Client IP information in DNS requests, would send along the first three quarters of a user’s IP address along with an DNS request. The last quarter would be cut off to preserve some privacy, but the first part should be enough to geographically target the answer in some cases, Google said in a blog post on Wednesday.

As designed, it would, for example, return the address for Google’s Dutch server, not Google’s California server, to a user in the Netherlands who needs to reach it.

For more on this story, see Google proposes geo-smart Internet speedup on CNET News.

Google aims to speed up DNS requests

Google and Neustar UltraDNS have proposed a extension to try to build some geographic awareness into the Domain Name System.

The proposed extension, called Client IP information in DNS requests, would send along the first three quarters of a user’s IP address along with an DNS request. The last quarter would be cut off to preserve some privacy, but the first part should be enough to geographically target the answer in some cases, Google said in a blog post on Wednesday.

As designed, it would, for example, return the address for Google’s Dutch server, not Google’s California server, to a user in the Netherlands who needs to reach it.

For more on this story, see Google proposes geo-smart Internet speedup on CNET News.

Saturday, December 12, 2009

The Story of an Insider

Introduction

I really enjoyed writing my first story in November, and I received loads of great feedback so I thought I'd do another one but from a slightly different angle. As well as writing my usual posts writing these stories really helps me learn new and different things.

So for my second effort I'm going to present a 3 part story. The first part will be the attackers story, the second and third parts will be the defenders perspective, focusing on the discovery of the attack and then some forensics thrown in for fun. I must point out that I am in no way trained in forensics, the techniques I will discuss would be those that any Systems Administrator could use to investigate an incident on his or her network after gaining permission.



Setting the Scene

As the title suggests this story will be about a rogue employee who feels poorly treated by his employers and wants revenge. His evil intention is to access restricted files and the sell plans for the eargerly awaited GNUphone to a popular website. Sounds easy? Well maybe I'll make things a bit interesting for him.

On the defending side is a keen Systems Administrator who looks after his network as if it's his baby. He has fought with management to have policies and procedures put in place to make his network secure.



So throughout December we'll see what the attacker does to get to the data, and what the Sys Admin does to try to prevent, detect and investigate the incident.

The Story of an Insider - Part 1. Shoulder Surfin Goodness

For a bit of background on this story you can read the intro here. This post details a low tech hack, primarily because its from the perspetive of a bog standard user. (If your reading this your probably not a bog standard user).

The Insiders story.

I've worked for this company for 2 years and all I get is crap from the boss. Those glory boys in design get all the praise for the GNUphone but if it weren't for people like me handling the suppliers and getting them down to rock bottom prices we couldn't even compete with the big boys in the market. It's launch day soon and all I see is the design lads getting party after party, rolling in late, taking long lunches and doing sod all. And to top it off I come in late once and I'm on a warning.

Well it just so happens that if I can just get the finished designs for the GNUphone to a guy I know over at MicroFone Magazine before the launch I'll be wiping the smile of those smug gits faces and I'll make a few quid too. I mean, it's not like i'm really hurting anyone, it justs means people get to see the phone a little early that's all.

I'll just have a poke around on the server and see what I can find...




Bugger! I can't get in the folder. I guess only the superstars in design are allowed access. Well I know the top guy down there is a football nut so it wouldn't take the brains of an astronaut to figure out his password.



Well none of that worked. But Mark did get really pissed at Carl the IT guy because his account was locked out. Then the boss had a go too, ranting that the security was an overkill and was preventing people from working. Yeah right! More like preventing people from getting to Facebook.


Well I better think about this because I have got to get the designs, i've told my mate I can get them and I don't want to look stupid. I need some of those hacking tools but our Internet access and email is monitored and were not allowed to bring software in. Were not even allowed USB devices for crying out loud! The Sys Admin is so paranoid he's got bloody policy after policy preventing anything and everything. He needs to get a life!

Well I know the boss has had it in the neck from everyone about the password policies so maybe I can push things over the edge. I have the usernames for everyone, I'll just lock out the accounts by accessing the webmail with my Iphone using the other employees usernames and the wrong passwords, either the policies will go or the crazy paranoid Admin will. At the very least I'll have great fun watching everyone get pissed off. Am I a genius or what!



Well that didn't take too long, a day of selectively locking out all the bosses accounts and the account lockout policy has been lifted, now I can just guess away till my hearts content.


1 day later...

Well this guessing game isn't as easy as it would seem, I've tried the all the names of the players in his beloved football team and I'm still not in. Hang on, here comes Mark now, typically back late from his extended lunch break. I think I'll have a chat with him as he walks back to his desk.

I can't believe it, after a days worth of guessing passwords and he goes and types it in right in front of me as I'm chatting to him. All I had to do was ask him if he'd checked out the news about “his team” and he went straight to the Sky Sports website. What a Sucker! And after all that the password was the star strikers name and number. I should have guessed that!

Right, so now I have the login name and password of the guy who designed the GNUphone, all I have to do is find a way of getting the designs out of the office once I have them. I can't email them out, that's to risky. Thumb drives are still strictly banned, but I do have my other at home and it has a 2GB memory card. There's nothing in the policy that mentions phones! It's risky but as long as I'm discreet I should be able to hook up the cable and download the files to my phone. Brilliant!


Well the next day I get in nice and early and I have plenty of time to copy the files. I'll just hook up my phone behind the PC, log in as Mark and have a search round for the designs. All being well i'll have the designs on my memory card before long and I can get them over to my mate at MicroFone Mag tonight.





Crap, the boss is on walkabouts. I better get rid of this cable and phone before he comes over here.



Coming up..........The Sys Admins story.


The Story of an Insider - Part 1. The Sys Admin Storys

This is my second part to a fictitious story about a theft of Intellectual Property by an insider and the detection and investigation of the incident.

The Sys Admins Story

So I get a call that Mark has locked himself out of his PC, well I guess when I implement password restrictions there's a price to pay. He says he never put the wrong password in though, yeah right, that's what they all say. I'll just check it out in the logs anyway.



Strange, that's not a design computer he's logging on from. Oh here he comes now, I'll ask him.

Man, I can't believe that, I just got my ass chewed from his boss for the last 10 minutes because HE forgot his password. Well I've got stuff to do, maybe I'll take it up with him later when he's in a better mood.


The next day......

Well something is definitely going on. Either this is a wind up or someone is trying to hack my network. I've had nearly every manager kicking my ass today about the lock out policy, all within the last few hours, I've got a stack of reports to write and patches to test and now my boss wants me in his office. This is just great! I'll quickly raise the support ticket and get this on the system so I don't get an ass kicking for that too.

Well, I've been told in no uncertain terms that either the account restrictions go or I do. I tried to explain that this is more likely an attack of some sort because I have changed nothing on the network. No new software, no new policy settings, nothing. But it's no good, he wants the lockout policy gone immediately. It's a total knee-jerk reaction and he would not listen to reason.

Oh god, I hope it's not a virus or something, I better check the logs and see what's going on. We'll I found nothing in the AV logs, but there is definitely something wrong. In my Server event logs I can see loads of lockouts today.


I used EventCombMT.exe to get all the lockout events and export them to a file.



Eventcomb will rip through the eventlogs on the server and extract into text files just the event's I'm interested in. From the results I can see that accounts are being locked out, but from the IP of the OWA box.



It must be that its infected with a virus. There was only that PC in buying that got an account locked out too, I bet that's got the same virus.

Well from the logs on the OWA box I can see all the lockouts are coming from something trying to get in using valid accounts with a wrong password.



It seems it's always an iPhone that is locking out the accounts, I'll just grep through the other logs with PowerShell to see if this has happened before.

gc *.log | select-string "iphone"



It hasn't happened before but in the older logs I can see that an iPhone has only been used once before, and it was Pete in buying that used it. Interesting!

I still don't have too much to go on but doing something has to be better than doing nothing right! Maybe the PC in buying does have something to do with it.

Again the AV checks out okay and is up to date, the firewall has pretty tight egress filtering and those logs are pretty clean. If there was something bad on the network I would expect it to show up on the firewall or the proxy logs and there's nothing.


I checked the PC is up to date on security patches. Let me run a script on the PC and the OWA box to see what's running, there must be something wrong. I have a batch file I created to respond to incidents such as this.


REM Usage: filename.bat ip-address/hostname outputfile
@echo off
set header1= **** Voliatile Data Gathering Script ****
cls

echo%header1%
type get-vol.bat > %2
REM Start Date & Time

time /T >> %2

date /T >> %2

REM System

psexec \\%1 systeminfo >> %2

REM Processes

psexec \\%1 tasklist >> %2

psexec \\%1 tasklist /svc >> %2

REM Networking

psexec \\%1 ipconfig /all >> %2

psexec \\%1 arp -a >> %2

psexec \\%1 netstat -anob >> %2

psexec \\%1 nbtstat -s >> %2

REM Finish Date & Time

time /T >> %2 date /T >> %2


The script isn't perfect because it's using the executables on the PC which could have been compromised, but it'll do for now until I can get round there and run something locally.

remote-info.bat gt-buy-01 c:\results-gt-buy-01.txt

The script runs commands that gets me details of the running processes, network connections, logged on users and all that sort of stuff. It's pretty good and I can really do with knowing what's happening on the PC right now.


Well the script ran fine, no weird processes, but there were some network connections to the file server in Design. Looking at my results file I can see that the NBTSTAT -s command shows some pretty big data transfers from the File-Server to the buying PC.




That's pretty weird, buying doesn't access files on that server they have there own server. I also saw that Mark from design had logged onto that PC. That's strange too, why would the Design Manager log onto a PC in buying to access his files? I'll update the Support Ticket and give him a call.

Well Mark from Design knew nothing about logging into a PC in buying. He said he has never logged onto any PC but his own and he is sure he has never given out his password.

I went back to my logs and I saw that my little HoneyPot has been tripped as well.



It's just a folder I set up that has object access logging on it. All the guys in design leave it alone and no one has any reason to go to it. That is no one goes to it if they now what they are looking for. Obviously someone doesn't know what they are looking for. Now I'm getting somewhere!



Now I know there is definitely something going on, and it looks as though someone has been accessing files that they shouldn't be.

I quickly check the profiles on the buying PC and sure enough it backs up what all the other tools have told me, Marks login has definitely been used on the buying PC.



I've informed my manager of what I have found, he has emailed me giving me permission to examine the buying PC whilst he has a chat with Pete in his office.


My goal at this point is to find out if an incident has occurred and then discover how this incident happened.



Coming Next.............. Sys Admin plays CSI.


The Story of an Insider - Part 1. Playing At CSI


Playing at CSI

Okay, so my manager has explained everything to Pete and has given me written permission to look at Pete's PC. Pete has also said that he was happy for me to look around his desk area. At the moment it may be nothing more than a virus or malware that has caused the log entries, but I need to be sure. My approach is to recapture the volatile data from the PC using a script similar to what I ran before. This time I use known good executables from a CD which is Read-Only media. I save the output to a network share as I want to make as little change as possible to the PC. After getting the volatile data off I'll image the PC and then create a VM from the image to look at further.

The output was pretty similar to what I got before when I ran the tools remotely although the connections through Netstat were different but that is to be expected.

I'm pretty sure that there is no virus on the PC so now I'm guessing that the PC has been used to gain access to restricted files in the Design share on File-Server.

Now I have the volatile data off the PC I want to make an image of the drive and use that for further examination, that way I can isolate this PC off the network and get back to my office for a well earned coffee.

I insert my Helix CD and attach my Western Digital portable hard drive to allow me to capture the DD image. Going to the Live Acquisition menu I select my source and destination and give the image a name.

Now I wait till the image is copied to the Western Digital Drive.

>


As soon as that is finished I check the log and the MD5 sums in the image folder and then I pull the plug on the PC and secure it until we get to the bottom of this issue.


Back in my office I make a copy of the DD image I have created and save it somewhere safe, that's just encase I screw up the one I'm working from. Now I use Live View to create a VM from the image that I can boot into to examine further.



Before I browse to the folder where I generated the cofig and double click the VMX file to boot into the VM I point the CD to a Helix ISO so I can use some other tools from the disk.



The system boots up and straight away I see that the last user logged in was MarkP, the Design Manager. Well now I know without doubt that the last account used was Marks.



I contact Mark and get his password, this makes life a little easier for examining the registry. If Mark wasn't available to give me his password I would have logged in as a local admin and likely used RegRipper to analyse the NTUSER.dat file. Luckily at this stage I don't have too.

I examine the recently used files and can see nothing untowards, I also create a list of all the files on the PC and pipe it out to a file on the same external WD hard disk. This is done for hidden files as well.

C:\Dir /s *.* > E:\gt-buy-01-files.txt

C:\Dir /s /a:h *.* > E:\gt-buy-01-hiddenfiles.txt

After searching through the text files I find nothing from the Design Share. This is frustrating, I'm sure that data has been downloaded because the NBTSTAT data from my remote volatile data collection indicated that some pretty big data transferes had been made.

I start Helix using RunAs and kick it off with local admin privileges.



As soon as Helix is running I check the processes again using the CD tools and just as I thought it's the same as before, nothing suspicious. I run PC Inspector File Recovery from the Helix CD. This will allow me to find deleted files on the PC.

And what do you know, here are some of the GNUphone design files, I recover them and as expected they are the same as in the Design share on the server.




The thing is, at this stage I don't know if Pete has just accessed the files and deleted them, or has he emailed them somewhere or copied them? I recheck Internet logs, look through his mailbox, checking the sent emails, the deleted and the deleted-deleted emails but nothing.

Ok, I'll try another useful tool from the CD, USBdeview maybe he has copied them to a USB drive. Ah, here we go. I can see 2 devices have been attached, one is the Western Digital USB drive I have been using and another is a HP USB thumb drive that's been attached today.



I search around Pete's desk looking for a thumb drive but I find nothing. I ring my boss to update him and he asks Pete to explain why he had been logged in as Mark and why he had used a USB thumb drive which is against company policy. I can here Pete say that he has no thumb drive and he empties his pockets to prove it.

Whilst he is busy pleading his innocence I Google the product ID and Vendor ID from the device that USBdeview found and it turns out to be a HP IPAQ.



When my boss pics up the phone I tell him that were looking for an IPAQ or Smartphone. Minutes later have a HP IPAQ Smartphone sitting on my desk and permission to search it.


GAME OVER. Sys Admin Wins!


But how did this happen? Was the Design Manager involved? Well it would make much sense if he was. Why wouldn't he just steal the data himself?

After interviewing the Design Manager it seems that he was very careful with is password. He never wrote it down, changed it regularly and never gave it to co-workers. I guess then I 'll never know. I write up my report and recommend that we reapply the password lock-out policy and increase the password length from 8 to 10 characters to make password guessing more difficult. I'll also propose regular password audits to identify weak predictable passwords and I email all staff reminding them of the importance of strong passwords and attach the Staff Computer Policy. Finally I propose that we review our stance on USB devices. In this day and age nearly everything has some form of storage on it, we need to look at some other way of protecting our data.



I hope anyone reading this has enjoyed it, i have enjoyed writing it and I hope to do more in the new year.


Incident Response - Finding Modified Files

Following an incident it is useful to look at a server or PC and see what files have changed. If you know the timeframe when an incident took place the following PowerShell script may be of use.

It can be run on a remote system (as long as you have permissions), will prompt you for dates to search (from and to) and will save the results to a file of your choosing.

Here's the script.

#Find-Files.ps1
$1 = (read-Host "Enter start date e.g yyyy/mm/dd")
$2 = (read-Host "Enter finish date e.g yyyy/mm/dd")
$path = (Read-Host "Enter path of target e.g \\server\c$\windows\")
$results = (Read-Host "Where do you want the results saved to? e.g c:\temp\")
$start = [datetime]$1
$end = [datetime] $2
$period = {$_.lastwritetime -gt $start -and $_.lastwritetime -lt $end}
gci $path -Recurse | where {!$_.psiscontainer -and (.$period)} | Out-File -Width 255 $Results


I hope this is of use to someone else.

Thanks to the guys from the forums on www.powershellcommunity.org who helped me with this.

Collecting Remote Volatile Data with PowerShell

This post is really about a script (Get-Volatile) I have been working on in PowerShell that will collect volatile data from a remote host using WMI. The aim of my script is to easily and quickly grab a bunch of useful information that may change from a host that I have an interest in for whatever reason. My script does assume thst you have permission and administrative access to the host that you are pulling information from.

Currently I use a bunch of batch files and Perl scripts written by Harlan Carvey and these are great because they help me keep an idea of what I want to achieve with my script.


The information I want to gather from a remote host with the script is the following:

  • System Time
  • Running Processes
  • Services
  • Shares
  • Sessions
  • Drivers
  • Logged on Users
  • Command History
  • Clipboard Contents
  • Hotfix/Patch Status
  • Start-up Information
  • Local Accounts & Groups
  • Networking Details & Open Ports
  • Network Connections

As my script is first run it will ask you for target and then for a name and location where you want to save the results. The results are simply a text file that can be used for further examination.

As the script is run it will have a friendly display to show where it is up to. I may well modify this to either state "1 of 2 tasks complete" or to display a progress bar.



The script is still evolving and as I have more code to add in I will update this post.

The code so far:

function Get-Volatile {

cls

$target = read-host "target?"
$Results = read-host "Results Location and Filename?"
write-host "Starting Get-Volatile V1.2 ........ Please Wait"
#
Write-Output "Current date on target as script starts" | Out-File -Width 255 $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Datenow = Get-Date
Write-Output $dateNow | Out-File -Width 255 -Append $Results
#
#OS Details
Write-Output "OS" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$OS = gwmi win32_operatingsystem -computername $target | Select CSName,Caption,CSDVersion,BuildNumber,RegisteredUser,Organization | Ft -AutoSize
Write-Output $OS | Out-File -Width 255 -Append $Results
#
write-host "Got OS........ Please Wait"
#
#
# Services & Processes
Write-Output "Running Services" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$services = gwmi win32_service -ComputerName $Target | select SystemName,ProcessID,Name,DisplayName,StartMode,State,PathName | sort StartMode | ft -AutoSize
Write-Output $Services | Out-File -Width 255 -Append $Results
#
write-host "Got Services........ Please Wait"
#
Write-Output "Running Processes" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Processes = gwmi win32_process -ComputerName $Target | select CSName,ProcessID,ProcessName,WS,CommandLine | sort WS -Descending | ft -AutoSize
Write-Output $Processes | Out-File -Width 255 -Append $Results
#
write-host "Got Processes........ Please Wait"
#
#
# Local Users and Groups
Write-Output "Local Users & Groups" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Users = gwmi Win32_UserAccount -filter "domain='$Target'" -ComputerName $Target | select name,Password*,LocalAccount,Lockout,SID | ft -AutoSize
Write-Output $Users | Out-File -Width 255 -Append $Results
#
write-host "Got Users ........ Please Wait"
#
#
$Groups = gwmi Win32_Group -filter "domain='$Target'" -ComputerName $Target | select Domain,Name,SID | ft -AutoSize
Write-Output $Groups | Out-File -Width 255 -Append $Results
#
write-host "Got Groups ........ Please Wait"
#
Write-Output "Profiles" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Profiles = Get-ChildItem -path "\\$target\C$\Documents and Settings" | Sort-Object LastWriteTime -descending | select Name,LastWriteTime | ft -AutoSize
Write-Output $Profiles | Out-File -Width 255 -Append $Results
#
#
# Networking
Write-Output "Shares" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Shares = gwmi win32_share -ComputerName $Target | ft -AutoSize
Write-Output $Shares | Out-File -Width 255 -Append $Results
#
write-host "Got Shares........ Please Wait"
#
Write-Output "Domain Details" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Domain = gwmi Win32_NTDomain -ComputerName $Target | Select DomainName,DCSiteName,DomainControllerAddress,DomainControllerName | ft -AutoSize
Write-Output $Domain | Out-File -Width 255 -Append $Results
#
write-host "Got Domain........ Please Wait"
#
# Software
#
Write-Output "Hotfixes" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Hotfixes = gwmi win32_quickfixengineering -ComputerName $Target | select CSName,HotfixID,ServicePackInEffect,Description,InstalledOn,InstalledBy | ft -AutoSize
Write-Output $Hotfixes | Out-File -Width 255 -Append $Results
#
write-host "Got Software and Hotfixes........ Please Wait"
#
Write-Output "Date and time as script finishes" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Datenow = Get-Date
Write-Output "date is $dateNow" | Out-File -Width 255 -Append $Results
#
Write-Host "Finished!"
}

Get-Volatile


Any suggestions or comment are welcome as always.


Change Log.
  • 27/09/08 - First script posted - Includes Date, Services, Processes, Local Users & Groups, Shares & Hotfixes.
  • 29/09/08 - Added in command to get a list of local profiles and some section headings for the output.
  • 07/09/08 - Added codeto retreive OS details and Domain & Site Details.

Retrieving Remote Processes with PowerShell

Keeping in line with my current theme of retrieving useful information from a compromised PC, below is a simple one-line that will grab the running processes from a remote host.

Get-WmiObject win32_process -ComputerName . | Select-Object CSName,Description,Processid,WS,Path | Sort-Object WS -Descending | Format-Table * -AutoSize


This is the full cmdlets rather than the aliases or shortened version, but for anyone reading this who might be wondering, that command would be:

gwmi win32_process -Co . | Select CSName,Description,Processid,WS,Path | Sort WS -Desc | Ft * -Au


And the output would be something like this.




Again, this can be run on an remote host by substituting . after -ComputerName to a remote computer name. The output can be exported straight to CSV by removing the Format-Table command and using Export-CSV cmdlet.

Retrieving Remote Services with PowerShell

In the few weeks that I have been using PowerShell I've been really keen to see how I could use it to help with the security parts of my job. In the past I have used scripts and tools from Harlan Carvey's book "Windows Forensics and Incident Recovery" when I have had to look at a PC that has been comprised. Now I'm beginning to grasp PowerShell I am keen to write my own scripts to investigate compromised PC's and retrieve volatile and non-volatile information.

In this post I will simply detail how to retrieve data about services from a remote PC using WMI and PowerShell.


Services

The information i'm interested in regarding Windows services is really what services are running, the state of them and the executable involved. Below is the command I would use to output that information to the screen.

gwmi win32_service -ComputerName . | sort StartMode | ft SystemName,DisplayName,StartMode,State,PathName




Unfortunately The whole output doesn't fit. So I would use this next Command to export the results to a CSV file for closer analysis.

gwmi win32_service -ComputerName . | sort StartMode | select SystemName,DisplayName,StartMode,State,PathName | export-csv -path d:\runningServices.csv

Now in the CSV i can see all of the output including the full path of the executable.



Obviously, in both examples the . after -ComputerName can be substituted fora remote computer that you have permission to query.

Data Recovery

Recently I was playing around with some old hard disk that I had formatted and I found that it was really easy to recover data from them even though the files had been deleted and the disk had been formatted.

The purpose of this post is to list methods of retrieving data and give a few tips on preventing data recovery if you are throwing away a computer / disk or selling it.

Firstly, when a file is deleted it is still on the disk. All that has happened is you have removed the pointer to it. When a disk is formatted all that you have done is remove the all the pointers. It's kind of like having a book and ripping out the index. The pages are still there but you don't know how to get to anything.


Data Recovery

A couple of the tools I have been playing with are Foremost and Photorec. PhotoRec is available on windows or Linux and I have found it to be quite good, however Foremost is what I have had most luck with.

Foremost will restore many types of files such as doc, jpg, zip, mpg, zip and many more. it's usage is simple too. I simply point it at a disk or an image file and tell it to either extract everything or just a particular filetype to a location.

foremost -v -o /home/syn/dump -t doc /dev/sdc

In the command above I have told foremost to use an output directory of /home/syn/dump and search for any docs on device /dev/sdc (note /dev/sdc is a hard disk connect by USB in this case). If I had left off the -t switch it would have looked for everything.


Data Deletion

After seeing how easy it was to retrieve deleted items I set about figuring out simple ways to prevent it.

I found that by overwriting the disk I could not get anything out of it using the tools I had. a simple way of overwriting a disk that was totally blank was by using DD with the command below:

dd if=/dev/zero of=/dev/sdc conv=notrunc

Or the same using dclfdd, but with dcfldd I got a progress bar.

But what about wiping free space on a disk that had data on or an OS. Well for that I used Truecrypt. I simply defragged the drive and filled the freespace with one huge Truecrypt file and then deleted it.

After re-running foremost and photorec I was unable to retrieve files that were retrievable before.

Hope this helps someone.

Finding Traces of Executables in the Registry

I found a registry key that is really quite interesting and I can see how it might come in handy when looking at a system that may have been compromised.

By following the procedure detailed below I was able to quickly find all programs or executables that have been installed or executed on a system by the logged in user.

These values are stored in clear text and are very simple to retrieve.


Tools

  • Reg (windows XP native command)
  • excel or any other spreadsheet

Steps

1. Im using a Windows XP SP2 system here. From a DOS prompt I execute the following command:

reg query HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\SHELLNOROAM\MUICACHE > outputfile.txt
The results are ouyput to a file called output.txt and stored inthe current directory.


2. Import into the file into excel and using auto filters Filter out all lines begining with @. You are left with a list of programs that have at some stage been installed and used.



As can be seen from the output there are several files listed that are just executables and have no installer. BAT files are also listed if they have been run. Also listed is the location from which the executable was run.




If you are interested in other ways to get the most of the registry I totally recommend Harlan Carvey's book "Windows Forensics and Incident Recovery ".

After writing this entry I found from Harlan thaty he had previously blogged on this registry key. In his blog Harlan goes into great detail about this. I link to his post here.

Forensics - Disk Imaging

For one reason or another you may want to make a copy of a hard disk. I will describe methods to create a bit-for-bit copy of a hard disk either to a local device or over a network.

The thing to remember throughout the examples listed below is Linux thinks of everything as a file. So the file it sees as hda in the /dev directory is actually the harddisk.

The following software will be used in the examples listed below.

  • A bootable live linux distro that does not auto mount drives such as Helix
  • dd
  • nc
  • split
  • md5sum
  • cat

dd, nc, md5sum, cat and split are available on Linux and Windows.

Regarding hardware you will require the following.

  • 2 x Computers (if creating a copy across a network)
  • USB thumb drive
  • USB hard drive (If creating the image to a USB hard drive)

Example 1 – A Copy Across A Network

To make a copy across a network you will need 2 computers, the target computer, Computer01, and the computer you will be copying to, Computer02.

  1. Insert the Linux boot disk into Computer01 and boot the system into Linux.
  1. Insert the USB thumb drive, if this doesn’t automatically mount it will require mounting. In my examples below I will assume it is /dev/sdb1 and has been mounted as /media/USB.
  1. Locate the disk you want to copy in the /dev directory, in my examples the hard disk will be called hda yours maybe something similar.
  1. Using the command md5sum /dev/hda >/mount/USB/diskimage_md5hash.txt create a MD5 hash of the drive on the mounted USB drive so you can test this against the copied file to verify the integrity.
  1. On Computer02 make sure you have enough diskspace to accommodate a file the size of the disk you are going to copy and using netcat (nc) run the command

nc –L –p 6677 >c:\diskimage.img

What you have done here is to set up netcat (nc) to listen persistently (-L) on port 6677 (-p 6677) and send the output to a file on C:\ of Computer02 (>c:\diskimage.img).

  1. From Computer01 run the following command:

dd if=/dev/hda | nc 192.168.1.2 6677

This command assumes that the IP address of Computer02 is 192.168.1.2. By running this command you will be copying the input file /dev/hda (if=/dev/hda) from Computer01 to C:\diskimage.img on Computer02 using netcat (nc).

  1. Finally, after the copy has finished you can run md5sum on Computer02 against the C:\diskimage.img file on Computer02 and compare this to the md5sum taken earlier to verify the copies are identical.

Example 2 – A Local Copy to a USB Storage Device

In this example you will need only the Target PC and a USB storage device large enough to hold the image.

  1. Insert the Linux boot disk into the computer and boot the system into Linux.
  2. Connect the USB storage device, if this doesn’t automatically mount it will require mounting. In my examples below I will assume it is /dev/sdb1 and has been mounted as /media/USB.
  1. Locate the disk you want to copy in the /dev directory, in my examples the hard disk will be called hda yours maybe something similar.
  1. Using the command md5sum /dev/hda >/mount/USB/diskimage_md5hash.txt create a MD5 hash of the drive on the mounted USB device so you can test this against the copied file to verify the integrity.
  1. Run the following command:

dd if=/dev/hda of=/media/usb/diskimage.img

This will copy the disk as a file onto the USB storage device as diskimage.img.

  1. Create another md5 hash of the image on the storage device and compare to the original to verify the integrity of the copy.

The result of both of the examples above is a forensically sound image of the hard disk.

Advanced Usage of dd for Imaging

Whilst using the methods above you may come across issues. For example, if the PC cannot read some of the sectors of the drive you are copying, or if the file needs splitting to fit onto CD’s. Or if the image needs slitting to fit on a device that is FAT32 and requires files to be smaller than 2GB.

Copying an image from a disk with bad sectors

When imaging a drive that is starting to have some bad sectors the command below can be used.

dd if=/dev/hda of=/media/USB conv=noerror,sync

This will allow dd to proceed past read errors, and pad the destination with 0's where there were errors on the source drive (so your size and offsets will match). If you do this, you may want to consider redirecting standard-error out to a file, so you have a record of where your errors were.

Splitting images

This can be done using a couple of different methods.

The easiest method is by using the split program. The syntax for the command if you required a 4GB image to fit on CD’s would be:

dd if=/dev/hda | split –b 620m - /USB/sda/

This will run the input file (/dev/hda) through split and create several files of 620MB (-b 620m) in the directory /USB/sda/. The files will usually be called x** (* denotes a wildcard in this example)

These files can be reformed into an image file using the cat command.

Cat x* > bigimage.img

Then create a hash of the file using md5sum and compare to the original hash value.

Md5sum bigimage.img

Alternatively, if split is not available you can use dd by itself but use the skip, bs (block size) and count switches to prevent it from reading from the beginning of the file.

dd if=dev/hda of=/media/USB/image1.img bs=1M count=620

dd if=dev/hda of=/media/USB/image2.img bs=1M count=620 skip= 621

dd if=dev/hda of=/media/USB/image3.img bs=1M count=620 skip= 1241

dd if=dev/hda of=/media/USB/image4.img bs=1M count=620 skip= 1861

dd if=dev/hda of=/media/USB/image5.img bs=1M count=620 skip= 2481

etc………until the end of the input file.

What is happening here is you are telling dd to work in 1MB blocks (bs=1M), to only copy 620MB at a time (count=620) and in some cases to skip to a particular part of the input file (skip=621 etc…) thus creating several images that can then be copied to CD’s. Once on the target system and in the same directory (I will assume directory is /home/me) they can be put back together into a single image using the command below.

Cat /home/me/image* > bigimage.img

Md5sum can be run against this image and compared to the original md5 hash to verify the integrity.

Dd To a Zipped Image

You can pipe dd through gzip to save on some disk space.

dd if=/dev/hda | gzip -f > /media/USB/compressed_image.img.gz

Using Split & Gzip Together

To help cope with size limits both gzip and split can be used together. This has the benefit of splitting the image and zipping it up also to save space and requires less work. Below is the syntax used to perform this and an explanation of the command.

dd if=/dev/hda | gzip –c | split -b 2000m - /media/USB/image.img.gz.

  1. dd is used to take an image of the harddrive.
  2. This is passed to gzip (-c is to stdout)
  3. The compressed image is then piped to the split tool (split then creates the files image.img.gzaa, image.img.gzab, etc )

To restore the multi-file backup, run the command below:

cat /USB/image.img.gz* | gzip -dc | dd of=/dev/hda

  1. Cat displays the contents of the zipped and split image files to stdout in order.
  2. Results are piped through gzip and decompressed.
  3. And are then written to the hard drive with dd.

Creating empty disk images

To create an empty disk image, get the data from /dev/zero. To create a 10MB image or file:

dd if=/dev/zero of=image bs=1M count=1024

Or

dd of=image bs=1M count=0 seek=1024

In the second example nothing is written, not even zeroes, we just seek 10MB into the file and close it. The result is a sparse file that is implicitly full of 10MB of zeroes, but that takes no disk space. ls -la will show 10MB, both du and df will show 0. When the file is written to, Linux will allocate disk space for the data. ls will continue to show 10MB, but du will gradually approach 10MB.

Notes:

Whilst researching the use of dd another tool was brought to my attention which is called dcfldd. This tool is like dd in many ways and uses similar syntax but is also able to produce hashes on the fly and can provide status of copying files amongst other useful features. It's available on both Linux and Windows.

Forensics - Volatile Data

Volatile Data is information that changes frequently and is often lost upon powering down the PC. Volatile data will include information about running process, network connections, clipboard contents, data in memory. This information may be critical to the discovery of the cause of an incident.”
  1. Introduction

  2. Preparing A Toolkit

  3. Responding To An Incident

  4. Removing Data From The PC


1. Introduction

In my work environment, when an incident occurs it's quite likely that upon discovery the first response will be to protect the network. Following that, to understand the incident and to perform a Root Cause Analysis (RCA) to discover the cause, implement safeguards to prevent further incidents of the same kind. Even though in most organisations legal action is not common it is beneficial to preserve as much evidence as possible, as until the incident is understood legal action cannot be ruled out.

The following blog entry describes the steps I perform to protect the network, whilst gathering the volatile data to help perform the RCA whilst preserving the data for further forensics if necessary. The guide below assumes that you have administrative control over the victim PC, network connectivity to a PC for the collection of data, network connectivity to a remote share or access to remote storage such as a USB device.


2. Preparing A Toolkit

To prevent any programs writing to the PC the following tools should be copied to a form of read-only media such as a CD-ROM or run from a read-only network share. Copying data to a comprimised PC may overwrite data on the victim PC and comprimise any legal procedings if they were to occur.


Command, Netstat, Psloglist, Netcat, Pslist, Netusers, Net (user, session), Pulist, ListDLLs, Handle, Tlist, Tasklist, PS, IPConfig, NBTStat, Fport, Openports, DOSKEY, GPList, Time, Date, Route


Many of the tools above collect similar information. However, they often have subtle differences and may provide information that the others lack. What is important is that tools come from good sources, so in the case of tools such as Command, Netstat and other Windows native tools this means taken from a fresh install of Windows. This is to prevent using tools that may be infected or that may have been altered. A disk with these tools on should always be kept safe and MD5Sums should be calculated and saved along with the tools. As important as this is familiarity of the tools. Become an expert at using them and learn there nuances. The switches with commands such as time /t are essential when piping commands to as listener.

To make the process of collecting volatile data easier it is useful to create a batch file to run the tools. Once the switches have been correctly identified and are entered into the batch file the command will be executed the same way each time, this will help save time and has the additional benefit of making the logging task slightly easier too.


3. Responding To An Incident

Firstly, the incident must be discovered. This may be through log monitoring, traffic analysis, alerts or just by stumbling across something that shouldn't be there such as a program, process or registry entry.

Once the incident has been discovered usually the first reaction is to pull the plug to protect the network. Although this does have the desired effect of isolating the PC from the network it also destroys critical volatile data. If the PC remains on and connected to the network this important data can be taken from the PC for further analysis. Also the system in question may be a critical business system that cannot be taken down without monitory loss.


4. Removing Data from the PC

After assembling the toolkit and testing the tools/batch files in a test environment you are ready to respond to an incident.

Data on the PC needs to be removed without altering the state of the PC as much as possible, as until the incident is understood it will not be known if any authorities are notified. This is done by using tools and scripts that can be run from the command-line and piped out to a netcat listener. This gets the volatile data off the PC so it can be disconnected from the network and powered down if necessary. If a listener is not available then every effort should be made to save the captured data on either a network share or some other form of removable media such as an attached USB drive, but be aware that connecting a USB device will write an entry to the registry so the make, model and serial no must be included in the log.


Log File

It is important that a log is kept of every action taken on the victim PC including the following:

  • Time
  • Tools Used (& versions)
  • Commands Used


Setting up a listener

To capture the data across a network connection a netcat listener can be set up on a remote PC using the following command:

c:>nc -L -p 4455 > victimPC_date.log

This will capture any data sent to port 4455 and log it to a file called victimPC_date.log.


From The Victim PC

Log onto the victim PC and run the commands or the prepared batch file from your toolkit and pipe the results out to the netcat listener, the USB device or the network share.

Below are examples of the commands that can be run.

Running each of the commands individually would look something like below:


date /t | nc -w 1 IP_ADDRESS_OF_LISTENER 4455

time /t | nc -w 1 IP_ADDRESS_OF_LISTENER 4455

netstat -anovb | nc -w 1 IP_ADDRESS_OF_LISTENER 4455

fport | nc -w 1 IP_ADDRESS_OF_LISTENER 4455


........Thats quite a lot of work if you get the picture. If you was to create a batch file file with entries such as the following in you could just pipe the batch file out to the listener or to a log file on a share or USB.

The batch file could contain the following:

date /t

time /t

ifconfig /all

netstat -anovb

net session

net user

.................and many more from the toolkit can be added. One thing to note is to make sure none of the commands require user input to continue. For example, time if used without the /t switch will hang as will date. This reiterates the point of becoming familier with the tools and testing them before an incident.


Supposing the batch file is called Volatile.bat you could execute the following command:

volatile.bat | nc -w 2 IP_ADDRESS_OF_LISTENER 4455


Or if F: is the USB or network share:

volatile.bat > F:\>Victim_PC_Name.log


You then have the envious task of going through the logs to find the cause of the incident. Once the data has been lifted from the PC it can be disconnected from the network by disconnecting the network cable if necessary.

If you require further information of the collection of volatile data or any aspects of forensics then the following books are an excellent resources.

  • Windows Forensics and Incident Recovery from Harlan Carvey.
  • Incident Response by Kevin Mandia & Chris Prosise

A computer crime and forensics podcast can be found by googling CyberSpeak.

+++

Share |

"make something then You never be lost"

wibiya widget