Sunday, February 7, 2010
4G handset to be demonstrated this month
NEC said on Monday that NTT will demonstrate the handset receiving streaming high-resolution video across an LTE network at Mobile World Congress, which kicks off on 15 February in Barcelona. According to NEC, the handset uses an LTE chipset that was developed by Fujitsu, NEC, NTT DoCoMo and Panasonic, and first sampled in October.
LTE, the ‘long-term evolution of 3G’, is the successor to HSDPA and is roughly 10 times faster, providing theoretical downlink speeds of at least 100Mbps and a theoretical uplink of at least 50Mbps. The technology was designed to reduce latency in data transmission and improve the efficiency of frequency usage, making it more suitable than 3G for services such as streaming HD video, video conferencing and online gaming.
The world’s first commercial LTE mobile broadband services went live in Oslo and Stockholm in December through the Scandinavian operator TeliaSonera, which is initially offering LTE access via a mobile dongle.
Huawei announced in December that it had completed its first UK-based LTE trials, held in conjunction with O2, that reached maximum downlink throughput of 150Mbps. The trial took place in the Slough area, where O2’s headquarters are located.
NTT has said it plans to spend between ?300bn-?400bn (?2bn-?3bn) on LTE rollouts over the next five years.
source : http://www.hacking-news.com/
4G handset to be demonstrated this month
NEC said on Monday that NTT will demonstrate the handset receiving streaming high-resolution video across an LTE network at Mobile World Congress, which kicks off on 15 February in Barcelona. According to NEC, the handset uses an LTE chipset that was developed by Fujitsu, NEC, NTT DoCoMo and Panasonic, and first sampled in October.
LTE, the ‘long-term evolution of 3G’, is the successor to HSDPA and is roughly 10 times faster, providing theoretical downlink speeds of at least 100Mbps and a theoretical uplink of at least 50Mbps. The technology was designed to reduce latency in data transmission and improve the efficiency of frequency usage, making it more suitable than 3G for services such as streaming HD video, video conferencing and online gaming.
The world’s first commercial LTE mobile broadband services went live in Oslo and Stockholm in December through the Scandinavian operator TeliaSonera, which is initially offering LTE access via a mobile dongle.
Huawei announced in December that it had completed its first UK-based LTE trials, held in conjunction with O2, that reached maximum downlink throughput of 150Mbps. The trial took place in the Slough area, where O2’s headquarters are located.
NTT has said it plans to spend between ?300bn-?400bn (?2bn-?3bn) on LTE rollouts over the next five years.
source : http://www.hacking-news.com/
Google aims to speed up DNS requests
Google and Neustar UltraDNS have proposed a extension to try to build some geographic awareness into the Domain Name System.
The proposed extension, called Client IP information in DNS requests, would send along the first three quarters of a user’s IP address along with an DNS request. The last quarter would be cut off to preserve some privacy, but the first part should be enough to geographically target the answer in some cases, Google said in a blog post on Wednesday.
As designed, it would, for example, return the address for Google’s Dutch server, not Google’s California server, to a user in the Netherlands who needs to reach it.
For more on this story, see Google proposes geo-smart Internet speedup on CNET News.
Google aims to speed up DNS requests
The proposed extension, called Client IP information in DNS requests, would send along the first three quarters of a user’s IP address along with an DNS request. The last quarter would be cut off to preserve some privacy, but the first part should be enough to geographically target the answer in some cases, Google said in a blog post on Wednesday.
As designed, it would, for example, return the address for Google’s Dutch server, not Google’s California server, to a user in the Netherlands who needs to reach it.
For more on this story, see Google proposes geo-smart Internet speedup on CNET News.
Saturday, December 12, 2009
The Story of an Insider
Introduction
I really enjoyed writing my first story in November, and I received loads of great feedback so I thought I'd do another one but from a slightly different angle. As well as writing my usual posts writing these stories really helps me learn new and different things.So for my second effort I'm going to present a 3 part story. The first part will be the attackers story, the second and third parts will be the defenders perspective, focusing on the discovery of the attack and then some forensics thrown in for fun. I must point out that I am in no way trained in forensics, the techniques I will discuss would be those that any Systems Administrator could use to investigate an incident on his or her network after gaining permission.
Setting the Scene
As the title suggests this story will be about a rogue employee who feels poorly treated by his employers and wants revenge. His evil intention is to access restricted files and the sell plans for the eargerly awaited GNUphone to a popular website. Sounds easy? Well maybe I'll make things a bit interesting for him.
On the defending side is a keen Systems Administrator who looks after his network as if it's his baby. He has fought with management to have policies and procedures put in place to make his network secure.
So throughout December we'll see what the attacker does to get to the data, and what the Sys Admin does to try to prevent, detect and investigate the incident.
The Story of an Insider - Part 1. Shoulder Surfin Goodness
For a bit of background on this story you can read the intro here. This post details a low tech hack, primarily because its from the perspetive of a bog standard user. (If your reading this your probably not a bog standard user).
The Insiders story.
I've worked for this company for 2 years and all I get is crap from the boss. Those glory boys in design get all the praise for the GNUphone but if it weren't for people like me handling the suppliers and getting them down to rock bottom prices we couldn't even compete with the big boys in the market. It's launch day soon and all I see is the design lads getting party after party, rolling in late, taking long lunches and doing sod all. And to top it off I come in late once and I'm on a warning.
Well it just so happens that if I can just get the finished designs for the GNUphone to a guy I know over at MicroFone Magazine before the launch I'll be wiping the smile of those smug gits faces and I'll make a few quid too. I mean, it's not like i'm really hurting anyone, it justs means people get to see the phone a little early that's all.
I'll just have a poke around on the server and see what I can find...
Bugger! I can't get in the folder. I guess only the superstars in design are allowed access. Well I know the top guy down there is a football nut so it wouldn't take the brains of an astronaut to figure out his password.
Well none of that worked. But Mark did get really pissed at Carl the IT guy because his account was locked out. Then the boss had a go too, ranting that the security was an overkill and was preventing people from working. Yeah right! More like preventing people from getting to Facebook.
Well I better think about this because I have got to get the designs, i've told my mate I can get them and I don't want to look stupid. I need some of those hacking tools but our Internet access and email is monitored and were not allowed to bring software in. Were not even allowed USB devices for crying out loud! The Sys Admin is so paranoid he's got bloody policy after policy preventing anything and everything. He needs to get a life!
Well I know the boss has had it in the neck from everyone about the password policies so maybe I can push things over the edge. I have the usernames for everyone, I'll just lock out the accounts by accessing the webmail with my Iphone using the other employees usernames and the wrong passwords, either the policies will go or the crazy paranoid Admin will. At the very least I'll have great fun watching everyone get pissed off. Am I a genius or what!
Well that didn't take too long, a day of selectively locking out all the bosses accounts and the account lockout policy has been lifted, now I can just guess away till my hearts content.
1 day later...
Well this guessing game isn't as easy as it would seem, I've tried the all the names of the players in his beloved football team and I'm still not in. Hang on, here comes Mark now, typically back late from his extended lunch break. I think I'll have a chat with him as he walks back to his desk.
I can't believe it, after a days worth of guessing passwords and he goes and types it in right in front of me as I'm chatting to him. All I had to do was ask him if he'd checked out the news about “his team” and he went straight to the Sky Sports website. What a Sucker! And after all that the password was the star strikers name and number. I should have guessed that!
Right, so now I have the login name and password of the guy who designed the GNUphone, all I have to do is find a way of getting the designs out of the office once I have them. I can't email them out, that's to risky. Thumb drives are still strictly banned, but I do have my other at home and it has a 2GB memory card. There's nothing in the policy that mentions phones! It's risky but as long as I'm discreet I should be able to hook up the cable and download the files to my phone. Brilliant!
Well the next day I get in nice and early and I have plenty of time to copy the files. I'll just hook up my phone behind the PC, log in as Mark and have a search round for the designs. All being well i'll have the designs on my memory card before long and I can get them over to my mate at MicroFone Mag tonight.
Crap, the boss is on walkabouts. I better get rid of this cable and phone before he comes over here.
Coming up..........The Sys Admins story.
The Story of an Insider - Part 1. The Sys Admin Storys
This is my second part to a fictitious story about a theft of Intellectual Property by an insider and the detection and investigation of the incident.
Strange, that's not a design computer he's logging on from. Oh here he comes now, I'll ask him.
Man, I can't believe that, I just got my ass chewed from his boss for the last 10 minutes because HE forgot his password. Well I've got stuff to do, maybe I'll take it up with him later when he's in a better mood.
The next day......
Well something is definitely going on. Either this is a wind up or someone is trying to hack my network. I've had nearly every manager kicking my ass today about the lock out policy, all within the last few hours, I've got a stack of reports to write and patches to test and now my boss wants me in his office. This is just great! I'll quickly raise the support ticket and get this on the system so I don't get an ass kicking for that too.
Well, I've been told in no uncertain terms that either the account restrictions go or I do. I tried to explain that this is more likely an attack of some sort because I have changed nothing on the network. No new software, no new policy settings, nothing. But it's no good, he wants the lockout policy gone immediately. It's a total knee-jerk reaction and he would not listen to reason.
Oh god, I hope it's not a virus or something, I better check the logs and see what's going on. We'll I found nothing in the AV logs, but there is definitely something wrong. In my Server event logs I can see loads of lockouts today.
I used EventCombMT.exe to get all the lockout events and export them to a file.

Eventcomb will rip through the eventlogs on the server and extract into text files just the event's I'm interested in. From the results I can see that accounts are being locked out, but from the IP of the OWA box.

It must be that its infected with a virus. There was only that PC in buying that got an account locked out too, I bet that's got the same virus.
Well from the logs on the OWA box I can see all the lockouts are coming from something trying to get in using valid accounts with a wrong password.

It seems it's always an iPhone that is locking out the accounts, I'll just grep through the other logs with PowerShell to see if this has happened before.
gc *.log | select-string "iphone"

It hasn't happened before but in the older logs I can see that an iPhone has only been used once before, and it was Pete in buying that used it. Interesting!
I still don't have too much to go on but doing something has to be better than doing nothing right! Maybe the PC in buying does have something to do with it.
Again the AV checks out okay and is up to date, the firewall has pretty tight egress filtering and those logs are pretty clean. If there was something bad on the network I would expect it to show up on the firewall or the proxy logs and there's nothing.
I checked the PC is up to date on security patches. Let me run a script on the PC and the OWA box to see what's running, there must be something wrong. I have a batch file I created to respond to incidents such as this.
REM Usage: filename.bat ip-address/hostname outputfile
@echo off set header1= **** Voliatile Data Gathering Script ****
cls
echo%header1% type get-vol.bat > %2
REM Start Date & Time
time /T >> %2
date /T >> %2
REM System
psexec \\%1 systeminfo >> %2
REM Processes
psexec \\%1 tasklist >> %2
psexec \\%1 tasklist /svc >> %2
REM Networking
psexec \\%1 ipconfig /all >> %2
psexec \\%1 arp -a >> %2
psexec \\%1 netstat -anob >> %2
psexec \\%1 nbtstat -s >> %2
REM Finish Date & Time
time /T >> %2 date /T >> %2
The script isn't perfect because it's using the executables on the PC which could have been compromised, but it'll do for now until I can get round there and run something locally.
remote-info.bat gt-buy-01 c:\results-gt-buy-01.txt
The script runs commands that gets me details of the running processes, network connections, logged on users and all that sort of stuff. It's pretty good and I can really do with knowing what's happening on the PC right now.
Well the script ran fine, no weird processes, but there were some network connections to the file server in Design. Looking at my results file I can see that the NBTSTAT -s command shows some pretty big data transfers from the File-Server to the buying PC.

That's pretty weird, buying doesn't access files on that server they have there own server. I also saw that Mark from design had logged onto that PC. That's strange too, why would the Design Manager log onto a PC in buying to access his files? I'll update the Support Ticket and give him a call.
Well Mark from Design knew nothing about logging into a PC in buying. He said he has never logged onto any PC but his own and he is sure he has never given out his password.
I went back to my logs and I saw that my little HoneyPot has been tripped as well.

It's just a folder I set up that has object access logging on it. All the guys in design leave it alone and no one has any reason to go to it. That is no one goes to it if they now what they are looking for. Obviously someone doesn't know what they are looking for. Now I'm getting somewhere!

Now I know there is definitely something going on, and it looks as though someone has been accessing files that they shouldn't be.
I quickly check the profiles on the buying PC and sure enough it backs up what all the other tools have told me, Marks login has definitely been used on the buying PC.

I've informed my manager of what I have found, he has emailed me giving me permission to examine the buying PC whilst he has a chat with Pete in his office.
My goal at this point is to find out if an incident has occurred and then discover how this incident happened.
The Story of an Insider - Part 1. Playing At CSI
Incident Response - Finding Modified Files
It can be run on a remote system (as long as you have permissions), will prompt you for dates to search (from and to) and will save the results to a file of your choosing.
Here's the script.
#Find-Files.ps1
$1 = (read-Host "Enter start date e.g yyyy/mm/dd")
$2 = (read-Host "Enter finish date e.g yyyy/mm/dd")
$path = (Read-Host "Enter path of target e.g \\server\c$\windows\")
$results = (Read-Host "Where do you want the results saved to? e.g c:\temp\")
$start = [datetime]$1
$end = [datetime] $2
$period = {$_.lastwritetime -gt $start -and $_.lastwritetime -lt $end}
gci $path -Recurse | where {!$_.psiscontainer -and (.$period)} | Out-File -Width 255 $Results
I hope this is of use to someone else.
Thanks to the guys from the forums on www.powershellcommunity.org who helped me with this.
Collecting Remote Volatile Data with PowerShell
This post is really about a script (Get-Volatile) I have been working on in PowerShell that will collect volatile data from a remote host using WMI. The aim of my script is to easily and quickly grab a bunch of useful information that may change from a host that I have an interest in for whatever reason. My script does assume thst you have permission and administrative access to the host that you are pulling information from.
Currently I use a bunch of batch files and Perl scripts written by Harlan Carvey and these are great because they help me keep an idea of what I want to achieve with my script.
The information I want to gather from a remote host with the script is the following:
- System Time
- Running Processes
- Services
- Shares
- Sessions
- Drivers
- Logged on Users
- Command History
- Clipboard Contents
- Hotfix/Patch Status
- Start-up Information
- Local Accounts & Groups
- Networking Details & Open Ports
- Network Connections
As my script is first run it will ask you for target and then for a name and location where you want to save the results. The results are simply a text file that can be used for further examination.
As the script is run it will have a friendly display to show where it is up to. I may well modify this to either state "1 of 2 tasks complete" or to display a progress bar.

The script is still evolving and as I have more code to add in I will update this post.
The code so far:
function Get-Volatile {
cls
$target = read-host "target?"
$Results = read-host "Results Location and Filename?"
write-host "Starting Get-Volatile V1.2 ........ Please Wait"
#
Write-Output "Current date on target as script starts" | Out-File -Width 255 $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Datenow = Get-Date
Write-Output $dateNow | Out-File -Width 255 -Append $Results
#
#OS Details
Write-Output "OS" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$OS = gwmi win32_operatingsystem -computername $target | Select CSName,Caption,CSDVersion,BuildNumber,RegisteredUser,Organization | Ft -AutoSize
Write-Output $OS | Out-File -Width 255 -Append $Results
#
write-host "Got OS........ Please Wait"
#
#
# Services & Processes
Write-Output "Running Services" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$services = gwmi win32_service -ComputerName $Target | select SystemName,ProcessID,Name,DisplayName,StartMode,State,PathName | sort StartMode | ft -AutoSize
Write-Output $Services | Out-File -Width 255 -Append $Results
#
write-host "Got Services........ Please Wait"
#
Write-Output "Running Processes" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Processes = gwmi win32_process -ComputerName $Target | select CSName,ProcessID,ProcessName,WS,CommandLine | sort WS -Descending | ft -AutoSize
Write-Output $Processes | Out-File -Width 255 -Append $Results
#
write-host "Got Processes........ Please Wait"
#
#
# Local Users and Groups
Write-Output "Local Users & Groups" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Users = gwmi Win32_UserAccount -filter "domain='$Target'" -ComputerName $Target | select name,Password*,LocalAccount,Lockout,SID | ft -AutoSize
Write-Output $Users | Out-File -Width 255 -Append $Results
#
write-host "Got Users ........ Please Wait"
#
#
$Groups = gwmi Win32_Group -filter "domain='$Target'" -ComputerName $Target | select Domain,Name,SID | ft -AutoSize
Write-Output $Groups | Out-File -Width 255 -Append $Results
#
write-host "Got Groups ........ Please Wait"
#
Write-Output "Profiles" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Profiles = Get-ChildItem -path "\\$target\C$\Documents and Settings" | Sort-Object LastWriteTime -descending | select Name,LastWriteTime | ft -AutoSize
Write-Output $Profiles | Out-File -Width 255 -Append $Results
#
#
# Networking
Write-Output "Shares" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Shares = gwmi win32_share -ComputerName $Target | ft -AutoSize
Write-Output $Shares | Out-File -Width 255 -Append $Results
#
write-host "Got Shares........ Please Wait"
#
Write-Output "Domain Details" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Domain = gwmi Win32_NTDomain -ComputerName $Target | Select DomainName,DCSiteName,DomainControllerAddress,DomainControllerName | ft -AutoSize
Write-Output $Domain | Out-File -Width 255 -Append $Results
#
write-host "Got Domain........ Please Wait"
#
# Software
#
Write-Output "Hotfixes" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Hotfixes = gwmi win32_quickfixengineering -ComputerName $Target | select CSName,HotfixID,ServicePackInEffect,Description,InstalledOn,InstalledBy | ft -AutoSize
Write-Output $Hotfixes | Out-File -Width 255 -Append $Results
#
write-host "Got Software and Hotfixes........ Please Wait"
#
Write-Output "Date and time as script finishes" | Out-File -Width 255 -Append $Results
Write-Output "" | Out-File -Width 255 -Append $Results
$Datenow = Get-Date
Write-Output "date is $dateNow" | Out-File -Width 255 -Append $Results
#
Write-Host "Finished!"
}
Get-Volatile
Any suggestions or comment are welcome as always.
Change Log.
- 27/09/08 - First script posted - Includes Date, Services, Processes, Local Users & Groups, Shares & Hotfixes.
- 29/09/08 - Added in command to get a list of local profiles and some section headings for the output.
- 07/09/08 - Added codeto retreive OS details and Domain & Site Details.
Retrieving Remote Processes with PowerShell
Get-WmiObject win32_process -ComputerName . | Select-Object CSName,Description,Processid,WS,Path | Sort-Object WS -Descending | Format-Table * -AutoSize
This is the full cmdlets rather than the aliases or shortened version, but for anyone reading this who might be wondering, that command would be:
gwmi win32_process -Co . | Select CSName,Description,Processid,WS,Path | Sort WS -Desc | Ft * -Au
And the output would be something like this.

Again, this can be run on an remote host by substituting . after -ComputerName to a remote computer name. The output can be exported straight to CSV by removing the Format-Table command and using Export-CSV cmdlet.
Retrieving Remote Services with PowerShell
In this post I will simply detail how to retrieve data about services from a remote PC using WMI and PowerShell.
Services
The information i'm interested in regarding Windows services is really what services are running, the state of them and the executable involved. Below is the command I would use to output that information to the screen.
gwmi win32_service -ComputerName . | sort StartMode | ft SystemName,DisplayName,StartMode,State,PathName


Unfortunately The whole output doesn't fit. So I would use this next Command to export the results to a CSV file for closer analysis.
gwmi win32_service -ComputerName . | sort StartMode | select SystemName,DisplayName,StartMode,State,PathName | export-csv -path d:\runningServices.csv
Now in the CSV i can see all of the output including the full path of the executable.

Obviously, in both examples the . after -ComputerName can be substituted fora remote computer that you have permission to query.
Data Recovery
The purpose of this post is to list methods of retrieving data and give a few tips on preventing data recovery if you are throwing away a computer / disk or selling it.
Firstly, when a file is deleted it is still on the disk. All that has happened is you have removed the pointer to it. When a disk is formatted all that you have done is remove the all the pointers. It's kind of like having a book and ripping out the index. The pages are still there but you don't know how to get to anything.
Data Recovery
A couple of the tools I have been playing with are Foremost and Photorec. PhotoRec is available on windows or Linux and I have found it to be quite good, however Foremost is what I have had most luck with.
Foremost will restore many types of files such as doc, jpg, zip, mpg, zip and many more. it's usage is simple too. I simply point it at a disk or an image file and tell it to either extract everything or just a particular filetype to a location.
foremost -v -o /home/syn/dump -t doc /dev/sdc
In the command above I have told foremost to use an output directory of /home/syn/dump and search for any docs on device /dev/sdc (note /dev/sdc is a hard disk connect by USB in this case). If I had left off the -t switch it would have looked for everything.
Data Deletion
After seeing how easy it was to retrieve deleted items I set about figuring out simple ways to prevent it.
I found that by overwriting the disk I could not get anything out of it using the tools I had. a simple way of overwriting a disk that was totally blank was by using DD with the command below:
dd if=/dev/zero of=/dev/sdc conv=notrunc
Or the same using dclfdd, but with dcfldd I got a progress bar.
But what about wiping free space on a disk that had data on or an OS. Well for that I used Truecrypt. I simply defragged the drive and filled the freespace with one huge Truecrypt file and then deleted it.
After re-running foremost and photorec I was unable to retrieve files that were retrievable before.
Hope this helps someone.
Finding Traces of Executables in the Registry
I found a registry key that is really quite interesting and I can see how it might come in handy when looking at a system that may have been compromised.
By following the procedure detailed below I was able to quickly find all programs or executables that have been installed or executed on a system by the logged in user.
These values are stored in clear text and are very simple to retrieve.
Tools
- Reg (windows XP native command)
- excel or any other spreadsheet
Steps
1. Im using a Windows XP SP2 system here. From a DOS prompt I execute the following command:
reg query HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\WINDOWS\SHELLNOROAM\MUICACHE > outputfile.txt
The results are ouyput to a file called output.txt and stored inthe current directory.
2. Import into the file into excel and using auto filters Filter out all lines begining with @. You are left with a list of programs that have at some stage been installed and used.

As can be seen from the output there are several files listed that are just executables and have no installer. BAT files are also listed if they have been run. Also listed is the location from which the executable was run.
If you are interested in other ways to get the most of the registry I totally recommend Harlan Carvey's book "Windows Forensics and Incident Recovery ".
After writing this entry I found from Harlan thaty he had previously blogged on this registry key. In his blog Harlan goes into great detail about this. I link to his post here.
Forensics - Disk Imaging
For one reason or another you may want to make a copy of a hard disk. I will describe methods to create a bit-for-bit copy of a hard disk either to a local device or over a network.
The thing to remember throughout the examples listed below is Linux thinks of everything as a file. So the file it sees as hda in the /dev directory is actually the harddisk.
The following software will be used in the examples listed below.
- A bootable live linux distro that does not auto mount drives such as Helix
- dd
- nc
- split
- md5sum
- cat
dd, nc, md5sum, cat and split are available on Linux and Windows.
Regarding hardware you will require the following.
- 2 x Computers (if creating a copy across a network)
- USB thumb drive
- USB hard drive (If creating the image to a USB hard drive)
Example 1 – A Copy Across A Network
To make a copy across a network you will need 2 computers, the target computer, Computer01, and the computer you will be copying to, Computer02.
- Insert the Linux boot disk into Computer01 and boot the system into Linux.
- Insert the USB thumb drive, if this doesn’t automatically mount it will require mounting. In my examples below I will assume it is /dev/sdb1 and has been mounted as /media/USB.
- Locate the disk you want to copy in the /dev directory, in my examples the hard disk will be called hda yours maybe something similar.
- Using the command md5sum /dev/hda >/mount/USB/diskimage_md5hash.txt create a MD5 hash of the drive on the mounted USB drive so you can test this against the copied file to verify the integrity.
- On Computer02 make sure you have enough diskspace to accommodate a file the size of the disk you are going to copy and using netcat (nc) run the command
nc –L –p 6677 >c:\diskimage.img
What you have done here is to set up netcat (nc) to listen persistently (-L) on port 6677 (-p 6677) and send the output to a file on C:\ of Computer02 (>c:\diskimage.img).
- From Computer01 run the following command:
dd if=/dev/hda | nc 192.168.1.2 6677
This command assumes that the IP address of Computer02 is 192.168.1.2. By running this command you will be copying the input file /dev/hda (if=/dev/hda) from Computer01 to C:\diskimage.img on Computer02 using netcat (nc).
- Finally, after the copy has finished you can run md5sum on Computer02 against the C:\diskimage.img file on Computer02 and compare this to the md5sum taken earlier to verify the copies are identical.
Example 2 – A Local Copy to a USB Storage Device
In this example you will need only the Target PC and a USB storage device large enough to hold the image.
- Insert the Linux boot disk into the computer and boot the system into Linux.
- Connect the USB storage device, if this doesn’t automatically mount it will require mounting. In my examples below I will assume it is /dev/sdb1 and has been mounted as /media/USB.
- Locate the disk you want to copy in the /dev directory, in my examples the hard disk will be called hda yours maybe something similar.
- Using the command md5sum /dev/hda >/mount/USB/diskimage_md5hash.txt create a MD5 hash of the drive on the mounted USB device so you can test this against the copied file to verify the integrity.
- Run the following command:
dd if=/dev/hda of=/media/usb/diskimage.img
This will copy the disk as a file onto the USB storage device as diskimage.img.
- Create another md5 hash of the image on the storage device and compare to the original to verify the integrity of the copy.
The result of both of the examples above is a forensically sound image of the hard disk.
Advanced Usage of dd for Imaging
Whilst using the methods above you may come across issues. For example, if the PC cannot read some of the sectors of the drive you are copying, or if the file needs splitting to fit onto CD’s. Or if the image needs slitting to fit on a device that is FAT32 and requires files to be smaller than 2GB.
Copying an image from a disk with bad sectors
When imaging a drive that is starting to have some bad sectors the command below can be used.
dd if=/dev/hda of=/media/USB conv=noerror,sync
This will allow dd to proceed past read errors, and pad the destination with 0's where there were errors on the source drive (so your size and offsets will match). If you do this, you may want to consider redirecting standard-error out to a file, so you have a record of where your errors were.
Splitting images
This can be done using a couple of different methods.
The easiest method is by using the split program. The syntax for the command if you required a 4GB image to fit on CD’s would be:
dd if=/dev/hda | split –b 620m - /USB/sda/
This will run the input file (/dev/hda) through split and create several files of 620MB (-b 620m) in the directory /USB/sda/. The files will usually be called x** (* denotes a wildcard in this example)
These files can be reformed into an image file using the cat command.
Cat x* > bigimage.img
Then create a hash of the file using md5sum and compare to the original hash value.
Md5sum bigimage.img
Alternatively, if split is not available you can use dd by itself but use the skip, bs (block size) and count switches to prevent it from reading from the beginning of the file.
dd if=dev/hda of=/media/USB/image1.img bs=1M count=620
dd if=dev/hda of=/media/USB/image2.img bs=1M count=620 skip= 621
dd if=dev/hda of=/media/USB/image3.img bs=1M count=620 skip= 1241
dd if=dev/hda of=/media/USB/image4.img bs=1M count=620 skip= 1861
dd if=dev/hda of=/media/USB/image5.img bs=1M count=620 skip= 2481
etc………until the end of the input file.
What is happening here is you are telling dd to work in 1MB blocks (bs=1M), to only copy 620MB at a time (count=620) and in some cases to skip to a particular part of the input file (skip=621 etc…) thus creating several images that can then be copied to CD’s. Once on the target system and in the same directory (I will assume directory is /home/me) they can be put back together into a single image using the command below.
Cat /home/me/image* > bigimage.img
Md5sum can be run against this image and compared to the original md5 hash to verify the integrity.
Dd To a Zipped Image
You can pipe dd through gzip to save on some disk space.
dd if=/dev/hda | gzip -f > /media/USB/compressed_image.img.gz
Using Split & Gzip Together
To help cope with size limits both gzip and split can be used together. This has the benefit of splitting the image and zipping it up also to save space and requires less work. Below is the syntax used to perform this and an explanation of the command.
dd if=/dev/hda | gzip –c | split -b 2000m - /media/USB/image.img.gz.
- dd is used to take an image of the harddrive.
- This is passed to gzip (-c is to stdout)
- The compressed image is then piped to the split tool (split then creates the files image.img.gzaa, image.img.gzab, etc )
To restore the multi-file backup, run the command below:
cat /USB/image.img.gz* | gzip -dc | dd of=/dev/hda
- Cat displays the contents of the zipped and split image files to stdout in order.
- Results are piped through gzip and decompressed.
- And are then written to the hard drive with dd.
To create an empty disk image, get the data from /dev/zero. To create a 10MB image or file:
dd if=/dev/zero of=image bs=1M count=1024
Or
dd of=image bs=1M count=0 seek=1024
In the second example nothing is written, not even zeroes, we just seek 10MB into the file and close it. The result is a sparse file that is implicitly full of 10MB of zeroes, but that takes no disk space. ls -la will show 10MB, both du and df will show 0. When the file is written to, Linux will allocate disk space for the data. ls will continue to show 10MB, but du will gradually approach 10MB.
Notes:
Whilst researching the use of dd another tool was brought to my attention which is called dcfldd. This tool is like dd in many ways and uses similar syntax but is also able to produce hashes on the fly and can provide status of copying files amongst other useful features. It's available on both Linux and Windows.
Forensics - Volatile Data
-
Introduction
-
Preparing A Toolkit
-
Responding To An Incident
-
Removing Data From The PC
1. Introduction
In my work environment, when an incident occurs it's quite likely that upon discovery the first response will be to protect the network. Following that, to understand the incident and to perform a Root Cause Analysis (RCA) to discover the cause, implement safeguards to prevent further incidents of the same kind. Even though in most organisations legal action is not common it is beneficial to preserve as much evidence as possible, as until the incident is understood legal action cannot be ruled out.
The following blog entry describes the steps I perform to protect the network, whilst gathering the volatile data to help perform the RCA whilst preserving the data for further forensics if necessary. The guide below assumes that you have administrative control over the victim PC, network connectivity to a PC for the collection of data, network connectivity to a remote share or access to remote storage such as a USB device.
2. Preparing A Toolkit
To prevent any programs writing to the PC the following tools should be copied to a form of read-only media such as a CD-ROM or run from a read-only network share. Copying data to a comprimised PC may overwrite data on the victim PC and comprimise any legal procedings if they were to occur.
Command, Netstat, Psloglist, Netcat, Pslist, Netusers, Net (user, session), Pulist, ListDLLs, Handle, Tlist, Tasklist, PS, IPConfig, NBTStat, Fport, Openports, DOSKEY, GPList, Time, Date, Route
Many of the tools above collect similar information. However, they often have subtle differences and may provide information that the others lack. What is important is that tools come from good sources, so in the case of tools such as Command, Netstat and other Windows native tools this means taken from a fresh install of Windows. This is to prevent using tools that may be infected or that may have been altered. A disk with these tools on should always be kept safe and MD5Sums should be calculated and saved along with the tools. As important as this is familiarity of the tools. Become an expert at using them and learn there nuances. The switches with commands such as time /t are essential when piping commands to as listener.
To make the process of collecting volatile data easier it is useful to create a batch file to run the tools. Once the switches have been correctly identified and are entered into the batch file the command will be executed the same way each time, this will help save time and has the additional benefit of making the logging task slightly easier too.
3. Responding To An Incident
Firstly, the incident must be discovered. This may be through log monitoring, traffic analysis, alerts or just by stumbling across something that shouldn't be there such as a program, process or registry entry.
Once the incident has been discovered usually the first reaction is to pull the plug to protect the network. Although this does have the desired effect of isolating the PC from the network it also destroys critical volatile data. If the PC remains on and connected to the network this important data can be taken from the PC for further analysis. Also the system in question may be a critical business system that cannot be taken down without monitory loss.
4. Removing Data from the PC
After assembling the toolkit and testing the tools/batch files in a test environment you are ready to respond to an incident.
Data on the PC needs to be removed without altering the state of the PC as much as possible, as until the incident is understood it will not be known if any authorities are notified. This is done by using tools and scripts that can be run from the command-line and piped out to a netcat listener. This gets the volatile data off the PC so it can be disconnected from the network and powered down if necessary. If a listener is not available then every effort should be made to save the captured data on either a network share or some other form of removable media such as an attached USB drive, but be aware that connecting a USB device will write an entry to the registry so the make, model and serial no must be included in the log.
Log File
It is important that a log is kept of every action taken on the victim PC including the following:
- Time
- Tools Used (& versions)
- Commands Used
Setting up a listener
To capture the data across a network connection a netcat listener can be set up on a remote PC using the following command:
c:>nc -L -p 4455 > victimPC_date.log
This will capture any data sent to port 4455 and log it to a file called victimPC_date.log.
From The Victim PC
Log onto the victim PC and run the commands or the prepared batch file from your toolkit and pipe the results out to the netcat listener, the USB device or the network share.
Below are examples of the commands that can be run.
Running each of the commands individually would look something like below:
date /t | nc -w 1 IP_ADDRESS_OF_LISTENER 4455
time /t | nc -w 1 IP_ADDRESS_OF_LISTENER 4455
netstat -anovb | nc -w 1 IP_ADDRESS_OF_LISTENER 4455
fport | nc -w 1 IP_ADDRESS_OF_LISTENER 4455
........Thats quite a lot of work if you get the picture. If you was to create a batch file file with entries such as the following in you could just pipe the batch file out to the listener or to a log file on a share or USB.
The batch file could contain the following:
date /t
time /t
ifconfig /all
netstat -anovb
net session
net user
.................and many more from the toolkit can be added. One thing to note is to make sure none of the commands require user input to continue. For example, time if used without the /t switch will hang as will date. This reiterates the point of becoming familier with the tools and testing them before an incident.
Supposing the batch file is called Volatile.bat you could execute the following command:
volatile.bat | nc -w 2 IP_ADDRESS_OF_LISTENER 4455
Or if F: is the USB or network share:
volatile.bat > F:\>Victim_PC_Name.log
You then have the envious task of going through the logs to find the cause of the incident. Once the data has been lifted from the PC it can be disconnected from the network by disconnecting the network cable if necessary.
If you require further information of the collection of volatile data or any aspects of forensics then the following books are an excellent resources.
- Windows Forensics and Incident Recovery from Harlan Carvey.
- Incident Response by Kevin Mandia & Chris Prosise
A computer crime and forensics podcast can be found by googling CyberSpeak.







