Showing posts with label Network Monitoring. Show all posts
Showing posts with label Network Monitoring. Show all posts

Wednesday, January 1, 2014

30 Cool Open Source Software I Discovered in 2013

#1 Replicant - Fully free Android distribution

Replicant is entirely free and open source distributions of Android on several devices including both phones and tablets. I have installed it on an older Nexus S. You can install apps from F-Droid store a GPLv2 client app that comes configured with a repository hosting only free as in freedom applications.

#2: Miro video converter

This is an open source, cross-platform application to convert videos from and to various formats, including formats suitable for devices such as Android/iOS phones. It is simple and easy to use software to convert almost any video to MP4, WebM (vp8), Ogg Theoraformat. Miro Video Converter is based on FFMPEG and act as a front end to FFMPEG command line tools.

#3 OwnCloud - Dropbox alternative for cloud storage service

I was looking for an alternative to Dropbox to run cloud on my own server at home and office. This software is open source software, and it is self hosted. I don't have to trust third party with my data. I found this software easy to install and quite useful. I started to use it for syncing files and other data. I have been using for couple of months and it has been proven reliable alternative to Dropbox. There are clients available for MS-Windows, OS X, Linux, and mobile apps for iOS and Android devices (or simply access data using the ownCloud web frontend).

#4 Docker - FreeBSD like container+API for Linux

The FreeBSD jail provides an operating system-level virtualization partition a FreeBSD-based serve into several independent mini-systems. You can do the same with Linux using OpenVZ. Linux Containers (LXC) is a virtualization method for running multiple isolated Linux systems. Docker extends LXC. It uses LXC, cgroups, Linux kernel and other parts to automate the deployment of applications inside software containers. It comes with API to runs processes in isolation. With docker I can pack WordPress (or any other app written in Python/Ruby/Php & friends) and its dependencies in a lightweight, portable, self-sufficient container. I can deploy and test such container on any Linux based server.

#5 Adminer - A lightweight and full-featured database management tool

Adminer is a full-featured database management tool written in PHP. Conversely to phpMyAdmin, it consists of a single file ready to deploy to the target server. Adminer is available for MySQL, PostgreSQL, SQLite, MS SQL and Oracle. I usually install this for clients who are new to PostgreSQL/MySQL. The software acts as a drop-in-replacement for phpMyAdmin with a better user interface, better support for MySQL features, higher performance and more security.

#6 MariaDB - Drop-in replacement for Oracle MySQL server

MariaDB is a community-developed fork of the MySQL server. MariaDB is going to be default in many popular Linux distro and open source project. Red Hat will switch the default database in its enterprise distribution, RHEL (including its clones such as CentOS), from MySQL to MariaDB, when version 7 is released in 2014. I started testing MariaDB and found no problems at all. The speed is same or better in some cases.

#7 RackTables - Manage your data center assets like a pro

I wish I discovered RackTables earlier. It is is a datacenter asset management system. With this software one can document hardware assets (such as server, workstations, routers, switches and more), network addresses, space in racks, networks configuration and more:
  1. List of all devices, racks, and enclosures you've got
  2. Mount the devices into the racks
  3. Maintain physical ports of the devices and links between them
  4. Manage IP addresses, assign them to the devices and group them into networks
  5. Document your NAT rules, describe your loadbalancing policy and store loadbalancing configuration
  6. Attach files to various objects in the system
  7. Create users, assign permissions and allow or deny any actions they can do

#8 Apache Cordova - Create smartphone app just with HTML, CSS, and JavaScript

Apache Cordova is a free and open source framework that allows you to create mobile apps using standardized web APIs. You can create apps that work on iOS, Andriod, BlackBerry, Windows, Ubuntu and other phone based operating systems. You write code once and run on selected mobile platforms with little or no change at all. PhoneGap uses Apache Cordova.

#9 Angry IP scanner - ipscan tool

Nmap is an open source security tool for network exploration, security scanning and auditing. ipscan (Angry IP Scanner) is an alternative to nmap command. It is also an open-source and cross-platform network scanner designed to be fast and simple to use. It scans IP addresses and ports as well as has many other features.

#10 Jekyll - Create simple static blog

Drupal, Typo3, WordPress and many other content management system (CMS)/blogging software dynamically create feature rich content. However, you may not need all the all features and complexity offered by modern CMS based systems. For example, a WordPress based blog like nixCraft requires multiple VMs, CDN for static assets, caching engine such as memcached, PHP, mysql database, comment moderation, and on going updates. A growing trend is to keep your blog simple by avoiding CMS and use static HTML generators that offers the following benefits:
  • No more complex setups i.e. no databases/php/caching engines required.
  • No more comment moderation.
  • Pesky updates.
  • Static files are more secure.
  • Easy to scale or cache on edge/CDN nodes.
  • Provides all the blog-aware visual bells and whistles such as categories, pages, posts, Permalinks, and custom layouts.

#11 TurnKey Linux - Deploy open source apps on VM or the clouds

You can setup a open source software such as WordPress, Drupal, ZenCart, and over 100+ other software easily with TurnKey Linux. It is a virtual appliance library that integrates and polishes the very best open source software into ready to use solutions. Each virtual appliance is optimized for ease of use and can be deployed in just a few minutes on bare metal, a virtual machine and in the cloud/in physical server. TurnKey Linux is based on Debian 7.2 with automatic security updates for all packages. It also includes a web management interface, web shell, and simple configuration console. I often use this to deploy development server in the cloud.

#12 DokuWiki - Create a personal wiki

DokuWiki is a simple to use and highly versatile open source wiki software that doesn't require a database. Easy to install on Linux or Unix-like operating systems with the following features:
  1. Ease of use and low system requirements.
  2. Built-in access control lists.
  3. Customization using large variety of extensions, plugins, and templates.
I use this on my laptop to keep notes about various projects.

#13 MediaGoblin - An alterative to Youtube/Flickr/Soundcloud

GNU MediaGoblin is free software, decentralized media publishing platform. You can host and share videos, music, and images using MediaGoblin. It is an alternative to major media-publishing services such as Flickr, deviantArt, YouTube, Soundcloud, etc. It is written in Python and SQL.

#14: Scrollout F1 - Create email firewall gateway

Scrollout F1 is easy to use and setup email firewall gateway system. It includes anti-spam and anti-virus protection for Microsoft Exchange, Postfix, Exim, Sendmail, Qmail and others. It runs on Debian and Ubuntu Linux operating systems. This is perfect software for filtering incoming messages and other features are as follows:
  1. TLS/SSL encryption with Perfect Forward Secrecy for SMTP & HTTPS
  2. Virus scanning and different Quarantine per domain
  3. Tagging and blocking SPAM at domain level
  4. Geographic filtering for Sender IP, Server IP, URL IP and TLDs
  5. Verifies incoming emails for DKIM and signs outgoing emails (2048 bits RSA)
  6. Protection against fake messages that appear to come from your domain or from yourself
  7. Protection against executable files, malicious content, scripts and more
  8. Protection against forged domains like (fake) yahoo.com, gmail.com etc.
  9. Whitelist and Blacklist
  10. Simple web interface for management

#15 Observium - Network observation and monitoring system

Observium is free and open source software written in PHP/MySQL. It collects data from devices using SNMP and presents it via a web interface. It includes support for a wide range of network hardware and operating systems including Cisco, Windows, Linux, HP, Dell, FreeBSD, Juniper, Brocade, Netscaler, NetApp and many more. I use this software along with Nagiosto get better understanding of certain devices and technologies. It provides historical and current performance statistics, configuration visualization and syslog capture.

#16 SimpleInvoices

It is a web based invoicing system. It helps me to create quick and nice looking invoices without having to set up too much services on server. All you have to do is install the SimpleInvoices software, enter a biller, a customer details and go creating invoices. You can easily track your finances; send invoices as PDF's and more. It is the best invoicing set up for my independent IT consultancy business.

#17 FileZilla - sftp/ftp client for noobs

This is a perfect open-source FTP, FTP over SSL/TLS (FTPS) and SSH File Transfer Protocol (SFTP) client for Windows, Mac OS X and GNU/Linux. It has the following features that new users might find useful:
  1. Drag & drop support
  2. Tabbed user interface
  3. File transfer queue and bookmarks
  4. Remote file editing and remote file search
  5. SOCKS5 and FTP-Proxy support

#18 WinSCP - Easily transfer file using scp

It is an open source free SFTP client and FTP client for Windows. Its main function is the secure file transfer between local and server under your control. Most new MS-Windows user find WinSCP an easier to use as compare to putty and friends.

#19 XAMPP - Easily write and test Apache+MySQL+PHP/Perl apps on desktop

I give this software to many developers. They can easily setup Apache, MySQL, PHP/Perl to deploy and write an application on their own desktop. No need to install virtual machine and Linux server. Just focus on development and skip real server management job to pros.

#20 Abiword - A nice little word processor

Many users only use 2% of the features of a program like Microsoft Word. No need to spend money or time on Microsoft Word. I personally use Abiword due to:
  1. Easy to use and not bloated as OO.org.
  2. Small size word processor i.e. it loads very fast on my old computer.
  3. I can read and write OpenOffice.org documents, Microsoft Word documents, WordPerfect documents, Rich Text Format documents, HTML web pages and more.
  4. Abiword is tightly integrated with the AbiCollab.net web service, which lets you store documents online, allows easy document sharing with your friends, and performs format conversions on the fly.

#21 {less}: The dynamic stylesheet language

LESS extends CSS with dynamic behavior such as variables, mixins, operations and functions. LESS can run on the client-side and server-side or can be compiled into plain CSS.

#22 Cinnamon

Cinnamon is a GTK+ based desktop environment and a fork of the GNOME Shell. It was initially developed by Linux Mint. It offers a user interface with the following features that I needed most:
  1. A movable panel equipped with a main menu, launchers, a window list and the system tray
  2. Various extensions and applets
  3. Cinnamon makes GNOME3 a useful desktop

#23 Tmux

Tmux is terminal multiplexers for Unix-like platforms. tmux offers several advantages over GNU/screen:
  1. Vi or emacs key layouts
  2. Multiple paste options
  3. Secure code base
  4. An option to limit the window size and more.

#24 Artica - Full SMTP/Mail/Proxy server Appliance in 10 minutes

It is a simple and straightforward software that offers the following features:
  1. Proxy server Appliance
  2. SMTP server Appliances
  3. Mail server Appliances
  4. NAS server Appliance
  5. Web based management

#25 Zentyal small business server

Zentyal is a full-featured Linux server for small and medium businesses that you can set up in less than 30 minutes. It is a drop-in replacement for Microsoft Small Business Server and Microsoft Exchange Server. It is easy to use software. Zentyal is based on Ubuntu and it can be installed either from Ubuntu repositories or from Zentyal's own installer.

#26 Ack-grep - a source code search tool for programmers

ack-grep is a grep like tool, optimized for programmers. This tool isn't aimed to "search all text files". It is specifically created to search source code trees, not trees of text files. It searches entire trees by default while ignoring Subversion, Git and other VCS directories and other files that aren't your source code.

#27 ditaa - DIagrams Through Ascii Art

ditaa is a small command-line utility, that can convert diagrams drawn using ascii art, into proper bitmap graphics. I use this tool all the time to draw diagrams and forwarding them via email or chat session.

#28 GNU parallel

GNU parallel is a shell tool for executing jobs in parallel using one or more computers. If you like xargs command, try GNU/parallel utility. It can run command/script/job on all available CPU's or on multiple computers.

#29 luckyBackup data back-up and synchronization tool

luckyBackup is an application for data back-up and synchronization powered by the rsync tool. It is simple to use, fast, safe, reliable and fully customizable backup software. I often set and recommend this too for new Ubuntu/Fedora desktop users to backup their own files.

#30 OpenShot video editor

OpenShot Video Editor is a free and open-source non-linear video editing software package for Linux. I use this tool to create videos for my youtube channel. It is a stable, free, and friendly to use video editor on Linux.

Saturday, May 14, 2011

Hping Examples


1. Testing ICMP: In this example hping3 will behave like a normal ping utility, sending ICMP-echo und receiving ICMP-reply
hping3 -1 0daysecurity.com
2. Traceroute using ICMP: This example is similar to famous utilities like tracert (windows) or traceroute (linux) who uses ICMP packets increasing every time in 1 its TTL value.
hping3 --traceroute -V -1 0daysecurity.com
3. Checking port: Here hping3 will send a Syn packet to a specified port (80 in our example). We can control also from which local port will start the scan (5050).
hping3 -V -S -p 80 -s 5050 0daysecurity.com
4. Traceroute to a determined port: A nice feature from Hping3 is that you can do a traceroute to a specified port watching where your packet is blocked. It can just be done by adding --traceroute to the last command.
hping3 --traceroute -V -S -p 80 -s 5050 0daysecurity.com
5. Other types of ICMP: This example sends a ICMP address mask request ( Type 17 ).
hping3 -c 1 -V -1 -C 17 0daysecurity.com
6. Other types of Port Scanning: First type we will try is the FIN scan. In a TCP connection the FIN flag is used to start the connection closing routine. If we do not receive a reply, that means the port is open. Normally firewalls send a RST+ACK packet back to signal that the port is closed..
hping3 -c 1 -V -p 80 -s 5050 -F 0daysecurity.com
7. Ack Scan: This scan can be used to see if a host is alive (when Ping is blocked for example). This should send a RST response back if the port is open.
hping3 -c 1 -V -p 80 -s 5050 -A 0daysecurity.com
8. Xmas Scan: This scan sets the sequence number to zero and set the URG + PSH + FIN flags in the packet. If the target device's TCP port is closed, the target device sends a TCP RST packet in reply. If the target device's TCP port is open, the target discards the TCP Xmas scan, sending no reply.
hping3 -c 1 -V -p 80 -s 5050 -M 0 -UPF 0daysecurity.com
9. Null Scan: This scan sets the sequence number to zero and have no flags set in the packet. If the target device's TCP port is closed, the target device sends a TCP RST packet in reply. If the target device's TCP port is open, the target discards the TCP NULL scan, sending no reply.
hping3 -c 1 -V -p 80 -s 5050 -Y 0daysecurity.com
10. Smurf Attack: This is a type of denial-of-service attack that floods a target system via spoofed broadcast ping messages.
hping3 -1 --flood -a VICTIM_IP BROADCAST_ADDRESS
11. DOS Land Attack:
hping3 -V -c 1000000 -d 120 -S -w 64 -p 445 -s 445 --flood --rand-source VICTIM_IP
  • --flood: sent packets as fast as possible. Don't show replies.
  • --rand-dest: random destionation address mode. see the man.
  • -V <-- Verbose
  • -c --count: packet count
  • -d --data: data size
  • -S --syn: set SYN flag
  • -w --win: winsize (default 64)
  • -p --destport [+][+] destination port(default 0) ctrl+z inc/dec
  • -s --baseport: base source port (default random)

Anex A Hping3 Help

usage: hping3 host [options]
-h --help show this help
-v --version show version
-c --count packet count
-i --interval wait (uX for X microseconds, for example -i u1000)
--fast alias for -i u10000 (10 packets for second)
--faster alias for -i u1000 (100 packets for second)
--flood sent packets as fast as possible. Don't show replies.
-n --numeric numeric output
-q --quiet quiet
-I --interface interface name (otherwise default routing interface)
-V --verbose verbose mode
-D --debug debugging info
-z --bind bind ctrl+z to ttl (default to dst port)
-Z --unbind unbind ctrl+z
--beep beep for every matching packet received
Mode
default mode TCP
-0 --rawip RAW IP mode
-1 --icmp ICMP mode
-2 --udp UDP mode
-8 --scan SCAN mode.
Example: hping --scan 1-30,70-90 -S www.target.host
-9 --listen listen mode
IP
-a --spoof spoof source address
--rand-dest random destionation address mode. see the man.
--rand-source random source address mode. see the man.
-t --ttl ttl (default 64)
-N --id id (default random)
-W --winid use win* id byte ordering
-r --rel relativize id field (to estimate host traffic)
-f --frag split packets in more frag. (may pass weak acl)
-x --morefrag set more fragments flag
-y --dontfrag set dont fragment flag
-g --fragoff set the fragment offset
-m --mtu set virtual mtu, implies --frag if packet size > mtu
-o --tos type of service (default 0x00), try --tos help
-G --rroute includes RECORD_ROUTE option and display the route buffer
--lsrr loose source routing and record route
--ssrr strict source routing and record route
-H --ipproto set the IP protocol field, only in RAW IP mode

ICMP
-C --icmptype icmp type (default echo request)
-K --icmpcode icmp code (default 0)
--force-icmp send all icmp types (default send only supported types)
--icmp-gw set gateway address for ICMP redirect (default 0.0.0.0)
--icmp-ts Alias for --icmp --icmptype 13 (ICMP timestamp)
--icmp-addr Alias for --icmp --icmptype 17 (ICMP address subnet mask)
--icmp-help display help for others icmp options

UDP/TCP
-s --baseport base source port (default random)
-p --destport [+][+] destination port(default 0) ctrl+z inc/dec
-k --keep keep still source port
-w --win winsize (default 64)
-O --tcpoff set fake tcp data offset (instead of tcphdrlen / 4)
-Q --seqnum shows only tcp sequence number
-b --badcksum (try to) send packets with a bad IP checksum many systems will fix the IP checksum sending the packet so you'll get bad UDP/TCP checksum instead.
-M --setseq set TCP sequence number
-L --setack set TCP ack
-F --fin set FIN flag
-S --syn set SYN flag
-R --rst set RST flag
-P --push set PUSH flag
-A --ack set ACK flag
-U --urg set URG flag
-X --xmas set X unused flag (0x40)
-Y --ymas set Y unused flag (0x80)
--tcpexitcode use last tcp->th_flags as exit code
--tcp-timestamp enable the TCP timestamp option to guess the HZ/uptime

Common
-d --data data size (default is 0)
-E --file data from file
-e --sign add 'signature'
-j --dump dump packets in hex
-J --print dump printable characters
-B --safe enable 'safe' protocol
-u --end tell you when --file reached EOF and prevent rewind
-T --traceroute traceroute mode (implies --bind and --ttl 1)
--tr-stop Exit when receive the first not ICMP in traceroute mode
--tr-keep-ttl Keep the source TTL fixed, useful to monitor just one hop
--tr-no-rtt Don't calculate/show RTT information in traceroute mode

ARS packet description (new, unstable)
--apd-send Send the packet described with APD (see docs/APD.txt)

Tuesday, April 26, 2011

Which ports is my Linux computer / Server listening to?

Introduction

Security, always a concern in these days, yes, it may be your house, your car even yourself, we are all in danger, and so are our servers and computers.

Well, to protect you Linux computer you can take a lot of actions, and one of them is to know which ports is your Linux listening to, this way if some of them are not needed you can shut the service down.

Which ports is my Linux listening to?

We’ll use netstat to find out which ports is our computer listening to.

netstat -t --listening
The output could look like this:

Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State
tcp 0 0 *:x11 *:* LISTEN
tcp 0 0 *:ssh *:* LISTEN
tcp 0 0 *:ipp *:* LISTEN
tcp 0 0 *:microsoft-ds *:* LISTEN
tcp 0 0 *:netbios-ssn *:* LISTEN
tcp 0 0 *:x11 *:* LISTEN
tcp 0 0 *:ipp *:* LISTEN
That is the example of my office computer, your output may change, and if it is a public server, you should have a lot less ports opened.

Find alive hosts in a network with ICMP nmap

Introduction

If you want to know which servers or hosts are alive and responding to ping in your local network, you can use nmap

Using nmap to discover ‘alive’ machines on a Network

To use this command and get an effective response, the servers or hosts you are pinging need to respond to it, today a lot of hosts by default have a firewall, and will not respond to pings, so be aware of that.

The command is:

nmap -sP 10.1.1.*
This will have a response like this:

Nmap scan report for 10.1.1.1
Host is up (0.0060s latency).
Nmap scan report for 10.1.1.192
Host is up (0.0023s latency).
Nmap scan report for 10.1.1.193
Host is up (0.061s latency).
Nmap scan report for 10.1.1.198
Host is up (0.0046s latency).
Nmap scan report for 10.1.1.200
Host is up (0.0044s latency).
Nmap scan report for 10.1.1.254
Host is up (0.030s latency).
Nmap done: 256 IP addresses (6 hosts up) scanned in 2.94 seconds
Those are the machines on, in a holy day at my office.

Saturday, August 7, 2010

NTOP Configuration


Like the command-line tool with a similar name, ntop is a monitoring agent. Instead of monitoring system resource usage like top, ntop monitors network usage and provides some very sophisticated and informative data.
Ntop, available at http://www.ntop.org/, can be downloaded and compiled from source or installed via your Linux vendor’s package repositories if available. The ntop Web site also provides Debian and RPM package formats that can be downloaded and installed.
Once ntop is installed, you must provide an administrative password on the first run, so instead of executing an initscript, run ntop directly:
# ntop -A
This will start ntop, ask you for the administrative password to use, and then exit. Once that is done, you can start ntop and begin monitoring network traffic.
A very basic invocation of ntop would be:
# ntop -P /var/lib/ntop
This will start ntop and write the database files to the directory /var/lib/ntop. Ntop needs to start as root, but it supports dropping privileges to an unprivileged user. Instead of running ntop as root all the time, run it as a dedicated user. To create the user ntop, execute:
# groupadd ntop
# useradd -M -s /bin/false -d /var/lib/ntop -c "ntop user" -g ntop ntop
These two commands will create the user and group for ntop. Finally, start ntop and tell it to drop privileges to the ntop user:
# ntop -P /var/lib/ntop -u ntop
This starts ntop and leaves it attached to the terminal; using ntop this way is great if you need to quickly visualize network traffic (perhaps to determine where a bottleneck is or to aid in network troubleshooting). Running ntop on a firewall or gateway device is best as it can watch all traffic; if you use Linux for a custom firewall, install ntop there to get the best data. Otherwise, ntop can watch traffic coming to and from the system it is installed on, which may be useful to determine what programs are opening connections, for example, from that system.
To view ntop statistics, connect to port 3000 on the system on which ntop is installed with a Web browser. You can configure the port and decide whether to use HTTPS instead of HTTP by adjusting the command-line options. For instance, to have ntop listen to port 4000 and only accept HTTPS traffic, use ntop -w 0 -W 4000. To have it listen on port 3000 for HTTP traffic and port 4000 for HTTPS traffic, use ntop -w 3000 -W 4000.
To have ntop start at boot and constantly watch traffic, add the following to/etc/init.d/rc.local or a similar script that is started at boot:
ntop -P /var/lib/ntop -u ntop -d
Specifying the -d option tells ntop to daemonize and fork to the background.
Ntop is a great analytical tool that can be extremely useful for seeing what is happening on the network in real-time. By design, ntop can consume a lot of memory, so if there is no need to run it constantly, it’s probably best to leave it as part of the troubleshooting arsenal and invoke it when necessary.

Wednesday, April 7, 2010

Firewall Identification & Traceroute,Firewalking,Hpinging,ICMP,NMAPing


Introduction:
Application gateways and Packet filtering gateways are two types of firewalls basically available in market. Application gateways are those proxies and they are causing some computational problems in computers due to heavy CPU usage, therefore on busy networks Packet filtering devices are more preferable. However, the vendors are trying to embed these two inevitable characteristics of firewall into one.
Installing a firewall into a gateway is not a security panacea. Those who attended BlackHat (www.blackhat.com) conference this July in Las Vegas still remember the presentations about FW-1 penetration. Security vulnerabilities are discovered every year with just about every firewall in the market. However, the worst thing might be the misconfigured, unattended and unmaintained ones. Is this laziness? Who knows, but it helps hackers.
There are many tools out there to test the security of our applications. However penetrating into computer networks are sometimes bottleneck because of firewalls.
As those skilled hackers, we need some methodologies to intrude into systems in our pen-tests. I will basically try to cover the methods used widely at wild. We need to understand the ACLs(access control lists) of a firewall or a router, we need to map what is behind the firewall, we wanna know what is allowed in and so on.
As one of our main aim is not to trigger intrusion detection software, we don’t wanna deploy full connection (3-way handshake)port scanning. Because, port scanner’s triggers this systems easily because of the enormous amount of SYN/ACK packets sent back and forth to every port of the firewall just to check them. Therefore, we don’t like noisy staff in our pen-tests.
Moreover, we should know that, most of the firewalls do not respond to ICMP echo requests (ping), as long as it is configured with an expert firewall administrator.



==================================================
Firewall Identification & Traceroute:
Traceroute is a network debugging utility, which attempts to map all the hosts on a route to a certain destination host/machine. It sends UDP datagrams by default or ICMP ECHO Request packets with TTL (time to live) fields set to 1 just before reaching the final target. Once the target reached, as TTL field gets zero, the target will discard the datagram and generate an ICMP Time Exceeded packet back to its originator. By the way, Windows systems use ICMP ECHO Request by default and you can not use UDP method with Microsoft’s traceroute implementation, "tracert".
Lets assume that a network is protected by a access control device, a firewall or some sort, and it denies everything in but dns traffic. A regular traceroute will be as follows:
[willyhacker]#traceroute 10.10.0.10
traceroute to 10.10.0.10 (10.10.0.10), 30 hops max, 40 byte packets
1 10.10.0.2 (10.10.0.2) 0.540 ms 0.394 ms 0.397 ms
2 10.10.0.4 (10.10.0.4) 2.455 ms 2.479 ms 2.512 ms
3 10.10.0.6 (10.10.0.6) 4.812 ms 4.780 ms 4.747 ms
4 * * *
5 * * *
As you see from the preceding example, we can not go beyond 10.10.0.6 which most probably means that there is a blocking device at hop 4. To understand this we have to dig a little deeper.
When traceroute is deployed with default UDP datagram option, it will increase the port number at every time it send a UDP datagram. Hence, we need a equation which will give the starting port number to reach to final target. So the starting port number is
(Target port – (number of hops * number of probes)) -1
where number of hops is from our probing box to the firewall, and number of probes is by default 3.
Knowing this, know lets look at our tracerouting
[willyhacker]#traceroute –p43 10.10.0.10
traceroute to 10.10.0.10 (10.10.0.10), 30 hops max, 40 byte packets
1 10.10.0.2 (10.10.0.2) 0.540 ms 0.394 ms 0.397 ms
2 10.10.0.4 (10.10.0.4) 2.455 ms 2.479 ms 2.512 ms
3 10.10.0.6 (10.10.0.6) 4.812 ms 4.780 ms 4.747 ms
4 10.10.0.8 (10.10.0.8) 4.972 ms 4.980 ms 6.361 ms
5 * * *
BOOM !, we penetrated in to firewall, which is 10.10.0.8 and get into the network which is most probably a DMZ. However we could not get a reply from 10.10.0.10. The reason is basic, we did not hit to UDP port 53 of this box. As traceroute has incremented our port number again and it has got stuck to ACL on the firewall.
Don’t worry, Mike Shiffman (the author of famous firewalk), has a remedy for that. With his modified version of traceroute, traceroute 1.4a5 you can grab it from (www.packetfactory.net)
[willyhacker]#traceroute –S –p53 10.10.0.10
traceroute to 10.10.0.10 (10.10.0.10), 30 hops max, 40 byte packets
1 10.10.0.2 (10.10.0.2) 0.540 ms 0.394 ms 0.397 ms
2 10.10.0.4 (10.10.0.4) 2.455 ms 2.479 ms 2.512 ms
3 10.10.0.6 (10.10.0.6) 4.812 ms 4.780 ms 4.747 ms
4 10.10.0.8 (10.10.0.8) 4.972 ms 4.980 ms 6.361 ms
5 10.10.0.10 (10.10.0.10) 6.1022 ms 5.660 ms 8.531 ms
boom, there we go.. So, what we know is that, we know the IP address and an ACL of firewall (allow TCP/UDP port53 in), a box behind the firewall. This juicy information can help us for further penetration in our tests.
As a result, to test other open ports we can try other ports, with a home grown script, it can be done systematically.
============================================================
Firewalking:
Firewalk is just another utility written by Mike Schiffman, and can also be found at www.packetfactory.net. The aim of this little handy tool is to find open ports on a filtering device, Firewall. It works by checking a live system behind a firewall, without touching this system to discover which services are permitted, which ports are open on that firewall.
A second potential advantage of firewalk is mapping the unknown network behind the filtering device. By sending packets to every host behind the firewall, an attacker can generate accurate topology of the network behind the firewall.
The firewalk scan works by sending out TCP or UDP packets with an IP TTL evaluated to expire just one hop past the firewall. If the filtering device allows the traffic in, then it will send the packets to target where the TTL will get zero and the target will elicit a TTL exceeded on transit back to attacker. If the filtering device does not allow the traffic in, then we will not see any packet back which means the port is closed.

[willyhacker]#firewalk -n –P135-140 –pTCP 10.10.0.5 10.10.0.20
Firewalking through 10.10.0.5 (towards 10.10.0.20) with a maximum of 25 hops.
Ramping up hopcounts to binding host...
probe: 1 TTL: 1 port 33434: [10.10.0.4]
probe: 2 TTL: 2 port 33434: [10.10.0.6]
probe: 3 TTL: 3 port 33434: [10.10.0.8]
probe: 4 TTL: 4 port 33434: [10.10.0.10]
probe: 5 TTL: 5 port 33434: Bound scan: 5 hops [10.10.0.10]
port 135: open
port 136: *
port 137: open
port 138: *
port 139: open
port 140: *
However, what we see on our tests is that, some firewalls recognize that the packet will expire when they get to the target host before applying ACL rules. And they elicit an ICMP TTL Expired packet back to attacker and this leads to false-positives.
To learn more about firewalk, you can check the following URL www.es2.net/research/firewalk

==================================================
Hpinging:
This tools is basically a TCP ping utility, however it has some additional functionality. You may grab it from www.kyuzz.org/antirez It allows user to play with some options of the TCP packet which may let it pass through some filtering devices even if they are blocked, and reports the packets it gets back. . By using the –p switch, we can set a fixed destination port, as in the case of traceroute and pass through the firewall. We can even fragment TCP packets as well, but it is basically a TCP ping sweeping utility.
[willyhacker]# hping 10.10.0.10 –S –p 53 –f
60 bytes from 10.10.0.10. flags=SA seq=0 ttl=124 id=17051 win=0 time 45.3
60 bytes from 10.10.0.10. flags=SA seq=1 ttl=124 id=19551 win=0 time 134.9
as you see whenever a port is open (TCP 53/DNS), we receive back SYN/ACK flags set packets.
Moreover, sometimes the filtering devices can not handle fragmented packets and let them in, thus we can map the network behind the filtering device.
==================================================
Stateless Firewalls & Source Port Scanning:
This method can apply to those filtering devices which does not keep the state of traffic. Namely, it wont work against stateful filtering devices. So what is the idea, basically think of such a device which will never remember if the connection has begun from inside or outside. Boom! I see your sparkling eyes. Right, FTP, or yes, DNS. Anyothers? Several… If we send a packet with the source port 20 in FTP, which is the default DATA port, we can check the system behind the firewall and map the network behind the firewall.
For this, we will use nmap, we will discover its features for other methods later on this paper. The –g switch of nmap will let us do that.
[willyhacker]# nmap –sS –P0 –g 20 –p 139 10.10.0.10
as you see, we use the SYN scan (-sS) without pinging (-P0) the target system.
If it comes out that the port is open, then it has two significant meanings, one the system probed is alive behind the firewall, which is good for network mapping, and second, FW ACL does not block TCP 139 port, which is a good starting point for hacking Windows based systems.
The authors of Hacking Exposed have also mentioned this method in their second edition and they got a very handy tool for utilizing this method to get into system, fpipe, you may grab it from www.foundstone.com This utility is a modified port redirector and you can set the source port to 20 with the help of it.

============================================================
ICMP Enumerating with icmpenum:
Ping is maybe the most known ICMP packet ICMP ECHO REQUEST (type 8) and the reply is ICMP ECHO REPLY (type 0). Therefore most firewall admins blocks incoming pings, however they do not care about other types of ICMP packets, which can be handy for gathering juicy information from the target.
To do use the other options of ICMP, our favorite tool is icmpenum from Simple Nomad. You may grab it from his personal site www.nmrc.org
Rather than ICMP ECHO packets, we may send ICMP TIME STAMP REQUEST and ICMP INFO packets to the system. Furthermore, it supports spoofing and promiscuous listening for reply packets. Icmpenum is great for enumerating networks who block ICMP Echo packets but have failed to block Timestamp or Information packet, or for upstream sniffing of trusted addresses.
[willyhacker]#icmpenum –I 2 –v 10.10.0.0
10.10.0.2 is up
10.10.0.4 is up
10.10.0.6 is up
10.10.0.8 is up
10.10.0.10 is up
in this preceding example, we have enumerated all alive hosts by sending ICMP TIME STAMP requests in the 10.10.0.0 network.
As we have mentioned earlier, it can spoof packets with –s switch and can listen in promiscuous mode with –p option.
[willyhacker]#icmpenum –I 3 –s 10.10.0.50 –p –v 10.10.0.10
In this example, we have spoofed the IP address 10.10.0.50 with –s switch and we get to promiscuous mode with –p option with ICMP INFO packets.
To summarize, this tool allows us to determine alive hosts behind the filtering devices with the help of ICMP types ECHO, INFO, TIME STAMP REQUEST. In many of pen-tests, I deploy this little and handy utility for checking the alive hosts behind the firewall and it works most of the time.
==================================================
Playing with the ICMP Packages:
The folk Ofir Arkin, has released a whitepaper about the hazards of ICMP and its usage about operating system guessing and filtering device testing. I strongly suggest you guys to take a check his study. This part of our study heavily depends on his study and findings. I have tested his findings in a laboratory and used some ideas in my pen-tests. I found them especially handy in network topology mapping and in ACL discovery. You can find his detailed document from www.blackhat.com, he has given a speech this year at BlackHat Europe.
We can use various methods to elicit an ICMP error message back from a probed host and discover its existence. Some of the methods are as follows:
• Mangling IP headers
o Header Length Field
o IP Options Field
• Using non-valid field values in the IP header
o Using valid field values in the IP header
• Abusing Fragmentation
• The UDP Scan Host Detection method
With the first method we are using bad IP headers in the IP datagram that would generate an ICMP Parameter Problem error back from the probed machine to the source IP address of the probing datagram. The second method use non-valid field values in the IP header in order to force the probed machine to generate ICMP Destination Unreachable error message back to the malicious computer attacker. The third method discussed uses fragmentation to trigger an ICMP Fragment Reassembly Time Exceeded error message from the probed machine. The last method uses the UDP Scan method to elicit ICMP Port Unreachable error message back from a closed UDP port(s) on the probed host(s).
The tool we will be using for playing with the ICMP packages is called ISIC written by Mark Frantzen. You can grab it from
the user can specify how often the packets will be fragmented, have IP options, TCP options and etc.
In the next example I have sent 20 IP Packets from a LINUX machine to a Microsoft Windows NT WRKS 4 SP4 machine. The datagrams were not fragmented nor bad IP version numbers were sent. The only weird thing sent inside the IP headers was random IP Header length, which have produced ICMP Parameter Problem Code 2 error message as I anticipated.
[root@stan packetshaping]# ./isic -s 192.168.5.5 -d 192.168.5.15 -p 20
-F 0 -V 0 -I 100
Compiled against Libnet 1.0
Installing Signal Handlers.
Seeding with 2015
No Maximum traffic limiter
Bad IP Version = 0% Odd IP Header Length = 100%
Frag'd Pcnt = 0%
Wrote 20 packets in 0.03s @ 637.94 pkts/s
tcpdump trace:
12:11:05.843480 eth0 > kenny.sys-security.com > cartman.sys-security.
com: ip-proto-110 226 [tos 0xe6,ECT] (ttl 110, id 119,
optlen=24[|ip])
12:11:05.843961 eth0 P cartman.sys-security.com > kenny.sys-security.
com: icmp: parameter problem - octet 21 Offending pkt:
kenny.sys-security.com > cartman.sys-security.com: ip-proto-110 226
[tos 0xe6,ECT] (ttl 110, id 119, optlen=24[|ip]) (ttl 128, id 37776)
If we probe the entire IP range of the targeted network with all combinations of protocols and ports, it would draw us the targeted network topology map, and will allow us to determine the access list (ACL) a Filtering Device (If present, and not blocking outgoing ICMP Parameter Problem Error messages) is forcing.
Moreover, if you wanna play with the low-level row TCP/IP packages in order to test your systems, firewalls and filtering devices, I do suggest using CASL (custom auditing and scripting language). Cybercop from NAI, www.nai.com has a unique feature which allow us to play with the low-level packets in a GUI interface. We can create any choice of our packets as scripts and run them against the firewalls or whatever system we want. By combinig this tool to the findings of Ofir arkin, we can get the idea what is happening on the victim site and determine the ACL and map the network topology. By the way, don’t forget to run your choice of sniffer on your attacking box to review the packets elicited from the target.


==================================================
NMAPing: (network mapping)
I must mention about the nmap, which you can get from www.insecure.org/nmap and it is such a wonderful tool, you cant do without it. It has many different switches, which eases our jobs from many different perspectives. Until recently this tool was mainly a UNIX tool, however the folks at eEye (www.eeye.com) has released an NT version which performs the same functions as in the UNIX version.
Albeit, it is basically a port scanner, its features let us do some quiet scanning for port probes. Yet, I should mention that, there are some intrusion detection SW out there capable of catching nmap scans.
As I mentioned, most of the firewalls do not respond to ICMP echo requests (ping), thus we will use the –P0 switch which disables ICMP pinging. –sS switch will perform a TCP SYN stealth scanning and so on. To get all the features of nmap type
[wilyhacker]# nmap –h
from your box.
A filtered port in nmap signifies one of three things.
No SYN/ACK packet is received
No RST/ACK packet is received
An ICMP type 3 message (Destination Unreachable) is received.
Nmap pulls all three of this conditions and report it as "filtered" port. To understand this nmap gathers the ICMP packages sent back to the attacker box. ICMP packets houses all the data necessary to understand what is happening.
The "unfiltered" port is reported only when we scan a number of ports and receive an RST/ACK packet back. In this state, either our packets are passing through the filtering device, but the target box do not listen on that port, OR the firewall is responding on behalf of the target with IP spoofing with RST/ACK flags set.
Anyway, I don’t wanna get into details of nmap, as there are many papers out there explaining the details of nmap, however as it is understood, it can be handy for network mapping behind firewalls and we can discover filtering device ACLs.
============================================================
Conclusion:
The aim of this paper was to give some idea about firewall penetration testing and network topology mapping behind firewalls. We have touched many different salts of firewall scanning tools, and there are many more at wild.
This methods are deployed in pen-tests to discover what is behind the filtering device and to figure out the ACL of this device. To do a successful pen-test, we need to know what is happening behind the closed doors. Who is watching the door? , what is he/she checking? and so on. Harvesting a wealth of information is the main step for a successful hacking, and to gather this information we have to penetrate through firewalls.
Watch your servers at wild
Mab-

Monday, November 24, 2008

SNMP & MRTG

How 2 Configure SNMP and MRTG

SNMP server configuration

Firstly, you need an SNMP server to provide network interface statstics on demand:

# apt-get install snmpd

You need to edit the configuration for this as it does not allow any connections by default. With your favourite editor, edit:

/etc/snmp/snmpd.conf

Comment out the following (prefix with #):

com2sec paranoid default public

Insert the following underneath the commented out section:

com2sec readonly default public

That gives anyone with access to the SNMP server read-only access to the public community. This is the one that contains the interface statistics.

To apply the changes, restart snmpd:

/etc/init.d/snmpd restart

Make sure you firewall off any SNMP related ports so that you don't get any unwanted visitors (check netstat and /etc/services for port information).

Installation of MRTG

MRTG is the main collection and graphing component of the traffic monitoring solution I am presenting here. Firstly, install MRTG:

# apt-get install mrtg

You can manually or automatically generate the configuration file for mrtg. I would recommend doing it automatically as it is a lot easier. Issue the following command:

# cfgmaker --global 'WorkDir: /var/www/mrtg' \
--output /etc/mrtg.cfg public@127.0.0.1

This will generate the configuration file. You then need to make an index file which contains a list of all of your interfaces. Issue the following command:

# indexmaker /etc/mrtg.cfg --columns=1 \
--output /var/www/mrtg/index.html

You will now need to execute mrtg manually 3 times to create the required database files. Issue the following command 3 times sequentially. On the third run, you should see no errors being reported:

# mrtg

This is executed every 5 minutes by cron. The cron job was added by dpkg for you so you do not have to configure it.

Conclusion

Finally, inspect your results! You will not see any reasonable graphs for quite some time so sit back end relax for a bit!

Browse to http://your-server-name/mrtg/