When you are using security tools like metasploit and want to analyse malware it can be helpful to have a tool that that quickly show you what changes a program (either good or bad) has made to your system.
There are plenty of tools that will do this for both windows or Linux (and Mac too). I will look at one for the windows platform. Specifically regshot.
The program can be downloaded from sourceforge at the following address : http://sourceforge.net/projects/regshot/
Once the program has been downloaded, extract it using your favorite file extractor such as winrar, winzip or 7zip. Then launch the regshot.exe file to open the program.
You can choose to save the output file as either a text file or HTML. HTML is a bit easier to read, so I'll use that. Then decide where you want to save the file. I'll put mine in "My Documents"
Once that is done you can take your first "shot" which records the state of the machine prior to installing anything as the first screen shot shows (choose "shot", instead of "shot and save").
Once you have saved your first shot, install some software (I installed audacity - an audio editor for this demo) as the next screen shows.
Finally, take your 2nd shot after the software has completed installing (again using "shot and save")
When that is complete the "compare" button which was previously greyed out should now be available. The resulting window should look something like this:
As you can see from the output Regshot will show you exactly what files were added to the machine, what registry entries were added and what values were added to those keys, as well as how many changes total there were.
This tool can be very handy if you want to examine malware (hopefully in a VM) and want to know what changes it has made to your system.
Friday, October 29, 2010
Sunday, October 3, 2010
Python Program to Scan IP's and Ports
Here is a program I wrote in Python to scan a range of IP's and a chosen port :
I started with this code first from class :
**************
Here's the code we started with:
import socket
IPRange = raw_input('Enter an IP Address: ')
Port = input('Enter the Port Number: ')
a, b, c, d = IPRange.split('.')
for x in range(1, 254):
ip = a + '.' + b + '.' + c + '.' + str(x)
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
try:
s.connect((ip, Port))
except socket.error:
print '%s: Port Closed' % ip
continue
print '%s: Port Open' % ip
****************
import socket
IPRange = raw_input('Enter an IP Address: ')
UserInput = raw_input('Enter IP Class to scan (A/B/C): ')
Port = input('Enter the Port Number: ')
a, b, c, d = IPRange.split('.')
if UserInput == 'C':
for x in range(1, 254):
ip = str(a) + '.' + str(b) + '.' + str(c) + '.' + str(x)
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
try:
s.connect((ip, Port))
except socket.error:
print '%s: Port Closed' % ip
continue
print '%s: Port Open' % ip
elif UserInput == 'B':
for y in range(1, 254):
for x in range(1,254):
ip = str(a) + '.' + str(b) + '.' + str(y) + '.' + str(x)
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
try:
s.connect((ip, Port))
except socket.error:
print '%s: Port Closed' % ip
continue
print '%s: Port Open' % ip
elif UserInput == 'A':
for z in range(1, 254):
for y in range(1,254):
for x in range(1,254):
ip = str(a) + '.' + str(z) + '.' + str(y) + '.' + str(x)
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
try:
s.connect((ip, Port))
except socket.error:
print '%s: Port Closed' % ip
continue
print '%s: Port Open' % ip
else:
print '%s: Input Error try again'
The above screenshot shows how the program works. It prompts you first for an ip address, then class and finally a port number (this would fail as the ip that I entered is not a web server).
Although I can see how this is useful to be able to write some apps using python, I much prefer using some prebuilt apps like Nmap which is far more flexible and powerful to be able to scan a range or ip's and ports.
I started with this code first from class :
**************
Here's the code we started with:
import socket
IPRange = raw_input('Enter an IP Address: ')
Port = input('Enter the Port Number: ')
a, b, c, d = IPRange.split('.')
for x in range(1, 254):
ip = a + '.' + b + '.' + c + '.' + str(x)
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
try:
s.connect((ip, Port))
except socket.error:
print '%s: Port Closed' % ip
continue
print '%s: Port Open' % ip
****************
import socket
IPRange = raw_input('Enter an IP Address: ')
UserInput = raw_input('Enter IP Class to scan (A/B/C): ')
Port = input('Enter the Port Number: ')
a, b, c, d = IPRange.split('.')
if UserInput == 'C':
for x in range(1, 254):
ip = str(a) + '.' + str(b) + '.' + str(c) + '.' + str(x)
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
try:
s.connect((ip, Port))
except socket.error:
print '%s: Port Closed' % ip
continue
print '%s: Port Open' % ip
elif UserInput == 'B':
for y in range(1, 254):
for x in range(1,254):
ip = str(a) + '.' + str(b) + '.' + str(y) + '.' + str(x)
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
try:
s.connect((ip, Port))
except socket.error:
print '%s: Port Closed' % ip
continue
print '%s: Port Open' % ip
elif UserInput == 'A':
for z in range(1, 254):
for y in range(1,254):
for x in range(1,254):
ip = str(a) + '.' + str(z) + '.' + str(y) + '.' + str(x)
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
try:
s.connect((ip, Port))
except socket.error:
print '%s: Port Closed' % ip
continue
print '%s: Port Open' % ip
else:
print '%s: Input Error try again'
The above screenshot shows how the program works. It prompts you first for an ip address, then class and finally a port number (this would fail as the ip that I entered is not a web server).
Although I can see how this is useful to be able to write some apps using python, I much prefer using some prebuilt apps like Nmap which is far more flexible and powerful to be able to scan a range or ip's and ports.
Monday, September 27, 2010
Installing Metasploit on Ubuntu
Metasploit is an open source tool that provides information about security vulnerabilities and aids in penetration testing.
Written first in Perl and then Ruby, it provides a powerful tool for investigating potential security vulnerabilities. Its most well known sub-project is the metasploit framework for developing exploit code to be used against a target machine.
To install metasploit on Ubuntu Linux, I used Ubuntu 10.04.1 in VMware Workstation 7.1.0 build 261024 with 2 NIC's. One was set to NAT and the other to bridged (but disconnected)
I booted up Ubuntu and logged in as a normal user and then used Firefox to download the latest version of Metasploit. I used version 3.4.1 i686 of the metasploit framework.
I then changed to root using the linux su command and moved the framework-3.4.1-linux-i686.run file to the root folder. But before I could install metasploit I needed to install Ruby as well as it has dependancies that the framework needs.
To install ruby use this command : apt-get install ruby
Once Ruby has installed install the Metasploit framework with the following command : ./framework-3.4.1-linux-i686.run
That's pretty much all there is too it. The tool can be launched by running the command "msfconsole" (without the quotes). The screenshot below is what it looked like on my machine once it is running.
It may interest you to know that metasploit has a web interface as well that can be used to select exploits, targets and payloads as well.
To use the web interface, it needs to be started at the command line. Type "msfweb" (no quotes) and then open firefox. Metasploit listens on port 55555 by default (although this behaviour can be changed).
The following screencapture shows msfweb starting:
Once msfweb is running, open firefox and point the address to the localhost IP, which is 127.0.0.1 on port 55555.
The last screenshot shows metasploits web interface. From here you can explore the application, see what vulnerabilites are in its database and direct a payload to an 'unsuspecting' victim.
This concludes the installation of metasploit, a powerful tool for discovering security vulnerabilities and penetration testing.
Written first in Perl and then Ruby, it provides a powerful tool for investigating potential security vulnerabilities. Its most well known sub-project is the metasploit framework for developing exploit code to be used against a target machine.
To install metasploit on Ubuntu Linux, I used Ubuntu 10.04.1 in VMware Workstation 7.1.0 build 261024 with 2 NIC's. One was set to NAT and the other to bridged (but disconnected)
I booted up Ubuntu and logged in as a normal user and then used Firefox to download the latest version of Metasploit. I used version 3.4.1 i686 of the metasploit framework.
I then changed to root using the linux su command and moved the framework-3.4.1-linux-i686.run file to the root folder. But before I could install metasploit I needed to install Ruby as well as it has dependancies that the framework needs.
To install ruby use this command : apt-get install ruby
Once Ruby has installed install the Metasploit framework with the following command : ./framework-3.4.1-linux-i686.run
That's pretty much all there is too it. The tool can be launched by running the command "msfconsole" (without the quotes). The screenshot below is what it looked like on my machine once it is running.
It may interest you to know that metasploit has a web interface as well that can be used to select exploits, targets and payloads as well.
To use the web interface, it needs to be started at the command line. Type "msfweb" (no quotes) and then open firefox. Metasploit listens on port 55555 by default (although this behaviour can be changed).
The following screencapture shows msfweb starting:
Once msfweb is running, open firefox and point the address to the localhost IP, which is 127.0.0.1 on port 55555.
The last screenshot shows metasploits web interface. From here you can explore the application, see what vulnerabilites are in its database and direct a payload to an 'unsuspecting' victim.
This concludes the installation of metasploit, a powerful tool for discovering security vulnerabilities and penetration testing.
Subscribe to:
Posts (Atom)



