<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: nsm]]></title>
    <link>http://securityratty.com/tag/nsm</link>
    <description></description>
    <pubDate>Thu, 03 Jan 2008 16:47:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Expanding Response: Deeper Analysis for Incident Handlers]]></title>
      <link>http://securityratty.com/article/3bd8455fedce6ac873ea3b9f63cd7b90</link>
      <guid>http://securityratty.com/article/3bd8455fedce6ac873ea3b9f63cd7b90</guid>
      <description><![CDATA[To achieve my GCIH Gold, I recently completed a paper called Expanding Response: Deeper Analysis for Incident Handlers , now available in the SANS Reading Room . The premise was to further expand on...]]></description>
      <content:encoded><![CDATA[To achieve my GCIH Gold, I recently completed a paper called <a href="http://www.sans.org/reading_room/whitepapers/incident/32904.php">Expanding Response: Deeper Analysis for Incident Handlers</a>, now available in the <a href="http://www.sans.org/reading_room/">SANS Reading Room</a>. The premise was to further expand on the topics discussed in my <a href="http://holisticinfosec.blogspot.com/2007/12/malware-analysis-tools.html">Malware analysis tools</a> post. This paper includes tools discussed at various times in my <a href="http://holisticinfosec.org/content/view/12/26/">toolsmith</a> column in the <a href="http://issa.org/Members/Journal.html">ISSA Journal</a>, and includes details on <a href="http://qosient.com/argus/">Argus</a>, <a href="http://www.rawpacket.org/projects/hex/hex-livecd/version-20-release">HeX</a>, <a href="http://writequit.org/projects/nsm-console/">NSM-Console</a>, and <a href="http://sourceforge.net/projects/networkminer/">NetworkMiner</a>.<br /><br />Abstract:<br />    <span style="font-style:italic;">"The perspective embraced for this discussion is that of an analyst who is working a process to determine the exact nature of malicious software on his network. He is in receipt of the above mentioned .exe and .pcap files and seeks to further his understanding with the use of less typical tools. She begins the process with the network capture, and then takes a closer look at the binary to see what can be learned and what the impacts of an outbreak on her network might be."</span><br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/10/expanding-response-deeper-analysis-for.html&title=Expanding%20Response:%20Deeper%20Analysis%20for%20Incident%20Handlers " title="Expanding Response: Deeper Analysis for Incident Handlers ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/10/expanding-response-deeper-analysis-for.html" title="Expanding Response: Deeper Analysis for Incident Handlers ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/10/expanding-response-deeper-analysis-for.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 04:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/paper includes tools">paper includes tools</category>
      <category domain="http://securityratty.com/tag/incident handlers">incident handlers</category>
      <category domain="http://securityratty.com/tag/network capture">network capture</category>
      <category domain="http://securityratty.com/tag/deeper analysis">deeper analysis</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <category domain="http://securityratty.com/tag/gcih gold">gcih gold</category>
      <category domain="http://securityratty.com/tag/includes details">includes details</category>
      <category domain="http://securityratty.com/tag/pcap files">pcap files</category>
      <source url="http://holisticinfosec.blogspot.com/2008/10/expanding-response-deeper-analysis-for.html">Expanding Response: Deeper Analysis for Incident Handlers</source>
    </item>
    <item>
      <title><![CDATA[EstDomains & Intercage: A Perfect Couple in Crime]]></title>
      <link>http://securityratty.com/article/8490240982532919695d5c4c9231e15f</link>
      <guid>http://securityratty.com/article/8490240982532919695d5c4c9231e15f</guid>
      <description><![CDATA[If you track malware issues as readily as I do, you're likely aware of the failings of clownpacks like EstDomains and their hosting buddies Atrivo/Intercage. You need only follow Sunbelt's take on the...]]></description>
      <content:encoded><![CDATA[If you track malware issues as readily as I do, you're likely aware of the failings of clownpacks like EstDomains and their hosting buddies Atrivo/Intercage. You need only follow Sunbelt's <a href="http://www.google.com/search?hl=en&q=site%3Asunbeltblog.blogspot.com+estdomains+atrivo+intercage&btnG=Search" target="_blank">take</a> on the topic, or <a href="http://www.emergingthreats.net/index.php?searchword=intercage&option=com_search&Itemid=5" target="_blank">search</a> Emergingthreats to come up to speed.<br />Yesterday, EstDomains posted the most inept, ridiculous <a href="http://www.domainnews.com/en/general/estdomains-denies-links-to-malware-distribution.html" target="_blank">response</a> ever issued to the endless and worthy criticism, largely <a href="http://technewsreview.com.au/article.php?article=5882" target="_blank">leveled</a> by Brian Krebs at the Washington Post. <br />Not only can't these morons from EstDomains write, they're either so deeply clueless or flagrantly malicious (likely both), it's beyond laughable. This section sums it up best:<br /><span style="font-style:italic;">"The company also has a reliable ally in its battle against malware in a face of Intercage, Inc which provides company with the hosting services of the highest quality. But the outstanding performance of hosting services is not the sole reason why EstDomains, Inc appreciates this partnership so greatly. Intercage, Inc generously provides EstDomains, Inc specialists with reports regarding discovered malware vehicles. As the main database for additional domain name management services is located in Intercage Data Center, EstDomains, Inc has the perfect opportunity to get notifications of the slightest mark of malware presence in the shortest time and take measures in advance."</span><br /><span style="font-weight:bold;">What? Really?</span> <br />Again, aside from the absolute butchery of the language, did they just say <span style="font-style:italic;">"The company also has a reliable ally in its battle against malware in a face of Intercage, Inc which provides company with the hosting services of the highest quality."</span>? SIGH...yes, they did.<br /><br />Allow me to exemplify just how ridiculous a claim that is.<br />Following is content from a packet capture I took during a recent Storm worm analysis.<br /><br />Using the ip2asn module included in <a href="http://writequit.org/projects/nsm-console/" target="_blank">NSM-console</a> availabe in <a href="http://www.rawpacket.org/projects/hex" target="_blank">HeX</a>, we find:<br />27595   | 216.255.189.211  | INTERCAGE - InterCage, Inc.<br /><br />Using Etherape, also included in <a href="http://www.rawpacket.org/projects/hex" target="_blank">HeX</a>, we see:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SM880rNW5JI/AAAAAAAAACs/dWY8MUgSMUU/s1600-h/etherape_intercage.png"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SM880rNW5JI/AAAAAAAAACs/dWY8MUgSMUU/s320/etherape_intercage.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5246478966559532178" /></a><br /><br />Using <a href="http://networkminer.wiki.sourceforge.net/NetworkMiner" target="_blank">Eric Hjelmvik's</a> <a href="http://holisticinfosec.org/toolsmith/docs/august2008.pdf" target="_blank">NetworkMiner</a>, we see:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SM8-JQvlEKI/AAAAAAAAAC0/vjYvpHAoFDw/s1600-h/NetworMiner_intercage.png"><img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SM8-JQvlEKI/AAAAAAAAAC0/vjYvpHAoFDw/s320/NetworMiner_intercage.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5246480419744190626" /></a><br /><br />See the recurring theme? Intercage, EstDomain's <span style="font-style:italic;">"reliable ally in its battle against malware"</span>.<br />Nice work, guys...keep it up.<br /><br />I'm submitting this to <a href="http://thedailywtf.com/" target="blank">The Daily WTF</a> as we speak.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html&title=EstDomains%20&%20Intercage:%20A%20Perfect%20Couple%20in%20Crime " title="EstDomains & Intercage: A Perfect Couple in Crime ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html" title="EstDomains & Intercage: A Perfect Couple in Crime ">digg</a>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 17:32:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/intercage">intercage</category>
      <category domain="http://securityratty.com/tag/estdomains">estdomains</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware presence">malware presence</category>
      <category domain="http://securityratty.com/tag/intercage data center">intercage data center</category>
      <category domain="http://securityratty.com/tag/track malware issues">track malware issues</category>
      <category domain="http://securityratty.com/tag/reliable ally">reliable ally</category>
      <category domain="http://securityratty.com/tag/management services">management services</category>
      <category domain="http://securityratty.com/tag/malware vehicles">malware vehicles</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html">EstDomains &amp; Intercage: A Perfect Couple in Crime</source>
    </item>
    <item>
      <title><![CDATA[NSM-Console and HeX update]]></title>
      <link>http://securityratty.com/article/23ca43a9d7f75783982ad6ad9ad47b34</link>
      <guid>http://securityratty.com/article/23ca43a9d7f75783982ad6ad9ad47b34</guid>
      <description><![CDATA[While researching the HeX System for the pending February toolsmith , I was extremely pleased to discover NSM-Console , from Matthew Lee Hinman. I've not yet seen such an efficient, useful, all...]]></description>
      <content:encoded><![CDATA[While researching the <a href="http://www.rawpacket.org/projects/hex">HeX System</a> for the pending February <span style="font-style:italic;">toolsmith</span>, I was extremely pleased to discover <a href="http://thnetos.wordpress.com/nsm-console/">NSM-Console</a>, from Matthew Lee Hinman. I've not yet seen such an efficient, useful, all encompassing framework for offline packet analysis. NSM-Console includes modules for:<br /># aimsnarf<br /># ngrep (gif/jpg/pdf/exe/pe/ne/elf/3pg/torrent)<br /># tcpxtract<br /># tcpflow<br /># chaosreader<br /># bro-IDS<br /># snort<br /># tcpdstat<br /># capinfos<br /># tshark<br /># argus<br /># ragator<br /># racount<br /># rahosts<br /># hash (md5 & sha256)<br /># ra<br /># honeysnap<br /># p0f<br /># pads<br /># fl0p<br /># iploc<br />Consider giving both <a href="http://www.rawpacket.org/projects/hex">HeX System</a> and the included <a href="http://thnetos.wordpress.com/nsm-console/">NSM-Console</a> an immediate look.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/01/nsm-console-and-hex-update.html&title=NSM-Console%20and HeX%20update" title="NSM-Console and HeX update del.icio.us"><img src="http://holisticinfosec.org/images/delicious.png" class="socialbkmark" border=0 alt="NSM-Console and HeX update at del.icio.us"></a><a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/01/nsm-console-and-hex-update.html" title="NSM-Console and HeX update "> <img src="http://digg.com/img/badges/16x16-digg-guy.gif" border=0 class="socialbkmark" alt="Digg NSM-Console and HeX update "></a>]]></content:encoded>
      <pubDate>Thu, 10 Jan 2008 09:50:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/nsm-console">nsm-console</category>
      <category domain="http://securityratty.com/tag/nsm-console includes modules">nsm-console includes modules</category>
      <category domain="http://securityratty.com/tag/hex system">hex system</category>
      <category domain="http://securityratty.com/tag/matthew lee hinman">matthew lee hinman</category>
      <category domain="http://securityratty.com/tag/discover nsm-console">discover nsm-console</category>
      <category domain="http://securityratty.com/tag/offline packet analysis">offline packet analysis</category>
      <category domain="http://securityratty.com/tag/february toolsmith">february toolsmith</category>
      <category domain="http://securityratty.com/tag/tcpflow">tcpflow</category>
      <category domain="http://securityratty.com/tag/ngrep">ngrep</category>
      <source url="http://holisticinfosec.blogspot.com/2008/01/nsm-console-and-hex-update.html">NSM-Console and HeX update</source>
    </item>
    <item>
      <title><![CDATA[January's toolsmith - Gpg4win]]></title>
      <link>http://securityratty.com/article/75c507f8a0df9231a9361b0e07ab5104</link>
      <guid>http://securityratty.com/article/75c507f8a0df9231a9361b0e07ab5104</guid>
      <description><![CDATA[January's toolsmith column in the ISSA Journal features Gpg4win , a suite that integrates GPG into your Windows envronment. Next month will be discussing more powerful NSM opportunities with HeX , a...]]></description>
      <content:encoded><![CDATA[January's <span style="font-style:italic;">toolsmith</span> column in the <a href="http://issa.org/Members/Journal.html">ISSA Journal</a> features <a href="http://www.gpg4win.org/">Gpg4win</a>, a suite that integrates GPG into your Windows envronment. Next month will be discussing more powerful NSM opportunities with <a href="http://rawpacket.org/">HeX</a>, a FreeBSD-based Live CD loaded with network security monitoring tools. toolsmith offers insights on tools useful to the infosec practitioner, typically open source or inexpensive. The ISSA Journal is available to members in print and online at issa.org. Article copies are available on the <a href="http://holisticinfosec.org/content/view/12/26/">toolsmith</a> page.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/01/januarys-toolsmith-gpg4win.html&title=January's%20toolsmith%20-%20Gpg4win" title="January's toolsmith - Gpg4win del.icio.us"><img src="http://holisticinfosec.org/images/delicious.png" class="socialbkmark" border=0 alt="January's toolsmith - Gpg4win at del.icio.us"></a><a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/01/januarys-toolsmith-gpg4win.html" title="January's toolsmith - Gpg4win "> <img src="http://digg.com/img/badges/16x16-digg-guy.gif" border=0 class="socialbkmark" alt="Digg January's toolsmith - Gpg4win "></a>]]></content:encoded>
      <pubDate>Thu, 03 Jan 2008 16:47:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/toolsmith offers insights">toolsmith offers insights</category>
      <category domain="http://securityratty.com/tag/issa journal">issa journal</category>
      <category domain="http://securityratty.com/tag/issa">issa</category>
      <category domain="http://securityratty.com/tag/powerful nsm opportunities">powerful nsm opportunities</category>
      <category domain="http://securityratty.com/tag/network security">network security</category>
      <category domain="http://securityratty.com/tag/toolsmith column">toolsmith column</category>
      <category domain="http://securityratty.com/tag/toolsmith page">toolsmith page</category>
      <category domain="http://securityratty.com/tag/live cd">live cd</category>
      <category domain="http://securityratty.com/tag/january">january</category>
      <source url="http://holisticinfosec.blogspot.com/2008/01/januarys-toolsmith-gpg4win.html">January's toolsmith - Gpg4win</source>
    </item>
  </channel>
</rss>
