I had a brilliant first day at LinuxFest NorthWest. I sat through five presentations on privacy and computer security in Haskell 115 at Bellingham Technical College. Brian Alseth of ACLU of Washington delivered the usual terrifying description of how data mining is destroying privacy. John Lock talked about Web Commerce Security. Gary Smith of PNL gave and excellent talk on Linux Server Hardening. Hal Pomeranz finished up the day with two hours on SE Linux. Wow! What a beast SE Linux is...
LinuxFest...a great thing.
Historic blog. No longer active. See Also http://horizontal-logic.blogspot.com for more Powershell code. AS of 2/27/2014 all Scripts are PS 4.0.
Saturday, April 24, 2010
Wednesday, April 21, 2010
Joanna Rutkowska and ITL and "Security by Isolation"
A day spent reading the research of Joanna Rutkowska and her Invisible Things Lab is a day spent improving your IQ. Ms. Rutkowska is famous for describing vulnerabilities in SMM, BIOS, and VM hypervisors. In short, rather than attack the Operating System (although she has done some of that as well), she and her team attack the layer between the Operating System and the hardware; specifically rings -1, -2, -3 to use her terminology. Her work has led her to some drastic conclusions about hardware and digital security. In Joanna's universe, it is not that "game is over" but that the digital industry has never really fielded a team that could win yet. To do something about this, she and her team have developed a customized version of Linux (Qubes-OS); partitioning off OS components into VMs to prevent the spread of malware through the access of "universal privilege" (my own term).
What do I mean by "universal privilege"? [Beware, the author's own untutored verbiage is to follow...] Computers are strange but beautiful machines. When the first computational devices were built, we wanted to send in questions and retrieve answers. After computer scientists achieved this breakthrough, they spent the next half century attempting to generate increasing profits by increasing the speed at which answers to their questions would be returned. And they did a damn fine job at this. The increase in computational speed has to count as the single greatest technical advancement of our species by this point in history. Watch any movie about the Hubble or the Mars Rover and ask yourself: How would that happen without digital data? We have designed our computational efforts as if we were children with thirsty minds and ravenous social needs; ready to exercise our "universal privilege" to discuss/communicate/download whatever our minds and souls desire.
Security is mainly the story of protection. Secrecy is mainly the story of compartmentalization. In contrast to the development of computational speed, we've done a poor job at protection and compartmentalization of computers and their networks. In fact, we've been so concerned about the spread of information, we've done everything possible to unleash the flow of digital data across the world. PCs and Servers are now everywhere, in every complex product, in every country. Our computer networks are now the most tangible and real-time evidence of our civilization. Computers still retain all of the "strange and beautiful" architecture designed upon the premise that we want very little between our computers and fast answers to our questions. We are by nature social creatures with unbounded curiosity and potentially unbounded need for "end to end" trust. Unfortunately, the reality of unconstrained digital response has helped created powerful offensive weaponry in the untrustworthy world we live in.
So now back to universal privilege and Joanna Rutkowska and her team at Invisible Things Lab. Eschewing (in part) the drive for secure code and secure micro-kernels, Joanna and her team attempt to do the following:
"Qubes implements Security by Isolation approach. To do this, Qubes utilizes virtualization technology, to be able to isolate various programs from each other, and even sandbox many system-level components, like networking or storage subsystem, so that their compromise don’t affect the integrity of the rest of the system."
They achieve this "security by isolation" by compartmentalizing their OS into secure virtual machines. It is a timely idea. As if to prove this, the NSF gave a $1.5 M dollar grant to an University of Illinois researcher nearly days after ITL's announcement of Qubes to do something similar. "Security by isolation" is an ancient concept thoroughly deployed by computer and software architecture at all levels. There are numerous examples: CPUs break down access to the processor into "Rings" (0-3). Operating Systems break down execution in kernel and userland and then compartmentalize execution further. Some kernels just boot the most basic OS components, (Most desktop OS kernels are monolithic). Software compartmentalizes (perhaps 'componentizes') itself into functions, system calls, objects, and libraries. Some software, like Java and C#, works hard at making code live in a secure 'sandbox'. Part of the developmental reason for object oriented programming (originally) was (marginally) security-based: 'encapsulation'. Networking software has followed the trend of security by compartmentalization from switch fabric to firewalls to NAC. Hosted services, in some very real sense, are a form of "security by isolation".
In reality, we continue to invent "security by isolation" in kernels, software layers, networks, network components, firewalls, and virtual machines. As processor speed grows in an untrustworthy world, the desktop and network will always continue to need the most advanced compartmentalization to protect them from the expanding digitized world. To this end, our "universal privilege" to keep asking questions of each other will always be haunted by the necessity of "security by isolation".
What do I mean by "universal privilege"? [Beware, the author's own untutored verbiage is to follow...] Computers are strange but beautiful machines. When the first computational devices were built, we wanted to send in questions and retrieve answers. After computer scientists achieved this breakthrough, they spent the next half century attempting to generate increasing profits by increasing the speed at which answers to their questions would be returned. And they did a damn fine job at this. The increase in computational speed has to count as the single greatest technical advancement of our species by this point in history. Watch any movie about the Hubble or the Mars Rover and ask yourself: How would that happen without digital data? We have designed our computational efforts as if we were children with thirsty minds and ravenous social needs; ready to exercise our "universal privilege" to discuss/communicate/download whatever our minds and souls desire.
Security is mainly the story of protection. Secrecy is mainly the story of compartmentalization. In contrast to the development of computational speed, we've done a poor job at protection and compartmentalization of computers and their networks. In fact, we've been so concerned about the spread of information, we've done everything possible to unleash the flow of digital data across the world. PCs and Servers are now everywhere, in every complex product, in every country. Our computer networks are now the most tangible and real-time evidence of our civilization. Computers still retain all of the "strange and beautiful" architecture designed upon the premise that we want very little between our computers and fast answers to our questions. We are by nature social creatures with unbounded curiosity and potentially unbounded need for "end to end" trust. Unfortunately, the reality of unconstrained digital response has helped created powerful offensive weaponry in the untrustworthy world we live in.
So now back to universal privilege and Joanna Rutkowska and her team at Invisible Things Lab. Eschewing (in part) the drive for secure code and secure micro-kernels, Joanna and her team attempt to do the following:
"Qubes implements Security by Isolation approach. To do this, Qubes utilizes virtualization technology, to be able to isolate various programs from each other, and even sandbox many system-level components, like networking or storage subsystem, so that their compromise don’t affect the integrity of the rest of the system."
They achieve this "security by isolation" by compartmentalizing their OS into secure virtual machines. It is a timely idea. As if to prove this, the NSF gave a $1.5 M dollar grant to an University of Illinois researcher nearly days after ITL's announcement of Qubes to do something similar. "Security by isolation" is an ancient concept thoroughly deployed by computer and software architecture at all levels. There are numerous examples: CPUs break down access to the processor into "Rings" (0-3). Operating Systems break down execution in kernel and userland and then compartmentalize execution further. Some kernels just boot the most basic OS components, (Most desktop OS kernels are monolithic). Software compartmentalizes (perhaps 'componentizes') itself into functions, system calls, objects, and libraries. Some software, like Java and C#, works hard at making code live in a secure 'sandbox'. Part of the developmental reason for object oriented programming (originally) was (marginally) security-based: 'encapsulation'. Networking software has followed the trend of security by compartmentalization from switch fabric to firewalls to NAC. Hosted services, in some very real sense, are a form of "security by isolation".
In reality, we continue to invent "security by isolation" in kernels, software layers, networks, network components, firewalls, and virtual machines. As processor speed grows in an untrustworthy world, the desktop and network will always continue to need the most advanced compartmentalization to protect them from the expanding digitized world. To this end, our "universal privilege" to keep asking questions of each other will always be haunted by the necessity of "security by isolation".
Sunday, April 18, 2010
tcpslice II
More uses for tcpslice, ipsumdump, BASH 4.1 :
[This gives you today's top source IP and source IP Port combination:
/usr/sbin/tcpslice `date +%Y"y"%m"m"%d"d"` $BASH_ARGV | ipsumdump --no-headers -sD -
./todays_dump.sh MarApr.snort.in.tcpd | sort -nr | uniq -c | sort -nr
13 85.144.201.237 7959
3 95.179.99.147 5900
3 64.206.157.2 23
3 222.45.112.59 8085
3 109.187.8.70 5900
2 98.247.214.152 23 ...
This gives you today's top source IP and source IP location:
/usr/sbin/tcpslice `date +%Y"y"%m"m"%d"d"` $BASH_ARGV |
for i in `ipsumdump --no-headers -s -`
do echo $i : $(printf "%s" `./geoip.sh $i | awk -F":" '{print $2}' | awk -F"," '{print $1","$2","$3}' ` )
done
./tgeodump.sh MarApr.snort.in.tcpd | sort -nr | uniq -c | sort -nr
13 85.144.201.237 : NL,07,Amsterdam
12 222.45.112.59 : CN,22,Beijing
4 222.215.230.49 : CN,32,Chengdu
3 95.179.99.147 : RU,43,Lipetsk
3 64.206.157.2 : US,NH,Nashua
3 109.187.8.70 : IPAddressnotfound,,
2 98.247.214.152 : US,WA,Bothell ...
where 'geoip.sh' is:
geoiplookup -f /usr/local/share/GeoIP/GeoLiteCity.dat $1
I note that file names like this '08Mar1142PST2010.in.1268074842' don't process through tcpslice.
Wednesday, April 14, 2010
tcpslice
Tcpslice is a useful tool from LBL network group that allows you to carve up a large pcap file format into time slices.
To look at the start and finish time stamps of the entire pcap file in various time formats:tcpslice -r Marchrferrisx.snort.in Marchrferrisx.snort.in Mon Mar 8 11:08:09 2010 Mon Apr 5 09:09:37 2010tcpslice -t Marchrferrisx.snort.inMarchrferrisx.snort.in 2010y03m08d11h08m09s660222u 2010y04m05d09h09m37s390876utcpslice -R Marchrferrisx.snort.inMarchrferrisx.snort.in 1268075289.660222 1270483777.390876
To return data from a particular time slice to a file with BPF filters use syntax like this: tcpslice 1257347146.060 1257347146.061 inputFile.tcpd | tcpdump -r - -w outputFile.tcpd 'host 192.168.1.175'
(Check out bothunter logs for more examples like this..)
In this example, I want all the packets that are not IPv6 for one date:/usr/sbin/tcpslice 2010y04m05d Marchrferrisx.snort.in | /usr/sbin/tcpdump -r - 'not(ip6)' | lessreading from file -, link-type EN10MB (Ethernet)
01:06:17.290514 IP 125.141.195.190.35460 > 192.168.0.12.ssh: S 1607742099:1607742099(0) win 65535
01:40:16.181816 IP c-98-247-214-152.hsd1.wa.comcast.net.catchpole > 192.168.0.12.telnet: SWE 498716114:498716114(0) win 5840
01:40:19.172942 IP c-98-247-214-152.hsd1.wa.comcast.net.catchpole > 192.168.0.12.telnet: SWE 498716114:498716114(0) win 5840
01:44:01.423708 IP hn.kd.ny.adsl.x11 > 192.168.0.12.ms-sql-s: S 833421312:833421312(0) win 16384
03:37:06.073237 IP 75.125.252.76.http > 192.168.0.12.48532: S 1175613974:1175613974(0) ack 143375003 win 14420
04:07:03.019711 IP 222.45.112.59.12200 > 192.168.0.12.ssm-els: S 363594672:363594672(0) win 8192 ... Now I want all ms-sql-s destination packets from the ingress pcap that are not IPv6 for all of March:/usr/sbin/tcpslice 2010y04m01d 2010y04m31d Marchrferrisx.snort.in | /usr/sbin/tcpdump -r - -n 'dst port(1433)'
reading from file -, link-type EN10MB (Ethernet)
18:33:42.614843 IP 125.46.78.100.x11 > 192.168.0.12.ms-sql-s: S 908984320:908984320(0) win 16384
23:38:50.771853 IP 61.183.172.35.x11 > 192.168.0.12.ms-sql-s: S 47316992:47316992(0) win 16384
03:35:18.351118 IP 121.12.125.7.x11 > 192.168.0.12.ms-sql-s: S 640548864:640548864(0) win 16384
11:09:45.631103 IP 218.61.127.71.x11 > 192.168.0.12.ms-sql-s: S 1613627392:1613627392(0) win 16384
00:47:21.207593 IP 218.90.163.66.x11 > 192.168.0.12.ms-sql-s: S 648937472:648937472(0) win 16384
08:56:05.732622 IP 61.183.172.35.x11 > 192.168.0.12.ms-sql-s: S 47316992:47316992(0) win 16384
18:06:53.798198 IP 59.51.114.39.x11 > 192.168.0.12.ms-sql-s: S 648937472:648937472(0) win 16384 ...
Something similar, but a little cleaner, can be done with ipsumdump:/usr/sbin/tcpslice 2010y04m01d 2010y04m31d Marchrferrisx.snort.in | ipsumdump -tsD | grep -w 14331270172022.614843 125.46.78.100 14331270190330.771853 61.183.172.35 14331270204518.351118 121.12.125.7 14331270231785.631103 218.61.127.71 14331270280841.207593 218.90.163.66 14331270310165.732622 61.183.172.35 14331270343213.798198 59.51.114.39 1433 ...
Labels:
ingress snort logs,
ipsumdump,
tcpslice
Saturday, April 10, 2010
One year anniversary
Today is the one year anniversary of this blog. This is my 48th post in that time period. According to Google Analytics, 1,250 “absolute unique visitors” have provided for 1,566 visits from 781 unique cities from 78 unique countries. 72 page titles were viewed a total of 2,241 times. Here are some of the most popular pages:
- /2009/05/i-receive-lots-of-6000-port-scans-on-my.html
- /2009/09/network-monitor-api-part-ii.html
- /2009/05/host-protection-working-with-microsofts.html
Actually, I have no idea what to make of any of these numbers.
Labels:
one year anniversary
Monday, April 5, 2010
More fun with ipsumdump
More fun with ipsumdump. Below, sorting March ingress by COUNT(SIP), COUNT(SPort), Sorted GeoIP location. All very fast.
ipsumdump -s --no-headers Marchrferrisx.snort.in |
sort -nr | uniq -c | sort -nr | less
626 75.125.252.73
384 74.125.19.191
358 125.45.109.196
286 66.165.46.165
242 74.125.127.191
234 74.125.53.191
138 67.214.120.156
138 204.236.155.168
127 67.228.177.148
120 74.125.19.19
107 173.14.243.230
105 221.195.73.86
103 221.192.199.35
....
ipsumdump -S --no-headers Marchrferrisx.snort.in |
sort -nr | uniq -c | sort -nr
6523 80
1669 443
1220 12200
553 63585
468 19150
459 19099
238 6000
198 19135
156 19134
93 21
46 110
34 5242
30 9875
21 52079
21 35356
20 1935
for i in `ipsumdump -s --no-headers Marchrferrisx.snort.in |
sort -nr | uniq |sort -nr`
do
echo $i `geoip.sh $i | awk -F: '{print $2$3}'`
done
222.86.62.237 CN, N/A, N/A, N/A, 35.000000, 105.000000, 0, 0
222.59.176.26 CN, 04, Wuxi, N/A, 31.577200, 120.293900, 0, 0
222.59.176.105 CN, 04, Wuxi, N/A, 31.577200, 120.293900, 0, 0
222.45.112.59 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.45.112.221 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.41.8.67 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.37.37.33 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.34.103.72 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.243.14.144 CN, 11, Xupu, N/A, 27.909401, 110.585800, 0, 0
222.219.236.209 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.215.230.49 CN, 32, Chengdu, N/A, 30.666700, 104.066597, 0, 0
222.215.230.170 CN, 32, Chengdu, N/A, 30.666700, 104.066597, 0, 0
222.214.218.188 CN, 32, Chengdu, N/A, 30.666700, 104.066597, 0, 0
222.211.69.13 CN, 32, Chengdu, N/A, 30.666700, 104.066597, 0, 0
222.208.183.218 CN, 32, Chengdu, N/A, 30.666700, 104.066597, 0, 0
222.186.25.143 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.186.24.37 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
...
ipsumdump -s --no-headers Marchrferrisx.snort.in |
sort -nr | uniq -c | sort -nr | less
626 75.125.252.73
384 74.125.19.191
358 125.45.109.196
286 66.165.46.165
242 74.125.127.191
234 74.125.53.191
138 67.214.120.156
138 204.236.155.168
127 67.228.177.148
120 74.125.19.19
107 173.14.243.230
105 221.195.73.86
103 221.192.199.35
....
ipsumdump -S --no-headers Marchrferrisx.snort.in |
sort -nr | uniq -c | sort -nr
6523 80
1669 443
1220 12200
553 63585
468 19150
459 19099
238 6000
198 19135
156 19134
93 21
46 110
34 5242
30 9875
21 52079
21 35356
20 1935
for i in `ipsumdump -s --no-headers Marchrferrisx.snort.in |
sort -nr | uniq |sort -nr`
do
echo $i `geoip.sh $i | awk -F: '{print $2$3}'`
done
222.86.62.237 CN, N/A, N/A, N/A, 35.000000, 105.000000, 0, 0
222.59.176.26 CN, 04, Wuxi, N/A, 31.577200, 120.293900, 0, 0
222.59.176.105 CN, 04, Wuxi, N/A, 31.577200, 120.293900, 0, 0
222.45.112.59 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.45.112.221 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.41.8.67 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.37.37.33 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.34.103.72 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.243.14.144 CN, 11, Xupu, N/A, 27.909401, 110.585800, 0, 0
222.219.236.209 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.215.230.49 CN, 32, Chengdu, N/A, 30.666700, 104.066597, 0, 0
222.215.230.170 CN, 32, Chengdu, N/A, 30.666700, 104.066597, 0, 0
222.214.218.188 CN, 32, Chengdu, N/A, 30.666700, 104.066597, 0, 0
222.211.69.13 CN, 32, Chengdu, N/A, 30.666700, 104.066597, 0, 0
222.208.183.218 CN, 32, Chengdu, N/A, 30.666700, 104.066597, 0, 0
222.186.25.143 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
222.186.24.37 CN, 22, Beijing, N/A, 39.928902, 116.388298, 0, 0
...
Friday, April 2, 2010
"One Page Checklist for Securing and Cleaning a Malware Infected Windows PC"
A "One Page Checklist for Securing and Cleaning a Malware Infected Windows PC" is available. From the paper:
In this process, you are looking for outbound and inbound communication and connection attempts that seem suspicious – data transfers that you can not account for, processes that seem inexplicable, or unsigned files. You may or may not see logon attempts, registry changes, file creation, file access, file permission changes. You may need to correlate Network Monitor logs with network ingress and egress firewall logs. Additional info at:
Wednesday, March 31, 2010
Vista logon.scr error
Vista, as most of us know, will take a machine out of standby (light sleep), to install the "Tuesday updates". After it reboots, I see this:
Logon screen error are traditionally dangerous because they have been used to bypass the logon screen.
Logon screen error are traditionally dangerous because they have been used to bypass the logon screen.
Labels:
Logon screen error;
Monday, March 22, 2010
Data Breaches 2010
Below is a list of 171 data breaches identified by public records found by the ID Theft Resource Center for the first two and one half months of 2010. ITRC has a justice department grant to catalog all known data breaches from credible sources. ITRC is a donor sponsored, multi-venue, non-profit working to resolve identity theft. If you are a public or private sector enterprise of any type - banking, financial services, insurance, University, medical provider, HMO, governmental department, law firm, hotelier, or non-profit - you will find analogs to your business in this list. I encourage you to read through this list if you have any network or data exposure and ask yourself:
ITRC20100316-01 John Hancock Financial Services
- What information assets does my group have to lose?
- How could we lose them?
ITRC20100316-01 John Hancock Financial Services
ITRC20100315-02 TD Bank PA Yes
ITRC20100311-01 US Bank OH
ITRC20100310-05 Securities and Exchange Commission
ITRC20100310-04 Assurity Financial Services US
ITRC20100309-10 Virgin Money USA Inc
ITRC20100309-01 Ally Bank US
ITRC20100308-16 Wells Fargo - Law
ITRC20100308-14 Partnership Federal Credit Union
ITRC20100308-09 Telhio Credit Union OH
ITRC20100308-08 M&T Bank MD
ITRC20100305-08 BlackRock US
ITRC20100226-01 CitiGroup US
ITRC20100224-01 SunTrust Banks FL
ITRC20100218-08 ING Fund US
ITRC20100201-03 Ameriquest Mortgage MN
ITRC20100126-07 Gregory Navone, First Interstate
ITRC20100114-02 Lincoln National Financial Securities
ITRC20100113-02 Suffolk County National Bank
ITRC20100104-01 Eastern Bank Corp MA
ITRC20100316-03 Beecher Carlson Holdings US
ITRC20100316-02 Beer & Wine Hobby
ITRC20100315-01 Littleton Pizza Hut franchisee
ITRC20100312-01 MonoPrice.com US
ITRC20100310-08 Experian US
ITRC20100310-07 GroupM US
ITRC20100310-06 Citco - Evanston Capital
ITRC20100310-03 Kraft Foods US
ITRC20100310-01 Thrivent Financial PA None
ITRC20100309-15 AlixPartners LLP US
ITRC20100309-14 T-Mobile MD
ITRC20100309-13 Hotels.com - vendor US
ITRC20100309-12 LitCon Group VA
ITRC20100309-11 AT&T - unknown vendor
ITRC20100309-08 California Business Bureau Medical
ITRC20100309-07 Wolters Kluwer - CCH
ITRC20100309-06 Center for American Progress
ITRC20100309-05 Ameriprise Financial - vendor
ITRC20100309-03 Priceline.com US -
ITRC20100309-02 United Guaranty Residential Insurance
ITRC20100308-15 Coffee.org US
ITRC20100308-13 LampSource US
ITRC20100308-12 Ameriprise Financial US
ITRC20100308-11 Bristol-Myers Squibb Company US
ITRC20100308-10 MoneyGram International US
ITRC20100308-07 National Audubon Society AZ
ITRC20100308-06 Willard InterContinental Hotel DC
ITRC20100308-05 Ameriprise Financial Inc US
ITRC20100308-04 Cell Phone Kiosk -
ITRC20100308-03 Arrow Electronics NY
ITRC20100308-01 Los Angeles Westin Bonaventure
ITRC20100305-12 Uniformed Services Benefit Association
ITRC20100305-11 Nuance Communications US Yes
ITRC20100305-10 FCI USA LLC US
ITRC20100305-09 Genworth Financial, Life Insurance
ITRC20100305-07 Thermo Fisher Scientific Inc
ITRC20100305-05 Moses,Phillips, Young, Brannon and
ITRC20100305-04 Easybakeware.com US
ITRC20100305-02 Hancock Fabrics US
ITRC20100304-03 Vernon Sales Promotion US
ITRC20100301-07 Feeney Agency PA
ITRC20100301-06 McGraw-Hill Construction UT
ITRC20100301-05 Erisa Pension Systems -
ITRC20100301-02 MSO of Puerto Rico
ITRC20100301-01 MSO of Puerto Rico
ITRC20100226-02 Wyndham Hotels US
ITRC20100225-01 Law Firms, Smyrna GA
ITRC20100224-02 Association for the Blind
ITRC20100223-24 Mid America Kidney Stone
ITRC20100223-17 Merkle Direct Marketing -
ITRC20100223-16 Health Services for Children
ITRC20100223-12 Public Employee Health Insurance
ITRC20100223-07 Private Practice, Wilmington NC
ITRC20100223-02 Educators Mutual Insurance Association
ITRC20100219-02 H&R Block IN Yes
ITRC20100218-09 Cullman Dairy Queen AL
ITRC20100218-07 Galeton, Gloves Inc US
ITRC20100218-06 Daedalus Books US
ITRC20100218-05 TGI Friday's - West
ITRC20100218-04 Eclipse Property Solutions FL
ITRC20100218-02 Small Dog Electronics US
ITRC20100212-03 Macy's - St Louis
ITRC20100212-01 Equifax US
ITRC20100209-13 Ozarks Area Community Action
ITRC20100209-11 St. Clair Winery &
ITRC20100209-10 Highmark US -
ITRC20100209-06 Ceridian US
ITRC20100209-03 AvMed Health Plans FL
ITRC20100202-03 Innotek US
ITRC20100202-02 P.F. Chang's Bistro
ITRC20100119-04 ExposeObama.com
ITRC20100119-03 Time Customer Service
ITRC20100119-02 Goodwill - Kent County
ITRC20100111-01 Metropark NY
ITRC20100104-02 Moriarty & Primack MA
ITRC20100305-01 New Mexico State University
ITRC20100301-04 Bennett College NC
ITRC20100219-01 Valdosta State University GA
ITRC20100218-01 Southern Illinois University IL
ITRC20100209-14 Kansas City Art Institute
ITRC20100209-04 University of Texas El
ITRC20100202-01 West Virginia University WV
ITRC20100201-04 Columbia University
ITRC20100201-02 Humboldt State University CA
ITRC20100126-05 University of Missouri MO
ITRC20100114-03 Eugene School District OR
ITRC20100114-01 Western Michigan University MI
ITRC20100316-04 St. Louis Metropolitan Police
ITRC20100305-06 Anne Arundel County's Fire
ITRC20100304-01 SC Department of Health
ITRC20100301-03 Arkansas Guard, Camp Robinson
ITRC20100223-25 New York Department of
ITRC20100223-14 Alaska Department of Health
ITRC20100223-13 Brooke Army Medical Center
ITRC20100222-01 TennCare TN Yes -
ITRC20100218-03 West Memphis Police Department
ITRC20100209-09 Social Security Administration NY
ITRC20100209-08 Wyoming Department of Health
ITRC20100209-07 Ohio Department of Administrative
ITRC20100209-02 D.C. Office of Tax
ITRC20100209-01 CA Department of Health
ITRC20100201-01 Iowa Racing and Gaming
ITRC20100128-01 PricewaterhouseCoopers - Alaska state
ITRC20100127-01 US Department of Commerce
ITRC20100126-08 New York Department of
ITRC20100126-06 Minnesota Department of Labor
ITRC20100126-04 Seattle Municipal Court WA
ITRC20100126-02 Internal Revenue Service -
ITRC20100126-01 Columbus Health Department OH
ITRC20100119-01 City of Oakridge OR
ITRC20100107-01 Housing Authority of New
ITRC20100104-03 Transportation Security Administration (TSA)
ITRC20100311-07 BlueCross BlueShield of RI
ITRC20100311-06 Center for Neurosciences AZ
ITRC20100311-05 Advanced NeuroSpinal Care CA
ITRC20100311-04 Lucille Packard Children's Hospital
ITRC20100311-03 University of New Mexico
ITRC20100311-02 North Carolina Baptist Hospital
ITRC20100310-02 Quest Diagnostics - AmeriPath
ITRC20100309-16 Empi Recovery Services -
ITRC20100309-04 DaVita - Renal Treatment
ITRC20100308-02 University of Texas Southwestern
ITRC20100305-03 Wake Forest University Baptist
ITRC20100302-01 Diabetes Direct FL
ITRC20100226-03 Shands HealthCare FL
ITRC20100225-02 University of Washington Medical
ITRC20100223-23 Private Practice Torrance #5
ITRC20100223-22 Private Practice Torrance #4
ITRC20100223-21 Private Practice Torrance #3
ITRC20100223-20 Private Practice Torrance #2
ITRC20100223-19 Private Practice, Torrance #1
ITRC20100223-18 City of Hope National
ITRC20100223-15 Cogent Healthcare of Wisconsin,
ITRC20100223-11 BlueCross BlueShield - DC,
ITRC20100223-10 Children's Medical Center of
ITRC20100223-09 Concentra TX
ITRC20100223-08 Advocate Health Care IL
ITRC20100223-06 Blue Island Radiology Consultants,
ITRC20100223-05 Private Practice, Stoughton MA
ITRC20100223-04 Cardiology Consultants FL Yes
ITRC20100223-01 Ashley and Gray DDS
ITRC20100222-02 Group Health WA
ITRC20100212-02 University of Texas Medical
ITRC20100209-12 Greensburg Dental Practices PA
ITRC20100209-05 Abbott Medical Optics CA
ITRC20100128-02 University of California -
ITRC20100127-02 University Medical Clinic -
ITRC20100126-09 Methodist Hospital - Texas
ITRC20100126-03 Unknown Dentist TX
ITRC20100113-01 Kaiser HMO CA
ITRC20100105-01 Massachusetts Eye and Ear
Labels:
data breaches; ITRC;2010
Thursday, March 18, 2010
ipsumdump..
It is easy to be fond of professor Eddie Kohler's ipsumdump. Take your monthly egress pcap file and filter it through something like this:
for i in `ipsumdump -s --no-headers $1 | sort -n | uniq`
do echo $i, `./geoip.sh $i | awk '{print $1""$7""$8" "$9""$10""$11}'`
done
( where geoip.sh is geoiplookup -f /usr/local/share/GeoIP/GeoLiteCity.dat $1 )
and what you are quickly returned something like this:
10.10.10.2, GeoIPAddressnot found
12.129.147.95, GeoIPVA,Ashburn, 20147,39.033501,-77.483803,
12.130.131.98, GeoIPCA,San Bruno,94066,37.622799,
12.130.81.249, GeoIPNY,Brooklyn, N/A,40.652500,-73.955399,
12.149.161.248, GeoIPCA,Mountain View,94043,37.419201,
12.25.91.250, GeoIPCT,Stamford, N/A,41.083099,-73.538803,
12.25.93.2, GeoIPNY,Newburgh, 12550,41.537498,-74.051201,
24.123.206.230, GeoIPIN,Lawrenceburg, 47025,39.162300,-84.891098,
24.226.158.219, GeoIPQC,Richmond, N/A,45.666698,-72.150002,
24.43.25.8, GeoIPCA,Los Angeles,N/A,34.041599,
24.43.43.169, GeoIPCA,Los Angeles,N/A,34.041599,
38.103.25.181, GeoIPVA,Alexandria, N/A,38.790901,-77.094704,
38.106.23.79, GeoIPN/A,N/A, N/A,38.000000,-97.000000,
41.208.20.155, GeoIP06,Alberton, N/A,-26.233299,28.133301,
58.19.117.118, GeoIP12,Wuhan, N/A,30.583300,114.266701,
58.215.75.62, GeoIP22,Beijing, N/A,39.928902,116.388298,
59.181.103.140, GeoIP16,Bombay, N/A,18.975000,72.825798,
59.36.98.195, GeoIP30,Dongguan, N/A,23.048901,113.744598,
59.51.114.39, GeoIP11,Changsha, N/A,28.179199,113.113602,
...
for i in `ipsumdump -s --no-headers $1 | sort -n | uniq`
do echo $i, `./geoip.sh $i | awk '{print $1""$7""$8" "$9""$10""$11}'`
done
( where geoip.sh is geoiplookup -f /usr/local/share/GeoIP/GeoLiteCity.dat $1 )
and what you are quickly returned something like this:
10.10.10.2, GeoIPAddressnot found
12.129.147.95, GeoIPVA,Ashburn, 20147,39.033501,-77.483803,
12.130.131.98, GeoIPCA,San Bruno,94066,37.622799,
12.130.81.249, GeoIPNY,Brooklyn, N/A,40.652500,-73.955399,
12.149.161.248, GeoIPCA,Mountain View,94043,37.419201,
12.25.91.250, GeoIPCT,Stamford, N/A,41.083099,-73.538803,
12.25.93.2, GeoIPNY,Newburgh, 12550,41.537498,-74.051201,
24.123.206.230, GeoIPIN,Lawrenceburg, 47025,39.162300,-84.891098,
24.226.158.219, GeoIPQC,Richmond, N/A,45.666698,-72.150002,
24.43.25.8, GeoIPCA,Los Angeles,N/A,34.041599,
24.43.43.169, GeoIPCA,Los Angeles,N/A,34.041599,
38.103.25.181, GeoIPVA,Alexandria, N/A,38.790901,-77.094704,
38.106.23.79, GeoIPN/A,N/A, N/A,38.000000,-97.000000,
41.208.20.155, GeoIP06,Alberton, N/A,-26.233299,28.133301,
58.19.117.118, GeoIP12,Wuhan, N/A,30.583300,114.266701,
58.215.75.62, GeoIP22,Beijing, N/A,39.928902,116.388298,
59.181.103.140, GeoIP16,Bombay, N/A,18.975000,72.825798,
59.36.98.195, GeoIP30,Dongguan, N/A,23.048901,113.744598,
59.51.114.39, GeoIP11,Changsha, N/A,28.179199,113.113602,
...
Labels:
Eddie Kohler; ipsumdump,
GeoIP
Tuesday, March 16, 2010
How the FEDS use social networking...
What type of security risk is social networking? A document obtained by the EFF and posted on Wired's Threat Level blog details how FBI and Secret Service are using social networking sites to obtain information. Here's a sample from the document:
"Overview of Key Social Networking Sites
GETTING INFO FROM FACEBOOK
Data is organized by user ID or group ID
Standard data productions (per LE guide):
Neoprint, Photoprint, User Contact Info, Group Contanct Info, IP Logs
HOWEVER, Facebook has other data available.
Often cooperative with emergency requests."
So glad to hear that FEDS are getting co-operation from Facebook. Think for a moment what this other data might be: your chats? your friend searches? your browsing? I have to wonder what Facebook "IP Logs" look like....
Labels:
Social Networking; EFF;Privacy
Friday, February 26, 2010
Some Thoughts on Computer Defense for Small Business
I have written a paper targeted for small business owners: "Some Thoughts on Computer Defense for Small Business"
"The problem of computer security will continue to increase in intensity in the coming years. Geo-political conflict, an increasing wealth divide between North and South in an increasingly networked world, and increasingly sophisticated threats will challenge the most well prepared specialists to secure your network. The passage of time has only made the following Unix administrator's adage become more true: “There are two kinds of computer users: those who have lost data and those who will.” Which part of that data loss cycle is your destiny?" read more
"The problem of computer security will continue to increase in intensity in the coming years. Geo-political conflict, an increasing wealth divide between North and South in an increasingly networked world, and increasingly sophisticated threats will challenge the most well prepared specialists to secure your network. The passage of time has only made the following Unix administrator's adage become more true: “There are two kinds of computer users: those who have lost data and those who will.” Which part of that data loss cycle is your destiny?" read more
Labels:
Small Business Owners
Wednesday, February 24, 2010
Advanced Persistent Threat IV
SRI's Malware Threat Center has issued version 1.5 of Bot Hunter. Bot Hunter uses a proprietary algorithm with data collection facilities of a customized Snort to determine the botnet communication on Windows hosts and at Unix bastion at the egress of your network. You can review the data it collects from its honey net. Here's a picture of it running on Vista:
Update: 02/27/10 And so I had a 1.10 Score. (Below) Bot Net Hunter reported that a Microsoft IP conducted an outbound scan of 18 IPs. Something to think about...
OUTBOUND SCAN (spp)
207.46.16.248 (2) (20:05:49.902 PST)
event=777:7777005 (2) {udp} E5[bh] Detected moderate malware port scanning of 18 IPs (11 /24s) (# pkts S/M/O/I=0/52/4/0): 137u:52, [] MAC_Src: 00:16:EA:4C:F3:AE
Funny, I had Netmon 3.3 running, but it didn't catch that IP at that time This turned out to be a Microsoft DNS IP:
9:41:51.287 192.168.0.14 80 (0x50) 207.46.16.248 207.46.16.248 msdn.microsoft.akadns.net 00-09-5B-00-F3-DA msdn.microsoft.akadns.net 5599 (0x15DF)
Labels:
Bot Hunter;SRI; APT;
Tuesday, February 16, 2010
Advanced Persistent Threat Part III
It certainly is possible to examine host or network outbound conversations. But we then have to determine which outbound conversations are legitimate. Current AV software attempts to block access to potentially 'known dangerous' or 'pre-determined dangerous' malware sites but such judgements are apparently failing to prevent APT from sending stolen data to weigh stations. On OpenBSD if we are looking at outbound connections, we might sniff as thus using Snort:
/usr/local/bin/snort -D -vdeXX -l . -L `date "+%d%b%H%S%Z%Y.out"` -i dc0 'port not(whois or domain or router) and not(broadcast or arp) and not(dst net 192.168.0.0/24 or 224.0.0.0/24 or 239.0.0.0/8)'
On Vista, we might have two interfaces (wired and wireless) we need to examine:
start /min cmd /c C:\snort\bin\snort.exe -vdeXX -l . -i 1 port not(whois or domain or router or 5353) and not(broadcast or arp) and not(dst net 192.168.0.0/24 or 224.0.0.0/24 or 239.0.0.0/8)
start /min cmd /c C:\snort\bin\snort.exe -vdeXX -l . -i 2 port not(whois or domain or router or 5353) and not(broadcast or arp) and not(dst net 192.168.0.0/24 or 224.0.0.0/24 or 239.0.0.0/8)
We can look at the logs. And we are surprised by the number of outbound connections we make:
C:\Snort\bin>snort -v -q -r snort.log.1266372570 | find "->" | gawk -F"->" '{print $2}' | sort /R | uniq -c | sort /R
327 74.125.103.208:80
133 74.202.67.83:80
105 216.35.221.76:80
100 198.104.200.154:80
51 72.21.91.19:80
32 96.17.70.50:80
....
Perhaps one solution to APT would be some real time co-ordination between sites suspected of being data theft transfer stations and real-time (firewall or host) blocking of the data-transfer to those hosts/servers. This type of solution has some headwind but may need to be implemented on a individual or corporate basis to prevent "incidental blacklisting". Other solutions might include:
(1) real time packet examination of data for critical or sensitive information
(2) heuristic detection of data flows that seems 'abnormal'
(3) heuristic detection of file access that seems 'abnormal'
The industry awaits such solutions.
/usr/local/bin/snort -D -vdeXX -l . -L `date "+%d%b%H%S%Z%Y.out"` -i dc0 'port not(whois or domain or router) and not(broadcast or arp) and not(dst net 192.168.0.0/24 or 224.0.0.0/24 or 239.0.0.0/8)'
On Vista, we might have two interfaces (wired and wireless) we need to examine:
start /min cmd /c C:\snort\bin\snort.exe -vdeXX -l . -i 1 port not(whois or domain or router or 5353) and not(broadcast or arp) and not(dst net 192.168.0.0/24 or 224.0.0.0/24 or 239.0.0.0/8)
start /min cmd /c C:\snort\bin\snort.exe -vdeXX -l . -i 2 port not(whois or domain or router or 5353) and not(broadcast or arp) and not(dst net 192.168.0.0/24 or 224.0.0.0/24 or 239.0.0.0/8)
We can look at the logs. And we are surprised by the number of outbound connections we make:
C:\Snort\bin>snort -v -q -r snort.log.1266372570 | find "->" | gawk -F"->" '{print $2}' | sort /R | uniq -c | sort /R
327 74.125.103.208:80
133 74.202.67.83:80
105 216.35.221.76:80
100 198.104.200.154:80
51 72.21.91.19:80
32 96.17.70.50:80
....
Perhaps one solution to APT would be some real time co-ordination between sites suspected of being data theft transfer stations and real-time (firewall or host) blocking of the data-transfer to those hosts/servers. This type of solution has some headwind but may need to be implemented on a individual or corporate basis to prevent "incidental blacklisting". Other solutions might include:
(1) real time packet examination of data for critical or sensitive information
(2) heuristic detection of data flows that seems 'abnormal'
(3) heuristic detection of file access that seems 'abnormal'
The industry awaits such solutions.
Labels:
APT;Snort;Data Protection
Friday, February 12, 2010
Advanced Persistent Threat Part II
These thoughts occur to me this week in reading the numerous blog posts on APT and the Mandiant Report. Somehow my research made me think of the bane of Othello the Moor ( "Iago" ). Very loosely translated from Latin, "Iago" might mean "I am nothing". Often it is more commonly translated as "supplanter" or "heel grabber".
(1) I don't have a binary, technical threat analysis, disassembled stub, class diagram or detection method for APT.
(2) I don't know any host based security products that would block "illegitimate APT" (outgoing traffic) on ports 80 and 443 from a legitimate user space request. How would developers even implement such a service? If you could trace all events to an un-hijacked input device, you could block any events that are not desktop based. This would probably put updates,software installations,sandbox scripts in a pickle. Therefore, is this a problem in search of a network based solution?
(3) I propose we solve the debate about how "APT style" threats can be distinguished from other threats by
(4) I don't know yet how to prototype or replicate an APT in my lab. Therefore, How do I know it exists outside of the conceptualization of others?
(5) Ten years ago last August I received this comment while working with an IDS developer: "This product will stop the script kiddies and most of the uber-hackers. Then there's the "Men in Black". I have no idea how we stop them."
- "Iago"
(1) I don't have a binary, technical threat analysis, disassembled stub, class diagram or detection method for APT.
(2) I don't know any host based security products that would block "illegitimate APT" (outgoing traffic) on ports 80 and 443 from a legitimate user space request. How would developers even implement such a service? If you could trace all events to an un-hijacked input device, you could block any events that are not desktop based. This would probably put updates,software installations,sandbox scripts in a pickle. Therefore, is this a problem in search of a network based solution?
(3) I propose we solve the debate about how "APT style" threats can be distinguished from other threats by
- (a) ranking the level of resources needed to complete them or
- (b) the level of functional immunity granted their perpetrators
(4) I don't know yet how to prototype or replicate an APT in my lab. Therefore, How do I know it exists outside of the conceptualization of others?
(5) Ten years ago last August I received this comment while working with an IDS developer: "This product will stop the script kiddies and most of the uber-hackers. Then there's the "Men in Black". I have no idea how we stop them."
- "Iago"
Tuesday, February 9, 2010
Advanced Persistent Threat
The news on "Advanced Persistent Threat" has been broken in a big way by Google and the recent Mandiant report. More comments will follow at a later date. But some occur to me now:
(1) Our current desktop and server Operating Systems are not secure.
(2) Computer networks are insecure for most organizations and at many levels.
(3) Digital data can no longer be protected against a determined foe.
(4) Security researchers and visionaries should receive more funding. Lots.
Order and read the Mandiant Report. Then imagine what a resourced foe could do if they believed the security of their nation-state depended upon seemless corporate intrusions. Now imagine those techniques automated and in the wild. In order for the world to have safe computing systems, our government and industry needs to sponsor more research and decriminalize vulnerability research. Otherwise, no data will ever be secret or protected again.
(1) Our current desktop and server Operating Systems are not secure.
(2) Computer networks are insecure for most organizations and at many levels.
(3) Digital data can no longer be protected against a determined foe.
(4) Security researchers and visionaries should receive more funding. Lots.
Order and read the Mandiant Report. Then imagine what a resourced foe could do if they believed the security of their nation-state depended upon seemless corporate intrusions. Now imagine those techniques automated and in the wild. In order for the world to have safe computing systems, our government and industry needs to sponsor more research and decriminalize vulnerability research. Otherwise, no data will ever be secret or protected again.
Labels:
Advanced Persistent Threat;
Monday, February 8, 2010
Defending Against the Small Business Threat
"Do you expect I'm going to solve this? I'm going to take on these Russian thieves? Clearly I'm not going to [be able to] do it." -small business owner defrauded by malware and "money mules"
A great and overdue article in the Wall Street Journal this morning: "Wanted: Defense Against Online Bank Fraud". The article discusses a now popular cyber-crime first popularized in 2008 which is initiated by an online theft/fraud of insecured ATM/payroll data on user/client/small business PCs. Fake payroll members are created and then [recruited] "money mules" cash out fraudulent paychecks from ATM terminals across the globe. If the fraud is timed right, a small business can lose large sums from their payroll accounts within 24 hours or less. The FBI and the IC3 has been warning about this for some time:
Small businesses during a recession make excellent targets. It is a bit like capitalizing on sick children. Large businesses and banks know the value of security infrastructure and development. They have lots to lose and they have been high priority targets in the past. (And they have just received big chunks of "Stimulus funding." ) Most small business employ limited staff, have a few PCs (perhaps running some accounting software), maybe some server or cloud infrastructure investments, and a web site or web/commerce site.
The few aggressive owners/proprietors that investigate securing their infrastructure may have done so on a "self-help" basis - implementing firewalls, UTM, anti-virus, anti-spyware. But even these self-motivated individuals are in no way prepared to be the targets of dedicated information warfare from skilled global criminal enterprises originating in eastern Europe, South America, Russia, China, etc. Thus, in less than 24 hours, small business payroll accounts, many of these derived from 'bridge loans' from local banks, are wiped out. The targeting of small business by cyber-criminals is an "anti-stimulus" effort; functioning to effectively siphon funds from a weakened American economy.
Tuesday, December 15, 2009
Security as Interdepartmental conflict...
I received this message in my hotmail this morning:
Why does Microsoft get dinged for this type of presentation? Why does it happen? On a small scale it was probably because the hotmail Calendar team wasn't talking with the hotmail Security team. But that doesn't answer much. Computer security is still, in almost all industries and architectures, and "add-in". It is overlaid on top of existing products and architectures. The "security guys" are on separate teams, their training is exclusive, their recommendations are "integrated" into existing products. The practice of security never fully integrates into test suites for most product development because it can't be marketed like a popsicle. It is sold as an immunity, a dose of antibiotic, a pill. Compatibility of security architecture with existing product development has ambiguous ownership.
Why does Microsoft get dinged for this type of presentation? Why does it happen? On a small scale it was probably because the hotmail Calendar team wasn't talking with the hotmail Security team. But that doesn't answer much. Computer security is still, in almost all industries and architectures, and "add-in". It is overlaid on top of existing products and architectures. The "security guys" are on separate teams, their training is exclusive, their recommendations are "integrated" into existing products. The practice of security never fully integrates into test suites for most product development because it can't be marketed like a popsicle. It is sold as an immunity, a dose of antibiotic, a pill. Compatibility of security architecture with existing product development has ambiguous ownership.
Labels:
Security;Hotmail;Microsoft
Saturday, December 5, 2009
Cell Tracking
This is the link to an absolutely extraordinary post on privacy by Christopher Soghoian:
http://paranoia.dubfire.net/2009/12/8-million-reasons-for-real-surveillance.html . Mr. Soghoian's post describes the evolution of "Cell Tracking", an issue the EFF has discussed for a number of years at http://www.eff.org/issues/cell-tracking. An exceptional video on current status of the law for "cell tracking" and "mobility tracking" can be found here: http://www.youtube.com/watch?v=YFo2VcfWCBQ&feature=channel/
The information reminds me that the OS inside most cell-phones is a literal "black box". Because I run midpssh, I can usually find cell's IP address in the netstat tables of my SSH Server. I can see there may be some filtered ports on my phone. But I cannot:
(1) access a console or ssh prompt
(2) run a network sniffer or IDS on my cell phone to see if someone is "pinging" my location or hacking me.
Your cell phone is a tracking device that forbids you from root access.
http://paranoia.dubfire.net/2009/12/8-million-reasons-for-real-surveillance.html . Mr. Soghoian's post describes the evolution of "Cell Tracking", an issue the EFF has discussed for a number of years at http://www.eff.org/issues/cell-tracking. An exceptional video on current status of the law for "cell tracking" and "mobility tracking" can be found here: http://www.youtube.com/watch?v=YFo2VcfWCBQ&feature=channel/
The information reminds me that the OS inside most cell-phones is a literal "black box". Because I run midpssh, I can usually find cell's IP address in the netstat tables of my SSH Server. I can see there may be some filtered ports on my phone. But I cannot:
(1) access a console or ssh prompt
(2) run a network sniffer or IDS on my cell phone to see if someone is "pinging" my location or hacking me.
Your cell phone is a tracking device that forbids you from root access.
Labels:
Cell Tracking
Monday, November 30, 2009
"The specified uptodateness vector is corrupt."
I haven't posted in awhile. Time to get back into the swing of things with a little pre-Christmas Season silliness. Occasionally, the practice of network security makes us all a little goofy. Seemingly random pursuits overtake us. Silly thoughts fill our console. Perhaps this is a result of low light in the northern latitudes this time of year...In any event, should use wish to query all of the messages available in the "net helpmsg" file on Windows Vista, you can run a command like this:
for /l %i in (1,1,16000) do @( echo %i && net helpmsg %i ) 2>NUL
This will give a formatted output of every existing net help msg and all numbers that are not so.. Keep in mind that there are most probably less than 5000 of these messages, however they are numbered somewhat inconsistently in the sequence between 1 - 16,000. With cygwin or GNUWin32 utilities loaded you could add:
for /l %i in (1,1,16000) do @( echo %i && net helpmsg %i ) 2>NUL | egrep -B 2 -i [a-z] | tr -d /-/- | tr -d \r
This would produce a long list of only those numbers with messages and, after some substantial period of time and processor use, would yield some very interesting reading. Here are a few of my favorites:
581
A Windows Server has an incorrect configuration.
593
NTVDM encountered a hard error.
597
The parameter(s) passed to the server in the clientserver shared memory window were invalid. Too much data may have been put in the shared memory window.
598
The stream is not a tiny stream.
611
There is an IP address conflict with another system on the network
612
There is an IP address conflict with another system on the network
615
The policy of your user account does not allow you to change passwords too frequently.
This is done to prevent users from changing back to a familiar, but potentially discovered, password.
If you feel your password has been compromised then please contact your administrator immediately to have a new one assigned.
617
You have attempted to change your password to one that you have used in the past.
The policy of your user account does not allow this. Please select a password that you have not previously used.
629
A group marked use for deny only cannot be enabled.
670
WOW Assertion Error.
677
{Too Much Information}
The specified access control list (ACL) contained more information than was expected.
678
This warning level status indicates that the transaction state already exists for the registry subtree, but that a transaction commit was previously aborted.
The commit has NOT been completed, but has not been rolled back either (so it may still be committed if desired).
680
{GUID Substitution}
During the translation of a global identifier (GUID) to a Windows security ID (SID), no administrativelydefined GUID prefix was found.
A substitute prefix was used, which will not compromise system security. However, this may provide a more restrictive access than intended.
704
{Redundant Read}
To satisfy a read request, the NT faulttolerant file system successfully read the requested data from a redundant copy.
This was done because the file system encountered a failure on a member of the faulttolerant volume, but was unable to reassign the failing area of the device.
705
{Redundant Write}
To satisfy a write request, the NT faulttolerant file system successfully wrote a redundant copy of the information.
This was done because the file system encountered a failure on a member of the faulttolerant volume, but was not able to reassign the failing area of the device.
730
The system has awoken
746
{Connect Failure on Primary Transport}
An attempt was made to connect to the remote server hs on the primary transport, but the connection failed.
The computer WAS able to connect on a secondary transport.
1265
The system detected a possible attempt to compromise security. Please ensure that you can contact the server that authenticated you.
1274
The group policy framework should call the extension in the synchronous foreground policy refresh.
1282
The system detected an overrun of a stackbased buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
1292
An operation attempted to exceed an implementationdefined limit.
1349
The type of the token is inappropriate for its attempted use.
1350
Unable to perform a security operation on an object that has no associated security.
1353
The domain was in the wrong state to perform the security operation.
1370
An internal security database corruption has been encountered.
1384
During a logon attempt, the user's security context accumulated too many security IDs.
2228
There are too many names in the user accounts database.
2385
The Run server you requested is paused.
2431
The alert table is full.
3013
The printer driver is known to be unreliable.
3014
The printer driver is known to harm the system.
3029
Local security could not be started because the user accounts database
(NET.ACC) was missing or corrupted, and no usable backup
database was present.
THE SYSTEM IS NOT SECURE.
3060
The service did not respond to control and was stopped with
the DosKillProc function.
3194
Hanging up a stuck session to ***.
3413
Your logon time at *** ends at ***.
Please clean up and log off.
3513
More data is available than can be returned by Windows.
3950
Reissue the given operation as a cached IO operation
4006
Replication with a nonconfigured partner is not allowed.
6628
Log space is exhausted.
6730
The transaction does not have a superior enlistment.
8606
Insufficient attributes were given to create an object. This object may not exist because it may have been deleted and already garbage collected.
8629
The specified uptodateness vector is corrupt.
8630
The request to replicate secrets is denied.
10038
An operation was attempted on something that is not a socket.
10059
Too many references to some kernel object.
10107
A system call that should never fail has failed.
11007
There are no senders.
11008
There are no receivers.
15250
The requested system device cannot be identified due to multiple indistinguishable devices potentially matching the identification criteria.
for /l %i in (1,1,16000) do @( echo %i && net helpmsg %i ) 2>NUL
This will give a formatted output of every existing net help msg and all numbers that are not so.. Keep in mind that there are most probably less than 5000 of these messages, however they are numbered somewhat inconsistently in the sequence between 1 - 16,000. With cygwin or GNUWin32 utilities loaded you could add:
for /l %i in (1,1,16000) do @( echo %i && net helpmsg %i ) 2>NUL | egrep -B 2 -i [a-z] | tr -d /-/- | tr -d \r
This would produce a long list of only those numbers with messages and, after some substantial period of time and processor use, would yield some very interesting reading. Here are a few of my favorites:
581
A Windows Server has an incorrect configuration.
593
NTVDM encountered a hard error.
597
The parameter(s) passed to the server in the clientserver shared memory window were invalid. Too much data may have been put in the shared memory window.
598
The stream is not a tiny stream.
611
There is an IP address conflict with another system on the network
612
There is an IP address conflict with another system on the network
615
The policy of your user account does not allow you to change passwords too frequently.
This is done to prevent users from changing back to a familiar, but potentially discovered, password.
If you feel your password has been compromised then please contact your administrator immediately to have a new one assigned.
617
You have attempted to change your password to one that you have used in the past.
The policy of your user account does not allow this. Please select a password that you have not previously used.
629
A group marked use for deny only cannot be enabled.
670
WOW Assertion Error.
677
{Too Much Information}
The specified access control list (ACL) contained more information than was expected.
678
This warning level status indicates that the transaction state already exists for the registry subtree, but that a transaction commit was previously aborted.
The commit has NOT been completed, but has not been rolled back either (so it may still be committed if desired).
680
{GUID Substitution}
During the translation of a global identifier (GUID) to a Windows security ID (SID), no administrativelydefined GUID prefix was found.
A substitute prefix was used, which will not compromise system security. However, this may provide a more restrictive access than intended.
704
{Redundant Read}
To satisfy a read request, the NT faulttolerant file system successfully read the requested data from a redundant copy.
This was done because the file system encountered a failure on a member of the faulttolerant volume, but was unable to reassign the failing area of the device.
705
{Redundant Write}
To satisfy a write request, the NT faulttolerant file system successfully wrote a redundant copy of the information.
This was done because the file system encountered a failure on a member of the faulttolerant volume, but was not able to reassign the failing area of the device.
730
The system has awoken
746
{Connect Failure on Primary Transport}
An attempt was made to connect to the remote server hs on the primary transport, but the connection failed.
The computer WAS able to connect on a secondary transport.
1265
The system detected a possible attempt to compromise security. Please ensure that you can contact the server that authenticated you.
1274
The group policy framework should call the extension in the synchronous foreground policy refresh.
1282
The system detected an overrun of a stackbased buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.
1292
An operation attempted to exceed an implementationdefined limit.
1349
The type of the token is inappropriate for its attempted use.
1350
Unable to perform a security operation on an object that has no associated security.
1353
The domain was in the wrong state to perform the security operation.
1370
An internal security database corruption has been encountered.
1384
During a logon attempt, the user's security context accumulated too many security IDs.
2228
There are too many names in the user accounts database.
2385
The Run server you requested is paused.
2431
The alert table is full.
3013
The printer driver is known to be unreliable.
3014
The printer driver is known to harm the system.
3029
Local security could not be started because the user accounts database
(NET.ACC) was missing or corrupted, and no usable backup
database was present.
THE SYSTEM IS NOT SECURE.
3060
The service did not respond to control and was stopped with
the DosKillProc function.
3194
Hanging up a stuck session to ***.
3413
Your logon time at *** ends at ***.
Please clean up and log off.
3513
More data is available than can be returned by Windows.
3950
Reissue the given operation as a cached IO operation
4006
Replication with a nonconfigured partner is not allowed.
6628
Log space is exhausted.
6730
The transaction does not have a superior enlistment.
8606
Insufficient attributes were given to create an object. This object may not exist because it may have been deleted and already garbage collected.
8629
The specified uptodateness vector is corrupt.
8630
The request to replicate secrets is denied.
10038
An operation was attempted on something that is not a socket.
10059
Too many references to some kernel object.
10107
A system call that should never fail has failed.
11007
There are no senders.
11008
There are no receivers.
15250
The requested system device cannot be identified due to multiple indistinguishable devices potentially matching the identification criteria.
Subscribe to:
Posts (Atom)


