<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.yobi.be/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=213.219.144.246</id>
	<title>YobiWiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.yobi.be/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=213.219.144.246"/>
	<link rel="alternate" type="text/html" href="https://wiki.yobi.be/index.php?title=Special:Contributions/213.219.144.246"/>
	<updated>2026-04-30T19:19:38Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.8</generator>
	<entry>
		<id>https://wiki.yobi.be/index.php?title=Forensics_on_Incident_2&amp;diff=2188</id>
		<title>Forensics on Incident 2</title>
		<link rel="alternate" type="text/html" href="https://wiki.yobi.be/index.php?title=Forensics_on_Incident_2&amp;diff=2188"/>
		<updated>2007-05-15T09:20:48Z</updated>

		<summary type="html">&lt;p&gt;213.219.144.246: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Breach in j.b.i. @ y.i==&lt;br /&gt;
===Analysis===&lt;br /&gt;
Initial report: one defaced page http://vserverX/eshare/catalog redirecting to http: // www . test . we-create . org&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
Note that if redirection works apparently with IE it didn&#039;t work with iceweasel, I could just see the attempt of redirection in the source of the page: &lt;br /&gt;
&amp;lt;script&amp;gt; window.location=\&amp;quot;http: // www . test . we-create . org/\&amp;quot;; &amp;lt;/script&amp;gt;&lt;br /&gt;
&lt;br /&gt;
# On host: &lt;br /&gt;
apt-get install tct sleuthkit&lt;br /&gt;
&lt;br /&gt;
# Isolate the vserverX&lt;br /&gt;
iptables -I INPUT -d &amp;lt;ip_of_vserverX&amp;gt; -j DROP&lt;br /&gt;
&lt;br /&gt;
# Grep mactimes before touching the system&lt;br /&gt;
grave-robber -o LINUX2 -c /path/to/vserverX/ -b ./vserverX -m &lt;br /&gt;
# mactime from one week ago till now&lt;br /&gt;
mactime -b vserverX -p /path/to/vserverX/etc/passwd mm/dd/yyyy |tee vserverX.mactime&lt;br /&gt;
# apparently mactime could work directly on live system with -d ...&lt;br /&gt;
&lt;br /&gt;
# Search string we-create in /var/www and /var/lib/mysql:&lt;br /&gt;
/var/lib/mysql/oscommerce/configuration.MYD&lt;br /&gt;
&lt;br /&gt;
# Extract corresponding sql table:&lt;br /&gt;
vserverX:/# mysqldump -uuserX -p  --opt oscommerce &amp;gt; oscommerce.sql&lt;br /&gt;
&lt;br /&gt;
# Analyse sql dump:&lt;br /&gt;
INSERT INTO `configuration` VALUES (1,&#039;Store Name&#039;,&#039;STORE_NAME&#039;,&#039;&amp;lt;script&amp;gt; window.location=\&amp;quot;http: // www . test . we-create . org/\&amp;quot;; &amp;lt;/script&amp;gt;&#039;,&#039;The name of my store&#039;,1,1,&#039;2007-05-11 21:04:30&#039;,&#039;2006-12-22 09:32:15&#039;,NULL,NULL)...&lt;br /&gt;
&lt;br /&gt;
# This is the modification apparent on the defaced page, done at &#039;2007-05-11 21:04:30&#039;&lt;br /&gt;
# note that there were other defacing attempts here:&lt;br /&gt;
INSERT INTO `categories_description` VALUES (...&lt;br /&gt;
   ,(25,4,&#039;&amp;lt;script&amp;gt; window.location=\&amp;quot;http:/&#039;)                                                                                                                               &lt;br /&gt;
   ,(25,2,&#039;&amp;lt;script&amp;gt; window.location=\&amp;quot;http:/&#039;)                                                                                                                               &lt;br /&gt;
&lt;br /&gt;
# extract infos around that time from mactime dump:&lt;br /&gt;
May 11 07 21:04:30    25168 m.c -rw-rw---- mysql    munin    /path/to/vserverX/var/lib/mysql/oscommerce/configuration.MYD                                           &lt;br /&gt;
# this is the defacing itself&lt;br /&gt;
May 11 07 21:12:15     3480 m.c drwxrwxrwx root     root     /path/to/vserverX/var/www/eshop/catalog/images                                                         &lt;br /&gt;
                       4396 mac -rwxrwxrwx www-data www-data /path/to/vserverX/var/www/eshop/catalog/images/images.jpg                                              &lt;br /&gt;
# upload of a &amp;quot;we hacked you&amp;quot; image&lt;br /&gt;
                       1164 m.c -rw-rw---- mysql    munin    /path/to/vserverX/var/lib/mysql/oscommerce/categories.MYD                                              &lt;br /&gt;
                       2508 m.c -rw-rw---- mysql    munin    /path/to/vserverX/var/lib/mysql/oscommerce/categories_description.MYD                                  &lt;br /&gt;
# this is the second attempt of defacing of the categories&lt;br /&gt;
&lt;br /&gt;
# extract infos around that time from apache logs (logs cleaned from .js and .gif urls)&lt;br /&gt;
# hacker client: &amp;quot;Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)&amp;quot;&lt;br /&gt;
85.105.88.202 - - [11/May/2007:20:55:14 +0200] &amp;quot;GET /eshop/catalog/admin/backup.php?action=restorelocal HTTP/1.1&amp;quot; 200 13939 &amp;quot;http://www.google.com.tr/search?q=inurl:catalog/admin/backup.php&amp;amp;hl=tr&amp;amp;start=40&amp;amp;sa=N&amp;amp;filter=0&amp;quot;&lt;br /&gt;
85.105.88.202 - - [11/May/2007:20:55:58 +0200] &amp;quot;GET /eshop/catalog/admin/backup.php?selected_box=tools&amp;amp;osCAdminID=5340c42e400b2a4aa53923c19fa5ede2 HTTP/1.1&amp;quot; 200 10648 &amp;quot;http://vserverX/eshop/catalog/admin/backup.php?action=restorelocal&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:07 +0200] &amp;quot;GET /eshop/catalog/admin/define_language.php HTTP/1.1&amp;quot; 200 18713 &amp;quot;http://vserverX/eshop/catalog/admin/backup.php?selected_box=tools&amp;amp;osCAdminID=5340c42e400b2a4aa53923c19fa5ede2&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:11 +0200] &amp;quot;GET /eshop/catalog/admin/define_language.php?lngdir=french&amp;amp;filename=index.php HTTP/1.1&amp;quot; 200 15345 &amp;quot;http://vserverX/eshop/catalog/admin/define_language.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:13 +0200] &amp;quot;GET /eshop/catalog/admin/define_language.php?lngdir=french HTTP/1.1&amp;quot; 200 18713 &amp;quot;http://vserverX/eshop/catalog/admin/define_language.php?lngdir=french&amp;amp;filename=index.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:16 +0200] &amp;quot;GET /eshop/catalog/admin/configuration.php?gID=1&amp;amp;selected_box=configuration HTTP/1.1&amp;quot; 200 22252 &amp;quot;http://vserverX/eshop/catalog/admin/define_language.php?lngdir=french&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:22 +0200] &amp;quot;GET /eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=edit HTTP/1.1&amp;quot; 200 22550 &amp;quot;http://vserverX/eshop/catalog/admin/configuration.php?gID=1&amp;amp;selected_box=configuration&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:29 +0200] &amp;quot;POST /eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=save HTTP/1.1&amp;quot; 302 - &amp;quot;http://vserverX/eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=edit&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:30 +0200] &amp;quot;GET /eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1 HTTP/1.1&amp;quot; 200 22329 &amp;quot;http://vserverX/eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=edit&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:30 +0200] &amp;quot;POST /eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=save HTTP/1.1&amp;quot; 302 - &amp;quot;http://vserverX/eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=edit&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:30 +0200] &amp;quot;GET /eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1 HTTP/1.1&amp;quot; 200 22329 &amp;quot;http://vserverX/eshop/catalog/admin/configuration.php?gID=1&amp;amp;cID=1&amp;amp;action=edit&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:04:47 +0200] &amp;quot;GET /eshop/catalog/ HTTP/1.1&amp;quot; 200 22419 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:05 +0200] &amp;quot;GET /eshop/catalog/ HTTP/1.1&amp;quot; 200 22419 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:28 +0200] &amp;quot;GET /eshop/catalog/admin HTTP/1.1&amp;quot; 301 375 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:29 +0200] &amp;quot;GET /eshop/catalog/admin/ HTTP/1.1&amp;quot; 200 17760 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:40 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?selected_box=tools&amp;amp;osCAdminID=7f009d2bed82fc3c7c9da8f616307e6a HTTP/1.1&amp;quot; 200 109384 &amp;quot;http://vserverX/eshop/catalog/admin/&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:46 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?info=index.php HTTP/1.1&amp;quot; 200 109692 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:49 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?info=index.php&amp;amp;action=edit HTTP/1.1&amp;quot; 200 33371 &amp;quot;http://vserverX/eshop/catalog/admin/file_manager.php?info=index.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:52 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?info=index.php HTTP/1.1&amp;quot; 200 109692 &amp;quot;http://vserverX/eshop/catalog/admin/file_manager.php?info=index.php&amp;amp;action=edit&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:05:55 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?info=index.php&amp;amp;action=new_file HTTP/1.1&amp;quot; 200 110032 &amp;quot;http://vserverX/eshop/catalog/admin/file_manager.php?info=index.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:11:49 +0200] &amp;quot;GET /eshop/catalog/admin/categories.php?selected_box=catalog HTTP/1.1&amp;quot; 200 14826 &amp;quot;http://vserverX/eshop/catalog/admin/file_manager.php?info=index.php&amp;amp;action=new_file&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:11:51 +0200] &amp;quot;GET /eshop/catalog/admin/categories.php?cPath=&amp;amp;cID=25&amp;amp;action=edit_category HTTP/1.1&amp;quot; 200 15717 &amp;quot;http://vserverX/eshop/catalog/admin/categories.php?selected_box=catalog&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:11:52 +0200] &amp;quot;GET /eshop/catalog/images/homepic4.jpg HTTP/1.1&amp;quot; 404 354 &amp;quot;http://vserverX/eshop/catalog/admin/categories.php?cPath=&amp;amp;cID=25&amp;amp;action=edit_category&amp;quot; &lt;br /&gt;
[Fri May 11 21:11:52 2007] [error] [client 85.105.88.202] File does not exist: /var/www/eshop/catalog/images/homepic4.jpg, referer: http://vserverX/eshop/catalog/admin/categories.php?cPath=&amp;amp;cID=25&amp;amp;action=edit_category&lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:12:15 +0200] &amp;quot;POST /eshop/catalog/admin/categories.php?action=update_category&amp;amp;cPath= HTTP/1.1&amp;quot; 200 1872 &amp;quot;http://vserverX/eshop/catalog/admin/categories.php?cPath=&amp;amp;cID=25&amp;amp;action=edit_category&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:12:32 +0200] &amp;quot;GET /eshop/catalog HTTP/1.1&amp;quot; 301 369 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:12:37 +0200] &amp;quot;GET /eshop/catalog/ HTTP/1.1&amp;quot; 200 22419 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [11/May/2007:21:12:53 +0200] &amp;quot;GET /eshop/ HTTP/1.1&amp;quot; 200 2268 &amp;quot;-&amp;quot; &lt;br /&gt;
&lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:42:13 +0200] &amp;quot;GET /eshop/catalog/admin/backup.php?action=restorelocal HTTP/1.1&amp;quot; 200 13939 &amp;quot;http://www.google.com.tr/search?q=inurl:catalog/admin/backup.php&amp;amp;hl=tr&amp;amp;start=30&amp;amp;sa=N&amp;amp;filter=0&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:42:45 +0200] &amp;quot;GET /eshop/catalog/admin/backup.php?selected_box=tools&amp;amp;osCAdminID=06f47581056b54ad6735566d29bdd3f2 HTTP/1.1&amp;quot; 200 10648 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:42:47 +0200] &amp;quot;GET /eshop/catalog/admin/define_language.php HTTP/1.1&amp;quot; 200 18713 &amp;quot;http://vserverX/eshop/catalog/admin/backup.php?selected_box=tools&amp;amp;osCAdminID=06f47581056b54ad6735566d29bdd3f2&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:42:51 +0200] &amp;quot;GET /eshop/catalog/admin/define_language.php?lngdir=french&amp;amp;filename=index.php HTTP/1.1&amp;quot; 200 15345 &amp;quot;http://vserverX/eshop/catalog/admin/define_language.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:42:53 +0200] &amp;quot;GET /eshop/catalog/admin/configuration.php?gID=1&amp;amp;selected_box=configuration HTTP/1.1&amp;quot; 200 22329 &amp;quot;http://vserverX/eshop/catalog/admin/define_language.php?lngdir=french&amp;amp;filename=index.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:42:53 +0200] &amp;quot;GET /eshop/catalog/admin/configuration.php?gID=1&amp;amp;selected_box=configuration HTTP/1.1&amp;quot; 200 8152 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:06 +0200] &amp;quot;GET /eshop/ HTTP/1.1&amp;quot; 200 2268 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:09 +0200] &amp;quot;GET /eshop/catalog/ HTTP/1.1&amp;quot; 200 22419 &amp;quot;http://vserverX/eshop/&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:17 +0200] &amp;quot;GET /eshop/catalog/admin HTTP/1.1&amp;quot; 301 375 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:17 +0200] &amp;quot;GET /eshop/catalog/admin/ HTTP/1.1&amp;quot; 200 16044 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:20 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?selected_box=tools HTTP/1.1&amp;quot; 200 109384 &amp;quot;http://vserverX/eshop/catalog/admin/&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:37 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?info=index.php HTTP/1.1&amp;quot; 200 109692 &amp;quot;-&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:45 +0200] &amp;quot;GET /eshop/catalog/admin/file_manager.php?info=index.php&amp;amp;action=edit HTTP/1.1&amp;quot; 200 33371 &amp;quot;http://vserverX/eshop/catalog/admin/file_manager.php?info=index.php&amp;quot; &lt;br /&gt;
85.105.88.202 - - [12/May/2007:21:43:57 +0200] &amp;quot;GET /admin HTTP/1.1&amp;quot; 404 326 &amp;quot;-&amp;quot; &lt;br /&gt;
[Sat May 12 21:43:57 2007] [error] [client 85.105.88.202] File does not exist: /var/www/admin&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Conclusions===&lt;br /&gt;
* Initial breach&lt;br /&gt;
** attack came from 85.105.88.202 = dsl.static.85-105-22730.ttnet.net.tr (Turkish ADSL)&lt;br /&gt;
** this site was found initially by a simple google search (Google Turkey!) for &amp;quot;catalog/admin/backup.php&amp;quot;&amp;lt;br&amp;gt;easy was to find unprotected oscommerce websites...&amp;lt;br&amp;gt;I visit another one from the Google list: http: // oscommerce . uksz . net/catalog/admin/&amp;lt;br&amp;gt;and surprise, Store Name = window.location=&amp;quot;http: // www . test . we-create . org/&amp;quot;;&amp;lt;br&amp;gt;no comment!&lt;br /&gt;
** eshare was defaced via eshop, simply both were sharing the same DB&lt;br /&gt;
* Counter-measures&lt;br /&gt;
** Protect access to catalog/admin&amp;lt;br&amp;gt;This was done but only for https, default conf with Apache was still AllowOverride None for http connections&lt;/div&gt;</summary>
		<author><name>213.219.144.246</name></author>
	</entry>
	<entry>
		<id>https://wiki.yobi.be/index.php?title=Table_of_contents&amp;diff=2187</id>
		<title>Table of contents</title>
		<link rel="alternate" type="text/html" href="https://wiki.yobi.be/index.php?title=Table_of_contents&amp;diff=2187"/>
		<updated>2007-05-15T08:43:09Z</updated>

		<summary type="html">&lt;p&gt;213.219.144.246: /* Security */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Note that I still have many pages to import from my [http://wiki.teuwen.org/TriPages old wiki]&lt;br /&gt;
==Security==&lt;br /&gt;
* [[Security Resources]]&lt;br /&gt;
* [[Forensics]]&lt;br /&gt;
** [[Forensics on Incident 1]]&lt;br /&gt;
** [[Forensics on Incident 2]]&lt;br /&gt;
* [[Network security tools]]&lt;br /&gt;
* [[Wi-Fi Protected Setup]]&lt;br /&gt;
* [[Bypass Proxy]]&lt;br /&gt;
** [[Bypass Proxy reference]]&lt;br /&gt;
* [[MiscCrypto]]&lt;br /&gt;
** [[Encfs]]&lt;br /&gt;
** [[LoopCrypt]]&lt;br /&gt;
* [[Belgian eGov]]&lt;br /&gt;
* [[MetaSploit Framework]]&lt;br /&gt;
* Specific attacks&lt;br /&gt;
** [[Reverse Cross-Site Request (RCSR) vulnerability]]&lt;br /&gt;
** [[Code Red]]&lt;br /&gt;
* [[Fuzzing]]&lt;br /&gt;
&lt;br /&gt;
==Hobbies==&lt;br /&gt;
* [[Photo]]&lt;br /&gt;
* [[Linux Certification]]&lt;br /&gt;
* [[Diving]]&lt;br /&gt;
&lt;br /&gt;
==Hardware==&lt;br /&gt;
* [[bttv]]&lt;br /&gt;
* [[Canon EOS]]&lt;br /&gt;
* [[Kiss 450]]&lt;br /&gt;
* [[Laptop Asus]]&lt;br /&gt;
* [[Laptop Dell Latitude D600]]&lt;br /&gt;
* [[Laptop Dell Latitude D610]]&lt;br /&gt;
* [[Photo Frame]]&lt;br /&gt;
* [[Philips Webcam]]&lt;br /&gt;
* [[Sony Handycam]]&lt;br /&gt;
* [[Amd64]]&lt;br /&gt;
* [[Tux Droid]]&lt;br /&gt;
* [[NSLU2]]&lt;br /&gt;
&lt;br /&gt;
==Software==&lt;br /&gt;
===Server side===&lt;br /&gt;
* [[Syslog]]&lt;br /&gt;
* [[Munin]]&lt;br /&gt;
* [[Apache]]&lt;br /&gt;
* [[AWFFull]]&lt;br /&gt;
* [[GeoIP]]&lt;br /&gt;
* [[Mysql]]&lt;br /&gt;
* [[Oracle]]&lt;br /&gt;
* [[CVS and Subversion]]&lt;br /&gt;
* [[MediaWiki]]&lt;br /&gt;
* [[Gallery]]&lt;br /&gt;
* [[PhpMyAdmin]]&lt;br /&gt;
* [[Webcalendar]]&lt;br /&gt;
* [[Avimanager]]&lt;br /&gt;
* [[Distributed Library Project]]&lt;br /&gt;
* [[Zope]]&lt;br /&gt;
* [[Plone]]&lt;br /&gt;
* [[Alert notifications]]&lt;br /&gt;
* [[Serial Login]]&lt;br /&gt;
* [[Virtual Private Networks]]&lt;br /&gt;
* [[BackupPc]]&lt;br /&gt;
====Mail services====&lt;br /&gt;
* [[qmail &amp;amp; ezmlm]]&lt;br /&gt;
* [[Exim]]&lt;br /&gt;
* [[Courier]]&lt;br /&gt;
* [[Procmail]]&lt;br /&gt;
* [[Imapproxy]]&lt;br /&gt;
* [[Squirrelmail]]&lt;br /&gt;
* [[Spamassassin]]&lt;br /&gt;
* [[Fetchmail]]&lt;br /&gt;
* [[Anti-Virus]]&lt;br /&gt;
====Syslog services====&lt;br /&gt;
* [[Syslog]]&lt;br /&gt;
* [[Logcheck]]&lt;br /&gt;
* [[Php-Syslog-ng]]&lt;br /&gt;
====Jabber====&lt;br /&gt;
* [[Jabberd]]&lt;br /&gt;
* [[Jabberd-Addons]]&lt;br /&gt;
* [[Jabberd-Conference]]&lt;br /&gt;
* [[Jabberd-Jud]]&lt;br /&gt;
* [[Jabberd-AIM]]&lt;br /&gt;
* [[Jabberd-Icq]]&lt;br /&gt;
* [[Jabberd-Irc]]&lt;br /&gt;
* [[Jabberd-MSN]]&lt;br /&gt;
* [[Jabberd-Yahoo]]&lt;br /&gt;
* [[RSS2Jabber]]&lt;br /&gt;
&lt;br /&gt;
====vserver====&lt;br /&gt;
* [[Vserver administration]]&lt;br /&gt;
* [[Vserver watchdogs]]&lt;br /&gt;
* [[Vserver tools]]&lt;br /&gt;
&lt;br /&gt;
====misc====&lt;br /&gt;
* [[Search engines]]&lt;br /&gt;
&lt;br /&gt;
===Desktop side===&lt;br /&gt;
* [[Dict Applications]]&lt;br /&gt;
* [[Screen Tips]]&lt;br /&gt;
* [[Firefox Tips]]&lt;br /&gt;
* [[Bash Tips]]&lt;br /&gt;
* [[Mail Tips]]&lt;br /&gt;
* [[Offlineimap]]&lt;br /&gt;
* [[IceWM]]&lt;br /&gt;
* [[CD &amp;amp; DVD Burning]]&lt;br /&gt;
* [[VoIP]]&lt;br /&gt;
====[[Jabber]]====&lt;br /&gt;
* [[Jabber Clients]]&lt;br /&gt;
* [[Jabber Send Message]]&lt;br /&gt;
* [[Jabber Utils]]&lt;br /&gt;
&lt;br /&gt;
===Debian===&lt;br /&gt;
* [[Debian Documentation]]&lt;br /&gt;
* [[Debian Commands]]&lt;br /&gt;
* [[DebTags]]&lt;br /&gt;
* [[Debian Alsa]]&lt;br /&gt;
* [[Debian Kernel]]&lt;br /&gt;
* [[Debian Soft Raid]]&lt;br /&gt;
* [[Debian on Amd64]]&lt;br /&gt;
* [[My Debian Bugreports]]&lt;br /&gt;
* [[Debian Tricks]]&lt;br /&gt;
&lt;br /&gt;
===Development===&lt;br /&gt;
* [[oprofile]]&lt;br /&gt;
* [[Customizing Knoppix]]&lt;br /&gt;
* [[Multi-CD USB stick]]&lt;br /&gt;
* [[Online PDF Viewer]]&lt;br /&gt;
* [[Wi-Fi Protected Setup]]&lt;br /&gt;
* [[USB]]&lt;br /&gt;
* [[WeekEndBootstrappers]]&lt;br /&gt;
&lt;br /&gt;
==Lifeware==&lt;br /&gt;
* [[whoami]]&lt;br /&gt;
* [[Généalogie]]&lt;br /&gt;
* [[Bébé]]&lt;br /&gt;
* [[Chassis Couronne]]&lt;br /&gt;
* [[Prêts et emprunts]]&lt;br /&gt;
* [[Brevets]]&lt;br /&gt;
* [[Site de prêts]]&lt;br /&gt;
* [[Vacances]]&lt;br /&gt;
&lt;br /&gt;
==Misc==&lt;br /&gt;
* [[External links]]&lt;br /&gt;
* [[Telephony]]&lt;/div&gt;</summary>
		<author><name>213.219.144.246</name></author>
	</entry>
	<entry>
		<id>https://wiki.yobi.be/index.php?title=Forensics&amp;diff=2186</id>
		<title>Forensics</title>
		<link rel="alternate" type="text/html" href="https://wiki.yobi.be/index.php?title=Forensics&amp;diff=2186"/>
		<updated>2007-05-15T08:41:25Z</updated>

		<summary type="html">&lt;p&gt;213.219.144.246: /* Generic forensic tools */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Books ==&lt;br /&gt;
* [http://www.porcupine.org/forensics/forensic-discovery/ Forensics Discovery]&lt;br /&gt;
== Links ==&lt;br /&gt;
&lt;br /&gt;
* http://www.d-fence.be and http://www.lnx4n6.be&lt;br /&gt;
** Among others the excellent FCCU GNU/Linux Forensic Boot CD, based on Knoppix&lt;br /&gt;
* [http://www.foo.be/gt/forensic/ Présentation d&#039;adulau]&lt;br /&gt;
* http://cve.mitre.org&lt;br /&gt;
* http://www.porcupine.org (Wieste Venema/TCT)&lt;br /&gt;
* [http://public.afosi.amc.af.mil U.S AirForce Office of Special Investigations]&lt;br /&gt;
* http://www.forensicswiki.org&lt;br /&gt;
&lt;br /&gt;
== Lists ==&lt;br /&gt;
&lt;br /&gt;
* http://groups.yahoo.com/group/linux_forensics/&lt;br /&gt;
&lt;br /&gt;
== Tools ==&lt;br /&gt;
&lt;br /&gt;
=== Generic forensic tools ===&lt;br /&gt;
* &#039;&#039;&#039;[http://www.porcupine.org/forensics/tct.html The Coroner Toolkit]&#039;&#039;&#039;&lt;br /&gt;
** apt-get install tct&lt;br /&gt;
** &#039;&#039;&#039;grave-robber&#039;&#039;&#039;: collecte d&#039;infos et empreinte -&amp;gt; /var/cache/tct/data&lt;br /&gt;
** &#039;&#039;&#039;lazarus&#039;&#039;&#039;: reconstitue les fichiers présents dans les clusters non référencés&lt;br /&gt;
** &#039;&#039;&#039;mactime&#039;&#039;&#039;: liste les fichiers dont le mactime a été modifié depuis une certaine date&lt;br /&gt;
* &#039;&#039;&#039;[http://sleuthkit.sourceforge.net/sleuthkit/index.php Sleuthkit]&#039;&#039;&#039; &amp;amp; &#039;&#039;&#039;Autopsy&#039;&#039;&#039; (GUI)&lt;br /&gt;
** apt-get install sleuthkit&lt;br /&gt;
** apt-get install autopsy&lt;br /&gt;
** [http://sleuthkit.sourceforge.net/sleuthkit/tools.php A lot] of tools&lt;br /&gt;
** Some [http://sleuthkit.sourceforge.net/informer/ very nice articles] online to learn how to use them.&lt;br /&gt;
&lt;br /&gt;
=== On live systems ===&lt;br /&gt;
* &#039;&#039;&#039;[http://staff.washington.edu/dittrich/talks/blackhat/blackhat/cryogenic.c Cryogenic.c]&#039;&#039;&#039;&lt;br /&gt;
** Captures process information stored in Linux&#039;s Proc_fs on a best effort basis&lt;br /&gt;
*&#039;&#039;&#039;[http://www.chrootkit.org Chkrootkit]&#039;&#039;&#039;&lt;br /&gt;
** Checks for signs of rootkits on the local system&lt;br /&gt;
** apt-get install chkrootkit&lt;br /&gt;
** &#039;&#039;&#039;chkdirs&#039;&#039;&#039;: détecte les anomalies entre le nombre de liens d&#039;un répertoire père et le nombre de sous-répertoires de ce dernier&lt;br /&gt;
** &#039;&#039;&#039;chkprocs&#039;&#039;&#039;: compare le contenu du répertoire /proc avec la sortie de la commande ps&lt;br /&gt;
* &#039;&#039;&#039;Kstat&#039;&#039;&#039;&lt;br /&gt;
** Détecte le détournement d&#039;appels systèmes&lt;br /&gt;
** wget http://s0ftpj.org/tools/kstat24_v1.1-2.tgz&lt;br /&gt;
* Less intrusive: mem dump via &#039;&#039;&#039;Firewire&#039;&#039;&#039;&lt;br /&gt;
** Presentation by A. Boileau: [http://www.security-assessment.com/files/presentations/ab_firewire_rux2k6-final.pdf Hit by a Bus: Physical Access Attacks with Firewire (PDF)]&lt;br /&gt;
** [http://www.storm.net.nz/projects/16 More on his page]&lt;br /&gt;
&lt;br /&gt;
=== Dumping data supports ===&lt;br /&gt;
* &#039;&#039;&#039;[http://www.gnu.org/software/ddrescue/ddrescue.html ddrescue]&#039;&#039;&#039;&lt;br /&gt;
** apt-get install gddrescue&lt;br /&gt;
** Seems to work better than the next one (not to be confounded with...)&lt;br /&gt;
* &#039;&#039;&#039;[http://www.garloff.de/kurt/linux/ddrescue/ dd_rescue]&#039;&#039;&#039;&lt;br /&gt;
** apt-get install ddrescue&lt;br /&gt;
* &#039;&#039;&#039;[http://www.ferzkopp.net/Software/CloneIt/CloneIt.html CloneIt]&#039;&#039;&#039;&lt;br /&gt;
** Networked Harddisk Replication System&lt;br /&gt;
** cf also netcat on [[Network security tools]]&lt;br /&gt;
* &#039;&#039;&#039;[http://www.heise.de/ct/05/16/links/078.shtml H2cdimage]&#039;&#039;&#039;&lt;br /&gt;
** To recover badly damaged CD/DVDs&lt;br /&gt;
&lt;br /&gt;
=== Guessing the filesystem used ===&lt;br /&gt;
* testdisk&lt;br /&gt;
** apt-get install testdisk&lt;br /&gt;
* gpart&lt;br /&gt;
** apt-get install gpart&lt;br /&gt;
* disktype&lt;br /&gt;
** apt-get install disktype&lt;br /&gt;
&lt;br /&gt;
=== Recovering files from filesystems ===&lt;br /&gt;
==== From ISO9660 ====&lt;br /&gt;
* &#039;&#039;&#039;[http://www.heise.de/ct/05/16/links/078.shtml dares]&#039;&#039;&#039;&lt;br /&gt;
** Description: rescue files from damaged CDs and DVDs (ncurses-interface)&amp;lt;br&amp;gt;Dares scans a CD/DVD image or a CD/DVD for files. This also works when the filesystem (ISO-9660 or UDF) on the disc is damaged and cannot be mounted anymore.&lt;br /&gt;
** apt-get install dares&lt;br /&gt;
** Note that it helps recovering a &#039;&#039;logically&#039;&#039; damaged image, if the disk is physically damaged, first use sth like gddrescue to cope with IO errors.&lt;br /&gt;
==== From ext2 ====&lt;br /&gt;
* e2undel&lt;br /&gt;
** apt-get install e2undel&lt;br /&gt;
* recover (and gtkrecover)&lt;br /&gt;
** apt-get install recover&lt;br /&gt;
Agnostic (any fs)&lt;br /&gt;
* &#039;&#039;&#039;[http://foremost.sourceforge.net/ foremost]&#039;&#039;&#039;&lt;br /&gt;
** Description: a forensics application to recover data&amp;lt;br&amp;gt;foremost is a console program to recover files based on their headers and footers for forensics purposes.&amp;lt;br&amp;gt; foremost can work on disk image files, such as those generated by dd, Safeback, Encase, etc, or directly on a drive. The headers and footers are specified by a configuration file, so you can pick and choose which headers you want to look for.&lt;br /&gt;
** apt-get install foremost&lt;br /&gt;
** Very good, nice progression report&lt;br /&gt;
** Example:&amp;lt;br&amp;gt;foremost -t avi -t mpg -t wmv -t mov -q -v -i /dev/hda -o /path/recovered&lt;br /&gt;
* &#039;&#039;&#039;[http://jbj.rapanden.dk/magicrescue/ Magic Rescue]&#039;&#039;&#039;&lt;br /&gt;
** very same purpose than foremost, very fast (but I didn&#039;t have yet the chance to compare it to foremost), no false positive, but less formats supported&lt;br /&gt;
** Comes with &#039;&#039;&#039;dupemap&#039;&#039;&#039;, a very handy tool to delete duplicates in recovered files (can work also against a backup to keep only new recovered files).&amp;lt;br&amp;gt;Example: dupemap delete,report /path/recovered&lt;br /&gt;
** To compile correctly dupemap, install libgdbm-dev&lt;br /&gt;
* &#039;&#039;&#039;[http://www.rfc1149.net/devel/recoverjpeg recoverjpeg]&#039;&#039;&#039;&lt;br /&gt;
** Idem but focuses on jpeg only&lt;br /&gt;
** apt-get install recoverjpeg&lt;br /&gt;
* photorec&lt;br /&gt;
** This one comes with testdisk, promises a lot of different formats (pdf, raw images, zip, wma etc etc) but seems to create a lot of false positive (at least experienced with mpg)&lt;br /&gt;
** apt-get install testdisk&lt;br /&gt;
&lt;br /&gt;
===Recovering information from files===&lt;br /&gt;
* &#039;&#039;&#039;[http://www.workshare.com/products/trace/ Trace!]&#039;&#039;&#039; by Workshare&lt;br /&gt;
** Windows-based tool for showing all Microsoft Office documents meta-information&lt;br /&gt;
** Quite heavy and requires Microsoft .NET to be installed&lt;br /&gt;
&lt;br /&gt;
==Anti-forensic resources==&lt;br /&gt;
* wipe: secure file deletion&lt;br /&gt;
** To wipe a max of the unallocated space of e.g. hda1, just create a big file and wipe it: (this doesn&#039;t wipe slack space!)&lt;br /&gt;
** dd if=/dev/zero of=/bigfile bs=512 count=$((2*$(df |gawk &#039;/hda1/{print $4}&#039;)))&lt;br /&gt;
* secure-delete: tools to wipe files, free disk space, swap and memory&lt;br /&gt;
* [http://dban.sourceforge.net Darik&#039;s Boot and Nuke (dban)]: secure harddrive deletion&lt;br /&gt;
* [http://www.sysinternals.com/Utilities/SDelete.html SDelete] from Sysinternals&lt;br /&gt;
* [http://www.phrack.org/phrack/59/p59-0x06.txt Defeating Forensic Analysis on Unix]&lt;br /&gt;
* [http://hack.lu/images/8/80/Venema.ppt Software Engineering Security (PPT)] by Wietse Venema at Hack.lu 2006&lt;br /&gt;
* [http://www.iusmentis.com/security/filewiping/realdelete/ Article at Ius Mentis]&lt;br /&gt;
&lt;br /&gt;
==Old stuff...==&lt;br /&gt;
&lt;br /&gt;
===Récupération des données volatiles===&lt;br /&gt;
====Identification====&lt;br /&gt;
*Nom du système et version&lt;br /&gt;
**uname -a&lt;br /&gt;
*Date et heure&lt;br /&gt;
**date&lt;br /&gt;
* Paramètres réseau&lt;br /&gt;
**ifconfig | grep &amp;quot;inet addr&amp;quot;&lt;br /&gt;
====Configuration====&lt;br /&gt;
* Uptime&lt;br /&gt;
**uptime&lt;br /&gt;
* Applications installées&lt;br /&gt;
**rpm -qa OU dpkg --get-selections&lt;br /&gt;
* Configuration réseau&lt;br /&gt;
** ifconfig -a&lt;br /&gt;
* Table de routage&lt;br /&gt;
**netstat -arn&lt;br /&gt;
* Stratégie de mots de passe&lt;br /&gt;
** cat /etc/pam.d/passwd -&amp;gt; /etc/pam.d/other -&amp;gt; /etc/pam.d/common-password&lt;br /&gt;
* Comptes utilisateurs&lt;br /&gt;
** cat /etc/passwd&lt;br /&gt;
* Groupes&lt;br /&gt;
** cat /etc/groups&lt;br /&gt;
====Activité====&lt;br /&gt;
* Utilisateurs connectés&lt;br /&gt;
** w (who)&lt;br /&gt;
* Processus en exécution&lt;br /&gt;
**ps auwx&lt;br /&gt;
* Sockets ouvertes &amp;amp; processus propriétaires&lt;br /&gt;
** netstat -anptuw&lt;br /&gt;
** s&#039;aider éventuellement de /etc/services&lt;br /&gt;
* Table ARP&lt;br /&gt;
** arp -a&lt;br /&gt;
====Historique====&lt;br /&gt;
* Connexions locales &amp;amp; distantes&lt;br /&gt;
**last -f /var/log/wtmp (et autres wtmp.N...)&lt;br /&gt;
* Echecs de connexion&lt;br /&gt;
** cf syslog&lt;br /&gt;
* Derniers fichiers accédés&lt;br /&gt;
**ls -alRu&lt;br /&gt;
* Dernière connexion de chaque utilisateur&lt;br /&gt;
**lastlog (lastlog|grep -v &amp;quot;\*\*.*\*\*&amp;quot;)&lt;br /&gt;
* Dernières commandes passées&lt;br /&gt;
**history (à faire pour chaque user ou cat ~/.bash_history ou cat ~/.history)&lt;br /&gt;
====Sniffers====&lt;br /&gt;
*ifconfig -a|grep PROMISC&lt;br /&gt;
*Processus ayant ouvert un fichier&lt;br /&gt;
*lsof...&lt;br /&gt;
*Processus ayant ouvert une socket&lt;br /&gt;
**for fd in $(find /proc -name fd); do echo $fd; ls -al $fd|grep socket;done;&lt;br /&gt;
====Dump de la RAM====&lt;br /&gt;
* copier /proc/kcore&lt;br /&gt;
===Récupération des données persistantes===&lt;br /&gt;
* dd&lt;br /&gt;
* dd_rescue (apt-get install ddrescue), see also gddrescue&lt;br /&gt;
** error-tolerant version of dd for rescuing data&lt;br /&gt;
* strings&lt;br /&gt;
* file&lt;br /&gt;
* md5sum&lt;br /&gt;
&lt;br /&gt;
==See also==&lt;br /&gt;
* [[Forensics on Incidents]]&lt;br /&gt;
* [[Network Security]]&lt;/div&gt;</summary>
		<author><name>213.219.144.246</name></author>
	</entry>
</feed>