<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>innismir.net &#187; Software</title>
	<atom:link href="http://www.innismir.net/article/category/software/feed" rel="self" type="application/rss+xml" />
	<link>http://www.innismir.net</link>
	<description>Pointless, vapid ramblings of a surly information security engineer</description>
	<lastBuildDate>Mon, 02 Aug 2010 20:06:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Brand spanking new DNS cache scraping tool</title>
		<link>http://www.innismir.net/article/497</link>
		<comments>http://www.innismir.net/article/497#comments</comments>
		<pubDate>Tue, 13 Apr 2010 18:57:02 +0000</pubDate>
		<dc:creator>Ben Jackson</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.innismir.net/?p=497</guid>
		<description><![CDATA[I mentioned in a previous post that the ZeuS scraper was more or less going to be kept in it&#8217;s then-current form while I work on a new and improved version, and I&#8217;m happy to say that it&#8217;s just been released with an expanded array of hosts to check as well. Share and Enjoy!]]></description>
			<content:encoded><![CDATA[<p>I mentioned in a <a href="http://www.innismir.net/article/483">previous post</a> that the ZeuS scraper was more or less going to be kept in it&#8217;s then-current form while I work on a new and improved version, and I&#8217;m happy to say that <a href="http://www.mayhemiclabs.com/?q=node/13">it&#8217;s just been released</a> with an expanded array of hosts to check as well.</p>
<p>Share and Enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.innismir.net/article/497/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Arduino Project #1: Trivial Morse Beacon</title>
		<link>http://www.innismir.net/article/423</link>
		<comments>http://www.innismir.net/article/423#comments</comments>
		<pubDate>Wed, 30 Dec 2009 03:45:12 +0000</pubDate>
		<dc:creator>Ben Jackson</dc:creator>
				<category><![CDATA[Ham Radio]]></category>
		<category><![CDATA[Hardware]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[arduino]]></category>
		<category><![CDATA[beacon]]></category>
		<category><![CDATA[morse]]></category>

		<guid isPermaLink="false">http://www.innismir.net/?p=423</guid>
		<description><![CDATA[Santa was very nice and I got a nice Arduino for Christmas. I&#8217;ve been meaning to snag one of these for a while but I kept putting it off. After reading the great documentation they have, I quickly started making LEDs blink and such. After messing about with the examples for a while, I decided [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;">Santa was very nice and I got a nice <a href="http://www.arduino.cc/">Arduino</a> for Christmas. I&#8217;ve been meaning to snag one of these for a while but I kept putting it off. After reading the great <a href="http://arduino.cc/en/Guide/HomePage">documentation</a> they have, I quickly started making LEDs blink and such.</p>
<p style="text-align: left;">After messing about with the examples for a while, I decided to see if I could whip something up from scratch. I had bookmarked Mark, K6HX&#8217;s entry about an <a href="http://brainwagon.org/2008/10/30/silly-arduino-project-1-a-trivial-beacon/">Arduino based Morse Code Beacon</a> and decided to take a crack at it. My <a href="http://www.innismir.net/etc/SimpleMorseKeyer.c">code</a> is a bit of a kludge, but it does work:</p>
<p style="text-align: center;"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/0dcl_POCzik&amp;hl=en_US&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/0dcl_POCzik&amp;hl=en_US&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<p style="text-align: left;">Now, to get this hooked up into a radio to make sure it can do more then blink an LED&#8230;</p>
<p style="text-align: left;"><strong>UPDATE:</strong> Uhhh&#8230; Yeah, so I guess Mark updated his beacon and <a href="http://brainwagon.org/2009/11/14/another-try-at-an-arduino-based-morse-beacon/">did some pretty impressive stuff</a>, making my implementation look like a Pinto while his is a Corvette. Oh well. It was a learning experience.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.innismir.net/article/423/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Another SOURCE Boston in the books</title>
		<link>http://www.innismir.net/article/264</link>
		<comments>http://www.innismir.net/article/264#comments</comments>
		<pubDate>Tue, 17 Mar 2009 03:38:13 +0000</pubDate>
		<dc:creator>Ben Jackson</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[conferences]]></category>
		<category><![CDATA[infosec]]></category>
		<category><![CDATA[SOURCE]]></category>
		<category><![CDATA[work]]></category>

		<guid isPermaLink="false">http://www.innismir.net/?p=264</guid>
		<description><![CDATA[SOURCE Boston 2009 wrapped up last Friday. Once again, the SOURCE Advisory board did a bang-up job picking talks: Normally, during a conference there are &#8220;collisions&#8221; in which there are two talks I want to see that run concurrently. SOURCE had this, but it seemed that it happened almost every single talk. I was desperately [...]]]></description>
			<content:encoded><![CDATA[<p>SOURCE Boston 2009 wrapped up last Friday. Once again, the SOURCE Advisory board did a bang-up job picking talks: Normally, during a conference there are &#8220;collisions&#8221; in which there are two talks I want to see that run concurrently. SOURCE had this, but it seemed that it happened almost <em>every single talk</em>. I was desperately switching my attention between the talk I was currently at and my twitter stream watching people live-tweet the other tracks. I constantly felt I was missing something great. SOURCE also improved the one complaint I had about SOURCE Boston 2009, lack of the ability to get to the venue via the MBTA. This year&#8217;s venue, the Seaport Hotel was easily accessible from the Silver line and the new digs were great.</p>
<p>My talk went as well as I could have hoped. Despite some minor issues with regards to what I could and couldn&#8217;t talk about and thus the presentation being much shorter then I wanted it to be, I felt I fielded all the questions cleanly and ones that I could not answer I made sure I got business cards so that I could follow up. For those of you interested in downloading my slide deck it is available here:</p>
<ul>
<li>Massachusetts Data Breach Laws, Regulations, and Responsibilities (<a href="http://www.innismir.net/etc/MADataBreachLawsRegsandResponsibilites.ppt">PPT</a>, 828K)</li>
<li>Massachusetts Data Breach Laws, Regulations, and Responsibilities (<a href="http://www.innismir.net/etc/MADataBreachLawsRegsandResponsibilites.pdf">PDF</a>, 286K)</li>
</ul>
<p>Some highlights of the conference:</p>
<ul>
<li><a href="http://twitter.com/mortman" target="_blank">David Mortman</a>&#8216;s delicious bread, which he handed out if you asked questions during his talk. I got a slice because I was able to answer a question.</li>
<li><a href="http://www.ranum.com/" target="_blank">Marcus Ranum</a>&#8216;s keynote. Despite being a presentation of &#8220;The industry is beyond repair, and here&#8217;s why&#8230;&#8221; gloom and doom, I was able to at least grab some good points out of it that will enable me to fight the good fight. He also made a great metaphor: &#8220;3D dancing pigs&#8221; meaning something which management wants and will try to implement despite any warnings.</li>
<li><a href="http://www.tscm.com/" target="_blank">James Atkinson</a>&#8216;s counter-surveillance talk. Last year he did telephones and this year he did automobiles. Crazy stuff.</li>
<li><a href="http://www.l0phtcrack.com/" target="_blank">L0phtCrack</a> 6 information session. I can&#8217;t wait.</li>
</ul>
<p>And these are just the ones I can remember off the top of my head.</p>
<p>SOURCE is a great conference and if I had the time and money, I&#8217;d seriously consider going to SOURCE Barcelona in September. If you have the chance in 2010, I would highly recommend attending.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.innismir.net/article/264/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Setting Up a Windows XP as a guest OS in VMware ESX server</title>
		<link>http://www.innismir.net/article/33</link>
		<comments>http://www.innismir.net/article/33#comments</comments>
		<pubDate>Tue, 20 May 2008 20:25:55 +0000</pubDate>
		<dc:creator>Ben Jackson</dc:creator>
				<category><![CDATA[Software]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[microsoft]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[One of my duties at my job is to the maintain the lab environment that we have to do our super 31337 skunk works projects in. As we all are quite lazy and don&#8217;t have room for gobs of hardware, we make good use of virtualized machines to do our projects. One of the annoying [...]]]></description>
			<content:encoded><![CDATA[<p>One of my duties at my job is to the maintain the lab environment that we have to do our super 31337 skunk works projects in. As we all are quite lazy and don&#8217;t have room for gobs of hardware, we make good use of virtualized machines to do our projects. One of the annoying issues that keeps popping its head up every time we need to install a fresh desktop install is that Windows XP does not like to run within VMware ESX server.  It&#8217;s frustrating and there is no real tutorial online with a definitive set of answers, just a bunch of forum posts with tidbits of info that if you arrange correctly, you can piece together what to do.</p>
<p>So, without further ado, here is how to make Windows XP install onto a VMware stock VM machine:</p>
<ol>
<li>Download the VMware SCSI Disk image from <a href="http://www.vmware.com/download/ws/drivers_tools.html">VMware Drivers &amp; Tools download page</a>. Save the image somewhere where you can locate it easier.</li>
<li>Follow the normal procedure for creating a VMware machine for Windows XP.</li>
<li>Select the machine in the Virtual Infrastructure client and select &#8220;Edit Settings&#8221;<br />
<img src="http://www.innismir.net/etc/vmwarexp1.png" alt="" /></li>
<li>On the settings screen, select the SCSI controller, then in the upper right click &#8220;Change Type&#8230;&#8221;<br />
<img src="http://www.innismir.net/etc/vmwarexp2.png" alt="" /></li>
<li>On the &#8220;Change SCSI Controller Type&#8221; screen, &#8220;LSI Logic&#8221; should be selected. Change that to &#8220;BusLogic&#8221;. Click OK.<br />
<img src="http://www.innismir.net/etc/vmwarexp3.png" alt="" /></li>
<li>Click OK on the settings screen.</li>
<li>Open the console of the Virtual Machine and Power it On.</li>
<li>During the VMware POST, press Escape to access the Boot Menu.</li>
<li>Click the &#8220;Virtual Floppy 0&#8243; button and select &#8220;Connect to Floppy Image&#8230;&#8221;<br />
<img src="http://www.innismir.net/etc/vmwarexp4.png" alt="" /></li>
<li>Select the floppy image that you downloaded from VMware in step 1.</li>
<li>Click the &#8220;Virtual CDROM&#8221; button and connect it to your install media</li>
<li>On the console select &#8220;CD-ROM Drive&#8221; and press Enter to boot from the CD-ROM</li>
<li>Immediately when the Windows installer boots, you will see the bottom of the screen &#8220;Press F6 if you need to install a third party SCSI or RAID driver.&#8221; Press F6. Windows will continue loading the installer.<br />
<img src="http://www.innismir.net/etc/vmwarexp5.png" alt="" /></li>
<li>Windows will eventually prompt you to load additional devices. Press &#8220;S&#8221;<br />
<img src="http://www.innismir.net/etc/vmwarexp6.png" alt="" /></li>
<li>There will be only one option: &#8220;VMware SCSI controller&#8221; Press Enter. <img src="http://www.innismir.net/etc/vmwarexp7.png" alt="" /></li>
<li>That will take you back to the previous screen. You are done. Press Enter.<br />
<img src="http://www.innismir.net/etc/vmwarexp8.png" alt="" /></li>
</ol>
<p>Windows will continue loading and now pick up the hard drive that you specified during the Virtual Machine creation process. You&#8217;re all set.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.innismir.net/article/33/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adding Geolocation Support to Prelude IDS&#8217;s Prewikka</title>
		<link>http://www.innismir.net/article/30</link>
		<comments>http://www.innismir.net/article/30#comments</comments>
		<pubDate>Thu, 01 May 2008 21:13:34 +0000</pubDate>
		<dc:creator>Ben Jackson</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[computers]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[ids]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I am a big fan of Prelude IDS to correlate reports from my honeypot/nepenthes/snort setup at my house. One of the things that was quite repetitive was finding the locations of IPs. So, I sat down and coded up a patch that grafted GeoIP onto Prelude&#8217;s Prewikka web interface. After a bit of effort figuring [...]]]></description>
			<content:encoded><![CDATA[<p>I am a big fan of <a href="http://www.prelude-ids.com">Prelude IDS</a> to correlate reports from my honeypot/nepenthes/snort setup at my house. One of the things that was quite repetitive was finding the locations of IPs. So, I sat down and coded up a patch that grafted <a href="http://sourceforge.net/projects/geoip/">GeoIP</a> onto Prelude&#8217;s Prewikka web interface. After a bit of effort figuring out Python and the template engine, I ended up with this:</p>
<p><img src="http://www.innismir.net/etc/prewikka_geolocation_screenshot.png" alt="" /></p>
<p>Of course, my patch doesn&#8217;t blur out the names like the screenshot, but it does add the spiffy little flags to show you what countries are attacking you.</p>
<p>You will need:</p>
<ul>
<li>A working GeoIP installation</li>
<li>The GeoIP Python module</li>
<li>A set of flag icons in PNG format. I recommend <a href="http://www.famfamfam.com/lab/icons/flags/">FamFamFam&#8217;s icons</a></li>
<li><a href="http://www.innismir.net/etc/prewikka_0.9.14_geolocation.patch">My patch</a></li>
<li><a href="http://www.prelude-ids.org/download/releases/prewikka-0.9.14.tar.gz">Prewikka 0.9.14</a> source tree.</li>
</ul>
<p>The GeoIP libraries are available from the link above. Installing them is pretty straightforward. Once that is done, untar the Prewikka tarball and apply the patch for Prewikka in the source directory. Then install as normal.</p>
<p>Unzip the flags archive somewhere on your system. Move the contents &#8220;png&#8221; directory to your web root under the folder &#8220;/images/flags&#8221;. You may need to make an adjustment to your Apache installation if Prewikka is running in the root web directory like I had to. I made an alias in my Apache configuration pointing /images/ back over to /var/www/images.</p>
<blockquote><p>Alias /images/ /var/www/images/</p></blockquote>
<p>With any luck, it should work. As always, your mileage may vary.</p>
<p>Share and enjoy!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.innismir.net/article/30/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

