Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register

SECURITY ADVISER 

Cool tools for hacker trackers

A honeynet reporting site and the latest version of a solid hacking package help security pros


If you want to keep up with the latest criminal exploits without having to collect malware yourself, take a look at SRI International's Cyber-Threat Analytics BotHunter Malware Analysis Web page. Reporting on information and statistics collected from a research honeynet, the BotHunter Malware Analysis page makes daily infection logs from high-interaction honeypots available for anyone to view. Although the scale of the project and information collected is fairly small, this is a useful site for gaining more insight into crimeware and the world of bots.

Clicking on any of the daily reports presents dozens of pieces of information on each day’s attacks. It starts off with time and date of each bot attack, and the honeypot platform type (e.g. Windows XP, Windows 2000, etc.). It reveals the Snort rules used to detect incoming malware and how many antivirus companies detected the malicious code.

[ RogerGrimes's column is now a blog! Get the latest IT security news from the Security Adviser blog. ]

Each captured malware program is run against 28 to 32 antivirus engines. Try browsing the daily reports to see how many times none of the antivirus scanners detected the malware. Surprisingly, this happens roughly one third of the time -- not a comforting statistic.

The honeynet automatically extracts plain text strings and tries to determine which executable packer was used. It decodes each executable and provides code traces. It appears that complete assemblies and packet traces are available upon request. A short summary forensic log can be obtained for each malware attack. Here's a sample:

FORENSIC LOG:

            Infection Source:
                        24.64.x.x
            Executables Delivered:
                        ftpupd.exe
                        keymmuda.exe
            Listen Ports Opened:
                        4166
                        4606
            Processes Created:
                        keymmuda.exe
                        MSMSGS.EXE
            Registry Entries Modified or Created:
                        HKEY_LOCAL_MACHINE@...Microsoft\Wireless

Cain & Abel update
Like many leading-edge technology companies, one of my favorite hacking utilities, Cain & Abel, is constantly updating itself. For years it’s been the hacker utility with the most built-in features of any GUI tool. It can crack at least 28 different password hashes, conduct ARP spoofing and man-in-the-middle attacks, and sniff more than a dozen different passwords off the wire. When converting password hashes to passwords, it can use several different cracking methods, including dictionary, brute force, and rainbow tables. It’s not the fastest (get John the Ripper for that), but it’s the easiest and most versatile tool available. The program's single downside is that it is only available for Windows.

I’ve been aiming to test Cain & Abel on Windows Vista since Vista came out almost a year ago. Although Cain & Abel must be started in elevated mode, many of the key features don’t work, as I suspected might be the case. Protected Storage, RDP, and Credential Dumper didn’t work, although a local LSAdump of custom service account passwords and wireless preshared keys and hashes did. I couldn’t get any of the man-in-the-middle attacks to work, and none of the tools for sniffing passwords off the network provided any usable data.

I was happy to see that the local password hash dump only discovered the harder-to-crack NT hashes with no super vulnerable LM hashes available. This reflects Microsoft’s decision to finally disable LM password hashes by default in Vista, a decision overdue by at least five years.

Some security administrators ask me why I promote the use of tools like Cain & Abel that make hacking so easy. Shouldn't I be afraid of putting dangerous tools into the hands of the script kiddies? My reply is always the same: Hackers don’t need Cain & Abel. They can do what they need to do without the easy-to-use GUIs. Cain & Abel is for the rest of us to make hacking easier to demonstrate. One good Cain & Abel demo to management can say more than a hundred computer security articles. And besides, most malicious hacking today is done by professional criminals … and they don’t use Cain & Abel either.

I often encourage system administrators to run Cain & Abel, with appropriate permission of course, to ferret out weak and plain text passwords on their own local system and on their networks. Most first-time users are surprised to find that plain text passwords abound on networks they believed were relatively secure.

Who am I kidding? Every system administrator I know thinks their network is like Swiss cheese. But Cain & Abel gives you a way to document the problem, and to begin doing something about it.

Roger A. Grimes is contributing editor of the InfoWorld Test Center. He also writes the Security Adviser blog and the Security Adviser column.

Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





COMPREHENSIVE DATA PROTECTION AND DISASTER RECOVERY
Traditional backup and recovery is becoming irrelevant. You need more. Watch this InfoWorld and Dell Equallogic webcast to learn the current trends in Comprehensive Data Protection and Disaster Recovery for VMware Virtual Infrastructure. Sponsored by Dell Equallogic:

»  Click here to view this Webcast
  Protection for Remote Sites and Branch Offices
This Whitepaper reviews the challenges of creating appropriate data protection, especially for small and midsize companies with remote and branch offices. It offers suggestions on how you can choose the most appropriate data protection solution for your company's needs. Sponsored by Overland

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 12/04/2008

Sun enters RIA realm with JavaFX, Adobe says it will cut 600 jobs, AMD...

 
 
 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist
TecChannel :: TecCommunity