Posts

Bejtlich to Speak at ShmooCon 2006

I just learned I will speak at ShmooCon 2006 in Washington, DC on Saturday, 14 January 2006 at 1600. The subject is Network Security Monitoring with Sguil.

First Hampton Roads, VA Snort Users Group Meeting

My friend David Bianco is organizing a Hampton Roads, VA Snort Users Group . The first meeting will be 1 December 2005. Check out the story for more details!

FreeBSD 6.0-RELEASE Available Soon

Image
According to this announcement by FreeBSD release engineer Scott Long, FreeBSD 6.0-RELEASE "will likely be announced by the end of the weekend or early next week, at the latest." This is great news. I plan to upgrade all of my 5.4 systems to 6.0 when it is available. I'll post my experiences.

New (IN)SECURE Magazine Features Bejtlich Article

The latest (IN)SECURE magazine was just published. Issue 1.4 features a 7-page article on Structured Traffic Analysis , a methodology to investigate network traces I developed for my Network Security Operations class. It uses open source tools to perform zero-knowledge analysis of saved traffic. After reading this article, you may share the sentiments of a student in one of my recent classes who said "I’m embarrassed I ever used Ethereal to start network analysis!"

Review of VMware Workstation 5 Handbook Posted

Image
Amazon.com just posted my four star review of VMware Workstation 5 Handbook . From the review : "Steven S. Warren's VMware Workstation 5 Handbook (VW5H) is a great book for beginning and intermediate VMware Workstation (WS) users. It is well-written, thorough, and informative. Those who are trying to deploy WS for average home, research, or corporate purposes will find their needs met. Those looking for in-depth coverage exceeding VMware's online documentation will be disappointed. Still, I've been using VMware for almost 4 years, and I learned a few new tricks. VMware's online documentation is excellent. Those seeking to install and operate WS will find most of their needs met reading VMware's free guides. VW5H provides context and problem-solving techniques that one may not acquire from VMware's documentation. For example, a new user may be unaware of the purpose of a product like VMware P2V Assistant. By reading Ch 15 of VW5H, the user will learn how P...

VMware Workstation Vnetsniffer

Did you know VMware Workstation ships with a sniffer? I should have know about it before now. Lenny Zeltser mentioned it in his 2001 paper on reverse engineering malware. There's only 15 references in Google Groups, however. Vnetsniffer is very limited with regard to reporting. Here is sample output: C:\Program Files\VMware\VMware Workstation>vnetsniffer usage: vnetsniffer [/e] (/p "pvnID" | VMnet?) C:\Program Files\VMware\VMware Workstation>runas /u:administrator "vnetsniffer /e vmnet0" Enter password for administrator: Attempting to start "vnetsniffer /e vmnet0" as user "administrator"... len 203 src 00:03:47:0f:1f:3c dst 00:13:10:65:2f:ab IP src 192.168.2.4 dst 208.185.174.52 TCP len 60 src 00:13:10:65:2f:ab dst 00:03:47:0f:1f:3c ARP sender 00:13:10:65:2f:ab 192.168.2.1 target 00:00:00:00:00:00 192.168.2.4 ARP request len 42 src 00:03:47:0f:1f:3c dst 00:13:10:65:2f:ab ARP sender 00:03:47:0f:1f:3c 192.168.2.4...

Bejtlich Books in HNS Contest

Mirko Zorz from Help Net Security notified me that two of my books are up for grabs in the HNS 7th Anniversary Book Contest . You could win Real Digital Forensics or Extrusion Detection: Security Monitoring for Internal Intrusions . The winners will be announced on Monday, 5 December 2005. Good luck!