Showing posts with label tools. Show all posts
Showing posts with label tools. Show all posts

Tuesday, September 15, 2009

Malware Analysis Tools and Techniques

Malware Analysis Tools and Techniques


Apart from what guidelines have been published in various books and articles. My this post will summarize the overall manual and automated techniques to simulate and test the samples of malwares collected and their behavioral activities. To be noted that a "Malware" could be delivered in the form of trojan, virus or worm.

Manual Toolset
These tools require the collaboration of other toolset used in conjunction, to support depth analysis of a malware.

Foundstone BINTEXT
Malzilla (Analyzing Web-Based Malwares - JavaScript/iFrame)
HTTP Proxy Debuggers (Paros, WebScarab)
Nepenthes
iDefense SysAnalyzer, HookExplorer and MAP (Malcode Analyst Pack)
RegShot
SysInternals Tools
PEiD Tool (Very important to detect packers/compilers/cryptors)
UPX
FireBug
OllyDbg
WinDbg
GDB GNU (Linux)
OllyDump
OllyScript
SoftICE (Reversing)
IDA Pro (Reversing)
Salamander Decompiler (.NET Applications)
Reflector.Net Tool
DaFixer's DeDe (Delphi)
Backerstreet.com REC
HeavenTools PE Explorer
HijackThis

Automated Online Tools
These online submission services automatically analyze the malware in a very restricted environment(simulate) and record their activites and produce results on the basis of various Anti-Virus/Malware detection.

CWSandbox.org
ThreatExpert.com
VirusScan.jotti.org
Norman.com/microsites/nsic/
Malwareinfo.org
VirusTotal.com
VirScan.org

Source: EthicalHacker.

Sunday, September 6, 2009

Memoria USB Booteable con Varias Distribuciones de Seguridad Informática

A continuación va la receta de cómo llevar nuestras distribuciones de seguridad preferidas en una sola memoria USB/pendrive, todas funcionando correctamente.

307668780bec332e7ba Memoria USB Booteable con Varias Distribuciones de Seguridad Informática

Primero de todo nos descargamos las herramientas que necesitamos.

Una vez nos hayamos descargado PeToUsb iniciamos y procedemos a formatear la llave USB.

 Memoria USB Booteable con Varias Distribuciones de Seguridad Informática

Ahora nos pedirá confirmación:

empezando..

Y aqui entonces nos avisa de que se eliminarán todos nuestros datos.

empezando..2

Entonces empezará el formateo:

 Memoria USB Booteable con Varias Distribuciones de Seguridad Informática

Cuando acabe el formateo nos saldrá un mensajito:

 Memoria USB Booteable con Varias Distribuciones de Seguridad Informática

Una vez tenemos preparado nuestro dispositivo vamos a instalar GRUB en él.

Abrimos la aplicación WinGrub que ya hemos instalado antes. Nada mas iniciarlo nos pedirá sobre que dispositovo USB instalaremos GRUB

 Memoria USB Booteable con Varias Distribuciones de Seguridad Informática

Ahora instalaremos GRUB en el USB.

 Memoria USB Booteable con Varias Distribuciones de Seguridad Informática

Ahora ya tendremos GRUB instalado.

Ahora cojeremos cualquier LIVE-CD y copiaremos su contenido en la raíz del USB.

Yo lo he echo con Backtrack.

Una vez hayamos copiado el contenido del CD dentro de la llave USB. Creamos un archivo en blanco que sea menu.lst

Dentro del archivo de configuración del Menú le ponemos como ha de arrancar la distribución en sí.

Ejemplo para backtrack:

title BackTrack 4
root (hd0,2)
kernel /boot/vmlinuz vga=0×317 ramdisk_size=6666 root=/dev/ram0 rw quiet
initrd=/boot/initrd.gz
boot

Con esto ya tendríamos el GRUB configurado.

Nota: Cada LIVE -CD se estructura normalmente con dos carpetas, una carpeta boot, y otra con el nombre de la distribución.

Si queremos poner mas de un LIVE-CD podemos renombrar la carpeta boot con otro nombre.

Ejemplo, backtrack4 le ponemos el nombre de bootbt4, kon-boot a bootkon y asi sucesivamente.

Si se cambia el nombre de boot, recordad de cambiarlo en el menu.lst también.

Yo por ejemplo ya he configurado mi grub y las distrubuciones que quería.

Me ha quedado algo así.

P9010037

Y si lo ponemos desde mas cerca…

P9010036

Y como veis podremos poner las distribuciones que queramos en nuestro USB.

Fuente: DragonJar.

Thursday, September 3, 2009

Graudit – Code Audit Tool Using Grep

Graudit is a simple script and signature sets that allows you to find potential security flaws in source code using the GNU utility grep. It’s comparable to other static analysis applications like RATS, SWAAT and flaw-finder while keeping the technical requirements to a minimum and being very flexible.

Usage

Graudit supports several options and tries to follow good shell practices. For a list of the options you can run graudit -h or see below. The simplest way to use graudit is;

graudit /path/to/scan

You can download Graudit v1.1 here:

graudit-1.1.tar.bz2

Or read more here.

From: Darknet.

Insecure Magazine 22 (September 2009)



Se encuentra publicada la revista Insecure de Septiembre (Inglés), la descarga se puede hacer del siguiente link:

DOWNLOAD ISSUE 22

Temas incluidos:
  • - Using real-time events to drive your network scans
  • - The Nmap project: Open source with style
  • - A look at geolocation, URL shortening and top Twitter threats
  • - Review: Data Locker
  • - Making clouds secure
  • - Top 5 myths about wireless protection
  • - Securing the foundation of IT systems
  • - Is your data recovery provider a data security problem?
  • - Security for multi-enterprise applications
  • - In mashups we trust?
  • AND MORE!

Otras revistas relacionadas con al seguridad de la Información...

Fuente: cryptex.