Suricata v0.8.1 released
Written by lirva32   
Friday, 16 April 2010

Suricata v0.8.1 released

 

The Suricata Engine is an Open Source Next Generation Intrusion Detection and Prevention Engine. This engine is not intended to just replace or emulate the existing tools in the industry, but will bring new ideas and technologies to the field.

New features:
- the engine will now detect the number of cpu’s/core’s and setup the engine to use them fully
- libhtp is now included in the source
- experimental CUDA support for NVIDIA GPU accelerated pattern matching
- initial support for Win32 (using mingw) was added
- FreeBSD/Mac OS X IPFW inline support was added
- many options in the configuration file for performance tuning
- VLAN decoding support was added
- Prelude output support

Major issues fixed & improvements made:
- threading issues in the unified1 and unified2 logging modules
- major stream engine issues were solved
- uricontent, urilen inspection is now done against the libhtp parsed uri
- ip only signature detection fixes in inline mode
- add the /P (request body) option to the pcre keyword
- many SMB, SMB2 and DCERPC improvements
- logging is more configurable
- pcap and pfring modes support for bpf was added
- many bugs were fixed, cleanups were made

Known issues:
- Some signatures fail to load because of missing keywords or keyword options
- We have identified some serious performance issues with certain signatures and traffic combinations
- Although we improved big endian support, there are still some issues
- CUDA code is expected to work only on 32bit and probably doesn’t speed things up yet as we will need further redsign to fully benefit

You can download Suricata in here :

Linux/Mac/FreeBSD/UNIX Source:

http://www.openinfosecfoundation.org/download/suricata-0.8.1.tar.gz

PGP Signature:

http://www.openinfosecfoundation.org/download/suricata-0.8.1.tar.gz.sig

 

Build Requirements:
- gcc
- make
- g++

If building from the git repository you will also need:
- automake
- autoconf
- libtool

Library Requirements:
- libpcre
- libnet 1.1.x
- libyaml
- libpcap
- libnetfilter-queue and libfnetlink (optional for use with ./configure --enable-nfqueue)
- libpthread (should be part of most glibc's)
- libpfring (optional for use with ./configure --enable-pfring)
- libz
- htp

For Debian/Ubuntu Users

sudo apt-get -y install libpcre3 libpcre3-dbg libpcre3-dev \
build-essential autoconf automake libtool libpcap-dev libnet1-dev \
libyaml-0-1 libyaml-dev zlib1g zlib1g-dev


### HTP
wget http://www.openinfosecfoundation.org/download/htp-current.tar.gz
tar -xzvf htp-current.tar.gz
cd htp-<version>
./configure
make
make install
ldconfig


#if using ubuntu-8.04 to use prebuilt yaml packages you need to uncomment the following two lines in your /etc/apt/sources.list to
enable hardy-backports.


#deb http://us.archive.ubuntu.com/ubuntu/ hardy-backports main restricted universe multiverse
#deb-src http://us.archive.ubuntu.com/ubuntu/ hardy-backports main restricted universe multiverse


#if building with IPS capabilities via ./configure --enable-nfqueue
sudo apt-get -y install libnetfilter-queue-dev libnetfilter-queue1
libnfnetlink-dev libnfnetlink0


### Suricata:
wget http://www.openinfosecfoundation.org/download/suricata-current.tar.gz
tar -xvzf suricata-current.tar.gz
cd suricata.<version>


If building from git sources:
bash autojunk.sh


#else
./configure
sudo mkdir /var/log/suricata/
make
make install

Reference :
http://www.openinfosecfoundation.org/

 

 

Last Updated ( Friday, 16 April 2010 )
 
SSIDCrawler
Written by lirva32   
Tuesday, 13 April 2010

 

Service set identifier, or SSID, is a name that identifies a particular 802.11 wireless LAN. A client device receives broadcast messages from all access points within range advertising their SSIDs. The client device can then either manually or automatically—based on configuration—select the network with which to associate. The SSID can be up to 32 characters long. As the SSID displays to users, it normally consists of human-readable characters. However, the standard does not require this. The SSID is defined as a sequence of 1–32 octets each of which may take any value.

It is legitimate for multiple access points to share the same SSID if they provide access to the same network as part of an extended service set.

Some wireless access points support broadcasting multiple SSIDs, allowing the creation of Virtual Access Points, partitioning a single physical access point into several virtual access points, each of which can have a different set of security and network settings. This is not yet part of the 802.11 standard.

I have a good way to find the Wireless SSID up to 1 km, by :


- pipe cap -

 


- pigtail cable with sma connector -

 


. pigtail cable with sma connector and usb wifi 23dBm +/-1 .

 

 


. pipe 60 cm .

 

 

 


. 15 dbi omni .

 


. 15 dbi omni + pigtail cable + usb wifi + usb cable extender .

 

 


. the end of project .

 

Greetz :
. all echo|staff
. mydaughter : Faiza Debian n Fivana Gutsy
. myalmamater : FTI_UBL
. all_indonesian_newbie_hacker

Last Updated ( Tuesday, 13 April 2010 )
 
InternetPhoneAdapter
Written by lirva32   
Friday, 26 March 2010

Hi all...
today, i'm writing about Internet Phone Adapter with Linksys PAP2T

The Linksys PAP2 is an analog telephony adapter (commonly referred to as ATA), which allows for the connection of one or two “normal” telephones to a VoIP provider using the Session Initiation Protocol (SIP) protocol. The SIP traffic is sent through the PAP2's Ethernet port. The device is one of Linksys's first entries into the Consumer / SOHO Voice over IP devices market.

The PAP2 is based on the Sipura SPA-2000 ATA design. The device is powered by an ESS Visba 3 (ES3890F) chipset. It utilizes a Realtek RTL8019AS 10BaseT Ethernet controller, which provides a 10 Mbit/s/ half duplex connection to a LAN.

The units have 2 RJ11 sockets, which allows for two "lines" (each with their own unique SIP registrar / username etc, for truly separate configuration).
The original PAP2 has been discontinued. The PAP2 version 2 and the PAP2T are successors with similar capabilities, the pap2t is reported to have twice the memory of the PAP2 version 1. They are different enough that they have distinct firmware. The PAP2 version 2, unlike the others, runs Linux (Linksys has released source for the GPLed portions of the firmware).




 

 

How to configue PAP2T :

1. Dial " **** " from your phone to enter interactive voice respone menu.
2. Press " 110 " to check current IP address of the phone adapter (ex : IP in my VoIP adapter : 200.200.1.10)
3. Now, use your web browser to entering VoIP adapter and you can configure, like :

 

 

 

 

Taaddddddaaaaa... now u can calling your family from anywhere with Intenet VoIP adapter.....

 

Shoutz :
. MyDaughter Faiza Debian Nafisa n Fifana Gutsy Ramadhani
. echo|staff
. MyAlmamater : FTI_Universitas_Budi_Luhur
. IndonesianNewbieHacker

 

 
MiniParabolic
Written by lirva32   
Saturday, 20 March 2010

I needed a parabolic reflector to eliminate off-property coverage. This design can reduce signal from some areas while enhancing signal in other areas. I designed this reflector to be installed in outdoor enclosures with WAP-11 access points, but it is becoming quite popular with people building indoor LANs, as well as with people building very short point-to-point links. This design offers very high performance and easy availability (scissors, tape, cardboard, mosquito net, and 20 minutes, and you are in business).

This antenna is so easy to make, tune, and install, and it performs so well, that it is foolish not to try one before electing to purchase a commercial antenna, if for no other reason than you can check to see whether you are purchasing enough commercial antenna gain to make the link you want to make.

Advantages over other antennas:

. No pigtail required
. No modification to AP (no voiding of warranty)
.
No matching (SWR) problems
.
No purchased parts
.
Trivially easy construction
.
Very low probability of error
.
As good as or better performance than the Pringles can antenna
.
Superior front-to-back/front-to-rear ratio
.
Improves wireless LAN privacy
.
Reduces interference

This design can easily complete links up to one kilometer by sitting two WAP-11s in windows at each end of a link with clean line of sight. The 6-inch version of the antenna gives you about 10 to 12 dB of gain over the stock antenna. With a WAP11, this equates to approximately 27 to 33 dB of Effective Isotropically Radiated Power (EIRP). This means you wind up with an apparent power in the favored direction between 500 mw and 2 Watts.

Of course, that gain has to come from somewhere. It comes from the back side of the reflector, so power that is normally transmitted in that direction is "bounced" forward. That feature of this antenna can be used to enhance the privacy of your wireless network, which was my reason for designing it in the first place. The rest is just gravy (but it is very real and rather tasty gravy).
tttaaaddddaaaaa.... this is my parabolic reflector :

 


mosquito net

 

 

circle board

 

holes on the board

 

tacks

 

 

End Project

 

End Project

 

Implementing Project

 

hopefully hepful....

Shoutz :
. MyDaughter : Debian n Gutsy
. AllCrewEcho.Or.ID
. IndonesianNewbieHacker
. MyAlmamater_FTI_Univ_Budi_Luhur

Last Updated ( Saturday, 20 March 2010 )
 
WRT54G-Raper
Written by lirva32   
Friday, 12 March 2010

Linksys WRT54G (and variants WRT54GS, WRT54GL, and WRTSL54GS) is a Wi-Fi capable residential gateway from Linksys. The device is capable of sharing internet connections among several computers via 802.3 Ethernet and 802.11b/g wireless data links.
The original WRT54G was first released in December 2002. It comes with a 4+1 port network switch (the Internet/WAN port is also in the same internal network switch, but on a different VLAN). The devices have two removable antennas connected through Reverse Polarity TNC connectors. The WRT54GC router is an exception and has an internal antenna with optional external antenna. As a cost-cutting measure, the design of the latest version of the WRT54G no longer has detachable antennas or TNC connectors. Instead, version 8 routers simply route thin wires into antenna 'shells' eliminating the connector. As a result, Linksys HGA7T and similar external antennas are no longer compatible with this model.

WRT54G Raper
WRT54G Authentication Bypass vulnerability Exploitation Tool. Once your wifi card has detected the WRT54G, you can simply click connect; even if this router asks for a password, it will still provide you with “Local Only” access in order to authenticate your key against the router. Once this “Local Access” is obtained, you can use the WRT54G Raper to disable the security and change the admin password.The rest is up to you.

 

 

How to Install in windows os :
1. Download WRT54G Raper : click here
2. Extract Files into your folder

3. Now, click the "setup.exe"
4. Taddddaaaa... Now you can having fun to crack WRT54G...;)

 

 

thx...
greetz to :

. AllMyFren
. MyDauthter : Debian n Gutsy

Last Updated ( Friday, 12 March 2010 )
Read more...
 
<< Start < Prev 1 2 3 4 5 Next > End >>

Results 13 - 18 of 27