WEBVTT

00:00.000 --> 00:09.460
This is dedicated to all the hackers and the crackers, to the hackers and the crackers.

00:09.760 --> 00:15.520
I see in binary, I speak source code, step on my toes, I'll post a million jpegs of you

00:15.520 --> 00:20.780
and a fag pwned, in your digital stance getting firewalled ho, cause I'm riding the net in

00:20.780 --> 00:26.440
my six-fold, I was a dick with my 56, now with my cable I'm able to get that stable,

00:26.440 --> 00:31.740
on the out, my name is Ace and I'm a Leo, on the digital highway, my name is Neo and

00:31.740 --> 00:37.240
I'm a hero, in a flash, I'll screw you on burning dreamcast, you need some ISO, let me through

00:37.240 --> 00:42.680
my hard drive rifle, our exchange you could never stifle, in a digital hug, you just caught

00:42.680 --> 00:48.940
the love bug, I bootlegged your CD, I caused a fight between Un and Jay-Z, your CG, it's

00:48.940 --> 00:53.460
all gonna be free, whether we take it by force or we take it nicely, you feel that rattling

00:53.460 --> 00:58.040
your phones, when I tell you we just hacked out Jones, and NASDAQ leaves your fight on

00:58.040 --> 01:03.100
your back, cause I am he who loves to hack and crack, cause I am he who loves to hack and

01:03.100 --> 01:09.460
crack, this is dedicated to the hackers and the crackers, serial codes, source codes, ISOs,

01:10.140 --> 01:16.460
RANs, SIFs, SIFs, this is dedicated to the hackers and the crack, this is dedicated to

01:16.460 --> 01:24.100
everybody and welcome to Binary Revolution Radio number 163, I am Stank Dog with you again

01:24.100 --> 01:32.480
this week, our air date this episode is September 12th, 2006, and you're in for a special treat

01:32.480 --> 01:38.320
this episode, as I try to keep from spitting all over myself, we are actually coming to you

01:38.320 --> 01:44.440
with another Bin Rev First, we bring you lots of firsts on this show, so this week we're doing

01:44.440 --> 01:50.780
our first ever, ever, ever, I'm having a really bad time with the show today, we're doing our

01:50.780 --> 01:56.480
first ever, is what I'm trying to say, Double Header, our double feature episode, back to back

01:56.480 --> 02:01.120
episodes of Binary Revolution Radio, trying to get back on track here, get a couple very

02:01.120 --> 02:06.720
technical shows in this week, and kind of get the flow going to the show again, and the

02:06.720 --> 02:11.600
reason this is a first on Bin Rev Radio, this particular episode has two reasons for being

02:11.600 --> 02:16.240
a first, it's the first time we've ever done a double header, two episodes, but this is

02:16.240 --> 02:22.980
also the first time where my co-host has been live in the same room, where we're actually

02:22.980 --> 02:29.600
not on the phone, we're not thousands of miles apart, we are actually about a foot and a half

02:29.600 --> 02:32.240
apart, so Quine, welcome to the show.

02:32.440 --> 02:35.520
Alright, thanks, I'm glad to be here, thanks for having me.

02:35.520 --> 02:40.340
So, I'm not sure about the sound quality, we did as best we could trying to do some

02:40.340 --> 02:45.880
sound checks and stuff up front, but I'm so naturally loud that it kind of made it a

02:45.880 --> 02:49.480
little bit hard getting a nice decent sound check, so we're going to see if this holds

02:49.480 --> 02:54.000
up, and hopefully there's not too much background noise in this episode, but it can't be worse

02:54.000 --> 03:01.680
than 159, I mean, let's move on, and since we have two episodes this week, we have, we're

03:01.680 --> 03:05.800
going to, let's see, we don't, we're going to kind of split up all of our normal housekeeping

03:05.800 --> 03:10.600
stuff and split up our emails, so that we have more time on each individual show for

03:10.600 --> 03:16.580
the main topic of that show, so, did you have any kind of housekeeping, actually, we should

03:16.580 --> 03:20.220
probably mention, we usually mention this at the end, we'll mention housekeeping that

03:20.220 --> 03:22.260
our BR407 meeting is this Friday.

03:22.380 --> 03:23.220
Yes, it is.

03:23.220 --> 03:28.540
So, this airing on Tuesday, I'd say Thursday, Friday, three days from, kind of, four days?

03:28.540 --> 03:31.420
Well, that is if everyone, you know, listens to it by then.

03:31.540 --> 03:33.720
Yeah, nobody listens to the show, what are we talking about?

03:34.780 --> 03:37.760
So, other than that, anything else worth mentioning?

03:38.020 --> 03:38.380
No.

03:39.100 --> 03:43.760
Well, you're going to be, actually, let's give a little back story to the, to the, today's

03:43.760 --> 03:44.220
topic.

03:44.280 --> 03:44.540
Okay.

03:45.140 --> 03:50.280
The, today's topic being open source security tools, which is kind of a vague topic, but

03:50.280 --> 03:57.220
I wanted to do this episode because you put together a presentation for this for an upcoming

03:57.220 --> 03:58.960
conference or something, what is that about?

03:59.460 --> 04:04.380
It's not, open source security tools, open source in general is just such a, I mean, that,

04:04.440 --> 04:10.760
that, that topic could be, you know, a series of shows in and of itself, let alone its own

04:10.760 --> 04:13.440
show, its own dedicated radio show.

04:14.200 --> 04:20.300
So, this, this topic is just very, I mean, we're scratching the surface on this, and hopefully

04:20.300 --> 04:25.800
it'll, it'll uncover some things, maybe, maybe a few people that know, or if anyone's just

04:25.800 --> 04:31.960
getting into a subject area like this, and kind of plant seeds in people's minds of, you

04:31.960 --> 04:33.940
know, more tools they can go out and find.

04:34.640 --> 04:39.800
And some of these tools that we're going to talk about today, many of our listeners have

04:39.800 --> 04:43.560
not only heard of, but are very, very familiar with these tools, but some of them they may

04:43.560 --> 04:45.780
not have, because there were some that I was not familiar with.

04:46.220 --> 04:51.200
So, hopefully, even though a couple of them you may have heard of before, maybe you'll hear

04:51.200 --> 04:54.480
something or learn something new about them that you didn't know, but you'll also pick

04:54.480 --> 04:57.800
up some of the other tools that we, that you may not be familiar with.

04:58.260 --> 05:05.140
So, yeah, let's, let's do, we're going to split the email up this week as well, but let's

05:05.140 --> 05:10.640
do a couple of this episode and a couple of next episodes, so let's give that a shot now.

05:10.640 --> 05:35.920
All right, so actually, kind of, let's put this under the email housekeeping portion.

05:35.920 --> 05:40.200
I don't want to read the emails, but I wanted to give a quick thanks to Craig, who sent me

05:40.200 --> 05:44.260
an email about having the file size on the podcast wrong last week.

05:44.600 --> 05:48.660
When we copied the file over, we have a script that copies the file over from one server to

05:48.660 --> 05:55.240
another, and it was uploaded fine, it streamed fine, the original file that we sent out, everything

05:55.240 --> 06:00.380
was fine with that, but the script that copies the file choked for whatever reason, so it

06:00.380 --> 06:05.680
sent over, out of a 15 or so megabyte file, it sent over a couple hundred K.

06:05.680 --> 06:09.860
So, it just died halfway through, and I didn't realize it when I added it to the podcast,

06:10.140 --> 06:14.020
and we have a little, kind of a, I won't say a little, a little bit of a content management

06:14.020 --> 06:19.480
system that we use to feed the podcast feed, to feed the podcast feed, yeah, something like

06:19.480 --> 06:19.720
that.

06:21.120 --> 06:24.640
So, that was, that was my mistake, and I fixed it quickly.

06:24.740 --> 06:27.740
Thanks to Craig for sending me an email about that, letting me know.

06:28.840 --> 06:32.840
Now, as far as the email, I think really, there's, just as one very short email, we'll save

06:32.840 --> 06:36.940
the rest for the next episode coming up in an hour and a half, stay tuned for that.

06:37.560 --> 06:42.560
So, our first email, and only email for this episode, comes from Prince Vegeta, and it is

06:42.560 --> 06:47.860
very short and to the point, and it just says, quote, I wanted, I just wanted to say that

06:47.860 --> 06:50.820
episode 149 was one of the best.

06:50.820 --> 06:57.860
So, straight to the point, Vegeta, thank you for that, I appreciate it, and episode 149,

06:58.160 --> 07:03.840
for those of you who may not remember offhand, was with our good friend, Tabiz, long-time

07:03.840 --> 07:08.440
friend of the show, long-time friend of mine in real life from the BR561 meetings, and also

07:08.440 --> 07:14.120
our newest forum moderator, Tabiz, so welcome him to the forums, to the, to moderating of the

07:14.120 --> 07:16.260
forums, of course, he's been around for a while, as many of you know.

07:16.260 --> 07:21.660
Now, the topic on that episode was digital forensics, where we went down this long list

07:21.660 --> 07:25.940
of different tools, with some interesting discussion and information about different

07:25.940 --> 07:32.440
forensics tools, whether it was hard drive, encrypting, decrypting, data recovery, etc., etc.,

07:32.440 --> 07:37.400
that sort of thing, and if you like that show, then I think you'll also like tonight's show

07:37.400 --> 07:41.420
as well, so I thought that was kind of a good segue into the main topic tonight.

07:41.420 --> 07:45.620
Alright, so, it is also good to know that people are still listening to the archives,

07:45.720 --> 07:51.420
I know, um, we do get email occasionally of somebody replying to something from even

07:51.960 --> 07:56.740
early episodes, or, or months old, several months old episodes, it's great that people

07:56.740 --> 08:01.460
are still listening to those, I do still believe, I occasionally will go back and listen to an

08:01.460 --> 08:07.480
old episode, or look for something specific, and I am surprised and proud of how well they

08:07.480 --> 08:08.100
stand up.

08:08.100 --> 08:13.360
A lot of that stuff has not expired, it hasn't changed a whole lot, so the principles and

08:13.360 --> 08:18.280
the things that we're trying to explain and hopefully teach about, the concepts don't

08:18.280 --> 08:22.480
really change that much, so really, you can start listening to some of those old episodes,

08:22.640 --> 08:27.880
even starting with one and try to catch up sequentially, or listen to the newest one while you start

08:27.880 --> 08:32.260
to catch up and keep up to date, and there's still a lot of good information, so please feel

08:32.260 --> 08:36.700
free to take advantage of the archive, don't worry about the bandwidth, I'll cover that,

08:36.700 --> 08:41.660
that comes out of my wallet, so, um, I'm glad to do that if you're enjoying and learning from

08:41.660 --> 08:42.040
the show.

08:42.040 --> 08:48.900
So, that being said, Quine, how about we kind of segue here into the main topic, which again

08:48.900 --> 08:51.620
is open source security tools.

08:51.740 --> 09:00.380
Now, first of all, why are we, we're talking about open source tools, not free tools, not

09:00.380 --> 09:07.460
freeware, not whatever, I mean, open source tools, which obviously means the source code

09:07.460 --> 09:08.120
being available.

09:08.120 --> 09:13.000
The source is available, and generally you can modify it, um, of course, with some licenses

09:13.000 --> 09:17.760
there are constraints that suggest that you should, should I talk, suggest that you should,

09:17.840 --> 09:23.880
um, redistribute that, that source, the modified source, uh, with the same license or with

09:23.880 --> 09:26.460
acknowledgements that are defined within the, uh, the license.

09:26.460 --> 09:30.340
So, this is very, very specific.

09:30.440 --> 09:32.620
This is what the man told me I needed to talk about.

09:32.900 --> 09:37.940
Oh, so, so, well, see, the thing is we could, honestly, we need to limit it because there's

09:37.940 --> 09:43.160
so many security tools out there we could spend episode after episode, we could spend an episode

09:43.160 --> 09:48.340
on each individual one if we really wanted to try to focus on details of each individual

09:48.340 --> 09:51.700
tool, which actually may be good shows to do at some point.

09:51.700 --> 09:56.360
Now, open source, of course, referring to open source code, the source code being available

09:56.360 --> 10:00.860
that you can view the source and see exactly what the program's doing and how it's doing

10:00.860 --> 10:01.040
it.

10:01.280 --> 10:06.140
Now, why are we, when you say open source tools, why are we focusing just on open source

10:06.140 --> 10:06.340
tools?

10:06.420 --> 10:07.580
We're not covering freeware, right?

10:07.940 --> 10:08.180
Right.

10:08.460 --> 10:15.320
This is, this is software for which the, the source code is available for you to view, uh,

10:15.660 --> 10:19.660
generally, we're, we're referring to ones that you can modify and redistribute, uh, some

10:19.660 --> 10:24.260
of the licenses, of course, say that you need to redistribute it with the same license, um,

10:24.640 --> 10:29.000
for everyone else to see, uh, that source code as well and modify it and do the things

10:29.000 --> 10:29.720
that you did to it.

10:29.980 --> 10:35.640
Well, and, and licensing is an interesting term to bring up because there are lots of different

10:35.640 --> 10:38.400
types of licenses on open source software.

10:39.340 --> 10:44.880
Yeah, there, there are a ton and there are a few that are pretty, um, adaptable, uh, one

10:44.880 --> 10:51.540
of which being the artistic license, uh, usually won't find, uh, the official definition of

10:51.540 --> 10:52.360
an artistic license.

10:52.480 --> 10:57.480
People are allowed to kind of adapt that, um, to, to, you know, how they want, uh, to come

10:57.480 --> 11:01.660
up with their own constraints or licensing terms, but it kind of falls under this artistic

11:01.660 --> 11:02.520
license umbrella.

11:03.000 --> 11:07.500
Uh, ones that other people are most familiar with, of course, are like the GNU general public

11:07.500 --> 11:13.840
license, the GPL, uh, the LGPL BSD license, Mozilla public license, uh, and of course Apache,

11:13.840 --> 11:19.500
um, and there are a few others that, uh, could be used as an open source, or, uh, excuse

11:19.500 --> 11:21.120
me, an open source license like Creative Commons.

11:22.120 --> 11:27.300
Um, yeah, and you know what, I'm kind of thinking to myself, we really could go into a whole episode

11:27.300 --> 11:32.860
just about that, so we probably shouldn't spend too much time here, except obviously knowing

11:32.860 --> 11:38.620
that there are several different types of licenses, but all work well with open source

11:38.620 --> 11:39.260
software.

11:39.260 --> 11:44.240
So maybe we'll do another episode about licenses separately one day.

11:44.420 --> 11:47.540
I'm not going to put you on the spot now to do it, um, but...

11:47.540 --> 11:49.300
I thought I wiped the sweat from my brow.

11:50.020 --> 11:54.640
But we do, it is worth mentioning, of course, that there are, the licenses exist on these,

11:54.980 --> 11:59.420
because sometimes people that don't understand open source don't realize there is a license,

11:59.600 --> 12:04.260
it's just that the license allows you to redistribute the source code, look at it, modify it,

12:04.260 --> 12:07.220
et cetera, whatever the limitation, but there is an actual license.

12:07.260 --> 12:12.000
It doesn't mean there's no license, there's just a very liberal license on what you can

12:12.000 --> 12:13.200
do with that source code.

12:13.420 --> 12:13.760
Right.

12:14.080 --> 12:14.840
Now...

12:14.840 --> 12:22.860
Within the context of the presentation, really what we mean by open source, um, is, uh, the

12:22.860 --> 12:28.680
one that goes by the jargon file, which is, um, and I quote, term, open source is a term

12:28.680 --> 12:34.560
point in March of 1998 that, uh, followed the Mozilla release to describe software distributed

12:34.560 --> 12:40.540
in source under licenses guaranteeing anybody rights to freely use, modify, and redistribute

12:40.540 --> 12:40.960
the code.

12:41.160 --> 12:42.180
So just keep that in mind.

12:42.240 --> 12:44.200
That's really what we mean when we say open source.

12:44.200 --> 12:46.380
So textbook definition, so to speak.

12:46.960 --> 12:48.820
Now, what are some other factors?

12:49.000 --> 12:51.480
Like, let's say you're looking at open source software.

12:52.460 --> 12:57.760
Now, again, we're, you know, from a hacker standpoint, a lot of this stuff, quite frankly,

12:57.760 --> 13:01.740
we don't care about to a certain extent, like, we just want to download it, compile it, and

13:01.740 --> 13:07.680
it works, but a lot of listeners of the show do have to be concerned with things like licenses.

13:08.780 --> 13:11.060
What other concerns would somebody like that have?

13:11.140 --> 13:14.180
I mean, and, and maybe even hackers to a certain extent might find some of this.

13:14.280 --> 13:19.500
I mean, like, for example, for example, is it important, like, the, who's writing the

13:19.500 --> 13:19.820
software?

13:20.120 --> 13:24.500
Like, whether it's some, you know, 13-year-old kid who's writing his first application.

13:24.860 --> 13:26.800
I mean, is, is stuff like that even come into play?

13:26.800 --> 13:31.520
Well, yeah, I mean, you want to take into consideration, is this piece of software you're

13:31.520 --> 13:34.380
looking at, is there a community behind it?

13:34.740 --> 13:36.940
Is, is, does it have a good reputation?

13:37.240 --> 13:43.720
I mean, if you're going to be running, you know, a project on the side, you know, that

13:43.720 --> 13:49.320
you're, you're hosting something, you know, your website or your content management system,

13:49.440 --> 13:53.380
as an example, what is the reputation of this software?

13:53.380 --> 13:57.960
Or is it frequently, uh, known to have vulnerabilities reported in it?

13:57.960 --> 13:59.420
Um, is it stable?

14:00.020 --> 14:05.640
Is, is the team behind it, uh, core team as in the case of something like OpenBSD?

14:05.920 --> 14:11.340
Or is it just a bunch of, of loose-knit, uh, contributors who are just contributing pieces

14:11.340 --> 14:16.340
of code, uploading things, you know, uh, submitting things, um, into subversion or committing things

14:16.340 --> 14:20.620
in CBS, you know, left and right with no real sanity checks here, you know?

14:20.620 --> 14:24.940
Is, is there someone who's reviewing this code, so to speak, or is it just kind of people

14:24.940 --> 14:28.900
throwing, um, snippets here and there and putting it together, hacking it together?

14:29.540 --> 14:30.240
Kernel hackers.

14:30.900 --> 14:32.560
Yeah, absolutely, you know, as an example.

14:32.660 --> 14:34.520
As a good example, yeah, I think so.

14:35.020 --> 14:38.860
So, another thing is maybe, is this, is this a mature piece of software?

14:38.940 --> 14:40.120
Has it been around for a while?

14:40.120 --> 14:46.600
Um, or is it just, is it, is it, is it an alpha, or pre-alpha, and has it been sitting

14:46.600 --> 14:52.960
there for a long time now, or did it just come out last week, and is the, is the, does

14:52.960 --> 14:56.200
it have kind of a, uh, exposure to the field, so to speak?

14:57.340 --> 15:01.500
Now, and I kind of said this as a joke earlier, that hackers might not care, but to a certain

15:01.500 --> 15:03.200
extent, we do care.

15:03.320 --> 15:04.080
Does, is it work?

15:04.140 --> 15:05.880
Is it going to do what we expect it to do?

15:06.080 --> 15:07.640
Or is it going to give us false information?

15:07.640 --> 15:14.140
So, we care to that extent, obviously, and if it's something that, again, some, some

15:14.140 --> 15:18.520
13-year-old kid could have written, and it could be brilliant, you know, user feedback

15:18.520 --> 15:20.100
and stuff like that comes into play.

15:20.200 --> 15:24.480
You can, other people that have been testing it, beta testing, forums, things like that,

15:24.520 --> 15:25.500
where they're giving you some feedback.

15:26.140 --> 15:29.460
Yeah, I mean, you want to look at, is there a community behind this?

15:29.460 --> 15:37.020
Is there a mailing list, um, or a forum, or a wiki, or something where people have information

15:37.020 --> 15:40.460
available, and feedback, uh, user feedback available?

15:40.860 --> 15:44.900
What do other users have to say about things like this, uh, about this piece of software?

15:45.680 --> 15:51.240
Or, or is there, is there some resource you can go to, someone that you know that's used

15:51.240 --> 15:57.860
this, um, software, and can vouch for its, for its stability, for its reputation?

15:57.860 --> 16:07.060
Uh, well, and, and that actually brings up another good point, that, um, let's, again,

16:07.120 --> 16:10.620
and this kind of goes back to maybe if you're using this in an office environment, or, or

16:10.620 --> 16:14.900
again, even as a hacker, for the most part, hackers provide their own support, I guess you

16:14.900 --> 16:21.060
would say, but sometimes you'll find a, a problem or a bug, or let's, again, shift to

16:21.060 --> 16:26.320
the office scenario if you're actually wanting to use this as a security professional, and we

16:26.320 --> 16:32.640
all know how much I love them, um, but seriously, you do, sometimes you need official support,

16:32.780 --> 16:38.820
and you, okay, so let me phrase it as a question, you can or cannot get support for any, some,

16:38.880 --> 16:40.640
or all of the tools that we're about to talk about?

16:40.640 --> 16:45.720
Uh, some of these, well, most of the ones that we're going to talk about, um, are generally

16:45.720 --> 16:51.480
not, there are a few of them that do have support available.

16:51.480 --> 16:57.700
In the cases of ones that, uh, don't have official support from the developers, or from

16:57.700 --> 17:03.000
the people who, who manage or control this piece of software, there are some organizations

17:03.000 --> 17:07.060
that do offer third-party support for open source applications.

17:07.420 --> 17:13.100
So let's say you go to Red Hat, and you buy, well, or you download, you know, you get Red

17:13.100 --> 17:13.720
Hat Linux.

17:14.060 --> 17:15.620
They'll offer commercial support from there.

17:15.620 --> 17:15.680
Well, Fedora.

17:16.020 --> 17:16.680
Well, Fedora.

17:17.180 --> 17:18.940
Um, well, no, you can still get Red Hat Enterprise.

17:19.420 --> 17:19.740
Uh.

17:20.120 --> 17:20.600
For free?

17:20.600 --> 17:22.920
I mean, you could download the source.

17:23.520 --> 17:23.880
Really?

17:24.160 --> 17:24.780
Uh, hmm.

17:24.960 --> 17:28.740
Well, you can get the binaries as well, but, like, to do updates, you have to be, you have

17:28.740 --> 17:32.660
to, oh, yeah, from where you can register one box, basically, per email address.

17:33.100 --> 17:38.320
Um, but you can get commercial support from them for certain pieces of software that they

17:38.320 --> 17:39.400
may, uh, sell.

17:39.800 --> 17:46.080
But there are organizations, there are companies that basically devote themselves to supporting

17:46.080 --> 17:50.760
open source software that might not otherwise have a support team behind it.

17:51.640 --> 17:57.040
Again, this kind of goes back to getting support from the user community, from the developers,

17:57.640 --> 18:03.400
um, from any other, or just learning about it yourself and kind of being self-sustaining.

18:03.400 --> 18:05.580
Right, and that's, that's the hacker side.

18:05.720 --> 18:05.840
Right.

18:05.940 --> 18:10.700
That's the hacker, the hacker methodology, unfortunately, because part of it is, part of it was from

18:10.700 --> 18:16.820
the hacker side where it's just like, my experience with support of any and all kinds that I've

18:16.820 --> 18:21.060
ever had is that the person on the other end of the line knows less than I do about the

18:21.060 --> 18:21.360
software.

18:21.360 --> 18:26.020
And that gets really frustrating, or I can't understand what they're saying to me, no offense,

18:26.360 --> 18:30.880
but they can't speak the language, and they want to walk me through the level one stuff.

18:31.020 --> 18:34.740
Oh, turn on your computer, you must restart your computer.

18:35.040 --> 18:39.180
Okay, look, I've done that, and I've done taking a look at the code, and I've sniffed the

18:39.180 --> 18:40.940
packets, and it looks like they're being malformed.

18:41.260 --> 18:42.820
Can I talk to somebody a little bit higher up?

18:42.860 --> 18:44.800
Okay, buddy, hold on just a minute.

18:45.440 --> 18:46.760
Did you reboot your computer?

18:46.880 --> 18:48.300
Yes, I rebooted the computer, shut up.

18:48.300 --> 18:53.800
Yeah, so yeah, I find that support for open source software is infinitely better than commercial

18:53.800 --> 18:59.360
software, because of commercial software vendors, that comes with, as part of the price of the

18:59.360 --> 19:03.160
software, with the open source, it's more community feeling.

19:03.680 --> 19:08.280
Like, what jumps to mind for me for that is, well, besides Linux, which has got so much

19:08.280 --> 19:12.080
support all over the place, and I know some of the listeners are kind of tired of hearing

19:12.080 --> 19:15.360
about this piece of software, but Asterisk is like that as well.

19:15.360 --> 19:20.760
So, it's got a lot of aftermarket support, and actually, the other thing that I have to

19:20.760 --> 19:30.020
say I like about the way they work there is that they do provide the software and make

19:30.020 --> 19:35.100
their money on the support, but so do a lot of other outside third-party companies provide

19:35.100 --> 19:36.340
support for it.

19:36.540 --> 19:41.300
A lot of free forums, mailing lists that are free provide some sort of support for it.

19:41.300 --> 19:45.360
Even our forums, a lot of Asterisk stuff gets worked out and debugged through the bin rev

19:45.360 --> 19:45.660
forum.

19:45.800 --> 19:49.900
I mean, so many different ways that you can get support, so obviously, I guess the bottom

19:49.900 --> 19:51.400
line is the more, the better.

19:51.880 --> 19:52.160
Well, yeah.

19:52.160 --> 19:52.720
As long as it's reliable.

19:52.760 --> 20:00.040
Well, you've got to take into account that a lot of organizations, a lot of companies, it's

20:00.040 --> 20:04.680
all well and good that you can get free support for this piece of open source software via

20:04.680 --> 20:10.180
forums and user communities, but they kind of have to CYA, so to speak, and cover their

20:10.180 --> 20:16.460
own butts and have official commercial support so that their customers, you know, they can

20:16.460 --> 20:21.340
kind of give this warm and fuzzy to their customers and say, oh, well, if we do have a problem with

20:21.340 --> 20:26.340
such and such piece of open source software that we run, we can refer to company XYZ that

20:26.340 --> 20:27.060
supports it.

20:27.060 --> 20:32.640
So we don't have to be, you know, scrambling to look through docs to figure out why this

20:32.640 --> 20:33.860
is doing this.

20:34.060 --> 20:37.900
Well, and something else kind of funny and an interesting way, and an interesting and

20:37.900 --> 20:43.960
a funny sort of way is there are some tools out there that are perpetually in a state of

20:43.960 --> 20:44.240
beta.

20:44.800 --> 20:45.020
Yeah.

20:45.100 --> 20:45.320
Right.

20:45.320 --> 20:49.560
Because they never want to officially release anything, possibly that being one of the reasons

20:49.560 --> 20:53.060
because then they have to support it, then they have to answer for this being final,

20:53.280 --> 20:55.220
fully tested code and things like that.

20:55.220 --> 21:01.060
And in their license, they can say, hey, this is, and this is very common, as is, we

21:01.060 --> 21:05.500
hold no responsibility or liability and stuff, those kind of clauses that you'll find a lot

21:05.500 --> 21:09.780
of open source software because they're not a company, they're not making big money, so

21:09.780 --> 21:11.080
they're not going to take that liability.

21:11.280 --> 21:15.840
But I actually, a lot of commercial software has been putting those clauses in there as

21:15.840 --> 21:19.720
well, so maybe that's because they're stealing a lot of open source code and putting it in.

21:19.740 --> 21:21.040
But that's a whole other topic.

21:21.980 --> 21:23.280
That's a show in and of itself.

21:23.280 --> 21:27.060
Exactly, we won't go there, although there's been some great stories.

21:27.260 --> 21:35.040
I know a friend of mine, well, Abaddon, better known probably these days as Mike Lynn, had

21:35.040 --> 21:37.080
one of the funniest stories of that that I ever saw.

21:37.180 --> 21:42.340
It was over on meme streams with the, oh, now help me out here if I can't remember the

21:42.340 --> 21:48.140
name, but it was, I think it was Pear OS or something, the Apple, where it was a copy

21:48.140 --> 21:54.940
of Apple, and he decompiled and found actual evidence of source code that was ripped off

21:54.940 --> 21:58.020
where the byte code matched or something along those lines, it was hilarious.

21:58.020 --> 22:08.660
I think it was Pear OS complained that Cherry OS had taken code from them.

22:08.880 --> 22:09.460
That's what it was.

22:09.460 --> 22:12.000
And it was like all the, I mean, it was identical.

22:12.900 --> 22:16.760
And they were saying that, you know, we never, Cherry OS was like, we never took anything.

22:16.980 --> 22:17.180
Yeah.

22:17.180 --> 22:22.860
I think that, you know, I could be, yeah, we are not held off, don't hold us liable if

22:22.860 --> 22:24.980
that's a little bit off, but I do think that's accurate.

22:24.980 --> 22:26.100
That's the gist of the story.

22:26.340 --> 22:26.700
Exactly.

22:27.660 --> 22:31.820
Without wasting time going and looking it up on the proverbial interweb.

22:31.960 --> 22:35.560
And there is one other thing that I think is important to mention before we start going

22:35.560 --> 22:41.800
and listening and talking about some individual tools, and that is the other big, big, biggest,

22:41.880 --> 22:44.180
and I would almost say the biggest benefit.

22:44.400 --> 22:48.420
I really would say the biggest, well, I guess realistically the biggest benefit is that they're

22:48.420 --> 22:49.100
generally free.

22:49.660 --> 22:50.360
Let's be honest.

22:50.500 --> 22:52.120
I mean, that's why a lot of people are using them.

22:52.420 --> 22:58.520
But the biggest benefit, in my personal opinion, is the fact that because you have the open source,

22:58.520 --> 23:00.780
that makes them infinitely flexible.

23:01.280 --> 23:03.960
If you need it tweaked or changed, you have the source code.

23:03.960 --> 23:06.800
You can recompile and make it do what you want.

23:07.800 --> 23:10.280
So flexibility, I would say, is a big thing.

23:10.440 --> 23:16.100
Now, do you think, that being said, the majority of people are just compiling it as is, or even

23:16.100 --> 23:17.720
downloading binaries.

23:17.780 --> 23:20.700
Even though it's open source, they'll still download the binaries of it and not mess with

23:20.700 --> 23:20.880
it.

23:21.820 --> 23:23.000
Do I think that's the case?

23:23.000 --> 23:31.000
Yeah, I think it usually is the case, but there still is a vast number of people who are fixing

23:31.820 --> 23:32.860
bugs in this software.

23:32.860 --> 23:34.300
Could there be more?

23:34.420 --> 23:34.580
Yeah.

23:34.860 --> 23:38.360
And I think a lot of people don't contribute back to these projects.

23:38.920 --> 23:41.500
They don't submit bug changes.

23:41.780 --> 23:42.320
They don't.

23:42.820 --> 23:44.520
That's why so many projects die.

23:44.680 --> 23:50.460
It's because the one or two people who started them and maintained them have lives, too.

23:50.600 --> 23:52.460
And they can't devote all their time to this.

23:52.500 --> 23:57.960
So they need people to contribute changes back and contribute fixes, give feedback, take the

23:57.960 --> 23:59.120
helm when it's needed.

23:59.120 --> 24:01.440
My world and welcome to it.

24:01.500 --> 24:01.700
Yeah.

24:01.920 --> 24:02.120
Right.

24:02.860 --> 24:03.180
All right.

24:03.260 --> 24:07.260
So we're going to actually, is there anything else that you want to talk about before we

24:07.260 --> 24:11.320
get into, like, glisting through some tools and discussing some of the specific tools?

24:11.680 --> 24:12.180
Well, no.

24:12.180 --> 24:17.220
I just, I think we can segue into kind of what do we mean by open source security tools.

24:17.440 --> 24:17.720
Okay.

24:17.820 --> 24:20.040
And then we can kind of go into the tools themselves.

24:20.240 --> 24:20.560
All right.

24:20.560 --> 24:26.380
So what do we, you know, we talk about what open source is in the context of this talk.

24:27.220 --> 24:31.180
Now we want to talk about what we mean by open source security tools, because even that

24:31.180 --> 24:33.360
in and of itself is kind of nebulous.

24:33.700 --> 24:33.980
Right.

24:34.020 --> 24:34.740
I mean, that can mean a lot.

24:34.800 --> 24:36.280
That can mean different things to different people.

24:36.800 --> 24:37.000
Right.

24:37.000 --> 24:44.220
And so actually there's kind of a misconception that people have on, and again, I'm not going

24:44.220 --> 24:47.900
into a rant about security professionals, but people don't realize that they think that

24:47.900 --> 24:52.080
if you become a security professional, you get paid to hack or pen test or stuff.

24:52.260 --> 24:52.440
Right.

24:52.440 --> 24:58.540
And a lot of that work is boring writing up of, well, I mean, not to insult it, but it's

24:58.540 --> 25:06.080
writing up a lot of password policies and rules for the company that you have to follow.

25:06.220 --> 25:11.560
You're only allowed to use this VPN client, or you're only allowed to use this type of

25:11.560 --> 25:14.060
antivirus, and you have to update it, and you have to change your password.

25:14.300 --> 25:19.580
You have to do a lot of policy work, and that is, that's a lot of what most people, anybody

25:19.580 --> 25:22.820
who thinks they're going in are going to have exciting pen testing and lots of tools and

25:22.820 --> 25:23.040
playing.

25:23.260 --> 25:31.560
A lot of it's writing and, well, again, security is just in the same vein that you can do a

25:31.560 --> 25:36.900
lot of different things related to hacking, because hacking means different things to

25:36.900 --> 25:39.140
different people, so does security.

25:39.280 --> 25:43.180
Security or information security, computer security, network security, whatever you want

25:43.180 --> 25:49.020
to call it, has so many different aspects to it, and there's so many different paths you

25:49.020 --> 25:49.480
can take.

25:49.660 --> 25:50.060
Exactly.

25:50.220 --> 25:51.340
That's what I was alluding to.

25:51.600 --> 25:51.820
Right, right.

25:52.560 --> 25:59.540
So, now, you broke these down into three different categories, or do you want to go there yet,

25:59.580 --> 26:00.360
or did you still want to?

26:00.400 --> 26:05.340
No, I still want to just kind of clear the air, just so everyone's on the same page, so

26:05.340 --> 26:05.820
to speak.

26:06.640 --> 26:14.860
What we mean by open source security tools in the context of the talk is software or applications

26:14.860 --> 26:22.820
that are covered under an open source license that are designed to either test or enhance

26:22.820 --> 26:24.960
one's security posture.

26:25.100 --> 26:29.860
That could be an attack in one case, or, you know, testing and security testing, or defense.

26:31.020 --> 26:38.080
Also, we have some other things that may not actually be security tools, just security

26:38.080 --> 26:40.580
tools, but may have an application to security.

26:40.580 --> 26:45.120
I think, for example, OpenLDAP, which we'll get into a little bit later.

26:45.540 --> 26:47.360
I'm sure some people are familiar with that.

26:47.880 --> 26:50.600
We'll go over that a little bit more later in the talk.

26:51.480 --> 26:57.700
So, we're going to cover, without further ado, we're going to actually dive into the tools

26:57.700 --> 26:58.240
themselves.

26:59.480 --> 27:02.380
And you broke them down as far as, and I like that.

27:02.460 --> 27:06.480
I think this is a good flow to the presentation that you're going to give, as well as for the

27:06.480 --> 27:12.900
show, is breaking them down into, and kind of what you're just alluding to, but tools

27:12.900 --> 27:20.660
of attacking, tools of defending, and then other, I guess, miscellaneous, other things

27:20.660 --> 27:22.560
that aren't quite as easily categorical.

27:22.800 --> 27:28.640
And actually, I found it interesting that some of these you classified in a group that I really

27:28.640 --> 27:33.420
didn't think that was where it would go at first glance, but you did it for a different

27:33.420 --> 27:35.180
reason that I didn't really think of at first.

27:35.240 --> 27:38.840
So, I guess we'll just kind of go through the list, and as that comes up, we'll...

27:38.840 --> 27:39.040
Right.

27:39.500 --> 27:39.840
Okay.

27:42.420 --> 27:44.820
Yeah, like I said, we're going to start with attack tools.

27:45.360 --> 27:50.040
And again, as we said before, this is just scratching the surface.

27:50.200 --> 27:53.260
I mean, this is not representative of all the tools that are out there.

27:53.340 --> 27:53.600
Of course.

27:53.600 --> 27:55.500
I mean, this could...

27:55.500 --> 28:01.600
We have so much time to fill and talk, but we could go on and have a year's worth of

28:01.600 --> 28:03.440
shows just dedicated to this.

28:03.600 --> 28:07.020
I mean, we could branch this off into its own radio show.

28:07.220 --> 28:07.440
Yeah.

28:07.580 --> 28:11.980
We're probably going to talk about, what, 10, 15, 20 tools in this whole thing.

28:12.100 --> 28:12.260
Right.

28:12.500 --> 28:13.500
And each one of those...

28:13.500 --> 28:14.840
That's not an exaggeration.

28:14.920 --> 28:16.300
Each one of those could probably be an episode.

28:16.480 --> 28:16.800
Exactly.

28:16.800 --> 28:17.400
They really could.

28:17.500 --> 28:20.040
They're going to the depth, especially because they're open source.

28:20.120 --> 28:23.180
We can talk about how they do it, why they do it, talk about source.

28:23.180 --> 28:26.060
I think that might be dry radio to listen to, but...

28:26.060 --> 28:26.080
Yeah.

28:27.140 --> 28:29.520
But, you know, it is...

28:29.520 --> 28:31.120
This is just scratching the surface.

28:31.340 --> 28:36.460
But hopefully, with this information, people will kind of get motivated to learn more about

28:36.460 --> 28:38.540
them or say, oh, I never knew about that tool.

28:38.620 --> 28:40.600
I didn't know this tool did that.

28:41.100 --> 28:45.240
And again, some of these tools, our listeners are going to be very familiar with.

28:45.280 --> 28:46.140
Others, maybe not.

28:46.660 --> 28:50.060
So, I guess, let's just kind of go through them.

28:50.140 --> 28:50.940
Enough about that.

28:51.080 --> 28:51.680
Starting with...

28:51.680 --> 28:52.140
Let's get running.

28:52.320 --> 28:53.060
...attacking tools.

28:53.060 --> 28:55.980
So, we're going to talk first about Edercap.

28:56.360 --> 29:03.120
And for those of you who aren't familiar, Edercap is an active and passive protocol analyzer

29:03.120 --> 29:06.020
or sniffer, as it's commonly referred to.

29:06.480 --> 29:08.120
It has a variety of features.

29:09.240 --> 29:13.360
Most notably, and what a lot of people who are familiar with Edercap know, is that it

29:13.360 --> 29:18.440
does ARP poisoning, address resolution protocol poisoning, which, for those of you who aren't

29:18.440 --> 29:23.320
familiar, are familiar, ARP is what maps IP addresses to MAC addresses or hardware addresses.

29:23.780 --> 29:30.640
And using that technique, we can effectively do man-in-the-middle attacks on switch networks

29:30.640 --> 29:36.000
and get in between hosts and capture traffic that would otherwise only go between them.

29:36.000 --> 29:46.060
It also supports data injection so that we can actually inject data into the traffic stream that we might have control over on, say, a

29:46.060 --> 29:50.820
switch network or in a shared network where we really have to do man-in-the-middle or ARP poison.

29:50.820 --> 29:53.640
And we can just inject the data into the traffic stream.

29:54.660 --> 30:08.060
And as do a lot of other tools, Edercap also has OS fingerprinting or operating system fingerprinting to let us know what operating system the target host might be running.

30:08.180 --> 30:15.100
This is passive, of course, as opposed to NMAP, which is actually sending traffic to the host and is a little more detectable.

30:15.460 --> 30:20.680
This isn't completely stealthy, especially if you're doing ARP poisoning, then traffic is actually being sent out.

30:20.820 --> 30:23.660
And don't a lot of intrusion detection systems.

30:23.780 --> 30:32.240
I think you were telling me this when we were doing this at the meeting about a lot of intrusion detection systems, IDS or IPS,

30:33.340 --> 30:38.740
they look for an unusually large amount of ARP packets, and that triggers some of them, right?

30:38.900 --> 30:49.420
There are some IDSs that have that capability, but bear in mind that most intrusion detection systems typically look at layer 3 and up,

30:49.420 --> 30:52.120
which would be the network layer, for example, IP.

30:52.260 --> 30:54.100
They would look at IP traffic and up.

30:54.880 --> 31:00.200
ARP poisoning occurs at layer 2, or the data link layer.

31:00.200 --> 31:09.280
Now, also, and I've got to, this is actually one of the ones I referred to a few minutes ago where I wasn't sure,

31:09.460 --> 31:13.560
I was kind of surprised at where some of you classified some of these enter cap as an attack tool,

31:13.620 --> 31:19.360
because I've always thought of it, I guess I never really thought too much about the ARP poisoning or the data injection,

31:19.700 --> 31:25.020
I've always thought about enter cap as a completely passive tool, a sniffer, like you said,

31:25.020 --> 31:29.700
that's what they're commonly referred to as, I've always thought of it as simply a quiet, passive tool

31:29.700 --> 31:34.380
that's just sniffing the data, doesn't let anybody know it's there, doesn't send anything out,

31:34.420 --> 31:39.500
it just stays in the middle, quietly sniffing all the traffic and either redirecting it to you or saving it

31:39.500 --> 31:44.140
so that you can come look at it or get it later, or whatever, so I never really considered that an attacking tool.

31:44.880 --> 31:48.940
Well, it really could be, I mean, there are plugins for enter cap that do different things,

31:48.940 --> 31:54.360
one of them, for example, would be to find other nodes that are doing ARP poisoning.

31:55.120 --> 32:00.580
Another one could be the Banshee plugin that was in there for a while, and I believe it's still in there,

32:01.140 --> 32:03.740
that actually just kills connections over and over again.

32:03.920 --> 32:11.660
So that's, of course, a little more of a denial of service, but a lot of these tools may feed into one another.

32:11.660 --> 32:17.600
I mean, if you're sitting there capturing traffic, that could be data that you could use later,

32:17.600 --> 32:23.080
such as, you know, usernames and passwords, or you could inject data in there

32:23.080 --> 32:30.220
and cause something else to occur, which would, you know, be a type of attack.

32:30.900 --> 32:36.940
So a lot of these tools may be chained together to formulate one big, giant attack, so to speak.

32:38.280 --> 32:42.660
Better cap is covered under the GPL, so...

32:42.660 --> 32:47.280
Well, and every one of these, I don't know if we want to mention the license for all of them,

32:47.280 --> 32:50.440
if it's too much, but, um, yeah, these are all under some open source.

32:50.820 --> 32:53.500
Your mileage may vary. Go check out the individual ones, and...

32:53.500 --> 32:56.840
A lot of these, a lot of these, of course, will tell you what license they're covered under.

32:57.680 --> 33:01.000
Sandy, naked pictures of your boobies license, is that all under artistic?

33:01.000 --> 33:02.300
I don't know, that's, um...

33:02.300 --> 33:03.380
It's an artistic license, huh?

33:03.720 --> 33:04.900
Yeah, it's definitely an artistic...

33:04.900 --> 33:07.000
Well, what do you call it? What do you consider art, you know?

33:07.200 --> 33:10.300
Well, that's not even... Let's not go all Mappletharp here or anything.

33:11.600 --> 33:12.960
That's a whole different show.

33:12.960 --> 33:15.040
Well, I don't know what show that is, but it's not different.

33:16.120 --> 33:22.780
Um, now, sticking with... Staying on topic here, um, Ettercap, there is a GUI for that, right?

33:22.780 --> 33:28.480
Well, there's the, uh, there's a Curses interface, which is a console menu-driven interface,

33:28.620 --> 33:34.560
but there's also an actual GTK, uh, interface for it, so you can actually point and click.

33:34.820 --> 33:36.960
Right, Curses is what I mean, that's your...

33:36.960 --> 33:38.780
Right, it's, it's...

33:38.780 --> 33:43.080
It's not a Windows, it's not a windowed GUI, like, uh, uh, an ex-Windows, or, uh...

33:43.080 --> 33:45.280
Right, it's a, it's a character-driven menu interface.

33:45.600 --> 33:51.740
But there is also a, a GTK, or, you know, you know, GIMP Toolkit, uh, interface.

33:51.740 --> 33:53.840
Now, is there much difference between the two? Are they pretty...

33:53.840 --> 33:55.420
No, they look pretty much the same.

33:55.460 --> 33:55.620
Really?

33:55.760 --> 34:00.440
Just, um, a little, you know, cleaner for some people.

34:00.440 --> 34:06.720
So, so, alright, well, Ettercap, again, it's kind of an interesting that you put it into attack tools,

34:06.860 --> 34:11.420
but, um, since I always think, I think of all Sniffers, the whole category, as a passive tool,

34:11.480 --> 34:14.980
so it gives me a new way to, to look at it and to think about it.

34:15.240 --> 34:18.040
Now, what else, what other kind of attacking tools do you have in here?

34:18.300 --> 34:22.020
Uh, the next one that we're gonna talk on, uh, touch on is Yersinia.

34:22.640 --> 34:28.800
Um, Yersinia is really, well, I think we called it at the BR-407 meeting, uh,

34:28.800 --> 34:31.300
the network fuck you up the ass tool.

34:32.720 --> 34:34.440
That was, that was how it was...

34:34.440 --> 34:39.180
Well, it's easier to pronounce than Yersinia, Y-E-R-S-I-N-I-A,

34:39.260 --> 34:40.740
just in case we're not enunciating.

34:40.840 --> 34:41.160
Right.

34:41.260 --> 34:42.600
It's a very unusual name.

34:43.020 --> 34:47.400
Um, so Yersinia is a multi, it's a multi-protocol attack...

34:47.400 --> 34:48.960
It's an accurate name, too, by the way.

34:49.380 --> 34:51.020
It really, that's an accurate name for the tool.

34:51.040 --> 34:52.060
Network fuck you up the ass tool.

34:52.240 --> 34:52.640
Exactly.

34:52.640 --> 34:57.640
Yeah, and the reason that being is, um, whereas a lot of other tools,

34:57.640 --> 35:03.680
tools, the network attack tools, or packet crafting tools, um, do just that.

35:03.760 --> 35:04.840
They craft packets.

35:05.620 --> 35:10.200
Uh, Yersinia really does more, does, like, layer two frames.

35:10.360 --> 35:11.380
It does layer two attacks.

35:11.800 --> 35:17.300
Uh, some of those include Spanning Tree Protocol, um, CDP or Cisco Discovery Protocol,

35:17.300 --> 35:23.920
uh, DHCP, um, HSRP, which is Hot Standby Router Protocol.

35:23.920 --> 35:28.960
It also does VLAN Trunking Protocol, and 802.1Q, which is also used for VLANs.

35:29.960 --> 35:37.140
Um, so what this allows us to do is, uh, to give you an example, Spanning Tree Protocol is used, uh,

35:37.140 --> 35:45.400
to eliminate, uh, loops within massive switch networks, uh, and within STP, or Spanning Tree Protocol,

35:46.120 --> 35:51.160
it, it also allows, uh, switches to know where other switches are located,

35:51.160 --> 35:57.580
so that traffic can get from one switch to the other, um, and in, in the case of switches being interlinked,

35:57.580 --> 36:06.140
it will, it will cause these, these crazy traffic loops, uh, so within STP, our, we have what's called the root bridge,

36:06.220 --> 36:12.160
or the root roll, and that is kind of like the core, that's, that's the switch that knows, kind of the, the infrastructure,

36:12.280 --> 36:14.860
that knows the, right, there's one, the topology.

36:15.040 --> 36:19.120
There's one that's a, everything kind of goes, an official, yeah, right.

36:19.120 --> 36:26.600
And there's all these other, uh, Spanning Tree is, is, is a mathematical, um, network, a mathematical tree,

36:26.940 --> 36:32.480
and it uses these, the Spanning Tree Protocol uses these different, uh, these different path costs

36:32.480 --> 36:36.860
to determine where, where the traffic needs to go, and what the shortest path is, and everything.

36:37.480 --> 36:43.800
Well, Yersinia, as an example, with, with regard to STP, allows us to do things, um, like, become the root roll,

36:44.240 --> 36:46.600
so that all traffic kind of goes to us.

36:46.600 --> 36:56.840
Instead of whatever the other root roll, right, and it also allows us to send out, um, raw, uh, topology updates,

36:57.020 --> 37:04.780
so that we can tell STP that the network topology has changed, and it'll have to go recalculate all these, uh, path costs and everything.

37:05.040 --> 37:08.560
Which can be bad, because it can kind of bring down a network, do you think?

37:08.700 --> 37:14.780
Um, in some cases, as, as STP has to, uh, learn, relearn the network.

37:14.780 --> 37:24.360
Um, it also, Yersinia also allows us to manipulate VLANs in a Cisco environment via, uh, VLAN trunking protocol.

37:24.580 --> 37:34.500
We can add VLANs, we can delete VLANs, and what that would allow us to do is, um, just that, create, create our own virtual LAN.

37:34.500 --> 37:48.700
Uh, Yersinia can also be used to actually hop VLANs, which has commonly been something that people have, have, have this misconception that VLANs can be used for security.

37:48.700 --> 38:01.060
They were designed for security. They were really designed more for management, more for, uh, creating virtual networks within, uh, a physical, for, within, uh, a physical switch.

38:01.060 --> 38:06.460
So, we can have virtual LANs that are physically on the same, uh, network device.

38:07.320 --> 38:18.120
So, Yersinia can be used to actually hop VLANs, or to have all VLANs come to one port, uh, when they would otherwise not be, uh, sent to that port.

38:18.280 --> 38:21.620
Yeah, but, uh, but the, the STP is my favorite part of it.

38:21.700 --> 38:21.920
Right.

38:21.920 --> 38:26.220
And, and actually, I had not heard of this tool. This is one of the ones that I said I, I was not familiar with.

38:26.280 --> 38:31.180
So, this was a new tool to me, and I found it very cool. Now, this also uses Curses, is that right?

38:31.300 --> 38:39.000
Yeah, there's a Curses interface. There's also, you can also, um, do it via the command line and just have, have it execute a particular attack.

38:39.000 --> 38:54.460
Yeah. There's also, uh, you can, it can run in what's, kind of a server mode, where you can connect to it as though you were connecting to, like, an iOS device and kind of, uh, uh, run commands that way.

38:55.080 --> 39:01.140
Um, they really touched on this a lot in, uh, hacking Cisco Networks Exposed.

39:01.140 --> 39:11.000
Because the guys over at Arhant, uh, Arhant Security went really in depth with this, uh, with this utility. And they, they did a bang-up job talking about it.

39:11.760 --> 39:12.660
And that, what was that again?

39:12.880 --> 39:13.140
That was?

39:13.140 --> 39:16.420
Uh, Hacking Cisco Networks Exposed, or Hacking Exposed Cisco Networks.

39:16.420 --> 39:16.760
Okay.

39:16.760 --> 39:16.920
It's a book.

39:17.580 --> 39:19.500
No, that's why I wanted to make sure the listeners heard it.

39:19.640 --> 39:22.840
And it, is that the, that's not from Singres, is it?

39:22.920 --> 39:24.180
No, that's actually from, um.

39:24.180 --> 39:25.300
They do the Black Hat series.

39:25.380 --> 39:25.520
Right.

39:25.520 --> 39:28.100
Who is it that does the Hacking Exposed?

39:28.100 --> 39:28.420
Is it?

39:29.360 --> 39:30.300
Oh, my goodness.

39:30.300 --> 39:34.240
Okay, well, I guess we'll let the listeners figure out.

39:34.380 --> 39:35.060
McGraw-Hill.

39:35.600 --> 39:37.020
No, it's not McGraw-Hill, is it?

39:37.380 --> 39:38.000
I don't think so.

39:38.060 --> 39:38.580
I don't remember.

39:38.980 --> 39:39.340
You know what?

39:39.520 --> 39:41.100
You guys can look that up, you lazy bastards.

39:41.700 --> 39:43.160
Alright, anyway, next tool.

39:43.600 --> 39:45.780
Since I can't remember it, I shift blame to the listener.

39:45.900 --> 39:46.740
See, it's easy as that.

39:47.300 --> 39:50.300
Um, I, gosh, but it's gonna bug me for the rest of the show now.

39:50.640 --> 39:51.700
It's sitting in the back of my head.

39:51.720 --> 39:54.340
If I remember it before the show is over, I will let you know.

39:54.620 --> 39:54.880
Right.

39:54.880 --> 40:00.040
So, it would be great if we could somehow access information through some sort of a browser or something

40:00.040 --> 40:03.160
online where I could look stuff up when I need to find the answer.

40:03.620 --> 40:10.400
If they ever invent a technology like that, some sort of, like, inter-web-connected network of a worldwide

40:10.400 --> 40:14.240
something like that, that would be really handy right about now.

40:14.240 --> 40:24.720
So, yeah, Yersinia, I mean, the, these, these STP BPDUs, as they're called, bridge protocol data units, um, can cause massive

40:24.720 --> 40:34.740
problems in, uh, networks that use Spanning Tree, um, or they can be used to make you the root roll, as I said before, and have a lot of traffic sent to you.

40:34.740 --> 40:43.500
Now, of course, you need a machine that can, that can handle that, otherwise, you're, you're gonna be noticed when the network slows to a complete crawl.

40:44.920 --> 40:49.800
Well, or maybe not, depending on how your network might be, that might be normal for your network.

40:50.800 --> 40:56.400
Again, we could do an entire show on Yersinia, and, um, you know, maybe one day, maybe, maybe we will.

40:56.400 --> 41:06.340
Also, uh, if you go to Yersinia.net, there's, uh, there was an entire, there was a presentation done at Black Hat 2005 that might be

41:06.340 --> 41:11.600
really, really useful if you want more information on Yersinia. It's a, it's a really good presentation.

41:11.600 --> 41:14.000
Yeah, if you want more, more detail on it, that's definitely.

41:14.140 --> 41:16.040
About the attacks and how they work.

41:16.140 --> 41:23.560
Right, because we're, we are glossing over these, um, talking about them from a, you know, give you a general idea of what a lot of these do,

41:23.560 --> 41:30.660
and some of the features and stuff on them, and, um, but certainly, again, I've, gosh, this is like the third time I've said it,

41:30.700 --> 41:35.580
any one of these could be an episode in and of themselves, but for this particular one, check out that Black Hat presentation.

41:35.720 --> 41:36.860
Did you go to that Black Hat that year?

41:37.200 --> 41:38.000
Uh, I did not.

41:38.000 --> 41:38.200
Oh, five?

41:38.280 --> 41:38.740
No, no.

41:39.420 --> 41:44.580
Alright, so, this next tool, like, this is, what is this, NMAP or something? Do we know? Is that?

41:45.520 --> 41:48.740
Well, it, I've never heard of this tool before. What exactly is this NMAP?

41:48.860 --> 41:53.540
No, I'm just joking. Actually, um, what about, what, we're not going to,

41:53.560 --> 41:56.740
we're not going to mention NMAP because I think, yeah, I think our listeners know that.

41:56.760 --> 42:00.420
I was just joking around, but what about, and I was going to say this is a joke,

42:00.480 --> 42:04.460
what about Metasploit? Will we, will we talk about that, you think, or, um,

42:04.460 --> 42:06.540
I mean, a lot of our listeners probably know Metasploit, too.

42:06.540 --> 42:08.340
Should we go into that one, or do you want to?

42:08.420 --> 42:12.780
Well, I think we should just, um, I'm going to explain what it is.

42:12.880 --> 42:16.720
Well, okay, so Metasploit Framework is, uh, for those of you who aren't familiar,

42:16.900 --> 42:19.460
is an exploit development, um, framework.

42:19.460 --> 42:22.840
Or, uh, it's also an exploit testing and execution framework.

42:23.520 --> 42:29.120
Um, one, one of the most notable things about Metasploit or Metasploit Framework,

42:29.280 --> 42:32.080
uh, really need to be more specific that it is the framework,

42:32.200 --> 42:33.700
because Metasploit is the project.

42:33.920 --> 42:34.220
Right.

42:34.360 --> 42:38.220
Metasploit Framework is what most people refer to as Metasploit.

42:38.420 --> 42:38.800
Right.

42:38.800 --> 42:43.920
Uh, so Metasploit Framework, um, separates the exploits from the payload.

42:44.040 --> 42:45.160
Everything is, is a module.

42:45.380 --> 42:52.740
So you've got an exploit module for, say, MS04, 0011, as an example.

42:52.900 --> 42:54.320
That's just the first one that comes to mind.

42:55.240 --> 42:58.660
Uh, so you have an exploit that, that attacks that.

42:58.740 --> 43:00.580
Well, then, once you've exploited that vulnerability,

43:01.660 --> 43:05.980
you can then have a, have a certain action occur, a payload.

43:05.980 --> 43:11.320
So, let's say you, you exploit that, or you exploit, uh, a vulnerability in Samba,

43:12.060 --> 43:16.220
for which there's a corresponding Metasploit Framework module, exploit module,

43:16.440 --> 43:24.200
and then you want to add a user, or you want to return a, uh, a shell, or execute a particular command.

43:24.360 --> 43:30.060
You can kind of have different, you know, payload than going to PacketStorm

43:30.060 --> 43:33.640
and downloading something that already has a, the exploit code, the shell code,

43:33.640 --> 43:35.940
and, you know, everything already there.

43:36.080 --> 43:37.660
You can, you can decide what you want to do.

43:37.900 --> 43:40.960
Right, so like, if you had, like, if the exploit that you developed

43:40.960 --> 43:44.120
gets you total root access to the box,

43:44.300 --> 43:48.680
you could actually write three or four different payloads of what you wanted to do.

43:48.760 --> 43:50.920
Do you want it to pop up a shell where you have root access?

43:51.200 --> 43:54.060
Do you want it to upload a file that's owned by root?

43:54.060 --> 43:57.380
I mean, you could write whatever payload, or is that...

43:57.380 --> 44:05.120
Well, the, the, you, you can have, um, you can have multiple exploits for each payload.

44:05.420 --> 44:08.180
You can have multiple exploits that have the same payload.

44:08.580 --> 44:11.940
They'd be written, they're independent from each other, but they do the same thing.

44:12.060 --> 44:14.740
But you can also have one exploit with multiple payloads.

44:14.840 --> 44:15.640
That's what I'm trying to say.

44:15.680 --> 44:17.080
Can't you have multiple payloads for each?

44:17.760 --> 44:18.120
Essentially.

44:18.120 --> 44:18.860
Essentially, essentially.

44:19.140 --> 44:23.800
So, you know, like, like I said, you would have, you would choose the exploit.

44:24.560 --> 44:26.420
I'm trying to think of one example off the top of my head,

44:26.440 --> 44:29.260
and I can't come up with a good one, but, um,

44:30.740 --> 44:35.460
it, the important thing being that it separates the two stages, the two phases.

44:36.020 --> 44:41.560
Exploits being one separate part, and payload being a different separate part.

44:41.560 --> 44:43.620
They're not independent, exactly.

44:44.220 --> 44:46.260
There is a relationship between the two of them.

44:46.260 --> 44:49.900
Um, but, they are two separate things.

44:50.000 --> 44:56.680
Right, so, like, as an example, let's say, you, you encounter an IIS box, um, which, you

44:56.680 --> 44:57.840
know, what are the odds of that, right?

44:57.900 --> 44:58.160
Right.

44:58.460 --> 45:07.740
Uh, and it's, for whatever reason, it's, you know, let's say, as, here's an example.

45:07.740 --> 45:16.220
So, you have a Windows 2000, um, IIS box, so it'd be IIS 5, and, for whatever reason,

45:16.260 --> 45:25.320
lazy admin hasn't updated his, his box, and he's running, uh, front page, uh, he's running

45:25.320 --> 45:30.020
front page extensions, and, I'm, I'm, I'm, like, reading what, what, one of the examples.

45:30.020 --> 45:31.840
It gives a specific example, sure, sure.

45:31.840 --> 45:39.300
So, this particular one would be MS-03-051, and that was a buffer overrun in, uh, in front

45:39.300 --> 45:39.900
page extensions.

45:39.900 --> 45:47.100
So, you would say, you would choose that particular exploit, uh, target that particular server,

45:47.100 --> 45:50.420
and then you decide what payload you want after that.

45:51.360 --> 45:56.780
Um, so, let's say you could, uh, you could have it return a shell, a command shell to

45:56.780 --> 46:02.360
you, you could have it add a user, uh, execute a specific command, or, in the case of Windows,

46:02.360 --> 46:07.520
uh, actually inject the VNC DLL and have it return a VNC Desk Comp to you.

46:08.860 --> 46:15.700
So, or, you could have, have it, um, you could write your own payload that did something

46:15.700 --> 46:15.960
with you.

46:15.960 --> 46:16.280
Right.

46:16.520 --> 46:21.760
Even though the exploit, using an exploit that's already there, write your own payload for it.

46:21.760 --> 46:21.940
Right.

46:22.060 --> 46:22.220
Right.

46:22.280 --> 46:25.640
And that's, that's, it's kind of hard to put that in, that's exactly what I was trying

46:25.640 --> 46:27.540
to explain earlier, it's hard to put that into words.

46:27.540 --> 46:31.020
Or, or write your own exploit and use a payload that's already there.

46:31.140 --> 46:36.700
Yeah, see, that's, they're, they can be independent, but they don't have to be independent, and

46:36.700 --> 46:41.540
it's, I don't know, I guess it's one of those things that, it is easier to see in real life.

46:41.620 --> 46:46.740
That's a more visual thing, so, unfortunately, we can't do too much justice to it on the radio,

46:47.340 --> 46:53.320
but, um, so, like, the current stable version of, and just for those of you who are familiar

46:53.320 --> 46:57.640
with the current stable version of Metasploit Framework is, it's written primarily in Perl.

46:58.900 --> 47:00.380
Um, that's version 2.6?

47:00.380 --> 47:01.820
2.6 is the current version.

47:02.320 --> 47:07.720
Uh, but the new beta version, which is 3.0, uh, is written, has been ported to Ruby.

47:08.000 --> 47:08.980
Yuck, Ruby!

47:09.380 --> 47:10.720
Don't, don't say yuck Ruby.

47:12.400 --> 47:15.360
So, Ray, I'll say yuck Rails, I can say that.

47:15.360 --> 47:18.360
I have, I'm not a web guy, so.

47:18.360 --> 47:24.200
Um, and there, there are multiple interfaces for Metasploit Framework.

47:24.300 --> 47:30.660
There's a, a Curses interface, um, well, actually, it's not, not really, no, it's not a Curses

47:30.660 --> 47:30.940
interface.

47:31.880 --> 47:35.360
It's a, it's a, a, can you term, read line interface, but, uh.

47:35.360 --> 47:36.420
But it's a similar.

47:36.520 --> 47:37.860
It's a shell kind of interface.

47:38.060 --> 47:40.440
I don't, I don't know why I said, I said Curses interface.

47:40.760 --> 47:43.200
I'm thinking, I'm thinking you're sitting at a Nettercap again.

47:43.400 --> 47:43.660
Yeah.

47:43.740 --> 47:47.200
Um, I don't, I don't have my, my notebook with me.

47:47.200 --> 47:51.100
Um, but there's also a, um, there's also a web interface for this as well, right?

47:51.100 --> 47:56.180
There is a web interface, uh, it comes with a, a web, a little web server, um, and you

47:56.180 --> 47:58.580
can kind of point and click at your target, select.

47:59.240 --> 48:07.260
You can filter by OS, filter by application, filter by architecture, um, pick what exploit

48:07.260 --> 48:15.020
you want, pick the, the payload, fill out a, fill in a few fields, and click, and there

48:15.020 --> 48:16.720
you go, and it's attacking your host.

48:17.080 --> 48:21.140
So, you have to have done a little footprinting ahead of time to know about your target system

48:21.140 --> 48:24.940
and what they might be running, what vulnerabilities they might have, that sort of thing?

48:25.820 --> 48:26.540
Generally, yeah.

48:26.620 --> 48:27.820
That would be advisable.

48:27.960 --> 48:31.520
And that would come back to Nmap, which we glossed over, and maybe we should have.

48:31.600 --> 48:32.920
Right, yeah, we, we, yeah.

48:32.920 --> 48:38.900
Yeah, I, I, I think that, I think our listeners know what, yeah, they know Nmap, and they know

48:38.900 --> 48:39.660
MetaSplight pretty well.

48:39.660 --> 48:43.380
There are some cool features, uh, in newer versions of Nmap, and there are some cool add-ons

48:43.380 --> 48:49.200
that are coming out, uh, one being like the Nmap scripting engine, um, but that's, that's

48:49.200 --> 48:52.620
something we can go over in another show, or even on, on the forums.

48:52.620 --> 48:54.140
Well, it's, it's still being developed, right?

48:54.220 --> 48:56.460
That's not out officially, is that a beta, or is that?

48:56.460 --> 49:01.400
No, Nmap scripting engine is out, I'm not sure what the status is right now.

49:01.480 --> 49:03.140
It's interaction with MetaSplight?

49:04.060 --> 49:04.900
No, this is.

49:04.940 --> 49:05.100
No?

49:05.200 --> 49:06.040
Okay, separate, okay.

49:06.280 --> 49:09.600
I don't see why you wouldn't be able to script it in there, have these things interact, as

49:09.600 --> 49:11.900
in the case of something like Biddy Blah, by, uh.

49:13.980 --> 49:19.820
Alright, well, and let's see, we talked about the web interface for it, so point and click

49:19.820 --> 49:21.340
and hack the intar web.

49:22.500 --> 49:23.400
That's always good.

49:23.400 --> 49:30.480
Um, I should give this to, um, I should give this to, um, uh, Verbal, because I think he

49:30.480 --> 49:31.780
sucks at the internets, right?

49:32.260 --> 49:33.620
Uh, he sucks at the online.

49:33.720 --> 49:35.400
At the online, I'm sorry, that's what he sucks at.

49:35.400 --> 49:40.380
At the online, yes, our listener last week said that he sucks at the online, so maybe

49:40.380 --> 49:41.060
he could use this.

49:41.300 --> 49:45.800
Now, you know, here's, here's another tool I see here on your list, which I'd be tempted

49:45.800 --> 49:50.160
to skip over, because some people might know this, but I actually, I would rather at

49:50.160 --> 49:56.500
least mention it briefly, and that is HYDR, or actually, it's what, THC?

49:56.860 --> 50:04.400
THC, uh, the hacker's choice, um, that's a, uh, European hacking group that's been around

50:04.400 --> 50:12.080
for many, many, many, many years, and they've, uh, they've written a variety of tools, they've

50:12.080 --> 50:18.980
had such a profound influence, and they've done so much for the community, um, they've

50:18.980 --> 50:27.960
written war dialers, they've written, uh, we, um, they, they, they've written a lot of

50:27.960 --> 50:28.300
tools.

50:28.820 --> 50:35.780
Yeah, they, the, the HYDR, though, is, is something, the THC HYDR, I, should I say THC every time

50:35.780 --> 50:37.080
I refer to it, what's proper, okay?

50:37.080 --> 50:42.300
We could just, we could just call it HYDRA, um, HYDRA is a, is a multi-protocol brute force

50:42.300 --> 50:48.220
cracker, and it's parallelized, parallelized, parallel, parallelized, so it can run, uh,

50:48.220 --> 50:56.060
multiple jobs at once, um, it performs, uh, 36 different, uh, attacks against 36 different

50:56.060 --> 51:05.900
services, including, uh, Telnet, FTP, SSH, uh, Oracle, uh, SNMP, uh, the one thing about

51:05.900 --> 51:11.620
this is, it's very noisy, so, I mean, you're, you're, all brute force tools are, bear in

51:11.620 --> 51:17.040
mind, this isn't brute force, this isn't your typical offline password cracker, this is actually

51:17.040 --> 51:23.860
attempting username and password combinations actively against a service, um, well, there

51:23.860 --> 51:28.000
are command line, there's a command line version, and also a, a GUI version as well.

51:28.000 --> 51:33.160
Well, and, and actually, speaking of that, maybe that's a transition, a transition to

51:33.160 --> 51:37.240
another tool that I had heard the name of, but hadn't really seen too much until you showed

51:37.240 --> 51:38.960
me more about it, and that is WebScarab.

51:39.640 --> 51:47.740
WebScarab is by OWASP, which is the Open Web Application Security Project, um, OWASP, O-W-A-S-P.org.

51:48.520 --> 51:54.760
Uh, WebScarab is a web application security testing framework that's written in Java, so anybody

51:54.760 --> 52:00.840
who has, who has an aversion to Java should probably just either get over it or avoid

52:00.840 --> 52:07.080
this tool, um, but I like this tool, so as much as I like to get over it, I actually did

52:07.080 --> 52:09.320
like this tool a lot, so, even though I hate Java.

52:09.380 --> 52:16.760
Right, uh, it, it's got a, it's got a variety of features, um, including an HTTP proxy, which

52:16.760 --> 52:22.500
doesn't seem like much, but that allows you to, uh, do, like, manual request interception,

52:22.500 --> 52:27.020
so you kind of, you, you know, connect back to yourself before you go back out, or connect

52:27.020 --> 52:31.180
to a box running this and go back out, and manual request interception will allow you

52:31.180 --> 52:37.320
to actually manipulate, um, HTTP headers, add HTTP headers, uh, remove HTTP headers.

52:38.100 --> 52:42.140
Uh, it also has a web spider, so you can spider a site and crawl it.

52:42.920 --> 52:49.220
Uh, it also has SOAP interaction, um, for anybody who's doing, like, a lot of web services-based

52:49.220 --> 52:49.560
stuff.

52:49.560 --> 52:52.300
Uh, one other thing that's, that's really...

52:52.300 --> 52:57.240
I wonder how good that actually works, though, because that seems like it'd be very difficult

52:57.240 --> 53:03.520
to, to really step, well, I guess, maybe not, I guess you can follow the logic along just

53:03.520 --> 53:06.080
as much as, as anything else.

53:06.140 --> 53:11.740
I, I, I, I want to see it in action, doing something SOAP-related, if there's such a phrase.

53:11.740 --> 53:17.080
Yeah, and, and, and web services is a huge deal right now, and it's going to be big for

53:17.080 --> 53:22.880
a while, so this might be something, if you're doing a lot of web, uh, web services development

53:22.880 --> 53:26.440
or web application security testing, this would be a helpful tool.

53:26.440 --> 53:31.160
And one other thing to mention is it has a, um, and this is just a few of the features,

53:31.520 --> 53:36.660
it has a, a fuzzer built in, so you can do automated substitution of values, uh, which

53:36.660 --> 53:40.400
might help expose, like, cross-site scripting attacks or SQL injection attacks.

53:40.780 --> 53:47.260
Um, and it also has another scripting interface, uh, via Bean Shell, so you can do, like, some

53:47.260 --> 53:53.580
built-in sort of Java scripting, not JavaScript, but Java-based scripting within the web scare

53:53.580 --> 53:54.240
of application.

53:55.180 --> 54:00.220
Yeah, and, and, the word fuzzer is actually something I wanted to go into on the show,

54:00.440 --> 54:04.520
and maybe we will, again, on a separate show, that's another, I'm getting a lot of ideas for

54:04.520 --> 54:06.340
some topics for upcoming shows, that's for sure.

54:06.820 --> 54:12.940
Um, fuzzing, or fuzzers, or fuzzing, was a term I heard a lot at DEFCON this year.

54:13.200 --> 54:18.800
There were some presentations, and there were, some of them were about fuzzing directly, and

54:18.800 --> 54:23.360
even the ones that weren't used, the term fuzzing, and used it in some of their,

54:23.580 --> 54:29.560
research to develop whatever their presentation was about fuzzing was something they used in

54:29.560 --> 54:30.040
the process.

54:30.140 --> 54:31.740
That was a word I heard frequently this year.

54:31.740 --> 54:41.540
Right, and fuzzing is doing some generalized, automated, um, attacks, well, or, not attacks

54:41.540 --> 54:43.420
so much as, it's really testing.

54:43.420 --> 54:47.480
It's really, it's really automated, kind of general automated testing to cause software

54:47.480 --> 54:53.120
faults, or to cause application faults, which can later then be investigated, or, or dove

54:53.120 --> 54:57.900
into a little bit more to determine if there's, uh, an exploitable condition in a piece of

54:57.900 --> 54:58.260
software.

54:58.460 --> 55:03.140
Right, and, and it's very much, um, less, well, I won't say less, but it's very, something

55:03.140 --> 55:09.720
that's extremely useful, regardless, or, or, not in relation necessarily to hacking.

55:09.720 --> 55:15.160
It is for hacking for obvious reasons, um, but really fuzzing is a technique that really

55:15.160 --> 55:21.420
is just, in programming, and debugging, and testing, unit testing, you run fuzzers against

55:21.420 --> 55:26.460
your own code to see if there's any holes to it, if there's any flaws, if it's gonna, if

55:26.460 --> 55:30.340
you're gonna send something to it that's either gonna, not only exploit it, but break it all

55:30.340 --> 55:34.060
together, uh, cause bad data to get inserted or updated somewhere.

55:34.060 --> 55:39.100
So just from a testing, software testing standpoint, it's valuable in that aspect, and it's kind

55:39.100 --> 55:44.220
of creeped into the hacking community for the same reason, because from an outsider using

55:44.220 --> 55:49.240
those, cause if you didn't do it when you developed your software, somebody on the outside, a hacker

55:49.240 --> 55:50.960
may be doing it to get into it, so.

55:50.960 --> 55:55.140
Right, and it's, it's a way of doing some kind of general, broad, uh, tests.

55:55.560 --> 55:59.860
Um, some other things, some other fuzzers that people might be familiar with are Spike, uh,

55:59.860 --> 56:02.740
or Peach Fuzz, those are some fuzzers that are available.

56:02.740 --> 56:08.060
Uh, WebScarab, of course, is, the fuzzer built into that engine is geared towards web applications

56:08.060 --> 56:08.720
specifically.

56:08.720 --> 56:14.820
Um, a lot of people might, might be familiar with protocol fuzzers, which are helpful for

56:14.820 --> 56:20.620
seeing how certain protocols, unknown application-level protocols, act under certain conditions,

56:20.740 --> 56:24.440
under some general conditions that might otherwise cause adverse effects.

56:26.000 --> 56:30.780
Alright, well, I tell you what, let's, um, I guess shift gears here a little bit, if we

56:30.780 --> 56:36.140
can, um, we've still got a little bit of time left in the show this week, so let's spend

56:36.140 --> 56:40.780
some time and kind of shift from offense to defense, if you will, from attacking tools

56:40.780 --> 56:44.180
to some defending tools or some defense tools.

56:44.740 --> 56:50.480
And again, you've got, um, some tools that you mentioned as defense tools that I hadn't

56:50.480 --> 56:55.360
really thought of in that way before, and really the first one that I think you were going to

56:55.360 --> 57:00.820
talk about, which was Snort, which a lot of our listeners are probably very familiar with

57:00.820 --> 57:01.240
as well.

57:01.380 --> 57:01.480
Right.

57:01.480 --> 57:07.020
Snort is, um, often referred to as the, as a lightweight intrusion detection system.

57:07.020 --> 57:17.020
Uh, it has capabilities to do just general packet capture and analysis, but, uh, it's used often

57:17.020 --> 57:19.200
as a network intrusion detection system.

57:19.200 --> 57:27.220
Um, so you build these rules that have an attack signature, uh, or protocol anomaly, um,

57:27.220 --> 57:34.140
like certain, certain header comment, certain header values that might be, uh, you know,

57:34.180 --> 57:35.900
it might be consistent with an attack.

57:36.380 --> 57:43.020
Um, and it goes, that goes into the Snort, the core, the core, Snort core engine, and then,

57:43.020 --> 57:47.780
you know, certain actions are taken, such as logging the packet, blocking it, if you have

57:47.780 --> 57:52.860
Snort set up as an IPS, which it has that capability as well, um, with certain add-ons.

57:52.860 --> 57:57.580
Yeah, and, and actually, I'm feeling kind of stupid now, because I got my notes out of

57:57.580 --> 58:01.520
order there, it's actually the next tool that I was thinking more from attack, not from this

58:01.520 --> 58:04.840
one, so I, I made a, kind of got my slides mixed up, but we're going to keep going with

58:04.840 --> 58:05.260
Snort anyway.

58:05.260 --> 58:12.020
Right, so, with Snort, um, we have a, a bunch of different pre-processors, which is another

58:12.020 --> 58:17.600
thing that's important about it, that normalize certain traffic, um, right, before it gets

58:17.600 --> 58:22.100
passed off to the, the main engine, and there are a variety of output plugins as well,

58:22.100 --> 58:29.680
uh, it can log to a database, it can log to a flat text file, uh, it can log to, uh, you

58:29.680 --> 58:38.180
know, raw, uh, PCAP or, uh, packet capture files, um, or it can log to syslog, as an example,

58:38.180 --> 58:44.860
it can fire off an SNMP trap, uh, Snort is another topic in and of itself, and it's been covered

58:44.860 --> 58:48.920
at, you know, at infinitum, so.

58:48.920 --> 58:54.220
And, and, uh, you mentioned the output plugins, and I think that's actually worthy of discussing

58:54.220 --> 59:01.520
for a moment, is, you know, these tools traditionally were developed by a lot of different, most of

59:01.520 --> 59:05.380
this stuff has been developed by hackers, and may be adopted and used by a lot of the security

59:05.380 --> 59:09.180
community, and some of the security community had a lot of, security community, security

59:09.180 --> 59:15.600
professionals had a lot of input and assistance with a lot of these as well, but as they're becoming

59:15.600 --> 59:20.360
more and more widespread use in corporations who are actually taking security seriously,

59:21.680 --> 59:26.600
it's not, traditionally a lot of attention hasn't been paid to the output or displaying

59:26.600 --> 59:31.180
or organizing of output so clearly, and I think that something else is starting to come around

59:31.180 --> 59:37.660
in a lot of these tools, not especially defense was the first ones that really made it in a more

59:37.660 --> 59:41.740
readable fashion, but even attacking tools now, if you want to do pen testing of your own boxes

59:41.740 --> 59:47.560
or internal testing and stuff, that it's starting to generate output in cleaner, nicer, prettier,

59:47.720 --> 59:52.160
whatever you want to define format, so that it's easier to read for upper management, we'll

59:52.160 --> 59:52.240
say.

59:52.240 --> 59:57.600
Right, and in the case of something like Snort, when you have it set to say, log, you know,

59:57.600 --> 01:00:04.500
log to a database, um, and, you know, like a MySQL or Postgres back in, or Oracle back

01:00:04.500 --> 01:00:09.740
in, where these, the IDS alerts are actually being sent to, they could then be displayed by

01:00:09.740 --> 01:00:16.220
something like Base, um, which is, which is, uh, a front, a web-based, a PHP-based web front

01:00:16.220 --> 01:00:21.080
end for those alerts, and it can generate graphs and, and all sorts of pretty reports,

01:00:21.080 --> 01:00:24.080
um, for, you know, the, the higher-ups.

01:00:24.080 --> 01:00:24.380
Upper management.

01:00:24.380 --> 01:00:30.380
And it's kind of a, a little more of a, easier to manage, uh, format for intrusion analysts.

01:00:30.380 --> 01:00:34.720
Um, Squeal would be another, another good engine, uh, SGU-I-L.

01:00:34.720 --> 01:00:37.220
Yeah, I, I'm saying that kind of as a joke, upper management.

01:00:37.220 --> 01:00:37.720
Right, right.

01:00:37.720 --> 01:00:39.340
No, it's, it really is helpful to anybody.

01:00:39.340 --> 01:00:41.920
It saves a lot of time, how you present information.

01:00:42.060 --> 01:00:45.760
If you don't, if I don't have to spend five minutes digging, searching, grepping to find

01:00:45.760 --> 01:00:49.920
the lines or the information that I want, you know, I'm not, I don't, I don't mean to

01:00:49.920 --> 01:00:50.420
belittle it.

01:00:50.660 --> 01:00:56.160
Generating output that's user-friendly and easy to maintain and find and search through

01:00:56.160 --> 01:01:00.700
is, is definitely a, a very important factor to add in there.

01:01:00.760 --> 01:01:06.880
It is, unfortunately, probably the least important behind general functionality of the tool itself.

01:01:06.880 --> 01:01:12.360
Well, again, Snort is something that we can, we can talk about for four shows.

01:01:12.420 --> 01:01:13.600
Right, right, absolutely.

01:01:13.600 --> 01:01:16.040
Just the, the flexibility of, of this app.

01:01:16.140 --> 01:01:19.720
Yeah, so, and actually, now I'll, I'll kind of explain what I was saying earlier.

01:01:19.800 --> 01:01:23.920
What I meant to be saying was I thought that our next tool coming up was, and what it is

01:01:23.920 --> 01:01:24.860
now is Kismet.

01:01:24.940 --> 01:01:28.920
And that's the one I was saying that I kind of think of that more as an offensive tool

01:01:28.920 --> 01:01:32.700
than a defensive tool, because I'm thinking of it from the war driver standpoint.

01:01:32.700 --> 01:01:36.620
Right, and, and typically it is associated with that.

01:01:37.340 --> 01:01:45.340
A lot of people think Kismet, they think, you know, detecting and, and, and, and doing

01:01:45.340 --> 01:01:49.620
war driving, detecting wireless networks, collecting traffic on these networks.

01:01:49.620 --> 01:01:50.700
Um, right.

01:01:50.960 --> 01:01:56.180
But it can also be used for, like, site surveys to see where your access points might be, uh,

01:01:56.240 --> 01:02:02.980
where, you know, where, where their, their limits are, um, or doing distributed wireless,

01:02:02.980 --> 01:02:04.780
uh, intrusion detection.

01:02:05.580 --> 01:02:12.080
Uh, one of the things that Kismet has is it has some basic wireless IDS or WIDS capability.

01:02:12.260 --> 01:02:17.260
That's another, another acronym that's, that's popular is WIDS, wireless IDS.

01:02:17.260 --> 01:02:24.580
Um, it has some basic signatures to see if other people are, are sending out, uh, or, are

01:02:24.580 --> 01:02:26.680
out, you know, probing for wireless networks.

01:02:27.280 --> 01:02:32.900
Um, one of the things is, like, it'll, it'll say, uh, such and such a node is, is probing

01:02:32.900 --> 01:02:36.200
networks but never participating, so that might be someone running NetStumblr.

01:02:36.980 --> 01:02:41.620
Um, it also has the capability to, uh, to...

01:02:41.620 --> 01:02:46.960
And, and actually, we talked about, we briefly talked about the difference between NetStumblr

01:02:46.960 --> 01:02:52.180
and Kismet on the first episode of Hack TV about how noisy NetStumblr is.

01:02:52.180 --> 01:02:55.220
Right, because NetStumblr is active, where Kismet is, is passive.

01:02:56.100 --> 01:03:02.680
Kismet will actually watch other people beaconing and, and watch other, watch for traffic on

01:03:02.680 --> 01:03:07.860
a certain channel and pick that up rather than actively sending out probes.

01:03:07.860 --> 01:03:15.720
Um, it also, the, has the capability to watch wireless networks and capture the traffic and

01:03:15.720 --> 01:03:19.820
write that to, say, like a socket from which something like Snort could read.

01:03:20.260 --> 01:03:26.640
So you could have a, uh, Kismet sensor watching for, you know, wireless networks that aren't

01:03:26.640 --> 01:03:32.420
necessarily your own or watch an access point through, you know, which Kismet is not necessarily

01:03:32.420 --> 01:03:36.980
actively associated, but watching the traffic on there and then have it sent back to a Snort,

01:03:36.980 --> 01:03:42.640
uh, an instance of Snort that's reading from a socket or something, uh, actually watching

01:03:42.640 --> 01:03:43.540
the, the traffic.

01:03:43.780 --> 01:03:46.540
Yeah, and that's another, you know, any, any...

01:03:46.540 --> 01:03:52.440
That, that brings up another interesting point, and that is, we're addressing these as, um,

01:03:52.440 --> 01:03:59.400
as separate, independent tools, but when combined together, there's, when you get some interaction

01:03:59.400 --> 01:04:04.000
between a lot of these, they become even more powerful when they cooperate and work together.

01:04:04.120 --> 01:04:08.880
They're being developed independently, but some of these groups are actually actively working

01:04:08.880 --> 01:04:15.220
with each other, either whether it's providing XML output formats that then this, in turn,

01:04:15.320 --> 01:04:21.180
uses, or sending it out to a common database that they both decide to use for ungod, unpronown,

01:04:21.180 --> 01:04:27.080
godly reason, MySQL, or something like that, that they can share, and, you know, they're sharing

01:04:27.080 --> 01:04:31.880
information back and forth, but if they're not directly connected, you can write your

01:04:31.880 --> 01:04:37.040
own Perl scripts, custom scripts, things like that, um, but just the general nature of them

01:04:37.040 --> 01:04:41.340
that I see, anyway, is that they're starting to come together where they have that common

01:04:41.340 --> 01:04:44.840
ground in cooperating with each other, instead of being standalone, independent tools.

01:04:45.000 --> 01:04:49.380
Yeah, and there are initiatives going on right now to try and come up with common language,

01:04:49.380 --> 01:04:55.500
so to speak, so that tools, uh, intrusion detection tools and vulnerability scanners can all kind

01:04:55.500 --> 01:05:00.860
of talk the same language, um, now, I actually just said that, I just said language, so talk

01:05:00.860 --> 01:05:05.680
the same language, so that they can all interact, so that, uh, vulnerability scanner that said you're

01:05:05.680 --> 01:05:11.360
vulnerable to X, uh, XYZ, uh, when you see that attack corresponding to XYZ on your network

01:05:11.360 --> 01:05:15.040
intrusion detection system, it kind of gets flagged just a little bit higher because, you know,

01:05:15.040 --> 01:05:21.100
you're known to be vulnerable to that. Right. So, so, yeah, and I, and this, you know, this is

01:05:21.100 --> 01:05:26.140
another one of those tools our listeners are very intimately familiar with, um, Kismet is very common

01:05:26.140 --> 01:05:33.600
and, and it's, and it's cousin Kismak. So, um, now, I actually, I may, I don't want to, I don't want to

01:05:33.600 --> 01:05:38.280
put you on the spot with this question, I don't know how familiar you are with Kismak, but is Kismak

01:05:38.280 --> 01:05:46.320
very far behind Kismet as far as functionality, I wonder? No, it's, uh, and maybe that's something

01:05:46.320 --> 01:05:49.360
a listener, yeah. I'm not intimately familiar with Kismak, and if anyone wants to, you know,

01:05:49.420 --> 01:05:53.060
chime in on that, uh, on the forum or. Yeah, radio at binrev.com and let me know, I'd like to,

01:05:53.160 --> 01:05:56.640
this is just me throwing out a question to the audience, actually, so. But I don't know how,

01:05:56.720 --> 01:06:01.420
how it is on, in terms of, uh, doing some of the defensive things, doing, like,

01:06:01.480 --> 01:06:07.340
distributed wireless IDS, um, I don't know, so. So, yeah, I, I might, and actually, I guess I could

01:06:07.340 --> 01:06:10.360
probably go to both sites and do a feature comparison list or whatever, but. You could,

01:06:10.640 --> 01:06:14.480
yeah. Or, I could post it out to the listeners who already have done that work for me, send

01:06:14.480 --> 01:06:19.560
it in, let us know. Um, all right, how about a couple other defense tools here? Some of

01:06:19.560 --> 01:06:23.560
these, again, these are some, some that I have not heard of in our next one here. So, Packet

01:06:23.560 --> 01:06:29.720
Fence, um, is an open source network access control system. If anyone's familiar with, uh,

01:06:29.720 --> 01:06:36.060
things like Cisco NAC, uh, network admission control, uh, this is an open source implementation,

01:06:36.060 --> 01:06:42.200
so to speak. This, uh, runs on Linux, um, because it does a lot of things with net filter

01:06:42.200 --> 01:06:48.860
or, uh, IP tables. Mm-hmm. So, what you do is, is this has, uh, registration capability

01:06:48.860 --> 01:06:54.380
via an HTTPS web portal. So, you would register your, your system with that, uh, once you first

01:06:54.380 --> 01:06:59.660
plugged in and got handed out an IP address. Uh, it would watch for any traffic you're emitting

01:06:59.660 --> 01:07:05.320
using Snort, uh, to see if you were scanning other hosts, uh, anything that might be consistent

01:07:05.320 --> 01:07:11.780
with Worm Activity or other malware. Uh, and it would also scan your host to see if you

01:07:11.780 --> 01:07:17.180
have any known vulnerabilities or missing, um, or anything that might be associated that

01:07:17.180 --> 01:07:23.320
could be addressed via a patch or simple configuration change. Uh, it will isolate any host that may

01:07:23.320 --> 01:07:31.320
be infected or, or otherwise insecure via IP tables. Um, or, and it would also redirect them

01:07:31.320 --> 01:07:38.780
to an appropriate URL, uh, or web page or website that would have information on how to download

01:07:38.780 --> 01:07:43.820
patches or remove any, you know, any malware that might be on their system. Uh, and once

01:07:43.820 --> 01:07:49.780
that's all done, they would re, you know, re-initiate these scans and, and, uh, traffic analyses.

01:07:49.780 --> 01:07:55.240
Uh, until you finally meet the criteria. Until eventually you met the criteria and it either

01:07:55.240 --> 01:08:00.240
adds a rule or drops a rule that thus grants you access to the rest of the, the network.

01:08:00.240 --> 01:08:07.720
Yeah. And, and, and the first application that jumps to mind of this for me is at, well, I

01:08:07.720 --> 01:08:12.120
guess companies would be, you know, uh, people that bring in their personal laptops or something

01:08:12.120 --> 01:08:15.560
and plug into the network. Contractors. You want to be careful. But the first one that jumps

01:08:15.560 --> 01:08:20.060
my mind and maybe this is just because of my background is higher education. Universities

01:08:20.060 --> 01:08:23.840
are famous for this. You got kids in the dorms, you got kids with their laptops, you got people

01:08:23.840 --> 01:08:30.700
coming in and making them, you know, make sure they have cause, you know, I only say, you

01:08:30.700 --> 01:08:34.920
know, college students don't really take the best care and aren't the most secure people

01:08:34.920 --> 01:08:40.880
with their laptops. And actually Packet Fence was, was originally, uh, developed, um, at a,

01:08:40.880 --> 01:08:45.380
uh, at a, a higher education facility to address some of the things with students, things

01:08:45.380 --> 01:08:50.560
like students in dorms who have, you know, their one, their one little laptop they got

01:08:50.560 --> 01:08:54.280
when they went off to college and they're not updating patches. They're not updating their

01:08:54.280 --> 01:08:58.980
antivirus signatures. They're still on Windows 95. They're downloading who knows what from

01:08:58.980 --> 01:09:11.480
Kazaa. Uh, so. And, um, it's, but this one is an open source one. So. Right. This is, this

01:09:11.480 --> 01:09:15.660
is free. Now actually I'm going, I am going to ask and question the license on this one

01:09:15.660 --> 01:09:20.800
because if you're using this at a, a large university, this is not just the person using

01:09:20.800 --> 01:09:26.400
it privately, which generally open source is kind of the way they go is normally a one

01:09:26.400 --> 01:09:30.640
person or a small business or whatever using it. But this, if you're running this at a large

01:09:30.640 --> 01:09:36.040
university or at your company, what license is this actual one? What type of license is

01:09:36.040 --> 01:09:42.580
this? This is a GPL. It's a GNU general public license. So this one, um, this one is the

01:09:42.580 --> 01:09:47.320
license with which most people who use things like Linux are a little more accustomed. Normal

01:09:47.320 --> 01:09:54.060
GPL. Um, so there are no, you're, you know, you're, you're, you're fine to use it. Uh, if

01:09:54.060 --> 01:10:00.500
you can use other GPL software, generally you shouldn't have a problem. Yeah. All right. Now

01:10:00.500 --> 01:10:05.620
that one was another one that I had not heard of, but I didn't, the next one actually, and

01:10:05.620 --> 01:10:10.880
I'll, I'll actually, you know what, I'm going to slide one in of my own here because, um,

01:10:11.600 --> 01:10:20.000
one thing that I think is important to everybody is antivirus and antivirus. There's lots of

01:10:20.000 --> 01:10:28.560
free ones or free versions or even online scanners out there, but there is clam antivirus and there's

01:10:28.560 --> 01:10:34.380
also it's bastard cousin clam win, which is just the windows version of clam antivirus.

01:10:34.960 --> 01:10:38.300
But, um, again, we'll kind of gloss over cause I think this is one that's very common, but

01:10:38.300 --> 01:10:43.960
for people out there that are ever looking for an open source, um, antivirus engine, I

01:10:43.960 --> 01:10:48.080
think clam is certainly worth mentioning in this and it seems to me it would be obviously

01:10:48.080 --> 01:10:54.120
defensive. Yeah, definitely. So, and I don't, I don't want to tie into a lot of other tools

01:10:54.120 --> 01:11:01.900
as well, so you can, you can have it do, uh, you know, well, content filter, malware filtering,

01:11:02.160 --> 01:11:06.580
you know, and virus filtering via, you know, through send mail. Yeah, I was going to say

01:11:06.580 --> 01:11:11.240
it plugs in and scans the mail coming through, so that's, that's really handy to have in there.

01:11:12.060 --> 01:11:18.400
Um, but it also, again, you know, really clam win and I'm not like endorsing it or anything,

01:11:18.400 --> 01:11:25.100
but, um, cause I use ABG free. I have several antivirus and spyware scanners running at any

01:11:25.100 --> 01:11:30.360
given time on all my machines. So, um, I definitely liked, uh, both of those ABG free,

01:11:30.480 --> 01:11:35.160
which is not an open source thing, I don't believe, but clam maybe is. So, but one thing

01:11:35.160 --> 01:11:46.180
that people have to keep in mind is, you know, just because they run Linux or, or one of the BSDs

01:11:46.180 --> 01:11:55.020
and are a little, let's just say less susceptible to, um, viruses, it's still, for best practices

01:11:55.020 --> 01:12:00.480
and for things like defense in depth, it's still advisable to run antivirus and have automated,

01:12:00.700 --> 01:12:08.000
you know, have, have scheduled jobs that scan or scan incoming, um, mail, or even in the cases

01:12:08.000 --> 01:12:14.140
of products that do support on-access scanning, uh, in Linux and BSD to use that when possible.

01:12:14.140 --> 01:12:20.920
Even if, even if you're not vulnerable to, or, or susceptible to, you know, common viruses,

01:12:21.400 --> 01:12:25.020
it's still just good practice and getting habits so that when something does come out,

01:12:25.400 --> 01:12:27.840
you're not, you know, you, you've already beaten it to the punch.

01:12:28.400 --> 01:12:33.900
Okay. All right. Well, did you have any other defensive tools that you wanted to bring up?

01:12:34.360 --> 01:12:35.780
Um, there's another one.

01:12:35.880 --> 01:12:38.880
Or we can move on to the quote-unquote other.

01:12:38.880 --> 01:12:47.400
One, one other thing is, um, the OSSEC project, OSSEC, uh, has, uh, host-based intrusion detection

01:12:47.400 --> 01:12:53.620
system called OSSEC HIDS. It's a host-based IDS as opposed to network-based IDSs that, um,

01:12:53.840 --> 01:12:59.560
look at traffic on the network. This looks at aspects of the host itself, uh, which can include

01:12:59.560 --> 01:13:06.340
things like log analysis, um, integrity checking, uh, like file integrity, um, or to make sure

01:13:06.340 --> 01:13:12.800
the host is, is, there aren't any, like, bad modules loaded. Uh, it also does rootkit detection,

01:13:12.800 --> 01:13:19.060
uh, it can, has multiple ways of alerting email, uh, log, other log entries, things like that.

01:13:19.060 --> 01:13:23.760
And one thing that's, uh, neat about OSSEC HIDS is it also has active response. So you

01:13:23.760 --> 01:13:29.060
can, you can have it execute a command or script out certain things that it can do based on

01:13:29.060 --> 01:13:35.180
certain log entries that it sees. Um, yeah, that just, that name gets me.

01:13:35.280 --> 01:13:36.280
OSSEC, OSSEC HIDS.

01:13:36.280 --> 01:13:42.100
It's, it's just awkward. OSSEC HIDS. It just sounds awkward coming, it's not, it just, I feel

01:13:42.100 --> 01:13:46.480
like I have Down syndrome. OSSEC HIDS. I don't know what the hell, it just sounds weird.

01:13:46.480 --> 01:13:54.420
Uh, also OSSEC HIDS has, uh, you can write these correlation rules so that based on different

01:13:54.420 --> 01:13:59.840
kinds of events, it can kind of assemble what maybe a certain attack was. So it sees a bunch

01:13:59.840 --> 01:14:06.320
of failed logins and then a successful login, uh, within a certain time window. That can

01:14:06.320 --> 01:14:10.580
be indicative that, you know, maybe somebody was brute forcing an account and eventually

01:14:10.580 --> 01:14:17.300
got in. So that it can, you know, send maybe a high priority alert to you. Uh, it also,

01:14:17.300 --> 01:14:22.440
one cool thing about OSSEC HIDS is it also supports, uh, Windows in addition to, you know,

01:14:22.920 --> 01:14:28.840
various Unix platforms. Um, but on the, on the Nix platforms, it has both the agent and

01:14:28.840 --> 01:14:33.660
the server because it has centralized reporting. On Windows side, it's just the agent only.

01:14:33.660 --> 01:14:40.120
So, all right. That's another one that we can talk about at, really, I mean, every, really,

01:14:40.200 --> 01:14:44.520
every single one of these. And actually, you know what, I, I guess we do have a few other,

01:14:44.520 --> 01:14:49.280
other tools, a few other miscellaneous tools or whatever we're going to call this. But, um,

01:14:49.720 --> 01:14:54.360
before we do, I'll go ahead and say to the audience and normally I'll wait till we're all

01:14:54.360 --> 01:15:01.480
done to say this, but, um, if there are any of these specifically that you would like someone

01:15:01.480 --> 01:15:06.840
to go into more detail, if you'd like us to do an episode, I hope I don't get emails

01:15:06.840 --> 01:15:11.040
from everybody saying every one of those go into more detail. But if there are some that

01:15:11.040 --> 01:15:15.160
are, that you're more curious about than others, like, I don't think anybody would really want

01:15:15.160 --> 01:15:20.080
us to do a full episode on, like, Kismet, for example, because I think so many people are

01:15:20.080 --> 01:15:24.840
already familiar with it. And some of the, you know, InMap, well, but see, InMap's got so

01:15:24.840 --> 01:15:29.440
many, I, I don't know, I don't know. So I'm saying to the listeners, you know, what do

01:15:29.440 --> 01:15:33.020
you, what, what of these tools has really piqued your interest, if any of these, and

01:15:33.020 --> 01:15:36.400
that you'd like to hear more detail. Like, again, we're just going through a list and

01:15:36.400 --> 01:15:39.860
giving you an overview of some of these. So if there's any that you would like to hear

01:15:39.860 --> 01:15:44.600
on more detail, please email us and let us know. And we'll see if we can't put that on

01:15:44.600 --> 01:15:49.800
the upcoming schedule to, you know, go into a few, go into some more detail on a few specific

01:15:49.800 --> 01:15:50.400
ones.

01:15:50.740 --> 01:15:54.420
And see, that's one thing I'm trying to do is not go, is not spend too much time on one

01:15:54.420 --> 01:15:54.860
of these.

01:15:54.980 --> 01:15:55.260
Right.

01:15:55.260 --> 01:15:58.600
And so that we can kind of just, okay, so this is what it does and let's move on to

01:15:58.600 --> 01:15:59.100
the next one.

01:15:59.820 --> 01:16:03.260
So, yeah. And then that's kind of what I said earlier. I'm getting a lot of great ideas

01:16:03.260 --> 01:16:07.500
for upcoming show topics, which is always, you know, the people that have done the show

01:16:07.500 --> 01:16:12.020
in the past, that's the one common thing they've said to me is, it's difficult to come up with

01:16:12.020 --> 01:16:15.660
topics or how do you come up with all these different topics? Well, there's, there's really

01:16:15.660 --> 01:16:19.780
a lot of them out there. It's just how much depth you want to go into it. So doing a show

01:16:19.780 --> 01:16:24.660
like this, where we can open the doors and say, here's a lot of different tools. Here's generally

01:16:24.660 --> 01:16:29.720
what they do. And people will either go into it by themselves and do their own research

01:16:29.720 --> 01:16:34.540
and find some things, or they'll ask us our opinions or, well, can we go into some more

01:16:34.540 --> 01:16:38.420
detail on it? And we can certainly do that, but we don't want to go through the detail

01:16:38.420 --> 01:16:43.240
on every single one of these because, yeah, I mean, I mean, I'm not even counting how many

01:16:43.240 --> 01:16:48.200
we've done so far, but what, we've been 10, 15 episodes by the time we're done with this.

01:16:48.200 --> 01:16:51.020
Yeah, so I don't want to sound like a banana head, like I don't know what I'm talking about

01:16:51.020 --> 01:16:54.760
with these tools, but I don't want to spend too much time on one of them. I'm sorry,

01:16:54.920 --> 01:16:59.580
a banana head? That's, that's from Empire Records, actually. Oh, okay, I didn't, yeah,

01:16:59.640 --> 01:17:04.220
you got me on that reference, I was, you caught me on that one. Okay. I like that word, banana

01:17:04.220 --> 01:17:08.520
head. Banana head, alright. So. I like banana phone. Ring, ring, ring, ring. No, no. Okay.

01:17:09.520 --> 01:17:14.640
Alright, well, how about some miscellaneous tools? We do have a few minutes to talk about

01:17:14.640 --> 01:17:20.220
a couple other miscellaneous tools, so what do you think, so again, some of these, I

01:17:20.220 --> 01:17:23.380
think we won't, I think, as a matter of fact, I think we'll skip over. Yeah, we're going

01:17:23.380 --> 01:17:28.000
to skip over. Open SSH, people know Open SSH pretty well. Right. But, I mean, a lot of

01:17:28.000 --> 01:17:33.440
people need to know also that Open SSH is not just an SSH client, it can be used to wrap

01:17:33.440 --> 01:17:39.400
otherwise insecure protocols, or protocols that might otherwise be in clear text. Right, and you

01:17:39.400 --> 01:17:43.140
know what? And build SSH tunnels. Funny, you know, this is, that's going to be a good

01:17:43.140 --> 01:17:47.860
segue into episode two tonight, the second of our back-to-back episodes, where we go

01:17:47.860 --> 01:17:53.000
and talk about tunneling. So, that's going to be a good segue into that. So, that's

01:17:53.000 --> 01:17:58.640
perfect, Tommy. Now, how about, you mentioned earlier, I think you mentioned Open LDAP?

01:17:58.700 --> 01:18:05.620
Yeah, I just gave it as an example. Open LDAP is an open source implementation of LDAP,

01:18:05.740 --> 01:18:10.440
Lightweight Directory Access Protocol. So, it's a directory server, an LDAP library, and it

01:18:10.440 --> 01:18:16.020
has client components. One thing that this, how this applies to security is we can create

01:18:16.020 --> 01:18:20.680
like a centralized authentication service. A lot of people might be familiar with Microsoft

01:18:20.680 --> 01:18:26.500
Active Directory, which is also LDAP-esque, and you can do, you can perform certain LDAP

01:18:26.500 --> 01:18:35.300
operations on Active Directory. So, the reason I just mentioned Open LDAP, again, is to do like

01:18:35.300 --> 01:18:40.880
centralized authentication so that we don't have usernames and passwords, user stores

01:18:40.880 --> 01:18:45.960
and username and password stores on multiple systems. We can have one consistent centralized

01:18:45.960 --> 01:18:53.620
authentication server to which all these things, you know, to which all users are authenticated

01:18:53.620 --> 01:18:57.180
regardless of what system they're longing. Now, a lot of people can argue, too, that, well,

01:18:57.200 --> 01:19:00.520
now you've got one central place that people need to break into to get your username and

01:19:00.520 --> 01:19:06.740
password. That's, that's a gray area. It's debatable. Yes, that might be true, but in

01:19:06.740 --> 01:19:10.960
terms of management and administration, that, that cuts back so that you, you don't have

01:19:10.960 --> 01:19:14.720
accounts, stale accounts on multiple systems that you didn't know were there.

01:19:14.920 --> 01:19:19.820
Right, right. And that, well, it's, you know, it's that balance of ease of use and convenience

01:19:19.820 --> 01:19:23.360
versus security. So, yes, you are putting them all in one, you're putting all your eggs

01:19:23.360 --> 01:19:27.700
in one basket, so to speak. And I think I've said this about, I think my example one time

01:19:27.700 --> 01:19:34.380
was talking about Microsoft Passport being a single sign-on, but that is also a single

01:19:34.380 --> 01:19:38.420
point of failure. I mean, not necessarily in regards to OpenLDAP, but having all your

01:19:38.420 --> 01:19:45.340
authentication coming from one area. However, you also, to play the other coin of that is

01:19:45.340 --> 01:19:49.980
now that you've got it all in one spot, you can concentrate all your security efforts on

01:19:49.980 --> 01:19:58.220
that one spot as well, so. Yeah, it's, it's, it's an argument. It's, I mean, it can be

01:19:58.220 --> 01:20:03.080
argued. Yeah, back and forth, yeah. It's basically just an opinion and however you feel either

01:20:03.080 --> 01:20:07.060
way on it. And, and actually, I don't, I, I see both sides of the argument, so I don't

01:20:07.060 --> 01:20:10.660
really have, like, I don't pick a side per se in that argument. I see both sides at the

01:20:10.660 --> 01:20:14.460
point. Yeah, as do I. And it's a balance, so. You know, for people looking for an

01:20:14.460 --> 01:20:18.360
alternative. Yeah, don't send us hate mail, we're not endorsing either side. Right. For people

01:20:18.360 --> 01:20:22.560
who are looking for, you know, an open source alternative to something like Active Directory

01:20:22.560 --> 01:20:32.780
or Novell eDirectory or something similar, this, this would be a good example. So, and it, you

01:20:32.780 --> 01:20:39.200
know, or, or if you just want an LDAP-based address book. I don't know. Well, hey, whatever.

01:20:39.460 --> 01:20:45.120
So, another thing that we can touch on real quick is OpenVPN. VPN, of course, virtual private

01:20:45.120 --> 01:20:51.020
network. A lot of people are familiar with IPsec-based VPNs or PPTP if you're ever so

01:20:51.020 --> 01:21:00.580
unlucky. But SSL VPN, secure socket layer VPNs are a big thing too. OpenVPN is a user space

01:21:00.580 --> 01:21:06.600
SSL VPN implementation that is, of course, open source. It'll run on most, you know, NICS

01:21:06.600 --> 01:21:13.540
platforms, BSD, Linux, Solaris, so forth and so on, but also on Windows as well. It takes

01:21:13.540 --> 01:21:18.540
advantage of OpenSSL, which is the open source secure socket layer library, which also does

01:21:18.540 --> 01:21:25.740
a variety of other cryptographic functions. And it is open source. It is open source. OpenVPN

01:21:25.740 --> 01:21:31.360
authenticates users through PAM, pluggable authentication modules, which can in turn be

01:21:31.360 --> 01:21:40.540
extended to a number of other authentication mechanisms such as LDAP or SMB, you know, through

01:21:40.540 --> 01:21:48.540
Active Directory or whatever, Pick Your Poison, MySQL, any number of backends. It has load

01:21:48.540 --> 01:21:54.540
balancing and failover capabilities and there are GUIs for it. So, for anyone who's accustomed

01:21:54.540 --> 01:22:01.540
to, like, Cisco's pretty VPN client or AT&T or anything like that, there is a front end

01:22:01.540 --> 01:22:09.540
for this. This could be helpful if you want secure access into your, you know, home network.

01:22:09.540 --> 01:22:14.540
Yeah, and this is also going to be, this is a great segue into the second episode tonight

01:22:14.540 --> 01:22:20.540
too, where we get into a lot of details about VPN in relation to tunneling and obvious reasons.

01:22:20.540 --> 01:22:27.540
So, and a whole other episode in and of itself VPNs. And it, and it, yeah, and it will be.

01:22:27.540 --> 01:22:34.540
Stick around. All right. So, uh, one of the last tools that I've really kind of got on my,

01:22:34.540 --> 01:22:43.540
my laundry list here, uh, is FreeRadius. Um, Radius is, uh, remote authentication dial-in user

01:22:43.540 --> 01:22:50.540
service, uh, and that was, that's used a lot for authenticating, like, traditionally was

01:22:50.540 --> 01:22:54.540
for authenticating, like, dial-in users on, uh, for modem pools and things like that.

01:22:54.540 --> 01:22:57.540
Okay. Or for remote access. Okay. Yeah, dial-in.

01:22:57.540 --> 01:23:04.540
Remote access dial-in user service. Uh, it's a, a free open source implementation of Radius.

01:23:04.540 --> 01:23:11.540
Um, it's one of the top five Radius servers worldwide based on, uh, number of users that are

01:23:11.540 --> 01:23:17.540
authenticated to it, you know, every day, uh, and based on deployment, uh, it's deployment base.

01:23:17.540 --> 01:23:23.540
Um, supports a variety of backends, including LDAP, uh, MySQL, PostgreSQL, and Oracle.

01:23:23.540 --> 01:23:28.540
Yay, Oracle, right? Yay! Um, one thing that's, that's cool about FreeRadius is if you're familiar

01:23:28.540 --> 01:23:35.540
with, uh, 802.1x authentication, uh, a lot of people know it, uh, as one of the implementations,

01:23:35.540 --> 01:23:42.540
which would be, like, Cisco Leap, um, which would be, like, Layer 2 authentication, 802.1x,

01:23:42.540 --> 01:23:48.540
uh, you can authenticate users before they're, they're really on, you know, given an IP address

01:23:48.540 --> 01:23:52.540
or, or before, port-based authentication is what it's sometimes called.

01:23:52.540 --> 01:23:53.540
Right. Now is that...

01:23:53.540 --> 01:23:58.540
FreeRadius supports that. Of course, your client needs to support that, um, but FreeRadius

01:23:58.540 --> 01:24:02.540
can be used to do that. Uh, it doesn't tie into something like, like, necessarily like the

01:24:02.540 --> 01:24:09.540
in the packet fence, because packet fence is, uh, layer three and up. Um, but FreeRadius,

01:24:09.540 --> 01:24:17.540
if you're looking for an alternative to, like, uh, Cisco's, uh, like, Cisco's, uh, authentication

01:24:17.540 --> 01:24:23.540
server, this would be an example. Um, this supports multiple, uh, extensible authentication

01:24:23.540 --> 01:24:30.540
protocol types, EAP, uh, including Cisco Leap. Uh, it supports proxying, uh, failover, load

01:24:30.540 --> 01:24:33.540
distancing, so if you're worried about, you know, my FreeRadius server went down, well,

01:24:33.540 --> 01:24:39.540
this has the capability to have, um, um, you know, failover radius servers.

01:24:39.540 --> 01:24:48.540
Okay. Uh, again, this is a whole nother topic unto itself, but, you know, this is just planting

01:24:48.540 --> 01:24:53.540
the seed for people who want to kind of learn more about these tools, and, um, like you said,

01:24:53.540 --> 01:25:00.540
if anyone wants to, us to cover these more in depth, uh, they can. There's also another,

01:25:00.540 --> 01:25:10.540
um, there's an entire presentation, uh, or, uh, how-to, rather, on doing 802.1x port-based

01:25:10.540 --> 01:25:16.540
authentication, um, via FreeRadius. That's at, uh, the Linux documentation project, tldp.org.

01:25:16.540 --> 01:25:24.540
Um, you can find that there, and that'll give you all you need to know how to do 802.1x

01:25:24.540 --> 01:25:33.540
authentication with FreeRadius. So, um, that's, that's really all I've, uh, I've got for the

01:25:33.540 --> 01:25:39.540
tools, um, I just, you know, think there's a lot of great open source, uh, security tools

01:25:39.540 --> 01:25:43.540
out there, and people need to contribute back to open source projects.

01:25:43.540 --> 01:25:46.540
Amen. So that, that's a huge thing. A lot of these, that's why a lot of these projects

01:25:46.540 --> 01:25:49.540
die, or don't really go anywhere, is because people...

01:25:49.540 --> 01:25:50.540
Or stagnate, yeah.

01:25:50.540 --> 01:25:53.540
They, they take, they take the code, they use it, but they don't really give any

01:25:53.540 --> 01:25:58.540
feedback, they don't contribute fixes, they don't, uh, contribute enhancements or features.

01:25:58.540 --> 01:26:04.540
Um, and that's, that's, um, something, someone in IRC used a perfect word one time

01:26:04.540 --> 01:26:09.540
when, when I was, we were having a conversation about this, and they just admitted up front

01:26:09.540 --> 01:26:14.540
that they are a consumer. They're not giving back, they're not contributing, they are a

01:26:14.540 --> 01:26:19.540
consumer, they are using the product. And there's nothing necessarily wrong with it, but just,

01:26:19.540 --> 01:26:23.540
if you do find something useful, or if you can think of ways to enhance or help a project,

01:26:23.540 --> 01:26:28.540
or even if it's just feedback, a bug report, anything as small as that, or spreading the word,

01:26:28.540 --> 01:26:32.540
spreading the word, getting, um, you know, getting other people to come and, and embrace

01:26:32.540 --> 01:26:36.540
the project, then maybe if you can't contribute directly back, maybe they can, so spreading

01:26:36.540 --> 01:26:40.540
the word indirectly helps out, so, so that's always a good thing.

01:26:40.540 --> 01:26:47.540
Um, or if, if, if by chance you have any, you know, free money lying around, a lot of

01:26:47.540 --> 01:26:48.540
these developers...

01:26:48.540 --> 01:26:49.540
I don't think they turn down...

01:26:49.540 --> 01:26:54.540
Right, no, they, you know, if you can contribute, uh, in the case of things like open, open BSD,

01:26:54.540 --> 01:27:01.540
contributing hardware, or testing things out yourself, um, that always helps too.

01:27:01.540 --> 01:27:07.540
I know, in the case of a lot of operating systems, people, they can really use hardware donations.

01:27:07.540 --> 01:27:12.540
Alright, well, I think that's, um, I think that's gonna about do it for this episode of

01:27:12.540 --> 01:27:17.540
the show, um, if there's anything, I think that's pretty much all we really had to...

01:27:17.540 --> 01:27:22.540
Again, I mean, it's one of those shows where it's kind of, and we've said this many times

01:27:22.540 --> 01:27:27.540
during the show that we could go into more detail about any of these, but I think this

01:27:27.540 --> 01:27:30.540
was a good overview of a, of several tools.

01:27:30.540 --> 01:27:34.540
The way we limited was to only focus on open source tools this time.

01:27:34.540 --> 01:27:39.540
We have, in past episodes of the show, gone into other tools in more detail, and in the

01:27:39.540 --> 01:27:41.540
future we will go into some in more detail.

01:27:41.540 --> 01:27:45.540
But if any of these specific ones that you'd like to hear, or if you've got some information

01:27:45.540 --> 01:27:51.540
that you want to add to what we've already talked about, by all means, email us at radio

01:27:51.540 --> 01:27:53.540
at binrev.com.

01:27:53.540 --> 01:28:01.540
Um, our site of the week is, uh, actually completely unrelated to the show, but in an article that

01:28:01.540 --> 01:28:03.540
I read in one of my magazines this week.

01:28:03.540 --> 01:28:09.540
I think this was from, I almost want to, no, I don't think this was in Popular Science.

01:28:09.540 --> 01:28:11.540
I don't remember, there was some magazine that I read this week.

01:28:11.540 --> 01:28:12.540
What is this right here?

01:28:12.540 --> 01:28:15.540
It is, it was Popular Mechanics, not Popular Science.

01:28:15.540 --> 01:28:27.540
And the site is spudtech.com, that's S-P-U-D-T-E-C-H, spudtech.com, which is everything you wanted to know,

01:28:27.540 --> 01:28:34.540
some directions, how-tos, advice, pictures, projects on making your own potato gun, which

01:28:34.540 --> 01:28:39.540
we do not have any liability whatsoever with anything that you may do, especially after

01:28:39.540 --> 01:28:40.540
I read that story.

01:28:40.540 --> 01:28:43.540
I think it was somebody, the guy won a Darwin Award.

01:28:43.540 --> 01:28:44.540
Did you ever remember that?

01:28:44.540 --> 01:28:48.540
This is probably going way off topic for the show, but there was a great Darwin Award

01:28:48.540 --> 01:28:53.540
probably four or five years ago about a kid who thought it would be funny to put a frog

01:28:53.540 --> 01:28:56.540
in the potato gun and shoot it, and it misfired.

01:28:56.540 --> 01:28:58.540
It didn't shoot the frog out.

01:28:58.540 --> 01:29:02.540
So being the brilliant person that he is, he looked down the barrel of the thing, and

01:29:02.540 --> 01:29:09.540
it accidentally shot off and threw shrapnel of frog bone through his skull, and killed

01:29:09.540 --> 01:29:10.540
him.

01:29:10.540 --> 01:29:12.540
That's sort of poetic justice in a way.

01:29:12.540 --> 01:29:13.540
Isn't it?

01:29:13.540 --> 01:29:14.540
Isn't it?

01:29:14.540 --> 01:29:16.540
I mean, it was just brilliant.

01:29:16.540 --> 01:29:19.540
The brilliant Darwin, maybe you should meet the Darwin Awards, the site of the week.

01:29:19.540 --> 01:29:22.540
And actually, since we have another episode coming up in a few minutes, you're going to

01:29:22.540 --> 01:29:25.540
get two sites of the week this week, so lucky, lucky you.

01:29:25.540 --> 01:29:30.540
And we're also going to split up the shouts this week, so any shouts that you have, I'll

01:29:30.540 --> 01:29:35.540
go ahead and stall a moment so you can think, and I will give shout outs to Savant, who I've

01:29:35.540 --> 01:29:44.540
been talking to a lot lately, and I think you'll back me up on this, to everybody at BR407.

01:29:44.540 --> 01:29:45.540
BR407.

01:29:45.540 --> 01:29:46.540
Yeah.

01:29:46.540 --> 01:29:49.540
So, anything else you wanted to add to that?

01:29:49.540 --> 01:29:51.540
I can give a few shout outs now that I think about it.

01:29:51.540 --> 01:29:52.540
Okay, go for it.

01:29:52.540 --> 01:29:56.540
I want to, if these people are, you know, some room, even if they're listening, I don't

01:29:56.540 --> 01:29:57.540
even know.

01:29:57.540 --> 01:29:58.540
Of course, they're going to listen because you're on the show.

01:29:58.540 --> 01:29:59.540
Right.

01:29:59.540 --> 01:30:00.540
Of course.

01:30:00.540 --> 01:30:01.540
Thanks.

01:30:01.540 --> 01:30:04.540
And the old NOP crew.

01:30:04.540 --> 01:30:06.540
If you're out there.

01:30:06.540 --> 01:30:07.540
If you're out there.

01:30:07.540 --> 01:30:12.540
Contact me at radio.binrev.com and maybe I'll forward some information on maybe.

01:30:12.540 --> 01:30:13.540
Maybe.

01:30:13.540 --> 01:30:15.540
Or, you know, pretend to be me.

01:30:15.540 --> 01:30:16.540
Or not.

01:30:16.540 --> 01:30:17.540
Or respond to them.

01:30:17.540 --> 01:30:18.540
There you go.

01:30:18.540 --> 01:30:22.540
Um, and, uh, let's see.

01:30:22.540 --> 01:30:26.540
Closing music tonight is The New Pornographers.

01:30:26.540 --> 01:30:28.540
It is a song called Use It.

01:30:28.540 --> 01:30:30.540
So, I think that's going to be it.

01:30:30.540 --> 01:30:32.540
Unless, did you have some more shouts before we close out?

01:30:32.540 --> 01:30:34.540
That's, that's all the shouts I have.

01:30:34.540 --> 01:30:39.540
Um, again, like you said, if anyone has any questions, they can email you, uh, email

01:30:39.540 --> 01:30:41.540
the show at radio at binrev.com.

01:30:41.540 --> 01:30:44.540
And I'm committing you to a future show.

01:30:44.540 --> 01:30:46.540
I will gladly be on a future show.

01:30:46.540 --> 01:30:50.540
If somebody comes in on some of these topics so we can go into more detail.

01:30:50.540 --> 01:30:53.540
So, so that people will actually know that I know what I'm talking about and can go

01:30:53.540 --> 01:30:55.540
in more in depth on some of these tools.

01:30:55.540 --> 01:30:59.540
I take, yeah, I'll take responsibility because I purposely reined you back and said, let's

01:30:59.540 --> 01:31:03.540
do overview stuff, which I know is difficult because you don't know where to draw the line

01:31:03.540 --> 01:31:07.540
and stop and going into too much detail or not enough detail.

01:31:07.540 --> 01:31:09.540
So, I'll take the credit that I caused you.

01:31:09.540 --> 01:31:10.540
I reined you in.

01:31:10.540 --> 01:31:14.540
So, future episodes, we'll pick a few of these and go into a lot more detail on it.

01:31:14.540 --> 01:31:17.540
So, I think that'll, something you're more comfortable with since you know these much

01:31:17.540 --> 01:31:20.540
more intimately than I do, obviously.

01:31:20.540 --> 01:31:23.540
And, that is going to do it for us this week.

01:31:23.540 --> 01:31:25.540
So, Quine, thank you for being on the show.

01:31:25.540 --> 01:31:26.540
Thank you for having me.

01:31:26.540 --> 01:31:31.540
And, for the rest of you, we will see you in a few minutes, actually.

01:31:31.540 --> 01:31:33.540
Slightly different hack time.

01:31:33.540 --> 01:31:36.540
Slightly different hack channel.

01:31:36.540 --> 01:31:37.540
No.

01:31:37.540 --> 01:31:38.540
Same hack channel.

01:31:38.540 --> 01:31:39.540
Same hack channel.

01:31:39.540 --> 01:31:40.540
I think.

01:31:40.540 --> 01:31:41.540
Something.

01:31:41.540 --> 01:31:42.540
I'm confused.

01:31:42.540 --> 01:31:43.540
Here's the music.

01:31:43.540 --> 01:31:55.540
The cat calls through the night.

01:31:55.540 --> 01:31:58.540
The two chicks in the parking lot cry.

01:31:58.540 --> 01:31:59.540
Why it's on the price of fame.

01:31:59.540 --> 01:32:00.540
They stood to gain.

01:32:00.540 --> 01:32:01.540
Phone books in the dark.

01:32:01.540 --> 01:32:02.540
And, two chicks in the dark.

01:32:02.540 --> 01:32:03.540
Across the way.

01:32:03.540 --> 01:32:04.540
No.

01:32:04.540 --> 01:32:05.540
The price of fame.

01:32:05.540 --> 01:32:06.540
No.

01:32:06.540 --> 01:32:07.540
The price of fame.

01:32:07.540 --> 01:32:08.540
No.

01:32:08.540 --> 01:32:09.540
The cat calls through the night.

01:32:09.540 --> 01:32:11.540
The two chicks in the parking lot cry.

01:32:11.540 --> 01:32:12.540
Why it's on the price of fame.

01:32:12.540 --> 01:32:13.540
They stood to gain.

01:32:13.540 --> 01:32:14.540
Phone books in the dark.

01:32:14.540 --> 01:32:15.540
And, two chicks in the dark.

01:32:15.540 --> 01:32:16.540
Across the way.

01:32:16.540 --> 01:32:17.540
No.

01:32:17.540 --> 01:32:18.540
The price of fame.

01:32:18.540 --> 01:32:19.540
They stood to gain.

01:32:19.540 --> 01:32:20.540
Phone books in the dark.

01:32:20.540 --> 01:32:21.540
And, two chicks in the dark.

01:32:21.540 --> 01:32:22.540
Across the way.

01:32:22.540 --> 01:32:23.540
No.

01:32:23.540 --> 01:32:24.540
The price of fame.

01:32:24.540 --> 01:32:25.540
It's weight and size.

01:32:25.540 --> 01:32:26.540
If you've got something.

01:32:26.540 --> 01:32:27.540
That sheds some light.

01:32:27.540 --> 01:32:28.540
Use it tonight.

01:32:28.540 --> 01:32:29.540
Tonight.

01:32:29.540 --> 01:32:30.540
Tonight.

01:32:30.540 --> 01:32:31.540
Tonight.

01:32:31.540 --> 01:32:32.540
Heads down.

01:32:32.540 --> 01:32:33.540
Thumbs up.

01:32:33.540 --> 01:32:34.540
Two sticks from the cup.

01:32:34.540 --> 01:32:35.540
Of human kindness.

01:32:35.540 --> 01:32:36.540
And, two chicks in the dark.

01:32:36.540 --> 01:32:37.540
It's weight and size.

01:32:37.540 --> 01:32:38.540
If you've got something.

01:32:38.540 --> 01:32:39.540
That sheds some light.

01:32:39.540 --> 01:32:40.540
Use it tonight.

01:32:40.540 --> 01:32:41.540
Tonight.

01:32:41.540 --> 01:32:42.540
Tonight.

01:32:42.540 --> 01:32:43.540
Tonight.

01:32:43.540 --> 01:32:44.540
Tonight.

01:32:44.540 --> 01:32:48.540
Tonight.

01:32:48.540 --> 01:32:49.540
Heads down.

01:32:49.540 --> 01:32:50.540
Thumbs up.

01:32:50.540 --> 01:32:51.540
Tonight.

01:32:51.540 --> 01:32:52.540
Tonight.

01:32:52.540 --> 01:32:53.540
Tonight.

01:32:53.540 --> 01:32:54.540
Tonight.

01:32:54.540 --> 01:32:55.540
Tonight.

01:32:55.540 --> 01:32:56.540
Tonight.

01:32:56.540 --> 01:32:57.540
Tonight.

01:32:57.540 --> 01:33:00.540
Tonight.

01:33:00.540 --> 01:33:02.540
Tonight.

01:33:02.540 --> 01:33:03.540
Tonight.

01:33:03.540 --> 01:33:04.540
Tonight.

01:33:04.540 --> 01:33:05.540
Today.

01:33:06.540 --> 01:33:07.540
Tonight.

01:33:12.540 --> 01:33:16.540
house.

01:33:22.540 --> 01:33:23.540
Today.

01:33:23.540 --> 01:33:31.540
Use it tonight, tonight

01:33:31.540 --> 01:33:35.540
You had to send a wrecking crew after me

01:33:35.540 --> 01:33:37.540
I can't walk right

01:33:37.540 --> 01:33:42.540
You had to send a wrecking crew after me

01:33:42.540 --> 01:33:44.540
I can't walk right

01:33:44.540 --> 01:33:54.540
The center of the heart

01:33:54.540 --> 01:33:57.540
Four beats from the party line

01:33:57.540 --> 01:34:01.540
Been mine since I was a child

01:34:01.540 --> 01:34:06.540
It just blew their world

01:34:06.540 --> 01:34:09.540
So heads down, thumbs up

01:34:09.540 --> 01:34:12.540
Four beats from Saturday

01:34:12.540 --> 01:34:16.540
Get set to exercise your right

01:34:16.540 --> 01:34:18.540
Use it tonight

01:34:18.540 --> 01:34:22.540
There's a choice between a chance and play

01:34:22.540 --> 01:34:30.540
Choose it tonight, tonight

01:34:30.540 --> 01:34:35.540
You had to send a wrecking crew after me

01:34:35.540 --> 01:34:37.540
I can't walk right

01:34:37.540 --> 01:34:41.540
You had to send a wrecking crew after me

01:34:41.540 --> 01:34:43.540
I can't walk right

01:34:43.540 --> 01:34:45.540
I can't walk right

01:34:47.540 --> 01:34:51.540
Use it tonight

01:34:51.540 --> 01:34:53.540
Tonight

01:34:53.540 --> 01:34:55.540
Tonight

01:34:55.540 --> 01:34:57.540
Tonight

01:34:57.540 --> 01:34:59.540
Tonight

01:34:59.540 --> 01:35:01.540
Tonight

01:35:01.540 --> 01:35:03.540
Night

01:35:03.540 --> 01:35:05.540
Night

01:35:05.540 --> 01:35:07.540
Tonight

01:35:07.540 --> 01:35:08.540
Two

01:35:08.540 --> 01:35:09.540
Tonight

01:35:09.540 --> 01:35:12.540
hm

