Jump to content

Leaderboard

Popular Content

Showing content with the highest reputation on 12/30/11 in all areas

  1. glTail is a tool for realtime log visualisation, which according to the website allows you to “view real-time data and statistics from any logfile on any server with SSH, in an intuitive and entertaining way.” glTail can read from any text logfile you like, and via a set of parsers can extract information such as IP addresses for graphical display. Each row from the logfile may trigger several blobs, e.g. source IP, dest IP, etc, as you can see in the video below: I’ve written some parsers for Snort, net-entropy and viewssld. A screenshot of them all in action is shown below (click here for full size view): The red blobs are related to Snort, cyan ones to net-entropy, and the yellow shades are from viewssld. The numeric columns show the rate at which each item is appearing, and the length of the coloured highlight bars show the proportion of occurences of a given item relative to the others. The parser files and a sample config.yaml file that uses them can be found here (snort.rb, net-entropy.rb, viewssld.rb and config.yaml). Useful? So, it’s a pretty visualisation of interesting stuff, but is it useful and actionable? It’s certainly hopeless for correlation – when a signature fires, it’s more or less impossible to tell the associated IP addresses and ports even if you have a very quiet sensor. At the other end of the scale, if you’re inundated with blobs you can alter the regexes in snort.rb to match on a specific IP/protocol/signature etc to be a little more selective. Where I think this may prove most useful is when you’re learning from an incident. If you’ve investigated an incident where someone compromised your webserver, you could pull all the relevant log entries that show: Snort alerts (when the attacker was probing for vulnerabilities) Apache/IIS log entries (showing everything else they did to your server) net-entropy logs (showing the attacker’s outbound backdoor SSH tunnel). If you were to pump all of these logs through gltail you’d have an effective visualisation of the attack. For inspiration, check this out: Download Source
    1 point
  2. 1 point
  3. 1 point
  4. lantern212 - Yenot212 kzirpolo - hockey markief3 - jsbach21 mcumm02 - entropy maxbison - onions mjc40769 - uropygi nckeni - aeh2112 nh7575 - nh555555 o0drown0o - br5tner pippo110-pippo111 rb3903-jkl12399 matguyvr-catguts teoman2006-beko3193 merollan-cowap1 sevenrach-boubi007 kapacha-123456 dmaye999-glenties fury06-ground hangsa-asgnah GewirtLH-G7looibl loof63-limpan mrnamojo-cancer 1qaz2-123456 9702pro-sandy970 av8r777-rtw123 bentonio-libertad bigc8841-con300 bj97gw-ranger blkbuddy-007968 blah123-123456 bigty58-allciaa birds1-front242 BonesLTJ-beer9999 Bobfather-dedham boogief1-formula1 catullan-drusus chase123-chase chopin22-112269 colbuga-duckwell cwmxcwmx-22342234 Cybare-vidcom dbson33-123456 dawg97-rikers97 dbelcher-jdmba4 denik86-arnold dep38141-reifit dmgm31-maddux drdremel-wicket drsw11-150272 dtran2k3-dreamcast ef2lsv-lantern dysasl-011607 forgot29-hunter29 flipper2-flipper frankn17-assman fsuels-15394600 gertime-tolkager gt0200b-buffman h191919-h191919 gwilson21-jessica hanserd-knollys Huisan2314-malcolm igero23-232122 imlikewhoa-dragon jaysin-sanfan japollo-apollo jball2121-414311 kemet111-kaned111 kristodj-chicaboy lantern212-Yenot212 kzirpolo-hockey markief3-jsbach21 mcumm02-entropy maxbison-onions mjc40769-uropygi nckeni-aeh2112 nh7575-nh555555 o0drown0o-br5tner pabloloko-123456 piyamas48-mam5073 RailBaron-atsf12 rally122-astragte rdmeans-123456 redred99-rreedd99 rufusjr-reidjr sheen4-jcole10 shane76-weasel76 shoe-shoe sld20044-032789 spider-123456 stevep77-paxman77 swimyxx-sexyxx tobyrd01-rebus01 Tstarnes-262637 twinizle-impala63 Vareso-Smurf1 vince269-estate wendi17-123417 wfbenton-ilnevel1 wparker-123456 pabloloko - 123456 piyamas48 - mam5073 RailBaron - atsf12 rally122 - astragte rdmeans - 123456 redred99 - rreedd99 rufusjr - reidjr sheen4 - jcole10 shane76 - weasel76 shoe - shoe sld20044 - 032789 spider - 123456 stevep77 - paxman77 swimyxx - sexyxx tobyrd01 - rebus01 Tstarnes - 262637 twinizle - impala63 Vareso - Smurf1 vince269 - estate wendi17 - 123417 wfbenton - ilnevel1 wparker - 123456 pippo110 - pippo111 rb3903 - jkl12399 matguyvr - catguts teoman2006 - beko3193 merollan - cowap1 sevenrach - boubi007 kapacha - 123456 dmaye999 - glenties fury06 - ground hangsa - asgnah GewirtLH - G7looibl loof63 - limpan mrnamojo - cancer 1qaz2 - 123456 9702pro - sandy970 av8r777 - rtw123 bentonio - libertad bigc8841 - con300 bj97gw - ranger blkbuddy - 007968 blah123 - 123456 bigty58 - allciaa birds1 - front242 BonesLTJ - beer9999 Bobfather - dedham boogief1 - formula1 catullan - drusus chase123 - chase chopin22 - 112269 colbuga - duckwell cwmxcwmx - 22342234 Cybare - vidcom dbson33 - 123456 dawg97 - rikers97 dbelcher - jdmba4 denik86 - arnold dep38141 - reifit dmgm31 - maddux drdremel - wicket drsw11 - 150272 dtran2k3 - dreamcast ef2lsv - lantern dysasl - 011607 forgot29 - hunter29 flipper2 - flipper frankn17 - assman fsuels - 15394600 gertime - tolkager gt0200b - buffman h191919 - h191919 gwilson21 - jessica hanserd - knollys Huisan2314 - malcolm igero23 - 232122 imlikewhoa - dragon jaysin - sanfan japollo - apollo jball2121 - 414311 kemet111 - kaned111 kristodj - chicaboy 9702pro - sandy970 ahkhiat - asparo alaincar - 121145 allanjl - filter1 antonio - 1234 bj97gw - ranger bobigb - roofer Bobfather - dedham chopin22 - 112269 cwgexpress - airborn dakhath - thx1138 cwmxcwmx - 22342234 dbelcher - jdmba4 dawg97 - rikers97 Denihilist - nodenial denik86 - arnold demasio - pvamuedu dmgm31 - maddux Doc.Holiday - holiday ef2lsv - lantern dysasl - 011607 forgot29 - hunter29 gege06 - gerard ghostlogos - gnosis giusedi - 250466 ginyusan - desire gullo1 - tq6jjh gregvs3 - Legion h191919 - h191919 hanedge - 12321232 harpv - 196950 hanserd - knollys gwilson21 - jessica henri66 - riton62 jaysin - sanfan japollo - apollo jims3356 - lizalex jimyc69 - password jmjawors - lspear jr1760 - jrok17 jowagn - skeets kblake12 - nupe12 kemet111 - kaned111 KR3000 - 02061980 kristodj - chicaboy kzirpolo - hockey kulani - raven1 mhalladay - nikki mjc40769 - uropygi mrx7777 - nodo90 Nate731 - fjdksl nh7575 - nh555555 o0drown0o - br5tner peeru60 - pmy60mhd peibol - pablamos pekolareko - peckys raker232 - 3557725 river666 - 181977 shady3oo - jaden3 sheen4 - jcole10 skaboat - weed420 sld20044 - 032789 sobo07 - tesla07 shane76 - weasel76 spider - 123456 srmtx2 - eagle2 stevep77 - paxman77 steveophx - brenda stcooley - 573200 swimyxx - sexyxx timone78 - 1tiffany toto7482 - 741982 twinizle - impala63 txtel33 - 117574 Trinitan - Ptange usc - trojans ulgn64 - guggen vince269 - estate vortak - dragon xhermesx - d1o2m3 zimpat - Tombctou Say thanks bitches!
    1 point
  5. http://4metin.ro/cos-de-reciclare/romanian-security-team-t50278.html#p402080 O gasca de copii care nu au trecut de varsta de 15 ani.
    -1 points
  6. Noci in prag de revelion nu pot sa stau fara sa dau ban! Va iubesc ) Ban de pe telefon!
    -1 points
  7. -1 points
×
×
  • Create New...