Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 34 guests and 2 members online
 
Advertisement

You are here: Home arrow Resourcesarrow Toolsarrow Fireshark Plug-in
EH-Net
May 21, 2013, 12:12:21 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Fireshark Plug-in  (Read 5197 times)
0 Members and 1 Guest are viewing this topic.
3xban
Hero Member
*****
Offline Offline

Posts: 605


View Profile WWW
« on: April 19, 2010, 03:52:08 PM »

Couple weeks ago I saw a post about Fireshark from the EU Blackhat conference.  Has anyone else took a look at it?  Current release is beta (fireshark.org) and documentation is lacking until the developer posts it.

Anyway, just wonder if anyone else has given it a shot.  I tossed mine on a VM of XP SP3 w/ latest Firefox and can't for the life of me figure out how to get it to run.  Mainly where to put the data file.  Directions state "Home Directory."

Also if anyone has gotten it to run, got any fun recommendations of suspicious sites to run it against?

Thanks!
Logged

Certs: GCWN
(@)Dewser
n1p
Jr. Member
**
Offline Offline

Posts: 89


View Profile WWW
« Reply #1 on: April 19, 2010, 05:20:38 PM »

It should work in C:\Documents and Settings\username\data.txt on XP. Linux would be /home/username/data.txt

Give that a try and report back. If you want to run it against some malicious sites. Just go to google and locate some of the malicious ones are there. Quite a few!

I also use Malware Domain List.... Ensure you are in VM though and hardening has been applied.
Logged
3xban
Hero Member
*****
Offline Offline

Posts: 605


View Profile WWW
« Reply #2 on: April 20, 2010, 08:00:59 PM »

Worked like a champ.  Now just need to get some sites to test against.  Was at work so didn't want to tempt fate too much.  Also made sure I did some snapshots before running it.  newb question, what else should I do to harden the system?  I switched my main user to a normal user, renamed the admin account and made sure everything had a password.  Also have some AV on it.  Threw on MS Security Essentials since its free and it would be interesting to see how it works.  Think I will mess with it more over the weekend.
Logged

Certs: GCWN
(@)Dewser
n1p
Jr. Member
**
Offline Offline

Posts: 89


View Profile WWW
« Reply #3 on: April 21, 2010, 05:13:07 PM »

Have a look at http://honeyclient.org/trac/wiki/VMHardeningGuide to further reassure you. Although, I would imagine you are ok as it is. The AV on the virtual machine may not let you run malware on it. I usually dont have one for my malware lab.

Logged
3xban
Hero Member
*****
Offline Offline

Posts: 605


View Profile WWW
« Reply #4 on: April 21, 2010, 07:46:33 PM »

Thanks n1p!  I'll have a look.
Logged

Certs: GCWN
(@)Dewser
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.059 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.