Post Humorous http://posthumorous.com funny died. welcome to the wake. root@posthumorous.com root@posthumorous.com Copyright 2008 Post Humorous GeekLog Thu, 10 Jul 2008 18:02:37 -0500 en-us UNIX and Linux Forensic Analysis is out http://posthumorous.com/article.php?story=2008071012201217 http://posthumorous.com/article.php?story=2008071012201217 Thu, 10 Jul 2008 12:20:00 -0500 http://posthumorous.com/article.php?story=2008071012201217#comments Forensics & IR <a href="http://www.amazon.com/gp/product/1597492698?ie=UTF8&amp;tag=posthumo-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=1597492698"><img width="500" height="500" src="http://posthumorous.com/images/articles/2008071012201217_1_original.jpg" alt=""></a><br><br>The <a href="http://www.amazon.com/gp/product/1597492698?ie=UTF8&amp;tag=posthumo-20&amp;linkCode=as2&amp;camp=1789&amp;creative=9325&amp;creativeASIN=1597492698">book I co-authored</a> is available now. I can't say I'm 100% pleased with my portions - I was brought in late in the process and we ran way short on time. I think my parts are good, not great. I'll be working on some more forensics/incident response texts in the future, so hopefully I'll have more time to polish up what I produce.<br><br>Regardless, you should buy it.<br><br>If you have any questions about the book or contents thereof, feel free to post or mail me.<br><br>Tag: <a class="tag_link" href="http://posthumorous.com/tag/index.php?tag="></a> <a class="tag_link" href="http://posthumorous.com/tag/index.php?tag=forensics">forensics</a> <a class="tag_link" href="http://posthumorous.com/tag/index.php?tag=unix">unix</a> <a class="tag_link" href="http://posthumorous.com/tag/index.php?tag=linux">linux</a> <a class="tag_link" href="http://posthumorous.com/tag/index.php?tag=book">book</a> http://posthumorous.com/trackback.php?id=2008071012201217 PTK Beta Released http://posthumorous.com/article.php?story=20080605124636994 http://posthumorous.com/article.php?story=20080605124636994 Thu, 05 Jun 2008 12:46:00 -0500 http://posthumorous.com/article.php?story=20080605124636994#comments Forensics & IR The open beta for PTK started a few days ago.<br><br>You can fetch it up at <a href="http://ptk.dflabs.com/">DFLabs</a>.<br><br>Description from the site:<br><br><i>"PTK is an alternative advanced interface for the suite TSK (The Sleuth Kit). PTK was developed from scratch and besides providing the functions already present in Autopsy Forensic Browser it implements numerous new features essential during forensic activity. PTK is not just a new graphic and highly professional interface based on Ajax technology but offers a great deal of features like analysis, search and management of complex cases of digital investigation."</i> Big improvements I've noticed over Sleuthkit since I've been playing with it:<br><br><ul> <li>Much much improved GUI/user experience</li> <li>Built in indexing</li> <li>Rocking graphical timeline feature</li> <li>No auto-display of gigantic binary files upon initial click</li> <li>Memory parsing (currently only of XP SP2 systems) courtesy <a href="https://www.volatilesystems.com/VolatileWeb/volatility.gsp">Volatility</a> plugin</li> <li>Super-rad bookmarking feature</li></ul>It's ridiculously easy to install on Ubuntu 8.04 Server (install LAMP server, add mysql root user when prompted, download &amp; install PTK. Browse to http://&#36;MYSERVER/ptk). I recommend you try it out so you can see what the cool kids are up to. http://posthumorous.com/trackback.php?id=20080605124636994 Argus 3.0 released http://posthumorous.com/article.php?story=20080520102340329 http://posthumorous.com/article.php?story=20080520102340329 Tue, 20 May 2008 10:23:00 -0500 http://posthumorous.com/article.php?story=20080520102340329#comments Forensics & IR This actually happened over a month ago, but I managed to not notice until now, thanks to a near absence of downtime.<br><br><a href="http://article.gmane.org/gmane.network.argus/5961">Argus 3.0 release announcement</a><br><br>If you're not aware of Argus, it's an excellent tool to use during both proactive and reactive network monitoring. I use it primarily in a response capacity - to turn packet captures into useful information very quickly.<br><br>The description from <a href="http://qosient.com/argus">the source:</a> Argus is a fixed-model Real Time Flow Monitor designed to track and report on the statusand performance of all network transactions seen in a data network traffic stream. Argusprovides a common data format for reporting flow metrics such as connectivity, capacity,demand, loss, delay, and jitter on a per transaction basis. The record format that Argususes is flexible and extensible, supporting generic flow identifiers and metrics, as well asapplication/protocol specific information.<br><br>Argus can be used to analyze and report on the contents of packet capture files or it canrun as a continuous monitor, examining data from a live interface; generating an audit logof all the network activity seen in the packet stream. Argus can be deployed to monitorindividual end-systems, or an entire enterprises network activity. As a continuousmonitor, Argus provides both push and pull data handling models, to allow flexiblestrategies for collecting network audit data. Argus data clients support a range ofoperations, such as sorting, aggregation, archival and reporting. There is XML supportfor Argus data, which makes handling Argus data a bit easier, see ArgusRecord.xsd.<br><br><a href="http://qosient.com/argus/src/">You can download Argus here.</a> It should build on pretty much any Unix you've got floating around, and the client apps will build and run in <a href="http://www.cygwin.com/">Cygwin</a>. If there is interest, I'll do a full writeup on building and using Argus client apps in an incident response capacity. http://posthumorous.com/trackback.php?id=20080520102340329 News from my old stomping grounds http://posthumorous.com/article.php?story=20080519144525188 http://posthumorous.com/article.php?story=20080519144525188 Mon, 19 May 2008 14:45:00 -0500 http://posthumorous.com/article.php?story=20080519144525188#comments Weird Been a while since I read <a href="http://www.valleywag.com">ValleyWag</a>... probably since I left Google. I'm at IBM now, though, and VW routinely makes fun of our ridiculous <a href="http://www.encyclopediadramatica.com/Second_Life">Second Life</a> initiatives (seriously, how many furries are buying iSeries?*) so I decided I should start keeping up again. I run across this gem:<br><br><b><a href="http://valleywag.com/390938/orkut-inventor-may-be-best-argument-against-h+1b-visas-yet">Orkut inventor may be best argument against H-1B visas yet</a></b><br><br>Stay beautiful! <br><br>* This is perhaps a question that is best left unaswered. http://posthumorous.com/trackback.php?id=20080519144525188 New Nine Inch Nails album. Already. And it's free. http://posthumorous.com/article.php?story=20080505224636321 http://posthumorous.com/article.php?story=20080505224636321 Mon, 05 May 2008 22:46:00 -0500 http://posthumorous.com/article.php?story=20080505224636321#comments General News Looks like Trent may actually just be in this for the music. Trent Reznor dropped a <a href="http://theslip.nin.com">new album</a> on us today, and I must say that I'm enjoying it. While it's definitely not his best work (I'll leave that honor to the broken EP, and I'm going song for song here), it is still very enjoyable, particularly to those who enjoyed his last 2 ventures (not including Ghosts). It definitely has elements of both, mainly in style; imagine a harder, more cohesive version of With Teeth (my least favorite NIN album, though it has grown on me) particularly the vocals, with some of the breakbeateyness of Year Zero (one of my favorite albums of all time*) tossed in for good measure. Portions almost have a <a href="http://en.wikipedia.org/wiki/Trip_hop">trip-hop</a> sound to them, which I thoroughly enjoyed. And for the asking price (US &#36;0) you can't go wrong, since the only thing that is required it that you give them an email to send the download link. And as we all know, anyone on the internet (with the exception of most grandmothers, invalids, and rural Americans) has the address they actually use, and the one they use for bonerpill offers and Nigerian bank scams. While there's not necessarily a reason to use the latter for the download link, having one does preclude you from using paranoia as your out on this.<br><br><br>True to form, Trent has followed the same path he did with Year Zero and is encouraging fans to <a href="http://remix.nin.com/">remix the album.</a> I've had fun <a href="http://remix.nin.com/member/ruiner314">remixing</a> several of the songs from Year Zero, and if you have either Ableton Live or GarageBand, and some free time and a love of creating music, give it a try. It sure beats jerkin' in to internet porn for the 5 time in a day, and you may just find you have some undiscovered talent that is acceptable in public.<br><br><br><br>* If you haven't figured this out yet: YES, I am a NIN fanboy, and no I don't include Pretty Hate Machine on my list of cumsplosively awesome albums. It's a capable album that had some good tunes, and I'm glad it provided enough encouragement for Trent to keep making good albums. http://posthumorous.com/trackback.php?id=20080505224636321 Zombie Strippers http://posthumorous.com/article.php?story=20080425112111132 http://posthumorous.com/article.php?story=20080425112111132 Fri, 25 Apr 2008 11:21:00 -0500 http://posthumorous.com/article.php?story=20080425112111132#comments Zombies <a href="http://www.sonypictures.com/movies/zombiestrippers/index.html">Zombie Strippers</a><br><br>wow<br><br> wow just wow<br><br>It looks like it might have too high of a budget to be sucky enough to be enjoyable <br><br>I call it the "Snakes On A Plane" effect.<br><br> <a href="http://posthumorous.com/images/articles/20080425112111132_1_original.jpg" title="View unscaled image"><img width="480" height="360" src="http://posthumorous.com/images/articles/20080425112111132_1.jpg" alt=""></a><br><br>For movies that *ARE* low budget enough to escape the Snakes On A Plane curse of mediocrity, check out 2005's <a href="http://www.imdb.com/title/tt0448177/">The Wickeds</a> (starring <a href="http://www.imdb.com/name/nm0000465/bio">The Hedgehog</a>) and <a href="http://www.imdb.com/title/tt0411806/">Return of the Living Dead: Rave to the Grave</a> (also 2005 - a banner year for <a href="http://us.imdb.com/title/tt0121766/">absolute shit</a>, apparently).<br><br><i>The Wickeds</i> stars Ron Jeremy as one half of a grave robbing team. Their grave robbing triggers some curse, and zombies attack a farmhouse full of teenagers. As these are the "Rise From the Dead" class of zombies, the most unsettling thing about the movie is the shabby state of burial garb many of the zombies showcase - ripped band T-shirts, jean shorts, nothing at all, etc.<br><br><i>Return of the Living Dead: Rave to the Grave</i> is one of those movies where you have to say the entire title, EVERY TIME, like <a href="http://www.youtube.com/watch?v=01l1WIC9mBo">Death Bed: The Bed That Eats People</a>. The plot revolves around a college chemistry major who is also a small-time party drug manufacturer - pretty standard fare so far. Unfortunately, he creates a new drug, 'Z' (see the foreshadowing?) using the contents of a biohazard canister he found in a ditch, or something (it's been a while). Fans of the ROTLD series will instantly recognize the canister as the source of the trioxin gas which creates the ROTLD-class zombies that originated the oft-reused line "BRAAAAAAAAAAAAINS."* Hijinks ensue (at a rave). (To the grave).<br><br>* <a href="http://www.imdb.com/name/nm0001681/">Romero's zombies</a> were not picky eaters, and showed no penchant for any particular cut of human. http://posthumorous.com/trackback.php?id=20080425112111132 FIRST POST http://posthumorous.com/article.php?story=20080424165413309 http://posthumorous.com/article.php?story=20080424165413309 Thu, 24 Apr 2008 16:54:00 -0500 http://posthumorous.com/article.php?story=20080424165413309#comments General News Welcome to my blog... web... thing.<br><br>One of my New Year's resolutions was to jump on early 2000's bandwagons, so I will be forwarding virus hoaxes and <a href="http://www.albinoblacksheep.com/flash/banana">Banana Dance</a> to everyone who's ever had the misfortune of mailing me. Additionally, I will be blogging infrequently. I'm not interested in one thing enough to have a blog dedicated to a particular topic (unlike my hard-working brothers-in-forensics you may have noticed in the Links section), so this will be a grab bag. So if you are just interested in forensics and incident response, and hate game news, tough shit.*<br><br>Because I'll be talking about whatever I find interesting at the time. It'll mostly be talking about forensics &amp; incident response (since that's what I do for a living) and electronic gaming (since that's what I do for fun). I may even have special guest bloggers for your enjoyment. EXCITING TIMES, EH, FRIENDO?<br><br>PS I also curse like a sailor.<br><br>PPS IRL too, it's quite a problem.<br><br>*It's not that tough, really - I mean you could just subscribe to stories posted in the Forensics topic. Show some initiative. http://posthumorous.com/trackback.php?id=20080424165413309