Tuesday, August 4, 2009

HOWTO delete a moinmoin wiki user

The MoinMoin instructions for how to delete a user, while correct, suck. First find your wiki settings file (mine is in /etc/moin/mywiki.py). In that file find your 'data_dir', mine was pointing to '/var/local/somewiki_wiki'. The user files sit in '/var/local/somewiki_wiki/user', one for each user. Grep that directory for the name you are looking for.

Delete the appropriate user file and also delete the cached username mapping file in ../cache/mywiki/user/name2id (this will be regenerated by django). Restart apache.

iptables the Ubuntu way

First, get your rules right on the commandline, some examples:
iptables -F
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -P FORWARD DROP
iptables -A INPUT -i lo -j ACCEPT 
iptables -A INPUT -i eth+ -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT 
iptables -A INPUT -i eth+ -p tcp -m tcp --dport 22 -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT

Then save to a file:
iptables-save >/etc/iptables.rules

Then in your /etc/network/interfaces file in the block for your interface:
pre-up iptables-restore < /etc/iptables.rules
If you are using network manager, you might want to put a script in dispatcher.d instead of using network/interfaces.

Another alternative is installing the iptables-persistent package, which installs a service that runs iptables-save and iptables-restore against rules in these files (for IPv4 and IPv6):
/etc/iptables/rules.v4
/etc/iptables/rules.v6
You can do iptables-save to create those files, or just get the rules the way you want then let the package do it for you:
sudo dpkg-reconfigure iptables-persistent

Sunday, August 2, 2009

mdd for windows memory dumps

I have used 'dd.exe' from the Forensic Acquistion Utilities toolkit for Windows memory dumps in the past. The website now appears to be down, so I tried out mdd, an open source project. Worked a treat.

And more malware - lsass.exe

Turns out the previous post wasn't the last of it. An AV message popped up alerting me to a buffer overflow on the heap triggered by C:\windows\cursors\lsass.exe (what is a regular user supposed to do about that?). There may have been some level of rootkitting because I couldn't see the file on the commandline or with windows explorer - booting a linux live CD fixed that problem. This is a location that has been associated with sasser, and this *may* have been a variant, but not a single AV picked it up at virus total. It was using this key to persist:

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"Shell"="Explorer.exe C:\\WINDOWS\\Cursors\\lsass.exe"

Sent to McAfee again, and a different Bangalore monkey produced another signature! Win.

Friday, July 31, 2009

Fun tracking down malware - svcchost.exe

I love being tech support. Found a little nasty called svcchost.exe (classic!) on a family windows computer. Run key in:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
C:\Documents and Settings\username\Application Data\Microsoft\svcchost.exe

Beacons:

1 0.000000 10.1.1.9 10.1.1.1 DNS Standard query A xdemonx.selfip.org
2 0.000590 10.1.1.1 10.1.1.9 DNS Standard query response A 96.18.166.50
3 0.000895 10.1.1.9 96.18.166.50 TCP 1588 > 3085 [SYN] Seq=0 Win=16384 Len=0 MSS=1460

Reported to McAfee. They actually have some decent advice for finding runkeys:
On Windows XP systems, click START RUN, type MSCONFIG and hit ENTERClick the Startup tab.

A McAfee monkey in Bangalore produced a signature and sent back an extra.dat file in just a few minutes. Mission accomplished.

Sunday, July 12, 2009

Advice on how to report an ubuntu bug

The Ubuntu wiki has a great page on how to report a bug. It includes details of how to install debugging symbol packages (I didn't know these existed, I always headed for the source and compiled a debug build), and detailed gdb instructions.

I also finally learnt a better way to find out which version you are running (usually I look at /etc/issue or /etc/apt/sources), but this:
lsb_release -rd
gives you the numerical release number. Sweet.

Restarting NFS after changes to /etc/exports

On ubuntu I was using
/etc/init.d/nfs-common restart
to restart NFS after making changes to /etc/exports. Unfortunately this doesn't work. Use "exportfs -a" to sync changes (clients don't need to re-mount either).