<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Shibumi Dojo &#187; Network</title>
	<atom:link href="http://www.shibumidojo.org/index.php/category/network/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.shibumidojo.org</link>
	<description></description>
	<lastBuildDate>Mon, 16 Jan 2012 07:48:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Isik University and Bahcesehir University Seminars</title>
		<link>http://www.shibumidojo.org/index.php/2010/04/04/isik-university-and-bahcesehir-university-seminars/</link>
		<comments>http://www.shibumidojo.org/index.php/2010/04/04/isik-university-and-bahcesehir-university-seminars/#comments</comments>
		<pubDate>Sun, 04 Apr 2010 15:25:27 +0000</pubDate>
		<dc:creator>CorpusCallosum</dc:creator>
				<category><![CDATA[Do]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Psychology]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.shibumidojo.org/?p=363</guid>
		<description><![CDATA[&#160;It&#8217;s been for a long time since my last post, and yes here is seminar news again. I had two seminars at two different universities with same topics which contains; &#160;&#160;&#160; * A mythical story about me &#160;&#160;&#160; * A demo for digital investigation and some brainstorming activities for an assassin plan &#160;&#160;&#160; * A [...]]]></description>
			<content:encoded><![CDATA[<p>&nbsp;It&#8217;s been for a long time since my last post, and yes here is seminar news again. I had two seminars at two different universities with same topics which contains;<span id="more-363"></span></p>
<p>&nbsp;&nbsp;&nbsp; * A mythical story about me<br />
&nbsp;&nbsp;&nbsp; * A demo for digital investigation and some brainstorming activities for an assassin plan<br />
&nbsp;&nbsp;&nbsp; * A demo for web application security includes port scanning, information gathering from http, https ports, banner grabbing, etc<br />
&nbsp;&nbsp;&nbsp; * Detailed information about OWASP and OWASP Turkey<br />
&nbsp;&nbsp;&nbsp; * Definition of Cyber World Concept<br />
&nbsp;&nbsp;&nbsp; * Examined the security necessity on cyber world<br />
&nbsp;&nbsp;&nbsp; * Defined cyber security concept<br />
&nbsp;&nbsp;&nbsp; * Talked about Terrorism, cyber-terrorism, cyber wars<br />
&nbsp;&nbsp;&nbsp; * Gave a functional approach to Terrorism<br />
&nbsp;&nbsp;&nbsp; * Highlighted the importance of web application security, threats, attack vectors, DoS, Buffer overflows, Injections,etc.<br />
&nbsp;&nbsp;&nbsp; * Generated a wide and deep multidisciplinary cyber security perspective<br />
&nbsp;&nbsp;&nbsp; * Finally, we talked about how we can prepare ourselves for future threats a little.</p>
<p>Actually, I was surprised by both seminars. I was planning to talk around 50 minutes however people were interested in the topic more than I could guess. So, I had to talk around 2-3 hours which I really enjoyed. <img src='http://www.shibumidojo.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>I think both seminars gave a new perspective about the future definitions of security and risk to listeners. I will write about these topics on this site later. </p>
<p>On the other hand, I will be in a IPTV show to talk about cyber terrorism with two lawyers soon, but before that, on the 29 April 2010, I will be in Yeditepe University, Istanbul to talk about cyber-terrorism for the Information Technologies Law Organization.</p>
<p>Besides that, I have a almost new job somewhere in Europe. I will also tell the details about that.</p>
<ul class="related_post"></ul>]]></content:encoded>
			<wfw:commentRss>http://www.shibumidojo.org/index.php/2010/04/04/isik-university-and-bahcesehir-university-seminars/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Seminar in Istanbul Kultur University</title>
		<link>http://www.shibumidojo.org/index.php/2009/12/27/seminar-in-istanbul-kultur-university/</link>
		<comments>http://www.shibumidojo.org/index.php/2009/12/27/seminar-in-istanbul-kultur-university/#comments</comments>
		<pubDate>Sun, 27 Dec 2009 07:46:41 +0000</pubDate>
		<dc:creator>CorpusCallosum</dc:creator>
				<category><![CDATA[Do]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Psychology]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.shibumidojo.org/?p=356</guid>
		<description><![CDATA[I will be in Istanbul Kultur University for a free seminar supported by OWASP. Fundamentally the topic will be about Cyber Wars, but also, will include; What is OWASP, OWASP&#160;Projects, seminar, society, etc. Internet as a new social and cultural domain Cyber world as a new milieu Why do we need a security perspective? First [...]]]></description>
			<content:encoded><![CDATA[<p><img src='http://www.shibumidojo.org/wp-content/plugins/simple-post-thumbnails/timthumb.php?src=/wp-content/thumbnails/356.jpg&amp;w=200&amp;h=150&amp;zc=1&amp;ft=jpg' alt='post thumbnail' /></p>
<p>I will be in Istanbul Kultur University for a free seminar supported by OWASP. Fundamentally the topic will be about <strong>Cyber Wars</strong>, but also, will include;<span id="more-356"></span></p>
<ul>
<li>What is OWASP, OWASP&nbsp;Projects, seminar, society, etc.</li>
<li>Internet as a new social and cultural domain</li>
<li>Cyber world as a new milieu</li>
<li>Why do we need a security perspective?</li>
<li>First aggressions on the Internet</li>
<li>Size and Shapes of threats</li>
<li>Threat hierarchy of timeline</li>
<li>Organized cyber crimes and cyber wars</li>
<li>Cyber World and International Relations</li>
<li>Terrorism and Cyber Terrorism</li>
<li>How can we prepare for the future ?</li>
</ul>
<p><strong>Date: Tuesday, December 29, 2009<br />
Time: 12:00pm &#8211; 1:30pm<br />
Location: İstanbul K&uuml;lt&uuml;r &Uuml;niersitesi, Atak&ouml;y Kamp&uuml;s&uuml;, &Ouml;nder &Ouml;ztunalı Konferans Salonu </strong></p>
<p><a href="http://www.webguvenligi.org/etkinlik/sunum-istanbul-kultur-universitesi.html" target="_blank">http://www.webguvenligi.org/<wbr></wbr>etkinlik/sunum-istanbul-<wbr></wbr>kultur-universitesi.html</a><br />
<a href="http://www.owasp.org/index.php/Turkey#tab=Meetings.2FConferences" target="_blank">http://www.owasp.org/index.<wbr></wbr>php/Turkey#tab=Meetings.<wbr></wbr>2FConferences</a><br />
<a href="http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure" target="_blank">http://www.owasp.org/index.<wbr></wbr>php/Turkey#tab=Local_News.<wbr></wbr>2FBrochure</a></p>
<p>&nbsp;</p>
<ul class="related_post"></ul>]]></content:encoded>
			<wfw:commentRss>http://www.shibumidojo.org/index.php/2009/12/27/seminar-in-istanbul-kultur-university/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SNMP and Security</title>
		<link>http://www.shibumidojo.org/index.php/2009/07/25/snmp-and-security/</link>
		<comments>http://www.shibumidojo.org/index.php/2009/07/25/snmp-and-security/#comments</comments>
		<pubDate>Sat, 25 Jul 2009 13:16:29 +0000</pubDate>
		<dc:creator>CorpusCallosum</dc:creator>
				<category><![CDATA[Network]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[snmp]]></category>
		<category><![CDATA[snmp vulnerabilities]]></category>
		<category><![CDATA[snmpv1]]></category>
		<category><![CDATA[snmpv2]]></category>
		<category><![CDATA[snmpv3]]></category>

		<guid isPermaLink="false">http://www.shibumidojo.org/?p=239</guid>
		<description><![CDATA[I will give some information about the definition of SNMP and what kind of security vulnerability risks come with this protocol. Many administrator have relied SNMP (Simple Network Management Protocol) in order to handle monitoring and management issues of network devices. Since the network concept has improved and also the necessities of administrators increased, the [...]]]></description>
			<content:encoded><![CDATA[<p>I will give some information about the definition of SNMP and what kind of security vulnerability risks come with this protocol. Many administrator have relied SNMP (Simple Network Management Protocol) in order to handle monitoring and management issues of network devices.<span id="more-239"></span>  Since the network concept has improved and also the necessities of administrators increased, the SNMP protocol has been established in the late 80&#8242;s in order to gain some useful information like if the router is working, or operating the devices from the remote networks like disable or enable UPS, etc.</p>
<p>Using SNMP it is possible to obtain the condition of a hard-drive partition, uptime of Switches, Routers, UPS, etc or traffic density on the port of a Router, etc. and run into Application Layer on TCP/IP stack. Furthermore, it runs multitude devices and operation systems such ;</p>
<ul>
<li>Core Network Devices (Routers, Switches, Hubs, Bridges, and Wireless Network Access Points)</li>
<li>Consumer Broadband Network Devices (Cable Modems and DSL Modems)</li>
<li>Consumer Electronic Devices (Cameras and Image Scanners)</li>
<li>Networked Office Equipment (Printers, Copiers, and FAX Machines)</li>
<li>Network and Systems Management/Diagnostic Frameworks (Network Sniffers and Network Analyzers)</li>
<li>Networked Medical Equipment (Imaging Units and Oscilloscopes)</li>
<li>Manufacturing and Processing Equipment, etc.&nbsp;</li>
</ul>
<p><img hspace="1" vspace="1" border="1" align="left" alt="" style="width: 329px; height: 301px;" src="http://www.shibumidojo.org/wp-content/uploads/image/CT845602.jpg" />The agent module which works and collect the information on the intended device, the manager part that interacts with the agent and takes the data from it, additionally, network management element which works on the manager and provides all the devices visible, traceable and reconfigurable, are the three main components of the SNMP protocol in order to work properly.</p>
<p>SNMP is a request-wait for apply based protocol. Network Management Component sends a request to a device that consist of Agent module, and after that the Agent returns the reply of the request to network management component.  Management and Monitoring issues are handled five different types of messages in SNMPv1 which is is formally defined in <a href="http://www.ietf.org/rfc/rfc1157.txt"><u>RFC1157</u></a> :  <i>GetRequest, SetRequest, GetNextRequest, GetResponse, </i>and <i>Trap</i><i>. </i></p>
<p>A single SNMP message is referred to as a Protocol Data Unit (PDU). These messages are described using Abstract Syntax Notation One (ASN.1) and translated into binary format using Basic Encoding Rules (BER). SNMP request messages are sent from managers to agents. Request messages can poll the agent for current performance or configuration data, ask for the next SNMP object in a Management Information Base (MIB), or modify configuration settings. SNMP agents should reliably decode request messages and process the resulting application data.</p>
<p><font face="Verdana"><small>OUSPG&#8217;s research focused on the manner in which SNMPv1 agents and managers handle request and trap messages.  By applying the <a href="http://www.ee.oulu.fi/research/ouspg/protos/testing/c06/snmpv1/0100.html">PROTOS c06-snmpv1 test suite</a> to a variety of popular SNMPv1-enabled products, the OUSPG revealed the following vulnerabilities: </small></font></p>
<p><font face="Verdana"><small><b><a href="http://www.kb.cert.org/vuls/id/107186">VU#107186</a> &#8211; Multiple vulnerabilities in SNMPv1 trap handling </b> </small></font></p>
<blockquote><p><font face="Verdana"><small> SNMP trap messages are sent from agents to managers. A trap message may indicate a warning or error condition or otherwise notify the manager about the agent&#8217;s state.  SNMP managers must properly decode trap messages and process the resulting data.  In testing, OUSPG found multiple vulnerabilities in the way many SNMP managers decode and process SNMP trap messages.  </small></font></p></blockquote>
<p><font face="Verdana"><small><b><a href="http://www.kb.cert.org/vuls/id/854306">VU#854306</a> &#8211; Multiple vulnerabilities in SNMPv1 request handling </b></small></font></p>
<blockquote><p> <font face="Verdana"><small>SNMP request messages are sent from managers to agents. Request messages might be issued to obtain information from an agent or to instruct the agent to configure the host device. SNMP agents must properly decode request messages and process the resulting data. In testing, OUSPG found multiple vulnerabilities in the way many SNMP agents decode and process SNMP request messages. </small></font></p></blockquote>
<p>Vulnerabilities in the decoding and subsequent processing of SNMP messages by both managers and agents may result in denial-of-service conditions, format string vulnerabilities, and buffer overflows. Some vulnerabilities do not require the SNMP message to use the correct SNMP community string.</p>
<p>The CERT Advisory goes on to report the impact of these vulnerabilities:<br />
&nbsp;&nbsp;&nbsp; 1. unauthorized privileged access<br />
&nbsp;&nbsp;&nbsp; 2. denial-of-service attacks<br />
&nbsp;&nbsp;&nbsp; 3. unstable behavior (service interruptions)<br />
The CISO needs to keep the following concerns in mind when managing risk in the enterprise.</p>
<ol>
<li><strong>Threat: Fuzzing &ndash; Exposed Shared Secrets:</strong> A major vulnerability of SNMP v1/v2c is that the shared secret is sent in the clear; it is not encrypted. This is true whether the SNMP request is querying counter information, inspecting topology data, or reconfiguring the device. Since the shared secret is not hidden, an attacker can monitor the SNMP traffic to determine network topology and harvest those shared secrets. Among hackers, this is called fuzzing; amongst security professionals, this is Packet Sniffing.
<p>    For example, using SNMP v1/v2c in an insecure network such as a DMZ means an attacker can monitor SNMP traffic and get community strings to perform their own queries or reconfigure devices using SNMP SET. By monitoring SNMP traffic or performing a query directly, an attacker can quickly determine the sysObjectID for each device. The sysObjectID tells the hacker the kind of operating system (OS) the device has. Knowing which OS allows the attacker to determine a suitable target and pick suitable tools to use against that target.<br />
    &nbsp;</li>
<li><strong>Threat: Service Interruptions</strong>: Vulnerabilities with decoding and processing the SNMP request message (whether a trapor request) in various software products is exploited by the Badly Formed SNMP Trap Attack. The impact of this attack is to blind the management software (prevent it from receiving more traps by causing it to crash) or blind the agent (making it unable to be queried by causing it to crash). The ability of the management software to continue to manage is degraded at best or disabled at worst.
<p>    From within a DMZ, an attacker can reach the management software in the secure network when holes in the firewall are open to allow SNMP traffic or SNMP traps through directly. The attacker constructs special packets with ASN.1 decode errors. When the management console receives the message, it may exit abnormally. When critical daemons exit abnormally, the management software is degraded, causing service<br />
    interruptions.<br />
    &nbsp;</li>
<li><strong>Threat: Denial Service : </strong>The denial-of-service attack disables management software by sending to a host more SNMP traffic than the host can process. The backlog of traffic to process causes the SNMP agent or manager to dedicate an unbalanced amount of CPU to process the attack&rsquo;s traffic.
<p>    From within a DMZ, an attacker can flood SNMP traps to the management console when SNMP traps are permitted to flow through firewalls from the DMZ to the secure side. This flood of traps (whether they are bogus or legitimate) causes the management software to backlog. The software uses too much CPU while processing the backlog, causing the management software to stop functioning effectively.</li>
<li><strong>Threat: Unauthorized Privilege Access</strong><strong>:</strong> This threat is the most feared by system managers &ndash; a vulnerability that can provide the attacker elevated, privileged access on a host or network device. A common vulnerability is caused by buffer overflow, but is specific to the software processing the SNMP packet.
<p>    If an attacker determines SNMP v1/v2c SET community strings, the attacker can execute privileged commands. On networking devices, privileged commands may be used to reconfigure the device to behave undesirably. With advanced host agents, commands may be sent to the agent, which then execute in privileged state.</li>
</ol>
<p>Today, mitigating risks with the SNMP protocol involves the choice of one or more mitigating factors:</p>
<ul>
<li>using SNMPv3 (not v1 or v2c),</li>
<li>deploying an IPS appliance to protect against denial-of-service, or</li>
<li>a management protocol proxy firewall which verifies SNMP traffic to ensure its authentic and valid as well as mitigating SNMP-based attacks.</li>
<li>changing the community strings after set up SNMP</li>
<li>keeping the protocol up to date</li>
</ul>
<p><strong><em>All the Resources are in the Reference Page. </em></strong></p>
<ul class="related_post"></ul>]]></content:encoded>
			<wfw:commentRss>http://www.shibumidojo.org/index.php/2009/07/25/snmp-and-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Midnight Excursion</title>
		<link>http://www.shibumidojo.org/index.php/2009/04/26/midnight-excursion/</link>
		<comments>http://www.shibumidojo.org/index.php/2009/04/26/midnight-excursion/#comments</comments>
		<pubDate>Sun, 26 Apr 2009 09:52:47 +0000</pubDate>
		<dc:creator>CorpusCallosum</dc:creator>
				<category><![CDATA[Do]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[koan]]></category>
		<category><![CDATA[zen]]></category>
		<category><![CDATA[zen koans]]></category>

		<guid isPermaLink="false">http://www.shibumidojo.org/?p=94</guid>
		<description><![CDATA[Many Zen pupils were studing meditation under the Zen master Sengai. One of them used to arise at night, climb over the temple wall, and go to town on a pleasure jaunt. Sengai, inspecting the dormitory quarters, found this pupil missing one night and also discovered the high stool he had used to scale the [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">Many Zen pupils were studing meditation under the Zen master Sengai.  One of them used to arise at night, climb over the temple wall, and go to  town on a pleasure jaunt. Sengai, inspecting the dormitory quarters, found this pupil missing one  night and also discovered the high stool he had used to scale the well.  <span id="more-94"></span>Sengai removed the stool and stood there in its place. When the wanderer returned, not knowing that Sengai was the stool, he  put his feet on the master&#8217;s head and jumped down into the grounds.  Discovering what he had done, he was aghast.</p>
<p>The pupil never went out at night again.</p>
<ul class="related_post"><li>10/07/2009 -- <a href="http://www.shibumidojo.org/index.php/2009/07/10/no-water-no-moon/" title="No Water, No Moon">No Water, No Moon (0)</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://www.shibumidojo.org/index.php/2009/04/26/midnight-excursion/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Installing XAMMP on Ubuntu</title>
		<link>http://www.shibumidojo.org/index.php/2008/12/21/installing-xammp-on-ubuntu/</link>
		<comments>http://www.shibumidojo.org/index.php/2008/12/21/installing-xammp-on-ubuntu/#comments</comments>
		<pubDate>Sun, 21 Dec 2008 20:06:29 +0000</pubDate>
		<dc:creator>CorpusCallosum</dc:creator>
				<category><![CDATA[GNU Linux]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[ubuntu]]></category>
		<category><![CDATA[xammp]]></category>

		<guid isPermaLink="false">http://www.shibumidojo.org/?p=82</guid>
		<description><![CDATA[PHP+MySQL+Apache+phpmyadmin, these are requirements of developing php web applications. Using XAMMP is eisiest way to install all the requirements. This manual helps you to install xammp to you ubuntu and&#160; any linux distro with small changes. As you guess easliy, the first thing that you have to do is download the latest version of xammp [...]]]></description>
			<content:encoded><![CDATA[<p>PHP+MySQL+Apache+phpmyadmin, these are requirements of developing php web applications. Using <strong>XAMMP </strong>is eisiest way to install all the requirements. This manual helps you to install <em>xammp </em>to you ubuntu and&nbsp; any linux distro with small changes. As you guess easliy, the first thing that you have to do is download the latest version of <em>xammp</em> from <a href="http://www.apachefriends.org/en/xampp-linux.html">here</a>. <span id="more-82"></span></p>
<p>After the downloading, you should extract the files you downloaded to <strong>/opt </strong></p>
<p><quote>tar xvfz yourxammp.tar.gz -C /opt</quote></p>
<p>If everthing goes ok, you have to start the lammp at first with <em><strong>&quot;/opt/lammp/lammp start&quot;</strong></em></p>
<p>Then you can try if it works or not with your browser by trying to enter the <em><strong>http://localhost</strong></em></p>
<p>The parameters you can use for XAMMP below</p>
<p><strong>start, stop, restart, startapache, startssl, startmysql, startftp, security</strong></p>
<p>Ex. <em>/opt/lammp/</em>lammp restart</p>
<ul class="related_post"></ul>]]></content:encoded>
			<wfw:commentRss>http://www.shibumidojo.org/index.php/2008/12/21/installing-xammp-on-ubuntu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hello World</title>
		<link>http://www.shibumidojo.org/index.php/2008/08/31/hello-world/</link>
		<comments>http://www.shibumidojo.org/index.php/2008/08/31/hello-world/#comments</comments>
		<pubDate>Sun, 31 Aug 2008 23:09:31 +0000</pubDate>
		<dc:creator>CorpusCallosum</dc:creator>
				<category><![CDATA[Do]]></category>
		<category><![CDATA[GNU Linux]]></category>
		<category><![CDATA[Network]]></category>
		<category><![CDATA[Personal]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.shibumidojo.org/?p=3</guid>
		<description><![CDATA[% in Prolog hello :- display(&#8216;Hello World!&#8217;) , nl .]]></description>
			<content:encoded><![CDATA[<p>% in Prolog</p>
<p>hello :- display(&#8216;Hello World!&#8217;) , nl .</p>
<ul class="related_post"></ul>]]></content:encoded>
			<wfw:commentRss>http://www.shibumidojo.org/index.php/2008/08/31/hello-world/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

