Thursday, December 15, 2016

Regular Expression Basics - 1

In this post I wanna share some basic regular expression rules. But first I need to write down the metacharacters. Metacharacters are those characters which have a special meaning in regular expressions. i.e. "-" and "[" handled differently in regular expressions. Metacharcters are are as follows:
 
[  {  (  )  \  ^  $  .  |  ?  *  +

/1.5/g
Dot (.) matches anything, except for the line breaks.

1a5, 41e5y, 1x5o, 89xy1&5P55 are all the same

****

If you need to include dot (.) in your search than you have to put a backslash (\) before the dot (.)
/3\.9/g
According to the above expression it matches only the characters "3" and "9" in between they have a "."
 
93.96, a3.9t, 13.9s, x3.9t

----
 
If you want to search more characters which you don't want to type one-by-one than there is a solution which is called quantifiers.
For example if you want to search 10 "b"s than you have to type either /bbbbbbbbbb/g or /b{10}/g. If you're gonna search 10 "b"s than that's may be okay but if you're gonna search 100 "b"s it doesn't seem so straightforward.
If you want to search at least 6 "b"s than you have to put a comma (,) after the number which is between paranthesis. /b{6,}/g won't catch 5 "b"s it will only catch "b"s which are 6 or more.
If you want at least 7 "b"s but at most 10 "b"s then you have to type two numbers in between the paranthesis. i.e. /b{7,10}/g

----
 
/[gyb]/g
This regexp matches either "g", or "y" or "b". This regexp finds only "1" occurence of one of these letters.

----
 
/[gyb]+/g
If you put a "+" after the square bracket then it will find any occurences of "g" or "y" or "b".
 
ggyybb, gyyyybbb, bbb, yy, bgyyy, yyggaaa, lkbgyata, 12hytbyggg90g0b

----
 
/[a-z]+/g
If you want to catch all the letters of the English alphabet in the regexp than you can define a range. The regular expression above catches every letter of the English alphabet. But it doesn't catch any numbers or symbols regardless of their occurences.
 
abjuyr, amnxc5, 77yhbbd76dg76, xbn8dmmdn, %!98hnsb!!mmcasd98lk=

----
 
/[a-z0-9]+/g
The expression above detects all the letters of the English alphabet and all the letters regardless of their occurences.
11009hsndh%88uj, 56+67=123=xyz, $var=99

----
 
/[a-zA-Z0-9_]+/g equals to /\w+/g
There are some shortcuts of the whole English alphabet and whole numbers. i.e. the regular expressions /[a-z0-9_]+/g and /\w+/g are the same. Both find the letters (small or capital) and numbers including the underscore (_) regardless of their occurences.

----
 
/[0-9]+/g equals to /\d+/g
If you want to match only numbers then you have to use the one of the above regular expressions.

----

/^[m-z]+/g
You can negate the classes with the "^" character. With the above regular expression you will catch the characters other than [t-z]. namely the regular expressin will match the small letters a, b, c, d, e, f, g, h, i, j, k, l and all the capital letters from A to Z and also the numbers 0, 1, 2, 3, 4, 5, 6, 7, 8, 9 and also symbols like %, & etc.

whatta99yathink88? iaint77do21ANYTHING%% HappyNewYear-In-2017!!!

----

/^\w+/g = /\W+/g
The above regualar expression above matches anything that's not the letter or number or underscore (_)

Mr.&MrsBrown_werein1960!s

----

/^\d+/g = /\D+/g

The above regular expression above matches anything that is not a number.

14mfly1ngt0C4n4ry15l4nd 4w0rldw1th0utr3g3xp5??!!
 

Thursday, December 8, 2016

What Does "Malware" Mean?

A very short but valuable description of malware:
 
The word "mal" has its origin in Latin and means "bad" in English. "Ware", on the other hand, carries the meaning of "products". Hence, when we put these two together, we get the sense of having bad products or goods made with a bad intent.
Learning Network Forensics - Samir Datt

Tuesday, December 6, 2016

Star Wars over Telnet


 
Anybody wanna watch Star Wars over telnet? If yes try this: "telnet towel.blinkenlights.nl"
 
I mean, open a command prompt in your computer, type "telnet towel.blinkenlights.nl", hit ENTER and just watch. Well. Have fun! =))

Monday, October 3, 2016

SIEM SIEM Dedikleri...

SIEM (Security Information and Event Management) kavramını esprili ve anlaşılır bir dille anlatan güzel bir yazıyı paylaşmak istiyorum buradan.

Yazı gerçekten güzel kaleme alınmış. En sondaki şiir ise cabası. Köroğlu, sistem yöneticisi olsaydı herhalde o da böyle bir şeyler yazardı. =))

https://www.linkedin.com/pulse/1-siem-nedir-2-neden-al%C4%B1n%C4%B1r-episode-1-evren-pazoglu

Wednesday, September 7, 2016

Suricata "Content" Parametresi

Suricata saldırı tespit/engelleme sistemi -beklendiği üzere- şifrelenmemiş paketlerin "veri" (payload) kısmına da bakarak saldırı örüntülerini (pattern) tespit edebilmektedir.
 
Bu tespitleri yapabilmek için Suricata imzalarında bir "content" alanı bulunmaktadır. Bu yazımızda Suricata imzalarındaki "content" alanıyla ilgili bilgi vermeye çalışacağız.
 
Öncelikle içeriğinde "content" geçen rastgele bir örnek imza aşağıda verilmiştir:
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"ET USER_AGENTS Lowercase User-Agent header purporting to be MSIE"; flow:established,to_server; content:"user-agent|3a 20|Mozilla/4.0|20|(compatible|3b 20|MSIE|20|"; http_header; content:!"|0d 0a|VIA|3a 20|"; http_header; classtype:trojan-activity; sid:2012607; rev:4;)

Örnekten de görülebileceği gibi bir Suricata imzasının içerisinde birden fazla "content" alanı da olabilmektedir.
 
"content" parametresiyle, gelen paketin veri (payload) kısmında aranacak harf-rakam kombinasyonunun tırnak içerisine yazılması gerekiyor. Örneğin Suricata imzasında content:"SALDIRIYORUM ULEYYNNN!!" yazmış olduğunuz takdirde Suricata, gelen paketlerin veri kısımlarında "SALDIRIYORUM ULEYYNNN!!" içeriği olan paketleri tespit edecektir.
 
alert tcp $HOME_NET any -> $EXTERNAL_NET any (msg:"YABAN SALDIRISI!!!"; flow:established,to_server; content:"SALDIRIYORUM ULEYYNNN!!"; classtype:yaban-activity; sid:2222220; rev:3;)
 
"content" parametresinin içerisine harflerin, rakamların ya da özel karakterlerin hexadecimal karşılıkları da yazılabilmektedir.

Suricata imzasının içerisine yazacağımız; content: "|53 41 4c 44 49 52 49 59 4f 52 55 4d 20 55 4c 45 59 59 4e 4e 4e 21 21|" ile content:"SALDIRIYORUM ULEYYNNN!!" aynı anlama gelmektedir. Harflere karşılık gelen hexadecimal değerler aşağıda verilmiştir.
S = 53, A =41, L = 4c, D = 44, I = 49, R = 52,I = 49, Y = 59, O = 4f, R = 52, U = 55, M = 4d, = 20, U = 55, L = 4c, E = 45, Y = 59, Y = 59, N = 4e, N = 4e, N = 4e, ! = 21, ! = 21
Normal karakterler iki adet "<örnek>" (tırnak) arasına yazılırken, hexadecimal karakterler iki tane |<örnek>| (pipe) arasına yazılmaktadır.

Bazı karakterler imzanın okunmasında karışıklığa yol açtıklarından dolayı bu karakterleri Suricata imzasının içerisine iki tırnak arasına yazmak mümkün olmamaktadır. Bu karakterleri imzanın içerisine mutlaka hexadecimal olarak yazmak gerekmektedir. Bu karakterler ve hexadecimal karşılıkları aşağıda verilmiştir:
" = |22|
; = |3B|
: = |3A|
| = |7C|
Buna bir örnek vermek gerekirse; Suricata imzasının içerisine content:"http://" yazılamamaktadır. Bunun yerine content:"http|3A|//" yazılabilmektedir. 
"content" parametresinin içeriği büyük-küçük harf duyarlıdır. Yani content:"SALDIRIYORUM ULEYYNNN!!" ile content:"saldiriyorum uleyynnn!!" aynı anlama gelmemektedir. Büyük-küçük harf duyarlılığımı iptal etmek için imzanın içerisinde "nocase" parametresinin kullanılması gerekmektedir.
 
Örneğin; content:"SALDIRIYORUM ULEYYNNN!!"; nocase; ile content:"saldiriyorum uleyynnn!!"; nocase; aynı anlama gelmektedir.
Peki bir Suricata imzası içinde iki adet "content" parametresi olması durumunda Suricata nasıl davranmaktadır? Öncelikle bu, anlaması biraz zor bir algoritmaya dayanmaktadır. Bu algoritmanın ayrıntılarına girmeyeceğiz. Genel olarak; "content" parametresi içerisindeki "daha uzun" (longer) ve "en çok değişen" (varied) harf/rakam kombinasyonları tercih edilmektedir.
 
Örneğin: Suricata imzası içerisinde content:"SALDIRIYORUM ULEYYNNN!!" ve content:"YAKALA oni!" parametrelerinin bulunduğunu kabul edelim. Birinci "content"in içerisinde 23 karakter bulunmakta, ikinci "content"in içerisinde de 11 karakter bulunmaktadır. Bu durumda Suricata content:"SALDIRIYORUM ULEYYNNN!!" parametresine öncelik verecektir.
 
"En çok değişen" kavramına da bir örnek vermeye çalışalım: content:"SALDIRIYORUM ULEYYNNN!!" ile content:"S|41|LD|49|R|49|YORUM ULEYY|4E||4E||4E|!!" arasında bir karar verilmek istenmesi durumunda Suricata content:"S|41|LD|49|R|49|YORUM ULEYY|4E||4E||4E|!!" parametresini tercih edecektir. Çünkü ikinci "content"in bizim tabirimizle "değişen parçaları" daha fazladır. (|41|, |49| vb...)

Suricata imzalarında "daha az değişen" veya "daha kısa" olan değişkenlere öncelik vermek istediğimiz takdirde de "fast_pattern" adlı parametreyi kullanmamız gerekmektedir. Örneğin, Suricata'ya daha uzun ve değişeni daha çok olan content:"SALD|49|R|49|YORUM ULEYY|4E||4E||4E|!!" yerine daha kısa ve değişeni olmayan content:"az bi dakka!" parametresini tercih ettirmek istiyorsak bunların imzanın içerisine aşadaki gibi yazılması gerekmektedir:
content:"SALD|49|R|49|YORUM ULEYY|4E||4E||4E|!!"; content:"az bi dakka!"; fast_pattern;
 
(İki adet "en çok değişen" ve iki adet "daha uzun" parametrelerine sahip olan "content" için bkz. https://redmine.openinfosecfoundation.org/projects/suricata/wiki/Suricata_Fast_Pattern_Determination_Explained)
 
Suricata imzasındaki "content" parametresi http trafiği için de özelleştirilmiştir. "content" parametresinin http trafiğinde nasıl kullanıldığını da başka bir yazıya bırakalım.