View by:

USB Device Tracking and PFsense

Wednesday, February 4th, 2009 – running time 39:59
In this episode Peter Giannoulis joins us from TheAcademyPro.com. Chris Gerling is back in studio talking about USB Device Tracking. And Matt is building the new HakHouse firewall/router with PFsense. Plus a ton of haksnax to get your grub on.

USB Device Tracking

If you've ever used a USB storage device and wondered how stealthy you can be with them, you're in for a scare. Windows XP logs pretty much everything you'd want to know about that USB key in the registry each time it's plugged in and written to.

When you plug in your USB drive, the Plug and Play manager gets notified and queries the device descriptor in the firmware for information about the device. This helps it locate a driver, which is referenced in the %SystemRoot%/inf folder by various .inf files. Once the device is identified and a driver selected, the information is dropped into HKEY_LOCAL_MACHINESystemCurrentControlSetEnumUSBSTOR with a format similar to Disk&Ven_###&Prod_###&Rev_### which will identify the device ID, manufacturer and more. An important number you will find here is the ParentID prefix, which I did not actually say during the segment but this is something that will appear in virtually every registry entry regarding the device.

Microsoft uses serial numbers on the devices to distinguish between devices with the same manufacturer or model. In the case that the serial number is not unique (or even not present), the PnP manager will create a unique instance ID for the device.

All of the numbers you find related to each device should be logged if you're doing any sort of investigation or trying to track a device across computers.

If you're trying to determine whether data was perhaps pilfered from your machine/network, you will want to look at HKEY_LOCAL_MACHINESystemCurrentControlSetControlDeviceClasses, where you will find the ParentID prefix and will be able to correlate to the device. You should also see the manufacturer name here. We are looking for the Last Write time which will help in determining whether data was pilfered by giving you a timeframe as to when someone last copied data to the device. In order to do this, you're going to right click on the entry that has the ParentID prefix and manufacturer name for the device you want, and then click Export. Change the file extension to .txt and name it anything you want, remembering where you save the file. Upon opening this file up, you will find the last write time.

There are many applications for this data, and you'll probably never be in the registry doing it quite this way, as there are many tools, both commercial and free that will simplify all of this. This data is also used in tools/services which help track your devices, such as iHound (ihoundsoftware.com), which helps you track devices if they're stolen.

If you have any questions feel free to contact me here and visit my website. Many thanks to Harlan Carvey, author of the 2007 book Windows Forensic Analysis (I think I might've errantly said 2005, sorry) for without this book I wouldn't have known as much as I do about the windows registry.

--Chris Gerling Jr.

PFsense

While our smoothwall is and has been working well for us for the past two years, I recently had the need for something a little more robust.

I came across a fork of the monowall project, pfSense is a free, open source customized distribution of FreeBSD tailored for use as a firewall and router. In addition to being a powerful, flexible firewalling and routing platform, it includes a long list of related features and a package system allowing further expandability without adding bloat and potential security vulnerabilities to the base distribution.

Here's a short summary of some of the eye catching features.

  • Filtering by source and destination IP, IP protocol, source and destination port for TCP and UDP traffic
  • Able to limit simultaneous connections on a per-rule basis
  • pfSense utilizes p0f, an advanced passive OS/network fingerprinting utility to allow you to filter by the Operating System initiating the connection. Want to allow FreeBSD and Linux machines to the Internet, but block Windows machines? pfSense can do so (amongst many other possibilities) by passively detecting the Operating System in use.
  • Option to log or not log traffic matching each rule.
  • Highly flexible policy routing possible by selecting gateway on a per-rule basis (for load balancing, failover, multiple WAN, etc.)
  • Aliases allow grouping and naming of IPs, networks and ports. This helps keep your firewall ruleset clean and easy to understand, especially in environments with multiple public IPs and numerous servers.
  • Transparent layer 2 firewalling capable - can bridge interfaces and filter traffic between them, even allowing for an IP-less firewall (though you probably want an IP for management purposes).
  • Packet normalization - Description from the pf scrub documentation - "Scrubbing" is the normalization of packets so there are no ambiguities in interpretation by the ultimate destination of the packet. The scrub directive also reassembles fragmented packets, protecting some operating systems from some forms of attack, and drops TCP packets that have invalid flag combinations.î
  • Enabled in pfSense by default
  • Can disable if necessary. This option causes problems for some NFS implementations, but is safe and should be left enabled on most installations.
  • Disable filter - you can turn off the firewall filter entirely if you wish to turn pfSense into a pure router.
  • pfSense offers three options for VPN connectivity, IPsec, OpenVPN, and PPTP.

Thereís a ton of other great features that you can read up on at http://is.gd/iauk

The LiveCD ISO is available from http://www.pfsense.org/mirror.php?section=downloads and for VMware folks, a prebuilt VM is available at http://files.pfsense.org/vmware/pfSense-1.2.2-VM.zip

--Matt Lestock

LAN Party

This month, we are playing Left4Dead and Zombie Panic! Join us for our LAN Party on Saturday, February 28th at L4D.hak5.org or ZP.hak5.org for a good ol' zombie apocalypse.

Trivia

Last week's trivia was: "In PHP, which is faster and why? echo"Hello World"; or print("Hello World");?" Zoltan answered right with: "Echo is faster because it doesn't set a return value and 'print' is a more complex function." Zoltan wins a copy of Pronobozo's CD 'Zero=One=Everything'. You can check out more of Pronobozo's music at his website.

If you want to win this week's giveaway, enter the letters you see popping up during the episode into our trivia page and answer the trivia question in the first 24 hours from when this episode releases. We will choose a random winner out of the correct answers!

iTunes

Remember to subscribe to our new HD feed on iTunes at Hak5.org.

Feedback

Have a segment suggestion, constructive feedback, or a snack idea for Kerby? Email your ideas to Feedback@hak5.org. Thank you!

Stickers

Don't forget! We've got brand new sticker packs as thanks for your donations at Hak5.org/stickers. Without your help, we wouldn't be HD right now.

Shmoocon

We will be at Shmoocon this weekend, February 6-8 in Washington DC. If you are in the area, join us for the annual podcaster's meetup. Meet our cast and crew as well as lots of other great podcasters from PaulDotCom, Securabit, Sploitcast, Cyber Speak, Security Justice, and more! Get the info at Podcaster's Meetup.com.

Survey

We're conducting a survey to get some additional information about our viewer. We would love your feedback. If you have a few minutes to spare, please do us a favor and take the survey at the survey page.

For those of you who complete the survey, you will be treated to a sneak peek at a new show that Revision3 has been working on and get a back stage look at the pre-production of a Hak5 episode.

Trust your Technolust!

Highlights
open source ( 3:46, 5:51, 3:46, 5:51 ) tax service ( 31:10, 31:10 ) Hak5 ( 0:05, 0:24, 7:42, 8:19, 16:39, 22:44, 24:13, 25:12, 25:44, 29:10, 31:59, 32:15, 0:05, 0:24, 7:42, 8:19, 16:39, 22:44, 24:13, 25:12, 25:44, 29:10, 31:59, 32:15 ) us open ( 29:45, 29:45 ) open source ( 3:46, 5:51, 3:46, 5:51 ) tax service ( 31:10, 31:10 ) Hak5 ( 0:05, 0:24, 7:42, 8:19, 16:39, 22:44, 24:13, 25:12, 25:44, 29:10, 31:59, 32:15, 0:05, 0:24, 7:42, 8:19, 16:39, 22:44, 24:13, 25:12, 25:44, 29:10, 31:59, 32:15 ) us open ( 29:45, 29:45 )

Automatically Generated Transcript(may not be 100% accurate) ( more )

" Wow. This episode of Hak5 is brought to you by GoDaddy. Netflix. Square space. And good news."

" Hello and Hak5 does your weekly does technology and Darren Kitchen I'm -- less stuck -- snouts. Now that -- I thought I think we're just given up on Apple. You guys don't -- bacterial anymore for much in the what you YouTube and actually the first three episodes which anymore it's in now and you watch aside from the fact that standard and looks like cable drag your truck. Com. And works well it was sham march this -- and out snobs. So it -- it can be its its you know since enough. -- hey anyway we have an Austin got in studio with us it is not NC. From the -- and studio insinuate that he's here. Present television on here I'm not gonna get into this with you right now anyway it's Peter Lewis from the academy pro dot com. Peter how argument."

" I'm great ideas. Rogers actions -- yet there. Europe thought this is is there better and it. -- home early in the media -- some I don't know like stuff but -- pretty much."

" Yeah I I can never space petticoat some like some patsy particle that up I learned that -- because in the -- and they. It's all they ever said they did and that's and webcam stuff. Woo hoo yeah. -- item on this so. So he had Peter -- you are the founder the creator of the the academy pro dot com right."

" How to build a I I've founder yes slot for help on the creation --"

" So would it out -- for those that are familiar with it would be proper for -- say it's kind of like the YouTube of security videos."

" I -- kind of although we don't let people just upload stuff applies that's pretty much the only difference."

" So it's like YouTube but without getting kicked in the nuts. Well it's YouTube with moderation. This come about."

" But a couple of years ago I was a -- consultant for about a little over a decade. And a couple years ago -- aren't a lot of ways you know better way of -- of a federal is actually give out information to people for free. To better configure their security technologies yet there are walls like yeah assistance. You know idea whatever Indians. Yeah that's how most frequent -- and we kind of inserted with. Crappy little Q and what have plates with a bunch of plug in Britain launched a website with 5060 -- on it and it's grown from their and that 300."

" So by taking you are you still -- I thought it looked a little word press it to be word printed area being in a security he would do you really probably don't want to run to follow when -- That's the target audiences -- this just like you dissing. But you look at it now now it's -- window and sort -- hold on a second hold on let me clarify this when you or web post. And you see somebody that does not update their -- well that's different and completely richer box should say the same thing about. We're press because I had word press one on one blog that. Anyway so let's hope it -- what because we're gonna subject see guys cover."

" hear anything from commercial products like you know checkpoint firewall source players she's an open source technology penetration testing you know with -- what spurred NASA as an all in all agree tools there. A little bit of everything."

" And you guys release like daily video isn't Tor is a step how to keep up with that."

" Basically what we're doing this weekend and is what we typically do every six to seven weeks is five or six guys sit together all weekend and you know basically created over hundred videos or slash lissouba. Two for months and that we have avoided them later on just put them ideally that's pretty budget and."

" How can you imagine density. How -- a whole lot how long -- Summer three for a -- summer -- Opens. Different episode and and that's is that he's got the Mubix. Waiting at Pearson. Yeah actually. OK so he's on the tarmac that get. You're in good hands in the -- is coming down and Italians now well yeah. So what it is like a hundred other places to go and get kind of late this this would you consider security training."

" Artwork track who or what we care what we try to do it because -- it. A lot of times vendors and accurately our Q are -- urban art does warcraft ever but you don't want Saddam out anymore. I'm not very technical their sales marketing information. What we wanted to -- was basically take. You know. What you want in specific video for example you I don't know how to configure you don't network address translation on a checkpoint firewall make -- minute -- that. You know if you want to know how to install checkpoint firewall on. And different platforms only that it takes -- units that fought so you kind of cold and unspecific -- yeah."

" So what -- considered like a special sauce that makes the academy unique. It. Is special uncle had a -- go to YouTube and just Google for whatever security thing is and there's fourteen year old that's gonna teach at what crack."

" Well you know what the problem is is I'm Paula to those sticky web crappy video straight girl might solve the problem is not enough. Vendor focused for example. You know we all likes to work as it is great you know open source idea -- and so on but not everybody can run under their environment because they're not commercial tools. You know it it's it's unfortunate -- that's just as always right so. Opinions were bringing commercial tools -- pretty much everybody for. I'm from the from the Chinese perspective."

" Very cool. Well we will be keeping an eye on it that its new website is the academy product coming also have a new site the academy home."

" Yeah the academy home dot com we launched -- couple weeks ago it's for all the pretty much that site came out of I don't want my relatives call me an offer support. You guys all know what I'm talking about yeah that's right pretty much -- go over there -- you have -- do you death so. And hopefully that wondrous little a little bigger as well so it's no good for the first."

" Awesome well Peter thanks so much for joining us this evening and we're look which next time -- in Toronto is you know you can -- records -- We gotta drive uses. Records in the -- That mostly men are. Excellent game and take care and good welcome that he had this weekend with -- and everybody."

" We pretty much -- so this stuff to the block and -- iteration and now see what's going on this week. And party. Actually this week when and I happen game but this client. -- Not -- panic. And -- prevent. Now I'm so credit. It's on February 20 that's Saturday and you can play -- in two of our servers you can play it Californians -- Hak5 dollars which is the last for that one. Or ZP dot hack I'd outward for the -- can't quite. We know that only sports that are eight players can actually get into left about it when times so -- And I have sat at -- scientific Netflix. It Netflix rent over 90000 titles online including possibly ray titles with free shipping both ways to your home. They got over forty shipping -- almost all deliveries happening just one this Wednesday. Netflix plans -- a 499. And as a -- you can get no risk two week free trial membership. Check it out and netflix.com slash Hak5 and he's so -- get the Debian communities. Except I think Chris is -- and this time. Some USB device training and."

" It's your back finally. Didn't bother them at the USB device tracking does that you're gonna lake stick a little device tracking inside my USB as a stealing your data inherently."

" No not really authority about it for -- that there's no devices that -- devices but it leaves a fingerprint years system. It leaves a fingerprint yeah it's actually figure it leaves it. Hey this is what I am this when this -- with the primaries where and so you got from it. And yes. Seeing how the registry all that I do I just -- again there's a lot of news veterans treated it is there it is -- Reagan's. Victory. Duty and so. What we do what we've mainly do is I got the stuff from wrote a book that he wrote. It. Was really. The stuff. So one of the place the goes to to start. It you know where is where oysters you know well you want to note that serial number. In the and you use this through -- to."

" So what do all of these different USB devices have different serum is even if they're like from the same model and most most of USB keys and he needs some time ago and it they don't. The appointment will sign a unique. Unique -- around town so we're here we're in the local machine entry go to each machine as we scroll down under software and will have this in the show all the different key task that's. Its its old maddening when it's going. I start with current version of underneath there -- witnessed -- version. And this is this'll tell you kind of where year's actual device -- that is. Which has all of the different. Driver IDs for all the different here you XP you know whatever -- missions -- drivers. Texas is a good place start going there and start writing down numbers in. You know and looking for those numbers here one good one of the better places to look you know. To actually find out what was plug in is under USB store -- new. I'll have -- but why would I actually spoke here. It's. Underneath here we can see there's a patriot device and then AUSB flash memory board here. Which the patriot want to -- one in the one. Yeah that's the one that I plugged in the end -- that class who that you -- me in the the drivers rather embarrassing number yet this is what it pulls from that kinda. So as a case of windows this is what you're gonna use for driver because it's used the device and -- Has a hard -- neat future memory. Apparently prefix in if you. Go back over here. Suppose back over this is the actual serial laboratory use to track everything through the registry and so that's out right now this."

" I hate it right down and is the other one we regret this down to. And if we go now. And what's we have these. We can go to another part. What's we have he's written down interest. Search you can search habits so it's a little easier to do it this way. We going to system current control set control and that device classes. Now this has every single you know kind of plug and play everything that is ever gonna plug in your computer. You know. So we just trying to -- I I actually went just open the ball up until iPhone which one's head there's about six or seven of them have different information about -- keys. These these two right here are just what happened to have the serial numbers in the."

" So. Saint somebody gets into my computers I see this random USB device is listed in here is their way that I can see if mainly. Tipped me off my computer since my days we're all about -- security."

" When Soviet very big race it would be there. In the -- in the registry. There is a way to actually determine when the last right -- want -- advice now here's our patriot device are here to open this up we put it. And we expose over. It's either this -- love it. Yeah we know that this injury here have to do with that hatred lies so by right clicking on this and I exported right as a textbook. Which Larry did. Okay we have an open right here. So we look at this exports data in -- right in here you can see last -- and it's and it twice but it has a lot of its extra data. 7:32 PM earlier today happens when it actually on this thing did -- into it."

" So -- says you."

" Eight and actually used this to cook."

" Robbery when you go to your recent documents folder under the documents and settings you can see drivers at a map to files that were recently opened. And you can you can go back in here and under -- to devices. Here I'll have this thing bonds due -- you can say okay. You can go in and figure out what drive letter was used within recent -- little bit more advanced but that's one of the uses frantically. That you can do you see okay it was drive letter half. The last right time with 7:33 PM and we know that -- semantics for -- you know some top secret missile. Was was taken -- So most likely it was that USB drive with that serial number. That if you don't do forensics there's a lot of other things that uses data for instance if you've ever heard of it's called I. It's yeah phoning home kind of software yeah L and I and I still right yeah iPod iPhone USB drives. And it actually pulls information of the same places and I'll actually a lot more places too because it identifies you know your actual computers via you know. Installation you know yet and it takes all this data and uses that so that it can identify the device -- from hey. This was plugged in from -- you know IP address in you know wherever Russia or something you know so and I you know it. You know somebody Russia has your."

" That's as well -- definitely gonna check this out on my own computer action -- Isaiah that so we can't find more information like this problem. I actually learned from from this book right here are -- reads windows forensic analysis. Per episode. Just. My boss -- book. And very great album actually get out so -- it warns. -- council there was also paper but who. Written by students -- the you'd going university. And they they used a lot of the same please use this book is -- reference. They were they put in very easily digestible. Form factors need I it was able -- intimate acts yet. So that it -- in you know it's."

" much credit. And I think we're finished and it's you can now for -- yet."

" That's right last week's trivia question was in PHP which is faster and why act over the world or. Hello world. Does correctly answered by -- old hand who wrote that -- is faster because it doesn't return value. We're gonna -- hooked him up with trial Lewis's awesome electronic albums zero equals one equals everything. You've heard the music throughout the show and bumpers and whatnot that statement. Check it out up front of those dot com. Now for this week's trivia he can go had just. Finally includes if you open up here in there and everywhere and you put together and that is a password the go ahead and her over I five dot org slash trivia. Good enter into -- your chance to win this week's trivia next week. With the weeks in the period that I've. -- a -- I've got to think are amazing sponsor for the -- tribute thing and that would be go -- if you'd like to make an impact on line godaddy.com has what you need."

" Dot com -- is low the dollar financial world class hosting patsy website builders and much --"

" Plus as a -- Hak5 you get five dollars off in order thirty dollars or more when you check out with code. Pack two. So anyway so restrictions apply to the fact need to be -- the Internet had. Eddie dot com thank -- government now and he was -- boom."

" Back in I believe was it season to -- Bronx is isn't that we did. Smooth wall. And -- smooth -- has been going flawlessly for the last two years. I came across a basically. Smooth wall on crack -- like it's called PF sense and basically it's built on free BS the and it's a four. Of the model wall project now some -- he's not a wall something you don't. You find out more about that I believe that model -- dot org. In the PF sense dot com to actually download a -- to live CD installer. Or an embedded installer will we're gonna do is I'm gonna show you guys how easy it is to set up PF sense. That's going to be this episode wanted to do is only been. Go on and show you some of the more advanced stuff like open BP and end you know VPNs like the sites so on and so forth. In future episodes so let's died in. Or going to do is we're gonna start our computer with the live CD that we burned. Yes I'm aware that any -- all the VMware tools and what we're gonna do is. It's gonna start up and we have the option to install. Or just run PF sense. From the live CD installation now the nice thing about that is before you wouldn't make any changes to an existing installation of say are smooth wall. You can actually verified that set -- is gonna work -- your hardware that it's going to work with you know your network infrastructure. Blah blah blah blah blah blah. So what it's doing now it is actually load a live CD it's a start up here and there's there's a two step process first we're gonna set up in the the shell. And then we're actually going to law again to yet sense from -- another computer to set up the wizard. Asa right now to -- that we want to set -- lance we have absolutely no purpose for being lands here in our infrastructure so we're gonna go ahead and say now. Now what we're gonna do is because. -- And in a DMI actually have to disconnect. Our network adapters. Because what it's gonna do is it's actually going to auto detect. For those of you who don't know -- or network interface names. I do but for the sake of showing you let's go ahead and do that now the -- go ahead and select a and it's gonna ask this Apple connecting Lan interface to -- go ahead were to connect the land interface which on ours is a virtual machine. Interface so we're gonna come on back over here to PF sense. It editor and EM zero is changed to link state -- so that's our Lan interface to come. Back and say hey now -- assets for the Lan interface so ring connect the way and it affects. Come back in -- PF sense. And hit enter and EM one link state changed to up. So now you have the option to set an orange interface. We don't need an orange interface Serena and and -- and it's gonna ask you to confirm your interface election -- zero being the land and EM one being York -- Yes we would like to proceed. So now it's actually. Done with its initial configuration in its gonna actually start -- access to the point where we can actually log into the web interface. Come on come up their ago so now what we're gonna deal is -- to come over and in another machine. Reopen Internet. Now for the sake of testing and show you guys I've already set up static IP the address for the local interface is defaulted to 1921681. Network so I've already got. I think. If I'd come down here. Regular address now the so right here written go to one point 216 it got one L one. And -- enter in the password Edmund and heard the username Edmund and it password is PS cents I'd fall. So here it's gonna launch the setup wizard for PF sense. Yet your -- guide me through the process you center hosting your domain your primary DNS server I myself when I'm testing things. Like -- DNS server external of my local DNS server just so that I know I had. Con activity. -- better for dot to dot to dot to. Dairy easy to remember fortitude to. If you ever need paying any thing. That's what -- just use because it's always up. So we're in a select our time zone and are. Server for time. -- a static here because were actually plugged into our existing. Internal network three to set a static address and it's going to be. Ten that. Ten dot zero dot 134. Now you guys would probably use you or cable modems. Static or DH CP information. Our subnet is a 24 and our gateways and that's and I don't know one. Come down here now these -- settings down here block bogey on networks and blocked RFC 1918. Networks. It's key if you're going to use. PF sense in a robber. Behind it Robert configuration because you need unchecked the 1918. Because otherwise it Walt brow correctly. It's like next and we're good with our Lan IP being 1921681. We're gonna enter a password of Hak5 because we're very insecure like that. And we're gonna reload the interface and -- With a new password a -- five. Come over here. And we are going to. Verify. Via the PF cents. Interface to see if we actually have connectivity or not so let's go ahead and see that -- house is option number seven. And -- back com. And when you look at that we've actually got. Connectivity within. Those five minutes. It's very simple to set up. What would go into later are some of the more advanced options of IPSec VP -- open BP yen a lot of the services virtual like you support things of that nature. It's a very very powerful. Platform for running -- routers here you know using a Linksys now you've got -- on machine. Laying around your house I highly suggest you guys check out yes that's that's great graphic with our -- tools are -- graphs. And just some really nice applications. And platforms that really are available to you Linksys users unless you're running past the open WRT. But that's the segment -- and check it out PF cents dot com and right now we are going to. And show finally. And he guy's been a long time but in and show -- Daryn back like only Hak5 can't. Mystical magical."

" dude. It -- do well thank you. Slated to answer. You know as we speak when -- news -- can't hold wished action. -- noticed that it's meant. I -- and I know about that but right hand. Yours. Yet really hold that thought -- right. We have a whole -- fun stuff that we need to entertain you it in and enlighten you about. But first I gonna get mad props and things one of our sponsors so let me tell you guys about square space I know told in the past square space is an excellent. Content management system has a very unique front and back -- system -- web host their answered like eight dollars. Round that at the -- of the W that's where it's based on -- eyes. Just go there and if we can check with coupon -- Hak5 10% off the life of your order so we're looking up let me show you one of the cool things you can do with squares where we -- that you can create blogs blogs a lot of the big stuff the -- concrete forms and to. You know really rich website. Blow when the neat things is when you want to change the look everything -- have you ever tried to install teams in different and we talk and Drupal earlier this is real simple right so we're in. Just the regular man this place you went there right but the blogging here get special cool bar at the top. A -- despite -- here. And I'm now in this style switching area and we've got this custom Hak5 theme for Lan party that looks awesome right. And it's all done with like you know just dragged itself into -- yes that's but they've also got a hold on a built in themes and you can just cycle through them. They clicking any of these and they've got a ton of them we can actually switch templates here and and it from one. You are -- real either not very good I got -- okay they have but be -- they're late that one or the news room. Looks pretty and you can actually lives see you know as your pick an amount C which like. It -- port and the cool thing is once you've created one you can clone it you can dig deep you can do this yes that's that showed you how easy it is to create forms and and file drops and all sorts of stuff with it it's just it's pretty -- it's."

" Probably one of the most powerful. Platforms that I've seen in ten years of hosting and both sides now playing with trial that this is for stuff that we covering now looking at Dreamweaver. And I mean little that on a code got myself but expert for a lot of people for 95%. People line and that just want a website. And whatever to show off their pick me do things -- Bob square -- base is the perfect I'm actually."

" Using it for -- I've been playing around with the you know London web redesign for you know the system and job yes yeah. Well -- I've just because first -- it would just be easier 'cause I'm. --"

" So its. Its like. Equal. To get them out there now. That's where -- com he's good on its importance on of that. Department code. I recently did little -- on the show. -- There which would -- that day and that is so. As I'm sure the rest of the Ayers and I thank you I didn't realize that -- was built and that's cool. So but I still believe that the fundamentals of notes chillingly. In reasonably PC and something like. The OC with HTTP it's back and split mechanism. I hope you can find something from that. If in like two weeks from now you're elected currently two -- from where all the on hack IV you know it's like. -- put the old in the last. -- for. So you have to work. -- It works. Workers though. It says. -- and you know if you are. And that's the odor and when LA. You know with the -- out there or code pink Jersey nets. From all right that's cool that's cool we've got the okay. If you felt. Here right Q let's get carpet -- all -- as we will be there you're watching this right now on. On Wednesday -- because awesome and you subscribe to the RSS feeds that you get automatically look to all of it -- At work on the home page right here guitars that speed. Hak5 on. Each Ph.D. New OW one that you're still watch -- Age. Else does on these actually never mind that gravity is so you know if you're downloading files -- Rates from the fast -- off -- Aussies directly from our. So -- on we will be there on the 68. You're doing podcast is -- up so head over to podcast dot com to find out how you can meet up with us open District of Columbia as well securabit. It's split Catholic speaks you're just argue. Episodes or something. Line. Instantly will get a guy yet so on there are so. One mention that you guys have heard of like Ted conference. Opt in and like -- talking -- you two in the about these totally stoked the built on write it it can. Yeah it's it's a grass roots saying just like people. Now why is it. Not for real. A connection that's it isn't always. I'm a -- their bring in great minds together. And and it's kind of like an -- conference thing's going to be big discussion. Bunched up presented and check out Revision 3 is broadcasting high. Without the gravity. Right so. February 7 and eight same time we're at -- check it out at revision3.com. Slash B."

" I know. Mad exactly want to let you guys know that we have the brand new -- march wag. Pack backpacks Hak -- yeah. Fast tax service packs one through three basically we've got -- you know different packages set aside for you guys that you order new designs -- stickers. The -- bus tickets which we've had a blast getting out there grid could actually get one out an actual bus driver going to give one to you as it is for you -- to -- yes definitely. So head on over -- five dot org slash stickers and get your new technolust year -- on."

" Yeah and and we appreciate all of your donations because it helps us figure out how to make on you work on. That's another story anyway yeah we much appreciated. So what else is going -- and we've got to we've got to mention that about the survey yes yeah. So as you guys know. We love you we know you are because you're up on -- house where you're up in the Hak5 buyers a year on the forums are we talking to us all the time writes -- and we're. Look I would love. Two and but the thing is like the people the powers that be and whatnot. Don't really know you guys what we do so if you could go over to revision3.com. Plus Hak5 survey and participate in this survey. Give us a little idea about the war and whatnot. It's gonna help us make this show better view and and and help us keep going and whatnot so we're conducting the survey. And would love your feedback to go and spend a few minutes at there and check it out rate if you complete the survey. It'll treat we Revision 3 has news sneak peek at some show that they're building exit I noticed it asks Mac but down. But you can check that out as well as a little behind the scenes look at it and she wouldn't like lot of there's an added that beautiful little. I was we'll see. I don't know view -- you'll see the craziness the the only got somebody just rip all my hair off and replaced it with buyer. And now we're -- to do an episode speaking of which use. The same -- yet so so that's the survey and what you guys to check that out these --"

" One last thing on lets you guys know about is hack stalkers. So okay check it out we've got packed house here. But the big guys in -- house chat and people who watches every day point 47 streaming for packed house dot com have gone ahead and set up their own site. -- stalkers knew basically what it is is where this stalkers become the stalk. They've set up and a beautiful. Rid of our website and it and they've actually you can actually embed your own and you stream. It's a social network for video don't yes and we're working with the guys -- trying to make the site a little bit more often this. Not crash. Every browser on try to improve because of the tab crashes your -- exactly so check out hacks dockers dot com that's HK stalkers. Dot com."

" Rather have a problem with that let you know this is -- all about -- would just love good info they go although -- undergo. Margaritas last African -- speaking what you need to do margaritas consultant who in the hash brownies with the these are not ice brownies unit I -- to -- hash brownies I mean I'm going to be making brownies and talk about hustle. I -- is and then mortgages assaulting. Oh and coming up after UConn. -- tag team and we're doing obfuscation. Or OS and OS fingerprinting so we'll network -- good."

" A lot of people have been asking me win the VMware segments back. Him soon yeah soon go I'm working on them and got some of these network out what they are products yeah the subsidies and -- with them. I like we're gonna remind you guys I've always trusted tech analyst. Yeah not -- Cause we -- you. It's like I thought you think you know millions. We've got it's awful -- Simon. You -- all the time I. But to be like here I'm giving you what the alert right now. Techno bucks on the table -- dollar dollar dollars. --"

" It's not if not I'm just trying to -- and lets you have to edit it and into the night."

" I didn't sign up for this idea."

" Wow. This episode of Hak5 is brought to you by GoDaddy. Netflix. Square space. And good news."

" Hello and Hak5 does your weekly does technology and Darren Kitchen I'm -- less stuck -- snouts. Now that -- I thought I think we're just given up on Apple. You guys don't -- bacterial anymore for much in the what you YouTube and actually the first three episodes which anymore it's in now and you watch aside from the fact that standard and looks like cable drag your truck. Com. And works well it was sham march this -- and out snobs. So it -- it can be its its you know since enough. -- hey anyway we have an Austin got in studio with us it is not NC. From the -- and studio insinuate that he's here. Present television on here I'm not gonna get into this with you right now anyway it's Peter Lewis from the academy pro dot com. Peter how argument."

" I'm great ideas. Rogers actions -- yet there. Europe thought this is is there better and it. -- home early in the media -- some I don't know like stuff but -- pretty much."

" Yeah I I can never space petticoat some like some patsy particle that up I learned that -- because in the -- and they. It's all they ever said they did and that's and webcam stuff. Woo hoo yeah. -- item on this so. So he had Peter -- you are the founder the creator of the the academy pro dot com right."

" How to build a I I've founder yes slot for help on the creation --"

" So would it out -- for those that are familiar with it would be proper for -- say it's kind of like the YouTube of security videos."

" I -- kind of although we don't let people just upload stuff applies that's pretty much the only difference."

" So it's like YouTube but without getting kicked in the nuts. Well it's YouTube with moderation. This come about."

" But a couple of years ago I was a -- consultant for about a little over a decade. And a couple years ago -- aren't a lot of ways you know better way of -- of a federal is actually give out information to people for free. To better configure their security technologies yet there are walls like yeah assistance. You know idea whatever Indians. Yeah that's how most frequent -- and we kind of inserted with. Crappy little Q and what have plates with a bunch of plug in Britain launched a website with 5060 -- on it and it's grown from their and that 300."

" So by taking you are you still -- I thought it looked a little word press it to be word printed area being in a security he would do you really probably don't want to run to follow when -- That's the target audiences -- this just like you dissing. But you look at it now now it's -- window and sort -- hold on a second hold on let me clarify this when you or web post. And you see somebody that does not update their -- well that's different and completely richer box should say the same thing about. We're press because I had word press one on one blog that. Anyway so let's hope it -- what because we're gonna subject see guys cover."

" hear anything from commercial products like you know checkpoint firewall source players she's an open source technology penetration testing you know with -- what spurred NASA as an all in all agree tools there. A little bit of everything."

" And you guys release like daily video isn't Tor is a step how to keep up with that."

" Basically what we're doing this weekend and is what we typically do every six to seven weeks is five or six guys sit together all weekend and you know basically created over hundred videos or slash lissouba. Two for months and that we have avoided them later on just put them ideally that's pretty budget and."

" How can you imagine density. How -- a whole lot how long -- Summer three for a -- summer -- Opens. Different episode and and that's is that he's got the Mubix. Waiting at Pearson. Yeah actually. OK so he's on the tarmac that get. You're in good hands in the -- is coming down and Italians now well yeah. So what it is like a hundred other places to go and get kind of late this this would you consider security training."

" Artwork track who or what we care what we try to do it because -- it. A lot of times vendors and accurately our Q are -- urban art does warcraft ever but you don't want Saddam out anymore. I'm not very technical their sales marketing information. What we wanted to -- was basically take. You know. What you want in specific video for example you I don't know how to configure you don't network address translation on a checkpoint firewall make -- minute -- that. You know if you want to know how to install checkpoint firewall on. And different platforms only that it takes -- units that fought so you kind of cold and unspecific -- yeah."

" So what -- considered like a special sauce that makes the academy unique. It. Is special uncle had a -- go to YouTube and just Google for whatever security thing is and there's fourteen year old that's gonna teach at what crack."

" Well you know what the problem is is I'm Paula to those sticky web crappy video straight girl might solve the problem is not enough. Vendor focused for example. You know we all likes to work as it is great you know open source idea -- and so on but not everybody can run under their environment because they're not commercial tools. You know it it's it's unfortunate -- that's just as always right so. Opinions were bringing commercial tools -- pretty much everybody for. I'm from the from the Chinese perspective."

" Very cool. Well we will be keeping an eye on it that its new website is the academy product coming also have a new site the academy home."

" Yeah the academy home dot com we launched -- couple weeks ago it's for all the pretty much that site came out of I don't want my relatives call me an offer support. You guys all know what I'm talking about yeah that's right pretty much -- go over there -- you have -- do you death so. And hopefully that wondrous little a little bigger as well so it's no good for the first."

" Awesome well Peter thanks so much for joining us this evening and we're look which next time -- in Toronto is you know you can -- records -- We gotta drive uses. Records in the -- That mostly men are. Excellent game and take care and good welcome that he had this weekend with -- and everybody."

" We pretty much -- so this stuff to the block and -- iteration and now see what's going on this week. And party. Actually this week when and I happen game but this client. -- Not -- panic. And -- prevent. Now I'm so credit. It's on February 20 that's Saturday and you can play -- in two of our servers you can play it Californians -- Hak5 dollars which is the last for that one. Or ZP dot hack I'd outward for the -- can't quite. We know that only sports that are eight players can actually get into left about it when times so -- And I have sat at -- scientific Netflix. It Netflix rent over 90000 titles online including possibly ray titles with free shipping both ways to your home. They got over forty shipping -- almost all deliveries happening just one this Wednesday. Netflix plans -- a 499. And as a -- you can get no risk two week free trial membership. Check it out and netflix.com slash Hak5 and he's so -- get the Debian communities. Except I think Chris is -- and this time. Some USB device training and."

" It's your back finally. Didn't bother them at the USB device tracking does that you're gonna lake stick a little device tracking inside my USB as a stealing your data inherently."

" No not really authority about it for -- that there's no devices that -- devices but it leaves a fingerprint years system. It leaves a fingerprint yeah it's actually figure it leaves it. Hey this is what I am this when this -- with the primaries where and so you got from it. And yes. Seeing how the registry all that I do I just -- again there's a lot of news veterans treated it is there it is -- Reagan's. Victory. Duty and so. What we do what we've mainly do is I got the stuff from wrote a book that he wrote. It. Was really. The stuff. So one of the place the goes to to start. It you know where is where oysters you know well you want to note that serial number. In the and you use this through -- to."

" So what do all of these different USB devices have different serum is even if they're like from the same model and most most of USB keys and he needs some time ago and it they don't. The appointment will sign a unique. Unique -- around town so we're here we're in the local machine entry go to each machine as we scroll down under software and will have this in the show all the different key task that's. Its its old maddening when it's going. I start with current version of underneath there -- witnessed -- version. And this is this'll tell you kind of where year's actual device -- that is. Which has all of the different. Driver IDs for all the different here you XP you know whatever -- missions -- drivers. Texas is a good place start going there and start writing down numbers in. You know and looking for those numbers here one good one of the better places to look you know. To actually find out what was plug in is under USB store -- new. I'll have -- but why would I actually spoke here. It's. Underneath here we can see there's a patriot device and then AUSB flash memory board here. Which the patriot want to -- one in the one. Yeah that's the one that I plugged in the end -- that class who that you -- me in the the drivers rather embarrassing number yet this is what it pulls from that kinda. So as a case of windows this is what you're gonna use for driver because it's used the device and -- Has a hard -- neat future memory. Apparently prefix in if you. Go back over here. Suppose back over this is the actual serial laboratory use to track everything through the registry and so that's out right now this."

" I hate it right down and is the other one we regret this down to. And if we go now. And what's we have these. We can go to another part. What's we have he's written down interest. Search you can search habits so it's a little easier to do it this way. We going to system current control set control and that device classes. Now this has every single you know kind of plug and play everything that is ever gonna plug in your computer. You know. So we just trying to -- I I actually went just open the ball up until iPhone which one's head there's about six or seven of them have different information about -- keys. These these two right here are just what happened to have the serial numbers in the."

" So. Saint somebody gets into my computers I see this random USB device is listed in here is their way that I can see if mainly. Tipped me off my computer since my days we're all about -- security."

" When Soviet very big race it would be there. In the -- in the registry. There is a way to actually determine when the last right -- want -- advice now here's our patriot device are here to open this up we put it. And we expose over. It's either this -- love it. Yeah we know that this injury here have to do with that hatred lies so by right clicking on this and I exported right as a textbook. Which Larry did. Okay we have an open right here. So we look at this exports data in -- right in here you can see last -- and it's and it twice but it has a lot of its extra data. 7:32 PM earlier today happens when it actually on this thing did -- into it."

" So -- says you."

" Eight and actually used this to cook."

" Robbery when you go to your recent documents folder under the documents and settings you can see drivers at a map to files that were recently opened. And you can you can go back in here and under -- to devices. Here I'll have this thing bonds due -- you can say okay. You can go in and figure out what drive letter was used within recent -- little bit more advanced but that's one of the uses frantically. That you can do you see okay it was drive letter half. The last right time with 7:33 PM and we know that -- semantics for -- you know some top secret missile. Was was taken -- So most likely it was that USB drive with that serial number. That if you don't do forensics there's a lot of other things that uses data for instance if you've ever heard of it's called I. It's yeah phoning home kind of software yeah L and I and I still right yeah iPod iPhone USB drives. And it actually pulls information of the same places and I'll actually a lot more places too because it identifies you know your actual computers via you know. Installation you know yet and it takes all this data and uses that so that it can identify the device -- from hey. This was plugged in from -- you know IP address in you know wherever Russia or something you know so and I you know it. You know somebody Russia has your."

" That's as well -- definitely gonna check this out on my own computer action -- Isaiah that so we can't find more information like this problem. I actually learned from from this book right here are -- reads windows forensic analysis. Per episode. Just. My boss -- book. And very great album actually get out so -- it warns. -- council there was also paper but who. Written by students -- the you'd going university. And they they used a lot of the same please use this book is -- reference. They were they put in very easily digestible. Form factors need I it was able -- intimate acts yet. So that it -- in you know it's."

" much credit. And I think we're finished and it's you can now for -- yet."

" That's right last week's trivia question was in PHP which is faster and why act over the world or. Hello world. Does correctly answered by -- old hand who wrote that -- is faster because it doesn't return value. We're gonna -- hooked him up with trial Lewis's awesome electronic albums zero equals one equals everything. You've heard the music throughout the show and bumpers and whatnot that statement. Check it out up front of those dot com. Now for this week's trivia he can go had just. Finally includes if you open up here in there and everywhere and you put together and that is a password the go ahead and her over I five dot org slash trivia. Good enter into -- your chance to win this week's trivia next week. With the weeks in the period that I've. -- a -- I've got to think are amazing sponsor for the -- tribute thing and that would be go -- if you'd like to make an impact on line godaddy.com has what you need."

" Dot com -- is low the dollar financial world class hosting patsy website builders and much --"

" Plus as a -- Hak5 you get five dollars off in order thirty dollars or more when you check out with code. Pack two. So anyway so restrictions apply to the fact need to be -- the Internet had. Eddie dot com thank -- government now and he was -- boom."

" Back in I believe was it season to -- Bronx is isn't that we did. Smooth wall. And -- smooth -- has been going flawlessly for the last two years. I came across a basically. Smooth wall on crack -- like it's called PF sense and basically it's built on free BS the and it's a four. Of the model wall project now some -- he's not a wall something you don't. You find out more about that I believe that model -- dot org. In the PF sense dot com to actually download a -- to live CD installer. Or an embedded installer will we're gonna do is I'm gonna show you guys how easy it is to set up PF sense. That's going to be this episode wanted to do is only been. Go on and show you some of the more advanced stuff like open BP and end you know VPNs like the sites so on and so forth. In future episodes so let's died in. Or going to do is we're gonna start our computer with the live CD that we burned. Yes I'm aware that any -- all the VMware tools and what we're gonna do is. It's gonna start up and we have the option to install. Or just run PF sense. From the live CD installation now the nice thing about that is before you wouldn't make any changes to an existing installation of say are smooth wall. You can actually verified that set -- is gonna work -- your hardware that it's going to work with you know your network infrastructure. Blah blah blah blah blah blah. So what it's doing now it is actually load a live CD it's a start up here and there's there's a two step process first we're gonna set up in the the shell. And then we're actually going to law again to yet sense from -- another computer to set up the wizard. Asa right now to -- that we want to set -- lance we have absolutely no purpose for being lands here in our infrastructure so we're gonna go ahead and say now. Now what we're gonna do is because. -- And in a DMI actually have to disconnect. Our network adapters. Because what it's gonna do is it's actually going to auto detect. For those of you who don't know -- or network interface names. I do but for the sake of showing you let's go ahead and do that now the -- go ahead and select a and it's gonna ask this Apple connecting Lan interface to -- go ahead were to connect the land interface which on ours is a virtual machine. Interface so we're gonna come on back over here to PF sense. It editor and EM zero is changed to link state -- so that's our Lan interface to come. Back and say hey now -- assets for the Lan interface so ring connect the way and it affects. Come back in -- PF sense. And hit enter and EM one link state changed to up. So now you have the option to set an orange interface. We don't need an orange interface Serena and and -- and it's gonna ask you to confirm your interface election -- zero being the land and EM one being York -- Yes we would like to proceed. So now it's actually. Done with its initial configuration in its gonna actually start -- access to the point where we can actually log into the web interface. Come on come up their ago so now what we're gonna deal is -- to come over and in another machine. Reopen Internet. Now for the sake of testing and show you guys I've already set up static IP the address for the local interface is defaulted to 1921681. Network so I've already got. I think. If I'd come down here. Regular address now the so right here written go to one point 216 it got one L one. And -- enter in the password Edmund and heard the username Edmund and it password is PS cents I'd fall. So here it's gonna launch the setup wizard for PF sense. Yet your -- guide me through the process you center hosting your domain your primary DNS server I myself when I'm testing things. Like -- DNS server external of my local DNS server just so that I know I had. Con activity. -- better for dot to dot to dot to. Dairy easy to remember fortitude to. If you ever need paying any thing. That's what -- just use because it's always up. So we're in a select our time zone and are. Server for time. -- a static here because were actually plugged into our existing. Internal network three to set a static address and it's going to be. Ten that. Ten dot zero dot 134. Now you guys would probably use you or cable modems. Static or DH CP information. Our subnet is a 24 and our gateways and that's and I don't know one. Come down here now these -- settings down here block bogey on networks and blocked RFC 1918. Networks. It's key if you're going to use. PF sense in a robber. Behind it Robert configuration because you need unchecked the 1918. Because otherwise it Walt brow correctly. It's like next and we're good with our Lan IP being 1921681. We're gonna enter a password of Hak5 because we're very insecure like that. And we're gonna reload the interface and -- With a new password a -- five. Come over here. And we are going to. Verify. Via the PF cents. Interface to see if we actually have connectivity or not so let's go ahead and see that -- house is option number seven. And -- back com. And when you look at that we've actually got. Connectivity within. Those five minutes. It's very simple to set up. What would go into later are some of the more advanced options of IPSec VP -- open BP yen a lot of the services virtual like you support things of that nature. It's a very very powerful. Platform for running -- routers here you know using a Linksys now you've got -- on machine. Laying around your house I highly suggest you guys check out yes that's that's great graphic with our -- tools are -- graphs. And just some really nice applications. And platforms that really are available to you Linksys users unless you're running past the open WRT. But that's the segment -- and check it out PF cents dot com and right now we are going to. And show finally. And he guy's been a long time but in and show -- Daryn back like only Hak5 can't. Mystical magical."

" dude. It -- do well thank you. Slated to answer. You know as we speak when -- news -- can't hold wished action. -- noticed that it's meant. I -- and I know about that but right hand. Yours. Yet really hold that thought -- right. We have a whole -- fun stuff that we need to entertain you it in and enlighten you about. But first I gonna get mad props and things one of our sponsors so let me tell you guys about square space I know told in the past square space is an excellent. Content management system has a very unique front and back -- system -- web host their answered like eight dollars. Round that at the -- of the W that's where it's based on -- eyes. Just go there and if we can check with coupon -- Hak5 10% off the life of your order so we're looking up let me show you one of the cool things you can do with squares where we -- that you can create blogs blogs a lot of the big stuff the -- concrete forms and to. You know really rich website. Blow when the neat things is when you want to change the look everything -- have you ever tried to install teams in different and we talk and Drupal earlier this is real simple right so we're in. Just the regular man this place you went there right but the blogging here get special cool bar at the top. A -- despite -- here. And I'm now in this style switching area and we've got this custom Hak5 theme for Lan party that looks awesome right. And it's all done with like you know just dragged itself into -- yes that's but they've also got a hold on a built in themes and you can just cycle through them. They clicking any of these and they've got a ton of them we can actually switch templates here and and it from one. You are -- real either not very good I got -- okay they have but be -- they're late that one or the news room. Looks pretty and you can actually lives see you know as your pick an amount C which like. It -- port and the cool thing is once you've created one you can clone it you can dig deep you can do this yes that's that showed you how easy it is to create forms and and file drops and all sorts of stuff with it it's just it's pretty -- it's."

" Probably one of the most powerful. Platforms that I've seen in ten years of hosting and both sides now playing with trial that this is for stuff that we covering now looking at Dreamweaver. And I mean little that on a code got myself but expert for a lot of people for 95%. People line and that just want a website. And whatever to show off their pick me do things -- Bob square -- base is the perfect I'm actually."

" Using it for -- I've been playing around with the you know London web redesign for you know the system and job yes yeah. Well -- I've just because first -- it would just be easier 'cause I'm. --"

" So its. Its like. Equal. To get them out there now. That's where -- com he's good on its importance on of that. Department code. I recently did little -- on the show. -- There which would -- that day and that is so. As I'm sure the rest of the Ayers and I thank you I didn't realize that -- was built and that's cool. So but I still believe that the fundamentals of notes chillingly. In reasonably PC and something like. The OC with HTTP it's back and split mechanism. I hope you can find something from that. If in like two weeks from now you're elected currently two -- from where all the on hack IV you know it's like. -- put the old in the last. -- for. So you have to work. -- It works. Workers though. It says. -- and you know if you are. And that's the odor and when LA. You know with the -- out there or code pink Jersey nets. From all right that's cool that's cool we've got the okay. If you felt. Here right Q let's get carpet -- all -- as we will be there you're watching this right now on. On Wednesday -- because awesome and you subscribe to the RSS feeds that you get automatically look to all of it -- At work on the home page right here guitars that speed. Hak5 on. Each Ph.D. New OW one that you're still watch -- Age. Else does on these actually never mind that gravity is so you know if you're downloading files -- Rates from the fast -- off -- Aussies directly from our. So -- on we will be there on the 68. You're doing podcast is -- up so head over to podcast dot com to find out how you can meet up with us open District of Columbia as well securabit. It's split Catholic speaks you're just argue. Episodes or something. Line. Instantly will get a guy yet so on there are so. One mention that you guys have heard of like Ted conference. Opt in and like -- talking -- you two in the about these totally stoked the built on write it it can. Yeah it's it's a grass roots saying just like people. Now why is it. Not for real. A connection that's it isn't always. I'm a -- their bring in great minds together. And and it's kind of like an -- conference thing's going to be big discussion. Bunched up presented and check out Revision 3 is broadcasting high. Without the gravity. Right so. February 7 and eight same time we're at -- check it out at revision3.com. Slash B."

" I know. Mad exactly want to let you guys know that we have the brand new -- march wag. Pack backpacks Hak -- yeah. Fast tax service packs one through three basically we've got -- you know different packages set aside for you guys that you order new designs -- stickers. The -- bus tickets which we've had a blast getting out there grid could actually get one out an actual bus driver going to give one to you as it is for you -- to -- yes definitely. So head on over -- five dot org slash stickers and get your new technolust year -- on."

" Yeah and and we appreciate all of your donations because it helps us figure out how to make on you work on. That's another story anyway yeah we much appreciated. So what else is going -- and we've got to we've got to mention that about the survey yes yeah. So as you guys know. We love you we know you are because you're up on -- house where you're up in the Hak5 buyers a year on the forums are we talking to us all the time writes -- and we're. Look I would love. Two and but the thing is like the people the powers that be and whatnot. Don't really know you guys what we do so if you could go over to revision3.com. Plus Hak5 survey and participate in this survey. Give us a little idea about the war and whatnot. It's gonna help us make this show better view and and and help us keep going and whatnot so we're conducting the survey. And would love your feedback to go and spend a few minutes at there and check it out rate if you complete the survey. It'll treat we Revision 3 has news sneak peek at some show that they're building exit I noticed it asks Mac but down. But you can check that out as well as a little behind the scenes look at it and she wouldn't like lot of there's an added that beautiful little. I was we'll see. I don't know view -- you'll see the craziness the the only got somebody just rip all my hair off and replaced it with buyer. And now we're -- to do an episode speaking of which use. The same -- yet so so that's the survey and what you guys to check that out these --"

" One last thing on lets you guys know about is hack stalkers. So okay check it out we've got packed house here. But the big guys in -- house chat and people who watches every day point 47 streaming for packed house dot com have gone ahead and set up their own site. -- stalkers knew basically what it is is where this stalkers become the stalk. They've set up and a beautiful. Rid of our website and it and they've actually you can actually embed your own and you stream. It's a social network for video don't yes and we're working with the guys -- trying to make the site a little bit more often this. Not crash. Every browser on try to improve because of the tab crashes your -- exactly so check out hacks dockers dot com that's HK stalkers. Dot com."

" Rather have a problem with that let you know this is -- all about -- would just love good info they go although -- undergo. Margaritas last African -- speaking what you need to do margaritas consultant who in the hash brownies with the these are not ice brownies unit I -- to -- hash brownies I mean I'm going to be making brownies and talk about hustle. I -- is and then mortgages assaulting. Oh and coming up after UConn. -- tag team and we're doing obfuscation. Or OS and OS fingerprinting so we'll network -- good."

" A lot of people have been asking me win the VMware segments back. Him soon yeah soon go I'm working on them and got some of these network out what they are products yeah the subsidies and -- with them. I like we're gonna remind you guys I've always trusted tech analyst. Yeah not -- Cause we -- you. It's like I thought you think you know millions. We've got it's awful -- Simon. You -- all the time I. But to be like here I'm giving you what the alert right now. Techno bucks on the table -- dollar dollar dollars. --"

" It's not if not I'm just trying to -- and lets you have to edit it and into the night."

" I didn't sign up for this idea."

mari1ee

Started discussion: February 4, 2009 @ 9:31am GMT

Episode 425 - USB Device Tracking and PFsense [Discussion]

In this episode Peter Giannoulis joins us from TheAcademyPro.com. Chris Gerling is back in studio talking about USB Device Tracking. And Matt is building the new HakHouse firewall/router with PFsense. Plus a ton of haksnax to get your grub on.

Watch or download now!

rikashay86
10 months ago

The part after the credits

the part after the credits was awesome hahaha - Great show as always, keep up the great work!
shevaneltaketwo
10 months ago
I'm finding myself slowly getting into this show more and more. Keep it up!
Hak5Matt
10 months ago
@shevaneltaketwo : Good to hear you're warming to the show! Let us know what you would like to see, and suggest some ideas to feedback@hak5.org :) We read every email I promise!

@rikashay86 : Glad you liked it :) it went on for about 5 minutes hehe

Please don't forget about the survey at http://www.revision3.com/hak5survey

Thanks again guys and gals!
Matt
Kamasutra
10 months ago
Seeing as how the part after the credits seemed staged, when Matt went to removed his mic I thought he was reaching for a fake gun or something. That would have been awesome.
xfuuey
10 months ago
I must have missed the "sneak peek" part at the end of that LONG survey?!? :rolleyes:

Anyone else see it?
rikashay86
10 months ago
I saw the video but it was messed up, the sound kept looping every 30 seconds on top of iteself. Maybe it was just me but it was unwatchable.
computoman
10 months ago
Pfsense, ipcop, and etc are cool. I started to use one of those on an old computer but dd-wrt and tomato came along. I bought the airlink 101 ar430w for 15 dollars and put dd-wrt on it, but ended up using the good old linksys wrt54gl with dd-wrt. Openwrt might also be neat to try. I would like to see the pineapple software on one of those arlink101's.
whatsit
9 months ago
After setting up a pfsense router this weekend, I must say that it is very easy. The hardest part was getting the correct routes through the firewall to my servers. Even then, it was all point and click.

I tried the dd-wrt / tomato option and the hardware (WRT54x) was WAY underpowered. While the feature set those custom firmwares provide is indeed feature rich, the hardware is subpar. Under any decent load (think lots of torrents / connections) the hardware was a major bottleneck.

Instead, I went with a small form factor pc (Dell GX150 SFF on eBay for
aviadra
4 months ago

pfSense didn’t… make ANY “sense” that is…

Seriously, don’t use this piece of @#$@$ and save yourself a world of pain.
I have this thing at my work place where I am the IT manager…

At first, being a long time DD-WRT user, I got excited that the last guy at my job implemented a triple WAN connection with this thing…

That was before I realized this thing creates more problems than it solves and doesn’t even live up to the clamed expectations.

We now have the recurring quote in our case documenting system and buzz words in the office saying that:
pfSense didn’t… make ANY “sense” that is…

Some of the problems we had include but are not limited to:
1. Firewall rules changing their behavior with no apparent reason
as I wasn’t the one who setup the firewall rules I was happy to assume that they are setup correctly, as everything seemed to be working fine.
ho boy, I don’t know how many mornings I spent on: lets figure out what is causing the problem when nothing has changed… only to reach the conclusion and I quote myself on this one:
“The firewall (pfSense) strikes again with its usual !#@$@!# and didn’t… make any "sense" that is – rules that are in the firewall before I am in the company changed their behavior and started resetting connections from the inside to the VPN server.”

While one might argue that this is a misconfiguration problem, I say that if its misconfigured it should NOT WORK from the beginning and not change according to the direction that the wind is blowing!

2. The triple WAN load-balancer is the touchy-est thing in existence and is the best detergent against none work related surfing that ever existed.
this should really be broken down into two parts:
a. The triple wan practically disables the internet if just one of its connections fails witch IMHO completely defeats the purpose of having a triple wan setup in the first place.
This is because instead of disabling the WAN interface that failed, the thing still tries to send connections through it… so a third of the DNS requests fail and even if you did get a resolution, a third of your connections to IPs fail.
In other words, you will not be surfing ever again until the failed wan is back.
b. Because the sticky connections options simply doesn’t work (that is, it drops connections with no apparent reason), going to sites that require a consistent connection throughout the session get thrown off track. For example practically every site that uses letter caption to prove you’re a human….. by the time you enter the letters you are already going through a different WAN and the site rejects your answer.
oh and youtube videos fail to load… ALOT (thank you pfSense… thank you so very much).

3. Being hardware agnostic isn’t always a good thing.
While one would think that the ability to install on any sort of hardware would be a good thing, in reality it makes for not only unexpected problems but unreliable behavior and plausible deniability (and you know that’s never a good thing).
What I mean is that when you buy a router from a reputable vendor, they had tons of QA tests thrown into testing their product witch nowadays more then not includes the hardware. This means that if your box is actually faulty you can figure it out fairly quickly.

what happens with my box is that for some unknown reason every once in a while, I will notice a significant slowdown of the internet speed… after trying to no avail to connect to the pfSense console (web or SSH) I walk up to the pfSense head…. Only to discover it is in an infinite loop of spitting out error messages about something with the network card in the alien language of the ancients (Unix). No human can read this lingo and after a useless battle, I am forced to use one of my Jedi powers to “force reboot” the server.

During one of my struggles with the box I actually replaced the add-on network card in the pizza server we use as the host… did that help?
You guessed it, it didn’t… and since the only other NIC on that server is the onboard one, I simply have to live with this problem.

so in my case I am left in a Limbo… were I don’t know if the fault lies with the software or the hardware, but if I had to guess… nof said…

oh and I can’t really complain to the “vendor” as he is “doing me a favor” by providing this software for free… so how dare I complain about it?

that’s it for my 2 cents… personally I bought a Juniper SRX210 to serve as the company router.

One last quote as its sorta related:
“Linux is only free if your time is worthless”.
View all 9 comments