Monday, October 6, 2008
HeX 2.0R Released!
1. FreeBSD 7 Stable
2. Unionfs
3. NSM Console updates
4. Tons of analysis alias and scripts
5. Tons of NSM tools' signatures
6. Firefox - Useful websites bookmark
7. Liferea - Security rss feeds
For more info: http://us.rawpacket.org
Thanks to the rest of the HeX team for diligent and hard work on this.... more to come!
J
Wednesday, March 19, 2008
FreeBSD USB Booting Issues (BTX)
Since we have been building LiveUSB tools that were based on FreeBSD there has historically been an issue with several makes of laptop/hardware on boot. This problem has manifested in many ways but always yields the same result; a non-working LiveUSB tool for the system owner. This problem had to do with the BTX Loader not playing well with the specific hardware in question and not loading/running properly via USB.The good news is that recently a patch was released that should rectify this issue! I will be applying this patch to all FreeBSD based LiveUSB releases going forward. Thanks for all of the community feedback and support on all of this.
For those that may be curious, here is the patch: http://people.freebsd.org/~jhb/patches/btx_real.patch. Moving forward (post 7.0R) all releases will be patched from the freebsd folks direclty.
Cheers,
JJC
Monday, March 17, 2008
HeX 1.0.3 LiveUSB Final (Bug Fixes)
You can get it (in torrent form) from the Security Torrent Depot at http://www.redsphereglobal.com:88/torrent.html?info_hash=77f31dbc8d641500530760e62f17d1a08e433b96 or you can get it from the below direct download site.
USA Site
MD5 (HeX-i386-1.0.3-final-usb.img.gz) = 5fb1498b3437fada0b38602324d8f5e0
Usage instructions are simple:
dd if=/path/to/HeX-i386-1.0.3-final-usb.img of=/path/to/usbstick/device bs=1M
Look for the new HeX 2.0 to be out soon, all based on FreeBSD 7.0R!
Note that some usb sticks will be smaller than others (even if it's "2G") and that even if you write it and dd produces an error saying that not enough space is available... this is OK and your HeX LiveUSB will still work fine.
Cheers,
JJC
Friday, February 29, 2008
Security Torrents
Toolkits
Anything that I or various other contributing members find useful, relevant or fun with respect to security. Current items that will go into this category are the various HeX (all) releases and InProtect LiveUSB releases.
Distros
Any custom distributions that have been designed to fit security needs and/or perform specific tasks.
Packet-Captures
Any large packet captures or trace files that are obviously not going to fit on the www.openpacket.org site. There is one up there now, it is the malicious traffic that Richard Bejlich captured at the 2007 Shmoocon. This torrent was created and added by giovani...so a shout out goes to him!
Having said all of that, we will (as with all trackers) need seeders. So if you have a little extra bandwidth and/or want to contribute in any way please let us know!
Cheers,
JJC
Friday, February 15, 2008
HeX 1.0.3 LiveUSB (CNY Release)
So for example on my freebsd system I would dd as follows:
dd if=/path/to/foo/hex-i386-1.0.3.usb.img of=/dev/da0 bs=1M
command is simple... if is the Input File, output is the Output File (in this case it is the da0 device) and bs=1M is setting the block size to 1mb - this helps to speed up the write process.
Downloads:
USA Site (521MB)
USA MD5 Verification
USA SHA256 Verification
Malaysia Mirrors to be populated soon, I'll post them when they are.
Cheers,
JJC
Thursday, February 14, 2008
HeX 1.0.3, the CNY Release
With the recent release of FreeBSD 7.0 RC2, we anticipate an actual 7.0 release in the near future. When the Release version of 7.0 becomes available we will begin working on the new HeX 2.0 project.
Get HeX 1.0.3 Here:
US Mirrors:
https://secure.redsphereglobal
https://secure.redsphereglobal
https://secure.redsphereglobal
Malaysia Mirrors:
http://bsd.ipv6.la/hex-i386-1
http://bsd.ipv6.la/hex-i386-1
http://bsd.ipv6.la/hex-i386-1
Fixed:
- pkg_info works after installation
- ping works without sudo
- procfs is correctly mounted on /proc at boot
Upgraded:
1. NSM Console 0.6-DEVEL
Features:
- 'dump' command added, you can now dump packet payloads into a binary
file for later analysis
- Significant speedups in the harimau module and 'checkip' command if
wget is installed
- tcpxtract configuration file changed to extract more types of files
- Added foremost module
- Added clamscan module (Thanks JohnQPublic)
- Argus and tcptrace have reverse dns turned off by default now, it
was causing the module to hang for extremely large pcap files. Can be
switched on by changed the module options
- rot13 encoding and decoding added :)
Bugfixes:
- alias command
- urlescape (en|de)coding
- file existence check
- many other things
All the other enhancements, bugfixes and additions since the 0.2
release (there have been many!)
New Application Packages:
- xplot
- uni2ascii
- vnc
- vsftpd
- samplicator
- sflowtool
- pmacct
- ming
- ploticus
- tcpick
- bvi
- elinks
- feh
- tftpgrab
- arpwatch
Misc:
- New wallpapers with different color schemes
The LiveUSB image will be out shortly, it is undergoing a quick regression test currently.
Cheers,
JJC
Monday, February 4, 2008
HeX and NSM-Console Writeup in ISSA Journal
If you are not an ISSA subscriber, you can access the writeup at Russ McRee's column or here in the form of pdf.
I would like to thank the community for their continued support and feedback on this project.
Cheers,
JJC
Thursday, January 10, 2008
HeX Virtual Appliance Image: 1.0.2R
This image is 825M in size and will decompress to a 3G VM.
https://secure.redsphereglobal.com/data/tools/security/live/HeX_1.0.2_VMware.tar.gz
https://secure.redsphereglobal.com/data/tools/security/live/HeX_1.0.2_VMware.tar.gz.md5
https://secure.redsphereglobal.com/data/tools/security/live/HeX_1.0.2_VMware.tar.gz.sha256
Enjoy,
JJC
Monday, January 7, 2008
HeX 1.0.2 LiveUSB Update
For additional information on the project, please read my earlier post at: http://global-security.blogspot.com/2008/01/hex-102r-liveusb-release.html
https://secure.redsphereglobal.com/data/tools/security/live/HeX-i386-1.0.2.img.gz
https://secure.redsphereglobal.com/data/tools/security/live/HeX-i386-1.0.2.img.gz.md5
https://secure.redsphereglobal.com/data/tools/security/live/HeX-i386-1.0.2.img.gz.sha256
Cheers,
JJC
HeX 1.0.2R LiveUSB Release
https://secure.redsphereglobal.com/data/tools/security/live/HeX-i386-1.0.2.img.gz
https://secure.redsphereglobal.com/data/tools/security/live/HeX-i386-1.0.2.img.gz.md5
https://secure.redsphereglobal.com/data/tools/security/live/HeX-i386-1.0.2.img.gz.sha256
For those that are not familiar with the HeX project, please read further at rawpacket.org. The LiveUSB project is a subset of the overall HeX project and adds a bit of functionality to suit your portable packet monkeying needs. Essentially it gives you a slightly larger (and writable) filesystem to do with what you please; i.e. update signatures, modify configurations, store data and the like.
To use the LiveUSB; simply download decompress and dd onto your device (example on fbsd: dd if=/path/to/HeX-i386-1.0.2.img of=/dev/da0 bs=1M). Note that for speed purposes it is important to increase your default block size in fbsd, the value of 1M takes about 200 seconds for my system to write the entire 2G image.
This release contains the NSM Console as described below.
Matthew(Dakrone) is the main developer of NSM Console, here’s the short description about it -
NSM Console (Network Security Monitoring Console) is a framework for performing analysis on packet capture files. It implements a modular structure to allow for an analyst to quickly write modules of their own without any programming language experience which means you can quickly integrate all the other NSM based tools to it. Using these modules a large amount of pcap analysis can be performed quickly using a set of global (as well as per-module) options. NSM Console also aims to be simple to run and easy to understand without lots of learning time.
If you want more information about what it is (and what it does), check out this introductory post -
http://thnetos.wordpress.com/2007/11/27/nsm-console-a-framework-for-running-things/
You can access NSM Console by clicking the menu -> NSM-Tools -> NSM Console
There are also several bug fixes in this release, as well as new nifty wallpapers (for the holiday season hah).http://www.rawpacket.org/projects/hex/artwork
1. unicornscan run time error
2. svn run time error
3. lsof run time error
4. firefox startup issue
5. pidgin and liferea dbus issue
6. CDROM-Mount.sh syntax error
7. script command issue
8. ping setuid issue
Other known major or minor issues in the Base System are fixed, thanks to chfl4gs_.
Cheers,
JJC
Monday, December 3, 2007
HeX 1.0.1R LiveUSB Image
To use this tool, simply download it from the below location, decompress it and use dd to place it onto your USB Key. If you are not familiar with the dd syntax it's quite simple really; dd if=/path/to/extracted/hex-i386-1.0.1.usb.img of=/dev/da0 (your USB device). Note, that you should not dd this to a mounted partition, it will not work. You need to dd onto a USB Key that you don't mind losing the data on, because this will overwrite everything on that key. You can create a small partition after the dd (this of course assumes that you know how to do this, leaving the existing partition in-place) and have that to write data to etc...
This image does require a minimum 2G key (actually uses 1.75G), and has no minimum memory requirements (other than standard fbsd and X requirements).
https://secure.redsphereglobal.com/data/tools/security/live/hex-i386-1.0.1.usb.img.gz
http://secure.redsphereglobal.com:8080/data/tools/security/live/hex-i386-1.0.1.usb.img.gz
MD5 (hex-i386-1.0.1.usb.img.gz) = cd7489ba0a2a1fe824d286c72eee6842
SHA256 (hex-i386-1.0.1.usb.img.gz) = ffbb428145e0184d3848e45afee0d10ba41a4d9177688db10befc943dd4058f5
Please test this out and let me know how it works for you, or let the entire team at rawpacket.org know.
Regards,
JJC
Monday, October 29, 2007
HeX-VA (Virtual Security Appliance)
I am pleased to announce the release of the HeX Virtual Appliance!To facilitate quick and easy use of the tools that are built into the HeX Live CD, we have installed the Live CD on four Virtual Machines to create four Security Virtual Appliance Images. These images are intended to aide in the rapid deployment and usability of the HeX Live Toolkit and we are dubbing it HeX-VA. The images are designed for use with Parallels, Qemu, VMware and Virtualbox virtualization technologies. If you have any problems using these images or have any suggestions, please feel free to contact us or stop by #rawpacket on freenode.
Thanks to geek00l for the screenshots and continued hard work on this project! I have included the US Mirrors below for your downloading pleasure. If you are not US based, there are other Malaysian mirrors listed on the official rawpacket.org site under the Virtual Appliance project section.
HeX-Paralleles | md5 | sha256
HeX-Qemu | md5 | sha256
HeX-VMware | md5 |sha256
HeX-Virtualbox | md5 |sha256
I'll be posting some detailed directions shortly on the usage of NTop and some specifics on tuning it for your environment (by request).
Cheers,
JJC


Friday, October 26, 2007
HeX 1.0.1 Release (Bug Fixes)
Another major issue that was occurring was with the msfweb not loading properly or not functioning when loaded. It turns out that this was actually a firefox related issue; deleting ~/.mozill/firefox and using the global Firefox configuration fixed the problem (note that this also fixed javascript issues in ntop and darkstat).
As geek00l says, we are "shamelessly" releasing this fixed version. As always please give it a roll and let us know if you experience any issues. You can report bugs using our Trac interface, the Mailing List or via IRC in #rawpacket on freenode.
Download URLs:
Cheers,
JJC
Thursday, October 18, 2007
HeX Live 1.0 Release
After 6 months of heavy development and debugging I am pleased to announce the release of the HeX Live CD 1.0 Release. What is HeX Live? HeX Live is the worlds first and foremost Network Security Monitoring & Network Based Forensics liveCD. The intent is to provide a wide array of highly usable tools in a pre-packaged format that the analyst can use to investigate and monitor real-time network activity, whether security related or in the course of reviewing traffic to determine bandwidth over utilization sources and so on...This will be the final major release of HeX LiveCD until the release of FreeBSD 7.0 Rel, this is of course pending no major bugs are located in HeX 1.0R. If there are any major bugs found, then a bug-fixed HeX will be released prior to FreeBSD 7.0 Rel.\\
For a detailed list of what applications can be found on HeX Live 1.0R check out the actual
project at rawpacket.org.I have also included in this posting the CD covers that were created by vickz, fantastic work man! You can download the HeX LiveCD 1.0R from the following locations:
I will try to get some decent screenshots posted soon so that everyone can see just how slick the HeX LiveCD 1.0R really is. I would also suggest that you download it and play with it. There are a good number of tools on here for packet monkeys of all ages and skill to have a good old time!
I'll leave it at that for now, and again would like to thank the community for their support and feedback throughout the development process of this tool.
Shout to Geek00l for organizing everything and kicking some a$$!
Shout to ch4flgs_ and zarul for everything!
Shout to all others involved in this project (esp for putting up with me)
Cheers,
JJC
Tuesday, October 9, 2007
HeX Live Pending Release

For all of you anxious packet monkeys out there, the HeX LiveCD 1.0R will soon be available. We are running through extensive tests and bug fixing excersizes right now, but anticipate releasing this new version within the next week. I'll post an update once released, as well as the standard US mirrors.
This project has also been gaining a good amount of momentum and continued community support. I would like to thank all involved, esp geek00l and chfl4gs_ (the core founders)!
If you want some additional information concerning this project, please check out www.rawpacket.org!
Cheers,
JJC
Friday, September 28, 2007
HeX Live Update
I would also like to thank everyone for their feedback and support of this project, one small step at a time. As to some additional information, there has been some discussion surrounding the creation of a VM image / Virtual Appliance that would embody the HeX Live CD capabilities and give the network analyst a broad set of tools. I'll post updated about this as they are available.For all the HeX liveCD users out there, we have been developing this liveCD for quite sometimes and I have received some positive and negative comments and various inputs from the users, therefore instead of me receiving the email and redirect to other co-developers, I decide to create the mailing list for the HeX liveCD so that it will has life of its own ;P
There you go -
http://groups.google.com/group/HeX-liveCD?hl=en
Since this is public group and mainly used for mailing list management, I decided to use google group as it is convenience and easy. Therefore feel free to join us!!!!!
On the other hand, you can visit us at Freenode #rawpacket. Most of us are slacking there.
Cheers,
JJC
Monday, August 20, 2007
Updated InProtect 0.22.5JC Patch
I have just fixed a bug that manifested in certain installs w/ specific php.ini options. The download links are the same but I'll still provide them...there is a new md5sum for the file though since I modified some things and repackaged.
Credit to progma in #inprotect for finding the bug!
New MD5 (InProtect_0.22.5JC.tar.gz) = cef93620ebaef7d4f2406e6133ff6e4e
Download Here
MD5 Verification
Enjoy,
JJC
Monday, August 6, 2007
HeX LiveCD 1.0 Beta 2
More information can be found at the rawpacket site, or from geek00l. I have included US based download mirrors in addition to the Malaysia site.
Boot up the LiveCD and "su" to root and type "installer" or "sudo installer" to start the installation. cpdup might take 10-30 minutes depending on you CDROM drive speed.
The only problem is BSD installer ncurses looks a bit weired under X. We still have no solution/workaround to that. However that shouldn't affect the installation process.
Malaysia Site | MD5
US Mirror 1 | MD5
US Mirror 2 | MD5
Cheers,
JJC
