There may be a chance that your Croissants not working. We now talking about how to trouble shoot it.
Step 1 :
To see if "suricata", "pigsty" and "snorby" are working (existing) or not.
sudo ps aux | grep suricata
sudo ps aux | grep pigsty
sudo ps aux | grep delayed
Step 2 :
If you encounter no alert on the Snorby, you can check if the "unified2.alert.*" is there. Please also note that it should be only one "unified2.alert.*" file.
ls /var/log/suricata
If you find more than one unified2.alert.*, delete the oldest and keep the current. Or simply delete all and then reboot.
Step 2a :
One more area to check for no alert is at Snorby.
Open the browser and point to the Snorby. "Administration" -- "Worker & Job Queue" is showing "OK" at the "Status".
Step 3 :
If you encounter any error, you can try to reboot the sensor (Croissants) to see if the problem is gone or not.
Step 4 :
To check the suricata.log to see if there is any error.
*** THE CURRENT VERSION OF CROISSANTS IS 0.1.2 (CROISSANTS-20150701.TAR.GZ) which is released on July 01, 2015 ***
What is Croissants?
Croissants is an Intrusion Detection and Prevention System and running with Suricata. The components also including Snorby (Event Manager & Web Interface), Pigsty (Event Spooler) and Pulledpork (Rules Manager).
Suricata is a high performance Network IDS, IPS and Network Security Monitoring Engine. Croissants running on AF_PACKET with Suricata and it throughtput is up to 10GB traffic. AF_PACKET is one of Linux kernal modules since version 3.6 and it is designed for packet capturing. It is almost plug and play.
AF_PACKET can be running on a very low-end x86 computer, such as Intel ATOM D2550 CPU with 4GB or 8GB RAM. I recommend to use at least 8GB RAM for home security purpose. More memory and faster as well as more cores Intel CPU for Home Office or larger business is suggested.
What Is My Home Network Looks Like?
I have 10Mbps internet connection. I do not run with any modem. I have a home router (TP-LINK TL-WR1043 v1.x with stock firmware). I have two home switches (TP-LINK TL-SG1008D, it is like a hub more than a switch in general).
I have a Linux web server, a Windows 7 desktop, several Linux boxes and some Mac machines as well as a Time Capsule. I connect these boxes to the home switches. I disabled the wireless function on my home router and use Time Capsule as wireless router and Time Machine for Mac machines.
I implement two IPS on my home network. The IPS is connected between ISP and the home router. The other IPS is connected between home router and home switches. Therefore, I can monitor the traffic outside and inside my home network. I do not trust internet and intranet at all.
Since MINIX Mini HD PC comes with 2 network interfaces, I need one more USB Gigabit Network interface on each box for monitoring purpose. You can either choose Level One USB-0401 USB Gigabit Ethernet Adapter or PCi USB 3.0 Gigabit LAN Adapter UE-1000T-G3 as they are fully compatible to Linux.
I installed 8GB RAM and 4GB RAM on IPS for experiment purpose. I suggest you to install 8GB RAM as MINIX Mini HD PC supports up to 8GB RAM even the official does not claimed that.
Internet -- IPS -- router -- IPS -- switch -- PCs and Time Capsule (including web server)
For better performance, I suggest you to use this motherboard with one more Intel LAN card and at least 8 GB RAM.
How About The Installation?
I select Ubuntu 14.04.2 LTS Server as the OS of the IDS/IPS. Since the network interfaces of MINIX Mini HD PC are Broadcom, the name of the interfaces on Ubuntu 14.04 is p2p1 and p4p1. While the USB Gigabit network interface is eth0.
Install Ubuntu Server on the MINIX Mini HD PC as usual. Make sure you only connect the network cable to one of the network interfaces. I recommend you to install the OpenSSH when asks. Update and/or upgrade the Ubuntu Server when necessary.
Download the Croissants from here. The current version at the time of this writing is version 0.1.2 dated July 01, 2015.
Please follow the instructions on the official site to install. Configure the nsm.conf. Make sure to remember the password of MySQL as it will be asked when install. The username and password of control panel (Snorby) will also be configured. At the end of the installation, you will be asked for the time zone. Please select UTC. By the way, you may notice that there will have some error warning on the screen when installing. You just ignore it.
After the installation is completed, you can plug in the other network cables and the USB network interface. Then, reboot the MINIX Mini HD PC(s). One more important thing is that you should configure your router to either DHCP or static IP addresses. If you selected DHCP, make sure it is reserved for the monitor interfaces (that is the USB Gigabit network interfaces). The p2p1 and p4p1 do not have any IP address.
If everything correct, you can access to the monitor interfaces by using your browser, such as http://192.168.20.180. Enter your pre-set username and password when login. At the top right corner, select "Settings" to configure your time zone. Make sure you enter your password at "Current password (we need your current password to confirm your changes)" and then update the settings.
At this moment, your two MINIX Mini HD PC are in IDS mode. How to enable it to IPS mode?
How To Configure To IPS?
Log in to the MINIX Mini HD PC via ssh or terminal. Then run the following command to configure the DROP rules.
sudo nano /etc/pulledpork/dropsid.conf
I suggest to append the following lines at the end of the files. They will block most unwanted traffic.
# HTTP request header invalid
1:2221013
# HTTP missing host header
1:2221014
# masscan port scanner
1:2017615,1:2017616
# DOS possible ssdp amplification scan
1:2019102
# DoS attacks -- UDP & ICMP Invalid checksum & packet too small
1:2200075,1:2200038,1:2200076,1:2200024
# IP & TCP Invalid checksum
1:2200073,1:2200074
# TCP packet too small
1:2200033
# stream established retransmission packet before last ack
#1:2210021
# stream established packet out of window
#1:2210020
# GPL attack response id check returned root
1:2100498
# COMPROMISED & DROP & CINS Active Threats
pcre:ET\sCOMPROMISED
pcre:ET\sDROP
pcre:ET\sCINS
# MALWARE, TROJAN, WORM, MOBILE_MALWARE, Amplification DoS, DDoS
pcre:ET\sMALWARE
pcre:ET\sTROJAN
pcre:WORM
pcre:ET\sMOBILE_MALWARE
pcre:ET\sSCAN
#pcre:ET\sSHELLCODE
pcre:Amplification
pcre:ET\sDOS
pcre:ET\sEXPLOIT
pcre:ET\sUSER_AGENTS
pcre:ET\sWEB_SERVER
pcre:GPL\sSNMP
#pcre:SURICATA\sSTREAM
pcre:ET\sCURRENT_EVENTS
pcre:ET\sWEB_SPECIFIC_APPS
# Outgoing basic auth base64 http password
1:2006380
# Quantum Insert Attack (by NSA)
# (SURICATA STREAM reassembly overlap with different data - 2210050)
# (LOCAL QI 302 and possible inject - 12345)
# https://github.com/fox-it/quantuminsert/tree/master/detection/suricata
1:2210050,1:12345
# GPL WEB_SERVER 403 Forbidden
1:2101201
# ET POLICY Suspicious inbound to MSSQL port 1433
1:2010935
# ET POLICY Suspicious inbound to mySQL port 3306
1:2010937
*** Please remember that you may enable some already disabled rules by the captioned setting. If you encounter any false positive alert, you can disable such rule(s) by the following.
sudo nano /etc/pulledpork/disablesid.conf
Append the following at the end of the file, for example.
# TROJAN 1.1.1.1
1:2017000
# DELETED
pcre:ET\sDELETED
# MOBILE_MALWARE Google Android Device HTTP Request
1:2012251
# MALWARE WhenUClick.com Weather App Checkin (2)
1:2000915
# SURICATA STREAM alerts
#pcre:SURICATA\sSTREAM
# SURICATA STREAM
#1:2210000-1:2210049
#1:2210051-1:2210057
# SURICATA STREAM alert when downloading
1:2210021
1:2210020
1:2210029
1:2210045
1:2200074
1:2210038
1:2210044
# ET CURRENT_EVENTS Possible Dynamic DNS Exploit Pack
1:2014445
# ET WEB_SERVER WebShell
1:2016683
1:2016992
# ET TROJAN Possible Downadup/Conficker-C P2P encrypted traffic UDP Ping Packet (bit value 5)
1:2009207
1:2009205
1:2009208
# ET TROJAN UPX compressed file download possible malware
1:2001046
# ET TROJAN VMProtect Packed Binary Inbound via HTTP
1:2009080
# ET WEB_SERVER Fake Googlebot UA 1 Inbound
#1:2015526
After that, you can reload the rules by the following command.
sudo nsm_cronjob_rules_update
or
sudo nsm_rules_update
How To Delete All Testing Traffic?
It is very easy to delete all testing traffic if you want to. However, it only delete all the traffic in the Snorby and leave all other setting untouched.
sudo nsm_snorby_db_reinstall
In addtion, I also suggest you to install anti-virus program on your Windows boxes for play safe. Meanwhile, you can classified the traffic on Snorby too.
The last thing should inform you that you are recommend to set the QoS at your router. Otherwise, the bandwidth will be consumed by one of the connections.
How About Performance Tuning?
You can follow this guide to tune the IDS/IPS to make it running more smoothly.
To have a more secured IDS/IPS, you can append the following line to the "/etc/fstab".
ArpON (ARP handler inspection) is a portable handler daemon that make ARP protocol secure in order to avoid the Man In The Middle (MITM) attack through ARP Spoofing, ARP Cache Poisoning or ARP Poison Routing (APR) attacks. It blocks also the derived attacks by it, which Sniffing, Hijacking, Injection, Filtering & co attacks for more complex derived attacks, as: DNS Spoofing, WEB Spoofing, Session Hijacking and SSL/TLS Hijacking & co attacks.
Step 1 :
apt-get update
apt-get install arpon
Step 2 :
nano /etc/default/arpon
Uncomment the DARPI and RUN, makes it looking as :
You have tune the performance of your Kali Linux by this method. This method will use lesser SWAP as possible. Therefore, all the caches will be in the memory.
It can be dropped those caches when the caches are no longer use by the following method. It will drop the unused caches on every 15 minutes :
It is not effective to use "NoScript" Add-ons on Iceweasel as almost all web pages are using javascript. However, you still need "NoScript" for XSS protection on Iceweasel. You just need to allow it globally and XSS will still in force. To protect your browser from being compromised, an alternative way is to implement the Apparmor. Apparmor for Iceweasel can be used in penetration testing and daily use.
A content delivery network or content distribution network (CDN) is a large distributed system of servers deployed in multiple data centers across the Internet. The goal of a CDN is to serve content to end-users with high availability and high performance. CDNs serve a large fraction of the Internet content today, including web objects (text, graphics and scripts), downloadable objects (media files, software, documents), applications (e-commerce, portals), live streaming media, on-demand streaming media, and social networks.
Content providers such as media companies and e-commerce vendors pay CDN operators to deliver their content to their audience of end-users. In turn, a CDN pays ISPs, carriers, and network operators for hosting its servers in their data centers. Besides better performance and availability, CDNs also offload the traffic served directly from the content provider's origin infrastructure, resulting in possible cost savings for the content provider. In addition, CDNs provide the content provider a degree of protection from DoS attacks by using their large distributed server infrastructure to absorb the attack traffic. While most early CDNs served content using dedicated servers owned and operated by the CDN, there is a recent trend to use a hybrid model that uses P2P technology. In the hybrid model, content is served using both dedicated servers and other peer-user-owned computers as applicable.
When the websites are using CDN, such as Cloudflare, their IP addresses may be hidden. However, those IP addresses can be retrieved by the following methods :
Chameleon is an Open Source project by Samiux under GPLv3. Chameleon is developing based on NoCloudAllowed.
As same as NoCloudAllowed (Perl script), Chameleon (Python script) assumes that the target website is within an IP address range(s). The IP address range(s) of a certain country can be obtained via IP2Location. Once you get a CIDR list of the country, you need to extract it to the IP addresses list.
For the comparsion, you need an *unique* string from the target site. Once the string is found, the findings will be recorded in a file for further processing.
For extracting the IP addresses from CIDR list that obtained from IP2Location, I use prips. prips is not installed in Kali Linux by default.
Chameleon is well tested on Kali Linux 1.1.0 and Ubuntu 14.04 LTS.
Limitation
If the IP address and/or the domain is not pointed to the web root directory, Chameleon cannot find the site as expected. Do NOT set the "--thread" too large as it will consume all your RAM.
FEB 22, 2015 - Version 0.0.1 (sha1sum : c2a7af574e0132ab19a8597ded97c13b5f94dece chameleon-0.0.1.tar.gz)
[+] First release
FEB 25, 2015 - Version 0.0.2 (sha1sum : 8714d5a8ef8566ff6d36adbbbbfaee65bff8a728 chameleon-0.0.2.tar.gz)
[+] Add input file for the ip address comparison
[+] Add timeout option
[-] Drop the single ip address for comparison
FEB 26, 2015 - Version 0.0.3 (sha1sum : dab2486c72d2745075d06698be0f693254dae0da chameleon-0.0.3.tar.gz)
[+] Add exceptional error handling
[+] Add threading option
[+] Add output file option
[+] Add batch of IP address per thread option
Usage
Usage: chameleon.py [options]
Options:
-h, --help show this help message and exit
-s SEARCHSTRING, --string=SEARCHSTRING
specify the unique string to search
-f INFILE, --file=INFILE
input file contains ip addresses for comparison
-p PROTO, --proto=PROTO
protocol to use, http or https
-o TIMEOUT, --timeout=TIMEOUT
timeout, default 2 seconds
-t NUMTHREAD, --thread=NUMTHREAD
number of threading, default is 1
-w OUTFILE, --write=OUTFILE
output file for findings, default is find.txt
-b BATCH, --batch=BATCH
batch of IP address per thread, default is 1
Off-the-Record Messaging (OTR) is a cryptographic protocol that provides encryption for instant messaging conversations. OTR uses a combination of AES symmetric-key algorithm with 128 bits key length, the Diffie–Hellman key exchange with 1536 bits group size, and the SHA-1 hash function. In addition to authentication and encryption, OTR provides forward secrecy and malleable encryption.
The primary motivation behind the protocol was providing deniable authentication for the conversation participants while keeping conversations confidential, like a private conversation in real life, or off the record in journalism sourcing.
CPU : Intel i7-3930K
RAM : 32GB DDR3
Hard Drive : 3TB
Display Card : Two nVidia GeForce GTX 590
Install Kali
Install Kali Linux 1.1.0 on the box as usual. Make sure "secure boot" is disabled in your BIOS before installing. After that, you update the Kali accordingly.
After that, reboot your Kali. Then, we need to install bumblebee.
Step 2 :
apt-get install bumblebee-nvidia primus
If you need to support i386 architecture 3D software in 64-bit Kali, you may need to install the following :
dpkg --add-architecture i386
apt-get update
apt-get install bumblebee-nvidia primus primus-libs:i386
Step 3 :
Now, you need to add you (e.g. root) to the bumblebee group.
adduser $USER bumblebee
Step 4 :
To run your application with the discrete nVidia card :
optirun iceweasel
If optirun displays the following error :
[ERROR]Cannot access secondary GPU - error: Could not load GPU driver
You need to edit the following :
sed 's/KernelDriver=nvidia/KernelDriver=nvidia-current/g' -i /etc/bumblebee/bumblebee.conf
The following are optional :
If you want to run glxgears with the discrete nVidia card, you need to install VirtualGL
32-bit Kali Linux - wget http://sourceforge.net/projects/virtualgl/files/2.3.90%20%282.4beta1%29/virtualgl_2.3.90_i386.deb/download -O virtualgl_2.3.90_i386.deb
64-bit Kali Linux - wget http://sourceforge.net/projects/virtualgl/files/2.3.90%20%282.4beta1%29/virtualgl_2.3.90_amd64.deb/download -O virtualgl_2.3.90_amd64.deb
dpkg -i virtualgl_2.3.90_i386.deb
or h
dpkg -i virtualgl_2.3.90_amd64.deb
Then run :
optirun glxgears -info
or
optirun glxgears
The following are CUDA applications :
Please note that the Kali official does not recommend to compile applications yourself for Kali as they think that it would damage kali.
The next steps are to install cudaHashcat, john, Cryptohaze and pyrit.
(1) cudaHashcat installation
Grab the source code and extract it. The current version is 1.31 at this writing.
wget http://hashcat.net/files-legacy/cudaHashcat-1.31.7z
7za x cudahashcat-1.31.7z
(Please noted that the current version of cudaHashcat 1.32 does not compatible with Kali 1.1.0's nVidia 340.x driver).
Then run the sample scripts to test the cudahashcat by the following commands.
cd cudaHashcat-1.31
optirun ./cudaExample0.sh
optirun ./cudaExample400.sh
optirun ./cudaExample500.sh
When it is your first time to run cudaHashcat, you will be prompted for the license and you just answer "YES" to continue.
(2) John the Ripper Installation
Install the required package before going further.
apt-get install libssl-dev
Grab the current version of john (the current version at this writing is 1.8.0-jumbo-1) and compile it.
wget http://www.openwall.com/john/j/john-1.8.0-jumbo-1.tar.gz
tar -xvzf john-1.8.0-jumbo-1.tar.gz
cd john-1.8.0-jumbo-1/src
./configure
make clean
make
To run john, you can execute the following command.
cd ../run
optirun ./john --format=sha512crypt-cuda /etc/shadow
Please note that the captioned command will have fruitless result when your password is longer than 8 characters which is the default for john. If requires, you can make some changes on "params.h". However, it is out of the scope of this guide.
(3) Cryptohaze Installation
Grab the current version of Cryptohaze (the current version is 1.3a at this writing).
wget http://sourceforge.net/projects/cryptohaze/files/Cryptohaze-Linux_x64_1_31a.tar.bz2/download -O Cryptohaze-Linux_x64_1_31a.tar.bz2
tar xjvf Cryptohaze-Linux_x64_1_31a.tar.bz2
cd Cryptohaze-Linux
To perform the sample run, you can execute the following command.
Kali Linux 1.1.0 is released recently. Some bugs had been fixed and the performance is improved a lot.
However, you may encounter that you need to set the volume of the sound device every time when you boot up. You can solve this problem by the following :
apt-get install alsa-base alsa-utils
amixer sset Master unmute
Then adjust the volume when necessary.
Secondary, when your hard driver or SSD is fully encrypted, your GRUB screen is in blue. You can get the awesome Kali GRUB screen back by the following :
The GRUB screen is already Kali GRUB awesome screen.
Thirdly, OpenJDK 6 and 7 are installed in Kali Linux 1.1.0. However, only OpenJDK 6 (1.6.x) is enabled. If your application requires OpenJDK 7 (1.7.x), you need to enable it. You can :
update-alternatives --config java
Then select OpenJDK 7. I select 2 in my case.
Fourthly, Transmission is dropped in this version. You need to install yourself.
apt-get install transmission-gtk
Known Issue
If you are running virtual machine, such as Virtualbox or VMWare and the guest network interface is running on NAT and/or bridged mode, you cannot access internet on every boot up. You can issue the following command to gain internet access :
My friend has a Lenovo Thinkpad New X1 Carbon. However, the touchpad is malfunction and caused the system hang up. Fortunately, he followed this WiKi (except the "The syndaemon Helper", if included, you cannot login.) the problem is solved.
You should install rEFInd 0.8.5 on Mac Pro which is running OSX 10.10.2. Please follow the instruction on rEFInd for the installation. It is very simple and easy.
Insert your Ubuntu Desktop 14.04 LTS USB boot stick. Then, boot up Mac Pro without pressing any key. You will see a penguin icon and press it. You will then see a GRUB boot menu, press any arrow key as soon as possible. Move the highlight bar back to "Try Ubuntu without install". Press "e" and insert "nomodeset radeon.audio=1" between "splash" and "--". After that, press F10 to boot to Ubuntu Live mode.
At the Ubuntu Live mode, click the Install icon to install. When reaching the partition option, select customize. Make sure you do NOT delete the "EFI" partition. You can repartition the existing HFS+ partition or delete it to configure it to your desired Linux partitions, such as / and swap.
When the installation is completed, you will ask to continue testing or restart. Select "continue". Click to the hard drive icon on the left hand side menu bar. Your hard drive (SSD) is mounted. Go to /media/ubuntu/[a serial number]/boot/grub/grub.cfg. Locate the "splash" and insert "nomodeset radeon.audio=1" and the end of "splash". Do the same thing at /media/ubuntu/[a serial number]/etc/default/grub.
Now, you can reboot your Mac Pro. If everything going fine, you can boot to Ubuntu. After login, you should run "sudo update-grub" to update the GRUB.
At last, do NOT try to install the AMD Radeon proprietary drivers from the Ubuntu repository or AMD official site. It is because you will unable to go to the login screen after installing the proprietary drivers.
If you have two network interface cards, you can bond two interfaces together to increase the bandwidth (aka teaming). I am going to show you how to configure Mode 0 (balance-rr). You can do it on Ubuntu too.
The content should be looking as the following. Please note that the address, gateway and netmask may be different from yours.
Restart your network :
/etc/init.d/networking restart
or service networking restart
To confirm the bonding is working by the following commands :
The result of ifconfig will be looking like this.
Then we check the bonding interfaces.
Description of Bonding modes
Mode 0 - balance-rr
Round-robin policy: Transmit packets in sequential order from the first available slave through the last. This mode provides load balancing and fault tolerance.
Mode 1 - active-backup
Active-backup policy: Only one slave in the bond is active. A different slave becomes active if, and only if, the active slave fails. The bond's MAC address is externally visible on only one port (network adapter) to avoid confusing the switch. This mode provides fault tolerance. The primary option affects the behavior of this mode.
Mode 2 - balance-xor
XOR policy: Transmit based on selectable hashing algorithm. The default policy is a simple source+destination MAC address algorithm. Alternate transmit policies may be selected via the xmit_hash_policy option, described below. This mode provides load balancing and fault tolerance.
Mode 3 - broadcast
Broadcast policy: transmits everything on all slave interfaces. This mode provides fault tolerance.
Mode 4 - 802.3ad
IEEE 802.3ad Dynamic link aggregation. Creates aggregation groups that share the same speed and duplex settings. Utilizes all slaves in the active aggregator according to the 802.3ad specification.
Prerequisites:
Ethtool support in the base drivers for retrieving the speed and duplex of each slave.
A switch that supports IEEE 802.3ad Dynamic link aggregation. Most switches will require some type of configuration to enable 802.3ad mode.
Mode 5 - balance-tlb
Adaptive transmit load balancing: channel bonding that does not require any special switch support. The outgoing traffic is distributed according to the current load (computed relative to the speed) on each slave. Incoming traffic is received by the current slave. If the receiving slave fails, another slave takes over the MAC address of the failed receiving slave.
Prerequisites:
Ethtool support in the base drivers for retrieving the speed of each slave.
Mode 6 - balance-alb
Adaptive load balancing: includes balance-tlb plus receive load balancing (rlb) for IPV4 traffic, and does not require any special switch support. The receive load balancing is achieved by ARP negotiation. The bonding driver intercepts the ARP Replies sent by the local system on their way out and overwrites the source hardware address with the unique hardware address of one of the slaves in the bond such that different peers use different hardware addresses for the server.
Jeremy Cullen find another way the make bond0 to work on his DELL Poweredge 1950 :
Now, you need to add you (e.g. root) to the bumblebee group.
adduser $USER bumblebee
Step 5 :
To run your application with the discrete nVidia card :
optirun iceweasel
If optirun displays the following error :
[ERROR]Cannot access secondary GPU - error: Could not load GPU driver
You need to edit the following :
sed 's/KernelDriver=nvidia/KernelDriver=nvidia-current/g' -i /etc/bumblebee/bumblebee.conf
If you want to run glxgears with the discrete nVidia card, you need to install VirtualGL
32-bit Kali Linux - wget http://sourceforge.net/projects/virtualgl/files/2.3.90%20%282.4beta1%29/virtualgl_2.3.90_i386.deb/download -O virtualgl_2.3.90_i386.deb
64-bit Kali Linux - wget http://sourceforge.net/projects/virtualgl/files/2.3.90%20%282.4beta1%29/virtualgl_2.3.90_amd64.deb/download -O virtualgl_2.3.90_amd64.deb
dpkg -i virtualgl_2.3.90_i386.deb
or h
dpkg -i virtualgl_2.3.90_amd64.deb
Then run :
optirun glxgears -info
or
optirun glxgears
The next steps are to install cudaHashcat, john, Cryptohaze and pyrit.
(1) cudaHashcat installation
Grab the source code and extract it. The current version is 1.31 at this writing.
wget http://hashcat.net/files/cudaHashcat-1.31.7z wget http://hashcat.net/files-legacy/cudaHashcat-1.31.7z
7za x cudahashcat-1.31.7z
(Please noted that the current version of cudaHashcat 1.32 does not compatible with nVidia 340.x driver).
Then run the sample scripts to test the cudahashcat by the following commands.
cd cudaHashcat-1.31
optirun ./cudaExample0.sh
optirun ./cudaExample400.sh
optirun ./cudaExample500.sh
When it is your first time to run cudaHashcat, you will be prompted for the license and you just answer "YES" to continue.
(2) John the Ripper Installation
Install the required package before going further.
apt-get install libssl-dev
Grab the current version of john (the current version at this writing is 1.8.0-jumbo-1) and compile it.
wget http://www.openwall.com/john/j/john-1.8.0-jumbo-1.tar.gz
tar -xvzf john-1.8.0-jumbo-1.tar.gz
cd john-1.8.0-jumbo-1/src
./configure
make clean
make
To run john, you can execute the following command.
cd ../run
optirun ./john --format=sha512crypt-cuda /etc/shadow
Please note that the captioned command will have friutless result when your password is longer than 8 characters which is the default for john. If requires, you can make some changes on "params.h". However, it is out of the scope of this guide.
(3) Cryptohaze Installation
Grab the current version of Cryptohaze (the current version is 1.3a at this writing).
wget http://sourceforge.net/projects/cryptohaze/files/Cryptohaze-Linux_x64_1_31a.tar.bz2/download -O Cryptohaze-Linux_x64_1_31a.tar.bz2
tar xjvf Cryptohaze-Linux_x64_1_31a.tar.bz2
cd Cryptohaze-Linux
To perform the sample run, you can execute the following command.
The most simplest way to flash NetHunter is by using Windows application that provided by Offensive Security at here (the version at this writing is 1.1.6). You should follow the instructions on the screen to complete the task.
I select OnePlus One 64GB version as it comes with 3GB RAM and 64GB storage. It is running Cyanogen CM11 (version 4.4.4) ROM. It is very ideal for installing NetHunter in my own opinion. The current version of NetHunter does not support Android 5.0 and please do not try to flash onto it.
I am using MacBook Air with VMWare Fusion and Windows 8.1 guest to flash NetHunter. The Android USB driver provided by the captioned application cannot be installed automatically in my case. I need to install it manually via "Device Manager". Make sure two certifications (ADB and Fastboot) as well as the USB driver have been installed properly, the process will be very smooth.
If you do not have Windows machine or virtual machine available, you should follow the instructions mentioned in the official site. Make sure you root the device before doing so. This task will be very hard and more easy to run into mistakes. Make sure you have read the instructions on the official site completely and carefully before doing so. Therefore, I recommend not to use this method unless you need to.
After the NetHunter is flashed, you can optionally encrypt your OnePlus One. Before doing that, you should unmount the Kali by issue the following by using "Terminal Emulator" :
su -c killkali
Then reboot the OnePlus One. Once it is reboot, you can carrying out the phone encryption procedure.
After the encryption is completed, you need to re-mount the Kali by issue the following command :