Tuesday, March 3, 2015

Random numbers

See the randomness of C++ generated random numbers by providing a fixed seed and a random seed.  Gather the numbers in may trials and chart the results.  Charts will give you an easier way to identify patterns to evaluate the randomness.  You should modify this code to write the values to a file and import them into Excel or OO Calc to chart.

Basic steps for file implementation:
#import<fstream>

ofstream outFile;
outfile.open("output.txt");
outfile<<zero<<one<<two<<three<<four<<endl;
outfile.close();

More details:
http://intro2cs-cpp.blogspot.com/2015/03/simple-file-io.html

Code to test randomness:
//Name: <Your Name>
//Class: 2012 Fall - COSC 1415/1436.8002
//Project 0: Random Number
//Revision: 1.0
//Date: 08/15/2012
//Description: This program show the concept of random  number generation

#include <iostream>   //string input/output header file
#include<time.h>

using namespace std;  //standard class library

int main(){
  srand ( time(NULL) );         //replace the seed with a fixed number a see the effects
  int zero=0,one=0, two=0, three=0, four=0;
for(int i=0;i<10000;i++){
  Richland = rand() % 5;
  switch(Richland){
  case 0:  zero++;   break;
  case 1:  one++;    break;
  case 2:  two++;    break;
  case 3:  three++;  break;
  case 4:  four++;   break;
  }
}
cout<<"The value of zeroes: "<<zero<<endl;
cout<<"The value of ones: "<<one<<endl;
cout<<"The value of twos: "<<two<<endl;
cout<<"The value of threes: "<<three<<endl;
cout<<"The value of fours: "<<four<<endl;

  system("pause");                           //pause the program so I can read the console 
  return 0;                                  //return 0 to show end of execution 
}

Monday, March 2, 2015

Simple File I/O

This code should give you a simple recipe type of instruction to learn how to handle file input and output operations.  The biggest challenge is to understand your file system navigation with Windows Explorer and the location of your source files.

Create an input file with a simple editor like Notepad.exe and make sure you know where you save the input file to.  Do not use spaces in creating the input file name.  also, understand the input file name does not have to match the ifstream variable name.  You can name your input file anything you'd like, just type the same file name when you open the file in your code.

In this example, the input_file.txt content is 92A98.76.

Start with a skeleton program like this one and place your pseudo code into the skeleton program as comments.

Write pseudo code 
1. Include strings in case if we need to specify a string for a file name
2. This library is needed for handling file input and output,  ifstream, ofstream
    Declare variables to store data read from file
3. Declare input file variable
4. Declare output file variable
4.1 Make sure there is an input file with proper data ( read only ) and your userID has write access to output location
5. Open input and output files.  The input file should be placed on the same path with your source code.  The output file will be written into the same path as your source code.
     if you need to specify a path to the file, escape the backslash
6. Use filestream variables like we use iostream variables
7. Close input and output files

Create actual skeleton program with pseudo code copied in as comments

#include <iostream> //cin, cout, endl

 //1. include strings in case if we need to specify a string for a file name
 //2. this library is needed for handling file input and output,  ifstream, ofstream


using namespace std;

int main()
{
//Declare variables to store data read from file
   
//3. declare input file variable

//4. declare output file variable

//4.1 make sure there is an input file with proper data ( read only ) and your userID has write access to output location

//5. open input and output files.  The input file should be placed on the same path with your source code.  The output file will be written into the same path as your source code.
     //if you need to specify a path to the file, escape the backslash

//6. use filestream variables like we use iostream variables
    //cin >> x >> grade >> y;

    /*    cout << "Your test score is: " << x << endl;
        cout << "Your letter grade is: " << grade << endl;
        cout << "Your class average is" << y << endl;        */

//7. close input and output files


    return 0;
}

Complete the code by first writing the cin/cout way of reading and printing values and change that to ifstream and ofstream variables later.

#include <iostream> //cin, cout, endl

#include <string>  //1. include strings in case if we need to specify a string for a file name
#include <fstream> //2. this library is needed for handling file input and output
                   //   ifstream, ofstream

using namespace std;

int main()
{
//Declare variables to store data read from file
    char grade;
    int x;
    float y;
   
//3. declare input file variable
    ifstream inFile;

//4. declare output file variable
    ofstream outFile;

//4.1 make sure there is an input file with proper data ( read only ) and your userID has write access to
     // output location


//5. open input and output files
    inFile.open("c:\\dell\\input_file.txt");  //if you need to specify a path to the file, escape the backslash
    outFile.open("c:\\temp\\output.txt");

//6. use filestream variables like we use iostream variables
    //cin >> x >> grade >> y;

    inFile >> x >> grade >> y;

    /*    cout << "Your test score is: " << x << endl;
        cout << "Your letter grade is: " << grade << endl;
        cout << "Your class average is" << y << endl;        */
   

    outFile << "Your test score is: " << x << endl;
    outFile << "Your letter grade is: " << grade << endl;
    outFile << "Your class average is" << y << endl;

//7. close input and output files
    inFile.close();
    outFile.close();

    return 0;
}

Compile the code by placing break points before and after the read operations.  Read the values for the variables before and after the read operations to identify problems with your input file.  Note: Later on, we'll learn how to validate input and code proper exit if the input or output files can not be manipulated.

if(!inFile){                                                              //validate input
    cout<<"Input file can not be located!"<<endl;
    return 2;                         //return a value to indicate error condition                                                  
}

if(!outFile){                                                             //validate output
    cout<<"You do not have enough space to store the output or you do not have right to write output at this location!"<<endl;
    return 4;                        //return a different value to indicate error condition

}

Read file into a c_string one line at a time.

ifstream inFile;
inFile.open("input.txt");
const int SIZE = 30;
 

if (!inFile){
     cout << "Input file was not found.";
     return 2;
}
 

char lineRead[SIZE];

while (!inFile.eof()){                                         //check to see if the end of the file is reached
          inFile.getline(lineRead, SIZE-1, '\n');
          cout << lineRead << endl;
}
 

inFile.close();

Read lines in a loop and make sure the first line is not empty before entering the loop.

    ifstream inFile;
    inFile.open("input.txt");
    const int SIZE = 30;
    if (!inFile){
        std::cout << "Input file was not found.";
        return 2;
    }
    char lineRead[SIZE];
    inFile.getline(lineRead, SIZE - 1, '\n');
    while (!inFile.eof() && lineRead[0]!='\0'){    //

        std::cout << lineRead << endl;
        //for (char ch : lineRead) cout << ch << endl;           //if you want to see each character read
        inFile.getline(lineRead, SIZE - 1, '\n');
    }
    inFile.close();

Sunday, February 22, 2015

Getting started

What is the output of string INSTITUTION = "Richland \rCollege"; ?  There is also a major implementation problem with this code that you should be able to find it easy.

//Project 0: Hello World
//Revision: 1.0
//Date: 08/15/2011
//Description: Chapter 2 Summary

#include <iostream>
#include <string>
#include <math.h>
#include"header.h"

using namespace std;
using namespace richland;

int main(){

    string INSTITUTION = "Richland \rCollege";
    cout << INSTITUTION << endl;

    float PI = 3.14E0;
    cout << PI << endl;

    int value = -200;

    cin >> celsius>>value;

    fahrenheit = (float)((celsius)*(9 / 5) + 32);

    cout << fahrenheit<< endl;

    float ans = (fahrenheit - 32)*(5 / 9);

    cout << ans << endl;

    char ch = 'A';
    cout << "The \"value\" is: " <<ch<< endl;
    cout << "The value is: " << ch+1 << endl;
    cout << "The value is: " << static_cast<char>(ch+1)<< endl;

    string hello = "Hello";

    hello[3] = 'p';

    cout << "The \nstring \tis: " << hello << endl;

    return 0;
}

Pattern recognition and simple applications

You can use system("pause"); to call the pause utility in Windows systems to pause your program execution, but not many students realize that you can call other applications from C++ using this system call and have a useful application quickly.

Like translating with Google translate only requires you to look at the URL when you translate something and recognize the pattern in the URL.  You should see that you format the URL string as /#source_language/destination_language/text_to_translate.

Thus, in this example you are translating from German to English and launch Firefox to display the results.


//Required libraries
‪#‎include‬<iostream> //cin, cout, endl
#include<string> //string

//Namespace specified to avoid using std:: with cin, cout, endl, ...
using namespace std;

int main(int argc, char* argv[]){
      string program = "\"C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe\"  
                                  https://translate.google.com/#de/en/ich%20bin%20ein%20kinder";
      char* prog;
      prog = &program[0];
      system(prog);                         //The magic happens here
      return 0;                                 //return integer data type to OS to indicate errorlevel
}


Look up information about an IP address.

// exceptions
#include <iostream>
#include <string>


using namespace std;
void printMe(string url){
    cout << url << endl;
    system(&url[0]);
}

int main() {
    string url = "start \"C:\\Program\ Files\ \(x86\)\\Google\\Chrome\\Application\\Chrome.exe\"\ \"http\://144\.162\.1\.180\.ipaddress\.com/#reverseip\"";
    printMe(url);

    return 0;
}


Map a location using Google maps and the location's GPS coordinates.

#include <iostream>
using namespace std;

int main()
{
    //Call Chrome browser and open a GPS coordinate
    system("\"C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe\" HTTP://MAPS.GOOGLE.COM/?q=32.921763,-96.729206");
       
    return 0;
}

Experiment with other useful application of this simple system call and go beyond what you use it for in standard applications.  Don't be afraid of creating something new and useful even if it looks simple.

Friday, November 21, 2014

Back to basics - Develop Forensic Analyst Mindset

This is a must watch video and must play game in order to even get started in developing an investigative mindset that is essential in incident response and cybersecurity investigations.

You can not just read about cybersecurity, you need to start developing skills, but will see that even basic skills an be challenging as you start using those skills in real environments.

This video will also show you that basic encoding can also be used by actual applications to store passwords.  It will also show you how Base64 works and how important log analysis is in this field.

http://youtu.be/9sGhmYlBrXU


Monday, October 27, 2014

Back to basics - Convert ICS to HTML and CSV

The discreet nature of calendar entries make seeing the over all picture or in investigations seeing a pattern of events is very difficult.  We need to be able to see the events in chronological order in a single document that we can use as a report or chart the values for easy understanding of events for non-technical professionals.

One of the most useful and versatile applications when it comes to Internet communication.  In this blog, I will explore the capability of this tool to convert .ics files, that is the only format that Google Calendar exports.

I also created a video to accommodate this blog post: http://youtu.be/WbBRhP6VXbs

So, in order to follow this process, you need to download and install Thunderbird, https://www.mozilla.org/en-US/thunderbird/download.

Login to your Google Calendar and create a new calendar.

Add new schedules to the new calendar and export the calendar as an .ics file.  Notice in the exported .ics file below the date and time stamps are not very user friendly to read, so it might need to be manually converted to make sense to non-technical professionals.  On the other hand, the HTML and CSV exported files below show the date and time stamps displayed in user friendly format that is easy to report and charted for easy interpretation without any manual conversion or risk of human error.


Import the .ics file into Thunderbird's Lightning add-on, that adds the calendar feature to Thunderbird.

Export the calendar as .ics, .html, or .csv format.


The HTML document can be directly used as a report, but the CSV format gives more flexibility to analyze the data or create chart to show clear patterns of events. 



Thus, digital forensics is about pattern recognition, but pattern can not emerge in some cases in its native format.  So, we need to focus on software capability to import certain file types and explore applications capability to export the data into different format that can aid our analysis and help identify patterns to solve cases.  

Back to basics - SQL and XSS

This post is accompanied by a video explaining this process and you can do about it.

http://youtu.be/-W3efiMT8H0

Sample web page to test Javascipts in browser.  Save the following code in a text file, name it test.html ad open it in your browser to see what it does.

<HTML>
<HEAD>>
              <script> window.open('http://zoltandfw.blogspot.com/','_blank')</script>
              <script> alert(document.cookie)</script>
              <script> alert("Your account has been compromised, please call (111)222-3333 to report!!!")               </script>
</HEAD>
<BODY>
              Just a test for JavaScripts
</BODY>
</HTML>

Sample log file entries showing details on what information might be collected in log files to investigate after the fact or monitor for real-time response.  

141027  7:39:45  122 Connect root@localhost on 
 122 Init DB badbank
 122 Query SELECT userid, accountnumber FROM badbank_accounts WHERE username='zoltan' AND password='9f1c050c2b226c2154d17a3ff9a602f6'
 122 Quit
141027  7:41:55  123 Connect root@localhost on 
 123 Init DB badbank
 123 Query SELECT userid, accountnumber FROM badbank_accounts WHERE username='zoltan' -- ' AND password='d41d8cd98f00b204e9800998ecf8427e'
 123 Quit
141027  8:00:30  124 Connect root@localhost on 
 124 Init DB badbank
 124 Quit
 125 Connect root@localhost on 
 125 Init DB badbank
 125 Quit
141027  8:42:47  126 Connect ODBC@localhost as  on 
 126 Query select @@version_comment limit 1
141027  8:42:55  126 Query show databases
141027  8:43:26  126 Query SELECT DATABASE()
 126 Init DB Access denied for user ''@'localhost' to database 'badbank'
141027  8:43:41  126 Quit

...

141027  9:04:20  130 Query select * from badbank_transactions
141027  9:05:22  213 Connect root@localhost on 
 213 Init DB badbank
 213 Query SELECT balance FROM badbank_accounts WHERE userid=61
 213 Quit
141027  9:05:37  214 Connect root@localhost on 
 214 Init DB badbank
 214 Query SELECT balance FROM badbank_accounts WHERE userid=61
 214 Query SELECT userid FROM badbank_accounts WHERE username='victim1'
 214 Query UPDATE badbank_accounts SET balance=balance-1 WHERE userid=61
 214 Query UPDATE badbank_accounts SET balance=balance+1 WHERE userid=60
 214 Query INSERT INTO badbank_transactions (userid,time,withdrawn,transactor,transfernote) VALUES (61,NOW(),1,60,'<script> alert(document.cookie)</script>')
 214 Query INSERT INTO badbank_transactions (userid,time,deposited,transactor,transfernote) VALUES (60,NOW(),1,61,'<script> alert(document.cookie)</script>')
 214 Quit
141027  9:05:41  215 Connect root@localhost on 
 215 Init DB badbank
 215 Quit
 216 Connect root@localhost on 
 216 Init DB badbank
 216 Quit