<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>data analysis Archives - Tech Chronicles</title>
	<atom:link href="http://kostacipo.stream/tag/data-analysis/feed/" rel="self" type="application/rss+xml" />
	<link>https://kostacipo.stream/tag/data-analysis/</link>
	<description>Ramblings of a Tech Dude</description>
	<lastBuildDate>Wed, 11 Nov 2020 20:38:21 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>

<image>
	<url>https://kostacipo.stream/wp-content/uploads/2019/12/cropped-profile-32x32.jpg</url>
	<title>data analysis Archives - Tech Chronicles</title>
	<link>https://kostacipo.stream/tag/data-analysis/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>NoSQLi &#8211; A Fast NoSQL Injection Scanner</title>
		<link>http://kostacipo.stream/nosqli-a-fast-nosql-injection-scanner/</link>
					<comments>http://kostacipo.stream/nosqli-a-fast-nosql-injection-scanner/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Wed, 11 Nov 2020 20:38:21 +0000</pubDate>
				<category><![CDATA[Data]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Vulnerability Analysis]]></category>
		<category><![CDATA[data analysis]]></category>
		<category><![CDATA[nosqli]]></category>
		<guid isPermaLink="false">http://www.kostacipo.stream/?p=1879</guid>

					<description><![CDATA[<p>&#160; nosqli was developed as an open source NoSQL scanner written in Go. It&#8217;s configurable with command line options, and runs a large number of injection attempts against targets. It&#8217;s mostly focused on Mongo injections, but does work to a lesser extent against any database that uses JavaScript. $ nosqli NoSQLInjector is a CLI tool [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/nosqli-a-fast-nosql-injection-scanner/">NoSQLi &#8211; A Fast NoSQL Injection Scanner</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<header class="post-header">
<div class="post-header-wrap">&nbsp;</div>
</header>
<section class="post-wrapper">
<section class="post-content"><a href="https://github.com/Charlie-belmer/nosqli">nosqli</a> was developed as an open source NoSQL scanner written in Go. It&#8217;s configurable with command line options, and runs a large number of injection attempts against targets. It&#8217;s mostly focused on Mongo injections, but does work to a lesser extent against any database that uses JavaScript.</p>
<pre class=" language-bash"><code class=" language-bash">$ nosqli
NoSQLInjector is a CLI tool <span class="token keyword">for</span> testing Datastores that 
<span class="token keyword">do</span> not depend on SQL as a query language. 

nosqli aims to be a simple automation tool <span class="token keyword">for</span> identifying and exploiting 
NoSQL Injection vectors.

Usage:
  nosqli <span class="token punctuation">[</span>command<span class="token punctuation">]</span>

Available Commands:
  <span class="token function">help</span>        Help about any <span class="token function">command</span>
  scan        Scan endpoint <span class="token keyword">for</span> NoSQL Injection vectors
  version     Prints the current version

Flags:
      --config string       config <span class="token function">file</span> <span class="token punctuation">(</span>default is <span class="token variable">$HOME</span>/.nosqli.yaml<span class="token punctuation">)</span>
  -d, --data string         Specify default post data <span class="token punctuation">(</span>should not include any injection strings<span class="token punctuation">)</span>
  -h, --help                <span class="token function">help</span> <span class="token keyword">for</span> nosqli
  -p, --proxy string        Proxy requests through this proxy URL. Defaults to HTTP_PROXY environment variable.
  -r, --request string      Load <span class="token keyword">in</span> a request from a file, such as a request generated <span class="token keyword">in</span> Burp or ZAP.
  -t, --target string       target url eg. http://site.com/page?arg<span class="token operator">=</span>1
  -u, --user-agent string   Specify a user agent

Use <span class="token string">"nosqli [command] --help"</span> <span class="token keyword">for</span> <span class="token function">more</span> information about a command.

$ nosqli scan -t http://localhost:4000/user/lookup?username<span class="token operator">=</span>test
Running Error based scan<span class="token punctuation">..</span>.
Running Boolean based scan<span class="token punctuation">..</span>.
Found Error based NoSQL Injection:
  URL: http://localhost:4000/user/lookup?<span class="token operator">=</span><span class="token operator">&amp;</span>username<span class="token operator">=</span>test
  param: username
  Injection: username<span class="token operator">=</span>'
</code></pre>
<h2 id="using-nosqli">Using NoSQLi</h2>
<figure class="kg-card kg-image-card kg-card-hascaption"><img decoding="async" class="kg-image" src="https://nullsweep.com/content/images/2020/09/nosqli_demo_nosql_injection_scan.gif" alt=""><figcaption>nosql scanning using nosqli</figcaption></figure>
<p>It has a simple and flexible CLI interface for scanning. You can pass in a target URL with GET parameters that need to be scanned, or a saved request with POST data. The scanner is smart enough to know if the data is JSON or form data, and will inject either way.</p>
<p>The configurations currently support running through a proxy (so you can view the generated traffic in Burp or similar software) and changing the user agent.</p>
<h2 id="scanning-types">Scanning Types</h2>
<p>NoSQLi has the most commonly found injection vectors implemented:</p>
<ol>
<li><strong>Error Scans: </strong>Look for known error strings in responses from the server.</li>
<li><strong>Blind Boolean Injections</strong>: When the page doesn&#8217;t return errors, but does return different data when <code>true</code> or <code>false</code> is returned from the database (or when some records are retrieved vs. no records)</li>
<li><strong>Timing based injections</strong>: When all else fails, if the database sends a delayed response after a successful injection.</li>
</ol>
<h2>&nbsp;</h2>
<h2 id="using-nosqli-with-requests">Using NoSQLi with Requests</h2>
<p>A key feature missing from a few previous scanners was the ability to export a request from a proxy and run the injections based on that. NoSQLi can leverage this easily, and keeps all the header information, including things like user agent.</p>
<p>While the tool does not yet support importing a full session log and executing tests against all requests sequentially, saving a standard HTTP request to a file and referencing that file allows repeatable tests, or extraction from other tools such as Burp.</p>
<h2 id="installing-nosqli">Installing NoSQLi</h2>
<p>The <a href="https://github.com/Charlie-belmer/nosqli">github page</a> has all the instructions. You can build from source or download and run the appropriate <a href="https://github.com/Charlie-belmer/nosqli/releases">executable</a> for your system.</p>
</section>
</section>
<p>The post <a href="http://kostacipo.stream/nosqli-a-fast-nosql-injection-scanner/">NoSQLi &#8211; A Fast NoSQL Injection Scanner</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/nosqli-a-fast-nosql-injection-scanner/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Nfstream &#8211; A Flexible Network Data Analysis Framework</title>
		<link>http://kostacipo.stream/nfstream-a-flexible-network-data-analysis-framework/</link>
					<comments>http://kostacipo.stream/nfstream-a-flexible-network-data-analysis-framework/#respond</comments>
		
		<dc:creator><![CDATA[Majordomo]]></dc:creator>
		<pubDate>Fri, 07 Feb 2020 10:29:59 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Data]]></category>
		<category><![CDATA[Hacks]]></category>
		<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[data analysis]]></category>
		<category><![CDATA[network]]></category>
		<guid isPermaLink="false">http://www.kostacipo.stream/?p=1745</guid>

					<description><![CDATA[<p>&#160; nfstream is a Python package providing fast, flexible, and expressive data structures designed to make working with online or offline network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, real world network data analysis in Python. Additionally, it has the broader goal of becoming a [&#8230;]</p>
<p>The post <a href="http://kostacipo.stream/nfstream-a-flexible-network-data-analysis-framework/">Nfstream &#8211; A Flexible Network Data Analysis Framework</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>&nbsp;</p>
<p><strong>nfstream</strong> is a Python package providing fast, flexible, and expressive data structures designed to make working with <strong>online</strong> or <strong>offline</strong> network data both easy and intuitive. It aims to be the fundamental high-level building block for doing practical, <strong>real world</strong> network data analysis in Python. Additionally, it has the broader goal of becoming <strong>a common network data processing framework for researchers</strong> providing data reproducibility across experiments.<br /><a name="more"></a><br /><b>Main Features</b></p>
<ul>
<li><strong>Performance:</strong> <strong>nfstream</strong> is designed to be fast (x10 faster with pypy3 support) with a small CPU and memory footprint.</li>
<li><strong>Layer-7 visibility:</strong> <strong>nfstream</strong> deep packet inspection engine is based on <a title="a flexible network data analysis framework. (15)" href="https://github.com/ntop/nDPI" target="_blank" rel="nofollow noopener noreferrer"><strong>nDPI</strong></a>. It allows nfstream to perform <a title="a flexible network data analysis framework. (16)" href="http://people.ac.upc.edu/pbarlet/papers/ground-truth.pam2014.pdf" target="_blank" rel="nofollow noopener noreferrer"><strong>reliable</strong></a> encrypted applications identification and metadata extraction (e.g. TLS, QUIC, TOR, HTTP, SSH, DNS).</li>
<li><strong>Flexibility:</strong> add a flow feature in 2 lines as an <a title="a flexible network data analysis framework. (18)" href="https://nfstream.readthedocs.io/en/latest/plugins.html" target="_blank" rel="nofollow noopener noreferrer"><strong>NFPlugin</strong></a>.</li>
<li><strong>Machine Learning oriented:</strong> add your trained model as an <a title="a flexible network data analysis framework. (19)" href="https://nfstream.readthedocs.io/en/latest/plugins.html" target="_blank" rel="nofollow noopener noreferrer"><strong>NFPlugin</strong></a>.</li>
</ul>
<p><b>How to use it?</b></p>
<ul>
<li>Dealing with a big pcap file and just want to aggregate it as network flows? <strong>nfstream</strong> make this path easier in few lines:</li>
</ul>
<div>
<pre><code>   from nfstream import NFStreamer
   my_awesome_streamer = NFStreamer(source="facebook.pcap") # or network interface (source="eth0")
   for flow in my_awesome_streamer:
       print(flow)  # print it, append to pandas Dataframe or whatever you want :)!</code></pre>
</div>
<div>
<pre><code>    NFEntry(
        id=0,
        first_seen=1472393122365,
        last_seen=1472393123665,
        version=4,
        src_port=52066,
        dst_port=443,
        protocol=6,
        vlan_id=0,
        src_ip='192.168.43.18',
        dst_ip='66.220.156.68',
        total_packets=19,
        total_bytes=5745,
        duration=1300,
        src2dst_packets=9,
        src2dst_bytes=1345,
        dst2src_packets=10,
        dst2src_bytes=4400,
        expiration_id=0,
        master_protocol=91,
        app_protocol=119,
        application_name='TLS.Facebook',
        category_name='SocialNetwork',
        client_info='facebook.com',
        server_info='*.facebook.com',
        j3a_client='bfcc1a3891601edb4f137ab7ab25b840',
        j3a_server='2d1eb5817ece335c24904f516ad5da12'
    )</code></pre>
</div>
<ul>
<li>From pcap to Pandas DataFrame?</li>
</ul>
<div>
<pre><code>    import pandas as pd 
    streamer_awesome = NFStreamer(source='devil.pcap')
    data = []
    for flow in streamer_awesome:
       data.append(flow.to_namedtuple())
    my_df = pd.DataFrame(data=data)
    my_df.head(5) # Enjoy!</code></pre>
</div>
<ul>
<li>Didn&#8217;t find a specific flow feature? add a plugin to <strong>nfstream</strong> in few lines:</li>
</ul>
<div>
<pre><code>    from nfstream import NFPlugin

    class my_awesome_plugin(NFPlugin):
        def on_update(self, obs, entry):
            if obs.length &gt;= 666:
                entry.my_awesome_plugin += 1
  
   streamer_awesome = NFStreamer(source='devil.pcap', plugins=[my_awesome_plugin()])
   for flow in streamer_awesome:
      print(flow.my_awesome_plugin) # see your dynamically created metric in generated flows</code></pre>
</div>
<ul>
<li>More example and details are provided on the official <a title="a flexible network data analysis framework. (20)" href="https://readthedocs.org/projects/nfstream/downloads/pdf/latest/" target="_blank" rel="nofollow noopener noreferrer"><strong>documentation</strong></a>.</li>
</ul>
<p><b>Prerequisites</b></p>
<div>
<pre><code>    apt-get install libpcap-dev</code></pre>
</div>
<p><b>Installation</b></p>
<p><b>Using pip</b><br />Binary installers for the latest released version are available:</p>
<div>
<pre><code>    pip3 install nfstream</code></pre>
</div>
<p><b>Build from source</b><br />If you want to build <strong>nfstream</strong> on your local machine:</p>
<div>
<pre><code>    git clone https://github.com/aouinizied/nfstream.git
    cd nfstream
    python3 setup.py install</code></pre>
</div>
<p><b>Contributing</b><br />Please read <a title="a flexible network data analysis framework. (21)" href="https://nfstream.readthedocs.io/en/latest/contributing.html" target="_blank" rel="nofollow noopener noreferrer"><strong>Contributing</strong></a> for details on our code of conduct, and the process for submitting pull requests to us.</p>
<p><b>Authors</b><br /><a title="a flexible network data analysis framework. (22)" href="https://www.linkedin.com/in/dr-zied-aouini" target="_blank" rel="nofollow noopener noreferrer"><strong>Zied Aouini</strong></a> created <strong>nfstream</strong> and <a title="a flexible network data analysis framework. (23)" href="https://github.com/aouinizied/nfstream/graphs/contributors" target="_blank" rel="nofollow noopener noreferrer"><strong>these fine people</strong></a> have contributed.</p>
<p><b>Ethics</b><br /><strong>nfstream</strong> is intended for network data research and forensics. Researchers and network data scientists can use these framework to build reliable datasets, train and evaluate network applied machine learning models. As with any packet monitoring tool, <strong>nfstream</strong> could potentially be misused. <strong>Do not run it on any network of which you are not the owner or the administrator</strong>.</p>
<p><b><a class="kiploit-download" title="Download Nfstream" href="https://github.com/aouinizied/nfstream" target="_blank" rel="nofollow noopener noreferrer">Download Nfstream</a></b></p>
<p>The post <a href="http://kostacipo.stream/nfstream-a-flexible-network-data-analysis-framework/">Nfstream &#8211; A Flexible Network Data Analysis Framework</a> appeared first on <a href="http://kostacipo.stream">Tech Chronicles</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>http://kostacipo.stream/nfstream-a-flexible-network-data-analysis-framework/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
