<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Open Source Tools on Martin Gallo</title><link>https://martingallo.ar/publications/tools/</link><description>Recent content in Open Source Tools on Martin Gallo</description><generator>Hugo</generator><language>en-us</language><copyright>CC BY-SA 4.0 - Martin Gallo</copyright><atom:link href="https://martingallo.ar/publications/tools/index.xml" rel="self" type="application/rss+xml"/><item><title>Impacket</title><link>https://martingallo.ar/publications/tools/impacket/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/tools/impacket/</guid><description>&lt;h2 id="contribution"&gt;Contribution&lt;/h2&gt;&#10;&lt;p&gt;Between March 2021 and August 2022, I acted as the core maintainer of the&#10;project, accepting, reviewing and coding contributions, as well as leading one&#10;part-time security researcher dedicated as a developer of the project. I also&#10;personally contributed with several research and features to the project.&lt;/p&gt;&#10;&lt;p&gt;The project was later transferred to Fortra/Core Security in October 2022 which&#10;was my employer at that time.&lt;/p&gt;&#10;&lt;h2 id="description"&gt;Description&lt;/h2&gt;&#10;&lt;p&gt;Impacket is a collection of Python classes for working with network protocols.&#10;Impacket is focused on providing low-level programmatic access to the packets&#10;and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation&#10;itself. Packets can be constructed from scratch, as well as parsed from raw&#10;data, and the object-oriented API makes it simple to work with deep hierarchies&#10;of protocols. The library provides a set of tools as examples of what can be&#10;done within the context of this library.&lt;/p&gt;</description></item><item><title>pysap</title><link>https://martingallo.ar/publications/tools/pysap/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/tools/pysap/</guid><description>&lt;h2 id="contribution"&gt;Contribution&lt;/h2&gt;&#10;&lt;p&gt;pysap was authored as part of my&#10;&lt;a href="https://martingallo.ar/publications/talks/2012-07-26-uncovering-sap-vulnerabilities-defcon"&gt;intial research&lt;/a&gt;&#10;about the Diag protocol and published as an open source tool in July 2012. The&#10;tool was further expanded to cover other SAP&amp;rsquo;s network protocols and then file&#10;formats.&lt;/p&gt;&#10;&lt;p&gt;pysap was contributed to the OWASP CBAS Project in October 2022 by SecureAuth&#10;which was my employer at that time. It&amp;rsquo;s been actively maintained as part of the&#10;CBAS Project since that time.&lt;/p&gt;</description></item><item><title>HoneySAP</title><link>https://martingallo.ar/publications/tools/honeysap/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/tools/honeysap/</guid><description>&lt;h2 id="contribution"&gt;Contribution&lt;/h2&gt;&#10;&lt;p&gt;HoneySAP was authored during my research about SAP&amp;rsquo;s deception which was&#10;&lt;a href="https://martingallo.ar/publications/talks/2015-03-18-honeysap-who-really-wants-your-money"&gt;presented&lt;/a&gt;&#10;in March 2015.&lt;/p&gt;&#10;&lt;p&gt;HoneySAP was contributed to the OWASP CBAS Project in October 2022 by SecureAuth&#10;which was my employer at that time. It&amp;rsquo;s been actively maintained as part of the&#10;CBAS Project since that time.&lt;/p&gt;&#10;&lt;h2 id="description"&gt;Description&lt;/h2&gt;&#10;&lt;p&gt;HoneySAP is a low-interaction research-focused honeypot specific for SAP&#10;services. It&amp;rsquo;s aimed at learn the techniques and motivations behind attacks&#10;against SAP systems.&lt;/p&gt;</description></item><item><title>SAP Dissection plug-in for Wireshark</title><link>https://martingallo.ar/publications/tools/sap-wireshark-plugin/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://martingallo.ar/publications/tools/sap-wireshark-plugin/</guid><description>&lt;h2 id="contribution"&gt;Contribution&lt;/h2&gt;&#10;&lt;p&gt;SAP Dissection plug-in was authored as part of my&#10;&lt;a href="https://martingallo.ar/publications/talks/2012-07-26-uncovering-sap-vulnerabilities-defcon"&gt;intial research&lt;/a&gt;&#10;about the Diag protocol and published as an open source tool in July 2012. The&#10;tool was further expanded to cover other SAP&amp;rsquo;s network protocols.&lt;/p&gt;&#10;&lt;p&gt;SAP Dissection plug-in was contributed to the main Wireshark project in October&#10;2022 by SecureAuth which was my employer at that time. The dissectors are now&#10;part of the core dissection library and been actively maintained by the&#10;Wireshark Foundation community.&lt;/p&gt;</description></item></channel></rss>