Search

Helping developers and enterprises secure their code is what we do. Got a project, an RFP, or just some questions? Let us know!

info(at)matasano.com
1-888-677-0666 x0

Playbook is our product. It does firewall sync. To learn more about Playbook, check out the site, or get in touch with us via the web, e-mail, or phone.

playbook(at)matasano.com
1-888-677-0666 x7529 (PLAY)

« A Working Theory About RC4 | Main | The Security Implications Of Google Native Client »
Thursday
Aug272009

Matasano PFI (as seen on TV!)

Do you ever find yourself on a reversing or pen-testing project with the need to peek into a TCP stream and modify a little bit of data?

Do you find yourself annoyed,  feeling that you’ve hacked together code to do this many times before, but simply can’t find it?

Do you find yourself hobbling together other tools to do what you need? Do you find yourself wishing you had a Burp for raw TCP connections?

No MORE! Using Matasano’s Port Forwarding Interceptor you have the tool you need right at your fingertips! Lets take a closer look at this exciting new tool shall we? 

Let’s say you are watching your favorite 15 minute ANSI art rendition of Star Wars on telnet://towel.blinkenlights.nl . You think to yourself:

“Man I sure wish I could get in-between my telnet client and the server and begin reversing this Star Wars protocol”.

Then you remember you got Matasano’s PFI off of Github earlier today!

You take a look at the usage and it seems pretty self explanatory…

So then you decide to try it out by running something like this:

(This sets up PFI as a TCP port forward listening on the loopback interface on port 23 and forwarding traffic to towel.blinkenlights.nl on port 23, but you knew that already of course, thats why you ran it…)

You are then greeted by the comforting and familiar PFI GUI windows. And hey, you didn’t even have to install any weird python modules or dependencies!

You take a minute to notice how simple and self-explanatory it all is. One window displays the intercepted text, and allows you to choose whether to intercept. The other window allows you to edit the intercepted data before it is passed on through the tunnel. How easy! It is like a “Burp” for raw TCP!

You then decide to try it out by connecting through the tunnel:

And begin watching your ANSI art show:

So the tunnel works! You look back at your PFI main window and see that data is in fact passing through PFI.

You select the “Intercept” check boxes and begin intercepting and editing data across the tunnel.

And as you begin reversing the complex  ANSI Star Wars protocol you cant help but feel yourself awash with gratitude that Matasano PFI saved you the trouble of having to dig out all your old scripts and programs. You give your monitor a thumbs up and say: “Thanks PFI!”

Then you remember that Matasano Blackbag also had a similar tool (called replug) and then you feel silly, not just about neglecting Blackbag but also that you gave your monitor a thumbs up.

References (4)

References allow you to track sources for this article, as well as articles that were written in response to this article.
  • Response
    We see a lot of fun hiding spots for javascript at the StopBadware office as we process webmaster appeals. Last week we realized something that the Matasano team stated in their recent blog entry for their new testing tool: debugging tools aren't al
  • Response
    As an Art Director, I don't feel inspired by this system at all. I applaud the effort, and it's admirable to spend so much time pro- bono. I like the banners, they look great. But as everyone else has mentioned it's far too trendy. Please don't pimp this logo out with ...
  • Response
    Keeps your remotes handy and under your control.
  • Response
    Response: Guygetsgirl
    The schoolgirl in pigtails has been naughty and she’ s in the principal’ s office ready to receive her punishment. It turns out that the administrator is a naughty babe too and she wants to experience the pleasure of a teen slut. Thus she punishes the girl by making her get ...

Reader Comments (52)

Well thanks for the 10 lines of code it takes to do a poll loop on an in/out connection (aka simple tcp proxy loop) that halts for buffer editing on every iteration. Good work.

August 28, 2009 | Unregistered Commenterawesome

Sorry but i could not download your PFI tool neither the blackbah suite.
thanks

August 28, 2009 | Unregistered Commenterm00dy

Juicy clothes
Buy full line Juicy couture products from our site at a low price to make yourself a fashionista! Dress juicy couture clothing, holding juicy couture
Shop prom dresses, formal dresses, prom shoes, 2010 designer prom gowns at dres4sale.
for cocktail dresses, dresses for prom, homecoming dresses, and evening dresses. Cheap prom dresses or couture designer evening gowns for your next formal.
evening dresses
Evening Dresses. Women's Formal & Special Occasion Dresses ... Welcome to Cheap Evening Dresses for Sale! ... Buy Cheap Evening Dresses Sales & Accessories
prom dresses

March 20, 2010 | Unregistered Commenterasdasd

I think this is so good to use. I think this is definitely the future. I would push this more and more in the future.
resume format

April 22, 2010 | Unregistered Commenterjames lee

I guess that to get the mortgage loans from creditors you ought to have a good reason. Nevertheless, one time I have got a auto loan, just because I was willing to buy a house.

April 22, 2010 | Unregistered CommenterValentineSaundra

I loved

April 27, 2010 | Unregistered Commentersale buy

This works so well. I think you did an awesome job with it. Keep up the good work.
denver mesothelioma lawyers

May 4, 2010 | Unregistered Commenterjohn caine

P90x .It really is not expensive if you factor in the cost

of a gym membership,P90x workout . The cost for P90X is

about three months of a paid gym membership but you get to

keep the program foreverP90x . You can try many of the

online sites, but it will be the same as buying from the

company or a Beachbody Coach. Make sure you are getting

original DVD's. People are selling copies all over. The

problem is how long will they last, P90x workout ,and you

truly need the exercise and nutrition guide to even follow

the program. You can go to any site

http://www.p90xmall.com/ or you can go to and click on

products. P90x dvd You can order directly from the

site,P90x dvd.

May 8, 2010 | Unregistered Commenterp90x

Provide high quality silver Tiffany jewellery including necklaces,rings and other style jewelry at wholesale prices.Pick your dreaming
Tiffany jewellery
Tiffany co
Tiffany
Tiffany Stores is the best online United Kingdom jewelry stores where you can buy the cheapest Tiffany & Co silver jewelry.
Our huge selection of Tiffany
Tiffany & Co Rings
Tiffany & Co Earrings
Tiffany & Co Bracelets
Buy cartier ring, cartier love on abcartier.com. We also provide cartier bracelet, cartier jewelry and so on. Now come on and get what you want.
Cartier Jewelry
Cartier jewellery

May 31, 2010 | Unregistered Commenterharry123

The article written by your very good, I like it very much. I will keep your new article.
rosetta stone spanish,
rosetta stone,
rosetta stone language.

June 6, 2010 | Unregistered Commenterrosetta

People usually say :"Seeing is believing." GHD Each attempt has a corresponding gain, in part or obvious, or vague. At least we have the kind of satisfaction After I bought this watch ,in a sense,it means a great deal to me. net a porter thank you!it is very useful tools to protect our time.If you never pay attention to yourself ,please grasp this chance.a few days ago,I bought a Rolex watches.IT's very good to use.So i want to write an article about watches to share with everyone on So as to more and more people to konw it. UGG brand is relatively common, in addition to the Rolex ping g15even see watch on the movement and you don't know.
Rolex watches

June 25, 2010 | Unregistered Commenterrolex watches

ED clothing
can be bought in many department stores and specialty shops located nationwide. Good thing there is ED Hardy Shoes
. You will simply head on over to our website and check out the selection of ED Hardy Shoes
. hardy shirt
is one of the labels that never become outdated.


Many online pharmacies sell fake or generic lida
. If the doctor approves your form, it means the usage of lida daidaihua
is safe for your use. daidaihua
is based on ancient Chinese formula. The lida slimming
stick to the basic theme. slimming capsule
is purely natural as it is made from plants no acids. The intake of slimming capsules
proves to be a safe obesity treatment option.

July 3, 2010 | Unregistered Commentered hardy

lv features Monogram canvas with natural cowhide trim. The classic louis vuitton and quatrefoil signature design always can attract appreciations from someone special hidden in the crowd. The shiny brass hardware and the modern, feminine shape make Louis vuitton bags exude a more luxurious look. Besides the pleasing appearance, louis vuitton handbags is multi-functional.

July 4, 2010 | Unregistered Commenterlouis vuitton

Finally advice from recent Microsoft CompTIA ExamMCITP test questions experiencers - personal experience is 70-680 the best Microsoft MCITP study guide and there is no Microsoft MCITP simulation like MCITP Microsoft MCITP tips from a friend. 70-680

July 8, 2010 | Unregistered Commenterliuhan

Safe, Faste, buy wow gold

July 12, 2010 | Unregistered Commenterabvcd

I agree with articles point it really very good. 4 week cna classes

July 12, 2010 | Unregistered Commenter4 week cna classes

Stock lace wigs and full lace wigs. We supply Indian remy hair stock, celebrity, and custom full lace front wigs & cheap lace front wigs worldwide.Besides that,cheap hair extensions service is also included.

Wearing front lace wigs is becoming more and more popular among women. Suddenly it seems there are more and more celebrity stars wearing lace front wigs. lace front wigs for black women are plentiful, allowing you to choose a color and style lace wig with hair extensions that fits your needs perfectly.

July 14, 2010 | Unregistered CommenterMonica

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>