<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7759993258951957706</id><updated>2011-08-27T12:50:24.531+01:00</updated><category term='google googlebot misuse user agent switcher string'/><category term='mass hack'/><category term='business'/><category term='googlebot'/><category term='zlob'/><category term='spam spammed worm'/><category term='ddos exploit vulnerability iphone apple'/><category term='malware macromedia flash spam new'/><category term='puper'/><category term='4'/><category term='apple'/><category term='vmsplice linux kernel vulnerability exploit'/><category term='hackers hacker phone phreaks symbian mobile pda pocketpc'/><category term='firewire'/><category term='malware'/><category term='macs'/><category term='hacking'/><category term='all'/><category term='valentines'/><category term='storm worm e-card ecard spam'/><category term='http://hacking4all.com'/><category term='pacsec'/><category term='storm worm spam april fools'/><category term='phishing'/><category term='scams'/><category term='rogue'/><category term='valentines day storm botnet rbn spam spammed worm'/><category term='linux rootkit exploit vulnerability legitimate domains compramised'/><category term='phishing spam scam fake IRS internal revenue service spammed'/><category term='storm'/><category term='rbn'/><category term='mac'/><category term='canada canadian botnet network hackers arrested bust'/><category term='network'/><category term='hacking4all'/><category term='russian'/><category term='macsweeper'/><category term='symbian mobile technology bluetooth malware extortianware china'/><category term='social engineering monaronadona malware virus'/><category term='google'/><category term='hacking4all.com'/><title type='text'>d4rkr1d3r's Computer Security Blog</title><subtitle type='html'>An insight into the shady world of computer security..</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>22</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-5668964214544493797</id><published>2008-08-24T03:44:00.002+01:00</published><updated>2008-08-24T03:47:14.179+01:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='all'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking4all'/><category scheme='http://www.blogger.com/atom/ns#' term='4'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking4all.com'/><category scheme='http://www.blogger.com/atom/ns#' term='http://hacking4all.com'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Visit Hacking4All.com!</title><content type='html'>I have a new site: &lt;a href="http://hacking4all.com"&gt;http://hacking4all.com&lt;/a&gt; !&lt;br /&gt;The domain is going to be turned into a computer security forum.&lt;br /&gt;It's still a work in progress but if you have the time, check it out, it'll be worth it!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-5668964214544493797?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/5668964214544493797/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=5668964214544493797' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/5668964214544493797'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/5668964214544493797'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/08/visit-hacking4allcom.html' title='Visit Hacking4All.com!'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-6011864369594447390</id><published>2008-06-04T10:35:00.012+01:00</published><updated>2008-12-09T23:49:00.944Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='googlebot'/><category scheme='http://www.blogger.com/atom/ns#' term='mass hack'/><category scheme='http://www.blogger.com/atom/ns#' term='google'/><title type='text'>'Google Bot' to blame for recent mass hacks</title><content type='html'>Mass hacks have become increasingly prevelent over the past year. However, despite the large number of recent mass hacks, each attack appears almost identical to the other.&lt;br /&gt;For example, all appear to have originated from China (examples of which are the 'Super Bowel' incident and March's 'dota11' attacks), employ 'SQL injection' and they all use 'GoogleBot'[1] to their advantage...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A few months ago I blogged about 'Google Hacking', a relatively new trend in the hacking community that utilises the popular search engine 'Google'[2] to locate vulnerabilities in websites indexed by 'Google's crawler bot: 'GoogleBot'.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This is generally done with the aid of automated search tools that make precise queries ("dorks") to 'Google'. This is what the Chinese hackers in question have been using to locate and exploit their targets. This however, was what the computer security community assumed but could not be sure of.. Until the 'SANS Internet Storm Center'[3] extracted the actual executable used in the 'dota11' attack from within the exploit coding of an infected domain (for an exact description of the application and it's functions, visit &lt;a href="http://isc.sans.org/diary.html?storyid=4294"&gt;http://isc.sans.org/diary.html?storyid=4294&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img id="BLOGGER_PHOTO_ID_5207987298359305650" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://2.bp.blogspot.com/_t1zE98SxW5s/SEZ82tFz5bI/AAAAAAAAAGU/8_eXH29TKg8/s320/InsertHTML.png" border="0" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;As you can see from the image above, the executable is an automated 'Google Hacker' much like the 'Goolag' application released by 'Cult Dead Cow' ('cDc') last year.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It seems that we can expect to see significantly more 'Google Hacking' in the future especially in the instance of mass hacks.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[1]: &lt;a href="http://www.google.com/support/webmasters/bin/topic.py?topic=8843"&gt;http://www.google.com/support/webmasters/bin/topic.py?topic=8843&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[2]: &lt;a href="http://www.google.com/"&gt;http://www.google.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[3]: &lt;a href="http://isc.sans.org/diary.html?storyid=4294"&gt;http://isc.sans.org/diary.html?storyid=4294&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-6011864369594447390?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/6011864369594447390/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=6011864369594447390' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/6011864369594447390'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/6011864369594447390'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/06/google-bot-to-blame-for-recent-mass.html' title='&apos;Google Bot&apos; to blame for recent mass hacks'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_t1zE98SxW5s/SEZ82tFz5bI/AAAAAAAAAGU/8_eXH29TKg8/s72-c/InsertHTML.png' height='72' width='72'/><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-8732046892063950974</id><published>2008-06-04T10:25:00.003+01:00</published><updated>2008-06-04T10:31:38.350+01:00</updated><title type='text'>I'm back</title><content type='html'>I've decided to get back to writing blog articles when I have the time. Sorry all for the brief hiatus but I have been fairly busy recently and simply haven't been able to access time needed for a blog.&lt;br /&gt;&lt;br /&gt;I'll be posting a new computer security at least once a week.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-8732046892063950974?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/8732046892063950974/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=8732046892063950974' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/8732046892063950974'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/8732046892063950974'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/06/im-back.html' title='I&apos;m back'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-6235117553536295206</id><published>2008-04-10T00:38:00.005+01:00</published><updated>2008-12-09T23:49:01.186Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='canada canadian botnet network hackers arrested bust'/><category scheme='http://www.blogger.com/atom/ns#' term='valentines'/><category scheme='http://www.blogger.com/atom/ns#' term='rbn'/><category scheme='http://www.blogger.com/atom/ns#' term='valentines day storm botnet rbn spam spammed worm'/><category scheme='http://www.blogger.com/atom/ns#' term='spam spammed worm'/><category scheme='http://www.blogger.com/atom/ns#' term='storm'/><title type='text'>'Storm worm' creators loose track of time</title><content type='html'>It seems the creators of the 'Storm Worm' have started yet another Valentine's Day campaign.. This time in April.&lt;br /&gt;E-mails have been spammed out with body text offering Valentine's Day e-cards and linking to abused 'Google Blogspot' pages. These pages are purely social engineering-based and require the user to download and run the 'Storm' executable, without the presence of exploits.&lt;br /&gt;&lt;br /&gt;It seems 'Blogspot' is now a popular target for malware authors, as it has recently been utilised by spammers as a domain forwarding method, to distribute the 'Zlob' trojan, and now 'Storm'.&lt;br /&gt;This may also represent yet another link between the 'RBN' ('Russian Business Network') and the 'Storm Worm', as the 'Zlob' trojan has been confirmed to be of definite 'RBN' origins.&lt;br /&gt;&lt;br /&gt;The executables involved in this wave are 'love.exe' and 'withlove.exe' and both are hosted on fast-flux domains.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_t1zE98SxW5s/R_1X47f4slI/AAAAAAAAAGM/29cC0Rk4WRo/s1600-h/Storm+April.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_t1zE98SxW5s/R_1X47f4slI/AAAAAAAAAGM/29cC0Rk4WRo/s320/Storm+April.jpg" alt="" id="BLOGGER_PHOTO_ID_5187398981356401234" border="0" /&gt;&lt;/a&gt;We do not know why the 'Storm' authors have decided to run a Valentine-based campaign this April and I doubt we ever will.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-6235117553536295206?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/6235117553536295206/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=6235117553536295206' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/6235117553536295206'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/6235117553536295206'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/04/storm-worm-creators-loose-track-of-time.html' title='&apos;Storm worm&apos; creators loose track of time'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_t1zE98SxW5s/R_1X47f4slI/AAAAAAAAAGM/29cC0Rk4WRo/s72-c/Storm+April.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-5709110372948950997</id><published>2008-04-06T10:08:00.006+01:00</published><updated>2008-12-09T23:49:01.489Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='storm worm spam april fools'/><title type='text'>"April Fool's! You're infected with storm!"</title><content type='html'>It seems while I was away in Italy (the past week), the 'Storm' worm has got up to it's old tricks, this time, in light of the recent 'April Fool's' day, a new e-mail spam campaign has been pushing storm.&lt;br /&gt;Generally displaying the similar short body phrases such as "Happy April Fool's Day", the e-mails all contain numeric-IP http links leading to this page:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_t1zE98SxW5s/R_iVmGpqdfI/AAAAAAAAAGE/gJc-CxkZigo/s1600-h/April_Fool.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_t1zE98SxW5s/R_iVmGpqdfI/AAAAAAAAAGE/gJc-CxkZigo/s320/April_Fool.jpg" alt="" id="BLOGGER_PHOTO_ID_5186059452770055666" border="0" /&gt;&lt;/a&gt;After 5 seconds, 'funny.exe' will commence downloading, the "click here" link downloads 'foolsday.exe' and clicking the image will download 'kickme.exe'.&lt;br /&gt;Regardless of this, all are simply a new 'Storm' variant.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-5709110372948950997?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/5709110372948950997/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=5709110372948950997' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/5709110372948950997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/5709110372948950997'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/04/april-fools-youre-infected-with-storm.html' title='&quot;April Fool&apos;s! You&apos;re infected with storm!&quot;'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_t1zE98SxW5s/R_iVmGpqdfI/AAAAAAAAAGE/gJc-CxkZigo/s72-c/April_Fool.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-42621088506517654</id><published>2008-03-23T19:06:00.005Z</published><updated>2008-12-09T23:49:01.853Z</updated><title type='text'>'Google Hacking' in detail</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_t1zE98SxW5s/R-axwmpqdbI/AAAAAAAAAFc/78WGsRPMRVo/s1600-h/lg-goolag.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_t1zE98SxW5s/R-axwmpqdbI/AAAAAAAAAFc/78WGsRPMRVo/s320/lg-goolag.gif" alt="" id="BLOGGER_PHOTO_ID_5181023869903467954" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;A new trend in the hacking world: 'Google Hacking' enables individuals to locate vulnerabilities, harvest sensitive information and even acquire 'warez' simply via 'Google' search.&lt;br /&gt;Recently made particularly popular by the 'grayhat'[1] hacking group: 'Cult Of The Dead Cow'[2] (or 'cDc', creators of the infamous 'Remote Access Tool': 'Black Orifice') and 'jonnyihackstuff'[3] ('JIHS'), 'Google hacking' is the utilisation of 'Google's syntax or it's individual language in order to locate security information via advanced 'Google' queries (or "dorks").&lt;br /&gt;&lt;br /&gt;An example of a "dork" is as followed:&lt;br /&gt;&lt;br /&gt;intitle:"index of admin"&lt;br /&gt;&lt;br /&gt;The 'intitle:' phrase is used to ensure the query appears in the title of a web page and the inverted commas ensure that the phrase will appear in the search results.&lt;br /&gt;As 'GoogleBot' crawls the web, indexing each page of a domain, it also indexes the 'admin' section of the domain. This "dork" enables users to search for and access indexed admin sections of domains.&lt;br /&gt;&lt;br /&gt;Here is a more relevant example of how 'Google Hacking' can be employed when searching for and hacking vulnerable domains.&lt;br /&gt;&lt;br /&gt;intext:"POWERED BY HIT JAMMER 1.0"&lt;br /&gt;&lt;br /&gt;The 'intext' phrase ensures that the query will be located in the text of each resultant domain and the inverted commas ensure that the query will appear in each search result.&lt;br /&gt;&lt;br /&gt;As follows is the description for this particular "dork" via 'JIHS'[4]:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"Hit Jammer is a Unix compatible script that allows you to manage the content and traffic exchange and make web changes, all without needing HTML. It is typicaly used by the underground sites on the Net who "pay for surfing ads" and advertise spam servic&lt;/span&gt;&lt;span style="font-style: italic;"&gt;es or software. An attacker can find these sites by searching for the typical "powered by hit jammer !" frase on the bottom of the main page. Then if he changes the URL to www.target.com/admin/admin.php he is taken to the admin panel. Hit Jammer administrators are warned to protect this page with the .htaccess logon procedure, but many fail to do just that. In such cases, customer information like email addresses and passwords are in clear view of the attacker. Since human beings often use one simple password for many things this is a very dangerous practice."&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;As you can see, 'Google Hacking' can be an extremely powerful tool for simple 'whitehat' domain auditing or for 'blackhat' hacking.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_t1zE98SxW5s/R-aysGpqdcI/AAAAAAAAAFk/Z6SEcFZ5G7w/s1600-h/CDC013.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_t1zE98SxW5s/R-aysGpqdcI/AAAAAAAAAFk/Z6SEcFZ5G7w/s320/CDC013.JPG" alt="" id="BLOGGER_PHOTO_ID_5181024892105684418" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The release of 'cDc's 'Goolag Scanner'[5], a program that searches domains for vulnerabilities using "dorks" has greatly increased the appeal for "Google Hacking" among the 'script kiddie' world and has been greatly enforced by 'JIHS' 'Google Hacking Database'[6].&lt;br /&gt;It is certain that 'Google Hacking', due to 'Google's already immense popularity can be expected to be a prevalent factor in the world of computer security.&lt;br /&gt;&lt;br /&gt;[1] : http://en.wikipedia.org/wiki/Grey_hat&lt;br /&gt;[2] : &lt;span class="a"&gt;cultdeadcow.com&lt;br /&gt;[3] : http://johnny.ihackstuff.com/&lt;br /&gt;[4] : http://johnny.ihackstuff.com/ghdb.php?function=detail&amp;amp;id=288&lt;br /&gt;[5] : http://www.goolag.org/&lt;br /&gt;[6] : &lt;/span&gt;&lt;span class="a"&gt;johnny.ihackstuff.com/ghdb.php&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-42621088506517654?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/42621088506517654/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=42621088506517654' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/42621088506517654'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/42621088506517654'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/03/google-hacking-in-detail.html' title='&apos;Google Hacking&apos; in detail'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_t1zE98SxW5s/R-axwmpqdbI/AAAAAAAAAFc/78WGsRPMRVo/s72-c/lg-goolag.gif' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-5319045906379191716</id><published>2008-03-09T18:43:00.005Z</published><updated>2008-12-09T23:49:02.055Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='pacsec'/><category scheme='http://www.blogger.com/atom/ns#' term='firewire'/><title type='text'>Security companies reccomend disabling 'firewire'</title><content type='html'>During the 'PacSec' security conference of 2004,  Maximillian Dornsief  demonstrated how an individual may gain access to a computers internal memory via physical access to it's 'firewire' port.&lt;br /&gt;Simply by plugging in a modified 'iPod' or laptop to the computer's firewire port, an attacker can install malware, harvest encryption keys, unlock 'Windows' and thusly preform a number of other malicious activities.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_t1zE98SxW5s/R9Q52tZzMrI/AAAAAAAAAFU/ZzmqMsifsog/s1600-h/430px-FireWire-46_Diagram.svg+copy.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_t1zE98SxW5s/R9Q52tZzMrI/AAAAAAAAAFU/ZzmqMsifsog/s320/430px-FireWire-46_Diagram.svg+copy.jpg" alt="" id="BLOGGER_PHOTO_ID_5175825483819070130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Many people are not yet aware of this issue and though the vulnerability was demonstrated in 2004,  a fix has not yet been generated for it and as a result of this, security experts are reccomending that users disable any generally unused or rarely used 'firewire' ports.&lt;br /&gt;For users that wish to learn more about this issue, the 'PowerPoint' presentation Dornsief utilized during his speech can be  downloaded from the 'PacSec' website[1].&lt;br /&gt;&lt;br /&gt;[1] : http://www.pacsec.jp/psj04/psj04-dornseif-e.ppt&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;/em&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-5319045906379191716?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/5319045906379191716/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=5319045906379191716' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/5319045906379191716'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/5319045906379191716'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/03/security-companies-reccomend-disabling.html' title='Security companies reccomend disabling &apos;firewire&apos;'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_t1zE98SxW5s/R9Q52tZzMrI/AAAAAAAAAFU/ZzmqMsifsog/s72-c/430px-FireWire-46_Diagram.svg+copy.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-4243451833694000606</id><published>2008-03-05T21:23:00.006Z</published><updated>2008-12-09T23:49:02.243Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='symbian mobile technology bluetooth malware extortianware china'/><title type='text'>Symbian, meet Window's old friend: Extortionware</title><content type='html'>Yesterday, 'McAfee Avert Labs' discovered yet another article of mobile technology-based malware, this time directed at 'Symbian 60 series' mobile phones. This one, as with the last, origionated from China and has been dubbed: 'SymbOS/Kaizha.A' by 'McAfee'.&lt;br /&gt;The 'extortionware' displays a message, informing the user that if they do not send RMB 50 (approximately $7 in American currency) to the malware author, they will never regain use of their phone.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_t1zE98SxW5s/R88Sov0eB1I/AAAAAAAAAFE/FopxcksopBc/s1600-h/symbianPhones.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_t1zE98SxW5s/R88Sov0eB1I/AAAAAAAAAFE/FopxcksopBc/s320/symbianPhones.jpg" alt="" id="BLOGGER_PHOTO_ID_5174374988112594770" border="0" /&gt;&lt;/a&gt;&lt;span style="font-size:78%;"&gt;&lt;br /&gt;Image property of 'mobilab.unina.it'&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;The extortianware is also bundled with other multiple droppers, simply emphasizing the point that the distribution malware aimed at mobile-based technology is raising at an alarming rate.&lt;br /&gt;Anti-virus applications are already beginning to become available for mobile-based technology and can be expected to be seen much more of in the future.&lt;br /&gt;Who knows, prehaps 'Microsoft', 'Nokia' and other large mobile technology brands will begin shipping their products with anti-virus products installed.&lt;br /&gt;One things for certain, the majourity of end-users are not even aware of any mobile-based threats out there and education is required as these sort of threats continue to become more prevelent.&lt;span style="font-size:78%;"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-4243451833694000606?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/4243451833694000606/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=4243451833694000606' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/4243451833694000606'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/4243451833694000606'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/03/symbian-meet-windows-old-friend.html' title='Symbian, meet Window&apos;s old friend: Extortionware'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_t1zE98SxW5s/R88Sov0eB1I/AAAAAAAAAFE/FopxcksopBc/s72-c/symbianPhones.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-6891361116124011243</id><published>2008-03-05T17:33:00.007Z</published><updated>2008-12-09T23:49:02.263Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='social engineering monaronadona malware virus'/><title type='text'>"MonaRonaDona": A revolution in social engineering</title><content type='html'>Recently, infections of the malware "MonaRonaDona" have been increasingly prevelent.&lt;br /&gt;Once "MonaRonaDona" is installed on a user's system, it displays the following message:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;"&lt;span style="font-family:arial;"&gt;Hi, My name is MonaRonaDona. I am a virus&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&amp;amp; I am here to Wreck your PC. If you&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;observe strange behaviour with your PC, like&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;program windows disappearing e.t.c, it's me&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;who is doing all this. I was created as a protest&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;against the Human Rights Violation&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;being observed throughout the world &amp;amp; the&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;very purpose of my existence is to remind&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;span style="font-family:arial;"&gt;&amp;amp; stress the world to respect humainty.&lt;/span&gt;"&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Once active, "MonaRonaDona" attempts to terminate the following services:&lt;br /&gt;&lt;span klmark="vlweblog:208187485"&gt;&lt;pre&gt;Date And Time&lt;br /&gt;Windows Task Manager&lt;br /&gt;Registry Editor&lt;br /&gt;Irfanview&lt;br /&gt;Google Talk&lt;br /&gt;Macromedia&lt;br /&gt;Adobe&lt;br /&gt;Microsoft Visual&lt;br /&gt;Windows Media Player&lt;br /&gt;Winamp&lt;br /&gt;Microsoft Office&lt;br /&gt;Microsoft Excel&lt;br /&gt;Microsoft Word&lt;br /&gt;Messenger&lt;/pre&gt;&lt;/span&gt;The 'Internet Explorer' title bar is also modified to contain text regarding "MonaRonaDona".&lt;br /&gt;&lt;br /&gt;Immidiatly after infection however, this activity will not be present as the malware registers itself to run as 'Windows' boots. As a result of this, how "MonaRonaDona" actually infects computers is still unknown as users often cannot remember their actions prior to the infection.&lt;br /&gt;&lt;br /&gt;However, this is where it gets interesting as due such actions as displaying a warning message once infected, actively terminating common 'Windows' processes and displaying messages in application's title bars, we are forced to ask ourselvs the simple question:&lt;br /&gt;&lt;br /&gt;"Why does the malware author want "MonaRonaDona" to be noticed by the user to such an extent?"&lt;br /&gt;&lt;br /&gt;The awnswer lies in a simple search for "MonaRonaDona" in one of today's popular search engines. This query will direct the user to a page similar to this one:&lt;br /&gt;&lt;br /&gt;&lt;span&gt;&lt;span klmark="vlweblog:208187485"&gt;&lt;pre&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_t1zE98SxW5s/R87olv0eBwI/AAAAAAAAAEc/MbRhBQg10j4/s1600-h/mona_2.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_t1zE98SxW5s/R87olv0eBwI/AAAAAAAAAEc/MbRhBQg10j4/s320/mona_2.png" alt="" id="BLOGGER_PHOTO_ID_5174328757084620546" border="0" /&gt;&lt;/a&gt;&lt;/pre&gt;&lt;/span&gt;&lt;/span&gt;Or alternatively a 'Digg' (a popular content sharing domain) article or 'YouTube' video, all advertising the same product:&lt;br /&gt;"Unigray antivirus".&lt;br /&gt;&lt;br /&gt;The article displayed in the image claims that "MonaRonaDona" can be fixed with the following legitimate applications:&lt;br /&gt;&lt;br /&gt;'Kapersky'&lt;br /&gt;'AVG'&lt;br /&gt;and 'McAfee'&lt;br /&gt;&lt;br /&gt;When in reality, only 'Kaspersky' has included "MonaRonaDona" in it's 'DATs' (as &lt;span klmark="vlweblog:208187485"&gt;'Trojan.Win32.Monagrey.a').&lt;br /&gt;The article also claims that the best application that a user can use to fix the malware is called 'Unigray antivirus'.&lt;br /&gt;'Unigray antivirus' is an application published on the web at the same time detections of "MonaRonaDona" began appearing.&lt;br /&gt;Furthermore, when examined by 'Kaspersky Labs', the application was found to only detect (to a minimal standard) 19 different threats (including "MonaRonaDona") yet only removes one.. "MonaRonaDona".&lt;br /&gt;When comparing the code of "MonaRonaDona" to that of 'Unigray', it is also noteable that there are many simularities.&lt;br /&gt;Therefore, it extremely probable that the individual(s) behind "MonaRonaDona" are the same individual(s) that created "Unigray Antivirus".&lt;br /&gt;It seems social engineering techniques are getting increasingly devious and manipulative and that fraudware/malware authors are gaining more insight into the psycology of their victims and can thusly be expected to be seen employing social engineering techniques as a venue for infection more regularly.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-6891361116124011243?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/6891361116124011243/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=6891361116124011243' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/6891361116124011243'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/6891361116124011243'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/03/monaronadona-revolution-in-social.html' title='&quot;MonaRonaDona&quot;: A revolution in social engineering'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_t1zE98SxW5s/R87olv0eBwI/AAAAAAAAAEc/MbRhBQg10j4/s72-c/mona_2.png' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-4474589581853751357</id><published>2008-03-05T17:16:00.005Z</published><updated>2008-12-09T23:49:02.487Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='storm worm e-card ecard spam'/><title type='text'>'Storm' returns to 'e-cards'</title><content type='html'>It seems the 'Storm' worm has returned to it's previous attempts to distribute via fake 'e-cards'.&lt;br /&gt;A large number of e-mails promising humerous 'e-cards' have been spammed around the globe.&lt;br /&gt;The e-mails direct the user to a numeric 'IP' link to a domain hosted on 'Storm'-infected computers. The domain purports to be a well known legitimate 'e-card' distributing domain named 'funnypostcard.com' (the legitimate domain' s owners are in no way responsible for these attacks).&lt;br /&gt;Once a user clicks the link, they are presented with a domain similar to this one:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_t1zE98SxW5s/R87YJv0eBvI/AAAAAAAAAEU/A93lMNRKUVI/s1600-h/nuwar0803-2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_t1zE98SxW5s/R87YJv0eBvI/AAAAAAAAAEU/A93lMNRKUVI/s320/nuwar0803-2.jpg" alt="" id="BLOGGER_PHOTO_ID_5174310683862238962" border="0" /&gt;&lt;/a&gt;Clicking on the "click here" text prompts the user to download 'e-card.exe', whereas clicking on the image directs the user to downlaod 'e-card.exe' and if the user remains inactive for 5 seconds, a download for 'ecard.exe' is automaticly activated.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-4474589581853751357?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/4474589581853751357/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=4474589581853751357' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/4474589581853751357'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/4474589581853751357'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/03/storm-returns-to-e-cards.html' title='&apos;Storm&apos; returns to &apos;e-cards&apos;'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_t1zE98SxW5s/R87YJv0eBvI/AAAAAAAAAEU/A93lMNRKUVI/s72-c/nuwar0803-2.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-5971247890300641611</id><published>2008-03-02T21:30:00.006Z</published><updated>2008-12-09T23:49:02.617Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='hackers hacker phone phreaks symbian mobile pda pocketpc'/><title type='text'>'Phone Phreaks' (1950): Are hackers regressing?</title><content type='html'>&lt;b&gt;&lt;span style=";font-family:Arial;font-size:100%;"  &gt;phreaking /freek'ing/ /n./ [from `phone phreak'] 1. The   art and science of cracking the phone network (so as, for example, to make free   long-distance calls). 2. By extension, security-cracking in any other context (especially,   but not exclusively, on communications networks).&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;'Hacking' began in the 1950s as a hobby called 'Phone Phreaking' (well known for 'Captain Crunch' an individual able to gain access to free long distance phone calls simply by whistling down a phone using his free 'Captain Crunch' whistle). 'Phone Phreaks' were individuals who misused the extensive knowledge they possessed of phones and how phones functioned in order to gain access to free long distance calls and execute social engineering techniques on phone company staff. It was primarily a hobby to begin with but became significantly more serious as the 'FBI' and phone companies began to crack down on 'Phone Phreaks'.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_t1zE98SxW5s/R8xzCgEvc_I/AAAAAAAAAEE/ffrgUxiZ3zg/s1600-h/phreaker.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 184px; height: 151px;" src="http://4.bp.blogspot.com/_t1zE98SxW5s/R8xzCgEvc_I/AAAAAAAAAEE/ffrgUxiZ3zg/s320/phreaker.jpg" alt="" id="BLOGGER_PHOTO_ID_5173636558748611570" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Once the first 'PC' ('Personal Computer') 'Simon' was made available as a building kit with each issue of Edmund Berkeley's 'Radio Electronics' magazine (1950), 'Phone Phreaking' began to die out.&lt;br /&gt;However, with the recent large rise in mobile technology-based malware, security researchers and hackers are beginning to once again return their focus to phones and other mobile technology. With the recent 'DDoS' ('Distributed Denial Of Service') vulnerability discovered in the 'iphone' recieveing so much press, 'McAfee's discovery of 'WinCE/InfoJack': a trojan for the PocketPC and the presentation at last week's 'Black Hat' conference regarding the exploitation of 'VoIP' for malicious uses, it seems that phone-based security threats are definantly growing and can be expected to be an important security topic in the future.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-5971247890300641611?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/5971247890300641611/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=5971247890300641611' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/5971247890300641611'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/5971247890300641611'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/03/phone-phreaks-1950-are-hackers.html' title='&apos;Phone Phreaks&apos; (1950): Are hackers regressing?'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_t1zE98SxW5s/R8xzCgEvc_I/AAAAAAAAAEE/ffrgUxiZ3zg/s72-c/phreaker.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-342476351946174388</id><published>2008-02-26T21:30:00.005Z</published><updated>2008-12-09T23:49:02.752Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='google googlebot misuse user agent switcher string'/><title type='text'>Misuse of 'GoogleBot'</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_t1zE98SxW5s/R8qdbQEvc-I/AAAAAAAAAD8/-tbJeBfyqZA/s1600-h/logo.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_t1zE98SxW5s/R8qdbQEvc-I/AAAAAAAAAD8/-tbJeBfyqZA/s320/logo.gif" alt="" id="BLOGGER_PHOTO_ID_5173120213485319138" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The alteration of a user's 'user agent string' can provide an individual the ability to discuise themselvs as any internet-based entity they wish.&lt;br /&gt;It has become a recent trend for end-users to duiscise themselvs as the 'GoogleBot', a bot that crawls domains searching for content to be displayed on the popular search engine: 'Google'.&lt;br /&gt;Normally this would not be an issue. However, some domains are configured to allow 'GoogleBot' full access and higher privilaged rights than the average guest user.&lt;br /&gt;For instance: A user discuised as 'GoogleBot' may be free to enter a registration-based forum or domain without the proper credentials to do so due to the domain's settings allowing 'GoogleBot' full access.&lt;br /&gt;This practice is called 'user agent switching' and has been made popular by the 'Mozilla Firefox' add-on: 'User Agent Switcher'[1].&lt;br /&gt;This adds further emphasis to the question "how much trouble can 'Mozilla Firefox' add-ons really cause for companies". With add-ons such as 'AdBlockPlus'[2] (a 'FireFox' add-on intended to block advertisments from user's browsers), some domain registrants are even attempting to make a point by completely blocking[3] 'FireFox' users from their sites.&lt;br /&gt;Will this 'FireFox'-hating trend catch on with domain registrants?&lt;br /&gt;Who knows, but it seems 'FireFox' already posesses an almost cult following that is unlikely to be phased by any attempt to dispuit the browser's success.&lt;br /&gt;&lt;br /&gt;For more information on 'user agent switching', visit 'whatsmyuseragent'[4].&lt;br /&gt;&lt;br /&gt;[1] : https://addons.mozilla.org/en-US/firefox/addon/59&lt;br /&gt;[2] : http://adblockplus.org/en/&lt;br /&gt;[3] : http://www.firefoxfacts.com/2007/08/21/anti-firefox-loons-go-off-deep-end/&lt;br /&gt;[4] : http://whatsmyuseragent.com/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-342476351946174388?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/342476351946174388/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=342476351946174388' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/342476351946174388'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/342476351946174388'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/02/misuse-of-googlebot.html' title='Misuse of &apos;GoogleBot&apos;'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_t1zE98SxW5s/R8qdbQEvc-I/AAAAAAAAAD8/-tbJeBfyqZA/s72-c/logo.gif' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-4523321525073680176</id><published>2008-02-25T09:59:00.002Z</published><updated>2008-03-04T00:53:35.568Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='canada canadian botnet network hackers arrested bust'/><title type='text'>Canada Botnet Arrests</title><content type='html'>On Febuary 20th, 17 individuals between the ages 17-26, all male except for one 19-year-old woman were apprehended on alleged charges of cyber-crime and profiting from the utilisation of cyber-crime via botnets.&lt;br /&gt;The Canadian hacking network arrested have been thought to have caused up to $45 Million in damages and gained control of over a millian computers during their period as cyber-criminals.&lt;br /&gt;The network had been under investigation for 2 years and the overall maximum sentence for the charges is 10 years in jail signifying quite a commendable bust for the Quebec police force.&lt;br /&gt;Cyber-crime in Canada has been fairly prevelent recently and it is good to see cyber-criminals being actively apprehended for their crimes as hopefully others will follow or at least take heed.&lt;br /&gt;More information on the arrests can be located on the 'canada.com' news network[1].&lt;br /&gt;&lt;br /&gt;[1] : http://www.canada.com/calgaryherald/news/story.html?id=f0f6138c-0bd7-4061-bb8e-be7d6d4b654d&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-4523321525073680176?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/4523321525073680176/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=4523321525073680176' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/4523321525073680176'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/4523321525073680176'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/02/canada-botnet-arrests.html' title='Canada Botnet Arrests'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-2934131899330886020</id><published>2008-02-21T11:59:00.006Z</published><updated>2008-03-06T20:42:55.094Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='vmsplice linux kernel vulnerability exploit'/><title type='text'>Linux Kernel 'vmsplice' Exploit</title><content type='html'>'CVE-2008-0600', a vulnerability in Linux kernels Versions 2.6.17 to 2.6.24.1 has recently been made public via 'Milw0rm.com' (A popular exploit and vulnerability archive domain established by the well known hacktivists: 'Milw0rm').&lt;br /&gt;The bug allows a local user to gain root privileges. Reports also claim that this exploit is currently being utilised in the wild.&lt;br /&gt;The vulnerability is present in the 'get_iovec_page_array' function (fs/splice.c, line numbers from 2.6.23.1-42.fc8 kernel - available via the vmsplice() system function).&lt;br /&gt;More information on how to patch the vulnerability can be located on 'KernelTrap'[1].&lt;br /&gt;&lt;br /&gt;[1] : &lt;a href="http://kerneltrap.org/Linux/Patching_CVE-2008-0600_Local_Root_Exploit"&gt;http://kerneltrap.org/Linux/Patching_CVE-2008-0600_Local_Root_Exploit&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-2934131899330886020?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/2934131899330886020/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=2934131899330886020' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/2934131899330886020'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/2934131899330886020'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/02/new-linux-kernel-vmsplice-exploit.html' title='Linux Kernel &apos;vmsplice&apos; Exploit'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-8106336050354041415</id><published>2008-02-20T23:37:00.007Z</published><updated>2008-12-09T23:49:03.416Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='ddos exploit vulnerability iphone apple'/><title type='text'>DoS vulnerability discovered in iPhone</title><content type='html'>Many security researchers in 2007 predicted a rise in 'Symbian' and mobile-based security threats in 2008. As a result, researchers are now beginning to direct attention towards mobile technology in order to identify and prove the existence and concept in the rise of such threats.&lt;br /&gt;While attempting to locate a method to unlock the filesystem on 'iPhones' running on the 1.1.3 firmware, researchers noticed vulnerability in the 'iPhone's 'Mobile Safari' that can be exploited to trigger a 'DoS' ('Denial Of Service') attack.&lt;br /&gt;The researchers created a proof of concept web page where a user can trigger the exploitation of the vulnerability by clicking a 'Go!' button.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_t1zE98SxW5s/R7y97xlEmfI/AAAAAAAAADc/Ws6b4m8Fb9I/s1600-h/AvertBlogBlogID567-fig1.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_t1zE98SxW5s/R7y97xlEmfI/AAAAAAAAADc/Ws6b4m8Fb9I/s320/AvertBlogBlogID567-fig1.png" alt="" id="BLOGGER_PHOTO_ID_5169215306933246450" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Once clicked, a pop up is created which then runs the exploit code.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_t1zE98SxW5s/R7y-BBlEmgI/AAAAAAAAADk/V98m4yxgxgU/s1600-h/AvertBlogBlogID567-fig2.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_t1zE98SxW5s/R7y-BBlEmgI/AAAAAAAAADk/V98m4yxgxgU/s320/AvertBlogBlogID567-fig2.png" alt="" id="BLOGGER_PHOTO_ID_5169215397127559682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The 'iPhone' is then rendered completely unresponsive until the system reboots under a minute later.&lt;br /&gt;The bug, partially based on a 'Javascript' code origionating from the 'Month of Browser Bugs' ('MOBB'), can only be prevented prior to patching, by disabling 'JavaScript'  (Home &gt; Settings &gt; Safari).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-8106336050354041415?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/8106336050354041415/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=8106336050354041415' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/8106336050354041415'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/8106336050354041415'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/02/dos-vulnerability-discovered-in-iphone.html' title='DoS vulnerability discovered in iPhone'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_t1zE98SxW5s/R7y97xlEmfI/AAAAAAAAADc/Ws6b4m8Fb9I/s72-c/AvertBlogBlogID567-fig1.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-151400406484905093</id><published>2008-02-14T01:04:00.004Z</published><updated>2008-12-09T23:49:04.206Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='valentines day storm botnet rbn spam spammed worm'/><title type='text'>Is your secret admirer a botnet?</title><content type='html'>On Monday evening, a vast number of new 'Storm' variants were spammed out. It seems these variants were (due to a new compiler utilised by the creator[s])  almost completely undetected by anti-malware vendors.&lt;br /&gt;The link in the e-mail directs the user to a domain displaying a rather festive "Valentines Day Bingo" image.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_t1zE98SxW5s/R7ShHxlEmcI/AAAAAAAAADE/_HcG_SFtgg4/s1600-h/nuwarblog0802_2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_t1zE98SxW5s/R7ShHxlEmcI/AAAAAAAAADE/_HcG_SFtgg4/s320/nuwarblog0802_2.jpg" alt="" id="BLOGGER_PHOTO_ID_5166931827440785858" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The domain then prompts the user to download/run an executable named 'valentine.exe'.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_t1zE98SxW5s/R7ShgxlEmeI/AAAAAAAAADU/m5zMS3KoA_M/s1600-h/nuwarblog0802_1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_t1zE98SxW5s/R7ShgxlEmeI/AAAAAAAAADU/m5zMS3KoA_M/s320/nuwarblog0802_1.jpg" alt="" id="BLOGGER_PHOTO_ID_5166932256937515490" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Once ran, the 'Storm' worm is free to wreak it's general havok.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-151400406484905093?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/151400406484905093/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=151400406484905093' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/151400406484905093'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/151400406484905093'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/02/is-your-seacret-admirer.html' title='Is your secret admirer a botnet?'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_t1zE98SxW5s/R7ShHxlEmcI/AAAAAAAAADE/_HcG_SFtgg4/s72-c/nuwarblog0802_2.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-1033156950804377149</id><published>2008-02-09T19:29:00.002Z</published><updated>2008-12-09T23:49:04.558Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware macromedia flash spam new'/><title type='text'>Infected in a flash!</title><content type='html'>&lt;span style="font-size:100%;"&gt;A new trojan downloader is currently being distributed via fake 'Macromedia Flash' downloads.&lt;br /&gt;Yesterday at 07:06:40 AM, my honeypot e-mail recieved spam from t&lt;/span&gt;&lt;span style="font-size:100%;"&gt;he spoofed address:&lt;br /&gt;'accounts@passport.com'.&lt;br /&gt;The e-mail's content was as follows:&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;"&lt;span style="font-style: italic;font-size:85%;" &gt;tudo bem? eu  esqueci de mandar as fotos! agora tá ai!!&lt;/span&gt;&lt;div class="ExternalClass" id="MsgContainer"&gt; &lt;p style="font-style: italic;"&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;Beijao meu amor&lt;/span&gt;&lt;/p&gt; &lt;p&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;&lt;span style="font-style: italic;"&gt;anexo: Baixa fotos.jpg (192 kb)&lt;/span&gt;"&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:100%;"  &gt;Roughly translated into english:&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=";font-family:Verdana,Arial,Helvetica,sans-serif;font-size:85%;"  &gt;&lt;span style="font-size:100%;"&gt;"&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;all good? I forgot to order the photos! now ok!  Beijao my love  attach&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;ed: Low fotos.jpg (192 kb)&lt;/span&gt;&lt;/span&gt;"&lt;/p&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_t1zE98SxW5s/R64MfhlEmZI/AAAAAAAAACs/Ha7h4oJue6c/s1600-h/Untitled-1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 313px; height: 120px;" src="http://3.bp.blogspot.com/_t1zE98SxW5s/R64MfhlEmZI/AAAAAAAAACs/Ha7h4oJue6c/s320/Untitled-1.jpg" alt="" id="BLOGGER_PHOTO_ID_5165079558369876370" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Once the link is clicked, they are directed to the domain: 'http://aualjbdp[REMOVED]3.com.sapo.pt/Macromedia_flash_install.html' which attempts to infect them with a trojan downloader via 'ActiveX' and social engineering techniques.&lt;/p&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_t1zE98SxW5s/R64LUBlEmXI/AAAAAAAAACc/Fh0U0UO-XNA/s1600-h/Untitled-2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_t1zE98SxW5s/R64LUBlEmXI/AAAAAAAAACc/Fh0U0UO-XNA/s320/Untitled-2.jpg" alt="" id="BLOGGER_PHOTO_ID_5165078261289752946" border="0" /&gt;&lt;/a&gt;This blog is the first resource on the internet to mention this particular variant as it seems to be relatively new. As a result, all detections from anti-malware applications (10/32 - 'VirusTotal') are simply based on heuristics:&lt;/p&gt;&lt;table id="tablaMotores" border="0" cellpadding="0" cellspacing="0" width="550"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;"AhnLab-V3&lt;/td&gt; &lt;td&gt;2008.2.6.10&lt;/td&gt; &lt;td&gt;2008.02.05&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;AntiVir&lt;/td&gt; &lt;td&gt;7.6.0.62&lt;/td&gt; &lt;td&gt;2008.02.08&lt;/td&gt; &lt;td class="positivo"&gt;TR/Crypt.CFI.Gen&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;Authentium&lt;/td&gt; &lt;td&gt;4.93.8&lt;/td&gt; &lt;td&gt;2008.02.08&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;Avast&lt;/td&gt; &lt;td&gt;4.7.1098.0&lt;/td&gt; &lt;td&gt;2008.02.08&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;AVG&lt;/td&gt; &lt;td&gt;7.5.0.516&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;BitDefender&lt;/td&gt; &lt;td&gt;7.2&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td class="positivo"&gt;Trojan.Downloader.Banload.NVX&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;CAT-QuickHeal&lt;/td&gt; &lt;td&gt;None&lt;/td&gt; &lt;td&gt;2008.02.08&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;ClamAV&lt;/td&gt; &lt;td&gt;0.92&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;DrWeb&lt;/td&gt; &lt;td&gt;4.44.0.09170&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;eSafe&lt;/td&gt; &lt;td&gt;7.0.15.0&lt;/td&gt; &lt;td&gt;2008.01.28&lt;/td&gt; &lt;td class="positivo"&gt;suspicious Trojan/Worm&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;eTrust-Vet&lt;/td&gt; &lt;td&gt;31.3.5522&lt;/td&gt; &lt;td&gt;2008.02.08&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;Ewido&lt;/td&gt; &lt;td&gt;4.0&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;FileAdvisor&lt;/td&gt; &lt;td&gt;1&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;Fortinet&lt;/td&gt; &lt;td&gt;3.14.0.0&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;F-Prot&lt;/td&gt; &lt;td&gt;4.4.2.54&lt;/td&gt; &lt;td&gt;2008.02.08&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;F-Secure&lt;/td&gt; &lt;td&gt;6.70.13260.0&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td class="positivo"&gt;W32/Downloader&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;Ikarus&lt;/td&gt; &lt;td&gt;T3.1.1.20&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td class="positivo"&gt;BehavesLikeTrojan.UserStartup&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;Kaspersky&lt;/td&gt; &lt;td&gt;7.0.0.125&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td class="positivo"&gt;Heur.Downloader&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;McAfee&lt;/td&gt; &lt;td&gt;5226&lt;/td&gt; &lt;td&gt;2008.02.08&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;Microsoft&lt;/td&gt; &lt;td&gt;1.3204&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;NOD32v2&lt;/td&gt; &lt;td&gt;2861&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;Norman&lt;/td&gt; &lt;td&gt;5.80.02&lt;/td&gt; &lt;td&gt;2008.02.08&lt;/td&gt; &lt;td class="positivo"&gt;W32/Downloader&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;Panda&lt;/td&gt; &lt;td&gt;9.0.0.4&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td class="positivo"&gt;Suspicious file&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;Prevx1&lt;/td&gt; &lt;td&gt;V2&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;Rising&lt;/td&gt; &lt;td&gt;20.29.22.00&lt;/td&gt; &lt;td&gt;2008.01.30&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;Sophos&lt;/td&gt; &lt;td&gt;4.26.0&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td class="positivo"&gt;Mal/Behav-130&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;Sunbelt&lt;/td&gt; &lt;td&gt;2.2.907.0&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;Symantec&lt;/td&gt; &lt;td&gt;10&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;TheHacker&lt;/td&gt; &lt;td&gt;6.2.9.213&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;VBA32&lt;/td&gt; &lt;td&gt;3.12.6.0&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr&gt; &lt;td&gt;VirusBuster&lt;/td&gt; &lt;td&gt;4.3.26:9&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td&gt;-&lt;/td&gt; &lt;/tr&gt; &lt;tr class="odd"&gt; &lt;td&gt;Webwasher-Gateway&lt;/td&gt; &lt;td&gt;6.6.2&lt;/td&gt; &lt;td&gt;2008.02.09&lt;/td&gt; &lt;td class="positivo"&gt;Trojan.Crypt.CFI.Gen"&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;The trojan downloader is of Portuguese origin and connects to several domains such as 'box[DOT]net' (a legitimate file storage domain) in order to download further malware (q25qp1hyc0.exe - A trojan downloader), 'smtps[DOT]uol[DOT]com.br' (200.221.4.131) and also attempts to connect to 'r0xlink3d[DOT]net ', a domain that is currently not responding.&lt;/p&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_t1zE98SxW5s/R64NwxlEmaI/AAAAAAAAAC0/kiKgNCKy0mQ/s1600-h/Untitled-1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://4.bp.blogspot.com/_t1zE98SxW5s/R64NwxlEmaI/AAAAAAAAAC0/kiKgNCKy0mQ/s320/Untitled-1.jpg" alt="" id="BLOGGER_PHOTO_ID_5165080954234247586" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;It also attempts to send a blank e-mail to 'inforte34@gmail[DOT]com' with the subject: '[VICTIM'S E-MAIL] o - USER',  as a notification of infection.&lt;/p&gt;&lt;p&gt;I have also located a server with three previous veriants on, suggesting there may be more to come.&lt;span style="text-decoration: underline;"&gt;.&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-1033156950804377149?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/1033156950804377149/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=1033156950804377149' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/1033156950804377149'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/1033156950804377149'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/02/infected-in-flash.html' title='Infected in a flash!'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_t1zE98SxW5s/R64MfhlEmZI/AAAAAAAAACs/Ha7h4oJue6c/s72-c/Untitled-1.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-4536654037063865054</id><published>2008-02-06T21:28:00.002Z</published><updated>2008-12-09T23:49:05.213Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing spam scam fake IRS internal revenue service spammed'/><title type='text'>More 'IRS' 'Phishing'...</title><content type='html'>U.S. Internal Revenue Service ('IRS') 'phishing' scams have been extremely prevalent recently, with e-mails containing the scam being mass 'spammed' to thousands of captured e-mail addresses.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_t1zE98SxW5s/R6orrT_N4-I/AAAAAAAAACM/G9_mx6iSaxA/s1600-h/blog-IRSTaxFraud1.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 347px; height: 425px;" src="http://3.bp.blogspot.com/_t1zE98SxW5s/R6orrT_N4-I/AAAAAAAAACM/G9_mx6iSaxA/s320/blog-IRSTaxFraud1.jpg" alt="" id="BLOGGER_PHOTO_ID_5163987945833489378" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The newest version of this scam arrives in the form of an e-mail notification via a spoofed 'IRS' address ('under-forms@irs.co.us') claiming that there has been a mistake in the calculation of the recipent's fiscal activity over the last year and they are in fact eligible for a tax refund of $375.20.&lt;br /&gt;The e-mail then links to a form requesting the victim’s name, social security number, credit card details, 'CVC/CVV2' and ATM pin number.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_t1zE98SxW5s/R6orxD_N4_I/AAAAAAAAACU/j-RvT2A_fwo/s1600-h/blog-IRSTaxFraud2.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_t1zE98SxW5s/R6orxD_N4_I/AAAAAAAAACU/j-RvT2A_fwo/s320/blog-IRSTaxFraud2.jpg" alt="" id="BLOGGER_PHOTO_ID_5163988044617737202" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;The 'phish' has been hosted on a compromised U.S. Halloween and movie props-based domain. This is yet another example of the increasing prevalence of compromised legitimate domains currently being favored by 'cyber-criminals' over their own malicious domains.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-4536654037063865054?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/4536654037063865054/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=4536654037063865054' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/4536654037063865054'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/4536654037063865054'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/02/nee.html' title='More &apos;IRS&apos; &apos;Phishing&apos;...'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_t1zE98SxW5s/R6orrT_N4-I/AAAAAAAAACM/G9_mx6iSaxA/s72-c/blog-IRSTaxFraud1.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-2044819451358204526</id><published>2008-02-03T17:44:00.001Z</published><updated>2008-03-04T00:57:35.876Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux rootkit exploit vulnerability legitimate domains compramised'/><title type='text'>10,000 legitimate domains and a 'Linux' rootkit..</title><content type='html'>Over 10,000 legitimate domains such as 'teagames[DOT]com' and 'Berkly University's website have been found to be serving malicious code to their customers.&lt;br /&gt;The attack occurs via a 'Javascript' written to preform diagnostics on the target PC in order to detect which exploit (from a list of 12 patched exploits in various applications including 'Yahoo Messenger' and 'QuickTime') in order to download a trojan onto the PC via 'drive-by-download'. Once downloaded the trojan connects the PC to a 'botnet', giving the 'botnet' author full control over the user's PC.&lt;br /&gt;However, the primary question is of coarse the matter of how so many highly regarded legitimate domains became compromised.&lt;br /&gt;Now here's where it gets interesting. It appears that all the web servers currently being hacked into are all 'Linux ' servers (predominantly running on 'Santos' 4/5, 'Fedora Core' or 'RedHat Enterprise', utilizing 'PHP', 'Apache' and some form of web control panel such as the popular 'cPanel' - meaning the intrusion method being employed by the hackers may well be via a security hole in any of these).&lt;br /&gt;While we may not know how these hackers are gaining 'root' access, we do know they are gaining an immediate 'root SSH' connection, meaning that either a password file was harvested or that an exploit was utilized. Once 'root' has been gained, they install an extremely effective 'Linux kernel rootkit' and then their own 'HTTP' server. Once the server is installed, they wait until a user visits your domain and harvest the reply that visit generated prior to it reaching the 'Linux' servers 'TCP/IP stack' and injects their own malicious code into it and sends it off to the visitor.&lt;br /&gt;This extremely devious and effective method of domain infection is both interesting and  chilling.&lt;br /&gt;'Linux' server users are encouraged to 'patch', utilize 'IDS' and 'firewalls' in order to aid the defense of their servers, but should also remember that as we are still currently unaware as to how these infections are occurring, this will not necessarily ensure complete protection.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-2044819451358204526?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/2044819451358204526/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=2044819451358204526' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/2044819451358204526'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/2044819451358204526'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/02/10000-legitimate-domains-and-linux.html' title='10,000 legitimate domains and a &apos;Linux&apos; rootkit..'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-1849683567685620474</id><published>2008-02-01T18:57:00.004Z</published><updated>2008-12-09T23:49:05.936Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='macs'/><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><category scheme='http://www.blogger.com/atom/ns#' term='network'/><category scheme='http://www.blogger.com/atom/ns#' term='rbn'/><category scheme='http://www.blogger.com/atom/ns#' term='mac'/><category scheme='http://www.blogger.com/atom/ns#' term='russian'/><category scheme='http://www.blogger.com/atom/ns#' term='macsweeper'/><category scheme='http://www.blogger.com/atom/ns#' term='business'/><title type='text'>'RBN' rogue security applications on Macs? What's next?'</title><content type='html'>It seems organised crime aimed at the 'Mac' platform has been revolutionized with the creation of the first rogue security application aimed at Macs.&lt;br /&gt;&lt;br /&gt;The application, 'MacSweeper' ('macsweeper[DOT]com') claims to be "an easy-to-use but powerful application that has the ability to improve your system performance" as well as preventing users from "being spied on and caught with inapropriate files on your computer".&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_t1zE98SxW5s/R6N52D_N45I/AAAAAAAAABg/AGxgGbTngEc/s1600-h/macsweeper_buy.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_t1zE98SxW5s/R6N52D_N45I/AAAAAAAAABg/AGxgGbTngEc/s320/macsweeper_buy.jpg" alt="" id="BLOGGER_PHOTO_ID_5162103567587074962" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;However, it seems, as with it's clone aimed at the 'Windows' platform: 'CLEANATOR' ('cleanator.com), has no helpful functionallity and simply detects fake threats in an attempt to goad users into purchasing the software (as with the majourity of rogue security applications).&lt;br /&gt;Another interesting factor is that of the reply 'F-Secure' recieved[1] after sending an e-mail notification to 'MacSweeper's support address ('support@macsweeper[DOT]com') which was as follows:&lt;br /&gt;&lt;br /&gt;"&lt;span class="rss:item"&gt;&lt;i&gt;I would like to explain all the situation, about MacSweeper.&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="rss:item"&gt;&lt;i&gt;We are really trying to make a good soft&lt;/i&gt;&lt;/span&gt;&lt;span class="rss:item"&gt;&lt;i&gt;ware, and you wont find any viruses/spyware/trojans/malware in MacSweeper (test it your self, if you don't believe me,&lt;/i&gt;&lt;/span&gt;&lt;span class="rss:item"&gt;&lt;i&gt; you can use any type of firewalls, dissemblers, or other tools) .&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;span class="rss:item"&gt;&lt;i&gt;&lt;br /&gt;The problem is that we are using selling partners that forces us to use this marketing type. We would like to leave them, we don't want to completely destroy Good Name of MacSweeper application.&lt;/i&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="rss:item"&gt;&lt;i&gt;Personally I adore Mac Platform, and it hearts to here that the program you wrote is said to be some kind of "Rogue application" , i wouldn't like to destroy good manners of software&lt;/i&gt;&lt;/span&gt;&lt;span class="rss:item"&gt;&lt;i&gt; written for it :((&lt;br /&gt;&lt;br /&gt;I would like to say sorry for all inconveniences that we could bring to you, but believe&lt;/i&gt;&lt;/span&gt;&lt;span class="rss:item"&gt;&lt;i&gt; MacSweeper is meant to be a useful application. You can ask Questions&lt;/i&gt;&lt;/span&gt;&lt;span class="rss:item"&gt;&lt;i&gt;, and i will try to answer them!&lt;br /&gt;&lt;br /&gt;Thank You!&lt;br /&gt;support@macsweeper.com"&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;/span&gt;&lt;/i&gt;('F-Secure' made several blog posts regarding 'MacSweeper'[1][2]  including a 'YouTube' video[3].)&lt;i&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/i&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_t1zE98SxW5s/R6N69z_N47I/AAAAAAAAABw/vBBRTpIbXYk/s1600-h/macsweeper_winbrowser.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_t1zE98SxW5s/R6N69z_N47I/AAAAAAAAABw/vBBRTpIbXYk/s320/macsweeper_winbrowser.jpg" alt="" id="BLOGGER_PHOTO_ID_5162104800242688946" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="rss:item"&gt;&lt;br /&gt;I &lt;/span&gt;&lt;span class="rss:item"&gt;myself, have noticed possibl&lt;/span&gt;&lt;span class="rss:item"&gt;e links with 'SpyShredder' and 'IEDefender'/'Files-Secure' due to use of identical images and text, backed up by their justification of their &lt;/span&gt;&lt;span class="rss:item"&gt;rogue software being extremely simlar to that in the case of&lt;/span&gt;&lt;span class="rss:item"&gt; 'IEDefender' who posted an attempted justification of their actions on 'CastleCops' forum.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_t1zE98SxW5s/R6N2oT_N41I/AAAAAAAAABA/viFvSudshPY/s1600-h/logobottom.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_t1zE98SxW5s/R6N2oT_N41I/AAAAAAAAABA/viFvSudshPY/s320/logobottom.gif" alt="" id="BLOGGER_PHOTO_ID_5162100032828990290" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_t1zE98SxW5s/R6N2uz_N42I/AAAAAAAAABI/cxi90tYhubM/s1600-h/index_32.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_t1zE98SxW5s/R6N2uz_N42I/AAAAAAAAABI/cxi90tYhubM/s320/index_32.jpg" alt="" id="BLOGGER_PHOTO_ID_5162100144498140002" border="0" /&gt;&lt;/a&gt;&lt;span class="rss:item"&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A&lt;/span&gt;&lt;span class="rss:item"&gt;s I &lt;/span&gt;&lt;span class="rss:item"&gt;previously&lt;/span&gt;&lt;span class="rss:item"&gt; noticed that 'IEDefender' may &lt;/span&gt;&lt;span class="rss:item"&gt;have been linked to &lt;/span&gt;&lt;span class="rss:item"&gt;'SpyFalcon' and 'MalwareAlarm' (due to use of identical images and text), two domains that are owned by and maintained by the 'RBN' ('Russian Business Network'), does this indicate that the 'RBN' are now (on top of creating trojans for macs - 'OSX/DNSChanger') also beginning to aim their rogue security applications at 'Macs'?&lt;br /&gt;Who knows? But one thing we can all be sure of is that malware and fraudware production aimed at 'Macs' is only going to get broader.&lt;br /&gt;This is going to be a bad year for 'Mac' users.&lt;br /&gt;&lt;br /&gt;[1] : http://www.f-secure.com/weblog/archives/00001365.html&lt;br /&gt;&lt;/span&gt;[2] : http://www.f-secure.com/weblog/archives/00001362.html&lt;br /&gt;[3] : http://www.youtube.com/watch?v=E4KWjqb8mEQ&lt;br /&gt;&lt;span class="rss:item"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-1849683567685620474?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/1849683567685620474/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=1849683567685620474' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/1849683567685620474'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/1849683567685620474'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/02/rbn-rogue-security-applications-on-macs.html' title='&apos;RBN&apos; rogue security applications on Macs? What&apos;s next?&apos;'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_t1zE98SxW5s/R6N52D_N45I/AAAAAAAAABg/AGxgGbTngEc/s72-c/macsweeper_buy.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-4511250095791727638</id><published>2008-01-28T20:18:00.001Z</published><updated>2008-12-09T23:49:06.254Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='puper'/><category scheme='http://www.blogger.com/atom/ns#' term='macs'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='zlob'/><category scheme='http://www.blogger.com/atom/ns#' term='mac'/><category scheme='http://www.blogger.com/atom/ns#' term='apple'/><title type='text'>Are 'Mac' Users Safe?</title><content type='html'>For my first post, I feel it is necessary to address the issue of the majority of the 'Apple Mac' user community's almost impermeable attitude towards malware.&lt;br /&gt;The big question is:&lt;br /&gt;"Are 'Mac's safe from malware and other internet-based threats?"&lt;br /&gt;Bear in mind that 'Apple's new operating System: 'Leopard's default security settings actually turn off the firewall by default. Does this mean that even 'Apple' think they are impenetrable to malware?&lt;br /&gt;Well, as I assume most of you know: No, they are not. The reason for the simplicity of my answer is simply that (as many of you may be aware) there has already been malware produced that is built primarily to and can infect Macs.&lt;br /&gt;Aside from all the old 'script kiddie' malware affecting machines running on previous versions 'Apple's OS', the first majour incident of malware infecting Macs running OS X was 'OSX/Leap.A' (as named by 'Symantec'). 'OSX/Leap.A is a parasitic worm that possesses the ability to spread via 'Apple's 'iChat'. &lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_t1zE98SxW5s/R546Uj_N4xI/AAAAAAAAAAc/h9d224hDMD8/s1600-h/2006-021614-4006-99.2.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_t1zE98SxW5s/R546Uj_N4xI/AAAAAAAAAAc/h9d224hDMD8/s320/2006-021614-4006-99.2.gif" alt="" id="BLOGGER_PHOTO_ID_5160626347945354002" border="0" /&gt;&lt;/a&gt;The worm first appeared on a popular 'Apple' community domain, advertising itself as images of 'Apple's new OS: 'Leopard' under the filename 'latestpics.gz' . The worm appears to have primarily 'spyware' characteristics, monitoring the user's most used application and sending such data off to remote locations.&lt;br /&gt;&lt;br /&gt;The second article of malware to affect the 'OS X' operating system, was dubbed as  'OSX/DNSChanger' by 'F-Secure'. Created by the infamous Russian crime syndicate: the 'RBN', 'OSX/DNSChanger' is a simplified clone of the 'RBN's previous highly successful trojan: 'trojan.zlob'. 'OSX/DNSChanger' modifies the machines default 'Domain Name Server' ('DNS') in order to redirect traffic to advertising domains located in Ukraine. The trojan is currently distributed via pornographic domains as well as domains already created by the 'RBN' with intent to distribute 'trojan.zlob' such as 'dvdaccess[DOT]net' and requires the user to actually download and install it.&lt;br /&gt;The trojan even displays a mock 'EULA' ('End-User License Agreement') which simply illustrates the focus of social engineering present in the creation and distribution.&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_t1zE98SxW5s/R549dz_N4yI/AAAAAAAAAAk/U0U3vJlVTwg/s1600-h/agreement.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 210px; height: 149px;" src="http://1.bp.blogspot.com/_t1zE98SxW5s/R549dz_N4yI/AAAAAAAAAAk/U0U3vJlVTwg/s320/agreement.jpg" alt="" id="BLOGGER_PHOTO_ID_5160629805394027298" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;However, due to 'Mac's default security settings, users are required to enter their username and password prior to the instillation of the trojan. Many users may think that this will significantly cripple the distribution of the trojan. However, if this was true, why would the 'RBN' be so intent to create yet more variants (currently 'OSX/DNSChanger.PK')&lt;br /&gt;Seems people will do anything for porn.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-4511250095791727638?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/4511250095791727638/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=4511250095791727638' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/4511250095791727638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/4511250095791727638'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/01/are-mac-users-safe_28.html' title='Are &apos;Mac&apos; Users Safe?'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_t1zE98SxW5s/R546Uj_N4xI/AAAAAAAAAAc/h9d224hDMD8/s72-c/2006-021614-4006-99.2.gif' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7759993258951957706.post-4014989821853771205</id><published>2008-01-28T18:12:00.000Z</published><updated>2008-02-09T20:49:13.533Z</updated><category scheme='http://www.blogger.com/atom/ns#' term='phishing'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='scams'/><title type='text'>Welcome</title><content type='html'>&lt;span style="font-family:courier new;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family: arial;"&gt;Welcome to my blog.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;I have been meaning to make a blog for some time and now that I hav finally got around to it, I have decided to compose it around the topic of PC security, primarily 'malware' and internet-based scams.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;'Malware' is the collective term of malicious coding. This incorporates spyware, viruses, adware, worms and trojans.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family: arial;"&gt;In this instance, scams will refer primarily to aspects of 'social engineering' (the term used to depict the goading of an individual to preform an action they would not usually). An example of such scams is 'phishing' which refers to the harvesting of bank details and other such personal information via acts of social engineering. An example of phishing may be a clone of a bank's login page where the user may enter their bank credentials in order to preform a transaction. However, when the user enters their credentials into a clone of the bank's login page, they are simply e-mailed to the 'phisher' who is free to do with them as he wishes.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7759993258951957706-4014989821853771205?l=synthasoft.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://synthasoft.blogspot.com/feeds/4014989821853771205/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7759993258951957706&amp;postID=4014989821853771205' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/4014989821853771205'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7759993258951957706/posts/default/4014989821853771205'/><link rel='alternate' type='text/html' href='http://synthasoft.blogspot.com/2008/01/welcome.html' title='Welcome'/><author><name>d4rkr1d3r</name><uri>http://www.blogger.com/profile/14595630378904422743</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
