<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ÎÜñ&#124;‹ø\/\/ñ [ÐëÞrëçã†ëð]&#039;s Blog &#187; .security</title>
	<atom:link href="http://desigeek.com/blog/amit/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://desigeek.com/blog/amit</link>
	<description>Amit Bahree&#039;s insight into stuff…</description>
	<lastBuildDate>Fri, 27 Jan 2012 15:53:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Facebook and Security again</title>
		<link>http://desigeek.com/blog/amit/2010/02/17/facebook-and-security-again/</link>
		<comments>http://desigeek.com/blog/amit/2010/02/17/facebook-and-security-again/#comments</comments>
		<pubDate>Wed, 17 Feb 2010 11:05:59 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false">http://desigeek.com/blog/amit/2010/02/17/facebook-and-security-again/</guid>
		<description><![CDATA[Facebook and my views of it in the context of Privacy and Security are well known. This conversation with one of their (anonymous) employees detailing a few internal processes and tools is actually quite scary. Now, I don’t know if this is true and how much of this is true; but if I was working [...]]]></description>
			<content:encoded><![CDATA[<p>Facebook and <a href="http://desigeek.com/blog/amit/2010/01/06/is-it-time-to-relook-at-facebook-again/" target="_blank">my views of it in the context of Privacy and Security</a> are well known. <strong><a href="http://therumpus.net/2010/01/conversations-about-the-internet-5-anonymous-facebook-employee/?full=yes" target="_blank">This conversation</a></strong> with one of their (anonymous) employees detailing a few internal processes and tools is actually quite scary. </p>
<p>Now, I don’t know if this is true and how much of this is true; but if I was working for Facebook then all of this is quite logical and makes sense. And, technically all the things talked about is very feasible and not too challenging (of course am over simplifying here).</p>
<p>I do have to admit that the perf and scalability challenges are quite interesting and would love to sink my teeth in it – I guess I need to look at PHP first. <img src='http://desigeek.com/blog/amit/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2010%2F02%2F17%2Ffacebook-and-security-again%2F&amp;title=Facebook%20and%20Security%20again" id="wpa2a_2"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2010/02/17/facebook-and-security-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is it time to relook at Facebook again?</title>
		<link>http://desigeek.com/blog/amit/2010/01/06/is-it-time-to-relook-at-facebook-again/</link>
		<comments>http://desigeek.com/blog/amit/2010/01/06/is-it-time-to-relook-at-facebook-again/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 23:52:31 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.live and learn]]></category>
		<category><![CDATA[.personal]]></category>
		<category><![CDATA[.security]]></category>

		<guid isPermaLink="false">http://desigeek.com/blog/amit/2010/01/06/is-it-time-to-relook-at-facebook-again/</guid>
		<description><![CDATA[I still don’t get Facebook – despite being on it. If I want to talk to someone I will call them, email them, text them, meet them, have dinner with them &#8211; get the picture? I am quite worried about the security and privacy elements of it – or rather the lack of it. Those [...]]]></description>
			<content:encoded><![CDATA[<p>I still don’t get Facebook – despite being on it. If I want to talk to someone I will call them, email them, text them, meet them, have dinner with them &#8211; get the picture? </p>
<p>I am quite worried about the security and privacy elements of it – or rather the lack of it. Those who know me well (anyone?) <img src='http://desigeek.com/blog/amit/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  know I was not always this paranoid but after attending a few Security courses – I cannot bury my head in the sand anymore. </p>
<p>The main issue I have is the commercialisation of the information and it will just get more as Facebook heads to compete with Google – it is my information after all and I don’t feel comfortable sharing so much of it – even after locking it down and setting the various privacy settings. It is very easy to exploit. Take the example where Facebook changed the settings where Google <strong><u>by default</u></strong> would be indexing a lot of this information. And it is you and I as users who had to login and explicitly change a setting to stop it from doing that. Furthermore, despite all the <a href="http://www.facebook.com/security" target="_blank">security measures</a> that Facebook might have in place (and they don’t mention how internally within the company walls is the information protected) all it takes is one disgruntled employee (or soon-to-be-ex-employee) to take it all and walk out the door!</p>
<p>The secondary issue I have is the fact that more and more of the information, friends, contacts, etc is marketing and spam (a lot of what we see on Twitter as well). I personally am (thankfully) seeing much less spam on emails these days; but on the flip side I see a dramatic uptick of spam on social site. Not sure if this is because our email spam filters are finally smart enough to work, or perhaps the spammers found the social networking sites to be richer pickings?</p>
<p>It is good to know <a href="http://www.nytimes.com/2009/08/30/magazine/30FOB-medium-t.html" target="_blank">that there are others out there with the same concern</a> and with some sites such as <a href="http://suicidemachine.org/" target="_blank">Suicide Machine</a> allow you to “all your energy sucking social-networking profiles, kill your fake virtual friends, and completely do away with your Web2.0 alterego” [<em>sic</em>]. Of course, <a href="http://news.bbc.co.uk/1/hi/technology/8441080.stm" target="_blank">all has not been peachy</a> for Suicide Machine at the same time. <img src='http://desigeek.com/blog/amit/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>If you are thinking like me and really giving it a go then suggest you <a href="http://www.wikihow.com/Quit-Facebook" target="_blank">seek some help as well</a> to make it easier.</p>
<p>The irony of all of this however is that I will be posting this it to my Facebook wall and also tweeting it.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2010%2F01%2F06%2Fis-it-time-to-relook-at-facebook-again%2F&amp;title=Is%20it%20time%20to%20relook%20at%20Facebook%20again%3F" id="wpa2a_4"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2010/01/06/is-it-time-to-relook-at-facebook-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cloud computing Risk Assessment</title>
		<link>http://desigeek.com/blog/amit/2009/11/27/cloud-computing-risk-assessment/</link>
		<comments>http://desigeek.com/blog/amit/2009/11/27/cloud-computing-risk-assessment/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 17:23:58 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false">http://desigeek.com/blog/amit/2009/11/27/cloud-computing-risk-assessment/</guid>
		<description><![CDATA[ENISA (European Network &#38; Information Security Agency) – phew that is a mouthful have gotten together with a number of industry leaders and released a Risk assessment for Cloud computing. I have not finished reading this and only eyeballed this, but looks good.]]></description>
			<content:encoded><![CDATA[<p>ENISA (European Network &amp; Information Security Agency) – phew that is a mouthful have gotten together with a number of industry leaders and released a <a href="http://www.enisa.europa.eu/act/rm/files/deliverables/cloud-computing-risk-assessment/" target="_blank">Risk assessment for Cloud computing</a>. I have not finished reading this and only eyeballed this, but looks good.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2009%2F11%2F27%2Fcloud-computing-risk-assessment%2F&amp;title=Cloud%20computing%20Risk%20Assessment" id="wpa2a_6"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2009/11/27/cloud-computing-risk-assessment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Implementing malware with VMs &#8211; Subvirt</title>
		<link>http://desigeek.com/blog/amit/2009/11/27/implementing-malware-with-vms-subvirt/</link>
		<comments>http://desigeek.com/blog/amit/2009/11/27/implementing-malware-with-vms-subvirt/#comments</comments>
		<pubDate>Fri, 27 Nov 2009 13:55:42 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false">http://desigeek.com/blog/amit/2009/11/27/implementing-malware-with-vms-subvirt/</guid>
		<description><![CDATA[Microsoft Research (MSR) along with University of Michigan have an interesting paper that showcases a new type of malware specifically for Virtual Machines and hosts running the VM’s (Hper-V, VMWare Server, etc). This malware installs a monitor underneath the host of the VMs as a Virtual Machine Monitor (VMM). All VMM’s run in Ring 0 [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft Research (MSR) along with University of Michigan have an <a href="http://research.microsoft.com/pubs/67911/subvirt.pdf" target="_blank">interesting paper</a> that showcases a new type of malware specifically for Virtual Machines and hosts running the VM’s (Hper-V, VMWare Server, etc). This malware installs a monitor underneath the host of the VMs as a Virtual Machine Monitor (VMM). All VMM’s run in <a href="http://en.wikipedia.org/wiki/Ring_(computer_security)" target="_blank">Ring 0</a> (kernel mode).</p>
<p>Essentially this is similar to a <a href="http://en.wikipedia.org/wiki/Rootkit" target="_blank">rootkit</a> and they call this a VM based rootkit (VMBR). A VMBR looks to get itself installed underneath the host and essentially runs the target OS as guest. It needs to manipulate the boot sequence to load it self before the ‘guest’ OS. This allows them to run silently with the ‘guest’ OS not even aware of their presence. Of course this makes their detection quite difficult (if not impossible) by the ‘guest’ OS. </p>
<p>They go on to implement a couple of prototypes which subvert both XP and Linux. The paper discusses ways to detect and prevent VMBR’s such as such as security software running even below the VMBR in an isolated layer which is not controlled by the VMBR. Another option is to boot up from a ‘safe’ medium like a ROM drive or a secure VMM which won’t stop a VMBR, but can at least help detect it.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2009%2F11%2F27%2Fimplementing-malware-with-vms-subvirt%2F&amp;title=Implementing%20malware%20with%20VMs%20%26%238211%3B%20Subvirt" id="wpa2a_8"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2009/11/27/implementing-malware-with-vms-subvirt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>On Security</title>
		<link>http://desigeek.com/blog/amit/2008/11/12/on-security/</link>
		<comments>http://desigeek.com/blog/amit/2008/11/12/on-security/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 22:27:59 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Security is a Social Construction &#8211; Andrew Martin]]></description>
			<content:encoded><![CDATA[<p>Security is a <em>Social Construction</em> &#8211; <a href="http://www.softeng.ox.ac.uk/Andrew.Martin/" target="_blank">Andrew Martin</a></p>
<p><img src="http://desigeek.com/weblog/aggbug.aspx?PostID=5242" width="1" height="1"></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2008%2F11%2F12%2Fon-security%2F&amp;title=On%20Security" id="wpa2a_10"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2008/11/12/on-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Worm (BlackAngel.B) spreading via MSN Messenger</title>
		<link>http://desigeek.com/blog/amit/2006/06/16/new-worm-blackangel-b-spreading-via-msn-messenger/</link>
		<comments>http://desigeek.com/blog/amit/2006/06/16/new-worm-blackangel-b-spreading-via-msn-messenger/#comments</comments>
		<pubDate>Fri, 16 Jun 2006 04:17:00 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Interesting new worm based on the likes of the movies such as the ring or feardotcom spreading via MSN. It is quite dangerous as it disables many security and antivirus software running such as antivirus, firewalls and even Windows programs like the Task Manager and RegEdit. It is easy to recognize, as you will get [...]]]></description>
			<content:encoded><![CDATA[<p>Interesting new worm based on the likes of the movies such as <a href="http://www.imdb.com/title/tt0295254/">the ring</a> or <a href="http://www.imdb.com/title/tt0295254/">feardotcom</a> spreading via MSN. It is quite dangerous as it disables many security and antivirus software running such as antivirus, firewalls and even Windows programs like the Task Manager and RegEdit. It is easy to recognize, as you will get the following instant message &#8211; which downloads a avi (only that is an exe), when you run that your system is infected and all your contacts on MSN will be send the same instant message.</p>
<blockquote dir=ltr style="MARGIN-RIGHT: 0px">
<p>- jaja look a that http://galeon.&lt;blocked&gt;verti2/fantasma.zip<br />- mira este video http://galeon.&lt;blocked&gt;verti2/fantasma.zip jaja</p>
</blockquote>
<p>So, be on the lookout and please <strong>do not</strong> click on that link!</p>
<p>More information can be <a href="http://enterprises.pandasoftware.com/virus_info/encyclopedia/overview.aspx?idvirus=120738">found here</a>.</p>
<p><img src="http://desigeek.com/weblog/aggbug.aspx?PostID=3094" width="1" height="1"></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2006%2F06%2F16%2Fnew-worm-blackangel-b-spreading-via-msn-messenger%2F&amp;title=New%20Worm%20%28BlackAngel.B%29%20spreading%20via%20MSN%20Messenger" id="wpa2a_12"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2006/06/16/new-worm-blackangel-b-spreading-via-msn-messenger/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Amex Trojan &#8211; Beware</title>
		<link>http://desigeek.com/blog/amit/2006/05/22/amex-trojan-beware/</link>
		<comments>http://desigeek.com/blog/amit/2006/05/22/amex-trojan-beware/#comments</comments>
		<pubDate>Mon, 22 May 2006 13:11:00 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[If you use American Express, then beware there is&#160;a Trojan going around that asks for secure information when when logged into Amex&#8217;s secure site. Amex has provided a screen shot of what it looks like, check it out so you know in case you see it. You can read more on this at eweek here.]]></description>
			<content:encoded><![CDATA[<p>If you use American Express, then beware there is&nbsp;a Trojan going around that asks for secure information when when logged into Amex&#8217;s secure site. <a href="http://www10.americanexpress.com/sif/cda/page/0,1641,24381,00.asp">Amex has provided a screen shot</a> of what it looks like, check it out so you know in case you see it. You can read more on this at <a href="http://www.eweek.com/article2/0,1895,1955288,00.asp">eweek here</a>.<img src="http://desigeek.com/weblog/aggbug.aspx?PostID=3088" width="1" height="1"></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2006%2F05%2F22%2Famex-trojan-beware%2F&amp;title=Amex%20Trojan%20%26%238211%3B%20Beware" id="wpa2a_14"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2006/05/22/amex-trojan-beware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Journal (MSJ) Scam</title>
		<link>http://desigeek.com/blog/amit/2006/01/07/microsoft-journal-msj-scam/</link>
		<comments>http://desigeek.com/blog/amit/2006/01/07/microsoft-journal-msj-scam/#comments</comments>
		<pubDate>Sat, 07 Jan 2006 00:22:00 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Stephen Toub at Microsoft warns about a scam where people have been getting mailings (not emails) offering them MSJ &#8211; this a scam as MSJ is not published anymore! Don&#8217;t send them your hard earned money.&#160;&#160;&#160;]]></description>
			<content:encoded><![CDATA[<p>Stephen Toub at Microsoft <a href="http://blogs.msdn.com/toub/archive/2006/01/06/510099.aspx">warns about a scam</a> where people have been getting mailings (not emails) offering them MSJ &#8211; this a scam as MSJ is not published anymore! Don&#8217;t send them your hard earned money.&nbsp;&nbsp;&nbsp;<img src="http://desigeek.com/weblog/aggbug.aspx?PostID=1829" width="1" height="1"></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2006%2F01%2F07%2Fmicrosoft-journal-msj-scam%2F&amp;title=Microsoft%20Journal%20%28MSJ%29%20Scam" id="wpa2a_16"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2006/01/07/microsoft-journal-msj-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Santa Instant Message Worm!</title>
		<link>http://desigeek.com/blog/amit/2005/12/21/santa-instant-message-worm/</link>
		<comments>http://desigeek.com/blog/amit/2005/12/21/santa-instant-message-worm/#comments</comments>
		<pubDate>Wed, 21 Dec 2005 17:29:00 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Beware, there is a new IM worm that promises a picture of Santa, but instead delivers a rootkit! The initial message will appear to come from someone on your IM list and will include &#8220;santaclause.aol.com/a?&#124;&#8221; DONT click on that link! The worm is called IM.GiftCom.All. Read more here.]]></description>
			<content:encoded><![CDATA[<p>Beware, there is a new IM worm that promises a picture of Santa, but instead delivers a <b>rootkit</b>! The initial message will appear to come from someone on your IM list and will include &#8220;santaclause.aol.com/a?|&#8221; <b>DONT click on that link!</b> The worm is called IM.GiftCom.All. Read <a href="http://www.pcworld.com/news/article/0,aid,124028,00.asp">more here</a>.<img src="http://desigeek.com/weblog/aggbug.aspx?PostID=1789" width="1" height="1"></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2005%2F12%2F21%2Fsanta-instant-message-worm%2F&amp;title=Santa%20Instant%20Message%20Worm%21" id="wpa2a_18"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2005/12/21/santa-instant-message-worm/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Combating rootkit with rootkit</title>
		<link>http://desigeek.com/blog/amit/2005/12/20/combating-rootkit-with-rootkit/</link>
		<comments>http://desigeek.com/blog/amit/2005/12/20/combating-rootkit-with-rootkit/#comments</comments>
		<pubDate>Tue, 20 Dec 2005 17:51:00 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[While I totally agree with the concept of combacting rootkit with rootkit when it comes to the new generation of spyware, etc. (remember Sony&#8217;s need for control fiasco), but my concern is there are many lazy programmers (yours truly included) out there and most companies are in a hurry to ship a product out the [...]]]></description>
			<content:encoded><![CDATA[<p>While I totally agree with the concept of <a href="http://www.eweek.com/article2/0,1895,1901907,00.asp">combacting rootkit with rootkit</a> when it comes to the new generation of spyware, etc. (remember <a href="http://desigeek.com/weblog/amit/archive/2005/11/16/1708.aspx">Sony&#8217;s <strike>need for control</strike> fiasco</a>), but my concern is there are many lazy programmers (yours truly included) out there and most companies are in a hurry to ship a product out the door without testing as thoroughly as one should, which means when dealing at the Kernel level for most end-users it could be a experience of more <a href="http://bsod.org/">BSOD&#8217;s</a>.<img src="http://desigeek.com/weblog/aggbug.aspx?PostID=1787" width="1" height="1"></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2005%2F12%2F20%2Fcombating-rootkit-with-rootkit%2F&amp;title=Combating%20rootkit%20with%20rootkit" id="wpa2a_20"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2005/12/20/combating-rootkit-with-rootkit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More DOS Pings</title>
		<link>http://desigeek.com/blog/amit/2005/12/20/more-dos-pings/</link>
		<comments>http://desigeek.com/blog/amit/2005/12/20/more-dos-pings/#comments</comments>
		<pubDate>Tue, 20 Dec 2005 17:40:00 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Here are a few more DOS pings from last night, I think these are poor souls who don&#8217;t know they have infected machines (or lets hope so). There is one (218.201.43.148) from China belonging to someone called Ming Chen in Chongqing, might have to drop his/her ISP an email. inetnum: 218.201.40.1 &#8211; 218.201.43.254netname: CQ-CHONGQINGYIDONGcountry: CNdescr: [...]]]></description>
			<content:encoded><![CDATA[<p>Here are a few more DOS pings from last night, I think these are poor souls who don&#8217;t know they have infected machines (or lets hope so). There is one (218.201.43.148) from China belonging to someone called Ming Chen in Chongqing, might have to drop his/her ISP an email.</p>
<p>inetnum: 218.201.40.1 &#8211; 218.201.43.254<br />netname: CQ-CHONGQINGYIDONG<br />country: CN<br />descr: Chong Qing Yi Dong IDC Yong HU<br />descr: 40-43 Duan Qi Yong</p>
<p>person: ming chen<br />nic-hdl: MC285-AP<br />e-mail: <a href="mailto:chenming@cq.chinamobile.com">chenming@cq.chinamobile.com</a><br />address: NO.300, L building, 6th street, keyuan, high-tech, industrial zone, Chongqing,400041<br />phone: +86-13983247186<br />fax-no: +86-13594249044<br />country: cn<br />changed: <a href="mailto:weichenguang@chinamobile.com">weichenguang@chinamobile.com</a> 20040625</p>
<p>Firewall log:<br />Tue Dec 20 05:27:18 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 05:27:18 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 05:27:18 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 05:33:39 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 05:33:59 2005 1 Blocked by DoS protection 66.235.167.62 <br />Tue Dec 20 05:36:42 2005 1 Blocked by DoS protection 221.203.145.54 <br />Tue Dec 20 05:40:00 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 05:46:22 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 05:46:22 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 05:46:22 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 05:46:22 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 05:47:07 2005 1 Blocked by DoS protection 221.1.204.251 <br />Tue Dec 20 05:51:20 2005 1 Blocked by DoS protection 202.96.87.41 <br />Tue Dec 20 05:52:44 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 05:52:44 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 05:52:44 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 05:52:44 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 05:59:05 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 06:04:25 2005 1 Blocked by DoS protection 58.18.64.162 <br />Tue Dec 20 06:04:25 2005 1 Blocked by DoS protection 58.18.64.162 <br />Tue Dec 20 06:05:28 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 06:05:28 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 06:09:37 2005 1 Blocked by DoS protection 221.203.145.54 <br />Tue Dec 20 06:11:48 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 06:11:48 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 06:18:09 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 06:18:09 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 06:18:09 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 06:18:09 2005 1 Blocked by DoS protection 218.201.43.148 <br />Tue Dec 20 06:19:15 2005 1 Blocked by DoS protection 82.49.110.167 <br />Tue Dec 20 06:28:17 2005 1 Blocked by DoS protection 202.96.87.41 <br />Tue Dec 20 06:30:40 2005 1 Blocked by DoS protection 213.142.181.48</p>
<p><img src="http://desigeek.com/weblog/aggbug.aspx?PostID=1786" width="1" height="1"></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2005%2F12%2F20%2Fmore-dos-pings%2F&amp;title=More%20DOS%20Pings" id="wpa2a_22"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2005/12/20/more-dos-pings/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sony Rootkit DRM Saga Gets Messy</title>
		<link>http://desigeek.com/blog/amit/2005/11/16/sony-rootkit-drm-saga-gets-messy/</link>
		<comments>http://desigeek.com/blog/amit/2005/11/16/sony-rootkit-drm-saga-gets-messy/#comments</comments>
		<pubDate>Wed, 16 Nov 2005 23:16:00 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[From PCMag, Sony&#8217;s incredible gaffe &#8211; creating a DRM applet that loads prior to the operating system &#8211; has caused an incredible furor. Sony agreed to suspend the program, but that&#8217;s not all. Now the rest of the world is piling on. Microsoft now says it will delete the rootkit directly with its anti-spyware program, [...]]]></description>
			<content:encoded><![CDATA[<p>From PCMag, Sony&#8217;s incredible gaffe &#8211; creating a DRM applet that loads prior to the operating system &#8211; has caused an incredible furor. <a href="http://www.eweek.com/article2/0,1895,1885868,00.asp">Sony agreed to suspend the program</a>, but that&#8217;s not all. Now the rest of the world is piling on. <a href="http://www.eweek.com/article2/0,1895,1886122,00.asp">Microsoft now says it will delete the rootkit directly</a> with its anti-spyware program, and it&#8217;ll be included in the December version of the Malicious Software Removal Tool. And it looks like <a href="http://www.extremedrm.com/article/Sonys+DRM+Rootkit+Comes+in+Mac+Flavor+Too/165172_1.aspx">the Macintosh, which is also affected by the rootkit</a>, might still be at risk.</p>
<p>I would be very careful of any of the new CD&#8217;s I buy &#8211; if they are from Sony/BMG then they might have this!</p>
<p><img src="http://desigeek.com/weblog/aggbug.aspx?PostID=1708" width="1" height="1"></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2005%2F11%2F16%2Fsony-rootkit-drm-saga-gets-messy%2F&amp;title=Sony%20Rootkit%20DRM%20Saga%20Gets%20Messy" id="wpa2a_24"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2005/11/16/sony-rootkit-drm-saga-gets-messy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploit code chases two Firefox flaws</title>
		<link>http://desigeek.com/blog/amit/2005/05/10/exploit-code-chases-two-firefox-flaws/</link>
		<comments>http://desigeek.com/blog/amit/2005/05/10/exploit-code-chases-two-firefox-flaws/#comments</comments>
		<pubDate>Tue, 10 May 2005 17:12:00 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Two vulnerabilities in the popular Firefox browser have been rated &#8220;extremely critical&#8221; because exploit code is now available to take advantage of them. The cross-site scripting and remote system access flaws were discovered in Firefox version 1.0.3, but other versions may also be affected, said security company Secunia, which issued the ratings Sunday. One flaw [...]]]></description>
			<content:encoded><![CDATA[<p>Two vulnerabilities in the popular Firefox browser have been rated &#8220;extremely critical&#8221; because exploit code is now available to take advantage of them. The cross-site scripting and remote system access flaws were discovered in Firefox version 1.0.3, but other versions may also be affected, said security company Secunia, which issued the ratings Sunday. One flaw involves &#8220;IFRAME&#8221; JavaScript URLs, which are not properly protected from being executed in the context of another URL in the history list. A second vulnerability exists in the IconURL parameter in InstallTrigger.install(). Information passed to this parameter is not properly verified before it&#8217;s used, allowing an attacker to gain user privileges. This flaw could allow an attacker to gain and escalate user privileges on a system.</p>
<p>You can disable JavaScript as a workaround for now, but when a patch is released, I guess I would <a href="http://desigeek.com/weblog/amit/archive/2005/04/19.aspx">need to reinstall</a> this all over again. *sigh*. And everyone says (including me) that this is more secure than IE. You can <a href="http://news.zdnet.com/2100-1009_22-5700204.html">read the details here</a>.</p>
<p><strong>Update:</strong> You can more information about the bug and the work around <a href="http://www.mozilla.org/security/announce/mfsa2005-42.html">from Mozilla here</a>.</p>
<p><img src="http://desigeek.com/weblog/aggbug.aspx?PostID=730" width="1" height="1"></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2005%2F05%2F10%2Fexploit-code-chases-two-firefox-flaws%2F&amp;title=Exploit%20code%20chases%20two%20Firefox%20flaws" id="wpa2a_26"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2005/05/10/exploit-code-chases-two-firefox-flaws/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Identity theft &#8211; done *legally* by cops&#8230;</title>
		<link>http://desigeek.com/blog/amit/2005/04/14/identity-theft-done-legally-by-cops/</link>
		<comments>http://desigeek.com/blog/amit/2005/04/14/identity-theft-done-legally-by-cops/#comments</comments>
		<pubDate>Thu, 14 Apr 2005 20:58:00 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Got this via internal communities at Avanade. Seems like in Ohio it is legal for cops to steal someone else&#8217;s identity as long as it is part of an investigation without your consent &#8211; quite scary I think.]]></description>
			<content:encoded><![CDATA[<p>Got this via internal communities at Avanade. Seems like in Ohio it is <a href="http://politechbot.com/2005/04/13/identity-theft-is/">legal for cops to steal someone else&#8217;s identity</a> as long as it is part of an investigation without your consent &#8211; quite scary I think.<img src="http://desigeek.com/weblog/aggbug.aspx?PostID=675" width="1" height="1"></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2005%2F04%2F14%2Fidentity-theft-done-legally-by-cops%2F&amp;title=Identity%20theft%20%26%238211%3B%20done%20%2Alegally%2A%20by%20cops%26%238230%3B" id="wpa2a_28"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2005/04/14/identity-theft-done-legally-by-cops/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WEP Dead Again?</title>
		<link>http://desigeek.com/blog/amit/2005/04/14/wep-dead-again/</link>
		<comments>http://desigeek.com/blog/amit/2005/04/14/wep-dead-again/#comments</comments>
		<pubDate>Thu, 14 Apr 2005 19:35:00 +0000</pubDate>
		<dc:creator>Amit Bahree</dc:creator>
				<category><![CDATA[.security]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[SecurityFocus has two part article that looks at the new generation of WEP cracking tools for WiFi networks, which offer dramatically faster speeds for penetration testers over the previous generation of tools. In many cases, a WEP key can be determined in seconds or minutes. Part one, compares the latest KoreK based tools that perform [...]]]></description>
			<content:encoded><![CDATA[<p><img title="" src="http://download.freshmeat.net/screenshots/48699_thumb.png" align=right border=0>SecurityFocus has <a href="http://www.securityfocus.com/infocus/1814">two part article</a> that looks at the new generation of WEP cracking tools for WiFi networks, which offer dramatically faster speeds for penetration testers over the previous generation of tools. In many cases, a WEP key can be determined in seconds or minutes. <a href="http://www.securityfocus.com/infocus/1814">Part one</a>, compares the latest KoreK based tools that perform passive statistical analysis and brute-force cracking on a sample of collected WEP traffic. <a href="http://www.securityfocus.com/infocus/1824">Part two</a>, looks at active attack vectors, including a method to dramatically increase the rate of packet collection to make statistical attacks even more potent.</p>
<p>On August 8th, 2004, a hacker named KoreK posted new WEP statistical cryptanalysis attack code (soon to become a tool called chopper) to the NetStumbler forums. While chopper is functional, it is not currently maintained, and the attacks have since seen better implementations in aircrack and WepLab. However, the KoreK attacks change everything. No longer are millions of packets required to crack a WEP key; no longer does the number of obviously &#8220;weak&#8221; or &#8220;interesting&#8221; IVs matter. With the new attacks, the critical ingredient is the total number of unique IVs captured, and a key can often be cracked with hundreds of thousands of packets, rather than millions.</p>
<p>One of the tools discussed is <a href="http://www.cr0.net:8040/code/network/aircrack/">Aircrack</a>, which implements KoreK&#8217;s attacks as well as improved FMS, aircrack provides the fastest and most effective statistical attacks available. To give aircrack a try, simply collect as many packets as possible from a WEP encrypted wireless network, save them as a pcap file, and then start aircrack from the command line.</p>
<p>More Information:</p>
<ul>
<li><a href="http://tinyurl.com/5mexu">http://tinyurl.com/5mexu</a>
<li><a href="http://tinyurl.com/6y2rr">http://tinyurl.com/6y2rr</a>
<li><a href="http://tinyurl.com/2k23o">http://tinyurl.com/2k23o</a>
<li><a href="http://tinyurl.com/3syo7">http://tinyurl.com/3syo7</a></li>
</ul>
<p><img src="http://desigeek.com/weblog/aggbug.aspx?PostID=674" width="1" height="1"></p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fdesigeek.com%2Fblog%2Famit%2F2005%2F04%2F14%2Fwep-dead-again%2F&amp;title=WEP%20Dead%20Again%3F" id="wpa2a_30"><img src="http://desigeek.com/blog/amit/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://desigeek.com/blog/amit/2005/04/14/wep-dead-again/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

