<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1523707327337901416</id><updated>2012-01-29T03:54:47.055-08:00</updated><category term='flash'/><category term='cyberwarfare'/><category term='hd moore'/><category term='LATVIA'/><category term='Egypt'/><category term='cyberwar'/><category term='Murofet'/><category term='encoding'/><category term='bug'/><category term='eldorado rootkit'/><category term='malware'/><category term='CVE-2010-0806'/><category term='Zbot.B'/><category term='xpl.pdf'/><category term='info'/><category term='russian business network'/><category term='ebnvnos.com'/><category term='Operation Shady RAT'/><category term='RSA'/><category term='318x'/><category term='firefox'/><category term='mobile malware'/><category term='cve-2011-0609'/><category term='CVE-2010-4091'/><category term='full disclosure'/><category term='dllhijacking'/><category term='cve-2010-2568'/><category term='tld'/><category term='cymru'/><category term='printSeps()'/><category term='TDSS'/><category term='coreflood'/><category term='java'/><category term='Black Hat Seo'/><category term='vmware'/><category term='sourceforge'/><category term='exposed'/><category term='robtex'/><category term='vispa'/><category term='metasploit'/><category term='printSeps'/><category term='mebroot'/><category term='rootkit'/><category term='e107'/><category term='AS8452'/><category term='pdf'/><category term='APT'/><category term='torpig'/><category term='flash player.'/><category term='bgplay'/><category term='exploits'/><category term='pushbot'/><category term='conficker.gen'/><category term='anonops'/><category term='sinowal'/><category term='HTRAN'/><category term='CVE-2004-0194'/><category term='china'/><category term='massive spreading'/><category term='ettercap'/><category term='owned'/><category term='DDOS'/><category term='pbot'/><category term='exploit'/><category term='fuzzing'/><category term='Bo'/><category term='bgp'/><category term='0day'/><category term='korea'/><category term='debugging'/><category term='malware analysis'/><category term='reverse engineering'/><category term='CVE-2010-3962'/><category term='VB.AAG Trojan'/><category term='sql injection'/><category term='censorship'/><category term='paimei'/><category term='as'/><category term='data breach'/><category term='leechers'/><category term='script'/><category term='conficker.e'/><category term='afcore'/><category term='irc'/><category term='Internet isolation'/><category term='Android'/><category term='exploiting'/><category term='SpyEye'/><category term='Backdoor.Pirpi'/><category term='Licat'/><category term='DroidKungFu'/><category term='breach'/><category term='bot'/><category term='Exploit-Comele'/><category term='downadup.gen'/><category term='exploi'/><category term='conficker.c'/><category term='poc'/><category term='CVE-2010-0249'/><category term='memory corruption'/><category term='javascript-analytics.com'/><category term='Egypt Telecom'/><category term='CVE-2010-3765'/><category term='DLL hijacking'/><category term='waledac'/><category term='botnet'/><category term='stuxnet'/><category term='Aurora'/><category term='chymine.a'/><category term='entrypoint'/><category term='rogue'/><category term='diginotar'/><category term='bulkbin.cn'/><category term='loic'/><category term='rbn'/><category term='mmspicture.ru'/><category term='CVE-2009-4324'/><category term='lsass'/><title type='text'>extraexploit</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>97</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7445088261888353752</id><published>2012-01-26T23:18:00.000-08:00</published><updated>2012-01-29T03:54:47.074-08:00</updated><title type='text'>the last/final touch!</title><summary type='text'>It's very sad to recognize and discover that the screenshots on my blog, which for some reason have been saved in the "Gallery" of my Android mobile phone, once cleared from there, will be deleted from the Google cloud! Someone could confirm this ? This blog has been to me a lot although I have ceased to update it ... but with this last touch .. I almost want to finalize it.

what remains of my </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7445088261888353752/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2012/01/last-touch.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7445088261888353752'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7445088261888353752'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2012/01/last-touch.html' title='the last/final touch!'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-9161919654827941976</id><published>2011-09-06T03:38:00.000-07:00</published><updated>2011-09-15T01:49:44.225-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cyberwar'/><category scheme='http://www.blogger.com/atom/ns#' term='diginotar'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><category scheme='http://www.blogger.com/atom/ns#' term='APT'/><title type='text'>DigiNotar facts - just some links</title><summary type='text'>



DigiNotar Certificate Authority breach “Operation Black Tulip”

http://t.co/VC91bjo 

DigiNotar CA compromise
http://community.websense.com/blogs/securitylabs/archive/2011/08/30/diginotar-ca-compromise.aspx 

Certificate hacker probably paid by Iran, say victimised firms
http://computerworld.co.nz/news.nsf/security/certificate-hacker-probably-paid-by-iran-say-victimized-firms

DigiNotar </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/9161919654827941976/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2011/09/diginotar-facts-just-some-links.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/9161919654827941976'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/9161919654827941976'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2011/09/diginotar-facts-just-some-links.html' title='DigiNotar facts - just some links'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-2086860530408859319</id><published>2011-08-04T02:18:00.000-07:00</published><updated>2011-08-04T02:49:34.099-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cyberwar'/><category scheme='http://www.blogger.com/atom/ns#' term='HTRAN'/><category scheme='http://www.blogger.com/atom/ns#' term='Operation Shady RAT'/><category scheme='http://www.blogger.com/atom/ns#' term='APT'/><title type='text'>Operation Shady RAT - HTran</title><summary type='text'>HTran and the Advanced Persistent Threat
http://www.secureworks.com/research/threats/htran/

The code  http://www.pudn.com/downloads119/sourcecode/windows/network/detail508294.html. 
(appears also in the Secureworks analysis)

What follows it's an abstract of the code:

 </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/2086860530408859319/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2011/08/operation-shady-rat-htran-is-this-code.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2086860530408859319'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2086860530408859319'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2011/08/operation-shady-rat-htran-is-this-code.html' title='Operation Shady RAT - HTran'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-nerfdsf3Im8/TjpjW_gDE7I/AAAAAAAABB0/DxWSTVEJhO0/s72-c/htran.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-6652975876595834124</id><published>2011-07-04T06:12:00.000-07:00</published><updated>2012-01-26T23:19:52.755-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2004-0194'/><category scheme='http://www.blogger.com/atom/ns#' term='encoding'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><title type='text'>an old bug for a new job ? CVE-2004-0194</title><summary type='text'>
A couple of months ago I receive an interesting challenge for get the final (I think) step in the job selection path for a big company (not a well known exploit research company but probably if you are reading this post you are using once of their os). The challenge it consist in the writing an exploit for the CVE-2004-0194. Obviously, at the first step I did follow, was a good googling acrivity</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/6652975876595834124/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2011/07/old-bug-for-new-job-cve-2004-0194.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6652975876595834124'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6652975876595834124'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2011/07/old-bug-for-new-job-cve-2004-0194.html' title='an old bug for a new job ? CVE-2004-0194'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-goi_MWbNzJA/ThG5KYpgAAI/AAAAAAAAA9U/q4zkN55vo1I/s72-c/NEOHAPSIS+-+Peace+of+Mind+Through+Integrity+and+Insight+-+Mozilla+Firefox_2011-07-04_14-56-07.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-3741072392835435700</id><published>2011-06-22T07:13:00.000-07:00</published><updated>2011-06-22T13:49:31.299-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TDSS'/><title type='text'>TDSS - SRVs list</title><summary type='text'>I just found via pastebin (http://pastebin.com/jWDhEfGB) a domains list related to TDSS. The SRVs , in according with this analysis http://resources.infosecinstitute.com/tdss4-part-2/, are the C&amp;C from where bots receive commands.What's sound a bit strange is that the content in the pastebin above match with the syntax used in the configuration file of the rootkit. Anyway is possible count 2514 </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/3741072392835435700/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2011/06/tdss-srvs-list.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3741072392835435700'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3741072392835435700'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2011/06/tdss-srvs-list.html' title='TDSS - SRVs list'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7768553909932247716</id><published>2011-06-07T05:33:00.000-07:00</published><updated>2012-01-26T23:33:33.877-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DroidKungFu'/><category scheme='http://www.blogger.com/atom/ns#' term='Android'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile malware'/><category scheme='http://www.blogger.com/atom/ns#' term='china'/><title type='text'>DroidKungFu - just some piece of code</title><summary type='text'>Following the trend of the moment, I play a bit with the sample of DroidKungFu retrieved from the  contagiodump malware sample repository. For obtaining the JAR archive I used dex2jar (http://code.google.com/p/dex2jar/downloads/list) after that I extracted the Dalvik Executable Format embedded in the APK. Once obtained the JAR file is very easy obtain the clear code with (for example) Java </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7768553909932247716/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2011/06/droidkungfu-just-some-piece-of-code.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7768553909932247716'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7768553909932247716'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2011/06/droidkungfu-just-some-piece-of-code.html' title='DroidKungFu - just some piece of code'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-a8krR0DGeB0/Te4W6CHRS8I/AAAAAAAAA8w/fvuBs7ck5n4/s72-c/shot001.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-4857918347350799840</id><published>2011-03-18T07:19:00.000-07:00</published><updated>2011-03-18T07:21:10.622-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='flash player.'/><category scheme='http://www.blogger.com/atom/ns#' term='bug'/><title type='text'>FlashUtil10m_Plugin.exe command line crash</title><summary type='text'>Is interesting observing how nowadays some old style bug are still available. I think that this one is not a security bug but a deeper investigation is left to all whose are interested.Anyway is sufficient pass a single char as command line parameter to this FlashUtil10m_Plugin.exe (also called Flash Player Installer/Uninstaller) for generate a crash. If you are Admin appear something like the </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/4857918347350799840/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2011/03/flashutil10mpluginexe-command-line.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4857918347350799840'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4857918347350799840'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2011/03/flashutil10mpluginexe-command-line.html' title='FlashUtil10m_Plugin.exe command line crash'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh4.googleusercontent.com/-RCNH2zebZqQ/TYNmzoFO0SI/AAAAAAAAA8g/lRSVUp3oqCA/s72-c/flashcrash.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-2905440232448788400</id><published>2011-03-15T09:00:00.000-07:00</published><updated>2011-04-04T07:42:13.818-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='RSA'/><category scheme='http://www.blogger.com/atom/ns#' term='cve-2011-0609'/><category scheme='http://www.blogger.com/atom/ns#' term='data breach'/><title type='text'>cve-2011-0609 - bugix blog analysis</title><summary type='text'>April 4, 2011 - Update:
RSA has release a blog post where is described that in the recently data-breach is been used this issue:
http://blogs.rsa.com/rivner/anatomy-of-an-attack/

March 15, 2011:  
A researcher has just added a very interesting analysis about this 0day:

bugix blog cve-2010-0609 analysis - by villys777 
http://bugix-security.blogspot.com/2011/03/cve-2011-0609-</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/2905440232448788400/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2011/03/cve-2011-0609-bugix-blog-analysis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2905440232448788400'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2905440232448788400'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2011/03/cve-2011-0609-bugix-blog-analysis.html' title='cve-2011-0609 - bugix blog analysis'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-8816299686305873099</id><published>2011-03-06T04:13:00.000-08:00</published><updated>2011-03-16T18:48:09.066-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mmspicture.ru'/><category scheme='http://www.blogger.com/atom/ns#' term='mobile malware'/><title type='text'>mmspicture.ru - mobile malware depot</title><summary type='text'>Following a well known mailing list (clean-mx aka viruswatch) it was been retrieved the following URL:

http://mmspicture.ru/mms112/mms112.jar (md5: 33EA90E2029478D47D33409B5F48E4EB)

The JAR file is already detected from Virustotal. Playing a bit around the URL path is possible retrieve another JAR file: 

http://mmspicture.ru/mms113/mms113.jar

The MD5 (4CC0EBCE1428EE3649C67A13734F2EDE) of this</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/8816299686305873099/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2011/03/mmspictureru-mobile-malware-depot.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8816299686305873099'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8816299686305873099'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2011/03/mmspictureru-mobile-malware-depot.html' title='mmspicture.ru - mobile malware depot'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='https://lh5.googleusercontent.com/-yWSp84Zje9k/TXNnNdfwmUI/AAAAAAAAA8E/FHyahgEjrTo/s72-c/javasshot001.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-4178313689334547061</id><published>2011-02-02T12:36:00.001-08:00</published><updated>2011-02-02T15:33:58.876-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Internet isolation'/><category scheme='http://www.blogger.com/atom/ns#' term='AS8452'/><category scheme='http://www.blogger.com/atom/ns#' term='Egypt Telecom'/><title type='text'>Egypt Telecom back online– ASN8452 TE DATA– prefix 81.10.0.0/17</title><summary type='text'>The prefix 81.10.0.0/17 “ALL-Routes” seems announced again to the rest of the world via Telecom Italia Sparkle Autonomous System (ASN 6762). Here the animation made  with BGPlay:







The time range is between the 29 of January 2011 00:00 and 2 of February 2011 08:00 PM (local time). For more info on bgplay see my previous post  http://extraexploit.blogspot.com/2011/01/</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/4178313689334547061/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2011/02/egypt-telecom-back-online-asn8452-te.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4178313689334547061'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4178313689334547061'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2011/02/egypt-telecom-back-online-asn8452-te.html' title='Egypt Telecom back online– ASN8452 TE DATA– prefix 81.10.0.0/17'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-6341740085920559177</id><published>2011-01-28T05:45:00.000-08:00</published><updated>2011-02-02T12:48:19.059-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='censorship'/><category scheme='http://www.blogger.com/atom/ns#' term='Internet isolation'/><category scheme='http://www.blogger.com/atom/ns#' term='AS8452'/><category scheme='http://www.blogger.com/atom/ns#' term='Egypt Telecom'/><category scheme='http://www.blogger.com/atom/ns#' term='bgplay'/><category scheme='http://www.blogger.com/atom/ns#' term='Egypt'/><category scheme='http://www.blogger.com/atom/ns#' term='cyberwarfare'/><title type='text'>Egypt Telecom AS isolation - BGPlay show it ?</title><summary type='text'>January 31, 2011 – Update:
An interesting snapshot of Egyptian's malware activity. ASN 20928 appears like still active

Egypt's malware activity post internet shutdownhttp://www.unveillance.com/latest-news/egypts-malware-activity-post-internet-shutdown/

Why One Egyptian ISP is Still Online 
http://newsgrange.com/why-one-egyptian-isp-is-still-online/

January 29, 2011 – Update:

I try to make the</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/6341740085920559177/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2011/01/egypt-telecom-as-isolation-bgplay-show.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6341740085920559177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6341740085920559177'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2011/01/egypt-telecom-as-isolation-bgplay-show.html' title='Egypt Telecom AS isolation - BGPlay show it ?'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/TULHmC9r0VI/AAAAAAAAA7o/BPcb5KqfSTw/s72-c/egypt001.PNG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7905162261028762228</id><published>2011-01-22T12:34:00.001-08:00</published><updated>2011-02-03T01:26:49.005-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='entrypoint'/><category scheme='http://www.blogger.com/atom/ns#' term='e107'/><category scheme='http://www.blogger.com/atom/ns#' term='breach'/><category scheme='http://www.blogger.com/atom/ns#' term='sourceforge'/><category scheme='http://www.blogger.com/atom/ns#' term='bot'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>the sourceforge entry point seems still active</title><summary type='text'>February 3, 2011 - Update:

A discussion on e107 official web site: http://e107.org/comment.php?comment.news.878


February 2, 2011 - Update:   
  
Just another evidence of the sourceforge breach used by a web bot. At least , from the following screenshot, seems that the entrypoint was detected by a web vuln scanner bot. The following figure shown a well known method by web bots to post in some </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7905162261028762228/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2011/01/sourceforge-entry-point-seems-still.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7905162261028762228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7905162261028762228'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2011/01/sourceforge-entry-point-seems-still.html' title='the sourceforge entry point seems still active'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_uioOPkGBTsE/TUlp24Iu0-I/AAAAAAAAA74/AOofSh3xHHU/s72-c/sourceforgeevidence.PNG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7191218177705762554</id><published>2010-12-29T10:06:00.001-08:00</published><updated>2010-12-30T00:03:04.940-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exposed'/><category scheme='http://www.blogger.com/atom/ns#' term='pbot'/><category scheme='http://www.blogger.com/atom/ns#' term='ettercap'/><category scheme='http://www.blogger.com/atom/ns#' term='breach'/><category scheme='http://www.blogger.com/atom/ns#' term='sourceforge'/><category scheme='http://www.blogger.com/atom/ns#' term='bot'/><category scheme='http://www.blogger.com/atom/ns#' term='owned'/><title type='text'>some considerations on Ettercap source code repository breach</title><summary type='text'>Recently it’s been released a new issue of a zine called “owned and exposed” (http://www.exploit-db.com/papers/15823/). I have to admit I laughed a lot when I saw this picture.                        I think that the picture above is the truth of what the security field is today. Anyway , ending my personal considerations, I would show you a mind map that I made during a past research on web bot </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7191218177705762554/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/12/some-considerations-on-ettercap-source.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7191218177705762554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7191218177705762554'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/12/some-considerations-on-ettercap-source.html' title='some considerations on Ettercap source code repository breach'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_uioOPkGBTsE/TRt4sDpWsfI/AAAAAAAAA64/uBlcTMYcxGo/s72-c/ownedandexposed_thumb%5B4%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-6591326666264634186</id><published>2010-12-14T01:33:00.000-08:00</published><updated>2010-12-14T17:24:39.787-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='loic'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='anonops'/><title type='text'>LOIC 1.1.1.15 - Crafted C&amp;C Channel Topic Could Lead A Crash</title><summary type='text'>Following the trend of these days I played (locally) with one of the latest release of LOIC (Low Orbit Ion Cannon DDOS Tool). Inserting a long (not so) string on the topic of a C&amp;C irc channel, there seems to be a memory corruption condition.

 The screen shot above show a crafted topic that trigger the issue. The impacted tested released is the 1.1.1.15. A few more details related to the .NET </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/6591326666264634186/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/12/loic-11115-buffer-overflow.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6591326666264634186'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6591326666264634186'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/12/loic-11115-buffer-overflow.html' title='LOIC 1.1.1.15 - Crafted C&amp;C Channel Topic Could Lead A Crash'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/TQc5UUAz6EI/AAAAAAAAA6k/c_p20H8dtD0/s72-c/loicbof.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7080032269034200183</id><published>2010-11-30T03:15:00.000-08:00</published><updated>2010-11-30T03:17:25.258-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='printSeps'/><category scheme='http://www.blogger.com/atom/ns#' term='poc'/><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2010-4091'/><category scheme='http://www.blogger.com/atom/ns#' term='pdf'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><title type='text'>cve-2010-4091 exploited ? – 0.2 – Adobe Reader 9.3.0</title><summary type='text'>Starting from the malwaretracker sample (see my previous posts) seem that edx and ecx are set to some interesting values:    </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7080032269034200183/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/11/cve-2010-4091-exploited-02-adobe-reader.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7080032269034200183'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7080032269034200183'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/11/cve-2010-4091-exploited-02-adobe-reader.html' title='cve-2010-4091 exploited ? – 0.2 – Adobe Reader 9.3.0'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_uioOPkGBTsE/TPTdQxcEq0I/AAAAAAAAA6c/7eqDgYMBDU8/s72-c/overwritten_thumb%5B3%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-5056704185624649049</id><published>2010-11-25T08:43:00.001-08:00</published><updated>2010-11-26T02:33:08.983-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='printSeps'/><category scheme='http://www.blogger.com/atom/ns#' term='poc'/><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2010-4091'/><category scheme='http://www.blogger.com/atom/ns#' term='pdf'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><title type='text'>cve-2010-4091 exploited ? – 0.1</title><summary type='text'>Trying to reversing the shell code contained within the PDF that seem exploit CVE-2010-4091, in according with the sample reported by MalwareTracker, it’s been founded the following URL:   http://212.117.168.89/ad/fi_16.php                         From Robtex:                         The URL above at this time is down or not more available. Did really exploited for retrieve malware from </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/5056704185624649049/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/11/cve-2010-4091-exploited-01.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5056704185624649049'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5056704185624649049'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/11/cve-2010-4091-exploited-01.html' title='cve-2010-4091 exploited ? – 0.1'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_uioOPkGBTsE/TO6SLHwPl0I/AAAAAAAAA6M/VykhH7kkUUk/s72-c/image_thumb%5B3%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-1957385644476162943</id><published>2010-11-19T06:40:00.001-08:00</published><updated>2010-11-24T14:00:08.301-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='printSeps'/><category scheme='http://www.blogger.com/atom/ns#' term='poc'/><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2010-4091'/><category scheme='http://www.blogger.com/atom/ns#' term='pdf'/><title type='text'>cve-2010-4091 exploited ?</title><summary type='text'>November 24,  2010 – Update:  Looking for other  exploiting attempts I found a Malwaretracker sample where the PDF seem spread via URL that contains:  filepdf.php@v=zday     The following analysis report the objects used within this PDF (that is different from the fulldisclosure PDF):  http://www.malwaretracker.com/pdfsearch.php?hash=0398e68507882a38a26a341058c94653&amp;submit=Search     November 22 </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/1957385644476162943/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/11/cve-2010-4091-exploited.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1957385644476162943'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1957385644476162943'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/11/cve-2010-4091-exploited.html' title='cve-2010-4091 exploited ?'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_uioOPkGBTsE/TO0hZNBIpYI/AAAAAAAAA6E/l9rh-MkoK0I/s72-c/image_thumb%5B3%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-5718083974596246122</id><published>2010-11-11T16:57:00.000-08:00</published><updated>2010-11-27T15:59:23.027-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='printSeps'/><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2010-4091'/><category scheme='http://www.blogger.com/atom/ns#' term='pdf'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><title type='text'>cve-2010-4091 – printSeps - exploitation attempts</title><summary type='text'>November 26, 2010 – update:     This is a very useful  presentation (from Immunity Sec) where is possible get some methods for approach the reversing of  Java script engine in Adobe Reader context:        Attacking Embedded Languages     http://www.immunitysec.com/downloads/ID_reCON_2008.odp        November 16, 2010 – update:      In previous post I didn’t report where is the place in the </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/5718083974596246122/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/11/cve-2010-4091-printseps-exploitation.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5718083974596246122'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5718083974596246122'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/11/cve-2010-4091-printseps-exploitation.html' title='cve-2010-4091 – printSeps - exploitation attempts'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_uioOPkGBTsE/TOKuqHxJeeI/AAAAAAAAA5Y/woww-pPWtmc/s72-c/image_thumb%5B3%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-5163498914798326035</id><published>2010-11-04T08:24:00.000-07:00</published><updated>2010-11-27T15:51:01.429-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2010-4091'/><category scheme='http://www.blogger.com/atom/ns#' term='pdf'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='xpl.pdf'/><category scheme='http://www.blogger.com/atom/ns#' term='printSeps()'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><title type='text'>full disclosure xpl.pdf Adober Reader 9.4 poc - printSeps() - cve-2010-4091</title><summary type='text'>     November 26,2010 – Update:            Thank you, Mario, but our printSeps() is in another castle !      http://esec-lab.sogeti.com/dotclear/index.php?post/2010/11/26/Thank-you-Mario-but-our-printSeps%28%29-is-in-another-castle  November 22, 2010 – Update:  Who’s looking for eggs in your PDF?  (reported also in  cve-2010-4091 exploited ?)      http://labs.m86security.com/2010/11/</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/5163498914798326035/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/11/full-disclosure-xplpdf-adober-reader-94.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5163498914798326035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5163498914798326035'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/11/full-disclosure-xplpdf-adober-reader-94.html' title='full disclosure xpl.pdf Adober Reader 9.4 poc - printSeps() - cve-2010-4091'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/TNf8hzluK1I/AAAAAAAAA5E/efI3o7cbR8s/s72-c/printseps0003.PNG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-5246424657732455201</id><published>2010-11-03T09:09:00.000-07:00</published><updated>2010-11-12T01:35:27.214-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2010-3962'/><category scheme='http://www.blogger.com/atom/ns#' term='Backdoor.Pirpi'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><title type='text'>CVE-2010-3962 - yet another Internet Explorer RCE</title><summary type='text'>Update - November, 12 2010:
Amnesty International Hong Kong Website Injected With Latest Internet Explorer 0-day 
http://community.websense.com/blogs/securitylabs/archive/2010/11/10/Amnesty-International-Hong-Kong-Website-Injected-With-Latest-Internet-Explorer-0_2D00_day-.aspx

 
Update - November, 5 2010:
CVE-2010-3962 - BindShell proof of concept:
http://www.offensive-security.com/0day/ie-</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/5246424657732455201/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/11/cve-2010-3962-yet-another-internet.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5246424657732455201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5246424657732455201'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/11/cve-2010-3962-yet-another-internet.html' title='CVE-2010-3962 - yet another Internet Explorer RCE'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_uioOPkGBTsE/TNJ8QdpimzI/AAAAAAAAA48/paJTav91ieA/s72-c/cve-2010-3962.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-4432438860368456209</id><published>2010-10-28T02:40:00.000-07:00</published><updated>2010-10-29T03:05:11.577-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='firefox'/><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2010-3765'/><category scheme='http://www.blogger.com/atom/ns#' term='poc'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><title type='text'>CVE-2010-3765 - proof of concept - update</title><summary type='text'>October, 29 1010 - UPDATE: the working exploit (in according with BugX blog): 
http://bugix-security.blogspot.com/2010/10/firefox-exploitcve-2010-3765.html
   
October, 28 2010 
For those who still do not know .. The proof of concept for CVE-2010-3765 is the following:



 















 More details at: https://bugzilla.mozilla.org/show_bug.cgi?id=607222. The issue seem resolved with Firefox </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/4432438860368456209/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/10/cve-2010-3765-proof-of-concept.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4432438860368456209'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4432438860368456209'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/10/cve-2010-3765-proof-of-concept.html' title='CVE-2010-3765 - proof of concept - update'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_uioOPkGBTsE/TMlEW_6V-NI/AAAAAAAAA44/MwWjjSD01UA/s72-c/cve-2010-CVE-3765.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-4687804388596796065</id><published>2010-10-14T08:24:00.001-07:00</published><updated>2010-11-02T03:22:14.915-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Murofet'/><category scheme='http://www.blogger.com/atom/ns#' term='Zbot.B'/><category scheme='http://www.blogger.com/atom/ns#' term='Licat'/><title type='text'>Some domains for the LICAT / Murofet / Trojan/ZBOT.B threat</title><summary type='text'>Update (2 November): A deep and very itneresting analysis from Trend Micro:
http://us.trendmicro.com/imperia/md/content/us/trendwatch/researchandanalysis/file-patching_zbot_variants_-_zeus_2.0_levels_up__oct_2010_.pdf

Update (15 October):  ThreatExpert has release the domain name generation algorithm for MUROFET/Licat 
http://blog.threatexpert.com/2010/10/domain-name-generator-for-murofet.html

</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/4687804388596796065/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/10/some-domains-for-licatmurofettrojanzbot.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4687804388596796065'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4687804388596796065'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/10/some-domains-for-licatmurofettrojanzbot.html' title='Some domains for the LICAT / Murofet / Trojan/ZBOT.B threat'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-5681959278754853763</id><published>2010-10-06T07:12:00.001-07:00</published><updated>2011-01-23T06:02:26.657-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Black Hat Seo'/><title type='text'>dollars javascript code – yet another Javascript obfuscation method for cc frauds ( and black hat seo ) – part 0.2</title><summary type='text'>Trying to find some common factors in the pages included in the compromised sites (as indicated in the previous post (http://extraexploit.blogspot.com/2010/10/dollars-javascript-code-yet-another.html) there is evidence of a large number of sites that are suffering the same problem. In particular, using keywords that are common to many of these malicious pages, you have the following results:    
</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/5681959278754853763/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/10/dollars-javascript-code-yet-another_06.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5681959278754853763'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5681959278754853763'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/10/dollars-javascript-code-yet-another_06.html' title='dollars javascript code – yet another Javascript obfuscation method for cc frauds ( and black hat seo ) – part 0.2'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_uioOPkGBTsE/TKyDg32dvDI/AAAAAAAAA4k/JWrpIjGy-6c/s72-c/sshot002_thumb%5B4%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-2941473789882491532</id><published>2010-10-05T16:17:00.000-07:00</published><updated>2011-01-25T02:16:38.719-08:00</updated><title type='text'>dollars javascript code – yet another Javascript obfuscation method for cc frauds</title><summary type='text'>January 25,  2011 – Update:
a detailed analysis also where is reported my post:
Internet  Explorer  exSploit Milk codes  
http://utf-8.jp/public/20101106/avtokyo.pptx
 
October 5, 2010:
From MDL forum, I get a post where a user (many thanks to Edgar) has been reported a strange Javascript code injected in some Italian web site. Specifically the message is located at the following URL: 
 http://</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/2941473789882491532/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/10/dollars-javascript-code-yet-another.html#comment-form' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2941473789882491532'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2941473789882491532'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/10/dollars-javascript-code-yet-another.html' title='dollars javascript code – yet another Javascript obfuscation method for cc frauds'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_uioOPkGBTsE/TKuzaGchYDI/AAAAAAAAA3A/uE3eKBGtndM/s72-c/dollarscode001_thumb%5B15%5D.png?imgmax=800' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-2657846651038808961</id><published>2010-08-25T19:23:00.000-07:00</published><updated>2010-08-30T07:24:42.791-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploits'/><category scheme='http://www.blogger.com/atom/ns#' term='exploi'/><category scheme='http://www.blogger.com/atom/ns#' term='dllhijacking'/><title type='text'>DLL Hijacking - my test cases on a default HP notebook installation - CyberLink products vulnerable</title><summary type='text'>CyberLink products appears like vulnerable. The Cyberlink tools (such as powet2go) exist in the default installation of the HP 64bit notebook (with  Microsoft Windows 7).

















. I have check and test the proof of concept generated by dllhijacking. The products are:

- CyberLink PowerDirector v7
- CyberLink Power2Go DVD v6.0

The  issue is trigger with the iso,pdl,pds,p2g and p2i file </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/2657846651038808961/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/08/dll-hijacking-my-test-cases-on-default.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2657846651038808961'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2657846651038808961'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/08/dll-hijacking-my-test-cases-on-default.html' title='DLL Hijacking - my test cases on a default HP notebook installation - CyberLink products vulnerable'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/THXRNJB-rfI/AAAAAAAAA0s/hxtKUigna1I/s72-c/dllhijackinghp001.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-4208565796847880205</id><published>2010-08-25T08:45:00.000-07:00</published><updated>2010-08-26T00:46:01.540-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DLL hijacking'/><category scheme='http://www.blogger.com/atom/ns#' term='exploiting'/><category scheme='http://www.blogger.com/atom/ns#' term='hd moore'/><title type='text'>DLL Hijacking - my test cases</title><summary type='text'> One of my testcases list on a VM system. 


</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/4208565796847880205/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/08/dll-hijacking.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4208565796847880205'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4208565796847880205'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/08/dll-hijacking.html' title='DLL Hijacking - my test cases'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_uioOPkGBTsE/THU6hTHw-kI/AAAAAAAAA0U/GXvziTCo1hM/s72-c/testcases001.PNG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-5251166410171250453</id><published>2010-08-25T02:05:00.000-07:00</published><updated>2010-08-25T02:46:04.511-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DLL hijacking'/><category scheme='http://www.blogger.com/atom/ns#' term='metasploit'/><category scheme='http://www.blogger.com/atom/ns#' term='hd moore'/><title type='text'>Sorry, you may have found a bug.... (in Fiddler)</title><summary type='text'>Playing with the HD Moore tools for dll hicjacking stuff  (Exploiting DLL Hijacking Flaws) , I found this interesting result on once of my VM:



 I don't know if I have time to spent for a deep investigation about this possible Fiddler bug... but in some cases the side effects are your best friends.</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/5251166410171250453/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/08/sorry-you-have-may-found-bug-in-fiddler.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5251166410171250453'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5251166410171250453'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/08/sorry-you-have-may-found-bug-in-fiddler.html' title='Sorry, you may have found a bug.... (in Fiddler)'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_uioOPkGBTsE/THTcSFOKCAI/AAAAAAAAA0M/Z0uFLH_ZpwA/s72-c/fiddlercrashed.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-6276385076258517951</id><published>2010-07-30T06:12:00.000-07:00</published><updated>2010-08-31T06:37:38.172-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='info'/><category scheme='http://www.blogger.com/atom/ns#' term='tld'/><category scheme='http://www.blogger.com/atom/ns#' term='VB.AAG Trojan'/><title type='text'>strange .info TLD domains</title><summary type='text'>Looking for something that might attract my attention I found the following URL:

9-4-1-0-1-4-1-1-1-0-.0-0-0-0-0-0-0-0-0-0-0-0-0-49-0-0-0-0-0-0-0-0-0-0-0-0-0.info
If at a first look may appears like a nonsense URL, googling more I found this message on Symantec community blog where is said something  about:

http://www.symantec.com/connect/blogs/malware-infections

Seems that this kind of domains</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/6276385076258517951/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/07/strange-info-tld-domains.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6276385076258517951'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6276385076258517951'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/07/strange-info-tld-domains.html' title='strange .info TLD domains'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/TFLMdcAAUnI/AAAAAAAAAz0/TyB-1vq3sdY/s72-c/strangeinfo0001.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7329109504213173909</id><published>2010-07-27T08:53:00.000-07:00</published><updated>2010-07-28T08:51:26.667-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='stuxnet'/><category scheme='http://www.blogger.com/atom/ns#' term='chymine.a'/><category scheme='http://www.blogger.com/atom/ns#' term='cve-2010-2568'/><title type='text'>Win32/Chymine.A</title><summary type='text'>Reading something about this trojan, which use the CVE-2010-2568 as spreading vector, I found that 
the binary is located at hxxxp://205.209.171.119/bin.exe. The process try to contact the following host:

imoges.dyndns.tv

From Robtex:
  
&lt;!--
 /* Font Definitions */
 @font-face
	{font-family:Verdana;
	panose-1:2 11 6 4 3 5 4 4 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7329109504213173909/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/07/win32chyminea.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7329109504213173909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7329109504213173909'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/07/win32chyminea.html' title='Win32/Chymine.A'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7211152619012111623</id><published>2010-06-23T06:57:00.000-07:00</published><updated>2010-07-06T06:15:03.605-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='SpyEye'/><category scheme='http://www.blogger.com/atom/ns#' term='Black Hat Seo'/><category scheme='http://www.blogger.com/atom/ns#' term='Bo'/><title type='text'>SpyEye C&amp;C and spreading with Microsoft SpyNet Black Hat Seo technique</title><summary type='text'>The following domain typo squat it's been detected googling the  URL:

hxxxxxp://www.microsoft-spynet.com 

As  know, Spy Net is a Microsoft forum where are discussed new threats,  malware and so on.
More info about this service are placed here:   http://en.wikipedia.org/wiki/Microsoft_SpyNet

In the following  screen shot it's reported result (shown with a smile) from Google: 


The red point  </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7211152619012111623/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/06/spyeye-spreading-with-spynet-black-hat.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7211152619012111623'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7211152619012111623'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/06/spyeye-spreading-with-spynet-black-hat.html' title='SpyEye C&amp;C and spreading with Microsoft SpyNet Black Hat Seo technique'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_uioOPkGBTsE/TCIP9y_fFtI/AAAAAAAAAzE/E9urVPXNUFg/s72-c/spyeye0001.JPG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-6833699442717124364</id><published>2010-06-13T08:37:00.000-07:00</published><updated>2010-06-13T08:38:04.735-07:00</updated><title type='text'>memory exploiting techniques timeline</title><summary type='text'>A good reference about time line of memory exploiting techniques 

http://ilm.thinkst.com/folklore/index.shtml</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/6833699442717124364/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/06/memory-exploiting-techniques-timeline.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6833699442717124364'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6833699442717124364'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/06/memory-exploiting-techniques-timeline.html' title='memory exploiting techniques timeline'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-8976602424588602034</id><published>2010-05-19T09:05:00.000-07:00</published><updated>2010-05-30T08:15:41.161-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><category scheme='http://www.blogger.com/atom/ns#' term='paimei'/><title type='text'>finally PAIMEI</title><summary type='text'>PAIMEI installed. Great framework!.

















The following code shown my "hello world!" PAIMEI script: given a process id, basically this script detect the creations of new threads and dump the first 5 assembly instructions for each one. In addition are dumped the process registers values during the CreateThread:

















Also, I've found a good resource for learn more about </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/8976602424588602034/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/05/finally-paimei.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8976602424588602034'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8976602424588602034'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/05/finally-paimei.html' title='finally PAIMEI'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/S_QMMEjp2EI/AAAAAAAAAyk/w890gTCEjk0/s72-c/paimei.JPG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-4566273073519351956</id><published>2010-03-10T08:12:00.000-08:00</published><updated>2010-03-11T02:46:08.712-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2010-0806'/><category scheme='http://www.blogger.com/atom/ns#' term='fuzzing'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><title type='text'>CVE-2010-0806 - Internet Explorer 6/7 0 day</title><summary type='text'>Some notes about:
Internet Explorer 0-day targeted in spam runs
http://www.sophos.com/blogs/sophoslabs/?p=9030

Targeted Internet Explorer 0day Attack Announced http://www.avertlabs.com/research/blog/index.php/2010/03/09/targeted-internet-explorer-0day-attack-announced-cve-2010-0806/
Robtex queries for the Mcafee reported URLs:
hxxxxp://topix21century.com/20100307.htm - http://www.robtex.com/ip/</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/4566273073519351956/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/03/cve-2010-0806-internet-explorer-67-0.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4566273073519351956'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4566273073519351956'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/03/cve-2010-0806-internet-explorer-67-0.html' title='CVE-2010-0806 - Internet Explorer 6/7 0 day'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/S5fEp2VrP0I/AAAAAAAAAyU/QCg_NMaj39E/s72-c/test0001.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-3208899960989130356</id><published>2010-03-03T03:24:00.000-08:00</published><updated>2010-03-03T08:18:50.125-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='firefox'/><title type='text'>Firefox 3.6.x - 0 day for document.write - yet another</title><summary type='text'>from misc sources:
http://www.exploit-db.com/exploits/11617

Bugzilla Mozilla Repository:
https://bugzilla.mozilla.org/buglist.cgi?query_format=specific&amp;order=relevance+desc&amp;bug_status=__open__&amp;product=Firefox&amp;content=crash

Misc Crash Stats for Mozilla projects:
http://crash-stats.mozilla.com/


"IE is not the only evil"</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/3208899960989130356/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/03/firefox-36x-0-day-for-documentwrite.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3208899960989130356'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3208899960989130356'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/03/firefox-36x-0-day-for-documentwrite.html' title='Firefox 3.6.x - 0 day for document.write - yet another'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-3592762231767027608</id><published>2010-03-03T02:36:00.000-08:00</published><updated>2010-03-03T02:36:39.871-08:00</updated><title type='text'>The Command Structure of the Aurora Botnet  - Damballa paper</title><summary type='text'>I just received the following link to a very nice analysis. IMHO, a clear example of how the analysis  of this kind should be made. I will try to take it into account if I will write other analysis in the future.

The Command Structure of the Aurora Botnet
http://www.damballa.com/downloads/r_pubs/Aurora_Botnet_Command_Structure.pdf</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/3592762231767027608/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/03/command-structure-of-aurora-botnet.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3592762231767027608'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3592762231767027608'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/03/command-structure-of-aurora-botnet.html' title='The Command Structure of the Aurora Botnet  - Damballa paper'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-4158998283830578112</id><published>2010-02-19T06:18:00.000-08:00</published><updated>2010-02-22T05:24:22.662-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='full disclosure'/><category scheme='http://www.blogger.com/atom/ns#' term='firefox'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><title type='text'>Firefox 3.6 "0day" - trying to find more info (and more "0day")</title><summary type='text'>About the recently Firefox 3.6 "0day":
http://hackingexpose.blogspot.com/2010/02/attack-code-for-firefox-zero-day-goes.html

Where to try to find some more info (or "how to try to find more 0day"):

Firefox  -  Crash Reports Stat 
http://crash-stats.mozilla.com/

Mozilla Bugzilla Repository 
https://bugzilla.mozilla.org/buglist.cgi?query_format=specific&amp;order=relevance+desc&amp;bug_status=__open__&amp;</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/4158998283830578112/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/02/firefox-36-0day-trying-to-find-more.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4158998283830578112'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4158998283830578112'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/02/firefox-36-0day-trying-to-find-more.html' title='Firefox 3.6 &quot;0day&quot; - trying to find more info (and more &quot;0day&quot;)'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/S36mV6hUScI/AAAAAAAAAyE/pYr0T2Wlw3s/s72-c/shot001.PNG' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-3455149331961325868</id><published>2010-01-27T06:54:00.001-08:00</published><updated>2010-01-27T08:03:54.677-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='robtex'/><category scheme='http://www.blogger.com/atom/ns#' term='Aurora'/><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2010-0249'/><title type='text'>using Robtex for fun and… (profit?)</title><summary type='text'>During some analysis related to robtex response I have found this funny (and not so useful) way for spending yours spare time. In this case what Robtex say about “Google vs China” (Operation Aurora)                         query used:  http://www.robtex.com/dot/www.google.com,72.14.204.103/20,as15169,72.14.204.103,chinese%20own%20google!1AS2,3NET1,4PTR0,1337A9,0UP4!4.png  </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/3455149331961325868/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/01/how-to-use-robtex-for-fun-and-profit.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3455149331961325868'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3455149331961325868'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/01/how-to-use-robtex-for-fun-and-profit.html' title='using Robtex for fun and… (profit?)'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh4.ggpht.com/_uioOPkGBTsE/S2BTu_7AQ6I/AAAAAAAAAx0/TyVZMiMp_i4/s72-c/image_thumb%5B5%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7172685386701573788</id><published>2010-01-25T08:57:00.001-08:00</published><updated>2010-01-25T08:57:32.559-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2010-0249'/><title type='text'>CVE-2010-0249 in the wild – part 0.3</title><summary type='text'>hxxxxp://h.d5d3.com/     (AS46475 LIMESTONENETWORKS Limestone Networks Inc.)                                                    MDecoder output:                         ThreatExpert Response:  http://www.threatexpert.com/report.aspx?md5=c229cac9ada74afaf59216fa67721be0  </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7172685386701573788/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/01/cve-2010-0249-in-wild-part-03.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7172685386701573788'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7172685386701573788'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/01/cve-2010-0249-in-wild-part-03.html' title='CVE-2010-0249 in the wild – part 0.3'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_uioOPkGBTsE/S13NcbfKfSI/AAAAAAAAAxU/5NomiljIAYI/s72-c/2010-01-25_174600_thumb%5B3%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-4332293604767471635</id><published>2010-01-24T06:06:00.001-08:00</published><updated>2010-01-24T07:28:54.182-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2010-0249'/><title type='text'>CVE-2010-0249 in the wild – part 0.2</title><summary type='text'>hxxxxp://www.qvodcom1.com/360/ie2.htm      (AS30058 FDCSERVERS AS for FDC Servers)               Click to enlarge           Malzilla and MDecoder output:               Click to enlarge             Wepawet analysis for hxxp://www.qvodcom1.com/360/ie2.htm:                http://wepawet.cs.ucsb.edu/view.php?hash=df830232d7e8735d15ead31b6835c30d&amp;t=1264092203&amp;type=js   (this post is under update)  </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/4332293604767471635/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/01/cve-2010-0249-in-wild-part-02.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4332293604767471635'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4332293604767471635'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/01/cve-2010-0249-in-wild-part-02.html' title='CVE-2010-0249 in the wild – part 0.2'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_uioOPkGBTsE/S1xUiRMJSxI/AAAAAAAAAw0/cl2W8xMyYh4/s72-c/ss0003245_thumb%5B3%5D.png?imgmax=800' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-672477114380363032</id><published>2010-01-23T05:11:00.001-08:00</published><updated>2010-03-03T07:28:20.687-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='leechers'/><title type='text'>extraexploit blog it’s been copied</title><summary type='text'>I’ve found a blog that replicate some my posts without any permission or request.   

The links are:  
http://omercakir.wordpress.com/2010/01/23/cve-2010-0249-xx222-8866-org/   
http://omercakir.wordpress.com/2010/01/20/cve-2010-0249-exploit-comele-hydraq-aurora-iexplorer-0day/   

handled by Ömer ÇAKIR.  Can I use him as backup :) ?

Yet another security blogger that use post of other bloggers:
</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/672477114380363032/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/01/extraexploit-blog-its-been-copied.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/672477114380363032'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/672477114380363032'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/01/extraexploit-blog-its-been-copied.html' title='extraexploit blog it’s been copied'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7747922846344194717</id><published>2010-01-23T04:59:00.001-08:00</published><updated>2010-01-24T07:28:06.599-08:00</updated><title type='text'>CVE-2010-0249 in the wild – part 0.1</title><summary type='text'>   hxxxxxp://mxd0102.3322.org/njk/index.htm      (AS4134 CHINA-TELECOM China Telecom)                         Click to enlarge          The URL above it’s been request using (IMHO a very useful tool) MDecoder 0.4 (http://mtian.net/down/MDecoder.zip). As shown in the following picture is detected a binary file downloaded from www.ynew.net:               Click to enlarge          Some network info </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7747922846344194717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/01/cve-2010-0249-in-wild-part-01.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7747922846344194717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7747922846344194717'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/01/cve-2010-0249-in-wild-part-01.html' title='CVE-2010-0249 in the wild – part 0.1'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_uioOPkGBTsE/S1ryqIf3VFI/AAAAAAAAAu8/ZNSDCJFAJ98/s72-c/image_thumb%5B9%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-1780228463061144200</id><published>2010-01-22T14:06:00.000-08:00</published><updated>2010-01-23T00:35:08.063-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='Aurora'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2010-0249'/><title type='text'>CVE-2010-0249 in the wild - xx222.8866.org and others – part 0</title><summary type='text'>   (22/01/2010)         hxxxxxxxxxxtp://www.babooa562.com/xp/48/au.htm     (AS30058 FDCSERVERS AS for FDC Servers)                            hxxxxxxxxxxtp://www.tsqzsb.cn/xp/13/au.htm     (AS4134 CHINA-TELECOM China Telecom)                           hxxxxxxxxxp://www.fsus.cn:85/ss/au.htm     (AS35908  - VPLSNET)                            hxxxxxxxxxp://googleie2.23sys23.cn/pz/au.htm     (AS4213</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/1780228463061144200/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/01/cve-2010-0249-in-wild-xx2228866org-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1780228463061144200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1780228463061144200'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/01/cve-2010-0249-in-wild-xx2228866org-and.html' title='CVE-2010-0249 in the wild - xx222.8866.org and others – part 0'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_uioOPkGBTsE/S1m3qbufh7I/AAAAAAAAAsQ/dSMhOJeIIHY/s72-c/image_thumb%5B7%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-5972812148482097191</id><published>2010-01-20T07:05:00.000-08:00</published><updated>2011-04-23T17:56:07.418-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exploit-Comele'/><category scheme='http://www.blogger.com/atom/ns#' term='Aurora'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2010-0249'/><title type='text'>IExplorer 0day CVE-2010-0249 – Exploit-Comele / Hydraq / Aurora</title><summary type='text'>From Microsoft KB it’s been released an advisory related to a possible “0 day” for IExplorer 6,7 and 8.  It’s an issue used for the recent attack against Google and others big companies through an Advanced Persistent Threat:     Why it’s been called Aurora ? (an old info)      http://www.chinadaily.com.cn/world/2007-09/27/content_6139437.htm        Operation Aurora: Clues in the Code     http://</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/5972812148482097191/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/01/iexplorer-0day-cve-2010-0249.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5972812148482097191'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5972812148482097191'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/01/iexplorer-0day-cve-2010-0249.html' title='IExplorer 0day CVE-2010-0249 – Exploit-Comele / Hydraq / Aurora'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_uioOPkGBTsE/S1K4734oXnI/AAAAAAAAApI/SAympIUe_Uk/s72-c/aurora01%5B83%5D.png?imgmax=800' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-2120212819820616968</id><published>2010-01-18T05:22:00.001-08:00</published><updated>2010-01-19T08:19:16.674-08:00</updated><title type='text'>Is not a security bug but… (RDP - mstsc.exe / mstscax.dll crash)</title><summary type='text'>It’s been detected on once of my system (XP SP3 updated to all MS bulletins. One note: the MS09-044 it was related to RDP Client Version 5.0.) this memory exception condition (under investigation) within “mstscax.dll”:                                        A better view permit to locate the method exposed by ActiveX MSTSCAX.dll where is triggered the issue (CClientHandler::GetAndParseXml(void)):</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/2120212819820616968/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/01/is-not-security-bug-but-mstscexe-rdp.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2120212819820616968'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2120212819820616968'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/01/is-not-security-bug-but-mstscexe-rdp.html' title='Is not a security bug but… (RDP - mstsc.exe / mstscax.dll crash)'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_uioOPkGBTsE/S1RgrULwt7I/AAAAAAAAApQ/JXeQNe1LXfM/s72-c/rdpcrash0001%5B7%5D.jpg?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-4962947493021781375</id><published>2010-01-12T03:16:00.001-08:00</published><updated>2010-01-23T12:43:42.161-08:00</updated><title type='text'>Adobe CVE-2009-4324 – Another one with AsciiHexDecode waiting for the patch day</title><summary type='text'>Many thanks to contagiodump for the following PDF:  http://contagiodump.blogspot.com/2010/01/jan-7-us-j-indiastrategicdialogue-from.html  In the document above it’s been detected the following PDF “not so rare” method for obfuscating the PDF directives:                         The #&lt;value&gt; sequences are evaluated by Adobe PDF reader as ASCII chars. So the snippet above became the following:</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/4962947493021781375/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/01/adobe-cve-2009-4324-another-one-with.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4962947493021781375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4962947493021781375'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/01/adobe-cve-2009-4324-another-one-with.html' title='Adobe CVE-2009-4324 – Another one with AsciiHexDecode waiting for the patch day'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh6.ggpht.com/_uioOPkGBTsE/S0xZ3oPLlJI/AAAAAAAAAiw/jYZBw--nBKU/s72-c/sshot001_thumb%5B2%5D.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-1565983230457267696</id><published>2010-01-08T07:52:00.001-08:00</published><updated>2010-01-09T17:12:20.595-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='vispa'/><category scheme='http://www.blogger.com/atom/ns#' term='DDOS'/><category scheme='http://www.blogger.com/atom/ns#' term='LATVIA'/><category scheme='http://www.blogger.com/atom/ns#' term='bgp'/><title type='text'>Trying to analyze VISPA ISP Outage</title><summary type='text'>TheRegister (http://www.theregister.co.uk/2010/01/08/vispa_ddoa/) has published today a news about an outage (caused by DDOS from Latvia) for the VISPA ISP (AS29129 VISPA-ASN).  The attack seems came from Baltic area and it lasted about 12 hours (between 1.00 AM and 12.30 PM).  The following analysis is to be intend as only an attempt to verify the DDOS behavior and nothing else.    For this </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/1565983230457267696/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/01/trying-to-analyze-vispa-isp-outage_08.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1565983230457267696'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1565983230457267696'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/01/trying-to-analyze-vispa-isp-outage_08.html' title='Trying to analyze VISPA ISP Outage'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_uioOPkGBTsE/S0dUv_hEQ9I/AAAAAAAAAfQ/0cp4VyRgebk/s72-c/prefixes_thumb.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-2005456236514573206</id><published>2010-01-07T07:12:00.000-08:00</published><updated>2010-01-07T14:39:59.303-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pdf'/><title type='text'>script for extract and load PDF Shell Code for IDA PRO 5.6</title><summary type='text'>PDF file loader to extract and analyse shellcode
http://hexblog.com/2010/01/pdf_file_loader_to_extract_and.html


</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/2005456236514573206/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2010/01/script-for-extract-and-load-pdf-shell.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2005456236514573206'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2005456236514573206'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2010/01/script-for-extract-and-load-pdf-shell.html' title='script for extract and load PDF Shell Code for IDA PRO 5.6'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-1835354246871057635</id><published>2009-12-29T14:54:00.001-08:00</published><updated>2010-01-05T05:20:01.459-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2009-4324'/><title type='text'>Adobe CVE-2009-4324 in the wild - (0day) - part 0.6 – from Taiwan govs with low detection</title><summary type='text'>   Through the  contagiodump.blogspot.com report, in this post will be analyzed a PDF with characteristics different from those in previous posts.  The document it’s collected through a mail attachment as well shown in the contagiodump blog:     (http://contagiodump.blogspot.com/2009/12/dec-29-cve-2009-4324-adobe-0-day.html)  In particular, as the first step, the file it’s been opened with an </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/1835354246871057635/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild-0day-part_1766.html#comment-form' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1835354246871057635'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1835354246871057635'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild-0day-part_1766.html' title='Adobe CVE-2009-4324 in the wild - (0day) - part 0.6 – from Taiwan govs with low detection'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh5.ggpht.com/_uioOPkGBTsE/SzqR4nXoQsI/AAAAAAAAAbw/x2GoQaWsS8Y/s72-c/s004_thumb%5B1%5D.png?imgmax=800' height='72' width='72'/><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-8829010770445918399</id><published>2009-12-29T08:14:00.001-08:00</published><updated>2009-12-29T09:10:39.880-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2009-4324'/><title type='text'>Adobe CVE-2009-4324 in the wild - (0day) - part 0.5 – yet another Elenore pack</title><summary type='text'>From (thanks to malwaredomainlist ) the follwing URL:        hxxxxp://macaples.in/my_usa/pdf.php      It’s been downloaded a PDF that looks like similar to those analyzed in the previous post. Again the Javascript code inflated from pdf it’s been contained in 4 files. One of them permit to obtain a clear javascript code. In this case the search is for “lka1” and replace with  “%”</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/8829010770445918399/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild-0day-part_29.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8829010770445918399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8829010770445918399'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild-0day-part_29.html' title='Adobe CVE-2009-4324 in the wild - (0day) - part 0.5 – yet another Elenore pack'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_uioOPkGBTsE/Szo3XZTL6EI/AAAAAAAAAa4/o7LnckSkA8E/s72-c/shot001_thumb.png?imgmax=800' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-515314457073480707</id><published>2009-12-28T17:30:00.000-08:00</published><updated>2009-12-28T22:32:47.685-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2009-4324'/><title type='text'>Adobe CVE-2009-4324 in the wild - (0day) - part 0.4 - yourenter.com</title><summary type='text'>   The following URL it's been reported by malwaredomainlist.com as a pdf exploiter:     hxxxxxxp://yourenter.com/pdf.php  (replace hxxxxxxp with http at your risk).                              Trying   with wepawet the pdf appears like "benign" (http://bit.ly/7IZ9SH). So it's been started a minimal manual analysis. Following the usual steps with pdf_inflater were obtained the followings clear </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/515314457073480707/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild-0day-part_28.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/515314457073480707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/515314457073480707'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild-0day-part_28.html' title='Adobe CVE-2009-4324 in the wild - (0day) - part 0.4 - yourenter.com'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/SzjGANyP2TI/AAAAAAAAAVw/nJ-s61RZ2EE/s72-c/1.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-9155629751959862832</id><published>2009-12-27T14:46:00.000-08:00</published><updated>2009-12-27T14:46:28.945-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bgp'/><title type='text'>unique prefixes found in the routing table - BGP</title><summary type='text'>Interesting stats from bgpmon.net


</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/9155629751959862832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/12/unique-prefixes-found-in-routing-table.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/9155629751959862832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/9155629751959862832'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/12/unique-prefixes-found-in-routing-table.html' title='unique prefixes found in the routing table - BGP'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/SzfiwBEWPeI/AAAAAAAAAVo/Vsy4eVa332Q/s72-c/stats0001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-6513261086798378701</id><published>2009-12-23T14:00:00.000-08:00</published><updated>2009-12-27T13:09:43.736-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='waledac'/><category scheme='http://www.blogger.com/atom/ns#' term='ebnvnos.com'/><title type='text'>ebnvnos.com - Flash Java and PDF vulnerabilities in the wild - Waledac - part 0.1</title><summary type='text'>Another URL (many thanks to mdl for rememinder) related to the ebnvnos.comhxxxxxxxp://ebnvnos.com/lib1/dontLayout.pdfand related wepawet analysis:http://wepawet.cs.ucsb.edu/view.php?hash=629a6aa81a426024099807b8c8817063&amp;t=1261430262&amp;type=jsthat seem to trigger CVE-2009-0927So in conclusion, therefore nothing new except the little-known URL.</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/6513261086798378701/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/12/ebnvnoscom-flash-java-and-pdf.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6513261086798378701'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6513261086798378701'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/12/ebnvnoscom-flash-java-and-pdf.html' title='ebnvnos.com - Flash Java and PDF vulnerabilities in the wild - Waledac - part 0.1'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-1040449661652614723</id><published>2009-12-23T10:18:00.001-08:00</published><updated>2009-12-23T17:13:19.458-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='java'/><category scheme='http://www.blogger.com/atom/ns#' term='waledac'/><category scheme='http://www.blogger.com/atom/ns#' term='korea'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='flash'/><category scheme='http://www.blogger.com/atom/ns#' term='ebnvnos.com'/><title type='text'>ebnvnos.com - Flash and Java vulnerabilities in the wild - Waledac - part 0</title><summary type='text'>The domain ebnvnos.com it seem related to once of the spreading stage that exploit something about Adobe Flash Player and Java. The following usually robtex screen shot help to know a bit more about it:Whois 217.23.12.79:inetnum:        217.23.12.0 - 217.23.12.255netname:        WORLDSTREAMdescr:          WorldStream IPv4.19country:        NLadmin-c:        WS1670-RIPEtech-c:         WS1670-</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/1040449661652614723/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/12/ebnvnoscom-flash-adn-java.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1040449661652614723'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1040449661652614723'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/12/ebnvnoscom-flash-adn-java.html' title='ebnvnos.com - Flash and Java vulnerabilities in the wild - Waledac - part 0'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_uioOPkGBTsE/SzJoErNI8-I/AAAAAAAAAVA/3Lcxiqaq-pw/s72-c/shot001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7072363653941268728</id><published>2009-12-19T02:15:00.000-08:00</published><updated>2009-12-22T06:04:53.913-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2009-4324'/><title type='text'>Adobe CVE-2009-4324  in the wild - (0day) - part 0.3 - merry christmas from (for) Taiwan ? :)</title><summary type='text'>Again from contagiodump... (merry christmas pdf) the following screen shot shown a  955bade419a9ba9e5650ccb3dda88844 obfuscated javascript code extracted from once of the stream objects within the pdfThe PDF (955bade419a9ba9e5650ccb3dda88844) generate (if the issue is triggered with success) a binary that became an .exe file named "temp.exe" with path "C:\Documents and Settings\Admin\Local </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7072363653941268728/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild-0day-part_19.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7072363653941268728'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7072363653941268728'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild-0day-part_19.html' title='Adobe CVE-2009-4324  in the wild - (0day) - part 0.3 - merry christmas from (for) Taiwan ? :)'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/Syyo8IOZDiI/AAAAAAAAAUY/yD3Wf8FvwbE/s72-c/first006.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-8475838518949910691</id><published>2009-12-18T14:16:00.000-08:00</published><updated>2009-12-22T05:51:17.269-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2009-4324'/><title type='text'>Adobe CVE-2009-4324  in the wild - (0day) - part 0.2 - shellcode and site down</title><summary type='text'>It seem that the spreading infrastructure it's down (or may be the admins has change domains or paths as well ). Anyway the following screenshots shown the shell code embedded in one of the well know PDFs (thank you contagiodump.blogspot.com) . For inflating deflate PDF stream it's been used PDF_streams_inflater  tool (not more available from malzilla site)http://www.mc-antivirus-test.com/modules</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/8475838518949910691/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild-0day-part_18.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8475838518949910691'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8475838518949910691'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild-0day-part_18.html' title='Adobe CVE-2009-4324  in the wild - (0day) - part 0.2 - shellcode and site down'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/SywCTsVjZ7I/AAAAAAAAATg/UyP_1zjDQ1w/s72-c/first001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-3740179934577367516</id><published>2009-12-15T15:43:00.001-08:00</published><updated>2009-12-27T13:08:09.159-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2009-4324'/><title type='text'>Adobe CVE-2009-4324  in the wild - (0day) - part 0.1 - browsing C&amp;Cs</title><summary type='text'>"playing" with one of the URL, run by a C &amp; C (see previous post http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild.html) you can access some path in which are content folder names match (probably) to hostnames infected. In the following scheenshots is documented the browsing for dailysummary.netThe root path: The host names list:The content (probably encrypted file):The root </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/3740179934577367516/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild-0day-part.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3740179934577367516'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3740179934577367516'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild-0day-part.html' title='Adobe CVE-2009-4324  in the wild - (0day) - part 0.1 - browsing C&amp;Cs'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/SygfPgwZS4I/AAAAAAAAAS4/XRm6Bu5k7Jk/s72-c/dump0008.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-6112355114834556120</id><published>2009-12-15T03:15:00.000-08:00</published><updated>2009-12-16T13:39:15.796-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='CVE-2009-4324'/><category scheme='http://www.blogger.com/atom/ns#' term='0day'/><title type='text'>Adobe CVE-2009-4324  in the wild - (0day) - part 0</title><summary type='text'>A quick analysis (This post is under update):Something more from other site:A detailed CVE-2009-4324 analysis  (many thanks vrt-sourcefire team :) ) :VRT-Sourcefirehttp://vrt-sourcefire.blogspot.com/2009/12/adobe-reader-medianewplayer-analysis.htmlOther interesting analysis about from contagiodump.blogspot.com (many thanks contagio :)) :http://contagiodump.blogspot.com/2009/12/adobe-cve-2009-4324</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/6112355114834556120/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6112355114834556120'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6112355114834556120'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/12/adobe-cve-2009-4324-in-wild.html' title='Adobe CVE-2009-4324  in the wild - (0day) - part 0'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_uioOPkGBTsE/Sydx8N9pz-I/AAAAAAAAARU/vxuHtWkZp-0/s72-c/acre0001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7086656056745751810</id><published>2009-12-11T12:29:00.000-08:00</published><updated>2009-12-14T09:01:30.892-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='318x'/><category scheme='http://www.blogger.com/atom/ns#' term='sql injection'/><category scheme='http://www.blogger.com/atom/ns#' term='massive spreading'/><category scheme='http://www.blogger.com/atom/ns#' term='eldorado rootkit'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>318x.com, 7o8.net and other evil "Eldorado" domains</title><summary type='text'>The domain already well-documented 318x.com is represented by the following IP address as Malwareurl web site said:The domain such 318x.com as domain 3b3.org does not currently appear active.  It remains a third domain which at this time apparently still operating:z360.net/c.jsIt remains a third person who apparently still in operation. To check the spreading ratio of this domain via google will </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7086656056745751810/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/12/318xcom-and-others-evil-domains.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7086656056745751810'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7086656056745751810'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/12/318xcom-and-others-evil-domains.html' title='318x.com, 7o8.net and other evil &quot;Eldorado&quot; domains'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/SyZIvaD-9xI/AAAAAAAAAQE/ZVbSIdesDEo/s72-c/buzus0001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-3579444823469664501</id><published>2009-09-02T04:14:00.000-07:00</published><updated>2009-09-02T17:53:26.776-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='memory corruption'/><title type='text'>Secunia PSI (RC3) - memory corruption</title><summary type='text'>Secunia PSI (Release Candidate 3) appears vulnerable to some memory corruption conditions. This kind of issues are usually detected in release candidate. This kind of bugs, IMHO, may be used for support analysis based on binary diff using the historical releases of an application for obtain a delta of "critical" zone.  But, again, it's only my opinion.Anyway the following screen shots shown the </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/3579444823469664501/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/09/secunia-psi-rc3-undefined-memory.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3579444823469664501'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3579444823469664501'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/09/secunia-psi-rc3-undefined-memory.html' title='Secunia PSI (RC3) - memory corruption'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/Sp5UQ0nE7oI/AAAAAAAAAPE/Mh64Ka6IMF0/s72-c/crash0001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7343152620284604677</id><published>2009-07-26T12:35:00.000-07:00</published><updated>2009-07-26T14:01:10.709-07:00</updated><title type='text'>something about CVE-2009-1862 PoC analysis</title><summary type='text'>Well, strarting from hereEvil.pdf filename it's been decided to start an (yet another) analysis about this critical vulnerabilty.From the proof of concept founded (http://www.milw0rm.com/exploits/9233):begin 644 hereEvil.pdfM)5!$1BTQ+C0*)"!;(#`N,3$Q,S,@+3`N,S(R-S4@,"XR,C$V.2`M...and so on... it's been decoded the TAR file above with the following result:%PDF-1.4%Çì�¢1 0 obj&lt;&lt; /Type /Catalog /</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7343152620284604677/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/07/something-about-cve-2009-1862-poc.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7343152620284604677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7343152620284604677'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/07/something-about-cve-2009-1862-poc.html' title='something about CVE-2009-1862 PoC analysis'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-2580236280348649748</id><published>2009-07-13T17:35:00.000-07:00</published><updated>2009-07-14T06:28:33.941-07:00</updated><title type='text'>something more about "Vulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execuion"</title><summary type='text'>A good keyord for search info about new "big vendors" vulnerabilities is "roadmap" :). Sometimes is very usefull, I think. Opss! another "good bug hunter trick it's just been fulldisclosed".http://blogs.msdn.com/excel/archive/2006/07/17/668544.aspxAnyway... The CLSID for this threat are:{0002E541-0000-0000-C000-000000000046} {0002E559-0000-0000-C000-000000000046}Check the following Registry entry</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/2580236280348649748/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/07/i-have-dreamed-good-keyord-for-search.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2580236280348649748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2580236280348649748'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/07/i-have-dreamed-good-keyord-for-search.html' title='something more about &quot;Vulnerability in Microsoft Office Web Components Control Could Allow Remote Code Execuion&quot;'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_uioOPkGBTsE/SlvYzh1HhdI/AAAAAAAAAO0/eAvSNvIAxFI/s72-c/owc00001.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-4786273416446886832</id><published>2009-07-13T12:54:00.000-07:00</published><updated>2009-07-13T17:39:20.313-07:00</updated><title type='text'>The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System</title><summary type='text'>Finally after a few of days I have received my copy of:The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the SystemSource: http://www.jbpub.com/covers/newlarge/1598220616.jpgI think that this is the best book for the Windows rootkit development and countermeasures.</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/4786273416446886832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/07/rootkit-arsenal-escape-and-evasion-in.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4786273416446886832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4786273416446886832'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/07/rootkit-arsenal-escape-and-evasion-in.html' title='The Rootkit Arsenal: Escape and Evasion in the Dark Corners of the System'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-8853458768852114397</id><published>2009-06-19T02:31:00.000-07:00</published><updated>2009-06-19T02:49:08.748-07:00</updated><title type='text'>some nine-ball information - part 0.1</title><summary type='text'>The following informations are intended as starting point for analyse "nine-ball".Starting from rnw.kz domain:querying the ns it's been obtained:The last HTTP redirection stage (via malzilla):Info for stopssse.info:</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/8853458768852114397/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/06/some-nine-ball-information-part-01.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8853458768852114397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8853458768852114397'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/06/some-nine-ball-information-part-01.html' title='some nine-ball information - part 0.1'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_uioOPkGBTsE/SjtbXfPgePI/AAAAAAAAAOM/ExlZxrnr0WQ/s72-c/nineball0001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-3487126279347315895</id><published>2009-06-10T14:06:00.002-07:00</published><updated>2010-08-15T11:41:11.677-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rbn'/><category scheme='http://www.blogger.com/atom/ns#' term='russian business network'/><category scheme='http://www.blogger.com/atom/ns#' term='as'/><title type='text'>is static. 202.88.46.78.clients.your-server.de a logs collector for rbn ? - part 0.4</title><summary type='text'>During some attempts to study RBN it's been found something of interesting. Let to start from the following rogue antivirus spreading URL:

http\\www.total-virusprotection.com

From robtex:



More interesting information for 92.241.176.220 are discovered asking, again via ROBTEX, other details:




That appears as a list of possible names server and hostname for other rogue antivirus domains. </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/3487126279347315895/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/06/is-static142884678clientsyour-serverde.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3487126279347315895'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3487126279347315895'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/06/is-static142884678clientsyour-serverde.html' title='is static. 202.88.46.78.clients.your-server.de a logs collector for rbn ? - part 0.4'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/SjAr02e-JsI/AAAAAAAAAMU/b1VVbjVPQ-w/s72-c/rbn0001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-8703606766465678858</id><published>2009-05-28T06:57:00.000-07:00</published><updated>2009-05-28T07:03:21.673-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bulkbin.cn'/><category scheme='http://www.blogger.com/atom/ns#' term='rbn'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>bulkbin.cn - russian business network related. it may be - part 0.3</title><summary type='text'>It's been found that 174.133.202.181 (bulkbin.cn)   it may be related to RBN. The following screen shot shown the rbn detection rules from emerginthreats.net updated list:http://www.emergingthreats.net/rules/emerging-rbn.rules</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/8703606766465678858/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/bulkbincn-russian-business-network.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8703606766465678858'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8703606766465678858'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/bulkbincn-russian-business-network.html' title='bulkbin.cn - russian business network related. it may be - part 0.3'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_uioOPkGBTsE/Sh6ZTzfxwaI/AAAAAAAAAL0/kuMIw9MLblg/s72-c/emerginthreatsrules001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7330847982317060824</id><published>2009-05-26T15:00:00.000-07:00</published><updated>2009-05-26T16:49:06.660-07:00</updated><title type='text'>bulkbin.cn - name server - part 0.2</title><summary type='text'>The following pictures shown the name server for bulkbin and others (xgguys.com...):whois 174.133.202.178%rwhois V-1.5:003eff:00 whois.theplanet.com (by Network Solutions, Inc. V-1.5.9.5)network:Class-Name:networknetwork:ID:NETBLK-THEPLANET-BLK-15network:Auth-Area:174.132.0.0/15network:Network-Name:TPIS-BLK-174-133-202-0network:IP-Network:174.133.202.176/28network:IP-Network-Block:174.133.202.176</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7330847982317060824/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/bulkbincn-name-server-part-02.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7330847982317060824'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7330847982317060824'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/bulkbincn-name-server-part-02.html' title='bulkbin.cn - name server - part 0.2'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/Shx2cxwMRlI/AAAAAAAAALs/GbywnVTS0i0/s72-c/authoritativens.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-8644962816343211534</id><published>2009-05-26T04:18:00.000-07:00</published><updated>2009-05-28T05:38:49.266-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware analysis'/><title type='text'>generic unpacking of self-modifying, aggressive, packed binary programs</title><summary type='text'>a good paper from Piotr Baniahttp://piotrbania.com/all/articles/pbania-dbi-unpacking2009.pdffrom the paper It's been found the follwing excelent malware analysis web site:https://aerie.cs.berkeley.edu</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/8644962816343211534/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/generic-unpacking-of-self-modifying.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8644962816343211534'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8644962816343211534'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/generic-unpacking-of-self-modifying.html' title='generic unpacking of self-modifying, aggressive, packed binary programs'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-6549513915991582586</id><published>2009-05-24T11:05:00.000-07:00</published><updated>2009-05-27T12:30:34.099-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bulkbin.cn'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='malware analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><title type='text'>bulkbin.cn - strange AS - part 0.1</title><summary type='text'>Hi there,looking around It's was found some URLS that are related to bulkbin.cnIt was found the following malicious url (replace \ with / if you are interested):http:\\azure.rr.nu\http:\\adolas.passingg.as\http:\\cemuryje.byinter.net\http:\\costens.byinter.net\http:\\colifit.redirect.hm\For each of the URL above, there is a common point: a javascript redirector.Specifically the following code, </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/6549513915991582586/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/bulkbincn-part-01.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6549513915991582586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6549513915991582586'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/bulkbincn-part-01.html' title='bulkbin.cn - strange AS - part 0.1'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/ShmlwwH54ZI/AAAAAAAAAK0/2thnVwf9_Dk/s72-c/redirector.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-4262763650942982603</id><published>2009-05-22T03:48:00.000-07:00</published><updated>2009-05-23T02:23:04.386-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='irc'/><category scheme='http://www.blogger.com/atom/ns#' term='pushbot'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>an irc server - part 0.1</title><summary type='text'>Hi there,during a survey activities it was been found the following irc server:main.updateserver.cn  (67.202.89.34)Searching by google the only infornatuib about is from threatexpert.com:http://www.threatexpert.com/report.aspx?md5=f699946ecde2c669adfbbaf4f019fc03it seems related to pushbot.The following mirc screen shots show the irc server banner:whois:$ whois 67.202.89.34OrgName:    NoZone, </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/4262763650942982603/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/irc-server-part-01.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4262763650942982603'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4262763650942982603'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/irc-server-part-01.html' title='an irc server - part 0.1'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_uioOPkGBTsE/ShaJFRMT1JI/AAAAAAAAAKs/-wNp7Pn_6fg/s72-c/irc0001.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-542390662378804429</id><published>2009-05-21T14:58:00.001-07:00</published><updated>2009-05-22T02:55:58.787-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sinowal'/><category scheme='http://www.blogger.com/atom/ns#' term='mebroot'/><category scheme='http://www.blogger.com/atom/ns#' term='torpig'/><category scheme='http://www.blogger.com/atom/ns#' term='malware analysis'/><title type='text'>another approach - trying to analyze mebroot (torpig) - part 0.6</title><summary type='text'>Starting from x53d03e99cfbfaa0df3695c27b2b5f364 it was been detect a pedantic anti debugging technique (IMHO). Specifically in this case the authors has used a pushf/popf tricks. Since the pushf popf anti debugging technique it seem require the writing of a custom exception handler for handling the ONE_STEP exception, and since I don't want use this approach for a trojan that is yet fully </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/542390662378804429/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/another-approach-trying-to-analyze.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/542390662378804429'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/542390662378804429'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/another-approach-trying-to-analyze.html' title='another approach - trying to analyze mebroot (torpig) - part 0.6'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_uioOPkGBTsE/ShXQV1jmPxI/AAAAAAAAAKU/tNBECm-WgpU/s72-c/create001.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7020962098583348127</id><published>2009-05-21T06:16:00.001-07:00</published><updated>2009-05-21T07:45:17.665-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>gumblar.cn and martuz.cn are dead</title><summary type='text'>robtex for gumblar.cn:robtex for martuz.cn:</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7020962098583348127/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/gumblarcn.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7020962098583348127'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7020962098583348127'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/gumblarcn.html' title='gumblar.cn and martuz.cn are dead'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_uioOPkGBTsE/ShVYGw0s8FI/AAAAAAAAAJ0/WZ_aLb_pd3o/s72-c/robtexgumblar.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7730781870434052492</id><published>2009-05-20T03:20:00.000-07:00</published><updated>2009-05-22T18:16:23.709-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='afcore'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='coreflood'/><title type='text'>afcore - trying to analyze coreflood - part 0</title><summary type='text'>md5:0x9054ce104254794fb0511d18bbe40ef5VirusTotal:http://www.virustotal.com/reanalisis.html?caf6f942e79dcaea76c2792959d52768ThreatExpert:http://www.threatexpert.com/report.aspx?md5=9054ce104254794fb0511d18bbe40ef5Some net related info:threatexpert analysis has detected HTTP requests for the following URL:http://secure.termobite.ws/forum/f7810f/44513dd/7c2891f/4/22b332c robtex:whois:netcraft:Some </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7730781870434052492/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/afcore-trying-to-analyze-coreflood-part.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7730781870434052492'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7730781870434052492'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/afcore-trying-to-analyze-coreflood-part.html' title='afcore - trying to analyze coreflood - part 0'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/ShQE8lRJLTI/AAAAAAAAAJE/Av4kZGkNq0Q/s72-c/coreflood.robtex.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7570935361468751220</id><published>2009-05-18T16:41:00.000-07:00</published><updated>2009-05-19T08:32:05.691-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><title type='text'>pushfd popfd - SEH and anti-debugging</title><summary type='text'>http://www.openrce.org/forums/posts/445#1443</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7570935361468751220/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/pushfd-popfd-anti-debugging-mechanism.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7570935361468751220'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7570935361468751220'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/pushfd-popfd-anti-debugging-mechanism.html' title='pushfd popfd - SEH and anti-debugging'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-3480425804971669973</id><published>2009-05-14T15:06:00.000-07:00</published><updated>2009-05-19T08:07:04.082-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sinowal'/><category scheme='http://www.blogger.com/atom/ns#' term='mebroot'/><category scheme='http://www.blogger.com/atom/ns#' term='torpig'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><title type='text'>first look  - trying to analyze mebroot (torpig) - part 0.5</title><summary type='text'>My submission to threatexpert.com for md5:0x53d03e99cfbfaa0df3695c27b2b5f364 (sinowal/mebroot and i hope torpig related):http://www.threatexpert.com/report.aspx?md5:0x53d03e99cfbfaa0df3695c27b2b5f364How virustotal.com detect 0x53d03e99cfbfaa0df3695c27b2b5f364:http://www.virustotal.com/analisis/65ccef31523490ed798110dab5bf884eWhat's shown with ArmInline for 0x53d03e99cfbfaa0df3695c27b2b5f364 run </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/3480425804971669973/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/first-look-trying-to-analyze-mebroot.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3480425804971669973'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3480425804971669973'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/first-look-trying-to-analyze-mebroot.html' title='first look  - trying to analyze mebroot (torpig) - part 0.5'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/SgyWECWjl3I/AAAAAAAAAIk/BKvRFVk8xXA/s72-c/firstlookup.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-1737885876021533006</id><published>2009-05-14T06:49:00.000-07:00</published><updated>2009-05-14T14:27:27.443-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sinowal'/><category scheme='http://www.blogger.com/atom/ns#' term='mebroot'/><category scheme='http://www.blogger.com/atom/ns#' term='torpig'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><title type='text'>got it ?  - trying to analyze mebroot (torpig) - part 0.4</title><summary type='text'>It's been discovered using an alias for mebroot (sinowal) as search keyword.So trying to retrieve one of the latest it was been discovered the following:md5: 0xba1f006b05e898c0e4a61458cd981870ormd5: 0x53d03e99cfbfaa0df3695c27b2b5f364URL:hxxp://----------.----/cgi-bin/index.cgi?ECVCEzzEZzZZsZrZZMzClEkuuMZEZZZZZZZZZMMkVkuukZZZZzZkZlZZZZZZZZzOZAt this time the URL , like a fast bulk place, doesn't </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/1737885876021533006/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/got-it-trying-to-analyze-mebroot-torpig.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1737885876021533006'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1737885876021533006'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/got-it-trying-to-analyze-mebroot-torpig.html' title='got it ?  - trying to analyze mebroot (torpig) - part 0.4'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-5436145712517705492</id><published>2009-05-13T18:34:00.001-07:00</published><updated>2009-05-28T05:37:03.060-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cymru'/><category scheme='http://www.blogger.com/atom/ns#' term='as'/><category scheme='http://www.blogger.com/atom/ns#' term='script'/><title type='text'>AS whois (cymru whois service) script</title><summary type='text'>This is a simple POC bash script for retrieving AS info (ASn and prefix)  from team-cymru whois service for a given IP address. It's created for work in separated folder and the input file  is a simple IP address list file. For each IP, the script creates a separated files (named with IP) and global unique log file where are saved all responses.So for a faster and  better using following this </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/5436145712517705492/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/cymru-as-whois-script.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5436145712517705492'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5436145712517705492'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/cymru-as-whois-script.html' title='AS whois (cymru whois service) script'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_uioOPkGBTsE/Sgt8DGQj8lI/AAAAAAAAAIM/TARxEIeaIfE/s72-c/cymruwhois.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-2790212438648727266</id><published>2009-05-11T15:52:00.000-07:00</published><updated>2009-05-28T05:36:42.194-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='malware analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='vmware'/><title type='text'>a "capture-server" night - a different night without IDA</title><summary type='text'>This is the first step of the installation for capture-client/server project by hpc project. Tank you very much to "security watch" owner for his suggestions. After a couple of hours for install and finding stuff needed, this is the time for "yet another" screen shots:Behind the scene a good starting guide web site for installing and using HPC Capture Server: http://www.emre.de/wiki/Capture-HPC</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/2790212438648727266/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/capture-server-night-different-night.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2790212438648727266'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2790212438648727266'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/capture-server-night-different-night.html' title='a &quot;capture-server&quot; night - a different night without IDA'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_uioOPkGBTsE/Sgiuu1vXeiI/AAAAAAAAAHs/8If0PHVJ8jE/s72-c/Screenshot.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-5839048952144414329</id><published>2009-05-10T12:34:00.000-07:00</published><updated>2009-05-21T16:02:21.480-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='sinowal'/><category scheme='http://www.blogger.com/atom/ns#' term='mebroot'/><category scheme='http://www.blogger.com/atom/ns#' term='torpig'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><title type='text'>still attempts for binaries retriving - trying to analyze mebroot (torpig) - part 0.3</title><summary type='text'>I'm still search for URL with a sort of binary to analyze. I'm evaluating to looking for another URL for get mebroot binaries. From the URL reported by malwaredomainlist.com I can't get anything then strange URL.I get a Symantec  report related to 15min.it where are shown URL for download binaries stuff. But seems not more available.http://safeweb.norton.com/report/show?name=15min.itFeedback are </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/5839048952144414329/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/still-attempts-for-binaries-retrivinf.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5839048952144414329'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5839048952144414329'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/still-attempts-for-binaries-retrivinf.html' title='still attempts for binaries retriving - trying to analyze mebroot (torpig) - part 0.3'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7109414476061140736</id><published>2009-05-10T04:49:00.000-07:00</published><updated>2009-05-10T04:53:03.276-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><category scheme='http://www.blogger.com/atom/ns#' term='lsass'/><category scheme='http://www.blogger.com/atom/ns#' term='debugging'/><title type='text'>LSASS.exe process</title><summary type='text'>Some useful info and other interesting readings for this kind of activities:How to debug LSASS.exe processhttp://blogs.msdn.com/alejacma/archive/2007/11/13/how-to-debug-lsass-exe-process.aspx</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7109414476061140736/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/lsassexe-process.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7109414476061140736'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7109414476061140736'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/lsassexe-process.html' title='LSASS.exe process'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-8982632368684192811</id><published>2009-05-07T14:13:00.000-07:00</published><updated>2009-05-08T02:38:43.550-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mebroot'/><category scheme='http://www.blogger.com/atom/ns#' term='torpig'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript-analytics.com'/><title type='text'>javascript-analytics.com: correlation between an increase in HTTP requests and the change of routes - trying to analyze mebroot (torpig) - part 0.2</title><summary type='text'>Using alexa.com the result for javascript-analytics.com in the latest days is the following:As it's shown in the screen shots above, from the start of May 2009, there is a increase of HTTP traffic for javascripts-analytics.comAnalyzing with bgplay the last month BGP behaviour of the ASn (AS36351) where javascript-analytics.com live it's possibile view a clear increasing "interest" for once of the</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/8982632368684192811/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/javascript-analyticscom-correlation.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8982632368684192811'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/8982632368684192811'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/javascript-analyticscom-correlation.html' title='javascript-analytics.com: correlation between an increase in HTTP requests and the change of routes - trying to analyze mebroot (torpig) - part 0.2'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/SgNQZrPAGUI/AAAAAAAAAHM/yeTllyhbVTI/s72-c/alexa.javascriptanalytics.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-2008586971642959104</id><published>2009-05-07T02:54:00.000-07:00</published><updated>2009-05-11T10:21:39.813-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rootkit'/><category scheme='http://www.blogger.com/atom/ns#' term='mebroot'/><category scheme='http://www.blogger.com/atom/ns#' term='torpig'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><category scheme='http://www.blogger.com/atom/ns#' term='javascript-analytics.com'/><title type='text'>who is javascript-analytics.com ? - trying to analyze mebroot (torpig) - part 0.1</title><summary type='text'>Related to previous post mebroot It's shown some info about javascipt-analytics.comwhat NETCRAFT says about:what WOT says about:http://www.mywot.com/en/scorecard/javascript-analytics.com</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/2008586971642959104/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/whois-javascript-analyticscom.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2008586971642959104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2008586971642959104'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/whois-javascript-analyticscom.html' title='who is javascript-analytics.com ? - trying to analyze mebroot (torpig) - part 0.1'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/SgNFS5e5-II/AAAAAAAAAHE/_Pv90uW5Rak/s72-c/netcraft.javascriptanalytics.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-3513353190488462490</id><published>2009-05-06T12:46:00.000-07:00</published><updated>2009-05-07T04:55:11.311-07:00</updated><title type='text'>wepawet information disclosure vulnerability?</title><summary type='text'>The night thinking.I've discovery  a worst method to probe wepawet.com object and plugin versioning  (is this intended as information disclosure vulnerability?) .  From their result about my post for analyse the url 15mm.it, I've seen some variable ,used by the exploiter (j.js from previous post) , with value that usually are not sandbox related.Can an attacker use this info for, theoretically, </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/3513353190488462490/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/wepawet-information-disclosure.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3513353190488462490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3513353190488462490'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/wepawet-information-disclosure.html' title='wepawet information disclosure vulnerability?'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-9218024175758215874</id><published>2009-05-06T07:02:00.000-07:00</published><updated>2009-05-06T12:32:30.789-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rootkit'/><category scheme='http://www.blogger.com/atom/ns#' term='mebroot'/><category scheme='http://www.blogger.com/atom/ns#' term='torpig'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>trying to analyze mebroot (torpig) - part 0</title><summary type='text'>This post is intended as an attempt to analyze mebroot (torpig botnet related). So some info at this time may be incorrect or not fully explained.Let to start from malwaredomainlist.com  where it's been found the following malicious URL indicated as once of mebroot spreading site :With malzilla the result it's a not so bad javascript obfuscated code:After a smart code analysis it was noted the </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/9218024175758215874/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/tryng-to-analyze-mebroot-part-0.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/9218024175758215874'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/9218024175758215874'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/tryng-to-analyze-mebroot-part-0.html' title='trying to analyze mebroot (torpig) - part 0'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/SgGZRtiqzuI/AAAAAAAAAFM/XHnxFt82T-o/s72-c/malwaredomainslist001.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-2471066087627762707</id><published>2009-05-05T01:40:00.000-07:00</published><updated>2009-05-05T02:32:50.805-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rootkit'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='botnet'/><title type='text'>torpig botnet</title><summary type='text'>A good paper:"Your Botnet is My Botnet: Analysis of a Botnet Takeover"http://www.cs.ucsb.edu/~seclab/projects/torpig/torpig.pdf</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/2471066087627762707/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/torpig-botnet-try-to-dissect-mebroot.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2471066087627762707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2471066087627762707'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/torpig-botnet-try-to-dissect-mebroot.html' title='torpig botnet'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-3501303128588730846</id><published>2009-05-02T15:23:00.000-07:00</published><updated>2009-05-02T15:36:40.482-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker.e'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><title type='text'>conficker.e analysis (.exe component) - part 0.9 - the 3rd of may</title><summary type='text'>These screen shots show what happen on 3rd of may.  In a few words is called the "MoveFileEx" Win32 API function. The file name is the ".exe" component name. I have a sort of doubts about this "idle and destroy" method.</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/3501303128588730846/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/05/confickere-analysis-exe-component-part.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3501303128588730846'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3501303128588730846'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/05/confickere-analysis-exe-component-part.html' title='conficker.e analysis (.exe component) - part 0.9 - the 3rd of may'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/SfzJiJm7v2I/AAAAAAAAAFE/JL0ssJsN-u0/s72-c/conficker.e.3rdmay.reg.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-2139422530813892136</id><published>2009-04-28T14:02:00.000-07:00</published><updated>2009-04-29T06:07:20.993-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker.e'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><title type='text'>conficker.e analysis (.exe component) - part 0.8 - "3rd command" reversing</title><summary type='text'>From the previous post it was show that the are always three valid command expected by the worm for its business.  The more meaning command during the dissecting is the "3rd command".When the worm receive the correct command syntax, it send a dump of the registry value "ds" referenced by the registry path: HKLM\Software\Microsoft\Windows\CurrentVersion\AppletsThe following screenshot shown the </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/2139422530813892136/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-exe-component-part_28.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2139422530813892136'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2139422530813892136'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-exe-component-part_28.html' title='conficker.e analysis (.exe component) - part 0.8 - &quot;3rd command&quot; reversing'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/SfdxVehPTRI/AAAAAAAAAEs/AG8TgXc5_X8/s72-c/conficker.e.commands3.dump.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7613286170026097097</id><published>2009-04-27T12:13:00.000-07:00</published><updated>2009-04-29T06:07:31.083-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker.e'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><title type='text'>conficker.e analysis (.exe component) - part 0.7 - listen port generation</title><summary type='text'>IMHO this screen shot show how conficker.e generate the listen port.In EDI the port. The code zone for this value is the following:The ports space is not so wide!. TCPView sayd:</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7613286170026097097/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-exe-component-part_27.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7613286170026097097'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7613286170026097097'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-exe-component-part_27.html' title='conficker.e analysis (.exe component) - part 0.7 - listen port generation'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/SfYEIBwZVuI/AAAAAAAAAEU/SIw4KaqVdM0/s72-c/conficker.e.listenport.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-4445736376738458055</id><published>2009-04-26T15:55:00.000-07:00</published><updated>2009-04-29T06:07:41.651-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker.e'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><title type='text'>conficker.e analysis (.exe component) - part 0.6 - commands smart analysis</title><summary type='text'>On test system, where were dissected conficker.e, are been identified three handled commands which follow this syntax reported in previous post.  Specifically:get /vulubmqa http/get /npms http/get /wvmvcnrb http/Each random string change after a random (maybe) time, so it's very difficult follow the behaviour. A good choice may be change at runtime the timer with a slow time for a better </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/4445736376738458055/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-exe-component-part.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4445736376738458055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4445736376738458055'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-exe-component-part.html' title='conficker.e analysis (.exe component) - part 0.6 - commands smart analysis'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_uioOPkGBTsE/SfTzPIIMZrI/AAAAAAAAAD8/PPoZIGVixBw/s72-c/sscommand01.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-1883195174803226585</id><published>2009-04-22T17:47:00.000-07:00</published><updated>2009-04-29T06:07:52.941-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker.e'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><title type='text'>conficker.e analysis (.exe component) - part 0.5 - command syntax</title><summary type='text'>The following screenshot shown the command syntax expected by conficker.e on TCP port 1382:As shown the syntax is /get wdomfknm http/ or /get random string http/</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/1883195174803226585/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-part-05-command.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1883195174803226585'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/1883195174803226585'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-part-05-command.html' title='conficker.e analysis (.exe component) - part 0.5 - command syntax'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_uioOPkGBTsE/Se-77P9nkEI/AAAAAAAAAD0/CRdrihsPAgY/s72-c/conficker.e.commands.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-7977040371931109435</id><published>2009-04-22T13:56:00.001-07:00</published><updated>2009-04-29T06:08:03.932-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker.e'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><title type='text'>conficker.e analysis (.exe component) - part 0.4 - hnetcfg.dll - getCurrentProfile</title><summary type='text'>how conficker.e it's interested to Microsoft fw policies:</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/7977040371931109435/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-part-04-hnetcfgdll.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7977040371931109435'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/7977040371931109435'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-part-04-hnetcfgdll.html' title='conficker.e analysis (.exe component) - part 0.4 - hnetcfg.dll - getCurrentProfile'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/Se-FO84jA_I/AAAAAAAAADs/_ZFAAqmPcg4/s72-c/hnetcfg.dll.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-4076153891000950826</id><published>2009-04-22T06:50:00.000-07:00</published><updated>2009-04-29T06:08:20.356-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker.e'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><title type='text'>conficker.e analysis (.exe component) - part 0.3 - service loader</title><summary type='text'>After read tcpip.sys, conficker.e exe component generates a tmp file with random name in the following path: c:\windows\system32\.tmp, then through, the API used for interfacing with ServiceManager, conficker.e try to load the previous tmp file name as a service.The service name is a random string. In this case:</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/4076153891000950826/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-part-03-service.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4076153891000950826'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/4076153891000950826'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-part-03-service.html' title='conficker.e analysis (.exe component) - part 0.3 - service loader'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/Se8k75FtD6I/AAAAAAAAADc/OIbSGr6pt9E/s72-c/conficker.e.service.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-3309894164717338420</id><published>2009-04-22T05:36:00.000-07:00</published><updated>2009-04-29T06:08:29.809-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker.e'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><title type='text'>conficker.e analysis (.exe component)  - part 0.2 - 3rd of may checker</title><summary type='text'>conficker.e date checker routine.  Check for the 3rd of May.Fitted view and zoomed view for the date checking routine Some historical events for the 3rd of may: http://en.wikipedia.org/wiki/May_3</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/3309894164717338420/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-part-02-date.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3309894164717338420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/3309894164717338420'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-part-02-date.html' title='conficker.e analysis (.exe component)  - part 0.2 - 3rd of may checker'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_uioOPkGBTsE/Se8QIFel8NI/AAAAAAAAADU/s8c0-DO84Ak/s72-c/conficker.e.date.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-5411822673903842775</id><published>2009-04-19T05:07:00.002-07:00</published><updated>2009-04-29T06:08:38.947-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker.e'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><title type='text'>conficker.e analysis (.exe component) - part 0.1</title><summary type='text'>Finally I have obtained the correctly dump from upx source (md5: 0x677daa8bf951ecce8eae7d7ee0301780) with the right OEP and IAT (Import Address Table) .Tools: LordPE,ImpRec,Ollydbg 2.0. With IDA the obtained exe file it's loaded correctly.Before the dump. After the dump with correct OEP:Some strings:                               The following screenshots show something of interesting:tcpip.sys </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/5411822673903842775/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-part-01.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5411822673903842775'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5411822673903842775'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-part-01.html' title='conficker.e analysis (.exe component) - part 0.1'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_uioOPkGBTsE/Sex_CE0DugI/AAAAAAAAAC8/tcAT0V_7qeQ/s72-c/register.winmain.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-5978495873778076008</id><published>2009-04-17T06:00:00.000-07:00</published><updated>2009-04-29T06:08:48.571-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker.e'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='reverse engineering'/><title type='text'>conficker.e analysis (.exe component)  - part 0</title><summary type='text'>This post is intended to present an attempt at unpacking and analyze conficker.e. The md5 of the file analysis is reported from most sources (antivirus vendors lab and so on): 0x677daa8bf951ecce8eae7d7ee0301780  The first runtime screenshot shown a zone of the decompressed binary with some stuff related to uPNP devicesa also It's showsomething about SSDP (Simple Service Discovery Protocol).  The </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/5978495873778076008/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-part-0.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5978495873778076008'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/5978495873778076008'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/04/confickere-analysis-part-0.html' title='conficker.e analysis (.exe component)  - part 0'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_uioOPkGBTsE/SegE7fz5e-I/AAAAAAAAACc/yqd0tryM9Pc/s72-c/conficker.e.3.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-6365198822977001278</id><published>2009-04-10T02:11:00.000-07:00</published><updated>2009-04-19T08:45:36.645-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rogue'/><category scheme='http://www.blogger.com/atom/ns#' term='conficker.gen'/><category scheme='http://www.blogger.com/atom/ns#' term='downadup.gen'/><title type='text'>W32.downadup.e and rogue AV</title><summary type='text'>I was looking for info about Downadup.E (conficker.c updated release) and I used one of the easiest keyword that probably may be used for make some research with Google:The result of this simple query it was the following:Google show up some interesting URL in the top ranking result and in ad space:The red points (shown in the pictures) show you warning level generated by WOT Addons for Firefox </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/6365198822977001278/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/04/wot-is-your-friend-google-not-so.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6365198822977001278'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6365198822977001278'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/04/wot-is-your-friend-google-not-so.html' title='W32.downadup.e and rogue AV'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_uioOPkGBTsE/Sd8PpsJkwFI/AAAAAAAAABE/e2OYhGCIFa0/s72-c/search0001.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-6019704682690004476</id><published>2009-04-10T01:49:00.000-07:00</published><updated>2009-04-19T08:44:17.290-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker.gen'/><title type='text'>w32.downadup.e</title><summary type='text'>Info about new Downadup.EMD5 related:677daa8bf951ecce8eae7d7ee0301780Online malware reports:VirusTotal reportThreatexpertBlog and technical details:[incidents.org] - Conficker update with payload[Symantec] - W32.Downadup.E[Garwarner] - Is There a Conficker E? Waledac makes a move...[TrendMicro] - DOWNAD/Conficker Watch: New Variant in The Mix?[MMPC] - Win32/Conficker Variants Update</summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/6019704682690004476/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/04/downadupe-confickere.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6019704682690004476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/6019704682690004476'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/04/downadupe-confickere.html' title='w32.downadup.e'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1523707327337901416.post-2116946007027962569</id><published>2009-04-02T08:15:00.001-07:00</published><updated>2009-04-27T05:15:44.321-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='conficker.c'/><title type='text'>conficker.c - ccTLD attractor</title><summary type='text'>This is my smart analysis about the first 20days of April 2009 ccTLD (country code top level domain) generated by the algorithm used by worm for pseudo random domain name generation.  The data used for this report are taken from http://mtc.sri.com/Conficker/addendumC/The following table show the frequency for each ccTLD. As you can see there is a sort of attractor for some ccTLD such as AG, BO, </summary><link rel='replies' type='application/atom+xml' href='http://extraexploit.blogspot.com/feeds/2116946007027962569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://extraexploit.blogspot.com/2009/04/conficker-first-20-days-tld-algorithm.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2116946007027962569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1523707327337901416/posts/default/2116946007027962569'/><link rel='alternate' type='text/html' href='http://extraexploit.blogspot.com/2009/04/conficker-first-20-days-tld-algorithm.html' title='conficker.c - ccTLD attractor'/><author><name>extraexploit</name><uri>http://www.blogger.com/profile/06719611599534668877</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_uioOPkGBTsE/SdTZhxnXeQI/AAAAAAAAAAs/SXi2ZMg_-7Q/s72-c/conficker20aprildays.JPG' height='72' width='72'/><thr:total>2</thr:total></entry></feed>
