<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DEIFQH8yfSp7ImA9WhRWF0k.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914</id><updated>2012-01-05T14:55:11.195+08:00</updated><category term="Network" /><category term="Wireless" /><category term="Malware" /><category term="Internet" /><category term="SPAM" /><category term="Backup" /><category term="General" /><category term="Advisory" /><category term="Security News" /><category term="Tools" /><category term="Gadgets" /><category term="Hacking" /><category term="Encryption" /><category term="Book" /><category term="Patches" /><category term="Video" /><category term="Challenge" /><category term="Systems" /><title>Wolf's Lair</title><subtitle type="html">"A lair is also referred to as a hideout for a superhero or supervillain"</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://werew01f.blogspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;v=2" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>127</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/WolfsLair" /><feedburner:info uri="wolfslair" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;A04MRHo_eip7ImA9WhdaFE4.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-7511688970168680790</id><published>2011-10-24T15:00:00.000+08:00</published><updated>2011-10-24T15:06:25.442+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-24T15:06:25.442+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Video" /><title>Android vs iOS security</title><content type="html">A interesting video on well-known security researcher Dr Charlie Miller, which discuss the security postures of Android and iOS&lt;br /&gt;&lt;br /&gt;&lt;object style="WIDTH: 440px; HEIGHT: 268px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/KsbOxT268bc?version=3&amp;amp;feature=player_detailpage"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;br /&gt;&lt;br /&gt;&lt;embed src="http://www.youtube.com/v/KsbOxT268bc?version=3&amp;feature=player_detailpage" type="application/x-shockwave-flash" allowfullscreen="true" allowscriptaccess="always" width="440" height="268"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-7511688970168680790?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/jZ4T1s-bWOVLd3XgtdX8UPp8YNk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/jZ4T1s-bWOVLd3XgtdX8UPp8YNk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/jZ4T1s-bWOVLd3XgtdX8UPp8YNk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/jZ4T1s-bWOVLd3XgtdX8UPp8YNk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/ktaCMtUAVsg" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/7511688970168680790/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=7511688970168680790" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/7511688970168680790?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/7511688970168680790?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/ktaCMtUAVsg/android-vs-ios-security.html" title="Android vs iOS security" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><thr:total>1</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2011/10/android-vs-ios-security.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0QAQXwzfyp7ImA9WhdaE0g.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-5462601301639091395</id><published>2011-10-23T12:49:00.007+08:00</published><updated>2011-10-23T14:29:00.287+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-10-23T14:29:00.287+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SPAM" /><title>My Million dollar ATM is ready for delivery??</title><content type="html">I have just received an interesting Scam mail. Think it will be useful to share with all my readers.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-isdeYUvtXIY/TqOqca4alcI/AAAAAAAABzE/Ksse3mhNdmo/s1600/scam3.JPG"&gt;&lt;img style="WIDTH: 400px; HEIGHT: 264px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5666560161391220162" border="0" alt="" src="http://1.bp.blogspot.com/-isdeYUvtXIY/TqOqca4alcI/AAAAAAAABzE/Ksse3mhNdmo/s400/scam3.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The email claims to be from FedEx. They are ready to deliver "my" million dollar ATM card in GHANA.&lt;br /&gt;&lt;br /&gt;&lt;span style="FONT-STYLE: italic;font-size:85%;" &gt;-Below are the extract-&lt;br /&gt;&lt;br /&gt;Dear Valued Customer.&lt;br /&gt;&lt;br /&gt;The office of the FedEx Managements in the capital city of ACCRA GHANA do hereby wish to inform you that your ATM card package is ready for delivery.&lt;br /&gt;&lt;br /&gt;The issuing bank of this ATM card has instructed us to inform you that your card has been credited with the total sum of US$4,750,000.00 (Four Million-Seven Hundred &amp;amp; Fifty Thousand Dollars) which is now accessible and you can make your withdrawal from any ATM machine worldwide.&lt;br /&gt;&lt;br /&gt;This ATM card with the PIN code and other vital documents has peen packaged into an Envelop which has been assigned for immediately delivery but unfortunately, the issuing bank has cleared (PAID) the delivery fee, insurance fee, custom duty fee, delivery permit fee but they were not allowed to pay the security bonded keeping fee because we have not been told when you will be coming for your claim not until the bank instructed us to contact you and inform you of the security bonded keeping fee which is only the sum of US$98 dollars, this is the only fee that you has to pay.&lt;br /&gt;&lt;br /&gt;We further request you to kindly clear security bonded keeping fee of US$98 Dollars to enable us effect the delivery of your ATM card to you as soon as possible. At the meantime, you have to get back to us with your address where your package would be delivered to you within the nest 48hrs.&lt;br /&gt;&lt;br /&gt;Your complete Name:…………………………&lt;br /&gt;Your Complete Address:………………………&lt;br /&gt;Your Mobile Number:…………………………..&lt;br /&gt;&lt;br /&gt;Upon your swift response, we shall instruct you on how you will make the payment to the security office before we would be allowed to move your package. Our delivery duration is only 48hrs starting from the time when your package was picked up and dispatched out from our office here in Ghana.&lt;br /&gt;&lt;br /&gt;We anticipate your response.&lt;br /&gt;&lt;br /&gt;Thank you.&lt;br /&gt;&lt;br /&gt;Mr. Mac Moses&lt;br /&gt;FedEx Delivery Officer&lt;br /&gt;Tel: 233- 247630112&lt;br /&gt;&lt;br /&gt;-End of email-&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;From the email header, you will able to see some useful information:&lt;br /&gt;1&amp;gt; Source email address.&lt;br /&gt;2&amp;gt; Source mail server&lt;br /&gt;3&amp;gt; Source IP address connected to mail server&lt;br /&gt;4&amp;gt; Reply to address&lt;br /&gt;&lt;br /&gt;&lt;img style="WIDTH: 450px; HEIGHT: 217px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5666563582259047122" border="0" alt="" src="http://3.bp.blogspot.com/-buESkTHq0hM/TqOtjim3KtI/AAAAAAAABzg/hn6HPJIVHbs/s400/Scam-1.JPG" /&gt;&lt;br /&gt;&lt;br /&gt;From the "1&amp;gt; Source email address", you know that the email is coming from "chinkyeyes@rogers.com". Rogers.com is exactly a Canadian ISP, which uses Yahoo mail gateway (as shown below). So it has verified the "2&amp;gt; Source mail server" in the mail header.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-FBQjPLZQhdo/TqOqcYfxscI/AAAAAAAABy8/VLQv6fia-Xs/s1600/scam2.JPG"&gt;&lt;img style="WIDTH: 400px; HEIGHT: 123px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5666560160751006146" border="0" alt="" src="http://4.bp.blogspot.com/-FBQjPLZQhdo/TqOqcYfxscI/AAAAAAAABy8/VLQv6fia-Xs/s400/scam2.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;From the "3&amp;gt; Source IP Address" (41.218.192.255), it was from Ghana. So it is likely that the user "chinkyeyes" account was compromised by the scammer.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-M169eBNTILA/TqOqcv5ajJI/AAAAAAAABzU/AuqxsgPHgZU/s1600/scam4.JPG"&gt;&lt;img style="WIDTH: 400px; HEIGHT: 165px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5666560167032556690" border="0" alt="" src="http://2.bp.blogspot.com/-M169eBNTILA/TqOqcv5ajJI/AAAAAAAABzU/AuqxsgPHgZU/s400/scam4.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Scam mail tends to show tell-tale sign such as spelling error.&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/-7sb8w8x8JMc/TqOy13vBdaI/AAAAAAAABzs/B6AWL0t8pfA/s1600/scam5.JPG"&gt;&lt;img style="WIDTH: 400px; HEIGHT: 54px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5666569394726204834" border="0" alt="" src="http://2.bp.blogspot.com/-7sb8w8x8JMc/TqOy13vBdaI/AAAAAAAABzs/B6AWL0t8pfA/s400/scam5.JPG" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-5462601301639091395?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/oNjJ5K79oZqqefskTGGTxPTniso/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oNjJ5K79oZqqefskTGGTxPTniso/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/oNjJ5K79oZqqefskTGGTxPTniso/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oNjJ5K79oZqqefskTGGTxPTniso/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/aEZwq-kplzU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/5462601301639091395/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=5462601301639091395" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/5462601301639091395?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/5462601301639091395?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/aEZwq-kplzU/my-million-dollar-atm-is-ready-for.html" title="My Million dollar ATM is ready for delivery??" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-isdeYUvtXIY/TqOqca4alcI/AAAAAAAABzE/Ksse3mhNdmo/s72-c/scam3.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2011/10/my-million-dollar-atm-is-ready-for.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0YARX8-eCp7ImA9WhdUE0U.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-294912324771715523</id><published>2011-09-30T18:06:00.006+08:00</published><updated>2011-09-30T19:12:24.150+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-30T19:12:24.150+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SPAM" /><category scheme="http://www.blogger.com/atom/ns#" term="Advisory" /><title>I won $10,000 worth of shopping voucher??</title><content type="html">I received an email informing me that i have won $10,000 worth of shopping voucher coming from HardwareZone's newsletter.&lt;br /&gt;&lt;br /&gt;The email format really give me the impression that i am the lucky winner, with two other "winners" listed in the email.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-lU-Fi5K6Cos/ToWVs7M2GSI/AAAAAAAAByY/riUH6g1cVic/s1600/Winner-1.JPG"&gt;&lt;img style="WIDTH: 443px; HEIGHT: 441px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5658093105899247906" border="0" alt="" src="http://1.bp.blogspot.com/-lU-Fi5K6Cos/ToWVs7M2GSI/AAAAAAAAByY/riUH6g1cVic/s400/Winner-1.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;But after reading through the emails, it start to show tell-tale sign that it is just an advertisment and i did not really won a prize. They skillfully claims that "you may be a possible winner" as not to be accused as fraud later.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-wFZshBuwgLQ/ToWVtILX7aI/AAAAAAAAByg/HbDL8pVsNzA/s1600/Winner-2.JPG"&gt;&lt;img style="WIDTH: 438px; HEIGHT: 153px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5658093109382737314" border="0" alt="" src="http://3.bp.blogspot.com/-wFZshBuwgLQ/ToWVtILX7aI/AAAAAAAAByg/HbDL8pVsNzA/s400/Winner-2.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;After clicking the link "&lt;em&gt;www.greatsingaporevoucher.com.sg&lt;/em&gt;" to "verify" your details, it was obvious that the email is actually a legal "spam".&lt;br /&gt;&lt;br /&gt;By "verifying" your details, you are actually joining the lucky draw instead. It also allow them to collect your information so to legally "spam" you further via Handphone, email, and mailing address.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/-w8sZfQpX-kM/ToWVtHtFhPI/AAAAAAAAByo/JAckyduoVSM/s1600/Winner-3.JPG"&gt;&lt;img style="WIDTH: 443px; HEIGHT: 284px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5658093109255701746" border="0" alt="" src="http://1.bp.blogspot.com/-w8sZfQpX-kM/ToWVtHtFhPI/AAAAAAAAByo/JAckyduoVSM/s400/Winner-3.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;em&gt;&lt;strong&gt;w01f advise: If anyone still interested to join this lucky draw (or any similar online contest) and to be "spam" further, make sure you read and understand their "Terms and Conditions" and "Privacy Policy" before releasing your personal information to them.&lt;/strong&gt;&lt;/em&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-294912324771715523?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/tEUeQvrOzoFpsTwT7uPdztgn4I0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tEUeQvrOzoFpsTwT7uPdztgn4I0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/tEUeQvrOzoFpsTwT7uPdztgn4I0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tEUeQvrOzoFpsTwT7uPdztgn4I0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/nztacmiFM_s" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/294912324771715523/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=294912324771715523" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/294912324771715523?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/294912324771715523?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/nztacmiFM_s/i-won-10000-worth-of-shopping-voucher.html" title="I won $10,000 worth of shopping voucher??" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-lU-Fi5K6Cos/ToWVs7M2GSI/AAAAAAAAByY/riUH6g1cVic/s72-c/Winner-1.JPG" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2011/09/i-won-10000-worth-of-shopping-voucher.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0IFRXg6fCp7ImA9WhdUE0U.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-1560299785820196130</id><published>2011-09-29T20:44:00.001+08:00</published><updated>2011-09-30T19:18:34.614+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-30T19:18:34.614+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><title>Default again?</title><content type="html">Another device found to be using default password. This time is a home router in Korea. It is a DAVOLINK DVW-2000N router.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-ylrgkAx_IP0/ToR5y-IG7VI/AAAAAAAAByQ/5dey-2an2OY/s1600/wireless-1.jpg"&gt;&lt;img style="WIDTH: 437px; HEIGHT: 273px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5657780948461612370" border="0" alt="" src="http://4.bp.blogspot.com/-ylrgkAx_IP0/ToR5y-IG7VI/AAAAAAAAByQ/5dey-2an2OY/s400/wireless-1.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;em&gt;w01f advise: Home router console should not be accessible from the Internet. The account should also be properly secured with strong password.&lt;br /&gt;&lt;br /&gt;&lt;/em&gt;&lt;/strong&gt;&lt;strong&gt;&lt;em&gt;&lt;/em&gt;&lt;/strong&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-1560299785820196130?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/j96fRpHiuNFZU1QeIdoeVnSUspw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/j96fRpHiuNFZU1QeIdoeVnSUspw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/j96fRpHiuNFZU1QeIdoeVnSUspw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/j96fRpHiuNFZU1QeIdoeVnSUspw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/xN_9zF2H2pk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/1560299785820196130/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=1560299785820196130" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/1560299785820196130?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/1560299785820196130?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/xN_9zF2H2pk/default-again.html" title="Default again?" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-ylrgkAx_IP0/ToR5y-IG7VI/AAAAAAAAByQ/5dey-2an2OY/s72-c/wireless-1.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2011/09/default-again.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0UERnYyfCp7ImA9WhdUEU4.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-1983648786609221307</id><published>2011-09-27T22:18:00.002+08:00</published><updated>2011-09-28T00:00:07.894+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-28T00:00:07.894+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><title>"Easy" access to exam questions?</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-8hs9pzNkCrA/ToHrtMihIMI/AAAAAAAABx4/rFUxgUQdmbA/s1600/shanghai-1.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 400px; height: 271px;" src="http://1.bp.blogspot.com/-8hs9pzNkCrA/ToHrtMihIMI/AAAAAAAABx4/rFUxgUQdmbA/s400/shanghai-1.jpg" alt="" id="BLOGGER_PHOTO_ID_5657061768646697154" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;While doing my "googling" and security analysis, i happen to come across a Shanghai school portal and manage to easily "gain access" into the &lt;span style="font-weight:bold;"&gt;"admin"&lt;/span&gt; account.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-6VZ1Q0E3BgE/ToHrtU0uy2I/AAAAAAAAByA/AYNqPAMc9RM/s1600/shanghai-2.jpg"&gt;&lt;img style="cursor: pointer; width: 465px; height: 315px;" src="http://3.bp.blogspot.com/-6VZ1Q0E3BgE/ToHrtU0uy2I/AAAAAAAAByA/AYNqPAMc9RM/s400/shanghai-2.jpg" alt="" id="BLOGGER_PHOTO_ID_5657061770870573922" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;With the admin access, i am able to access to all the documents in the portal. Wondering if there are any exam questions in there?&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-dhsxR-vuQik/ToHrtQP7LAI/AAAAAAAAByI/O9x44NphaiM/s1600/shanghai-3.jpg"&gt;&lt;img style="cursor: pointer; width: 466px; height: 314px;" src="http://4.bp.blogspot.com/-dhsxR-vuQik/ToHrtQP7LAI/AAAAAAAAByI/O9x44NphaiM/s400/shanghai-3.jpg" alt="" id="BLOGGER_PHOTO_ID_5657061769642454018" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I can do a listing of all the user account, which i can edit or delete.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;w01f advise: Web portal should be proper secured, especially the administrative account. Strong password should also be used by all users.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;font-size:60%;" &gt;Disclaimer:&lt;/span&gt;&lt;span style="font-size:60%;"&gt; Only access to the "main" and "user account" page, &lt;span style="font-weight: bold;"&gt;no&lt;/span&gt; modification to the portal  and &lt;span style="font-weight: bold;"&gt;no&lt;/span&gt; download of any files from this portal. It is purely for security awareness purpose with no malicious intent. &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-1983648786609221307?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/LCsbRqMU5aoYdBZ4gG-3xdvCCGE/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LCsbRqMU5aoYdBZ4gG-3xdvCCGE/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/LCsbRqMU5aoYdBZ4gG-3xdvCCGE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LCsbRqMU5aoYdBZ4gG-3xdvCCGE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/4nQNTMf-G5U" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/1983648786609221307/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=1983648786609221307" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/1983648786609221307?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/1983648786609221307?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/4nQNTMf-G5U/easy-access-to-exam-questions.html" title="&quot;Easy&quot; access to exam questions?" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-8hs9pzNkCrA/ToHrtMihIMI/AAAAAAAABx4/rFUxgUQdmbA/s72-c/shanghai-1.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2011/09/easy-access-to-exam-questions.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkMGSHY6fyp7ImA9WhdUEUk.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-6411635085476028510</id><published>2011-09-25T20:28:00.006+08:00</published><updated>2011-09-28T00:20:29.817+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-09-28T00:20:29.817+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><title>Should print server be secured?</title><content type="html">Recently, there are many news on data lost of customer information, product designs and algorithms from big corporation. WikiLeaks that exposed sensitive communication. Printers can be one of the good source of data leakage.&lt;br /&gt;&lt;br /&gt;When surfing and "googling" around the Internet, we still see many print servers accessible from Internet. Some of these print servers were even configured with &lt;span style="font-weight:bold;"&gt;default login&lt;/span&gt; credential.&lt;br /&gt;&lt;br /&gt;Beside data leakage, you can also create some disruptions to their business by making unauthorized changes.&lt;br /&gt;&lt;br /&gt;Below are some examples, which i manage to gain access.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/-S6vD3gk8Gkg/ToHhr4Zg1cI/AAAAAAAABxg/gH7-MGoO9RQ/s1600/printer-1.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 453px; height: 273px;" src="http://3.bp.blogspot.com/-S6vD3gk8Gkg/ToHhr4Zg1cI/AAAAAAAABxg/gH7-MGoO9RQ/s400/printer-1.jpg" alt="" id="BLOGGER_PHOTO_ID_5657050750944073154" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;From the Admin console, we can access the "System Tools".&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-914f3lpNs8w/ToHhsJjMmlI/AAAAAAAABxo/lft-6riCsYU/s1600/printer-2.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 455px; height: 274px;" src="http://4.bp.blogspot.com/-914f3lpNs8w/ToHhsJjMmlI/AAAAAAAABxo/lft-6riCsYU/s400/printer-2.jpg" alt="" id="BLOGGER_PHOTO_ID_5657050755548093010" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;We can also make changes in "Advanced Setting".&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-NC-aat11ZsQ/ToHhseS7usI/AAAAAAAABxw/tc_khq2bRc8/s1600/Pserver-1.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 460px; height: 344px;" src="http://4.bp.blogspot.com/-NC-aat11ZsQ/ToHhseS7usI/AAAAAAAABxw/tc_khq2bRc8/s400/Pserver-1.jpg" alt="" id="BLOGGER_PHOTO_ID_5657050761117022914" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;w01f advise: Print server should not be accessible from the Internet. If access from the Internet is required, make sure it is properly secured and change all default login.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-6411635085476028510?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/K9KAxbgzyjSDiZGyQSou22DYa38/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/K9KAxbgzyjSDiZGyQSou22DYa38/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/K9KAxbgzyjSDiZGyQSou22DYa38/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/K9KAxbgzyjSDiZGyQSou22DYa38/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/E7iFZogoRsc" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/6411635085476028510/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=6411635085476028510" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/6411635085476028510?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/6411635085476028510?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/E7iFZogoRsc/should-print-server-be-secured.html" title="Should print server be secured?" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-S6vD3gk8Gkg/ToHhr4Zg1cI/AAAAAAAABxg/gH7-MGoO9RQ/s72-c/printer-1.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2011/09/should-print-server-be-secured.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkYHSXY-eip7ImA9WhZaFko.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-8563001970002857997</id><published>2011-07-01T14:04:00.001+08:00</published><updated>2011-07-03T14:22:18.852+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-03T14:22:18.852+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Video" /><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="Wireless" /><title>Test Drive OmniPeek 6.6</title><content type="html">&lt;a href="http://4.bp.blogspot.com/-cYiUpwFd27U/ThAI2JYJOkI/AAAAAAAABxA/M-0uOLU4dx0/s1600/WildPackets_header.jpg"&gt;&lt;img style="WIDTH: 400px; HEIGHT: 87px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5625005660908894786" border="0" alt="" src="http://4.bp.blogspot.com/-cYiUpwFd27U/ThAI2JYJOkI/AAAAAAAABxA/M-0uOLU4dx0/s400/WildPackets_header.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;Last week, WildPackets released OmniPeek 6.6, the first network analyzer with 802.11n 3-stream wireless support. You can test it out but downloading the&lt;a href="http://www.elabs6.com/c.html?rtr=on&amp;amp;s=7cmme,p0em,iho,k5hi,7g65,j2td,hd6q"&gt; Wireless Essentials Pack&lt;/a&gt;. The pack includes the OmniPeek Enterprise 6.6 demo software as well as three popular wireless add-ons: Wireless Signal Stats, Wireless Channel Aggregator, and Roaming Latency Analyzer.&lt;br /&gt;&lt;br /&gt;The video below with &lt;em&gt;Jay Botelho&lt;/em&gt;, Director, Product Management, and &lt;em&gt;Chris Bloom&lt;/em&gt;, developer and evangelist of WildPackets will tell you all about OmniPeek's wireless capabilities. &lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;object style="height: 268px; width: 440px"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Ol4D7Vn_DsE?version=3"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/Ol4D7Vn_DsE?version=3" type="application/x-shockwave-flash" allowfullscreen="true" allowScriptAccess="always" width="440" height="268"&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-8563001970002857997?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/bBbEYB_crISBbGW0x2SuepaCBeA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/bBbEYB_crISBbGW0x2SuepaCBeA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/bBbEYB_crISBbGW0x2SuepaCBeA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/bBbEYB_crISBbGW0x2SuepaCBeA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/0UEMa3hfBK4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/8563001970002857997/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=8563001970002857997" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/8563001970002857997?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/8563001970002857997?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/0UEMa3hfBK4/test-drive-omnipeek-66.html" title="Test Drive OmniPeek 6.6" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-cYiUpwFd27U/ThAI2JYJOkI/AAAAAAAABxA/M-0uOLU4dx0/s72-c/WildPackets_header.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2011/07/test-drive-omnipeek-66.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0cMQ3s7cSp7ImA9WhZbF0Q.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-313564584329381860</id><published>2011-06-23T11:08:00.001+08:00</published><updated>2011-06-23T11:18:02.509+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-06-23T11:18:02.509+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Malware" /><title>10 Steps: Removing Spyware/Malware/Adware from a PC</title><content type="html">To completely remove spyware from a PC can be very difficult. Most spyware like malware propagates in&amp;nbsp;many different locations i.e. registry, files, system and folders and removing all the erroneous files can&amp;nbsp;be a challenge.&lt;br /&gt;
In some instances spyware software will disable antivirus, firewall and other well known&lt;br /&gt;
security software as well as create fake BSODs.&amp;nbsp;Some may even remove the Microsoft Windows Security&amp;nbsp;Center and replace it with a fake one as well as hijack the browser and stop users from clicking on links&amp;nbsp;to security websites. Worse still a PC may stop loading Windows altogether.&lt;br /&gt;
So you can see the difficulty&amp;nbsp;in attempting to clean a PC. There are some simple steps to removing most spyware and adware – these&amp;nbsp;are generic and provide useful guidance when identifying and cleaning spyware and self-replicating&amp;nbsp;malware from a PC.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;STEP 1:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Reboot PC in Safe Mode with Networking – always log as the same user that was previously logged in&lt;br /&gt;
with, in normal Windows mode*.&lt;br /&gt;
&lt;br /&gt;
An analysis of the spyware threat and how to protect a PC&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;STEP 2:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Launch IE and from Tools&amp;gt;Internet Options&amp;gt;Connections tab click LAN SETTINGS and uncheck the&lt;br /&gt;
checkbox labelled Use a proxy server for your LAN.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;STEP 3:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Download Process Explorer – iexplore.exe (or explorer.scr) – use this program to look for processes&lt;br /&gt;
linked to the rogue program you have installed. Rename the iexplore.exe or winlogon.exe installers.&lt;br /&gt;
Alternatively download and use AutoRuns from SysInternals (you can also run this from removable&lt;br /&gt;
media).&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;STEP 4:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Check the hosts file and if it has any entries other than 127.0.0.1, comment them out –notepad&lt;br /&gt;
c:\windows\system32\drivers\etc\hosts**.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;STEP 5:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Download Malwarebytes Anti-malware – if this doesn’t happen then download both the program and&amp;nbsp;signature update database from another PC and install on the infected PC using removable media.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;STEP 6:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Then download Spybot S&amp;amp;D and Spyware Doctor.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;STEP 7:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Reboot the PC in Safe Mode again and in most situations the malicious files have been removed.&amp;nbsp;Download/update the antivirus and firewall and any other security products on the PC.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;STEP 8:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Run a full scan not a fingerprint scan and then reboot the PC.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;STEP 9:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Download and install CCleaner and click the Registry tab to run a registry clean – don’t forget to make a&lt;br /&gt;
backup of the registry.&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;STEP 10:&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
Download and install NovaShield Anti-malware software – this program uses the OS Kernel to monitor&amp;nbsp;any file; registry; process and network changes. This program will work alongside your existing antivirus&amp;nbsp;and firewall software.&lt;br /&gt;
&lt;br /&gt;
* Sometimes the Safe Mode is disabled by the spyware/malware – this happens because the malicious&amp;nbsp;file has deleted the Safeboot registry keys. It is possible to merge a reg file with the missing Safeboot&amp;nbsp;entries to re-enable Safe Mode.&lt;br /&gt;
&lt;br /&gt;
** Spybot S&amp;amp;D inserts entries into the host file – as long as the host file IP address is 127.0.0.1 then all&amp;nbsp;should be ok. According to Spybot S&amp;amp;D these entries (which can be in their thousands and is known to&amp;nbsp;affect browser performance) are inserted as part of the immunization process.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;Did you know?&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
Antivirus software actually makes silent calls to servers to check application status/virus definition&amp;nbsp;updates and some collect operating system data. The malicious spyware will continue to be a threat.&amp;nbsp;Expect spyware authors to develop more cunning ways to deliver spyware as part of a malicious payload.&amp;nbsp;The attack vectors will include looking for vulnerabilities in Java, Microsoft Windows, website browsers,&amp;nbsp;Active X, and sending users to IFrame websites (can be done from links in search engines) just to name&amp;nbsp;a few.&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;b&gt;By the way&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
You can make some extra $$$ with this guide&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-313564584329381860?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/iJ_obPEFy2D91suT2O3hF1T5LsU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iJ_obPEFy2D91suT2O3hF1T5LsU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/iJ_obPEFy2D91suT2O3hF1T5LsU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iJ_obPEFy2D91suT2O3hF1T5LsU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/JcEdhMTbpj4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/313564584329381860/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=313564584329381860" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/313564584329381860?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/313564584329381860?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/JcEdhMTbpj4/step-by-step-removing.html" title="10 Steps: Removing Spyware/Malware/Adware from a PC" /><author><name>Reny</name><uri>http://www.blogger.com/profile/06877683042739261563</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="25" height="32" src="http://1.bp.blogspot.com/_7NxeMTUZdwE/SsMC4v_dQ8I/AAAAAAAAAC0/U93DwfUEdGw/S220/Evil+toufu.jpg" /></author><thr:total>1</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2011/06/step-by-step-removing.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkYFRX47fSp7ImA9Wx9UE0k.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-5799592190171455093</id><published>2011-02-09T21:57:00.001+08:00</published><updated>2011-02-10T22:28:34.005+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-02-10T22:28:34.005+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><title>Hacker for Hire</title><content type="html">Recently i receive an Marketing Email which sell hacking guides, tools, services and even hiring a hacker.&lt;br /&gt;&lt;br /&gt;The hacking guide they are selling includes:&lt;br /&gt;- Credit card hacking&lt;br /&gt;- Bypass Virtual keyboard in Internet banking&lt;br /&gt;- Exploit and malware development&lt;br /&gt;&lt;br /&gt;They also selling tools like&lt;br /&gt;- Polomorphic Crypter's (to bypass AV Scantime,runtime)&lt;br /&gt;- Paid Botnets&lt;br /&gt;- IRC Bots&lt;br /&gt;- Exploit packs&lt;br /&gt;&lt;br /&gt;Services such as&lt;br /&gt;- VPN Encrypted Connection (Hide your real Ip Address)&lt;br /&gt;- Fake Emailer or Email Bomber&lt;br /&gt;- DDOS attacks&lt;br /&gt;&lt;br /&gt;If you dont know anything about hacking, you can ever hire a hacker to do the job.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/-EuFbhA5c2wE/TVP1G8Uz90I/AAAAAAAABwA/86tZ8k2iR5o/s1600/russian.jpg"&gt;&lt;img style="WIDTH: 455px; HEIGHT: 274px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5572066663608874818" border="0" alt="" src="http://4.bp.blogspot.com/-EuFbhA5c2wE/TVP1G8Uz90I/AAAAAAAABwA/86tZ8k2iR5o/s400/russian.jpg" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;They even have a website that allow you to order their service online. Even hacker give discount.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/-FpnfVXUtL3s/TVP1G70eemI/AAAAAAAABwI/7UeVYFDa1JE/s1600/russian2.JPG"&gt;&lt;img style="WIDTH: 455px; HEIGHT: 283px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5572066663473248866" border="0" alt="" src="http://3.bp.blogspot.com/-FpnfVXUtL3s/TVP1G70eemI/AAAAAAAABwI/7UeVYFDa1JE/s400/russian2.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-5799592190171455093?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/NSedtYDxQK2aeT1cFxyPzGj-lDU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NSedtYDxQK2aeT1cFxyPzGj-lDU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/NSedtYDxQK2aeT1cFxyPzGj-lDU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/NSedtYDxQK2aeT1cFxyPzGj-lDU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/2Lu6G_sA_NY" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/5799592190171455093/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=5799592190171455093" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/5799592190171455093?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/5799592190171455093?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/2Lu6G_sA_NY/hacker-for-hire.html" title="Hacker for Hire" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-EuFbhA5c2wE/TVP1G8Uz90I/AAAAAAAABwA/86tZ8k2iR5o/s72-c/russian.jpg" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2011/02/hacker-for-hire.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE4GQXo5cCp7ImA9Wx9VGUo.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-1375325857136971340</id><published>2011-01-16T14:39:00.000+08:00</published><updated>2011-02-06T15:22:00.428+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-02-06T15:22:00.428+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><category scheme="http://www.blogger.com/atom/ns#" term="Challenge" /><title>Swiss Cyber Storm Cargame Challenge</title><content type="html">&lt;a href="http://1.bp.blogspot.com/_DVupdUqY77M/TU5GwfNzEFI/AAAAAAAABv0/7Cg3PbLLgAs/s1600/win_a_car.jpg"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 268px; FLOAT: left; HEIGHT: 151px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5570467587930918994" border="0" alt="" src="http://1.bp.blogspot.com/_DVupdUqY77M/TU5GwfNzEFI/AAAAAAAABv0/7Cg3PbLLgAs/s400/win_a_car.jpg" /&gt;&lt;/a&gt;Swiss Cyber Storm 3 is having a online January CarGame challenge. It is a Pen-testing wargame that you have to gain access into a vulnerable web application. Try to solve this challenge and win a new car.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;strong&gt;Challenge Description &lt;/strong&gt;&lt;br /&gt;&lt;/span&gt;In Hacking-Lab, it provides a vulnerable web application - and somewhere on the web server you will be able to disclose a backend server &lt;em&gt;&lt;strong&gt;DB connection properties file&lt;/strong&gt;&lt;/em&gt; including &lt;em&gt;&lt;strong&gt;hostname, IP, username and password&lt;/strong&gt;&lt;/em&gt;. It is your goal to disclose this DB property file and then get a SQL connection to the database server. This DB server is vulnerable too! Please &lt;strong&gt;&lt;em&gt;gain interactive access on the database server&lt;/em&gt;&lt;/strong&gt; and proof your access by sending a screenshot of having access, some server info you gather with commands like "hostname" or similar.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Goal&lt;br /&gt;&lt;/span&gt;&lt;/strong&gt;Gain interactive access to the database server. Proof you are able to access the box.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:130%;"&gt;Details&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;You must be &lt;a href="http://www.hacking-lab.com/events/registerform.html?eventid=137"&gt;authenticated&lt;/a&gt; and &lt;a href="http://www.hacking-lab.com/events/registerform.html?eventid=137"&gt;registered&lt;/a&gt; for the January 2011 CarGame Challenge in Hacking-Lab to see the full details of this wargame!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;More details - &lt;/span&gt;&lt;a href="http://www.hacking-lab.com/cases/7025-database-hijack-cargame-challenge/index.html"&gt;&lt;span style="font-size:85%;"&gt;http://www.hacking-lab.com/cases/7025-database-hijack-cargame-challenge/index.html&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;Challenge Registration - &lt;/span&gt;&lt;a href="http://www.hacking-lab.com/events/registerform.html?eventid=137"&gt;&lt;span style="font-size:85%;"&gt;http://www.hacking-lab.com/events/registerform.html?eventid=137&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;br /&gt;Watch &lt;/span&gt;&lt;a href="http://media.hacking-lab.com/movies/v02/"&gt;&lt;span style="font-size:85%;"&gt;Intro video &lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;"&gt;(on how to participate)&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a href="https://www.swisscyberstorm.com/"&gt;&lt;span style="font-size:85%;"&gt;Official Swiss Cyber Storm 3 website&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-1375325857136971340?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/qj8-mLHQ4-6TZIU2xVEwi7TQVG4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qj8-mLHQ4-6TZIU2xVEwi7TQVG4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/qj8-mLHQ4-6TZIU2xVEwi7TQVG4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/qj8-mLHQ4-6TZIU2xVEwi7TQVG4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/NIIQzOWNVT4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/1375325857136971340/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=1375325857136971340" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/1375325857136971340?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/1375325857136971340?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/NIIQzOWNVT4/swiss-cyber-storm-cargame-challenge.html" title="Swiss Cyber Storm Cargame Challenge" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_DVupdUqY77M/TU5GwfNzEFI/AAAAAAAABv0/7Cg3PbLLgAs/s72-c/win_a_car.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2011/02/swiss-cyber-storm-cargame-challenge.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0MMSHw4eyp7ImA9Wx9XGUo.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-4433609023557035189</id><published>2011-01-14T11:24:00.000+08:00</published><updated>2011-01-14T11:24:49.233+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-01-14T11:24:49.233+08:00</app:edited><title>Hacker Space</title><content type="html">Hi all,&lt;br /&gt;
&amp;nbsp;&amp;nbsp;Just want to share this place called Hackerspace in Singapore. &amp;nbsp;There are many such places around the world. &amp;nbsp;You can find more information here :&amp;nbsp;&lt;a href="http://hackerspaces.org/wiki/"&gt;http://hackerspaces.org/wiki/&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="http://en.wikipedia.org/wiki/Hackerspace"&gt;http://en.wikipedia.org/wiki/Hackerspace&lt;/a&gt;&amp;nbsp;.It's an interesting initiative and the local site is here -&amp;nbsp;&lt;a href="http://hackerspace.sg/"&gt;http://hackerspace.sg/&lt;/a&gt;&amp;nbsp;. &amp;nbsp;Only downside is the membership fee due to maintenance of space. &amp;nbsp;I think it's a good spin off from the 2600 monthly meetings-&amp;nbsp;&lt;a href="http://en.wikipedia.org/wiki/2600:_The_Hacker_Quarterly"&gt;http://en.wikipedia.org/wiki/2600:_The_Hacker_Quarterly&lt;/a&gt;&amp;nbsp;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-4433609023557035189?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/G0Bhy1vDfACED9m7pHl0PXFRvUw/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/G0Bhy1vDfACED9m7pHl0PXFRvUw/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/G0Bhy1vDfACED9m7pHl0PXFRvUw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/G0Bhy1vDfACED9m7pHl0PXFRvUw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/SdDesdwSBLs" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/4433609023557035189/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=4433609023557035189" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/4433609023557035189?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/4433609023557035189?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/SdDesdwSBLs/hacker-space.html" title="Hacker Space" /><author><name>Alf</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2011/01/hacker-space.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEcCSXw-fSp7ImA9Wx9RFUU.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-3776566665486057032</id><published>2010-12-17T18:34:00.000+08:00</published><updated>2010-12-17T18:34:28.255+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-17T18:34:28.255+08:00</app:edited><title>Part Two: Two Factor Authentication!?!</title><content type="html">Alas, finally I made it to part two after so long. &amp;nbsp;:)&lt;br /&gt;
&lt;br /&gt;
Continuing from the previous post, OTP tokens are generally time-based or event-based. &amp;nbsp;For time-based tokens, the pseudo-random number changes at a pre-determined interval, usually 30-60 seconds. For event-based tokens, it's based on a user event such as user pressing the button on the token and using a mathematical algorithm to generate the pseudo-random number and so on from there. &amp;nbsp;Further explanation can be found here about what is an OTP -&amp;nbsp;&lt;a href="http://en.wikipedia.org/wiki/One-time_password"&gt;http://en.wikipedia.org/wiki/One-time_password&lt;/a&gt;&amp;nbsp;.&lt;br /&gt;
&lt;br /&gt;
There are now several companies providing such security tokens used for two factor authentication (TFA). &amp;nbsp;A good explanation of the various types of security tokens can be found here -&amp;nbsp;&lt;a href="http://en.wikipedia.org/wiki/Security_token"&gt;http://en.wikipedia.org/wiki/Security_token&lt;/a&gt;&amp;nbsp;.&lt;br /&gt;
&lt;br /&gt;
In Singapore or even worldwide, for most internet banking services, it's already a practice to use such tokens to improve security. &amp;nbsp;(For the curious or security people, you are able to find out which particular token you are using from the list shown earlier.) Although it adds a layer of protection by using security tokens with TFA, it is still not totally foolproof. &lt;br /&gt;
&lt;br /&gt;
With Wikileaks, cyber attacks in Singapore and other recent events, Singaporeans should not be complacent about security. &amp;nbsp;One such event is the DBS false login page that was in the news and luckily the user was knowledgable to not proceed on. &amp;nbsp;Here is one such notice on phishing by the bank -&amp;nbsp;&lt;a href="http://www.dbs.com/sg/personal/ibanking/additionalinfo/security/phishing/default.aspx"&gt;http://www.dbs.com/sg/personal/ibanking/additionalinfo/security/phishing/default.aspx&lt;/a&gt;&amp;nbsp;. The banks has done their part in informing the general public and taking other measures for prevention. &amp;nbsp;Normal users still need to be informed of such risks and how to identify them. &amp;nbsp; &lt;br /&gt;
&lt;br /&gt;
For the technically inclined on how it happens and recommendation of TFA usage, Bruce Schneier mentioned it in his blog here -&lt;a href="http://www.schneier.com/blog/archives/2005/03/the_failure_of.html"&gt;http://www.schneier.com/blog/archives/2005/03/the_failure_of.html&lt;/a&gt;&amp;nbsp;. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
References:&lt;br /&gt;
- Wikipedia&lt;br /&gt;
-&amp;nbsp;&lt;a href="http://www.schneier.com/"&gt;http://www.schneier.com/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-3776566665486057032?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/oErA4sfgcfnbzvlhNQJpO91Qum4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oErA4sfgcfnbzvlhNQJpO91Qum4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/oErA4sfgcfnbzvlhNQJpO91Qum4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/oErA4sfgcfnbzvlhNQJpO91Qum4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/vN0dH4NGgm0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/3776566665486057032/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=3776566665486057032" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/3776566665486057032?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/3776566665486057032?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/vN0dH4NGgm0/part-two-two-factor-authentication.html" title="Part Two: Two Factor Authentication!?!" /><author><name>Alf</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>3</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/12/part-two-two-factor-authentication.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0QBQHw8eip7ImA9Wx5aFEg.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-6469813123673920160</id><published>2010-11-10T16:08:00.005+08:00</published><updated>2010-11-11T14:02:31.272+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-11-11T14:02:31.272+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="Malware" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><category scheme="http://www.blogger.com/atom/ns#" term="Advisory" /><title>Eleonore exploit pack</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_DVupdUqY77M/TNuEVh8wihI/AAAAAAAABu8/Cqby61zGuow/s1600/Eleonore%2Blogin.png"&gt;&lt;img style="cursor: pointer; width: 400px; height: 281px;" src="http://4.bp.blogspot.com/_DVupdUqY77M/TNuEVh8wihI/AAAAAAAABu8/Cqby61zGuow/s400/Eleonore%2Blogin.png" alt="" id="BLOGGER_PHOTO_ID_5538165672207485458" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Exploit packs have been selling in the underground for hundreds of dollars in recent years. These pre-packaged kits are designed to probe the visitor’s browser for known security vulnerabilities, and then use the first one found as a vehicle to quietly install malicious software. They normally comes with a Web administration page, which gives the attacker real-time statistics about victims, such as which browser exploits are working best, and which browsers and browser versions are most successfully attacked. Those commonly found in the market were iPack, Crimepack and Eleonore.&lt;br /&gt;&lt;br /&gt;The latter, Eleonore, is the most popular kit and have been making the headlines recently. It is claim to cost between USD$500 - USD$1000 (based on the version). The package was updated approximately every month with the latest browser, PDF and Java vulnerabilities. These kit providers provide "secured" support, updates and even cleanup of the package service if necessary.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_DVupdUqY77M/TNuEV7xRGhI/AAAAAAAABvE/8dG_QFMo6h8/s1600/eleonore1.jpg"&gt;&lt;img style="cursor: pointer; width: 400px; height: 348px;" src="http://2.bp.blogspot.com/_DVupdUqY77M/TNuEV7xRGhI/AAAAAAAABvE/8dG_QFMo6h8/s400/eleonore1.jpg" alt="" id="BLOGGER_PHOTO_ID_5538165679138609682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;Eleonore Web administration page&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_DVupdUqY77M/TNuEV1zmlmI/AAAAAAAABvM/4LQtVjx4ZeY/s1600/crimepack.jpg"&gt;&lt;img style="cursor: pointer; width: 400px; height: 375px;" src="http://3.bp.blogspot.com/_DVupdUqY77M/TNuEV1zmlmI/AAAAAAAABvM/4LQtVjx4ZeY/s400/crimepack.jpg" alt="" id="BLOGGER_PHOTO_ID_5538165677537793634" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;Crimepack Web administration page&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;w01f advise: Always patch up your system, especially Internet browser, Java, Flash and PDF applications.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-6469813123673920160?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/j_RAuOj342U8f7DQ51rUqT4XfMA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/j_RAuOj342U8f7DQ51rUqT4XfMA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/j_RAuOj342U8f7DQ51rUqT4XfMA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/j_RAuOj342U8f7DQ51rUqT4XfMA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/YYq1jbvfMB4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/6469813123673920160/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=6469813123673920160" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/6469813123673920160?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/6469813123673920160?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/YYq1jbvfMB4/eleonore-exploit-pack.html" title="Eleonore exploit pack" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_DVupdUqY77M/TNuEVh8wihI/AAAAAAAABu8/Cqby61zGuow/s72-c/Eleonore%2Blogin.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/11/eleonore-exploit-pack.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUYDQ38-cSp7ImA9Wx5aEkQ.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-1579811976082615913</id><published>2010-11-09T15:12:00.007+08:00</published><updated>2010-11-09T16:59:32.159+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-11-09T16:59:32.159+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><title>FireSheep Vs BlackSheep</title><content type="html">&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Firesheep&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;It is a Firefox extension that demonstrates HTTP session hijacking attacks. HTTP session hijecking (commonly known as Sidejacking) is a common vulnerability, which sniff the network traffic and extract victim's session information or cookie. With the session information, it can gain access to the victim's account without the need of username and password.&lt;br /&gt;&lt;br /&gt;I have previously blog on &lt;a href="http://werew01f.blogspot.com/2009/04/sidejacking-with-ferret-and-hamster-20.html"&gt;sidejacking with Ferret and Hamster.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://codebutler.github.com/firesheep"&gt;Firesheep&lt;/a&gt; is free, open source, and is available now for Mac OS X and Windows.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_DVupdUqY77M/TNkH-MSkvhI/AAAAAAAABuc/FHvL6fYmA_s/s1600/FireSheep.png"&gt;&lt;img style="cursor: pointer; width: 400px; height: 242px;" src="http://4.bp.blogspot.com/_DVupdUqY77M/TNkH-MSkvhI/AAAAAAAABuc/FHvL6fYmA_s/s400/FireSheep.png" alt="" id="BLOGGER_PHOTO_ID_5537465981861150226" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;BlackSheep&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.zscaler.com/blacksheep.html"&gt;BlackSheep&lt;/a&gt;, also a Firefox plugin is designed to combat Firesheep. BlackSheep does this by dropping ‘fake’ session ID information on the wire and then monitors traffic to see if it has been hijacked. While Firesheep is largely passive, once it identifies session information for a targeted domain, it then makes a subsequent request to that same domain, using the hijacked session information in order to obtain the name of the hijacked user along with an image of the person, if available. It is this request that BlackSheep identifies in order to detect the presence of Firesheep on the network. When identified, the user will be receive the following warning message:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_DVupdUqY77M/TNkI7wO5QpI/AAAAAAAABuk/qjQciHPn_h0/s1600/blacksheep.png"&gt;&lt;img style="cursor: pointer; width: 400px; height: 39px;" src="http://4.bp.blogspot.com/_DVupdUqY77M/TNkI7wO5QpI/AAAAAAAABuk/qjQciHPn_h0/s400/blacksheep.png" alt="" id="BLOGGER_PHOTO_ID_5537467039481414290" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Please note that Firesheep and BlackSheep cannot be installed on the same Firefox instance as they share much of the same code base. If you want to run both Firesheep and BlackSheep on the same machine, they should be installed in separate Firefox profiles.&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-1579811976082615913?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/-nJAMg4vLp43fbEO1dPYY9Bukug/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-nJAMg4vLp43fbEO1dPYY9Bukug/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/-nJAMg4vLp43fbEO1dPYY9Bukug/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/-nJAMg4vLp43fbEO1dPYY9Bukug/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/sa_c-h7JYg0" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/1579811976082615913/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=1579811976082615913" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/1579811976082615913?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/1579811976082615913?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/sa_c-h7JYg0/firesheep-vs-blacksheep.html" title="FireSheep Vs BlackSheep" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_DVupdUqY77M/TNkH-MSkvhI/AAAAAAAABuc/FHvL6fYmA_s/s72-c/FireSheep.png" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/11/firesheep-vs-blacksheep.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkQCSXY8eCp7ImA9Wx9VGUo.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-3119381956123008384</id><published>2010-11-08T17:09:00.003+08:00</published><updated>2011-02-06T14:39:28.870+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-02-06T14:39:28.870+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><title>DotDotPwn 2.1</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_DVupdUqY77M/TNkQIXF3jqI/AAAAAAAABus/Z8Ma9FKwezM/s1600/DotDotpwn.JPG"&gt;&lt;img style="MARGIN: 0pt 10px 10px 0pt; WIDTH: 347px; FLOAT: left; HEIGHT: 201px; CURSOR: pointer" id="BLOGGER_PHOTO_ID_5537474952652361378" border="0" alt="" src="http://4.bp.blogspot.com/_DVupdUqY77M/TNkQIXF3jqI/AAAAAAAABus/Z8Ma9FKwezM/s320/DotDotpwn.JPG" /&gt;&lt;/a&gt;&lt;a href="http://dotdotpwn.sectester.net/"&gt;DotDotPwn&lt;/a&gt; is a Directory Traversal Fuzzer. It works on HTTP, FTP and TFTP servers directory traversal vulnerability. It's written in perl language and can be run either under *NIX or Windows platform.&lt;br /&gt;&lt;br /&gt;It is written by &lt;a href="http://chr1x.sectester.net/"&gt;chr1x&lt;/a&gt; (member of our sectester group) and nitr0us. It had just released &lt;a href="http://dotdotpwn.sectester.net/"&gt;v2.1&lt;/a&gt;, which is more flexible intelligent. So far, 8 security vulnerabilities were discovered by this tools. It was also voted to be included in the next release of the Backtrack Distro.&lt;br /&gt;&lt;br /&gt;Well Done chr1x!!&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-3119381956123008384?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Y7EbWh0xJIDD_xPCuSgDRo90kfU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Y7EbWh0xJIDD_xPCuSgDRo90kfU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Y7EbWh0xJIDD_xPCuSgDRo90kfU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Y7EbWh0xJIDD_xPCuSgDRo90kfU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/QCZRKBVK52E" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/3119381956123008384/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=3119381956123008384" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/3119381956123008384?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/3119381956123008384?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/QCZRKBVK52E/dotdotpwn-21.html" title="DotDotPwn 2.1" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_DVupdUqY77M/TNkQIXF3jqI/AAAAAAAABus/Z8Ma9FKwezM/s72-c/DotDotpwn.JPG" height="72" width="72" /><thr:total>1</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/11/dotdotpwn-21.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUQDRHg4fSp7ImA9Wx5QEUk.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-2525652205660400153</id><published>2010-08-26T12:51:00.002+08:00</published><updated>2010-08-30T13:49:35.635+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-30T13:49:35.635+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Advisory" /><title>New DLL injection attack in Windows</title><content type="html">Microsoft had release an advisory on the vulnerability in Windows applications that allows attacker to execute malicious code remotely on victim's system.&lt;br /&gt;&lt;br /&gt;Some exploits were found attacking third party applications. Microsoft is currently investigating whether any of their applications are susceptible to this DLL injection attack.&lt;br /&gt;&lt;br /&gt;Many friends are asking me about this vulnerability. I think it will be good to explain in more details and share with everyone here.&lt;br /&gt;&lt;br /&gt;The root cause of this vulnerability is the loading of dynamic libraries (DLL), which is the behavior and design of Windows. To better understand, you will need to know how DLL is used in Windows.&lt;br /&gt;&lt;br /&gt;Windows provides a lot of DLL, which allow programmers to use functions from those DLL in their applications. Normally application load their libraries from the current working directory. But if the DLL is not found, there will be a search order that windows will perform.&lt;br /&gt;&lt;br /&gt;Search order:&lt;br /&gt;1. The directory from which the application loaded.&lt;br /&gt;2. The system directory.&lt;br /&gt;3. The 16-bit system directory.&lt;br /&gt;4. The Windows directory.&lt;br /&gt;5. The current directory.&lt;br /&gt;6. The directories that are listed in the PATH environment variable.&lt;br /&gt;&lt;br /&gt;If multiple directories hold a DLL with the same name, the first match be used.&lt;br /&gt;&lt;br /&gt;So attacks exploit the weakness in the way windows search and load associated DLL. This DLL can be located in various directories, which include network paths that is controlled by the attacker. The malicious DLL may then be loaded.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Fix and workaround&lt;/span&gt;&lt;br /&gt;Microsoft mentions that this flaw cannot be fixed in Windows without "Breaking expected functionality". It is because there are many applications that are written to search for their library based only on the file name, rather than the full directory path.&lt;br /&gt;&lt;br /&gt;But Microsoft did provide some workaround such as disable loading of libraries from WebDAV and remote network shares. For more details, refer to the &lt;a href="http://www.microsoft.com/technet/security/advisory/2269637.mspx"&gt;Microsoft Security Advisory (226937)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Related reports:&lt;br /&gt;&lt;span style="font-size:85%;"&gt;- &lt;a href="http://www.theregister.co.uk/2010/08/24/binary_planting_attack_advisory/"&gt;The Register: Microsoft confirms code-execution bug in Windows apps&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;- &lt;a href="http://darkreading.com/vulnerability_management/security/vulnerabilities/showArticle.jhtml?articleID=226900209"&gt;Dark Reading: Microsoft Issues Advisory On New DLL Hijacking Attack&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-2525652205660400153?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/khTgyCBsaFyB9gxtsZ9pCpjaw8s/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/khTgyCBsaFyB9gxtsZ9pCpjaw8s/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/khTgyCBsaFyB9gxtsZ9pCpjaw8s/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/khTgyCBsaFyB9gxtsZ9pCpjaw8s/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/abI7zePIx1Y" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/2525652205660400153/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=2525652205660400153" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/2525652205660400153?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/2525652205660400153?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/abI7zePIx1Y/new-dll-injection-attack-in-windows.html" title="New DLL injection attack in Windows" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/08/new-dll-injection-attack-in-windows.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DkIFQH47cCp7ImA9Wx5REUU.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-3145333005910277470</id><published>2010-08-14T17:19:00.006+08:00</published><updated>2010-08-19T10:21:51.008+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-08-19T10:21:51.008+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Video" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><category scheme="http://www.blogger.com/atom/ns#" term="Advisory" /><title>XSS found in Linkbucks.com</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_DVupdUqY77M/TGuo16WikcI/AAAAAAAABts/XLXIAy1yy6o/s1600/linkbucks_logo1.JPG"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 195px; height: 102px;" src="http://3.bp.blogspot.com/_DVupdUqY77M/TGuo16WikcI/AAAAAAAABts/XLXIAy1yy6o/s320/linkbucks_logo1.JPG" alt="" id="BLOGGER_PHOTO_ID_5506680613540893122" border="0" /&gt;&lt;/a&gt;Linkbucks.com website was found to be vulnerable to Cross Site Scripting(XSS) vulnerability, which could be exploited using malicious scripts.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Vulnerability Description:&lt;br /&gt;==================&lt;br /&gt;Linkbucks.com is a famous advertising network site that brings web users, websites and marketers together. The XSS vulnerability is found in the &lt;span style="font-style: italic;"&gt;Default.aspx&lt;/span&gt; page. Script can be injected to the &lt;span style="font-style: italic;"&gt;Message&lt;/span&gt; and &lt;span style="font-style: italic;"&gt;Returnurl&lt;/span&gt; parameters. This can be exploited by injecting arbitrary HTML and malicious script code, which will execute in a user's browser session. Unvalidated redirection and forwarding is also possible.&lt;br /&gt;&lt;br /&gt;Vulnerability testing:&lt;br /&gt;===============&lt;br /&gt;Vulnerable URL: &lt;span style="font-style: italic;"&gt;http://www.linkbucks.com/Default.aspx?&lt;/span&gt;&lt;br /&gt;Tested with: Firefox 3.5 and Internet Explorer 7 on Windows XP SP3&lt;br /&gt;&lt;br /&gt;A simple "alert("You are hACked by w01f")" script was injected to the "Default" page. It was executed and display on the web browser. Malicious  script could be executed using this method.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_DVupdUqY77M/TGuv1IVZdrI/AAAAAAAABt0/Ft2SEz5w-tg/s1600/Linkbucks1.JPG"&gt;&lt;img style="cursor: pointer; width: 452px; height: 257px;" src="http://3.bp.blogspot.com/_DVupdUqY77M/TGuv1IVZdrI/AAAAAAAABt0/Ft2SEz5w-tg/s400/Linkbucks1.JPG" alt="" id="BLOGGER_PHOTO_ID_5506688296695723698" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Below is the video demonstration on exploiting the XSS vulnerability using redirection. It will redirect to my blog. Hacker can redirect to a spoofed Linkbucks site with malicious code.&lt;br /&gt;&lt;br /&gt;&lt;object height="372" width="460"&gt;&lt;param name="movie" value="http://www.youtube.com/v/xGNshx60rFo&amp;amp;hl=en&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/xGNshx60rFo&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="372" width="460"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Remediation:&lt;br /&gt;==========&lt;br /&gt;The Message and ReturnURL parameters need to be properly sanitized after a user's logging out. The Linksbuck support team was contacted on the vulnerability. The support ticket is "#KHT-97974-227" but so far no fixed was done.&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-3145333005910277470?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/OP8BwUTuXH5PP8SSwB5CSGGivM4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/OP8BwUTuXH5PP8SSwB5CSGGivM4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/OP8BwUTuXH5PP8SSwB5CSGGivM4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/OP8BwUTuXH5PP8SSwB5CSGGivM4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/ynDjOA7CsTE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/3145333005910277470/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=3145333005910277470" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/3145333005910277470?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/3145333005910277470?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/ynDjOA7CsTE/xss-found-in-linkbuckscom.html" title="XSS found in Linkbucks.com" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_DVupdUqY77M/TGuo16WikcI/AAAAAAAABts/XLXIAy1yy6o/s72-c/linkbucks_logo1.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/08/xss-found-in-linkbuckscom.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkEFRXw7eip7ImA9Wx5TEk8.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-871736663495733128</id><published>2010-07-27T17:15:00.006+08:00</published><updated>2010-07-27T19:03:34.202+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-07-27T19:03:34.202+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Video" /><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="Malware" /><title>Windows Lnk Exploit Protection Tool</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_DVupdUqY77M/TE6kMsB9BHI/AAAAAAAABtY/wNkhAP_6RXE/s1600/windows-shortcut.jpg"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 80px; height: 80px;" src="http://4.bp.blogspot.com/_DVupdUqY77M/TE6kMsB9BHI/AAAAAAAABtY/wNkhAP_6RXE/s320/windows-shortcut.jpg" alt="" id="BLOGGER_PHOTO_ID_5498512732950692978" border="0" /&gt;&lt;/a&gt;The Recent Microsoft vulnerability in Windows Shell could allow Remote Code Execution such as using shortcut. Many malwares were found exploiting this vulnerability. Sophos had recently released a free protection tool that claims to be able to detect and block this Windows shortcut exploit from running. It will also work with your existing Anti Virus.&lt;br /&gt;&lt;br /&gt;The tools can be downloaded from this &lt;a href="http://www.sophos.com/products/free-tools/sophos-windows-shortcut-exploit-protection-tool.html"&gt;official website&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Below is the demo video of the tools&lt;br /&gt;&lt;object height="265" width="440"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Gucn5xWZ1m8&amp;amp;hl=en_US&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;embed src="http://www.youtube.com/v/Gucn5xWZ1m8&amp;amp;hl=en_US&amp;amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" height="265" width="440"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Related Report:&lt;br /&gt;- &lt;a href="http://www.microsoft.com/technet/security/advisory/2286198.mspx"&gt;TechNet: Microsoft Security Advisory (2286198)&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Disclamer: I do not in any way endorsed this tool nor responsible for any problem or issue cause by it.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-871736663495733128?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/iIzbm6UuEVlVIl4K79LGFB7K-3k/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iIzbm6UuEVlVIl4K79LGFB7K-3k/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/iIzbm6UuEVlVIl4K79LGFB7K-3k/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/iIzbm6UuEVlVIl4K79LGFB7K-3k/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/LAIcwQhpTr4" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/871736663495733128/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=871736663495733128" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/871736663495733128?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/871736663495733128?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/LAIcwQhpTr4/windows-lnk-exploit-protection-tool.html" title="Windows Lnk Exploit Protection Tool" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_DVupdUqY77M/TE6kMsB9BHI/AAAAAAAABtY/wNkhAP_6RXE/s72-c/windows-shortcut.jpg" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/07/windows-lnk-exploit-protection-tool.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0MFQnY7eip7ImA9Wx5TEkw.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-2249144492601731781</id><published>2010-07-27T13:43:00.003+08:00</published><updated>2010-07-27T14:16:53.802+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-07-27T14:16:53.802+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Wireless" /><category scheme="http://www.blogger.com/atom/ns#" term="Security News" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><title>Vulnerability found in WPA2</title><content type="html">Recently, a vulnerability was found in WPA2 protocol. It is an insider vulnerability where authenticated attacker could launch a "Man in the Middle" attack by decrypting and injecting malicious traffic into the wireless network.&lt;br /&gt;&lt;br /&gt;WPA2 is currently the strongest WiFi encryption and authentication protocol available. According to the researcher in AirTight networks, this vulnerability is a design loophole in IEEE 802.11 Standard.&lt;br /&gt;&lt;br /&gt;Based on the standard, Group Temporal Key (GTK), which is used to protect broadcast data sent to multiple clients, is using a common shared key. This allows authenticated user to use the common key to encrypt and sends spoofed packets to other clients.&lt;br /&gt;&lt;br /&gt;Currently there isn't any patch on this standard.&lt;br /&gt;&lt;br /&gt;Related Report:&lt;br /&gt;&lt;a href="http://www.networkworld.com/newsletters/wireless/2010/072610wireless1.html"&gt;&lt;span style="font-size:85%;"&gt;- NetworkWorld: WPA2 vulnerability found&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-2249144492601731781?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/3OK-rP3CJCq6faxYiqyj70jg-ik/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3OK-rP3CJCq6faxYiqyj70jg-ik/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/3OK-rP3CJCq6faxYiqyj70jg-ik/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3OK-rP3CJCq6faxYiqyj70jg-ik/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/F6kqw36v6EI" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/2249144492601731781/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=2249144492601731781" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/2249144492601731781?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/2249144492601731781?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/F6kqw36v6EI/vulnerability-found-in-wpa2.html" title="Vulnerability found in WPA2" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/07/vulnerability-found-in-wpa2.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU8AR3s9fyp7ImA9Wx5TEk0.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-8682928271985199522</id><published>2010-07-25T12:40:00.000+08:00</published><updated>2010-07-27T13:17:26.567+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-07-27T13:17:26.567+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SPAM" /><title>Email Scam Reloaded</title><content type="html">I have not been receiving any scam email for some time. Finally got last week. This one spoofed to be from the director of &lt;span style="font-weight: bold; font-style: italic;"&gt;United Nations Compensation Commission&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;- Extracted from the Scam mail -&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;From: Jeffrey S. Mears &lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;To: brady@pisem.net&lt;/span&gt; &lt;span style="font-style: italic;"&gt;&lt;br /&gt;Subject: Swift Transafer Notification&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;Jeffrey S. Mears Director,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;United Nations Compensation Commission (UNCC)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;3 Vivian Avenue, London SW1Y 4TE&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;London UK&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;We need to confirm from you if JP Morgan Chase NA, London UK has credited your&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;account, with the approved amount of US$18Million dollars as&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;instructed by United Nations and African Union.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;The African Union and UN has instructed for an immediate transfer to all&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;beneficiaries who has an outstanding payment to collect&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;We will be obliged to confirm from you if you have received the money from our&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;corresponding bank the JP Morgan Chase NA London UK,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;to enable us close your file and put our record straight.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Thanks for the anticipated cooperation.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Jeffrey S. Mears Director,&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;United Nations Compensation Commission (UNCC)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;3 Vivian Avenue, London SW1Y 4TE&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;London UK&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;- End of Email -&lt;br /&gt;&lt;br /&gt;The letter may looks genuine to many, but it gives alot of tell-tale sign that it is actually a scam mail.&lt;br /&gt;&lt;br /&gt;Firstly, the mail was send "To:" some unknown email instead of your own email address. for this case, "To:" field is to "brady@pisem.net".&lt;br /&gt;&lt;br /&gt;Secondly, the sender is suppose to be "Jeffrey S. Mears" of the United Nations Compensation Commission. But the "From:" field is from "wangqm@im.ac.cn", which the domain is not from UN.org.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_DVupdUqY77M/TE5l2tVSMHI/AAAAAAAABs4/6TInamFjG8w/s1600/Scam-1.JPG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 304px;" src="http://1.bp.blogspot.com/_DVupdUqY77M/TE5l2tVSMHI/AAAAAAAABs4/6TInamFjG8w/s400/Scam-1.JPG" alt="" id="BLOGGER_PHOTO_ID_5498444185622163570" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;From the Mail header, the mail seems to be coming from "&lt;span style="font-weight: bold; font-style: italic;"&gt;mail.im.ac.cn&lt;/span&gt;" and the message body was not in plain text but encoded.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_DVupdUqY77M/TE5l3CJAQ1I/AAAAAAAABtA/9_Zkg2cDqho/s1600/scam-2.JPG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 281px;" src="http://1.bp.blogspot.com/_DVupdUqY77M/TE5l3CJAQ1I/AAAAAAAABtA/9_Zkg2cDqho/s400/scam-2.JPG" alt="" id="BLOGGER_PHOTO_ID_5498444191207801682" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Checking on the "mail.im.ac.cn", it is actually from the email system of the "Institute of Microbiology, Chinese Academy of Science" in China. Seems that the user "Wangqm" account was being hacked and used by the scammer.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_DVupdUqY77M/TE5l3UYwC6I/AAAAAAAABtI/rqy42195mO4/s1600/scam3.JPG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 274px;" src="http://2.bp.blogspot.com/_DVupdUqY77M/TE5l3UYwC6I/AAAAAAAABtI/rqy42195mO4/s400/scam3.JPG" alt="" id="BLOGGER_PHOTO_ID_5498444196105685922" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-8682928271985199522?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/UqxcTXpBL_FdJIlUihgm9oKje1E/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/UqxcTXpBL_FdJIlUihgm9oKje1E/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/UqxcTXpBL_FdJIlUihgm9oKje1E/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/UqxcTXpBL_FdJIlUihgm9oKje1E/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/oBKpPAlXicU" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/8682928271985199522/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=8682928271985199522" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/8682928271985199522?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/8682928271985199522?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/oBKpPAlXicU/email-scam-reloaded.html" title="Email Scam Reloaded" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_DVupdUqY77M/TE5l2tVSMHI/AAAAAAAABs4/6TInamFjG8w/s72-c/Scam-1.JPG" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/07/email-scam-reloaded.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU8AQXo5fip7ImA9WxFaFko.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-3243146364573946196</id><published>2010-06-30T17:22:00.004+08:00</published><updated>2010-07-21T10:04:00.426+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-07-21T10:04:00.426+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><title>Reverse Engineering Flash games</title><content type="html">Majority of online games uses Adobe Flash these days. While trying out this online games, i was surprised find out that there are still many unsecured flash games. Some are still sending the score in clear text (shown below). I think it is the basic for all online games to protect the score (or data) while submitting back to the server. I even created a simple &lt;a href="http://werew01f.blogspot.com/2010/05/web-security-challenge-4.html"&gt;Web challenge&lt;/a&gt; (Data Manipulation attacks for Web applications) on this flaw several months back, to teach and share this knowleadge.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_DVupdUqY77M/TDLOP0KRywI/AAAAAAAABrc/t2pllQMOGG0/s1600/shu.JPG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 51px;" src="http://1.bp.blogspot.com/_DVupdUqY77M/TDLOP0KRywI/AAAAAAAABrc/t2pllQMOGG0/s400/shu.JPG" alt="" id="BLOGGER_PHOTO_ID_5490677666813168386" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;Hashing, good enough?&lt;/span&gt;&lt;br /&gt;But there are others that try to protect the score that is transmit back to the server using hashing. They hash the score with a secret key or "Salt". It look safe to many by protecting the data transmission. But they did not protect the Flash itself. It can be easily decompiled to extract the key (shown below) or change the code. Flash code should be obfuscated so that decompiling could not be easily done.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_DVupdUqY77M/TDLOPsgvlLI/AAAAAAAABrU/Pga8kfKF-Qc/s1600/shu_game.JPG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 156px;" src="http://2.bp.blogspot.com/_DVupdUqY77M/TDLOPsgvlLI/AAAAAAAABrU/Pga8kfKF-Qc/s400/shu_game.JPG" alt="" id="BLOGGER_PHOTO_ID_5490677664759911602" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Below is the example of the unsecured Flash game that i came across recently. I had inform their administrator about the possible hacking on their game but they never reply to find out more. So i decided to share some of my finding and show how easy it can be reverse engineered.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_DVupdUqY77M/TDLOPWnV2hI/AAAAAAAABrM/UatNxfRoA28/s1600/WD+game.JPG"&gt;&lt;img style="cursor: pointer; width: 464px; height: 201px;" src="http://3.bp.blogspot.com/_DVupdUqY77M/TDLOPWnV2hI/AAAAAAAABrM/UatNxfRoA28/s400/WD+game.JPG" alt="" id="BLOGGER_PHOTO_ID_5490677658882005522" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Below is function that calls the hashing and submit the user's info and score.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_DVupdUqY77M/TDLOPESWtTI/AAAAAAAABrE/sCShaz2RXOY/s1600/WD_game1.JPG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 144px;" src="http://3.bp.blogspot.com/_DVupdUqY77M/TDLOPESWtTI/AAAAAAAABrE/sCShaz2RXOY/s400/WD_game1.JPG" alt="" id="BLOGGER_PHOTO_ID_5490677653962143026" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Below shows the "key" or "Salt" that is use for the hashing.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_DVupdUqY77M/TDLOOkSxXVI/AAAAAAAABq8/2uWryPiz3SY/s1600/WD_game2.JPG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 89px;" src="http://4.bp.blogspot.com/_DVupdUqY77M/TDLOOkSxXVI/AAAAAAAABq8/2uWryPiz3SY/s400/WD_game2.JPG" alt="" id="BLOGGER_PHOTO_ID_5490677645373955410" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0); font-weight: bold;"&gt;-Update on 19 Jul&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;After the programmer of the game (that i previously  mentioned) tried to secure their code, they were hacked again. This time it looks like an Indonesian hacker, which uses the name "Rank 1 to 10 all cheated" in Bahasa Indonesia,  put himself on the top of the score table (with obvious reason).&lt;br /&gt;&lt;br /&gt;Looks like the programmer don't understand malay language at all as the name was listed for a few days and was not removed. Time for me to send them a note again.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_DVupdUqY77M/TEZRB5l2cGI/AAAAAAAABsw/8qc2pqpmau0/s1600/WD_hacks.JPG"&gt;&lt;img style="float: left; margin: 0pt 10px 10px 0pt; cursor: pointer; width: 450px; height: 226px;" src="http://2.bp.blogspot.com/_DVupdUqY77M/TEZRB5l2cGI/AAAAAAAABsw/8qc2pqpmau0/s400/WD_hacks.JPG" alt="" id="BLOGGER_PHOTO_ID_5496169488333566050" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-3243146364573946196?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/JjQx35IaoZZ1wVny5uAryd293Xk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/JjQx35IaoZZ1wVny5uAryd293Xk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/JjQx35IaoZZ1wVny5uAryd293Xk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/JjQx35IaoZZ1wVny5uAryd293Xk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/9iiBNOPi-1c" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/3243146364573946196/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=3243146364573946196" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/3243146364573946196?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/3243146364573946196?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/9iiBNOPi-1c/reverse-engineering-flash-games.html" title="Reverse Engineering Flash games" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_DVupdUqY77M/TDLOP0KRywI/AAAAAAAABrc/t2pllQMOGG0/s72-c/shu.JPG" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/06/reverse-engineering-flash-games.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE4MQ34zeSp7ImA9Wx9SFkk.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-5829279160856376297</id><published>2010-06-01T10:09:00.004+08:00</published><updated>2010-12-06T21:43:02.081+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-12-06T21:43:02.081+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Advisory" /><title>Wing FTP Server XSS vulnerability by w01f Labs</title><content type="html">New finding from the w01f Labs, the Wing FTP Server was found to be vulnerable to Cross Site Scripting(XSS) vulnerability, which could be exploited using malicious scripts.&lt;br /&gt;&lt;br /&gt;Discovered Date: May 31, 2010&lt;br /&gt;System affected: Wing FTP Server for Windows, Version 3.5.0 and prior version&lt;br /&gt;&lt;br /&gt;For more detail on this vulnerability, visit my research site - &lt;a href="http://labs-werew01f.blogspot.com/2010/06/wing-ftp-server-cross-site-scripting.html"&gt;w01f Labs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;References:&lt;br /&gt;&lt;span style="font-size:85%;"&gt;- &lt;a href="http://www.securityfocus.com/bid/40510"&gt;SecurityFocus: Wing FTP Server 'admin_loginok.html' HTML Injection Vulnerability&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;- &lt;a href="http://seclists.org/bugtraq/2010/Jun/30"&gt;Bugtraq: Wing FTP Server - Cross Site Scripting Vulnerability&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-5829279160856376297?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/LNZdF0JpWv0Q24Qxh2BMoGmDKUU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LNZdF0JpWv0Q24Qxh2BMoGmDKUU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/LNZdF0JpWv0Q24Qxh2BMoGmDKUU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LNZdF0JpWv0Q24Qxh2BMoGmDKUU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/vjDZzqweIrw" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/5829279160856376297/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=5829279160856376297" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/5829279160856376297?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/5829279160856376297?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/vjDZzqweIrw/wing-ftp-server-xss-vulnerability-by.html" title="Wing FTP Server XSS vulnerability by w01f Labs" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/06/wing-ftp-server-xss-vulnerability-by.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A08MRn0-eip7ImA9WxFVFEo.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-405679802121752041</id><published>2010-05-31T16:03:00.007+08:00</published><updated>2010-06-14T09:44:47.352+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-06-14T09:44:47.352+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Tools" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><title>Nessus Plugin for VicFTPS Vulnerability</title><content type="html">Wrote a Nessus Plugin to test on the VicFTPS Directory Traversal Vulnerability, that was discovered by &lt;a href="http://chr1x.sectester.net/"&gt;chr1x&lt;/a&gt; (member of our sectester team).&lt;br /&gt;&lt;br /&gt;This plugin will exploited the directory traversal vulnerability and return results if successful. I will be sending it to Nessus to get it added into the Plugin Feeds to be share with everyone. You can download the plugin &lt;a href="http://cid-74d1e225b6278058.office.live.com/self.aspx/werew01f/vicFTPS%5E_ftp%5E_traversal.zip" target="_blank"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;-Test with NASL Interpreter&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_DVupdUqY77M/TATMWiUb22I/AAAAAAAABpc/NUq2ykdl6cU/s1600/nasl_test.JPG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 151px;" src="http://4.bp.blogspot.com/_DVupdUqY77M/TATMWiUb22I/AAAAAAAABpc/NUq2ykdl6cU/s320/nasl_test.JPG" alt="" id="BLOGGER_PHOTO_ID_5477727734331071330" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;- Added the Plugin&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_DVupdUqY77M/TATMgXUtzAI/AAAAAAAABpk/oMJbJv19Oyk/s1600/nessus_test1.JPG"&gt;&lt;img style="cursor: pointer; width: 369px; height: 400px;" src="http://1.bp.blogspot.com/_DVupdUqY77M/TATMgXUtzAI/AAAAAAAABpk/oMJbJv19Oyk/s400/nessus_test1.JPG" alt="" id="BLOGGER_PHOTO_ID_5477727903178148866" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;font-size:85%;" &gt;-Result from a scan&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_DVupdUqY77M/TATMg0_5VMI/AAAAAAAABps/Q3WfvunxGpA/s1600/nessus_test3.JPG"&gt;&lt;img style="cursor: pointer; width: 400px; height: 277px;" src="http://3.bp.blogspot.com/_DVupdUqY77M/TATMg0_5VMI/AAAAAAAABps/Q3WfvunxGpA/s400/nessus_test3.JPG" alt="" id="BLOGGER_PHOTO_ID_5477727911143888066" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;References:&lt;br /&gt;&lt;span style="font-size:85%;"&gt;- &lt;a href="http://www.securityfocus.com/bid/39919" target="_blank"&gt;SecurityFocus: VicFTPS Directory Traversal Vulnerability&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-405679802121752041?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/LEJw6W2kC0xreza9ec9xnpG_krc/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LEJw6W2kC0xreza9ec9xnpG_krc/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/LEJw6W2kC0xreza9ec9xnpG_krc/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/LEJw6W2kC0xreza9ec9xnpG_krc/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/0SF428ibuIk" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/405679802121752041/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=405679802121752041" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/405679802121752041?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/405679802121752041?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/0SF428ibuIk/nessus-plugin-for-vicftps-vulnerability.html" title="Nessus Plugin for VicFTPS Vulnerability" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_DVupdUqY77M/TATMWiUb22I/AAAAAAAABpc/NUq2ykdl6cU/s72-c/nasl_test.JPG" height="72" width="72" /><thr:total>2</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/05/nessus-plugin-for-vicftps-vulnerability.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU8CQ385eip7ImA9WxFWGUU.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-4841164629607356221</id><published>2010-05-26T10:11:00.002+08:00</published><updated>2010-06-08T15:57:42.122+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-06-08T15:57:42.122+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Security News" /><category scheme="http://www.blogger.com/atom/ns#" term="Hacking" /><category scheme="http://www.blogger.com/atom/ns#" term="General" /><title>The Pwn2Own 2010 Contest</title><content type="html">&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_DVupdUqY77M/S_3W6nPekLI/AAAAAAAABpU/hnv_XcmfmfE/s1600/dvlabs_logo.gif"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer; width: 162px; height: 56px;" src="http://4.bp.blogspot.com/_DVupdUqY77M/S_3W6nPekLI/AAAAAAAABpU/hnv_XcmfmfE/s320/dvlabs_logo.gif" alt="DVLabs" id="BLOGGER_PHOTO_ID_5475769024407048370" border="0" /&gt;&lt;/a&gt;The Pwn2Own 2010 organized by &lt;a href="http://dvlabs.tippingpoint.com/blog/2010/02/15/pwn2own-2010"&gt;DVlabs&lt;/a&gt; was over. But there are some interesting information to share.&lt;br /&gt;&lt;span style="font-size:78%;"&gt;(Extract from "&lt;a href="http://threatpost.com/en_us/slideshow/10%20Lessons%20From%20The%20Pwn2Own%20Hacker%20Contest"&gt;10 Lessons From The Pwn2Own Hacker Contest&lt;/a&gt;")&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Google Chrome the &lt;span style="font-style: italic;"&gt;Most Secured&lt;/span&gt;?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;"The only browser that survived Pwn2Own this year was Google Chrome. This led to numerous news reports like this one suggesting that Google's browser was somehow more secure than the others. This is far from the truth.  In fact, the vulnerability that caused the iPhone's downfall was in the WebKit engine and also affected the Google Chrome browser. Chrome's sandbox was also held up as a major CanSecWest roadblock but there's already scuttlebutt circulating that at least two security researchers have found a way to break out of the Chrome sandbox. Keep in mind that the iPhone has a sandbox that didn't help much when hackers hijacked the SMS database at Pwn2Own.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;Survival at the Pwn2Own contest simply means that researchers weren't motivated enough to give up their vulnerabilities/exploits in exchange for a smartphone and cash prizes. The iPhone survived in 2008, didn't it?"&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;IE 8 seems to be &lt;span style="font-style: italic;"&gt;Most Protected&lt;/span&gt; Browser.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;"Despite the survival of Google Chrome and the fall of Internet Explorer 8 (running on Windows 7), all the browser hackers at the contest maintained that Microsoft's browser is by far the most difficult to exploit. For starters, IE 8 is the only browser to fully -- and properly -- implement ASLR. Peter Vreugdenhil, the researcher behind the successful IE 8 hack, needed two different vulnerabilities and several exploitation tricks to get it to work. However, because IE is the world's most widely deployed browser, it will continue to attract the attention of hackers and malware writers. Security doesn't equate to safety."&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Apple Safari still the &lt;span style="font-style: italic;"&gt;Easiest&lt;/span&gt; to Hack?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-style: italic;"&gt;"For the third year in a row, security researcher Charlie Miller successfully compromised a fully patched MacBook Pro machine with a Safari vulnerability and exploit. Despite Apple's best efforts at making it difficult to exploit the Mac OS X, Miller's exploits show that Safari is still easy pickings because it lacks the mitigations found in Microsoft Windows. For example, Safari does not implement ASLR properly and does not have a sandbox to limit the damage from a hacker attack."&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-4841164629607356221?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/0MEMlq1SO7thtgJ0hrtOhsHv7aU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0MEMlq1SO7thtgJ0hrtOhsHv7aU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/0MEMlq1SO7thtgJ0hrtOhsHv7aU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0MEMlq1SO7thtgJ0hrtOhsHv7aU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/LVRKMhcm6lE" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/4841164629607356221/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=4841164629607356221" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/4841164629607356221?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/4841164629607356221?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/LVRKMhcm6lE/pwn2own-2010-contest.html" title="The Pwn2Own 2010 Contest" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_DVupdUqY77M/S_3W6nPekLI/AAAAAAAABpU/hnv_XcmfmfE/s72-c/dvlabs_logo.gif" height="72" width="72" /><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/05/pwn2own-2010-contest.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0UHQH88eCp7ImA9WxFWGE0.&quot;"><id>tag:blogger.com,1999:blog-8593126747356640914.post-6140801478932422422</id><published>2010-05-19T10:41:00.005+08:00</published><updated>2010-06-06T14:20:31.170+08:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2010-06-06T14:20:31.170+08:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Advisory" /><title>D-Link Router XSS vulnerability found by w01f Labs</title><content type="html">I have discover a Cross site Scripting (XSS) vulnerability on my own D-Link Router while working on fuzzing and vulnerability research last week. This vulnerability allows injecting of arbitrary HTML and malicious script code in the user's browser session.&lt;br /&gt;&lt;br /&gt;Discovered Date: May 14, 2010&lt;br /&gt;System affected: D-Link DI-724P+ Router, Firmware Version: v1.03&lt;br /&gt;&lt;br /&gt;For more detail on this vulnerability, visit my research site - &lt;a href="http://labs-werew01f.blogspot.com/2010/05/xss-vulnerability-found-on-d-link.html"&gt;w01f Labs&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Other References:&lt;br /&gt;&lt;span style="font-size:85%;"&gt;- &lt;a href="http://www.securityfocus.com/bid/40261/info"&gt;SecurityFocus: D-Link DI-724P+ Router 'wlap.htm' HTML Injection Vulnerability&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;- &lt;a href="http://osvdb.org/show/osvdb/65002"&gt;OSVDB 65002 : D-Link DI-724P+ Admin Interface wlap.htm GET String XSS&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;- &lt;a href="http://www.sans.org/newsletters/risk/display.php?v=9&amp;amp;i=22#10.22.111"&gt;SANS: @RISK: The Consensus Security Vulnerability Alert&lt;/a&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8593126747356640914-6140801478932422422?l=werew01f.blogspot.com' alt='' /&gt;&lt;/div&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/65H_goca1HOFbFOwsRuTFLyBg4o/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/65H_goca1HOFbFOwsRuTFLyBg4o/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/65H_goca1HOFbFOwsRuTFLyBg4o/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/65H_goca1HOFbFOwsRuTFLyBg4o/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/WolfsLair/~4/Uj79heRwC5U" height="1" width="1"/&gt;</content><link rel="replies" type="application/atom+xml" href="http://werew01f.blogspot.com/feeds/6140801478932422422/comments/default" title="Post Comments" /><link rel="replies" type="text/html" href="http://www.blogger.com/comment.g?blogID=8593126747356640914&amp;postID=6140801478932422422" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/6140801478932422422?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/8593126747356640914/posts/default/6140801478932422422?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/WolfsLair/~3/Uj79heRwC5U/d-link-router-xss-vulnerability-found.html" title="D-Link Router XSS vulnerability found by w01f Labs" /><author><name>w01f</name><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="24" height="32" src="http://bp0.blogger.com/_DVupdUqY77M/SI03LYe4epI/AAAAAAAAAk0/K8drhVsUSJY/S220/Bert-closeup.JPG" /></author><thr:total>0</thr:total><feedburner:origLink>http://werew01f.blogspot.com/2010/05/d-link-router-xss-vulnerability-found.html</feedburner:origLink></entry></feed>

