<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>WARLOCK</title>
	
	<link>http://www.akati.com/warlock</link>
	<description>Gothically Secure</description>
	<pubDate>Wed, 09 Jun 2010 05:03:53 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/akati/LLyT" /><feedburner:info uri="akati/llyt" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><creativeCommons:license>http://creativecommons.org/licenses/by/3.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by/3.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><feedburner:emailServiceId>akati/LLyT</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Security Threats in 2010 !</title>
		<link>http://feedproxy.google.com/~r/akati/LLyT/~3/6bT3z0xdSP4/</link>
		<comments>http://www.akati.com/warlock/?p=73#comments</comments>
		<pubDate>Tue, 05 Jan 2010 00:36:36 +0000</pubDate>
		<dc:creator>warlock</dc:creator>
		
		<category><![CDATA[Consulting]]></category>

		<category><![CDATA[Exploits]]></category>

		<category><![CDATA[General]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.akati.com/warlock/?p=73</guid>
		<description><![CDATA[Now we had some request to post this earlier and through the Warlock blog, and since most of you found the previous 2008 and 2009 " security predictions" useful, we hope you find this useful too !]]></description>
			<content:encoded><![CDATA[<p>Hi There folks !</p>
<p>Happy New Year 2010, Greetings from Warlock !</p>
<p>( Yup, he ain&#8217;t dead yet )</p>
<p>Now we had some request to post this earlier and through the Warlock blog, and since most of you found the previous 2008 and 2009 &#8221; security predictions&#8221; posts useful, we hope you find this useful too !</p>
<p><img src="http://farm3.static.flickr.com/2761/4245728045_f7e7c83bd5_m.jpg" alt="iPhone Hacked" /></p>
<p>•	Well you guessed it ! Social Networks topped the list for 2010, with malware targetting Social Network sites like Koobface (that appeared for Facebook) to be more common,</p>
<p>•	File Sharing Sites (Rapidshare, other file share services utilizing cloud computing , yup that includes torrents *smile* )  will continue to be a prime target,</p>
<p>•	Botnets and Botnet gang partnerships will increase dramatically this year,</p>
<p>•	Adobe Acrobat and Flash Attacks</p>
<p>•	iPhone and Android Massive Attacks !</p>
<p>•	New wave of attacks on Web services such as the new Google wave, is a hot cake</p>
<p>•	Traditional exploit epidemics will continue as 2009 was rather quiet compared to 2008</p>
<p>That&#8217;s it folks , Put your security hats on , and all the best !</p>
<p>Hasta La Vista for now !</p>
<img src="http://feeds.feedburner.com/~r/akati/LLyT/~4/6bT3z0xdSP4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.akati.com/warlock/?feed=rss2&amp;p=73</wfw:commentRss>
		<feedburner:origLink>http://www.akati.com/warlock/?p=73</feedburner:origLink></item>
		<item>
		<title>Tomorrow - Biggest ever Microsoft Patch Tuesday</title>
		<link>http://feedproxy.google.com/~r/akati/LLyT/~3/cqUsw_D4PZI/</link>
		<comments>http://www.akati.com/warlock/?p=71#comments</comments>
		<pubDate>Mon, 12 Oct 2009 03:30:48 +0000</pubDate>
		<dc:creator>warlock</dc:creator>
		
		<category><![CDATA[Exploits]]></category>

		<category><![CDATA[General]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.akati.com/warlock/?p=71</guid>
		<description><![CDATA[Microsoft is preparing for its biggest ever batch of patches, this Tuesday , with a total of 34 security flaws across a wide spectrum of Microsoft products, including SMBv2 Zero Day Exploit.]]></description>
			<content:encoded><![CDATA[<p>Microsoft is preparing for its biggest ever batch of patches, this Tuesday , with a total of 34 security flaws across a wide spectrum of Microsoft products. Eight of the security bulletin&#8217;s earn the dread classification of critical, Microsoft&#8217;s highest severity rating.</p>
<p>Two of these upcoming critical updates address the targets of active hacking attacks - a vulnerability in SMBv2 (Server Message Block, version 2) and a security flaw in the FTP component in Microsoft&#8217;s IIS web server software.</p>
<p>Other patches cover IE, Office, developer tools, and SQL Server. All supported versions of Windows will need patching for one reason or another, including Windows 7. The operating system doesn&#8217;t ship till 22 October but its RTM code needs patching ahead of that to defend against critical IE8-related security bugs.</p>
<p>The 13 bulletins compare with the previous high-water mark of 12, reached by Microsoft in February 2007 and equalled in October 2008.</p>
<p>For a PoC  <img src='http://www.akati.com/warlock/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> Code by Metasploit on SMBv2 <a href="http://trac.metasploit.com/browser/framework3/trunk/modules/exploits/windows/smb/smb2.rb?rev=7085">click here </a></p>
<p><a href="http://www.microsoft.com/technet/security/advisory/975497.mspx">See here</a> on how to disable SMBv2 </p>
<img src="http://feeds.feedburner.com/~r/akati/LLyT/~4/cqUsw_D4PZI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.akati.com/warlock/?feed=rss2&amp;p=71</wfw:commentRss>
		<feedburner:origLink>http://www.akati.com/warlock/?p=71</feedburner:origLink></item>
		<item>
		<title>Online Privacy Protection Methods - Digital Safety</title>
		<link>http://feedproxy.google.com/~r/akati/LLyT/~3/FRSDffcjurc/</link>
		<comments>http://www.akati.com/warlock/?p=67#comments</comments>
		<pubDate>Fri, 17 Jul 2009 02:13:26 +0000</pubDate>
		<dc:creator>warlock</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.akati.com/warlock/?p=67</guid>
		<description><![CDATA[Here are a few links to softwares and techniques you can use to have a safer, better, browsing and online experience !]]></description>
			<content:encoded><![CDATA[<p>Hi Everyone , </p>
<p>Here are a few links to softwares and techniques you can use to have a safer, better, browsing and online experience !</p>
<p><strong>Online Browsing Privacy </strong></p>
<p>Fix: </p>
<p>- Try using your browsers Private Browsing features ( In Private for IE8 )</p>
<p>- Firefox users, you could try <a href="http://www.gness.com/distrust/">“Distrust” </a>(http://www.gness.com/distrust/)</p>
<p>- Instruct IE to save its cache to a portable drive that you keep plugged in whenever you need to use the browser<br />
(Open the Internet Options control panel, click the Settings button in the Temporary Internet Files section, click the Move Folder button, and navigate to a folder on your external drive.)</p>
<p>- Using a software utility to wipe the cache securely after you&#8217;re done surfing.<br />
Try <a href="http://www.heidi.ie/eraser/">Eraser </a>(http://www.heidi.ie/eraser/)</p>
<p>- <a href="http://secunia.com/">Secunia Personal Software Inspector</a> ( http://secunia.com/) </p>
<p>- If you suspect a virus infected file , go ahead to <a href="http://www.virustotal.com/">VirusTotal</a> (http://www.virustotal.com/) , get the file scanned online by over 35 different AV engines.</p>
<p><strong>Anti Phishing</strong> - The best approach, and the most straightforward, is never to click a link in any e-mail message to access your confidential sites. Instead, always type the URL or use a bookmark. That one habit will protect you from almost every phishing attack.</p>
<p>But no browser can completely prevent sites from tracking your visit. For better anonymity, use <a href="http://www.anonymizer.com/">Anonymizer</a> (http://www.anonymizer.com/) or the <a href="http://tor.eff.org/">excellent Tor or The Onion Ring</a> ( http://tor.eff.org/).</p>
<p><strong>Password Privacy </strong></p>
<p><img alt="" src="http://www.michaeltbarrett.com/images/palin.jpg" title="Sarah Palin" class="alignnone" width="380" height="475" /></p>
<p>Why You Should Care: Your passwords are the keys to everything you&#8217;ve locked inside.<br />
These days everyone has a LinkedIn account, a Facebook profile, and a Twitter feed, and these information make it all too easy to guess the answers to commonly used security questions such as the high school you attended or the name of your dog. You may have blogged about these things half a dozen times or more.</p>
<p>Fix: </p>
<p>Use a password manager religiously, and back up your password files. <a href="http://portableapps.com/">Portableapps.com version of the KeePass software</a> (http://portableapps.com/)  is a good place to start. And once you&#8217;ve created a random, unguessable password, generate a second, different password in the manager - use as the answer to the inevitable &#8220;mother&#8217;s maiden name&#8221; question (or questions). </p>
<p>Mom may not appreciate being identified as Miss L33t#r5, but no one will ever guess that that&#8217;s how you listed her in your &#8220;secret questions&#8221; data sheet.</p>
<p>Also If you can restart a public PC that you need to use, then bring your own bootable OS ( XP, Linux, etc ) and preload it with an AV , Password Manager that could be downloaded at PortableApps.com</p>
<p>Also Be careful of Using Laptops in Hotspots for your Online Banking Needs !</p>
<p><strong>Cell Phone Security </strong></p>
<p><img alt="" src="http://images.crackberry.com/files/kevin/parishiltoncurve.jpg" title="Paris Blackberry" class="alignnone" width="300" height="300" /></p>
<p>Fix: </p>
<p>Before you ditch an old phone, use your phone&#8217;s reset codes or menu options to clear your message archives and your contacts list. Check the <a href="http://www.recellular.com/recycling/data_eraser/">ReCellular Data Eraser</a> (http://www.recellular.com/recycling/data_eraser/) page to learn how to reset your phone, and follow the instructions there.</p>
<p><strong>Fake Anti-Malware</strong></p>
<p>Scenario: Fraudulently advertised, ineffective antimalware ranks among the fastest-growing types of online scams. Products with names like DriveCleaner, WinFixer, Antivirus XP, and Antivirus 2009 are touted through online ads that simulate Windows alert messages, warning you that your computer is infected with some sort of malware and advising you to buy a particular antivirus product to fix it. </p>
<p>Fix : Use a real anti malware , based on ratings done by independent researchers </p>
<p><strong>OS Exploit Attacks ( 0h Day )</strong></p>
<p>Fix : Smile and Pray </p>
<p>You just have to keep up on the latest security news and visit <a href="http://update.microsoft.com">update.microsoft.com</a> as soon as you hear about any out-of-band patches, rather than waiting for Automatic Updates to kick in.</p>
<img src="http://feeds.feedburner.com/~r/akati/LLyT/~4/FRSDffcjurc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.akati.com/warlock/?feed=rss2&amp;p=67</wfw:commentRss>
		<feedburner:origLink>http://www.akati.com/warlock/?p=67</feedburner:origLink></item>
		<item>
		<title>Security Incidents in 2008 and 2009</title>
		<link>http://feedproxy.google.com/~r/akati/LLyT/~3/j6LWphcOlWY/</link>
		<comments>http://www.akati.com/warlock/?p=66#comments</comments>
		<pubDate>Mon, 13 Apr 2009 02:35:11 +0000</pubDate>
		<dc:creator>warlock</dc:creator>
		
		<category><![CDATA[Consulting]]></category>

		<category><![CDATA[Exploits]]></category>

		<category><![CDATA[General]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.akati.com/warlock/?p=66</guid>
		<description><![CDATA[Hi Everyone, Sorry for the silence for couple of weeks, have been swamped with work ..anyway, here is something i would like to share with everyone, although we first presented this in a Web Jurist Conference in Lagos, Nigeria, I&#8217;d thought that it would benefit a lot of IT Professionals out there..
In 2008 :
67% percent [...]]]></description>
			<content:encoded><![CDATA[<p>Hi Everyone, Sorry for the silence for couple of weeks, have been swamped with work ..anyway, here is something i would like to share with everyone, although we first presented this in a Web Jurist Conference in Lagos, Nigeria, I&#8217;d thought that it would benefit a lot of IT Professionals out there..</p>
<p>In 2008 :</p>
<p>67% percent of the attacks in 2008 were &#8220;for profit&#8221; motivated.</p>
<p>Ideological hacking came second.</p>
<p>With 20%, good old SQL injections dominated as the most common techniques used in the attacks.</p>
<p>XSS finished 4th with 12 percent and the young and promising CSRF is still only seldom exploited out there and was included in the &#8220;others&#8221; group.</p>
<p></p>
<p>In 2009:</p>
<p>1. Bots will be the dominant issue for 2009</p>
<p>2. Web 2.0 services and sites will come under targeted attacks – XSS &amp; CSRF</p>
<p>3. Social networking sites will continue to provide helpless victims.</p>
<p>4. Windows Vista will become a more appealing target to attackers.</p>
<p>5. Mobile Hacking – Blackberry &amp; iPhone Hacking</p>
<p>6. Smarter malware – Obfuscation Techniques</p>
<p>7. Take advantage of opportunity – Corporate Espionage &amp; Competitive Intelligence</p>
<p>8. Drive-by Pharming</p>
<p></p>
<img src="http://feeds.feedburner.com/~r/akati/LLyT/~4/j6LWphcOlWY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.akati.com/warlock/?feed=rss2&amp;p=66</wfw:commentRss>
		<feedburner:origLink>http://www.akati.com/warlock/?p=66</feedburner:origLink></item>
		<item>
		<title>Dangerous - JBIG2 Adobe Acrobat Universal Exploit !</title>
		<link>http://feedproxy.google.com/~r/akati/LLyT/~3/NuZyFrdSmcg/</link>
		<comments>http://www.akati.com/warlock/?p=64#comments</comments>
		<pubDate>Wed, 25 Mar 2009 05:11:13 +0000</pubDate>
		<dc:creator>warlock</dc:creator>
		
		<category><![CDATA[Exploits]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.akati.com/warlock/?p=64</guid>
		<description><![CDATA[Disclaimer: This post is for research/education purposes only and AKATI Consulting (UK) Ltd. will not be held liable for anything that you do with this information.
Hi Guys ! Here is something *dangerous* for you to learn and experiment with.
This time, I thought I’d post about the recent JBIG2 Adobe Acrobat Universal Exploit (APSB09-01 (aka CVE-2009-0658))
The [...]]]></description>
			<content:encoded><![CDATA[<p><span style="color: #333333; font-family: 'Trebuchet MS'; line-height: normal;"><b>Disclaimer: This post is for research/education purposes only and AKATI Consulting (UK) Ltd. will not be held liable for anything that you do with this information.</b></span></p>
<p>Hi Guys ! Here is something *dangerous* for you to learn and experiment with.</p>
<p>This time, I thought I’d post about the recent JBIG2 Adobe Acrobat Universal Exploit (APSB09-01 (aka CVE-2009-0658))</p>
<p>The guys at <a href="http://bl4cksecurity.blogspot.com/">Blacksecurity</a> have written a very neat modification of the original blog post in the <a href="http://vrt-sourcefire.blogspot.com/2009/02/have-nice-weekend-pdf-love.html">snort VRT blog posting</a> (http://vrt-sourcefire.blogspot.com/2009/02/have-nice-weekend-pdf-love.html)</p>
<p>The actual bug stems from a pointer-indexing issue when utilizing a specifically crafted JBIG2 structure. And the Blasksec folks have made it available in a pdf format.</p>
<p>All you have to do is :</p>
<p>1. Download the <a href="http://www.akati.com/poc/bl4ck-adobe9-acro-%26-reader-exploit-bindshell5500-2.pdf">exploit here</a> (Please dont use Adobe Acrobat *grin* )</p>
<p>2. Execute it on the victim machine</p>
<p><a href="http://www.flickr.com/photos/95532890@N00/3383645729/"><img src="http://farm4.static.flickr.com/3454/3383645729_ed4bbc26e1.jpg" height="375" width="500" alt="adobe-exploit-JBIG2" /></a></p>
<p>3. Telnet from another machine to the victim machine on port 5500. (Yup ! The exploit binds a shell to port 5500 )</p>
<p><a href="http://www.flickr.com/photos/95532890@N00/3383646175/"><img src="http://farm4.static.flickr.com/3555/3383646175_31b5013dda.jpg" height="375" width="500" alt="shell-5500" /></a></p>
<p>Have fun, folks !</p>
<p><a href="http://bl4cksecurity.blogspot.com/2009/03/adobe-acrobatreader-universal-exploit.html">Read more about how it is done here</a></p>
<img src="http://feeds.feedburner.com/~r/akati/LLyT/~4/NuZyFrdSmcg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.akati.com/warlock/?feed=rss2&amp;p=64</wfw:commentRss>
		<feedburner:origLink>http://www.akati.com/warlock/?p=64</feedburner:origLink></item>
		<item>
		<title>Woman jailed for online scam in Malaysia</title>
		<link>http://feedproxy.google.com/~r/akati/LLyT/~3/8ozSwLhstFc/</link>
		<comments>http://www.akati.com/warlock/?p=63#comments</comments>
		<pubDate>Tue, 24 Mar 2009 14:50:59 +0000</pubDate>
		<dc:creator>warlock</dc:creator>
		
		<category><![CDATA[Forensics]]></category>

		<category><![CDATA[General]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.akati.com/warlock/?p=63</guid>
		<description><![CDATA[Hi Everyone, you know back in Malaysia.. there is a very interesting saying.. &#8220;Malaysia Boleh !&#8221; , which means &#8221; Malaysia Can !&#8221; , the following is an example of how it can be twisted at times..
As i was reading TheStar Online , i came across this interesting *flawed?* article.
It says : Nigerian woman jailed [...]]]></description>
			<content:encoded><![CDATA[<p>Hi Everyone, you know back in Malaysia.. there is a very interesting saying.. &#8220;Malaysia Boleh !&#8221; , which means &#8221; Malaysia Can !&#8221; , the following is an example of how it can be twisted at times..</p>
<p>As i was reading TheStar Online , i came across this interesting *flawed?* article.</p>
<p>It says : <span style="color: #000000; font-family: Arial; font-size: 29px; font-weight: bold; line-height: 36px;">Nigerian woman jailed for online scam</span></p>
<p>Then somewhere in between the article , it says</p>
<p>&#8220;<span style="color: #333333; font-family: Arial; font-size: 14px; line-height: 21px;">Peace Okotie, 26, a business studies student at a private college here, is said to be the first person to be convicted under the Penal Code for such a scam.</span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;"><strong>Okotie from Benin</strong>, who changed her plea to guilty after a witness testified at her trial earlier, was also slapped with four months’ jail for overstaying in Malaysia after her student pass expired on July 22 last year. &#8220;</span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;"><br /></span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;">So, dude, Is she from Benin (purple below) or Nigeria (green below) ? or perhaps they mean the Benin City of Nigeria ? anyway, &#8220;Malaysia Boleh !&#8221;</span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;"><br /></span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;"><a href="http://www.flickr.com/photos/95532890@N00/3382539474/"><img src="http://farm4.static.flickr.com/3463/3382539474_7706f9d642.jpg" height="375" width="500" alt="africa_map" /></a><br /></span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;"><br /></span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;">Now this girl is convicted , Why ? you may ask .. Why then do we still get these types of Email Scams ? Shouldn&#8217;t the authorities go all out to catch all of them ? Or.. Was it , that the victim was an influential person ? One sided Justice, one may say. I say &#8221; Malaysia Boleh ! &#8220;</span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;">Now , here is a tinker , to all of you , namely :</span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;">1. M. Mageswari - The Star Journalist<br />
2. Magistrate Siti Shakirah Mohtarudin<br />
3. DPP Azimul Azami Mohd Nor<br />
4. Buang Md Sayuti - The infamous &#8220;victim&#8221;</span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;">&#8221; Why did the &#8216;innocent&#8217; victim , entertain the e-mail in the first place ? &#8220;</span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;">Some may answer : &#8221; Its your GREED. E-mail scam victims, and victims of GREED. The very thought that you have myteriously, or mistakenly been awarded USD 1 million &#8220;</span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;">I say : Malaysia Boleh !</span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;"><br /></span></p>
<p style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-left: 0px; font-size: 14px; color: #333333; font-family: Arial; margin-bottom: 15px; line-height: 21px;"><span style="color: #000000; font-family: Arial; font-size: 12px;">I think this could make a very good topic for a talkshow.. Hitz, BFM , TV3 , Astro ?</span></p>
<img src="http://feeds.feedburner.com/~r/akati/LLyT/~4/8ozSwLhstFc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.akati.com/warlock/?feed=rss2&amp;p=63</wfw:commentRss>
		<feedburner:origLink>http://www.akati.com/warlock/?p=63</feedburner:origLink></item>
		<item>
		<title>Cisco.com was falsely identified as a Hacking Site !</title>
		<link>http://feedproxy.google.com/~r/akati/LLyT/~3/1u4jgersNqY/</link>
		<comments>http://www.akati.com/warlock/?p=62#comments</comments>
		<pubDate>Sat, 21 Mar 2009 14:06:55 +0000</pubDate>
		<dc:creator>warlock</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.akati.com/warlock/?p=62</guid>
		<description><![CDATA[Here is an interesting read..
Earlier this week, Cisco&#8217;s homepage was briefly classified by Websense as a hacking site.
This bungle happened as a result of their censorware, picking up an IP currently being used by Cisco, which was previously used by a hacking site.
As a result of this, corporate users of Websense&#8217;s web filtering technology were [...]]]></description>
			<content:encoded><![CDATA[<p>Here is an interesting read..</p>
<p>Earlier this week, Cisco&#8217;s homepage was briefly classified by Websense as a hacking site.</p>
<p>This bungle happened as a result of their censorware, picking up an IP currently being used by Cisco, which was previously used by a hacking site.</p>
<p>As a result of this, corporate users of Websense&#8217;s web filtering technology were denied access to Cisco.com for about 15 minutes on Tuesday</p>
<p>The hosting IP of the site http://www.cisco.com/ was flagged for investigation for potential suspicious activity as the IP had formerly been in the hacking category.</p>
<p>After a thorough investigation the site was reviewed and identified safe for browsing within 15 minutes.</p>
<p>While I dont think the 15 minutes outage would have adversely affected Cisco.com traffic or users, however, this is a simple example of how false positives / alarms from security products could affect users.</p>
<p><a href="http://www.flickr.com/photos/95532890@N00/3372917018/"><img src="http://farm4.static.flickr.com/3572/3372917018_53e1620eb5.jpg" height="375" width="500" alt="websense_cisco" /></a></p>
<img src="http://feeds.feedburner.com/~r/akati/LLyT/~4/1u4jgersNqY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.akati.com/warlock/?feed=rss2&amp;p=62</wfw:commentRss>
		<feedburner:origLink>http://www.akati.com/warlock/?p=62</feedburner:origLink></item>
		<item>
		<title>Dumping Physical Memory to extract SAM Hashes</title>
		<link>http://feedproxy.google.com/~r/akati/LLyT/~3/vM91Mp1ueZ4/</link>
		<comments>http://www.akati.com/warlock/?p=61#comments</comments>
		<pubDate>Fri, 20 Mar 2009 12:04:34 +0000</pubDate>
		<dc:creator>warlock</dc:creator>
		
		<category><![CDATA[Forensics]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.akati.com/warlock/?p=61</guid>
		<description><![CDATA[Tools Needed :
MDD
pyCrypto
Volatility 1.3 Beta
Volatility Plugin from Moyix
ManTech Memory DD (MDD) (http://www.mantech.com/msma/MDD.asp) is released under GPL by Mantech International. MDD is capable of copying the complete contents of memory on the following Microsoft Operating Systems: Windows 2000, Windows XP, Windows 2003 Server, Windows 2008 Server.
After downloading MDD from the Mantech site you need to run [...]]]></description>
			<content:encoded><![CDATA[<p>Tools Needed :</p>
<p><a href="http://www.mantech.com/msma/MDD.asp">MDD</a></p>
<p><a href="http://www.voidspace.org.uk/downloads/pycrypto-2.0.1.win32-py2.6.exe">pyCrypto</a></p>
<p><a href="https://www.volatilesystems.com/volatility/1.3/Volatility-1.3_Beta.zip">Volatility 1.3 Beta</a></p>
<p><a href="http://kurtz.cs.wesleyan.edu/%7Ebdolangavitt/memory/volreg-0.2.zip">Volatility Plugin from Moyix</a></p>
<p>ManTech Memory DD (MDD) (http://www.mantech.com/msma/MDD.asp) is released under GPL by Mantech International. MDD is capable of copying the complete contents of memory on the following Microsoft Operating Systems: Windows 2000, Windows XP, Windows 2003 Server, Windows 2008 Server.</p>
<p>After downloading MDD from the Mantech site you need to run the program at the command line.</p>
<p>MDD Command Line Usage:</p>
<p><span style="font-style: italic;">mdd -o OUTPUTFILENAME</span></p>
<p>Step by Step Example :</p>
<p>First of all, run MDD to dump the memory of the machine. The output file , would be an image of the physical memory, and MDD is often used to only dump the memory.</p>
<p><span style="font-style: italic;">C:\Documents and Settings\Administrator\Desktop\MDD&gt;mdd_1.3.exe -o dump.dd</span></p>
<p><span style="font-style: italic;">-&gt; mdd</span></p>
<p><span style="font-style: italic;">-&gt; ManTech Physical Memory Dump Utility</span></p>
<p><span style="font-style: italic;">Copyright (C) 2008 ManTech Security &amp; Mission Assurance</span></p>
<p><span style="font-style: italic;">-&gt; This program comes with ABSOLUTELY NO WARRANTY; for details use option `-w&#8217;</span></p>
<p><span style="font-style: italic;">This is free software, and you are welcome to redistribute it</span></p>
<p><span style="font-style: italic;">under certain conditions; use option `-c&#8217; for details.</span></p>
<p><span style="font-style: italic;">-&gt; Dumping 511.48 MB of physical memory to file &#8216;dump.dd&#8217;.</span></p>
<p><span style="font-style: italic;">130938 map operations succeeded (1.00)</span></p>
<p><span style="font-style: italic;">0 map operations failed</span></p>
<p><span style="font-style: italic;">took 32 seconds to write</span></p>
<p><span style="font-style: italic;">MD5 is: 78924418adaf67d22a6687dcc6ff4e23</span></p>
<p><span style="font-style: italic;">C:\Documents and Settings\Administrator\Desktop\MDD&gt;</span></p>
<p>Next, we will need to analyze the &#8220;memory image&#8221; - dump.dd .</p>
<p>For this, we will be using Using Volatility (1.3_Beta), Volatility Plugin from Moyix, and a Windows Hash/Password Finder (SamInside) to identify the passwords.</p>
<p>1. First of all, most of these scripts are written in python, and as such, you would need to download and install a python interpreter (Active Python ).</p>
<p>2. Download Volatility (1.3_Beta) , extract it to a folder.</p>
<p>3. Download Volatility Plugin from Moyix, extract it, and copy its content into the Volatility folder, overwriting your existing forensics, memory_objects, and memory_plugins folders.</p>
<p>4. Download pyCrypto and install it.</p>
<p>5. Copy the dump.dd file (output file of MDD) into the Volatility folder.</p>
<p>6. Run hivescan from volatility to get the hive offsets. Execute the following:</p>
<p><span style="font-style: italic;">C:\Documents and Settings\Administrator\Desktop\Volatility-1.3_Beta&gt; python volatility hivescan -f dump.dd</span></p>
<p><span style="font-style: italic;">Offset (hex)</span></p>
<p><span style="font-style: italic;">45147992 0&#215;2b0e758</span></p>
<p><span style="font-style: italic;">45393752 0&#215;2b4a758</span></p>
<p><span style="font-style: italic;">49832984 0&#215;2f86418</span></p>
<p><span style="font-style: italic;">56797016 0&#215;362a758</span></p>
<p><span style="font-style: italic;">58091352 0&#215;3766758</span></p>
<p><span style="font-style: italic;">64191328 0&#215;3d37b60</span></p>
<p><span style="font-style: italic;">145440776 0&#215;8ab4008</span></p>
<p><span style="font-style: italic;">146819936 0&#215;8c04b60</span></p>
<p><span style="font-style: italic;">147082080 0&#215;8c44b60</span></p>
<p><span style="font-style: italic;">197245792 0xbc1bb60</span></p>
<p><span style="font-style: italic;">215368912 0xcd644d0</span></p>
<p><span style="font-style: italic;">228964464 0xda5b870</span></p>
<p><span style="font-style: italic;">244838408 0xe97f008</span></p>
<p><span style="font-style: italic;">271077384 0&#215;10285008</span></p>
<p><span style="font-style: italic;">271171592 0&#215;1029c008</span></p>
<p><span style="font-style: italic;">361696096 0&#215;158f0b60</span></p>
<p><span style="font-style: italic;">373147760 0&#215;163dc870</span></p>
<p><span style="font-style: italic;">401433808 0&#215;17ed64d0</span></p>
<p><span style="font-style: italic;">425734152 0&#215;19603008</span></p>
<p><span style="font-style: italic;">435642376 0&#215;19f76008</span></p>
<p><span style="font-style: italic;">452021088 0&#215;1af14b60</span></p>
<p><span style="font-style: italic;">489651040 0&#215;1d2f7b60</span></p>
<p><span style="font-style: italic;">506391392 0&#215;1e2eeb60</span></p>
<p><span style="font-style: italic;">509397104 0&#215;1e5cc870</span></p>
<p><span style="font-style: italic;">526976208 0&#215;1f6904d0</span></p>
<p><span style="font-style: italic;">C:\Documents and Settings\Administrator\Desktop\Volatility-1.3_Beta&gt;</span></p>
<p>7. Next, Run hivelist from volatility with the first hivescan offset, from previous output. Execute the following:</p>
<p><span style="font-style: italic;">C:\Documents and Settings\Administrator\Desktop\Volatility-1.3_Beta&gt;python volatility hivelist -f dump.dd -o 0&#215;2b0e758</span></p>
<p><span style="font-style: italic;">Address Name</span></p>
<p><span style="font-style: italic;">0xe1cda008 \Documents and Settings\Administrator\Local Settings\Application Da</span></p>
<p><span style="font-style: italic;">ta\Microsoft\Windows\UsrClass.dat</span></p>
<p><span style="font-style: italic;">0xe1cc4008 \Documents and Settings\Administrator\NTUSER.DAT</span></p>
<p><span style="font-style: italic;">0xe1afeb60 \Documents and Settings\LocalService\Local Settings\Application Dat</span></p>
<p><span style="font-style: italic;">a\Microsoft\Windows\UsrClass.dat</span></p>
<p><span style="font-style: italic;">0xe1b4c008 \Documents and Settings\LocalService\NTUSER.DAT</span></p>
<p><span style="font-style: italic;">0xe1b13870 \Documents and Settings\NetworkService\Local Settings\Application D</span></p>
<p><span style="font-style: italic;">ata\Microsoft\Windows\UsrClass.dat</span></p>
<p><span style="font-style: italic;">0xe1b004d0 \Documents and Settings\NetworkService\NTUSER.DAT</span></p>
<p><span style="font-style: italic;">0xe1609b60 \WINDOWS\system32\config\software</span></p>
<p><span style="font-style: italic;">0xe160bb60 \WINDOWS\system32\config\default</span></p>
<p><span style="font-style: italic;">0xe1741b60 \WINDOWS\system32\config\SAM</span></p>
<p><span style="font-style: italic;">0xe1607008 \WINDOWS\system32\config\SECURITY</span></p>
<p><span style="font-style: italic;">0xe142e418 [no name]</span></p>
<p><span style="font-style: italic;">0xe1036758 \WINDOWS\system32\config\system</span></p>
<p><span style="font-style: italic;">0xe1022758 [no name]</span></p>
<p><span style="font-style: italic;">C:\Documents and Settings\Administrator\Desktop\Volatility-1.3_Beta&gt;</span></p>
<p>8. Now that we have the address locations, Pay attention to SAM &amp; SYSTEM addresses. Find Password Hash using this command : python volatility hashdump -f dump.dd -y System Hive Offset -s SAM Hive Offset.</p>
<p><span style="font-style: italic;">python volatility hashdump -f dump.dd -y 0xe1036758 -s 0xe1741b60</span></p>
<p>Extracted SAM :</p>
<p><span style="font-style: italic;">Administrator:500:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::</span></p>
<p><span style="font-style: italic;">Guest:501:aad3b435b51404eeaad3b435b51404ee:31d6cfe0d16ae931b73c59d7e0c089c0:::</span></p>
<p><span style="font-style: italic;">HelpAssistant:1000:e342f6782d705142f81cce8f13488846:5cc6a7ed5dce2e04e648b8b6c14c9eed:::</span></p>
<p><span style="font-style: italic;">SUPPORT_388945a0:1002:aad3b435b51404eeaad3b435b51404ee:00fb5891d8488d816968e68a09a868b8:::</span></p>
<p><span style="font-style: italic;">john:1003:972d6bbe1f00e65eaad3b435b51404ee:69bf94898385467264708f3cc51cf0a4:::</span></p>
<p>Now you can just open this as a pwdump file in SamInside and crack it !</p>
<p>Here is how your final output should look like ! Good Luck Guys !</p>
<p><a href="http://www.flickr.com/photos/95532890@N00/3370355082/"><img src="http://farm4.static.flickr.com/3622/3370355082_718e51a6ed.jpg" height="375" width="500" alt="sam-inside" /></a></p>
<img src="http://feeds.feedburner.com/~r/akati/LLyT/~4/vM91Mp1ueZ4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.akati.com/warlock/?feed=rss2&amp;p=61</wfw:commentRss>
		<feedburner:origLink>http://www.akati.com/warlock/?p=61</feedburner:origLink></item>
		<item>
		<title>IE 8 Gold Released !</title>
		<link>http://feedproxy.google.com/~r/akati/LLyT/~3/lqxAGeMeMvw/</link>
		<comments>http://www.akati.com/warlock/?p=60#comments</comments>
		<pubDate>Fri, 20 Mar 2009 00:46:25 +0000</pubDate>
		<dc:creator>warlock</dc:creator>
		
		<category><![CDATA[General]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.akati.com/warlock/?p=60</guid>
		<description><![CDATA[Browsers have arguably become more important than the underlying OS in the modern, connected world.

When the clock strikes 12:00 noon in New York, Microsoft says it&#8217;ll release its much anticipated Internet Explorer 8 software to the world.
So take note when Microsoft announces an update to the Web-dominating software favored by your IT department.
Out of beta, [...]]]></description>
			<content:encoded><![CDATA[<p>Browsers have arguably become more important than the underlying OS in the modern, connected world.</p>
<p><a href="http://www.flickr.com/photos/95532890@N00/3369408132/"><img src="http://farm4.static.flickr.com/3635/3369408132_ce93c061b0_m.jpg" height="240" width="240" alt="internet_explorer" /></a></p>
<p>When the clock strikes 12:00 noon in New York, Microsoft says it&#8217;ll release its much anticipated Internet Explorer 8 software to the world.</p>
<p>So take note when Microsoft announces an update to the Web-dominating software favored by your IT department.</p>
<p>Out of beta, Steve Ballmer claims that IE 8, &#8220;gets people to the information they need, fast, and provides protection that no other browser can match.&#8221;</p>
<p>Time will tell, eh hax0rs? Cansec West was interesting , with all the pwning of browsers going on&#8230; Only time will tell.. Short period of time , that is&#8230; Well, infact it&#8217;s already pwned *grin*</p>
<p><a href="http://www.microsoft.com/windows/internet-explorer/default.aspx">Internet Explorer 8 Homepage</a></p>
<p><a href="http://blogs.zdnet.com/security/?p=2917">CanSec West Pwn2Own Contest</a></p>
<img src="http://feeds.feedburner.com/~r/akati/LLyT/~4/lqxAGeMeMvw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.akati.com/warlock/?feed=rss2&amp;p=60</wfw:commentRss>
		<feedburner:origLink>http://www.akati.com/warlock/?p=60</feedburner:origLink></item>
		<item>
		<title>Natasha Richardson - in Loving Memory, but not by Crackers</title>
		<link>http://feedproxy.google.com/~r/akati/LLyT/~3/n34At7KJ2TA/</link>
		<comments>http://www.akati.com/warlock/?p=59#comments</comments>
		<pubDate>Fri, 20 Mar 2009 00:35:36 +0000</pubDate>
		<dc:creator>warlock</dc:creator>
		
		<category><![CDATA[Exploits]]></category>

		<category><![CDATA[General]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.akati.com/warlock/?p=59</guid>
		<description><![CDATA[Cybercrooks are busy creating malicious webpages and filling them with keywords related to the actress&#8217;s untimely death following a skiing accident earlier this week, according to net security firm Sophos. The ruse, which takes advantage of content scraped from legitimate news websites, is designed to create a high search engine ranking for sites harbouring malicious [...]]]></description>
			<content:encoded><![CDATA[<p>Cybercrooks are busy creating malicious webpages and filling them with keywords related to the actress&#8217;s untimely death following a skiing accident earlier this week, according to net security firm Sophos. The ruse, which takes advantage of content scraped from legitimate news websites, is designed to create a high search engine ranking for sites harbouring malicious code</p>
<p><a href="http://www.flickr.com/photos/95532890@N00/3368566395/"><img src="http://farm4.static.flickr.com/3443/3368566395_f3ec434317_m.jpg" height="150" width="240" alt="PD*4914050" /></a></p>
<p>Users who wind up happening across maliciously constructed websites will be exposed to a malicious script, categorised by Sophos as Reffor-A, designed to alarm users into purchasing a scareware package. Such scareware (fake anti-virus) packages are among the internet&#8217;s fastest growing nuisances. These applications typically attempt to frighten users into thinking their computers are riddled with malware, even if the PC is clean, as a ruse designed to trick people in purchasing ineffective clean-up tools.</p>
<p>Hackers regularly take advantage of breaking news story, often acting in advance of any kind of security response.</p>
<p>Previous situations have been during Benazir Bhutto&#8217;s death, Valentine&#8217;s Day, President Obama&#8217;s Inauguration, and others.</p>
<p>Recently for example, hackers exploited confusion created by the Symantec / PIFTS.EXE incident earlier this month and similar keyword stuffing tactics, to draw surfers towards rogue sites, also punting fake anti-malware scanning software.</p>
<p>Talk about creativity !</p>
<p>
<a href="http://www.sophos.com/blogs/gc/g/2009/03/19/natasha-richardsons-death-exploited">Read more from Sophos Blog</a></p>
<img src="http://feeds.feedburner.com/~r/akati/LLyT/~4/n34At7KJ2TA" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.akati.com/warlock/?feed=rss2&amp;p=59</wfw:commentRss>
		<feedburner:origLink>http://www.akati.com/warlock/?p=59</feedburner:origLink></item>
	</channel>
</rss>
