<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title />
	
	<link>http://www.data0.net</link>
	<description />
	<lastBuildDate>Mon, 09 Jan 2012 00:15:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/data0/feeds" /><feedburner:info uri="data0/feeds" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Root: Samsung Galaxy Tab 8.9 GT-P7300</title>
		<link>http://feedproxy.google.com/~r/data0/feeds/~3/PGIGVpEQNzw/</link>
		<comments>http://www.data0.net/?p=784#comments</comments>
		<pubDate>Tue, 03 Jan 2012 08:57:31 +0000</pubDate>
		<dc:creator>alternator</dc:creator>
				<category><![CDATA[How to ...]]></category>
		<category><![CDATA[Security Tips]]></category>
		<category><![CDATA[Tutorials]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[galaxy]]></category>
		<category><![CDATA[galaxy tab]]></category>
		<category><![CDATA[honeycomb]]></category>
		<category><![CDATA[root]]></category>
		<category><![CDATA[samsung]]></category>

		<guid isPermaLink="false">http://www.data0.net/?p=784</guid>
		<description><![CDATA[Just bought a new Samsung Galaxy Tab 8.9 P7300. Well, there&#8217;s a lot of cool things we can do besides of playing games, social networks, notes, or whatever entertainment. For some of you probably software developer might want more &#8216;fun&#8217; with it. But with factory settings nothing much we can do even you can&#8217;t run a [...]]]></description>
			<content:encoded><![CDATA[<p>Just bought a new Samsung Galaxy Tab 8.9 P7300. Well, there&#8217;s a lot of cool things we can do besides of playing games, social networks, notes, or whatever entertainment. For some of you probably software developer might want more &#8216;fun&#8217; with it. But with factory settings nothing much we can do even you can&#8217;t run a software as simple as phone call apps or access to a little special command on terminal console. So, before we start read the following:</p>
<p><span style="color: #ff9900;"><strong>Warning: Please make sure you have a backup copy of your firmware.</strong></span><br />
<span style="color: #ff9900;"><strong>Warning: Please make sure backup all your important data.</strong></span><br />
<span style="color: #ff9900;"><strong>Warning: Your warranty may get void once doing this process.</strong></span><br />
<span style="color: #ff9900;"><strong>Warning: Recommended to install SuperUser app to get prompt permission when launching an apps with root level.</strong></span><br />
<span style="color: #ff9900;"><strong>Warning: I did on Samsung Galaxy Tab 8.9 P7300 + Android 3.1 (Honeycomb) ONLY. Never try yet on other devices.</strong></span><br />
<strong><span style="color: #3366ff;">Disclaimer: The author of this write-up do not take any responsibilities for any damage causes by this action.</span></strong></p>
<p><span style="text-decoration: underline;">Follow step by step below:</span></p>
<p>1. First of all download this file package first. Download here &gt;&gt; <a href="http://www.data0.net/wp-content/uploads/2012/01/root_2.zip">root_2.zip</a>.</p>
<p>2. Put the root_2.zip into the root directory (No need to extract).</p>
<p><center><a href="http://www.data0.net/wp-content/uploads/2012/01/1n.png"><img class="size-medium wp-image-789 aligncenter" style="border-style: initial; border-color: initial;" title="1n" src="http://www.data0.net/wp-content/uploads/2012/01/1n-300x254.png" alt="" width="300" height="254" /></a></center>3. Turn OFF your device.</p>
<p><center><a href="http://www.data0.net/wp-content/uploads/2012/01/SC20120103-145031b1.jpg"><img class="aligncenter size-full wp-image-788" style="border-style: initial; border-color: initial;" title="SC20120103-145031b1" src="http://www.data0.net/wp-content/uploads/2012/01/SC20120103-145031b1.jpg" alt="" width="573" height="269" /></a></center>4. Then turn ON your device by holding Power and Volume Down button. Repeat this process if you are not successful.</p>
<p><center><a href="http://www.data0.net/wp-content/uploads/2012/01/020120120262.jpg"><img class="aligncenter size-full wp-image-787" style="border-style: initial; border-color: initial;" title="020120120262" src="http://www.data0.net/wp-content/uploads/2012/01/020120120262.jpg" alt="" width="512" height="384" /></a></center>5. If success, you&#8217;ll get two icon on the screen which is Recovery and Download Mode. See picture above.</p>
<p>6. Choose Recovery Mode on your left by pressing Volume Down button then press Volume Up button for confirmation.</p>
<p>7. Choose &#8216;apply update from /sdcard&#8217; by using your volume up/down button. Make sure you choose the &#8216;root_2.zip&#8217; on your root storage. Then press Power button to confirm.</p>
<p><center><a href="http://www.data0.net/wp-content/uploads/2012/01/Recovery-Mode.jpg"><img class="aligncenter size-full wp-image-790" style="border-style: initial; border-color: initial;" title="Recovery-Mode" src="http://www.data0.net/wp-content/uploads/2012/01/Recovery-Mode.jpg" alt="" width="525" height="320" /></a></center>8. You will get &#8216;Install from sdcard complete&#8217; message if successful.</p>
<p>9. Now choose &#8216;reboot system now&#8217; to restart your device. Your device should be rooted now.</p>
<p>10. You can verify whether your device is successful rooted or not by opening Terminal console and type &#8216;su&#8217; and ENTER. Then type &#8216;id&#8217; and ENTER. You&#8217;ll see your user id now is &#8216;root&#8217; as shown in image below.</p>
<p><center><a href="http://www.data0.net/wp-content/uploads/2012/01/SC20120103-155715b.jpg"><img class="aligncenter size-full wp-image-786" style="border-style: initial; border-color: initial;" title="SC20120103-155715b" src="http://www.data0.net/wp-content/uploads/2012/01/SC20120103-155715b.jpg" alt="" width="539" height="158" /></a></center>At this point any software that need a higher access level will be able to install and run as a root privilege. For example VPNC Widget, Samba Filesharing, Superuser and so on. Have a nice day.</p>
<p><span style="text-decoration: underline;"><strong>UPDATE (09/01/2012):</strong></span></p>
<p>Another two devices from a friend of mines which is using Samsung Galaxy Tab 7.0+ and Samsung Galaxy Tab 10.1 seem to be work with those step.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.data0.net/?feed=rss2&amp;p=784</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://www.data0.net/?p=784</feedburner:origLink></item>
		<item>
		<title>Another Chinese Internet Fraudulent (yhoo-it.com)</title>
		<link>http://feedproxy.google.com/~r/data0/feeds/~3/xDsoEO0kbAQ/</link>
		<comments>http://www.data0.net/?p=771#comments</comments>
		<pubDate>Fri, 30 Dec 2011 16:22:14 +0000</pubDate>
		<dc:creator>alternator</dc:creator>
				<category><![CDATA[Analysis]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Security Tips]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[scammer]]></category>

		<guid isPermaLink="false">http://www.data0.net/?p=771</guid>
		<description><![CDATA[While I was watching &#8216;The Pacific&#8217; movie suddenly I just get a Yahoo Messenger popup message from my old friend (which is he&#8217;s already Rest-In-Peace on Aug 2009 ago). This is interesting and kind of surprise for me while seeing my very close friend suddenly &#8216;wake-up&#8217; from his long rest. I was monitoring this scammer about few months [...]]]></description>
			<content:encoded><![CDATA[<p>While I was watching &#8216;The Pacific&#8217; movie suddenly I just get a Yahoo Messenger popup message from my old friend (which is he&#8217;s already Rest-In-Peace on Aug 2009 ago). This is interesting and kind of surprise for me while seeing my very close friend suddenly &#8216;wake-up&#8217; from his long rest. I was monitoring this scammer about few months ago after surprising his online status. Check this out from the chatting using web browser YM:</p>
<p><center><a href="http://www.data0.net/wp-content/uploads/2011/12/15.png"><img class="size-full wp-image-772 aligncenter" title="1" src="http://www.data0.net/wp-content/uploads/2011/12/15.png" alt="" width="600" height="482" /></a></center>From the given shortened URL it will redirect user to the following URL:</p>
<p>http://yhoo-it.com/?id=4ccda25f27843014&#038;s=1&#038;user=matkamil2000</p>
<p>The URL seem to be already expired. But soon it will appeared again. The actual website will appear some kind of offering  money that needs user to input their user name and email.</p>
<p><center><a href="http://www.data0.net/wp-content/uploads/2011/12/2.jpg"><img class="size-full wp-image-773 aligncenter" title="2" src="http://www.data0.net/wp-content/uploads/2011/12/2.jpg" alt="" width="464" height="141" /></a></center>Let&#8217;s take a look closer on the URL. The URL seem to be trying to fool the user that pretend it was coming from Yahoo. Based on whois information the URL was registered from China. Obviously.</p>
<blockquote><p>Registration Service Provided By: Bizcn.com<br />
Website: http://www.bizcn.com<br />
Whois Server: whois.bizcn.com</p>
<p>Domain name: yhoo-it.com</p>
<p>Registrant Contact:<br />
zhang yu<br />
yu zhang sdfgsdfghf@msn.com<br />
0463965823 fax: 0463965823<br />
changhailu12hao<br />
nanning guangxi 230254<br />
cn</p>
<p>Administrative Contact:<br />
yu zhang sdfgsdfghf@msn.com<br />
0463965823 fax: 0463965823<br />
changhailu12hao<br />
nanning guangxi 230254<br />
cn</p>
<p>Technical Contact:<br />
yu zhang sdfgsdfghf@msn.com<br />
0463965823 fax: 0463965823<br />
changhailu12hao<br />
nanning guangxi 230254<br />
cn</p>
<p>Billing Contact:<br />
yu zhang sdfgsdfghf@msn.com<br />
0463965823 fax: 0463965823<br />
changhailu12hao<br />
nanning guangxi 230254<br />
cn</p>
<p>DNS:<br />
ns7.cnmsn.net<br />
ns8.cnmsn.net</p>
<p>Created: 2011-12-04<br />
Expires: 2012-12-04</p></blockquote>
<p>The domain name seem to be newly registered and exactly the time I was start monitoring it. The domain has been pointed to two DNS ns7.cnmsn.net and ns8.cnmsn.net. The DNS server were also registered from China.</p>
<blockquote><p>Registration Service Provided By: Bizcn.com<br />
Website: http://www.bizcn.com<br />
Whois Server: whois.bizcn.com</p>
<p>Domain name: cnmsn.net</p>
<p>Registrant Contact:<br />
XiaMen Longtop Online Technology Co.,Ltd<br />
huiping yi hpyi@longtoponline.com<br />
+865922577888 fax: +865922577111<br />
61, WangHai Road, Longtop Group Building, Xiamen Software Park<br />
xiamen fujian 361008<br />
cn</p>
<p>Administrative Contact:<br />
huiping yi hpyi@longtoponline.com<br />
+865922577888 fax: +865922577111<br />
61, WangHai Road, Longtop Group Building, Xiamen Software Park<br />
xiamen fujian 361008<br />
cn</p>
<p>Technical Contact:<br />
huiping yi hpyi@longtoponline.com<br />
+865922577888 fax: +865922577111<br />
61, WangHai Road, Longtop Group Building, Xiamen Software Park<br />
xiamen fujian 361008<br />
cn</p>
<p>Billing Contact:<br />
huiping yi hpyi@longtoponline.com<br />
+865922577888 fax: +865922577111<br />
61, WangHai Road, Longtop Group Building, Xiamen Software Park<br />
xiamen fujian 361008<br />
cn</p>
<p>DNS:<br />
dns.bizcn.com<br />
dns.cnmsn.net<br />
ns5.cnmsn.net<br />
ns6.cnmsn.net<br />
ns1.4everdns.com<br />
ns2.4everdns.com</p>
<p>Created: 2003-08-08<br />
Expires: 2015-02-27</p></blockquote>
<p>Well, lets dig some more.</p>
<blockquote><p>Nmap scan report for yhoo-it.com (109.230.222.53)<br />
Host is up (0.29s latency).<br />
rDNS record for 109.230.222.53: hosted.by.xsserver.eu<br />
Not shown: 986 closed ports<br />
PORT STATE SERVICE VERSION<br />
25/tcp filtered smtp<br />
80/tcp open http nginx 1.0.4<br />
|_http-title: Site doesn&#8217;t have a title (text/html).<br />
|_http-methods: No Allow or Public header in OPTIONS response (status code 405)<br />
111/tcp open rpcbind 2 (rpc #100000)<br />
135/tcp filtered msrpc<br />
139/tcp filtered netbios-ssn<br />
443/tcp open ssh OpenSSH 5.5p1 Debian 6 (protocol 2.0)<br />
| ssh-hostkey: 1024 6e:96:96:b1:aa:4b:e2:1a:e5:9f:35:9c:6a:79:af:df (DSA)<br />
|_2048 48:bb:c1:d4:bf:08:4d:c6:41:30:ea:57:3e:eb:fe:19 (RSA)<br />
445/tcp filtered microsoft-ds<br />
593/tcp filtered http-rpc-epmap<br />
1026/tcp filtered LSA-or-nterm<br />
1027/tcp filtered IIS<br />
4444/tcp filtered krb524<br />
5432/tcp open postgresql PostgreSQL DB 8.4.1 &#8211; 8.4.4<br />
6129/tcp filtered unknown<br />
6580/tcp open parsec-master?<br />
Device type: general purpose|WAP|router<br />
Running (JUST GUESSING): Linux 2.6.X|2.4.X (95%), Linksys Linux 2.4.X (92%), Netgear embedded (92%), D-Link embedded (92%), Linksys embedded (92%), Peplink embedded (92%)<br />
, Asus Linux 2.6.X (91%)<br />
Aggressive OS guesses: Linux 2.6.23 &#8211; 2.6.33 (95%), Linux 2.6.35 (94%), Linux 2.6.31 (94%), Linux 2.6.32 (94%), Linux 2.6.22 (94%), OpenWrt White Russian 0.9 (Linux 2.4.3<br />
0) (92%), Linux 2.6.18 &#8211; 2.6.27 (92%), Linux 2.6.31 &#8211; 2.6.34 (92%), Linux 2.6.34 (92%), Netgear DG834G WAP (92%)<br />
No exact OS matches for host (test conditions non-ideal).<br />
Network Distance: 9 hops<br />
Service Info: OS: Linux</p>
<p>TRACEROUTE (using port 23/tcp)<br />
HOP RTT ADDRESS<br />
1 12.00 ms 60.53.173.202<br />
2 16.00 ms 60.53.173.213<br />
3 16.00 ms 60.53.173.213<br />
4 228.00 ms 10.55.192.38<br />
5 229.00 ms 10gigabitethernet1-3.core1.lax1.he.net (206.223.123.37)<br />
6 290.00 ms 10gigabitethernet4-3.core1.nyc4.he.net (72.52.92.225)<br />
7 333.00 ms 10gigabitethernet1-2.core1.lon1.he.net (72.52.92.242)<br />
8 399.00 ms 10gigabitethernet4-2.core1.fra1.he.net (184.105.213.146)<br />
9 290.00 ms hosted.by.xsserver.eu (109.230.222.53)</p></blockquote>
<p>Since I don&#8217;t trust any source from China even their web hosting provider, I make some Nmap scanning to seem what its got. The web server seem to be running on Unix machine with several web services port opened.</p>
<p>The Yahoo Messenger online status is coming from the expired phone number which probably has been taken by China scammer that live in Malaysia. Malaysia has multicultural country and it&#8217;s not impossible that a Chinese from China can disguise as Chinese from Malaysia. Another thing is that probably the YM account has been stolen from his machine via malware infection.</p>
<p>More updates coming up soon.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.data0.net/?feed=rss2&amp;p=771</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.data0.net/?p=771</feedburner:origLink></item>
		<item>
		<title>MS Word Document (CVE-2010-3333) Exploit</title>
		<link>http://feedproxy.google.com/~r/data0/feeds/~3/iDdYos3-das/</link>
		<comments>http://www.data0.net/?p=749#comments</comments>
		<pubDate>Mon, 05 Dec 2011 09:48:54 +0000</pubDate>
		<dc:creator>alternator</dc:creator>
				<category><![CDATA[Debugging]]></category>
		<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[CVE-2010-3333]]></category>
		<category><![CDATA[doc exploit]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.data0.net/?p=749</guid>
		<description><![CDATA[A week ago as I checking for the new email and suddenly received an email with MS Word document as an attachment on my inbox (not spam box). This make me curious to know what the heck is that. Lets take a look closer. I rename the MSWord document to &#8216;gigi.doc&#8217;. The .doc file size [...]]]></description>
			<content:encoded><![CDATA[<p>A week ago as I checking for the new email and suddenly received an email with MS Word document as an attachment on my inbox (not spam box). This make me curious to know what the heck is that. Lets take a look closer. I rename the MSWord document to &#8216;gigi.doc&#8217;. The .doc file size is about 160,192 bytes long.</p>
<p>The .doc file contain Rich Text Format (RTF) encoding format and we can see a lot of 0&#215;41 slide until we found the exact shellcode within the slide character. Below show you the location of the exploit code in hex format:</p>
<p style="text-align: center;"><a href="http://www.data0.net/wp-content/uploads/2011/12/21.png"><img class="size-large wp-image-752 aligncenter" title="2" src="http://www.data0.net/wp-content/uploads/2011/12/21-1024x183.png" alt="" width="612" height="141" /></a></p>
<p style="text-align: center;"><a href="http://www.data0.net/wp-content/uploads/2011/12/5.png"><img class="size-full wp-image-756 aligncenter" title="5" src="http://www.data0.net/wp-content/uploads/2011/12/5.png" alt="" width="601" height="195" /></a></p>
<p>As I convert the hex format to binary, we can see some interesting strings. I&#8217;m not sure why its trying to execute ping command to localhost. Well, after execute the malicious .doc file. It will create a file named csrss.exe (921C724CCB04B9F672B294FFFF83CE7B) and execute it then rename it to &#8216;winword.exe&#8217;. Then it will launch the cmd.exe to execute the ping command to 127.0.0.1 with 1 byte. After that, the malware will execute a clean Word.doc file.</p>
<p style="text-align: center;"><a href="http://www.data0.net/wp-content/uploads/2011/12/4.png"><img class="size-full wp-image-755 aligncenter" title="4" src="http://www.data0.net/wp-content/uploads/2011/12/4.png" alt="" width="668" height="307" /></a></p>
<p>The running csrss.exe will create the Update.bat on user StartMenu startup folder with the following content:</p>
<blockquote>
<pre>Echo off
REG ADD "HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows" /v Load /t REG_SZ /d "C:\DOCUME~1\User\LOCALS~1\Temp\csrss.exe" /f
del %%0</pre>
</blockquote>
<p>The batch command file will add a startup into user Windows registry pointing to csrss.exe located in user temporary folder. Then, lets take a look through packet capture:</p>
<p style="text-align: center;"><a href="http://www.data0.net/wp-content/uploads/2011/12/3.png"><img class="size-full wp-image-754 aligncenter" title="3" src="http://www.data0.net/wp-content/uploads/2011/12/3.png" alt="" width="606" height="415" /></a></p>
<p>The captured packet show that the malicious file attempt to POST request to the following URL:</p>
<blockquote><p>http://ymhz1.dyndns.biz:8080/</p>
<p>http://2011fm.dyndns.org:8080/</p>
<p>IP Addess: 114.248.90.120</p></blockquote>
<p>The IP address was originated from China and still active at the time I was writing these. The csrss.exe will keep running on memory and sleep for every 60 second and check back to the given URL.</p>
<p>Note: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3333</p>
]]></content:encoded>
			<wfw:commentRss>http://www.data0.net/?feed=rss2&amp;p=749</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.data0.net/?p=749</feedburner:origLink></item>
		<item>
		<title>W32/Ramnit.C Quick Analysis</title>
		<link>http://feedproxy.google.com/~r/data0/feeds/~3/sbcHCtBfVaw/</link>
		<comments>http://www.data0.net/?p=736#comments</comments>
		<pubDate>Thu, 01 Dec 2011 08:28:44 +0000</pubDate>
		<dc:creator>alternator</dc:creator>
				<category><![CDATA[Debugging]]></category>
		<category><![CDATA[RCE]]></category>
		<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[malware analysis]]></category>
		<category><![CDATA[ramnit]]></category>

		<guid isPermaLink="false">http://www.data0.net/?p=736</guid>
		<description><![CDATA[I just received a laptop from a friend of mine that heavily infected with multiple viruses. I don&#8217;t know how he can comfortably using it for few months until he felt so many annoying activities coming from the viruses. One of my interesting sample to be quickly analyze is W32/Ramnit. Based on few security blogs that I found this [...]]]></description>
			<content:encoded><![CDATA[<p>I just received a laptop from a friend of mine that heavily infected with multiple viruses. I don&#8217;t know how he can comfortably using it for few months until he felt so many annoying activities coming from the viruses. One of my interesting sample to be quickly analyze is W32/Ramnit. Based on few security blogs that I found this malware has been already discovered around April 2010. Let&#8217;s check it out.</p>
<p>At the first detection I was notice that a lot of infections is coming from the HTML files (as Avira detecting so many HTML infection).</p>
<p style="text-align: center;"><a href="http://www.data0.net/wp-content/uploads/2011/12/11.png"><img class="aligncenter size-full wp-image-739" title="1" src="http://www.data0.net/wp-content/uploads/2011/12/11.png" alt="" width="628" height="472" /></a></p>
<p style="text-align: left;">The HTML files contains a small VB Script that carrying embedded EXE files in Hex format that will drop in Windows temporary folder once user opening the infected HTML in their browser (only IE6 support VBScript). At the end of the infected HTML files seem to be a random garbage character in attempt to prevent a static size of HTML files.</p>
<p style="text-align: left;">Once the EXE file has been dropped, it will automatically execute the file. The EXE is about 108,032 bytes sizes (9B49FEC7E03C33277F188A2819B8D726). I&#8217;ll explain quick going through what is the characteristic of the EXE file. The EXE has been compressed with UPX 3.03. Upon execution the following routine will be started:</p>
<ul>
<li>Search for EXE, DLL and  HTML file extensions.</li>
<li>Infect all EXE and DLL by creating additional .text section on the PE file.</li>
<li>Infect HTML files by overwriting it with VBScript and Hexdecimal format of the EXE file.</li>
</ul>
<div>The infected PE file will be create an additional PE sections called .text as shown on image below:</div>
<div><a href="http://www.data0.net/wp-content/uploads/2011/12/2.png"><img class="aligncenter size-full wp-image-741" title="2" src="http://www.data0.net/wp-content/uploads/2011/12/2.png" alt="" width="619" height="432" /></a></div>
<div>A large size of additional .text section (about 540kb) created which is contains a malicious code. The EP has been modify to execute malicous code first and point it back to actual EP to execute original code.</div>
<div>Manual cleaning for this type of malware probably impossible for end-user. Mass infection on users PC make it difficult to remove. The best way to fix it is either using <a title="NOD32 On-Demand Scanner (Portable)" href="http://adf.ly/P7aF" target="_blank">NOD32  On-Demand Scanner (Portable)</a> or format your Hard drive and installing new Windows.</div>
]]></content:encoded>
			<wfw:commentRss>http://www.data0.net/?feed=rss2&amp;p=736</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.data0.net/?p=736</feedburner:origLink></item>
		<item>
		<title>Revoking Trust in DigiCert by Certificate Authority</title>
		<link>http://feedproxy.google.com/~r/data0/feeds/~3/jsWLme-rzs4/</link>
		<comments>http://www.data0.net/?p=730#comments</comments>
		<pubDate>Fri, 04 Nov 2011 04:50:51 +0000</pubDate>
		<dc:creator>alternator</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[revoke]]></category>
		<category><![CDATA[ssl cert]]></category>

		<guid isPermaLink="false">http://www.data0.net/?p=730</guid>
		<description><![CDATA[Just reading news today about revoking most commonly use cert especially in Malaysia. The news is taken from Mozilla Blog. Issue Entrust, Inc., a certificate authority in Mozilla’s root program, has informed us that one of their subordinate CAs, the Malaysian company DigiCert Sdn. Bhd, has issued 22 certificates with weak keys. While there is [...]]]></description>
			<content:encoded><![CDATA[<p>Just reading news today about revoking most commonly use cert especially in Malaysia. The news is taken from Mozilla Blog.</p>
<blockquote><p>Issue</p>
<p>Entrust, Inc., a certificate authority in Mozilla’s root program, has informed us that one of their subordinate CAs, the Malaysian company DigiCert Sdn. Bhd, has issued 22 certificates with weak keys. While there is no indication they were issued fraudulently, the weak keys have allowed the certificates to be compromised. Furthermore, certificates from this CA contain several technical issues. They lack an EKU extension specifying their intended usage and they have been issued without revocation information.</p>
<p>This is not a Firefox-specific issue. Nevertheless, given our concerns about the technical practices of this certificate authority, we intend to revoke trust in the DigiCert Sdn. Bhd. intermediate certificate authority.</p>
<p>DigiCert Sdn. Bhd is a Malaysian subordinate CA under Entrust and Verizon (GTE CyberTrust). It bears no affiliation whatsoever with the US-based corporation DigiCert, Inc., which is a member of Mozilla’s root program.</p>
<p>Impact</p>
<p>An attacker could use one of these weak certificates to impersonate the legitimate owners. This could deceive users into trusting websites or signed software appearing to originate from these owners, but actually containing malicious content or software. The certificates in question were issued to a mix of Malaysian government websites and internal systems. We do not believe other sites are at risk.</p>
<p>Status</p>
<p>Mozilla is revoking trust in all certificates issued by DigiCert Sdn. Bhd. and the update will be in Firefox 8 and Firefox 3.6.24. Entrust has issued their own statement on the subject.</p>
<p>Credit</p>
<p>The issue was reported to us by Entrust, Inc.</p></blockquote>
<p>Source: <a href="http://blog.mozilla.com/security/2011/11/03/revoking-trust-in-digicert-sdn-bhd-intermediate-certificate-authority/">http://blog.mozilla.com/security/2011/11/03/revoking-trust-in-digicert-sdn-bhd-intermediate-certificate-authority/</a></p>
<p>&nbsp;</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.data0.net/?feed=rss2&amp;p=730</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.data0.net/?p=730</feedburner:origLink></item>
		<item>
		<title>New Version of Stuxnet ‘Stars’ Reported</title>
		<link>http://feedproxy.google.com/~r/data0/feeds/~3/6j1FaC9dmQo/</link>
		<comments>http://www.data0.net/?p=711#comments</comments>
		<pubDate>Tue, 26 Apr 2011 03:00:16 +0000</pubDate>
		<dc:creator>alternator</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[new stuxnet]]></category>
		<category><![CDATA[stars]]></category>
		<category><![CDATA[stuxnet]]></category>
		<category><![CDATA[stuxnet v2]]></category>

		<guid isPermaLink="false">http://www.data0.net/?p=711</guid>
		<description><![CDATA[Just read few news today that says new version of stuxnet has been appeared in Iran. At this moment I can&#8217;t find any sample related to the new stuxnet v2 with codenamed &#8216;Stars&#8217;. This news still remain unclear and could be another rumors or just another version of another malware. More update will be available [...]]]></description>
			<content:encoded><![CDATA[<p>Just read few news today that says new version of stuxnet has been appeared in Iran. At this moment I can&#8217;t find any sample related to the new stuxnet v2 with codenamed &#8216;Stars&#8217;. This news still remain unclear and could be another rumors or just another version of another malware. More update will be available soon.</p>
<p><center><br />
<img class="aligncenter" src="http://www.dailyspotlight.net/public/.mann_egan_stuxnet_worm_cnn_640x360_m.jpg" alt="Stuxnet news" /></center></p>
<p>UPDATES (1 MAY 2011):<br />
After being investigated from most resources, I was unable to find the sample and strong news about related story. At this moment, I just consider that it is a hoax.</p>
<p><strong>News related:</strong><br />
<a href="http://www.f-secure.com/weblog/">http://www.f-secure.com/weblog/</a><br />
<a href="http://blogs.csoonline.com/1483/after_stuxnet_a_star_is_born">http://blogs.csoonline.com/1483/after_stuxnet_a_star_is_born</a><br />
<a href="http://www.google.com.my/search?um=1&amp;hl=en&amp;prmdo=1&amp;biw=1138&amp;bih=519&amp;q=%27stars%27%20stuxnet&amp;ie=UTF-8&amp;sa=N&amp;tab=iw">http://www.google.com.my/search?um=1&amp;hl=en&amp;prmdo=1&amp;biw=1138&amp;bih=519&amp;q=%27stars%27%20stuxnet&amp;ie=UTF-8&amp;sa=N&amp;tab=iw</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.data0.net/?feed=rss2&amp;p=711</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.data0.net/?p=711</feedburner:origLink></item>
		<item>
		<title>The 5th annual Counter-eCrime Operations Summit (CeCOS V)</title>
		<link>http://feedproxy.google.com/~r/data0/feeds/~3/v5O6A8iasTs/</link>
		<comments>http://www.data0.net/?p=691#comments</comments>
		<pubDate>Thu, 14 Apr 2011 03:36:09 +0000</pubDate>
		<dc:creator>alternator</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://www.data0.net/?p=691</guid>
		<description><![CDATA[The fifth annual Counter-eCrime Operations Summit (CeCOS V) will engage questions of operational challenges and the development of common resources for the first responders and forensic professionals who protect consumers and enterprises from the ecrime threat every day. This year&#8217;s meeting will focus on the development of response paradigms and resources for counter-ecrime managers and [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">The fifth annual Counter-eCrime Operations Summit (CeCOS V) will engage  questions of operational challenges and the development of common  resources for the first responders and forensic professionals who   protect consumers and enterprises from the ecrime threat every day.   This year&#8217;s meeting will focus on the development of response paradigms  and resources for counter-ecrime managers and forensic professionals.  Presenters will proffer case studies of national and regional economies  under attack, narratives of successful trans-national forensic  cooperation as well as models for cooperation and unified response  against ecrime and data resources for forensic activities.</p>
<p><center><img src="http://www.antiphishing.org/images/kualaLumpurWebBanner.jpg" alt="CeCOS V" /></center></p>
<p style="text-align: justify;">The program will be spread across a three-day conference event on April  27, 28 and 29 in <a href="http://maps.google.com/maps/ms?hl=en&amp;ie=UTF8&amp;msa=0&amp;msid=211354629192232708452.0004994579a6db888dd3c&amp;ll=3.155085,101.710954&amp;spn=0.012041,0.016587&amp;z=16">Kuala Lumpur, Malaysia at the Crown Plaza Hotel</a>. The  APWG believes under-appreciated operational issues are important enough  to be the focus of a conference dedicated exclusively to them. They&#8217;re  often talked about as sidelights but rarely addressed directly as an  organizational imperative for the entire counter-ecrime community. CeCOS  V makes those operational issue the central focus of the program for  the benefit of all ecrime fighters.</p>
<p style="text-align: justify;"><strong><span style="text-decoration: underline;">References:</span></strong></p>
<p style="text-align: justify;"><a href="http://www.antiphishing.org/events/2011_opSummit.html">http://www.antiphishing.org/events/2011_opSummit.html</a></p>
<p style="text-align: justify;">&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.data0.net/?feed=rss2&amp;p=691</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.data0.net/?p=691</feedburner:origLink></item>
		<item>
		<title>Zeus source code leaked</title>
		<link>http://feedproxy.google.com/~r/data0/feeds/~3/GzNNL1S4h9M/</link>
		<comments>http://www.data0.net/?p=679#comments</comments>
		<pubDate>Mon, 04 Apr 2011 23:58:10 +0000</pubDate>
		<dc:creator>alternator</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[source code]]></category>
		<category><![CDATA[spyeye]]></category>
		<category><![CDATA[zeus]]></category>

		<guid isPermaLink="false">http://www.data0.net/?p=679</guid>
		<description><![CDATA[Just read the news today that the Zeus source code has been made public and can be downloaded by anyone. Luckily that the RARed file is password protected and prevent malicious people from using it as the code was written in Visual C++ (probably VC++ 2005 &#8211; 2010) and PHP and easy to  compile it. [...]]]></description>
			<content:encoded><![CDATA[<p>Just read the news today that the Zeus source code has been made public and can be downloaded by anyone. Luckily that the RARed file is password protected and prevent malicious people from using it as the code was written in Visual C++ (probably VC++ 2005 &#8211; 2010) and PHP and easy to  compile it. The source code is already made public around couple of weeks ago and probably sold by the malware author.</p>
<div id="attachment_680" class="wp-caption aligncenter" style="width: 522px"><a href="http://www.data0.net/wp-content/uploads/2011/04/zeus-sc.png"><img class="size-full wp-image-680" title="Zeus Source Code" src="http://www.data0.net/wp-content/uploads/2011/04/zeus-sc.png" alt="" width="512" height="497" /></a><p class="wp-caption-text">Zeus Source Code</p></div>
<p>At the time I was writing this blog, there is no sign that people already crack the password. This could be dangerous once the password is cracked especially when it&#8217;s fall into a wrong hand.</p>
<p>UPDATE &#8211; 06/04/2011</p>
<p>The source code seem to be already posted at r00tw0rm.com which is currently down due to the missing file.</p>
<p><a href="http://www.data0.net/wp-content/uploads/2011/04/zeus-google.png"><img class="aligncenter size-full wp-image-686" title="zeus-google" src="http://www.data0.net/wp-content/uploads/2011/04/zeus-google.png" border="1" alt="" width="661" height="228" /></a></p>
<p>The CMS they are using is probably vBulletin which is contain missing file.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.data0.net/?feed=rss2&amp;p=679</wfw:commentRss>
		<slash:comments>8</slash:comments>
		<feedburner:origLink>http://www.data0.net/?p=679</feedburner:origLink></item>
		<item>
		<title>VERA: Reverse Engineering Malware in Visualize</title>
		<link>http://feedproxy.google.com/~r/data0/feeds/~3/z2TLT5x2Vyw/</link>
		<comments>http://www.data0.net/?p=666#comments</comments>
		<pubDate>Mon, 21 Feb 2011 13:38:12 +0000</pubDate>
		<dc:creator>alternator</dc:creator>
				<category><![CDATA[Debugging]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security Tips]]></category>
		<category><![CDATA[Tools]]></category>

		<guid isPermaLink="false">http://www.data0.net/?p=666</guid>
		<description><![CDATA[VERA is a visualization tool for reverse engineer to produce a nice view and made easy to understand of program behavior. The latest version so far is v0.31 and can be download it from here. Setting up this tools probably a bit complicated if you got no experiences. Just follow the instruction manual and you [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><a href="http://csr.lanl.gov/vera/netbull.png"><img class="aligncenter" title="VERA Demo" src="http://csr.lanl.gov/vera/netbull.png" alt="" width="554" height="180" /></a></p>
<p style="text-align: justify;">VERA is a visualization tool for reverse engineer to produce a nice view and made easy to understand of program behavior. The latest version so far is v0.31 and can be download it from <a href="http://www.offensivecomputing.net/?q=node/1687">here</a>. Setting up this tools probably a bit complicated if you got no experiences. Just follow the instruction manual and you should be fine.</p>
<p><strong>References:</strong></p>
<p><a href="http://www.offensivecomputing.net/?q=node/1687">http://www.offensivecomputing.net/?q=node/1687</a><br />
<a href="http://www.pentestit.com/2010/12/23/update-vera-v03/">http://www.pentestit.com/2010/12/23/update-vera-v03/</a><br />
<a href="http://ether.gtisc.gatech.edu/source.html">http://ether.gtisc.gatech.edu/source.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.data0.net/?feed=rss2&amp;p=666</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.data0.net/?p=666</feedburner:origLink></item>
		<item>
		<title>Decrypt Strings:Geinimi Android Trojan</title>
		<link>http://feedproxy.google.com/~r/data0/feeds/~3/RoUQLUCuGS4/</link>
		<comments>http://www.data0.net/?p=635#comments</comments>
		<pubDate>Thu, 06 Jan 2011 00:41:59 +0000</pubDate>
		<dc:creator>alternator</dc:creator>
				<category><![CDATA[Debugging]]></category>
		<category><![CDATA[Viruses]]></category>

		<guid isPermaLink="false">http://www.data0.net/?p=635</guid>
		<description><![CDATA[Just analyzing an Android trojan couple of days ago and I was able to decrypt the strings inside the binary sample. Here it is a source code written in VB.Net. Imports CryptoSysAPI Module Module1 Sub Main() Dim Hexdata As String = &#34;64656275675F696E7465726E656C0202&#34; ' hex data here! Dim plainHex As String = Des.Pad(Hexdata) plainHex = Des.Decrypt(Hexdata, [...]]]></description>
			<content:encoded><![CDATA[<p>Just analyzing an Android trojan couple of days ago and I was able to decrypt the strings inside the binary sample. Here it is a source code written in VB.Net.</p>

<div class="wp_syntax"><div class="code"><pre class="vb" style="font-family:monospace;">Imports CryptoSysAPI
Module Module1
    <span style="color: #E56717; font-weight: bold;">Sub</span> Main()
        <span style="color: #151B8D; font-weight: bold;">Dim</span> Hexdata <span style="color: #151B8D; font-weight: bold;">As</span> <span style="color: #F660AB; font-weight: bold;">String</span> = <span style="color: #800000;">&quot;64656275675F696E7465726E656C0202&quot;</span> <span style="color: #008000;">' hex data here!
</span>        <span style="color: #151B8D; font-weight: bold;">Dim</span> plainHex <span style="color: #151B8D; font-weight: bold;">As</span> <span style="color: #F660AB; font-weight: bold;">String</span> = Des.Pad(Hexdata)
        plainHex = Des.Decrypt(Hexdata, <span style="color: #800000;">&quot;0102030405060708&quot;</span>, Mode.ECB, <span style="color: #800000;">&quot;&quot;</span>)
        Hexdata = Des.Unpad(plainHex)
        <span style="color: #8D38C9; font-weight: bold;">If</span> Hexdata.Length = plainHex.Length <span style="color: #8D38C9; font-weight: bold;">Then</span> Return
        Console.WriteLine(<span style="color: #800000;">&quot;Input: {0}&quot;</span>, Hexdata);
        Console.WriteLine(<span style="color: #800000;">&quot;Decrypt(DES-ECB): {0}&quot;</span>, Cnv.StringFromHex(Hexdata))
    <span style="color: #8D38C9; font-weight: bold;">End</span> <span style="color: #E56717; font-weight: bold;">Sub</span>
<span style="color: #8D38C9; font-weight: bold;">End</span> Module</pre></div></div>

<p>Example Output:</p>

<div class="wp_syntax"><div class="code"><pre class="batch" style="font-family:monospace;">C:\&gt;&quot;C:\Projects\Krypton\Krypton\bin\Release\Krypton.exe&quot;
Input: 64656275675F696E7465726E656C0202
Decrypt(DES-ECB): debug_internel</pre></div></div>

<p>Note: You need <a href="http://www.cryptosys.net/">CryptoSysAPI</a> library in order to compile this code.</p>
<p>References:<br />
<a href="http://www.alienvault.com/blog/jaime/Malware/Inside_Geinimi_Android_Trojan._Chapter_One_Encrypted_data_and_communication.html">http://www.alienvault.com/blog/jaime/Malware/Inside_Geinimi_Android_Trojan._Chapter_One_Encrypted_data_and_communication.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.data0.net/?feed=rss2&amp;p=635</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.data0.net/?p=635</feedburner:origLink></item>
	</channel>
</rss>

