<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>SecTechno</title>
	
	<link>http://www.sectechno.com</link>
	<description>Information Security Blog</description>
	<lastBuildDate>Wed, 28 Jul 2010 20:51:21 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/Sectechno" /><feedburner:info uri="sectechno" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><creativeCommons:license>http://creativecommons.org/licenses/by-nc-nd/3.0/</creativeCommons:license><image><link>http://creativecommons.org/licenses/by-nc-nd/3.0/</link><url>http://creativecommons.org/images/public/somerights20.gif</url><title>Some Rights Reserved</title></image><feedburner:emailServiceId>Sectechno</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item>
		<title>Security Acts Magazine No.4</title>
		<link>http://feedproxy.google.com/~r/Sectechno/~3/cHOQ0vkJGTc/</link>
		<comments>http://www.sectechno.com/2010/07/28/security-acts-magazine-no-4/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 20:06:13 +0000</pubDate>
		<dc:creator>Mourad Ben Lakhoua</dc:creator>
				<category><![CDATA[Security Magazine]]></category>
		<category><![CDATA[Security Acts]]></category>

		<guid isPermaLink="false">http://www.sectechno.com/?p=2460</guid>
		<description><![CDATA[My Friends I want to share with you this new release of security acts, the Magazine contains a very interesting articles on Information security. Thanks for your follow and continues support. Wish you a happy reading! http://www.securityacts.com/securityacts04.pdf make sure you subscribe to my RSS feed! Security Acts Magazine No.3]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F28%2Fsecurity-acts-magazine-no-4%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F28%2Fsecurity-acts-magazine-no-4%2F&amp;source=Sectechno&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.sectechno.com/wp-content/uploads/2010/07/securityacts04.jpg"><img src="http://www.sectechno.com/wp-content/uploads/2010/07/securityacts04.jpg" alt="" title="securityacts04" width="212" height="300" class="alignleft size-full wp-image-2461" /></a>My Friends I want to share with you this new release of security acts, the Magazine contains a very interesting articles on Information security.</p>
<p>Thanks for your follow and continues support. Wish you a happy reading! </p>
<p> <a href="http://www.securityacts.com/securityacts04.pdf">http://www.securityacts.com/securityacts04.pdf</a></p>
<p><em>make sure you <a href="http://feeds.feedburner.com/Sectechno">subscribe to my RSS feed!<br />
</a></em></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.sectechno.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p><ul class="related_post"><li><a href="http://www.sectechno.com/2010/06/21/security-acts-magazine-no-3/" title="Security Acts Magazine No.3">Security Acts Magazine No.3</a></li></ul><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Sectechno?a=cHOQ0vkJGTc:vf20rDhck0w:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=cHOQ0vkJGTc:vf20rDhck0w:IxlGyXgVFhU"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=cHOQ0vkJGTc:vf20rDhck0w:IxlGyXgVFhU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=cHOQ0vkJGTc:vf20rDhck0w:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=cHOQ0vkJGTc:vf20rDhck0w:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=cHOQ0vkJGTc:vf20rDhck0w:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=cHOQ0vkJGTc:vf20rDhck0w:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=cHOQ0vkJGTc:vf20rDhck0w:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=TzevzKxY174" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=cHOQ0vkJGTc:vf20rDhck0w:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=7Q72WNTAKBA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Sectechno/~4/cHOQ0vkJGTc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.sectechno.com/2010/07/28/security-acts-magazine-no-4/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.sectechno.com/2010/07/28/security-acts-magazine-no-4/</feedburner:origLink></item>
		<item>
		<title>WPA2 Might Be Spoofed!</title>
		<link>http://feedproxy.google.com/~r/Sectechno/~3/ZxsbU1QNwgM/</link>
		<comments>http://www.sectechno.com/2010/07/26/wpa2-might-be-spoofed/#comments</comments>
		<pubDate>Mon, 26 Jul 2010 22:04:35 +0000</pubDate>
		<dc:creator>Mourad Ben Lakhoua</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Privacy & data protection]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Vulnerabilities & attacks]]></category>
		<category><![CDATA[Tech Hacking]]></category>
		<category><![CDATA[Wireless Security]]></category>

		<guid isPermaLink="false">http://www.sectechno.com/?p=2455</guid>
		<description><![CDATA[WPA2 (Wireless Protected Access ver. 2.0) &#8211; is the second version of a set of algorithms and protocols that protect data in wireless networks. As expected, WPA2 should significantly increase the security of wireless networks Wi-Fi compared with previous technologies. The standard provides the mandatory use of more powerful encryption algorithm AES (Advanced Encryption Standard) [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F26%2Fwpa2-might-be-spoofed%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F26%2Fwpa2-might-be-spoofed%2F&amp;source=Sectechno&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.sectechno.com/wp-content/uploads/2009/08/wifi.gif"><img src="http://www.sectechno.com/wp-content/uploads/2009/08/wifi.gif" alt="" title="wifi" width="81" height="60" class="alignleft size-full wp-image-1334" /></a>WPA2 (Wireless Protected Access ver. 2.0) &#8211; is the second version of a set of algorithms and protocols that protect data in wireless networks. As expected, WPA2 should significantly increase the security of wireless networks Wi-Fi compared with previous technologies. The standard provides the mandatory use of more powerful encryption algorithm AES (Advanced Encryption Standard) and authentication of 802.1X. </p>
<p>Panel of researchers reported discovering vulnerability in this protocol while it is widely used as a secure standard for wireless network. AirTight Networks said that this vulnerability concerns networks that match the IEEE802.11 Standard. The first demonstration of this vulnerability will be held in Defcon 18 on this week at Vegas.</p>
<p>Hole 196 is the name of this vulnerability and it uses the Man-in-the-middle method of attack, where the user is authorized in a WiFi network to intercept and decrypt all data transmitted and received by others on the same wireless network. Information that the exploit code will be publicly available, so that everyone can test it and use it, while there will be update by and standardizing bodies have been able to make adjustments in WP2. </p>
<p>Md Sohail Ahmad who will be demonstrating the attack at Defcon says that it took about 10 lines of code in open source MadWiFi driver software, freely available on the Internet, and an off-the-shelf client card for him to spoof the MAC address of the AP, pretending to be the gateway for sending out traffic. Clients who receive the message see the client as the gateway and &#8220;respond with PTKs&#8221;, which are private and which the insider can decrypt.</p>
<p>We will be following this research especially that all Access points are using this protocol and there should be un update available before the demo to fix this vulnerability.</p>
<p><em>make sure you <a href="http://feeds.feedburner.com/Sectechno">subscribe to my RSS feed!<br />
</a></em></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.sectechno.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p><ul class="related_post"><li><a href="http://www.sectechno.com/2010/06/21/security-acts-magazine-no-3/" title="Security Acts Magazine No.3">Security Acts Magazine No.3</a></li><li><a href="http://www.sectechno.com/2009/10/06/mcafee-announce-a-major-initiative-to-fight-cybercrime/" title="McAfee Announces Major Initiative to Fight Cybercrime">McAfee Announces Major Initiative to Fight Cybercrime</a></li><li><a href="http://www.sectechno.com/2009/09/11/securitytubecon-first-online-hacker-conference/" title="SecurityTubeCon: first online Hacker Conference">SecurityTubeCon: first online Hacker Conference</a></li><li><a href="http://www.sectechno.com/2009/08/30/60-seconds-to-crack-wi-fi-encryption/" title="60 seconds to Crack Wi-Fi encryption">60 seconds to Crack Wi-Fi encryption</a></li></ul><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Sectechno?a=ZxsbU1QNwgM:lz0Qw5e47hU:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=ZxsbU1QNwgM:lz0Qw5e47hU:IxlGyXgVFhU"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=ZxsbU1QNwgM:lz0Qw5e47hU:IxlGyXgVFhU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=ZxsbU1QNwgM:lz0Qw5e47hU:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=ZxsbU1QNwgM:lz0Qw5e47hU:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=ZxsbU1QNwgM:lz0Qw5e47hU:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=ZxsbU1QNwgM:lz0Qw5e47hU:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=ZxsbU1QNwgM:lz0Qw5e47hU:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=TzevzKxY174" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=ZxsbU1QNwgM:lz0Qw5e47hU:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=7Q72WNTAKBA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Sectechno/~4/ZxsbU1QNwgM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.sectechno.com/2010/07/26/wpa2-might-be-spoofed/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.sectechno.com/2010/07/26/wpa2-might-be-spoofed/</feedburner:origLink></item>
		<item>
		<title>Hell Pizza’s Customer Database Hacked</title>
		<link>http://feedproxy.google.com/~r/Sectechno/~3/CMQs9qPjZtI/</link>
		<comments>http://www.sectechno.com/2010/07/25/hell-pizzas-customer-database-hacked/#comments</comments>
		<pubDate>Sun, 25 Jul 2010 03:24:49 +0000</pubDate>
		<dc:creator>Mourad Ben Lakhoua</dc:creator>
				<category><![CDATA[Cybercrime & Hacking]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Breaches]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Hell Pizza]]></category>

		<guid isPermaLink="false">http://www.sectechno.com/?p=2447</guid>
		<description><![CDATA[An online database for a Pizza store chain has been compromised this is According risky.biz, there is no credit card numbers but it contains about 400MB of customer’s information. Currently Pizza stores are located in New Zealand, England, Australia and Ireland. Customers information are very important for this case as if a hacker managed to [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F25%2Fhell-pizzas-customer-database-hacked%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F25%2Fhell-pizzas-customer-database-hacked%2F&amp;source=Sectechno&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.sectechno.com/wp-content/uploads/2010/07/hell1.jpg"><img src="http://www.sectechno.com/wp-content/uploads/2010/07/hell1.jpg" alt="" title="hell" width="222" height="100" class="aligncenter size-full wp-image-2449" /></a>An online database for a Pizza store chain has been compromised this is According <a href="http://risky.biz/hell">risky.biz</a>, there is no credit card numbers but it contains about 400MB of customer’s information.</p>
<p>Currently Pizza stores are located in New Zealand, England, Australia and Ireland. Customers information are very important for this case as if a hacker managed to get access to these information (full names, addresses, phone numbers, e-mail addresses, passwords and order history ) the emails/phones can be used to extend the spam list and attack while all records and information can be lost.</p>
<p><em>One source Risky.Biz spoke to says they looked into the security of the website when rumours of the breach started doing the rounds: </p>
<p>Immediately I spotted the SQL Queries being made by the Flash SWF as part of the query string to the server-side. The Flash client makes queries which are hard-coded in the .swf (this is dumb as it means SQL Injection is effectively a &#8216;feature&#8217; of the store).</p>
<p>You could easily alter the query string to show the hashes stored in the MySQL users table. I figured out the version of MySQL was 4.0 (Debian Sarge) &#8211; and the hashes in this version are very weak, cracking them would take less than a couple of hours.</p>
<p>MySQL was listening on a remote port, so one could simply log in remotely and run queries or dump the database slowly so as to not be noticed.</p>
<p>Security researcher and Metasploit creator H D Moore described the security arrangements of the online ordering portal, as described above, as &#8220;about 50 steps of fail&#8221;.</p>
<p>Another penetration tester says the Hell Pizza database is an excellent example of &#8220;non critical&#8221; information<br />
that could still be used by attackers for great benefit.</em></p>
<p>Now the Hell Pizza invited to notify all costumers about the breach so they can take the security measures regarding thier credentials. </p>
<p><em>make sure you <a href="http://feeds.feedburner.com/Sectechno">subscribe to my RSS feed!<br />
</a></em></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.sectechno.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p><ul class="related_post"><li><a href="http://www.sectechno.com/2010/07/23/spreading-ghosts-attacks/" title="Spreading Ghosts Attacks">Spreading Ghosts Attacks</a></li><li><a href="http://www.sectechno.com/2010/07/11/black-hat-usa-2010/" title="Black Hat USA 2010 ">Black Hat USA 2010 </a></li><li><a href="http://www.sectechno.com/2010/06/13/hacking-approach-to-voip-skype/" title="Hacking Approach to VoIP &#038; Skype">Hacking Approach to VoIP &#038; Skype</a></li><li><a href="http://www.sectechno.com/2010/01/01/sniffingmitm-attacks-on-tor-network/" title="Sniffing/MITM Attacks on Tor network">Sniffing/MITM Attacks on Tor network</a></li></ul><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Sectechno?a=CMQs9qPjZtI:ROrH07pmUI0:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=CMQs9qPjZtI:ROrH07pmUI0:IxlGyXgVFhU"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=CMQs9qPjZtI:ROrH07pmUI0:IxlGyXgVFhU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=CMQs9qPjZtI:ROrH07pmUI0:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=CMQs9qPjZtI:ROrH07pmUI0:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=CMQs9qPjZtI:ROrH07pmUI0:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=CMQs9qPjZtI:ROrH07pmUI0:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=CMQs9qPjZtI:ROrH07pmUI0:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=TzevzKxY174" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=CMQs9qPjZtI:ROrH07pmUI0:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=7Q72WNTAKBA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Sectechno/~4/CMQs9qPjZtI" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.sectechno.com/2010/07/25/hell-pizzas-customer-database-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.sectechno.com/2010/07/25/hell-pizzas-customer-database-hacked/</feedburner:origLink></item>
		<item>
		<title>Spreading Ghosts Attacks</title>
		<link>http://feedproxy.google.com/~r/Sectechno/~3/FeuPMowXU3E/</link>
		<comments>http://www.sectechno.com/2010/07/23/spreading-ghosts-attacks/#comments</comments>
		<pubDate>Fri, 23 Jul 2010 20:07:12 +0000</pubDate>
		<dc:creator>Mourad Ben Lakhoua</dc:creator>
				<category><![CDATA[Anti-Viruses]]></category>
		<category><![CDATA[Vulnerabilities & attacks]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Antiviruses]]></category>
		<category><![CDATA[AV failor]]></category>
		<category><![CDATA[USBsploit]]></category>

		<guid isPermaLink="false">http://www.sectechno.com/?p=2436</guid>
		<description><![CDATA[Leonardo Da vinci is widely considered to be one of the greatest painters of all time, and perhaps the most diversely talented person ever to have lived. Leonardo said that there are three types of people that one may encounter: &#8220;Those who see. Those who see when they are shown. Those who do not see.&#8221; [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F23%2Fspreading-ghosts-attacks%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F23%2Fspreading-ghosts-attacks%2F&amp;source=Sectechno&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.sectechno.com/wp-content/uploads/2010/07/ghostglass.jpg"><img src="http://www.sectechno.com/wp-content/uploads/2010/07/ghostglass.jpg" alt="" title="ghost" width="143" height="100" class="alignleft size-full wp-image-2439" /></a>Leonardo Da vinci is widely considered to be one of the greatest painters of all time, and perhaps the most diversely talented person ever to have lived. Leonardo said that there are three types of people that one may encounter: &#8220;Those who see. Those who see when they are shown. Those who do not see.&#8221; </p>
<p>But here I want to add a class of people who see even if they are prevented &#8211; we are talking about the Hacker class.</p>
<p>One of the first things an attacker will do to compromise a remote system is use a Backdoor. I am referring to a ghost &#8211; a piece of software that by running it an attacker can have access to a remote system and collect all activities on the targeted machine.</p>
<p><a href="http://secuobs.com/news/14072010-usbsploit_v0.1b_meterpreter_msf_5.shtml">USBsploit</a> is a tool that is still in beta version and has been created by an Infosec researcher and owner of the popular portal <a href="http://secuobs.com/">Secubs</a>. This tool makes it simple for any person looking to generate Backdoors within a few steps.</p>
<p>First, you need to start with choosing the right distribution, this can be Backtrack/Debian or Ubuntu with the original dependency from Metasploit, than you can follow the clear and easy steps mentioned on the official website.</p>
<p>When you run USBsploit you will find a menu with the list of action you are looking to perform:</p>
<p>1. Create a Backdoor</p>
<p>2. Create a Backdoor and launch a Listener only for the USB Dump attack</p>
<p>3. Launch a Listener for the USB Dump attack from the last Dump configuration file</p>
<p>4. Update the USBsploit Framework</p>
<p>5. Edit the last Dump configuration file (needs vi)</p>
<p>6. Edit the global options (needs vi)</p>
<p>7. Edit the file extensions set to dump (needs vi)</p>
<p>If you choose to create a Backdoor you will be asked to select the IP address of the listener, and by default it will detect local machine IP.</p>
<p>Next you will be asked to select the kind of backdoor you are looking to deploy, depending on victim’s Operating system: </p>
<p>1. Windows Meterpreter Reverse_TCP                                  Spawn a shell on victim and send back to attacker.<br />
2. Windows Meterpreter Reverse_TCP X64                          Connect back to the attacker (Windows x64)<br />
3. Windows Meterpreter Egress Buster                                  Spawn a shell and find a port home via multiple ports</p>
<p>And here an important step you will be choosing the kind of encodings to try and bypass weak Antiviruses.</p>
<p>Select one of the below, Backdoored Executable is typically the best.</p>
<p>1. shikata_ga_nai (Very Good)</p>
<p>2. Multi-Encoder (Excellent)</p>
<p>3. Backdoored Executable (BEST)</p>
<p>After encoding you will find the executable file in &#8220;/opt/usbsploit/lib/msf/data/usbsploitbackdoor.exe&#8221;</p>
<p>This amazing tools helps to create a backdoor that can bypass most popular antiviruses in just a few steps.</p>
<p>My experience was interesting because when testing the generated executable file that had been encoded by msfencode, only 10 out of 42 antiviruses detected it as a Trojan.</p>
<p>(<a href="http://www.virustotal.com/analisis/fd17814e613849ae76d9e571f1af037a555f6f8bfd1ab021fc3854c34b6a4c63-1279835899">http://www.virustotal.com/analisis/fd17814e613849ae76d9e571f1af037a555f6f8bfd1ab021fc3854c34b6a4c63-1279835899</a>). </p>
<p>You can run the .exe file on a windows machine even if it contains one of the Antiviruses that was not able to detect the malicious code, even with the latest definition such as Kaspersky and activate the listener.</p>
<p>Here you will access all activities on the target machine and have total visibility of the whole system.</p>
<p><em>make sure you <a href="http://feeds.feedburner.com/Sectechno">subscribe to my RSS feed!<br />
</a></em></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.sectechno.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p><ul class="related_post"><li><a href="http://www.sectechno.com/2010/07/25/hell-pizzas-customer-database-hacked/" title="Hell Pizza&#8217;s Customer Database Hacked">Hell Pizza&#8217;s Customer Database Hacked</a></li><li><a href="http://www.sectechno.com/2010/07/11/black-hat-usa-2010/" title="Black Hat USA 2010 ">Black Hat USA 2010 </a></li><li><a href="http://www.sectechno.com/2010/06/13/hacking-approach-to-voip-skype/" title="Hacking Approach to VoIP &#038; Skype">Hacking Approach to VoIP &#038; Skype</a></li><li><a href="http://www.sectechno.com/2010/01/01/sniffingmitm-attacks-on-tor-network/" title="Sniffing/MITM Attacks on Tor network">Sniffing/MITM Attacks on Tor network</a></li></ul><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Sectechno?a=FeuPMowXU3E:J2bRyu9mPuk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=FeuPMowXU3E:J2bRyu9mPuk:IxlGyXgVFhU"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=FeuPMowXU3E:J2bRyu9mPuk:IxlGyXgVFhU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=FeuPMowXU3E:J2bRyu9mPuk:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=FeuPMowXU3E:J2bRyu9mPuk:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=FeuPMowXU3E:J2bRyu9mPuk:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=FeuPMowXU3E:J2bRyu9mPuk:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=FeuPMowXU3E:J2bRyu9mPuk:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=TzevzKxY174" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=FeuPMowXU3E:J2bRyu9mPuk:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=7Q72WNTAKBA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Sectechno/~4/FeuPMowXU3E" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.sectechno.com/2010/07/23/spreading-ghosts-attacks/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.sectechno.com/2010/07/23/spreading-ghosts-attacks/</feedburner:origLink></item>
		<item>
		<title>TrueCrypt 7.0 New Release</title>
		<link>http://feedproxy.google.com/~r/Sectechno/~3/m_GzjQIHr5A/</link>
		<comments>http://www.sectechno.com/2010/07/19/truecrypt-7-0-new-release/#comments</comments>
		<pubDate>Mon, 19 Jul 2010 22:00:57 +0000</pubDate>
		<dc:creator>Mourad Ben Lakhoua</dc:creator>
				<category><![CDATA[Encryption]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[hard disk encryption]]></category>
		<category><![CDATA[TrueCrypt]]></category>

		<guid isPermaLink="false">http://www.sectechno.com/?p=2421</guid>
		<description><![CDATA[TrueCrypt one of the popular tools for encrypting and hiding partition under Linux, MacOS and Windows system has released a new version. The new features at this release include: * AES Hardware-accelerated encryption this function is supported by some processors and helps to accelerate encryption performed in a faster way than by purely software implementations [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F19%2Ftruecrypt-7-0-new-release%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F19%2Ftruecrypt-7-0-new-release%2F&amp;source=Sectechno&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.sectechno.com/wp-content/uploads/2009/10/10882-ZGitRDun8705-TrueCrypt.png"><img src="http://www.sectechno.com/wp-content/uploads/2009/10/10882-ZGitRDun8705-TrueCrypt.png" alt="" title="TrueCrypt" width="88" height="88" class="alignleft size-full wp-image-1696" /></a>TrueCrypt one of the popular tools for encrypting and hiding partition under Linux, MacOS and Windows system has released a new version.</p>
<p>The new features at this release include:</p>
<p>* AES Hardware-accelerated encryption this function is supported by some processors and helps to accelerate encryption performed in a faster way than by purely software implementations on the same processors.</p>
<p>* Now it is possible to configure TrueCrypt container on a USB flash drive to mount the drive automatically whenever you insert the USB flash drive into the USB port. This is cool.</p>
<p>* Partition/device-hosted volumes can now be created on drives that use a sector size of 4096, 2048, or 1024 bytes.</p>
<p>*  Favorite Volumes Organizer this means that now you can organize your mounted device upon logon to system as read only or removable medium</p>
<p>* The Favorites menu now contains a list of your non-system favorite volumes. When you select a volume from the list, you are asked for its password (and/or keyfiles) (unless it is cached) and if it is correct, the volume is mounted. </p>
<p>It is always recommended to use Truecrypt instead of other built in encryption system because it can hide your volumes and make it impossible for anyone to note the file existing on the HD, plus it provides a flexible way to choose encryption algorithms.</p>
<p>With TruCrypt your data remains encrypted until you need it. Go get your copy by following <a href="http://www.truecrypt.org/">this link</a>.</p>
<p><em>make sure you <a href="http://feeds.feedburner.com/Sectechno">subscribe to my RSS feed!<br />
</a></em></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.sectechno.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p><ul class="related_post"><li><a href="http://www.sectechno.com/2009/10/23/truecrypt-6-3-free-open-source-disk-encryption-software/" title="TrueCrypt 6.3 Free Open-Source Disk Encryption Software ">TrueCrypt 6.3 Free Open-Source Disk Encryption Software </a></li><li><a href="http://www.sectechno.com/2009/04/21/full-disk-encryption-comes-to-ssds-for-mobile-devices-laptops/" title="Full disk encryption comes to SSDs for mobile devices, laptops">Full disk encryption comes to SSDs for mobile devices, laptops</a></li></ul><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Sectechno?a=m_GzjQIHr5A:eSVVQ_OldFo:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=m_GzjQIHr5A:eSVVQ_OldFo:IxlGyXgVFhU"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=m_GzjQIHr5A:eSVVQ_OldFo:IxlGyXgVFhU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=m_GzjQIHr5A:eSVVQ_OldFo:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=m_GzjQIHr5A:eSVVQ_OldFo:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=m_GzjQIHr5A:eSVVQ_OldFo:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=m_GzjQIHr5A:eSVVQ_OldFo:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=m_GzjQIHr5A:eSVVQ_OldFo:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=TzevzKxY174" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=m_GzjQIHr5A:eSVVQ_OldFo:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=7Q72WNTAKBA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Sectechno/~4/m_GzjQIHr5A" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.sectechno.com/2010/07/19/truecrypt-7-0-new-release/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.sectechno.com/2010/07/19/truecrypt-7-0-new-release/</feedburner:origLink></item>
		<item>
		<title>TRANCHULAS Ethical-Hacking Online Training</title>
		<link>http://feedproxy.google.com/~r/Sectechno/~3/W2nEm42NGkk/</link>
		<comments>http://www.sectechno.com/2010/07/18/tranchulas-ethical-hacking-online-training/#comments</comments>
		<pubDate>Sun, 18 Jul 2010 19:23:57 +0000</pubDate>
		<dc:creator>Mourad Ben Lakhoua</dc:creator>
				<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[Security Training]]></category>
		<category><![CDATA[Ethical Hacking]]></category>
		<category><![CDATA[Online Training Course]]></category>

		<guid isPermaLink="false">http://www.sectechno.com/?p=2414</guid>
		<description><![CDATA[Tranchulas is an international consulting firm that started a new e-learning services launched from Pakistan. Training includes different IT Security topics from: 1- Web Application Security Workshop 2- PCI-Data Security Standard Training 3- Hands-On Ethical Hacking 4-ISO/IEC 27001 &#8211; ISMS Implementation Before attending the training courses a test are conducted to evaluate the knowledge of [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F18%2Ftranchulas-ethical-hacking-online-training%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F18%2Ftranchulas-ethical-hacking-online-training%2F&amp;source=Sectechno&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.sectechno.com/wp-content/uploads/2010/07/TRANCHULAS.png"><img src="http://www.sectechno.com/wp-content/uploads/2010/07/TRANCHULAS.png" alt="" title="TRANCHULAS" width="315" height="33" class="aligncenter size-full wp-image-2417" /></a>Tranchulas is an international consulting firm that started a new e-learning services launched from Pakistan. Training includes different IT Security topics from:</p>
<p>1- Web Application Security Workshop<br />
2- PCI-Data Security Standard Training<br />
3- Hands-On Ethical Hacking<br />
4-ISO/IEC 27001 &#8211; ISMS Implementation</p>
<p>Before attending the training courses a test are conducted to evaluate the knowledge of attendees and according to the result the student will be associated to the required level.<br />
Today I have attended a small demonstration on the Ethical Hacking course .The course teaches advanced techniques on arp spoofing and scanning the network using Backtrack. There is a very nice scenarios that are made on live to help student deeply understand how it is simple to conduct a Man In the middle attack on a real working environment even if the traffic are encrypted using SSL.</p>
<p>Zubair Khan Chief Executive Officer has conducted security trainings at various forums in Pakistan and abroad. He has previously presented at renowned security conferences including Hack.lu Luxembourg, Hack In The Box Malaysia and Infosek Slovenia. Chairman of Pakistan Engineering Development Board and Chairman of Pakistan Engineering Council recognize his research and work. </p>
<p>This is a cutting-edge course and currently outline: Basic Bash Scripting, Information Gathering (Google Hacking and Harvesting, Netcraft, DNS Reconnaissance…), Port scanning, ARP spoofing, Buffer overflow Exploitation ,Bind shells and reverse shells etc..</p>
<p>For more information and details on next trainings you can visit the <a href="http://tranchulas.com/">official website</a>.</p>
<p><em>make sure you <a href="http://feeds.feedburner.com/Sectechno">subscribe to my RSS feed!<br />
</a></em></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.sectechno.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p><ul class="related_post"><li><a href="http://www.sectechno.com/2010/07/12/hacking-lotus-domino/" title="Hacking Lotus Domino">Hacking Lotus Domino</a></li><li><a href="http://www.sectechno.com/2009/09/27/ways-for-effective-network-penetration-testing-and-ethical-hacking/" title="Ways for Effective Network Penetration Testing">Ways for Effective Network Penetration Testing</a></li><li><a href="http://www.sectechno.com/2009/06/22/http-dos-attack-tool-on-apache-web-server/" title="HTTP DoS-attack tool on Apache web server">HTTP DoS-attack tool on Apache web server</a></li><li><a href="http://www.sectechno.com/2009/06/16/phrack-66-is-out/" title="Phrack #66 is out">Phrack #66 is out</a></li></ul><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Sectechno?a=W2nEm42NGkk:iprdRIIohE4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=W2nEm42NGkk:iprdRIIohE4:IxlGyXgVFhU"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=W2nEm42NGkk:iprdRIIohE4:IxlGyXgVFhU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=W2nEm42NGkk:iprdRIIohE4:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=W2nEm42NGkk:iprdRIIohE4:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=W2nEm42NGkk:iprdRIIohE4:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=W2nEm42NGkk:iprdRIIohE4:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=W2nEm42NGkk:iprdRIIohE4:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=TzevzKxY174" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=W2nEm42NGkk:iprdRIIohE4:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=7Q72WNTAKBA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Sectechno/~4/W2nEm42NGkk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.sectechno.com/2010/07/18/tranchulas-ethical-hacking-online-training/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.sectechno.com/2010/07/18/tranchulas-ethical-hacking-online-training/</feedburner:origLink></item>
		<item>
		<title>Mozilla Sniffer Add-on Blocklisted for Security Purposes</title>
		<link>http://feedproxy.google.com/~r/Sectechno/~3/il1Ym2vKqGg/</link>
		<comments>http://www.sectechno.com/2010/07/15/mozilla-sniffer-add-on-blocklisted-for-security-purposes/#comments</comments>
		<pubDate>Thu, 15 Jul 2010 11:05:42 +0000</pubDate>
		<dc:creator>Mourad Ben Lakhoua</dc:creator>
				<category><![CDATA[Browser]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[Vulnerabilities & attacks]]></category>
		<category><![CDATA[Add-on]]></category>
		<category><![CDATA[CoolPreviews]]></category>
		<category><![CDATA[Mozilla]]></category>
		<category><![CDATA[Mozilla Sniffer]]></category>

		<guid isPermaLink="false">http://www.sectechno.com/?p=2409</guid>
		<description><![CDATA[Mozilla has blocklisted a malicious plugin that has been submitted on their official website as an add-on since 6th of June, the add-on named Mozilla Sniffer and contains a serious security vulnerability. According to a blog post the plugin includes a code that intercepts all login data on any website and sends this credential to [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F15%2Fmozilla-sniffer-add-on-blocklisted-for-security-purposes%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F15%2Fmozilla-sniffer-add-on-blocklisted-for-security-purposes%2F&amp;source=Sectechno&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.sectechno.com/wp-content/uploads/2010/06/firefoxlogo.jpg"><img src="http://www.sectechno.com/wp-content/uploads/2010/06/firefoxlogo.jpg" alt="" title="firefoxlogo" width="100" height="100" class="alignleft size-full wp-image-2308" /></a>Mozilla has blocklisted a malicious plugin that has been submitted on their official website as an add-on since 6th of June, the add-on named Mozilla Sniffer and contains a serious security vulnerability. </p>
<p>According to a <a href="http://blog.mozilla.com/addons/2010/07/13/add-on-security-announcement/">blog post</a> the plugin includes a code that intercepts all login data on any website and sends this credential to a remote location. Mozilla security specialists informed that All current users should receive an uninstall notification and invite all users to remove the plugin and change all web authentication credential they are using. </p>
<p>The Plugin code has not been verified as it has been submitted online directly, it was just checked against malware without reviewing the functionality before make it public. While a new method of work will be considered in the future with a purpose to <a href="https://docs.google.com/Doc?docid=0Acwo2Bn17-PrZGZudHRobnJfNzdka3Q2bTdkYw&#038;hl=en">Review Process &#038; Delightful Add-ons</a>.</p>
<p>On the same post security vulnerability in CoolPreviews version 3.0.1 has been reported. This plugin help users in previewing a link in a website by just putting the cursor on it. The Bug allows an attacker to execute a malicious JavaScript code with local privileges, potentially gaining access to the file system and allowing code download and execution.   </p>
<p>Currently, 177,000 users have a vulnerable version installed. All users are invited to update the plugin while the vulnerable versions will be blocklisted soon.</p>
<p><em>make sure you <a href="http://feeds.feedburner.com/Sectechno">subscribe to my RSS feed!<br />
</a></em></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.sectechno.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p><ul class="related_post"><li><a href="http://www.sectechno.com/2010/06/24/mozilla-fixes-9-vulnerabilities-adds-a-crash-protection-to-firefox/" title="Mozilla Fixes 9 vulnerabilities &#038; adds a Crash Protection to Firefox">Mozilla Fixes 9 vulnerabilities &#038; adds a Crash Protection to Firefox</a></li></ul><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Sectechno?a=il1Ym2vKqGg:0ut83WRbrVk:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=il1Ym2vKqGg:0ut83WRbrVk:IxlGyXgVFhU"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=il1Ym2vKqGg:0ut83WRbrVk:IxlGyXgVFhU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=il1Ym2vKqGg:0ut83WRbrVk:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=il1Ym2vKqGg:0ut83WRbrVk:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=il1Ym2vKqGg:0ut83WRbrVk:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=il1Ym2vKqGg:0ut83WRbrVk:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=il1Ym2vKqGg:0ut83WRbrVk:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=TzevzKxY174" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=il1Ym2vKqGg:0ut83WRbrVk:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=7Q72WNTAKBA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Sectechno/~4/il1Ym2vKqGg" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.sectechno.com/2010/07/15/mozilla-sniffer-add-on-blocklisted-for-security-purposes/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.sectechno.com/2010/07/15/mozilla-sniffer-add-on-blocklisted-for-security-purposes/</feedburner:origLink></item>
		<item>
		<title>Zeus baddies unleash nasty new bank Trojan</title>
		<link>http://feedproxy.google.com/~r/Sectechno/~3/D0M_Anc2So0/</link>
		<comments>http://www.sectechno.com/2010/07/14/zeus-baddies-unleash-nasty-new-bank-trojan/#comments</comments>
		<pubDate>Wed, 14 Jul 2010 04:14:27 +0000</pubDate>
		<dc:creator>Mourad Ben Lakhoua</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Cybercrime]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Zeus bot]]></category>

		<guid isPermaLink="false">http://www.sectechno.com/?p=2403</guid>
		<description><![CDATA[Hackers have created a new version of the Zeus crimeware toolkit that&#8217;s designed to swipe bank login details of Spanish, German, UK and US banks. The malware payload, described by CA as Zeus version 3, is far more selective in the banks it targets. Previous versions targeted financial institutions around the world while the latest [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F14%2Fzeus-baddies-unleash-nasty-new-bank-trojan%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F14%2Fzeus-baddies-unleash-nasty-new-bank-trojan%2F&amp;source=Sectechno&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.sectechno.com/wp-content/uploads/2010/07/TheReg.png"><img src="http://www.sectechno.com/wp-content/uploads/2010/07/TheReg.png" alt="" title="TheReg" width="414" height="80" class="aligncenter size-full wp-image-2405" /></a><br />
Hackers have created a new version of the Zeus crimeware toolkit that&#8217;s designed to swipe bank login details of Spanish, German, UK and US banks.</p>
<p>The malware payload, described by CA as Zeus version 3, is far more selective in the banks it targets. Previous versions targeted financial institutions around the world while the latest variant comes in two flavours: one that only target banks in Spain and Germany, and a second that only targets financial institutions in the UK and US.</p>
<p>In addition the latest version of Zeus contains features that makes it far harder for security researchers to figure out what the malware is doing. Zombie drones on the Zeus botnet operate on a need to know basis, CA <a href="http://community.ca.com/blogs/securityadvisor/archive/2010/07/12/zeus-version-3-target-spain-germany-uk-and-usa-banks.aspx">explains</a>.</p>
<p>&#8220;In earlier versions, Zeus handles this configuration file in a way that security researchers can easily manage to reverse engineer and capture the actual full configuration content,&#8221; writes Zarestel Ferrer, a senior research engineer with CA&#8217;s Internet Security Business Unit.</p>
<p>&#8220;This is no longer the case for the latest Zeus bot version 3, which is already in the wild.</p>
<p>&#8220;It employs layers of protection by applying the principle of least privilege. It means that the bot must only access remote command, information and resources that are necessary to a specific function and purpose.&#8221;</p>
<p>Command and control systems associated with the bot are &#8220;mostly hosted in Russia&#8221;, according to CA. Banks in Spain, UK, USA and Germany were the most targeted institutions in previous versions of the banking Trojan.</p>
<p>The unknown cybercrooks have tightened this focus with the latest version of the cybercrime toolkit, meeting customer demand in a manner akin to legitimate software developers releasing localised versions of tools in key geographical markets.</p>
<p>[Source: <a href="http://www.theregister.co.uk/2010/07/13/zeus_goes_local/">The Register</a>]</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.sectechno.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p><ul class="related_post"><li><a href="http://www.sectechno.com/2010/06/27/asprox-is-back/" title="Asprox is back!">Asprox is back!</a></li><li><a href="http://www.sectechno.com/2009/12/12/malware-is-hiding-in-amazon-cloud/" title="Malware is Hiding in Amazon Cloud">Malware is Hiding in Amazon Cloud</a></li><li><a href="http://www.sectechno.com/2009/12/06/guest-blog-defending-against-ddos/" title="Guest Blog: Defending against DDoS">Guest Blog: Defending against DDoS</a></li><li><a href="http://www.sectechno.com/2009/11/02/ddos-attack-target-swedish-police-network/" title="DDoS Attack Target Swedish Police Network">DDoS Attack Target Swedish Police Network</a></li></ul><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Sectechno?a=D0M_Anc2So0:5-iI_lLqAO8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=D0M_Anc2So0:5-iI_lLqAO8:IxlGyXgVFhU"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=D0M_Anc2So0:5-iI_lLqAO8:IxlGyXgVFhU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=D0M_Anc2So0:5-iI_lLqAO8:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=D0M_Anc2So0:5-iI_lLqAO8:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=D0M_Anc2So0:5-iI_lLqAO8:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=D0M_Anc2So0:5-iI_lLqAO8:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=D0M_Anc2So0:5-iI_lLqAO8:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=TzevzKxY174" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=D0M_Anc2So0:5-iI_lLqAO8:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=7Q72WNTAKBA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Sectechno/~4/D0M_Anc2So0" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.sectechno.com/2010/07/14/zeus-baddies-unleash-nasty-new-bank-trojan/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		<feedburner:origLink>http://www.sectechno.com/2010/07/14/zeus-baddies-unleash-nasty-new-bank-trojan/</feedburner:origLink></item>
		<item>
		<title>Hacking Lotus Domino</title>
		<link>http://feedproxy.google.com/~r/Sectechno/~3/jTTHk1BDres/</link>
		<comments>http://www.sectechno.com/2010/07/12/hacking-lotus-domino/#comments</comments>
		<pubDate>Mon, 12 Jul 2010 20:36:10 +0000</pubDate>
		<dc:creator>Mourad Ben Lakhoua</dc:creator>
				<category><![CDATA[Password Security]]></category>
		<category><![CDATA[Pentesting]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Ethical Hacking]]></category>
		<category><![CDATA[Google Hacking]]></category>
		<category><![CDATA[Lotus Domino]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.sectechno.com/?p=2388</guid>
		<description><![CDATA[IBM Lotus Domino Server is a solution for the corporate environment that provides different services to manage electronic documents, and it includes many models such as Mail server, Http server and Data base. The current version is Lotus Domino 8.5.1. To detect the server we start by scanning the network, usually the server runs a [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F12%2Fhacking-lotus-domino%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F12%2Fhacking-lotus-domino%2F&amp;source=Sectechno&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.sectechno.com/wp-content/uploads/2010/07/DOMINO.jpg"><img src="http://www.sectechno.com/wp-content/uploads/2010/07/DOMINO.jpg" alt="" title="DOMINO" width="263" height="151" class="aligncenter size-full wp-image-2392" /></a>IBM Lotus Domino Server is a solution for the corporate environment that provides different services to manage electronic documents, and it includes many models such as Mail server, Http server and Data base. The current version is Lotus Domino 8.5.1.</p>
<p>To detect the server we start by scanning the network, usually the server runs a web interface Lotus Domino httpd, so we run Nmap and scan the targeted network as follows:</p>
<p>Nmap –sV  172.16.1.0.24 –p 80<br />
Nmap scan report for 172.16.1.7<br />
Host is up (0.017s latency).<br />
Not shown: 65533 filtered ports<br />
PORT                    STATE   SERVICE               VERSION<br />
80                           open     http                       Lotus Domino httpd</p>
<p>Now as you can see the IP address of the Domino server is found and you can open your web browser to check some nice Domino web pages with the version: http://serverip/homepage.nsf.  </p>
<p>You can use the Google Hack method to find all web servers running on Domino by searching for inurl:homepage.nsf. In the results you will find thousands of Domino based web pages. Now it is very important to note that you should not attempt training yourself on these sites.</p>
<p>Usually when you install Lotus client you need to connect as a user to the server, and a screen for authentication appears to make non experienced hackers terrified, but if you concentrate and check everything slowly you will find the gaps and admin faults. </p>
<p>First you start by learning the important resources on the server, on Domino most important files are with the .NSF extension, so we have:</p>
<p>/Names.nsf       File in Domino server contains file name and path (Most important database in the Domino environment)</p>
<p>You can find other files using <a href="http://sourceforge.net/projects/dominohunter/">DominoHunter</a> which provides you a list on all .nsf files. But what we need is the names.nsf database which includes all mail addresses, users information, users operating systems, security applications on Lotus notes and other important information. </p>
<p>What is interesting that on most Domino servers this file can be accessed by anonymous users =-).<br />
Now the kind of information that we will need take care of:</p>
<p>1.       List of user’s login so we can guess there passwords also which user account is the admin.</p>
<p>2.       All information can be used in the social engineering to trick non trained personal.</p>
<p>3.       In the names.nsf you will find also OS version as lotus notes client version this will be very helpful to find the 0-days for all users and application and OS. Here an attacker can use even vulnerability in Internet explorer to compromise some accounts. </p>
<p>Gathering information is not all what is possible &#8211; in 2005 there someone discovered a vulnerability allows an attacker to get Internet users password hash. The vulnerability is not difficult to exploit because all users hash passwords are stored in Hidden HTTPPassowrd or dspHTTPPassword files, depending on the version.<br />
What is strange that this vulnerability remains unfixed.</p>
<p>Now the number of users can be hundreds or thousands, so you will need to have all hashes in automatic way. On 2007 an exploit has been released for Dumping Password Hash <a href="http://www.networksecurityarchive.org/html/Exploits-HackingTools/2007-02/msg00053.html">Raptor_dominohash</a> that allows downloading of all users’ hashes.</p>
<p><a href="http://www.securiteinfo.com/outils/DominoHashBreaker.shtml">DominoHashBreaker</a> is also an important tool that tries to find the clear text form of the password by utilizing a dictionary attack. The goal is to make it possible for an administrator to check the robustness of the passwords of its users.</p>
<p>But for the best results, <a href="http://www.openwall.com/john/">John the Ripper with Jumbo patch</a> &#8211; which adds modern password hashes &#8211; and all you need is give HASH.txt to JohnTheRipper (in the form  username:hash). If you find one account password you will be able to know the password policy for all users and will not consume much time to have all passwords list. And these passwords are for Domino web access.</p>
<p>If we have the administrator password account, then its ok, if not we should repeat the previous steps. Something interesting is that the admin password will allow attacker to open  webadmin.nsf (servername/webadmin.nsf) this is for administrating Lotus Domino webserver interface, and by getting access to this resource you can add, remove or modify users.</p>
<p>On domino there is another protocol which is NRPC using port 1352, and this allows users to have client Lotus notes and Lotus designer, and the client should have a certificate to approve his identity with extension ID. There is also a password authentication mechanism.</p>
<p>Passwords are used to decrypt the ID file, so to have access to any Domino account we will need 2 things: an ID file and password for this file. This is more complicated than the Web access but it is always possible. </p>
<p>To get the ID file you can exploit a vulnerability in Lotus Domino where the server keeps a copy of the ID stored on the server, so if you have users login as shown using names.nsf. you will have the ID for the password there is 3 tools that can search for the ID password which is ( ID Password recovery, Lotus Notes Password Recovery or Notes Password Recovery by <a href="http://www.smashingpasswords.com/3-best-lotus-notes-password-recovery-free-softwares">following this link</a> ,all three tools for free.</p>
<p>This post presents a clear idea about the different configuration faults that can exist in a Domino server with a small vulnerability that can allow an outsider to take full control of the server and manipulate a corporation&#8217;s very sensitive information. </p>
<p><em>Reference: <a href="http://dsecrg.com/pages/pub/show.php?id=2">http://dsecrg.com/pages/pub/show.php?id=2</a> </em></p>
<p><em>make sure you <a href="http://feeds.feedburner.com/Sectechno">subscribe to my RSS feed!<br />
</a></em></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.sectechno.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p><ul class="related_post"><li><a href="http://www.sectechno.com/2009/06/22/http-dos-attack-tool-on-apache-web-server/" title="HTTP DoS-attack tool on Apache web server">HTTP DoS-attack tool on Apache web server</a></li><li><a href="http://www.sectechno.com/2009/06/16/phrack-66-is-out/" title="Phrack #66 is out">Phrack #66 is out</a></li><li><a href="http://www.sectechno.com/2009/04/15/qa-johnny-long-%e2%80%93-professional-hacker-pirate-ninja/" title="Q&amp;A: Johnny Long – Professional hacker, Pirate, Ninja">Q&amp;A: Johnny Long – Professional hacker, Pirate, Ninja</a></li><li><a href="http://www.sectechno.com/2009/03/21/hackers-are-making-the-mac-a-first-class-target-for-metasploit-toolkit/" title="Hackers are making the Mac a &#039;first-class target&#039; for Metasploit toolkit">Hackers are making the Mac a &#039;first-class target&#039; for Metasploit toolkit</a></li></ul><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Sectechno?a=jTTHk1BDres:q9xdzZcq7JA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=jTTHk1BDres:q9xdzZcq7JA:IxlGyXgVFhU"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=jTTHk1BDres:q9xdzZcq7JA:IxlGyXgVFhU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=jTTHk1BDres:q9xdzZcq7JA:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=jTTHk1BDres:q9xdzZcq7JA:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=jTTHk1BDres:q9xdzZcq7JA:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=jTTHk1BDres:q9xdzZcq7JA:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=jTTHk1BDres:q9xdzZcq7JA:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=TzevzKxY174" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=jTTHk1BDres:q9xdzZcq7JA:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=7Q72WNTAKBA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Sectechno/~4/jTTHk1BDres" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.sectechno.com/2010/07/12/hacking-lotus-domino/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		<feedburner:origLink>http://www.sectechno.com/2010/07/12/hacking-lotus-domino/</feedburner:origLink></item>
		<item>
		<title>Fake Windows IME Trojan</title>
		<link>http://feedproxy.google.com/~r/Sectechno/~3/9ncfl972HCQ/</link>
		<comments>http://www.sectechno.com/2010/07/11/fake-windows-ime-trojan/#comments</comments>
		<pubDate>Sun, 11 Jul 2010 20:58:20 +0000</pubDate>
		<dc:creator>Mourad Ben Lakhoua</dc:creator>
				<category><![CDATA[Cybercrime & Hacking]]></category>
		<category><![CDATA[Vulnerabilities & attacks]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Malware Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Viruses]]></category>
		<category><![CDATA[Websense]]></category>

		<guid isPermaLink="false">http://www.sectechno.com/?p=2369</guid>
		<description><![CDATA[Security researchers at Websense have discovered a new Trojan that are using a windows system to disable and delete antivirus software and compromising victim machine. The Malicious program installs itself as the Windows input method editor (IME) and then stop all AV processes and delete the executable files and mask itself in the system as [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F11%2Ffake-windows-ime-trojan%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.sectechno.com%2F2010%2F07%2F11%2Ffake-windows-ime-trojan%2F&amp;source=Sectechno&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><a href="http://www.sectechno.com/wp-content/uploads/2010/06/Malware.jpg"><img src="http://www.sectechno.com/wp-content/uploads/2010/06/Malware-150x150.jpg" alt="" title="Malware" width="100" height="100" class="alignleft size-thumbnail wp-image-2269" /></a>Security researchers at Websense have discovered a new Trojan that are using a windows system to disable and delete antivirus software and compromising victim machine.</p>
<p>The Malicious program installs itself as the Windows input method editor (IME) and then stop all AV processes and delete the executable files and mask itself in the system as an antivirus update package.</p>
<p><a href="http://community.websense.com/blogs/securitylabs/archive/2010/07/05/trojan-using-input-method-inject-technology.aspx">Websense has issued a blog post</a> defining the way that this Trojan is able to infect windows system. After running the malware a winnea.ime will be created under the system folder in windows.</p>
<p>By opening the default input method, the previous created file winnea.ime will start to search and detects antiviruses.</p>
<p>At the same time, winnea.ime creates a file called pcij.sys to the system folder and loads it as a driver process.</p>
<p>Next DeviceIOControl kills the running process of any antivirus in the list; the control code is sent to the driver process pcij.sys</p>
<p>As it is clear that the input method in Windows is now a popular way for hackers to inject malicious code.</p>
<p><em>make sure you <a href="http://feeds.feedburner.com/Sectechno">subscribe to my RSS feed!<br />
</a></em></p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://www.sectechno.com/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p><ul class="related_post"><li><a href="http://www.sectechno.com/2010/03/07/building-your-own-malware-lab-part-2/" title="Building your OWN Malware Lab (Part 2)">Building your OWN Malware Lab (Part 2)</a></li><li><a href="http://www.sectechno.com/2010/02/27/building-your-own-malware-lab-part-1/" title="Building your OWN Malware Lab (Part 1)">Building your OWN Malware Lab (Part 1)</a></li><li><a href="http://www.sectechno.com/2009/05/14/zombies-an-increasing-concern/" title="Zombies an Increasing Concern">Zombies an Increasing Concern</a></li><li><a href="http://www.sectechno.com/2009/03/26/conficker-c-overview/" title="Conficker.C Overview">Conficker.C Overview</a></li></ul><div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/Sectechno?a=9ncfl972HCQ:VKMtWAhUX2k:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=9ncfl972HCQ:VKMtWAhUX2k:IxlGyXgVFhU"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=9ncfl972HCQ:VKMtWAhUX2k:IxlGyXgVFhU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=9ncfl972HCQ:VKMtWAhUX2k:dnMXMwOfBR0"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=dnMXMwOfBR0" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=9ncfl972HCQ:VKMtWAhUX2k:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=9ncfl972HCQ:VKMtWAhUX2k:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/Sectechno?i=9ncfl972HCQ:VKMtWAhUX2k:gIN9vFwOqvQ" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=9ncfl972HCQ:VKMtWAhUX2k:TzevzKxY174"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=TzevzKxY174" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/Sectechno?a=9ncfl972HCQ:VKMtWAhUX2k:7Q72WNTAKBA"><img src="http://feeds.feedburner.com/~ff/Sectechno?d=7Q72WNTAKBA" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/Sectechno/~4/9ncfl972HCQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.sectechno.com/2010/07/11/fake-windows-ime-trojan/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://www.sectechno.com/2010/07/11/fake-windows-ime-trojan/</feedburner:origLink></item>
	</channel>
</rss>
