<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-26689187</id><updated>2011-12-28T03:50:14.155-08:00</updated><category term='massive malware push'/><category term='lindsay Lohan exploit'/><category term='dangerous searches'/><category term='zenturi exploit'/><category term='two attack waves italy'/><category term='good spyware installs rootkit'/><category term='arthur c clarke dies space.com hacked'/><category term='feta hacked neosploit bbc'/><category term='mpack webattacker'/><category term='webattacker mpack'/><category term='Neosploit caListCtrl computer associates'/><category term='storm neosploit'/><category term='blount county neosploit'/><category term='monster exploit'/><category term='google adwords driveby downloads'/><category term='iframers st petersburg rustock rootkit'/><category term='alicia keys hack myspace'/><category term='storm'/><category term='g-pack'/><category term='boise hacked'/><category term='lure'/><category term='malwarealarm avg social engineering'/><category term='russian attack exploits'/><category term='rootkits'/><category term='snoop dog beyonce'/><category term='storm gom'/><category term='malicious website exploit'/><category term='mlb.com nhl.com fake scans exploits'/><category term='uc0810 CA MDAC'/><category term='gpack'/><category term='funny support'/><category term='storm botnet'/><category term='0-day baofeng storm'/><category term='0-day'/><category term='k1 martial arts exploit'/><category term='saints defamed st kilda'/><category term='korean antivirus'/><category term='david tarloff fake codec'/><category term='hacked .gov websites'/><category term='neosploit jukebox activevoice'/><category term='bank of india hack'/><category term='lures'/><category term='hacked gov websites'/><category term='innocent searches'/><category term='grisoft linkscanner'/><category term='transient web site hack linkscanner avg'/><category term='warren county hacked'/><category term='smarttrack bbb exploit'/><category term='edus porn exploits'/><category term='bank of india exploit'/><category term='winzip exploit'/><category term='storm superbuddy'/><category term='exploit'/><category term='dangerous searchers'/><category term='bait and switch'/><category term='aol hacked'/><title type='text'>Exploit Prevention Labs</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default?start-index=101&amp;max-results=100'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>142</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-26689187.post-82569452527935326</id><published>2008-09-01T06:45:00.000-07:00</published><updated>2008-09-01T06:49:42.684-07:00</updated><title type='text'>New blog</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;please visit and bookmark my new blog at &lt;a href="http://thompson.blog.avg.com/"&gt;http://thompson.blog.avg.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-82569452527935326?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/82569452527935326/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=82569452527935326' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/82569452527935326'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/82569452527935326'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/09/new-blog.html' title='New blog'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-6923455960536396056</id><published>2008-05-27T11:59:00.000-07:00</published><updated>2008-05-27T12:10:49.214-07:00</updated><title type='text'>Riddle us this, Batman</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Normally, we provide answers here, but today we have a question.&lt;br /&gt;&lt;br /&gt;If you whois xpantivirus2008.com, it shows that the registrar is ESTDOMAINS (the actual owner is hidden, as usual).&lt;br /&gt;&lt;br /&gt;If you look up the IP address of xpantivirus2008.com, it shows as 72.14.207.99.&lt;br /&gt;&lt;br /&gt;If you whois 72.14.207.99, _that_ shows as GOOGLE!&lt;br /&gt;&lt;br /&gt;The question is .... why? All we can think of is that they have a sense of humor.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-6923455960536396056?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/6923455960536396056/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=6923455960536396056' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6923455960536396056'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6923455960536396056'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/05/riddle-us-this-batman.html' title='Riddle us this, Batman'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-773252425129881554</id><published>2008-05-16T04:44:00.000-07:00</published><updated>2008-12-08T16:20:00.090-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='aol hacked'/><title type='text'>Here's a whoopsie to start the day</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;One of the rolling headlines on AOL.com this morning is this ...&lt;br /&gt;&lt;br /&gt;"Disgraced 'Oprah' Author Is Back",&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_loJ1Rw68BvQ/SC126kgTScI/AAAAAAAAAEE/aDU7yVWr9JU/s1600-h/AOL+main+page.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_loJ1Rw68BvQ/SC126kgTScI/AAAAAAAAAEE/aDU7yVWr9JU/s400/AOL+main+page.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5200943893286439362" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt; and if you click on the link, you're taken to this page...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_loJ1Rw68BvQ/SC13D0gTSdI/AAAAAAAAAEM/eeU2NcSaPT8/s1600-h/AOL+fake+codec.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_loJ1Rw68BvQ/SC13D0gTSdI/AAAAAAAAAEM/eeU2NcSaPT8/s400/AOL+fake+codec.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5200944052200229330" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Attentive readers of this blog will immediately recognize that as being a probable fake codec, but not everyone is an attentive reader of this blog, and if you click the link, you're rewarded with this screen...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_loJ1Rw68BvQ/SC14ekgTSeI/AAAAAAAAAEU/ES_BffwcL-g/s1600-h/result.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_loJ1Rw68BvQ/SC14ekgTSeI/AAAAAAAAAEU/ES_BffwcL-g/s400/result.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5200945611273357794" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Folks, the rule is this ... if ever you have to install a codec to watch a vid, DON'T!!!. It's just not worth the risk. Btw, these guys frequently target MAC users too. It's increasingly common for them to look at your OS platform and offer up a MAC binary instead of Windows.&lt;br /&gt;&lt;br /&gt;Btw, I know that AOL takes security &lt;em&gt;seriously&lt;/em&gt;, so if they can get caught, anyone can get caught with this trick. &lt;br /&gt;&lt;br /&gt;And shout-outs to Bruce for noticing this one.&lt;br /&gt;&lt;br /&gt;Keep safe folks!&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-773252425129881554?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/773252425129881554/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=773252425129881554' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/773252425129881554'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/773252425129881554'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/05/heres-whoopsie-to-start-day.html' title='Here&apos;s a whoopsie to start the day'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_loJ1Rw68BvQ/SC126kgTScI/AAAAAAAAAEE/aDU7yVWr9JU/s72-c/AOL+main+page.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5904207484429494409</id><published>2008-03-31T12:32:00.000-07:00</published><updated>2008-12-08T16:20:00.679-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='boise hacked'/><title type='text'>Well, there goes the Montana option</title><content type='html'>or at least the Idaho variant. &lt;br /&gt;&lt;br /&gt;Hi folks,&lt;br /&gt;&lt;br /&gt;One of our in-house jokes is that the only real way to be safe on the Internet is to sell all your computers and move to Montana.&lt;br /&gt;&lt;br /&gt;Regretably, today we noticed that the innocent and bucolic sounding boise.com was showing up as carrying a link to a known exploit site.&lt;br /&gt;&lt;br /&gt;Thinking it couldn't possibly be so, we went to look at the website thusly...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_loJ1Rw68BvQ/R_E-sKYiimI/AAAAAAAAADc/zIdfNDKcIrg/s1600-h/boise+main+page.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_loJ1Rw68BvQ/R_E-sKYiimI/AAAAAAAAADc/zIdfNDKcIrg/s400/boise+main+page.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5183993574502599266" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Looks innocent enough, but a view of the source reveals a chunk of escaped javascript ...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_loJ1Rw68BvQ/R_E_7KYiinI/AAAAAAAAADk/TB7w3Irr8LE/s1600-h/source.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_loJ1Rw68BvQ/R_E_7KYiinI/AAAAAAAAADk/TB7w3Irr8LE/s400/source.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5183994931712264818" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Aha! That looks suspicious.... And a look at our debug tool shows a call out to a gpack exploit site...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_loJ1Rw68BvQ/R_FAQKYiioI/AAAAAAAAADs/opxFlrPyW_o/s1600-h/bho.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_loJ1Rw68BvQ/R_FAQKYiioI/AAAAAAAAADs/opxFlrPyW_o/s400/bho.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5183995292489517698" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The web cams are actually pretty interesting, but we can't find any way to contact the site owner to tell him, so we thought we'd post it here.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5904207484429494409?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5904207484429494409/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5904207484429494409' title='10 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5904207484429494409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5904207484429494409'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/03/well-there-goes-montana-option.html' title='Well, there goes the Montana option'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_loJ1Rw68BvQ/R_E-sKYiimI/AAAAAAAAADc/zIdfNDKcIrg/s72-c/boise+main+page.jpg' height='72' width='72'/><thr:total>10</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-3135865697745583173</id><published>2008-03-30T18:30:00.000-07:00</published><updated>2008-12-08T16:20:01.398-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='good spyware installs rootkit'/><title type='text'>This might be the ultimate irony</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Today we found what might be the ultimate irony... a spyware product where the home page has been hacked, and is installing someone else's rootkit!&lt;br /&gt;&lt;br /&gt;The product is one of those spy-on-your-spouse/kids/employees things that says it's stealthy (in other words, _it's_ supposed to be a rootkit itself), and the home page has a chunk of escaped javascript &lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R_BEmqYiikI/AAAAAAAAADM/BUGQ9Kp3TKg/s1600-h/escaped+code.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R_BEmqYiikI/AAAAAAAAADM/BUGQ9Kp3TKg/s400/escaped+code.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5183718602106374722" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;that calls out to a Neosploit site that's installing a rootkit. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_loJ1Rw68BvQ/R_BELKYiijI/AAAAAAAAADE/2Uv9d1reXwM/s1600-h/rootkit.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_loJ1Rw68BvQ/R_BELKYiijI/AAAAAAAAADE/2Uv9d1reXwM/s400/rootkit.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5183718129659972146" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;And it's the new Neosploit too.&lt;br /&gt;&lt;br /&gt;We're trying to contact the site owner to tell them, but the "contact me" page crashes.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_loJ1Rw68BvQ/R_BFEKYiilI/AAAAAAAAADU/tHQXKwVP_uk/s1600-h/email+submit.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_loJ1Rw68BvQ/R_BFEKYiilI/AAAAAAAAADU/tHQXKwVP_uk/s400/email+submit.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5183719108912515666" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Oh well... we'll keep trying.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-3135865697745583173?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/3135865697745583173/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=3135865697745583173' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3135865697745583173'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3135865697745583173'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/03/this-might-be-ultimate-irony.html' title='This might be the ultimate irony'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_loJ1Rw68BvQ/R_BEmqYiikI/AAAAAAAAADM/BUGQ9Kp3TKg/s72-c/escaped+code.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5892325859292276694</id><published>2008-03-28T15:25:00.000-07:00</published><updated>2008-03-28T17:50:26.872-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='gpack'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><category scheme='http://www.blogger.com/atom/ns#' term='g-pack'/><title type='text'>GPack</title><content type='html'>Correction: Sorry folks... there's so much happening at the moment, I've merged a couple of kits in my mind. It's not a mix of vbscript and javascript. It's just javascript, and thus far, we've only seen one exploit come out of it ... a mouldy, old MS06-014, although we expect there are more than that. The rest of the write-up is reasonably accurate, and we'll continue to correct things as we find more.&lt;br /&gt;&lt;br /&gt;Hi folks,&lt;br /&gt;&lt;br /&gt;A new exploit framework, called Gpack, has been popping up on our radar for a while now. We couldn't find much information on it, so we thought we'd better write some.&lt;br /&gt;&lt;br /&gt;The first interesting thing about it is that the external, obfuscated wrapping script is a mix of vbscript and javascript. In other words, some of it is interpretted by the vbscript engine, and then the result of that is used to interpret the javascript portion. The idea here is to make it hard to decrypt and hard for av engines to follow it. To some extent they're successful with this, as the un-obfuscated code is seriously ugly and hard to follow.&lt;br /&gt;&lt;br /&gt;The second interesting point is that there is nothing new in it. They've gone to a lot of trouble to obfuscate some really old and common exploits.&lt;br /&gt;&lt;br /&gt;The third interesting thing is the number of innocent websites that have been hacked by someone pointing back at this kit. There are lots and lots of them... mostly mom and pop shops, but _lots_. We haven't figured out what the common thread between them is so far, but there clearly is one, for so many to be hacked.&lt;br /&gt;&lt;br /&gt;The fourth interesting thing is that while there is clearly more than one set of Bad Guys involved, most of them seem to being hosted by the same ISP, because the exploit IPs are similar.&lt;br /&gt;&lt;br /&gt;By the way, the exploit set seems to be:&lt;br /&gt;&lt;br /&gt;MDAC/ MS06-014&lt;br /&gt;MDAC variant - MS06-042&lt;br /&gt;QuickTime&lt;br /&gt;SetSlice&lt;br /&gt;WinZip&lt;br /&gt;VML&lt;br /&gt;&lt;br /&gt;These are very common, and we can assume the author simply lifted them from the public domain, and put most of his effort into the obfuscation.&lt;br /&gt;&lt;br /&gt;Nothing new here folks, except that it's being quite widely adopted.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5892325859292276694?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5892325859292276694/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5892325859292276694' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5892325859292276694'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5892325859292276694'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/03/gpack.html' title='GPack'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-954760105618177759</id><published>2008-03-28T09:59:00.000-07:00</published><updated>2008-03-28T15:54:38.769-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Neosploit caListCtrl computer associates'/><title type='text'>New Exploit Targets Corporate Users of CA Apps</title><content type='html'>Update: We should note that CA has offered a patch for this vulnerability. What is not clear is how widely adopted that patch is.&lt;br /&gt;&lt;br /&gt;Hi folks,&lt;br /&gt;&lt;br /&gt;On about March 17, 2008, some folks, such as frsirt started talking about a vulnerability in dll/ ocx used in various CA products. See here http://www.frsirt.com/english/advisories/2008/0902 , for example. &lt;br /&gt;&lt;br /&gt;Today we found it in the wild, in none other than a new NeoSploit framework.&lt;br /&gt;&lt;br /&gt;This means several things...&lt;br /&gt;&lt;br /&gt;Firstly, the Neo developers are _very_ active.&lt;br /&gt;&lt;br /&gt;Secondly, the vulnerability is likely to be quite widespread, simply because of CA's size and spread within the corporate market.&lt;br /&gt;&lt;br /&gt;Thirdly, the exploit will likely soon also be quite widespread, simply because it is Neo, and Neo is quite popular as an exploit package.&lt;br /&gt;&lt;br /&gt;Fourthly, corporate clients should probably be pretty nervous, because their firewall is unlikely to protect them against this. Remember, web traffic is usually permitted to go right thru the firewall, because it _starts_ from a trusted place ... _inside_ the firewall. &lt;br /&gt;&lt;br /&gt;Another contributing factor to corporate nervousness is that they rarely allow automatic patching. This is an example where they probably should.&lt;br /&gt;&lt;br /&gt;The current list of exploits is therefore:-&lt;br /&gt;&lt;br /&gt;Mdac/ MS06-014&lt;br /&gt;SuperBuddy&lt;br /&gt;CaListCtrl&lt;br /&gt;NctAudio&lt;br /&gt;GomWebCtrl&lt;br /&gt;SetSlice&lt;br /&gt;DaxCtle&lt;br /&gt;&lt;br /&gt;In other words, they've added the CaListCtrl exploit, and dropped the Yahoo Jukebox and Microsoft xVoice exploits, presuambly because they were not productive.&lt;br /&gt;&lt;br /&gt;Folks, this appears to be one for the corporates rather than consumers, but it highlights that the Bad Guys are still thinking hard and probing hard.&lt;br /&gt;&lt;br /&gt;Natuarally, LinkScanner and AVG 8 users have little to fear, as we detect it and block it just fine (which is how we noticed it in the first place)&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-954760105618177759?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/954760105618177759/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=954760105618177759' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/954760105618177759'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/954760105618177759'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/03/oooo-that-was-pretty-quick.html' title='New Exploit Targets Corporate Users of CA Apps'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5226242406116742650</id><published>2008-03-23T18:24:00.000-07:00</published><updated>2008-12-08T16:20:01.797-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='arthur c clarke dies space.com hacked'/><title type='text'>Arthur C Clark dies, and Space.com gets hacked!</title><content type='html'>Can't you see the pattern emerging??&lt;br /&gt;&lt;br /&gt;Seriously though, uplink.space.com (careful) has had an iframe injected into it, and it's reaching out to another seemingly hacked site (www.forvideo.at - careful), &lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_loJ1Rw68BvQ/R-cNPKYiihI/AAAAAAAAAC0/VUQ8r09ZhgM/s1600-h/iframe.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_loJ1Rw68BvQ/R-cNPKYiihI/AAAAAAAAAC0/VUQ8r09ZhgM/s400/iframe.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5181124450449525266" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;and launching a encrypted javascript &lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_loJ1Rw68BvQ/R-cNvaYiiiI/AAAAAAAAAC8/jtmZGGzzXk8/s1600-h/exploit.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_loJ1Rw68BvQ/R-cNvaYiiiI/AAAAAAAAAC8/jtmZGGzzXk8/s400/exploit.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5181125004500306466" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;that turns out to be a simple and venerable MS06-014 exploit. &lt;br /&gt;&lt;br /&gt;It's not an exploit pack, so it's just a single exploit, and it's tracking IPs, so it'll only come once, but it's there.&lt;br /&gt;&lt;br /&gt;And the exploit is only an MS06-014, but the point is that if the website is vulnerable enough to have a mouldie old exploit injected, it could have something much newer and fiercer. Space.com needs to fix their website, and we've sent them an email about it. Hopefully they will, because they get an awful lot of visitors each month.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5226242406116742650?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5226242406116742650/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5226242406116742650' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5226242406116742650'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5226242406116742650'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/03/arthur-c-clark-dies-and-spacecom-gets.html' title='Arthur C Clark dies, and Space.com gets hacked!'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_loJ1Rw68BvQ/R-cNPKYiihI/AAAAAAAAAC0/VUQ8r09ZhgM/s72-c/iframe.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5997007989437461307</id><published>2008-03-20T17:17:00.000-07:00</published><updated>2008-03-20T19:00:35.516-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='zenturi exploit'/><title type='text'>Something new tonight</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Tonight we found something new in an exploit pack coming from a site in China. Well, the exploit is actually from May 2007, but this is the first time we've seen it in use. This indicates two things... the first is that the Bad Guys are apparently combing older exploit announcements looking for appropriate samples. When you think about it, any exploit that allows remote code execution, and for which there is no forced or automatic upgrade of the vulnerable program is useful to them. Remember, they don't _want_ to catch everybody. They couldn't manage 100k victims. They don't want to cut down the apple tree, but rather just shake it, and pick up the fruit that falls off. What this means is that old exploits are still valuable when there is no automatic patch mechanism.&lt;br /&gt;&lt;br /&gt;Btw, the exploit in question is a buffer overflow in something called Zenturi ProgramChecker, and is described nicely here ... http://www.kb.cert.org/vuls/id/603529.&lt;br /&gt;&lt;br /&gt;The second interesting thing is that it is obviously Yet Another Exploit Pack. It has all the common ones that we've come to love and expect with Mpack/IcePack/Neosploit, and the obfuscation scheme is very similar to the one in use with Mpack/ IcePack, so this probably means that someone has bought or stolen a copy of Mpack/ IcePack, and has modified it with the addition of the Zenturi exploit, and is now selling it as their own work. &lt;br /&gt;&lt;br /&gt;GASP... no, there's no honor among thieves, and Copyright means when you copy it, it'll be right, and all that stuff.&lt;br /&gt;&lt;br /&gt;The full list of exploits is ...&lt;br /&gt;&lt;br /&gt;Zenturi ProgramChecker&lt;br /&gt;MDAC/MS06-014&lt;br /&gt;VML/MS07-004&lt;br /&gt;Yahoo Webcam Image Uploader&lt;br /&gt;Yahoo Webcam Viewer&lt;br /&gt;Winzip&lt;br /&gt;QuickTime&lt;br /&gt;and&lt;br /&gt;MSXML/MS06-067&lt;br /&gt;&lt;br /&gt;By the way, the exploit site is in China (no surprise there), but the lure site is in the USA, and is quite interesting. We might write about that tomorrow.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5997007989437461307?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5997007989437461307/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5997007989437461307' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5997007989437461307'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5997007989437461307'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/03/something-new-tonight.html' title='Something new tonight'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5712025619155775635</id><published>2008-03-13T13:50:00.000-07:00</published><updated>2008-12-08T16:20:02.166-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='blount county neosploit'/><title type='text'>Unfortunate hack at tax time</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;We noticed a couple of Alabama county websites have been hacked, with a Neosploit call out to a website in Germany.&lt;br /&gt;&lt;br /&gt;The two websites are...&lt;br /&gt;&lt;br /&gt;hxxp://www.co.blount.al.us/  and &lt;br /&gt;hxxp://www.blountrevenue.com/&lt;br /&gt;&lt;br /&gt;(The actual exploit server in Germany seems to be 404 at the moment, but you should still be careful)&lt;br /&gt;&lt;br /&gt;The second one is more interesting, particularly given the time of year. The front page looks like this ... &lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R9ma04UghNI/AAAAAAAAACs/ilqkBXsHabo/s1600-h/Revenue_main.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R9ma04UghNI/AAAAAAAAACs/ilqkBXsHabo/s400/Revenue_main.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5177339479901373650" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Looks pretty innocent, doesn't it? If you're good at html, and you make a point of looking at page source, you might notice something weird at the top of the page ...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R9mZa4UghLI/AAAAAAAAACc/-8edyEPXwpU/s1600-h/Revenue_sce.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R9mZa4UghLI/AAAAAAAAACc/-8edyEPXwpU/s400/Revenue_sce.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5177337933713147058" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;but you probably won't, because no one looks at source much anyway. ;-) &lt;br /&gt;&lt;br /&gt;If you have a Really Useful Tool (tm) like our Browser Helper Object, you'll probably notice that it's reaching out to a funny looking site ...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_loJ1Rw68BvQ/R9maiIUghMI/AAAAAAAAACk/l9IMsFn-P8w/s1600-h/Revenue_bho1.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_loJ1Rw68BvQ/R9maiIUghMI/AAAAAAAAACk/l9IMsFn-P8w/s400/Revenue_bho1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5177339157778826434" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;That's because the funny looking javascript s actually a Neosploit obfuscation that decrypts to a call to an attack script at 78.47.147.188. This site is currently 404, but it might come back to life at any time, so be careful.&lt;br /&gt;&lt;br /&gt;We've told the very nice folks at the revenue website, so it should be cleaned up soon. It's just a particularly unfortunate website to be hacked at tax time.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5712025619155775635?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5712025619155775635/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5712025619155775635' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5712025619155775635'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5712025619155775635'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/03/unfortunate-hack-at-tax-time.html' title='Unfortunate hack at tax time'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_loJ1Rw68BvQ/R9ma04UghNI/AAAAAAAAACs/ilqkBXsHabo/s72-c/Revenue_main.jpg' height='72' width='72'/><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-1319911620982241268</id><published>2008-03-02T11:20:00.000-08:00</published><updated>2008-03-02T11:23:45.456-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='korean antivirus'/><title type='text'>Something interesting</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;hat-tip to Ståle Fagerland of Norman for noticing this article...&lt;br /&gt;&lt;br /&gt;http://joongangdaily.joins.com/article/view.asp?aid=2886846&lt;br /&gt;&lt;br /&gt;To save you _having_ to read it, the story is about a CEO of a Korean software company being arrested for foisting fake anti-spy software on unsuspecting victims. (entering sarcasm mode) Gosh, who`d have thought it? (leaving sarcasm mode) Apparently, not only would the software lie about detecting problems on the system, and try really hard to get victims to pony up a payment to register the software, sometimes it made the victims re-buy the software every month!&lt;br /&gt;&lt;br /&gt;Now, arresting theses guys is not a bad idea in itself, but that`s not the most interesting aspect of the story. In fact,if the article is correct, there are two stunning revelations.  &lt;br /&gt;&lt;br /&gt;The first is that they made $10m doing this over two or three years!!! Another couple of years at that rate, and before you know it, you`re talking real money. No wonder we see so much of this stuff!&lt;br /&gt;&lt;br /&gt;The second astonishing thing is that, according to the article, there are over 200 anti virus companies in Korea! If that is correct, that is simply amazing for an industry that`s 20 years old!&lt;br /&gt;&lt;br /&gt;That would seem to indicate...&lt;br /&gt;&lt;br /&gt;(1) that the US and European companies have not dominated and rationalized the market there, and &lt;br /&gt;(2) none of the local companies have managed to dominate either.&lt;br /&gt;&lt;br /&gt;It must also mean that there`s an awful lot of av guys not making much money, so it`s not entirely surprising that people are tempted to initiate frauds like this.&lt;br /&gt;&lt;br /&gt;And if there are that many in Korea, how many must there be in China!?&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-1319911620982241268?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/1319911620982241268/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=1319911620982241268' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/1319911620982241268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/1319911620982241268'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/03/something-interesting.html' title='Something interesting'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-4988349878844246349</id><published>2008-02-25T14:09:00.000-08:00</published><updated>2008-12-08T16:20:02.306-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='saints defamed st kilda'/><title type='text'>google defames saints ... bolts of lightning fall</title><content type='html'>I'm kidding, I'm kidding!!!!!!!&lt;br /&gt;&lt;br /&gt;Update number 2: Feb 26, 2008, 6:30am est&lt;br /&gt;&lt;br /&gt;Dang, that was quick. Some of the sites, such as St Kilda, and the Geelong Cats sites, are now correctly marked as clean. They're not all correct though ... the Brisbane Lions site is still incorrectly marked as dangerous, for example, but that was still quick for the others, and we hope that all will shortly be corrected. Shout-outs to google for reacting quickly!&lt;br /&gt;&lt;br /&gt;Update number 1:&lt;br /&gt;&lt;br /&gt;Some of our team in the Australian office noticed that it wasn't just the Saints, but also the Victorian based clubs of North Melbourne Kangaroos, Carlton Blues, Geelong Cats, Hawthorn Hawks, Melbourne Demons and Richmond Tigers, plus Port Adelaide Power (South Australia), Sydney Swans (New South Wales) and Brisbane Lions (Queensland) all being blocked by Google the same way. Shout-outs to the guys down-unda!&lt;br /&gt;&lt;br /&gt;-----------------------------------------------------------------&lt;br /&gt;&lt;br /&gt;Hi folks,&lt;br /&gt;&lt;br /&gt;What I'm really talking about is that if you search for "saints football club", the number 3 organic search result is the famous (to Australians) St Kilda Football club. The "defamation" bit is that google has one of its "This site may harm your computer" messages against it.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_loJ1Rw68BvQ/R8NHMnQec_I/AAAAAAAAACE/VlbhqYe-hbk/s1600-h/google+search.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_loJ1Rw68BvQ/R8NHMnQec_I/AAAAAAAAACE/VlbhqYe-hbk/s400/google+search.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5171055079173551090" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;(If you look at the screen snapshot, you'll notice that LinkScanner assesses the site to be clean... the correct result)&lt;br /&gt;&lt;br /&gt;This means that it is not possible for anyone to click thru a google search and get to the St Kilda website... you have to deliberately cut and paste the url back into your browser bar.&lt;br /&gt;&lt;br /&gt;The reason that they're doing it is that, probably, at some point the website was hacked, and was infecting people, but ....GOOGLE-GUYS!!! IT'S CLEAN NOW!!! TAKE THE BLOCK OFF, PLEASE!!! (I feel like saying "Mr Google! Tear down this wall!", but I wouldn't be so bold.)&lt;br /&gt;&lt;br /&gt;What this really underscores is the concept that a centralized database is useless at detecting web issues... the problem is simply too transient.&lt;br /&gt;&lt;br /&gt;This happens quite a bit, and I must admit that I'm surprised that no one has accused google of damaging their brand. I'm sure regular readers of my blog will remember the case of k1-usa.net. They used to be the number one organic result when people searched for k1. They were hacked for about 10 days, and then cleaned, but in the mean time, they had earned the "This site maye harm your computer label", and over the next 12 months, before the label was removed, their rating slipped, and slipped, until finally it was nowhere on the first three pages.&lt;br /&gt;&lt;br /&gt;I can't imagine St Kilda taking it lying down if their ratings start to slip, and I can't imagine google meaning that to happen. It just shows how difficult it is to keep up.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-4988349878844246349?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/4988349878844246349/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=4988349878844246349' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4988349878844246349'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4988349878844246349'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/02/google-defames-saints-bolts-of.html' title='google defames saints ... bolts of lightning fall'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_loJ1Rw68BvQ/R8NHMnQec_I/AAAAAAAAACE/VlbhqYe-hbk/s72-c/google+search.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-6585275566968176891</id><published>2008-02-22T08:24:00.000-08:00</published><updated>2008-12-08T16:20:02.985-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='warren county hacked'/><title type='text'>Another gov site hacked</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Who can see what's wrong with this picture?&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R773zHQec7I/AAAAAAAAABk/GYCzn86zM5k/s1600-h/mainpage.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R773zHQec7I/AAAAAAAAABk/GYCzn86zM5k/s400/mainpage.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5169841879761449906" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Looks pretty reasonable, doesn't it? Here's what you see if you have a suitable monitoring tool...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_loJ1Rw68BvQ/R774OXQec8I/AAAAAAAAABs/aAwC0bPadQI/s1600-h/bho.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_loJ1Rw68BvQ/R774OXQec8I/AAAAAAAAABs/aAwC0bPadQI/s400/bho.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5169842347912885186" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Enquiring Minds will wonder why a county government site is reaching out to pepato.org.&lt;br /&gt;&lt;br /&gt;And here's what you see on a vulnerable pc, _if_ you're running another suitable monitoring tool...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R774-HQec9I/AAAAAAAAAB0/iEqrM19ngow/s1600-h/crit+files.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R774-HQec9I/AAAAAAAAAB0/iEqrM19ngow/s400/crit+files.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5169843168251638738" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;And here's the offending code in the page source ...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://1.bp.blogspot.com/_loJ1Rw68BvQ/R775QnQec-I/AAAAAAAAAB8/OR0OEbkq4tY/s1600-h/dodgy+script.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_loJ1Rw68BvQ/R775QnQec-I/AAAAAAAAAB8/OR0OEbkq4tY/s400/dodgy+script.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5169843486079218658" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Yes, it's hacked. Bit hard to tell without some tools, though, eh? We've told the county, so we expect it'll get cleaned up very quickly, but be careful in the mean time.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-6585275566968176891?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/6585275566968176891/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=6585275566968176891' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6585275566968176891'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6585275566968176891'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/02/another-gov-site-hacked.html' title='Another gov site hacked'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_loJ1Rw68BvQ/R773zHQec7I/AAAAAAAAABk/GYCzn86zM5k/s72-c/mainpage.jpg' height='72' width='72'/><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-8707516482445163958</id><published>2008-02-21T19:55:00.000-08:00</published><updated>2008-12-08T16:20:03.084-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='funny support'/><title type='text'>This is kind of funny</title><content type='html'>Hi folks, &lt;br /&gt;&lt;br /&gt;We've been following up on the new Neosploit that we reported last night. This was actually a pretty high-profile site, so we wanted to notify them. We couldn't find a contact point on the hacked domain, but we found another subdomain that had an online support chat option, and we gave it a try. The conversation was sufficiently funny that we grabbed a screen capture (anonymized to protect the innocent). You might have to double-click it to read it, but it's worthwhile...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_loJ1Rw68BvQ/R77XxXQec6I/AAAAAAAAABc/CuUuP-qnQoo/s1600-h/support_chat2_modified.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_loJ1Rw68BvQ/R77XxXQec6I/AAAAAAAAABc/CuUuP-qnQoo/s400/support_chat2_modified.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5169806665324589986" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;:-)&lt;br /&gt;&lt;br /&gt;Fwiw, we eventually found someone who understood, and we got it cleaned up.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-8707516482445163958?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/8707516482445163958/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=8707516482445163958' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8707516482445163958'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8707516482445163958'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/02/this-is-kind-of-funny.html' title='This is kind of funny'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_loJ1Rw68BvQ/R77XxXQec6I/AAAAAAAAABc/CuUuP-qnQoo/s72-c/support_chat2_modified.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-3208430718998738320</id><published>2008-02-20T08:46:00.000-08:00</published><updated>2008-02-20T15:03:33.104-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='neosploit jukebox activevoice'/><title type='text'>New Neo Now</title><content type='html'>(Sorry... the alliteration bug bit me)&lt;br /&gt;&lt;br /&gt;Hi folks,&lt;br /&gt;&lt;br /&gt;Last night, as the title suggests, we found a new version of Neosploit. It has two new exploits, one uses a clsid of EEE78591-FE22-11D0-8BEF-0060081841DE, which appears to be the ActiveVoice ActiveX dll from Microsoft, and the other clsid is 5F810AFC-BB5F-4416-BE63-E01DD117BD6C, which is the Music Jukebox control from Yahoo.&lt;br /&gt;&lt;br /&gt;The most recent ActiveVoice exploit seems to be from about June 2007, but the most recent JukeBox exploit is from Feb 2008, so that's kind of interesting.&lt;br /&gt;&lt;br /&gt;We'll try to figure out over the next couple of days if these are the ones that indeed match up, but the bottom line is that the Neosploit developers are very active.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-3208430718998738320?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/3208430718998738320/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=3208430718998738320' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3208430718998738320'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3208430718998738320'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/02/new-neo-now.html' title='New Neo Now'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-900061939934862562</id><published>2008-02-16T19:30:00.000-08:00</published><updated>2008-12-08T16:20:03.490-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='david tarloff fake codec'/><title type='text'>Wow... this was quick</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;I'm sure most people know about the horrific attack on the poor NYC psych. In the news tonight, we noticed that the police had arrested someone named David Tarloff for allegedly being the perp. With the web being what it is, we often find that if you look quickly, you can find personal pages about these people, often before the police get them taken down. Ok, it's a little morbid, but it's interesting at the same time.&lt;br /&gt;&lt;br /&gt;So, when we googled for David Tarloff, here was the result...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R7erm3Qec0I/AAAAAAAAAAs/Cft_dp-8RWY/s1600-h/bait.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R7erm3Qec0I/AAAAAAAAAAs/Cft_dp-8RWY/s400/bait.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5167787781587366722" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Hmmm... an AOL journal account... that sounds plausible for a personal page... click...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R7esK3Qec1I/AAAAAAAAAA0/ktzBwgqz12o/s1600-h/and.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R7esK3Qec1I/AAAAAAAAAA0/ktzBwgqz12o/s400/and.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5167788400062657362" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Yep ... still looks plausible ... let's click the name ... click...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R7esY3Qec2I/AAAAAAAAAA8/SyL6ZmSHvPU/s1600-h/switch.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R7esY3Qec2I/AAAAAAAAAA8/SyL6ZmSHvPU/s400/switch.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5167788640580825954" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;WAAAAIT A MINUTE!!!!! That ain't no Hank William's song! (Pop culture reference to Bob, of Bob's Country Bunker in the Blues Brothers, where Bob suddenly realizes that that the boys aren't really a country and western band, and that he's been had.)&lt;br /&gt;&lt;br /&gt;Attentive readers will instantly notice that this is a Fake Codec, and will close the browser. Non-attentive readers will attempt to install the codec, and will be rewarded with a rootkit.&lt;br /&gt;&lt;br /&gt;But how quick was that? We only noticed that the guy had been arrested and named today, and yet they not only managed to get their lure in place on AOL, but they also managed to get their site the Number One organic result on Google if you search for David Tarloff! And on the weekend at that! These boys are on the ball. We're grudgingly impressed.&lt;br /&gt;&lt;br /&gt;Be careful folks, it's a tricky world out there.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-900061939934862562?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/900061939934862562/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=900061939934862562' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/900061939934862562'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/900061939934862562'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/02/wow-this-was-quick.html' title='Wow... this was quick'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_loJ1Rw68BvQ/R7erm3Qec0I/AAAAAAAAAAs/Cft_dp-8RWY/s72-c/bait.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-286455227667747372</id><published>2008-02-07T14:35:00.000-08:00</published><updated>2008-02-07T14:37:40.303-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malwarealarm avg social engineering'/><title type='text'>MalwareAlarm</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;MalwareAlarm is so common now, we decided to give it it's own vid. Remember, it's not really scanning your pc, it's just pretending to, but it does a very good job of pretending. Enjoy...&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="350"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Zct4TwA3M8Y"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/Zct4TwA3M8Y" type="application/x-shockwave-flash" width="425" height="350"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-286455227667747372?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/286455227667747372/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=286455227667747372' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/286455227667747372'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/286455227667747372'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/02/malwarealarm.html' title='MalwareAlarm'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-1769203558967700937</id><published>2008-02-06T05:39:00.000-08:00</published><updated>2008-12-08T16:20:03.734-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='feta hacked neosploit bbc'/><title type='text'>UK .gov site hacked</title><content type='html'>Note: One of our users, John Thomson (no relation as far as I know :-) ) noticed this first and brought it to our attention. His blog entry is here ...&lt;br /&gt;http://www.roundtripsolutions.com/blog/2008/02/06/317/forth-road-bridge-website-hacked/&lt;br /&gt;&lt;br /&gt;Sorry John! :-) &lt;br /&gt;&lt;br /&gt;Hi folks,&lt;br /&gt;&lt;br /&gt;Sometime between the 1st Feb 2008, and the 3rd of Feb 2008, the official website for the Forth Estuary Transport Authority was hacked an obfuscated iframe, using Neosploit encoding, was injected.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_loJ1Rw68BvQ/R6nD0Ha25hI/AAAAAAAAAAc/HuzAmVgb8Yo/s1600-h/neo+in+main.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_loJ1Rw68BvQ/R6nD0Ha25hI/AAAAAAAAAAc/HuzAmVgb8Yo/s400/neo+in+main.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5163873747869296146" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This decoded to an iframe that called to 88.255.90.130 (careful about going there, folks)...&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R6nE1Xa25iI/AAAAAAAAAAk/AeJBq6Mz8CU/s1600-h/neo+decrypted.jpg"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://3.bp.blogspot.com/_loJ1Rw68BvQ/R6nE1Xa25iI/AAAAAAAAAAk/AeJBq6Mz8CU/s400/neo+decrypted.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5163874868855760418" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This, in turn, loaded one of the current Neosploit exploit package (we have a full write-up on Neo a little further down this blog). If you're patched, or running LinkScanner, you're ok, but if not, you probably got a rootkit, so if you visited that website in the last couple of days, you might like to run an anti-root and an anti virus over your system. AVG has a free one here ... http://free.grisoft.com .&lt;br /&gt;&lt;br /&gt;One of the most interesting aspects of this is that inside the full Neosploit download was an attempt to load bbc.com.uk , presuamably after the infection, presumably to hide what had happened a little bit. That's no big deal in itself, but a hacked uk gov website, pointing to the bbc afterwards makes us think it was not a random hack, but something more deliberate. Interesting times, folks.&lt;br /&gt;&lt;br /&gt;Looks like they cleaned the site this morning, although the google cache is still infective, so be careful.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-1769203558967700937?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/1769203558967700937/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=1769203558967700937' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/1769203558967700937'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/1769203558967700937'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/02/uk-gov-site-hacked.html' title='UK .gov site hacked'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_loJ1Rw68BvQ/R6nD0Ha25hI/AAAAAAAAAAc/HuzAmVgb8Yo/s72-c/neo+in+main.jpg' height='72' width='72'/><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-7264149536211561881</id><published>2008-02-02T14:11:00.000-08:00</published><updated>2008-02-02T14:20:21.863-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='innocent searches'/><title type='text'>Return of Innocent Searches</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;I keep getting requests offline for more innocent searches, so here are some from the last couple of days. Enjoy...&lt;br /&gt;&lt;br /&gt;coal furnace with gas insert - fake codec&lt;br /&gt;road trip - neosploit&lt;br /&gt;pearl shop - neosploit&lt;br /&gt;high capacity battery pack - fake codec/ rootkit&lt;br /&gt;eyelashes + adhesive - fake codec&lt;br /&gt;camping turon gate - fake codec&lt;br /&gt;greenville gremlins - fake codec&lt;br /&gt;blueberry jam - mpack/ icepack&lt;br /&gt;school closings in illinois parents - search engine hijack&lt;br /&gt;las vegas wedding photographers - mdac &lt;br /&gt;carolina theater - mpack/ icepack&lt;br /&gt;&lt;br /&gt;Stay safe folks,&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-7264149536211561881?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/7264149536211561881/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=7264149536211561881' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7264149536211561881'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7264149536211561881'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/02/return-of-innocent-searches.html' title='Return of Innocent Searches'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-4543397216003270919</id><published>2008-01-30T19:06:00.000-08:00</published><updated>2008-01-30T19:39:32.387-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='transient web site hack linkscanner avg'/><title type='text'>A transient hack</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;A few days ago, we were looking at a website that was being blogged about (on Jan 21st) as being hacked, but when we looked (on Jan 21st) it was already clean. What we normally do in such cases is go to the google cache, and that usually gets us a copy of the exploit, but in this case, it was clean in the cache as well, so... what gives???&lt;br /&gt;&lt;br /&gt;The google bots went past three days earlier, so we wondered if there was a different result from the other search engine caches, and lo and behold, the yahoo cache was still infective. :-)&lt;br /&gt;&lt;br /&gt;Now, yahoo doesn't show the date that they went by, but a quick email exchange with the blog author confirmed that it was definitely infective on the 21st.&lt;br /&gt;&lt;br /&gt;What this means is that it was clean on the 18th, but hacked after that, and then cleaned on the 21st.&lt;br /&gt;&lt;br /&gt;Just for fun, we made this vid about it...&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="350"&gt;&lt;param name="movie" value="http://www.youtube.com/v/UzVgQX7gvZw"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/UzVgQX7gvZw" type="application/x-shockwave-flash" width="425" height="350"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Keep safe folks&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-4543397216003270919?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/4543397216003270919/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=4543397216003270919' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4543397216003270919'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4543397216003270919'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/01/transient-hack.html' title='A transient hack'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-8300192593683624881</id><published>2008-01-13T18:43:00.000-08:00</published><updated>2008-01-13T19:07:24.394-08:00</updated><title type='text'>Pigs fly... oh, and another 0-day ... ho hum</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;In a previous entry I suggested that we'd probably never know how the uc8010.com mass hack occurred unless one of the website victims told us, and that the chances of that were about the same as flying pigs. Guess what ... it turns out that some people do have the right combination of nerve, public spirit, and willingness to share about security matters... so... pigs _can_ fly, and now we know how it happened. I _did_ promise it was off the record, so we can't share it further, but at least we know. Bravo to that person!&lt;br /&gt;&lt;br /&gt;And why ho-hum about a 0-day? It only affects users of a product called QVOD Player, which seems to be a popular Chinese media player, but which is probably only on Chinese user's machines.&lt;br /&gt;&lt;br /&gt;The exploit code is coming from a Chinese website, so that makes sense, and it is obfuscated by flipping all the high-order bits in the javascript, to make it harder to read and notice.&lt;br /&gt;&lt;br /&gt;Fortunately, this appears unlikely to be taken up by the gangs targeting Western PCs and the kit developers, so it's probably not going to be a major problem.&lt;br /&gt;&lt;br /&gt;The real message, of course, is that the Bad Guys are still thinking.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-8300192593683624881?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/8300192593683624881/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=8300192593683624881' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8300192593683624881'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8300192593683624881'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/01/pigs-fly-oh-and-another-0-day-ho-hum.html' title='Pigs fly... oh, and another 0-day ... ho hum'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-390795163150121139</id><published>2008-01-05T18:09:00.000-08:00</published><updated>2008-01-05T18:50:31.998-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='uc0810 CA MDAC'/><title type='text'>So this is kind of interesting...</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;This domain uc8010(dot)com was registered just a few days ago (Dec 28), and yet, at one point Google showed script injections pointing to it were showing up on over 70k domains.&lt;br /&gt;&lt;br /&gt;So the first point is that this was a pretty good mass-hack, and it wasn't just that they got into a server farm, as the victims were quite diverse, with presumably the only common point being whatever vulnerability they all shared.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The second point is that some victims were pretty sophisticated in terms of security smarts, including, apparently, some Computer Associates pages. The exploit must have been pretty new. I wonder if any of the website operators will have the nerve to own up and tell us how they got nailed? Pigs might fly too.&lt;br /&gt;&lt;br /&gt;The third point is how fast the victims are being cleaned up. If you google for uc8010(dot)com, you still get about 50k hits, but if you are running something like LinkScanner (something that can check out each of those sites in real time by crawling to them), you will see that although the google snapshot still shows them infected, LinkScanner shows that the majority of them are already clean. (Btw, what this means is that the cached copy is probably still infective, so don't go testing it out yourself unless you know what you're doing)&lt;br /&gt;&lt;br /&gt;The fourth interesting point is that the only exploit we were able to coax out of them was the venerable MS06-014 (MDAC) patched in September 2006. What this means is that they went to the trouble of preparing a good website exploit, and a good mass-hack, but then used a mouldy old client exploit. It's almost a dichotomy.&lt;br /&gt;&lt;br /&gt;Stay safe folks!&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;br /&gt;Chief Research Officer&lt;br /&gt;AVG/ Grisoft&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-390795163150121139?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/390795163150121139/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=390795163150121139' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/390795163150121139'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/390795163150121139'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/01/so-this-is-kind-of-interesting.html' title='So this is kind of interesting...'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-7728117926971056714</id><published>2008-01-03T15:25:00.000-08:00</published><updated>2008-01-03T17:41:17.435-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='storm neosploit'/><title type='text'>Neosploit January 2008</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Welcome to 2008. Let's hope it's a safer year than last.&lt;br /&gt;&lt;br /&gt;Given that Neosploit seems to be gaining in popularity, and seems to be being modified fairly often, we thought it would be worthwhile to take a bit of a snapshot of it, for posterity's sake, if nothing else.&lt;br /&gt;&lt;br /&gt;Here's what we're seeing in January 2008: (Props to Glenn Jordan of AVG/ Grisoft, and Nick FitzGerald for their Most Excellent help with decryption and analysis)&lt;br /&gt;&lt;br /&gt;First there's a sort of pre-amble... typically there is a launcher script whose job it is to simply redirect to the exploit script. We say "simply" with our tongue firmly in our cheek because the launch scripts are typically encoded twice with Neosploit to make it hard for crawl-bots (but not a browser) to follow, and it appears that they might be encoded with the ip of victim, so that the exe is hard to get (except for a victim).&lt;br /&gt;&lt;br /&gt;Then the exploit script itself is also double encoded, again with the Neo-algorithm, and contains the following exploits...&lt;br /&gt;&lt;br /&gt;(1) first is the venerable MDAC (MS06-014). It's old, (worked up to Sep 2006), but it works like a charm if you're not patched.&lt;br /&gt;(2) second is one of the many QuickTime exploits. It's not easy to determine which version it is, but it's probably one of last years.&lt;br /&gt;(3) three is AOL's SuperBuddy, from April 2007&lt;br /&gt;(4) is an NCTAudioFile2 overflow from January 2007&lt;br /&gt;(5) is the GomWebCtrl from October 2007, and which has recently appeared in the Storm exploit pack as well (an idea that is Catching On (tm))&lt;br /&gt;(6) is SetSlice, patched in October 2006 and &lt;br /&gt;(7) is the ANI exploit from April 2007.&lt;br /&gt;&lt;br /&gt;Interestingly the previously-popular WinZip exploit has been dropped.&lt;br /&gt;&lt;br /&gt;The payload, or the exe that gets delivered, of course varies from website to website.&lt;br /&gt;&lt;br /&gt;It will be interesting to see how long it takes to update it with the current RealPlayer exploit.&lt;br /&gt;&lt;br /&gt;Keep safe folks!&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-7728117926971056714?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/7728117926971056714/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=7728117926971056714' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7728117926971056714'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7728117926971056714'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2008/01/neosploit-january-2008.html' title='Neosploit January 2008'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-7807874247977029758</id><published>2007-12-24T11:25:00.000-08:00</published><updated>2007-12-24T11:42:02.418-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='storm gom'/><title type='text'>Storm is b-a-a-a-a-ack</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;As you've probably noticed, Storm is back for Christmas. There are only two noteworthy points about it.&lt;br /&gt;&lt;br /&gt;The first is that they've added another fairly new exploit to it, and that is for something called GomPlayer, or the Gretech Online Movie Player, which is apparently very popular in South Korea.&lt;br /&gt;&lt;br /&gt;The exploit is from October 2007, and is explained here, http://www.milw0rm.com/exploits/4579, but the key point is that if you're using GomPlayer, you're potentially vulnerable.&lt;br /&gt;&lt;br /&gt;The second point is that 3rd party dlls continue to provide the attack points for new exploits. This is kind of interesting, and either means that Microsoft is patching faster than the exploits are coming out, or 3rd parties are not patching fast enough, or perhaps both.&lt;br /&gt;&lt;br /&gt;Of course, this also highlights that the Bad Guys don't want or need a massive number of infections... they couldn't handle that... all they want is enough to make a profit. Folks, they're farming the Internet.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Rog&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-7807874247977029758?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/7807874247977029758/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=7807874247977029758' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7807874247977029758'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7807874247977029758'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/12/storm-is-b-a-a-ack.html' title='Storm is b-a-a-a-a-ack'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-2431793291182002260</id><published>2007-12-19T18:14:00.000-08:00</published><updated>2007-12-19T19:31:15.258-08:00</updated><title type='text'>In the news today... December 19, 2007</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Things have been quiet for a few weeks now, and we've been patiently waiting for the other shoe to drop, especially given that it's the run-up to Christmas, but four fairly notable things have happened today...&lt;br /&gt;&lt;br /&gt;First is that the DollarRevenue guys have been fined $1m euros for dodgy practises, with the full story &lt;a href="http://www.opta.nl/asp/en/newsandpublications/pressreleases/document.asp?id=2459"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Shout-outs to OPTA, although a bigger fine would have been even better.&lt;br /&gt;&lt;br /&gt;(Props: Larry @ Spamhaus)&lt;br /&gt;&lt;br /&gt;Second is that the authors of the popular Pinch trojan have been arrested in Russia, full story &lt;a href="http://www.viruslist.com/en/weblog?weblogid=208187472"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;(Props: Kaspersky Labs and Ferg)&lt;br /&gt;&lt;br /&gt;Surely those two events will serve to make perpetrators think twice.&lt;br /&gt;&lt;br /&gt;Third is that, seemingly overnight, there was a web worm on Orkut, which seemingly lived, infected 400k computers, and died again overnight due to google being quick to react (shout-outs to google for that). Basic story is that any place where 3rd parties can post to a website, such as scrapbook entries on Orkut, represent an issue. If the 3rd party can post javascript, there's a good chance they can do something malicious, so all such inputs are supposed to be sanitized against that, but in this case the perp found a way to disguise the javascript enough to get past the validation/ sanitization process, and voila .... a webworm. It's a wonder we don't see more of them. Fuller story &lt;a href="http://ryanlrussell.blogspot.com/2007/12/more-on-orkut-worm.html"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;(Props: Ryan)&lt;br /&gt;&lt;br /&gt;The fourth thing is that one of our goat machines we got a virus today from a website. A really, truly virus called Cekar! Cekar is not particularly new, having been around the early part of 2007, and its main function is to steal passwords from a Chinese chat program called QQ (according to McAfee ... http://vil.nai.com/vil/content/v_141463.htm), and this makes sense, because it came in from a Chinese exploit server. The exploit that delivered it was old too... an MDAC (MS06-014), but it was interesting to watch it infect the system. It was a fast infector too... instead of waiting for a program to execute before infecting, it hit the whole disk, and all visible network drives in one pass. Quite took us back to the Old Days of the early 90's when fast infectors were the problem du jour.&lt;br /&gt;&lt;br /&gt;This really underscores two points... (1) it's way better to keep these things off your disk in the first place, because a fast infector messes you big time, and (2) we are _always_ going to need good antiviruses, just for the times when they manage to get in.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-2431793291182002260?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/2431793291182002260/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=2431793291182002260' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2431793291182002260'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2431793291182002260'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/12/in-news-today-december-19-2007.html' title='In the news today... December 19, 2007'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-6421482935691834391</id><published>2007-12-06T18:20:00.000-08:00</published><updated>2007-12-06T18:33:39.298-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='grisoft linkscanner'/><title type='text'>Grisoft acquires XPL</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Sorry for not writing something sooner... it's been a busy few days. We're pleased to announce that we've been acquired by Grisoft, the developer of AVG. Nearly all the tech and marketing folk, including me and the other researchers from XPL are joining Grisoft, and we're all very excited about it.&lt;br /&gt;&lt;br /&gt;AVG is a great little anti virus program, with a huge number of users, and we're looking forward to adding our software to their product. I expect that standalone LinkScanner will continue to exist as long as there are users for it.&lt;br /&gt;&lt;br /&gt;The web continues to be the primary attack vector for those who would build their botnets and pwn other people's computers, and real time evaluation of incoming web-pages continues to be the best way to prevent the attacks.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-6421482935691834391?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/6421482935691834391/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=6421482935691834391' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6421482935691834391'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6421482935691834391'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/12/grisoft-acquires-xpl.html' title='Grisoft acquires XPL'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-2254400424118975275</id><published>2007-11-26T19:06:00.000-08:00</published><updated>2007-11-28T09:38:38.893-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='massive malware push'/><title type='text'>Innocent searches for Nov 26 2007</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Our friends at Sunbelt have blogged about a massive push of malware here ... http://sunbeltblog.blogspot.com/2007/11/breaking-massive-amounts-of-malware.html&lt;br /&gt;&lt;br /&gt;We agree. This is the same stuff we talk about when we talk about innocent searches, mostly anyway, and it must be working because there's a huge push at the moment. Please bear in mind that we see this nearly every day, but here are today's innocent searches...&lt;br /&gt;&lt;br /&gt;Please also bear in mind that most of these come on the first page of google results, so be careful... the wrong choice lands you in trouble.&lt;br /&gt;&lt;br /&gt;"john cougar mellancamp scarecrow torrent" - exploit site/ rootkit&lt;br /&gt;"Microsoft Access linked Outlook field names" - exploit site/ rootkit&lt;br /&gt;"kings hyundai" - exploit site/ rootkit&lt;br /&gt;"harbour fitness" - exploit site&lt;br /&gt;"craigslist medford" - exploit site/ rootkit&lt;br /&gt;"Vinegar draw silver" - exploit site/ rootkit&lt;br /&gt;"hacking a samsung c417" - exploit site/ rootkit&lt;br /&gt;"bose 701 wiring diagram" - exploit site/ rootkit&lt;br /&gt;"Grove Haven" NC" - rootkit&lt;br /&gt;"el camino real restaurant universal city texas" - exploit site/rootkit&lt;br /&gt;"youtube snl robert deniro" - exploit site/ rootkit&lt;br /&gt;"spray tanning pelham alabama" - exploit site/ rootkit&lt;br /&gt;"ditripan" - exploit site/ rootkit&lt;br /&gt;"kaye jewelers" - rootkit&lt;br /&gt;"1997 dodge dakota" &amp; "ignition switch" - exploit site / rootkit&lt;br /&gt;"batteria acer travelmate 212tx" - exploit site/ rootkit&lt;br /&gt;"rhyl credit union" - mdac exploit&lt;br /&gt;"epson cx7000 driver download" - exploit site/ rootkit&lt;br /&gt;"Baseball Gloves" - mdac exploit&lt;br /&gt;"rival crock pot replacement parts" - exploit site/ rootkit&lt;br /&gt;"1990 mazda protoge bluebook" - exploit site/ rootkit&lt;br /&gt;"career fairs , new york" - exploit site/ rootkit&lt;br /&gt;"sam's club torrance" - you guessed it&lt;br /&gt;"oakland tn commercial lease" - and again&lt;br /&gt;"somerville tn commercial lease" - and again&lt;br /&gt;"texasworksource" - ditto&lt;br /&gt;"automobile battery marietta ignition" - sigh&lt;br /&gt;&lt;br /&gt;That's about half for today. The list goes on and on, but you get the idea.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-2254400424118975275?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/2254400424118975275/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=2254400424118975275' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2254400424118975275'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2254400424118975275'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/11/innocent-searches-for-nov-26-2007.html' title='Innocent searches for Nov 26 2007'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5695418613079926405</id><published>2007-11-21T18:12:00.000-08:00</published><updated>2007-11-21T18:31:41.135-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='rootkits'/><category scheme='http://www.blogger.com/atom/ns#' term='innocent searches'/><title type='text'>Innocent searches for Nov 21 2007</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Here are some of the Innocent Searches that might get you into trouble from just today. There are rather a lot of them...&lt;br /&gt;&lt;br /&gt;AREA MEASUREMENT - wrong choice gets a link to a known exploit site&lt;br /&gt;recipe for bine turkey - what's a bine turkey? anyway, wrong choice gets a rootkit&lt;br /&gt;currency converter - rootkit&lt;br /&gt;americanexpress/activate - rootkit&lt;br /&gt;sixth avenue electronics - rootkit&lt;br /&gt;deltashuttle - rootkit&lt;br /&gt;blue licenses holding - rootkit&lt;br /&gt;office depot links paper templates - rootkit&lt;br /&gt;knitted or crocheted dachshund patterns - rootkit&lt;br /&gt;fishing site - rootkit&lt;br /&gt;avolon grand cancun,mexico - mdac exploit&lt;br /&gt;demising - rootkit&lt;br /&gt;radio blog club - mdac exploit&lt;br /&gt;hp csn - rootkit&lt;br /&gt;LEGO DUPLO Block-o-dile - rootkit&lt;br /&gt;degrassi fan fiction - rootkit&lt;br /&gt;ASA 5510 throttling - rootkit&lt;br /&gt;durrants auctions - WebAttacker/MPack&lt;br /&gt;cluck u chicken - link to known exploit site&lt;br /&gt;define scupper - rootkit&lt;br /&gt;nfl picks - link to known exploit site&lt;br /&gt;gary senner myspace - trojan installer&lt;br /&gt;laundromat franchises - link to known exploit site&lt;br /&gt;&lt;br /&gt;Two interesting things... (1) most of the rootkits are being installed by social engineering tricks and (2) we're seeing about this many "Innocent searches" turning up malicious sites every day, which is a big increase from what we used to see.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5695418613079926405?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5695418613079926405/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5695418613079926405' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5695418613079926405'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5695418613079926405'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/11/innocent-searches-for-nov-21-2007.html' title='Innocent searches for Nov 21 2007'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-8396405321331923865</id><published>2007-11-19T14:51:00.000-08:00</published><updated>2007-11-19T15:15:07.871-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='monster exploit'/><title type='text'>Big hack today</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;It seems that company.monster.com suffered some sort of iframe injection attack today. Our SearchShield prevalence data has detected multiple brands affected, including Eddie Bauer, GMAC Mortgage, BestBuy, Toyota Financial, Tricounties Bank as hacked and iframing out to an exploit server.&lt;br /&gt;&lt;br /&gt;It was probably just today, as it wasn't showing up yesterday, and was not in any search engine cache that we could see.&lt;br /&gt;&lt;br /&gt;Monster has already taken the pages offline. Yay, Monster. &lt;br /&gt;&lt;br /&gt;We detect it as the Neosploit exploit package. It is fairly well encrypted, so it's not yet clear exactly what exploits are in use. We'll post more information as we figure that out.&lt;br /&gt;&lt;br /&gt;It is also not clear how many pages were affected, but it is likely that the attack was the same for all companies on the website, which _might_ turn out to be a pretty good set of Fortune 500.&lt;br /&gt;&lt;br /&gt;A couple of individual researchers noticed it at about the same time we did, but I'm not sure if they can be mentioned / want to be mentioned, so I'll reserve that for the moment.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-8396405321331923865?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/8396405321331923865/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=8396405321331923865' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8396405321331923865'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8396405321331923865'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/11/big-hack-today.html' title='Big hack today'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-6140828618431189664</id><published>2007-11-18T17:41:00.000-08:00</published><updated>2007-11-18T17:54:24.803-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='innocent searches'/><title type='text'>Just for grins...</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Just for grins, I thought I'd list some more innocent searches from the last two of days...&lt;br /&gt;&lt;br /&gt;"crash bandicoot warped iso" gets a rootkit via social engineering&lt;br /&gt;"The Hartford" wrong choice gets a WebAttacker/ Mpack&lt;br /&gt;"sock monkeys" wrong choice gets a link to a rootkitter&lt;br /&gt;"chinese bamboo fountain" wrong choice gets a rootkit&lt;br /&gt;"free dachshund sweater patterns online" wrong choice gets a rootkit ... whatever&lt;br /&gt;"woodhaven cellars" - rootkit&lt;br /&gt;"wwww.mapquest.com" - rootkit&lt;br /&gt;"table legs" - rootkit&lt;br /&gt;"car parts search toronto %22sun visor%22 honda" - rootkit&lt;br /&gt;"michigan christmas walpaper" - rootkit&lt;br /&gt;"cincinati model railroads" - rootkit&lt;br /&gt;"1978 trans ams for sale" - rootkit&lt;br /&gt;"workwear boots in lake street, minneapolis" - rootkit&lt;br /&gt;"irish gifts annapolis" - rootkit&lt;br /&gt;and last but not least&lt;br /&gt;"TRAMPOLINE cakes" - rootkit.&lt;br /&gt;&lt;br /&gt;Whatever!&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-6140828618431189664?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/6140828618431189664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=6140828618431189664' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6140828618431189664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6140828618431189664'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/11/just-for-grins.html' title='Just for grins...'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-393914823965845212</id><published>2007-11-18T05:29:00.000-08:00</published><updated>2007-11-18T06:04:33.182-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hacked gov websites'/><title type='text'>Hacked .gov websites _still_</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Over the last _three_ months, Alex Eckelberry has blogged multiple times about hacked .gov websites &lt;a href="http://sunbeltblog.blogspot.com/"&gt;here&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Two months ago, we blogged about it &lt;a href="http://explabs.blogspot.com/2007_09_01_archive.html"&gt;here&lt;/a&gt;, and and made this video... &lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://www.youtube.com/v/G_jh8lHb49w&amp;rel=1"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/G_jh8lHb49w&amp;rel=1" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt; .&lt;br /&gt;&lt;br /&gt;You'd think they'd be fixed by now, wouldn't you?&lt;br /&gt;&lt;br /&gt;Some are, but alas, here is a list from the last two days. Please be careful if you decide to look. You should expect exploits and social engineering.&lt;br /&gt;&lt;br /&gt;http://burbankil.gov/_themes/inf/0/2077.html &lt;br /&gt;http://csm.ca.gov/bios/_vti_cnf/inf/0/2968.html&lt;br /&gt;http://7.z.cityofplainville-ks.gov/7/586.html&lt;br /&gt;&lt;br /&gt;Some are hosting the code, and some are hacked dns.C'mon guys ... FIX them. &lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-393914823965845212?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/393914823965845212/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=393914823965845212' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/393914823965845212'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/393914823965845212'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/11/hacked-gov-websites-still.html' title='Hacked .gov websites _still_'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-1074272547440433414</id><published>2007-11-15T19:19:00.000-08:00</published><updated>2007-11-15T19:45:18.924-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='lures'/><title type='text'>120mb of lures</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;This is kind of interesting. Last night, our researchers found an infective, hacked site similar to the .gov that we documented &lt;a href="http://www.youtube.com/watch?v=G_jh8lHb49w"&gt;here&lt;/a&gt; By itself, that's really common, but the neat thing about this was that it was all open and readable, and we were able to download all the lure files.&lt;br /&gt;&lt;br /&gt;That turned out to be a stunning 1999 files, totaling 120mb of keywords. The idea is that the search bots find and index these pages, and after a week or two, they change the the lure pages out to a simple redirect to a fake codec or an exploit site.&lt;br /&gt;&lt;br /&gt;So, this is not earth shattering or anything, but it provides a useful insight into how the Bad Guys set their traps.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-1074272547440433414?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/1074272547440433414/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=1074272547440433414' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/1074272547440433414'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/1074272547440433414'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/11/120mb-of-lures.html' title='120mb of lures'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-8947417316787754826</id><published>2007-11-13T16:43:00.000-08:00</published><updated>2007-11-13T17:58:06.810-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mlb.com nhl.com fake scans exploits'/><title type='text'>Banner ads from major sites</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Ok, we all know that infective banner ads are not new, but this is more interesting than most because they're currently fairly common from both mlb.com and nhl.com. &lt;br /&gt;&lt;br /&gt;These are really hard to track down, because they don't happen every time you visit a site ... it took us hours to get our first capture... but it was both interesting and instructive that when _we_ got a capture, one of our researchers on the other side of the world got one at about the same minute. Now, it was a different fake scanner, and a different path thru the ad network, but it was a startlingly similar style and almost the same time. We don't believe in coincidences.&lt;br /&gt;&lt;br /&gt;Here's the chain for mlb.com ...&lt;br /&gt;&lt;br /&gt;mlb.mlb.com/index.jsp calls to ad.doubleclick.net&lt;br /&gt;ad.doubleclick.net calls to newbieadguide.com&lt;br /&gt;newbieadguide.com calls to fixthemnow.com - this is where the code comes from&lt;br /&gt;fixthemnow.com calls to bsa.safetydownload.com&lt;br /&gt;&lt;br /&gt;and here's the chain from nhl.com ...&lt;br /&gt;&lt;br /&gt;www.nhl.com calls to m1.2mdn.net   &lt;br /&gt;m1.2mdn.net with a parameter of ad.doubleclick.net calls to adtraff.com&lt;br /&gt;adtraff.com calls to blessedads.com   &lt;br /&gt;adtraff.com calls also to prevedmarketing.com (which is the same ip as blessedads.com)&lt;br /&gt;one of those two does a 302 (temporary redirect) to scanner2.malware-scan.com, which does the fake scan.&lt;br /&gt;&lt;br /&gt;Full URLs are available to appropriate interested parties.&lt;br /&gt;&lt;br /&gt;Here's a vid for anyone who'd like to watch it in action...&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="350"&gt;&lt;param name="movie" value="http://www.youtube.com/v/8lBUQqufZWc"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/8lBUQqufZWc" type="application/x-shockwave-flash" width="425" height="350"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-8947417316787754826?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/8947417316787754826/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=8947417316787754826' title='10 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8947417316787754826'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8947417316787754826'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/11/banner-ads-from-major-sites.html' title='Banner ads from major sites'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>10</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-7243089361744893066</id><published>2007-11-09T11:32:00.000-08:00</published><updated>2007-11-09T12:02:37.119-08:00</updated><title type='text'>whoops - sorry Chris</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Evidently I owe Chris Boyd an apology.&lt;br /&gt;&lt;br /&gt;Here's what happened. About a week ago, our prevalence network, independently of any other input, detected the Alicia Keys MySpace hack, because of the link to the fake codec, and we started trying to make a video about it.&lt;br /&gt;&lt;br /&gt;I recalled Alex Eckelberry making a post about a couple of different MySpace hacks over the last week or so, and in fact credited them as we made the video. When I checked with Alex to find a blog to link to, he told me it was Chris and not his guys. It was too late to change the vid, but I intended to mention it in the blog, and simply forgot.&lt;br /&gt;&lt;br /&gt;To be fair to Chris, he was first, although when I looked at the link Alex gave me, it mentioned the Passarounders, and when I found Alex's original message, it mentioned a band called greementsoffortune ... not Alicia Keys, which was much bigger news to me. It was the same Bad Guys, but, truly, _we found it independently_.&lt;br /&gt;&lt;br /&gt;So Chris... I apologize ... I didn't steal any of your work, and didn't mean to steal your thunder.&lt;br /&gt;&lt;br /&gt;Everyone knows you do good work, and I clearly owe you at least one beer sometime.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-7243089361744893066?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/7243089361744893066/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=7243089361744893066' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7243089361744893066'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7243089361744893066'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/11/whoops-sorry-chris.html' title='whoops - sorry Chris'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5449651126195600522</id><published>2007-11-08T20:00:00.000-08:00</published><updated>2007-11-08T20:16:36.110-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='alicia keys hack myspace'/><title type='text'>Ok, now this is pretty funny...</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;So as we reported, Alicia Keys' myspace page was hacked, with a background image linking out to co8vd.cn. Within a couple of hours of releasing our blog and vid, myspace had fixed the page... Yay MySpace!!! (which had been hacked for at least three or four days earlier, because that's when we first noticed it... and someone just reminded me that PaperGhost over at http://www.vitalsecurity.org/2007/11/myspace-band-hacks-continue_05.html had noticed it for some other bands separately at a similar time or even earlier time), but here's the funny bit.&lt;br /&gt;&lt;br /&gt;It looks like it's hacked again!!!&lt;br /&gt;&lt;br /&gt;The original hack was an href image reference to co8vd.cn/s/ and while that's now out of the html, there's now an href image reference to acilot.cn/s/ .... see any similarities there??? :-)&lt;br /&gt;&lt;br /&gt;Now, to be fair, acilot.cn is currently 404, but it _might_ still be coming online, and it sure looks suspicious.&lt;br /&gt;&lt;br /&gt;Hacked... clean for a couple of hours... hacked again... pretty funny.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5449651126195600522?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5449651126195600522/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5449651126195600522' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5449651126195600522'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5449651126195600522'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/11/ok-now-this-is-pretty-funny.html' title='Ok, now this is pretty funny...'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-4812059523600450399</id><published>2007-11-08T13:51:00.000-08:00</published><updated>2007-11-08T14:47:09.552-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='alicia keys hack myspace'/><title type='text'>Alicia Keys MySpace page is hacked</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Attacks on MySpace seem to be on the rise. First, at the end of October, there were a number of links added as friend-comments that went via MySpace's open-redirector (MSPlinks) to exploit sites in China. This was reported publicly on the FunSec mailing list. (All myspace friend-comments _seem_ to automatically redirect thru MSPlinks, probably as a way to try to filter out spam and phishing, but a downside is that the URL is base64 encoded, and is thus impossible for a human being to eyeball, and therefore possibly reject ... the effect of the well-intentioned msplinks is thus to make an open-redirector)&lt;br /&gt;&lt;br /&gt;Now, we keep finding MySpace pages that have had some sort of image-background link injected, that are reaching out to a different site in China that is both throwing exploits and using social engineering to install rootkits and (probably) dns-changers.&lt;br /&gt;&lt;br /&gt;The interesting thing about this is that rather than using an iframe for an automatic embed, as they usually do, they've added some sort of image background href, with a large size ... 8000 by 1000 pixels, with the effect that a click that slightly *misses* a control or link on the page, ends up going to the exploit site. &lt;br /&gt;&lt;br /&gt;The fact that this site is media-rich, with lots of sound and videos means that the FakeCodec trick will be much more effective. The click-er is probably expecting to see a vid, or hear a song, and is quite likely to think he genuinely needs to install something extra.&lt;br /&gt;&lt;br /&gt;This could easily be the same group that recently started watching for Mac users, and offering a Mac trojan as needed, and if that's so, will also add to the effectiveness of the attack.&lt;br /&gt;&lt;br /&gt;What's not clear at this point is how they're doing it, and how widespread it is. Neither google nor myspace seems to be indexing the critical bit of html. If you search for the exploit site (co8vd.cn), the only results seem to be victims, or people talking about victims.&lt;br /&gt;&lt;br /&gt;I guess we'll have to wait for MySpace to tell us what happened.&lt;br /&gt;&lt;br /&gt;Here's a vid that shows a bit more...&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="355"&gt;&lt;param name="movie" value="http://www.youtube.com/v/_VipylmHnII&amp;rel=1"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/_VipylmHnII&amp;rel=1" type="application/x-shockwave-flash" wmode="transparent" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-4812059523600450399?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/4812059523600450399/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=4812059523600450399' title='16 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4812059523600450399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4812059523600450399'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/11/alicia-keys-myspace-page-is-hacked.html' title='Alicia Keys MySpace page is hacked'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>16</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-6306537865397879959</id><published>2007-11-07T19:01:00.000-08:00</published><updated>2007-11-07T19:13:58.242-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='storm superbuddy'/><title type='text'>and the _other_ shoe drops</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;There are two important things happening at the moment, and one shoe dropping. One is that we have the feeling that the Bad Guys are re-grouping... moving countries, and reorganizing.&lt;br /&gt;&lt;br /&gt;The second is that the pre-packaged exploits like MPack and Icepack have largely disappeared...replaced by social engineering tricks which are being used _extensively_.&lt;br /&gt;&lt;br /&gt;The other shoe that's dropped is that the Storm boyz have been relatively quiet for a while, which is never a good sign. Our respected colleague, Nick FitzGerald pointed out tonight that they've added two new exploits to their exploit package. One seems to be for AOL's SuperBuddy, and the other is the NCTAudioFile2 dll, used with lots of widely adopted packages, such as Movavi. CERT has a nice write-up here ... http://www.kb.cert.org/vuls/id/292713.&lt;br /&gt;&lt;br /&gt;Now, we have to stress that neither of these is 0-day... SuperBuddy seems to be from March 2007, and NCTAudioFile2 seems to be from January, but these dlls are probably not part of a systematic upgrade, so there are likely to be enough unpatched systems around to make it worth their while. And it may not even be new for Storm, but we've only just noticed, so there's a good chance it is new for them. They keep using the same encryption/ obfuscation routines so it looks enough like Storm, that we've been detecting it anyway.&lt;br /&gt;&lt;br /&gt;Anyway, I certainly feel that this is the _other_ shoe dropping for Storm, and explains why they've been quiet for a while. &lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-6306537865397879959?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/6306537865397879959/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=6306537865397879959' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6306537865397879959'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6306537865397879959'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/11/and-other-shoe-drops.html' title='and the _other_ shoe drops'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-639806928118184783</id><published>2007-10-17T19:33:00.000-07:00</published><updated>2007-10-17T19:43:09.897-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='storm'/><title type='text'>And the other shoe drops ...</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Our respected colleague, Joe Stewart, has noticed that Storm is now using encryption (albeit trivial) to communicate with its peers. What this means is that Storm bots can only communicate with other Storm bots that know that key. He speculates that this might be a precursor to selling off chunks of the botnet!&lt;br /&gt;&lt;br /&gt;This fits perfectly with what we noticed, whereby Storm had been ... vigorous... but was now quiet. It felt, to us, that they were planning/ changing something, and this would make perfect sense.&lt;br /&gt;&lt;br /&gt;What this means to everyone is that we can look forward to even _increased_ Storm botnet activity, as other groups try to use it for their various and nefarious purposes.&lt;br /&gt;&lt;br /&gt;Interesting times, folks.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-639806928118184783?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/639806928118184783/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=639806928118184783' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/639806928118184783'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/639806928118184783'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/10/and-other-shoe-drops.html' title='And the other shoe drops ...'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-3991347345927770969</id><published>2007-10-05T15:12:00.000-07:00</published><updated>2007-10-05T15:17:52.202-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='storm botnet'/><title type='text'>Waiting for the other shoe to drop</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;This has been a really busy couple of weeks with hacked websites, new exploits, and improved encryption all over the place... we see most of the different groups working hard with the exception of the Storm guys.&lt;br /&gt;&lt;br /&gt;Given how active they've been in the past, creating new lure pages every few days, sending huge amounts of spam, and sometimes creating new versions of their bots every few minutes, one has to wonder where they are?&lt;br /&gt;&lt;br /&gt;It'd be nice to think they've given up, and got legit jobs, but one has to wonder if this is simply the proverbial calm before the (new) Storm.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-3991347345927770969?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/3991347345927770969/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=3991347345927770969' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3991347345927770969'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3991347345927770969'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/10/waiting-for-other-shoe-to-drop.html' title='Waiting for the other shoe to drop'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-2140558279101699100</id><published>2007-10-03T12:52:00.000-07:00</published><updated>2007-10-03T13:20:54.338-07:00</updated><title type='text'>Cisrt hack</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;The most interesting part of this story has been poorly reported, as far as we can see, and that is that at least two of the many exploits being fired by the exploit servers in this hack are brand new! (0-days by some definitions, but probably more correctly Undercover Exploits)&lt;br /&gt;&lt;br /&gt;One exploit impacts the Baidu Soba searchbar, (Apparently Baidu is a popular Chinese search engine, and they make a searchbar) which isn't going to impact non-Chinese users too much, but given that CISRT is the Chinese Internet Security Response Team, there's a fair chance it got a bunch of local victims before it was cleaned up.&lt;br /&gt;&lt;br /&gt;The second new exploit seemingly targets another third-party toolbar. It's not 100% clear at this point, but the clsid seems to be the OcSearchAssistant (spyware) searchbar. This is kind of funny, because it means it was targetting stuff that was probably installed by slightly nefarious means in the first place. I thought there was honor among thieves.&lt;br /&gt;&lt;br /&gt;These bring to four the number of new 3rd party dll exploits in use for the first time, in just about one month. It seems an idea that is Catching On (tm).&lt;br /&gt;&lt;br /&gt;The third under-reported side to this is the sheer complexity of the encryption being used to obfuscate the exploits. We have still not decrypted some of them, so there could well be more surprises to be found.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-2140558279101699100?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/2140558279101699100/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=2140558279101699100' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2140558279101699100'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2140558279101699100'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/10/cisrt-hack.html' title='Cisrt hack'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-6959546065417106775</id><published>2007-10-02T19:22:00.000-07:00</published><updated>2007-10-02T19:37:14.446-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bait and switch'/><title type='text'>More google stuff</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Here is a video we made some time ago, and only recent decided to publish it, mostly because some other folk have noticed it too. It's called Playing Bait and Switch with the search engines. Basically what happens is that the Bad Guys create a new website and load it up with pages of keywords ... some porno, some startlingly innocent. They give it a week or so to allow all the search bots to find and index them, and then switch it out to either an exploit or a social engineering trick.&lt;br /&gt;&lt;br /&gt;The result is that really innocent searches take unwary users to really dangerous places.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="350"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Fp0q2VrwqzY"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/Fp0q2VrwqzY" type="application/x-shockwave-flash" wmode="transparent" width="425" height="350"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-6959546065417106775?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/6959546065417106775/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=6959546065417106775' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6959546065417106775'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6959546065417106775'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/10/more-google-stuff.html' title='More google stuff'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-4786695925798996711</id><published>2007-09-30T13:03:00.000-07:00</published><updated>2007-09-30T13:16:57.507-07:00</updated><title type='text'>Not just US .gov websites</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;It's fairly well understood now that there are bunches of US .gov websites that are either directly hacked, or at least have compromised DNSs, but over the last few days, we have seen .gov for both the Philippines and Saudi Arabia exhibiting the same symptoms. I suspect the Kingdom would be very upset if they knew what they were hosting, or at least said to be hosting.&lt;br /&gt;&lt;br /&gt;And at least one Syrian Embassy website is also hacked, with an invisible iframe link to an Esthost (Russian) exploit server. That server is currently not talking to anyone, but it can be brought online at any minute.&lt;br /&gt;&lt;br /&gt;It's nice to know that website security is not limited to US gov.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-4786695925798996711?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/4786695925798996711/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=4786695925798996711' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4786695925798996711'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4786695925798996711'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/09/not-just-us-gov-websites.html' title='Not just US .gov websites'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5085433279567699781</id><published>2007-09-26T12:22:00.000-07:00</published><updated>2007-09-26T12:39:31.239-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='0-day baofeng storm'/><title type='text'>And another 0-day ITW</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Today we have found yet another 0-day ITW. ITW stands for In The Wild, and means that the exploit has been found alive on a website, and actually trying to install real malware, as opposed to ITZ. ITZ stands for In The Zoo, and refers to those exploits which are proofs of concept only, and which are not actually in use.&lt;br /&gt;&lt;br /&gt;Anyway, today we found another one.&lt;br /&gt;&lt;br /&gt;It's another activex buffer overflow in a Chinese product called Baofeng Storm. NIST has a write-up here... http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-4816.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We're not really sure what that is, because the website is in Chinese only, and that makes it a bit hard to read for those of us who only speak English. :-) The good news is that this probably means it is unlikely to be on too many computers outside China.&lt;br /&gt;&lt;br /&gt;The bad news is that this seems to have only been announced in the middle of Septmeber, so it again shows that the Bad Guys are being really vigilant.&lt;br /&gt;&lt;br /&gt;Naturally, we detect it anyway. :-)&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5085433279567699781?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5085433279567699781/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5085433279567699781' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5085433279567699781'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5085433279567699781'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/09/and-another-0-day-itw.html' title='And another 0-day ITW'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-3799191928589828053</id><published>2007-09-23T15:42:00.000-07:00</published><updated>2007-09-23T15:51:17.530-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='0-day'/><title type='text'>0-day ITW... but relax</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Today we've found a 0-day ITW, but it's probably not going to affect too many people, so it's not a huge worry.&lt;br /&gt;&lt;br /&gt;The issue is a buffer overflow in the PowerPlayer.dll ActiveX control in PPStream, CVE reference CVE-2007-4748. PPStream is a Chinese P2P video streaming application. As far as we know, there is no English version, but it probably won't affect too many people outside China.&lt;br /&gt;&lt;br /&gt;It shows that the Bad Guys are still thinking and watching.&lt;br /&gt;&lt;br /&gt;By the way, they teased us a bit because they also had an exploit named ms07-042, which would have been much more "interesting", but when we decrypted it, it turned out to just be another VML.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-3799191928589828053?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/3799191928589828053/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=3799191928589828053' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3799191928589828053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3799191928589828053'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/09/0-day-itw-but-relax.html' title='0-day ITW... but relax'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5823398546506330365</id><published>2007-09-21T11:38:00.000-07:00</published><updated>2007-09-21T11:45:00.967-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='storm botnet'/><title type='text'>Storm in September 07</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Just for grins we made a small vid of a mid-September 07 Storm lure. Their websites have evolved from simple text based "Click-here-to-view-your-ecard" type things to content rich, impressive websites with animated gifs. &lt;object width="425" height="350"&gt;&lt;param name="movie" value="http://www.youtube.com/v/XEBmX-pHq4I"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/XEBmX-pHq4I" type="application/x-shockwave-flash" width="425" height="350"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;There's nothing startling about it, but it's impressive for a pure lure.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5823398546506330365?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5823398546506330365/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5823398546506330365' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5823398546506330365'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5823398546506330365'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/09/storm-in-september-07.html' title='Storm in September 07'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-2449362246840782997</id><published>2007-09-14T12:52:00.000-07:00</published><updated>2007-09-14T13:01:18.910-07:00</updated><title type='text'>Ad vendor serving exploits thru Facebook</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Last night I was reading a friend's blog on FaceBook, and IE popped up a message saying that the webpage was trying to start RDS (Remote Data Services) services, and would I allow it. I clicked "No", and then thought "Hang on... it shouldn't have been starting RDS!" (It was late and I was a bit slow), so I opened up a goat machine, retraced my steps, and about a minute later.... blam... programs dropped and executed on my machine.&lt;br /&gt;&lt;br /&gt;No rootkit, and no detection from any avs that I had access to, but after a reboot, I found that now, when I started IE and went to my home page, I got extra copies of the browser starting, and ads being served.&lt;br /&gt;&lt;br /&gt;It’s hard to sort out, but here’s the critical sequence of connections …&lt;br /&gt;&lt;strong&gt;Facebook calls to bannerconnect&lt;/strong&gt;&lt;br /&gt;208_67_70_3   Referer: http://ads.ak.facebook.com/ads [snip]  ,Host: ad.bannerconnect.net   &lt;br /&gt;&lt;strong&gt;bannerconnect calls to yieldmanager&lt;/strong&gt;&lt;br /&gt;208_67_70_3   Referer: http://ad.bannerconnect.net/st?ad_t [snip] ,Host: ad.yieldmanager.com   208_67_70_3   Referer: http://ad.bannerconnect.net/st?ad_t [snip] ,Host: ad.yieldmanager.com   &lt;br /&gt;&lt;strong&gt;yieldmanager calls to valuead&lt;/strong&gt;&lt;br /&gt;69_63_219_104 Referer: http://ad.yieldmanager.com/iframe3? [snip] ,Host: reduxads.valuead.com   69_63_219_104 Referer: http://ad.yieldmanager.com/iframe3? [snip] ,Host: reduxads.valuead.com   &lt;br /&gt;&lt;strong&gt;valuead calls to megapromition, which throws an exploit (MS06-014), which runs an adware installer&lt;/strong&gt;85_17_161_17  Referer: http://reduxads.valuead.com/test?pi [snip] ,Host: www.megapromition.net  &lt;br /&gt;After reboot, an Internet Explorer launch that should just show google looked like this …&lt;br /&gt; &lt;br /&gt;&lt;a href="http://wormradar.com/afterboot.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 400px;" src="http://wormradar.com/afterboot.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It might well be an old exploit, but adware vendors shouldn't be doing it.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-2449362246840782997?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/2449362246840782997/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=2449362246840782997' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2449362246840782997'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2449362246840782997'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/09/ad-vendor-serving-exploits-thru.html' title='Ad vendor serving exploits thru Facebook'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-2077948797097191549</id><published>2007-09-08T13:43:00.000-07:00</published><updated>2007-09-08T13:45:12.631-07:00</updated><title type='text'>A new exploit this weekend</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;It looks like there's a new version of IcePack, and it's pretty interesting. As well as the venerable but trusty MDAC and SetSlice exploits that we've come to love and expect, it also contains some new stuff. &lt;br /&gt;&lt;br /&gt;The newest, and most interesting, is a buffer overflow in a DirectX dll. The vulnerability was announced in August 2007, and is documented here http://www.kb.cert.org/vuls/id/466601. As far we have found, there is not yet a patch for it, which can make things .... interesting. The best mitigator is that the vulnerable DLL is probably not in standard XP or Vista, and therefore is probably not massively available as a target. The problem with that is that it's not clear what packages it _is_ included with, so if you're not running something like LinkScanner, there's an element of Russian Roulette here.&lt;br /&gt;&lt;br /&gt;The next interesting thing is that it contains not one, but two yahoo IM exploits. One is a control stack buffer overflow for Yahoo! Widgets Plugin, also announced in August 2007, and the second is a Yahoo! Webcam exploit from June 2007.&lt;br /&gt;&lt;br /&gt;Just to round things out it also contains...&lt;br /&gt;&lt;br /&gt;VML - MS07-004&lt;br /&gt;MDAC/RDS - MS06-014 (patched in April 2006, but this version works up until September 2006)&lt;br /&gt;SetSlice &lt;br /&gt;WinZip&lt;br /&gt;&lt;br /&gt;oh, and a Firefox exploit that appears to be the venerable WMplayer exploit from a couple of years ago.&lt;br /&gt;&lt;br /&gt;They tend to keep things that work, reasoning that they don't don't need to exploit every box on the internet ... just enough for them to make money, so the mix of old and new exploits is to be expected, but three new ones in one update is pretty impressive.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-2077948797097191549?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/2077948797097191549/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=2077948797097191549' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2077948797097191549'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2077948797097191549'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/09/new-exploit-this-weekend.html' title='A new exploit this weekend'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-8603379056115238078</id><published>2007-09-07T10:45:00.000-07:00</published><updated>2007-09-07T11:26:45.022-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hacked .gov websites'/><title type='text'>Hacked .gov websites</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;A couple of days ago, our SearchShield intelligence network noticed a&lt;br /&gt;bunch of .gov sites serving malware via drive-by downloaded exploits and&lt;br /&gt;social engineering. The front pages of the .gov sites are seemingly not&lt;br /&gt;hacked themselves, but they're hosting pages that serve it.  We've&lt;br /&gt;identified about a dozen poisoned sites so far, though we expect there&lt;br /&gt;are many more related to this hack. The first dozen or so seem to be city governments such as lasalle, il and frenchsettlement-la.&lt;br /&gt;&lt;br /&gt;The attacking pages seem to try one of three things. First they try an&lt;br /&gt;exploit to install their malware, and if that doesn't work, they try to&lt;br /&gt;trick you into installing a fake codec, and if that doesn't work, they&lt;br /&gt;run a fake antispy scan, and try to convince you that your machine is&lt;br /&gt;already compromised, but their software can fix it... just click the&lt;br /&gt;install button. &lt;br /&gt;&lt;br /&gt;We've made a video about it, and it's at youtube &lt;a href="http://www.youtube.com/watch?v=G_jh8lHb49w"&gt;here ...&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;with a hires .mov &lt;a href="http://explabs.com/gov-hack-1.asp"&gt;here... &lt;/a&gt; &lt;br /&gt;&lt;br /&gt;These particular pages were detected with adult/XXX type queries, but many innocent searches also return the sites.&lt;br /&gt;&lt;br /&gt;We'll add more details in this blog as we go.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-8603379056115238078?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/8603379056115238078/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=8603379056115238078' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8603379056115238078'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8603379056115238078'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/09/hacked-gov-websites.html' title='Hacked .gov websites'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-3460894277770984919</id><published>2007-09-01T15:26:00.000-07:00</published><updated>2007-09-01T19:30:46.780-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bank of india exploit'/><title type='text'>Bank of India hack update</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;This is a round-up of the latest news on the Bank Of India hack.&lt;br /&gt;&lt;br /&gt;As of 10:15pm est on Saturday September 1st 2007, the bank website is still disabled, with a note saying it's undergoing maintenance, and asking for patience.&lt;br /&gt;&lt;br /&gt;This is a good thing, because it means they're examining all their pages for intrusions, and with appropriate care they'll also correct the vulnerabilities that allowed the site to be hacked in the first place. This is an important step, because we see entirely too many sites that get hacked, then are cleaned, and then they get hacked again because the holes have not been plugged.&lt;br /&gt;&lt;br /&gt;Now that the dust has cleared, it is apparent that the attacking servers fired at least two different exploit sets. One was a simple MS06-042, which was essentially cut and pasted from the original Milw0rm proof of concept. The second exploit set was an as yet unidentified exploit package, along the lines of mpack/icepack/webattacker.&lt;br /&gt;&lt;br /&gt;It contained a vml exploit, probably MS07-004, another MS06-042, a WinZip, a QuickTime, and a SetSlice. This would be very similar to mpack/icepack except that it is missing an ANI (MS07-017), and it contains instead the VML.&lt;br /&gt;&lt;br /&gt;The real difference, however, is that it had machine generated variable and function names. In other words, the server side script was generating the scripts in order to try to defeat scanners. For a variety of reasons that I won't go into here, this fails to defeat the scanners, especially LinkScanner, but it's an interesting step.&lt;br /&gt;&lt;br /&gt;Btw, we now have an edited version of the video. Hires .mov can be found &lt;a href="http://wormradar.com/boi.mov"&gt;here &lt;/a&gt; and a youtube vesion &lt;a href="http://youtube.com/watch?v=aWV8d2rWf8E"&gt;here&lt;/a&gt; .&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-3460894277770984919?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/3460894277770984919/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=3460894277770984919' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3460894277770984919'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3460894277770984919'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/09/bank-of-india-hack-update.html' title='Bank of India hack update'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-3049954837029936741</id><published>2007-08-30T16:43:00.000-07:00</published><updated>2007-08-31T03:40:02.301-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bank of india hack'/><title type='text'>Compromised bank website</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Props to our clever colleagues at Sunbelt for noticing this one.&lt;br /&gt;&lt;br /&gt;It seems that the official website of the Bank of India has been compromised and is serving exploits. It's not clear when it was compromised, but the google cache seems to show that it was clean on the 29th August, and we saw it as dirty on the 30th August, so that narrows it down a little bit, timezones notwithstanding. &lt;br /&gt;&lt;br /&gt;Please note that the bank did _not_ do this deliberately, and is as much a victim as anyone else. Undoubtedly it'll be cleaned up as soon as the bank's IT staff comes in to work, so &lt;a href="http://wormradar.com/boi.wmv"&gt;here's &lt;/a&gt; a video to preserve it for posterity. &lt;br /&gt;&lt;br /&gt;The vid's a bit rough at the moment, and some of the bits are currently unreadable, but we'll be editing it as we go, so clearer versions will soon be available, but it's still interesting.&lt;br /&gt;&lt;br /&gt;UPDATE: It's been cleaned. Good job by the bank staff for the quick reaction. &lt;br /&gt;&lt;br /&gt;Also, I've had a few questions off-list about whether LinkScanner Pro blocked it already, and the answer is yes... it was using standard Mpack/Icepack stuff. We blocked it fine. There was no new exploit. The interesting bit was that even a professional, commercial website can be a victim too.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-3049954837029936741?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/3049954837029936741/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=3049954837029936741' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3049954837029936741'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3049954837029936741'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/08/compromised-bank-website.html' title='Compromised bank website'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-8773450044074474523</id><published>2007-08-29T18:31:00.000-07:00</published><updated>2007-08-29T18:44:17.642-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='snoop dog beyonce'/><title type='text'>Snoop Dog, Eagles, Beyonce ... is nothing sacred?</title><content type='html'>Apparently not. &lt;br /&gt;&lt;br /&gt;The Storm botnet has switched from fake youtube vids to early previews of new music videos. Here's a sample pitch...&lt;br /&gt;&lt;br /&gt;Snoop Dog filmed the most amazing new video.&lt;br /&gt;&lt;br /&gt;See the version before MTV airs it. Click the link to play it:&lt;br /&gt;&lt;br /&gt;and&lt;br /&gt;&lt;br /&gt;Eagles just filmed their new video.&lt;br /&gt;&lt;br /&gt;Get it before it comes out. Click the link to play it:&lt;br /&gt;&lt;br /&gt;So, no, nothing is sacred, and there's still no such thing as a free lunch. If the deal looks to good to be true, it probably isn't true.&lt;br /&gt;&lt;br /&gt;Btw, there are still no new exploits in the package, and LinkScanner detects it just fine. Keep safe, folks.&lt;br /&gt;&lt;br /&gt;:-)&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-8773450044074474523?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/8773450044074474523/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=8773450044074474523' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8773450044074474523'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8773450044074474523'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/08/snoop-dog-eagles-beyonce-is-nothing.html' title='Snoop Dog, Eagles, Beyonce ... is nothing sacred?'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-2776059138691797965</id><published>2007-08-28T17:06:00.000-07:00</published><updated>2007-08-28T17:18:05.934-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='lindsay Lohan exploit'/><title type='text'>Poor Lindsay</title><content type='html'>She just gets out of the jail thing, and a website using her name turns out to be infective! To be accurate, there's no reason to believe that the website has anything to do with her, other than use her name, but it's infective, none-the-less. I guess it's showing up because people are searching for her a little more often, but I guess she can't catch a break.&lt;br /&gt;&lt;br /&gt;By the way, I've been getting _lots_ of requests off-list for more Dangerous Searches, so here are a few from the last couple of days...&lt;br /&gt;&lt;br /&gt;Hymn to Red October - Wrong choice gets you a fake codec&lt;br /&gt;Portsmouth boat adjustment table - fake codec&lt;br /&gt;Power Wrestling - wrong choice gets a WebAttacker/ MPack&lt;br /&gt;traditional sparrow tattoos - gets a search engine hijack.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-2776059138691797965?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/2776059138691797965/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=2776059138691797965' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2776059138691797965'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2776059138691797965'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/08/poor-lindsay.html' title='Poor Lindsay'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-7457767543697158136</id><published>2007-08-25T19:42:00.000-07:00</published><updated>2007-08-25T19:47:57.942-07:00</updated><title type='text'>Storm twist</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;There has been a slightly interesting development with the massive storm botnet today, in that they are referencing a youtube video.&lt;br /&gt;&lt;br /&gt;This is typical email text ...&lt;br /&gt;&lt;br /&gt;"You can see your face right in the video. its all over the web dude. this is the link to it."&lt;br /&gt;&lt;br /&gt;followed by what seems to be a youtube link.&lt;br /&gt;&lt;br /&gt;At first we thought they'd done something cunningly bad to youtube, but it's just an email/ html trick. ALl they're doing is displaying an html link, which in fact takes you directly to a Storm node, which in turn tries to use a Q406 Rollup package to infect you.&lt;br /&gt;&lt;br /&gt;What this all means is that LinkScanner sees thru all their subterfuge just fine, but lots of non-LinkScanner users will be tempted to view the youtube video (which are always safe, aren't they?)&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-7457767543697158136?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/7457767543697158136/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=7457767543697158136' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7457767543697158136'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7457767543697158136'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/08/storm-twist.html' title='Storm twist'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-8404430076888497451</id><published>2007-08-13T19:52:00.000-07:00</published><updated>2007-08-13T20:15:29.294-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='russian attack exploits'/><title type='text'>Russian Attack Imminent</title><content type='html'>I'm kidding... I'm kidding!!! Despite the views of some of our esteemed competitors, we just can't see it. Are there lots of Russian sites launching exploits? Sure, but not that many more than usual. We think what people are seeing is a by-product of the combination of the increasing number of pre-packaged exploit sets like MPack and IcePack together with improvements in the ability of the Bad Guys to mass-infect webfarms.&lt;br /&gt;&lt;br /&gt;In fact, we think everything is exceptionally quiet at the moment, which suits us all just fine. Let's hope it's not a calm before the storm kind of thing.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-8404430076888497451?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/8404430076888497451/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=8404430076888497451' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8404430076888497451'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8404430076888497451'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/08/russian-attack-imminent.html' title='Russian Attack Imminent'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-4638972547029021194</id><published>2007-08-08T21:13:00.000-07:00</published><updated>2007-08-08T21:29:26.029-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webattacker mpack'/><title type='text'>WebAttacker2</title><content type='html'>Ok .... now we really think we've seen one. Let us explain...&lt;br /&gt;&lt;br /&gt;The original WebAttacker was a set of exploits sold as a package. The idea was to allow would-be evil WebMeisters to add drive-by downloads to their websites for whatever reason they might have. The original developers would release a new version every other month or so. As new exploits were discovered, the WA authors would add them to their package. All went well (for them) until about September 2006, when they tried to add one of the September 0-days, and their implementation was buggy. It just didn't work. The next couple of months saw them trying to add a couple more exploits-du-jour, and unforch, they didn't work either. Their user base abandoned them for other packages (which we now now to be MPack, IcePack and Neosploit) which _did_ work, and they lost their market share. WebAttacker went the way of any software package that doesn't work. &lt;br /&gt;&lt;br /&gt;This weekend, however, it seems that they've re-surfaced. Our researchers have noticed URLs being spammed out, with exploit packages that look similar to Mpack/ Icepack but different, and very reminiscent of the original WebAttacker... exploit urls are reminiscent... launcher scripts are reminiscent, even to the point of determining if they are running on the archiac Windows 98 (but then doing nothing with that information). Nothing newer than ANI (MS07-017), but it doesn't include Winzip and Quicktime, which again makes it different from MPack/ Icepack.&lt;br /&gt;&lt;br /&gt;It looks like they're ba-a-a-ack!&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-4638972547029021194?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/4638972547029021194/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=4638972547029021194' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4638972547029021194'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4638972547029021194'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/08/webattacker2.html' title='WebAttacker2'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-8827710850896206181</id><published>2007-07-28T19:01:00.000-07:00</published><updated>2007-07-28T19:15:19.969-07:00</updated><title type='text'>New (ish) Chinese exploit in the wild</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;We are able to confirm that some Chinese websites are now using a WebThunder ActiveX exploit.WebThunder appears to be a Chinese P2P networking application that is quite popular there, but we think everyone else is pretty safe.&lt;br /&gt;&lt;br /&gt;The main point is to be aware that the Bad Guys are still thinking and probing.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-8827710850896206181?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/8827710850896206181/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=8827710850896206181' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8827710850896206181'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8827710850896206181'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/07/new-ish-chinese-exploit-in-wild.html' title='New (ish) Chinese exploit in the wild'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-3333685525732068882</id><published>2007-07-20T19:26:00.000-07:00</published><updated>2007-07-20T19:44:09.404-07:00</updated><title type='text'>Catching up</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Firstly, let us apologize for not blogging more frequently. The last couple of weeks have been tumultuous with some things we can discuss, and some we cannot.&lt;br /&gt;&lt;br /&gt;Here's a summary...&lt;br /&gt;&lt;br /&gt;(1) Dangerous searches still abound. Here are a few examples from the last day or two...&lt;br /&gt;&lt;br /&gt;Robert Cleridge women's shoes - wrong choice gets a link to a known rootkitter&lt;br /&gt;&lt;br /&gt;Wallpapers - wrong choice gets a WebAttacker&lt;br /&gt;&lt;br /&gt;Janet Jackson photos - duh!&lt;br /&gt;&lt;br /&gt;download constrained regression nonlinear - one might argue that a query that geeky deserves an exploit, except that we're all proud geeks here, so we cannot.&lt;br /&gt;&lt;br /&gt;(2) The Storm botnet attacks have been unfolding in relentless waves. We cannot talk too much about that at the moment, except to say they've been very interesting and quite impressive. &lt;br /&gt;&lt;br /&gt;(3) There are now at least six different exploit packs being sold ala WebAttacker. It seems to be an idea that is Catching On (tm). We'll write more about them over the next week or so.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-3333685525732068882?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/3333685525732068882/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=3333685525732068882' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3333685525732068882'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3333685525732068882'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/07/catching-up.html' title='Catching up'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-30828710555619450</id><published>2007-07-10T10:33:00.000-07:00</published><updated>2007-07-10T10:36:45.479-07:00</updated><title type='text'>IE 0-day today</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Thor Larholm announced an IE 0-day today, which works like a champ. See his write-up here... http://larholm.com/2007/07/10/internet-explorer-0day-exploit/ ... &lt;br /&gt;&lt;br /&gt;We have added a sig for it, so our users should be well-protected.&lt;br /&gt;&lt;br /&gt;So far this is not in the Wild, but it is entirely too easy to modify for the Bad Guys to ignore.&lt;br /&gt;&lt;br /&gt;I'm betting about 24 hours.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-30828710555619450?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/30828710555619450/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=30828710555619450' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/30828710555619450'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/30828710555619450'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/07/ie-0-day-today.html' title='IE 0-day today'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-8478707887191906420</id><published>2007-07-02T18:38:00.000-07:00</published><updated>2007-07-02T19:36:44.397-07:00</updated><title type='text'>Dangerous searches - July 1st, 2007</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;I've had a few folks ask off-list how to find these "dangerous searches". The tongue-in-cheek answer is "It's really hard", unless you're running LinkScanner, and then it's still a bit hard. Nearly all the searches that we list here come up on the first or second page of search results, but _sometimes it depends on which search engine you're using_! It's a bit surprising, but even the google searches depend on which countries version of the engine you're searching.&lt;br /&gt;&lt;br /&gt;Never the less, here are some of the entertaining "Dangerous searches" for the last few days...&lt;br /&gt;&lt;br /&gt;"domestic warthog" ... i kid you not&lt;br /&gt;"used building supplies georgia"&lt;br /&gt;"penders grove primary school" ... MDAC exploit - the kids have been hacked&lt;br /&gt;"akai 42 plasma tv review" ... this one can get you a fake codec ... usually a ZLOB rootkit downloader&lt;br /&gt;"kittens" ... still nothing sacred&lt;br /&gt;and &lt;br /&gt;"plane tickets"&lt;br /&gt;&lt;br /&gt;Cheers &lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-8478707887191906420?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/8478707887191906420/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=8478707887191906420' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8478707887191906420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8478707887191906420'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/07/dangerous-searches-july-1st-2007.html' title='Dangerous searches - July 1st, 2007'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5315990635654228995</id><published>2007-06-27T20:19:00.000-07:00</published><updated>2007-06-27T20:38:02.579-07:00</updated><title type='text'>Dangerous searches - June 27, 2007</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;It been a few days, and I thought I'd post the highlights. Over the last few days, it's been dangerous to search for such diverse things as ...&lt;br /&gt;&lt;br /&gt;"music without voice" - WebAttacker2/ Mpack&lt;br /&gt;&lt;br /&gt;"famous cubists" - WebAttacker/ MPack&lt;br /&gt;&lt;br /&gt;"what is the regulation height of a dartboard" - believe it or not, this can get you a fake codec. Is nothing sacred?&lt;br /&gt;&lt;br /&gt;"travel line buses sheffield" - MDAC&lt;br /&gt;&lt;br /&gt;"polly pocket" - MDAC - no, nothing is sacred&lt;br /&gt;&lt;br /&gt;"florida baptist churches" - nope, nothing.&lt;br /&gt;&lt;br /&gt;"blank paper invitation pockets" - WebAttacker2/MPack&lt;br /&gt;&lt;br /&gt;"web counter that works on myspace" - MDAC&lt;br /&gt;&lt;br /&gt;and we don't usually care about p0rno queries, but this one is too funny to ignore...&lt;br /&gt;&lt;br /&gt;"looney toon porn" .... whatever!&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5315990635654228995?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5315990635654228995/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5315990635654228995' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5315990635654228995'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5315990635654228995'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/dangerous-searches-june-27-2007.html' title='Dangerous searches - June 27, 2007'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-2028221450346515835</id><published>2007-06-23T19:15:00.000-07:00</published><updated>2007-06-23T19:45:08.848-07:00</updated><title type='text'>Dangerous searches - June 23, 2007</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;The overall state of play is that there are still two significant attack waves happening. The ecard guys out of the .hk domains have cleaned up their English and prettied up their email a bit. It's now downloading 2mb of something. We're not sure what it is at this point, but it's probably not friendly, and there are still lots of compromised Italian sites launching MPack/ WebAttacker2.&lt;br /&gt;&lt;br /&gt;Here are some of the more interesting (and unexpected) dangerous search terms from the last couple of days...&lt;br /&gt;&lt;br /&gt;"Firefox" ... ! Fortunately, that's only dangerous if you're using Internet Explorer to search for it.&lt;br /&gt;&lt;br /&gt;"watch movies for free" ... wrong selection gets you a WebAttacker2/ Mpack.&lt;br /&gt;&lt;br /&gt;"wallpaper" ... webattacker2/mpack&lt;br /&gt;&lt;br /&gt;"blue book" ... is still dangerous. That's been about a week now, which is unusual. Most of these get cleaned up quite quickly.&lt;br /&gt;&lt;br /&gt;"stem cell research"... that's a bit mean&lt;br /&gt;&lt;br /&gt;"bulgarian mp3 music download" ... that's too easy (JUST KIDDING!)&lt;br /&gt;&lt;br /&gt;and "radio blogs" ... wrong choice gets an MDAC.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-2028221450346515835?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/2028221450346515835/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=2028221450346515835' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2028221450346515835'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2028221450346515835'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/dangerous-searches-june-23-2007.html' title='Dangerous searches - June 23, 2007'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5680722413714899325</id><published>2007-06-20T19:19:00.000-07:00</published><updated>2007-06-20T19:43:31.699-07:00</updated><title type='text'>Dangerous searches - June 20, 2007</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;I'd stopped tracking this stuff because I thought no one cared, but emails I've had off-list have convinced me otherwise. I think it's _really_ interesting to see what innocent searches can get you into trouble, and we're happy to share. I've also had the question off-list "Does this mean you track all your user's queries?" to which the answer is "Heck no!", but we do track the queries that result in exploit attempts. This is what we _do_. We couldn't care less who _you_ are and what queries _you_ make, but we sure want to know who tries to bite you! This is our job!&lt;br /&gt;&lt;br /&gt;Here are the most interesting dangerous searches for the last few days...&lt;br /&gt;&lt;br /&gt;"go karts" - wrong selection gets an MDAC exploit&lt;br /&gt;&lt;br /&gt;almost any national park in the southwest is still dangerous, rattlesnakes not withstanding&lt;br /&gt;&lt;br /&gt;"texas tea slots online" - wrong selection gets an MDAC&lt;br /&gt;&lt;br /&gt;"insurance australia" - clearly that's dangerous ;-) ... the wrong result looks to be just an Orphaned Lure, but you can never be sure about Orphans.&lt;br /&gt;&lt;br /&gt;"cannot find server" - clearly _that's_ dangerous! ... wrong  selection gets a WebAttacker/ Mpack.&lt;br /&gt;&lt;br /&gt;"top wallpapers" gets an MDAC&lt;br /&gt;&lt;br /&gt;"free lottery" gets an Orphaned Lure&lt;br /&gt;&lt;br /&gt;As someone famous once said "There's a million of them"&lt;br /&gt;&lt;br /&gt;Of course, there are also _lots_ of Italian references which we don't understand, but which are hitting WebAttacker/ Mpacks.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5680722413714899325?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5680722413714899325/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5680722413714899325' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5680722413714899325'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5680722413714899325'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/dangerous-searches-june-20-2007.html' title='Dangerous searches - June 20, 2007'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-3854242723520600764</id><published>2007-06-18T13:11:00.000-07:00</published><updated>2007-06-18T13:39:01.402-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='two attack waves italy'/><title type='text'>Two pretty good attack waves</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;At the moment,it appears there are two determined but separate waves of attack underway. One involves a large number of hacked websites, seemingly in Italy, which are iframed and reaching back to an MPack/ WebAttacker exploit server (or servers), and the second is the continuing wave of allenged greeting cards, mostly from .hk domains. This second one is the one we blogged about over the weekend that uses an ani together with a circa-2005 exploit... sort of a sublime and a ridiculous thing simultaneously.&lt;br /&gt;&lt;br /&gt;Of course, LinkScanner detects it all just fine.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-3854242723520600764?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/3854242723520600764/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=3854242723520600764' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3854242723520600764'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3854242723520600764'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/two-pretty-good-attack-waves.html' title='Two pretty good attack waves'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-3829728826897335622</id><published>2007-06-16T19:39:00.000-07:00</published><updated>2007-06-16T19:50:30.318-07:00</updated><title type='text'>New attack underway</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;There is a significant attack run underway over the weekend. It involves a spam run telling people they have a Greeting Card, not that this is a new tactic, but it involves a seemingly large number of .hk domains. If you click the link to view the card, it throws an ANI exploit, which is new-ish (patched in April 2007), and ms06-042, which is old-ish (patched in October 2006), and an ms05-052!!! I have no idea when that was patched except that it was 2005 sometime, and if someone has not patched since then... well... they have a name for people like that... serially pwned.&lt;br /&gt;&lt;br /&gt;If it manages to nail you, it installs a downloader for which av detection is low, and it, in turn, downloads a rootkit for which av detection is _very_ low.&lt;br /&gt;&lt;br /&gt;What this all means is that the weird thing is the use of a two year old exploit, that we have not seen in use anywhere else until now. Go figure.&lt;br /&gt;&lt;br /&gt;If you're patched, or are running LinkScanner, all is well.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-3829728826897335622?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/3829728826897335622/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=3829728826897335622' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3829728826897335622'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3829728826897335622'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/new-attack-underway.html' title='New attack underway'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-2322854514388373490</id><published>2007-06-14T19:04:00.000-07:00</published><updated>2007-06-14T19:23:26.525-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='dangerous searchers'/><title type='text'>Dangerous searches June 14th 2007</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Today it's dangerous to search for &lt;br /&gt;&lt;br /&gt;atlas mountains country ... (wrong result gets you a WebAttacker 2 or MPack)&lt;br /&gt;&lt;br /&gt;rotweiller rescue&lt;br /&gt;&lt;br /&gt;North Padre Island (WebAttacker 2 or Mpack)&lt;br /&gt;&lt;br /&gt;arches national park (WebAttacker 2 or MPack)&lt;br /&gt;&lt;br /&gt;canyonlands national park (in fact, lots of National Parks in that part of the world ... the Badlands can still be dangerous)&lt;br /&gt;&lt;br /&gt;and the mass lottery&lt;br /&gt;&lt;br /&gt;Keep safe&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-2322854514388373490?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/2322854514388373490/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=2322854514388373490' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2322854514388373490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2322854514388373490'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/dangerous-searches-june-14th-2007.html' title='Dangerous searches June 14th 2007'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5457519103270507582</id><published>2007-06-13T19:05:00.000-07:00</published><updated>2007-06-13T19:20:38.341-07:00</updated><title type='text'>Dangerous searches</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Today it's dangerous to search for &lt;br /&gt;&lt;br /&gt;air disasters in Florida (wrong answer will get you a WebAttacker 2)&lt;br /&gt;&lt;br /&gt;cd key windows xp profesional (that's another 'duh!')&lt;br /&gt;&lt;br /&gt;and &lt;br /&gt;&lt;br /&gt;batmobile for sale (does that need a comment?)&lt;br /&gt;&lt;br /&gt;Mostly, it's a quiet day folks. Works for us.&lt;br /&gt;&lt;br /&gt;:-)&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5457519103270507582?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5457519103270507582/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5457519103270507582' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5457519103270507582'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5457519103270507582'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/dangerous-searches_13.html' title='Dangerous searches'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5766366217665583935</id><published>2007-06-12T17:36:00.000-07:00</published><updated>2007-06-12T17:45:00.784-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='dangerous searches'/><title type='text'>Dangerous searches</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Today it's dangerous to search for ...&lt;br /&gt;&lt;br /&gt;victoria's secret (duh! the wrong website here gets you a fake codec)&lt;br /&gt;&lt;br /&gt;pokemon ruby gamesharks (I couldn't make this stuff up)&lt;br /&gt;&lt;br /&gt;blue book (wrong website gets you an mdac exploit)&lt;br /&gt;&lt;br /&gt;bulletin boards in norwich, ct (that'll get you an Orphaned Lure which might not be an orphan)&lt;br /&gt;&lt;br /&gt;and .... music! (webattacker 2 or mpack)&lt;br /&gt;&lt;br /&gt;:-)&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5766366217665583935?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5766366217665583935/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5766366217665583935' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5766366217665583935'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5766366217665583935'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/dangerous-searches_12.html' title='Dangerous searches'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-6906863887300866770</id><published>2007-06-11T18:09:00.000-07:00</published><updated>2007-06-11T18:16:34.076-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='dangerous searches'/><title type='text'>Dangerous searches</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Today it's dangerous to search for IBM stock, pallet fire (what's that???), Nigerian economic and financial crimes (there's a shock), and/ or to find out who's a rat.&lt;br /&gt;&lt;br /&gt;It's left as an exercise to the Attentive Reader (tm) to find the exploitive websites. Anyone running the SearchShield function of LinkScanner should find it easy.&lt;br /&gt;&lt;br /&gt;:-)&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-6906863887300866770?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/6906863887300866770/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=6906863887300866770' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6906863887300866770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6906863887300866770'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/dangerous-searches.html' title='Dangerous searches'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-2032511270623355398</id><published>2007-06-11T13:49:00.000-07:00</published><updated>2007-06-11T14:09:28.485-07:00</updated><title type='text'>A cunning rootkit</title><content type='html'>Ok, I see what they're doing now. &lt;br /&gt;&lt;br /&gt;First some background ... Most rootkits _hide_ themselves from Windows api, and the anti-rootkits _find_ them by looking first with the normal Windows api, and then making another pass of the disk making calls directly to the kernel, and then comparing the lists. If they find a file in the second list that's not in the first, they report it as a hidden and there's a good chance it's a rootkit. This method is far from foolproof, because, for example, files might be legitimately created, say by a Browser, in between passes, and it will look like a hidden file, but it's good enough to provide a clue anyway.&lt;br /&gt;&lt;br /&gt;What's happening with this one is that it is _not_ hidden. It sits in plain sight, and when the cross-viewing anti rootkits compare their lists, they get no differences, and therefore no hidden files, and most declare there to be no rootkit on the system.&lt;br /&gt;&lt;br /&gt;Why is it a rootkit then? Instead of hooking the file list functions, they're hooking the _file open_ functions. If you try to view, or scan, or copy the contents of the rootkit, you get a "file does not exist" error!!! What this means is that even if your scanner has a signature for that rootkit, it probably won't be able to open the file anyway.&lt;br /&gt;&lt;br /&gt;I dunno about you but I think that's pretty cunning!&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-2032511270623355398?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/2032511270623355398/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=2032511270623355398' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2032511270623355398'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2032511270623355398'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/cunning-rootkit.html' title='A cunning rootkit'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-7678088973499847697</id><published>2007-06-10T15:41:00.000-07:00</published><updated>2007-06-10T15:44:02.461-07:00</updated><title type='text'>They swapped it out</title><content type='html'>That's interesting .... the St Petersburg Iframers have swapped out the new rootkit for something old and mouldy that everyone can detect!&lt;br /&gt;&lt;br /&gt;One wonders when the new one will come back.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-7678088973499847697?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/7678088973499847697/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=7678088973499847697' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7678088973499847697'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7678088973499847697'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/they-swapped-it-out.html' title='They swapped it out'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-1606062122795637052</id><published>2007-06-10T07:14:00.000-07:00</published><updated>2007-06-10T07:17:54.528-07:00</updated><title type='text'>Yahoo exploit In The Wild</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Recently a couple of exploits were announced for Yahoo Messenger Webcam dlls, and today there are websites actively using it to install malcode. We don't expect this to be an important or widespread outbreak, but we do expect it to be adopted by the rest of the malicious webmeisters over the next few weeks.&lt;br /&gt;&lt;br /&gt;Naturally, we've added detection for it to LinkScanner.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-1606062122795637052?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/1606062122795637052/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=1606062122795637052' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/1606062122795637052'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/1606062122795637052'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/yahoo-exploit-in-wild.html' title='Yahoo exploit In The Wild'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-4222225781144120734</id><published>2007-06-09T19:58:00.000-07:00</published><updated>2007-06-09T20:09:18.775-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iframers st petersburg rustock rootkit'/><title type='text'>Keep those rootkits out</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;The St Petersburg iframers have a new rootkit. None of the scanners that I have access to can put a name to it so far, and none of the generic cross-viewers that I have can see it, with the exception of GMER, and GMER isn't sure about it.&lt;br /&gt;&lt;br /&gt;That these guys would have something new and difficult is not really surprising... they were using Rustock variants for a long time, which gave most anti virus/ anti spy products a hard time by storing themselves in an Alternate Data Stream and then hiding the ADS, but lots of av/as products can now see in the ADS. It's reasonable to assume they'd move to something newer.&lt;br /&gt;&lt;br /&gt;Somewhat amusingly, they're still using the same exploits to plant it, so if you're patched and/or running LinkScanner, you have nothing to fear, but if you're not ... you don't want to get this one on your system.&lt;br /&gt;&lt;br /&gt;Trust me ... it's better to keep them out than to try to remove them once they're in!&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-4222225781144120734?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/4222225781144120734/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=4222225781144120734' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4222225781144120734'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4222225781144120734'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/keep-those-rootkits-out.html' title='Keep those rootkits out'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-7631619737985088209</id><published>2007-06-07T14:59:00.000-07:00</published><updated>2007-06-07T15:14:48.060-07:00</updated><title type='text'>At least they're honest about ripping you off...</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;One of our users brought this to our attention. A bunch of websites are offering free web-counters. -start channeling Homer- Free? How could I go wrong? I'd have to be an idiot to pass that up. - end channeling Homer-&lt;br /&gt;&lt;br /&gt;Well, if you read the Terms and Conditions, it contains this gem...&lt;br /&gt;&lt;br /&gt;"Possible uses includes (but to are not limited to) &lt;br /&gt;to directory of the sites using our service, the purpose situated &lt;br /&gt;scripts inserted in your web can be used by us for every of profit, &lt;br /&gt;general promotional uses, any purpose of profit, activx, pay Internet,&lt;br /&gt;Dialer, Premium Number, redirect, etc."&lt;br /&gt;&lt;br /&gt;Disregarding the poor English, at least they're telling you what they plan to do to you and your customers!&lt;br /&gt;&lt;br /&gt;Read those EULAs folks!.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-7631619737985088209?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/7631619737985088209/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=7631619737985088209' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7631619737985088209'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7631619737985088209'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/at-least-theyre-honest-about-ripping.html' title='At least they&apos;re honest about ripping you off...'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-1988109977923414034</id><published>2007-06-06T18:55:00.000-07:00</published><updated>2007-06-06T19:18:33.466-07:00</updated><title type='text'>You've got to like it ...</title><content type='html'>when you find the Bad Guys development sites. :-)&lt;br /&gt;&lt;br /&gt;In the last three days, our researchers have found two such sites. We've already added sigs for their efforts. :-) &lt;br /&gt;&lt;br /&gt;Seriously though, I'm fairly confident that we're going thru a quiet period, where the various groups are re-organizing themselves. Some good exploits have surfaced in the last couple of days, and some of them will find their way to websites in the next few weeks.&lt;br /&gt;&lt;br /&gt;We'll be watching, and will keep you posted.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-1988109977923414034?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/1988109977923414034/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=1988109977923414034' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/1988109977923414034'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/1988109977923414034'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/youve-got-to-like-it.html' title='You&apos;ve got to like it ...'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-6496889354776613306</id><published>2007-06-02T08:30:00.000-07:00</published><updated>2007-06-02T08:55:24.238-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='webattacker mpack'/><title type='text'>Exploit-y news</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Thare are two developments worth mentioning.&lt;br /&gt;&lt;br /&gt;First is that we are detecting increased usage of MS07-027. (MS07-027 patched several vulnerabilities, but the one we're seeing in use involves a dll called MDSAUTH which apparantly allows arbitrary file writing). The critical think about this is that it  was only patched on May 8th, however, and the proof of concept code was released and available almost immediately, and it is certainly being used by the Chinese gangs. These guys have a habit of hacking large numbers of innocent websites and turning them into unwitting lures.&lt;br /&gt;&lt;br /&gt;The second is that we are seeing _lots_ of activity involving the MPack exploit package (what we used to call WebAttacker 2). There are clearly large numbers of hacked websites involved here, and the exploit code works really well. This is the package that we've talked about before, and which contains lots of different exploits. The most dangerous are probably WinZip, because there is no automatic upgrade path for WinZip, and many people will still be using a vulnerable version, and the April 2007 animated cursor exploit, simply because it's so new. Many corporates will not be patched to April.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-6496889354776613306?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/6496889354776613306/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=6496889354776613306' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6496889354776613306'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6496889354776613306'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/06/exploit-y-news.html' title='Exploit-y news'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-4503226483362557915</id><published>2007-05-31T17:46:00.000-07:00</published><updated>2007-05-31T18:39:46.420-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='edus porn exploits'/><title type='text'>Everyone knows the Internet is for porn...</title><content type='html'>but did you know our EDUs are too? This is either funny or sad, depending on your point of view, but sooooooo many EDUs turn up in our prevalence data, that you could just about make the case that EDUs are the biggest identifiable segment for porn hosting. &lt;br /&gt;&lt;br /&gt;Here are a few examples of the charming subject matter that we regularly detect in EDUs...&lt;br /&gt;&lt;br /&gt;/incest-porn.html&lt;br /&gt;/porn-videos.html&lt;br /&gt;/mature-porn.html&lt;br /&gt;/ladyboys.html&lt;br /&gt;/teen-sex.html &lt;br /&gt;&lt;br /&gt;Now, the fact that we keep seeing the same directory names on _geographically_ diverse EDUs actually means that the students and EDU's are not doing this deliberately, but rather that it's a deliberate and systematic hacking by some group. These directories are typically full of exploits, and fake codecs, so they're a good place to avoid anyway, but very often they have probable child pornography (LinkScanner is often able to detect kiddie porn by analyzing the html on the page, and preemptively blocks those pages) on them, so they're probably dangerously illegal as well as malicious.&lt;br /&gt;&lt;br /&gt;As much as I'd like to think that EDUs might rise up en masse, and evict all this stuff, and fix their security, I don't like our chances, and I anticipate that they're part of the exploit infrastructure of the web forever.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-4503226483362557915?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/4503226483362557915/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=4503226483362557915' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4503226483362557915'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4503226483362557915'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/05/everyone-knows-internet-is-for-porn.html' title='Everyone knows the Internet is for porn...'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-9166009014526981907</id><published>2007-05-30T08:12:00.000-07:00</published><updated>2007-05-30T08:13:07.704-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mpack webattacker'/><title type='text'>One mystery solved - it's MPACK not WebAttacker2</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;For ages now, we've been seeing certain patterns of exploits, wrapped in distinctive patterns of obfuscation. We saw them start at a particular site in Russia, and gradually spread to _many_ other places, and it was obvious to us that it was being sold as a package. So obvious, in fact, that we blogged about it with the title "WebAttacker is dead, Long live WebAttacker". In other words, there was clearly at least one new kid on the pre-packaged exploit block, but we didn't know what to call it.&lt;br /&gt;&lt;br /&gt;Today we do... it's called MPACK (Thanks to Symantec and Panda for figuring that out). &lt;br /&gt;&lt;br /&gt;It's been interesting to watch the development of this one, as they've added exploits, and changed their encryption. Like WebAttacker, they track the visitors IPs and won't serve the exploits a second time. They used to say "Sorry! You ip is blocked." but now they just display a grumpy face if you come back for a second look.... like this ... :[ .&lt;br /&gt;&lt;br /&gt;At least they have a sense of humor.&lt;br /&gt;&lt;br /&gt;We've seen a real uptick in hacked legit sites pointing to other servers that have been hacked and are now MPACK exploit servers, so everyone should be careful for a bit.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-9166009014526981907?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/9166009014526981907/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=9166009014526981907' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/9166009014526981907'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/9166009014526981907'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/05/one-mystery-solved-its-mpack-not.html' title='One mystery solved - it&apos;s MPACK not WebAttacker2'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5439306301873387279</id><published>2007-05-17T20:36:00.000-07:00</published><updated>2007-05-17T20:47:52.201-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='winzip exploit'/><title type='text'>And I thought I was patched!</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;We got all excited today because one of our fully-patched goat pcs got nailed by a website. (The fact that we got all excited tends to show how sad malware researchers are in general, but that's another matter)&lt;br /&gt;&lt;br /&gt;"0-day!", we thought, but as we examined the packets from our sniffers, we sadly realized that we weren't really fully patched. Turns out we had an old copy of WinZip (yes, licensed!), and this particular website had a WinZip exploit, along with several others.&lt;br /&gt;&lt;br /&gt;This got us to thinking and wondering, however, how many other machines have some third party software that is not patched? Windows is ubiquitous, some third-party software is _almost_ so, and an exploit for a third party package is likely to be just as productive as a windows 0-day.&lt;br /&gt;&lt;br /&gt;The moral of the story, folks, is keep _all_ your software up to date.&lt;br /&gt;&lt;br /&gt;Remember, the Bad Guys don't want to shut down the Internet any more... they don't want to cut down the tree... they just shake it from time to time, and see what apples fall off.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5439306301873387279?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5439306301873387279/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5439306301873387279' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5439306301873387279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5439306301873387279'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/05/and-i-thought-i-was-patched.html' title='And I thought I was patched!'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-4829973594397276309</id><published>2007-05-14T19:39:00.000-07:00</published><updated>2007-05-15T05:38:18.228-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='google adwords driveby downloads'/><title type='text'>Three bags full</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;The title actually bears little relationship to the story... it merely reflects that I have little kids and have been reading too much Mother Goose.&lt;br /&gt;&lt;br /&gt;There are three items I'd like to share though.&lt;br /&gt;&lt;br /&gt;The first is this excellent article by Didier Stevens. See &lt;a href="http://didierstevens.wordpress.com/2007/05/07/is-your-pc-virus-free-get-it-infected-here/"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The nub of this matter is that Didier conducted an experiment where he registered adwords and waited to see how many clicks he'd get. The adwords were variations of "drive by download" and for $23 his ad was displayed 259,723 times over six months, and clicked on 409 times. It's a great article and well worth a read.&lt;br /&gt;&lt;br /&gt;The second item I wanted to share was that the iframecash boyz have now started using .hk domains. It will be interesting to see how this pans out.&lt;br /&gt;&lt;br /&gt;The third item is that, overall, things are pleasantly quiet in the web-based exploit world. We sincerely hope that it's not calm-before-storm stuff.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-4829973594397276309?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/4829973594397276309/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=4829973594397276309' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4829973594397276309'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4829973594397276309'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/05/three-bags-full.html' title='Three bags full'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-2157089478701378172</id><published>2007-05-05T18:36:00.001-07:00</published><updated>2007-05-05T19:32:31.253-07:00</updated><title type='text'>So, Cinco de Mayo is dangerous</title><content type='html'>Hi folks, &lt;br /&gt;&lt;br /&gt;Of course, you could have called that in from your couch. It turns out that these guys, http://freewebcards.com have been hacked. Let me stress that they are not deliberately doing this, but they are now an Innocent Lure. We first noticed them on April 26th, and they fixed it almost immediately, and noted that they were trying to address the problem.&lt;br /&gt;&lt;br /&gt;Today, however, it turned up on SearchShield results. If you search for "what is cinco de mayo" in google, it shows up on the second page with an MDAC injection. See &lt;a href="http://wormradar.com/SearchShield.jpg"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The webpage looks like &lt;br /&gt;&lt;br /&gt;&lt;a href="http://wormradar.com/webpage.jpg"&gt;this&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;and a source view shows a chunk of obfuscated javascript like &lt;a href="http://wormradar.com/PageSource.jpg"&gt;this.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Now, these guys are obviously trying to be careful. See &lt;a href="http://wormradar.com/apr26th.jpg"&gt;this&lt;/a&gt; message from 26th April, where they acknowledged that people were getting at them, and they trying to sort it out, so if these guys can get nailed again within a couple of weeks, _anyone_ can get nailed.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-2157089478701378172?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/2157089478701378172/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=2157089478701378172' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2157089478701378172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/2157089478701378172'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/05/so-cinco-de-mayo-is-dangerous.html' title='So, Cinco de Mayo is dangerous'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-7167950424172333585</id><published>2007-05-01T13:17:00.000-07:00</published><updated>2007-05-01T13:38:12.652-07:00</updated><title type='text'>Nope, they're victims too</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Over the last few days, I've had lots of people asking me questions about the targetted sites, such as Better Business Bureau, with some people thinking mistakenly that the BBB is actually serving exploits to them. That is not the situation at all. BBB (and all the other websites targetted by the scam) had nothing to do with it, and didn't even know their name was being used.&lt;br /&gt;&lt;br /&gt;I've also had lots of people asking me what they can do to stay safe from this sort of thing, and the short answer is (1) patch and (2) install LinkScanner (shameless plug). It's actually worth installing LinkScanner even if you do patch because it's nice to know if a website _tried_ to bite you, even if you were not vulnerable.&lt;br /&gt;&lt;br /&gt;LinkScanner scans all webpages returned by search engines when you do a query, and the Pro version also scans all tcpip traffic in real time anyway. What this means is that even if a bad web page is cunning enough to wait until you actually try to surf to it to launch the exploit, LinkScanner will still see it and block it.&lt;br /&gt;&lt;br /&gt;By the way, we've found some more interesting sponsored links (not google this time), and as soon as we finish documenting them, we'll write about it here.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-7167950424172333585?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/7167950424172333585/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=7167950424172333585' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7167950424172333585'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/7167950424172333585'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/05/nope-theyre-victims-too.html' title='Nope, they&apos;re victims too'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5703375458392944525</id><published>2007-04-27T15:27:00.000-07:00</published><updated>2007-04-27T15:47:05.933-07:00</updated><title type='text'>A video</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;We were fortunate enough to capture some video of the google / BBB / SmartTrack issues. Here is a &lt;a href="http://www.youtube.com/watch?v=iD0wdzQb8XY"&gt;link&lt;/a&gt; if you'd like to watch it.&lt;br /&gt;&lt;br /&gt;and there's a &lt;a href="http://explabs.com/media/movies/nailedin30seconds.mp4"&gt;hi-res version here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5703375458392944525?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5703375458392944525/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5703375458392944525' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5703375458392944525'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5703375458392944525'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/video.html' title='A video'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-107319916147904134</id><published>2007-04-24T11:20:00.000-07:00</published><updated>2007-04-24T17:27:28.488-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='smarttrack bbb exploit'/><title type='text'>Google sponsored links not safe?</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;We've been watching an interesting puzzle for a couple of weeks now, and last night the last couple of pieces fell into place. Since the 10th April, our community intelligence network has been finding exploit detections _seemingly_ at household name sites like the Better Business Bureau and&lt;br /&gt;cars.com but are actually coming from a place called smarttrack.org&lt;br /&gt;masquerading as one of the legit sites.  &lt;br /&gt;&lt;br /&gt;Google searches such as the phrase BetterBusinessBureau OR "Florida Business&lt;br /&gt;Opportunity Law" or "Modern cars airbags required" will turn up these&lt;br /&gt;dangerous sites (more on that below).  Last night our researchers discovered that one of these rogue links was the number 1 sponsored link when people entered the phrase BetterBusinessBureau. See &lt;a href="http://www.explabs.com/CaseStudies/bbb/gs.jpg"&gt;here&lt;/a&gt;. It looks safe, but a mouse-over our red verdict reveals &lt;a href="http://www.explabs.com/CaseStudies/bbb/gs2.jpg"&gt;the truth&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;It sure looks like it will take you to a BBB website, and that's where you end up. Here's a screensnap of the &lt;a href="http://www.explabs.com/CaseStudies/bbb/result.jpg"&gt;result&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;First, however, it takes the unwary traveler through smarttrack.org, which uses a modified MDAC exploit to try to install a backdoor and a post-logger on your system. The post-logger is specifically targeting about 100 banks from around the world, by injecting extra html into those banks response pages, to try to coax extra information out of the victim. (Although it specifically targets those 100, it is an equal-opportunity logger and happily logs all user ids and passwords for any webpage.)&lt;br /&gt;&lt;br /&gt;Also, because the post logger is a browser helper object, it is part of the end-point of any SSL transaction, and can see everything in plain text, instead of encrypted.&lt;br /&gt;&lt;br /&gt;Now, lots of links in any search engine point to infective sites, so that's not really a surprise, but this does highlight a significant issue. When you move the mouse over a normal, organic search result, google shows the url you are about to navigate to if you click. See &lt;a href="http://www.explabs.com/CaseStudies/bbb/gsh.jpg"&gt;here&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;If, however, you mouse-over a sponsored result, no URL preview is shown! This means that a user has no clue where she is about to navigate to. See &lt;a href="http://www.explabs.com/CaseStudies/bbb/gnh.jpg"&gt;here&lt;/a&gt;. Savvy search engine users will know that often these sponsored links will take you through a &lt;br /&gt;'Click-manager' or other advertising service and so seeing your browser pass&lt;br /&gt;through smarttrack.org will appear benign enough.&lt;br /&gt;&lt;br /&gt;Fortunately, google seems to have terminated that account as of about 11am est, but we detected about 20 different search strings that resulted in links to smarttrack.org, so it is not yet clear if all the links have been cleared up, but LinkScanner and SearchShield will surely reveal that over the next few days.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-107319916147904134?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/107319916147904134/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=107319916147904134' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/107319916147904134'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/107319916147904134'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/google-sponsored-links-not-safe.html' title='Google sponsored links not safe?'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-1262407037314379901</id><published>2007-04-22T19:04:00.000-07:00</published><updated>2007-04-22T19:28:43.653-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='k1 martial arts exploit'/><title type='text'>A real knockout website</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;One of the most entertaining features of our product is SearchShield. LinkScanner is able to fold into both Internet Explorer and Firefox and is able to pre-scan search results for google, yahoo and msn. It takes a little bit longer, because it physically has to go fetch all the webpages and scan them, but it's so much fun to watch it's worth installing it just for the entertainment value. Exploitive websites are really hard to find, but they pop up when they are entirely unexpected (which is why databased solutions can never keep up with a programmatic solution). Time after time, you'll be searching for something innocent, and bam!... something unexpectedly gets marked with our famous red X.&lt;br /&gt;&lt;br /&gt;For example, a simple google for K1 turns up an exploitive site as the first result.&lt;br /&gt;(WARNING! Don't go to any of these sites unless you really know what you're doing)&lt;br /&gt;&lt;br /&gt;It seems that K1 is shorthand for a form of Ultimate Fighting, and this one, www.k-1usa.net, is infected by the Chinese WoW hackers. &lt;br /&gt;&lt;br /&gt;There's some irony in real martial artist warriors being impacted by virtual reality World Of Warcraft players. &lt;br /&gt;&lt;br /&gt;I can't help but feel that the K1 guys would like five minutes with the World of Warcraft guys.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-1262407037314379901?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/1262407037314379901/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=1262407037314379901' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/1262407037314379901'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/1262407037314379901'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/real-knockout-website.html' title='A real knockout website'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-6638319392815832220</id><published>2007-04-20T16:10:00.000-07:00</published><updated>2007-04-20T17:26:22.193-07:00</updated><title type='text'>WebAttacker is dead, long live WebAttacker</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Anyone who has read my blog knows that I thought WebAttacker was an interesting bit of software. For those who haven't read my blog, WebAttacker was a Russian-built canned-exploit package. For a few hundred bucks, you too Mr Lamer could be a Malicious Webmeister by adding WebAttacker to your website. Each month, the WA authors would add the best new exploits to their package, and provide an update to their clients. The wheels started to fall off for them in September 2006, when their attempt to add the vml 0-day failed miserably, and they failed again the next month to add the October 0-day (XML exploit, from memory). They made no attempt that I could find to release an update after that, and I decided that they went the way of all software developers whose products failed.&lt;br /&gt;&lt;br /&gt;At about the same time, we began to find what we called the Q4-06 Exploit Rollup Package. This was a javascript containing all the nifty exploits from September and October 2006 (SetSlice, VML, MS06-042, XML, Daxctle), sometimes in plain text, and sometimes encrypted. Being available as plain javascript, it was free, easy to modify and was quickly and widely adopted. &lt;br /&gt;&lt;br /&gt;There was one version, however, that stood out from the others, principally because it was well encrypted, _and_ it tracked visiting ips, ala WebAttacker. If you came back to the same exploit website,from the same machine, it would refuse to re-serve the exploit, and would instead display "Sorry! You ip is blocked." (Yes, bad grammer and all). We have long seen that specific error message associated with a particular exploit hub in Russia (Stela-something ... those who know, know who we mean) , and it was no surprise to see them upgrade to the newest exploits, but the kicker is this...&lt;br /&gt;&lt;br /&gt;We now see that exact error message coming from _many_ exploit websites. That means that the backend part of this is finding its way to other websites. That's significant. You can easily copy the client portion, but you cannot get hold of the server part unless someone wants you to. Either the Stela folks have been hacked themselves... or _they're_ selling the package, perhaps to fill the void left by the WebAttacker departure! Hence WebAttacker is dead, long live WebAttacker.&lt;br /&gt;&lt;br /&gt;These are interesting days folks.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-6638319392815832220?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/6638319392815832220/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=6638319392815832220' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6638319392815832220'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/6638319392815832220'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/webattacker-is-dead-long-live.html' title='WebAttacker is dead, long live WebAttacker'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-3903544244320686162</id><published>2007-04-17T19:54:00.000-07:00</published><updated>2007-04-18T10:21:58.766-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='malicious website exploit'/><title type='text'>The world is changing</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;A couple of months ago, someone asked me what was happening in the malicious website world, and I replied that I thought it was all changing, but I wasn't sure how. &lt;br /&gt;&lt;br /&gt;It has changed, but it's still not clear how much, but here's what we're seeing.&lt;br /&gt;&lt;br /&gt;The first notable change is geographic. A year ago, we would have said that 90% of the malicious website activity was Russian based. Today, those guys are still there, but we now have huge activity from China, Morocco, Brazil and France as well, and the Russian component is probably less than 30%.&lt;br /&gt;&lt;br /&gt;The second change is the sheer volume of attacks. If you don't believe me, go google for .cn/1.js, and see how many results are returned. (WARNING!!! Don't go to any of the result websites, unless you're well protected by LinkScanner, or you're patched). Today, you get about 60,000 hits, and a week ago, it was about 120,000. Now, this is not _proof_ of anything, because some of the returned results are now clean, and some have never been infected in the first place, but it does give an indication of the scope of the problem because 1.js is just one example of one of the recent Chinese attack scripts, and there are _lots_ of other ones.&lt;br /&gt;&lt;br /&gt;The third change is the reduction of adware. I guess there's still lots of it, but it doesn't seem to figure as prominantly in the malicious website equation. It used to be that the first thing a malicious website did when it nailed you was to install 20mb of adware (usually the variety that paid commissions per install), followed by keylogger/ rootkit, and a pitch for a fake antispy to remove it all (for just $49.95). Now we just see the keylogger/ rootkit, and sometimes the pitch for the fake antispy.&lt;br /&gt;&lt;br /&gt;In other words, the whole idea of malicious websites seems to be Catching On (tm), and the payloads are less innocent, and more overtly criminal.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-3903544244320686162?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/3903544244320686162/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=3903544244320686162' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3903544244320686162'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3903544244320686162'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/world-has-changing.html' title='The world is changing'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-5195447300153719156</id><published>2007-04-13T19:11:00.000-07:00</published><updated>2007-04-13T19:44:41.809-07:00</updated><title type='text'>An orphan no longer</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;One of the more interesting ideas that we monitor is that of an Orphaned Lure. That's where you have some site that has been hacked,  and made into an Innocent Lure, but then the exploit server is offline. The Lure is now an orphan, but in a macabre parody of a B-grade horror movie the exploit serves can come back to life, and start serving exploits again.&lt;br /&gt;&lt;br /&gt;This has happened tonight.&lt;br /&gt;&lt;br /&gt;One of the common hacks that we see is an injection of some unescaped code that starts like this ...&lt;br /&gt;&lt;br /&gt;&lt; s c ript language="j a vascript"&gt; document.write( unescape( '%3C%69%66%72%61%6D etc&lt;br /&gt;&lt;br /&gt;When you decrypt this, it resolves to something like this ...&lt;br /&gt;&lt;br /&gt;&lt; iframe src=hxxp:// 81.95.nnn.nn/index.html&lt;br /&gt;&lt;br /&gt;where nnn.nn is a substitute to save people from accidently hurting themselves.&lt;br /&gt;&lt;br /&gt;This ip has been offline for at least a month, maybe two, but tonight it is live again, and serving stuff.&lt;br /&gt;&lt;br /&gt;The moral of the story is that you cannot trust a hacked site. The lure in this case is a hairdressing salon.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-5195447300153719156?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/5195447300153719156/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=5195447300153719156' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5195447300153719156'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/5195447300153719156'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/orphan-no-longer.html' title='An orphan no longer'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-4185509248034205195</id><published>2007-04-11T19:08:00.000-07:00</published><updated>2007-04-11T19:22:23.219-07:00</updated><title type='text'>ANI and WoW stuff</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;I've had a flurry of emails and instant messages that have caused me to realize that I have not explained something properly. The thing that I have not explained is that, almost certainly, the ANI exploit was discovered by some Chinese college student who wanted to steal World Of Warcraft passwords,  (That must surely narrow it down to a mere half a million suspects, so he must be almost caught now ;) ) and these are the same guys that earlier hacked the Superbowl website, and who have been using the very effective RDS version of MDAC (infective up to and including August 2006 patch) and the January 2007 version of the VML exploit. In other words, these guys are kids, but exceptionally smart and exceptionally dangerous. (And, yes, we're fairly sure we know who he is, but that's another matter)&lt;br /&gt;&lt;br /&gt;Now, of course, all the Serious Bad Guys on the Internet have gone "Whoa... this works great! I'll have one of those!" and have adopted the ANI exploit for reasons far more nefarious than simple WoW password stealing, but that does nothing to change the fact that the most dangerous exploit to be released on the Internet so far in 2007 was discovered by someone whose sole intent was stealing passwords for some online game.&lt;br /&gt;&lt;br /&gt;Is this a great Internet, or what???&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-4185509248034205195?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/4185509248034205195/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=4185509248034205195' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4185509248034205195'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/4185509248034205195'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/ani-and-wow-stuff.html' title='ANI and WoW stuff'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-799521212573210378</id><published>2007-04-10T19:02:00.000-07:00</published><updated>2007-04-10T19:03:37.107-07:00</updated><title type='text'>ASUS again???</title><content type='html'>Hi folks,&lt;br /&gt;Ok .... that's weird .... asus.com.tw and several other asus web sites have been unavailable for at least two hours now. That's strange, to say the least. I wonder why?&lt;br /&gt;Cheers&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-799521212573210378?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/799521212573210378/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=799521212573210378' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/799521212573210378'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/799521212573210378'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/asus-again.html' title='ASUS again???'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-3775454705830658258</id><published>2007-04-10T16:03:00.000-07:00</published><updated>2007-04-10T16:09:44.016-07:00</updated><title type='text'>An interesting hacked site + a couple of hours</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;"Shout outs" to the webmeisters at &lt;a href="http://www.pocketpcmag.com"&gt;http://www.pocketpcmag.com&lt;/a&gt;... their website is now clean. They responded to our notification email almost immediately and found and cleaned up the problem within a couple of hours.&lt;br /&gt;&lt;br /&gt;This is a stark contrast to most of these events where the webmeisters not only ignore our notifications, but (or perhaps because of that) remain infective for weeks or even months. _Anyone_ can get hacked... the issue then becomes _responding_ appropriately.&lt;br /&gt;&lt;br /&gt;Well done and cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-3775454705830658258?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/3775454705830658258/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=3775454705830658258' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3775454705830658258'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/3775454705830658258'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/interesting-hacked-site-couple-of-hours.html' title='An interesting hacked site + a couple of hours'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-278125427171930729</id><published>2007-04-10T10:45:00.000-07:00</published><updated>2007-04-10T11:03:16.057-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='lure'/><category scheme='http://www.blogger.com/atom/ns#' term='exploit'/><title type='text'>An interesting hacked site</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;On the heels of the asus.com.tw hack, here is another example of how even an obviously well designed and well used website can be hacked.&lt;br /&gt;&lt;br /&gt;At least two of the pages on hxxp://www.pocketpcmag.com (the website owner has been notified) are hacked with iframes pointing to some of the well known Chinese exploit servers. Interestingly, it seems like it's a recent hack, because the google cache of the now-infected pages shows them as clean on Apr 3rd 2007.&lt;br /&gt;&lt;br /&gt;If you thought you were safe because you never visited Chinese websites, think again. :-)&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-278125427171930729?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/278125427171930729/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=278125427171930729' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/278125427171930729'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/278125427171930729'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/interesting-hacked-site.html' title='An interesting hacked site'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-8923511266940452926</id><published>2007-04-09T18:27:00.000-07:00</published><updated>2007-04-09T19:03:23.134-07:00</updated><title type='text'>ANI - Monday Apr 9th</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Things seem to have settled down in that all the major exploitive web groups seem to have picked up the ANI exploit, and it's now part of the general exploit fabric of the web.&lt;br /&gt;&lt;br /&gt;By this we mean that there probably won't be any more surprises with this one, and it will now follow the pattern that we see with the other web exploits... major bad guys will continue trying to find ways to hide their use of it, minor bad guys will continue to adopt it as they figure it out... spammers and malicious e-carders will continue to send it out for whatever it produces for them. Anyone who's patched or is running something like LinkScanner is pretty safe.&lt;br /&gt;&lt;br /&gt;Interestingly, these guys (spammers and ecarders) will now mostly catch corporate victims because corporates tend not to patch automatically.... they break too many mission-critical systems with automatic patching. They rely instead, on their corporate av and firewalls to protect them, and the bad guys know how to bypass av any time they like, and firewalls are no protection against web exploits, because the browser creates an instant tunnel right thru them.&lt;br /&gt;&lt;br /&gt;A lot of people do their online banking at work (not to mention checking their MySpace or Hotmail accounts), exactly because they think they're safer at work protected by the corporate av and firewall, only to find out that it was not so.  Given the predilection of the recent Chinese gangs for installing rootkits and network sniffers, that cannot be a happy outcome for a corporation.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-8923511266940452926?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/8923511266940452926/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=8923511266940452926' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8923511266940452926'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/8923511266940452926'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/ani-monday-apr-9th.html' title='ANI - Monday Apr 9th'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-117604091367105090</id><published>2007-04-08T06:11:00.000-07:00</published><updated>2007-04-08T07:01:53.683-07:00</updated><title type='text'>ANI - Sunday morning - Phax Phishing continues</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We've now received some more reports of Phax Phishing (that's where they send you a fax and try to convince you to visit an exploitive URL on your pc), and while we find it highly amusing, I guess it must work at least a bit or the Bad Guys wouldn't keep doing it. What this means is ... watch out for faxes. :-)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;ANI-serving websites continue to pop up all over, but the Chinese websites deserve a special mention because of the convoluted nature of the hacks. When we find hacked websites, it's quite common to find they've been hacked multiple times, usually by different gangs, but sometimes multiple times by the same gang (which is also amusing, as well as instructive, because it proves that the hacks are automated .... human beings are not doing it by hand), but the hacked Chinese websites are _impressively_  cross hacked.&lt;br /&gt;&lt;br /&gt;They're all using the same exploit combination... MS06-014 (modified to infect up to and including an August 2006 patch), MS07-004, and the ANI exploit... so the cross-hacks don't raise the danger much as far as regular web surfers are concerned, but do they make it difficult for researchers to categorize and understand. We can typicially figure out who we're dealing with by examining which exploit combinations are being used, together with how they're encrypted, together with the payload, but the cross-hacks, with their sheer volumes, make it really tough going, albeit _very_ interesting.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-117604091367105090?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/117604091367105090/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=117604091367105090' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117604091367105090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117604091367105090'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/ani-sunday-morning-phax-phishing.html' title='ANI - Sunday morning - Phax Phishing continues'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-117589236270930392</id><published>2007-04-06T12:53:00.000-07:00</published><updated>2007-04-06T13:46:02.720-07:00</updated><title type='text'>ANI - Friday afternoon</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Two interesting things have happened today.&lt;br /&gt;&lt;br /&gt;First, is (and probably lots of people already know this, but ) that sometime in the last few days, it appears that the Taiwanese site for ASUS was hacked, and an iframe to an ANI inserted. Fortunately, the site where it was trying to download the exe from is now offline, but the iframe is still in the ASUS site, so one needs to be careful. It's now officially an Orphaned Lure. &lt;br /&gt;&lt;br /&gt;Second is that I've now heard of a second target being phished by fax! The victim has to read the fax, and go type a URL into a browser. The URL has the same version of the exploit package that I wrote about a few days ago in association with the Britney Spears spam run... an ANI, a SetSlice, a winzip, a quicktime, an MS06-042, and a VML. It's a bit like a Moron Virus (that's where you have to copy the virus onto each file yourself, because the virus writer was too dumb to do it programatically)&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-117589236270930392?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/117589236270930392/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=117589236270930392' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117589236270930392'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117589236270930392'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/ani-friday-afternoon.html' title='ANI - Friday afternoon'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-117582948928411553</id><published>2007-04-05T20:05:00.000-07:00</published><updated>2007-04-05T20:18:09.300-07:00</updated><title type='text'>ANI -Thursday evening ... late</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Although the number of infected websites is continuing to grow, we feel we have the outbreak contained, at least as far as our users are concerned, and we're starting to look at the many and varied payloads.&lt;br /&gt;&lt;br /&gt;The most interesting thing we've seen so far is one that is a genuine virus (in other words, it infects other files really well). That is unusual enough, but it also installs a network packet sniffer, _and_ it installs a copy of the Microsoft Platform SDK... 14,500 files over 1.1gb. At this point, we have absolutely no idea why they would do that. It just doesn't make sense.&lt;br /&gt;&lt;br /&gt;You could understand making something viral, and you could understand why the virus might also install a network sniffer, but then to download 1.1gb of SDK is hardly subtle, and tends to give the game away a bit. Also interesting is that some of the infected files call _frequently_ to a url containing MsnPortalHome, which _looks_ like adware. All very odd.&lt;br /&gt;&lt;br /&gt;We'll post more as we find out!&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-117582948928411553?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/117582948928411553/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=117582948928411553' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117582948928411553'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117582948928411553'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/ani-thursday-evening-late.html' title='ANI -Thursday evening ... late'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-117579940305393844</id><published>2007-04-05T11:56:00.000-07:00</published><updated>2007-04-05T11:56:43.066-07:00</updated><title type='text'>ANI - Thursday morning</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Overnight we discovered that the group that we call TriModers (so called, be cause when we first noticed them, they were using a package of three exploits), is now attempting to use an ANI exploit. Their vesion is currently broken, and I'm not going to tell them how to fix it, but I expect they'll get it working soon, and we can add their farms to the list of villains using it.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-117579940305393844?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/117579940305393844/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=117579940305393844' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117579940305393844'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117579940305393844'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/ani-thursday-morning.html' title='ANI - Thursday morning'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-117573290802662996</id><published>2007-04-04T17:24:00.000-07:00</published><updated>2007-04-04T17:28:28.036-07:00</updated><title type='text'>ANI Wed evening</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;Well, the official patch is out, but the use of the ANI exploit continues to grow. Significant numbers of exploit servers and their lures continue to be found, mostly in China and Russia.&lt;br /&gt;&lt;br /&gt;On a slightly different note, someone asked me recently how to measure the importance of a web-based exploit problem, and I thought it was a fair question. When you have a network worm or mass-mailing worm, it's fairly easy to guage the size of the outbreak, simply by watching your firewall logs, or by looking at what comes into your InBox. &lt;br /&gt;&lt;br /&gt;Web-based stuff is much more subtle. They rarely come looking for you, but rely on their network of Lures to draw you in. For example, a single exploit server I looked at recently had fifty IP addresses that called directly to it. Each of those fifty (which were under the direct control of the owner of the exploit server) had about 300 domains on it.  If you assume that each of those domains had just ten external links in, from open blogs, or hacked sites, that made 150,000 ways to be drawn to the exploit, with just a couple of unwary surfs. If they could create 100 first generation links in, that would be 1.5m. It mounts up quickly. &lt;br /&gt;&lt;br /&gt;Not only that, but a frequent target of the exploiters is to hack into an unwitting small business website, like a resaurant or a mortgage broker. They're always poorly defended, but the owner is usually canny enough to try to create many links into her website. Some potential diner tries to find out what's on the menu, and gets a belly full of rootkit instead.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-117573290802662996?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/117573290802662996/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=117573290802662996' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117573290802662996'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117573290802662996'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/ani-wed-evening.html' title='ANI Wed evening'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-117563866001887817</id><published>2007-04-03T15:17:00.000-07:00</published><updated>2007-04-03T15:17:40.030-07:00</updated><title type='text'>ANI Tues afternoon+10 minutes</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;I just swung by some iframer lures, and guess what .... they're now infective with the ANI 0-day. Not sure what that payload is yet, but they usually install a Rustok rootkit. They have a strong and large system of Lures, so this is a pretty good escalation of events. Good thing the patch came out today.&lt;br /&gt;&lt;br /&gt;Naturally, LinkScanner users have little to fear, as it detects all the variants so far.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-117563866001887817?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/117563866001887817/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=117563866001887817' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117563866001887817'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117563866001887817'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/ani-tues-afternoon10-minutes.html' title='ANI Tues afternoon+10 minutes'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-117563756062814593</id><published>2007-04-03T10:11:00.000-07:00</published><updated>2007-04-03T14:59:20.653-07:00</updated><title type='text'>ANI Tuesday afternoon</title><content type='html'>Hi folks,&lt;br /&gt;&lt;br /&gt;It's Tuesday afternoon about 6pm est. It's been an exceptionally busy day, but here are the main points so far.&lt;br /&gt;&lt;br /&gt;(1) ANI exploits continue to be spammed out, mostly disguised as Britney pictures, mostly installing spam engines and backdoors.&lt;br /&gt;&lt;br /&gt;(2) There are quite large numbers of hacked websites, mostly Chinese, installing a considerable variety of payloads, some of which are viral. We're analysing them now.&lt;br /&gt;&lt;br /&gt;All very interesting.&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-117563756062814593?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/117563756062814593/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=117563756062814593' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117563756062814593'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117563756062814593'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/ani-tuesday-afternoon.html' title='ANI Tuesday afternoon'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-26689187.post-117556760488465201</id><published>2007-04-02T19:32:00.000-07:00</published><updated>2007-04-02T19:33:24.896-07:00</updated><title type='text'>ANI last entry for Monday</title><content type='html'>We now have some more details about the payload of this exploit spam run. It downloads a 36k progam called 200.exe. When run, 200.exe writes itself back out as Winlogon.exe, and adds itself to HKCU... CurrentVersion\Run to ensure it gets into the execution cycle on reboot.&lt;br /&gt;&lt;br /&gt;When it runs, it emails out to a hotmail account, presumably to announce that the victim has been 0wned, and then calls out to a different server on port 80 every five minutes, presumably looking for commands. In other words, it's a bot / backdoor. Oh, and it's a rootkit.&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;&lt;br /&gt;Roger&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/26689187-117556760488465201?l=explabs.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://explabs.blogspot.com/feeds/117556760488465201/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=26689187&amp;postID=117556760488465201' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117556760488465201'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/26689187/posts/default/117556760488465201'/><link rel='alternate' type='text/html' href='http://explabs.blogspot.com/2007/04/ani-last-entry-for-monday.html' title='ANI last entry for Monday'/><author><name>Roger Thompson</name><uri>http://www.blogger.com/profile/16820150960002669874</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='23' height='32' src='http://4.bp.blogspot.com/-izIORnhF9sE/ThJUleD6j7I/AAAAAAAAALw/ZTBZa5rbfSI/s1600/rjt.jpg'/></author><thr:total>0</thr:total></entry></feed>
