<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Mischel Internet Security - Blog</title>
	<atom:link href="http://blog.misec.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.misec.net</link>
	<description>The latest in security - from the developers of TrojanHunter</description>
	<pubDate>Tue, 21 Oct 2008 18:10:29 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>McAfee Flagging TrojanHunter Installation as Malicious</title>
		<link>http://blog.misec.net/2008/10/21/mcafee-flagging-trojanhunter-installation-as-malicious/</link>
		<comments>http://blog.misec.net/2008/10/21/mcafee-flagging-trojanhunter-installation-as-malicious/#comments</comments>
		<pubDate>Tue, 21 Oct 2008 18:10:06 +0000</pubDate>
		<dc:creator>Magnus</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://misec.wordpress.com/?p=120</guid>
		<description><![CDATA[McAfee VirusScan has now been (incorrectly) flagging a file installed with TrojanHunter as malware for several weeks. We have contacted McAfee to get them to fix this false positive, but so far to no avail. One has to wonder if McAfee are doing a little creative &#8220;competition control&#8221; as they haven&#8217;t bothered replying to or [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>McAfee VirusScan has now been (incorrectly) flagging a file installed with TrojanHunter as malware for several weeks. We have contacted McAfee to get them to fix this false positive, but so far to no avail. One has to wonder if McAfee are doing a little creative &#8220;competition control&#8221; as they haven&#8217;t bothered replying to or taking action on our false positive report. No doubt several of their users must have contacted them about this as well by now.</p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/misec.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/misec.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/misec.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/misec.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/misec.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/misec.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/misec.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/misec.wordpress.com/120/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/misec.wordpress.com/120/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/misec.wordpress.com/120/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.misec.net&blog=1445666&post=120&subd=misec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.misec.net/2008/10/21/mcafee-flagging-trojanhunter-installation-as-malicious/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Support Requests&#8230; How Not to Compose Them</title>
		<link>http://blog.misec.net/2008/10/08/support-requests-how-not-to-compose-them/</link>
		<comments>http://blog.misec.net/2008/10/08/support-requests-how-not-to-compose-them/#comments</comments>
		<pubDate>Wed, 08 Oct 2008 14:15:29 +0000</pubDate>
		<dc:creator>Magnus</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://misec.wordpress.com/?p=118</guid>
		<description><![CDATA[People, if you&#8217;re emailing the technical support address because you have a problem with some software, here is a great example of what not to write:
I&#8217;m having a problem with the program.
While I&#8217;m sure some support technicians love Zen koans as much as the next guy, you might want to clarify exactly what problem you [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>People, if you&#8217;re emailing the technical support address because you have a problem with some software, here is a great example of what <i>not</i> to write:</p>
<blockquote><p><i>I&#8217;m having a problem with the program.</i></p></blockquote>
<p>While I&#8217;m sure some support technicians love Zen koans as much as the next guy, you might want to clarify exactly <i>what</i> problem you have running the program. All the above will lead to is another email where the support technician has to get back to you and ask what exactly the problem is.</p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/misec.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/misec.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/misec.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/misec.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/misec.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/misec.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/misec.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/misec.wordpress.com/118/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/misec.wordpress.com/118/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/misec.wordpress.com/118/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.misec.net&blog=1445666&post=118&subd=misec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.misec.net/2008/10/08/support-requests-how-not-to-compose-them/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Total Secure 2009 - New Heights of Being Annoying (With Removal Guide)</title>
		<link>http://blog.misec.net/2008/10/02/total-secure-2009-new-heights-of-being-annoying-with-removal-guide/</link>
		<comments>http://blog.misec.net/2008/10/02/total-secure-2009-new-heights-of-being-annoying-with-removal-guide/#comments</comments>
		<pubDate>Thu, 02 Oct 2008 14:44:19 +0000</pubDate>
		<dc:creator>Magnus</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://misec.wordpress.com/?p=116</guid>
		<description><![CDATA[Total Secure 2009 is a rogue anti-malware product (meaning it floods you with fake alerts about malware that you don&#8217;t actually have on your system). While analyzing the product for inclusion in the TrojanHunter detection database I experienced the annoying effects of this program first-hand.
There are lots of removal guides out there, but most of [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Total Secure 2009 is a rogue anti-malware product (meaning it floods you with fake alerts about malware that you don&#8217;t actually have on your system). While analyzing the product for inclusion in the TrojanHunter detection database I experienced the annoying effects of this program first-hand.</p>
<p>There are lots of removal guides out there, but most of them miss a crucial file. This is a DLL file that is loaded into explorer.exe and causes incredibly annoying &#8220;warning&#8221; messages to appear when you browse folders in Windows Explorer. For all practical purposes it makes Windows Explorer useless.</p>
<p>The latest variants place the offending DLL file in C:\Windows\system32\ with the name <b>sysbase32.dll</b>. Note that it is difficult to remove this file manually while loaded into explorer.exe. I recommend booting into Safe Mode and removing the entire Total Secure 2009 folder from there, as well as the DLL file. The DLL file also changes names between releases, so use a signature-based scanning product like <a href="http://www.misec.net/trojanhunter">TrojanHunter</a> to detect and remove it. Note that TrojanHunter is able to unload and remove the DLL file from a running system which is something that no other program is able to do at the moment.</p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/misec.wordpress.com/116/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/misec.wordpress.com/116/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/misec.wordpress.com/116/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/misec.wordpress.com/116/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/misec.wordpress.com/116/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/misec.wordpress.com/116/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/misec.wordpress.com/116/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/misec.wordpress.com/116/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/misec.wordpress.com/116/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/misec.wordpress.com/116/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.misec.net&blog=1445666&post=116&subd=misec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.misec.net/2008/10/02/total-secure-2009-new-heights-of-being-annoying-with-removal-guide/feed/</wfw:commentRss>
		</item>
		<item>
		<title>No Good Deed Goes Unpunished</title>
		<link>http://blog.misec.net/2008/10/02/no-good-deed-goes-unpunished/</link>
		<comments>http://blog.misec.net/2008/10/02/no-good-deed-goes-unpunished/#comments</comments>
		<pubDate>Thu, 02 Oct 2008 08:18:50 +0000</pubDate>
		<dc:creator>Magnus</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://misec.wordpress.com/?p=112</guid>
		<description><![CDATA[A university student who discovered vulnerabilities in his school&#8217;s computer network, investigated them and then sent a full report of how to fix them to the administrators is currently awaiting trial on computer intrusion charges. 
The 20-year old student from Ottawa, Ontario will hopefully have a shining career as a security expert some day. What [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://misec.files.wordpress.com/2008/10/greyhat.png"><img src="http://misec.files.wordpress.com/2008/10/greyhat.png?w=200&#038;h=155" alt="" title="greyhat" width="200" height="155" class="alignnone size-full wp-image-113" /></a>A university student who discovered vulnerabilities in his school&#8217;s computer network, investigated them and then sent a full report of how to fix them to the administrators is currently awaiting trial on computer intrusion charges. </p>
<p>The 20-year old student from Ottawa, Ontario will hopefully have a shining career as a security expert some day. What he did could easily be labelled &#8220;penetration testing&#8221;, only in this case the university got the professional services for free instead of having to fork up $550 per hour.</p>
<p><a href="http://www.securityfocus.com/brief/829">Security Focus has more details.</a></p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/misec.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/misec.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/misec.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/misec.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/misec.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/misec.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/misec.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/misec.wordpress.com/112/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/misec.wordpress.com/112/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/misec.wordpress.com/112/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.misec.net&blog=1445666&post=112&subd=misec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.misec.net/2008/10/02/no-good-deed-goes-unpunished/feed/</wfw:commentRss>
	
		<media:content url="http://misec.files.wordpress.com/2008/10/greyhat.png" medium="image">
			<media:title type="html">greyhat</media:title>
		</media:content>
	</item>
		<item>
		<title>Antivirus XP Creator Finally Sued (by Microsoft!)</title>
		<link>http://blog.misec.net/2008/10/01/antivirus-xp-creator-finally-sued-by-microsoft/</link>
		<comments>http://blog.misec.net/2008/10/01/antivirus-xp-creator-finally-sued-by-microsoft/#comments</comments>
		<pubDate>Wed, 01 Oct 2008 10:15:16 +0000</pubDate>
		<dc:creator>Magnus</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://misec.wordpress.com/?p=110</guid>
		<description><![CDATA[Apparently you can&#8217;t get away forever with fooling users into thinking they have malware on their system when they really don&#8217;t, and then offering to sell them a &#8220;removal tool&#8221; that does absolutely nothing but remove the fake alerts.
The creators of such programs as Antivirus XP, Registry Cleaner XP and WinDefender are getting sued by [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Apparently you can&#8217;t get away forever with fooling users into thinking they have malware on their system when they really don&#8217;t, and then offering to sell them a &#8220;removal tool&#8221; that does absolutely nothing but remove the fake alerts.</p>
<p>The creators of such programs as Antivirus XP, Registry Cleaner XP and WinDefender are getting <a href="http://voices.washingtonpost.com/securityfix/2008/09/microsoft_washington_state_tar.html?nav=rss_blog">sued</a> by Microsoft and the state of Washington under the state&#8217;s Computer Spyware Act which prohibits making false claims of spyware or malware on a system. The penalty is actual damages incurred or a punitive damage of $100,000 per offense, whichever is greater.</p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/misec.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/misec.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/misec.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/misec.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/misec.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/misec.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/misec.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/misec.wordpress.com/110/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/misec.wordpress.com/110/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/misec.wordpress.com/110/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.misec.net&blog=1445666&post=110&subd=misec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.misec.net/2008/10/01/antivirus-xp-creator-finally-sued-by-microsoft/feed/</wfw:commentRss>
		</item>
		<item>
		<title>ClickJacking - The New Browser Security Threat</title>
		<link>http://blog.misec.net/2008/09/30/clickjacking-the-new-browser-security-threat/</link>
		<comments>http://blog.misec.net/2008/09/30/clickjacking-the-new-browser-security-threat/#comments</comments>
		<pubDate>Tue, 30 Sep 2008 11:10:41 +0000</pubDate>
		<dc:creator>Magnus</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://misec.wordpress.com/?p=100</guid>
		<description><![CDATA[
The latest buzzword these days is &#8220;ClickJacking&#8221;. There is discussion about this going on in various places.
The basic exploit at work here is loading a web site (such as MySpace) in an IFRAME. You then cover the IFRAME with your own content (such as e.g. a very exciting monkey-punching game). Then you position shiny, clickable [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://misec.files.wordpress.com/2008/05/mousegest.jpg"><img src="http://misec.files.wordpress.com/2008/05/mousegest.jpg?w=150&#038;h=138" alt="" title="mousegest" width="150" height="138" class="alignnone size-full wp-image-61" /></a></p>
<p>The latest buzzword these days is &#8220;ClickJacking&#8221;. There is discussion about this going on in <a href="http://www.wilderssecurity.com/showthread.php?t=221353">various</a> <a href="http://lists.whatwg.org/pipermail/whatwg-whatwg.org/2008-September/016284.html">places</a>.</p>
<p>The basic exploit at work here is loading a web site (such as MySpace) in an IFRAME. You then cover the IFRAME with your own content (such as e.g. a very exciting monkey-punching game). Then you position shiny, clickable portions of your monkey-punching game so that they overlap user interface elements on the MySpace page. Thus when the user clicks on your monkeys he will in reality be executing some action on his MySpace account. This works because most often the cookie will be set for the MySpace page and the user will already be logged in. With some clever design the malicious page could get you to perform complex sequences of actions on the desired target page (think forwarding your entire GMail inbox to someone else).</p>
<p>So how do you protect yourself against this? So far there is no live malicious web page known to take advantage of this. Frankly, I think this is a bit overhyped at the moment. But if you&#8217;re worried, you need to disable IFRAMEs on your web browser. You can do this in a variety of ways. On Firefox (which unfortunately doesn&#8217;t have a way to disable IFRAMEs in its settings) you need to install the extension <a href="http://noscript.net/getit">NoScript</a>. Then bring up NoScript&#8217;s configuration dialog and enable the option &#8220;Forbid &lt;IFRAME&gt;&#8221;. This will disable IFRAMEs and keep you safe from ClickJacking attack.</p>
<p><a href="http://misec.files.wordpress.com/2008/09/forbid_iframe.png"><img src="http://misec.files.wordpress.com/2008/09/forbid_iframe.png?w=571&#038;h=81" alt="" title="forbid_iframe" width="571" height="81" class="aligncenter size-full wp-image-104" /></a></p>
<p>So what&#8217;s the long-term solution to this? Various browser and HTML extensions have been proposed to deal with this. Personally I think that the safest solution is to prevent IFRAMEs from loading pages from an external domain unless the user specifically authorizes it. IFRAMEs are a horribly ugly crutch anyway, and if you&#8217;re relying on them in your web page you need to either fire your web designer or read up on better ways to accomplish the same thing without using them. </p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/misec.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/misec.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/misec.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/misec.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/misec.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/misec.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/misec.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/misec.wordpress.com/100/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/misec.wordpress.com/100/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/misec.wordpress.com/100/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.misec.net&blog=1445666&post=100&subd=misec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.misec.net/2008/09/30/clickjacking-the-new-browser-security-threat/feed/</wfw:commentRss>
	
		<media:content url="http://misec.files.wordpress.com/2008/05/mousegest.jpg" medium="image">
			<media:title type="html">mousegest</media:title>
		</media:content>

		<media:content url="http://misec.files.wordpress.com/2008/09/forbid_iframe.png" medium="image">
			<media:title type="html">forbid_iframe</media:title>
		</media:content>
	</item>
		<item>
		<title>New Malicious Firefox Extension: FirestarterFox</title>
		<link>http://blog.misec.net/2008/09/25/new-malicious-firefox-extension-firestarterfox/</link>
		<comments>http://blog.misec.net/2008/09/25/new-malicious-firefox-extension-firestarterfox/#comments</comments>
		<pubDate>Thu, 25 Sep 2008 09:38:54 +0000</pubDate>
		<dc:creator>Magnus</dc:creator>
		
		<category><![CDATA[Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Trojans]]></category>

		<guid isPermaLink="false">http://misec.wordpress.com/?p=97</guid>
		<description><![CDATA[A malicious Firefox extension called FirestarterFox is being installed by some of the latest malware variants. This extension hijacks all search requests through Google, Yahoo and Microsoft Live search and redirects them through the Russian site thebestwebsearch.net. This is done with the intention of showing ads on the search results page which presumably make money [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://misec.files.wordpress.com/2007/07/firefox-logosvg.png"><img src="http://misec.files.wordpress.com/2007/07/firefox-logosvg.png?w=133&#038;h=127" alt="" title="Firefox Logo" width="133" height="127" class="alignnone size-full wp-image-8" /></a>A malicious Firefox extension called FirestarterFox is being installed by some of the latest malware variants. This extension hijacks all search requests through Google, Yahoo and Microsoft Live search and redirects them through the Russian site thebestwebsearch.net. This is done with the intention of showing ads on the search results page which presumably make money for the creator of this piece of malware.</p>
<p><a href="http://misec.files.wordpress.com/2008/09/firestarterfox.png"><img src="http://misec.files.wordpress.com/2008/09/firestarterfox.png?w=351&#038;h=254" alt="" title="firestarterfox" width="351" height="254" class="aligncenter size-full wp-image-98" /></a></p>
<p>Luckily the extension can&#8217;t be silently installed since Firefox alerts users to all new extensions. So if you ever start Firefox and get the message that a new extension called FirestarterFox has been installed you will immediately know that you have malware on your system and should take steps to remove it or reformat your system.</p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/misec.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/misec.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/misec.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/misec.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/misec.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/misec.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/misec.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/misec.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/misec.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/misec.wordpress.com/97/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.misec.net&blog=1445666&post=97&subd=misec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.misec.net/2008/09/25/new-malicious-firefox-extension-firestarterfox/feed/</wfw:commentRss>
	
		<media:content url="http://misec.files.wordpress.com/2007/07/firefox-logosvg.png" medium="image">
			<media:title type="html">Firefox Logo</media:title>
		</media:content>

		<media:content url="http://misec.files.wordpress.com/2008/09/firestarterfox.png" medium="image">
			<media:title type="html">firestarterfox</media:title>
		</media:content>
	</item>
		<item>
		<title>New Anti-Rootkit Tool: Packed Driver Detector 0.9 Released</title>
		<link>http://blog.misec.net/2008/09/21/new-anti-rootkit-tool-packed-driver-detector-09-released/</link>
		<comments>http://blog.misec.net/2008/09/21/new-anti-rootkit-tool-packed-driver-detector-09-released/#comments</comments>
		<pubDate>Sun, 21 Sep 2008 02:36:04 +0000</pubDate>
		<dc:creator>Magnus</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://misec.wordpress.com/?p=91</guid>
		<description><![CDATA[We&#8217;ve just released the beta version of a new tool named Packed Driver Detector.
Download: http://www.misec.net/products/PDD.exe
(No installation required - simply run file.) 
 
What does this thing do?
Drivers are system files that are used in kernel mode to execute system code. Rootkits use a driver (.sys) file to subvert the Windows kernel and hide their presence [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>We&#8217;ve just released the beta version of a new tool named Packed Driver Detector.</p>
<p><strong>Download: <a href="http://www.misec.net/products/PDD.exe">http://www.misec.net/products/PDD.exe</a></strong><br />
(No installation required - simply run file.) </p>
<p><a href="http://misec.files.wordpress.com/2008/09/pdd1.png"><img src="http://misec.files.wordpress.com/2008/09/pdd1.png?w=450&#038;h=204" alt="" title="pdd1" width="450" height="204" class="alignleft size-full wp-image-92" /></a> </p>
<p><b>What does this thing do?</b></p>
<p>Drivers are system files that are used in kernel mode to execute system code. Rootkits use a driver (.sys) file to subvert the Windows kernel and hide their presence in the system. Recent rootkits have begun packing and/or encrypting their driver files to make them harder to detect.  </p>
<p>This tool identifies packed driver files. On an uninfected system there should be no packed driver files. Use this tool to identify any packed driver files on your system.</p>
<p><b>How can I help?</b></p>
<p>This is the first beta release of Packed Driver Identifier. If you want to help out testing it, download and run it to scan your system. If the tool identifies any packed drivers, don&#8217;t panic. This is the first release of the tool and the identified files are very likely legitimate. Please email the detected driver files to support@misec.net along with your scan log. We will analyze the files for you and tell you if they really are something to worry about.</p>
<p><u>It would be very helpful if you could post your scan report as a comment to this post</u> even if no packed drivers are identified. This is to help verify that the tool is actually not reporting any packed files on most (presumably clean) systems.</p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/misec.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/misec.wordpress.com/91/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/misec.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/misec.wordpress.com/91/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/misec.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/misec.wordpress.com/91/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/misec.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/misec.wordpress.com/91/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/misec.wordpress.com/91/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/misec.wordpress.com/91/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.misec.net&blog=1445666&post=91&subd=misec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.misec.net/2008/09/21/new-anti-rootkit-tool-packed-driver-detector-09-released/feed/</wfw:commentRss>
	
		<media:content url="http://misec.files.wordpress.com/2008/09/pdd1.png" medium="image">
			<media:title type="html">pdd1</media:title>
		</media:content>
	</item>
		<item>
		<title>How to terminate a process without calling TerminateProcess</title>
		<link>http://blog.misec.net/2008/09/20/how-to-terminate-a-process-without-calling-terminateprocess/</link>
		<comments>http://blog.misec.net/2008/09/20/how-to-terminate-a-process-without-calling-terminateprocess/#comments</comments>
		<pubDate>Sat, 20 Sep 2008 08:56:10 +0000</pubDate>
		<dc:creator>Magnus</dc:creator>
		
		<category><![CDATA[Code]]></category>

		<guid isPermaLink="false">http://misec.wordpress.com/?p=83</guid>
		<description><![CDATA[This is absolutely beautiful stuff that very few people will understand. I&#8217;m just putting it out here so that those who know can look at it and go &#8220;ah!&#8221;. This assembler code calls TerminateProcess by using the sysenter function. The first line of code executes a new process and stores its process handle in the [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>This is absolutely beautiful stuff that very few people will understand. I&#8217;m just putting it out here so that those who know can look at it and go &#8220;ah!&#8221;. This assembler code calls TerminateProcess by using the sysenter function. The first line of code executes a new process and stores its process handle in the variable called Handle.</p>
<p>Note that this code will only work on Windows XP since Win2K uses int 2e instead of sysenter to call the kernel. (Also won&#8217;t work on Vista as the syscall function number is different there &#8212; see <a href="http://www.metasploit.com/users/opcode/syscalls.html">this metasploit page</a> for a table of the different system call numbers.)</p>
<pre>
  Handle <FONT COLOR="BLUE" SIZE="+1"><B>:</B></FONT><FONT COLOR="BLUE" SIZE="+1">=</FONT> ExecNewProcess<FONT COLOR="BLUE" SIZE="+1"><B>;</B></FONT>

  <FONT COLOR="RED"><B>asm</B></FONT>
    push <FONT COLOR="BROWN">0</FONT>              <FONT COLOR="GREEN"><I>// Exit code for the process we're terminating

</I></FONT>    push Handle         <FONT COLOR="GREEN"><I>// Handle of the process we're terminating
</I></FONT>    push offset <FONT COLOR="BLUE" SIZE="+1">@</FONT><FONT COLOR="BLUE" SIZE="+1">@</FONT>done  <FONT COLOR="GREEN"><I>// Return address (not used)
</I></FONT>    push offset <FONT COLOR="BLUE" SIZE="+1">@</FONT><FONT COLOR="BLUE" SIZE="+1">@</FONT>done  <FONT COLOR="GREEN"><I>// Return address
</I></FONT>
    mov eax<FONT COLOR="BLUE" SIZE="+1"><B>,</B></FONT> <FONT COLOR="PINK">$101</FONT>       <FONT COLOR="GREEN"><I>// We want system function 0x101 = TerminateProcess

</I></FONT>    mov edx<FONT COLOR="BLUE" SIZE="+1"><B>,</B></FONT> esp        <FONT COLOR="GREEN"><I>// Save esp in edx so that syscall knows where our function parameters are
</I></FONT>    mov ecx<FONT COLOR="BLUE" SIZE="+1"><B>,</B></FONT> offset <FONT COLOR="BLUE" SIZE="+1">@</FONT><FONT COLOR="BLUE" SIZE="+1">@</FONT>done  <FONT COLOR="GREEN"><I>// Save the address to return to in ecx
</I></FONT>
    sysenter           <FONT COLOR="GREEN"><I>// Call the kernel!

</I></FONT>
    <FONT COLOR="BLUE" SIZE="+1">@</FONT><FONT COLOR="BLUE" SIZE="+1">@</FONT>done<FONT COLOR="BLUE" SIZE="+1"><B>:</B></FONT>
    add esp<FONT COLOR="BLUE" SIZE="+1"><B>,</B></FONT> <FONT COLOR="PINK">$0C</FONT>       <FONT COLOR="GREEN"><I>// Restore stack pointer
</I></FONT>  <FONT COLOR="RED"><B>end</B></FONT><FONT COLOR="BLUE" SIZE="+1"><B>;</B></FONT>
</pre>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/misec.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/misec.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/misec.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/misec.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/misec.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/misec.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/misec.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/misec.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/misec.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/misec.wordpress.com/83/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.misec.net&blog=1445666&post=83&subd=misec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.misec.net/2008/09/20/how-to-terminate-a-process-without-calling-terminateprocess/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Old-School File Hiding</title>
		<link>http://blog.misec.net/2008/09/20/old-school-file-hiding/</link>
		<comments>http://blog.misec.net/2008/09/20/old-school-file-hiding/#comments</comments>
		<pubDate>Sat, 20 Sep 2008 05:41:47 +0000</pubDate>
		<dc:creator>Magnus</dc:creator>
		
		<category><![CDATA[Analysis]]></category>

		<category><![CDATA[Rootkits]]></category>

		<category><![CDATA[Trojans]]></category>

		<guid isPermaLink="false">http://misec.wordpress.com/?p=68</guid>
		<description><![CDATA[A new sample came in today - an ad injector for Internet Explorer. I was analyzing it and noticed that the malware hid several of its key files. &#8220;Aha - a rootkit!&#8221; I thought and proceeded to find out how the trojan had hooked into the system to hide its traces. An SSDT hook perhaps, [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>A new sample came in today - an ad injector for Internet Explorer. I was analyzing it and noticed that the malware hid several of its key files. &#8220;Aha - a rootkit!&#8221; I thought and proceeded to find out how the trojan had hooked into the system to hide its traces. An SSDT hook perhaps, or maybe an injected user-mode DLL?</p>
<p>I looked and looked and couldn&#8217;t find a thing. No rootkit, no driver, no IAT modifications; nothing. Even stranger, the trojan seemed to have rootkitted the entire C:\Windows\system32 folder - it was invisible in Windows Explorer and couldn&#8217;t be seen when executing dir in a CMD prompt. That&#8217;s strange - why would a rootkit want to hide the system32 folder? If anything would tip you off that something is horribly wrong with your system, a missing system32 folder would be it (see figure 1 below).</p>
<div id="attachment_69" class="wp-caption alignnone" style="width: 460px"><a href="http://misec.files.wordpress.com/2008/09/sys32missing.png"><img src="http://misec.files.wordpress.com/2008/09/sys32missing.png?w=450&#038;h=108" alt="system32 missing" title="Fig 1. Bad things are going on if you open up Explorer and see this." width="450" height="108" class="size-full wp-image-69" /></a><p class="wp-caption-text">Fig 1. Bad things are going on if you open up Explorer and see this.</p></div>
<p>After about an hour of looking for the rootkit and not finding it I started to get frustrated. So I decided to take another look at RegMon to see what the trojan was doing with the registry. That&#8217;s when I stumbled upon this:</p>
<div id="attachment_73" class="wp-caption alignnone" style="width: 667px"><a href="http://misec.files.wordpress.com/2008/09/superhid.png"><img src="http://misec.files.wordpress.com/2008/09/superhid.png?w=657&#038;h=94" alt="superhid" title="superhid" width="657" height="94" class="size-full wp-image-73" /></a><p class="wp-caption-text">Fig 2. The trojan modifies the ShowSuperHidden setting for Windows Explorer</p></div>
<p>The HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\<b>ShowSuperHidden</b> determines whether or not Explorer shows files that have the hidden and system attribute set. It wasn&#8217;t a rootkit after all! The trojan simply disabled this setting and this caused all files with the system and hidden attribute to be invisible in Windows Explorer. And since the lab machine had the ShowSuperHidden setting enabled the trojan was hidden after performing the above registry tweak.</p>
<p>However, this didn&#8217;t explain why the files and folders were invisible in a Command Prompt as well. The explanation is obvious and simple: I had entered a simple &#8220;dir&#8221;. And since the system32 folder and the trojan files had attributes +h +s (hidden and system) set, they were hidden in the listing. Doing a &#8220;dir /ah&#8221; showed the missing files. </p>
<p>Moral of the story: Somtimes malware will use &#8220;old reliable&#8221; instead of messing about with a rootkit and drivers. So check the obvious stuff first before assuming it&#8217;s something more advanced.</p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/misec.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/misec.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/misec.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/misec.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/misec.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/misec.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/misec.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/misec.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/misec.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/misec.wordpress.com/68/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.misec.net&blog=1445666&post=68&subd=misec&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://blog.misec.net/2008/09/20/old-school-file-hiding/feed/</wfw:commentRss>
	
		<media:content url="http://misec.files.wordpress.com/2008/09/sys32missing.png" medium="image">
			<media:title type="html">Fig 1. Bad things are going on if you open up Explorer and see this.</media:title>
		</media:content>

		<media:content url="http://misec.files.wordpress.com/2008/09/superhid.png" medium="image">
			<media:title type="html">superhid</media:title>
		</media:content>
	</item>
	</channel>
</rss>