Blog - Bloglines - Jaiku - Ports - Wiki


(J)ack (O)f (A)ll (T)rades
Mostly Security, Some
Blogging, Misc. Admin,
and Bits of My Life.









August 2007
Sun Mon Tue Wed Thu Fri Sat
     
 

Recent Comments

Wiki RSS

Blog Search

Categories

Archives

























Del.icio.us


Wed, 31 Jan 2007

Interview 31 Jan
For some, the ICQ interview with the trojan author may be interesting. I agree with Mikko in that this guy will eventually be caught (probably via follow-the-money).

joat: 01:11:24 31 Jan 2007


Sun, 17 Dec 2006

DNS black holes 17 Dec
A long time ago, I experimented with forging domain authority on internal DNS servers as a anti-spam/anti-porn measure. It does work though I don't recommend it as a countermeasure unless you're willing to devote (I'm not kidding) a lot of time to updating the zone files. Over a one year period, I added 21K zones and still could not get ahead of the game.

I guess it would help to have an organized project to rely on. Something like Bleeding Edge's black-hole DNS project. Mix in a little policy-based routing (IP and port redirects that are invisible to users) and your troublemakers get quite frustrated. If you manage a network, I recommend looking at this.

Side note: what you use as a DNS server will determine how well you can scale the project. Windows DNS handles 21K domains poorly. Linux doesn't fare much better. (They do work but overload easily.) FreeBSD variants a bit better. The one that I recommend as a DNS server for heavy uses is BSDi (the commercial one). Wind River purchased BSDi and discontinued the product some time in 2003. It's still a very stable platform if you have the license.

Side note: Wind River has purchased and discontinued at least one other OS. They're also the parent to VxWorks, which is that annoying OS in the newer 54G's. Would it suprise you that they've also been a partner to Redhat?

joat: 13:00:00 17 Dec 2006


Mon, 13 Nov 2006

Gromozon 13 Nov
Here is the paper that appears to have started the battle between a security company and a spamming/malware group.

joat: 13:00:00 13 Nov 2006


Sat, 11 Nov 2006

MyDoom 11 Nov
Attention! Would the owner of the system at 12.213.13.12 (in Middletown, NY) please take a look at his/her system? You are infected with a zipped/UPX-packed MyDoom variant and you are annoying the rest of the planet.

Also, would Stephanie Micheneau please review the need for response e-mails for detected infections? MyDoom forges source addresses and I do not run networked systems susceptable to W32 viruses. So please stop yelling at me... (heh)

joat: 21:30:00 11 Nov 2006


Thu, 02 Nov 2006

WildList 02 Nov
It really doesn't look like a computer security site but it is. The WildList is a site devoted to listing "in the wild" viruses and related information.

joat: 13:00:00 2 Nov 2006


Sun, 17 Sep 2006

Botnet Economy 17 Sep
Hopefully we'll see more from Thorsten Holtz, over at the honeyblog, on "The Economics of Botnets" (part 1)(part 2).

joat: 12:00:00 17 Sep 2006


Mon, 11 Sep 2006

EFS attacks 11 Sep
McAfee's Avert Labs has a piece on "preventing EFS-based attacks" which describes a few steps to prevent your data from being held hostage. Basically, it describes the steps for disabling the encrypted file system capability in your Windows box.

Side note: McAfee appears to be twisting trackbacks and making them look like comments.

joat: 20:30:00 11 Sep 2006


Sun, 27 Aug 2006

WORM 27 Aug

joat: 12:00:00 27 Aug 2006


Sun, 20 Aug 2006

Mocbot 20 Aug
LURHQ has posted their analysis of Mocbot spam to accompany their initial analsys of the bot.

joat: 12:00:00 20 Aug 2006


Mon, 10 Jul 2006

Using Google to find bad sites 10 Jul
PCWorld has a short piece about a group using Google little-known/used binary search feature to find malicious websites. Although there's not a whole of detail, it is an interesting concept.

joat: 12:00:00 10 Jul 2006


Sat, 24 Jun 2006

DDOS 24 Jun
Here is a paper which discusses the D-Link NTP ddos and includes other ddos attacks as historical examples.

joat: 20:30:00 24 Jun 2006


Tue, 13 Jun 2006

Argggh! 13 Jun
Note to anti-virus companies: Please add the feature where if the malware is known to steal, borrow or otherwise forge the source address on an infected email, the code will NOT send an email back to the supposed source. I'm now getting complaints about my non-existent MS mail client in Italian.

Grazie!

joat: 10:30:00 13 Jun 2006


Wed, 07 Jun 2006

Malware Analysis for Admins 07 Jun
Here is a SecurityFocus piece entitled "Malware Analysis for Administrators".

joat: 12:00:00 7 Jun 2006


Sat, 03 Jun 2006

Cryzip Analysis 03 Jun
LURHQ has also posted an analysis of the Cryzip ransomware trojan.

joat: 12:00:00 3 Jun 2006


Fri, 02 Jun 2006

Arhiveus Analysis 02 Jun
LURHQ has posted an analysis of the Arhiveus ransomware trojan.

joat: 20:30:00 2 Jun 2006


Sun, 07 May 2006

Old school 07 May
For you history buffs, here's analyses on Stacheldraht and Trinoo.

joat: 12:00:00 7 May 2006


Sat, 21 Jan 2006

Suspicious 21 Jan
A lot of crap gets cached in Google. I'm having trouble with various searches this morning as the majority of them default to a page at search.ug. I wonder how long it'll take until someone at Google catches on and cleans the sludge out of their caches. There's a lot of talk about it in various forums.

joat: 15:13:10 21 Jan 2006


Mon, 19 Dec 2005

Dasher 19 Dec
The Worm Blog has some initial comments on the Dasher worm. There's also some comment about Dasher.C.

joat: 21:30:00 19 Dec 2005


Sun, 18 Dec 2005

Offensive Computing 18 Dec
Offensive Computing may be a site to keep an eye on. Their stated purpose is to improve computer/network security via analysis of malware.

joat: 21:30:00 18 Dec 2005


Sun, 11 Dec 2005

FBI 11 Dec
Not that it's new but I received one from a friendly Mytob worm that I hadn't seen yet. It was from veeby@fbi.gov and said "Here are your bank documents." So, if you're IP is 202.177.156.97 (India), please take a look at your system. It's infected.

joat: 13:00:00 11 Dec 2005


robtex