BotTrax: Malware and Bot Tracking

Tips, tricks and hacks to have fun, and avoid becoming a victim…

[ad]
Subscribe to BotTrax: Malware and Bot Tracking
Technorati
del.icio.us
July-16-09

Next Attack Vector – Twitter

posted by 1C3Man

Alright, so I have been preaching this to industry experts all over the place and everyone agrees, Twitter is going to be the next major attack vector.

Why? Because people that use Twitter LOVE to click links AND Twitter constantly obfuscates the urls with TinyURL so you have no idea where you are headed.

Here is how the attack would work:

  1. Sign up for free site hosting using a fake name
  2. Upload the malware to the newly created site
  3. Compromise the Twitter account of a highly popular celeb or public figure like Oprah, ThatsBadAss, or uSearchIt
  4. Use the compromised Twitter account to Tweet an enticing message that includes the long URL that is now obfuscated with TinyURL
  5. The followers then click the link
  6. Malware dominance ensues

The moral of the story for Twitter users… DONT CLICK THE LINK, STEP BACK FROM THE COMPUTER, STAY AWAY FROM THE LIGHT…

There are a number of add-ons for FireFox that will show you the click through URL but that is not always a sure thing. Malware distributors will many times use multiple redirects, or referral monitoring, to adjust the behavior so a single hop wont tell you much.

June-12-09

More Mac Malware

posted by 1C3Man

pen

I dont like malware, just like everyone else, except the author, but I giggle devilishly to myself every time another Mac gets pwned. I do this because Mac owners are always on their high horse claiming they dont have to worry about antivirus software, firewalls, or a good router… BITE ME!

This is spread through Flash-based porn sites. I thought Mac owners were too stuffy to enjoy a good XXX site but I could be wrong.

The Sophos antivirus company has done a good job of bringing attention to the infection and has developed some generic ways to detect the current strain, as well as some future variants.

The malware is a worm by the name OSX/Tored-Fam.

Is it safe to surf for porn on an Apple Mac? from Sophos Labs on Vimeo.

March-11-09

Hacking the WRT54GL

posted by 1C3Man
  1. You will need to download the most current hacked firmware at http://www.dd-wrt.com
    1. I used the mini generic and the standard generic
  2. The first firmware upgrade will be the mini generic

    clip_image001

  3. You should get an "Upgrade is successful" screen with a Continue button upon completion
    1. NOTE: It may take a couple minutes for the router to become available for connection
  4. Exciting…. Brand new UI :)

    clip_image002

  5. Password seems to have changed… :o
    1. New username is "root" and password is "admin"
  6. The next firmware upgrade will be done using the standard generic

    clip_image003

  7. You should now see "Upgrade successful. Unit is rebooting now. Please wait a moment…"
  8. After a short wait you will then see the following with the buttons Continue and Close:
    1. Please check the followings before connecting again:
      1. If you have changed your router’s IP address, please note that you must release/renew your client(s) address(s) on the network.
      2. If you are connected via WLAN, please join the network and then click Continue.
  9. UI is pretty much the same but now has some additional options

    clip_image004

  10. Lets first boost the wireless signal by going to the Wireless tab
  11. Next go to the Advanced Settings
  12. Locate Xmit or TX Power with a default value of 70
    1. I turned mine up to 200mW
      1. WARNING: Increasing the TX power too much can damage your router, reduce its life, and could cause overheating which could result in fire

    Some additional resources:

    http://lifehacker.com/software/router/hack-attack-turn-your-60-router-into-a-600-router-178132.php

    http://www.dd-wrt.com/phpBB2/index.php

    http://www.dd-wrt.com/dd-wrtv3/dd-wrt/hardware.html

Tags:
March-10-09

Camera Search Tools

posted by 1C3Man

Here is a cool little personal security camera locator, been around for a while but I can never remember it when I want to. Basically do a search for inurl:’viewerframe?mode=motion’ in your favorite search engine, because we like to support our friends we use uSearchIt. You may need to install an ActiveX control to view the stream of these cameras to beware. Any time you are asked to install an ActiveX control make sure you know where it is coming from. Here is a link to search for the cameras:

  • inurl:’viewerframe?mode=motion’: uSearchIt.com
    • Countermeasure: Modify the file structure of your install.

Another camera search, similar to the one above for the AXIS cameras. Again, here is a link to search, this time for intitle:’Live View / – AXIS’:

  • intitle:’Live View / – AXIS’: uSearchIt.com
    • Countermeasure: Modify the source of the files to update Live View / – AXIS

Here are four others. Camera searches of these types can be good for recon when you are tracking someone, or an organization who might be running something shady.

  • inurl:indexFrame.shtml ‘AXIS Video Server’: uSearchIt.com
    • Countermeasure: Modify install file names and source code.
  • inurl:LvAppl Intitle:liveapplet: uSearchIt.com
    • Countermeasure: Modify install file names and source code.
  • intitle:’WJ-NT104 Main’: uSearchIt.com
    • Countermeasure: Modify the source of the files to update WJ-NT104 Main
  • intitle:’snc-rz30 home’: uSearchIt.com
    • Countermeasure: Modify the source of the files to update snc-rz30 home

February-10-09

Trending Keywords for 02/12/2009

posted by 1C3Man

Google Trends for today:

1 seth binzer cardiac arrest
2 her energy drink
3 david golshan
4 worms in the brain
5 magic ball
6 aubrey danity kane
7 frankie lymon
8 buffalo plane crash
9 naacp
10 aubrey o day nude
11 buffalo news
12 naacp image awards
13 postpartum psychosis
14 seth sober house
15 crazytown
16 daniel sadek
17 joaquin phoenix david letterman
18 alcan highway
19 seth shifty
20 mississippi masala
21 day 26
22 survivor tocantins
23 zola taylor
24 plane crash clarence ny
25 john sununu
26 seth crazy town
27 rihanna bruises
28 street fighter movie
29 cbs survivor
30 seth binzer heart attack
31 parasitic cysts
32 ed colbert
33 pagans mc
34 da band
35 miley cyrus sued
36 danity kane break up
37 cbs letterman
38 tocantins brazil
39 survivor series
40 lpga.com leaderboard
41 jennifer hudson pregnant
42 vision systems group
43 shifty binzer
44 house of cards cnbc
45 bill maher
46 making the band 4
47 brett jacobson
48 lpga
49 valentines day poems
50 buffalo niagara airport
51 printable valentine cards
52 max keebles big move
53 schimpff s confectionery
54 octumom
55 sarita choudhury
56 6050 long street clarence ny
57 er the family man
58 stimulus package breakdown
59 the office lecture circuit part 2
60 surtr
61 this is curly
62 lincoln public schools
63 phil gramm
64 carolina eastwood
65 chris brown facebook
66 donnie klang
67 lee redmond
68 alexandra pelosi
69 dominican republic real estate
70 rihanna pictures beat up
71 levitating ball
72 life is like a slideshow lyrics
73 sean levert
74 lovopoly
75 david weintraub
76 quick loan funding
77 farrah fawcett letterman
78 naacp history
79 daytona 500 lineup
80 low alpha lead
81 pagans motorcycle club
82 louis gossett jr
83 why do fools fall in love
84 aubrey playboy
85 children of the mountains
86 russell simmons
87 morgan fairchild
88 valentines day e cards
89 praveen andapally
90 kyle bass
91 alex d. linz
92 ryan bingham
93 crispin glover
94 my best friends wedding
95 american idol disqualified
96 northern lights
97 joaquin phoenix late show
98 delocated
99 cdo
### joaquin phoenix interview video

ToSeeka Trends for today:

1 personal ads
2 russian women
3 http:www. hotel
4 it services
5 loans
6 japanese girl
7 slot
8 single
9 wills texas
10 www.hotel
11 hp.com
12 dental
13 dentists
14 new york state wills
15 find friend
16 japanese massage therapist
17 domains
18 diets
19 michigan wills
20 or map
21 singles
22 gas prices
23 california wills
24 free movie
25 on cd
26 married personal
27 truck drivers
28 john wills
29 older woman personal
30 dental insurance
31 vietnamese girl
32 create .pdf
33 diabetes
34 hosting
35 monitors
36 employment
37 big ases
38 an estate
39 dating free
40 mortgages
41 older women
42 it online
43 sex teen
44 russian brides
45 room chat
46 black singles
47 adults sex
48 flu shots
49 chat video
50 i am music
51 sex
52 forms of wills
53 i am mp3
54 sex, live
55 i am university
56 truck drivers job
57 wills software
58 courses
59 driving maps
60 men seeking women
61 www casino
62 depression http:
63 colorado
64 interracial dating
65 wedding reception
66 georgia wills
67 windows on the
68 men seeking men
69 in software in
70 voip http
71 pa wills
72 photosex
73 www bank
74 tractors used
75 swinger site
76 transmission
77 wills info
78 what is website
79 bus sales
80 super8motel
81 careers
82 chat rooms
83 recipes
84 voip
85 casinos
86 minnesota wills
87 com webhosting
88 it systems
89 cellular
90 si and am
91 comcast
92 child support
93 date
94 hot russian women
95 parts auto
96 am video
97 spongebob squarepants games online
98 gay sex
99 friend find
### big bear rentals
### xxx the movie
### http www hotel
### www.single
### college's
### i am king
### com links
### am i blue
### xxx adult
### amish furniture
### ??????????????? mp3
### computers for a
### patent
### conference call with
### it security
### pussy amateur
### visa
### i am love
### newjersey wills
### pro am
### www nutrion
Tags:
February-1-09

New IM Worm Spreading

posted by 1C3Man

Ok I might be jumping the gun here but there appears to be a new compromised, someone that has me on their IM list got pwnd or some list is being generated somewhere.

I returned to my computer this evening to find an IM from someone that I did not know and the following message:

——————————————————

mmmmmm88@hotmail.fr [h:mm PM]:
  OMG u gotta see this! Go here: _hxxp://xxxx.obama-offers.com

——————————————————

Obviously I modified it slightly to avoid accidental clicks and to keep somewhat anonymous, but you get the picture.

So lets see what we can learn about obama-offers.com and the sender.

  1. The usual checks for other reports using uSearchIt.com. I prefer using this site because I can easily compare results across search engines as well as other sites like Twitter.
    1. Results – Couple reports on Twitter but nothing in the search engines so I went to Google directly. Found a page but the translator didnt work and there is no cached page. Using obama + offers as a domain was a pretty smart way to hide.
  2. Checking Dataopedia for any clues as to the origin of the site.
    1. Results – Private registration but appears to have been set up today. Not surprisingly there isnt enough traffic to get any hits in Alexa, Compete.com, or Quantcast.
  3. Next stop BuiltWith.com to see what we can learn about the technical side of the site before visiting it directly.
    1. Results – Running on a server with Linux CentOS and Apache. They are using PHP with frames, surprise surprise… NOT.
  4. Lets not forget domainwhitepages to see if there is anything interesting about the route of traffic or maybe, if we are lucky, better information about the registrar.
    1. Results – IP 208.116.34.163. WhoIs information FortressITX 100 Delawanna Ave Clifton NJ 07014. Looks like they are using an email forwarder. OH BOY my old friends ThePlanet and Level3. From what I have investigated over the years these guys shouldnt even be on the web.
  5. Another great resource is YouGetSignal. This site offers a number of useful tools for reverse lookups.
    1. Results – Mostly results aligned with those on other sites but i found that there are 3546 other domains hosted on the same server. A quick scan of the domain names makes me wonder if looking too far into this could be a can of worms that turns into a needle in a haystack.
  6. Time for a virtual machine with Fiddler running.
    1. Results – I used the name jonsmith figuring the page would not perform as intended without a subdomain. I got a generic parking page but lots loaded in the background. See details below:

image

Here is the page source and enough information if someone were to take legal action to know who to subpoena records for from the various companies:

———————————————————————————

<html><head><title></title></head><frameset rows=’100%, *’ frameborder=no framespacing=0 border=0><frame src="http://64.34.154.95/ads" name=mainwindow frameborder=no framespacing=0 marginheight=0 marginwidth=0></frame></frameset><noframes><h2>Your browser does not support frames. We recommend upgrading your browser.</h2><br><br><center>Click <a href="http://64.34.154.95/ads" >here</a> to enter the site.</center></noframes></html>

———————————————————————————

Source of hxxp://64.34.154.95/ads

———————————————————————————

<html>
<head>
<title>Great Offers For You</title>
</head>
<frameset rows="*,1" frameborder=0>

  <frame src="indexx.php" name="">
  <frame src="body.php" name= frameborder=no framespacing=0 marginheight=0 marginwidth=0></frame>

</frameset>
</html>

———————————————————————————

indexx.php calls a redirect:

———————————————————————————

Location: hxxp://www.herbalaffiliateprogram.com/herbalalternatives/aff_manager/newaff/redirect.cfm/i/2009015138

———————————————————————————

body.php looks like it isnt working correctly

———————————————————————————

HTTP/1.1 200 OK
Transfer-Encoding: chunked
X-Powered-By: PHP/4.4.8
Content-type: text/html
Date: Mon, 02 Feb 2009 15:17:58 GMT
Server: lighttpd/1.4.19

71
<br />
<b>Parse error</b>:  syntax error, unexpected ‘<’ in <b>/home/www/ads/body.php</b> on line <b>3</b><br />

0

———————————————————————————

indexx.php redirector call is responded to drop a cookie

———————————————————————————

HTTP/1.1 200 OK
Connection: close
Date: Mon, 02 Feb 2009 06:12:29 GMT
Server: Microsoft-IIS/6.0
X-Powered-By: ASP.NET
Content-type: text/html
P3P: CP="ALL DSP COR NID CURo OUR STP PUR OTPo COM NAV"
Page-Completion-Status: Normal
Page-Completion-Status: Normal
Set-Cookie: AFFILIATEID=2009015138; expires=Tue, 03-Feb-2009 00:12:29 GMT; path=/;
Set-Cookie: CAMPAIGNID=0; expires=Tue, 03-Feb-2009 00:12:29 GMT; path=/;
Set-Cookie: CFGLOBALS=HITCOUNT%3D1%23LASTVISIT%3D%7Bts+%272009%2D02%2D02+00%3A12%3A29%27%7D%23TIMECREATED%3D%7Bts+%272009%2D02%2D02+00%3A12%3A29%27%7D%23; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/;
Set-Cookie: CFID=10309480; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/;
Set-Cookie: CFTOKEN=44372689; expires=Sun, 27-Sep-2037 00:00:00 GMT; path=/;
Set-Cookie: LINKID=0; expires=Tue, 03-Feb-2009 00:12:29 GMT; path=/;

———————————————————————————

indexx.php redirector next loads the page www.diet-pills-natural-fast-weight-loss-supplements-fat-product.com, notice that it captured the visiting IP

———————————————————————————

<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1" /><title>
    natural supplement vitamin colloidal silver at diet-pills-natural-fast-weight-loss-supplements-fat-product.com
</title>
<meta name="keywords" content="natural,supplement,vitamin,colloidal,silver,vitacost.com,antioxidant,eniva,solgar,liquid" />
<meta name="description" content="primal defense hair vitamin nature way sea silver the greatest" />
<SCRIPT LANGUAGE=’Javascript’ SRC=’/diet-pills-natural-fast-weight-loss-supplements-fat-product.com.js’></SCRIPT>
<link javascript’ type=’Text/Javascript’>
function GetIPPI(g) {
    var xmlHttp = createXMLHttpRequest();
    if (xmlHttp != null) {
        xmlHttp.open(‘GET’, ‘/’+g+’.ippi?g=’+g, true);
        xmlHttp.send(null);
    }
}

function createXMLHttpRequest() {
  try { return new ActiveXObject(‘Msxml2.XMLHTTP’); } catch(e) {}
  try { return new ActiveXObject(‘Microsoft.XMLHTTP’); } catch(e) {}
  try { return new XMLHttpRequest(); } catch(e) {}
  return null;
}

GetIPPI(‘e4f67e00-123e-49f0-88a0-d9a6c847a437′);
</script>

</body>
</html>

———————————————————————————

next comes the .js GET /diet-pills-natural-fast-weight-loss-supplements-fat-product.com.js

———————————————————————————

var mydate=new Date()
var year=mydate.getYear()
if (year < 1000)
year+=1900
var day=mydate.getDay()
var month=mydate.getMonth()
var daym=mydate.getDate()
if (daym<10)
daym=’0′+daym
var dayarray=new Array(‘Sunday’,'Monday’,'Tuesday’,'Wednesday’,'Thursday’,'Friday’,'Saturday’)
var montharray=new Array(‘January’,'February’,'March’,'April’,'May’,'June’,'July’,'August’,'September’,'October’,'November’,'December’)
var d=(dayarray[day]+’, ‘+montharray[month]+’ ‘+daym+’, ‘+year)

function getPage()
{
    var c = ‘rd302.a’;
    var y = ‘p’;
    var a = ‘fo’;
    var x = ’s’;
    var z = ‘x’;
    var b = ‘rwa’;
    return a + b + c + x + y + z;
}

function pcNav(url)
{
    var x = ‘/’ + getPage() + url;
    //alert(x);
    window.parent.location.href = x;
}

function slNav(url)
{
window.parent.location.href = url;
}

function createCookie(name,value,days) {
    if (days) {
        var date = new Date();
        date.setTime(date.getTime()+(days*24*60*60*1000));
        var expires = ‘; expires=’+date.toGMTString();
    }
    else var expires = ”;
    document.cookie = name+’='+value+expires+’; path=/’;
}

function readCookie(name) {
    var nameEQ = name + ‘=’;
    var ca = document.cookie.split(‘;’);
    for(var i=0;i < ca.length;i++) {
        var c = ca[i];
        while (c.charAt(0)==’ ‘) c = c.substring(1,c.length);
        if (c.indexOf(nameEQ) == 0) return c.substring(nameEQ.length,c.length);
    }
    return null;
}

function eraseCookie(name) {
    createCookie(name,”,-1);
}

———————————————————————————

then the .css request GET /css/dbstore.css?def=Akamai%3aHostingURL%3dhttp%3a%2f%2fi.nuseek.com%7cBdyStyl%3aPageBackgroundColor%3d%23fff%7cBdyStyl%3aFont%3darial%7cBdyStyl%3aFontSize%3d12%7cBdyStyl%3aFontColor%3d%230e5fd8%7cBdyStyl%3aPrimaryColor%3d%231b5709%7cBdyStyl%3aPrimaryColorComplement%3d%23fff%7cBdyStyl%3aSecondaryColor%3d%23c44242%7cBdyStyl%3aSecondaryColorComplement%3d%23edc6c6%7cBdyStyl%3aTertiaryColor%3d%23f3f3f3%7cBdyStyl%3aTertiaryColorComplement%3d%23476ec7%7cPgHdr%3aFontSize%3d18%7cPgHdr%3aFont%3dVerdana%7cRelLink%3aFont%3darial%7cRelLink%3aFontSize%3d14%7cRelLink%3aFontColor%3d%23476ec7%7cRelLink%3aHoverFontColor%3d%23c03625%7cRelLink%3aBackgroundColor%3d%23fafad9%7cRelLink%3aDividerColor%3d%23e2dfb8%7cRelLink%3aHoverBackgroundColor%3d%23fbfbf5%7cRelLink%3aImagePath%3d%2fimages%2fThemes%2fT101%2fbullets%2f0006.gif%7cRelLink%3aImageWidth%3d10%7cRelLink%3aImageHeight%3d10%7cBottomNav%3aImagePath%3d%2fimages%2fThemes%2fT101%2fbullets_9×9%2f0006.gif%7cResult%3aImagePath%3d%2fimages%2fThemes%2fT101%2fbullets%2f0006.gif%7cResult%3aHeaderFont%3darial%7cResult%3aHeaderFontSize%3d12%7cResult%3aHeaderFontColor%3d%23000%7cResult%3aTitleFont%3darial%7cResult%3aTitleFontSize%3d16%7cResult%3aTitleFontColor%3d%2300c%7cResult%3aAbstractFont%3darial%7cResult%3aAbstractFontSize%3d12%7cResult%3aAbstractFontColor%3d%23000%7cResult%3aURLFont%3darial%7cResult%3aURLFontSize%3d12%7cResult%3aURLFontColor%3d%23008000%7cResult%3aSidebarBorderColor%3d%23ccc%7cSrchBox%3aImagePath%3d%2fimages%2fThemes%2fT101%2fbuttons%2f0006.gif%7cSrchBox%3aImageWidth%3d60%7cSrchBox%3aImageHeight%3d22%7cSrchBox%3aAlign%3dright%7cSearchLinkGroup%3aHoverLinkColor%3d%23ff9%7cUsrCust%3aFontType%3dverdana%7cUsrCust%3aFontSize%3d11%7cUsrCust%3aFontColor%3d%23666%7cUsrCust%3aLinkColor%3d%230e5fd8%7cSrchBox%3aTextboxWidth%3d0&cssid=101 HTTP/1.1

———————————————————————————

/*———————————————————————–
Template101_Billboard
———————————————————————–*/

* {padding:0;margin:0}
body {background:#fff;font:12px arial,sans-serif;color:#0e5fd8;text-align:center}
h1,h2,h3,h4,h5,h6 {font-size:100%}
.clear {clear:both}

/* GRID */
#container {width:754px;text-align:left;margin:40px auto 20px}
.col1,.col3 {display:none}
#twoColLayout {width:100%;background:#f6f6f6 url(‘http://i.nuseek.com/Images/Shared/relLinkBkg.gif’) repeat-x bottom;border:1px solid #fff}
.twoColL {background:#e2dfb8;vertical-align:top}
.twoColR {background:#fff;vertical-align:top}
.pg1 .twoColL {width:100%}

/* HEADER */
.hdr {width:100%;background:#1b5709;color:#fff;padding:0}
.pg2 .hdr {border-bottom:26px solid #c44242}
.hdrL {width:100%;border-bottom:1px solid #fff}
.header h1 {font:400 18px Verdana,sans-serif;margin:5px 10px}
.pg2 .header h1 a {color:#fff;text-decoration:none}

/* Google Label Slot */
    /* Default */
    .leftNavHdrOff {height:26px;background:#c44242;position:relative}
    .leftNavHdrOff span {display:none}
    /* If Google */
    .leftNavHdrOn {height:26px;background:#c44242;position:relative}
    .leftNavHdrOn span {width:90%;color:#edc6c6;font-size:100%;position:absolute;left:25px;top:5px;font-weight:700}

/* TWO_COL pg1 */
.ldrRelLinks ul {list-style-type:none;border-top:1px solid white /*fix for IE6/7 gap */}
.ldrRelLinks a:link,.ldrRelLinks a:visited {display:block;width:100%;background:#fafad9 url(‘http://i.nuseek.com/images/Themes/T101/bullets/0006.gif’) no-repeat 25px center;font:700 14px arial,sans-serif;color:#476ec7;text-decoration:none;padding:5px 5px 4px 50px;border-top:1px solid #fff;border-bottom:1px solid #fff;margin-bottom:1px}
.ldrRelLinks a.first:link,.ldrRelLinks a.first:visited {margin-top:1px}
.ldrRelLinks a.last:link,.ldrRelLinks a.last:visited {border-bottom:none}
.ldrRelLinks a:hover {background:#fbfbf5 url(‘http://i.nuseek.com/images/Themes/T101/bullets/0006.gif’) no-repeat 30px center;color:#c03625}
    /* JS DISPLAY */
    .ldrRelLinks li span.outer {display:block;width:100%;background:#fafad9 url(‘http://i.nuseek.com/images/Themes/T101/bullets/0006.gif’) no-repeat 25px center;font:700 14px arial,sans-serif;color:#476ec7;text-decoration:none;padding:5px 5px 4px 50px;border-top:1px solid #fff;border-bottom:1px solid #fff;margin-bottom:1px;cursor:pointer}
    .ldrRelLinks li span.outer:hover {background:#fbfbf5 url(‘http://i.nuseek.com/images/Themes/T101/bullets/0006.gif’) no-repeat 30px center;color:#c03625}

/* IMAGE DISPLAY */
.mainImg {width:360px;height:308px;overflow:hidden;border-left:1px solid #fff;float:right}

/* TWO_COL pg2 */
.resMain {width:500px;padding:10px;margin:0;background:#fff}
.resMain h2 {color:#000;font:400 12px arial,sans-serif;margin:0;/* UPDATE SKINS => color:#000 */}
.resMain ul {list-style-type:none}
.resMain li {background:transparent url(‘http://i.nuseek.com/images/Themes/T101/bullets/0006.gif’) no-repeat 0 3px;padding:0 0 0 25px;margin:15px 0}
.resMain li span {cursor:pointer}
.resMain .title {font:700 16px arial,sans-serif;color:#00c;display:inline-block}
.resMain .titleJS {font:700 16px arial,sans-serif;color:#00c;display:inline-block;border-bottom:1px solid #00c} /* JS version */
.resMain .abstract {font:400 12px arial,sans-serif;color:#000;text-decoration:none}
.resMain .abstractNoClick {font:400 12px arial,sans-serif;color:#000;text-decoration:none;cursor:default}
.resMain .url {font:400 12px arial,sans-serif;color:#008000;text-decoration:none}
.prev {display:block;float:left;padding-left:15px;background:transparent url(‘http://i.nuseek.com/Images/Shared/prev.gif’) no-repeat 0 50%;text-transform:capitalize}
.next {display:block;text-align:right;margin-bottom:10px;padding-right:15px;/* */background:transparent url(‘http://i.nuseek.com/Images/Shared/next.gif’) no-repeat right 50%;text-transform:capitalize}
.prevDisable {float:left;padding-left:15px;background:transparent url(‘http://i.nuseek.com/Images/Shared/prev.gif’) no-repeat 0 50%;color:#ccc;text-transform:capitalize}
.nextDisable {float:right;padding-right:15px;color:#ccc;text-transform:capitalize}
.pg2 .twoColL {background:#fff}

.resRelLinks {padding-top:20px}
.resRelLinks,.demandGadget {/*width:215px*/}
.resRelLinks_Hdr,.demandGadget_Header {background:#1b5709;color:#fff;font-weight:700;padding:5px 10px;margin-right:10px}
.resRelLinks ul,.demandGadget ul {padding:5px 10px;margin:0 10px 10px 0;background:#fafad9;list-style:none}
.resRelLinks li,.demandGadget li {margin:5px 0}
.resRelLinks a:link,.resRelLinks a:visited,.demandGadget a:link,.demandGadget a:visited {color:#476ec7;text-decoration:none;font-weight:400}
.resRelLinks a:hover,.demandGadget a:hover {text-decoration:underline;font-weight:400}
    /* JS DISPLAY */
    .resRelLinks span.outer {cursor:pointer}
    .resRelLinks span.outer:hover {text-decoration:underline;color:#476ec7}
    .resRelLinks li span.inner {color:#476ec7}

/* SEARCH */
.searchBox {width:100%;height:28px;background:#c44242;padding-top:3px;border-bottom:1px solid #fff}
.searchBox table {float:right;margin:0 10px 0 25px;display:inline}
.searchBox .SearchBoxText {font-size:16px;width:250px;border:1px inset #999}
.searchBox .sb_btn {width:60px;height:22px;margin-left:1px;background:transparent url(‘http://i.nuseek.com/images/Themes/T101/buttons/0006.gif’) no-repeat}

/* BOT NAV */
.searchLinkGroup {background:#1b5709;padding:5px 10px;font:400 11px verdana,sans-serif}
.searchLinkGroup h4 {color:#fff;font:700 100% Tahoma;text-transform:uppercase;display:inline}
.searchLinkGroup_Hdr {text-transform:uppercase;color:#fff;float:left;padding-right:5px;font-weight:700}
.searchLinkGroup ul {list-style-type:none;display:inline}
.searchLinkGroup li {display:inline;border-left:1px solid #fff}
.searchLinkGroup li.first {border-left:none}
.searchLinkGroup a:link,.searchLinkGroup a:visited {color:#fff;text-decoration:none;text-transform:uppercase;padding:0 7px/* */;background:#1b5709}
.searchLinkGroup a.first:link,.searchLinkGroup a.first:visited {padding:0 7px 0 0}
.searchLinkGroup a:hover {text-decoration:underline;color:#ff9}
    /* JS DISPLAY */
    .searchLinkGroup li span.outer {color:#fff;text-decoration:none;text-transform:uppercase;padding:0 7px/* */;background:#1b5709;cursor:pointer}
    .searchLinkGroup li span.outer:hover {text-decoration:underline;color:#ff9}

/* FOOTER */
.ftr {text-align:center;margin-top:10px}
.ftr a:link,.ftr a:visited {color:#0e5fd8}
.userCustom,.userCustom2 {color:#666;font:400 11px verdana,sans-serif}
.userCustom2 {text-align:center;padding-bottom:10px}
.forSale {color:blue;font-size:16px;font-weight:700}

/* AD 300×250 */
.banner {margin:10px 10px 10px 0}

/* BRIDGE */
#bridge {background:#fff;font:12px arial;color:#0e5fd8;margin-top:20px;text-align:center}
#bridge div.hdr {width:100%;background:#1b5709;border-bottom:none}
#bridge div.hdr h1 {color:#fff;font:bold 18px Verdana;text-transform:uppercase;padding:5px 0 5px 15px;border:1px solid #fff}
#bridge h4.explicit {color:#1b5709;font-size:14px}
#bridge p.strong {font-weight:600}
#bridge p,#bridge h4,#bridge ul,#bridge ol,#bridge li {margin:15px 0}
#bridge li {margin-left:40px}
#bridge #container {width:653px;text-align:left;margin:20px auto}
#bridge #cntwrap1 {background:#f3f3f3;border:4px solid #f3f3f3;margin:5px 0}
#bridge #cntwrap2 {border:1px solid #1b5709;padding-bottom:5px}
#bridge #cntwrap4 {color:#333 /* default */;padding:0 10px 10px}
#bridge div.call-to-action {text-align:center;margin:10px auto}
#bridge .ftr {height:15px;background:#1b5709;margin:5px 0;padding:5px 10px;text-align:left;border:1px solid #fff}
#bridge .ftr a.popuplink {color:#fff;font-size:10px;text-decoration:underline;cursor:pointer}
#bridge button.btn-enter {height:30px;background:#1b5709;color:#fff;padding:3px 15px;border:2px solid #333;border-top:2px solid #eee;border-left:2px solid #eee;cursor:pointer;font:bold 14px "Lucida Grande",Tahoma;text-transform:uppercase;letter-spacing:.05em}
#bridge button.btn-exit {margin-left:5px;height:30px;background:#1b5709;color:#fff;padding:3px 15px;border:2px solid #333;border-top:2px solid #eee;border-left:2px solid #eee;cursor:pointer;cursor:hand /* for IE 5.x */;font:bold 14px "Lucida Grande",Tahoma;text-transform:uppercase;letter-spacing:.05em}

———————————————————————————

another .js GET /gateway/gw.js?csid=F08747 HTTP/1.1 from Host: js.revsci.net

———————————————————————————

HTTP/1.1 200 OK
Server: Apache-Coyote/1.1
Last-Modified: Mon, 02 Feb 2009 06:14:00 GMT
Cache-Control: max-age=86400, public
Expires: Tue, 03 Feb 2009 06:14:00 GMT
Content-Type: text/javascript;charset=ISO-8859-1
Content-Encoding: gzip
Vary: Accept-Encoding
Date: Mon, 02 Feb 2009 06:14:00 GMT
Connection: close

‹

———————————————————————————

Tags:

Here is what we experienced…

—————————————————————————————————-

Visiting a website with YouTube videos on it today resulted in an infection notice from my resident AV… My coworkers also reported a similar message when viewing a Google video.

Repro:

  1. Visit hxxp://www.youtube.com/v/O7tB1pYSNuE&rel=1
  2. Get owned

 Google has been engaged and this is an open investigation so I am unable to relay anything more at this time.

—————————————————————————————————-

Here is what we found out, all is well:

—————————————————————————————————-

http://www.crunchgear.com/2008/12/02/actnsswift-virus-affecting-embedded-youtube-vids/

——————————————————

[UPDATE: Spoke with Google/YouTube and apparently anti-spyware software from Computer Associates had been returning false positives, identifying certain files contained within YouTube embed codes as malware. The specific YouTube issue is apparently being corrected by Computer Associates and wasn't actually harmful in the first place. If you've got CA software, you might want to check for any updates.]

——————————————————

http://www.supergeekblog.com/2008/12/youtube-virus-actnsswift/

——————————————————

“Good afternoon. This email is in regards to issue xxxxxx for eTrust AV. I am aware that you are being infected with ACTNS/SWIF.T VIRUS.

Support and the Research team is aware of this “false positive” and is actively working on releasing public signatures to correct this.

In the meantime you can download the beta signatures that will correct the false positive.

Thank you,

CA Technical Support

——————————————————

Tags:
October-14-08

Vundo Infection? No Problem

posted by 1C3Man

I came across this site the other day and highly recommend it if you’re, or a client is, suffering from a nasty Vundo infection.

AKA
Adware.VirtuMonde (Symantec)
Troj/AgentSpy-A (Sophos)
Trojan.Vundo.B (Symantec)

Visit http://www.removevundo.com/ for solid help removing the bad stuff.

Tags:
October-1-08

Real-time Outbreak Monitor

posted by 1C3Man

Cool little monitor from CommTouch

Tags:
September-29-08

Wells Fargo Poor Login Practices

posted by 1C3Man

Just a quick post to make Wells Fargo banking customers aware…

Apparently Wells Fargo has taken extra steps to remove the need for the username and password to be case sensitive when you log in. This makes the login process far less secure than if it were case sensitive. Additionally the password field has a vulnerability in that it discards characters after the password.

What does this mean?

Username “JohnDoe” could be entered “johndoe”, “johnDoe”, “JOHNDOE”, etc and it would always be accepted. Same applies for the password. That is bad because if you think about the number of combinations needed to bypass your username and password and it doesn’t require it to match the case you have removed more than half the time to crack it.

On the password character discarding issue the password could be “JohnDoePW” but the person trying to bypass this could just enter “johndoepw1234″ and still get in. Similar to before the number of attempts to bypass the password are dramatically reduced by not having it require an exact match. Not good…

If anyone has other banks that have similar vulnerabilities let them know.

Tags:
Theme Provided By: Wordpress Theme - Phoenix Online Degree