<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-8402228841467920387</id><updated>2011-11-27T16:51:58.338-08:00</updated><category term='TDSS'/><category term='hack'/><category term='pirates'/><category term='wired'/><category term='myspace spam hacking ebay exploit'/><category term='9.10'/><category term='slax'/><category term='comcast'/><category term='mount'/><category term='blackhat'/><category term='malware'/><category term='truecrypt'/><category term='buisness'/><category term='how to'/><category term='FBI'/><category term='09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0'/><category term='censorship'/><category term='hackers'/><category term='Schmoocon'/><category term='freedom'/><category term='DEM digital rights magagement windows vista'/><category term='goverment'/><category term='VMware'/><category term='internet riot'/><category term='spam'/><category term='whitehat'/><category term='spyware'/><category term='TDSS rootkit'/><category term='craigslist'/><category term='windows'/><category term='CIPAV'/><category term='Ubuntu'/><category term='fail'/><category term='dirty'/><category term='Directory Traversal'/><title type='text'>The MonKey juNGle</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>26</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-5672853066621805237</id><published>2010-02-12T13:06:00.000-08:00</published><updated>2010-02-12T13:25:06.678-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='VMware'/><category scheme='http://www.blogger.com/atom/ns#' term='Directory Traversal'/><category scheme='http://www.blogger.com/atom/ns#' term='Schmoocon'/><title type='text'>Directory Traversal Fun</title><content type='html'>I came across a few interesting posts today on this topic today and I thought I would share. The first one I landed on was an interesting read about a poorly secured malicious server from Russ McRee at HolisticInfoSec.com.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2010/02/directory-traversal-as-reconnaisance.html"&gt;http://holisticinfosec.blogspot.com/2010/02/directory-traversal-as-reconnaisance.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Next, I ended up on the OWASP page on testing for these kinds of vulnerabilities:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/Testing_for_Path_Traversal"&gt;http://www.owasp.org/index.php/Testing_for_Path_Traversal&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Then finally, a nice NMAP script for the VMware directory traversal vulnerability (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3733"&gt;CVE-2009-3733&lt;/a&gt;) recently discussed at Shmoocon:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://holisticinfosec.blogspot.com/2010/02/directory-traversal-as-reconnaisance.html"&gt;&lt;/a&gt;&lt;a href="http://www.skullsecurity.org/blog/?p=436"&gt;http://www.skullsecurity.org/blog/?p=436&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;good times.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-5672853066621805237?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/5672853066621805237/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=5672853066621805237' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/5672853066621805237'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/5672853066621805237'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2010/02/directory-traversal-fun.html' title='Directory Traversal Fun'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-1843898837997200578</id><published>2010-02-05T09:00:00.000-08:00</published><updated>2010-02-05T09:02:40.166-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='9.10'/><category scheme='http://www.blogger.com/atom/ns#' term='truecrypt'/><category scheme='http://www.blogger.com/atom/ns#' term='how to'/><category scheme='http://www.blogger.com/atom/ns#' term='Ubuntu'/><title type='text'>TrueCrypt Ubuntu 9.10</title><content type='html'>http://www.truecrypt.org/downloads&lt;br /&gt;&lt;br /&gt;get deb package&lt;br /&gt;&lt;br /&gt;untar file&lt;br /&gt;&lt;br /&gt;sudo sh ./truecrypt-6.3a-setup-ubuntu-x64&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-1843898837997200578?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/1843898837997200578/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=1843898837997200578' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/1843898837997200578'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/1843898837997200578'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2010/02/truecrypt-ubuntu-910.html' title='TrueCrypt Ubuntu 9.10'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-7762721032125810060</id><published>2009-12-29T20:17:00.001-08:00</published><updated>2010-01-02T10:05:36.467-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='buisness'/><category scheme='http://www.blogger.com/atom/ns#' term='comcast'/><category scheme='http://www.blogger.com/atom/ns#' term='fail'/><category scheme='http://www.blogger.com/atom/ns#' term='hack'/><title type='text'>two calls to comcast</title><content type='html'>one of our accounts got shut off. I called comcast business support to make a payment.&lt;br /&gt;&lt;br /&gt;800-391-3000&lt;br /&gt;&lt;br /&gt;1st prompt: new or existing crusty&lt;br /&gt;&lt;br /&gt;2nd prompt: Zip Code&lt;br /&gt;&lt;br /&gt;3rd prompt: tech support, billing....&lt;br /&gt;&lt;br /&gt;4th prompt: account details menu&lt;br /&gt;&lt;br /&gt;so comcast takes your ph&lt;span style="color: rgb(51, 204, 255);"&gt;o&lt;/span&gt;ne number and z&lt;span style="color: rgb(51, 255, 255);"&gt;i&lt;/span&gt;p code, then authenticates you into an account.&lt;br /&gt;&lt;br /&gt;In this particular case it happed to not  be my account.  I before I realized what was happening, I heard info on last payment date/amount, total balance due. hung up.&lt;br /&gt;&lt;br /&gt;call #2&lt;br /&gt;&lt;br /&gt;existing crust&lt;br /&gt;zip&lt;br /&gt;tech support --&gt; Hu&lt;span style="color: rgb(51, 51, 255);"&gt;m&lt;/span&gt;an&lt;br /&gt;&lt;br /&gt;    name, address, phone number&lt;br /&gt;&lt;br /&gt;three accounts pop (account from 1st call was not one of them).&lt;br /&gt;&lt;br /&gt;tech support explanation was that phone number links accounts across all comcast boards (biz/residential).&lt;br /&gt;&lt;br /&gt;busted.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-7762721032125810060?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/7762721032125810060/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=7762721032125810060' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/7762721032125810060'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/7762721032125810060'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2009/12/two-calls-to-comcast.html' title='two calls to comcast'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-7057978907908986494</id><published>2009-12-27T19:25:00.000-08:00</published><updated>2009-12-27T19:34:41.891-08:00</updated><title type='text'>new gmail privacy feature</title><content type='html'>Hey, this is important: We don't have a password recovery email address or phone number for your account. If you lose access, we may not be able to help you.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-7057978907908986494?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/7057978907908986494/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=7057978907908986494' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/7057978907908986494'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/7057978907908986494'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2009/12/new-gmail-privacy-feature.html' title='new gmail privacy feature'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-7413400977635006236</id><published>2009-12-23T15:03:00.000-08:00</published><updated>2010-01-02T11:31:26.575-08:00</updated><title type='text'>ubuntu security</title><content type='html'>this is not a guide.&lt;br /&gt;&lt;br /&gt;1. automated sniffing: Snort&lt;br /&gt;&lt;br /&gt;2. View Log Files:&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;  sudo gedit /var/log/XXX&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;3. manual sniffing: TCPDump &amp;amp; WireShark&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;sudo tcpdump -vvi eth1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;installing wireShark ubuntu:&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;sudo apt-get install wireshark&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;4.&lt;br /&gt;&lt;br /&gt;vulnerability scanner:Nessus&lt;br /&gt;&lt;br /&gt;http://ubuntuforums.org/showthread.php?t=27674&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;sudo apt-get install nessusd nessus nessus-plugins&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;sudo /etc/init.d/nessusd restart&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;register nessus.&lt;br /&gt;&lt;br /&gt;use this path if you used apt-get:&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;sudo /bin/nessus-fetch XXXXXXX&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;sudo update-nessus-plugins&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;not sure of your path?&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;dpkg -L nessus&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bias9.blogspot.com/"&gt;scan result break down&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;checks for rootKits.&lt;br /&gt;&lt;br /&gt;http://www.chkrootkit.org/&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;./chkrootkit -x | more&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;examine suspicious strings in the&lt;br /&gt;binary programs that may indicate a trojan&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;RooTkit Hunter:&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;sudo apt-get install rkhunter&lt;/span&gt;&lt;code&gt;&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;sudo rkhunter --propupd&lt;/span&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;then:&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;sudo rkhunter --check&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;5. AV&lt;br /&gt;&lt;br /&gt;http://www.itsecurity.com/features/ubuntu-secure-install-resource/&lt;br /&gt;&lt;/code&gt;&lt;h3&gt;Antivirus&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a target="_blank" href="http://www.clamav.net/"&gt;Clam AntiVirus&lt;/a&gt; - One of the most popular UNIX based antivirus solutions. Works well with email gateways.&lt;/li&gt;&lt;li&gt;&lt;a target="_blank" href="http://free.grisoft.com/freeweb.php/doc/5390/lng/us/tpl/v5#avg-anti-virus-free"&gt;AVG Anti-Virus&lt;/a&gt; - Free version of a popular commercial virus scanner.&lt;/li&gt;&lt;li&gt;&lt;a href="https://help.ubuntu.com/community/BitDefender"&gt;BitDefender&lt;/a&gt; - On demand command line/shell script scanner.&lt;/li&gt;&lt;li&gt;&lt;a target="_blank" href="http://www.pandasoftware.com/download/linux/linux.asp"&gt;Panda Antivirus&lt;/a&gt; - Uses sophisticated software to remove viruses from workstations connected to a Linux server.&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:78%;"&gt;6. fine tune the os&lt;br /&gt;&lt;br /&gt;turn off bonjour --&gt;&lt;br /&gt;&lt;br /&gt;sudo /etc/init.d/avahi-daemon stop&lt;br /&gt;&lt;br /&gt;sudo nano /etc/default/avahi-daemon&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;pre&gt;AVAHI_DAEMON_START=0&lt;br /&gt;&lt;br /&gt;sudo /etc/init.d/cups stop&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;http://www.zolved.com/synapse/view_content/27995/Top_Ten_basic_things_to_know_about_securing_Ubuntu&lt;br /&gt;1. http://ubuntuforums.org/showthread.php?t=7353&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-7413400977635006236?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/7413400977635006236/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=7413400977635006236' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/7413400977635006236'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/7413400977635006236'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2009/12/ubuntu-security.html' title='ubuntu security'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-1729638877161051668</id><published>2009-12-22T21:56:00.000-08:00</published><updated>2009-12-23T10:01:30.777-08:00</updated><title type='text'>youtube's Privacy Options</title><content type='html'>&lt;p&gt;I noticed today that there is flag for "privacy mode" in the "customize" options menu for embedding a youTube video.  According to google this feature is designed to give user's more control:&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;blockquote&gt;We've been working to give our users more options and control over these cookies. One such option is the privacy-enhanced mode for our embed player. This mode restricts YouTube's ability to set cookies for a user who views a web page that contains a privacy-enhanced YouTube embed video player, but does not click on the video to begin playback. YouTube may still set cookies on the user's computer once the visitor clicks on the YouTube video player, but YouTube will not store personally-identifiable cookie information for playbacks of embedded videos using the privacy-enhanced mode.&lt;/blockquote&gt;&lt;br /&gt;Awesome, thanks for the option. But hey, wait.  If privacy mode &lt;span style="color: rgb(204, 102, 204);"&gt;"on"&lt;/span&gt; means that you don't set cookies when a "user" views the page (instead when they actually click play), the past, and often current method, privacy mode &lt;span style="color: rgb(204, 102, 204);"&gt;"off"&lt;/span&gt;, is that you set cookies on a "user" machine every time someone views a web page with a youtube video embedded (regardless of whether or not they actually click play).&lt;br /&gt;&lt;br /&gt;Ok, so tracking cookies, no big deal right. Old news. Just wanted to point that out.&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-1729638877161051668?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/1729638877161051668/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=1729638877161051668' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/1729638877161051668'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/1729638877161051668'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2009/12/youtubes-privacy-options.html' title='youtube&apos;s Privacy Options'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-6654572469389451257</id><published>2009-12-07T19:47:00.000-08:00</published><updated>2009-12-07T20:16:43.177-08:00</updated><title type='text'>chess.com + meebo</title><content type='html'>noticed today that chess.com (who I recently paid for a membership too) slipped a meebo on me when I saw a small but crafty ad on the bottom left hand corner of my browser. some of those lowKey pop up toolbars work great, like on the hype machine, but in this case because I was not expecting it, it put me off.&lt;br /&gt;&lt;br /&gt;    I told her many stories about how the world could be, and she listened calmly. she knew right when I was going to finish my sentences, and saw my words in a clear and distant vision. we stood on the deck looking out into the valley. the cold mountain air was no match for our combined warmth. i held her close to me and felt the future from many years away. before I could see it up close, my attention snapped and I was tugged back to the evening. Maybe I wasnt supposed to get that close?  We stepped back in side, having seen something beautiful, strange and frightening.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-6654572469389451257?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/6654572469389451257/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=6654572469389451257' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/6654572469389451257'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/6654572469389451257'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2009/12/chesscom-meebo.html' title='chess.com + meebo'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-250594185452182460</id><published>2009-05-07T09:11:00.000-07:00</published><updated>2009-05-07T09:13:19.325-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='dirty'/><category scheme='http://www.blogger.com/atom/ns#' term='windows'/><category scheme='http://www.blogger.com/atom/ns#' term='mount'/><category scheme='http://www.blogger.com/atom/ns#' term='slax'/><title type='text'>mount dirty windows drive in slax</title><content type='html'>mount -t ntfs-3g -o force /dev/xxx /mnt/xxx&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-250594185452182460?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/250594185452182460/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=250594185452182460' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/250594185452182460'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/250594185452182460'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2009/05/mount-dirty-windows-drive-in-slax.html' title='mount dirty windows drive in slax'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-5888175439401203480</id><published>2009-04-18T20:57:00.000-07:00</published><updated>2009-04-18T20:58:25.101-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CIPAV'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='goverment'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><title type='text'>random text from CIPAV PDF</title><content type='html'>3 b o r t e d that residential address 6133 Winhwood Loop SE, Olympia, WA, 98515&lt;br /&gt;    received Comcast Internet services for the following subscriber:&lt;br /&gt;14&lt;br /&gt;            Sam Spiering&lt;br /&gt;:IS&lt;br /&gt;            6133 W i w o o d Loop SE, Lacey, WA 98513&lt;br /&gt;            Telephdne (360) 455-0569&lt;br /&gt;17&lt;br /&gt;            Dynamically Assigned Active Account&lt;br /&gt;            Account Number: 8498380070269681&lt;br /&gt;19&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;                    On June 4.2007. Cioogle provided subscriber, registration. and IF Address&lt;br /&gt;25&lt;br /&gt;     log history for e-mail address "douebriggS11236email.corn"with the following results:&lt;br /&gt;26&lt;br /&gt;                    E a l d (user deleted account)&lt;br /&gt;                     nbe&lt;br /&gt;27          Status:&lt;br /&gt;            Setvims: Talk, Search History, Gmail&lt;br /&gt;28&lt;br /&gt;   *&lt;br /&gt;&lt;br /&gt;                 On June 7,2007, a request to MySpace for subscriber and IP&lt;br /&gt;           b.&lt;br /&gt;            )&lt;br /&gt;ddress l&amp;amp;s for Myspace user "Timberlinebombinfo"provided the foilowing results:&lt;br /&gt;    User I :&lt;br /&gt;           D           199219316&lt;br /&gt;    Fs Name:&lt;br /&gt;     it&lt;br /&gt;      r                Doug&lt;br /&gt;    last Name: ,       Briggs&lt;br /&gt;                       Male&lt;br /&gt;     Gender;                    .&lt;br /&gt;     Dt of B r h&lt;br /&gt;      ae i t :         12110J1992&lt;br /&gt;     Age;              14&lt;br /&gt;"&lt;br /&gt;                       US&lt;br /&gt;     couq:&lt;br /&gt;                       Law&lt;br /&gt;    City:&lt;br /&gt;&lt;br /&gt;   stal Code:      985003&lt;br /&gt;                   Western Australia&lt;br /&gt;Region:&lt;br /&gt;Email'Address:'   tirnberljne.sucksB~mai1&lt;br /&gt;                                        .corn&lt;br /&gt;User Name:         timberlinebambinfo&lt;br /&gt;Sign up I Address:&lt;br /&gt;          P              80.76.80.103&lt;br /&gt;Sign up Date:     Juae 7,2007 7:49PM&lt;br /&gt;                   NIA&lt;br /&gt;Delete Date:&lt;br /&gt;                  June 7,20077:49:32:247 PM I Address 80.76.80.103&lt;br /&gt;                                              P&lt;br /&gt;Login Date&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;:page 76:&lt;br /&gt;&lt;br /&gt;15.   The C P A V will be deployed through an electronic messaging program&lt;br /&gt;    ,&lt;br /&gt;          conaolled by the FBI. The computers sending  and receiving the&lt;br /&gt;           CIPVA will be machines controlled by the FBI. The electtonic message deploying the&lt;br /&gt;            CIPAV will be directed to the administrator(s) of the "Timberlinebambinfo"&lt;br /&gt;     &lt;br /&gt;        Electronic messaging accouuts commonly require a unique user&lt;br /&gt;      a).&lt;br /&gt;              same and password.&lt;br /&gt;              Once the CIPAV is successfully deployed, it will conduct a one-&lt;br /&gt;      b.&lt;br /&gt;       )&lt;br /&gt;              time search of the activat'ing computer and capture the information&lt;br /&gt;              desctibed in paragraph seven.&lt;br /&gt;              The captured information will be forwarded to a computer&lt;br /&gt;      c).&lt;br /&gt;              conmlled by the FBI located within the Eastern Disuicc of&lt;br /&gt;          ,&lt;br /&gt;              Virginia.&lt;br /&gt;              After the onetime search, the CIPAV will function asa pen register&lt;br /&gt;      d).&lt;br /&gt;              device anxl record the muting and destination addressing information&lt;br /&gt;              for electronic communications originating f o the activahg&lt;br /&gt;                                                           rm&lt;br /&gt;              computer.&lt;br /&gt;&lt;br /&gt;    The pen register will recod PB address, dates, m d times of the&lt;br /&gt;e).&lt;br /&gt;    electronic comwnicatiom, but not the aoutents of such&lt;br /&gt;    ccmmunieatioas or the contents contained on the computer, and&lt;br /&gt;                   address data to a computer cantroned by bhye&lt;br /&gt;    U'mard the&lt;br /&gt;    FBI,P r p d o d of (60) days.&lt;br /&gt;           w&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-5888175439401203480?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/5888175439401203480/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=5888175439401203480' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/5888175439401203480'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/5888175439401203480'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2009/04/random-text-from-cipav-pdf.html' title='random text from CIPAV PDF'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-3526984842908898909</id><published>2009-04-18T18:11:00.000-07:00</published><updated>2009-12-23T21:19:36.985-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CIPAV'/><category scheme='http://www.blogger.com/atom/ns#' term='malware'/><category scheme='http://www.blogger.com/atom/ns#' term='wired'/><category scheme='http://www.blogger.com/atom/ns#' term='goverment'/><category scheme='http://www.blogger.com/atom/ns#' term='FBI'/><category scheme='http://www.blogger.com/atom/ns#' term='spyware'/><title type='text'>more info released on FBI's home brewed malware, CIPAV</title><content type='html'>Recently, the &lt;a href="http://en.wikipedia.org/wiki/Freedom_of_Information_Act_%28United_States%29"&gt;Freedom of Information Act&lt;/a&gt; was invoked by the EFF, CNET and Wired to declassify documents relating to the FBI's home brewed malware,  CIPAV.&lt;br /&gt;&lt;br /&gt;The newly released PDF weighs in at a healthy 150 pages, with info on various requests and cases where CIPAV was used.&lt;br /&gt;&lt;br /&gt;At this time it does not seem to be public knowledge exactly what the software does and more importantly, how it gets on the "victims" machine.&lt;br /&gt;&lt;br /&gt;After a 2007 affidavit some of the security community's finest had put together a pretty good profile of what the software was likely doing:&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;The full capabilities of the FBI's "computer and internet protocol address verifier" are closely guarded secrets, but here's some of the data the malware collects from a computer immediately after infiltrating it, according to a bureau affidavit acquired by Wired News. &lt;/p&gt;  &lt;ul&gt;&lt;li&gt;IP address  &lt;/li&gt;&lt;li&gt;MAC address of ethernet cards  &lt;/li&gt;&lt;li&gt;A list of open TCP and UDP ports  &lt;/li&gt;&lt;li&gt;A list of running programs  &lt;/li&gt;&lt;li&gt;The operating system type, version and serial number  &lt;/li&gt;&lt;li&gt;The default internet browser and version  &lt;/li&gt;&lt;li&gt;The registered user of the operating system, and registered company name, if any  &lt;/li&gt;&lt;li&gt;The current logged-in user name &lt;/li&gt;&lt;li&gt;The last visited URL &lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.schneier.com/blog/archives/2007/07/federal_agents_1.html"&gt;http://www.schneier.com/blog/archives/2007/07/federal_agents_1.html&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;More clues are likely to emerge from the recently released documents, but my guess is that it will still remain a guessing game as to what exactly the software does.&lt;br /&gt;&lt;br /&gt;Regardless of what information the malware collects, the new documents shed some interesting light on the complicated and precise environment that the malware is supposed to run in on &lt;a href="http://news.cnet.com/8301-10784_3-9746451-7.html"&gt;one&lt;/a&gt; particular case.  On page 78 of the PDF it is noted that the software should only be &lt;span style="font-weight: bold;"&gt;deployed&lt;/span&gt; between the hours of 6AM and 10PM PST.  Once deployed, messages can &lt;span style="font-weight: bold;"&gt;read&lt;/span&gt; coming from the infected machine at any time. Interesting for sure, perhaps even a bit strange. My guess is that the deployment hours correlate to previous bomb threats, and thus the regulated window, but thats purely speculation.&lt;br /&gt;&lt;br /&gt;In the following page of the PDF, 79 it is noted that if the CIPAV does not activate on the victims machine, they will attempt to deploy and activate until successful. This with in the 10 day allotted window for deployment. This seems to be a key factor in understanding how this malware works. An application to collect the above mentioned data could be written in any number of languages and hidden on the machine in an overwhelming number of ways. When you consider the infection from the FBI's point of view, it would probably make the most sense to send a windows based app first, but maybe its all universal now anway?. First thing it does after activation is open up an SSL connection and phone home, IP, MAC, last URL and so on... Now, if activation does not occur right away, they act quickly while the Myspace vunerablilty is still active and  send over a totally different app, wait for phone home and repeat.&lt;br /&gt;&lt;br /&gt;The &lt;a href="http://blog.wired.com/27bstroke6/2007/07/fbi-spyware-how.html"&gt;Wired&lt;/a&gt; article does a great job of looking at the attack vector.&lt;br /&gt;&lt;br /&gt;Lots more interesting info coming out of that PDF. I'm looking forward to the next fews days.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-3526984842908898909?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/3526984842908898909/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=3526984842908898909' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/3526984842908898909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/3526984842908898909'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2009/04/more-info-released-on-fbis-home-brewed.html' title='more info released on FBI&apos;s home brewed malware, CIPAV'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-3171423862088989401</id><published>2009-04-14T15:54:00.000-07:00</published><updated>2009-04-14T19:43:51.768-07:00</updated><title type='text'>Malware String Analysis Part 1 - Getting the Strings</title><content type='html'>String analysis can be very useful when it comes to researching and gathering information on suspicious or unknown files.  There is all different kinds of information that can be gathered from the strings of a file, and there are of course any number of ways to obtain and process this information. In this "part 1" i'm going to go over some of the more common ways to extract the strings from a file.&lt;br /&gt;&lt;br /&gt;If you are doing your research on a windows machine, one of the easiest ways to extract the strings of a file is to use the  Sysinternals tool &lt;a href="http://technet.microsoft.com/en-us/sysinternals/bb897439.aspx"&gt;Strings&lt;/a&gt;&lt;span style="text-decoration: underline;"&gt;.&lt;/span&gt;  I like to run application against files with a batch file in the "send to" folder. This allows me to simply right click on the file in question and click "send to", then,  Strings". As instructed by my batch file, the app pushes the extracted strings into a txt file for me. You can set your research box up in a similar fashion by doing the following:&lt;br /&gt;&lt;br /&gt;click start, run, the type "sendto"&lt;br /&gt;&lt;br /&gt;This will open the sendto folder. Right click, "new", "text document". Here's what I use, but you could of course modify as you like:&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;strings -a %1 &gt;"C:\strings.txt"&lt;br /&gt;"C:\strings.txt"&lt;br /&gt;exit&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/blockquote&gt;Make sure you save the file with the extension .bat, and not .txt. Strings.bat is a pretty good name.&lt;br /&gt;&lt;br /&gt;As stated on the man page on in the link above, there are various options you can use with the Strings command:&lt;br /&gt;&lt;br /&gt;Using Strings&lt;p&gt;&lt;strong&gt;Usage: strings.exe [-a] [-b bytes] [-n length] [-o] [-q] [-s] [-u] &lt;file&gt;&lt;/file&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Strings takes wild-card expressions for file names, and additional command line parameters are defined as follows:&lt;/p&gt;&lt;table width="100%" border="0" cellpadding="1" cellspacing="2"&gt;&lt;tbody&gt;&lt;tr valign="top" align="left"&gt;&lt;td width="30"&gt;&lt;strong&gt;-s&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Recurse subdirectories.&lt;/td&gt;&lt;/tr&gt;&lt;tr valign="top" align="left"&gt;&lt;td&gt;&lt;strong&gt;-o&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Print offset in file string is located.&lt;/td&gt;&lt;/tr&gt;&lt;tr valign="top" align="left"&gt;&lt;td&gt;&lt;strong&gt;-a&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Scan for ASCII only.&lt;/td&gt;&lt;/tr&gt;&lt;tr valign="top" align="left"&gt;&lt;td&gt;&lt;strong&gt;-u&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Scan for UNICODE only.&lt;/td&gt;&lt;/tr&gt;&lt;tr valign="top" align="left"&gt;&lt;td&gt;&lt;strong&gt;-b bytes&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Bytes of file to scan.&lt;/td&gt;&lt;/tr&gt;&lt;tr valign="top" align="left"&gt;&lt;td&gt;&lt;strong&gt;-n X&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Strings must be a minimum of X characters in length.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;To search one or more files for the presence of a particular string using strings use a command like this:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;strings * | findstr /i TextToSearchFor&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;Using the above method you should be able to extract the strings of a file pretty quickly with out much of a hassle.&lt;br /&gt;&lt;br /&gt;If you want to do the same on Linux, chances are that you already have the necessary tool. If you type "strings" at the command prompt you know pretty quickly.  In order to get this working the same as the Sysinternals tool you will need to add some extra arguments as its defualt output is pretty raw. I'm not entierly sure what those are as I usually just rip the strings off my windows research box, but if anyone know the equivilant command please post it up.&lt;br /&gt;&lt;br /&gt;Really basic stuff, but there is all kinds of interesting things that can come from those strings.  Next time we'll looks at some output files and a cool tool called &lt;a href="http://code.google.com/p/yara-project/"&gt;Yara&lt;/a&gt;, that helps parse the strings all quick like.&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;p&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-3171423862088989401?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/3171423862088989401/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=3171423862088989401' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/3171423862088989401'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/3171423862088989401'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2009/04/malware-string-analysis-part-1-getting.html' title='Malware String Analysis Part 1 - Getting the Strings'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-6157442190969252139</id><published>2009-01-08T11:37:00.000-08:00</published><updated>2009-01-08T11:45:26.832-08:00</updated><title type='text'>Virtual box w/Ubuntu 8.10 x64</title><content type='html'>Started here:http://www.howtoforge.com/installing-virtualbox-2.0.0-on-ubuntu-8.10-desktop&lt;br /&gt;&lt;br /&gt;Ok, well that was so easy and worked exactly as expected that there is no need to write anything up. awesome.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-6157442190969252139?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/6157442190969252139/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=6157442190969252139' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/6157442190969252139'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/6157442190969252139'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2009/01/virtual-box-wubuntu-810-x64.html' title='Virtual box w/Ubuntu 8.10 x64'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-7017061937491480002</id><published>2008-11-27T09:25:00.000-08:00</published><updated>2008-11-27T10:22:31.598-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='TDSS rootkit'/><category scheme='http://www.blogger.com/atom/ns#' term='TDSS'/><title type='text'>TDSS Rootkit Removal</title><content type='html'>I got a call the other day from a friend asking if I could take a look at his computer. Based on what he described, it sounded like a pretty standard combo infection of Anti-Virus 2009 and FakeAlert. He gave me the box, and a few days later I took a look.&lt;br /&gt;&lt;br /&gt;The box would only boot into Windows successfully about one out of every 4 times. Once into windows, I found Antivirus 2009 and FakeAlert.  As always, I tried the easiest things first, install Spy Sweeper and or Hijack This.  Neither would install normally, so I changed the HJT folder name and .exe name, still would not run. Although Spy Sweeper would install, upon reboot it would say that the install was corrupt or something. At this point I should have realized there was a Rootkit.&lt;br /&gt;&lt;br /&gt;I booted the box into a Slax live CD and went about removing AntiVirus2009 manually. Slax doesn't mount NTFS drives with write privileges by default, in order to accomplish this I ran the following commands:&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;umount /dev/hda2&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;ntfsmount /dev/hda2  /mnt/hda2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Now, had I know there was a rootkit and know a little about it TDSS, I could have probably killed it this time around. As I didn't, the process ended up taking quite a bit longer. Instead of simply removing Antivirus2009, I should have tried something like:&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;cd /mnt/hda2/windows/system32/drivers&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;ls tdss*&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;rm tdss*&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;cd ..&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 204, 0);"&gt;ls&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;and delete all .exe and .dll files with dates of 2009 on them (this may not work in a few months!)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Since I didn't realize there was a rootkit I simply removed Antivirus 2009 and rebooted.&lt;br /&gt;&lt;br /&gt;Once I booted back into Windows I saw that fakealert was still there (and re-installing  Antivirus2009) I decided to run rootkit revealer and see what it came up with. Sure enough there were a few entries for TDSSserv.sys and TDSSdata, and then two errors where it said it couldn't mount the the C and D driver. Did a little research on TDSS and realized that the box was most definitely rootkitted.&lt;br /&gt;&lt;br /&gt;I played with the registry through regedit, but guess what, the only TDSS entries that were showing up were legacy data that would not stop the rootkit.  No surprise.  I searched the intewebs, read a variety of posts, grabbed a bunch of tools, Gmer, Icesword, and a bunch of others that I didn't end up using. I also created a UBCD4WIN boot disk based on this&lt;a href="http://www.s-t-f-u.com/2008/10/29/rootkit-tdsssys-sucks-worse-than-a-2-dollar-whore-remove-it/"&gt; http://www.s-t-f-u.com/2008/10/29/rootkit-tdsssys-sucks-worse-than-a-2-dollar-whore-remove-it&lt;/a&gt;/ excellent post.&lt;br /&gt;&lt;br /&gt;Now since I removed antivirus 2009 manually through Slax, I had created some discrepancies or problems with the disk. It still booted, into windows, but would not run a scheduled CHKDSK and I could no longer mount the volume in Slax because it gave some error, saying the volume was dirty and needed a chkdsk run.&lt;br /&gt;&lt;br /&gt;I guess I really didnt need the UBCD4Win, as after like 15 mins it still hadn't booted, and  because I'm impatient I just killed it and and used it to boot into the recovery console, but still, seems like something I will most definitely be using in the future.&lt;br /&gt;&lt;br /&gt;After booting into the recovery console, I did what I should have done though Slax the first time around, and went to system32 removed all .exe's and .dll's with 2009 timestamps on them (at the time of this writing, that worked great, but probably wont soon as its almost 2009), and then into system32/ drivers got rid of all the TdssXXXX.sys files (where X= equals random characters). There were also some .ini files with 2009 dates on them that I probably could have removed, but didn't.&lt;br /&gt;&lt;br /&gt;Rebooted into windows, to find that fakealert was still there. Opened Icesword (which is a fuking cool app) and killed the fakealert .exe manually (bratsk.exe or something).  Since I couldn't find a way to search the registry though Icesword I just used regedit to search for "tdss" then navigated to those locations in IceSword (it takes care of permissions so deleting keys is far easier than in regedit) and delete the fuk out of anything tdss.  The most interesting by far was the disallow section of TDSSDATA (I think that was it). It contained all the hooks that kept SS, Gmer, and all those other apps from running.   I was able delete all TDSS entries. Rebooted.&lt;br /&gt;&lt;br /&gt;Still had Fakealert. Searched the registry for TDSS. TDSSDATA was still there, but it looked like it hadn't fully set up as the keys were not there. Deleted it.  At this point I was able to successfully install my prefered malware removal app (and inserted newest def set manually cause I work for them)  and when I rebooted, the CHKDSK that I had scheduled many boot cycles actually kicked off.&lt;br /&gt;The malware removal app install went through this time and I ran a full scan. Still waiting to see what all it found and removed, but at this point i'm pretty confident that the TDSS rootkit is dead.  Big ups to the TDSS guy though, thats a pretty nice rootkit, and I know for a fact that you have at least one major malware vendor re-working their engine to accommodate removal (even if you hit after the engine was installed). &lt;br /&gt;&lt;br /&gt;So, for the first time after getting the box, i feel safe connecting it up to the intewebs to get some likely much needed updates which is my guess where this came from.&lt;br /&gt;&lt;br /&gt;Also, I heard that Microsoft released an update this week that removed over 1 million copies of rogue Antivirus apps? very interesting.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-7017061937491480002?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/7017061937491480002/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=7017061937491480002' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/7017061937491480002'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/7017061937491480002'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2008/11/tdss-rootkit-removal.html' title='TDSS Rootkit Removal'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-568182129446009871</id><published>2008-11-11T09:50:00.000-08:00</published><updated>2008-11-11T09:52:05.498-08:00</updated><title type='text'>Enabling VNC in Ubuntu Intrepid</title><content type='html'>If you want to use the VNC viewer client in Ubuntu Intrepid but its greyed out, simply run:&lt;br /&gt;&lt;pre&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;sudo apt-get install xtightvncviewer&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;and you should be all set.&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-568182129446009871?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/568182129446009871/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=568182129446009871' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/568182129446009871'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/568182129446009871'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2008/11/enabling-vnc-in-ubuntu-intrepid.html' title='Enabling VNC in Ubuntu Intrepid'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-2300286379646011322</id><published>2008-11-08T09:43:00.000-08:00</published><updated>2008-11-08T10:30:50.258-08:00</updated><title type='text'>DarkIce with Darksnow Debian Etch</title><content type='html'>Ugh. This was slightly painful process, heres what I ended up doing:&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);" class="postbody"&gt; apt-get source darkice&lt;br /&gt;apt-get install liblame-dev&lt;br /&gt;apt-get build-dep darkice&lt;br /&gt;cd darkice*&lt;br /&gt;vi debian/rules&lt;br /&gt;# remove --without-lame&lt;br /&gt;dpkg-buildpackage&lt;br /&gt;cd ../&lt;br /&gt;dpkg -i darkice*.deb&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;apt-get install libgtk2.0-dev&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Find and download Darksnow, as of this writing, i was able to get the latest deb release here:http://www.twiki.ufba.br/twiki/pub/RadioFACED/ComoFunciona/darksnow_0.5.2-1_i386.deb&lt;br /&gt;&lt;span style="color: rgb(0, 0, 255);font-family:courier new,courier,monospace;" &gt;&lt;br /&gt;unzip&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;cd darksnow-0.X.X&lt;/span&gt;&lt;/span&gt;&lt;span style="color: rgb(0, 0, 255);font-family:courier new,courier,monospace;" &gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;./configure&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;make&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;make install&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;Added these to /etc/apt/sources.list&lt;span style="color: rgb(0, 0, 255);font-family:courier new,courier,monospace;" &gt;&lt;span style="color: rgb(51, 255, 51);"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;deb http://archive.ubuntu.com/ubuntu dapper main restricted universe multiverse&lt;br /&gt;deb-src http://archive.ubuntu.com/ubuntu dapper main restricted universe multiverse&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;sudo apt-get install lame liblame0&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 255);font-family:courier new,courier,monospace;" &gt;&lt;span style="color: rgb(51, 255, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;This will need some updating, still tweaking...use at your own risk.&lt;span style="color: rgb(0, 0, 255);font-family:courier new,courier,monospace;" &gt;&lt;span style="color: rgb(51, 255, 51);"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-2300286379646011322?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/2300286379646011322/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=2300286379646011322' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/2300286379646011322'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/2300286379646011322'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2008/11/darkice-with-darksnow-debian-etch.html' title='DarkIce with Darksnow Debian Etch'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-277626708692030395</id><published>2008-11-05T16:08:00.000-08:00</published><updated>2008-11-06T08:38:04.709-08:00</updated><title type='text'>Upgrading Snort Schema from 1.06 to 1.07</title><content type='html'>Use this if you need to update you snort DB Schema from 1.06 to 1.07: &lt;span style="color: rgb(51, 255, 51);"&gt;&lt;br /&gt;&lt;br /&gt;USE snort;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;ALTER TABLE signature ADD sig_gid INT UNSIGNED;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;INSERT INTO `schema` (vseq, ctime) VALUES ('107', now()); &lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;DELETE FROM `schema` where vseq = '106';&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;The only change to the tables comes from the second line. The last two lines are just for updating the version number. &lt;span style="color: rgb(51, 255, 51);"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-277626708692030395?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/277626708692030395/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=277626708692030395' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/277626708692030395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/277626708692030395'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2008/11/upgrading-snort-schema-from-106-to-107.html' title='Upgrading Snort Schema from 1.06 to 1.07'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-4143891304445149345</id><published>2008-11-05T08:27:00.000-08:00</published><updated>2008-11-05T09:45:07.802-08:00</updated><title type='text'>Install Base and Apache2 Ubuntu 8.10 interpid</title><content type='html'>&lt;span style="font-weight: bold; color: rgb(51, 255, 51);"&gt;sudo apt-get install apache2 php5-mysql libphp-adodb &lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;br /&gt;If you get a message about the path to adodb changing, take note on what the new path is. &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;cd /var/www&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;sudo wget http://downloads.sourceforge.net/secureideas/base-1.4.1.tar.gz?modtime=1217804205&amp;amp;big_mirror=0&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;You might not want to copy and paste the above code as it could be outdated. Just download the newest version and drop it in /var/www and unpack.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;&lt;br /&gt;sudo tar -xvzf base-1.4.1.tar.gz&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold; color: rgb(51, 255, 51);"&gt;sudo rm base-1.4.1.tar.gz&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(51, 255, 51);"&gt;sudo mv base-php4 base&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Change "base" to whatever you want your path to base to be: IE http://mywebserver/base&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;sudo apt-get install php-pear php5-gd&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(51, 255, 51);"&gt;sudo pear install Mail Mail_Mime Image_Color Image_Canvas-alpha    Image_Graph-alpha&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;Open a web browser and navigate to  you website, http://localhost/base/ which should take you to, http://localhost/base/setup/setup1.php&lt;br /&gt;&lt;br /&gt;Make sure it says that your config file is writable. If not, you could try something like:&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(51, 255, 51);"&gt;&lt;br /&gt;sudo chmod -R 777 base&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;The next screen will ask you for the path to adodb&lt;span style="font-weight: bold;"&gt;. &lt;/span&gt;If you are not sure what that is, you could try something like:&lt;br /&gt;&lt;span style="font-weight: bold; color: rgb(51, 255, 51);"&gt;&lt;br /&gt;sudo find / -name adodb&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span&gt;The next screen will ask for your DB connection information. Since this guide does not cover getting snort set up I will assume you already have snort set up and know you database information.  &lt;/span&gt;&lt;span&gt;Add information as necessary. &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;&lt;br /&gt;The final screen will ask if you want would like to require authentication to access the BASE website. I highly recommend setting up a user. &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;Should be all set up after that. Depending on how many snort alerts are in your DB and various other hardware related factors, it could take some time for BASE to query the data in the database, so be patient if it doesn't come up right away!&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-4143891304445149345?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/4143891304445149345/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=4143891304445149345' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/4143891304445149345'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/4143891304445149345'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2008/11/install-base-and-apache2-ubuntu-810.html' title='Install Base and Apache2 Ubuntu 8.10 interpid'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-6434395931920044436</id><published>2008-10-30T12:40:00.000-07:00</published><updated>2008-10-30T12:44:37.980-07:00</updated><title type='text'>Keys not working In VMware</title><content type='html'>I'm posting this primarily as a reminder to me, but perhaps it will help some else as well.  I just upgraded to Ubuntu 8.10 beta 64bit, installed VMware 6.5 and my up and down arrows were not working (one was opening the windows menu and some other crazy stuff).  A co-worker of mine pointed me towards this handy little fix:&lt;br /&gt;&lt;h3&gt; &lt;span class="mw-headline"&gt;Function/arrow keys, etc. not working&lt;/span&gt;&lt;/h3&gt; &lt;p&gt;&lt;b&gt;This is an upstream bug in VMware’s code.&lt;/b&gt;  If your keyboard is not functioning correctly in VMware, add this line to &lt;code&gt;~/.vmware/config&lt;/code&gt; (create file if necessary): &lt;/p&gt; &lt;pre&gt;xkeymap.nokeycodeMap = true&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.ultimalinux.com/wiki/VMware"&gt;http://www.ultimalinux.com/wiki/VMware&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Worked like a charm. Awesome.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-6434395931920044436?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/6434395931920044436/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=6434395931920044436' title='11 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/6434395931920044436'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/6434395931920044436'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2008/10/keys-not-working-in-vmware.html' title='Keys not working In VMware'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>11</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-7437787803966889146</id><published>2008-10-23T09:08:00.000-07:00</published><updated>2008-10-23T09:10:22.677-07:00</updated><title type='text'>Microsoft Emergency Patch</title><content type='html'>&lt;div id="body"&gt; &lt;p&gt;"Microsoft is about to issue an emergency security update to plug a vulnerability which could allow an internet worm to be spread via a computer without the user doing anything.&lt;/p&gt;  &lt;p&gt;The update is rated as critical for users of Windows 2000, XP and Server 2003 and the less severe rating of "important" for users of Windows Server 2008 and Windows Vista. The patch is scheduled for 10.00am Pacific Time (6pm BST).&lt;/p&gt;  &lt;p&gt;There will be &lt;a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032393978&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US" target="_blank"&gt;a webcast&lt;/a&gt; at 1.00pm Pacific Time (9pm BST) explaining the issue in more detail.&lt;/p&gt;  &lt;p&gt;The exploit potentially allows remote code to be executed.&lt;/p&gt;  &lt;p&gt;The Advance Notification is &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx" target="_blank"&gt;here.&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Microsoft tries to make life easier for administrators by bundling its updates into one monthly slot, known as Patch Tuesday, in the second week of every month. It has broken this cycle &lt;a href="http://www.theregister.co.uk/2004/02/03/ms_plugs_ie_phishing_bug/"&gt;before&lt;/a&gt;, but it is unusual. "&lt;br /&gt;&lt;/p&gt; &lt;/div&gt;&lt;br /&gt;&lt;a href="http://www.theregister.co.uk/2008/10/23/windows_emergency_update/"&gt;&lt;br /&gt;http://www.theregister.co.uk/2008/10/23/windows_emergency_update/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-7437787803966889146?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/7437787803966889146/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=7437787803966889146' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/7437787803966889146'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/7437787803966889146'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2008/10/microsoft-emergency-patch.html' title='Microsoft Emergency Patch'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-4263743297596298145</id><published>2007-10-01T19:47:00.000-07:00</published><updated>2007-10-01T21:42:51.918-07:00</updated><title type='text'>I'm Not Allowed In Canada</title><content type='html'>As a kid, I always wanted to travel for business. The lure of distant cities and strange adventures has always had a mysterious glowing appeal to me.  A month or so ago I was  promoted, and with the promotion came the opportunity to do just that.   Now I would get to travel, and I'd be getting paid to do it.&lt;br /&gt;&lt;br /&gt;My first trip was to a relatively small island North West of Seattle.  Not bad for getting my feet wet.  Throw a ferry in there, a cool rent a car, a nice little hotel, and it was a pretty nice trip overall.&lt;br /&gt;&lt;br /&gt;The thing is though, when I think of travel, be it business or leisure,  I'm looking for some action.  I don't mean that like A-Team style action either, just a little good old fashioned excitement.  Upon making my way up to a small city of Regina, in the Canadian  province of Saskatchewan I got a little more than I bargained for.&lt;br /&gt;&lt;br /&gt;I walked out of my front door at the brisk hour of 5AM.  I began the 10 minute walk to the airport bus in style,  nodding my head un-rhythmically to Tool's epic 46 and 2.&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt; I wanna feel the change consume me,&lt;br /&gt;Feel the outside turning in.&lt;br /&gt;I wanna feel the metamorphosis and&lt;br /&gt;Cleansing I've endured within&lt;/blockquote&gt;&lt;br /&gt;My timing was bad, as I approached the intersection upon where I would catch the elusive AB bus to DIA.  As I began to cross the street, going a list of items in my head. At that moment, it struck my sharply  and painfully.  My passport was still sitting on my desk at home.  This seemed to set the tone of the day.  If I only knew what I was in for.&lt;br /&gt;&lt;br /&gt;I angrily walked home grabbed my passport and caught the next bus. This put me at the air port about 60 minutes before departure.  Not ideal for an international flight, but it would do.  As I snaked though the rapidly moving and dreadfully long lines of security I recalled an unfortunate even that had landed me in a Denver court a little over a year before. How I had forgot to remove a knife from my book bag I can't say.  Why I had an illegal switch blade in the first place is easy.  It was a gift from a friend a few years ago who was leaving town on a plane and knew better than taking it to the air port.  As  I put my shoes back on and headed for the terminal I felt a sigh of relief move though my body,  no arguing with the TSA goons about what constitutes an illegal knife this time.  Things were looking up.&lt;br /&gt;&lt;br /&gt;Upon arriving in Calgary, I quickly made my way to customs and started in on the rat race.  Upon refection, this is the one place I could have strategically avoided the mess I was about to be in.  "I'm just visiting a friend" is all I would have had to say.   Instead I  said I was on business, which then lead to the inevitable "what kind of business?" and catastrophically to  "you ever been arrested?".  At this point I did what I have done for the past 9 years when asked that question, or at least some situational variation there of.  I though of course he was looking at my conviction for brining an illegal switch blade into the airport.  I threw it out there,  being truthful, "I accidentally brought a knife to the air port". He pried, "what kind of kife?" I dropped the bomb.  "a switch blade". A tense silence gripped the air.  "ever been arrested for anything else?" he dropped nonchalantly.     "uhh yeah, I stumbled" quickly catching pace.  "Once in Ohio, for disturbing the peace."  "and what happened there" he quickly questioned.  I knew I could leave out the details on this one. There was no need for me to dip into the gritty details. What good would do for him to know about how we were  snaked from the back and chased down that icy river bank by an unknown number of cops with lazer guided tazers.  "Oh you know, my and a buddy drank a little to much, just out side causing a ruckus." I though about sitting in that cop car on Christmas eve,  as the cops tried to mad dog me.  "we know what you did, if you admit we'll let you go" there wasn't a chance I was going to fess up.  Apparently my buddy already had, and even though I refused to break, they let us go with a pay out ticket.   It was then that the real bomb dropped.  "what about 99, you get in any trouble then?" I knew right away this was a problem.  Confused and shook, I answered with a question "in 99?", in the same way that Ron Burgandy might if some one were to throw a question mark on his teleprompter.   "yeah it uhh says here you have a felony, trafficking a controlled substance, Marijuana".  The last time I had heard or seen a word about this case was just over 9 years ago, and  I was signing away some plea, that apparently I did not read closely enough.  For the last 9 years I was under the impression that as my lawyer told  me, the charge was dropped to some minuscule offense, "attempting to bring prescription pills into interstate commerce with out a prescription."  This apparently was not the case. I pushed the confusion aside to deal with the matter at hand.  If I was denied entry into Canada it could potentially have a relatively unsavory effect on my job.  I was not prepared to let this happen.  I was search and questioned relentlessly.  Every credit card was removed from my wallet, the bottoms of my pockets searched for residue.  I realized how bad things could really get it they were to run some swabs on my ID or probably half the cards in my wallet.  I stared coldly into the air as the woman sifted though my underwear.   I was taken back to the customs officer and asked to wait while they discussed what was to happen next.   I pondered the Canadian law that kept felons from entering the country.  I pondered the idea that I had been felon for the last 9 years and not known it.  I was called to the desk by the customs official.  I was convinced I was going home.  He engaged me in some conversation about the quantity of marijuana I had on my possession at the time. "funny thing is I told him, we didnt even have any", Which is entirely true. (we did have Hash but they didn't even know what it was)  He looked at me blankly. I though about explaining to him what had actually happened on that cool Nevada night. I though about the cute blond girl back home that I had a crush  on, and couldn't stop thinking about.  "two grams" I corrected.  "thats it?" he said.  "Yeah, Nevada is no tolerance state there is no such thing as a 'personal amount'." I said. "Really?" he said, "well in Canada there is, and there is also a thing up here that we practice called balance, I'm going to seize your passport, and let you go do your business, but I'm not actually admitting you into Canada". For that moment,  I had a small amount of faith in humanity temporarily restored.   I signed a few papers, he took my passport, I headed to nearest airport bar, gulped down two large Heineken's  just in time to jump on my connecting flight to Regina.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-4263743297596298145?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/4263743297596298145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=4263743297596298145' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/4263743297596298145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/4263743297596298145'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2007/10/im-not-allowed-in-canada.html' title='I&apos;m Not Allowed In Canada'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-8052321247482588347</id><published>2007-07-19T20:50:00.001-07:00</published><updated>2007-07-19T21:50:02.274-07:00</updated><title type='text'>I hate Myspace</title><content type='html'>Yes I did have a profile or two for some time, but for the love all things holy.  Now that my job involves me to work on the internet all day, I don't get the same pleasure out of surfing the web.  Its no secret the way these things work, its fun until it becomes your job and then no more right? Well maybe not.  These days I am permitted to flow as I please across networks across the world.  For the most part I am confined to the states, but on special occasions I make connections abroad.  Dealing with IT folks is for the most part a pleasure.  I guess that part of it is really relative to who you are though right? Back to the subject at hand though.  I am convinced that internet is by far the most amazing and strange change we will ever see in our life time, or I should say has the greatest impact on the largest amount of people that we have ever seen.  What that impact is or whether is good or bad is not my place to say.  I am a participant, along for the ride so to speak.  So  where does myspace fit into this?  And when I say myspace, I don't mean literally "my", "space" on the web.  Funny thing is, I know that anyone and everyone who reads this knows what I am talking about.  There are catchy buzz words to categorize this concept of interactive web, shedding light for the masses on transition of life and culture.   But does it really matter where you lie in the whole spectrum of these things? At a company meeting/party today (yeah my work kicks ass) the president discussed with us Mircosoft's four postitions one can take on soft ware in respect to age.  Cutting edge, not cutting edge, slow but steady, and 19 80. Well at least thats what I remember from it.  Where do you stand? Does it really matter?  Does it change?  Myspace is so 2000 and I hate it.  Perhaps I should make a list.&lt;br /&gt;&lt;br /&gt;I hate Myspace because:&lt;br /&gt;&lt;br /&gt;1. I did not come up with the idea.&lt;br /&gt;2. I wasn't friends with the person that did. &lt;br /&gt;3. If I add all my real friends I will be taken to court and my child support will go up.&lt;br /&gt;4. Advertisements.&lt;br /&gt;5. I thought I was bleeding edge because I made a fake profile to sell VIOP service.&lt;br /&gt;6.  It further complicate strange social  circles that I never understood in the first place.&lt;br /&gt;7. They sold out.&lt;br /&gt;8.  It introduced HTML to the masses. &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Well thats about all I can come up with.   Can anybody help me out with some of the finer points that I have missed?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-8052321247482588347?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/8052321247482588347/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=8052321247482588347' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/8052321247482588347'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/8052321247482588347'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2007/07/i-hate-myspace.html' title='I hate Myspace'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-9123026222356912315</id><published>2007-05-02T10:41:00.000-07:00</published><updated>2007-05-02T12:10:07.626-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='internet riot'/><category scheme='http://www.blogger.com/atom/ns#' term='censorship'/><category scheme='http://www.blogger.com/atom/ns#' term='09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0'/><category scheme='http://www.blogger.com/atom/ns#' term='freedom'/><title type='text'>Aftermath</title><content type='html'>I have to say I am incredibly disappointed with the direction or lack there of that the this the user revolt has taken.  Kevin Rose posted this,&lt;br /&gt;&lt;blockquote&gt;"But now, after seeing hundreds of stories and reading thousands of comments, you ’ve made it clear. You’d rather see Digg go down fighting than bow down to a bigger company. We hear you, and effective immediately we won’t delete stories or comments containing the code and will deal with whatever the consequences might be." &lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;Everyone dugg it, then Kevin himself posted the numbers, and now all I see is a bunch of whiny ass people babbling out shit like this,&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;...&lt;br /&gt;I truly cannot believe how many people decided they were going to stand up (while sitting down mind you) for a cause that 50% of them were not going to actively participate in anyway. If "protesting" or "sticking it to the man" as they call it, is in fact possible by simply clicking your mouse a few hundred times then I for one welcome our new carpal-tunnel ridden overlords.&lt;br /&gt;&lt;br /&gt;IF we're all done acting like 5 year olds, I'm sure someone's got a great picture of a cute kitten in a computer to submit.&lt;br /&gt;&lt;br /&gt;That's REAL Digg frontpage news... :) &lt;/blockquote&gt;&lt;br /&gt;For the love of all things holy.  It was obvious that diggers DID recognize the importance of the issue at hand, but less than 24hrs later comments like the one above are getting Dugg hand over foot.  I just don't get it? And for the record, let be clear on one thing, "protesting" and "sticking it to the man" can ABSOLUTELY, with out a doubt be accomplished with a few hundred clicks.  A few million people clicking something a few hundred times.....hmmm that sound like a political bot net of sorts.  Why wait for someone to create a bot net that actually stands behind a real cause or idea, not just extortion and greed, when we could do it with out all the zombie boxes?  (Although I must say, Zombie box's are cool with me as long and they are not spamming and extorting).  &lt;br /&gt;&lt;br /&gt;Then there is this comment in direct response to Kevin's story,  which it would seem by the number of Digg's clearly represents the overall attitude of the digg community. &lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;"Well said.  Can we move on now?"&lt;/blockquote&gt;This to me is what is really sad.  Maybe the guy was right in the first comment above? Most of the people who were out there digging like mad last night were just a bunch of coffee shop revolutionaries, attention spans no longer than a few hours who have already moved on to the newest IPhone  pictures , but I refuse to adopt that attitude (even though it may very well be true) simply because I am stubborn and I have faith in both political and conscious movement. &lt;br /&gt;Really, if you sit back and look at it for a few minutes,  what happened on Digg on May, 1st 2007 has some pretty interesting implications in the grand scheme of things.  I encourage those of you who have yet to see it to take a closer look.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-9123026222356912315?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/9123026222356912315/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=9123026222356912315' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/9123026222356912315'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/9123026222356912315'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2007/05/aftermath.html' title='Aftermath'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-26946479938456069</id><published>2007-05-01T21:10:00.000-07:00</published><updated>2008-12-10T16:14:09.128-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pirates'/><category scheme='http://www.blogger.com/atom/ns#' term='internet riot'/><category scheme='http://www.blogger.com/atom/ns#' term='censorship'/><category scheme='http://www.blogger.com/atom/ns#' term='09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0'/><category scheme='http://www.blogger.com/atom/ns#' term='hackers'/><category scheme='http://www.blogger.com/atom/ns#' term='freedom'/><title type='text'>Internet Riot! 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0</title><content type='html'>I  am purposing to take this thing beyond digg have a full blown Internet Riot! If you don't know whats going on yet, I'm not going to explain the numbers, 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0 but you can head over to digg.com and read up on it. Lets really open our vocal chords and yell this time. Go to every Blog you can find (including this one) and post the numbers! Hit fourms, and fill out contact forms loaded with the numbers. Don't forget to be crafty and throw in the MD5 of the numbers for good form. Lets make sure that we make our selves clear this time! You cannot stop us! Your censorship is useless!&lt;br /&gt;&lt;br /&gt;What a beautiful screen shot of Digg.com's  infamous front page:&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_0HdptvMZpuE/RjgP0wJ_vJI/AAAAAAAAAB4/S6n7iGD4lAM/s1600-h/diggriot.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_0HdptvMZpuE/RjgP0wJ_vJI/AAAAAAAAAB4/S6n7iGD4lAM/s320/diggriot.jpg" alt="" id="BLOGGER_PHOTO_ID_5059811580305194130" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-26946479938456069?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/26946479938456069/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=26946479938456069' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/26946479938456069'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/26946479938456069'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2007/05/internet-riot-09-f9-11-02-9d-74-e3-5b_01.html' title='Internet Riot! 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_0HdptvMZpuE/RjgP0wJ_vJI/AAAAAAAAAB4/S6n7iGD4lAM/s72-c/diggriot.jpg' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-3906625074564983145</id><published>2007-03-20T08:22:00.000-07:00</published><updated>2007-03-22T07:40:11.530-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='whitehat'/><category scheme='http://www.blogger.com/atom/ns#' term='blackhat'/><category scheme='http://www.blogger.com/atom/ns#' term='craigslist'/><category scheme='http://www.blogger.com/atom/ns#' term='spam'/><title type='text'>Bust a Spammer In The Grill</title><content type='html'>Heres a good post from Craigslist that a friend of mine made some time ago.  The success rate to  this method is not  100%, but it will work a good amount of the time.  This is written with the average end internet user in mind, but if you read past the part about how to identify spam it gets into the good stuff.&lt;br /&gt;&lt;br /&gt;"I have not been on here a for awhile, and I am amazed to see how much spam is flooding this section.&lt;br /&gt;&lt;br /&gt;Just quick heads up for those that don't know:&lt;br /&gt;&lt;br /&gt;If a posting takes you to a link that has no where to click except for on advertisements then it is spam!&lt;br /&gt;&lt;br /&gt;For example this site,&lt;br /&gt;&lt;a class="user" href="http://www.lowincomebostonapartments.com/portland.htm"&gt;http://www.lowincomebostonapartments.com/portland.htm&lt;/a&gt;&lt;br /&gt;which was posted earlier today on portland craigslist IS SPAM!!&lt;br /&gt;There are no apartments at all for rent, what they are trying to do is trick you into clicking on the google advertisement, which intern earns them money for each click you make. Also, try swapping the the /portland.htm to any major city for example, /denver.htm and look what happens! These people are making good money off abusing CL!!&lt;br /&gt;&lt;br /&gt;(white hat method)&lt;br /&gt;CL is a great service, and the best way to keep it that way and stop greedy spammers (who are to lazy to make a decent living) is being informed about what you are clicking on, AND recognizing and flagging these posts as SPAM.&lt;br /&gt;&lt;br /&gt;(black hat method)&lt;br /&gt;Now, if you are like me, and you dont have any problems fighting fire with fire, there is another way to cripple these spammers and render their scam useless. Now, a little heads up. IF you choose to undertake this, I warn you now that this is may or may not be legal, and it IS NOT the most up and up way to stop this particular kind of spam. Also if you get in trouble, dont blame me because you are on you own with this!!!&lt;br /&gt;&lt;br /&gt;Now on to the good stuff:&lt;br /&gt;According to wiki, Click fraud is defined as the following,&lt;br /&gt;&lt;br /&gt;"Click fraud occurs in pay per click online advertising when a person, automated script, or computer program imitates a legitimate user of a web browser clicking on an ad, for the purpose of generating a charge per click without having actual interest in the target of the ad's link. Click fraud is the subject of some controversy and increasing litigation due to the advertising networks being a key beneficiary of the fraud whether they like it or not."&lt;br /&gt;&lt;br /&gt;So, what you do it take about five minutes of your day, and click on the SAME ad as over and over and over again on one of these sites (make SURE it IS a spamming site) and then just wait. It may take some time, upwards of a day for anything to happen, so be patient.;&lt;br /&gt;Now, what happens is that this sets off red flags with the google people, and the person who owns that account (spammer) will have there google ad sense account frozen. Now for the good part, all the money that they have made and not been paid for up until this point, (which could be a whole lot) will be frozen as well. These ad sense accounts are bound to and confirmed by social security # and other things that are not easily scammed. So, although they may be able to setup another account and get back at it, it will not be easy and it will probably take time. "&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-3906625074564983145?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/3906625074564983145/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=3906625074564983145' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/3906625074564983145'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/3906625074564983145'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2007/03/bust-spammer-in-grill.html' title='Bust a Spammer In The Grill'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-2719370971759666944</id><published>2007-02-14T10:49:00.000-08:00</published><updated>2008-12-10T16:14:09.835-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='myspace spam hacking ebay exploit'/><title type='text'>Exposing a Script Kiddie</title><content type='html'>I'm not a huge myspace fan. I had a profile for awhile, but recently bailed on the whole thing. A few days ago I was checking out the myspace page for &lt;a href="http://radiodiscon.com/"&gt;Radio Discon&lt;/a&gt; and I noticed that a comment had just been made from a friend of the station that obviously was not real.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;"Oh, my fault I must have gave you the wrong link then. The people I use to&lt;br /&gt;make make money should be &lt;a href="http://bias9.blogspot.com/"&gt;just go here (click here)&lt;/a&gt;.&lt;br /&gt;Well I hope it works for you this time, remember that&lt;br /&gt;if the site is not up they are not excepting anyone else. I told you I'm making&lt;br /&gt;about $900 a week and it's consistent. Just make sure that you take taxes into&lt;br /&gt;consideration, it's a little different than that job your always complaining&lt;br /&gt;about.LOL anyways that is funny about Laura, what else did&lt;br /&gt;she say about it? I'm not even going to worry about it ya know? Oh well,&lt;br /&gt;call me later or I'll catch you on here, see ya. "&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;&lt;blockquote&gt;&lt;/blockquote&gt;&lt;br /&gt;&lt;br /&gt;My curiosity set in and I decided to do a little research on the nature of this beast. The click here link directed you to &lt;a href="http://bais9.blogspot.com/"&gt;game-blast.net/paidetc.php&lt;/a&gt;. Before clicking on the link I headed over to the root of the domain. game-blast.net/. It was an Apache server directory listing;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;img id="BLOGGER_PHOTO_ID_5031472127750855746" style="margin: 0px auto 10px; display: block; text-align: center;" alt="" src="http://2.bp.blogspot.com/_0HdptvMZpuE/RdNhPgfeXEI/AAAAAAAAAAM/KZBUrXUqFwA/s320/gameblast.JPG" border="0" /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;By navigating to the admin folder, game-blast/admin you end up at at jumbled up web page that will happily generate errors for you when clicking on some of the different links. At this point I went ahead and clicked on one of the PHP pages. game-blast.net/scout2.php. The page redirects you to some online money making scam. Not bad, considering it does not appear to be infecting you with malware or anything of the sort. I checked out a couple of the other pages from directory listing, including the original link that came in the myspace comment. What really got this scavenger hunt going was when I noticed the affiliate account being passed in plain text in the address bar of the scout2.php redirect.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_0HdptvMZpuE/RdRsdgfeXGI/AAAAAAAAAAg/egTomwbmQB4/s1600-h/Clipboard03.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5031765937873640546" style="margin: 0px auto 10px; display: block; width: 400px; cursor: pointer; height: 300px; text-align: center;" alt="" src="http://3.bp.blogspot.com/_0HdptvMZpuE/RdRsdgfeXGI/AAAAAAAAAAg/egTomwbmQB4/s400/Clipboard03.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Now I had someone to look for, Ksruckman. I started off with a simple Google search. Within 20 minutes I felt like I knew ksruckman, or Ralph Ruckman as he's known to Uncle Sam. After seeing that his PHP scripts were nothing but redirects to cheesy money making sites, I began the profile of ksruckman as a low end Internet scammer, or to be nice, marketeer. Most of my initial information came from forum posts. For example, on one site in the fall of 2006 he had some serious issues with premissions on his wordress blog. Someone kindly explained to him the CHMOD command and he was back on track. This lead me to believe that he likely knows very little about the back ends of websites, html, and/ or FTP. At this point I had pretty much pinned him as a script kiddie. As I read through various forum posts and searched popular photo sharing sites my profile became more in depth. On one set of forums he boasted on recent earnings of a Craiglist scam and then about his earning mantra of three dollars per site within the first five days. It really makes me wonder how different the Internet would be with out all the junk sites. Who's to judge though I guess? Moving along, just a few pages in to the Google search I stumbled across another huge piece of the puzzle, Ralph's eBay profile. For the most part he was purchasing Xbox live cards and the like. One auction in particular brought the search full circle:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_0HdptvMZpuE/RdRwUQfeXHI/AAAAAAAAAAs/p9gO53YggAA/s1600-h/Clipboard01.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5031770177006361714" style="margin: 0px auto 10px; display: block; cursor: pointer; text-align: center;" alt="" src="http://2.bp.blogspot.com/_0HdptvMZpuE/RdRwUQfeXHI/AAAAAAAAAAs/p9gO53YggAA/s400/Clipboard01.jpg" border="0" /&gt;&lt;/a&gt; &lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Yes that's right, he bought the script off EBay. For less than $20 none the less. I'd imagine that he probably made a pretty good little stash of cash off the exploit. At this point, I'm feeling pretty satisfied, although I do still have a few questions about the specific exploit. &lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;p align="center"&gt;&lt;a href="http://2.bp.blogspot.com/_0HdptvMZpuE/RdSPCQfeXII/AAAAAAAAAA4/m6uZ4bec8FU/s1600-h/ralph.gif"&gt;&lt;/a&gt;&lt;/p&gt;&lt;div align="center"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align="center"&gt;&lt;/div&gt;&lt;div align="center"&gt;!EDIT!&lt;br /&gt;I decided enough was enough, your name has been removed.  Google should be clear of it soon.&lt;br /&gt;Sorry Bro It Had to Be Done.   &lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-2719370971759666944?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/2719370971759666944/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=2719370971759666944' title='8 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/2719370971759666944'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/2719370971759666944'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2007/02/my-space.html' title='Exposing a Script Kiddie'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_0HdptvMZpuE/RdNhPgfeXEI/AAAAAAAAAAM/KZBUrXUqFwA/s72-c/gameblast.JPG' height='72' width='72'/><thr:total>8</thr:total></entry><entry><id>tag:blogger.com,1999:blog-8402228841467920387.post-5521015754719812248</id><published>2007-01-30T13:01:00.000-08:00</published><updated>2007-02-15T07:14:24.855-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='DEM digital rights magagement windows vista'/><title type='text'>DRM and the new world order.</title><content type='html'>As a tech support representative I have been asked quite a few times in the past few months what I think about Windows Vista. As a side note, it should be noted that average caller in my support center tends to know about as much about computers as a squirrel does toasters. I have no problem with this as it pays my bills and I have reasonably good time doing it. In the past my responses to this dreaded question have remained trivial and and far from honest. I have found it much easier to respond with a simple "I'm curious to see" than to dig deeper into my philosophy on operating systems, open source, pirates and end users. Truth be told, aside from an episode of &lt;a href="http://www.grc.com/securitynow.htm"&gt;Security Now&lt;/a&gt; and a few articles here and there, I don't know much about Vista other than that it supports &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0" onclick="BLOG_clickHandler(this)"&gt;IPV&lt;/span&gt;6 and 64 bit processors.&lt;br /&gt;What little faith I did have in Windows took a serious blow today when I read this article I found on &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1" onclick="BLOG_clickHandler(this)"&gt;Digg&lt;/span&gt;. &lt;a href="http://polishlinux.com/gnu/drm-vista-and-your-rights/"&gt;http://polishlinux.com/gnu/drm-vista-and-your-rights/&lt;/a&gt;. I strongly recommend reading over this article. I used to think of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2" onclick="BLOG_clickHandler(this)"&gt;DRM&lt;/span&gt; like the barking dog that never shuts up in your &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_3"&gt;neighbors&lt;/span&gt; yard, yes its annoying, but if the music is turned up loud enough you won't hear it anyway. I am now realizing that this is not the case.  The serious implementation of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4" onclick="BLOG_clickHandler(this)"&gt;DRM&lt;/span&gt; into operating systems is a huge problem and will likely mark a whole new era of hell and headaches for the average end user.   While companies like &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_5"&gt;Microsoft&lt;/span&gt; and Sony struggle, kicking and screaming to hang on to old ways of doing &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_6"&gt;business&lt;/span&gt;, it becomes more and more clear that the model of taking advantage people who &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_7"&gt;don't&lt;/span&gt; know any better is not that  all that cool.  What I &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_8"&gt;don't&lt;/span&gt; understand is how these companies really think that by implementing &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9" onclick="BLOG_clickHandler(this)"&gt;DRM&lt;/span&gt; they will be able to protect there products.  The fact of the matter remains, no matter how hard they try, or how stiff the punishment, there will always be crackers and pirates.  The end result to me really seems like Windows is polarizing the internet universe like never before.  While typing this up at work, I recieved my first call on a Vista Machine.  It was unable to connect to the internet,  and I sent him off to the OEM for support.  I only have one more day of work here and as far as I'm concerned I have no desire to learn about Vista unless I really have to.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/8402228841467920387-5521015754719812248?l=bias9.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://bias9.blogspot.com/feeds/5521015754719812248/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=8402228841467920387&amp;postID=5521015754719812248' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/5521015754719812248'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/8402228841467920387/posts/default/5521015754719812248'/><link rel='alternate' type='text/html' href='http://bias9.blogspot.com/2007/01/drm-and-new-world-order.html' title='DRM and the new world order.'/><author><name>projektd</name><uri>http://www.blogger.com/profile/05553474253725975104</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
