<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Recognize-Security &#187; Malware</title>
	<atom:link href="http://www.rec-sec.com/category/malware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rec-sec.com</link>
	<description>a non-profit information security web site authored by Moshe Ben Abu (Trancer), focusing on vulnerability research, exploit development (mainly for the Metasploit Framework), web application security, information security and hacking news from around the world.</description>
	<lastBuildDate>Sun, 14 Mar 2010 17:44:35 +0000</lastBuildDate>
	<generator>http://www.rec-sec.com</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='www.rec-sec.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com" />
	<atom:link rel="hub" href="http://superfeedr.com/hubbub" />
			<item>
		<title>Twitter XSS Worms</title>
		<link>http://www.rec-sec.com/2009/04/13/twitter-xss-worms/</link>
		<comments>http://www.rec-sec.com/2009/04/13/twitter-xss-worms/#comments</comments>
		<pubDate>Mon, 13 Apr 2009 19:35:26 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=379</guid>
		<description><![CDATA[For the past few days two web worms are spreading through Twitter, the popular social micro-blogging utility. The first worm, called the &#8220;StalkDaily&#8221; worm, start spreading on Saturday, infect user profile pages, steal users browser cookies and post unwanted tweets. A second variation called the &#8220;Mikeyy&#8221; worm, start spreading on Sunday and does pretty much [...]]]></description>
			<content:encoded><![CDATA[<p><img alt="Twitter" width="193" height="108" class="right" src="images/twitter-logo.png" />For the past few days two web worms are spreading through <a href="http://twitter.com/" title="Twitter">Twitter</a>, the popular social micro-blogging utility. The first worm, called the &#8220;StalkDaily&#8221; worm, start spreading on Saturday, infect user profile pages, steal users browser cookies and post unwanted tweets. A second variation called the &#8220;Mikeyy&#8221; worm, start spreading on Sunday and does pretty much the same.<br />
The worms use a Cross-Site Scripting and Cross-Site Request Forgery vulnerabilities to spread, which the Twitter guys already closed.<br />
Both worms were created by Michael &#8220;Mikeyy&#8221; Mooney, a 17 year old teenager. You can read an interview with Mooney on <a href="http://news.cnet.com/8301-1009_3-10217684-83.html" title="Teen takes responsibility for Twitter worms | Security - CNET News">CNET News</a>.</p>
<p>Here&#8217;s both &#8220;StalkDaily&#8221; worm and &#8220;Mikeyy&#8221; worm JavaScript code, for educational purposes.</p>
<ul>
<li><a href="code/stalkdaily.txt" title="Twitter StalkDaily XSS worm code">Twitter &#8220;StalkDaily&#8221; worm code (unobfuscated)</a>.</li>
<li><a href="code/mikeyy.txt" title="Twitter Mikeyy XSS worm code">Twitter &#8220;Mikeyy&#8221; worm code (obfuscated)</a>.</li>
</ul>
<p>Further reading:<br />
<a href="http://blog.twitter.com/2009/04/wily-weekend-worms.html" title="Twitter Blog: Wily Weekend Worms">Twitter Blog: Wily Weekend Worms</a>.<br />
<a href="http://www.f-secure.com/weblog/archives/00001653.html" title="Twitter worm outbreak over Easter - F-Secure Weblog : News from the Lab">F-Secure &#8211; Twitter worm outbreak over Easter</a>.<br />
<a href="http://tacticalwebappsec.blogspot.com/2009/04/twitter-worm-cross-site-request-forgery.html" title="Tactical Web Application Security: Twitter Worm - Cross-site Request Forgery Attacks">Twitter Worm Analysis by Ryan Barnett</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2009/04/13/twitter-xss-worms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conficker</title>
		<link>http://www.rec-sec.com/2009/03/01/conficker/</link>
		<comments>http://www.rec-sec.com/2009/03/01/conficker/#comments</comments>
		<pubDate>Sun, 01 Mar 2009 15:17:46 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=153</guid>
		<description><![CDATA[Right after an exploit code was published for the MS08-067 vulnerability it was only a matter of time until virus coders will write a virus that use this vulnerability to spread.
Well, exploiting this vulnerability is one of the techniques the Conficker (aka Downadup and Kido) virus use to spread itself, and that&#8217;s what makes it [...]]]></description>
			<content:encoded><![CDATA[<p><img alt="Virus" width="200" height="150" class="left" src="images/virus.png" />Right after an exploit code was published for the <a href="http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx" title="Microsoft Security Bulletin MS08-067 &#8211; Critical: Vulnerability in Server Service Could Allow Remote Code Execution (958644)">MS08-067</a> vulnerability it was only a matter of time until virus coders will write a virus that use this vulnerability to spread.<br />
Well, exploiting this vulnerability is one of the techniques the Conficker (aka Downadup and Kido) virus use to spread itself, and that&#8217;s what makes it so dangerous.<br />
With more then 20 millions infected computers out there, security firms say it is the severest computer virus since the <abbr title="Structured Query Language">SQL</abbr> Slammer, and Microsoft is going nuts over it, offering a $250,000 bounty for information leading to the catch of the guys who created and/or distribute the virus.<br />
In my opinion, 20 million is a really rough estimate of the infected computers out there. I believe the numbers are greater, due to the fact that the virus also spread itself through portable storage devices (<abbr title="Universal Serial Bus">USB</abbr> drives and other removable media) and by that slipping in to organizations internal networks. Here&#8217;s where the numbers are getting blurry, we don&#8217;t know what&#8217;s the virus infection scale inside these internal networks, where it can spread much more easily using network shares, computers with weak passwords and exploiting the MS08-067 vulnerability.<br />
It&#8217;s a known fact that the software and operating systems inside these organizations internal networks aren&#8217;t always up-to-date, and sometimes it takes months, if not years, for these organizations to update their computers.<br />
It happens mostly when vendors release major service packs or&#8230; after a virus infects their networks :-)<br />
Conficker is that example, a lesson for all these organizations that doesn&#8217;t patch their systems. I guess they need these kind of lesson every once and a while.<br />
Even the <abbr title="Israel Defense Forces">IDF</abbr> internal networks got <a href="http://www.ynet.co.il/articles/0,7340,L-3659822,00.html" title="Ynet - Conficker infects IDF internal networks">infected by Conficker</a> (Hebrew).</p>
<p>Conficker comes in three variants &#8211; Win32/Conficker.A, Win32/Conficker.B and Win32/Conficker.B++.<br />
SRI International Malware Threat Center wrote a great analysis for the virus and all the variants here &#8211; <a href="http://mtc.sri.com/Conficker/" title="SRI - An Analysis of Conficker">An Analysis of Conficker&#8217;s Logic and Rendezvous Points</a>.<br />
See also:<br />
<a href="https://forums2.symantec.com/t5/Malicious-Code/Downadup-Advanced-Crypto-Protection/ba-p/391311" title="Downadup - Advanced Crypto Protection">Downadup &#8211; Advanced Crypto Protection</a> by Elia Florio of Symantec.<br />
Microsoft help protecting yourself against the <a href="http://www.microsoft.com/protect/computer/viruses/worms/conficker.mspx" title="Microsoft Security | Protect yourself from the Conficker computer worm">Conficker worm</a>.</p>
<p><strong>Update:</strong><br />
Win32/Conficker.C is on the loose, armed with more self protection mechanisms and a larger domain pool.<br />
On April 1st, Conficker.C will attempt to dial home to 500 random domains out of 50000 generated domains. A great change from the previous variants that would dial home to 32 out of 250 domains.<br />
This time the worm is also much more violent and will attempt to disable Windows Automatic Updates and stop access to the Windows Security Center, also killing anti-virus processes, preventing access to anti-virus websites, delete system restore points, disable various protection services such as Windows Defender and the Windows Error Reporting Service and much more.</p>
<p>For a detailed analysis of Conficker.C, check the <a href="http://www.ca.com/us/securityadvisor/virusinfo/virus.aspx?id=77976" title="Win32/Conficker.C - CA"><abbr title="Computer Associates Inc">CA</abbr> Win32/Conficker.C Virus Analysis</a> and the SRI International Malware Threat Center <a href="http://mtc.sri.com/Conficker/addendumC/index.html" title="SRI - An Analysis of Conficker C">analysis of Conficker C</a>.<br />
Also see this <a href="http://www.cert.at/static/conficker/TR_Conficker_Detection.pdf" title="Detecting Conficker in your Network">Detecting Conficker in your Network</a> paper.</p>
<p>See you on Conficker.D ?!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2009/03/01/conficker/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
