<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Hero &#187; Lab</title>
	<atom:link href="http://sechero.com/tag/lab/feed/" rel="self" type="application/rss+xml" />
	<link>http://sechero.com</link>
	<description>If it's about security, you heard it here first</description>
	<lastBuildDate>Mon, 12 Jul 2010 23:27:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Nikto 2.1.0 released</title>
		<link>http://sechero.com/nikto-2-1-0-released/</link>
		<comments>http://sechero.com/nikto-2-1-0-released/#comments</comments>
		<pubDate>Sun, 18 Oct 2009 20:45:22 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Lab]]></category>

		<guid isPermaLink="false">http://sechero.com/?p=20976</guid>
		<description><![CDATA[Nikto 2.1.0 released Posted by david lodge on Oct 18 It&#8217;s final time to stop procrastinating: Nikto 2.1.0 is here! (Available from http://cirt.net/nikto2) This version has gone through significant rewrites under the hood to how Nikto works, to make it more expandable and usable. Changes include: * Rewrite to the plugin engine allowing more control [...]]]></description>
			<content:encoded><![CDATA[<h1><a href="http://seclists.org/fulldisclosure/2009/Oct/249">Nikto 2.1.0 released</a></h1>
<p>Posted by david lodge on Oct 18</p>
<p>It&#8217;s final time to stop procrastinating: Nikto 2.1.0 is here!</p>
<p>(Available from <a href="http://cirt.net/nikto2" rel="nofollow">http://cirt.net/nikto2</a>)</p>
<p>This version has gone through significant rewrites under the hood to</p>
<p>how Nikto works, to make it more expandable and usable.</p>
<p>Changes include:</p>
<p>* Rewrite to the plugin engine allowing more control of the plugin</p>
<p>structure and making it easier to add plugins</p>
<p>* Rewrite to the reporting engine allowing reporting plugins to cover</p>
<p>more and also&#8230;
<p>URL: <a href="http://seclists.org/fulldisclosure/2009/Oct/249">http://seclists.org/fulldisclosure/2009/Oct/249</a></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/nikto-2-1-0-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DOS attack tool can be used in lab</title>
		<link>http://sechero.com/dos-attack-tool-can-be-used-in-lab/</link>
		<comments>http://sechero.com/dos-attack-tool-can-be-used-in-lab/#comments</comments>
		<pubDate>Sat, 05 Sep 2009 02:47:55 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Lab]]></category>

		<guid isPermaLink="false">http://sechero.com/?p=20953</guid>
		<description><![CDATA[DOS attack tool can be used in lab Posted by L. Pop on Sep 2 Hi Guys, Recently one of our freebsd servers always experience &#34;Socket: No buffer space available&#8230;&#34; Errors,Â and there are too many FIN_Wait1s in system,Â itÂ is likelyÂ that we are beingÂ DOSed. Is there any handyÂ DOS simulate tool that i can use in lab to [...]]]></description>
			<content:encoded><![CDATA[<h1><a href="http://seclists.org/pen-test/2009/Sep/0001.html">DOS attack tool can be used in lab</a></h1>
<p>Posted by L. Pop on Sep 2
<p></p>
<p>
Hi Guys,</p>
<p>
Recently one of our freebsd servers always experience &quot;Socket: No<br />
buffer space available&#8230;&quot; Errors,Â and there are too many FIN_Wait1s<br />
in system,Â itÂ is likelyÂ that we are beingÂ DOSed.</p>
<p></p>
<p>
Is there any handyÂ DOS simulate tool that i can use in lab to<br />
reproduce theÂ problem&#8230;.
<p>URL: <a href="http://seclists.org/pen-test/2009/Sep/0001.html">http://seclists.org/pen-test/2009/Sep/0001.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/dos-attack-tool-can-be-used-in-lab/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Wiki page planned</title>
		<link>http://sechero.com/cyber-wiki-page-planned/</link>
		<comments>http://sechero.com/cyber-wiki-page-planned/#comments</comments>
		<pubDate>Sat, 22 Aug 2009 04:45:32 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[Proxy]]></category>

		<guid isPermaLink="false">http://sechero.com/?p=20948</guid>
		<description><![CDATA[Cyber Wiki page planned The U.S. Department of Homeland Security intends to contract with WiiKno, a Texas-based knowledge management solutions provider, to create a Wiki page for the agency that will be used to share information among the National Cyber Security Center and its six federal cybersecurity centers, according to a notice posted this week [...]]]></description>
			<content:encoded><![CDATA[<h1><a href="http://feedproxy.google.com/~r/SCMagazineHome/~3/vOtdnYeB8xA/">Cyber Wiki page planned</a></h1>
<p>The U.S. Department of Homeland Security intends to contract with WiiKno, a Texas-based knowledge management solutions provider, to create a Wiki page for the agency that will be used to share information among the National Cyber Security Center and its six federal cybersecurity centers, according to a notice posted this week on the Federal Business Opportunities website. The Wiki page will offer a &#8220;development platform for improved situational awareness&#8221; for communication and collaboration related to national cybersecurity plans. ¡X DK</p>
<p><a href="http://feedads.g.doubleclick.net/~a/urFHTK32l2vngLcVf3AAP2VwWSM/0/da"><img border="0" src="http://feedads.g.doubleclick.net/~a/urFHTK32l2vngLcVf3AAP2VwWSM/0/di" /></a></p>
<p><a href="http://feedads.g.doubleclick.net/~a/urFHTK32l2vngLcVf3AAP2VwWSM/1/da"><img border="0" src="http://feedads.g.doubleclick.net/~a/urFHTK32l2vngLcVf3AAP2VwWSM/1/di" /></a></p>
<p><img height="1" src="http://feeds.feedburner.com/~r/SCMagazineHome/~4/vOtdnYeB8xA" width="1" />
<p>URL: <a href="http://feedproxy.google.com/~r/SCMagazineHome/~3/vOtdnYeB8xA/">http://feedproxy.google.com/~r/SCMagazineHome/~3/vOtdnYeB8xA/</a></p>
<p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/cyber-wiki-page-planned/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Service vulnerability</title>
		<link>http://sechero.com/service-vulnerability/</link>
		<comments>http://sechero.com/service-vulnerability/#comments</comments>
		<pubDate>Sun, 26 Jul 2009 20:48:20 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://sechero.com/?p=20919</guid>
		<description><![CDATA[Cisco WLC 4402 Denial-of-Service vulnerability Posted by SySS security advisories &#8212; Christoph Bott on Jul 26 ======================================= Vulnerable Product: Cisco WLC 4402 (most likely among many others) Vulnerability discovered: January 2009 Reported to vendor: Jan 01, 2009 Fix available: not yet ======================================= TIMELINE: &#8230; URL: http://seclists.org/fulldisclosure/2009/Jul/0407.html]]></description>
			<content:encoded><![CDATA[<h1><a href="http://seclists.org/fulldisclosure/2009/Jul/0407.html">Cisco WLC 4402 Denial-of-Service vulnerability</a></h1>
<p>Posted by SySS security advisories &#8212; Christoph Bott on Jul 26
<p></p>
<p>
=======================================</p>
<p>
Vulnerable Product: Cisco WLC 4402 (most likely among many others)</p>
<p>
Vulnerability discovered: January 2009</p>
<p>
Reported to vendor: Jan 01, 2009</p>
<p>
Fix available: not yet</p>
<p>
=======================================</p>
<p></p>
<p>
<p>TIMELINE:</p>
<p>&#8230;
<p>URL: <a href="http://seclists.org/fulldisclosure/2009/Jul/0407.html">http://seclists.org/fulldisclosure/2009/Jul/0407.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/service-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Woman responsible for loss of anonymity</title>
		<link>http://sechero.com/woman-responsible-for-loss-of-anonymity/</link>
		<comments>http://sechero.com/woman-responsible-for-loss-of-anonymity/#comments</comments>
		<pubDate>Sun, 26 Jul 2009 11:48:21 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Lab]]></category>

		<guid isPermaLink="false">http://sechero.com/?p=20915</guid>
		<description><![CDATA[Woman responsible for loss of anonymity The civil complaint doesn&#8217;t just accuse Ben Roethlisberger of a heinous and despicable act. It also labels him a slob. That curious assertion sticks out in the 36-page lawsuit that accuses the Steelers&#8217; star quarterback of sexually assaulting a woman in a Nevada hotel room in July 2008. It [...]]]></description>
			<content:encoded><![CDATA[<h1><a href="http://www.pogowasright.org/?p=2224">Woman responsible for loss of anonymity</a></h1>
<p>The civil complaint doesn&#8217;t just accuse Ben Roethlisberger of a heinous and despicable act.</p>
<p>It also labels him a slob.</p>
<p>That curious assertion sticks out in the 36-page lawsuit that accuses the Steelers&#8217; star quarterback of sexually assaulting a woman in a Nevada hotel room in July 2008.</p>
<p>It sticks out because the &#8230;
<p>URL: <a href="http://www.pogowasright.org/?p=2224">http://www.pogowasright.org/?p=2224</a></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/woman-responsible-for-loss-of-anonymity/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CIS releases security configuration standards for iPhone</title>
		<link>http://sechero.com/cis-releases-security-configuration-standards-for-iphone/</link>
		<comments>http://sechero.com/cis-releases-security-configuration-standards-for-iphone/#comments</comments>
		<pubDate>Sun, 31 May 2009 02:32:20 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://sechero.com/cis-releases-security-configuration-standards-for-iphone/</guid>
		<description><![CDATA[CIS releases security configuration standards for iPhone The nonprofit Center for Internet Security (CIS) this week released free guidelines that can help organizations develop custom policies related to use of the increasingly popular mobile device, said Blake Frantz, CTO of the CIS. The benchmarks inform users about the security configuration settings available to them on [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31541">CIS releases security configuration standards for iPhone</a></h1>
</p>
<p>The nonprofit Center for Internet Security (CIS) this week released free guidelines that can help organizations develop custom policies related to use of the increasingly popular mobile device, said Blake Frantz, CTO of the CIS. The benchmarks inform users about the security configuration settings available to them on the iPhone. For example, the standards explain how to make adjustments to protect data and deter potential attacks, such as disabling Bluetooth or JavaScript, or creating a strong password policy.</p>
<p>Frantz told <a href="http://SCMagazineUS.com" title="http://SCMagazineUS.com" target="_blank">SCMagazineUS.com</a> on Friday that feedback from the CIS&#8217; 150 members showed that there was a need for iPhone security standards. &#8220;It&#8217;s going to have your organization&#8217;s confidential information on it,&#8221; he said. &#8220;We want to equip organizations with some best practices that that information remains confidential.&#8221;</p>
<p>The guidance arrive at a time when businesses are facing increased pressure to manage their employees&#8217; smartphones. A recent Osterman Research study, sponsored by Zenprise, provider of mobile management solutions, reported that the percentage of North American workers issued mobile devices by their employers will double from 23 percent last year to 46 percent in 2011. Other studies have said the number of iPhones in use in the enterprise will triple between now and 2011.
<p>URL: <a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31541">http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31541</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/cis-releases-security-configuration-standards-for-iphone/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4117</title>
		<link>http://sechero.com/4117/</link>
		<comments>http://sechero.com/4117/#comments</comments>
		<pubDate>Sat, 30 May 2009 13:49:38 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[4117 PDF/Exploit.Pidief.ONG, VBS/TrojanDownloader.Small.L (6), Win32/Adware.BHO.GBP (2), Win32/Adware.BHO.NCG (2), Win32/Adware.GooochiBiz (4), Win32/Adware.WSearch, Win32/Agent.NXT (2), Win32/AutoRun.Agent.NP, Win32/AutoRun.Delf.BY, Win32/Delf.PFS, Win32/FlyStudio.NML, Win32/FlyStudio.NMM (5), Win32/Hupigon, Win32/Hupigon.NPE, Win32/KillAV.NDV (2), Win32/Koutodoor.AF (3), Win32/Koutodoor.G, Win32/Peerfrag.AG, Win32/Poison.NBC (2), Win32/PSW.Agent.NLP (2), Win32/PSW.OnLineGames.NMP (2), Win32/PSW.OnLineGames.NMY (3), Win32/PSW.OnLineGames.NNM, Win32/PSW.OnLineGames.NSU (2), Win32/PSW.OnLineGames.OKE, Win32/PSW.WOW.DZI, Win32/PSWTool.MailPassView.151 (4), Win32/Rootkit.Agent.NLY, Win32/Rustock.NIH, Win32/Rustock.NIK (3), Win32/Spy.Banker.AFFJ, Win32/Spy.Banker.QLG (4), Win32/TrojanDownloader.Bredolab.AA (2), Win32/TrojanDownloader.FakeAlert.AAX, Win32/TrojanDownloader.FakeAlert.ABV, Win32/TrojanDownloader.FakeAlert.ACU, Win32/TrojanDownloader.FakeAlert.ACV [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6089&amp;Itemid=26">4117</a></h1>
</p>
<p>PDF/Exploit.Pidief.ONG, VBS/TrojanDownloader.Small.L (6), Win32/Adware.BHO.GBP (2), Win32/Adware.BHO.NCG (2), Win32/Adware.GooochiBiz (4), Win32/Adware.WSearch, Win32/Agent.NXT (2), Win32/AutoRun.Agent.NP, Win32/AutoRun.Delf.BY, Win32/Delf.PFS, Win32/FlyStudio.NML, Win32/FlyStudio.NMM (5), Win32/Hupigon, Win32/Hupigon.NPE, Win32/KillAV.NDV (2), Win32/Koutodoor.AF (3), Win32/Koutodoor.G, Win32/Peerfrag.AG, Win32/Poison.NBC (2), Win32/PSW.Agent.NLP (2), Win32/PSW.OnLineGames.NMP (2), Win32/PSW.OnLineGames.NMY (3), Win32/PSW.OnLineGames.NNM, Win32/PSW.OnLineGames.NSU (2), Win32/PSW.OnLineGames.OKE, Win32/PSW.WOW.DZI, Win32/PSWTool.MailPassView.151 (4), Win32/Rootkit.Agent.NLY, Win32/Rustock.NIH, Win32/Rustock.NIK (3), Win32/Spy.Banker.AFFJ, Win32/Spy.Banker.QLG (4), Win32/TrojanDownloader.Bredolab.AA (2), Win32/TrojanDownloader.FakeAlert.AAX, Win32/TrojanDownloader.FakeAlert.ABV, Win32/TrojanDownloader.FakeAlert.ACU, Win32/TrojanDownloader.FakeAlert.ACV (2), Win32/TrojanDownloader.Zlob.CZJ, Win32/TrojanDropperDelf.NNM (2), Win32/TrojanDropper.VB.NHZ (2), Win32/Wigon.KU (2), Win32/Wigon.KY
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6089&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6089&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4117/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mass Injection Compromises More than Twenty-Thousand Web Sites</title>
		<link>http://sechero.com/mass-injection-compromises-more-than-twenty-thousand-web-sites/</link>
		<comments>http://sechero.com/mass-injection-compromises-more-than-twenty-thousand-web-sites/#comments</comments>
		<pubDate>Fri, 29 May 2009 19:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Lab]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Malicious Web Site / Malicious Code: Mass Injection Compromises More than Twenty-Thousand Web Sites Websense Security Labsâ„¢ Threatseekerâ„¢ Network has detected that a large compromise of legitimate Web sites is currently taking place around the globe. Thousands of legitimate Web sites have been discovered to be injected with malicious Javascript, obfuscated code that leads to [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://securitylabs.websense.com/content/Alerts/3405.aspx">Malicious Web Site / Malicious Code: Mass Injection Compromises More than Twenty-Thousand Web Sites</a></h1>
</p>
<p>
<p>Websense Security Labsâ„¢ Threatseekerâ„¢ Network has detected that a large compromise of legitimate Web sites is currently taking place around the globe. Thousands of legitimate Web sites have been discovered to be injected with malicious Javascript, obfuscated code that leads to an active exploit site. The active exploit site uses a name similar to the legitimate Google Analytics domain (<a href="http://google-analytics.com" title="http://google-analytics.com" target="_blank">google-analytics.com</a>), which provides statistical services to Web sites. </p>
<p>This mass injection attack does not seem related to Gumblar. The location of the injection, as well as the decoded code itself, seem to indicate a new, unrelated, mass injection campaign. </p>
<p>Screeenshot of injected code in an injected site: </p>
<p>&nbsp;
<p>The exploit site is laden with various attacks. After successful exploitation, a malicious file is run on the exploited computer. The executed malware file has a very low AV detection rate. </p>
<p>WebsenseÂ® Messaging and Websense Web Security customers are protected against this attack.
<p>URL: <a href="http://securitylabs.websense.com/content/Alerts/3405.aspx">http://securitylabs.websense.com/content/Alerts/3405.aspx</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/mass-injection-compromises-more-than-twenty-thousand-web-sites/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Its summer&#8230;Do you know what your kids are doing?, (Fri, May 29th)</title>
		<link>http://sechero.com/its-summerdo-you-know-what-your-kids-are-doing-fri-may-29th/</link>
		<comments>http://sechero.com/its-summerdo-you-know-what-your-kids-are-doing-fri-may-29th/#comments</comments>
		<pubDate>Fri, 29 May 2009 18:42:56 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Its summer&#8230;Do you know what your kids are doing?, (Fri, May 29th) School is over or about to be over for many kids. With that comes many families whose parents work and kids will be left at home to relax and enjoy their summer vacation. This means alot of free time and an internet out [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://isc.sans.org/diary.php?storyid=6490&amp;rss">Its summer&#8230;Do you know what your kids are doing?, (Fri, May 29th)</a></h1>
</p>
<p>School is over or about to be over for many kids. With that comes many families whose parents work and kids will be left at home to relax and enjoy their summer vacation. This means alot of free time and an internet out there just waiting to be explored. Everyone is aware of the need to keep your kids safe while on the internet. But in some cases, there is a need to keep the internet and others safe from your kids. Let me explain that last comment. Kids with too much time on their hands get into trouble. You hear about it all the time on the news with kids getting into trouble with things such as vandalism, stealing,etc. What about kids getting into trouble on the internet?<br /> Do a google search on the phrase teenage hacker and see what comes up. Kids are curious and learn fast. The internet can become a playground for them to explore and test out cool new programs and tools they find on the internet or write themselves. Chat rooms are available where kids can learn many things from others and want to try them for themselves. They can also get pulled into the wrong crowd on the internet and get in way over their heads fast. They may not even see anything wrong with it, its just computers after all.<br /> Most of the filtering technology today focuses on web traffic. What are your kids looking at on the web. That is a good thing, but there are many other ports and protocols available and nothing watching them. Would you know if your child was running a botnet? Stealing credit card numbers? Hacking into websites? Its not a game and there are real consequences to it, even sometimes when the intent may have been to do good.Here are some recent examples:<br /> Nineteen-year-old  Dmitriy Guzner from New Jersey was part of an underground hacking group named  &#8216;Anonymous&#8217; that targeted the church with several attacks. He could face ten  years in prison on computer hacking charges and is due to be sentenced on August  24. <a href="http://www.securecomputing.net.au/News/144850,teenage-hacker-pleads-guilty-to-church-of-scientology-cyber-attacks.aspx<br" title="http://www.securecomputing.net.au/News/144850,teenage-hacker-pleads-guilty-to-church-of-scientology-cyber-attacks.aspx<br" target="_blank">www.securecomputing.net.au/News/144850,teenage-hacker-pleads-guilty-to-church-of-scientology-cyber-attacks.aspx<br</a> /></p>
<p></p>
<p> Twitter has announced a review into four worm attacks on the site as a teenage hacker admits he could be jailed for his role in the stunt. <a href="http://news.sky.com/skynews/Home/Technology/Twitter-Worm-Attack-Biz-Stone-Announces-Review-As-Teenage-Hacker-Michael-Mooney-Speaks-Out/Article/200904215261579<br" title="http://news.sky.com/skynews/Home/Technology/Twitter-Worm-Attack-Biz-Stone-Announces-Review-As-Teenage-Hacker-Michael-Mooney-Speaks-Out/Article/200904215261579<br" target="_blank">news.sky.com/skynews/Home/Technology/Twitter-Worm-Attack-Biz-Stone-Announces-Review-As-Teenage-Hacker-Michael-Mooney-Speaks-Out/Article/200904215261579<br</a> /> A teenage hacker whose campaign to expose holes in Internet security sparked an FBI investigation was being sentenced in court today. <a href="http://www.independent.co.uk/news/business/news/teenage-hacker-to-be-sentenced-for-internet-crusade-676871.html<br" title="http://www.independent.co.uk/news/business/news/teenage-hacker-to-be-sentenced-for-internet-crusade-676871.html<br" target="_blank">www.independent.co.uk/news/business/news/teenage-hacker-to-be-sentenced-for-internet-crusade-676871.html<br</a> /> <br /> As parents, we need to also talk to our kids about the other dangers that are on the internet. Dangers such as hacking, virus making, botnet creation, stealing, etc. You may think your child is doing nothing but sitting on a computer playing. But keep in mind that computer on the internet is a portal to a whole nother world.
<p>URL: <a href="http://isc.sans.org/diary.php?storyid=6490&amp;rss">http://isc.sans.org/diary.php?storyid=6490&amp;rss</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/its-summerdo-you-know-what-your-kids-are-doing-fri-may-29th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>President Obama address nation on cyber security</title>
		<link>http://sechero.com/president-obama-address-nation-on-cyber-security/</link>
		<comments>http://sechero.com/president-obama-address-nation-on-cyber-security/#comments</comments>
		<pubDate>Fri, 29 May 2009 15:28:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[Spyware]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[President Obama address nation on cyber security Within the past hour, President Obama addressed the nation from the White House to emphasize the importance of cyber security, to announce the release of the administration&#8217;s report of its 60-day cyberspace policy review, and to announce the creation of a new White House position, the Coordinator of [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://blog.stopbadware.org/2009/05/29/president-obama-address-nation-on-cyber-security">President Obama address nation on cyber security</a></h1>
</p>
<p>
<p>Within the past hour, President Obama addressed the nation from the White House to emphasize the importance of cyber security, to announce the release of the administration&#8217;s report of its 60-day cyberspace policy review, and to announce the creation of a new White House position, the Coordinator of National Cyber Security.</p>
<p>This represents an enormous step forward in national awareness of the role cyber security in general and malware in particular play in our economy and our physical security. Having the &quot;leader of the free world&quot; describe the threat of botnets and spyware on national television will expand press and citizen interest in this issue.</p>
<p>As important as the threats, though, are the freedoms that the President discussed. He emphasized the importance of preserving both personal privacy and net neutrality while securing our infrastructure. He also pointed out that this will require a collaborative effort amongst individuals, schools, corporations, and governments from the local level through the national level, not just in the U.S., but internationally, as well.</p>
<p>The attention is an important start, but of course execution is the key. Melissa Hathaway, Cybersecurity Chief at the National Security Council, posted some <a href="http://www.whitehouse.gov/CyberReview/">information about the policy review</a> she led, as well as links to <a href="http://www.whitehouse.gov/asset.aspx?AssetId=1732">the report</a> (PDF) and to <a href="http://www.whitehouse.gov/cyberreview/documents/">the papers</a> that informed the report. Based on a preview of the report that Melissa Hathaway delivered at the Kennedy School last night, I expect the administration is moving in the right direction. I look forward to reading the report, and I encourage others to do so, as well. Meanwhile, it&#8217;s up to all of us to work together to build a safer Internet. StopBadware looks forward to playing a role in bringing together the people, the organizations, and the data that make this possible.</p>
<p><img height="1" src="http://feeds2.feedburner.com/~r/StopbadwareBlog/~4/nPpvttF2Hoc" width="1" />
<p>URL: <a href="http://blog.stopbadware.org/2009/05/29/president-obama-address-nation-on-cyber-security">http://blog.stopbadware.org/2009/05/29/president-obama-address-nation-on-cyber-security</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/president-obama-address-nation-on-cyber-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4116</title>
		<link>http://sechero.com/4116/</link>
		<comments>http://sechero.com/4116/#comments</comments>
		<pubDate>Fri, 29 May 2009 08:23:12 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Spyware]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[4116 BAT/Qhost.NBP (2), INF/Autorun (3), PDF/Exploit.Pidief.ONM, PDF/Exploit.Pidief.ONN (2), PDF/Exploit.Pidief.ONO, PDF/Exploit.Pidief.ONP (2), Win32/Adware.BHO.NCX, Win32/Adware.Coolezweb (4), Win32/Adware.InternetAntivirus, Win32/Adware.PersonalAntivirus, Win32/Adware.SpywareRemover, Win32/Adware.SystemSecurity (18), Win32/Agent.PMR (2), Win32/Agent.WPI, Win32/AntiAV.AZQ, Win32/AntiAV.NAO (2), Win32/AutoRun.ABH, Win32/AutoRun.ADR (2), Win32/AutoRun.FakeAlert.BR, Win32/AutoRun.FakeAlert.M, Win32/AutoRun.VB.CN (2), Win32/Bagle.RG, Win32/Delf.NSQ (3), Win32/Dialer.NHQ (3), Win32/Dialer.NHR (3), Win32/FlyStudio.NMJ, Win32/FlyStudio.NMK, Win32/Hupigon.NPD, Win32/Injector.PK, Win32/IRCBot.ADZ, Win32/Koobface.NBG (2), Win32/Koutodoor.AB, Win32/Koutodoor.AD, Win32/Koutodoor.AE (4), Win32/Koutodoor.G, Win32/Kryptik.QY, Win32/Olmarik.GW (2), Win32/Olmarik.HG [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6085&amp;Itemid=26">4116</a></h1>
</p>
<p>BAT/Qhost.NBP (2), INF/Autorun (3), PDF/Exploit.Pidief.ONM, PDF/Exploit.Pidief.ONN (2), PDF/Exploit.Pidief.ONO, PDF/Exploit.Pidief.ONP (2), Win32/Adware.BHO.NCX, Win32/Adware.Coolezweb (4), Win32/Adware.InternetAntivirus, Win32/Adware.PersonalAntivirus, Win32/Adware.SpywareRemover, Win32/Adware.SystemSecurity (18), Win32/Agent.PMR (2), Win32/Agent.WPI, Win32/AntiAV.AZQ, Win32/AntiAV.NAO (2), Win32/AutoRun.ABH, Win32/AutoRun.ADR (2), Win32/AutoRun.FakeAlert.BR, Win32/AutoRun.FakeAlert.M, Win32/AutoRun.VB.CN (2), Win32/Bagle.RG, Win32/Delf.NSQ (3), Win32/Dialer.NHQ (3), Win32/Dialer.NHR (3), Win32/FlyStudio.NMJ, Win32/FlyStudio.NMK, Win32/Hupigon.NPD, Win32/Injector.PK, Win32/IRCBot.ADZ, Win32/Koobface.NBG (2), Win32/Koutodoor.AB, Win32/Koutodoor.AD, Win32/Koutodoor.AE (4), Win32/Koutodoor.G, Win32/Kryptik.QY, Win32/Olmarik.GW (2), Win32/Olmarik.HG (4), Win32/Olmarik.IB, Win32/Peerfrag.BA, Win32/Peerfrag.BG, Win32/Peerfrag.BH, Win32/Popwin.NBJ (2), Win32/PSW.OnLineGames.NMP, Win32/PSW.OnLineGames.NMY, Win32/PSW.OnLineGames.OKC, Win32/PSW.Small.NBE (4), Win32/Qhost, Win32/Qhost.NIJ (2), Win32/Rootkit.Agent.KZU, Win32/Rootkit.Ressdt.NBS, Win32/Spy.Banker.QRW (2), Win32/Spy.Banker.QYO (3), Win32/Spy.Banker.QZB (2), Win32/Spy.Banker.QZC (2), Win32/Spy.Goldun.NFA, Win32/Spy.Zbot.JF (3), Win32/Spy.Zbot.PG (2), Win32/Spy.Zbot.RD, Win32/Spy.Zbot.RN, Win32/Tifaut.C (4), Win32/TrojanDownloader.Agent.PCZ, Win32/TrojanDownloader.Agent.PDA, Win32/TrojanDownloader.Agent.PDB, Win32/TrojanDownloader.Agent.PDC, Win32/TrojanDownloader.Agent.PDD, Win32/TrojanDownloader.Bagle.NBJ, Win32/TrojanDownloader.Bredolab.AB, Win32/TrojanDownloader.FakeAlert.AAX, Win32/TrojanDownloader.FakeAlert.ABV, Win32/TrojanDownloader.Small.OPS (2), Win32/TrojanDownloader.Zlob.CZK, Win32/VB.NHD, Win32/VB.OEY (2), Win32/Wigon.KX
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6085&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6085&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4116/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4115</title>
		<link>http://sechero.com/4115/</link>
		<comments>http://sechero.com/4115/#comments</comments>
		<pubDate>Fri, 29 May 2009 03:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false">http://sechero.com/4115/</guid>
		<description><![CDATA[4115 PDF/Exploit.Pidief.ODH, PDF/Exploit.Pidief.OLC, PDF/Exploit.Pidief.ONL, Win32/Adware.SystemSecurity, Win32/Agent.PMP (2), Win32/Agent.PMQ, Win32/AutoRun.Agent.OJ (2), Win32/AutoRun.KS (2), Win32/BHO.NPK (2), Win32/Injector.PJ, Win32/KillFiles.NCF, Win32/Kryptik.QX, Win32/Peerfrag.BF (2), Win32/Rootkit.Agent.NMA, Win32/Rootkit.Ressdt.NBR, Win32/SpamTool.Agent.NCL, Win32/TrojanDownloader.Bredolab.AA (4) URL: http://www.eset.com/joomla/index.php?option=com_content&#38;task=view&#38;id=6084&#38;Itemid=26]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6084&amp;Itemid=26">4115</a></h1>
</p>
<p>PDF/Exploit.Pidief.ODH, PDF/Exploit.Pidief.OLC, PDF/Exploit.Pidief.ONL, Win32/Adware.SystemSecurity, Win32/Agent.PMP (2), Win32/Agent.PMQ, Win32/AutoRun.Agent.OJ (2), Win32/AutoRun.KS (2), Win32/BHO.NPK (2), Win32/Injector.PJ, Win32/KillFiles.NCF, Win32/Kryptik.QX, Win32/Peerfrag.BF (2), Win32/Rootkit.Agent.NMA, Win32/Rootkit.Ressdt.NBR, Win32/SpamTool.Agent.NCL, Win32/TrojanDownloader.Bredolab.AA (4)
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6084&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6084&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4115/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4113</title>
		<link>http://sechero.com/4113/</link>
		<comments>http://sechero.com/4113/#comments</comments>
		<pubDate>Thu, 28 May 2009 10:40:12 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Proxy]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[4113 BAT/Agent.NBW, PDF/Exploit.Pidief.ONK, Win32/Adware.Antivirus2008 (2), Win32/Adware.Coolezweb (2), Win32/Adware.InternetAntivirus (5), Win32/Adware.SystemSecurity (4), Win32/Agent.NXT, Win32/Agent.PHC, Win32/Agent.PKT (2), Win32/Agent.WPI (4), Win32/AutoRun.Agent.OG, Win32/AutoRun.Agent.OH, Win32/AutoRun.Agent.OI, Win32/AutoRun.FakeAlert.AF (3), Win32/AutoRun.KS, Win32/AutoRun.VB.DQ, Win32/Boberog.AC, Win32/Dialer.NHP (2), Win32/Hupigon.NPB, Win32/Hupigon.NPC, Win32/Injector.PH, Win32/Injector.PI, Win32/IRCBot.ADZ (2), Win32/KeyLogger.BitLogic, Win32/NetPass (2), Win32/Obfuscated.NCY, Win32/Olmarik.HG (4), Win32/Poebot, Win32/Prosti.NCL (2), Win32/PSW.LdPinch.NJG, Win32/PSW.WOW.NKO (2), Win32/PSW.YahooPass.NAD (2), Win32/PSWTool.IEPassView.NAD, Win32/PSWTool.MailPassView.150, Win32/PSWTool.PassFox.111 (2), Win32/Rustock.NIH, Win32/Rustock.NIK, Win32/Sohanad.BM, Win32/Sohanad.NEJ, [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6082&amp;Itemid=26">4113</a></h1>
</p>
<p>BAT/Agent.NBW, PDF/Exploit.Pidief.ONK, Win32/Adware.Antivirus2008 (2), Win32/Adware.Coolezweb (2), Win32/Adware.InternetAntivirus (5), Win32/Adware.SystemSecurity (4), Win32/Agent.NXT, Win32/Agent.PHC, Win32/Agent.PKT (2), Win32/Agent.WPI (4), Win32/AutoRun.Agent.OG, Win32/AutoRun.Agent.OH, Win32/AutoRun.Agent.OI, Win32/AutoRun.FakeAlert.AF (3), Win32/AutoRun.KS, Win32/AutoRun.VB.DQ, Win32/Boberog.AC, Win32/Dialer.NHP (2), Win32/Hupigon.NPB, Win32/Hupigon.NPC, Win32/Injector.PH, Win32/Injector.PI, Win32/IRCBot.ADZ (2), Win32/KeyLogger.BitLogic, Win32/NetPass (2), Win32/Obfuscated.NCY, Win32/Olmarik.HG (4), Win32/Poebot, Win32/Prosti.NCL (2), Win32/PSW.LdPinch.NJG, Win32/PSW.WOW.NKO (2), Win32/PSW.YahooPass.NAD (2), Win32/PSWTool.IEPassView.NAD, Win32/PSWTool.MailPassView.150, Win32/PSWTool.PassFox.111 (2), Win32/Rustock.NIH, Win32/Rustock.NIK, Win32/Sohanad.BM, Win32/Sohanad.NEJ, Win32/Spy.Banker.QZA, Win32/Spy.KeyLogger.NEC (2), Win32/Spy.Zbot.CK, Win32/Spy.Zbot.JF, Win32/Spy.Zbot.RL, Win32/Spy.Zbot.RM, Win32/StartPage.BR, Win32/StartPage.NKJ (3), Win32/TrojanClicker.Agent.NGT (2), Win32/TrojanClicker.VB.NHG (2), Win32/TrojanClicker.VB.NHH, Win32/TrojanDownloader.Agent.PAQ (2), Win32/TrojanDownloader.Agent.PCY, Win32/TrojanDownloader.Bredolab.AB (2), Win32/TrojanDownloader.FakeAlert.UX, Win32/TrojanDownloader.Small.NTQ (3), Win32/TrojanDownloader.Small.OCS (2), Win32/TrojanDownloader.Small.OOT, Win32/TrojanDownloader.Small.OPP, Win32/TrojanDownloader.Small.OPR, Win32/TrojanDownloader.Zlob.CZK, Win32/TrojanDropper.VB.NHW, Win32/TrojanProxy.Wintu.B
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6082&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6082&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4113/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Host file black lists , (Wed, May 27th)</title>
		<link>http://sechero.com/host-file-black-lists-wed-may-27th/</link>
		<comments>http://sechero.com/host-file-black-lists-wed-may-27th/#comments</comments>
		<pubDate>Wed, 27 May 2009 17:21:08 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[ASCII]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Proxy]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Host file black lists , (Wed, May 27th) Henry Hertz Hobbit who maintains a black list of bad hosts wrote in today with some host file links and comments on them. I have included most of his comments with very little editing (I removed a few names and comments about other list maintainers and corrected [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://isc.sans.org/diary.php?storyid=6469&amp;rss">Host file black lists , (Wed, May 27th)</a></h1>
</p>
<p>Henry Hertz Hobbit who maintains a black list of bad hosts wrote in today with some host file links </p>
<p> and comments on them. I have included most of his comments with very little editing</p>
<p> (I removed a few names and comments about other list maintainers and corrected a bit of the grammer). </p>
<p> I have NOT verified all of the lists than Henry discusses below. Our users should be warned that </p>
<p> I have seen poorly maintained lists block legitimate sites in the past. </p>
<p> We have had some less attentive or overly aggressive list maintainers use our hosts </p>
<p> list as a block list even though it clearly states DO NOT USE AS A BLOCK LIST </p>
<p> and then blame <a href="http://isc.sans.org" title="http://isc.sans.org" target="_blank">isc.sans.org</a> for the listing, <a href="http://isc.sans.org/ipsascii.html" title="http://isc.sans.org/ipsascii.html" target="_blank">isc.sans.org/ipsascii.html</a>. </p>
<p> Other handlers have written some excellent diaries about blacklists addressing issues </p>
<p> such as Spam blocking by RBLs, Blacklists and politics, </p>
<p> and making the right choice in black list selection:</p>
<p> <a href="http://isc.sans.org/diary.html?storyid=3194<br" title="http://isc.sans.org/diary.html?storyid=3194<br" target="_blank">isc.sans.org/diary.html?storyid=3194<br</a> /></p>
<p> <a href="http://isc.sans.org/diary.html?storyid=3042<br" title="http://isc.sans.org/diary.html?storyid=3042<br" target="_blank">isc.sans.org/diary.html?storyid=3042<br</a> /></p>
<p> <a href="http://isc.sans.org/diary.html?storyid=1309<br" title="http://isc.sans.org/diary.html?storyid=1309<br" target="_blank">isc.sans.org/diary.html?storyid=1309<br</a> /></p>
</p>
<p> For more information on host based blocking this site has a good descriptions, </p>
<p> some lists that are on Henrys lists and some additional lists didnt include in his set.</p>
<p> <a href="http://www.malwarehelp.org/how-to-effectively-prevent-malware-hosts-file.html<br" title="http://www.malwarehelp.org/how-to-effectively-prevent-malware-hosts-file.html<br" target="_blank">www.malwarehelp.org/how-to-effectively-prevent-malware-hosts-file.html<br</a> /></p>
</p>
<p> &gt;From Henry Hertz Hobbit:</p>
<p> Two old venerable lists are MVPHosts and hpHosts.</p>
<p> <a href="http://www.mvps.org/winhelp2002/hosts.htm<br" title="http://www.mvps.org/winhelp2002/hosts.htm<br" target="_blank">www.mvps.org/winhelp2002/hosts.htm<br</a> /></p>
<p> <a href="http://hosts-file.net/<br" title="http://hosts-file.net/<br" target="_blank">hosts-file.net/<br</a> /></p>
</p>
<p> MalwareDomainList is here with their lists and they block ONLY sites with malicious </p>
<p> content (no ads or trackers / spies):</p>
<p> <a href="http://www.malwaredomainlist.com/hostslist/hosts.txt<br" title="http://www.malwaredomainlist.com/hostslist/hosts.txt<br" target="_blank">www.malwaredomainlist.com/hostslist/hosts.txt<br</a> /></p>
<p> <a href="http://www.malwaredomainlist.com/<br" title="http://www.malwaredomainlist.com/<br" target="_blank">www.malwaredomainlist.com/<br</a> /></p>
<p> <a href="http://www.malwaredomainlist.com/mdl.php<br" title="http://www.malwaredomainlist.com/mdl.php<br" target="_blank">www.malwaredomainlist.com/mdl.php<br</a> /></p>
</p>
<p> The French connection consists of what I would call the MVPHosts file with a Franais twist </p>
<p> (there are some trackers that are quite prevalent if France that don&#8217;t exist any place else):</p>
<p> <a href="http://sysctl.org/cameleon/hosts<br" title="http://sysctl.org/cameleon/hosts<br" target="_blank">sysctl.org/cameleon/hosts<br</a> /></p>
<p> <a href="http://sysctl.org/cameleon/<br" title="http://sysctl.org/cameleon/<br" target="_blank">sysctl.org/cameleon/<br</a> /></p>
</p>
<p> Another list that has the most comprehensive lists that may need some pruning:</p>
<p> <a href="http://rlwpx.free.fr/WPFF/hosts.htm<br" title="http://rlwpx.free.fr/WPFF/hosts.htm<br" target="_blank">rlwpx.free.fr/WPFF/hosts.htm<br</a> /></p>
</p>
<p> This list primarily don&#8217;t belong on the desktop but into something like this:</p>
<p> <a href="http://www.peereboom.us/adsuck/<br" title="http://www.peereboom.us/adsuck/<br" target="_blank">www.peereboom.us/adsuck/<br</a> /></p>
</p>
<p> And then there is my list which includes many of the hosts that MalwareDomainList lists.</p>
<p> <a href="http://www.SecureMecca.com/hosts.html<br" title="http://www.SecureMecca.com/hosts.html<br" target="_blank">www.SecureMecca.com/hosts.html<br</a> /></p>
<p> <a href="http://www.HostsFile.org/hosts.html<br" title="http://www.HostsFile.org/hosts.html<br" target="_blank">www.HostsFile.org/hosts.html<br</a> /></p>
</p>
<p> But I provide something far more powerful called a PAC (Proxy Auto Configuration) filter </p>
<p> that blocks unknown threats:</p>
<p> <a href="http://www.SecureMecca.com/pac.html<br" title="http://www.SecureMecca.com/pac.html<br" target="_blank">www.SecureMecca.com/pac.html<br</a> /></p>
<p> <a href="http://www.HostsFile.org/pac.html<br" title="http://www.HostsFile.org/pac.html<br" target="_blank">www.HostsFile.org/pac.html<br</a> /></p>
<p> <a href="http://www.SecureMecca.com/Downloads/<br" title="http://www.SecureMecca.com/Downloads/<br" target="_blank">www.SecureMecca.com/Downloads/<br</a> /></p>
</p>
<p> Now I have heard you need an IQ of 130 plus or higher to use the PAC filter. </p>
<p> If that is a problem so be it. But consider the following points.</p>
</p>
<p> 1. hpHosts (<a href="http://hosts-file.net" title="http://hosts-file.net" target="_blank">hosts-file.net</a>) blocks approximately 3700 typo hosts. </p>
<p> I block them with just two hosts in the hosts file (<a href="http://ownbox.com" title="http://ownbox.com" target="_blank">ownbox.com</a> and <a href="http://www.ownbox.com" title="http://www.ownbox.com" target="_blank">www.ownbox.com</a>) </p>
<p> and these two rules in the PAC filter:</p>
</p>
<p> // OWNBOX FE TYPO</p>
<p> BadNetworks[i++] = 216.65.41.185, 255.255.255.255</p>
<p> BadNetworks[i++] = 216.65.41.188, 255.255.255.255</p>
</p>
<p> Now that cuts it down to size, doesn&#8217;t it? There is a lot of other power reducers and </p>
<p> falling through the cracks rules in there! Otherwise my file would be almost as large </p>
<p> as the list at rlwpx.free.fr/WPFF/hosts.htm.</p>
</p>
<p> 2. If you enable the PAC filter on Windows in IE you will have your eyes opened. </p>
<p> I had full debug on that way once and found the PAC filter was even working at the level </p>
<p> of tellimg me I sent a print-out to the network printer! But debug really should only </p>
<p> be used in Firefox with debug mode set to debugNormal. Do not turn debug on in Opera or </p>
<p> Safari (they kill it), or IE (you will have pop-up nightmares).</p>
</p>
<p> 3. The REGEXPs are precompiled for speed. It is faster in debug mode than John LoVerso&#8217;s </p>
<p> original was without any debug. But then I noticed some of his ad patterns are pretty convoluted. </p>
<p> But if you have to interpret them every time &#8230;</p>
</p>
<p> 4. I notice patterns that occur frequently enough that I block yet to be discovered </p>
<p> hosts with patterns like these:</p>
<p> BadHostParts[i++] = antispy // VOTRE CHOIX</p>
<p> BadHostParts[i++] = antivir // VOTRE CHOIX</p>
</p>
<p> There are of course some white-list rules to counteract the bad rules </p>
<p> (and now you are back to blocking in the hosts file):</p>
<p> GoodDomains[i++] = <a href="http://antispamfilterblocker.com" title="http://antispamfilterblocker.com" target="_blank">antispamfilterblocker.com</a></p>
<p> GoodDomains[i++] = <a href="http://antivirusyellowpages.com" title="http://antivirusyellowpages.com" target="_blank">antivirusyellowpages.com</a></p>
<p> GoodDomains[i++] = <a href="http://pcantivirusreviews.com" title="http://pcantivirusreviews.com" target="_blank">pcantivirusreviews.com</a></p>
</p>
<p> 5. Even if hosts make it past the rules for the hosts and there is no host block, </p>
<p> for some of the malware there are patterns and I block them as I discover and </p>
<p> mentally count them and consider the count high enough to go into panic mode </p>
<p> (and I think a lot of people are already there now):</p>
</p>
<p> BadURL_Parts[i++] = av2008</p>
<p> BadURL_Parts[i++] = av2009</p>
<p> BadURL_Parts[i++] = sms.exe</p>
<p> BadURL_Parts[i++] = smsreader</p>
</p>
<p> Oh yes, HostsMan is available here:</p>
<p> <a href="http://www.abelhadigital.com/" title="http://www.abelhadigital.com/" target="_blank">www.abelhadigital.com/</a> </p>
<p>
<p>URL: <a href="http://isc.sans.org/diary.php?storyid=6469&amp;rss">http://isc.sans.org/diary.php?storyid=6469&amp;rss</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/host-file-black-lists-wed-may-27th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4109</title>
		<link>http://sechero.com/4109/</link>
		<comments>http://sechero.com/4109/#comments</comments>
		<pubDate>Wed, 27 May 2009 07:37:54 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[AdWare]]></category>
		<category><![CDATA[Downloader]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Win32]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[4109 IRC/SdBot, Win32/Adware.AdvancedCleaner (3), Win32/Adware.BHO.NCG, Win32/Adware.BHO.NCX, Win32/Adware.Coolezweb (2), Win32/Adware.PersonalAntivirus.AA, Win32/Adware.PersonalAntivirus.AB, Win32/Adware.SystemSecurity.AA (2), Win32/Adware.Virtumonde, Win32/Adware.WinPCDefender (2), Win32/Adware.WSearch, Win32/Agent.PME, Win32/Agent.PMF, Win32/Agent.PMG (6), Win32/Agent.PMH (2), Win32/AntiAV.NAK, Win32/AutoRun.Autoit.P, Win32/BHO.NOS, Win32/BHO.NPJ, Win32/BHO.TBL (2), Win32/Bifrose.ADR, Win32/Delf.OJA (2), Win32/Flyagent.NAV (2), Win32/Flyagent.NAW (2), Win32/FlyStudio.NMH, Win32/Injector.PB, Win32/Injector.PC, Win32/Koutodoor.AB (3), Win32/Koutodoor.G, Win32/Kryptik.QO, Win32/Kryptik.QP, Win32/Mebroot.BL, Win32/Merond.P (2), Win32/Olmarik.GW, Win32/Olmarik.HG (2), Win32/Popwin.NBI, Win32/PSW.OnLineGames.NMY, Win32/PSW.OnLineGames.OKB (3), Win32/PSW.QQPass.NEH (4), [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6078&amp;Itemid=26">4109</a></h1>
</p>
<p>IRC/SdBot, Win32/Adware.AdvancedCleaner (3), Win32/Adware.BHO.NCG, Win32/Adware.BHO.NCX, Win32/Adware.Coolezweb (2), Win32/Adware.PersonalAntivirus.AA, Win32/Adware.PersonalAntivirus.AB, Win32/Adware.SystemSecurity.AA (2), Win32/Adware.Virtumonde, Win32/Adware.WinPCDefender (2), Win32/Adware.WSearch, Win32/Agent.PME, Win32/Agent.PMF, Win32/Agent.PMG (6), Win32/Agent.PMH (2), Win32/AntiAV.NAK, Win32/AutoRun.Autoit.P, Win32/BHO.NOS, Win32/BHO.NPJ, Win32/BHO.TBL (2), Win32/Bifrose.ADR, Win32/Delf.OJA (2), Win32/Flyagent.NAV (2), Win32/Flyagent.NAW (2), Win32/FlyStudio.NMH, Win32/Injector.PB, Win32/Injector.PC, Win32/Koutodoor.AB (3), Win32/Koutodoor.G, Win32/Kryptik.QO, Win32/Kryptik.QP, Win32/Mebroot.BL, Win32/Merond.P (2), Win32/Olmarik.GW, Win32/Olmarik.HG (2), Win32/Popwin.NBI, Win32/PSW.OnLineGames.NMY, Win32/PSW.OnLineGames.OKB (3), Win32/PSW.QQPass.NEH (4), Win32/Rootkit.Agent.NLZ (2), Win32/Rootkit.Podnuha.NCB, Win32/Rustock.NIH, Win32/Rustock.NIK, Win32/Spy.Agent.NNQ, Win32/Spy.Banbra.NPR (2), Win32/Spy.Banker.QQJ, Win32/Spy.Banker.QYP (2), Win32/Spy.Banker.QYQ (2), Win32/Spy.Banker.QYR (2), Win32/Spy.Banker.QYS (2), Win32/Spy.Banker.QYT (2), Win32/Spy.Banker.QYU (2), Win32/Spy.Delf.NUL (2), Win32/SpyBot (2), Win32/StartPage.BR, Win32/TrojanDownloader.Adload.NFC, Win32/TrojanDownloader.Agent.PCW (2), Win32/TrojanDownloader.Autoit.NAM, Win32/TrojanDownloader.Bredolab.AA (2), Win32/TrojanDownloader.FakeAlert.AAX, Win32/TrojanDownloader.FakeAlert.ACS (2), Win32/TrojanDownloader.Flux, Win32/TrojanDownloader.Small.OPO, Win32/TrojanDownloader.Swizzor.NCA (2), Win32/TrojanDownloader.Zlob.CZK, Win32/TrojanDownloader.Zlob.CZV (3), Win32/TrojanDropper.Agent.OBD, Win32/TrojanDropper.Delf.NNK, Win32/VB.NRL, Win32/VB.OET (3)
<p>URL: <a href="http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6078&amp;Itemid=26">http://www.eset.com/joomla/index.php?option=com_content&amp;task=view&amp;id=6078&amp;Itemid=26</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4109/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

