<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Philosophically Secure &#187; reversing</title>
	<atom:link href="http://eugk.net/wordpress/category/reversing/feed/" rel="self" type="application/rss+xml" />
	<link>http://eugk.net/wordpress</link>
	<description>Eugene Kogan&#039;s blog on information security and software engineering</description>
	<lastBuildDate>Wed, 13 Jan 2010 01:11:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Automated Web-Based Malware Behavior Analysis</title>
		<link>http://eugk.net/wordpress/2008/10/21/automated-web-based-malware-behavior-analysis/</link>
		<comments>http://eugk.net/wordpress/2008/10/21/automated-web-based-malware-behavior-analysis/#comments</comments>
		<pubDate>Wed, 22 Oct 2008 00:10:12 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[reversing]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[virtualization]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/?p=166</guid>
		<description><![CDATA[I just watched a video presentation from September's OWASP conference. The presenter, Tyler Hudak, talked about the Truman-based hybrid sandnet he created to automate the analysis of web-based malware. He references Google's The Ghost in the Browser paper, as well as the Honeynet Project. One tool he used to help automate things in Windows is [...]]]></description>
			<content:encoded><![CDATA[<p>I just watched a video presentation from September's <a href="http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference">OWASP conference</a>. The presenter, Tyler Hudak, talked about the <a href="http://www.secureworks.com/research/tools/truman.html">Truman</a>-based hybrid sandnet he created to <a href="http://video.google.com/videoplay?docid=4204600308807371535&amp;hl=en">automate the analysis of web-based malware</a>. He references Google's <a href="http://www.usenix.org/event/hotbots07/tech/full_papers/provos/provos.pdf">The Ghost in the Browser</a> paper, as well as the <a href="http://www.honeynet.org/papers/">Honeynet Project</a>. One tool he used to help automate things in Windows is <a href="http://www.autoitscript.com/autoit3/index.shtml">AutoIt</a>, something I had not heard of before, but it sounds handy. The demo also shows a tool called <a href="http://www.pcmag.com/article2/0,4149,9882,00.asp">InCtrl5</a>, a utility for Windows that monitors changes to your system, primarily for use when installing some new program. I guess it's used to compliment the usual <a href="http://technet.microsoft.com/en-us/sysinternals/default.aspx" target="_blank">Sysinternals</a> tools, so maybe it has some extra features that Tyler finds useful.</p>
<p>Some of the problems this approach is trying to solve are browser-dependent obfuscated JavaScript, plug-in dependencies (like Flash), multiple redirects, etc. All of these issues make malware analysis more complex and time consuming, so any automation you can get away with is a big help. The demo at the end is pretty cool, but he glossed over how the information from the automated analysis is presented to the user. I'm guessing it's not (yet) in a pretty report format. Either way, you still need someone with the right knowledge to analyze the output and decide what to do with it to help defend your network.</p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DAutomated%2520Web-Based%2520Malware%2520Behavior%2520Analysis%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F10%252F21%252Fautomated-web-based-malware-behavior-analysis%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F10%252F21%252Fautomated-web-based-malware-behavior-analysis%252F%26amp%3Btitle%3DAutomated%2520Web-Based%2520Malware%2520Behavior%2520Analysis%26amp%3Bbodytext%3DI%2520just%2520watched%2520a%2520video%2520presentation%2520from%2520September%2527s%2520OWASP%2520conference.%2520The%2520presenter%252C%2520Tyler%2520Hudak%252C%2520talked%2520about%2520the%2520Truman-based%2520hybrid%2520sandnet%2520he%2520created%2520to%2520automate%2520the%2520analysis%2520of%2520web-based%2520malware.%2520He%2520references%2520Google%2527s%2520The%2520Ghost%2520in%2520the%2520Browser%2520';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F10%252F21%252Fautomated-web-based-malware-behavior-analysis%252F%26amp%3Bt%3DAutomated%2520Web-Based%2520Malware%2520Behavior%2520Analysis';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F10%252F21%252Fautomated-web-based-malware-behavior-analysis%252F%26amp%3Btitle%3DAutomated%2520Web-Based%2520Malware%2520Behavior%2520Analysis%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DI%2520just%2520watched%2520a%2520video%2520presentation%2520from%2520September%2527s%2520OWASP%2520conference.%2520The%2520presenter%252C%2520Tyler%2520Hudak%252C%2520talked%2520about%2520the%2520Truman-based%2520hybrid%2520sandnet%2520he%2520created%2520to%2520automate%2520the%2520analysis%2520of%2520web-based%2520malware.%2520He%2520references%2520Google%2527s%2520The%2520Ghost%2520in%2520the%2520Browser%2520';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F10%252F21%252Fautomated-web-based-malware-behavior-analysis%252F%26amp%3Btitle%3DAutomated%2520Web-Based%2520Malware%2520Behavior%2520Analysis%26amp%3Bnotes%3DI%2520just%2520watched%2520a%2520video%2520presentation%2520from%2520September%2527s%2520OWASP%2520conference.%2520The%2520presenter%252C%2520Tyler%2520Hudak%252C%2520talked%2520about%2520the%2520Truman-based%2520hybrid%2520sandnet%2520he%2520created%2520to%2520automate%2520the%2520analysis%2520of%2520web-based%2520malware.%2520He%2520references%2520Google%2527s%2520The%2520Ghost%2520in%2520the%2520Browser%2520';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F10%252F21%252Fautomated-web-based-malware-behavior-analysis%252F%26amp%3Btitle%3DAutomated%2520Web-Based%2520Malware%2520Behavior%2520Analysis';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2008/10/21/automated-web-based-malware-behavior-analysis/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Malicious CHM file targets PGP</title>
		<link>http://eugk.net/wordpress/2008/03/27/malicious-chm-file-targets-pgp/</link>
		<comments>http://eugk.net/wordpress/2008/03/27/malicious-chm-file-targets-pgp/#comments</comments>
		<pubDate>Fri, 28 Mar 2008 00:45:16 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[hacking]]></category>
		<category><![CDATA[reversing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/2008/03/27/malicious-chm-file-targets-pgp/</guid>
		<description><![CDATA[Let's not forget that CHM files can be dangerous. They can contain embedded executables that get launched automatically when you open them. This post on SANS ISC details a particular malicious CHM file that was sent out via email. After some investigation, it was determined that the program it ran specifically targeted PGP keyrings.
The code [...]]]></description>
			<content:encoded><![CDATA[<p>Let's not forget that <a href="http://en.wikipedia.org/wiki/Microsoft_Compressed_HTML_Help" target="_blank">CHM files</a> can be dangerous. They can contain embedded executables that get launched automatically when you open them. <a href="http://isc.sans.org/diary.html?storyid=4207" target="_blank">This post on SANS ISC</a> details a particular malicious CHM file that was sent out via email. After some investigation, it was determined that the program it ran specifically targeted <a href="http://www.cit.cornell.edu/identity/pgp/glossary.html" target="_blank">PGP keyrings</a>.</p>
<p>The code searched for these files (.pkr and .skr) and copied them off to the attacker's system. To really make use of a PGP keyring, you need the passphrase. Well, this is why the malware came bundled with a keylogger, just in case you happened to be using PGP while it was running. The ISC post also notes that it collected .doc files, which could be an attempt to harvest documents that users created to help them keep track of their passphrases.</p>
<p>I'm not sure if I see enough evidence to agree with the conclusion that the attacker was simply trying to map relationships between PGP users, but I guess that is a possibility. Do recent versions of PGP even use these same keyring files?</p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DMalicious%2520CHM%2520file%2520targets%2520PGP%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F03%252F27%252Fmalicious-chm-file-targets-pgp%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F03%252F27%252Fmalicious-chm-file-targets-pgp%252F%26amp%3Btitle%3DMalicious%2520CHM%2520file%2520targets%2520PGP%26amp%3Bbodytext%3DLet%2527s%2520not%2520forget%2520that%2520CHM%2520files%2520can%2520be%2520dangerous.%2520They%2520can%2520contain%2520embedded%2520executables%2520that%2520get%2520launched%2520automatically%2520when%2520you%2520open%2520them.%2520This%2520post%2520on%2520SANS%2520ISC%2520details%2520a%2520particular%2520malicious%2520CHM%2520file%2520that%2520was%2520sent%2520out%2520via%2520email.%2520After%2520some%2520investig';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F03%252F27%252Fmalicious-chm-file-targets-pgp%252F%26amp%3Bt%3DMalicious%2520CHM%2520file%2520targets%2520PGP';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F03%252F27%252Fmalicious-chm-file-targets-pgp%252F%26amp%3Btitle%3DMalicious%2520CHM%2520file%2520targets%2520PGP%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DLet%2527s%2520not%2520forget%2520that%2520CHM%2520files%2520can%2520be%2520dangerous.%2520They%2520can%2520contain%2520embedded%2520executables%2520that%2520get%2520launched%2520automatically%2520when%2520you%2520open%2520them.%2520This%2520post%2520on%2520SANS%2520ISC%2520details%2520a%2520particular%2520malicious%2520CHM%2520file%2520that%2520was%2520sent%2520out%2520via%2520email.%2520After%2520some%2520investig';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F03%252F27%252Fmalicious-chm-file-targets-pgp%252F%26amp%3Btitle%3DMalicious%2520CHM%2520file%2520targets%2520PGP%26amp%3Bnotes%3DLet%2527s%2520not%2520forget%2520that%2520CHM%2520files%2520can%2520be%2520dangerous.%2520They%2520can%2520contain%2520embedded%2520executables%2520that%2520get%2520launched%2520automatically%2520when%2520you%2520open%2520them.%2520This%2520post%2520on%2520SANS%2520ISC%2520details%2520a%2520particular%2520malicious%2520CHM%2520file%2520that%2520was%2520sent%2520out%2520via%2520email.%2520After%2520some%2520investig';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F03%252F27%252Fmalicious-chm-file-targets-pgp%252F%26amp%3Btitle%3DMalicious%2520CHM%2520file%2520targets%2520PGP';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2008/03/27/malicious-chm-file-targets-pgp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>G-Archiver is evil</title>
		<link>http://eugk.net/wordpress/2008/03/12/g-archiver-is-evil/</link>
		<comments>http://eugk.net/wordpress/2008/03/12/g-archiver-is-evil/#comments</comments>
		<pubDate>Wed, 12 Mar 2008 23:12:36 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[google]]></category>
		<category><![CDATA[reversing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/2008/03/12/g-archiver-is-evil/</guid>
		<description><![CDATA[This is a great lesson in why not to blindly trust random software that you find on the Internet. G-Archiver, a program created to help users locally save their Gmail messages, has a piece of code in it that sends your Gmail login and password to the author. You can see a scary screen shot [...]]]></description>
			<content:encoded><![CDATA[<p>This is a great lesson in why not to blindly trust random software that you find on the Internet. G-Archiver, a program created to help users locally save their Gmail messages, has a piece of code in it that sends your Gmail login and password to the author. You can see a scary screen shot of his inbox, since the guy had his own Gmail credentials hard coded right into the program, which was obviously discovered.</p>
<p>The details are at <a href="http://isc.sans.org/diary.html?storyid=4129&amp;rss">SANS ISC (source code)</a> and <a href="http://www.codinghorror.com/blog/archives/001072.html">Coding Horror (screen shot)</a>.</p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DG-Archiver%2520is%2520evil%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F03%252F12%252Fg-archiver-is-evil%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F03%252F12%252Fg-archiver-is-evil%252F%26amp%3Btitle%3DG-Archiver%2520is%2520evil%26amp%3Bbodytext%3DThis%2520is%2520a%2520great%2520lesson%2520in%2520why%2520not%2520to%2520blindly%2520trust%2520random%2520software%2520that%2520you%2520find%2520on%2520the%2520Internet.%2520G-Archiver%252C%2520a%2520program%2520created%2520to%2520help%2520users%2520locally%2520save%2520their%2520Gmail%2520messages%252C%2520has%2520a%2520piece%2520of%2520code%2520in%2520it%2520that%2520sends%2520your%2520Gmail%2520login%2520and%2520password%2520to%2520the';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F03%252F12%252Fg-archiver-is-evil%252F%26amp%3Bt%3DG-Archiver%2520is%2520evil';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F03%252F12%252Fg-archiver-is-evil%252F%26amp%3Btitle%3DG-Archiver%2520is%2520evil%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DThis%2520is%2520a%2520great%2520lesson%2520in%2520why%2520not%2520to%2520blindly%2520trust%2520random%2520software%2520that%2520you%2520find%2520on%2520the%2520Internet.%2520G-Archiver%252C%2520a%2520program%2520created%2520to%2520help%2520users%2520locally%2520save%2520their%2520Gmail%2520messages%252C%2520has%2520a%2520piece%2520of%2520code%2520in%2520it%2520that%2520sends%2520your%2520Gmail%2520login%2520and%2520password%2520to%2520the';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F03%252F12%252Fg-archiver-is-evil%252F%26amp%3Btitle%3DG-Archiver%2520is%2520evil%26amp%3Bnotes%3DThis%2520is%2520a%2520great%2520lesson%2520in%2520why%2520not%2520to%2520blindly%2520trust%2520random%2520software%2520that%2520you%2520find%2520on%2520the%2520Internet.%2520G-Archiver%252C%2520a%2520program%2520created%2520to%2520help%2520users%2520locally%2520save%2520their%2520Gmail%2520messages%252C%2520has%2520a%2520piece%2520of%2520code%2520in%2520it%2520that%2520sends%2520your%2520Gmail%2520login%2520and%2520password%2520to%2520the';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F03%252F12%252Fg-archiver-is-evil%252F%26amp%3Btitle%3DG-Archiver%2520is%2520evil';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2008/03/12/g-archiver-is-evil/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>JavaScript Packers</title>
		<link>http://eugk.net/wordpress/2008/01/28/javascript-packers/</link>
		<comments>http://eugk.net/wordpress/2008/01/28/javascript-packers/#comments</comments>
		<pubDate>Tue, 29 Jan 2008 01:08:54 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[development]]></category>
		<category><![CDATA[reversing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://eugk.net/wordpress/2008/01/28/javascript-packers/</guid>
		<description><![CDATA[This article by SecureWorks, titled "The Packer 2.0 Threat", is a good introduction to and overview of some of the most popular JavaScript packers. It discusses both the legitimate (although possibly misguided) uses of packers, as well as their role in obfuscating malware. The packers mentioned in the article include: Dojo ShrinkSafe, MOOtools, YUI Compressor, [...]]]></description>
			<content:encoded><![CDATA[<p>This article by SecureWorks, titled <a href="http://www.secureworks.com/research/threats/thepacker/?threat=thepacker" target="_blank">"The Packer 2.0 Threat"</a>, is a good introduction to and overview of some of the most popular JavaScript packers. It discusses both the legitimate (although possibly misguided) uses of <a href="http://en.wikipedia.org/wiki/Executable_compression" target="_blank">packers</a>, as well as their role in obfuscating malware. The packers mentioned in the article include: Dojo ShrinkSafe, MOOtools, YUI Compressor, JSMin, and the Dean Edwards Packer.</p>
<p>Basically, the author argues that packing JavaScript leads to several unintended consequences that are bad for security. The most obvious problem is that it becomes much more difficult for network traffic inspection tools, including IDS, to tell the difference between friendly and malicious code. Other techniques, such as gzip compression, are probably good enough to improve bandwidth efficiency.</p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DJavaScript%2520Packers%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F01%252F28%252Fjavascript-packers%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F01%252F28%252Fjavascript-packers%252F%26amp%3Btitle%3DJavaScript%2520Packers%26amp%3Bbodytext%3DThis%2520article%2520by%2520SecureWorks%252C%2520titled%2520%2522The%2520Packer%25202.0%2520Threat%2522%252C%2520is%2520a%2520good%2520introduction%2520to%2520and%2520overview%2520of%2520some%2520of%2520the%2520most%2520popular%2520JavaScript%2520packers.%2520It%2520discusses%2520both%2520the%2520legitimate%2520%2528although%2520possibly%2520misguided%2529%2520uses%2520of%2520packers%252C%2520as%2520well%2520as%2520their%2520role%2520';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F01%252F28%252Fjavascript-packers%252F%26amp%3Bt%3DJavaScript%2520Packers';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F01%252F28%252Fjavascript-packers%252F%26amp%3Btitle%3DJavaScript%2520Packers%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DThis%2520article%2520by%2520SecureWorks%252C%2520titled%2520%2522The%2520Packer%25202.0%2520Threat%2522%252C%2520is%2520a%2520good%2520introduction%2520to%2520and%2520overview%2520of%2520some%2520of%2520the%2520most%2520popular%2520JavaScript%2520packers.%2520It%2520discusses%2520both%2520the%2520legitimate%2520%2528although%2520possibly%2520misguided%2529%2520uses%2520of%2520packers%252C%2520as%2520well%2520as%2520their%2520role%2520';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F01%252F28%252Fjavascript-packers%252F%26amp%3Btitle%3DJavaScript%2520Packers%26amp%3Bnotes%3DThis%2520article%2520by%2520SecureWorks%252C%2520titled%2520%2522The%2520Packer%25202.0%2520Threat%2522%252C%2520is%2520a%2520good%2520introduction%2520to%2520and%2520overview%2520of%2520some%2520of%2520the%2520most%2520popular%2520JavaScript%2520packers.%2520It%2520discusses%2520both%2520the%2520legitimate%2520%2528although%2520possibly%2520misguided%2529%2520uses%2520of%2520packers%252C%2520as%2520well%2520as%2520their%2520role%2520';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F01%252F28%252Fjavascript-packers%252F%26amp%3Btitle%3DJavaScript%2520Packers';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2008/01/28/javascript-packers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Software Reverse Engineering Tool Library</title>
		<link>http://eugk.net/wordpress/2008/01/02/collaborative-rce-tool-library/</link>
		<comments>http://eugk.net/wordpress/2008/01/02/collaborative-rce-tool-library/#comments</comments>
		<pubDate>Thu, 03 Jan 2008 00:40:51 +0000</pubDate>
		<dc:creator>eugenekogan</dc:creator>
				<category><![CDATA[forensics]]></category>
		<category><![CDATA[reversing]]></category>

		<guid isPermaLink="false">http://eugenekogan.net/wordpress/2008/01/02/collaborative-rce-tool-library/</guid>
		<description><![CDATA[This is pretty cool. It's the new Collaborative RCE Tool Library, a nearly comprehensive directory of reverse engineering tools. Not only does it list the tools and provide links to download them, the directory also has pretty good descriptions and resources to learn more about each topic. The tools are conveniently sorted by target type [...]]]></description>
			<content:encoded><![CDATA[<p>This is pretty cool. It's the new <a href="http://www.woodmann.com/collaborative/tools/index.php/Category:RCE_Tools" target="_blank">Collaborative RCE Tool Library</a>, a nearly comprehensive directory of reverse engineering tools. Not only does it list the tools and provide links to download them, the directory also has pretty good descriptions and resources to learn more about each topic. The tools are conveniently sorted by target type (e.g., Java, Flash, Linux) as well as tool type (e.g., debuggers, PE editors, unpackers) and the whole thing is searchable, which makes it pretty easy to find what you need. (Although, right now the search seems to be broken.)<br />
<a href="http://www.woodmann.com/collaborative/tools/index.php/Category:RCE_Tools"> <img src="http://eugenekogan.net/wordpress/wp-content/images/rcetools.png" align="right" hspace="10" vspace="10" /></a><br />
Perhaps the best feature of the RCE Tool Library is that it's collaborative, meaning users can improve upon entires, add new ones as new tools are created, and generally keep everything up to date. That will definitely help keep the directory from becoming stale.</p>

<div class="sociable">

<ul>
	<li class="sociablefirst"><a rel="nofollow" id="email" target="_blank" href="javascript:window.location='mailto%3A%3Fsubject%3DSoftware%2520Reverse%2520Engineering%2520Tool%2520Library%26amp%3Bbody%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F01%252F02%252Fcollaborative-rce-tool-library%252F';" title="E-mail this story to a friend!"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/email_link.png" title="E-mail this story to a friend!" alt="E-mail this story to a friend!" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="digg" target="_blank" href="javascript:window.location='http%3A%2F%2Fdigg.com%2Fsubmit%3Fphase%3D2%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F01%252F02%252Fcollaborative-rce-tool-library%252F%26amp%3Btitle%3DSoftware%2520Reverse%2520Engineering%2520Tool%2520Library%26amp%3Bbodytext%3DThis%2520is%2520pretty%2520cool.%2520It%2527s%2520the%2520new%2520Collaborative%2520RCE%2520Tool%2520Library%252C%2520a%2520nearly%2520comprehensive%2520directory%2520of%2520reverse%2520engineering%2520tools.%2520Not%2520only%2520does%2520it%2520list%2520the%2520tools%2520and%2520provide%2520links%2520to%2520download%2520them%252C%2520the%2520directory%2520also%2520has%2520pretty%2520good%2520descriptions%2520and%2520r';" title="Digg"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="facebook" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.facebook.com%2Fshare.php%3Fu%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F01%252F02%252Fcollaborative-rce-tool-library%252F%26amp%3Bt%3DSoftware%2520Reverse%2520Engineering%2520Tool%2520Library';" title="Facebook"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="linkedin" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.linkedin.com%2FshareArticle%3Fmini%3Dtrue%26amp%3Burl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F01%252F02%252Fcollaborative-rce-tool-library%252F%26amp%3Btitle%3DSoftware%2520Reverse%2520Engineering%2520Tool%2520Library%26amp%3Bsource%3DPhilosophically%2BSecure%2BEugene%2BKogan%2526%2523039%253Bs%2Bblog%2Bon%2Binformation%2Bsecurity%2Band%2Bsoftware%2Bengineering%26amp%3Bsummary%3DThis%2520is%2520pretty%2520cool.%2520It%2527s%2520the%2520new%2520Collaborative%2520RCE%2520Tool%2520Library%252C%2520a%2520nearly%2520comprehensive%2520directory%2520of%2520reverse%2520engineering%2520tools.%2520Not%2520only%2520does%2520it%2520list%2520the%2520tools%2520and%2520provide%2520links%2520to%2520download%2520them%252C%2520the%2520directory%2520also%2520has%2520pretty%2520good%2520descriptions%2520and%2520r';" title="LinkedIn"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow" id="del.icio.us" target="_blank" href="javascript:window.location='http%3A%2F%2Fdelicious.com%2Fpost%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F01%252F02%252Fcollaborative-rce-tool-library%252F%26amp%3Btitle%3DSoftware%2520Reverse%2520Engineering%2520Tool%2520Library%26amp%3Bnotes%3DThis%2520is%2520pretty%2520cool.%2520It%2527s%2520the%2520new%2520Collaborative%2520RCE%2520Tool%2520Library%252C%2520a%2520nearly%2520comprehensive%2520directory%2520of%2520reverse%2520engineering%2520tools.%2520Not%2520only%2520does%2520it%2520list%2520the%2520tools%2520and%2520provide%2520links%2520to%2520download%2520them%252C%2520the%2520directory%2520also%2520has%2520pretty%2520good%2520descriptions%2520and%2520r';" title="del.icio.us"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow" id="stumbleupon" target="_blank" href="javascript:window.location='http%3A%2F%2Fwww.stumbleupon.com%2Fsubmit%3Furl%3Dhttp%253A%252F%252Feugk.net%252Fwordpress%252F2008%252F01%252F02%252Fcollaborative-rce-tool-library%252F%26amp%3Btitle%3DSoftware%2520Reverse%2520Engineering%2520Tool%2520Library';" title="StumbleUpon"><img src="http://eugk.net/wordpress/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://eugk.net/wordpress/2008/01/02/collaborative-rce-tool-library/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
