<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>PC Sympathy</title>
	<atom:link href="http://www.pcsympathy.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pcsympathy.com</link>
	<description>Your Source for PC News and Technical Support</description>
	<pubDate>Fri, 09 May 2008 20:47:57 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
			<item>
		<title>Phishing Campaign Targets Tax Rebate Checks</title>
		<link>http://www.pcsympathy.com/2008/05/09/phishing-campaign-targets-tax-rebate-checks/</link>
		<comments>http://www.pcsympathy.com/2008/05/09/phishing-campaign-targets-tax-rebate-checks/#comments</comments>
		<pubDate>Fri, 09 May 2008 20:47:57 +0000</pubDate>
		<dc:creator>manunkind</dc:creator>
		
		<category><![CDATA[General BS]]></category>

		<category><![CDATA[Privacy]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[credit]]></category>

		<category><![CDATA[identity theft]]></category>

		<category><![CDATA[password]]></category>

		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.pcsympathy.com/?p=729</guid>
		<description><![CDATA[The Internet Crime Complaint Center (IC3) on Thursday issued a warning about a phishing campaign designed to steal personal information from consumers using the promise of a tax rebate check as bait.IC3 is jointly run by the Federal Bureau of Investigation, the National White Collar Crime Center, and the Bureau of Justice Assistance.
The phishing messages [...]]]></description>
			<content:encoded><![CDATA[<p>The Internet Crime Complaint Center (IC3) on Thursday <a href="http://www.ic3.gov/media/2008/080508.htm" target="_blank">issued a warning</a> about a phishing campaign designed to steal personal information from consumers using the promise of a tax rebate check as bait.IC3 is jointly run by the Federal Bureau of Investigation, the National White Collar Crime Center, and the Bureau of Justice Assistance.</p>
<p>The phishing messages claim that the fasted way to receive one&#8217;s economic stimulus tax rebate is through direct deposit. They include a Web link to an online submission form designed to steal submitted information from those fooled into believing that providing personal data will hasten the arrival of their tax rebate.</p>
<p>The IC3 includes a sample phishing message that purports to be from the Internal Revenue Service. It warns recipients that failure to submit information by May 10th may delay the promised funds.</p>
<p>In fact, the IRS is <a href="http://www.irs.gov/irs/article/0,,id=177937,00.html" target="_blank">sending economic stimulus payments</a> out to about 130 million U.S. households this month, ranging from $300 to $1, 200. But it&#8217;s not sending anyone e-mail offering to hasten delivery through direct deposit of the funds.</p>
<p>&#8220;Consumers are advised that the IRS does not initiate taxpayer communications via e-mail,&#8221; IC3 warns. &#8220;In addition, the IRS does not request detailed personal information via e-mail or ask taxpayers for the PIN numbers, passwords, or similar secret access information for their credit card, bank, or other financial accounts.&#8221;</p>
<p>Furthermore, IC3 advises against opening e-mail from unknown senders or clicking on links in such messages.</p>
<p>According to the <a href="http://www.antiphishing.org/" target="_blank">Anti-Phishing Working Group</a>, 29,284 unique phishing reports were submitted to the organization in January, an increase of more than 3,600 from the previous month.</p>
<p><a href="http://www.informationweek.com/news/security/government/showArticle.jhtml?articleID=207601673&amp;cid=RSSfeed_IWK_All" target="_blank">Read the rest of the story&#8230;</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F09%2Fphishing-campaign-targets-tax-rebate-checks%2F&amp;title=Phishing+Campaign+Targets+Tax+Rebate+Checks" title="Slashdot It!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/slash.ico" height="16" width="16"  border="0" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F09%2Fphishing-campaign-targets-tax-rebate-checks%2F&amp;title=Phishing+Campaign+Targets+Tax+Rebate+Checks" title="Digg This Story"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/digg.ico" width="16" height="16"  border="0" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F09%2Fphishing-campaign-targets-tax-rebate-checks%2F&amp;title=Phishing+Campaign+Targets+Tax+Rebate+Checks" title="Reddit"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/reddit.ico" width="16" height="16"  border="0" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F09%2Fphishing-campaign-targets-tax-rebate-checks%2F&amp;title=Phishing+Campaign+Targets+Tax+Rebate+Checks" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F09%2Fphishing-campaign-targets-tax-rebate-checks%2F&amp;title=Phishing+Campaign+Targets+Tax+Rebate+Checks', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/deli.ico" width="16" height="16"  border="0" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F09%2Fphishing-campaign-targets-tax-rebate-checks%2F" title="Share on Facebook"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/facebook.ico" width="16" height="16"  border="0" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F09%2Fphishing-campaign-targets-tax-rebate-checks%2F" title="Add to my Technorati Favorites"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/tech.ico" width="16" height="16"  border="0" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F09%2Fphishing-campaign-targets-tax-rebate-checks%2F&amp;title=Phishing+Campaign+Targets+Tax+Rebate+Checks" title="Save to Google Bookmarks"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/google.ico" width="16" height="16"  border="0" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F09%2Fphishing-campaign-targets-tax-rebate-checks%2F&amp;title=Phishing+Campaign+Targets+Tax+Rebate+Checks" title="Stumble it!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/stumble.ico" width="16" height="16"  border="0" alt="[StumbleUpon]" /></a>
</span>
	<h3>Related posts:</h3>
	<ul class="st-related-posts">
	<li><a href="http://www.pcsympathy.com/2008/03/08/threat-alert-spear-phishing/" title="Threat Alert: Spear Phishing (March 8, 2008)">Threat Alert: Spear Phishing</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/17/paypal-plans-to-ban-unsafe-browsers/" title="PayPal Plans to Ban Unsafe Browsers (April 17, 2008)">PayPal Plans to Ban Unsafe Browsers</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/17/how-anonymous-are-you/" title="How Anonymous Are You? (April 17, 2008)">How Anonymous Are You?</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/28/long-term-phishing-attack-underway/" title="&#8216;Long-Term&#8217; Phishing Attack Underway (April 28, 2008)">&#8216;Long-Term&#8217; Phishing Attack Underway</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/26/yubikey/" title="YubiKey - One-time Password and Authentication Device (April 26, 2008)">YubiKey - One-time Password and Authentication Device</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.pcsympathy.com/2008/05/09/phishing-campaign-targets-tax-rebate-checks/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Windows Vista More Vulnerable To Malware Than Windows 2000</title>
		<link>http://www.pcsympathy.com/2008/05/08/windows-vista-more-vulnerable-to-malware-than-windows-2000/</link>
		<comments>http://www.pcsympathy.com/2008/05/08/windows-vista-more-vulnerable-to-malware-than-windows-2000/#comments</comments>
		<pubDate>Thu, 08 May 2008 23:59:31 +0000</pubDate>
		<dc:creator>manunkind</dc:creator>
		
		<category><![CDATA[Internet]]></category>

		<category><![CDATA[Privacy]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Windows]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[microsoft]]></category>

		<category><![CDATA[virus]]></category>

		<category><![CDATA[vista]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[windows 2000]]></category>

		<category><![CDATA[windows xp]]></category>

		<guid isPermaLink="false">http://www.pcsympathy.com/?p=728</guid>
		<description><![CDATA[Microsoft&#8217;s Vista operating system is more susceptible to malware than Windows 2000, and though it&#8217;s 37% more secure than Windows XP, it&#8217;s still too vulnerable.That&#8217;s the contention of security vendor PC Tools, which has a financial interest in the vulnerability of Microsoft&#8217;s software.
&#8220;Ironically, the new operating system has been hailed by Microsoft as the most [...]]]></description>
			<content:encoded><![CDATA[<p><span id="articleBody">Microsoft&#8217;s <a href="http://www.microsoft.com/windows/products/windowsvista/default.aspx" target="_blank">Vista</a> operating system is more susceptible to malware than Windows 2000, and though it&#8217;s 37% more secure than Windows XP, it&#8217;s still too vulnerable.That&#8217;s the contention of security vendor PC Tools, which has a financial interest in the vulnerability of Microsoft&#8217;s software.</p>
<p><span id="articleBody">&#8220;Ironically, the new operating system has been hailed by Microsoft as the most secure version of Windows to date,&#8221; said Simon Clausen, CEO of <a href="http://www.pctools.com/" target="_blank">PC Tools Software</a> in a statement. &#8220;However, recent research conducted with statistics from over 1.4 million computers within the ThreatFire community has shown that Windows Vista is more susceptible to malware than the eight year old Windows 2000 operating system, and only 37% more secure than Windows XP.&#8221;According to statistics gathered from users of PC Tools&#8217; <a href="http://www.threatfire.com/" target="_blank">ThreatFire</a> security service, Vista let 639 threats per thousand computers through, compared to 586 for Windows 2000, 478 for Windows 2003, and 1,021 for Windows XP.</p>
<p>ThreatFire is an anti-malware system that tries to block malicious software based on its behavior rather than by signature matching.</p>
<p>Given an infection rate of 639 per 1,000 PCs, almost 64% of Vista users should have compromised machines.</p>
<p>Michael Greene, VP of product strategy for PC Tools Software, said that the malware identified had &#8220;gotten to the desktop and to the point of doing something bad.&#8221; He said that he didn&#8217;t have the ThreatFire data immediately accessible but said that presumably some of the monitored machines also had third-party anti-virus software that missed the malware.</p>
<p>That tendency, the inability of signature-based anti-virus systems to keep up with auto-generated malware variants, is the reason PC Tools developed ThreatFire, Greene explained.</p>
<p><a href="http://www.informationweek.com/news/windows/operatingsystems/showArticle.jhtml?articleID=207601217&amp;cid=RSSfeed_IWK_All" target="_blank">Read the rest of the story&#8230;</a></p>
<p></span></p>
<p></span></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Fwindows-vista-more-vulnerable-to-malware-than-windows-2000%2F&amp;title=Windows+Vista+More+Vulnerable+To+Malware+Than+Windows+2000" title="Slashdot It!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/slash.ico" height="16" width="16"  border="0" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Fwindows-vista-more-vulnerable-to-malware-than-windows-2000%2F&amp;title=Windows+Vista+More+Vulnerable+To+Malware+Than+Windows+2000" title="Digg This Story"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/digg.ico" width="16" height="16"  border="0" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Fwindows-vista-more-vulnerable-to-malware-than-windows-2000%2F&amp;title=Windows+Vista+More+Vulnerable+To+Malware+Than+Windows+2000" title="Reddit"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/reddit.ico" width="16" height="16"  border="0" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Fwindows-vista-more-vulnerable-to-malware-than-windows-2000%2F&amp;title=Windows+Vista+More+Vulnerable+To+Malware+Than+Windows+2000" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Fwindows-vista-more-vulnerable-to-malware-than-windows-2000%2F&amp;title=Windows+Vista+More+Vulnerable+To+Malware+Than+Windows+2000', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/deli.ico" width="16" height="16"  border="0" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Fwindows-vista-more-vulnerable-to-malware-than-windows-2000%2F" title="Share on Facebook"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/facebook.ico" width="16" height="16"  border="0" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Fwindows-vista-more-vulnerable-to-malware-than-windows-2000%2F" title="Add to my Technorati Favorites"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/tech.ico" width="16" height="16"  border="0" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Fwindows-vista-more-vulnerable-to-malware-than-windows-2000%2F&amp;title=Windows+Vista+More+Vulnerable+To+Malware+Than+Windows+2000" title="Save to Google Bookmarks"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/google.ico" width="16" height="16"  border="0" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Fwindows-vista-more-vulnerable-to-malware-than-windows-2000%2F&amp;title=Windows+Vista+More+Vulnerable+To+Malware+Than+Windows+2000" title="Stumble it!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/stumble.ico" width="16" height="16"  border="0" alt="[StumbleUpon]" /></a>
</span>
	<h3>Related posts:</h3>
	<ul class="st-related-posts">
	<li><a href="http://www.pcsympathy.com/2008/04/03/microsoft-plans-five-critical-security-updates-for-windows-explorer/" title="Microsoft Plans Five &#8216;Critical&#8217; Security Updates For Windows, Explorer (April 3, 2008)">Microsoft Plans Five &#8216;Critical&#8217; Security Updates For Windows, Explorer</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/16/hacker-releases-working-gdi-bug-attack-code/" title="Hacker releases working GDI-bug attack code (April 16, 2008)">Hacker releases working GDI-bug attack code</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/17/windows-vista-one-year-vulnerability-report/" title="Windows Vista One Year Vulnerability Report (April 17, 2008)">Windows Vista One Year Vulnerability Report</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/18/vulnerability-in-windows-could-allow-elevation-of-privilege/" title="Vulnerability in Windows Could Allow Elevation of Privilege (April 18, 2008)">Vulnerability in Windows Could Allow Elevation of Privilege</a></li>
	<li><a href="http://www.pcsympathy.com/2008/03/08/nt2kxp-a-brief-history/" title="NT/2K/XP - A Brief History (March 8, 2008)">NT/2K/XP - A Brief History</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.pcsympathy.com/2008/05/08/windows-vista-more-vulnerable-to-malware-than-windows-2000/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Top Six Database Attacks</title>
		<link>http://www.pcsympathy.com/2008/05/08/top-six-database-attacks/</link>
		<comments>http://www.pcsympathy.com/2008/05/08/top-six-database-attacks/#comments</comments>
		<pubDate>Thu, 08 May 2008 23:31:50 +0000</pubDate>
		<dc:creator>manunkind</dc:creator>
		
		<category><![CDATA[Internet]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[attack]]></category>

		<category><![CDATA[attacker]]></category>

		<category><![CDATA[backup]]></category>

		<category><![CDATA[buffer overflow]]></category>

		<category><![CDATA[Data]]></category>

		<category><![CDATA[database]]></category>

		<category><![CDATA[hacker]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[intruder]]></category>

		<category><![CDATA[password]]></category>

		<category><![CDATA[Perl]]></category>

		<category><![CDATA[SQL]]></category>

		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://www.pcsympathy.com/?p=727</guid>
		<description><![CDATA[It takes the average attacker less than 10 seconds to hack in and out of a database &#8212; hardly enough time for the database administrator even notice the intruder. So it’s no surprise that many database attacks go unnoticed by organizations until long after the data has been compromised.
And surprisingly, according to many experts, the [...]]]></description>
			<content:encoded><![CDATA[<p>It takes the average attacker less than 10 seconds to hack in and out of a database &#8212; hardly enough time for the database administrator even notice the intruder. So it’s no surprise that many database attacks go unnoticed by organizations until long after the data has been compromised.</p>
<p>And surprisingly, according to many experts, the database &#8212; home of the enterprise’s crown jewels &#8212; is still not secured properly in many enterprises. Malicious hackers are using shockingly simple attack methods to break into databases, such as exploiting weak passwords and lax configuration, and capitalizing on known vulnerabilities that go unpatched.</p>
<p>And don’t even get us started on the epidemic of missing backup tapes: If the lost or stolen tapes are unencrypted, you’re toast if a bad guy gets hold of them. No hack required.</p>
<p>“One of the biggest problems is that many database attacks are not even known” about, says Noel Yuhanna, principal analyst with The Forrester Group. “The typical database may have 15,000 to 20,000 connections per second. It’s not humanly possible to know what all of these [connections] are doing.”</p>
<p>Hackers are well aware of enterprises&#8217; database patch dilemma &#8212; in fact, they’re banking on a backlog. Gone are the days when companies could lock down a handful of databases in the data center: Most organizations today have hundreds, even thousands of databases to configure, secure, and monitor &#8212; and remote users, customers, and business partners all need access to them.</p>
<p>“The big thing that bothers me is when I go to a customer’s site, usually their [database] configuration is so weak that it’s easy to exploit. You usually don’t need buffer overflow or SQL injection [attacks] because the initial setup of the database is totally insecure,” says Slavik Markovich, CTO of Sentrigo, a database security vendor.</p>
<p>Database attacks don’t have to be complicated with all of this low-lying fruit hanging around. “Those are basic configuration problems, so a hacker doesn’t have to do something really sophisticated because these easy things work,” Markovich says.</p>
<p><a href="http://www.darkreading.com/document.asp?doc_id=153291" target="_blank">Read the rest of the story&#8230;</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Ftop-six-database-attacks%2F&amp;title=Top+Six+Database+Attacks" title="Slashdot It!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/slash.ico" height="16" width="16"  border="0" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Ftop-six-database-attacks%2F&amp;title=Top+Six+Database+Attacks" title="Digg This Story"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/digg.ico" width="16" height="16"  border="0" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Ftop-six-database-attacks%2F&amp;title=Top+Six+Database+Attacks" title="Reddit"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/reddit.ico" width="16" height="16"  border="0" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Ftop-six-database-attacks%2F&amp;title=Top+Six+Database+Attacks" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Ftop-six-database-attacks%2F&amp;title=Top+Six+Database+Attacks', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/deli.ico" width="16" height="16"  border="0" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Ftop-six-database-attacks%2F" title="Share on Facebook"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/facebook.ico" width="16" height="16"  border="0" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Ftop-six-database-attacks%2F" title="Add to my Technorati Favorites"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/tech.ico" width="16" height="16"  border="0" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Ftop-six-database-attacks%2F&amp;title=Top+Six+Database+Attacks" title="Save to Google Bookmarks"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/google.ico" width="16" height="16"  border="0" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F08%2Ftop-six-database-attacks%2F&amp;title=Top+Six+Database+Attacks" title="Stumble it!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/stumble.ico" width="16" height="16"  border="0" alt="[StumbleUpon]" /></a>
</span>
	<h3>Related posts:</h3>
	<ul class="st-related-posts">
	<li><a href="http://www.pcsympathy.com/2008/04/21/the-snare-of-unauthorized-requests/" title="The Snare Of Unauthorized Requests (April 21, 2008)">The Snare Of Unauthorized Requests</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/28/microsoft-offers-assistance-to-combat-mass-sql-injection/" title="Microsoft offers assistance to combat mass SQL injection (April 28, 2008)">Microsoft offers assistance to combat mass SQL injection</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/24/mass-sql-injection/" title="Mass SQL injection (April 24, 2008)">Mass SQL injection</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/15/sqlninja-022-released-sql-injection-tool/" title="sqlninja 0.2.2 Released - SQL Injection Tool (April 15, 2008)">sqlninja 0.2.2 Released - SQL Injection Tool</a></li>
	<li><a href="http://www.pcsympathy.com/2008/03/28/sql-query-injection-for-dummies/" title="SQL query injection for dummies (March 28, 2008)">SQL query injection for dummies</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.pcsympathy.com/2008/05/08/top-six-database-attacks/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Ultimate Boot CD for Windows (UBCD4Win)</title>
		<link>http://www.pcsympathy.com/2008/05/07/ultimate-boot-cd-for-windows-ubcd4win/</link>
		<comments>http://www.pcsympathy.com/2008/05/07/ultimate-boot-cd-for-windows-ubcd4win/#comments</comments>
		<pubDate>Thu, 08 May 2008 01:22:48 +0000</pubDate>
		<dc:creator>manunkind</dc:creator>
		
		<category><![CDATA[Windows]]></category>

		<category><![CDATA[recovery]]></category>

		<category><![CDATA[UBCD]]></category>

		<category><![CDATA[UBCD4Win]]></category>

		<category><![CDATA[ultimate boot cd]]></category>

		<guid isPermaLink="false">http://www.pcsympathy.com/?p=725</guid>
		<description><![CDATA[UBCD4Win is a bootable recovery CD that contains software used for repairing, restoring, or diagnosing almost any computer problem. Our goal is to be the most complete and easy to use free computer diagnostic tool. Almost all software included in UBCD4Win are freeware utilities for Windows.

Please visit the &#8220;List of Tools&#8221; page for a complete [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.ubcd4win.com/index.htm" target="_blank">UBCD4Win</a> is a bootable recovery CD that contains software used for repairing, restoring, or diagnosing almost any computer problem. Our goal is to be the most complete and easy to use free computer diagnostic tool. Almost all software included in UBCD4Win are freeware utilities for Windows.</p>
<p><img class="alignnone size-full wp-image-726" title="av" src="http://www.pcsympathy.com/wp-content/uploads/2008/05/av.jpg" alt="" width="500" height="375" /></p>
<p>Please visit the &#8220;<a href="http://www.ubcd4win.com/contents.htm" target="_blank">List of Tools</a>&#8221; page for a complete list of what is included in the latest version of UBCD4Win.</p>
<p><a href="http://www.ubcd4win.com/downloads.htm" target="_blank">Download here</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fultimate-boot-cd-for-windows-ubcd4win%2F&amp;title=Ultimate+Boot+CD+for+Windows+%28UBCD4Win%29" title="Slashdot It!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/slash.ico" height="16" width="16"  border="0" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fultimate-boot-cd-for-windows-ubcd4win%2F&amp;title=Ultimate+Boot+CD+for+Windows+%28UBCD4Win%29" title="Digg This Story"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/digg.ico" width="16" height="16"  border="0" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fultimate-boot-cd-for-windows-ubcd4win%2F&amp;title=Ultimate+Boot+CD+for+Windows+%28UBCD4Win%29" title="Reddit"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/reddit.ico" width="16" height="16"  border="0" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fultimate-boot-cd-for-windows-ubcd4win%2F&amp;title=Ultimate+Boot+CD+for+Windows+%28UBCD4Win%29" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fultimate-boot-cd-for-windows-ubcd4win%2F&amp;title=Ultimate+Boot+CD+for+Windows+%28UBCD4Win%29', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/deli.ico" width="16" height="16"  border="0" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fultimate-boot-cd-for-windows-ubcd4win%2F" title="Share on Facebook"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/facebook.ico" width="16" height="16"  border="0" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fultimate-boot-cd-for-windows-ubcd4win%2F" title="Add to my Technorati Favorites"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/tech.ico" width="16" height="16"  border="0" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fultimate-boot-cd-for-windows-ubcd4win%2F&amp;title=Ultimate+Boot+CD+for+Windows+%28UBCD4Win%29" title="Save to Google Bookmarks"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/google.ico" width="16" height="16"  border="0" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fultimate-boot-cd-for-windows-ubcd4win%2F&amp;title=Ultimate+Boot+CD+for+Windows+%28UBCD4Win%29" title="Stumble it!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/stumble.ico" width="16" height="16"  border="0" alt="[StumbleUpon]" /></a>
</span>
	<h3>Related posts:</h3>
	<ul class="st-related-posts">
	<li><a href="http://www.pcsympathy.com/2008/05/06/who-killed-my-hard-drive/" title="Who Killed My Hard Drive? (May 6, 2008)">Who Killed My Hard Drive?</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/11/choose-a-home-pc-backup-method/" title="How to Choose a Home PC Backup Method (April 11, 2008)">How to Choose a Home PC Backup Method</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/15/dealing-with-hard-drive-problems/" title="Dealing With Hard Drive Problems (April 15, 2008)">Dealing With Hard Drive Problems</a></li>
	<li><a href="http://www.pcsympathy.com/2008/03/08/beginners-guides-back-up-and-restore-data-in-winxp/" title="Beginners Guides: Back up and Restore Data in WinXP (March 8, 2008)">Beginners Guides: Back up and Restore Data in WinXP</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.pcsympathy.com/2008/05/07/ultimate-boot-cd-for-windows-ubcd4win/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox Plugin Shipped With Malicious Code</title>
		<link>http://www.pcsympathy.com/2008/05/07/firefox-plugin-shipped-with-malicious-code/</link>
		<comments>http://www.pcsympathy.com/2008/05/07/firefox-plugin-shipped-with-malicious-code/#comments</comments>
		<pubDate>Thu, 08 May 2008 01:11:20 +0000</pubDate>
		<dc:creator>manunkind</dc:creator>
		
		<category><![CDATA[Internet]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[adware]]></category>

		<category><![CDATA[banner]]></category>

		<category><![CDATA[firefox]]></category>

		<category><![CDATA[infection]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[mozilla]]></category>

		<category><![CDATA[Open-source]]></category>

		<category><![CDATA[plugin]]></category>

		<category><![CDATA[Trojan]]></category>

		<category><![CDATA[virus]]></category>

		<category><![CDATA[Xorer]]></category>

		<guid isPermaLink="false">http://www.pcsympathy.com/?p=724</guid>
		<description><![CDATA[Mozilla warned Wednesday that a malicious program inserted adware code into a Firefox plugin that has been downloaded thousands of times over the past three months.
Because of a virus infection, the Vietnamese language pack for Firefox 2 was polluted with adware, Mozilla security chief Window Snyder said in a blog posting. &#8220;Everyone who downloaded the [...]]]></description>
			<content:encoded><![CDATA[<p>Mozilla warned Wednesday that a malicious program inserted adware code into a Firefox plugin that has been downloaded thousands of times over the past three months.</p>
<p>Because of a virus infection, the Vietnamese language pack for Firefox 2 was polluted with adware, Mozilla security chief Window Snyder said in a <a href="http://blog.mozilla.com/security/2008/05/07/compromised-file-in-vietnamese-language-pack-for-firefox-2/" target="_blank">blog posting</a>. &#8220;Everyone who downloaded the most recent Vietnamese language pack since February 18, 2008 got an infected copy,&#8221; she wrote. &#8220;Mozilla does virus scans at upload time but the virus scanner did not catch this issue until several months after the upload.&#8221;</p>
<p>Mozilla is now going to add additional scans of its software to prevent this kind of thing from happening in the future, she said.</p>
<p>The malware in the language pack is from the <a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?idvirus=189095&amp;sitepanda=particulares" target="_blank">Xorer Trojan</a>, according to <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=432406" target="_blank">discussion</a> on Mozilla&#8217;s Bugzilla developer Web site, which indicates that Mozilla developers first discovered the issue on Tuesday.</p>
<p>&#8220;I think it (happened) just because the author&#8217;s local network was infected with the virus, so it modified HTML files,&#8221; wrote developer Hai-Nam Nguyen. &#8220;The infected code just display(s) annoying banner but it can&#8217;t propagate.&#8221;</p>
<p>The open-source browser maker does not know how many people were infected with the adware, but the plugin was downloaded more than 1,200 times in the past week and has been downloaded 16,667 times since November.</p>
<p>On Wednesday afternoon, the <a href="https://addons.mozilla.org/en-US/firefox/addon/5954" target="_blank">Web page</a> for the plugin was off-line as Mozilla scrambled to come up with a new, adware-free version of the language pack. In the meantime, users of the software should disable the plugin, Snyder said.</p>
<p>Source: <a href="http://www.pcworld.com/businesscenter/article/145617/mozilla_firefox_plugin_shipped_with_malicious_code.html" target="_blank">PC World</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Ffirefox-plugin-shipped-with-malicious-code%2F&amp;title=Firefox+Plugin+Shipped+With+Malicious+Code" title="Slashdot It!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/slash.ico" height="16" width="16"  border="0" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Ffirefox-plugin-shipped-with-malicious-code%2F&amp;title=Firefox+Plugin+Shipped+With+Malicious+Code" title="Digg This Story"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/digg.ico" width="16" height="16"  border="0" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Ffirefox-plugin-shipped-with-malicious-code%2F&amp;title=Firefox+Plugin+Shipped+With+Malicious+Code" title="Reddit"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/reddit.ico" width="16" height="16"  border="0" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Ffirefox-plugin-shipped-with-malicious-code%2F&amp;title=Firefox+Plugin+Shipped+With+Malicious+Code" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Ffirefox-plugin-shipped-with-malicious-code%2F&amp;title=Firefox+Plugin+Shipped+With+Malicious+Code', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/deli.ico" width="16" height="16"  border="0" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Ffirefox-plugin-shipped-with-malicious-code%2F" title="Share on Facebook"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/facebook.ico" width="16" height="16"  border="0" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Ffirefox-plugin-shipped-with-malicious-code%2F" title="Add to my Technorati Favorites"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/tech.ico" width="16" height="16"  border="0" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Ffirefox-plugin-shipped-with-malicious-code%2F&amp;title=Firefox+Plugin+Shipped+With+Malicious+Code" title="Save to Google Bookmarks"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/google.ico" width="16" height="16"  border="0" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Ffirefox-plugin-shipped-with-malicious-code%2F&amp;title=Firefox+Plugin+Shipped+With+Malicious+Code" title="Stumble it!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/stumble.ico" width="16" height="16"  border="0" alt="[StumbleUpon]" /></a>
</span>
	<h3>Related posts:</h3>
	<ul class="st-related-posts">
	<li><a href="http://www.pcsympathy.com/2008/04/09/why-your-computer-runs-so-slowly/" title="Why Your Computer Runs So Slowly (April 9, 2008)">Why Your Computer Runs So Slowly</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/12/vista-security-is-annoying-by-design/" title="Vista Security Is Annoying by Design (April 12, 2008)">Vista Security Is Annoying by Design</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/02/usb-malware-on-the-rise/" title="USB malware on the rise (April 2, 2008)">USB malware on the rise</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/06/top-15-malicious-spyware-actions/" title="Top 15 Malicious Spyware Actions (April 6, 2008)">Top 15 Malicious Spyware Actions</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/24/targeted-attacks-using-malicious-pdf-files/" title="Targeted attacks using malicious PDF files (April 24, 2008)">Targeted attacks using malicious PDF files</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.pcsympathy.com/2008/05/07/firefox-plugin-shipped-with-malicious-code/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Human Area Networking (HAN)</title>
		<link>http://www.pcsympathy.com/2008/05/07/human-area-networking-han/</link>
		<comments>http://www.pcsympathy.com/2008/05/07/human-area-networking-han/#comments</comments>
		<pubDate>Wed, 07 May 2008 16:07:40 +0000</pubDate>
		<dc:creator>manunkind</dc:creator>
		
		<category><![CDATA[General BS]]></category>

		<category><![CDATA[Networking]]></category>

		<category><![CDATA[Privacy]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[HAN]]></category>

		<category><![CDATA[Human Area Networking]]></category>

		<category><![CDATA[Mbps]]></category>

		<category><![CDATA[Network]]></category>

		<category><![CDATA[RedTacton]]></category>

		<category><![CDATA[Transmission]]></category>

		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://www.pcsympathy.com/?p=722</guid>
		<description><![CDATA[RedTacton is a new Human Area Networking technology that uses the surface of the human body as a safe, high speed network transmission path.


Using a new super-sensitive photonic electric field sensor, RedTacton can achieve duplex communication over the human body at a maximum speed of 10 Mbps.
RedTacton uses the minute electric fieldemitted on the surface [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.redtacton.com/en/info/index.html" target="_blank">RedTacton</a> is a new Human Area Networking technology that uses the surface of the human body as a safe, high speed network transmission path.</p>
<p><img class="alignnone size-full wp-image-723" style="border: 0px;" title="Human Area Networking" src="http://www.pcsympathy.com/wp-content/uploads/2008/05/c1-1.gif" alt="Human Area Networking" width="490" height="322" /></p>
<ul>
<li>Using a new super-sensitive photonic electric field sensor, <span class="Attention">RedTacton</span> can achieve duplex communication over the human body at a maximum speed of 10 Mbps.</li>
<li>RedTacton uses the minute electric fieldemitted on the surface of the human body. Technically, it is completely distinct from wireless and infrared.</li>
<li>A transmission path is formed at the moment a part of the human body comes in contact with a RedTacton transceiver. Physically separating ends the contact and thus ends communication.</li>
<li>Using RedTacton, communication starts when terminals carried by the user or embedded in devices are linked in various combinations according to the user&#8217;s natural, physical movements.</li>
<li>Communication is possible using any body surfaces, such as the hands, fingers, arms, feet, face, legs or torso. <span class="Attention">RedTacton</span> works through shoes and clothing as well.</li>
</ul>
<p><a href="http://www.redtacton.com/en/info/index.html" target="_blank">RedTacton Homepage</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fhuman-area-networking-han%2F&amp;title=Human+Area+Networking+%28HAN%29" title="Slashdot It!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/slash.ico" height="16" width="16"  border="0" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fhuman-area-networking-han%2F&amp;title=Human+Area+Networking+%28HAN%29" title="Digg This Story"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/digg.ico" width="16" height="16"  border="0" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fhuman-area-networking-han%2F&amp;title=Human+Area+Networking+%28HAN%29" title="Reddit"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/reddit.ico" width="16" height="16"  border="0" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fhuman-area-networking-han%2F&amp;title=Human+Area+Networking+%28HAN%29" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fhuman-area-networking-han%2F&amp;title=Human+Area+Networking+%28HAN%29', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/deli.ico" width="16" height="16"  border="0" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fhuman-area-networking-han%2F" title="Share on Facebook"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/facebook.ico" width="16" height="16"  border="0" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fhuman-area-networking-han%2F" title="Add to my Technorati Favorites"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/tech.ico" width="16" height="16"  border="0" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fhuman-area-networking-han%2F&amp;title=Human+Area+Networking+%28HAN%29" title="Save to Google Bookmarks"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/google.ico" width="16" height="16"  border="0" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fhuman-area-networking-han%2F&amp;title=Human+Area+Networking+%28HAN%29" title="Stumble it!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/stumble.ico" width="16" height="16"  border="0" alt="[StumbleUpon]" /></a>
</span>
	<h3>Related posts:</h3>
	<ul class="st-related-posts">
	<li><a href="http://www.pcsympathy.com/2008/05/01/wireless-modem-considerations/" title="Wireless modem considerations (May 1, 2008)">Wireless modem considerations</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/23/protect-yourself-from-pc-security-pitfalls/" title="Protect Yourself From PC Security Pitfalls (April 23, 2008)">Protect Yourself From PC Security Pitfalls</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/21/how-to-disable-usb-storage-devices/" title="How to disable USB storage devices (April 21, 2008)">How to disable USB storage devices</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/28/detecting-rogue-wireless/" title="Detecting Rogue Wireless (April 28, 2008)">Detecting Rogue Wireless</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/16/wireless-security-gets-boost-from-new-round-of-products/" title="Wireless Security Gets Boost From New Round of Products (April 16, 2008)">Wireless Security Gets Boost From New Round of Products</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.pcsympathy.com/2008/05/07/human-area-networking-han/feed/</wfw:commentRss>
		</item>
		<item>
		<title>SQL Injection Worm on the Loose</title>
		<link>http://www.pcsympathy.com/2008/05/07/sql-injection-worm-on-the-loose/</link>
		<comments>http://www.pcsympathy.com/2008/05/07/sql-injection-worm-on-the-loose/#comments</comments>
		<pubDate>Wed, 07 May 2008 12:06:06 +0000</pubDate>
		<dc:creator>manunkind</dc:creator>
		
		<category><![CDATA[Coding]]></category>

		<category><![CDATA[Internet]]></category>

		<category><![CDATA[Privacy]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[attack]]></category>

		<category><![CDATA[Data]]></category>

		<category><![CDATA[exploits]]></category>

		<category><![CDATA[IFRAMES]]></category>

		<category><![CDATA[infection]]></category>

		<category><![CDATA[SANS]]></category>

		<category><![CDATA[SQL]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[worm]]></category>

		<guid isPermaLink="false">http://www.pcsympathy.com/?p=721</guid>
		<description><![CDATA[A loyal ISC reader, Rob, wrote in to point us at what looks to be a SQL Injection worm that is on the loose.  From a quick google search it shows that there are about 4,000 websites infected and that this worm started at least mid-April if not earlier.  Right now we can&#8217;t speak intelligently [...]]]></description>
			<content:encoded><![CDATA[<p>A loyal ISC reader, Rob, wrote in to point us at what looks to be a SQL Injection worm that is on the loose.  From a quick google search it shows that there are about 4,000 websites infected and that this worm started at least mid-April if not earlier.  Right now we can&#8217;t speak intelligently to how they are getting into databases, but what they are doing is putting in some scripts and iframes to take over visitors to the websites.  It looks like the infection of user machines is by Real Player vulnerabilities that seem more or less detected pretty well.</p>
<p>The details, the script source that is injected into webpages is hxxp://winzipices.cn/#.js (where # is 1-5).  This, in turn, points to a cooresponding asp page on the same server.  (i.e. hxxp://winzipices.cn/#.asp).  This in turn points back to the exploits.  Either from the cnzz.com domain or the 51.la domain.  The cnzz.com (hxxp://s141.cnzz.com) domain looks like it could be set up for single flux, but it&#8217;s the same pool of IP address all the time right now.  hxxp://www.51.la just points to 51la.ajiang.net which has a short TTL, but only one IP is serving it.</p>
<p><span style="color: #ff0000;">Fair warning, if you google this hostnames, you will find exploited sites that will try and reach out and &#8220;touch&#8221; you&#8230; even if you are looking at the &#8220;cached&#8221; page.  Proceed at your own risk.</span></p>
<p>UPDATE: We&#8217;re also see this website serving up some attacks in connection with this SQL Worm (hxxp://bbs.jueduizuan.com)</p>
<p>Source: <a href="http://isc.sans.org/diary.html" target="_blank">SANS</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fsql-injection-worm-on-the-loose%2F&amp;title=SQL+Injection+Worm+on+the+Loose" title="Slashdot It!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/slash.ico" height="16" width="16"  border="0" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fsql-injection-worm-on-the-loose%2F&amp;title=SQL+Injection+Worm+on+the+Loose" title="Digg This Story"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/digg.ico" width="16" height="16"  border="0" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fsql-injection-worm-on-the-loose%2F&amp;title=SQL+Injection+Worm+on+the+Loose" title="Reddit"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/reddit.ico" width="16" height="16"  border="0" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fsql-injection-worm-on-the-loose%2F&amp;title=SQL+Injection+Worm+on+the+Loose" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fsql-injection-worm-on-the-loose%2F&amp;title=SQL+Injection+Worm+on+the+Loose', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/deli.ico" width="16" height="16"  border="0" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fsql-injection-worm-on-the-loose%2F" title="Share on Facebook"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/facebook.ico" width="16" height="16"  border="0" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fsql-injection-worm-on-the-loose%2F" title="Add to my Technorati Favorites"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/tech.ico" width="16" height="16"  border="0" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fsql-injection-worm-on-the-loose%2F&amp;title=SQL+Injection+Worm+on+the+Loose" title="Save to Google Bookmarks"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/google.ico" width="16" height="16"  border="0" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fsql-injection-worm-on-the-loose%2F&amp;title=SQL+Injection+Worm+on+the+Loose" title="Stumble it!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/stumble.ico" width="16" height="16"  border="0" alt="[StumbleUpon]" /></a>
</span>
	<h3>Related posts:</h3>
	<ul class="st-related-posts">
	<li><a href="http://www.pcsympathy.com/2008/04/17/sans-solves-mystery-of-mass-web-site-infections/" title="SANS solves mystery of mass Web site infections (April 17, 2008)">SANS solves mystery of mass Web site infections</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/21/the-snare-of-unauthorized-requests/" title="The Snare Of Unauthorized Requests (April 21, 2008)">The Snare Of Unauthorized Requests</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/28/microsoft-offers-assistance-to-combat-mass-sql-injection/" title="Microsoft offers assistance to combat mass SQL injection (April 28, 2008)">Microsoft offers assistance to combat mass SQL injection</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/24/mass-sql-injection/" title="Mass SQL injection (April 24, 2008)">Mass SQL injection</a></li>
	<li><a href="http://www.pcsympathy.com/2008/05/08/top-six-database-attacks/" title="Top Six Database Attacks (May 8, 2008)">Top Six Database Attacks</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.pcsympathy.com/2008/05/07/sql-injection-worm-on-the-loose/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Yahoo displays warnings about malware links</title>
		<link>http://www.pcsympathy.com/2008/05/07/yahoo-displays-warnings-about-malware-links/</link>
		<comments>http://www.pcsympathy.com/2008/05/07/yahoo-displays-warnings-about-malware-links/#comments</comments>
		<pubDate>Wed, 07 May 2008 11:54:38 +0000</pubDate>
		<dc:creator>manunkind</dc:creator>
		
		<category><![CDATA[Internet]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Software]]></category>

		<category><![CDATA[Javascript]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[McAfee]]></category>

		<category><![CDATA[SearchScan]]></category>

		<category><![CDATA[SiteAdvisor]]></category>

		<category><![CDATA[Trojan]]></category>

		<category><![CDATA[Yahoo]]></category>

		<guid isPermaLink="false">http://www.pcsympathy.com/?p=719</guid>
		<description><![CDATA[Yahoo is to start flagging links to sites that may contain dangerous content. Google has been warning users if a potentially dangerous website is behind the link in the list of hits displayed for some time now. Yahoo is following suit by marking websites that could possibly infect visitors with malicious code in its list [...]]]></description>
			<content:encoded><![CDATA[<p>Yahoo is to start flagging links to sites that may contain dangerous content. Google has been warning users if a potentially dangerous website is behind the link in the list of hits displayed for some time now. Yahoo is following suit by marking websites that could possibly infect visitors with malicious code in its list of hits.</p>
<p>Yahoo is using McAfee&#8217;s <a rel="external" href="http://www.siteadvisor.com/" target="_blank">SiteAdvisor</a> to identify malicious websites. The Yahoo version, called <a rel="external" href="http://help.yahoo.com/l/uk/yahoo/search/security/" target="_blank">SearchScan</a>, will display a warning in the list of hits if potentially dangerous websites are found that fall into the categories <em>dangerous downloads</em>, <em>risk of being hacked</em> and <em>unsolicited e-mails</em> – indeed, Yahoo goes so far as to suppress from the hit list sites that are categorised as <em>risk of being hacked</em>.</p>
<p><img class="alignnone size-full wp-image-720" title="Yahoo" src="http://www.pcsympathy.com/wp-content/uploads/2008/05/0.png" alt="Yahoo" width="336" height="216" /></p>
<p>As with most of the currently available link assessment systems such as McAfee&#8217;s SiteAdvisor, Finjan&#8217;s <a rel="external" href="http://securebrowsing.finjan.com/" target="_blank">SecureBrowsing</a>, and CAE&#8217;s LinkAdvisor, users should not automatically assume that links not flagged as malicious are always harmless. The flagging of suspect websites can help reduce the number of people who become infected with a Trojan via security vulnerabilities in their browser or add-ons when browsing the web. Importantly, the basic &#8220;red triangle&#8221; warning appears by a suspect listing in the Yahoo results whether or not JavaScript is enabled, so secure browsing does not prevent the message getting through. However, the information bubble and further details are only available if JavaScript is enabled.</p>
<p>Source: <a href="http://www.heise-online.co.uk/news/Yahoo-displays-warnings-about-malware-links--/110674" target="_blank">Heise Security</a></p>

<span class="slashdigglicious">
<a href="http://slashdot.org/bookmark.pl?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fyahoo-displays-warnings-about-malware-links%2F&amp;title=Yahoo+displays+warnings+about+malware+links" title="Slashdot It!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/slash.ico" height="16" width="16"  border="0" alt="[Slashdot]" /></a>
<a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fyahoo-displays-warnings-about-malware-links%2F&amp;title=Yahoo+displays+warnings+about+malware+links" title="Digg This Story"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/digg.ico" width="16" height="16"  border="0" alt="[Digg]" /></a>
<a href="http://reddit.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fyahoo-displays-warnings-about-malware-links%2F&amp;title=Yahoo+displays+warnings+about+malware+links" title="Reddit"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/reddit.ico" width="16" height="16"  border="0" alt="[Reddit]" /></a>
<a href="http://del.icio.us/post?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fyahoo-displays-warnings-about-malware-links%2F&amp;title=Yahoo+displays+warnings+about+malware+links" title="Save to del.icio.us" onclick="window.open('http://del.icio.us/post?v=4&amp;noui&amp;jump=close&amp;url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fyahoo-displays-warnings-about-malware-links%2F&amp;title=Yahoo+displays+warnings+about+malware+links', 'delicious', 'toolbar=no,width=700,height=400'); return false;"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/deli.ico" width="16" height="16"  border="0" alt="[del.icio.us]" /></a>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fyahoo-displays-warnings-about-malware-links%2F" title="Share on Facebook"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/facebook.ico" width="16" height="16"  border="0" alt="[Facebook]" /></a>
<a href="http://technorati.com/faves?add=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fyahoo-displays-warnings-about-malware-links%2F" title="Add to my Technorati Favorites"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/tech.ico" width="16" height="16"  border="0" alt="[Technorati]" /></a>
<a href="http://www.google.com/bookmarks/mark?op=edit&amp;output=popup&amp;bkmk=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fyahoo-displays-warnings-about-malware-links%2F&amp;title=Yahoo+displays+warnings+about+malware+links" title="Save to Google Bookmarks"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/google.ico" width="16" height="16"  border="0" alt="[Google]" /></a>
<a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.pcsympathy.com%2F2008%2F05%2F07%2Fyahoo-displays-warnings-about-malware-links%2F&amp;title=Yahoo+displays+warnings+about+malware+links" title="Stumble it!"><img src="http://www.pcsympathy.com/wp-content/themes/css/images/stumble.ico" width="16" height="16"  border="0" alt="[StumbleUpon]" /></a>
</span>
	<h3>Related posts:</h3>
	<ul class="st-related-posts">
	<li><a href="http://www.pcsympathy.com/2008/03/18/second-mass-hack-exposed/" title="Second mass hack exposed (March 18, 2008)">Second mass hack exposed</a></li>
	<li><a href="http://www.pcsympathy.com/2008/03/22/javascript-malware-source-code/" title="Javascript Malware Source Code (March 22, 2008)">Javascript Malware Source Code</a></li>
	<li><a href="http://www.pcsympathy.com/2008/03/08/click-here-to-become-infected/" title="Click here to become infected (March 8, 2008)">Click here to become infected</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/15/advice-for-securing-your-site-and-your-reputation/" title="Advice for securing your site and your reputation (April 15, 2008)">Advice for securing your site and your reputation</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/16/pro-tibet-rootkit-attacks-windows-pcs/" title="&#8216;Pro-Tibet&#8217; Rootkit Attacks Windows PCs (April 16, 2008)">&#8216;Pro-Tibet&#8217; Rootkit Attacks Windows PCs</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.pcsympathy.com/2008/05/07/yahoo-displays-warnings-about-malware-links/feed/</wfw:commentRss>
		</item>
		<item>
		<title>PHP Multibyte Shell Command Escaping Bypass Vulnerability</title>
		<link>http://www.pcsympathy.com/2008/05/07/php-multibyte-shell-command-escaping-bypass-vulnerability/</link>
		<comments>http://www.pcsympathy.com/2008/05/07/php-multibyte-shell-command-escaping-bypass-vulnerability/#comments</comments>
		<pubDate>Wed, 07 May 2008 11:41:20 +0000</pubDate>
		<dc:creator>manunkind</dc:creator>
		
		<category><![CDATA[Coding]]></category>

		<category><![CDATA[PHP]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[backslash]]></category>

		<category><![CDATA[escapeshellarg]]></category>

		<category><![CDATA[escapeshellcmd]]></category>

		<category><![CDATA[injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.pcsympathy.com/?p=718</guid>
		<description><![CDATA[In PHP there exist two functions to escape shell commands or arguments to shell commands that are used in PHP applications to protect against shell command injection vulnerabilities.
- escapeshellcmd()
- escapeshellarg()
Unfortunately it was discovered that both functions fail to protect against shell command injection when the shell uses a locale with a variable width character set [...]]]></description>
			<content:encoded><![CDATA[<p>In PHP there exist two functions to escape shell commands or arguments to shell commands that are used in PHP applications to protect against shell command injection vulnerabilities.<br />
- escapeshellcmd()<br />
- escapeshellarg()</p>
<p>Unfortunately it was discovered that both functions fail to protect against shell command injection when the shell uses a locale with a variable width character set like GBK, EUC-KR, SJIS, ..</p>
<p>This can lead to arbitrary shell command injection vulnerabilities in PHP applications believed to be safe. In addition to that exploiting this problem in PHP functions that use this shell escaping internally allows safe_mode and disable_functions bypass.</p>
<p><span id="more-718"></span></p>
<p><strong>Details:</strong><br />
<span style="text-decoration: underline;">escapeshellcmd()</span><br />
escapeshellcmd() will put a single backslash character in front of every shell meta character like ; $ &lt; &gt; &#8230; to escape it. This function is normally used to ensure that only a single shell command is executed and that it is not possible to append further shell commands.</p>
<p>The problem is that the backslash character is a legal second byte of several variable width encodings. Because of this a shell that is for example configured to use a locale with the GBK character set will consider the introduced backslash as part of a multibyte character instead of an escaping of following meta character.</p>
<p><strong>Example:</strong><br />
escapeshellcmd(&#8221;echo &#8220;.chr(0xc0).&#8221;;id&#8221;);</p>
<p>Executing the result of this will therefore result in echo and id being executed.</p>
<p><span style="text-decoration: underline;">escapeshellarg()</span><br />
escapeshellarg() does not use the backslash character to escape shell meta characters. Instead it places the argument in single quotes and only escapes single quotes in the qrgument with the string &#8216;\&#8221; . Because of this it is not possible to use the same trick. However in case there are multiple inputs it is possible to &#8220;eat&#8221; the terminating single quote which results in a shell command injection through the second argument.</p>
<p><strong>Example:</strong><br />
$arg1 = chr(0xc0);<br />
$arg2 = &#8220;; id ; #&#8221;;<br />
$cmd = &#8220;echo &#8220;.escapeshellarg($arg1).&#8221; &#8220;.escapeshellarg($arg2);</p>
<p>In this example the 0xC0 character forms a multibyte character with the terminating single quote. Therefore the starting single quote of $arg2 will be used as terminating single quote and the content of $arg2 can be used to inject everything.</p>
<p>NOTE: This attack works because even invalid second byte characters are accepted on several platforms as valid.</p>
<p><span style="text-decoration: underline;">safe_mode_exec_dir bypass</span><br />
Because of the vulnerability described above, it is possible to bypass the safe_mode_exec_dir directive of PHP. This directive is supposed to ensure that only shell commands within the allowed directory can be executed.</p>
<p>This attack is however only feasible when the shell uses one of the vulnerable locales, because during safe_mode it is not possible to set the LANG environment variable that would influence the shell.</p>
<p><span style="text-decoration: underline;">mail() fifth parameter - disable_functions bypass</span><br />
Because of the vulnerability described above, it is possible to execute arbitrary shell commands on a system even when all shell execution functions like shell_exec(), system(), &#8230; are disabled by the disable_functions directive, but mail() is still allowed. This attack relies on the fact that the fifth mail() parameter is used as argument to the sendmail binary and escaped with escapeshellcmd() internally to ensure that no further shell commands are appended.</p>
<p>Because PHP scripts can influence the locale of the shell (unless running in safe_mode) this attack allows bypassing the setting of disable_functions when a vulnerable locale is installed on the system. In case the system&#8217;s shell does not support one of the vulnerable character sets the attack is not feasible.</p>
<p><a href="http://www.securiteam.com/unixfocus/5EP0120OAI.html" target="_blank">Read the rest of the story&#8230;</a></p>

	<h3>Related posts:</h3>
	<ul class="st-related-posts">
	<li><a href="http://www.pcsympathy.com/2008/04/28/two-wordpress-25-vulnerabilities/" title="WordPress PHP Code Execution and Cross-Site Scripting (April 28, 2008)">WordPress PHP Code Execution and Cross-Site Scripting</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/15/sqlninja-022-released-sql-injection-tool/" title="sqlninja 0.2.2 Released - SQL Injection Tool (April 15, 2008)">sqlninja 0.2.2 Released - SQL Injection Tool</a></li>
	<li><a href="http://www.pcsympathy.com/2008/05/07/php-weak-random-number-seed-vulnerability/" title="PHP Weak Random Number Seed Vulnerability (May 7, 2008)">PHP Weak Random Number Seed Vulnerability</a></li>
	<li><a href="http://www.pcsympathy.com/2008/05/02/php-526-plugs-security-holes/" title="PHP 5.2.6 plugs security holes (May 2, 2008)">PHP 5.2.6 plugs security holes</a></li>
	<li><a href="http://www.pcsympathy.com/2008/05/05/cross-site-scripting-with-morse-code/" title="Cross-Site-Scripting with Morse code (May 5, 2008)">Cross-Site-Scripting with Morse code</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.pcsympathy.com/2008/05/07/php-multibyte-shell-command-escaping-bypass-vulnerability/feed/</wfw:commentRss>
		</item>
		<item>
		<title>PHP Weak Random Number Seed Vulnerability</title>
		<link>http://www.pcsympathy.com/2008/05/07/php-weak-random-number-seed-vulnerability/</link>
		<comments>http://www.pcsympathy.com/2008/05/07/php-weak-random-number-seed-vulnerability/#comments</comments>
		<pubDate>Wed, 07 May 2008 11:38:14 +0000</pubDate>
		<dc:creator>manunkind</dc:creator>
		
		<category><![CDATA[Coding]]></category>

		<category><![CDATA[PHP]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[attack]]></category>

		<category><![CDATA[attacker]]></category>

		<category><![CDATA[entropy]]></category>

		<category><![CDATA[random number generators]]></category>

		<category><![CDATA[SEED]]></category>

		<category><![CDATA[Unix]]></category>

		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.pcsympathy.com/?p=717</guid>
		<description><![CDATA[Since version 4.2.0 PHP automatically seeds the random number generators on the first usage of rand() and mt_rand(). This is done with the help of the GENERATE_SEED() macro.
Unfortunately it was discovered that the GENERATE_SEED() macro contains several problems that can lead to a weaker seed than expected. In the worst case the seed is directly [...]]]></description>
			<content:encoded><![CDATA[<p>Since version 4.2.0 PHP automatically seeds the random number generators on the first usage of rand() and mt_rand(). This is done with the help of the GENERATE_SEED() macro.</p>
<p>Unfortunately it was discovered that the GENERATE_SEED() macro contains several problems that can lead to a weaker seed than expected. In the worst case the seed is directly predictable, which allows to predict all random numbers from the outside.</p>
<p>NOTICE: Neither rand() nor mt_rand() produce cryptographically secure random numbers and should therefore never be used for such applications.</p>
<p>ATTENTION: This vulnerability was not mentioned in the security changelog of PHP 5.2.6</p>
<p><span id="more-717"></span></p>
<p><strong>Details:</strong><br />
PHP uses the following macro on the first usage of rand() or mt_rand() within a PHP process to seed the different random number generators.</p>
<p>#ifdef PHP_WIN32<br />
#define GENERATE_SEED() ((long) (time(0) * GetCurrentProcessId() \<br />
* 1000000 * php_combined_lcg(TSRMLS_C)))<br />
#else<br />
#define GENERATE_SEED() ((long) (time(0) * getpid() * 1000000 \<br />
* php_combined_lcg(TSRMLS_C)))<br />
#endif</p>
<p>This produces a seed that depends on the unix timestamp, the process identifier the factor 1000000 and a value between 0 and 1 that itself depends on the current microsecond and the process identifier.</p>
<p>It should be obvious that this not cryptographically strong because the current unix timestamp is known to the attacker and only a part of the process identifier and the microsecond can be considered as entropy. However this macro contains two problems that weakens the produced seed. One affects 32 bit systems and the other only affects 64 bit systems.</p>
<p><span style="text-decoration: underline;">zero factor problem</span><br />
When you have a look on the code generated by the compiler you will see that it first multiplies the timestamp, process identifier and the numerical factor. This is performed in modular integer arithmetic. It was therefore evaluated how likely it is that the multiplication will result in a zero, because then the seed will be zero, too. (on older PHP versions the seed will be 1 for mt_rand() because the lowest bit will be forced to be 1)</p>
<p>1000000 is a number with its lowest 6 bits set to zero. Therefore the multiplication will result in zero if the timestamp and process identifier contain together 26 lower zero bits.</p>
<p>Because the process identifier cannot be influenced directly the timestamp is the easier part to influence. The timestamp has its 26 lower bits all zero once every 2.1 years. This means every 2.1 years there is a second in which the random number generator will be seeded with a seed of zero. An attack happening during this second on a freshly seeded random number generator (very easy to trigger on CGI installations) will therefore allow to predict all generated random numbers.</p>
<p>To overcome the &#8220;only once every 2.1 years&#8221; problem it is possible to use the lower bits of the process identifier in the multiplication. On some platforms (windows) the process identifier is for example always even which means on these platforms the attack is possible every 1.05 years. This can be further improved by sending more requests at the same time. They all will be handled by different process identifiers and by triggering enough requests the probability of for example 3 lower bits being zero is high. With 3 lower zero bits the attack is feasible every 3 months.</p>
<p><span style="text-decoration: underline;">precision problem</span><br />
On 64 bit systems a different problem arises from the multiplication. Because the multiplication is performed in 64 bit the result of the multiplication usually contains too many digits to be converted to a double without loss of precision. Therefore several lower bits of the results are usually lost during the conversion which results in a seed with zeroes in the lower bits. During our tests the lower 8 bits were most of the time zero.</p>
<p>This means the seed generated by GENERATE_SEED() is in the majority of invocations only 24 bit strong. This means that bruteforcing the seed on a 64 bit system should be done by first populating the higher bits to ensure the result is found faster.</p>
<p><a href="http://www.securiteam.com/unixfocus/5FP0220OAE.html" target="_blank">Read the rest of the story&#8230;</a></p>

	<h3>Related posts:</h3>
	<ul class="st-related-posts">
	<li><a href="http://www.pcsympathy.com/2008/04/26/wordpress-25-cookie-forging-explained/" title="WordPress 2.5 Cookie Forging Explained (April 26, 2008)">WordPress 2.5 Cookie Forging Explained</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/03/web-bugs-return-using-digital-certificates/" title="Web bugs return using digital certificates (April 3, 2008)">Web bugs return using digital certificates</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/14/vulnerability-in-google-spreadsheets-allows-cookie-stealing/" title="Vulnerability in Google spreadsheets allows cookie stealing (April 14, 2008)">Vulnerability in Google spreadsheets allows cookie stealing</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/24/targeted-attacks-using-malicious-pdf-files/" title="Targeted attacks using malicious PDF files (April 24, 2008)">Targeted attacks using malicious PDF files</a></li>
	<li><a href="http://www.pcsympathy.com/2008/04/11/security-guru-gives-hackers-a-taste-of-their-own-medicine/" title="Security Guru Gives Hackers a Taste of Their Own Medicine (April 11, 2008)">Security Guru Gives Hackers a Taste of Their Own Medicine</a></li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.pcsympathy.com/2008/05/07/php-weak-random-number-seed-vulnerability/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.881 seconds -->
