02 September 2010
Hardware Trojans
On July 22, 2010 in the magazine «NewScientist» was published Note , which reported that, according to published on the Dell Forum Trojan Worm.Win32.Spybot was found in a flash memory of a motherboard. This board is included in PowerEdge R310, PowerEdge R410, PowerEdge R510 and PowerEdge T410 Dell servers. The worm payload was in spreading through peer-to-peer networks and instant messaging clients. Given the fact that the worm is run under Windows, it can be neutralized by anti-virus software, but removing the worm's code from the flash memory of the motherboard is unlikely to force by a normal virus scanner. The company has already announced that it will urgently replaces all infected boards of servers.
|
26 August 2010
IDA for Linux
Today we continue the story of malicious software running under Linux. At this time we will discuss the heavy artillery - IDA Pro. This indispensable tool has the ability to debug programs running under Windows, Linux and Mac OS. We will mention Mac OS next time, but now we use familiar Virtual Machine VirtualBox running Ubuntu 10.04 on board as an experimental platform.
|
Today I'd want to talk about such things as "certificates".
Accessing certain sites, you can see a browser warning about the unreliability of the certificate. For example, such message for Firefox...
|
We continue to experiment with the Kaspersky Rescue Disk. This time, we will try to cram its contents on the USB flash drive, and then make it bootable. Thus we will need: Linux Live CD that uses the grub loader and Kaspersky Rescue Disc.
|
This story begins with the fact that I accidentally found Kaspersky Rescue Disk update. More precisely, it begins with the thought that Registry Editor is needed for KRD. I downloaded Rescue Disk without thinking twice using built-in tools...
|
In the previous review of the graphical desktop sharing system we brought together the computers running Windows XP Home and Ubuntu OS without any problems. It is time to make friends these OS with the Mac one. (This is the addition to the last article especially for the few users of Mac OS.)
|
Recently there was a need to get remote access to a computer running Windows XP Home. And it turned out an unpleasant restriction of home version: the absence of the usual Pro-version for the rdp-server. That is why, it is possible to connect with XP Home, but to XP Home - impossible. But as always there is an tradeoff!
|
The idea to use pending file rename operations had come into my mind when I searched for another way to humiliate the Trojan-ransoms. Consider the example of Trojan-Ransom.Win32.PogBlock.xg
|
Is it possible to create a virus that does not cause any suspicion of its presence? Is there a universal way to evade all existing security software, even if this way will be done open to the public? Is it possible to execute random code on a remote machine without any notification to a user and unnoticed for "artificial intelligence"?
|
The immediate sketch on the theme "My security is in my hands." In this article the author describes in detail the cure system procedure for malware Trojan-Ransom.Win32.Chameleon. It is very topical and useful lesson.
At this time I will narrate about Trojan-Ransom.Win32.Chameleon.
|
|
|