<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; Windows Hacking</title>
	<atom:link href="http://www.darknet.org.uk/category/windows-hacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>No BEAST Fix From Microsoft In December Patch Tuesday &#8211; But They Fixed Duqu Bug</title>
		<link>http://www.darknet.org.uk/2011/12/no-beast-fix-from-microsoft-in-december-patch-tuesday-but-they-fixed-duqu-bug/</link>
		<comments>http://www.darknet.org.uk/2011/12/no-beast-fix-from-microsoft-in-december-patch-tuesday-but-they-fixed-duqu-bug/#comments</comments>
		<pubDate>Thu, 15 Dec 2011 08:41:44 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[beast]]></category>
		<category><![CDATA[beast bug]]></category>
		<category><![CDATA[duqu]]></category>
		<category><![CDATA[duqu bug]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[hacking microsoft]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[patch-tuesday]]></category>
		<category><![CDATA[patches]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3238</guid>
		<description><![CDATA[It looks like Microsoft originally had a patch for the BEAST vulnerability, but for some reason they have withdrawn it for the December Patch Tuesday. It&#8217;s a pretty bumper crop of patches though with 13 bulletins and 19 vulnerabilities fixed, the highest profile one being a patch for the zero-day vulnerability exploited by Duqu. The [...]]]></description>
			<content:encoded><![CDATA[<p>It looks like <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> originally had a patch for the BEAST vulnerability, but for some reason they have withdrawn it for the December Patch Tuesday.</p>
<p>It&#8217;s a pretty bumper crop of patches though with 13 bulletins and 19 vulnerabilities fixed, the highest profile one being a patch for the zero-day vulnerability exploited by Duqu.</p>
<p>The pulling of the BEAST patch is good in a way though I guess, it shows that Microsoft are doing comprehensive compatibility testing to ensure the patches don&#8217;t cause any problems (including with 3rd party software).</p>
<blockquote><p>Microsoft released 13 security bulletins addressing 19 vulnerabilities overnight, as part of a bumper final Patch Tuesday of the year.</p>
<p>Highlight of the baker&#8217;s dozen is a patch for the the zero-day vulnerability exploited by Duqu (sibling of Stuxnet) worm back in October. Fixing the underlying flaw exploited by Duqu involves the resolution of a problem in how Windows kernel mode driver handles TrueType font files.</p>
<p>Aside from this critical update the batch includes an update to address a critical flaw n Windows Media Player. A cumulative security update of ActiveX kill bits is covered by the third, and final, critical update this month. The other ten bulletins address less severe (important) flaws in Windows, IE and Office. Altogether its a desktop-heavy patch batch, as you can see from Microsoft&#8217;s summary here.</p>
<p>Microsoft originally promised 14 bulletins for the December edition of Patch Tuesday but one has been pulled, probably for quality control reasons. The original anticipated 14th bulletin was for the BEAST attack, but did not make it in time for the holidays due to a last minute software incompatibility uncovered during third party testing, security services firm Qualys reports. The absence of this fix means that Microsoft has issued a grand total of 99 bulletins this year, one less than the ton up that might have resulted in adverse headlines.</p></blockquote>
<p>Both BEAST and Duqu are pretty nasty <a href="http://www.darknet.org.uk/category/virustrojanswormsrootkits/">malware</a>, I&#8217;d guess seen as though they&#8217;ve already fixed the BEAST problem &#8211; they just need to work on compatibility issues &#8211; that we&#8217;ll definitely be seeing the patch rolled out in the January <a href="http://www.darknet.org.uk/tag/patch-tuesday/">Patch Tuesday</a>.</p>
<p>It&#8217;s good to see a bunch of important patches rolled out pre Christmas though as there&#8217;s always an influx of malware, scams, spams and <a href="http://www.darknet.org.uk/category/phishing/">phishing</a> attempts around this period (trying to leverage on people&#8217;s good will I guess).</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>The BEAST attack affects web servers that support SSLv3/TLSv1 encryption. Although a patch will have to wait until January, at least, Microsoft has already published a workaround, which involves using the non affected RC4 cipher in SSL setups.</p>
<p>The Internet Storm Centre has produced a helpful graphical overview of the Black Tuesday updates from Microsoft here. It reckons that some of the flaws are more severe than Redmond&#8217;s rating. By the ISC&#8217;s count there are EIGHT critical updates. Either way you look at it, this is a lot of patching work even before we think about other security updates doing the rounds.</p>
<p>Google and Adobe are also joining in on the season of giving by releasing updates of their own. Adobe last week issued a critical updates for Adobe Reader and Acrobat. The latest version of Adobe PDF-reading software, Adobe Reader X, is not affected by this vulnerability thanks to the use of sand-boxing technology. So users have the option to either upgrade or apply a patch to the earlier version of the software.</p>
<p>In addition, Google published an update to its Chrome browser that addresses 15 security flaws, including six high-risk vulnerabilities, on Tuesday. More details of what&#8217;s fixed inside Chrome 16.0.912.63, the latest cross-platform version of the browser (yes Mac and Linux fans you ought to update too), can be found <a href="http://googlechromereleases.blogspot.com/2011/12/stable-channel-update.html">here</a>.</p></blockquote>
<p>There has been some other nasty bugs around too with a zero-day for Adobe Reader last week and Google just released a massive update of Chrome including 6 high risk vulnerabilities.</p>
<p>SANS ISC as always gives a great summary of the patches and classifies some of them more seriously than Microsoft does &#8211; you can check out the details here:</p>
<p><a href="http://isc.sans.org/diary/December+2011+Microsoft+Black+Tuesday+Summary/12193">December 2011 Microsoft Black Tuesday Summary</a></p>
<p>Source: <a href="http://www.theregister.co.uk/2011/12/14/ms_bumper_patch_tuesday/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=No+BEAST+Fix+From+Microsoft+In+December+Patch+Tuesday+%E2%80%93+But+They+Fixed+Duqu+Bug+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3238+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/12/no-beast-fix-from-microsoft-in-december-patch-tuesday-but-they-fixed-duqu-bug/&amp;t=No+BEAST+Fix+From+Microsoft+In+December+Patch+Tuesday+%E2%80%93+But+They+Fixed+Duqu+Bug" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/12/no-beast-fix-from-microsoft-in-december-patch-tuesday-but-they-fixed-duqu-bug/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/12/no-beast-fix-from-microsoft-in-december-patch-tuesday-but-they-fixed-duqu-bug/&amp;title=No+BEAST+Fix+From+Microsoft+In+December+Patch+Tuesday+%E2%80%93+But+They+Fixed+Duqu+Bug" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/12/no-beast-fix-from-microsoft-in-december-patch-tuesday-but-they-fixed-duqu-bug/&amp;title=No+BEAST+Fix+From+Microsoft+In+December+Patch+Tuesday+%E2%80%93+But+They+Fixed+Duqu+Bug" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/12/no-beast-fix-from-microsoft-in-december-patch-tuesday-but-they-fixed-duqu-bug/&amp;title=No+BEAST+Fix+From+Microsoft+In+December+Patch+Tuesday+%E2%80%93+But+They+Fixed+Duqu+Bug" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/12/no-beast-fix-from-microsoft-in-december-patch-tuesday-but-they-fixed-duqu-bug/&amp;title=No+BEAST+Fix+From+Microsoft+In+December+Patch+Tuesday+%E2%80%93+But+They+Fixed+Duqu+Bug" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F12%2Fno-beast-fix-from-microsoft-in-december-patch-tuesday-but-they-fixed-duqu-bug%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/12/no-beast-fix-from-microsoft-in-december-patch-tuesday-but-they-fixed-duqu-bug/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>winAUTOPWN v2.8 Released For Download &#8211; Windows Auto-Hacking Toolkit</title>
		<link>http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/</link>
		<comments>http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/#comments</comments>
		<pubDate>Tue, 18 Oct 2011 17:27:26 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[auto hacking]]></category>
		<category><![CDATA[auto hacking tool]]></category>
		<category><![CDATA[automated exploit]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploit tool]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[win hacking tool]]></category>
		<category><![CDATA[winautopwn]]></category>
		<category><![CDATA[windows-exploit]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3205</guid>
		<description><![CDATA[I wanted to post this a while back, but the site (and thus the download) was down again &#8211; it seems to be a common occurrence. Someone get this guy some proper hosting! winAUTOPWN and bsdAUTOPWN are minimal Interactive Frameworks which act as a frontend for quick systems vulnerability exploitation. It takes inputs like IP [...]]]></description>
			<content:encoded><![CDATA[<p>I wanted to post this a while back, but the site (and thus the download) was down again &#8211; it seems to be a common occurrence. Someone get this guy some proper hosting!</p>
<p>winAUTOPWN and bsdAUTOPWN are minimal Interactive Frameworks which act as a frontend for quick systems vulnerability exploitation. It takes inputs like IP address, Hostname, CMS Path, etc. and does a smart multi-threaded portscan for TCP ports 1 to 65535. Exploits capable of giving Remote Shells, which are released publicly over the Internet by active contributors and exploit writers are constantly added to winAUTOPWN/bsdAUTOPWN. A lot of these exploits are written in scripting languages like python, perl and php. Presence of these language interpreters is essential for successful exploitations using winAUTOPWN/bsdAUTOPWN.</p>
<p>Exploits written in languages like C, Delphi, ASM which can be compiled are pre-compiled and added along-with others. On successful exploitation winAUTOPWN/bsdAUTOPWN gives a remote shell and waits for the attacker to use the shell before trying other exploits. This way the attacker can count and check the number of exploits which actually worked on a Target System.</p>
<p>This version covers almost all remote exploits up-till September 2011 and a few older ones as well. Also added in this release are a few ruby exploits which require &#8216;socket&#8217; alone for interpretation. Gee-Hence, winAUTOPWN now requires ruby installed as well, just like perl, python and php.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>This version incorporates a new command-line parameters: -targetOS to allow selection of the target Operating System. This is essential for a few exploits to work perfectly. The List of OS and the corresponding OS codes are available and asked when winAUTOPWN OR bsdAUTOPWN is executed.</p>
<p>Untill the last release there was only a bind_shell TCP shellcode available in the exploits. This release brings yet another feature which gives the freedom to choose from a variety of shellcodes. You can now select reverse_tcp for Windows cmd and other shellcodes for Solaris, Linux, FreeBSD, etc. This is all done by mod_shellcode which has been created and added to WINDOWS AUTOPWN and BSD AUTOPWN as well. mod_shellcode gets automatically invoked by WINDOWS AUTOPWN for every scripted exploit code whose shellcode can be manually changed. Note that there are a few exploits in a compiled binary form which lack reverse shell and other shellcode features.</p>
<p>mod_shellcode is available as a separate binary in the exploits/ directory for Windows, FreeBSD x86, FreeBSD x64 and DragonFly BSD platforms (just like the main BSD AUTOPWN and other exploit binaries) and hence can also be manually used by exploit writers and exploiters to quickly change shellcodes in their exploit files.</p>
<p>You can download winAUTOPWn v2.8 here:</p>
<p><a href="http://27.106.39.222/w/winAUTOPWN_2.8.7z">winAUTOPWN_2.8.7z</a></p>
<p>And well because the site is always down, I&#8217;ve uploaded a mirror copy here:</p>
<p><a href="http://www.filesonic.com/file/2644314211/winAUTOPWN_2.8.7z">winAUTOPWN_2.8.7z (FileSonic)</a></p>
<p>Or read more <a href="http://winautopwn.co.nr">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=winAUTOPWN+v2.8+Released+For+Download+%E2%80%93+Windows+Auto-Hacking+Toolkit+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3205+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/&amp;t=winAUTOPWN+v2.8+Released+For+Download+%E2%80%93+Windows+Auto-Hacking+Toolkit" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/&amp;title=winAUTOPWN+v2.8+Released+For+Download+%E2%80%93+Windows+Auto-Hacking+Toolkit" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/&amp;title=winAUTOPWN+v2.8+Released+For+Download+%E2%80%93+Windows+Auto-Hacking+Toolkit" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/&amp;title=winAUTOPWN+v2.8+Released+For+Download+%E2%80%93+Windows+Auto-Hacking+Toolkit" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/&amp;title=winAUTOPWN+v2.8+Released+For+Download+%E2%80%93+Windows+Auto-Hacking+Toolkit" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F10%2Fwinautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/10/winautopwn-v2-8-released-for-download-windows-auto-hacking-toolkit/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>NetworkMiner v1.1 Released &#8211; Windows Packet Analyzer &amp; Sniffer</title>
		<link>http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/</link>
		<comments>http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/#comments</comments>
		<pubDate>Tue, 20 Sep 2011 15:09:46 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[hacking-networks]]></category>
		<category><![CDATA[network miner]]></category>
		<category><![CDATA[network-forensics]]></category>
		<category><![CDATA[network-security]]></category>
		<category><![CDATA[network-sniffing]]></category>
		<category><![CDATA[networkminer]]></category>
		<category><![CDATA[packet-sniffer]]></category>
		<category><![CDATA[passive network sniffer]]></category>
		<category><![CDATA[windows network sniffer]]></category>
		<category><![CDATA[windows packet capture tool]]></category>
		<category><![CDATA[windows packet sniffer]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3190</guid>
		<description><![CDATA[NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc. without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates [...]]]></description>
			<content:encoded><![CDATA[<p>NetworkMiner is a Network Forensic Analysis Tool (NFAT) for Windows. NetworkMiner can be used as a passive network sniffer/packet capturing tool in order to detect operating systems, sessions, hostnames, open ports etc. without putting any traffic on the network. NetworkMiner can also parse PCAP files for off-line analysis and to regenerate/reassemble transmitted files and certificates from PCAP files.</p>
<p>NetworkMiner collects data (such as forensic evidence) about hosts on the network rather than to collect data regarding the traffic on the network. The main user interface view is host centric (information grouped per host) rather than packet centric (information showed as a list of packets/frames).</p>
<p>NetworkMiner has, since the first release in 2007, become popular tool among incident response teams as well as law enforcement. NetworkMiner is today used by companies and organizations all over the world. </p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p>It&#8217;s been a long time since we last mentioned NetworkMiner, it was back in 2008 &#8211; <a href="http://www.darknet.org.uk/2008/02/networkminer-passive-sniffer-packet-analysis-tool-for-windows/">NetworkMiner – Passive Sniffer &#038; Packet Analysis Tool for Windows</a>.</p>
<p>Now there&#8217;s a new version!</p>
<p><strong>New in v1.1</strong></p>
<p>The new version supports features such as:</p>
<ul>
<li>Extraction of Google Analytics data</li>
<li>Better parsing of SMB data</li>
<li>Support for PPP frames</li>
<li>Even more stable than the 1.0 release</li>
</ul>
<p>You can download NetworkMiner v1.1 here:</p>
<p><a href="http://sourceforge.net/projects/networkminer/files/networkminer/NetworkMiner-1.1/NetworkMiner_1-1.zip/download">NetworkMiner_1-1.zip</a></p>
<p>Or read more <a href="http://www.netresec.com/?page=NetworkMiner">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3190+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;t=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;title=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;title=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;title=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/&amp;title=NetworkMiner+v1.1+Released+%E2%80%93+Windows+Packet+Analyzer+%26+Sniffer" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F09%2Fnetworkminer-v1-1-released-windows-packet-analyzer-sniffer%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/09/networkminer-v1-1-released-windows-packet-analyzer-sniffer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>winAUTOPWN v2.7 Released &#8211; Windows Autohacking Tool</title>
		<link>http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/</link>
		<comments>http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/#comments</comments>
		<pubDate>Tue, 06 Sep 2011 10:45:42 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[auto hacking]]></category>
		<category><![CDATA[auto hacking tool]]></category>
		<category><![CDATA[automated exploit]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[exploit tool]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[win hacking tool]]></category>
		<category><![CDATA[winautopwn]]></category>
		<category><![CDATA[windows-exploit]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3085</guid>
		<description><![CDATA[I&#8217;ve always been skeptical about this tool, especially seen as though the first version was released on April Fools day in 2009, anyway it&#8217;s 2 years later now and it still seems to be around so I think it&#8217;s worth publishing an update. If any of you have actually tested this tool out, do drop [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve always been skeptical about this tool, especially seen as though the first version was released on <a href="http://www.darknet.org.uk/2009/04/winautopwn-windows-autohacking-tool/">April Fools day in 2009</a>, anyway it&#8217;s 2 years later now and it still seems to be around so I think it&#8217;s worth publishing an update.</p>
<p>If any of you have actually tested this tool out, do drop a comment below.</p>
<p>winAUTOPWN and bsdAUTOPWN are minimal Interactive Frameworks which act as a frontend for quick systems vulnerability exploitation. It takes inputs like IP address, Hostname, CMS Path, etc. and does a smart multi-threaded portscan for TCP ports 1 to 65535. Exploits capable of giving Remote Shells, which are released publicly over the Internet by active contributors and exploit writers are constantly added to winAUTOPWN/bsdAUTOPWN. A lot of these exploits are written in scripting languages like python, perl and php. Presence of these language interpreters is essential for successful exploitations using winAUTOPWN/bsdAUTOPWN.</p>
<p>Exploits written in languages like C, Delphi, ASM which can be compiled are pre-compiled and added along-with others. On successful exploitation winAUTOPWN/bsdAUTOPWN gives a remote shell and waits for the attacker to use the shell before trying other exploits. This way the attacker can count and check the number of exploits which actually worked on a Target System.</p>
<p><strong>New in v2.7</strong></p>
<p>This version covers almost all remote exploits up-till mid-July 2011 and a few older ones as well.  This version incorporates a few new commandline parameters: -perlrevshURL (for a PERL Reverse Shell URL), &#8211; mailFROM (smtpsender) and -mailTO (smtpreceiver).  These are the commandline arguments required for a few exploits which require remote connect-back using a perl shell and email server exploits requiring authentication respectively.  This version also tackles various internal bugs and fixes them.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p> A complete list of all Exploits in winAUTOPWN is available in CHANGELOG.TXT<br />
 A complete list of User Interface changes is available in UI_CHANGES.txt</p>
<p>Also, in this version :</p>
<ul>
<li> BSDAUTOPWN has been upgraded to version 1.5.</li>
<li> In this release you will also find pre-compiled binaries for :</li>
<li> FreeBSD x86</li>
<li> FreeBSD x64</li>
<li> DragonFly BSD x86</li>
</ul>
<p>You can download winAUTOPWN v2.7 here:</p>
<p><a href="http://27.106.13.152/w/winAUTOPWN_2.7.RAR">winAUTOPWN_2.7.RAR</a></p>
<p>Or read more <a href="http://winautopwn.co.nr">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=winAUTOPWN+v2.7+Released+%E2%80%93+Windows+Autohacking+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3085+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/&amp;t=winAUTOPWN+v2.7+Released+%E2%80%93+Windows+Autohacking+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/&amp;title=winAUTOPWN+v2.7+Released+%E2%80%93+Windows+Autohacking+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/&amp;title=winAUTOPWN+v2.7+Released+%E2%80%93+Windows+Autohacking+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/&amp;title=winAUTOPWN+v2.7+Released+%E2%80%93+Windows+Autohacking+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/&amp;title=winAUTOPWN+v2.7+Released+%E2%80%93+Windows+Autohacking+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F09%2Fwinautopwn-v2-7-released-windows-autohacking-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/09/winautopwn-v2-7-released-windows-autohacking-tool/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Security Researchers Discover 4 Million Strong &#8216;Indestructible&#8217; Botnet &#8211; TDSS/TDL</title>
		<link>http://www.darknet.org.uk/2011/07/security-researchers-discover-4-million-strong-indestructible-botnet-tdsstdl/</link>
		<comments>http://www.darknet.org.uk/2011/07/security-researchers-discover-4-million-strong-indestructible-botnet-tdsstdl/#comments</comments>
		<pubDate>Mon, 04 Jul 2011 11:06:26 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[alureon]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[cast iron botnet]]></category>
		<category><![CDATA[huge botnet]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[tdl]]></category>
		<category><![CDATA[tdl botnet]]></category>
		<category><![CDATA[tdl malware]]></category>
		<category><![CDATA[tdl trojan]]></category>
		<category><![CDATA[tdl-4]]></category>
		<category><![CDATA[tdss]]></category>
		<category><![CDATA[trojans]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3141</guid>
		<description><![CDATA[It&#8217;s been recently uncovered that there&#8217;s a HUGE botnet, which is extremely advanced and constantly evolving a variant of the ever popular (and usually quite advanced) TDL strain. We did write about a TDL variant earlier in 2010 &#8211; TDL AKA Alureon Rootkit Now Infecting 64-Bit Windows 7 Platform. TDL itself has been around several [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been recently uncovered that there&#8217;s a HUGE botnet, which is extremely advanced and constantly evolving a variant of the ever popular (and usually quite advanced) <a href="http://www.darknet.org.uk/tag/tdl/">TDL</a> strain. We did write about a TDL variant earlier in 2010 &#8211; <a href="http://www.darknet.org.uk/2010/11/tdl-aka-alureon-rootkit-now-infecting-64-bit-windows-7-platform/">TDL AKA Alureon Rootkit Now Infecting 64-Bit Windows 7 Platform</a>.</p>
<p>TDL itself has been around several years, but the new TDSS variant is really sophisticated and comes loaded with anti-virus capabilities to stop the <a href="http://www.darknet.org.uk/tag/windows/">Windows</a> host PC getting infected by other malware or botmasters.</p>
<p>Development has been going on since TDL since 2008 (or perhaps even earlier) and now is on version 4 (TDL-4). You can see how these guys think as they only apportion a part of the CPU resources to their own <a href="http://www.darknet.org.uk/category/virustrojanswormsrootkits/">malware</a> so as to remain undercover.</p>
<blockquote><p>A new strain of the TDSS malware has been pegged as &#8220;the most sophisticated threat&#8221; to computer security in the world today by a Kaspersky Labs researcher and is being used to slave more than 4.5 million PCs in a massive botnet that&#8217;s equipped with an &#8220;anti-virus&#8221; to prevent other bot-creating viruses from taking it over.</p>
<p>&#8220;TDSS uses a range of methods to evade signature, heuristic, and proactive detection, and uses encryption to facilitate communication between its bots and the botnet command and control center,&#8221; security expert Sergey Golovanov writes this week a research note in on the SecureList site.</p>
<p>Botnets are networks of malware-infected computers that can be commanded by cybercriminals and hacktivists to conduct such activities as delivering spam, launching distributed denial-of-service attacks to bring down targeted websites, manipulating search results and adware, and facilitating network intrusions to steal sensitive data.</p>
<p>Sophisticated bot-creating programs like TDSS, which according to Golovanov has been under development since 2008 and is now in its fourth version (TDL-4), can harness a portion of the computing power of each system it infects, leaving owners of infected computers with somewhat slower machines but none the wiser as to their participation in a botnet.</p>
<p>There a few distinctive improvements in TDL-4 over previous TDSS generations, the Kaspersky Labs researcher writes. One is that the latest edition of TDSS includes a kind of &#8220;anti-virus&#8221; that scans a slave bot&#8217;s registry for malicious programs that could interfere with a slaved computer&#8217;s efficiency or even try to take over the computer to make it part of a rival botnet. </p></blockquote>
<p>Now this is a fairly huge operation with 4-5 million infected hosts within the <a href="http://www.darknet.org.uk/tag/botnet/">botnet</a>, it&#8217;s very difficult to remove and in most parts &#8211; because of it&#8217;s fairly intelligent design &#8211; it doesn&#8217;t even get spotted in the first place.</p>
<p>The downfall (if it really is) of such a complex piece of malware is that it&#8217;s more likely to have coding bugs/exploits contained in it&#8217;s own code &#8211; this is where security researchers can leverage their own hacking skills to gather more knowledge about the botnet.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>&#8220;TDSS contains code to remove approximately 20 malicious programs, including Gbot, ZeuS, Clishmic, Optima, etc.,&#8221; Golovanov writes. &#8220;TDSS scans the registry, searches for specific file names, blacklists the addresses of the command and control centers of other botnets and prevents victim machines from contacting them.</p>
<p>&#8220;This &#8216;antivirus&#8217; actually helps TDSS; on the one hand, it fights cybercrime competition, while on the other hand it protects TDSS and associated malware against undesirable interactions that could be caused by other malware on the infected machine.&#8221;</p>
<p>Another advance for TDL-4 is the extent to which it burrows into infected systems, making the botnets it creates &#8220;indestructible,&#8221; according to the researcher. Other improvements over the previous TDL-3 generation of TDSS malware include the encryption of communications between a botnet operator&#8217;s command-and-control servers and the botnet, and the ability to transmit commands to a botnet over the publicly accessible, peer-to-peer Kad network via TDL-4&#8242;s kad.dll module.</p>
<p>According to Golovanov, TDL &#8220;affiliates&#8221; can earn up to $200 when they manage 1,000 installations of the malware on victim computers.</p>
<p>&#8220;Affiliates can use any installation method they choose,&#8221; he writes. &#8220;Most often, TDL is planted on adult content sites, bootleg websites, and video and file storage services.&#8221;</p>
<p>About a third of the TDL-4-infected computers are in the U.S., according to Golovanov, and about 60 TDL-4 command-and-control centers all around the world have been identified since the beginning of 2011. </p></blockquote>
<p>Most of the motivation behind such large botnets is of course money, we&#8217;ve written before about the <a href="http://www.darknet.org.uk/2011/01/digital-underground-offering-cheap-botnets-for-hire/">Digital Underground Offering Cheap Botnets For Hire</a> and about people getting caught like &#8211; <a href="http://www.darknet.org.uk/2010/04/texas-man-pleads-guilty-to-bot-network-for-hire/">Texas Man Pleads Guilty To Bot Network For Hire</a>.</p>
<p>It seems like the main infection vector is still via the browser, people who visit dodgy sites (porn/pirated software etc) with old browsers are getting infected with botnet laden malware like this.</p>
<p>I doubt anyone reading is any danger of infection, but still &#8211; it pays to know what is out there.</p>
<p>Source: <a href="http://www.pcmag.com/article2/0,2817,2387891,00.asp">PC Mag</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Security+Researchers+Discover+4+Million+Strong+%E2%80%98Indestructible%E2%80%99+Botnet+%E2%80%93+TDSS%2FTDL+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3141+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/07/security-researchers-discover-4-million-strong-indestructible-botnet-tdsstdl/&amp;t=Security+Researchers+Discover+4+Million+Strong+%E2%80%98Indestructible%E2%80%99+Botnet+%E2%80%93+TDSS%2FTDL" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/07/security-researchers-discover-4-million-strong-indestructible-botnet-tdsstdl/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/07/security-researchers-discover-4-million-strong-indestructible-botnet-tdsstdl/&amp;title=Security+Researchers+Discover+4+Million+Strong+%E2%80%98Indestructible%E2%80%99+Botnet+%E2%80%93+TDSS%2FTDL" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/07/security-researchers-discover-4-million-strong-indestructible-botnet-tdsstdl/&amp;title=Security+Researchers+Discover+4+Million+Strong+%E2%80%98Indestructible%E2%80%99+Botnet+%E2%80%93+TDSS%2FTDL" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/07/security-researchers-discover-4-million-strong-indestructible-botnet-tdsstdl/&amp;title=Security+Researchers+Discover+4+Million+Strong+%E2%80%98Indestructible%E2%80%99+Botnet+%E2%80%93+TDSS%2FTDL" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/07/security-researchers-discover-4-million-strong-indestructible-botnet-tdsstdl/&amp;title=Security+Researchers+Discover+4+Million+Strong+%E2%80%98Indestructible%E2%80%99+Botnet+%E2%80%93+TDSS%2FTDL" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F07%2Fsecurity-researchers-discover-4-million-strong-indestructible-botnet-tdsstdl%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/07/security-researchers-discover-4-million-strong-indestructible-botnet-tdsstdl/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Microsoft Enhanced Mitigation Evaluation Toolkit (EMET)</title>
		<link>http://www.darknet.org.uk/2011/06/microsoft-enhanced-mitigation-evaluation-toolkit-emet/</link>
		<comments>http://www.darknet.org.uk/2011/06/microsoft-enhanced-mitigation-evaluation-toolkit-emet/#comments</comments>
		<pubDate>Wed, 01 Jun 2011 10:38:29 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[emet]]></category>
		<category><![CDATA[enhanced mitigiation evaluation toolkit]]></category>
		<category><![CDATA[hacking-windows]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft emet]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[microsoft-hacking]]></category>
		<category><![CDATA[security mitigation]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3113</guid>
		<description><![CDATA[The enhanced Mitigation Experience Toolkit (EMET) is designed to help prevent hackers from gaining access to your system. Software vulnerabilities and exploits have become an everyday part of life. Virtually every product has to deal with them and consequently, users are faced with a stream of security updates. For users who get attacked before the [...]]]></description>
			<content:encoded><![CDATA[<p>The enhanced Mitigation Experience Toolkit (EMET) is designed to help prevent hackers from gaining access to your system.</p>
<p>Software vulnerabilities and exploits have become an everyday part of life. Virtually every product has to deal with them and consequently, users are faced with a stream of security updates. For users who get attacked before the latest updates have been applied or who get attacked before an update is even available, the results can be devastating: malware, loss of PII, etc.</p>
<p>Security mitigation technologies are designed to make it more difficult for an attacker to exploit vulnerabilities in a given piece of software. EMET allows users to manage these technologies on their system and provides several unique benefits:</p>
<p><strong>1. No source code needed</strong>: Until now, several of the available mitigations (such as Data Execution Prevention) have required for an application to be manually opted in and recompiled. EMET changes this by allowing a user to opt in applications without recompilation. This is especially handy for deploying mitigations on software that was written before the mitigations were available and when source code is not available.</p>
<p><strong>2. Highly configurable:</strong> EMET provides a higher degree of granularity by allowing mitigations to be individually applied on a per process basis. There is no need to enable an entire product or suite of applications. This is helpful in situations where a process is not compatible with a particular mitigation technology. When that happens, a user can simply turn that mitigation off for that process.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<p><strong>3. Helps harden legacy applications:</strong> It’s not uncommon to have a hard dependency on old legacy software that cannot easily be rewritten and needs to be phased out slowly. Unfortunately, this can easily pose a security risk as legacy software is notorious for having security vulnerabilities. While the real solution to this is migrating away from the legacy software, EMET can help manage the risk while this is occurring by making it harder to hackers to exploit vulnerabilities in the legacy software.</p>
<p><strong>4. Ease of use:</strong> The policy for system wide mitigations can be seen and configured with EMET&#8217;s graphical user interface. There is no need to locate up and decipher registry keys or run platform dependent utilities. With EMET you can adjust setting with a single consistent interface regardless of the underlying platform.</p>
<p><strong>5. Ongoing improvement:</strong> EMET is a living tool designed to be updated as new mitigation technologies become available. This provides a chance for users to try out and benefit from cutting edge mitigations. The release cycle for EMET is also not tied to any product. EMET updates can be made dynamically as soon as new mitigations are ready</p>
<p>The toolkit includes several pseudo mitigation technologies aimed at disrupting current exploit techniques. These pseudo mitigations are not robust enough to stop future exploit techniques, but can help prevent users from being compromised by many of the exploits currently in use. The mitigations are also designed so that they can be easily updated as attackers start using new exploit techniques.</p>
<p>You can download EMET v2.1 here:</p>
<p><a href="http://www.microsoft.com/downloads/en/confirmation.aspx?FamilyID=e127dfaf-f8f3-4cd5-8b08-115192c491cb">EMET Setup.msi</a></p>
<p>Or read more <a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=e127dfaf-f8f3-4cd5-8b08-115192c491cb#QuickDetails">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Enhanced+Mitigation+Evaluation+Toolkit+%28EMET%29+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3113+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/06/microsoft-enhanced-mitigation-evaluation-toolkit-emet/&amp;t=Microsoft+Enhanced+Mitigation+Evaluation+Toolkit+%28EMET%29" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/06/microsoft-enhanced-mitigation-evaluation-toolkit-emet/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/06/microsoft-enhanced-mitigation-evaluation-toolkit-emet/&amp;title=Microsoft+Enhanced+Mitigation+Evaluation+Toolkit+%28EMET%29" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/06/microsoft-enhanced-mitigation-evaluation-toolkit-emet/&amp;title=Microsoft+Enhanced+Mitigation+Evaluation+Toolkit+%28EMET%29" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/06/microsoft-enhanced-mitigation-evaluation-toolkit-emet/&amp;title=Microsoft+Enhanced+Mitigation+Evaluation+Toolkit+%28EMET%29" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/06/microsoft-enhanced-mitigation-evaluation-toolkit-emet/&amp;title=Microsoft+Enhanced+Mitigation+Evaluation+Toolkit+%28EMET%29" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F06%2Fmicrosoft-enhanced-mitigation-evaluation-toolkit-emet%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/06/microsoft-enhanced-mitigation-evaluation-toolkit-emet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Implements Company Policy For Vulnerability Disclosure</title>
		<link>http://www.darknet.org.uk/2011/04/microsoft-implements-company-policy-for-vulnerability-disclosure/</link>
		<comments>http://www.darknet.org.uk/2011/04/microsoft-implements-company-policy-for-vulnerability-disclosure/#comments</comments>
		<pubDate>Wed, 20 Apr 2011 11:22:20 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[disclosure policy]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft disclosure policy]]></category>
		<category><![CDATA[microsoft employee]]></category>
		<category><![CDATA[microsoft employees]]></category>
		<category><![CDATA[microsoft vulnerability disclosure]]></category>
		<category><![CDATA[microsoft vulnerability disclosure policy]]></category>
		<category><![CDATA[vulnerability disclosure]]></category>
		<category><![CDATA[vulnerability disclosure policy]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3098</guid>
		<description><![CDATA[Microsoft has implemented a new company policy regarding vulnerability disclosure in non-Microsoft products (third-party products). Unsurprisingly they are following the &#8216;responsible disclosure&#8217; line rather than the &#8216;full disclosure&#8217; line favoured by the infosec community. It&#8217;s fair enough though, as they say treat others as you wish to be treated. I&#8217;m pretty sure Microsoft would much [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> has implemented a new company policy regarding vulnerability disclosure in non-Microsoft products (third-party products). Unsurprisingly they are following the &#8216;responsible disclosure&#8217; line rather than the &#8216;full disclosure&#8217; line favoured by the infosec community.</p>
<p>It&#8217;s fair enough though, as they say treat others as you wish to be treated. I&#8217;m pretty sure Microsoft would much prefer people to report vulnerabilities to them privately and give them adequate time to fix the problem before disclosing publicly.</p>
<p>If you really THAT interested, you can actually download the policy <a href="http://go.microsoft.com/?linkid=9770197">here</a> (MS Word).</p>
<blockquote><p>Microsoft has implemented a new company policy requiring all employees to follow a detailed set of procedures when reporting security vulnerabilities in third-party products.</p>
<p>The practices are an evolution of the coordinated vulnerability disclosure doctrine it proposed in July. They&#8217;re intended to simplify communication among affected parties and reduce the chances that vulnerability reports will result in it being exploited in the wild. Among other things, they require employees to send private notifications to the organization responsible for the vulnerable software, hardware or service and only later publish a public advisory.</p>
<p>“We&#8217;re definitely into the idea of no surprises for any of our vendors that we find vulnerabilities in,” said Microsoft Senior Security Strategist Katie Moussouris. “We&#8217;re basically following the golden rule for disclosure, and it&#8217;s all about protecting customers, because there&#8217;s no reason to unnecessarily amplify risk by imposing some sort of one-size-fits-all deadline on things.”</p>
<p>The policy (MS Word document here) applies to all Microsoft employees, whether they find vulnerabilities during their personal time or as part of their official duties. The procedures are intended to move away from the doctrine of “responsible disclosure,” which many people in security circles came to resent because it suggested all who disagreed with it were somehow behaving improperly.</p></blockquote>
<p>It&#8217;s interesting to see a company really showing the public at large how they intend to deal with finding vulnerabilities in other peoples software. Google has published a similar (but MUCH less detailed) policy regarding disclosure.</p>
<p><a href="http://www.darknet.org.uk/tag/google/">Google</a> will generally give 60 days before they publish a vulnerability publicly, a lot of people give up trying to contact vendors after a few bounced or unreplied e-mails and just post the details on mailing lists like Bugtraq or Full-disclosure.</p>
<p>What will be fascinating is to see what kind of vulnerabilities Microsoft will publish, it&#8217;ll give us some idea as to which products and what types of software they are looking at.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>Under the policy, Microsoft employees who discover vulnerabilities will report them privately to the third-party organizations responsible. Encrypted email is the favored medium, but only after the employee has identified the right third-party person to receive the report. The reports should include crash dump information, proofs of concept or exploit code, root cause analysis, and other technical details.</p>
<p>“Any vulnerability information provided to the vendor is not intended for public use, but for the vendor&#8217;s use to identify and remediate the vulnerability,” the policy states.</p>
<p>For the first time, Microsoft will begin publishing advisories about the vulnerabilities its employees have discovered – preferably only after the security hole has been patched. Microsoft may also issue advisories if it learns the bug is being exploited, or in cases where it receives no response from the third party.</p>
<p>The policy appears to be the first time a company has said publicly exactly when and how it will report vulnerabilities in the products of its peers, partners and competitors. In July, Google&#8217;s security team issued a less detailed policy that said members would generally give companies 60 days to patch vulnerabilities before making them known publicly.</p>
<p>Microsoft has yet to implement a bug-bounty program that compensates researchers for their time and expertise in reporting vulnerabilities in its products. Google and Mozilla have paid rewards for years. Security firm Tipping Point has pledged to make vulnerabilities public six months after reporting them privately.</p></blockquote>
<p>The focus for everyone seems to &#8216;protecting the end user&#8217; &#8211; why the shift in focus? I&#8217;m not entirely sure, but it&#8217;s not a bad thing.</p>
<p>You can read the Google Policy here:</p>
<p><a href="http://googleonlinesecurity.blogspot.com/2010/07/rebooting-responsible-disclosure-focus.html">Rebooting Responsible Disclosure: a focus on protecting end users</a></p>
<p>Perhaps Microsoft took a leaf from the Google book after all.</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/04/19/microsoft_vulnerability_disclosure_policy/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Implements+Company+Policy+For+Vulnerability+Disclosure+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3098+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/04/microsoft-implements-company-policy-for-vulnerability-disclosure/&amp;t=Microsoft+Implements+Company+Policy+For+Vulnerability+Disclosure" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/04/microsoft-implements-company-policy-for-vulnerability-disclosure/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/04/microsoft-implements-company-policy-for-vulnerability-disclosure/&amp;title=Microsoft+Implements+Company+Policy+For+Vulnerability+Disclosure" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/04/microsoft-implements-company-policy-for-vulnerability-disclosure/&amp;title=Microsoft+Implements+Company+Policy+For+Vulnerability+Disclosure" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/04/microsoft-implements-company-policy-for-vulnerability-disclosure/&amp;title=Microsoft+Implements+Company+Policy+For+Vulnerability+Disclosure" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/04/microsoft-implements-company-policy-for-vulnerability-disclosure/&amp;title=Microsoft+Implements+Company+Policy+For+Vulnerability+Disclosure" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F04%2Fmicrosoft-implements-company-policy-for-vulnerability-disclosure%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/04/microsoft-implements-company-policy-for-vulnerability-disclosure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Unleashes Record Breaking Patch Tuesday &#8211; April 2011</title>
		<link>http://www.darknet.org.uk/2011/04/microsoft-unleashes-record-breaking-patch-tuesday-april-2011/</link>
		<comments>http://www.darknet.org.uk/2011/04/microsoft-unleashes-record-breaking-patch-tuesday-april-2011/#comments</comments>
		<pubDate>Wed, 13 Apr 2011 10:19:28 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[april 2011 patch tuesday]]></category>
		<category><![CDATA[black tuesday]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft patch tuesday]]></category>
		<category><![CDATA[microsoft patches]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[patch-tuesday]]></category>
		<category><![CDATA[windows 0day]]></category>
		<category><![CDATA[windows zero day]]></category>
		<category><![CDATA[windows zeroday]]></category>
		<category><![CDATA[windows-exploits]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3091</guid>
		<description><![CDATA[We all love Patch Tuesday &#8211; no doubt about that right? Well Microsoft has blessed us this month with the biggest Patch Tuesday in the history of the program. That&#8217;s a good thing because it&#8217;s had some horribly effective vulnerabilities revealed lately. It managed to package up a massive bundle of patches for 64 vulnerabilities [...]]]></description>
			<content:encoded><![CDATA[<p>We all love <a href="http://www.darknet.org.uk/tag/patch-tuesday/">Patch Tuesday</a> &#8211; no doubt about that right? Well <a href="http://www.darknet.org.uk/tag/microsoft/">Microsoft</a> has blessed us this month with the biggest Patch Tuesday in the history of the program.</p>
<p>That&#8217;s a good thing because it&#8217;s had some horribly effective vulnerabilities revealed lately. It managed to package up a massive bundle of patches for 64 vulnerabilities in Windows, Office and a few other software packages.</p>
<p>So if you&#8217;re running any <a href="http://www.darknet.org.uk/tag/windows/">Windows</a> installations anywhere, make sure you get your Windows Update on ASAP and get those patches downloaded.</p>
<blockquote><p>Microsoft has patched a record 64 vulnerabilities in Windows, Office and five other software packages, many of which allowed attackers to remotely install malware on end user machines.</p>
<p>The most important fixes addressed a vulnerability in the Internet Explorer browser that was exploited in last month&#8217;s Pwn2Own contest. Although details were kept confidential, hackers have begun exploiting the critical flaw in real-world attacks, Microsoft warned. The use-after-free vulnerability affects versions 8 and earlier of the Microsoft browser.</p>
<p>The other top priority should be updates that patch critical vulnerabilities in the way Windows handles networking requests using the SMB, or Server Message Block, protocol. By sending malformed packets, attackers can remotely install malware on vulnerable machines with no user interaction required.</p>
<p>Researchers have warned that the flaw could be exploited to install self-replicating worms in much the way a similar vulnerability from 2008 did. Even after Microsoft issued an emergency patch for the flaw, it still opened the door to the Conficker Worm, which commandeered millions of machines.</p></blockquote>
<p>If you remember back in March we reported on <a href="http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/">Day One At Pwn2Own Takes Out Microsoft Internet Explorer and Apple Safari</a>, they&#8217;ve fixed that flaw &#8211; which has been exploited in the wild.</p>
<p>I think <a href="http://www.darknet.org.uk/tag/pwn2own/">Pwn2Own</a> does play an important role in the security industry and really helps get some nasty bugs patched up. Of course I don&#8217;t think any of us are using <a href="http://www.darknet.org.uk/tag/internet-explorer/">Internet Explorer</a> anyway&#8230;but still &#8211; a lot of people are.</p>
<p>Even on this site 18.3% of visitors are still using some version of IE (with the majority using 8, then 7 then 9 with 6 thankfully in 4th place).</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>The monster patch batch also included relief for another flaw in all supported versions of Windows that Google has said was being exploited by &#8220;politically motivated&#8221; attackers against activists. The MS11-026 update fixes the way Windows parses webpages containing MIME-formatted content.</p>
<p>Microsoft also introduced two tools that are designed to thwart malware attacks. One extends a protection known as Office File Validation to older versions of Office. The feature, which was previously available only to users of Office 2010, helps users to identify malicious Office files by scanning and validating them before they are opened.</p>
<p>The second tool is an update to the winload.exe component that helps flag device drivers that have been booby-trapped to install malware.</p>
<p>The patches were released in 17 bulletins, nine of which carried a rating of “critical,” a designation typically reserved for vulnerabilities that can be remotely exploited to install malware or expose sensitive user data. The remaining eight bulletins were rated “important.”</p></blockquote>
<p>If you just wanna get down to the details of the patches and what was released, you can read the summary from Microsoft here:</p>
<p><a href="http://blogs.technet.com/b/msrc/archive/2011/04/12/april-2011-security-bulletin-release.aspx">April 2011 Security Bulletin Release</a></p>
<p>Also check this out:</p>
<p><a href="http://blogs.technet.com/b/srd/archive/2011/04/12/assessing-the-risk-of-the-april-security-updates.aspx">Assessing the risk of the April security updates</a></p>
<p>And of course SANS always has a useful recap:</p>
<p><a href="http://isc.sans.edu/diary.html?storyid=10693">April 2011 Microsoft Black Tuesday Summary</a></p>
<p>Source: <a href="http://www.theregister.co.uk/2011/04/12/microsoft_patch_tuesday_april_2011/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+Unleashes+Record+Breaking+Patch+Tuesday+%E2%80%93+April+2011+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3091+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/04/microsoft-unleashes-record-breaking-patch-tuesday-april-2011/&amp;t=Microsoft+Unleashes+Record+Breaking+Patch+Tuesday+%E2%80%93+April+2011" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/04/microsoft-unleashes-record-breaking-patch-tuesday-april-2011/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/04/microsoft-unleashes-record-breaking-patch-tuesday-april-2011/&amp;title=Microsoft+Unleashes+Record+Breaking+Patch+Tuesday+%E2%80%93+April+2011" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/04/microsoft-unleashes-record-breaking-patch-tuesday-april-2011/&amp;title=Microsoft+Unleashes+Record+Breaking+Patch+Tuesday+%E2%80%93+April+2011" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/04/microsoft-unleashes-record-breaking-patch-tuesday-april-2011/&amp;title=Microsoft+Unleashes+Record+Breaking+Patch+Tuesday+%E2%80%93+April+2011" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/04/microsoft-unleashes-record-breaking-patch-tuesday-april-2011/&amp;title=Microsoft+Unleashes+Record+Breaking+Patch+Tuesday+%E2%80%93+April+2011" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F04%2Fmicrosoft-unleashes-record-breaking-patch-tuesday-april-2011%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/04/microsoft-unleashes-record-breaking-patch-tuesday-april-2011/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>RawCap &#8211; Free Command Line Packet/Network Sniffer For Windows (Raw Sockets)</title>
		<link>http://www.darknet.org.uk/2011/04/rawcap-free-command-line-packetnetwork-sniffer-for-windows-raw-sockets/</link>
		<comments>http://www.darknet.org.uk/2011/04/rawcap-free-command-line-packetnetwork-sniffer-for-windows-raw-sockets/#comments</comments>
		<pubDate>Tue, 12 Apr 2011 09:58:30 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Network Hacking]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[pcap]]></category>
		<category><![CDATA[raw sockets]]></category>
		<category><![CDATA[rawcap]]></category>
		<category><![CDATA[tcpcap]]></category>
		<category><![CDATA[wincap]]></category>
		<category><![CDATA[windows network sniffer]]></category>
		<category><![CDATA[windows packet sniffer]]></category>
		<category><![CDATA[winpcap]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3089</guid>
		<description><![CDATA[RawCap is a free command line network sniffer for Windows that uses raw sockets. Features Can sniff any interface that has got an IP address, including 127.0.0.1 (localhost/loopback) RawCap.exe is just 17 kB No external libraries or DLL&#8217;s needed other than .NET Framework 2.0 No installation required, just download RawCap.exe and sniff Can sniff most [...]]]></description>
			<content:encoded><![CDATA[<p>RawCap is a free command line network sniffer for Windows that uses raw sockets.</p>
<p><strong>Features</strong></p>
<ul>
<li>Can sniff any interface that has got an IP address, including 127.0.0.1 (localhost/loopback)</li>
<li>RawCap.exe is just 17 kB</li>
<li>No external libraries or DLL&#8217;s needed other than .NET Framework 2.0</li>
<li>No installation required, just download RawCap.exe and sniff</li>
<li>Can sniff most interface types, including WiFi and PPP interfaces</li>
<li>Minimal memory and CPU load</li>
<li>Reliable and simple to use</li>
</ul>
<p><strong>Raw sockets limitations in Vista and Win7</strong></p>
<p>Due to current limitations in the raw sockets implementations for Windows Vista and Windows 7 we suggest running RawCap on Windows XP. The main problem with raw socket sniffing in Vista and Win7 is that you might not receive either incoming packets (Win7) or outgoing packets (Vista). </p>
<p>You can download RawCap here:</p>
<p><a href="http://www.netresec.com/products/RawCap/RawCap.exe">RawCap.exe</a></p>
<p>Or read more <a href="http://www.netresec.com/?page=RawCap">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=RawCap+%E2%80%93+Free+Command+Line+Packet%2FNetwork+Sniffer+For+Windows+%28Raw+Sockets%29+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3089+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/04/rawcap-free-command-line-packetnetwork-sniffer-for-windows-raw-sockets/&amp;t=RawCap+%E2%80%93+Free+Command+Line+Packet%2FNetwork+Sniffer+For+Windows+%28Raw+Sockets%29" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/04/rawcap-free-command-line-packetnetwork-sniffer-for-windows-raw-sockets/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/04/rawcap-free-command-line-packetnetwork-sniffer-for-windows-raw-sockets/&amp;title=RawCap+%E2%80%93+Free+Command+Line+Packet%2FNetwork+Sniffer+For+Windows+%28Raw+Sockets%29" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/04/rawcap-free-command-line-packetnetwork-sniffer-for-windows-raw-sockets/&amp;title=RawCap+%E2%80%93+Free+Command+Line+Packet%2FNetwork+Sniffer+For+Windows+%28Raw+Sockets%29" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/04/rawcap-free-command-line-packetnetwork-sniffer-for-windows-raw-sockets/&amp;title=RawCap+%E2%80%93+Free+Command+Line+Packet%2FNetwork+Sniffer+For+Windows+%28Raw+Sockets%29" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/04/rawcap-free-command-line-packetnetwork-sniffer-for-windows-raw-sockets/&amp;title=RawCap+%E2%80%93+Free+Command+Line+Packet%2FNetwork+Sniffer+For+Windows+%28Raw+Sockets%29" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F04%2Frawcap-free-command-line-packetnetwork-sniffer-for-windows-raw-sockets%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/04/rawcap-free-command-line-packetnetwork-sniffer-for-windows-raw-sockets/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Day One At Pwn2Own Takes Out Microsoft Internet Explorer and Apple Safari</title>
		<link>http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/</link>
		<comments>http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/#comments</comments>
		<pubDate>Thu, 10 Mar 2011 09:39:01 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[chaouki bekrar]]></category>
		<category><![CDATA[charlie miller]]></category>
		<category><![CDATA[hacking apple]]></category>
		<category><![CDATA[hacking macbook]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[internet explorer hack]]></category>
		<category><![CDATA[internet-explorer]]></category>
		<category><![CDATA[pwn2own]]></category>
		<category><![CDATA[return oriented programming]]></category>
		<category><![CDATA[safari]]></category>
		<category><![CDATA[safari-exploit]]></category>
		<category><![CDATA[safari-security]]></category>
		<category><![CDATA[use-after-free flaw]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=3063</guid>
		<description><![CDATA[Well it&#8217;s March again and well we love March because it&#8217;s Pwn2Own time! Every year around this time we get some goodies to discuss way back since: 2008 &#8211; Mac owned on 2nd day of Pwn2Own hack contest 2009 &#8211; Charlie Miller Does It Again At PWN2OWN 2010 &#8211; Mozilla Beats Apple &#038; Microsoft to [...]]]></description>
			<content:encoded><![CDATA[<p>Well it&#8217;s March again and well we love March because it&#8217;s <a href="http://www.darknet.org.uk/tag/pwn2own/">Pwn2Own</a> time! Every year around this time we get some goodies to discuss way back since:</p>
<ul>
<li>2008 &#8211; <a href="http://www.darknet.org.uk/2008/03/mac-owned-on-2nd-day-of-pwn2own-hack-contest/">Mac owned on 2nd day of Pwn2Own hack contest</a></li>
<li>2009 &#8211; <a href="http://www.darknet.org.uk/2009/03/charlie-miller-does-it-again-at-pwn2own/">Charlie Miller Does It Again At PWN2OWN</a></li>
<li>2010 &#8211; <a href="http://www.darknet.org.uk/2010/04/mozilla-beats-apple-microsoft-to-pwn2own-patch-for-firefox/">Mozilla Beats Apple &#038; Microsoft to Pwn2Own Patch For Firefox</a></li>
</ul>
<p>It took Microsoft till June last year to fix the Pwn2Own bug &#8211; <a href="http://www.darknet.org.uk/2010/06/microsoft-patches-at-least-34-bugs-including-pwn2own-vulnerability/">Microsoft Patches At Least 34 Bugs Including Pwn2Own Vulnerability</a>.</p>
<p>This time both <a href="http://www.darknet.org.uk/tag/internet-explorer/">Internet Explorer</a> and <a href="http://www.darknet.org.uk/tag/safari/">Safari</a> fell on the first day! </p>
<blockquote><p>Contestants in a high-stakes hacking contest had no trouble toppling the Apple Safari and Microsoft Internet Explorer browsers, proving for a fifth year in a row that no software or application is safe from people with the expertise and motivation to exploit them.</p>
<p>The attacks came on Day One of the Pwn2Own contest, which pays more than $15,000 apiece for exploits that successfully give the attacker full remote access of the targeted machine. Wednesday&#8217;s event saw hackers take complete control of a fully patched Sony Vaio and MacBook Air by compromising IE and Safari respectively. Google&#8217;s Chrome browser was also up for grabs, but no one stepped forward to try hacking it.</p>
<p>“Every browser, every operating system, has its own vulnerabilities,” said Chaouki Bekrar, CEO of Vupen Security and the contestant who successfully hacked Safari. “This is what we wanted to demonstrate – that we can create a very reliable exploit for Apple Mac OS and Safari without even crashing the browser.”</p>
<p>Contest rules forbid him from disclosing most technical details behind the vulnerability, but he was permitted to say that it involved what&#8217;s known as a use-after-free flaw in the Apple browser. He said the exploit used a technique known as return-oriented programming to bypass a security protection known as data execution prevention that is built into many Apple programs.</p></blockquote>
<p>There have been a barrage of patches recently too with Microsoft patching some very serious bugs in the <a href="http://isc.sans.edu/diary.html?storyid=10510&#038;rss">March 2011 Black Tuesday</a>, <a href="http://www.networkworld.com/news/2011/030911-apple-patches-critical-mac-bugs.html?source=nww_rss">Apple patches critical Mac bugs with Java updates</a>, <a href="http://lists.apple.com/archives/security-announce/2011/Mar/msg00004.html">Apple patching 62 bugs in Safari</a> and Jon Oberheide killing his own <a href="http://www.darknet.org.uk/tag/internet-explorer/">Android</a> bug by <a href="http://www.theregister.co.uk/2011/03/07/android_pwn2own_bug_killed/">reporting it to Google</a>.</p>
<p>Also sadly one of the Pwn2Own champions <a href="http://www.darknet.org.uk/tag/geohot/">Geohot</a> wasn&#8217;t present most likely to to the <a href="http://www.darknet.org.uk/2011/01/happy-new-year-geohot-court-orders-seizure-of-ps3-hackers-computers/">shit storm Sony is throwing at him</a>.</p>
<p>It&#8217;ll be interesting to what else comes out of Pwn2Own this year.</p>
<p><div align="center"><script type="text/javascript"><!--
google_ad_client = "pub-3033787195489589";
/* Darknet-Body468 */
google_ad_slot = "1341243171";
google_ad_width = 468;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><br /></p>
<blockquote><p>After building the tools from scratch, it took him about two weeks to find the bug and set out to exploit it. The result was an attack that reliably commandeers a Mac when Safari visits a website that hosts the malicious code.</p>
<p>“Just after visiting the webpage with the affected version of Safari, we can, for example, launch the calculator or open a shell or do anything else we want,” he said a minute or two after demonstrating the exploit at the contest, which was attended by members of Apple&#8217;s security team. “We have the same privileges as the user who visited the webpage.”</p>
<p>He said users would have no way of knowing their machines have been compromised. There is no prompt asking for a password. The only way to thwart the attack is to run Safari from an account that has been configured to have limited privileges.</p>
<p>Under competition rules, contestants drew a lottery to determine who was the first to attempt hacking a particular browser. Once a browser was compromised, it was eliminated from the running. Both IE and Safari were hacked on the first try.</p>
<p>“I have an exploit all ready to go, and now it&#8217;s just sitting in my bag,” said Charlie Miller, a three-time Pwn2Own winner, shortly after Bekrar took this year&#8217;s prize. “You&#8217;d think Apple would be concerned about it.”</p>
<p>Miller said he&#8217;s had the working attack for more than nine months now. Even after Apple patched a whopping 62 Safari security bugs just hours before the contest started, Miller&#8217;s exploit still worked, he said.</p></blockquote>
<p><a href="http://www.darknet.org.uk/tag/charlie-miller/">Charlie Miller</a> has a working exploit sitting in his back too after Bekrar already took the prize. It seems like it&#8217;s really quite worth developing a reliable, working 0-day exploit for $15,000!</p>
<p>The new sandbox in IE got pwned pretty easily too, which shows..slapping on some tonka toy security controls isn&#8217;t ever going to stop a dedicated attacker. There was one contestant who stepped up to the plate to take down <a href="http://www.darknet.org.uk/tag/chrome/">Google&#8217;s Chrome</a>, but perhaps the exploit didn&#8217;t work as there&#8217;s no reports on that.</p>
<p>Day two of Pwn2Own will see attacks on Smart-phone platforms &#8211; Windows 7 Mobile, an iPhone 4, a BlackBerry Torch 9800, and a Nexus S running Google&#8217;s Android. There are multiple contestants signed up for each platform!</p>
<p>Source: <a href="http://www.theregister.co.uk/2011/03/10/apple_safari_ie_stomped/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D3063+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;t=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;title=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;title=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;title=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/&amp;title=Day+One+At+Pwn2Own+Takes+Out+Microsoft+Internet+Explorer+and+Apple+Safari" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2011%2F03%2Fday-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2011/03/day-one-at-pwn2own-takes-out-microsoft-internet-explorer-and-apple-safari/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

