<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; software-security</title>
	<atom:link href="http://www.darknet.org.uk/tag/software-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>ReFrameworker &#8211; General Purpose Framework Modifier</title>
		<link>http://www.darknet.org.uk/2010/04/reframeworker-general-purpose-framework-modifier/</link>
		<comments>http://www.darknet.org.uk/2010/04/reframeworker-general-purpose-framework-modifier/#comments</comments>
		<pubDate>Fri, 23 Apr 2010 09:57:04 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[binary tampering]]></category>
		<category><![CDATA[code injection]]></category>
		<category><![CDATA[disassemble]]></category>
		<category><![CDATA[framework modifier]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[managed code rootkits]]></category>
		<category><![CDATA[mcr]]></category>
		<category><![CDATA[modify binary]]></category>
		<category><![CDATA[reframeworker]]></category>
		<category><![CDATA[rootkits]]></category>
		<category><![CDATA[runtime manipulation]]></category>
		<category><![CDATA[runtime tweaking]]></category>
		<category><![CDATA[software-security]]></category>
		<category><![CDATA[virtual patching]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2676</guid>
		<description><![CDATA[ReFrameworker is a general purpose Framework modifier, used to reconstruct framework Runtimes by creating modified versions from the original implementation that was provided by the framework vendor. ReFrameworker performs the required steps of runtime manipulation by tampering with the binaries containing the framework&#8217;s classes, in order to produce modified binaries that can replace the original [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>ReFrameworker is a general purpose Framework modifier, used to reconstruct framework Runtimes by creating modified versions from the original implementation that was provided by the framework vendor. ReFrameworker performs the required steps of runtime manipulation by tampering with the binaries containing the framework&#8217;s classes, in order to produce modified binaries that can replace the original ones.</p>
<p>It was developed to experiment with and demonstrate deployment of MCR (Managed Code Rootkits) code into a given framework.</p>
<p><strong>Features</strong></p>
<ul>
<li>Performs all the required steps needed for modifying framework binaries (disassemble, code injection, reassemble, precompiled images cleaning, etc.)</li>
<li>Fast development and deployment of a modified behavior into a given framework</li>
<li>Auto generated deployers</li>
<li>Modules: a separation between general purpose &#8220;building blocks&#8221; that can be injected into any given binary, allowing the users to create small pieces of code that can be later combined to form a specific injection task.</li>
<li>Can be easily adapted to support multiple frameworks by minimal configuration (currently comes preconfigured for the .NET framework)</li>
<li>Comes with many &#8220;preconfigured&#8221; proof-of-concept attacks (implemented as modules) that demonstrate its usage that can be easily extended to perform many other things. </li>
</ul>
<p>ReFrameworker, as a general purpose framework modification tool, can be used in other contexts besides security such as customizing frameworks for performance tuning, Runtime tweaking, virtual patching, hardening, and probably other usages &#8211; It all depends on what it is instructed to do.</p>
<p>You can download ReFrameworker v1.1 here:</p>
<p>Software &#8211; <a href="http://www.appsec.co.il/system/files/ReFrameworker_V1.1.zip">ReFrameworker_V1.1.zip</a><br />
Source Code: <a href="http://www.appsec.co.il/system/files/ReFrameworker_V1.1_Source_Code.zip">ReFrameworker_V1.1_Source_Code.zip</a></p>
<p></p>
<p>Or read more <a href="http://www.appsec.co.il/Managed_Code_Rootkits">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=ReFrameworker+%E2%80%93+General+Purpose+Framework+Modifier+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2676+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2010/04/reframeworker-general-purpose-framework-modifier/&amp;t=ReFrameworker+%E2%80%93+General+Purpose+Framework+Modifier" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2010/04/reframeworker-general-purpose-framework-modifier/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2010/04/reframeworker-general-purpose-framework-modifier/&amp;title=ReFrameworker+%E2%80%93+General+Purpose+Framework+Modifier" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2010/04/reframeworker-general-purpose-framework-modifier/&amp;title=ReFrameworker+%E2%80%93+General+Purpose+Framework+Modifier" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2010/04/reframeworker-general-purpose-framework-modifier/&amp;title=ReFrameworker+%E2%80%93+General+Purpose+Framework+Modifier" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2010/04/reframeworker-general-purpose-framework-modifier/&amp;title=ReFrameworker+%E2%80%93+General+Purpose+Framework+Modifier" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2010%2F04%2Freframeworker-general-purpose-framework-modifier%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2010/04/reframeworker-general-purpose-framework-modifier/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft CAT.NET v1.1.1.9 &#8211; Binary Code Analysis Tool .NET</title>
		<link>http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/</link>
		<comments>http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/#comments</comments>
		<pubDate>Mon, 14 Dec 2009 09:39:16 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[.net auditing tool]]></category>
		<category><![CDATA[.net security]]></category>
		<category><![CDATA[application-security]]></category>
		<category><![CDATA[binary code analysis]]></category>
		<category><![CDATA[binary-analysis]]></category>
		<category><![CDATA[cat.net]]></category>
		<category><![CDATA[code-auditing]]></category>
		<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[cross-site-scripting]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[software-security]]></category>
		<category><![CDATA[source code auditing tool]]></category>
		<category><![CDATA[sql-injection]]></category>
		<category><![CDATA[static analysis]]></category>
		<category><![CDATA[visual studio ide]]></category>
		<category><![CDATA[Visual-Studio]]></category>
		<category><![CDATA[windows-security]]></category>
		<category><![CDATA[xpath injection]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=2321</guid>
		<description><![CDATA[CAT.NET is a binary code analysis tool that helps identify common variants of certain prevailing vulnerabilities that can give rise to common attack vectors such as Cross-Site Scripting (XSS), SQL Injection and XPath Injection. CAT.NET is a snap-in to the Visual Studio IDE that helps you identify security flaws within a managed code (C#, Visual [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>CAT.NET is a binary code analysis tool that helps identify common variants of certain prevailing vulnerabilities that can give rise to common attack vectors such as Cross-Site Scripting (XSS), SQL Injection and XPath Injection.</p>
<p>CAT.NET is a snap-in to the Visual Studio IDE that helps you identify security flaws within a managed code (C#, Visual Basic .NET, J#) application you are developing. It does so by scanning the binary and/or assembly of the application, and tracing the data flow among its statements, methods, and assemblies.</p>
<p>This includes indirect data types such as property assignments and instance tainting operations. The engine works by reading the target assembly and all reference assemblies used in the application — module-by-module — and then analyzing all of the methods contained within each. It finally displays the issues its finds in a list that you can use to jump directly to the places in your application’s source code where those issues were found.</p>
<p>The following rules are currently support by this version of the tool</p>
<ul>
<li>Cross Site Scripting</li>
<li>SQL Injection</li>
<li>Process Command Injection</li>
<li>File Canonicalization</li>
<li>Exception Information</li>
<li>LDAP Injection</li>
<li>XPATH Injection</li>
<li>Redirection to User Controlled Site</li>
</ul>
<p><strong>System Requirements</strong></p>
<p>Supported Operating Systems: Windows Vista; Windows XP</p>
<p>OS: XP, Vista Software: .NET Framework 2.0, Visual Studio 2005 or 2008. </p>
<p>You can download CAT.NET here:</p>
<p><a href="http://www.microsoft.com/downloads/info.aspx?na=90&#038;p=&#038;SrcDisplayLang=en&#038;SrcCategoryId=&#038;SrcFamilyId=0178e2ef-9da8-445e-9348-c93f24cc9f9d&#038;u=http%3a%2f%2fdownload.microsoft.com%2fdownload%2f3%2f3%2f4%2f334E8A84-0F1B-4E3C-AF5F-99DA8AE0601F%2fCATNETx32.msi">CATNETx32.msi</a></p>
<p></p>
<p>Or read more <a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=0178e2ef-9da8-445e-9348-c93f24cc9f9d&#038;displaylang=en">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D2321+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;t=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/&amp;title=Microsoft+CAT.NET+v1.1.1.9+%E2%80%93+Binary+Code+Analysis+Tool+.NET" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F12%2Fmicrosoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/12/microsoft-cat-net-v1-1-1-9-binary-code-analysis-tool-net/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>fm-fsf &#8211; Freakin&#8217; Simple Fuzzer &#8211; Cross Platform Fuzzing Tool</title>
		<link>http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/</link>
		<comments>http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/#comments</comments>
		<pubDate>Wed, 17 Jun 2009 09:39:42 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Hacking Tools]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[.NET]]></category>
		<category><![CDATA[application hacking]]></category>
		<category><![CDATA[application-security]]></category>
		<category><![CDATA[data scraper]]></category>
		<category><![CDATA[ferruh mavituna]]></category>
		<category><![CDATA[fm-fsf]]></category>
		<category><![CDATA[freakin simple fuzzer]]></category>
		<category><![CDATA[fuzzer]]></category>
		<category><![CDATA[fuzzing tools]]></category>
		<category><![CDATA[fuzzing-tool]]></category>
		<category><![CDATA[hacking-software]]></category>
		<category><![CDATA[mono]]></category>
		<category><![CDATA[personal software security]]></category>
		<category><![CDATA[software-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1855</guid>
		<description><![CDATA[fm-fsf is a new fuzzer/data scraper that works under OSX, Linux (with Mono) and Windows (.NET Framework). Fuzzing tools are always useful if you are looking at discovering some new flaws in a software or web service. Quick Info FSF is a plug-in based freakin&#8217; simple fuzzer for fuzzing web applications and scraping data. It [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>fm-fsf is a new fuzzer/data scraper that works under OSX, Linux (with Mono) and Windows (.NET Framework). <a href="http://www.darknet.org.uk/tag/fuzzing-tool/">Fuzzing tools</a> are always useful if you are looking at discovering some new flaws in a software or web service.</p>
<p><strong>Quick Info</strong></p>
<p>FSF is a plug-in based freakin&#8217; simple fuzzer for fuzzing web applications and scraping data. </p>
<p>It supports some basic stuff and is missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.</p>
<p>It&#8217;s still in early stage of development so don&#8217;t expect too much.</p>
<p><strong>Why bring yet another fuzzer into this cruel world?</strong></p>
<p>The author was trying to fuzz something and after spending about 2-3 hours about 3-4 different terribly designed fuzzers he thought knocking up his own would be better.</p>
<p><strong>Don&#8217;t use if you&#8230;.</strong></p>
<ul>
<li>Want a fuzzer where you can control the raw HTTP request</li>
<li>Need some crazy features such as fuzzing multiple locations at a time </li>
</ul>
<p><strong>Use if you need a fuzzer&#8230;</strong></p>
<ul>
<li>That allows to take advantage of RegEx with the full power for scraping data (this is quite useful while exploiting SQL Injections, gathering data, looking for some hidden resource or trying to enumerate all valid &#8220;user id&#8221;s)</li>
<li>Simple to run and easy to use</li>
<li>Which makes it easy to write your own fuzzing modules</li>
<li>With simple and compact .NET code </li>
</ul>
<p>You can download fm-fsf here:</p>
<p><a href="http://fm-fsf.googlecode.com/files/FSF-7.1.0.0.tar.gz">FSF-7.1.0.0.tar.gz</a></p>
<p></p>
<p>Or read more <a href="http://code.google.com/p/fm-fsf/">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=fm-fsf+%E2%80%93+Freakin%E2%80%99+Simple+Fuzzer+%E2%80%93+Cross+Platform+Fuzzing+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1855+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/&amp;t=fm-fsf+%E2%80%93+Freakin%E2%80%99+Simple+Fuzzer+%E2%80%93+Cross+Platform+Fuzzing+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/&amp;title=fm-fsf+%E2%80%93+Freakin%E2%80%99+Simple+Fuzzer+%E2%80%93+Cross+Platform+Fuzzing+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/&amp;title=fm-fsf+%E2%80%93+Freakin%E2%80%99+Simple+Fuzzer+%E2%80%93+Cross+Platform+Fuzzing+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/&amp;title=fm-fsf+%E2%80%93+Freakin%E2%80%99+Simple+Fuzzer+%E2%80%93+Cross+Platform+Fuzzing+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/&amp;title=fm-fsf+%E2%80%93+Freakin%E2%80%99+Simple+Fuzzer+%E2%80%93+Cross+Platform+Fuzzing+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F06%2Ffm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/06/fm-fsf-freakin-simple-fuzzer-cross-platform-fuzzing-tool/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Releases New Browser Chrome &#8211; Vulnerabilities on First Day</title>
		<link>http://www.darknet.org.uk/2008/09/google-releases-new-browser-chrome-vulnerabilities-on-first-day/</link>
		<comments>http://www.darknet.org.uk/2008/09/google-releases-new-browser-chrome-vulnerabilities-on-first-day/#comments</comments>
		<pubDate>Tue, 09 Sep 2008 04:00:17 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[browser-exploit]]></category>
		<category><![CDATA[browser-security]]></category>
		<category><![CDATA[chrome browser]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[google chrome]]></category>
		<category><![CDATA[google chrome exploit]]></category>
		<category><![CDATA[google chrome security]]></category>
		<category><![CDATA[google chrome vulnerability]]></category>
		<category><![CDATA[hacking google chrome]]></category>
		<category><![CDATA[software-security]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1039</guid>
		<description><![CDATA[So as most of you probably know the big buzz on the Internet last week was that Google (after supporting Firefox for so long) have actually launched their own browser. It&#8217;s cooled Google Chrome. Now of course in typical Google fashion they call it BETA software, and a number of flaws have popped up during [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>So as most of you probably know the big buzz on the Internet last week was that Google (after supporting Firefox for so long) have actually launched their own browser.</p>
<p>It&#8217;s cooled <a href="http://www.google.com/chrome">Google Chrome</a>. Now of course in typical Google fashion they call it BETA software, and a number of flaws have popped up during the first couple of days of release.</p>
<p>One cool thing though is that each tab runs it&#8217;s own threaded process, so if one tab bombs out it won&#8217;t take down your whole browser.</p>
<p>The browser is a move for Google into the online/offline integration they started with <a href="http://www.darknet.org.uk/tag/google-desktop/">Google Desktop</a>, there are more and more online apps (Google Office) that people still want to use offline with a Google made browser this will be possible.</p>
<p>You also have to consider the privacy implications though, if you are also using Gmail&#8230;Google will basically know everything you do, even worse if you also use Google Desktop they will know what you have on your computer, what e-mail you send and receive and what you surf on the web.</p>
<p>The <a href="http://valleywag.com/5046665/german-government-tells-citizens-not-to-use-google-chrome">German Government has come out and told its citzens NOT to use Google Chrome</a>.</p>
<p>There have been a few flaws released since Chrome came out such as a <a href="http://blogs.zdnet.com/security/?p=1843">carpet bombing flaw</a>:</p>
<blockquote><p>Google’s shiny new Web browser is vulnerable to a carpet-bombing vulnerability that could expose Windows users to malicious hacker attacks.</p>
<p>Just hours after the release of Google Chrome, researcher Aviv Raff discovered that he could combine two vulnerabilities — a flaw in Apple Safari (WebKit) and a Java bug discussed at this year’s Black Hat conference — to trick users into launching executables direct from the new browser.</p></blockquote>
<p>The PoC is here: <a href="http://raffon.net/research/google/chrome/carpet.html">http://raffon.net/research/google/chrome/carpet.html</a></p>
<p>Another is a crash in chrome.dlll.</p>
<blockquote><p>An issue exists in how chrome behaves with undefined-handlers in chrome.dll version 0.2.149.27. A crash can result without user interaction. When a user is made to visit a malicious link, which has an undefined handler followed by a &#8216;special&#8217; character, the chrome crashes with a Google Chrome message window &#8220;Whoa! Google Chrome has crashed. Restart now?&#8221;. It fails in dealing with the POP EBP instruction when pointed out by the EIP register at 0x01002FF4.</p></blockquote>
<p>The PoC is here: <a href="http://evilfingers.com/advisory/google_chrome_poc.php">http://evilfingers.com/advisory/google_chrome_poc.php</a></p>
<p>And a few people have also been complaining that it allows auto-download of executable without a user prompt.</p>
<p></p>
<p>We will be keeping an eye on Google Chrome.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Google+Releases+New+Browser+Chrome+%E2%80%93+Vulnerabilities+on+First+Day+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1039+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/09/google-releases-new-browser-chrome-vulnerabilities-on-first-day/&amp;t=Google+Releases+New+Browser+Chrome+%E2%80%93+Vulnerabilities+on+First+Day" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/09/google-releases-new-browser-chrome-vulnerabilities-on-first-day/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/09/google-releases-new-browser-chrome-vulnerabilities-on-first-day/&amp;title=Google+Releases+New+Browser+Chrome+%E2%80%93+Vulnerabilities+on+First+Day" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/09/google-releases-new-browser-chrome-vulnerabilities-on-first-day/&amp;title=Google+Releases+New+Browser+Chrome+%E2%80%93+Vulnerabilities+on+First+Day" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/09/google-releases-new-browser-chrome-vulnerabilities-on-first-day/&amp;title=Google+Releases+New+Browser+Chrome+%E2%80%93+Vulnerabilities+on+First+Day" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/09/google-releases-new-browser-chrome-vulnerabilities-on-first-day/&amp;title=Google+Releases+New+Browser+Chrome+%E2%80%93+Vulnerabilities+on+First+Day" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F09%2Fgoogle-releases-new-browser-chrome-vulnerabilities-on-first-day%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/09/google-releases-new-browser-chrome-vulnerabilities-on-first-day/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>SCARE &#8211; Source Code Analysis Risk Evaluation Tool</title>
		<link>http://www.darknet.org.uk/2008/02/scare-source-code-analysis-risk-evaluation-tool/</link>
		<comments>http://www.darknet.org.uk/2008/02/scare-source-code-analysis-risk-evaluation-tool/#comments</comments>
		<pubDate>Fri, 29 Feb 2008 04:22:34 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[code auditing tool]]></category>
		<category><![CDATA[code-auditing]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[risk evaluation]]></category>
		<category><![CDATA[scare]]></category>
		<category><![CDATA[software-security]]></category>
		<category><![CDATA[source code auditing]]></category>
		<category><![CDATA[source-code-analysis]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2008/02/scare-source-code-analysis-risk-evaluation-tool/</guid>
		<description><![CDATA[The Source Code Analysis Risk Evaluation project is a study to create a security complexity metric that will analyze source code and provide a realistic and factual representation of the potential of that source code to create a problematic binary. This metric will not say that the binary will be exploited nor does it do [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>The Source Code Analysis Risk Evaluation project is a study to create a security complexity metric that will analyze source code and provide a realistic and factual representation of the potential of that source code to create a problematic binary. This metric will not say that the binary will be exploited nor does it do a static analysis for known limitations like vulnerabilities. However it will flag code for a particular interaction type or control and allow the developer to understand which Operational Security (OpSec) holes are not protected even if it can&#8217;t say the effectiveness of that protection at this time.</p>
<p>This computation will provide a final SCARE value, like the RAV, where 100% is the proper balance between controls to OpSec holes and no Limitations. Conversely, less than that shows an imbalance where too few Controls protect OpSec holes or Limitations in OpSec and Controls degrade the security.</p>
<p>The SCARE analysis tool is run against source code.  Currently only C code is supported.  The output file will contain all operational interactions possible which need controls (the current version does not yet say if and what controls are already there).  At the bottom of the list are three numbers: Visibilities, Access, and Trusts.  These 3 numbers can be plugged into the RAV Calculation spreadsheet available at <a href="http://www.isecom.org/ravs">http://www.isecom.org/ravs</a>.  The Delta value is then subtracted from 100 to give the SCARE percentage which indicates the complexity for securing this particular application.  The lower the value, the worse the SCARE.</p>
<p>At this stage, the tool cannot yet tell which interactions have controls already or if those controls are applicable however once that is available it will change the RAV but not the SCARE.  The SCARE will also not yet tell you where the bugs are in the code however if you are bug hunting, it will extract all the places where user inputs and trusts with user-accessible resources can be found in the code.</p>
<p>Currently, SCARE is designed to work for any programming language. While this methodology shows the C language, they need input and feedback from developers of other languages to expand this further.</p>
<p>If you are interested in helping with this project please <a href="http://www.isecom.org/contact.shtml">contact ISECOM</a>.</p>
<p>You can download SCARE here:</p>
<p><a href="http://www.isecom.info/mirror/scare_analyst.zip">scare_analyst.zip</a></p>
<p></p>
<p>Or you can read more <a href="http://www.isecom.org/scare">here</a>.</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=SCARE+%E2%80%93+Source+Code+Analysis+Risk+Evaluation+Tool+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D756+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/02/scare-source-code-analysis-risk-evaluation-tool/&amp;t=SCARE+%E2%80%93+Source+Code+Analysis+Risk+Evaluation+Tool" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/02/scare-source-code-analysis-risk-evaluation-tool/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/02/scare-source-code-analysis-risk-evaluation-tool/&amp;title=SCARE+%E2%80%93+Source+Code+Analysis+Risk+Evaluation+Tool" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/02/scare-source-code-analysis-risk-evaluation-tool/&amp;title=SCARE+%E2%80%93+Source+Code+Analysis+Risk+Evaluation+Tool" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/02/scare-source-code-analysis-risk-evaluation-tool/&amp;title=SCARE+%E2%80%93+Source+Code+Analysis+Risk+Evaluation+Tool" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/02/scare-source-code-analysis-risk-evaluation-tool/&amp;title=SCARE+%E2%80%93+Source+Code+Analysis+Risk+Evaluation+Tool" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F02%2Fscare-source-code-analysis-risk-evaluation-tool%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/02/scare-source-code-analysis-risk-evaluation-tool/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Data Leakage Bug in Mozilla Firefox Confirmed</title>
		<link>http://www.darknet.org.uk/2008/01/data-leakage-bug-in-mozilla-firefox-confirmed/</link>
		<comments>http://www.darknet.org.uk/2008/01/data-leakage-bug-in-mozilla-firefox-confirmed/#comments</comments>
		<pubDate>Mon, 28 Jan 2008 09:54:30 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firefox exploit]]></category>
		<category><![CDATA[firefox-vulnerability]]></category>
		<category><![CDATA[hacking-firefox]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[mozilla firefox]]></category>
		<category><![CDATA[software-security]]></category>
		<category><![CDATA[web-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2008/01/data-leakage-bug-in-mozilla-firefox-confirmed/</guid>
		<description><![CDATA[It seems a data leakage bug has struck Firefox recently and has been confirmed by Window Snyder the security bod at Mozilla. It&#8217;s basically a Chrome directory traversal bug (It seems a lot of the Firefox issues have had to do with chrome?). It&#8217;s rated as low risk, but it can give away the existence [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It seems a data leakage bug has struck Firefox recently and has been <a href="http://blog.mozilla.com/security/2008/01/22/chrome-protocol-directory-traversal/">confirmed by Window Snyder</a> the security bod at Mozilla.</p>
<p>It&#8217;s basically a Chrome directory traversal bug (It seems a lot of the Firefox issues have had to do with chrome?).</p>
<p>It&#8217;s rated as low risk, but it can give away the existence of files (if the attacker knows the name and location).</p>
<blockquote><p>The bug resides in Firefox&#8217;s chrome protocol scheme and allows for a directory traversal when certain types of extensions are installed. Attackers could use it to detect if certain programs or files are present on a machine, gaining information to use in perpetrating another, more malicious exploit.</p>
<p>Normally, Firefox&#8217;s chrome package is restricted to a limited number of directories, but a bug in the way it handles escaped sequences (i.e. %2e%2e%2f) allows attackers to escape those confines and access more sensitive parts of a user&#8217;s computer. The exploit only works if a user has made use of Firefox extensions that are &#8220;flat,&#8221; this is, those that don&#8217;t package their files in a jar archive. Examples of flat add-ons include Download Statusbar and Greasemonkey.</p></blockquote>
<p>You can protect yourself by using <a href="http://noscript.net/">NoScript</a>, which I would guess most of you guys are using already.</p>
<p>The open bug can be found <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=413250">here</a>.</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2008/01/24/firefox_data_leakage_bug/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Data+Leakage+Bug+in+Mozilla+Firefox+Confirmed+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D793+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2008/01/data-leakage-bug-in-mozilla-firefox-confirmed/&amp;t=Data+Leakage+Bug+in+Mozilla+Firefox+Confirmed" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2008/01/data-leakage-bug-in-mozilla-firefox-confirmed/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2008/01/data-leakage-bug-in-mozilla-firefox-confirmed/&amp;title=Data+Leakage+Bug+in+Mozilla+Firefox+Confirmed" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2008/01/data-leakage-bug-in-mozilla-firefox-confirmed/&amp;title=Data+Leakage+Bug+in+Mozilla+Firefox+Confirmed" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2008/01/data-leakage-bug-in-mozilla-firefox-confirmed/&amp;title=Data+Leakage+Bug+in+Mozilla+Firefox+Confirmed" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2008/01/data-leakage-bug-in-mozilla-firefox-confirmed/&amp;title=Data+Leakage+Bug+in+Mozilla+Firefox+Confirmed" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2008%2F01%2Fdata-leakage-bug-in-mozilla-firefox-confirmed%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2008/01/data-leakage-bug-in-mozilla-firefox-confirmed/feed/</wfw:commentRss>
		<slash:comments>24</slash:comments>
		</item>
		<item>
		<title>Firefox Patches 8 Security Vulnerabilities with 2.0.0.1</title>
		<link>http://www.darknet.org.uk/2006/12/firefox-patches-8-security-vulnerabilities-with-2001/</link>
		<comments>http://www.darknet.org.uk/2006/12/firefox-patches-8-security-vulnerabilities-with-2001/#comments</comments>
		<pubDate>Wed, 27 Dec 2006 02:56:33 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Exploits/Vulnerabilities]]></category>
		<category><![CDATA[Web Hacking]]></category>
		<category><![CDATA[browser-security]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[firefox-2.0.0.1]]></category>
		<category><![CDATA[firefox-release]]></category>
		<category><![CDATA[firefox-security]]></category>
		<category><![CDATA[firefox-vulnerability]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[software-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/12/firefox-patches-8-security-vulnerabilities-with-2001/</guid>
		<description><![CDATA[Grab the new Firefox now, 2.0.0.1! 8 Security Vulnerabilities have been fixed in this last release of the year 2006. I&#8217;m glad to see Firefox upholding their quick turnaround and rapid fixing of issues that spring up during development and improvement of their product. Mozilla has released the first update for the Firefox 2.0 browser [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Grab the new Firefox now, 2.0.0.1! 8 Security Vulnerabilities have been fixed in this last release of the year 2006.</p>
<p>I&#8217;m glad to see Firefox upholding their quick turnaround and rapid fixing of issues that spring up during development and improvement of their product.</p>
<blockquote><p>Mozilla has released the first update for the Firefox 2.0 browser to fix eight security vulnerabilities.</p>
<p>According to the company, release 2.0.0.1 of Firefox fixes flaws in memory corruption as well as the way the browser executes RSS (really simple syndication), Javascript and CSS (cascading style sheets) code, among other vulnerabilities. Mozilla also patched similar flaws in its Firefox 1.5 browser.</p>
<p>Five of the eight flaws were rated as critical, according to Firefox. A critical rating means a Firefox user would be vulnerable to attack and remote software installation on their machines just from browsing the Web in the usual fashion. Two of the flaws were rated as high, while one received a low security-risk rating, Firefox said.</p></blockquote>
<p>Mozilla&#8217;s advisory and information on the update can be found on the company&#8217;s <a href="http://www.mozilla.org/projects/security/known-vulnerabilities.html">Web site</a>.</p>
<p>Danish security firm Secunia ApS also posted information about the patches on its <a href="http://secunia.com/advisories/23282/">Web site</a>.</p>
<p></p>
<p>Source: <a href="http://www.infoworld.com/article/06/12/19/HNfirefox2.0fix_1.html">Infoworld</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Firefox+Patches+8+Security+Vulnerabilities+with+2.0.0.1+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D431+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/12/firefox-patches-8-security-vulnerabilities-with-2001/&amp;t=Firefox+Patches+8+Security+Vulnerabilities+with+2.0.0.1" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/12/firefox-patches-8-security-vulnerabilities-with-2001/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/12/firefox-patches-8-security-vulnerabilities-with-2001/&amp;title=Firefox+Patches+8+Security+Vulnerabilities+with+2.0.0.1" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/12/firefox-patches-8-security-vulnerabilities-with-2001/&amp;title=Firefox+Patches+8+Security+Vulnerabilities+with+2.0.0.1" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/12/firefox-patches-8-security-vulnerabilities-with-2001/&amp;title=Firefox+Patches+8+Security+Vulnerabilities+with+2.0.0.1" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/12/firefox-patches-8-security-vulnerabilities-with-2001/&amp;title=Firefox+Patches+8+Security+Vulnerabilities+with+2.0.0.1" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F12%2Ffirefox-patches-8-security-vulnerabilities-with-2001%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/12/firefox-patches-8-security-vulnerabilities-with-2001/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla Hires Ex-Microsoft Security Strategist Window Snyder</title>
		<link>http://www.darknet.org.uk/2006/10/mozilla-hires-ex-microsoft-security-strategist-window-snyder/</link>
		<comments>http://www.darknet.org.uk/2006/10/mozilla-hires-ex-microsoft-security-strategist-window-snyder/#comments</comments>
		<pubDate>Wed, 18 Oct 2006 08:31:57 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Information-Security]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[microsoft-hacker]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[mozzila-foundation]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[software-security]]></category>
		<category><![CDATA[window-snyder]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/10/mozilla-hires-ex-microsoft-security-strategist-window-snyder/</guid>
		<description><![CDATA[Looks like Mozilla is toughening it&#8217;s stance on security, people have been putting it down lately, especially those from the Microsoft camp as there have been a few flaws. But well, it&#8217;s still not part of the operating system, the flaws are generally fixed within a couple of days and the patching system is simple [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Looks like Mozilla is toughening it&#8217;s stance on security, people have been putting it down lately, especially those from the Microsoft camp as there have been a few flaws.</p>
<p>But well, it&#8217;s still not part of the operating system, the flaws are generally fixed within a couple of days and the patching system is simple and bandwidth friendly since version 1.5.0.1.</p>
<p>I generally find it more effecient, better designed, more secure and less proprietary :P than Internet Exploder.</p>
<p>Anyway back on topic..</p>
<blockquote><p> Former Microsoft security strategist Window Snyder is joining Mozilla to lead the company&#8217;s effort to protect its range of desktop applications from malicious hacker attacks.</p>
<p>Snyder, who was responsible for security sign-off for Microsoft&#8217;s Windows XP Service Pack 2 and Windows Server 2003, will spearhead Mozilla&#8217;s security strategy, eWEEK has learned.</p>
<p>The hiring of Snyder is a coup for Mozilla Corp., the for-profit subsidiary of the Mozilla Foundation, based in Mountain View, Calif.</p>
<p>The group has seen its flagship Firefox Web browser chip away at the market dominance of Microsoft&#8217;s Internet Explorer, largely because of high-profile security flaws in and attacks on IE, and the addition of Snyder is sure to help beef up Mozilla&#8217;s security process and improve its communications with bug finders. </p></blockquote>
<p>Sounds like a very good idea to me, with a proper security stance and process in place Firefox will become a market dominating product, it&#8217;s already fantastic, now it&#8217;s getting more money and skills injected, it&#8217;s evolving faster and smoother than ever.</p>
<blockquote><p>Snyder most recently served as principal and founder of Matasano Security, a New York-based startup that was one of several external penetration testers hired by Microsoft to conduct simulated hacking attacks on Windows Vista.</p>
<p>She is also credited with seeding the idea for Microsoft&#8217;s internal &#8220;Blue Hat&#8221; security briefings, in which the crÃ¨me de la crÃ¨me of the hacking community is invited to the company&#8217;s Redmond, Wash., headquarters to discuss security with employees.</p>
<p>Snyder, a regular at security conferences, helped to soothe Microsoft&#8217;s contentious relationship with security consultants, and played a part in the improvement of the software maker&#8217;s strategy for reaching out to security vendors and researchers. </p></blockquote>
<p>She was HITB conference this year I think if anyone was there, she&#8217;s quite cute too :P</p>
<p></p>
<p>Source: <a href="http://www.eweek.com/article2/0,1895,2012804,00.asp">eWeek</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Mozilla+Hires+Ex-Microsoft+Security+Strategist+Window+Snyder+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D339+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/10/mozilla-hires-ex-microsoft-security-strategist-window-snyder/&amp;t=Mozilla+Hires+Ex-Microsoft+Security+Strategist+Window+Snyder" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/10/mozilla-hires-ex-microsoft-security-strategist-window-snyder/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/10/mozilla-hires-ex-microsoft-security-strategist-window-snyder/&amp;title=Mozilla+Hires+Ex-Microsoft+Security+Strategist+Window+Snyder" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/10/mozilla-hires-ex-microsoft-security-strategist-window-snyder/&amp;title=Mozilla+Hires+Ex-Microsoft+Security+Strategist+Window+Snyder" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/10/mozilla-hires-ex-microsoft-security-strategist-window-snyder/&amp;title=Mozilla+Hires+Ex-Microsoft+Security+Strategist+Window+Snyder" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/10/mozilla-hires-ex-microsoft-security-strategist-window-snyder/&amp;title=Mozilla+Hires+Ex-Microsoft+Security+Strategist+Window+Snyder" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F10%2Fmozilla-hires-ex-microsoft-security-strategist-window-snyder%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/10/mozilla-hires-ex-microsoft-security-strategist-window-snyder/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Browzar is Bullshit</title>
		<link>http://www.darknet.org.uk/2006/10/browzar-is-bullshit/</link>
		<comments>http://www.darknet.org.uk/2006/10/browzar-is-bullshit/#comments</comments>
		<pubDate>Tue, 03 Oct 2006 18:33:58 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General News]]></category>
		<category><![CDATA[Security Software]]></category>
		<category><![CDATA[Browser-Hacking]]></category>
		<category><![CDATA[browser-security]]></category>
		<category><![CDATA[browzar]]></category>
		<category><![CDATA[browzar-backlash]]></category>
		<category><![CDATA[browzar-bullshit]]></category>
		<category><![CDATA[darknet]]></category>
		<category><![CDATA[secure-browser]]></category>
		<category><![CDATA[software-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/10/browzar-is-bullshit/</guid>
		<description><![CDATA[Not sure if any of you heard of this new super secure ultra cool web browser called Browzar? There was a bit of a backlash as it turned out Browzar was just another custom wrapper for Internet Exploder. Security experts are crying foul over a new supposedly secure browser application. Browzar is promoted as an [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Not sure if any of you heard of this new super secure ultra cool web browser called Browzar?</p>
<p>There was a bit of a backlash as it turned out Browzar was just another custom wrapper for Internet Exploder.</p>
<blockquote><p>Security experts are crying foul over a new supposedly secure browser application.</p>
<p>Browzar is promoted as an easy way for users to surf the web without leaving traces of sensitive information behind on their PCs. Critics say it fails to do what it says on the tin and, worse still, the software manipulates search results to push ads at users.</p>
<p>Browzar, according to its developers, is designed not to retain information. Browzar automatically deletes internet caches, histories, cookies. It doesn&#8217;t use auto-complete forms, a feature that anticipates the search term or web address a user might enter.</p></blockquote>
<p>Ah wow sounds amazing eh&#8230;.but?</p>
<blockquote><p>Although positioned as a fully fledged browser application, Browzar is a simple &#8220;custom wrapper&#8221; and user interface for IE that inherits any problems an installed version of Internet Explorer might have, while adding some all of its own. The software is supposed to get rid of all records of sites surfers may have visited, along with cookies and history files relating to a Browzar session from users&#8217; PCs.</p>
<p>But Browzar does not clean up all traces of surfing as promised. Deleted files are not wiped and would be easy to recover &#8211; allowing anyone with a basic data recovery tool to access history, cookies or any other media downloaded using Browzar. Furthermore, because Browzar uses IE&#8217;s ActiveX control, a list of browsed websites stills appear in the index.dat file. Browzar therefore, according to critics, offers a false sense of privacy protection.</p></blockquote>
<p>What&#8217;s worse than no security? Yes&#8230;a false sense of security, the same goes for privacy.</p>
<p>Plus what&#8217;s worse&#8230;it seems to actually be along the lines of ad-ware spyware..</p>
<blockquote><p>As if that wasn&#8217;t enough reason to be wary of the software, Browzar steers users towards the firm&#8217;s own search page which allows the browser&#8217;s developers to insert sponsored links intermixed with regular search results. Much of the criticism of Browzar has focused on its skewed search engine and the use of Browzar&#8217;s website as the default (unchangeable) home page for surfers.</p></blockquote>
<p></p>
<p><a href="http://www.theregister.co.uk/2006/09/04/browzar_backlash/">The Register</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Browzar+is+Bullshit+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D333+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/10/browzar-is-bullshit/&amp;t=Browzar+is+Bullshit" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/10/browzar-is-bullshit/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/10/browzar-is-bullshit/&amp;title=Browzar+is+Bullshit" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/10/browzar-is-bullshit/&amp;title=Browzar+is+Bullshit" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/10/browzar-is-bullshit/&amp;title=Browzar+is+Bullshit" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/10/browzar-is-bullshit/&amp;title=Browzar+is+Bullshit" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F10%2Fbrowzar-is-bullshit%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/10/browzar-is-bullshit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sophos Offers Free Rootkit Detection Tool/Software</title>
		<link>http://www.darknet.org.uk/2006/08/sophos-offers-free-rootkit-detection-toolsoftware/</link>
		<comments>http://www.darknet.org.uk/2006/08/sophos-offers-free-rootkit-detection-toolsoftware/#comments</comments>
		<pubDate>Sun, 27 Aug 2006 23:50:17 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Countermeasures]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows Hacking]]></category>
		<category><![CDATA[anti-rootkit]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[chkrootkit]]></category>
		<category><![CDATA[computer-security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[rootkit-detection]]></category>
		<category><![CDATA[software-security]]></category>
		<category><![CDATA[sony-rootkit]]></category>
		<category><![CDATA[sophos]]></category>
		<category><![CDATA[windows-security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/2006/08/sophos-offers-free-rootkit-detection-toolsoftware/</guid>
		<description><![CDATA[Ah, here at Darknet we have always been a fan of Sophos and the way they operate, a very efficient company and good to see good technical products still coming out of the UK! Another good move by them, they have decided to offer a free rootkit detection tool called Sophos Anti-Rootkit..Yah I know, not [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>Ah, here at Darknet we have always been a fan of Sophos and the way they operate, a very efficient company and good to see good technical products still coming out of the UK!</p>
<p>Another good move by them, they have decided to offer a free rootkit detection tool called Sophos Anti-Rootkit..Yah I know, not a very imaginative name eh?</p>
<blockquote><p>Called Sophos Anti-Rootkit, the software will detect and remove both known and unknown rootkits, and it will warn systems administrators if removing the software might harm operating system integrity.</p>
<p>Rootkits are a collection of tools used by hackers to gain administrative privileges on compromised machines. They are typically used to help hide other forms of malware &#8212; keyloggers or Trojan horse programs, for example &#8212; from antivirus software.</p></blockquote>
<p>Rootkits got a LOT of press after the whole <a href="http://www.darknet.org.uk/2006/02/us-considers-banning-drm-rootkits-sony-bmg/">Sony rootkit fiasco</a>, so it&#8217;s good to see a decent free tool being offered to the general public.</p>
<blockquote><p>Sophos Anti-Rootkit works with the Windows NT, 2000, XP and Windows Server 2003 operating systems. The software features a graphical interface to help guide users through the process of detecting and removing the malicious software.</p>
<p>Since the Sony fiasco, the security industry has paid more attention to the rootkit problem, and there are now a number of free utilities designed to identify this type of software. Other tools include RootkitRevealer, GMER and IceSword.</p></blockquote>
<p>We shall try out as soon as possible, after all we&#8217;ve had <a href="http://www.chkrootkit.org/">chkrootkit</a> on *nix forever&#8230;about time someone did something similar for Windows.</p>
<p>You can <a href="http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html">download Sophos Anti-Rootkit here</a>.</p>
<p></p>
<p>Source: <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&#038;articleId=9002681&#038;source=rss_topic85">ComputerWorld</a></p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Sophos+Offers+Free+Rootkit+Detection+Tool%2FSoftware+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D319+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2006/08/sophos-offers-free-rootkit-detection-toolsoftware/&amp;t=Sophos+Offers+Free+Rootkit+Detection+Tool%2FSoftware" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2006/08/sophos-offers-free-rootkit-detection-toolsoftware/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2006/08/sophos-offers-free-rootkit-detection-toolsoftware/&amp;title=Sophos+Offers+Free+Rootkit+Detection+Tool%2FSoftware" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2006/08/sophos-offers-free-rootkit-detection-toolsoftware/&amp;title=Sophos+Offers+Free+Rootkit+Detection+Tool%2FSoftware" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2006/08/sophos-offers-free-rootkit-detection-toolsoftware/&amp;title=Sophos+Offers+Free+Rootkit+Detection+Tool%2FSoftware" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2006/08/sophos-offers-free-rootkit-detection-toolsoftware/&amp;title=Sophos+Offers+Free+Rootkit+Detection+Tool%2FSoftware" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2006%2F08%2Fsophos-offers-free-rootkit-detection-toolsoftware%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2006/08/sophos-offers-free-rootkit-detection-toolsoftware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

