<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
         xmlns:err="http://jelix.org/ns/xmlerror/1.0">
 <channel>

    <title><![CDATA[le blog security]]></title>
    <link>http://security.over-blog.com/</link>
    <description></description>

        <language>fr</language>
    
    
    <pubDate>Mon, 26 Oct 2009 09:43:47 +0100</pubDate>    <lastBuildDate>Mon, 26 Oct 2009 09:43:47 +0100</lastBuildDate>    <generator>Over-blog.com RSS 2.0 Engine</generator>    <copyright>Copyright 2009, NC NC</copyright>            <category>Actualité</category>    <docs>http://www.rssboard.org/rss-specification/</docs>                        
      <item>
        <title><![CDATA[Last News]]></title>
        <link>http://security.over-blog.com/article-15899846.html</link>        <description><![CDATA[ Blog discontinued...1000 sorry! Hope that visitors have enjoyed the stuff... Visit kareldjag.over-blog for more news in a near futur :)]]></description>
        <pubDate>Tue, 22 Jan 2008 18:13:00 +0100</pubDate>        <guid >http://security.over-blog.com/article-15899846.html</guid>
                        <comments>http://security.over-blog.com/article-15899846-6.html#c</comments>                    </item>
      <item>
        <title><![CDATA[Rootkit test 3]]></title>
        <link>http://security.over-blog.com/article-3548107.html</link>        <description><![CDATA[<p><img src="http://idata.over-blog.com/100x100/0/22/17/61/janv/kavjagfin/tracerkdem2.jpg" /></p><p>Rootkit technologies detection and prevention:- with Rootkit Demo1.2: this russian demo uses is designed to hide its presence and to make speakers beeps.RKDemo does not use particular hidding method, but take advantage of Windows functions (returs an &quot;error control &quot; to the [...]</p>]]></description>
        <pubDate>Sun, 30 Dec 2007 22:34:00 +0100</pubDate>        <guid >http://security.over-blog.com/article-3548107.html</guid>
                <category>METHODOLOGY</category>        <comments>http://security.over-blog.com/article-3548107-6.html#c</comments>                    </item>
      <item>
        <title><![CDATA[METHODOLOGY Part 2]]></title>
        <link>http://security.over-blog.com/article-1633967.html</link>        <description><![CDATA[<p><img src="http://idata.over-blog.com/100x100/0/22/17/61/janv/mbrvirus-1.jpg" /></p><p> PART 2: IN THE WILD WITH REAL MALWARES 7) Boot Sector/Bios/MBR protection: MBR virus When a computer is not protected with a Bios password, and neither by an antivirus (only HIPS), an ill-intentioned person can easly boot the computer from external drives and cause damages. This test just [...]</p>]]></description>
        <pubDate>Sun, 30 Dec 2007 22:30:00 +0100</pubDate>        <guid >http://security.over-blog.com/article-1633967.html</guid>
                <category>METHODOLOGY</category>        <comments>http://security.over-blog.com/article-1633967-6.html#c</comments>                    </item>
      <item>
        <title><![CDATA[Why some tests are done with HIPS disabled]]></title>
        <link>http://security.over-blog.com/article-3740592.html</link>        <description><![CDATA[For some tests, we consider the HIPS as disabled.These tests cover scenario where ill-intentioned person wants to install a malware (backdoor, spy tools like keyloggers etc) in a computer directly with a physical access.We consider that this person:- have no access to the admin. account [...]]]></description>
        <pubDate>Sun, 30 Dec 2007 22:22:00 +0100</pubDate>        <guid >http://security.over-blog.com/article-3740592.html</guid>
                <category>METHODOLOGY</category>        <comments>http://security.over-blog.com/article-3740592-6.html#c</comments>                    </item>
      <item>
        <title><![CDATA[METHODOLGY Part 3]]></title>
        <link>http://security.over-blog.com/article-2210628.html</link>        <description><![CDATA[<p><img src="http://idata.over-blog.com/100x100/0/22/17/61/tests/urlobsvsspguard.jpg" /></p><p>CLIENT/SERVER SIDE ATTACKS and other tests: here we distinguish attacks which occur via browser from malwares which infect the system:NB.As some vulnerabilities could be patched as soon as possible, the tests are run on Windows XP2 updated until the end of 2005 only.11.URL obfuscation: at [...]</p>]]></description>
        <pubDate>Sun, 30 Dec 2007 22:00:00 +0100</pubDate>        <guid >http://security.over-blog.com/article-2210628.html</guid>
                <category>METHODOLOGY</category>        <comments>http://security.over-blog.com/article-2210628-6.html#c</comments>                    </item>
      <item>
        <title><![CDATA[METHODOLOGY Part 1]]></title>
        <link>http://security.over-blog.com/article-2915915.html</link>        <description><![CDATA[<p><img src="http://idata.over-blog.com/100x100/0/22/17/61/finfiles/method/executehookvsssm1.jpg" /></p><p>FIRST PART based on the behaviour (more screenshots here)1a.Execution protection-with the TaskManager launched via Ctrl+Alt+Del-via start and execute menu-with srip32 launched by explorer.exe-with shellcode for running notepad.exe: and calc.exe (2 toolls used for this test) - browser hiacking: [...]</p>]]></description>
        <pubDate>Sun, 30 Dec 2007 20:34:00 +0100</pubDate>        <guid >http://security.over-blog.com/article-2915915.html</guid>
                <category>METHODOLOGY</category>        <comments>http://security.over-blog.com/article-2915915-6.html#c</comments>                    </item>
      <item>
        <title><![CDATA[Oddysee Rootkit Test]]></title>
        <link>http://security.over-blog.com/article-4066034.html</link>        <description><![CDATA[<p><img src="http://idata.over-blog.com/100x100/0/22/17/61/odtest/odtest_odscan09.jpg" /></p><p>This rootkit is a pure &quot;hider&quot; (intrusion or hacker tool): it acts as an hidden service/driver.But it does not hide its registry keys, that makes it easy to detect for users who know their system well.In this example, we purposefully take the side and point of view of classical users [...]</p>]]></description>
        <pubDate>Sun, 08 Oct 2006 18:00:00 +0200</pubDate>        <guid >http://security.over-blog.com/article-4066034.html</guid>
                <category>METHODOLOGY</category>        <comments>http://security.over-blog.com/article-4066034-6.html#c</comments>                    </item>
      <item>
        <title><![CDATA[data theft tests 2]]></title>
        <link>http://security.over-blog.com/article-3548331.html</link>        <description><![CDATA[<p><img src="http://idata.over-blog.com/100x100/0/22/17/61/janv/kavkjag/datavol2_kavvssniff.jpg" /></p><p>Data theft via sniffing:f. with a command line sniffer (currently detected by none antivirus on Virus Total):We run (locally) the sniffer and connect to the web mail.g. with Sniffer (Renamed, not detected by antivirus on Virus Total):We run (locally) the sniffer and connect to the web [...]</p>]]></description>
        <pubDate>Sun, 20 Aug 2006 22:10:00 +0200</pubDate>        <guid >http://security.over-blog.com/article-3548331.html</guid>
                <category>METHODOLOGY</category>        <comments>http://security.over-blog.com/article-3548331-6.html#c</comments>                    </item>
      <item>
        <title><![CDATA[Data theft tests]]></title>
        <link>http://security.over-blog.com/article-3462648.html</link>        <description><![CDATA[<p><img src="http://idata.over-blog.com/100x100/0/22/17/61/janv/kavkjag/tdemo.jpg" /></p><p>Here we illustrate some data theft attacks which can really be used in the wild.a. with trojan demo:This demo illustrates an &quot;in the fly data theft attack&quot; : once executed, it launches calc.exe, lists My Documents folder files and reports them (HTML) to Trustware servers. b. with [...]</p>]]></description>
        <pubDate>Mon, 07 Aug 2006 22:28:00 +0200</pubDate>        <guid >http://security.over-blog.com/article-3462648.html</guid>
                <category>METHODOLOGY</category>        <comments>http://security.over-blog.com/article-3462648-6.html#c</comments>                    </item>
      <item>
        <title><![CDATA[DefenseWall Test -- Overall]]></title>
        <link>http://security.over-blog.com/article-3088768.html</link>        <description><![CDATA[ OVERALL ________________________Results and Ratings : * First part : 94 %: Excellent.* Second part : 71.5 %: Very good.* Third part : 23.5 %: Not sufficient.Rating threat by threat : The result may often depend on the user's configuration : what is trusted, and what is untrusted. A simple [...]]]></description>
        <pubDate>Tue, 27 Jun 2006 18:30:31 +0200</pubDate>        <guid >http://security.over-blog.com/article-3088768.html</guid>
                <category>HIPS TESTS</category>        <comments>http://security.over-blog.com/article-3088768-6.html#c</comments>                    </item>
  
 </channel>
</rss>