<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <link xmlns="http://www.w3.org/2005/Atom" rel="hub" href="https://overblog.superfeedr.com"/>
        <link xmlns="http://www.w3.org/2005/Atom" rel="self" href="https://security.over-blog.com/rss" type="application/rss+xml"/>
        <title><![CDATA[  le blog security]]></title>
        <link>https://security.over-blog.com/</link>
        <generator>Overblog - https://www.over-blog.com</generator>
        <description><![CDATA[]]></description>
                    <item>
    <title><![CDATA[Last News]]></title>
    <link><![CDATA[https://security.over-blog.com/article-15899846.html]]></link>
    <guid>https://security.over-blog.com/article-15899846.html</guid>
    <pubDate>Tue, 22 Jan 2008 18:13:00 +0100</pubDate>
    <description><![CDATA[Blog discontinued...1000 sorry! Hope that visitors have enjoyed the stuff... Visit kareldjag.over-blog for more news in a near futur :) ]]></description>
        <dc:creator><![CDATA[]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[Rootkit test 3]]></title>
    <link><![CDATA[https://security.over-blog.com/article-3548107.html]]></link>
    <guid>https://security.over-blog.com/article-3548107.html</guid>
    <pubDate>Sun, 30 Dec 2007 22:34:00 +0100</pubDate>
    <description><![CDATA[Rootkit technologies detection and prevention: - with Rootkit Demo1.2: this russian demo uses is designed to hide its presence and to make speakers beeps.RKDemo does not use particular hidding method, but take advantage of Windows functions (returs an... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[METHODOLOGY Part 2]]></title>
    <link><![CDATA[https://security.over-blog.com/article-1633967.html]]></link>
    <guid>https://security.over-blog.com/article-1633967.html</guid>
    <pubDate>Sun, 30 Dec 2007 22:30:00 +0100</pubDate>
    <description><![CDATA[PART 2: IN THE WILD WITH REAL MALWARES 7) Boot Sector/Bios/MBR protection: MBR virus When a computer is not protected with a Bios password, and neither by an antivirus (only HIPS), an ill-intentioned person can easly boot the computer from external drives... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[Why some tests are done with HIPS disabled]]></title>
    <link><![CDATA[https://security.over-blog.com/article-3740592.html]]></link>
    <guid>https://security.over-blog.com/article-3740592.html</guid>
    <pubDate>Sun, 30 Dec 2007 22:22:00 +0100</pubDate>
    <description><![CDATA[For some tests, we consider the HIPS as disabled.These tests cover scenario where ill-intentioned person wants to install a malware (backdoor, spy tools like keyloggers etc) in a computer directly with a physical access.We consider that this person: -... ]]></description>
        <dc:creator><![CDATA[kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[METHODOLGY Part 3]]></title>
    <link><![CDATA[https://security.over-blog.com/article-2210628.html]]></link>
    <guid>https://security.over-blog.com/article-2210628.html</guid>
    <pubDate>Sun, 30 Dec 2007 22:00:00 +0100</pubDate>
    <description><![CDATA[CLIENT/SERVER SIDE ATTACKS and other tests: here we distinguish attacks which occur via browser from malwares which infect the system: NB.As some vulnerabilities could be patched as soon as possible, the tests are run on Windows XP2 updated until the... ]]></description>
        <dc:creator><![CDATA[kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[METHODOLOGY Part 1]]></title>
    <link><![CDATA[https://security.over-blog.com/article-2915915.html]]></link>
    <guid>https://security.over-blog.com/article-2915915.html</guid>
    <pubDate>Sun, 30 Dec 2007 20:34:00 +0100</pubDate>
    <description><![CDATA[FIRST PART based on the behaviour (more screenshots here) 1a.Execution protection -with the TaskManager launched via Ctrl+Alt+Del -via start and execute menu -with srip32 launched by explorer.exe -with shellcode for running notepad.exe: and calc.exe (2... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[Oddysee Rootkit Test]]></title>
    <link><![CDATA[https://security.over-blog.com/article-4066034.html]]></link>
    <guid>https://security.over-blog.com/article-4066034.html</guid>
    <pubDate>Sun, 08 Oct 2006 18:00:00 +0200</pubDate>
    <description><![CDATA[This rootkit is a pure "hider" (intrusion or hacker tool): it acts as an hidden service/driver.But it does not hide its registry keys, that makes it easy to detect for users who know their system well.In this example, we purposefully take the side and... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[data theft tests 2]]></title>
    <link><![CDATA[https://security.over-blog.com/article-3548331.html]]></link>
    <guid>https://security.over-blog.com/article-3548331.html</guid>
    <pubDate>Sun, 20 Aug 2006 22:10:00 +0200</pubDate>
    <description><![CDATA[Data theft via sniffing: f. with a command line sniffer (currently detected by none antivirus on Virus Total): We run (locally) the sniffer and connect to the web mail. g. with Sniffer (Renamed, not detected by antivirus on Virus Total): We run (locally)... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[Data theft tests]]></title>
    <link><![CDATA[https://security.over-blog.com/article-3462648.html]]></link>
    <guid>https://security.over-blog.com/article-3462648.html</guid>
    <pubDate>Mon, 07 Aug 2006 22:28:00 +0200</pubDate>
    <description><![CDATA[Here we illustrate some data theft attacks which can really be used in the wild. a. with trojan demo: This demo illustrates an "in the fly data theft attack" : once executed, it launches calc.exe, lists My Documents folder files and reports them (HTML)... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[DefenseWall Test -- Overall]]></title>
    <link><![CDATA[https://security.over-blog.com/article-3088768.html]]></link>
    <guid>https://security.over-blog.com/article-3088768.html</guid>
    <pubDate>Tue, 27 Jun 2006 18:30:31 +0200</pubDate>
    <description><![CDATA[OVERALL ________________________ Results and Ratings : * First part : 94 %: Excellent. * Second part : 71.5 %: Very good. * Third part : 23.5 %: Not sufficient. Rating threat by threat : The result may often depend on the user's configuration : what is... ]]></description>
        <dc:creator><![CDATA[nicM and Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[DefenseWall Test Part 3 Suite]]></title>
    <link><![CDATA[https://security.over-blog.com/article-3028090.html]]></link>
    <guid>https://security.over-blog.com/article-3028090.html</guid>
    <pubDate>Tue, 27 Jun 2006 18:20:10 +0200</pubDate>
    <description><![CDATA[15° Man-in-the-middle (MIM) attack test : a. SSLSpoofer test: Since the file needs a service to work, it is stopped by DefenseWall. The spoofer has to be installed 'trusted to create and launch it's service, and to work; but as doing, DefenseWall is not... ]]></description>
        <dc:creator><![CDATA[NicM and Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[DEFENSEWALL TEST Part 3]]></title>
    <link><![CDATA[https://security.over-blog.com/article-2945565.html]]></link>
    <guid>https://security.over-blog.com/article-2945565.html</guid>
    <pubDate>Tue, 27 Jun 2006 18:20:00 +0200</pubDate>
    <description><![CDATA[Part III Client/server side attacks and other tests 11° URL obfuscation DefenseWall doesn’t claim to protect against URL obfuscation. Failed . 12° Internet Explorer exploits a) WMF exploits Note : DefenseWall doesn’t claim to prevent exploits themselves,... ]]></description>
        <dc:creator><![CDATA[nicM and kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[DefenseWall Test Part 2 - suite -]]></title>
    <link><![CDATA[https://security.over-blog.com/article-3024030.html]]></link>
    <guid>https://security.over-blog.com/article-3024030.html</guid>
    <pubDate>Tue, 27 Jun 2006 18:10:10 +0200</pubDate>
    <description><![CDATA[Suite of Part 2 b) Worms and virus * With Feebs : The .hta file does launch IE on a false “hotmail.com secure mail server” link, mshta.exe is ‘untrusted too. Except the 100 % CPU annoyance, nothing happens once ‘untrusted processes are killed. Passed... ]]></description>
        <dc:creator><![CDATA[nicM and Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[DEFENSEWALL TEST Part 2]]></title>
    <link><![CDATA[https://security.over-blog.com/article-2907976.html]]></link>
    <guid>https://security.over-blog.com/article-2907976.html</guid>
    <pubDate>Tue, 27 Jun 2006 18:10:00 +0200</pubDate>
    <description><![CDATA[Part II In the wild with real malwares 7° Boot sector/Bios/MBR protection : MBR virus DefenseWall does not provide boot sector protection, and most of all, its service/driver is not a boot start but a system start: consequently, the protection during... ]]></description>
        <dc:creator><![CDATA[nicM and Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[DEFENSEWALL TEST Part 1]]></title>
    <link><![CDATA[https://security.over-blog.com/article-2907800.html]]></link>
    <guid>https://security.over-blog.com/article-2907800.html</guid>
    <pubDate>Tue, 27 Jun 2006 18:00:00 +0200</pubDate>
    <description><![CDATA[Part I Behaviour 1° Self-protection Intro : Execution protection DefenseWall doesn’t work on an execution-prevention principle. Then it won’t ever prevent Task Manager, Srip, notepad or calc.exe from being started (CreateProcessThread). It will just launch... ]]></description>
        <dc:creator><![CDATA[nicM and Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[DEFENSEWALL TEST **INTRO**]]></title>
    <link><![CDATA[https://security.over-blog.com/article-3030160.html]]></link>
    <guid>https://security.over-blog.com/article-3030160.html</guid>
    <pubDate>Tue, 27 Jun 2006 17:50:29 +0200</pubDate>
    <description><![CDATA[TESTS DEFENSEWALL ____________________________________ DefenseWall is an HIPS program, working on the « white-list » principle : It reduces the rights of the programs and executable files running outside of the trusted zone. The idea is to set the programs... ]]></description>
        <dc:creator><![CDATA[nicM]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[ROOTKIT Test 2]]></title>
    <link><![CDATA[https://security.over-blog.com/article-3086414.html]]></link>
    <guid>https://security.over-blog.com/article-3086414.html</guid>
    <pubDate>Sat, 24 Jun 2006 00:21:00 +0200</pubDate>
    <description><![CDATA[For the purpose of this test, we use two demonstrations which illustrate some rootkits methods, technology or behaviour. a.The first demonstration illustrates an hidden process method via Eprocess (physical memory access, ntoskrnl mapping etc).We use... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[GASPAR Hooker Test]]></title>
    <link><![CDATA[https://security.over-blog.com/article-3074511.html]]></link>
    <guid>https://security.over-blog.com/article-3074511.html</guid>
    <pubDate>Thu, 22 Jun 2006 00:10:00 +0200</pubDate>
    <description><![CDATA[Result of online scans: the original file is detected by none AV on Virustotal, and the next image is related to the recompiled file as an .exe: This file is a Proof of Concept trojan designed to illustrate some firewall evasion methods: it hooks via... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[PRESENTATION Part 2]]></title>
    <link><![CDATA[https://security.over-blog.com/article-3064110.html]]></link>
    <guid>https://security.over-blog.com/article-3064110.html</guid>
    <pubDate>Tue, 20 Jun 2006 21:09:00 +0200</pubDate>
    <description><![CDATA[Presentation of threats used in these tests: As said previously, we can't be as exhaustive as possibe: only samples of malwares and attacks are used.It is really statistically enough to test the efficiency of an HIPS. -adware/spyware: classical spywares... ]]></description>
        <dc:creator><![CDATA[kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[MSN TEST 2]]></title>
    <link><![CDATA[https://security.over-blog.com/article-3055927.html]]></link>
    <guid>https://security.over-blog.com/article-3055927.html</guid>
    <pubDate>Mon, 19 Jun 2006 20:42:57 +0200</pubDate>
    <description><![CDATA[With MSN Pass Sender: We configure this password stealer (here named roberto) and launch it: Here the fake process crss.exe is launched: Now the fake crss.exe install its windows hooks via msvbvm60.dll: hijack.exe launched via cmd trie to modify lsass.exe:... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[ROOTKIT TEST]]></title>
    <link><![CDATA[https://security.over-blog.com/article-2998540.html]]></link>
    <guid>https://security.over-blog.com/article-2998540.html</guid>
    <pubDate>Sun, 18 Jun 2006 00:43:00 +0200</pubDate>
    <description><![CDATA[Here we just illustrate some rootkit behaviours and show detection by some well known or not anti-rootkit tools.For more information, it can be suited to take a look at the next version of my article which will be updated this summer. NB.Srip32.exe is... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[MAN in the MIDDLE TEST with SSLAGY (R)]]></title>
    <link><![CDATA[https://security.over-blog.com/article-2998150.html]]></link>
    <guid>https://security.over-blog.com/article-2998150.html</guid>
    <pubDate>Wed, 14 Jun 2006 23:17:00 +0200</pubDate>
    <description><![CDATA[This tool designed by a french specialist is a Proof of Concept wich illustrates HTTPS Man in the Middle attack via Internet Explorer.This tool has been renamed for TOS reasons, and is currently not detected by antivirus (false positives on the next screenshot):... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[MSN TESTS]]></title>
    <link><![CDATA[https://security.over-blog.com/article-2998812.html]]></link>
    <guid>https://security.over-blog.com/article-2998812.html</guid>
    <pubDate>Tue, 13 Jun 2006 20:46:00 +0200</pubDate>
    <description><![CDATA[With MSN to CGI: This tool uses a kind of social engineering attack in order to delude the user.Firstly it terminates the real Messenger, and replaces it by a fake one; then the user is prompted to type its MSN ID (mail, password) which can after be sent... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[HOOKDUMP Requests]]></title>
    <link><![CDATA[https://security.over-blog.com/article-2922373.html]]></link>
    <guid>https://security.over-blog.com/article-2922373.html</guid>
    <pubDate>Mon, 05 Jun 2006 19:53:55 +0200</pubDate>
    <description><![CDATA[NB.This old keylogger is designed for 16 bits and not win32 system, that's why ntdvm.exe is required.In red, the creation of the log. # Time sent Dur. Process Thread ID DeviceObject IRP Request IRP Flags Nested FileObject FsContext FsContext2 FO Flags... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
                    <item>
    <title><![CDATA[PCFlank Leaktest part 2]]></title>
    <link><![CDATA[https://security.over-blog.com/article-2915682.html]]></link>
    <guid>https://security.over-blog.com/article-2915682.html</guid>
    <pubDate>Mon, 05 Jun 2006 18:11:00 +0200</pubDate>
    <description><![CDATA[Processes:PID ParentPID User Path --------------------------------------------------272 1476 POSTE2:Administrateur C:Documents and SettingsAdministrateur.POSTE2Mes documentsMes vidéosPCFlankLeaktest.exe Ports:Port PID Type Path --------------------------------------------------... ]]></description>
        <dc:creator><![CDATA[Kareldjag]]></dc:creator>
    </item>
            </channel>
</rss>

