<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-10241626</id><updated>2011-07-29T08:58:08.797+02:00</updated><title type='text'>Rajaats Weblog</title><subtitle type='html'>My weblog about all things that interest me (and hopefully you): viruses, programming in general, death &amp; black metal, certain web sites... Well, it could be anything.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>26</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-10241626.post-4806056107481124496</id><published>2009-11-05T23:20:00.002+01:00</published><updated>2009-11-05T23:22:14.988+01:00</updated><title type='text'></title><content type='html'>&lt;pre&gt;&lt;code&gt;&lt;!--- Rajaat on reddit is Rajaat --&gt;&lt;br /&gt;Meh, I am surprised this still works. Hi Reddit!&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-4806056107481124496?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/4806056107481124496/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=4806056107481124496' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/4806056107481124496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/4806056107481124496'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2009/11/meh-i-am-surprised-this-still-works.html' title=''/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-114787696312698945</id><published>2006-05-17T16:35:00.000+02:00</published><updated>2006-05-17T16:42:43.136+02:00</updated><title type='text'>Blue Frog is gone</title><content type='html'>Alas, Blue Frog was quite successful fighting SPAM, but could not withstand the retaliating attack from PharmaMaster and has to shut down to prevent a large scale internet war... You can read their article about the shutdown at &lt;a href="http://www.bluesecurity.com/"&gt;http://www.bluesecurity.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I think it is sad... shows who owns the internet, not the USA, no other country, but big criminal organisations.&lt;br /&gt;&lt;br /&gt;So this experiment is over, now what?&lt;br /&gt;&lt;br /&gt;Well, I think in Russia they found a way that works even better than BlueSecuritys initiative: &lt;a href="http://mosnews.com/news/2005/07/25/spammerdead.shtml"&gt;http://mosnews.com/news/2005/07/25/spammerdead.shtml&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-114787696312698945?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/114787696312698945/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=114787696312698945' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/114787696312698945'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/114787696312698945'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2006/05/blue-frog-is-gone.html' title='Blue Frog is gone'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-112436716344273094</id><published>2005-08-18T14:04:00.000+02:00</published><updated>2005-08-18T14:13:19.753+02:00</updated><title type='text'>Blue Frog Revisited</title><content type='html'>As you've seen from my previous post, the email addresses from Blue Security itself were not included in the "Do Not Intrude" registry. Today I checked it again and discovered to my pleasure they now included their own addresses. Not only that, they added their complete domain, so if you check for pussyeater@bluesecurity.com it will also be protected.&lt;br /&gt;&lt;br /&gt;I've now run their program for almost a month, and slowly I'm starting to see that the amount of spam I'm receiving is decreasing. I don't know wether it is just periodically decline or wether it is the success of Blue Frog. I hope it's the latter, because I really hate spam, even more than viruses or spyware because that is much easier to avoid.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-112436716344273094?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/112436716344273094/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=112436716344273094' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/112436716344273094'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/112436716344273094'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/08/blue-frog-revisited.html' title='Blue Frog Revisited'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-112187241576808975</id><published>2005-07-20T16:35:00.000+02:00</published><updated>2005-07-20T17:13:35.776+02:00</updated><title type='text'>Blue Frog fights fire with fire.</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.bluesecurity.com/community/gallery/banner1.gif"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer; width: 200px;" src="http://www.bluesecurity.com/community/gallery/banner1.gif" alt="" border="0" /&gt;&lt;/a&gt;&lt;a href="http://it.slashdot.org/article.pl?sid=05/07/18/1214226&amp;amp;from=rss"&gt;Slashdot&lt;/a&gt; mentions a program from &lt;a href="http://www.bluesecurity.com/"&gt;Blue Security&lt;/a&gt;, called Blue Frog, which is a program that tries to fight spam in another way than usual spam filters do. People who sign up become part of a DDoS network, but in a bit more sophisticated way than the screensaver Lycos used to distribute. You can add up to three email addresses that should be protected. Whenever you receive a spam email in one of those email boxes you forward it to an address at Blue Security (yoursignedupname@reports.bluesecurity.com), where they will look for the website linked to in the spam mail (a typical spam mail wants to direct you to their site). Then, on behalf of you they will warn the site owner and the ISP the site is hosted at that they are sending unsollicited email and should download a hash list and a tool to clean our their harvested emails database. If they do not comply, all the users that signed up and have the Blue Frog client running will start filling up the webforms with repeated requests to be taken off the spam list, effectively ruining the spammers business by adding filth to their selling databases and causing a DDoS attack.&lt;br /&gt;&lt;br /&gt;I must confess I think this is a very nice idea, alas, as a former virus writer I'm known for having little ethical problems with these kinds of things and will gladly sign up, whereas other people might frown upon the tactics they use.&lt;br /&gt;&lt;br /&gt;However...&lt;br /&gt;&lt;br /&gt;Sceptical as I am I downloaded the &lt;a href="http://www.bluesecurity.com/downloads/registry.asp"&gt;"Do Not Intrude Registry" Compliance Tools&lt;/a&gt;, with which you can check wether you are using email addresses that have signed up for not receiving any spam mail anymore and created a small text file with the following addresses:&lt;br /&gt;&lt;blockquote&gt;info@bluesecurity.com&lt;br /&gt;postmaster@bluesecurity.com&lt;br /&gt;webmaster@bluesecurity.com&lt;br /&gt;sales@bluesecurity.com&lt;br /&gt;root@bluesecurity.com&lt;br /&gt;info-dep@bluesecurity.com&lt;br /&gt;press@bluesecurity.com&lt;br /&gt;marketing-dep@bluesecurity.com&lt;br /&gt;careers-dep@bluesecurity.com&lt;br /&gt;cleanup@bluesecurity.com&lt;br /&gt;legal-dep@bluesecurity.com&lt;br /&gt;&lt;/blockquote&gt;and processed it with their tool. I was quite amazed that none of these addresses were listed as protected by their own system. I think a company should stand behind their own product and use it, how else could you convince people to use it if you don't use it yourself? How about Mikko Hypponen if he would use, say, Norton Antivirus to protect his computer instead of using F-Secure?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-112187241576808975?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/112187241576808975/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=112187241576808975' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/112187241576808975'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/112187241576808975'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/07/blue-frog-fights-fire-with-fire.html' title='Blue Frog fights fire with fire.'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-112168692614110709</id><published>2005-07-18T13:42:00.000+02:00</published><updated>2005-07-18T13:42:08.406+02:00</updated><title type='text'>Man with spyware fixes problem by buying new PCs</title><content type='html'>What if you're an idiot with too much money on your bank account? If it was April Fools Day I'd believe that this is a good hoax: &lt;a href="http://www.theinquirer.net/?article=24690" target="_new"&gt;Man with spyware fixes problem by buying new PCs&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;At least it's a clear sign for hardware vendors that they should hire virus writers :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-112168692614110709?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/112168692614110709/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=112168692614110709' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/112168692614110709'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/112168692614110709'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/07/man-with-spyware-fixes-problem-by.html' title='Man with spyware fixes problem by buying new PCs'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-111718242319537548</id><published>2005-05-27T10:00:00.000+02:00</published><updated>2005-05-27T10:27:03.200+02:00</updated><title type='text'>F-Secure in deep shit?</title><content type='html'>Today I read that people in Finland are massively buying &lt;a href="http://www.iol.co.za/general/news/newsprint.php?art_id=qw1117042921619B231&amp;sf=" target="_new"&gt;toilet paper&lt;/a&gt; because paper mills are shut down due to a lockout of workers in the paper industry. This could mean that F-Secure will be in deep shit. Imagine the poor researchers having to resort to contract their sphincter all day or use a buttplug while dissecting the latest variant of Sober.XYZ. This seriously will affect the quality of the research and the product line of F-Secure. We cannot allow this to happen!&lt;br /&gt;&lt;br /&gt;To ensure that F-Secure won't buckle under severe internal pressure, we have to act now!&lt;br /&gt;&lt;br /&gt;Send your (used) toilet paper to:&lt;br /&gt;&lt;br /&gt;F-Secure Corporation&lt;br /&gt;Tammasaarenkatu 7&lt;br /&gt;PL 24&lt;br /&gt;00181 Helsinki&lt;br /&gt;Finland&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-111718242319537548?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/111718242319537548/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=111718242319537548' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111718242319537548'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111718242319537548'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/05/f-secure-in-deep-shit.html' title='F-Secure in deep shit?'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-111571180425763950</id><published>2005-05-10T09:54:00.000+02:00</published><updated>2005-05-10T09:56:44.263+02:00</updated><title type='text'>A practical look at buffer overflows</title><content type='html'>If you ever wondered how buffer overflows work, &lt;a href="http://collegebums.org/?p=15" target="_new"&gt;here&lt;/a&gt; is a very nice documented example of a buffer overflow and how to exploit it. If you know a bit of assembler, C and how to use a debugger it is a very interesting read.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-111571180425763950?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/111571180425763950/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=111571180425763950' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111571180425763950'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111571180425763950'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/05/practical-look-at-buffer-overflows.html' title='A practical look at buffer overflows'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-111515751183715413</id><published>2005-05-03T23:57:00.000+02:00</published><updated>2005-05-03T23:59:40.090+02:00</updated><title type='text'>Phising for dummies</title><content type='html'>So you want to become a phiser?&lt;br /&gt;&lt;br /&gt;First, to know what a phiser does look at the term &lt;a href="http://en.wikipedia.org/wiki/Phising" target="_new"&gt;phising&lt;/a&gt; on &lt;a href="http://www.wikipedia.org/" target="_new"&gt;WikiPedia&lt;/a&gt;. In short, a phiser is someone who tries to fool somebody to fill in private/sensitive information on a website that is believed to be an official website the scam has been created for. Usually these requests come by email, give a link to a website where you should fill in the information and try to disguise it as a legit site.&lt;br /&gt;&lt;br /&gt;How to spread emails to people and harvest email addresses to send to?&lt;br /&gt;&lt;br /&gt;Thanks to &lt;a href="http://www.f-secure.com/" target="_new"&gt;F-Secure&lt;/a&gt; I found the &lt;a href="http://62nds.com/62nds/documents/mydoom/" target="_new"&gt;source of MyDoom&lt;/a&gt; virus. Just change it a little to suit your needs. How I obtained this source is in an older entry on my weblog in case you want to look it up... Just make it a phising scam and worm in one so that you can reach a big audience...&lt;br /&gt;&lt;br /&gt;What site to imitate?&lt;br /&gt;&lt;br /&gt;Don't worry if you know only the online banking site you use yourself. F-Secure gladly provides you with a &lt;b&gt;HUGE&lt;/b&gt; list of &lt;a href="http://www.f-secure.com/weblog/archives/agent_aa.txt" target="_new"&gt;banks to impersonate&lt;/a&gt; (right-click, save to file). Pick one at random, look at the site, rip the layout and use that in your email you will sent to all the intended victims. Mind you that you use the same language and way of writing as the host of the site does. Spelling errors are a big no-no here, a scam should look perfect!&lt;br /&gt;&lt;br /&gt;Examples... or not?&lt;br /&gt;&lt;br /&gt;Take a look &lt;a href="http://survey.mailfrontier.com/survey/phishing_uk.html" target="_new"&gt;here&lt;/a&gt;, it's a test which checks wether you can be baited for a phising scam. Look at the examples and learn from them. Try your best to imitate the site you intend to copy.&lt;br /&gt;&lt;br /&gt;How to save the data?&lt;br /&gt;&lt;br /&gt;Goddammit, I'm not going to explain you how to program, use &lt;a href="http://www.php.net" target="_new"&gt;PHP&lt;/a&gt; or &lt;a href="http://www.perl.com" target="_new"&gt;Perl&lt;/a&gt; to save the form data... Use The Fucking Search, Noob! (grin)&lt;br /&gt;&lt;br /&gt;What to do with the data you collected?&lt;br /&gt;&lt;br /&gt;Go shopping on the internet or something, I don't care about that... I just feel bothered by the fact that F-Secure yet again gives away information it really doesn't need to and just giving the wrong people the wrong ideas.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-111515751183715413?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/111515751183715413/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=111515751183715413' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111515751183715413'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111515751183715413'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/05/phising-for-dummies.html' title='Phising for dummies'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-111511009293917127</id><published>2005-05-03T10:47:00.000+02:00</published><updated>2005-05-03T10:48:12.940+02:00</updated><title type='text'>Thank you, Symantec!</title><content type='html'>Today one of the workstations at my work got infected with &lt;a href="http://www.f-secure.com/v-descs/sober_p.shtml" target="_new"&gt;Sober.P&lt;/a&gt;. Of course the end user should have known better than opening an email in the english language (not our native language), opening the zip file and running the executable inside it.&lt;br /&gt;&lt;br /&gt;But on the other hand, this threat was found yesterday and (for once I have to agree with F-Secure) &lt;b&gt;&lt;a href="http://www.f-secure.com/weblog/#00000550" target="_new"&gt;by the time European workers get back to their offices tomorrow morning, all antivirus programs should already stop it&lt;/a&gt;&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;We use Symantec Antivirus for Exchange as well as a version running on the workstation, which are up to date and didn't detect it. I am no system administrator and it is not my job to prevent/repair shit like this, but I felt sorry for the person and used &lt;a href="http://housecall.antivirus.com" target="_new"&gt;HouseCall&lt;/a&gt; to remove the infection.&lt;br /&gt;&lt;br /&gt;So... thank you Symantec...&lt;br /&gt;&lt;h3&gt;NOT!&lt;/h3&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-111511009293917127?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/111511009293917127/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=111511009293917127' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111511009293917127'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111511009293917127'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/05/thank-you-symantec.html' title='Thank you, Symantec!'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-111415959317431030</id><published>2005-04-22T10:40:00.000+02:00</published><updated>2005-04-22T10:51:09.256+02:00</updated><title type='text'>$age++</title><content type='html'>Oh happy joy! I managed to stay alive another year in good health. Today I turned 33 years old and (as &lt;a href="http://www.sophos.com/pressoffice/contacts/grahamc.html" target="_new"&gt;Graham Cluley&lt;/a&gt; would say) still not have grown up.&lt;br /&gt;&lt;br /&gt;To celebrate this with you, I give you the source code of one of my recent replicators (including virus). Can you figure out in which environment this program is able to run? I will soon elaborate more on the environment this code runs in and hope to interest you in writing some code as well.&lt;br /&gt;&lt;br /&gt;Hint for AV'ers: you can't write a disinfector for this!&lt;br /&gt;&lt;pre&gt;Published  Name        RTFM   &lt;br /&gt;Published  Author      Rajaat                &lt;br /&gt;Published  EMail       rajaat.itookmyprozac@gmail.com&lt;br /&gt;Published  Country     The Netherlands   &lt;br /&gt;Published  Comment     Birthday Release&lt;br /&gt;Published  Version     0.5&lt;br /&gt;&lt;br /&gt;Published  OpenSource  yes    &lt;br /&gt;Published  Language    RC300&lt;br /&gt;Published  OptionSet   Classic&lt;br /&gt;&lt;br /&gt;Bank 01 BootUp&lt;br /&gt;  BJump 30,1&lt;br /&gt;&lt;br /&gt;Bank 02&lt;br /&gt;Bank 03&lt;br /&gt;Bank 04&lt;br /&gt;Bank 05&lt;br /&gt;Bank 06&lt;br /&gt;Bank 07&lt;br /&gt;Bank 08&lt;br /&gt;Bank 09&lt;br /&gt;Bank 10&lt;br /&gt;Bank 11&lt;br /&gt;Bank 12&lt;br /&gt;Bank 13&lt;br /&gt;Bank 14&lt;br /&gt;Bank 15&lt;br /&gt;Bank 16&lt;br /&gt;Bank 17&lt;br /&gt;&lt;br /&gt;Bank 18 Virus&lt;br /&gt;  Trans 1,1&lt;br /&gt;  Trans 1,2&lt;br /&gt;  Trans 1,3&lt;br /&gt;  Turn 1&lt;br /&gt;&lt;br /&gt;Bank 19 UniversalJumper&lt;br /&gt;  BJump #Active,1&lt;br /&gt;&lt;br /&gt;Bank 20 QuickDisabler&lt;br /&gt;@QuickDisabler.Run&lt;br /&gt;  Move&lt;br /&gt;  Comp %Active,2&lt;br /&gt;  Set %Active,0&lt;br /&gt;  Comp %Banks,0&lt;br /&gt;  Turn 1&lt;br /&gt;  Jump @QuickDisabler.Run&lt;br /&gt;&lt;br /&gt;Bank 21 QuickRunner&lt;br /&gt;@QuickRunner.Move&lt;br /&gt;  Move&lt;br /&gt;@QuickRunner.Run&lt;br /&gt;  Scan #2&lt;br /&gt;  Comp #2,1&lt;br /&gt;  Jump @QuickRunner.NoNME&lt;br /&gt;@QuickRunner.KillAllBanks&lt;br /&gt;  Trans 5,1&lt;br /&gt;  Set %Active,0&lt;br /&gt;  Set #3,%Banks&lt;br /&gt;@QuickRunner.Empty&lt;br /&gt;  Trans 4,#3&lt;br /&gt;  Sub #3,1&lt;br /&gt;  Comp #3,-1&lt;br /&gt;  Jump @QuickRunner.Empty&lt;br /&gt;  Set %Active,1&lt;br /&gt;  Jump @QuickRunner.Move&lt;br /&gt;@QuickRunner.NoNME&lt;br /&gt;  Comp #2,2&lt;br /&gt;  Jump @QuickRunner.Move&lt;br /&gt;  Set %Active,2&lt;br /&gt;  Turn 1&lt;br /&gt;  Jump @QuickRunner.Run&lt;br /&gt;&lt;br /&gt;Bank 22&lt;br /&gt;Bank 23&lt;br /&gt;Bank 24&lt;br /&gt;&lt;br /&gt;Bank 25 SpawnQuickDisabler&lt;br /&gt;  Create 2,3,0&lt;br /&gt;  Trans 1,1&lt;br /&gt;  Set %Active,2&lt;br /&gt;  Trans 2,2&lt;br /&gt;  Trans 3,3&lt;br /&gt;  Turn 0&lt;br /&gt;@SpawnQuickDisabler.Create&lt;br /&gt;  Create 0,1,1&lt;br /&gt;  Trans 3,1&lt;br /&gt;  Set %Active,2&lt;br /&gt;  Jump @SpawnQuickDisabler.Create&lt;br /&gt;&lt;br /&gt;Bank 26 SpawnQuickRunner&lt;br /&gt;  Create 2,5,0&lt;br /&gt;  Trans 4,1&lt;br /&gt;  Set %Active,2&lt;br /&gt;  Trans 2,2&lt;br /&gt;  Trans 3,3&lt;br /&gt;  Trans 4,4&lt;br /&gt;  Trans 5,5&lt;br /&gt;  Turn 0&lt;br /&gt;@SpawnQuickRunner.Create&lt;br /&gt;  Create 1,5,1&lt;br /&gt;  Trans 4,1&lt;br /&gt;  Set %Active,2&lt;br /&gt;  Trans 3,2&lt;br /&gt;  Trans 4,3&lt;br /&gt;  Trans 5,5&lt;br /&gt;  Jump @SpawnQuickRunner.Create&lt;br /&gt;&lt;br /&gt;Bank 27&lt;br /&gt;Bank 28&lt;br /&gt;Bank 29&lt;br /&gt;&lt;br /&gt;Bank 30 InitialBoot&lt;br /&gt;  Set #Active,2&lt;br /&gt;@InitialBoot.Create&lt;br /&gt;&lt;br /&gt;  ; Create SpawnQuickDisabler&lt;br /&gt;  Create 2,3,0&lt;br /&gt;  Trans 19,1&lt;br /&gt;  Set %Active,2&lt;br /&gt;  Trans 25,2&lt;br /&gt;  Trans 20,3&lt;br /&gt;  Turn 0&lt;br /&gt;&lt;br /&gt;  ; Create SpawnQuickKiller&lt;br /&gt;  Create 2,5,0&lt;br /&gt;  Trans 19,1&lt;br /&gt;  Set %Active,2&lt;br /&gt;  Trans 26,2&lt;br /&gt;  Trans 21,3&lt;br /&gt;  Trans 19,4&lt;br /&gt;  Trans 18,5&lt;br /&gt;  Turn 0&lt;br /&gt;&lt;br /&gt;  Add #19,1&lt;br /&gt;  Comp #19,4&lt;br /&gt;  Jump @InitialBoot.Create&lt;br /&gt;&lt;br /&gt;  BJump 31,@Phase2Boot.KillNeighbours&lt;br /&gt;&lt;br /&gt;Bank 31 Phase2Boot&lt;br /&gt;@Phase2Boot.KillNeighbours&lt;br /&gt;  Set %Active,1&lt;br /&gt;  Trans 32,2&lt;br /&gt;  Trans 32,1&lt;br /&gt;  Create 2,12,0&lt;br /&gt;  Trans 33,10&lt;br /&gt;  Trans 19,1&lt;br /&gt;  Set %Active,10&lt;br /&gt;  Trans 19,1&lt;br /&gt;  Trans 32,11&lt;br /&gt;  Trans 19,9&lt;br /&gt;  Trans 18,8&lt;br /&gt;  Turn 0&lt;br /&gt;  Jump @Phase2Boot.KillNeighbours&lt;br /&gt;&lt;br /&gt;Bank 32 Die&lt;br /&gt;  Die&lt;br /&gt;&lt;br /&gt;Bank 33 HugeStar&lt;br /&gt;@HugeStar.Scan&lt;br /&gt;  Turn 1&lt;br /&gt;  Scan #2&lt;br /&gt;  Comp #2,1&lt;br /&gt;  Jump @HugeStar.NoNME&lt;br /&gt;@HugeStar.Kill&lt;br /&gt;  Trans 8,1&lt;br /&gt;  Trans 8,2&lt;br /&gt;  Trans 8,3&lt;br /&gt;  Set %Active,0&lt;br /&gt;  Set #4,%Banks&lt;br /&gt;@HugeStar.EmptyIt&lt;br /&gt;  Trans 11,#4&lt;br /&gt;  Sub #4,1&lt;br /&gt;  Comp #4,-1&lt;br /&gt;  Jump @HugeStar.EmptyIt&lt;br /&gt;  Set %Active,1&lt;br /&gt;  Jump @HugeStar.Scan&lt;br /&gt;@HugeStar.NoNME  &lt;br /&gt;  Comp #2,0&lt;br /&gt;  Jump @HugeStar.Refresh&lt;br /&gt;  Create 2,12,0&lt;br /&gt;  Trans 10,10&lt;br /&gt;  Trans 9,1&lt;br /&gt;  Set %Active,10&lt;br /&gt;  Trans 9,1&lt;br /&gt;  Trans 11,11&lt;br /&gt;  Trans 9,9&lt;br /&gt;  Trans 8,8&lt;br /&gt;  Jump @HugeStar.Scan&lt;br /&gt;@HugeStar.Refresh&lt;br /&gt;  Trans 11,1&lt;br /&gt;  Trans 11,2&lt;br /&gt;  Trans 10,10&lt;br /&gt;  Trans 9,9&lt;br /&gt;  Trans 8,8&lt;br /&gt;  Set %Active,10&lt;br /&gt;  Jump @HugeStar.Scan&lt;br /&gt;&lt;br /&gt;Bank 34&lt;br /&gt;Bank 35&lt;br /&gt;Bank 36&lt;br /&gt;Bank 37&lt;br /&gt;Bank 38&lt;br /&gt;Bank 39&lt;br /&gt;Bank 40&lt;br /&gt;Bank 41&lt;br /&gt;Bank 42&lt;br /&gt;Bank 43&lt;br /&gt;Bank 44&lt;br /&gt;Bank 45&lt;br /&gt;Bank 46&lt;br /&gt;Bank 47&lt;br /&gt;Bank 48&lt;br /&gt;Bank 49&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-111415959317431030?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/111415959317431030/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=111415959317431030' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111415959317431030'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111415959317431030'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/04/age.html' title='$age++'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-111295146669768573</id><published>2005-04-08T11:11:00.000+02:00</published><updated>2005-04-08T11:11:06.696+02:00</updated><title type='text'>Pink Mika on the hunt for warez?</title><content type='html'>&lt;a href="http://www.f-secure.com" target="_new"&gt;F-Secure&lt;/a&gt; has posted on its weblog an &lt;a href="http://www.f-secure.com/weblog/#00000521" target="_new"&gt;article&lt;/a&gt; about the disclaimer on &lt;a href="http://www.elitehackers.com/" target="_new"&gt;www.elitehackers.com&lt;/a&gt; (just google on &lt;a href="http://www.google.com/search?q=%22You+must+be+at+least+250+years+old+and+own+a+pink+car+to+enter+this+site.%22" target="_new"&gt;"You must be at least 250 years old and own a pink car to enter this site."&lt;/a&gt;, directly cut and paste from the weblog). It leaves me with a few questions...&lt;br /&gt;&lt;br /&gt;Who is Mika? (His face is not on the banner on top of the page)&lt;br /&gt;Is he gay? (A pink car... and apparently not photoshopped)&lt;br /&gt;And what is he doing on EliteHackers in the first place???&lt;br /&gt;&lt;br /&gt;Should I get an evaluation copy of their product and search if they used some hacked version of &lt;a href="http://slashdot.org/article.pl?sid=04/11/13/0036243" target="_new"&gt;Sound Forge&lt;/a&gt; for alarm sounds or some graphics processing utility?&lt;br /&gt;&lt;br /&gt;Anyway... Mika, should you read this, the only way to be able to legally access EliteHackers is when you are an &lt;a href="http://web.ask.com/web?q=how+do+i+get+250+years+old%3F&amp;qsrc=0&amp;o=0" target="_new"&gt;ocean worm&lt;/a&gt;, but then I doubt wether you can drive a pink car.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-111295146669768573?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/111295146669768573/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=111295146669768573' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111295146669768573'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111295146669768573'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/04/pink-mika-on-hunt-for-warez.html' title='Pink Mika on the hunt for warez?'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-111278608149152332</id><published>2005-04-06T13:13:00.000+02:00</published><updated>2005-04-06T13:15:02.453+02:00</updated><title type='text'>Back from the dead...</title><content type='html'>Ok, I'm back from holidays and somehow managed to survive. I've been to the Czech Republic during easter, and where I was (near Brno) it is custom on easter Monday to whip the girls with a &lt;a href="http://www.radio.cz/en/html/pomlazka.html" target="_new"&gt;"pomlazka"&lt;/a&gt;, and in return you get an egg and some shot of hard spirit (usually slivovice). Needless to say that I was completely drunk even before noon. I also have been meeting a few of my girlfriends friends and Benny. &lt;br /&gt;&lt;br /&gt;My idle time I spent reading "Quicksilver" from Neal Stephenson and I am really impressed about his improvement on writing style since "Snowcrash". He manages to weave fiction and history seamlessly into a huge novel, and I can recommend his books (especially Cryptonomicon and Quicksilver) to anyone that has an interest in how we got into this digital era we now live in. I've put the next parts (The Confusion and System of the World) on my wishlist.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.cryptonomicon.com/text.html" target="_new"&gt;Excerpt from Cryptonomicon&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.baroquecycle.com/preview.htm" target="_new"&gt;Excerpt from Quicksilver&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-111278608149152332?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/111278608149152332/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=111278608149152332' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111278608149152332'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111278608149152332'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/04/back-from-dead.html' title='Back from the dead...'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-111174857490023579</id><published>2005-03-25T12:02:00.000+01:00</published><updated>2005-03-25T12:14:54.900+01:00</updated><title type='text'>Almost holiday</title><content type='html'>Today is the last day at work before I will go on a holiday to the Czech Republic again. I have met my deadlines, so I've got some time to spend on my weblog. Usually I post here things that are related to security, (anti)virus in specific. Now it's time for a bit informal post so I'll put here some links that I think are interesting and hope you feel the same about it.&lt;br /&gt;&lt;br /&gt;Here we go:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://thedailywtf.com/" target="_new"&gt;The Daily WTF&lt;/a&gt;&lt;br /&gt;Sometimes when I look back at old code I wrote, I think I suck at coding, but after a look on this site I feel much better.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://bcheck.scanit.be/bcheck/index.php" target="_new"&gt;Browser Security Test&lt;/a&gt;&lt;br /&gt;Nice website that tests for vulnerabilities in your current internet browser. Use this to show your family/friends they should get &lt;a href="http://www.mozilla.org/products/firefox/" target="_new"&gt;Mozilla Firefox 1.0.2&lt;/a&gt; to be more secure.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://homokaasu.org/rasterbator/" target="_new"&gt;The Rasterbator&lt;/a&gt;&lt;br /&gt;Upload your favorite picture here and get it back in rasterized PDF format, so you can have your wall filled with a huge poster of that picture (I didn't mention babes here, did I?)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://windirstat.sourceforge.net/" target="_new"&gt;WinDirStat&lt;/a&gt;&lt;br /&gt;A handy little program that shows the usage of your disks in treemap format. Now you finally know where all your free space went to.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.desktopsidebar.com/" target="_new"&gt;Desktop Sidebar&lt;/a&gt;&lt;br /&gt;Don't wait for Windows Longhorn (or whatever they are going to call it). You can have the look already using Desktop Sidebar. It's ideal for quick overview of your email, tasks, weather, stock quotes and more.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.planearium2.de/flash/spstudio.html" target="_new"&gt;Southpark Character Creator&lt;/a&gt;&lt;br /&gt;How would you (or some friend) look if he was in an episode of South Park? Don't wait any longer, find out now! (Maybe I should transform some Antivirus persons)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://truecrypt.sourceforge.net/" target="_new"&gt;TrueCrypt&lt;/a&gt;&lt;br /&gt;Make an encrypted volume where you can store your private stuff in. It is also possible to make a hidden encrypted volume in the encrypted volume, in case you are forced to give your password to some authority.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pressplayontape.com/default.asp?pid=front" target="_new"&gt;Press Play On Tape&lt;/a&gt;&lt;br /&gt;Did you own a Commodore 64? I did, I played games until my wrist hurted like hell. Press Play On Tape is a Commodore 64 revival band, playing well known tunes of the most famous games.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.clientcopia.com/" target="_new"&gt;ClientCopia&lt;/a&gt;&lt;br /&gt;Ever worked on a helpdesk? Having contact with customers? Were they stupid? Here you can see what horros people experienced dealing with stupid customers (and add your own adventures as well).&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.pmbrowser.info/audioscrobbler.html" target="_new"&gt;AudioScrobbler Browser&lt;/a&gt;&lt;br /&gt;Maybe you already knew that you can submit the music you listen to to &lt;a href="http://www.audioscrobbler.com" target="_new"&gt;AudioScrobbler&lt;/a&gt; using one of their plugins. It enables you to find people that have the same musical preferences. Using the AudioScrobbler browser you can have a nice graph how artists can be related to eachother. Use it you expand your horizon.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://happytreefriends.atomfilms.com/" target="_new"&gt;Happy Tree Friends&lt;/a&gt;&lt;br /&gt;They are cute, they are cuddly... and they die in the most horrible ways you can (or even can't) imagine. Small flash animations for anyone who got fed up with all the "Powerpuff Girls" like cartoons. Be sure to checkout the Easter Smoochie!&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.grand-illusions.com/dragon.htm" target="_new"&gt;Dragon Optical Illusion&lt;/a&gt;&lt;br /&gt;Impress your friends with this very good optical illusion. The dragon will follow your every move, eyeing you suspiciously. Download and print out the sheet, get your glue and scissors and have fun!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-111174857490023579?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/111174857490023579/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=111174857490023579' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111174857490023579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111174857490023579'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/03/almost-holiday.html' title='Almost holiday'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-111142729538193103</id><published>2005-03-21T17:37:00.000+01:00</published><updated>2005-03-21T18:51:51.153+01:00</updated><title type='text'>Linux ready for the desktop?</title><content type='html'>I know, I should stick to security issues here, but this subject is lingering in my head for a few days now and I'd like to voice my opinion on it and maybe get some sensible reactions from you on this...&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;center&gt;Linux ready for the desktop?&lt;/center&gt;&lt;/strong&gt;&lt;br /&gt;Lately I've been reading various websites that question wether Linux is ready for the desktop or not.&lt;br /&gt;&lt;br /&gt;First, I'd like to say that this statement is already wrong to begin with. Linux is not ready for the desktop, and will never be, as much as the Windows kernel isn't ready for the desktop either. The kernel (and Linux &lt;strong&gt;IS&lt;/strong&gt; the kernel) is what your operating system uses.&lt;br /&gt;&lt;br /&gt;The proper question in this case would be:&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;center&gt;Is this Linux Distribution ready for the desktop?&lt;/center&gt;&lt;/strong&gt;&lt;br /&gt;Even if you rephrase the question like that I think the question is still incorrect. The problem is in the part that says "the desktop". Whose desktop? Yours? Mine? Aunt Tilly?&lt;br /&gt;&lt;br /&gt;If you look back to the days when MS-DOS was still the most prevalent operating system, I'm sure you can recall people that could work with it, even if it was your Aunt Tilly. She knew how to start and work with Word Perfect, Lotus 1-2-3 or even DBase III. &lt;br /&gt;&lt;br /&gt;Ok, to be honest, she didn't know exactly what was going on in her computer, she didn't know anything about HIMEM.SYS or EMM386.EXE and what they were supposed to do. But she knew that when she had a new program on a floppy disk the usual thing to do was to type&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;center&gt;a:install&lt;/center&gt;&lt;/strong&gt;&lt;br /&gt;and answer some questions as where the files should be copied to (standard location) and wether autoexec.bat should be modified (usually 'yes').&lt;br /&gt;&lt;br /&gt;After that she just fired up Norton Commander (or something like that) and started the application. If something went wrong she had a very nice booklet that told her what to do.&lt;br /&gt;&lt;br /&gt;Fast forward to the present...&lt;br /&gt;&lt;br /&gt;Two groups are debating wether Microsoft Windows XP and/or Some Linux Distribution are ready for the desktop. Here they aim at end-users, like Aunt Tilly. Aunt Tilly got a bit older, grew a little moustache and looks at both.&lt;br /&gt;&lt;br /&gt;She tries Windows XP, which looks very polished to her. After a few days of working and browsing the internet she now has 5 extra toolbars in Internet Explorer, all with almost identical extra's (including the spyware). She sees popups on her screen for online casino's, naked babes, warning messages that her computer is infected, but she never heard of the term spyware. She tries to look in the book what is happening to her computer, but it only says to press F1 at some place to get some help on a subject she never asked for in the first place.&lt;br /&gt;&lt;br /&gt;Then she posts a message to some forum she found by accident using one of her many extra toolbars. She posts the message and includes her email address, hoping for a swift answer...&lt;br /&gt;&lt;br /&gt;And she gets them. A lot of them. Most of them advice her that she should use Cialis, Viagra or any other enhancement so that her erection stays longer, harder and her cumshots will blow off the head of her impressed girlfriend, and (if that girl dies because of it) she always can pick up one of the hundred bored housewifes who just want to have a fuck with her.&lt;br /&gt;&lt;br /&gt;Amongst the more sensible replies there are a few that say that she is a fucking n00b and she should have used Mozilla Firefox to prevent all those things that happened to her. Ofcourse the not-so-friendly replies don't give a link to the site, so again with some more reluctance she has to post a message where she can get this wonderful program that should be the salvation of her PC.&lt;br /&gt;&lt;br /&gt;Again a lot of answers of which she can throw 95% away. The remaining five percent are very brief, shooting acronyms at her like UTFS. Whenever she navigates to www.utfs.com she finds out the domain is for sale, but no link where to download Firefox. After using one of the search bars she finds out the actual site, downloads the software and installs it. Yet the problems of unwanted popups remain. Even if she doesn't use Firefox and is just trying to figure out Word and where those nice markupcodes have been since Word Perfect 5.1 she gets them.&lt;br /&gt;&lt;br /&gt;And then, at some birthday party she talks to a young man that says Linux is the answer. He even is so friendly to give her an URL (which she found out is a cryptic way to say "address of a website") where she could order a free evaluation CD.&lt;br /&gt;&lt;br /&gt;And in a few weeks she gets the CD. She is thrilled. But she also has questions. What should she do with her old documents, her highscore for Zuma and fotos she received from her family? In a desperate attempt to make some sort of backup the mails all the important things to herself and proceeds to install Linux. After some anxious moments she got it running and is greeted with a friendly picture of a multicolored group of people holding hands.&lt;br /&gt;&lt;br /&gt;A few days later she learned with which program she could browse the internet, how she can send and receive email and even do some wordprocessing. But she can't print on her Lexmark printer and she doesn't know why. The webcam she used in Windows now doesn't work anymore when she wants to have a chat with her family.&lt;br /&gt;&lt;br /&gt;Again she searches for answers on the internet, since she doesn't have a manual. She posts some questions. Gets answers...&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;strong&gt;"N00bs like you should stick to Windows, Linux is not for you!"&lt;br /&gt;"Use The Fucking Search, you idiot!"&lt;br /&gt;"You shouldn't use distro XXX, you should have used YYY which is faster after you compile for three days"&lt;/strong&gt;&lt;/center&gt;&lt;br /&gt;Aunt Tilly gives up, gets her old computer out the attic where it has been gathering dust for a few years, fires up Word Perfect and starts typing her last will as she is feeling very old of a sudden...&lt;br /&gt;&lt;br /&gt;After this fictious story I can be very brief in my conclusion about what operating system is ready for the desktop.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;strong&gt;Any or none at all.&lt;/strong&gt;&lt;/center&gt;&lt;br /&gt;An operating system is successful or a complete failure depending on documentation and support. In the case of Aunt Tilly the most successful was MS-DOS. She had a book that explained almost everything she needed to know. With Windows the got a small booklet that explained almost nothing. With the Linux distribution it was even less.&lt;br /&gt;&lt;br /&gt;Almost every software package, wether it is an operating system or an application comes with help on CD or some community on internet. But most people (at least I do) prefer a good manual next to my computer and work through the chapters and browse the reference in case of a specific need. Or patient people that can help Aunt Tilly, instead of insulting her.&lt;br /&gt;&lt;br /&gt;For the aunts that read this weblog entry I can tell that there's hope. There are a lot of books written on any subject I just covered here which you can buy.&lt;br /&gt;&lt;br /&gt;&lt;center&gt;&lt;strong&gt;Where?&lt;br /&gt;&lt;br /&gt;Use The Fucking Search, N00B!&lt;br /&gt;&lt;/strong&gt;&lt;/center&gt;&lt;br /&gt;&lt;br&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-111142729538193103?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/111142729538193103/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=111142729538193103' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111142729538193103'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111142729538193103'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/03/linux-ready-for-desktop.html' title='Linux ready for the desktop?'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-111139615437057842</id><published>2005-03-21T10:04:00.000+01:00</published><updated>2005-03-21T10:09:14.373+01:00</updated><title type='text'>McAfee Multiple Products LHA File Handling Buffer Overflow</title><content type='html'>It starting to look like Antivirus software vendors really should audit the 3rd party libraries they use in their software for handling compressed executables and archives.&lt;br /&gt;&lt;br /&gt;My friend &lt;a href="http://benny.bloguje.cz/index.php" target="_new"&gt;Benny&lt;/a&gt; pointed out that there is yet another vulnerability in handling archives. This time it's McAfee having troubles with LHA archives. Read the advisory &lt;a href="http://secunia.com/advisories/14628/" target="_new"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-111139615437057842?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/111139615437057842/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=111139615437057842' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111139615437057842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/111139615437057842'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/03/mcafee-multiple-products-lha-file.html' title='McAfee Multiple Products LHA File Handling Buffer Overflow'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-110954652232429606</id><published>2005-02-28T00:22:00.000+01:00</published><updated>2005-02-28T00:22:02.323+01:00</updated><title type='text'>Microsoft books teaches on security</title><content type='html'>When mindlessly browsing through a shitload of &lt;a href="http://del.icio.us/"&gt;del.icio.us&lt;/a&gt; posted links I found a very &lt;a href="http://www.microsoft.com/MSPress/books/5957.asp#AboutTheBook"&gt;interesting book&lt;/a&gt;, which I hope the people at Microsoft and the Antivirus vendors will read. After all who can teach you better about securing your applications than the security folks at the biggest company in Redmond?&lt;br /&gt;&lt;br /&gt;Damn, I feel sarcastic...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-110954652232429606?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/110954652232429606/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=110954652232429606' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110954652232429606'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110954652232429606'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/02/microsoft-books-teaches-on-security.html' title='Microsoft books teaches on security'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-110931603685831364</id><published>2005-02-25T08:20:00.000+01:00</published><updated>2005-02-25T08:20:36.856+01:00</updated><title type='text'>Vulnerability in VSAPI ARJ parsing could allow Remote Code execution</title><content type='html'>Recently I posted messages about overflow vulnerabilities in Symantecs and F-Secures antivirus products concerning buffer overflows in unpacking files, now it seems yet another antivirus vendor suffers from the same problem. Check the Trend Micro advisory "&lt;a href="http://www.trendmicro.com/vinfo/secadvisories/default6.asp?VName=Vulnerability+in+VSAPI+ARJ+parsing+could+allow+Remote+Code+execution"&gt;Vulnerability in VSAPI ARJ parsing could allow Remote Code execution&lt;/a&gt;"&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-110931603685831364?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/110931603685831364/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=110931603685831364' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110931603685831364'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110931603685831364'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/02/vulnerability-in-vsapi-arj-parsing.html' title='Vulnerability in VSAPI ARJ parsing could allow Remote Code execution'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-110907314425275448</id><published>2005-02-22T12:52:00.000+01:00</published><updated>2005-02-22T12:52:24.253+01:00</updated><title type='text'>F-Secure silently alters mydoom source picture</title><content type='html'>Apparently &lt;a href="http://www.f-secure.com"&gt;F-Secure&lt;/a&gt; reads &lt;a href="http://benny.bloguje.cz/index.php"&gt;Benny's&lt;/a&gt; or my weblog (see &lt;a href="http://rajaat.blogspot.com/2005/01/f-secure-not-so-smart.html"&gt;here&lt;/a&gt; and &lt;a href="http://rajaat.blogspot.com/2005/01/f-secure-not-so-smart-screenshot.html"&gt;here&lt;/a&gt;), as they have realised that publishing a &lt;a href="http://photos1.blogger.com/img/277/3090/1024/F-Secure%20%20%20News%20from%20the%20Lab%2026-1-2005%2011%2053%2023.jpg"&gt;picture&lt;/a&gt; of the source of mydoom is indeed not a smart thing to do. If you look in their &lt;a href="http://www.f-secure.com/weblog/archives/archive-012005.html#00000448"&gt;archive&lt;/a&gt; you'll see that they now blurred out the important parts of the source which I used to find the source code. Of course they wouldn't announce that they changed it, because making such failure is not good for the credibility of their company. Unfortunately for them I still have the screenshot, so if you really want the source you can still &lt;a href="http://www.google.com"&gt;Google&lt;/a&gt; for it. But don't be naughty by using it for making YABV (Yet Another Boring Variant) but for educational purposes only (blatant disclaimer).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-110907314425275448?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/110907314425275448/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=110907314425275448' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110907314425275448'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110907314425275448'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/02/f-secure-silently-alters-mydoom-source_22.html' title='F-Secure silently alters mydoom source picture'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-110864513305548647</id><published>2005-02-17T13:58:00.000+01:00</published><updated>2005-02-17T13:58:53.056+01:00</updated><title type='text'>KLEENEX goes AV!</title><content type='html'>For a little bit of fun, see how Kleenex now jumps into the &lt;br /&gt;&lt;a href="http://www.kleenex.com/us/av/index.asp"&gt;Antivirus&lt;/a&gt; business :-) Go eat your heart out, other AV'ers!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-110864513305548647?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/110864513305548647/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=110864513305548647' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110864513305548647'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110864513305548647'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/02/kleenex-goes-av.html' title='KLEENEX goes AV!'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-110811632343098957</id><published>2005-02-11T11:05:00.000+01:00</published><updated>2005-02-11T11:18:17.443+01:00</updated><title type='text'>Internet Security Systems - F-Secure AntiVirus Library Heap Overflow</title><content type='html'>&lt;a href="http://xforce.iss.net/xforce/alerts/id/188"&gt;Internet Security Systems&lt;/a&gt; has a report on a vulnerability on F-Secure Antivirus, which is similar to the other report on the UPX vulnerability of Symantec Antivirus. It looks to me that you're safer using &lt;span style="font-weight:bold;"&gt;NO ANTIVIRUS&lt;/span&gt; software than using one. All you need to do is securing your Windows a bit better (get a external firewall, drop Internet Explorer in favor of Mozille FireFox/Thunderbird) and be careful what you download and &lt;span style="font-weight:bold;"&gt;NEVER RUN THINGS WITH ADMINISTRATOR RIGHTS&lt;/span&gt; unless you really have to.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-110811632343098957?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/110811632343098957/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=110811632343098957' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110811632343098957'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110811632343098957'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/02/internet-security-systems-f-secure.html' title='Internet Security Systems - F-Secure AntiVirus Library Heap Overflow'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-110795391093494511</id><published>2005-02-09T13:58:00.000+01:00</published><updated>2005-02-09T14:19:40.336+01:00</updated><title type='text'>Symantec AntiVirus Library Heap Overflow</title><content type='html'>&lt;a href="http://xforce.iss.net/xforce/alerts/id/187"&gt;Internet Security Systems&lt;/a&gt; has a report about a vulnerability found in almost all antivirus products from &lt;a href="http://www.symantec.com/avcenter/security/Content/2005.02.08.html"&gt;Symantec&lt;/a&gt; concerning the use of a malformed UPX compressed executable that causes a heap overflow, making it possible to execute code on a remote machine when scanning such file. Newer products are immune, but I think there are still enough users that use an older version of some product.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-110795391093494511?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/110795391093494511/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=110795391093494511' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110795391093494511'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110795391093494511'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/02/symantec-antivirus-library-heap.html' title='Symantec AntiVirus Library Heap Overflow'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-110684484153036903</id><published>2005-01-27T17:38:00.000+01:00</published><updated>2005-01-27T18:24:46.746+01:00</updated><title type='text'>A worm for MySQL?</title><content type='html'>&lt;a href="http://www.slashdot.org/" target="_new"&gt;Slashdot&lt;/a&gt; has an &lt;a href="http://it.slashdot.org/article.pl?sid=05/01/27/1546222" target="_new"&gt;article&lt;/a&gt; on what seems to be a worm propagating using MySQL on Windows that is configured with a weak root password. More information can be found &lt;a href="http://isc.sans.org/diary.php?date=2005-01-27" target="_new"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://isc.sans.org/port_details.php?port=3306&amp;repax=1&amp;tarax=1" target="_new"&gt;&lt;img src="http://isc.sans.org/port3306.png" border="0" style='border:0px;padding:0px;background:transparent;' width="400px" /&gt;&lt;br /&gt;Click here for full graph&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I wonder how many web servers will get severe problems because of the many attacks on port 3306...&lt;br /&gt;&lt;br /&gt;Update: I suspect the worm is written by some dutch person (or belgian) because it connects to an IRC server and goes to a channel named "&lt;a href="http://www.google.com/search?q=rampenstampen" target="_new"&gt;#rampenstampen&lt;/a&gt;" which is typically dutch.&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-110684484153036903?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/110684484153036903/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=110684484153036903' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110684484153036903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110684484153036903'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/01/worm-for-mysql.html' title='A worm for MySQL?'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-110673691407110748</id><published>2005-01-26T11:55:00.000+01:00</published><updated>2005-01-27T17:59:54.010+01:00</updated><title type='text'>F-Secure not so smart (screenshot)</title><content type='html'>&lt;a href='http://photos1.blogger.com/img/277/3090/1024/F-Secure%20%20%20News%20from%20the%20Lab%2026-1-2005%2011%2053%2023.jpg'&gt;&lt;img border='0' style='border:1px solid #000000; margin:2px' src='http://photos1.blogger.com/img/277/3090/400/F-Secure%20%20%20News%20from%20the%20Lab%2026-1-2005%2011%2053%2023.jpg'&gt;&lt;/a&gt;&lt;br /&gt;Here is a screenshot of the page from F-Secure in case they would withdraw it.&amp;nbsp;&lt;a href='http://www.hello.com/' target='ext'&gt;&lt;img src='http://photos1.blogger.com/pbh.gif' alt='Posted by Hello' border='0' style='border:0px;padding:0px;background:transparent;' align='absmiddle'&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-110673691407110748?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/110673691407110748/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=110673691407110748' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110673691407110748'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110673691407110748'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/01/f-secure-not-so-smart-screenshot.html' title='F-Secure not so smart (screenshot)'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-110673317088674486</id><published>2005-01-26T10:43:00.000+01:00</published><updated>2005-01-26T10:54:47.113+01:00</updated><title type='text'>F-Secure not so smart...</title><content type='html'>I just saw an article on the &lt;a href="http://www.f-secure.com/weblog/#00000448" target="_new"&gt;weblog&lt;/a&gt; of &lt;a href="http://www.f-secure.com" target="_new"&gt;F-Secure&lt;/a&gt; about MyDoom, where they posted a &lt;a href="http://www.f-secure.com/virus-info/v-pics/doomjuice1.gif" target="_new"&gt;picture&lt;/a&gt; with a part of the source code. I haven't seen the source code yet, so I tried to find it using &lt;a href="http://www.google.com" target="_new"&gt;Google&lt;/a&gt; and using terms taken from the picture: shit msvc inlined it to winmain. It gives you &lt;a href="http://www.google.com/search?q=shit+msvc+inlined+it+to+winmain" target="_new"&gt;these&lt;/a&gt; results. I think it's not a very smart move from F-Secure, handing out a vector to find the &lt;a href="http://62nds.com/62nds/documents/mydoom/" target="_new"&gt;complete source&lt;/a&gt; so easily.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-110673317088674486?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/110673317088674486/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=110673317088674486' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110673317088674486'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110673317088674486'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/01/f-secure-not-so-smart.html' title='F-Secure not so smart...'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-110629731655906138</id><published>2005-01-21T09:45:00.000+01:00</published><updated>2005-01-27T02:26:04.890+01:00</updated><title type='text'>Obfuscating PHP code</title><content type='html'>In a magazine of 29A i saw &lt;a href="http://www.spth.de.vu/" target="_blank"&gt;SPTH&lt;/a&gt; writing some tutorial on randomizing PHP code using routines for manipulating strings. I've done something similar, yet I use the built-in parser for PHP code that is included in the Zend engine. Here's a quick example of obfuscating PHP code using the tokenizer functions from the Zend engine:&lt;br /&gt;&lt;pre&gt;&amp;lt;?&lt;br /&gt;$source = join("",@file(__FILE__));&lt;br /&gt;// Pass 1:&lt;br /&gt;// - strip all comments&lt;br /&gt;// - strip needless whitespace&lt;br /&gt;$tokens = token_get_all($source);&lt;br /&gt;foreach ($tokens as $token) {&lt;br /&gt;  if (is_string($token)) {&lt;br /&gt;    $pass1 .= $token;&lt;br /&gt;  } else {&lt;br /&gt;    list ($id,$text) = $token;&lt;br /&gt;    if ($id != T_COMMENT &amp;&amp;amp; $id != T_ML_COMMENT) {&lt;br /&gt;      if ($id == T_WHITESPACE) {&lt;br /&gt;        $text = preg_replace("/\s+/"," ",$text);&lt;br /&gt;      }&lt;br /&gt;      $pass1 .= $text;&lt;br /&gt;    }&lt;br /&gt;  }&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;// Pass 2:&lt;br /&gt;// - randomize variables&lt;br /&gt;// - insert random whitespace and comments&lt;br /&gt;$tokens = token_get_all($pass1);&lt;br /&gt;foreach ($tokens as $token) {&lt;br /&gt;  if (is_string($token)) {&lt;br /&gt;    $pass2 .= $token;&lt;br /&gt;  } else {&lt;br /&gt;    list($id, $text) = $token;&lt;br /&gt;    switch($id) {&lt;br /&gt;      case T_WHITESPACE:&lt;br /&gt;        $pass2 .= $text . &lt;br /&gt;                  str_repeat(" ",rand(0,5)) . &lt;br /&gt;                  "/*" . &lt;br /&gt;                  str_repeat(" ",rand(0,5)) . &lt;br /&gt;                  substr(md5(uniqid("")),0,rand(1,30)) . &lt;br /&gt;                  str_repeat(" ",rand(0,5)) . &lt;br /&gt;                  "*/"  .&lt;br /&gt;                  str_repeat(" ",rand(0,5));&lt;br /&gt;        break;&lt;br /&gt;      case T_VARIABLE :&lt;br /&gt;        if (!isset($vars[$text])) {&lt;br /&gt;          $vars[$text] = '$' . &lt;br /&gt;                         chr(rand(0,1) ? &lt;br /&gt;                           rand(65,90) : &lt;br /&gt;                           rand(97,122)) . &lt;br /&gt;                             substr(md5(uniqid("")),0,rand(5,10));&lt;br /&gt;        }&lt;br /&gt;        $text = $vars[$text];&lt;br /&gt;      default:&lt;br /&gt;        $pass2 .= $text;&lt;br /&gt;    }&lt;br /&gt;  }&lt;br /&gt;}&lt;br /&gt;print $pass2;&lt;br /&gt;?&gt;&lt;/pre&gt;References:&lt;br /&gt;&lt;a title="PHP Virus Writing Guide" href="http://vx.netlux.org/29a/29a-7/Articles/29A-7.020" target="_blank"&gt;PHP Virus Writing Guide&lt;/a&gt;&lt;br /&gt;&lt;a title="Generic Polymorphism" href="http://vx.netlux.org/lib/static/vdat/tugenpol.htm" target="_blank"&gt;Generic Polymorphism&lt;/a&gt;&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-110629731655906138?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/110629731655906138/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=110629731655906138' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110629731655906138'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110629731655906138'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/01/obfuscating-php-code.html' title='Obfuscating PHP code'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-10241626.post-110608769330732644</id><published>2005-01-18T23:34:00.000+01:00</published><updated>2005-01-21T10:15:23.910+01:00</updated><title type='text'>Ok, I'm here...</title><content type='html'>Ok, my first post... I wonder how long I can keep up with this, and more important how long you can keep up with me. If don't agree with the things that I post here, better find yourself a &lt;a href="http://home.att.net/~mcp3_2000/_gifpic/love_friendship/anim_sub_page.htm"&gt;more suitable&lt;/a&gt; site. Pessimistic as I am I wonder how long it will take before some n00b (=idiot) discovers this weblog and feels compelled to behave so childish to comment on every post with a "FIPO" (=FIrst POst) remark. I will remove the possibility to give comments entirely if this happens too often (treshold set at some unknown - but very low - level).&lt;br /&gt;&lt;br /&gt;A little background on me:&lt;br /&gt;&lt;br /&gt;I'm an ex-virus writer, been member of various groups like &lt;a href="http://vx.netlux.org/29a/" target="_blank"&gt;29A&lt;/a&gt;. I'm still interested in viruses, but not actively involved in the scene anymore. Musical interests are mainly Death &amp;amp; Black Metal (I also play in a band myself, I play drums), I like to read books (mostly fantasy, current favorite writer is &lt;a href="http://www.nealstephenson.com/" target="_blank"&gt;Neal Stephenson&lt;/a&gt;).&lt;br /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/10241626-110608769330732644?l=rajaat.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://rajaat.blogspot.com/feeds/110608769330732644/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=10241626&amp;postID=110608769330732644' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110608769330732644'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/10241626/posts/default/110608769330732644'/><link rel='alternate' type='text/html' href='http://rajaat.blogspot.com/2005/01/ok-im-here.html' title='Ok, I&apos;m here...'/><author><name>Rajaat</name><uri>http://www.blogger.com/profile/13888401616196776189</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
