<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Analysis of a dll injector &#8211; Trojan.Win32.Inject.dnz</title>
	<atom:link href="http://www.martinsecurity.net/2008/08/28/analysis-of-a-dll-injector-trojanwin32injectdnz/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.martinsecurity.net/2008/08/28/analysis-of-a-dll-injector-trojanwin32injectdnz/</link>
	<description>Viewing InfoSec from the trenches (formerly Real Security)</description>
	<lastBuildDate>Mon, 14 Dec 2009 07:06:01 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: Matt</title>
		<link>http://www.martinsecurity.net/2008/08/28/analysis-of-a-dll-injector-trojanwin32injectdnz/comment-page-1/#comment-35</link>
		<dc:creator>Matt</dc:creator>
		<pubDate>Tue, 11 Nov 2008 13:52:20 +0000</pubDate>
		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=8#comment-35</guid>
		<description>The content has been a valuable piece of information.
Three cheers!!</description>
		<content:encoded><![CDATA[<p>The content has been a valuable piece of information.<br />
Three cheers!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Maynard</title>
		<link>http://www.martinsecurity.net/2008/08/28/analysis-of-a-dll-injector-trojanwin32injectdnz/comment-page-1/#comment-34</link>
		<dc:creator>Maynard</dc:creator>
		<pubDate>Sun, 12 Oct 2008 20:19:18 +0000</pubDate>
		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=8#comment-34</guid>
		<description>VERY interested. Not a programmer myself by career, but always digging down into my OS&#039;s, and trained since I was 15..

I will follow the path you have set out here learn, much clearer than anyting i have found outside of private (an very expensive) seminars.

I am VERY interested in 209.160.21.76. I have a spare and old machine running Windows server 2003. Its my mps player. Its ports were cut down to a total minimum. To do that I accessed some ex-colleagues in a major countrie&#039;s DOD. I was given the doc, and managed to cut everything down to less than 3 ports open, then shielded them by a very good software firewall, IE was never used except for update. It has always been kept up-to-date on a weekly basis.

Now I am supposed to have an &quot;infection&quot; on this machine. On reboot it tries to connect to 209.160.21.76. But there is nothing  in any scan I have tried (Kasprksy, AVG, Boclean running) that tells me I have an infection. HJT is clean, nothing unknown. IceAword shows what I would expect, the firewall hooks(Comodo). But some how, on this inocent little machine, some bastard has managed to find a way n. Connections are zero, the entrie domain of 209.160.0.255 to 209.160.255.255 is excluded from internet transactions. But it keeps trying, and I can&#039;t see from where. But I WILL get it. I WILL find the fucker who did it, and more importantly, I will find out how to protect the 353 machines I live with better.

Thanks for the post dude. You are obviously way beyond me in coding, but you gave me a huge leg up. Most of the real gurus seem to target the corporate networks and megabucks. Most fail, but they leave a trail behind of people who don&#039;t believe.

Mine is MY network. I rent it out for a pittance (cost plus) to local bands and smal  companies. It a good deal for them and I get to learn a lot. 10 years on no, 3 OS&#039;s.

Thanks! I&#039;ll get the bastard one way or another. I had a company in Iran who rented space for a fashion company. So I checked all their jvs for problems (only jvs allowed on my sites), it was clean.

Then I found a leak going upstream, found the site that was drawing it. They were distributing KP (CP CHild-porn) from one of my servers and hadn&#039;t paid a cent! So I wnt to windows  update and the firewall updateand fixed that.

You are so ahead of the game that my minor problems are &quot;under the horizon&quot;, but your musings on-line have helped my brain re-engage. Now I don&#039;t groan and hang my head down nad say &quot;fuck it, who cares&quot;. I jump up and say to myself &quot;last post you made is for her friends&quot; Then I look at the calendar and realise i graduated 2 years ago. It&#039;s OK.

I&#039;ve changed from monitoring 0 to monitoring 65%

Thanks a bunch. I got a lot of reading to do now!

Real meaty post. Even though you introduced it as a taster.

God bless!

When I find out who, I&#039;ll hang the bones on the door as I leave!</description>
		<content:encoded><![CDATA[<p>VERY interested. Not a programmer myself by career, but always digging down into my OS&#8217;s, and trained since I was 15..</p>
<p>I will follow the path you have set out here learn, much clearer than anyting i have found outside of private (an very expensive) seminars.</p>
<p>I am VERY interested in 209.160.21.76. I have a spare and old machine running Windows server 2003. Its my mps player. Its ports were cut down to a total minimum. To do that I accessed some ex-colleagues in a major countrie&#8217;s DOD. I was given the doc, and managed to cut everything down to less than 3 ports open, then shielded them by a very good software firewall, IE was never used except for update. It has always been kept up-to-date on a weekly basis.</p>
<p>Now I am supposed to have an &#8220;infection&#8221; on this machine. On reboot it tries to connect to 209.160.21.76. But there is nothing  in any scan I have tried (Kasprksy, AVG, Boclean running) that tells me I have an infection. HJT is clean, nothing unknown. IceAword shows what I would expect, the firewall hooks(Comodo). But some how, on this inocent little machine, some bastard has managed to find a way n. Connections are zero, the entrie domain of 209.160.0.255 to 209.160.255.255 is excluded from internet transactions. But it keeps trying, and I can&#8217;t see from where. But I WILL get it. I WILL find the fucker who did it, and more importantly, I will find out how to protect the 353 machines I live with better.</p>
<p>Thanks for the post dude. You are obviously way beyond me in coding, but you gave me a huge leg up. Most of the real gurus seem to target the corporate networks and megabucks. Most fail, but they leave a trail behind of people who don&#8217;t believe.</p>
<p>Mine is MY network. I rent it out for a pittance (cost plus) to local bands and smal  companies. It a good deal for them and I get to learn a lot. 10 years on no, 3 OS&#8217;s.</p>
<p>Thanks! I&#8217;ll get the bastard one way or another. I had a company in Iran who rented space for a fashion company. So I checked all their jvs for problems (only jvs allowed on my sites), it was clean.</p>
<p>Then I found a leak going upstream, found the site that was drawing it. They were distributing KP (CP CHild-porn) from one of my servers and hadn&#8217;t paid a cent! So I wnt to windows  update and the firewall updateand fixed that.</p>
<p>You are so ahead of the game that my minor problems are &#8220;under the horizon&#8221;, but your musings on-line have helped my brain re-engage. Now I don&#8217;t groan and hang my head down nad say &#8220;fuck it, who cares&#8221;. I jump up and say to myself &#8220;last post you made is for her friends&#8221; Then I look at the calendar and realise i graduated 2 years ago. It&#8217;s OK.</p>
<p>I&#8217;ve changed from monitoring 0 to monitoring 65%</p>
<p>Thanks a bunch. I got a lot of reading to do now!</p>
<p>Real meaty post. Even though you introduced it as a taster.</p>
<p>God bless!</p>
<p>When I find out who, I&#8217;ll hang the bones on the door as I leave!</p>
]]></content:encoded>
	</item>
</channel>
</rss>

