Gumblar Virus

March 24th, 2010

Not had alot to post here recently so thought I would post about Gumblar!

Earlier this week a friend of mine who operates a gaming website with me was infected with a variant of the Gumblar virus.

Basically this virus stole ftp details from his computer, then used these to login to our FTP and add a small piece of code to the end of all pages which started with the word index, ended with .js, and additionally select Wordpress and phpBB files. This code then advised some users visiting the website that they had a virus and needed to purchase the anti virus solution offered, others caught the site trying to download trojans on their anti virus.

Whilst fortunately this particular site is on a different web server and account to the site in question it did mean a sizeable cleanup operation which disrupted our website significantly and wasted about 6 hours of my life!

I figured I would post up the offending code incase anyone did want to have a look through it.

Code Samples:
Code as at the end of the file
Code spaced out and url encoding removed

So there we have it! It pays to have a good antivirus, and if you don’t need to store your ftp password, don’t! For me it was alot of work sorting out my site, for my friend it was twice as much as all his other sites have been edited too!

More on IP Tracability

January 14th, 2010

More from Light Blue Touchpaper, a continuation of my last post about IP traceability on mobile networks has now been released, parts 2 and 3 are availiable at the below links:

http://www.lightbluetouchpaper.org/2010/01/13/practical-mobile-internet-access-traceability/

http://www.lightbluetouchpaper.org/2010/01/14/mobile-internet-access-data-retention-not/

What is pentesting?

January 14th, 2010

I saw this question asked on the maemo forums while looking into pentesting apps for the Nokia n900.

I thought this answer by a user called brendan was brilliant:

“pentesting is a term for the QA team under the employ of companies like Bic and PaperMate, that scribble with the pens coming off the production line, to ensure that each one works before it is packaged and shipped to retail stores.

a mundane and monotonous job, but someone has to do it.”


Now in the future I know what to answer when someone asks me!

If anyone does want a real definition please see http://en.wikipedia.org/wiki/Penetration_test.

IP Tracing

January 12th, 2010

Read another interesting article today from Light Blue Touchpaper about tracability of people based on IP addresses, learnt some things I wasn’t aware of and looking forward to the next article, read it at http://www.lightbluetouchpaper.org/2010/01/12/extending-the-requirements-for-traceability/

Interview with a Blackhat

January 12th, 2010

Just finished listening to the first of tmacuk’s interview with a Blackhat series, very interesting to see how the other-side thinks, I was particularly surprised when he said he would like to go whitehat if he had the chance, perhaps there is hope yet if they all feel that way! Check it out at http://tmacuk.co.uk/?p=109

Ubuntu and more

January 12th, 2010

Well I finally got ubuntu 9.10 installed on a partition last night, planning to use it as my main OS and do everything in it unless I have to go into Windows 7! This should help me get a good grasp on it which will help me with my degree in the future :)

I’ve accepted the offer to study at Northumbria and completed my accomadation application, just waiting on some further info for my student finance application and they should be all set.

University!

January 11th, 2010

Well I had an offer a few days ago, and I have today accepted it!

From September I will be studying Ethical Hacking for Computer Security at Northumbria University! Just need to sort out where I am going to be living and how I am going to be paying for this and I’m set :D

Who am I?

January 3rd, 2010

Well, my name is Daniel and I currently work in tech support!

I am keenly interested in computer security and hoping to go into the field as a career, currently I am applying to several UK universities to study an Ethical Hacking based undergraduate degree.

As part of my work towards this I am currently teaching myself C++ and following several security websites and twitter feeds.

I don’t have alot to write about currently but I will be updating this blog with what I have learnt and some intresting stories, as well as other news.

Hello world!

January 1st, 2010

This is my new blog, in the traditions of blogging and coding therefore the first output must be HELLO WORLD!