<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>ACATTAG</title>
	<link>http://www.joestewart.org</link>
	<description>When all you have is a debugger, everything starts to look like code.</description>
	<pubDate>Mon, 09 Aug 2010 14:33:04 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2</generator>
	<language>en</language>
			<item>
		<title>Fixed!</title>
		<link>http://www.joestewart.org/?p=32</link>
		<comments>http://www.joestewart.org/?p=32#comments</comments>
		<pubDate>Mon, 09 Aug 2010 14:33:04 +0000</pubDate>
		<dc:creator>joe</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.joestewart.org/?p=32</guid>
		<description><![CDATA[So rather than take my wrecked bike to the body shop to fix the dented gas tank and bent handlebars, I decided to fix it on my own, with nothing more than body filler, spray paint, new emblems and a lot of banging and bending. Not exactly a professional restoration job, but I don&#8217;t think [...]]]></description>
			<content:encoded><![CDATA[<p>So rather than take my wrecked bike to the body shop to fix the dented gas tank and bent handlebars, I decided to fix it on my own, with nothing more than body filler, spray paint, new emblems and a lot of banging and bending. Not exactly a professional restoration job, but I don&#8217;t think it turned out so bad.</p>
<p><center><br />
<img src="/bikenodent.jpg" height=325 width=400 alt="Vulcan 800 after DIY repair"></p>
<p></center></p>
]]></content:encoded>
			<wfw:commentRss>http://www.joestewart.org/?feed=rss2&amp;p=32</wfw:commentRss>
		</item>
		<item>
		<title>Operation Aurora: Clues in the Code</title>
		<link>http://www.joestewart.org/?p=31</link>
		<comments>http://www.joestewart.org/?p=31#comments</comments>
		<pubDate>Wed, 20 Jan 2010 18:19:58 +0000</pubDate>
		<dc:creator>joe</dc:creator>
		
		<category><![CDATA[Malware Analysis]]></category>

		<category><![CDATA[Computer Security]]></category>

		<category><![CDATA[Reverse Engineering]]></category>

		<guid isPermaLink="false">http://www.joestewart.org/?p=31</guid>
		<description><![CDATA[With the recently disclosed hacking incident inside Google and other major companies, much of the world has begun to wake up to what the infosec community has known for some time – there is a persistent campaign of &#8220;espionage-by-malware&#8221; emanating from the People’s Republic of China (PRC). Corporate and state secrets both have been shanghaied [...]]]></description>
			<content:encoded><![CDATA[<p>With the recently disclosed hacking incident inside Google and other major companies, much of the world has begun to wake up to what the infosec community has known for some time – there is a persistent campaign of &#8220;espionage-by-malware&#8221; emanating from the People’s Republic of China (PRC). Corporate and state secrets both have been shanghaied over a period of five or more years, and the activity becomes bolder over time with little public acknowledgement or response from the U.S. government.</p>
<p><a href="http://www.secureworks.com/research/blog/index.php/2010/01/20/operation-aurora-clues-in-the-code/">Read more&#8230;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.joestewart.org/?feed=rss2&amp;p=31</wfw:commentRss>
		</item>
		<item>
		<title>Virut, FFSearcher, Twitter</title>
		<link>http://www.joestewart.org/?p=30</link>
		<comments>http://www.joestewart.org/?p=30#comments</comments>
		<pubDate>Fri, 26 Jun 2009 19:42:40 +0000</pubDate>
		<dc:creator>joe</dc:creator>
		
		<category><![CDATA[Malware Analysis]]></category>

		<category><![CDATA[Reverse Engineering]]></category>

		<guid isPermaLink="false">http://www.joestewart.org/?p=30</guid>
		<description><![CDATA[Just finished a couple of back-to-back research pieces. First, a rundown on the C&#038;C protocol encryption in the latest Virut, then a look at a new Firefox browser hijacker that carries out a clever scheme to defraud Google&#8217;s Adsense for Search program.
Also, I&#8217;m now posting my new research to Twitter as soon as it is [...]]]></description>
			<content:encoded><![CDATA[<p>Just finished a couple of back-to-back research pieces. First, a <a href="http://www.secureworks.com/research/threats/virut-encryption-analysis">rundown on the C&#038;C protocol encryption in the latest Virut</a>, then a look at a new <a href="http://www.secureworks.com/research/threats/ffsearcher">Firefox browser hijacker</a> that carries out a clever scheme to defraud Google&#8217;s Adsense for Search program.</p>
<p>Also, I&#8217;m now posting my new research to Twitter as soon as it is available for public consumption. Follow <a href="http://twitter.com/joestewart71">joestewart71</a> to get these links as soon as they are posted.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joestewart.org/?feed=rss2&amp;p=30</wfw:commentRss>
		</item>
		<item>
		<title>On The New Cybersecurity Bill</title>
		<link>http://www.joestewart.org/?p=28</link>
		<comments>http://www.joestewart.org/?p=28#comments</comments>
		<pubDate>Fri, 22 May 2009 18:52:47 +0000</pubDate>
		<dc:creator>joe</dc:creator>
		
		<category><![CDATA[Computer Security]]></category>

		<guid isPermaLink="false">http://www.joestewart.org/?p=28</guid>
		<description><![CDATA[On April 1, 2009, while the rest of the cybersecurity world was largely focused on the Conficker worm, Senators John (Jay) Rockefeller and Olympia Snowe introduced the Cybersecurity Act of 2009. Since the hype over Conficker has died down now, I’ve had a chance to review the text of this somewhat controversial bill and add [...]]]></description>
			<content:encoded><![CDATA[<p><img src="/strongbill.png" width=200 height=138 align=left>On April 1, 2009, while the rest of the cybersecurity world was largely focused on the Conficker worm, Senators John (Jay) Rockefeller and Olympia Snowe introduced the Cybersecurity Act of 2009. Since the hype over Conficker has died down now, I’ve had a chance to review the text of this somewhat controversial bill and add my two cents to the discussion. There are 23 sections to the bill, a few of which have raised some alarm in the infosec community.<br />
<a href="http://www.secureworks.com/research/blog/index.php/2009/05/20/on-the-new-cybersecurity-bill/">Read more&#8230;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.joestewart.org/?feed=rss2&amp;p=28</wfw:commentRss>
		</item>
		<item>
		<title>Wrecked!</title>
		<link>http://www.joestewart.org/?p=29</link>
		<comments>http://www.joestewart.org/?p=29#comments</comments>
		<pubDate>Thu, 21 May 2009 18:43:10 +0000</pubDate>
		<dc:creator>joe</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.joestewart.org/?p=29</guid>
		<description><![CDATA[Last Wednesday, just after leaving work, a minivan travelling in the opposite direction turned left in front of me. The short stopping distance required, compounded with being on a curve at the time equalled me skidding sideways, tipping over and landing on the pavement. No broken bones, just some road rash, a sprained foot and [...]]]></description>
			<content:encoded><![CDATA[<p>Last Wednesday, just after leaving work, a minivan travelling in the opposite direction turned left in front of me. The short stopping distance required, compounded with being on a curve at the time equalled me skidding sideways, tipping over and landing on the pavement. No broken bones, just some road rash, a sprained foot and ankle, and a nasty-looking bruise on my inner thigh that looks strangely like the Kawasaki logo in reverse.</p>
<p><center><img src="/bikedent.jpg" width=400 height=325></center></p>
<p>Although I don&#8217;t believe in mandatory helmet laws, I wear mine pretty much all the time - also my motorcycle boots and gloves. Together, these left me a lot better off than I would have been without them.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joestewart.org/?feed=rss2&amp;p=29</wfw:commentRss>
		</item>
		<item>
		<title>Speaking at RSA</title>
		<link>http://www.joestewart.org/?p=27</link>
		<comments>http://www.joestewart.org/?p=27#comments</comments>
		<pubDate>Fri, 17 Apr 2009 17:27:55 +0000</pubDate>
		<dc:creator>joe</dc:creator>
		
		<category><![CDATA[Computer Security]]></category>

		<guid isPermaLink="false">http://www.joestewart.org/?p=27</guid>
		<description><![CDATA[The 2009 RSA conference kicks off next week in San Francisco. It looks like a busy week for me - I’ll be presenting first on Tuesday, April 21st at the SecureWorks booth on the showfloor at 1:00 PM PDT. This will be a “Conficker Q&#038;A” session. I’ll be answering questions with the knowledge I’ve gained [...]]]></description>
			<content:encoded><![CDATA[<p><img src="/rsabadge2008.jpg" height=99 width=140 align=right>The 2009 RSA conference kicks off next week in San Francisco. It looks like a busy week for me - I’ll be presenting first on Tuesday, April 21st at the SecureWorks booth on the showfloor at 1:00 PM PDT. This will be a “Conficker Q&#038;A” session. I’ll be answering questions with the knowledge I’ve gained from reverse-engineering Conficker and also from my participation in the Conficker Working Group. So, if you have any burning questions about the threat posed by the Conficker worm, drop by the booth at that time and I’ll try to answer them.</p>
<p><a href="http://www.secureworks.com/research/blog/index.php/2009/04/17/speaking-at-rsa/">Read more&#8230;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.joestewart.org/?feed=rss2&amp;p=27</wfw:commentRss>
		</item>
		<item>
		<title>Conficker Eye Chart</title>
		<link>http://www.joestewart.org/?p=26</link>
		<comments>http://www.joestewart.org/?p=26#comments</comments>
		<pubDate>Thu, 02 Apr 2009 12:39:22 +0000</pubDate>
		<dc:creator>joe</dc:creator>
		
		<category><![CDATA[Malware Analysis]]></category>

		<category><![CDATA[Computer Security]]></category>

		<guid isPermaLink="false">http://www.joestewart.org/?p=26</guid>
		<description><![CDATA[I&#8217;ve been working on a few different ways to detect Conficker via a web page load. I originally came up with a javascript method but I decided to go with a simpler approach using only images. Thus, the Conficker Eye Chart was born.  It&#8217;s a simple visual test you can use to evaluate a [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been working on a few different ways to detect Conficker via a web page load. I originally came up with a javascript method but I decided to go with a simpler approach using only images. Thus, the <a href="http://www.joestewart.org/cfeyechart.html">Conficker Eye Chart</a> was born. <a href="http://www.joestewart.org/cfeyechart.html"><img src="/chartnormal.jpg" width=200 height=109 align=left vspace=10 hspace=10></a> It&#8217;s a simple visual test you can use to evaluate a Windows PC just by surfing to that page and looking at the images. It doesn&#8217;t work if you&#8217;re behind a web proxy (since the proxy will resolve the remote sites for you, bypassing Conficker&#8217;s blocking ability). But if you are behind a proxy, you should already be getting your Windows updates (including the MSRT tool) on time and updates from your anti-virus company as normal, so you shouldn&#8217;t be infected, right?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.joestewart.org/?feed=rss2&amp;p=26</wfw:commentRss>
		</item>
		<item>
		<title>Conficker April Fools Hype</title>
		<link>http://www.joestewart.org/?p=25</link>
		<comments>http://www.joestewart.org/?p=25#comments</comments>
		<pubDate>Fri, 27 Mar 2009 12:49:27 +0000</pubDate>
		<dc:creator>joe</dc:creator>
		
		<category><![CDATA[Malware Analysis]]></category>

		<category><![CDATA[Computer Security]]></category>

		<guid isPermaLink="false">http://www.joestewart.org/?p=25</guid>
		<description><![CDATA[If you’ve been reading any news at all on the Internet in the past week, you’ve probably heard that Conficker Armageddon is approaching, and it’s scheduled for April 1st, only a few days from now. The SecureWorks Counter Threat Unit has been receiving an increasing number of inquiries asking what one needs to do to [...]]]></description>
			<content:encoded><![CDATA[<p>If you’ve been reading any news at all on the Internet in the past week, you’ve probably heard that Conficker Armageddon is approaching, and it’s scheduled for April 1st, only a few days from now. The SecureWorks Counter Threat Unit has been receiving an increasing number of inquiries asking what one needs to do to prepare for the impending April 1st outbreak.</p>
<p><img src="conficker-april-fool.jpg" align=right width=150 height=194></p>
<p>The truth is, there will be no April 1st outbreak, despite what some of the press stories have said so far. The only thing that will happen with Conficker on April 1st is that already-infected systems will begin to use a new algorithm to locate potential update servers. There, that’s not so scary, is it?</p>
<p><a href="http://www.secureworks.com/research/blog/index.php/2009/03/27/conficker-april-fools-hype/">Read more&#8230;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.joestewart.org/?feed=rss2&amp;p=25</wfw:commentRss>
		</item>
		<item>
		<title>Clever Hack, or Carders-at-Work?</title>
		<link>http://www.joestewart.org/?p=24</link>
		<comments>http://www.joestewart.org/?p=24#comments</comments>
		<pubDate>Thu, 12 Mar 2009 17:00:59 +0000</pubDate>
		<dc:creator>joe</dc:creator>
		
		<category><![CDATA[Computer Security]]></category>

		<guid isPermaLink="false">http://www.joestewart.org/?p=24</guid>
		<description><![CDATA[Earlier this week, reports began to circulate in the media about Chinese hackers selling $200 USD iTunes gift cards online for 17.90 RMB (about $2.60 USD). It was explained that these hackers were able to acheive the remarkable feat of cracking Apple’s algorithm for generating the gift voucher codes, and were thus able to generate [...]]]></description>
			<content:encoded><![CDATA[<p>Earlier this week, reports began to circulate in the media about Chinese hackers selling $200 USD iTunes gift cards online for 17.90 RMB (about $2.60 USD). It was explained that these hackers were able to acheive the remarkable feat of cracking Apple’s algorithm for generating the gift voucher codes, and were thus able to generate as many cards as they liked, all of which would be redeemable in the iTunes store.</p>
<p><a href="http://www.secureworks.com/research/blog/index.php/2009/03/12/clever-hack-or-carders-at-work/">Read more&#8230;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.joestewart.org/?feed=rss2&amp;p=24</wfw:commentRss>
		</item>
		<item>
		<title>Ozdok: Watching the Watchers</title>
		<link>http://www.joestewart.org/?p=23</link>
		<comments>http://www.joestewart.org/?p=23#comments</comments>
		<pubDate>Tue, 20 Jan 2009 20:44:06 +0000</pubDate>
		<dc:creator>joe</dc:creator>
		
		<category><![CDATA[Malware Analysis]]></category>

		<category><![CDATA[Computer Security]]></category>

		<guid isPermaLink="false">http://www.joestewart.org/?p=23</guid>
		<description><![CDATA[Recently, with the help of Spamhaus, we were given access to files collected from yet another Ozdok/Mega-D command-and-control server. Although we have seen the controller code before, it was surprising to learn that this variant was collecting screenshots from its victims’ computers, and that thousands of them were stored on the control server. Grabbing screenshots [...]]]></description>
			<content:encoded><![CDATA[<p>Recently, with the help of Spamhaus, we were given access to files collected from yet another Ozdok/Mega-D command-and-control server. Although we have seen the controller code before, it was surprising to learn that this variant was collecting screenshots from its victims’ computers, and that thousands of them were stored on the control server. Grabbing screenshots isn’t new for backdoor trojans, but it’s the first time we’ve seen this functionality in a spambot.</p>
<p><a href="http://www.secureworks.com/research/blog/index.php/2009/01/20/ozdok-watching-the-watchers/">Read more&#8230;</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.joestewart.org/?feed=rss2&amp;p=23</wfw:commentRss>
		</item>
	</channel>
</rss>
