<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>chackraview.net &#187; Information Security</title>
	<atom:link href="http://blog.chackraview.net/category/information-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.chackraview.net</link>
	<description>There is no such thing as closed source software…the processor sees every instruction and so does the reverse engineer…</description>
	<lastBuildDate>Fri, 03 Feb 2012 17:51:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Exploitation of CVE-2012-0003: Heap Overflow in winmm.dll</title>
		<link>http://blog.chackraview.net/2012/01/30/exploitation-of-cve-2012-0003-heap-overflow-in-the-midioutplaynextpolyevent/</link>
		<comments>http://blog.chackraview.net/2012/01/30/exploitation-of-cve-2012-0003-heap-overflow-in-the-midioutplaynextpolyevent/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 09:28:25 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Exploitation]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[CVE-2012-0003]]></category>
		<category><![CDATA[MS12-004]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=938</guid>
		<description><![CDATA[Very first exploit for the MS12-004 was seen in the wild on last Friday. As soon as the discovery of the exploit attempt was made, researchers were quick to post their analysis on the vulnerability. Metasploit module was also made available to public in its latest revision 14640. In this post I will share a [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/30/exploitation-of-cve-2012-0003-heap-overflow-in-the-midioutplaynextpolyevent/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://blog.chackraview.net/wp-content/uploads/2012/01/CVE-2012-0003-Exploitation.mp4" length="4154167" type="video/mp4" />
		</item>
		<item>
		<title>Understanding CVE-2012-0003: RCE in Microsoft Windows Media Player</title>
		<link>http://blog.chackraview.net/2012/01/29/understanding-cve-2012-0003-rce-in-microsoft-windows-media-player/</link>
		<comments>http://blog.chackraview.net/2012/01/29/understanding-cve-2012-0003-rce-in-microsoft-windows-media-player/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 05:26:37 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Exploitation]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[CVE-2012-0003]]></category>
		<category><![CDATA[MIDI Exploit]]></category>
		<category><![CDATA[MS12-004]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=927</guid>
		<description><![CDATA[As ever, the opinions expressed in this website are personal to me and do not necessarily reflect the opinions of my employer. As part of January’s Patch Tuesday, we released 7 patches targeting 8 individual vulnerabilities. Out of these 8 vulnerabilities, I will talk about CVE-2012-0003 &#8211; memory corruption vulnerability in Windows Media component that [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/29/understanding-cve-2012-0003-rce-in-microsoft-windows-media-player/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anonymous rules out SOPA &amp; PIPA</title>
		<link>http://blog.chackraview.net/2012/01/23/anonymous-rules-out-sopa-pipa/</link>
		<comments>http://blog.chackraview.net/2012/01/23/anonymous-rules-out-sopa-pipa/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 19:25:12 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[JS LOIC]]></category>
		<category><![CDATA[Low Orbit Ian Cannon]]></category>
		<category><![CDATA[PIPA]]></category>
		<category><![CDATA[SOPA]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=892</guid>
		<description><![CDATA[The newly proposed legislation acts SOPA (Stop Online Piracy Act) and PIPA (Protect Intellectual Property Act) are very much controversial and are potentially bound to damage the freedom of Internet. US department of Justice shut down megaupload.com under the SOPA legislation and alleged copyright infringement. To oppose these acts many sites including Wikipedia, GoDady, took [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/23/anonymous-rules-out-sopa-pipa/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Network detection rules for WorldMail 3.0 IMAPD SEH overflow</title>
		<link>http://blog.chackraview.net/2012/01/20/network-detection-rules-for-worldmail-3-0-imapd-seh-overflow/</link>
		<comments>http://blog.chackraview.net/2012/01/20/network-detection-rules-for-worldmail-3-0-imapd-seh-overflow/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 11:02:45 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Exploitation]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[Snort Rules]]></category>
		<category><![CDATA[worldmail IMAPD SEH overflow]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=853</guid>
		<description><![CDATA[NullSecurity.net publically released a security advisory on SEH overflow in WorldMail 3.0 IMPAD product. An attacker could exploit this issue to execute arbitrary code in the context of the application. This may facilitate to the compromise of the application and underlying system. Attackers do not need to authenticate to exploit this vulnerability making its threat [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/20/network-detection-rules-for-worldmail-3-0-imapd-seh-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Network detection rules for old TFTP RRQ Buffer Overflow vulnerability</title>
		<link>http://blog.chackraview.net/2012/01/14/network-detection-rules-for-old-tftp-rrq-buffer-overflow-vulnerability/</link>
		<comments>http://blog.chackraview.net/2012/01/14/network-detection-rules-for-old-tftp-rrq-buffer-overflow-vulnerability/#comments</comments>
		<pubDate>Sat, 14 Jan 2012 11:24:24 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[CVE-2008-1611]]></category>
		<category><![CDATA[TFTP Buffer Overflow]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=849</guid>
		<description><![CDATA[Exploit-DB posted a new exploit code for old buffer overflow vulnerability in read/write request packet processing code of TFTP Server version 1.4. I thought it will be a nice rule writing practice to develop IDS detection rule for it. Below Snort rule will be help to detect the exploit attempt for this vulnerability. Snort provides [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/14/network-detection-rules-for-old-tftp-rrq-buffer-overflow-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analysis of CVE-2011-4862: Telnetd Buffer Overflow</title>
		<link>http://blog.chackraview.net/2012/01/12/analysis-of-cve-2011-4862-telnetd-buffer-overflow/</link>
		<comments>http://blog.chackraview.net/2012/01/12/analysis-of-cve-2011-4862-telnetd-buffer-overflow/#comments</comments>
		<pubDate>Thu, 12 Jan 2012 18:07:56 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Exploitation]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[CVE-2011-4862]]></category>
		<category><![CDATA[exploit detection]]></category>
		<category><![CDATA[telnetd buffer overflow]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=843</guid>
		<description><![CDATA[Just before the end of 2011, new buffer overflow vulnerability was detected in telnetd in FreeBSD 7.3 through 9.0 allowing remote attackers to execute arbitrary code. This vulnerability was tracked under CVE-2011-4862 and exploited in the wild. We all know that telnet sends data in plain text over wire and can be easily eavesdropped. To [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/12/analysis-of-cve-2011-4862-telnetd-buffer-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SNORT Rules for CVE-2011-3416</title>
		<link>http://blog.chackraview.net/2012/01/05/snort-rules-for-cve-2011-3416/</link>
		<comments>http://blog.chackraview.net/2012/01/05/snort-rules-for-cve-2011-3416/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 06:37:54 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[CVE-2011-3416]]></category>
		<category><![CDATA[Snort Rules]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=829</guid>
		<description><![CDATA[Just before we say good bye to 2011, Microsoft released a security bulletin for escalation of privileges vulnerability in .Net Framework. NIST describe the vulnerability as &#8211; The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/05/snort-rules-for-cve-2011-3416/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analysis of CVE-2010-806 (IEPeers.dll) Use-After-Free Vulnerability</title>
		<link>http://blog.chackraview.net/2011/10/01/analysis-of-cve-2010-806-iepeers-dll-use-after-free-vulnerability/</link>
		<comments>http://blog.chackraview.net/2011/10/01/analysis-of-cve-2010-806-iepeers-dll-use-after-free-vulnerability/#comments</comments>
		<pubDate>Sat, 01 Oct 2011 12:00:32 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[CVE-2010-806]]></category>
		<category><![CDATA[Web attacks]]></category>
		<category><![CDATA[Webpwnd.A]]></category>
		<category><![CDATA[Zuten.gen!A]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=761</guid>
		<description><![CDATA[This is a quick post about some of the analysis I did in the start of this week. This is a case of yet another exploit for CVE-2010-0806. I am seeing exploits for this vulnerability floating a lot from past couple of months. As described on mitre.org: &#8220;Use-after-free vulnerability in the Peer Objects component (aka [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2011/10/01/analysis-of-cve-2010-806-iepeers-dll-use-after-free-vulnerability/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Analysis of CVE-2007-0024 Exploit and its Payload</title>
		<link>http://blog.chackraview.net/2011/07/14/analysis-of-cve-2007-0024-exploit-and-its-payload/</link>
		<comments>http://blog.chackraview.net/2011/07/14/analysis-of-cve-2007-0024-exploit-and-its-payload/#comments</comments>
		<pubDate>Thu, 14 Jul 2011 17:13:31 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Reverse Engineering]]></category>
		<category><![CDATA[CVE-2007-024]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[MS10-004]]></category>
		<category><![CDATA[PWS:Win32/OnLineGames.KN]]></category>
		<category><![CDATA[Trojan:Win32/Sistyserav.A]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=741</guid>
		<description><![CDATA[CVE-2007-0024 is quite old and you might think, there would be no more active exploitation of this vulnerability as it was patched long back. I will say, think again. Today, I analyzed live attack while exploiting above vulnerability. Here is the gist of my analysis. Overview of CVE-2007-0024: An Integer overflow in the Vector Markup [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2011/07/14/analysis-of-cve-2007-0024-exploit-and-its-payload/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Layman&#8217;s guide to remove FakeAV malware</title>
		<link>http://blog.chackraview.net/2011/06/14/laymans-guide-to-remove-fakeav-malware/</link>
		<comments>http://blog.chackraview.net/2011/06/14/laymans-guide-to-remove-fakeav-malware/#comments</comments>
		<pubDate>Tue, 14 Jun 2011 16:50:47 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[BestAntivirus2011]]></category>
		<category><![CDATA[FakeAV]]></category>
		<category><![CDATA[MS Removal tool]]></category>
		<category><![CDATA[WinWebSec]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=727</guid>
		<description><![CDATA[In my previous blog post, I talked about FakeAV malware and its new techniques to spread by disguising legitimate software download. In this post I will talk about a very simple technique to clean the FakeAV infection. Before I talk about the infection removal, let me list out all the measures taken by malware to prevent [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2011/06/14/laymans-guide-to-remove-fakeav-malware/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

