<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>chackraview.net</title>
	<atom:link href="http://blog.chackraview.net/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.chackraview.net</link>
	<description>There is no such thing as closed source software…the processor sees every instruction and so does the reverse engineer…</description>
	<lastBuildDate>Fri, 03 Feb 2012 17:51:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Snort Detection Rules for APT Malware MSUpdater.exe</title>
		<link>http://blog.chackraview.net/2012/02/03/snort-detection-rules-for-apt-malware-msupdater-exe/</link>
		<comments>http://blog.chackraview.net/2012/02/03/snort-detection-rules-for-apt-malware-msupdater-exe/#comments</comments>
		<pubDate>Fri, 03 Feb 2012 17:46:10 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[APT]]></category>
		<category><![CDATA[MSUpdater.exe]]></category>
		<category><![CDATA[Snort Rules]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=965</guid>
		<description><![CDATA[Background: On 31st January 2012, ZScalar and Seculert posted analysis on recently identified RAT malware which is believed to be used in government related targeted attacks. Both of these firms, identified command and control beacon patterns and independently published them on their respective websites. Similar to all the APT attacks, these C&#38;C patterns were built [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/02/03/snort-detection-rules-for-apt-malware-msupdater-exe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploitation of CVE-2012-0003: Heap Overflow in winmm.dll</title>
		<link>http://blog.chackraview.net/2012/01/30/exploitation-of-cve-2012-0003-heap-overflow-in-the-midioutplaynextpolyevent/</link>
		<comments>http://blog.chackraview.net/2012/01/30/exploitation-of-cve-2012-0003-heap-overflow-in-the-midioutplaynextpolyevent/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 09:28:25 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Exploitation]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[CVE-2012-0003]]></category>
		<category><![CDATA[MS12-004]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=938</guid>
		<description><![CDATA[Very first exploit for the MS12-004 was seen in the wild on last Friday. As soon as the discovery of the exploit attempt was made, researchers were quick to post their analysis on the vulnerability. Metasploit module was also made available to public in its latest revision 14640. In this post I will share a [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/30/exploitation-of-cve-2012-0003-heap-overflow-in-the-midioutplaynextpolyevent/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
<enclosure url="http://blog.chackraview.net/wp-content/uploads/2012/01/CVE-2012-0003-Exploitation.mp4" length="4154167" type="video/mp4" />
		</item>
		<item>
		<title>Understanding CVE-2012-0003: RCE in Microsoft Windows Media Player</title>
		<link>http://blog.chackraview.net/2012/01/29/understanding-cve-2012-0003-rce-in-microsoft-windows-media-player/</link>
		<comments>http://blog.chackraview.net/2012/01/29/understanding-cve-2012-0003-rce-in-microsoft-windows-media-player/#comments</comments>
		<pubDate>Mon, 30 Jan 2012 05:26:37 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Exploitation]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[CVE-2012-0003]]></category>
		<category><![CDATA[MIDI Exploit]]></category>
		<category><![CDATA[MS12-004]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=927</guid>
		<description><![CDATA[As ever, the opinions expressed in this website are personal to me and do not necessarily reflect the opinions of my employer. As part of January’s Patch Tuesday, we released 7 patches targeting 8 individual vulnerabilities. Out of these 8 vulnerabilities, I will talk about CVE-2012-0003 &#8211; memory corruption vulnerability in Windows Media component that [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/29/understanding-cve-2012-0003-rce-in-microsoft-windows-media-player/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analyzing Twitter short URLs</title>
		<link>http://blog.chackraview.net/2012/01/26/analyzing-twitter-short-urls/</link>
		<comments>http://blog.chackraview.net/2012/01/26/analyzing-twitter-short-urls/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 19:47:23 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[obama sex]]></category>
		<category><![CDATA[Short URLs]]></category>
		<category><![CDATA[TrojanDownloader:Win32/Small.AIN]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=903</guid>
		<description><![CDATA[Short URL is a concept of reducing long and non-human friendly URLs. This is especially useful when it comes to micro blogging sites like Twitter. Twitter has a word limit of only 140 characters for a tweet. Hence posting long URLs along with a descriptive message is somewhat difficult. A link shortening service from twitter [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/26/analyzing-twitter-short-urls/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anonymous rules out SOPA &amp; PIPA</title>
		<link>http://blog.chackraview.net/2012/01/23/anonymous-rules-out-sopa-pipa/</link>
		<comments>http://blog.chackraview.net/2012/01/23/anonymous-rules-out-sopa-pipa/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 19:25:12 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[JS LOIC]]></category>
		<category><![CDATA[Low Orbit Ian Cannon]]></category>
		<category><![CDATA[PIPA]]></category>
		<category><![CDATA[SOPA]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=892</guid>
		<description><![CDATA[The newly proposed legislation acts SOPA (Stop Online Piracy Act) and PIPA (Protect Intellectual Property Act) are very much controversial and are potentially bound to damage the freedom of Internet. US department of Justice shut down megaupload.com under the SOPA legislation and alleged copyright infringement. To oppose these acts many sites including Wikipedia, GoDady, took [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/23/anonymous-rules-out-sopa-pipa/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Network detection rules for WorldMail 3.0 IMAPD SEH overflow</title>
		<link>http://blog.chackraview.net/2012/01/20/network-detection-rules-for-worldmail-3-0-imapd-seh-overflow/</link>
		<comments>http://blog.chackraview.net/2012/01/20/network-detection-rules-for-worldmail-3-0-imapd-seh-overflow/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 11:02:45 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Exploitation]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[Snort Rules]]></category>
		<category><![CDATA[worldmail IMAPD SEH overflow]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=853</guid>
		<description><![CDATA[NullSecurity.net publically released a security advisory on SEH overflow in WorldMail 3.0 IMPAD product. An attacker could exploit this issue to execute arbitrary code in the context of the application. This may facilitate to the compromise of the application and underlying system. Attackers do not need to authenticate to exploit this vulnerability making its threat [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/20/network-detection-rules-for-worldmail-3-0-imapd-seh-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Network detection rules for old TFTP RRQ Buffer Overflow vulnerability</title>
		<link>http://blog.chackraview.net/2012/01/14/network-detection-rules-for-old-tftp-rrq-buffer-overflow-vulnerability/</link>
		<comments>http://blog.chackraview.net/2012/01/14/network-detection-rules-for-old-tftp-rrq-buffer-overflow-vulnerability/#comments</comments>
		<pubDate>Sat, 14 Jan 2012 11:24:24 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[CVE-2008-1611]]></category>
		<category><![CDATA[TFTP Buffer Overflow]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=849</guid>
		<description><![CDATA[Exploit-DB posted a new exploit code for old buffer overflow vulnerability in read/write request packet processing code of TFTP Server version 1.4. I thought it will be a nice rule writing practice to develop IDS detection rule for it. Below Snort rule will be help to detect the exploit attempt for this vulnerability. Snort provides [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/14/network-detection-rules-for-old-tftp-rrq-buffer-overflow-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analysis of CVE-2011-4862: Telnetd Buffer Overflow</title>
		<link>http://blog.chackraview.net/2012/01/12/analysis-of-cve-2011-4862-telnetd-buffer-overflow/</link>
		<comments>http://blog.chackraview.net/2012/01/12/analysis-of-cve-2011-4862-telnetd-buffer-overflow/#comments</comments>
		<pubDate>Thu, 12 Jan 2012 18:07:56 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Exploitation]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[CVE-2011-4862]]></category>
		<category><![CDATA[exploit detection]]></category>
		<category><![CDATA[telnetd buffer overflow]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=843</guid>
		<description><![CDATA[Just before the end of 2011, new buffer overflow vulnerability was detected in telnetd in FreeBSD 7.3 through 9.0 allowing remote attackers to execute arbitrary code. This vulnerability was tracked under CVE-2011-4862 and exploited in the wild. We all know that telnet sends data in plain text over wire and can be easily eavesdropped. To [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/12/analysis-of-cve-2011-4862-telnetd-buffer-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The system cannot find the path specified: Demystified</title>
		<link>http://blog.chackraview.net/2012/01/09/the-system-cannot-find-the-path-specified-demystified/</link>
		<comments>http://blog.chackraview.net/2012/01/09/the-system-cannot-find-the-path-specified-demystified/#comments</comments>
		<pubDate>Mon, 09 Jan 2012 16:47:56 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Error code : 3]]></category>
		<category><![CDATA[FS Redirector]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=838</guid>
		<description><![CDATA[Have you ever tried running some cryptographic hash calculator on some of the existing system files? Or even tried reading them programmatically and it failed with below error?        Error msg  : The system cannot find the path specified. Guess what, I had a similar issue last weekend.  I knew file existed at the location [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/09/the-system-cannot-find-the-path-specified-demystified/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>SNORT Rules for CVE-2011-3416</title>
		<link>http://blog.chackraview.net/2012/01/05/snort-rules-for-cve-2011-3416/</link>
		<comments>http://blog.chackraview.net/2012/01/05/snort-rules-for-cve-2011-3416/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 06:37:54 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Snort Signature]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[CVE-2011-3416]]></category>
		<category><![CDATA[Snort Rules]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=829</guid>
		<description><![CDATA[Just before we say good bye to 2011, Microsoft released a security bulletin for escalation of privileges vulnerability in .Net Framework. NIST describe the vulnerability as &#8211; The Forms Authentication feature in the ASP.NET subsystem in Microsoft .NET Framework 1.1 SP1, 2.0 SP2, 3.5 SP1, 3.5.1, and 4.0 allows remote authenticated users to obtain access [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2012/01/05/snort-rules-for-cve-2011-3416/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

