<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-35973745</id><updated>2011-12-14T18:38:52.221-08:00</updated><category term='filename con aux nul'/><category term='hide file metadata'/><category term='Img807.zip MsnPoopy vpcrtf virus'/><category term='tech ShowCert X.509 certificates'/><title type='text'>Matrixalaya</title><subtitle type='html'>Circling around computer, philosophy and music.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://matrixalaya.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://matrixalaya.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>GNUlihd</name><uri>http://www.blogger.com/profile/05810387471599613365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>7</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-35973745.post-3837493294368918750</id><published>2007-08-14T02:57:00.000-07:00</published><updated>2007-08-14T05:17:52.149-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Img807.zip MsnPoopy vpcrtf virus'/><title type='text'>Img807.zip or MsnPoopy</title><content type='html'>Yesterday I was receiving some innocuous looking file transfer requests from my friends in &lt;i&gt;MSN Messenger&lt;/i&gt;. File was &lt;span&gt;&lt;i&gt;&lt;span style="color:#990000;"&gt;Img807.zip&lt;/span&gt;&lt;/i&gt;&lt;/span&gt; with message like&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#990000;"&gt;&lt;span&gt;&lt;i&gt;Did you take this picture?&lt;br /&gt;is that you on the left?&lt;br /&gt;How drunk was I in this picture?&lt;br /&gt;Is that your mom in this picture?&lt;br /&gt;lol, your mom just sent me this picture?&lt;/i&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Zip contains a file&lt;span style="color:#990000;"&gt; &lt;i&gt;&lt;span&gt;img807.jpg-www.photoalbums.com&lt;/span&gt;&lt;/i&gt;&lt;/span&gt; which seems like a url. This was actually a worm!&lt;br /&gt;&lt;br /&gt;I have written a small&lt;strong&gt;&lt;span&gt; &lt;/span&gt;&lt;/strong&gt;&lt;a href="http://gnulihd.110mb.com/bin/tools/cleanvpc.zip"&gt;&lt;strong&gt;&lt;span&gt;removal tool&lt;/span&gt;&lt;/strong&gt;&lt;/a&gt;. You can get it&lt;a href="http://gnulihd.110mb.com/bin/tools/cleanvpc.zip"&gt; here&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;It seems to be a variant of worm &lt;a href="http://www.pandasecurity.com/homeusers/security-info/about-malware/encyclopedia/overview.aspx?lst=det&amp;idvirus=170240"&gt;MsnPoopy.A&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Quick analysis shows that.&lt;br /&gt;1. It creates a batch file&lt;span&gt; &lt;/span&gt;&lt;span style="color:#990000;"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;c:\a.bat&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt; (deleted later) to execute the worm.&lt;br /&gt;&lt;br /&gt;2. Stops “Security Center” and any running VNC servers (&lt;span&gt;net1 stop winvnc4&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;3. Creates two files&lt;span style="color:#990000;"&gt; &lt;span&gt;&lt;span&gt;&lt;span&gt;c:\windows\vpcrtf.exe&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt; &lt;/span&gt;and &lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;span style="color:#990000;"&gt;c:\windows\img807.zip&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;. The original .com file and the vpcrtf.exe is same files (MD5&lt;span&gt; &lt;/span&gt;&lt;span style="color:#666666;"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;7299c5d5d5761779dfedfbd3808c8ed8&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;4. Modifies IE Security Zonemaps and resets IE BypassProxy to enabled. (&lt;span&gt;&lt;span&gt;&lt;span style="color:#990000;"&gt;HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;5. Creates a startup entry named “&lt;span style="color:#990000;"&gt;&lt;span&gt;&lt;span&gt;Microsoft Visual Application&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;” at &lt;i&gt;&lt;span&gt;&lt;span&gt;&lt;span style="color:#990000;"&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/i&gt;&lt;br /&gt;6. Creates connection to 85.114.143.159 (&lt;span style="color:#990000;"&gt;&lt;span&gt;&lt;span&gt;chat2.ms.com&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;). Excerpt of the TCP stream shows it is creating a chat session to that server with a random name.&lt;br /&gt;&lt;br /&gt;Text like this was found inside the exe.&lt;br /&gt;&lt;br /&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color:#990000;"&gt;&lt;span&gt;&lt;span&gt;[DDoS]: Flooding %s:%s with %s for %s seconds&lt;br /&gt;[DDoS]: Done with flood (%iKB/sec).&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Commands used in chat server are&lt;br /&gt;&lt;span style="color:#999999;"&gt;&lt;span style="font-size:85%;"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;PASS %s&lt;br /&gt;NICK %s&lt;br /&gt;USER %s * 0 :%s&lt;br /&gt;Leaving&lt;br /&gt;QUIT %s&lt;br /&gt;QUIT&lt;br /&gt;JOIN&lt;br /&gt;PART&lt;br /&gt;QUIT&lt;br /&gt;NOTICE&lt;br /&gt;PRIVMSG&lt;br /&gt;NICK&lt;br /&gt;PING&lt;br /&gt;PONG %s&lt;br /&gt;NOTICE %s :%s&lt;br /&gt;PRIVMSG %s :%s&lt;br /&gt;PRIVMSG %s :%s&lt;br /&gt;JOIN %s&lt;br /&gt;JOIN %s %s&lt;br /&gt;PART %s&lt;br /&gt;MODE %s %s&lt;br /&gt;MODE %s %s %s&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;An instance of communication to chat2.ms.com&lt;br /&gt;&lt;span style="color:#999999;"&gt;&lt;span style="font-size:78%;"&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;PASS letmein&lt;br /&gt;NICK drcdetbkfr&lt;br /&gt;USER drcdetbkfr * 0 :XXXXX&lt;br /&gt;:chat2.ms.com NOTICE AUTH :*** Looking up your hostname...&lt;br /&gt;:chat2.ms.com NOTICE AUTH :*** Couldn't resolve your hostname; using your IP address instead&lt;br /&gt;:chat2.ms.com NOTICE drcdetbkfr :*** If you are having problems connecting due to ping timeouts, please type /quote pong E7514D5C or /raw pong E7514D5C now.&lt;br /&gt;PING :E7514D5C&lt;br /&gt;PONG E7514D5C&lt;br /&gt;:chat2.ms.com 001 drcdetbkfr&lt;br /&gt;:chat2.ms.com 002 drcdetbkfr :               M0dded by uNkn0wn Crew       &lt;br /&gt;:chat2.ms.com 003 drcdetbkfr&lt;br /&gt;:chat2.ms.com 004 drcdetbkfr :          www.uNkn0wn.eu - iD@uNkn0wn.eu    &lt;br /&gt;:chat2.ms.com 005 drcdetbkfr&lt;br /&gt;:chat2.ms.com 005 drcdetbkfr&lt;br /&gt;:chat2.ms.com 005 drcdetbkfr&lt;br /&gt;:chat2.ms.com 422 drcdetbkfr :MOTD File is missing&lt;br /&gt;:drcdetbkfr MODE drcdetbkfr :+iwxG&lt;br /&gt;MODE drcdetbkfr -ix&lt;br /&gt;JOIN ##L## torrent&lt;br /&gt;MODE drcdetbkfr -ix&lt;br /&gt;JOIN ##L## torrent&lt;br /&gt;MODE drcdetbkfr -ix&lt;br /&gt;JOIN ##L## torrent&lt;br /&gt;MODE drcdetbkfr -ix&lt;br /&gt;JOIN ##L## torrent&lt;br /&gt;:drcdetbkfr!drcdetbkfr@18BA964C.E3E058E5.86DFE602.IP JOIN :##l##&lt;br /&gt;:chat2.ms.com 332 drcdetbkfr ##l## :.msnstop|.msnstart&lt;br /&gt;:chat2.ms.com 333 drcdetbkfr ##l## C 1186984256&lt;br /&gt;:jmixkwtc!jmixkwtc@adsl-pool-222.123.92-138.tttmaxnet.com JOIN :##l##&lt;br /&gt;:xfjgadoe!nawcggrq@222.111.240.15 JOIN :##l##&lt;br /&gt;:toltsnwg!toltsnwg@0wn3d-5CBFC5F9.adsl.totbb.net QUIT :Ping timeout&lt;br /&gt;PRIVMSG ##l## :MSN Spread Has Been Deactivated.&lt;br /&gt;:xgdpzrej!xgdpzrej@0wn3d-B63C2A2.hinet-ip.hinet.net QUIT :Connection reset by peer&lt;br /&gt;:lfysnvlf!lfysnvlf@0wn3d-B63C2A2.hinet-ip.hinet.net QUIT :Connection reset by peer&lt;br /&gt;:chat2.ms.com 404 drcdetbkfr ##l## :You must have a registered nick (+r) to talk on this channel (##l##)&lt;br /&gt;:kqeocoup!kqeocoup@0wn3d-E41BFE89.tttmaxnet.com JOIN :##l##&lt;br /&gt;:lyoiwhnz!lyoiwhnz@0wn3d-6F3B1EB.revip2.asianet.co.th JOIN :##l##&lt;br /&gt;:kulbdupj!kulbdupj@aworklan024095.netvigator.com QUIT :Connection reset by peer&lt;br /&gt;:cfpmzenv!cfpmzenv@A634004F.F5AADB4E.2BA61D.IP QUIT :Ping timeout&lt;br /&gt;PRIVMSG ##l## :MSN worm sent to: 0 contacts&lt;br /&gt;&lt;br /&gt;:koopoxxg!koopoxxg@59.44.43.155 JOIN :##l##&lt;br /&gt;:ztuxqkph!ztuxqkph@0wn3d-B63C2A2.hinet-ip.hinet.net QUIT :Connection reset by peer&lt;br /&gt;PRIVMSG ##l## :MSN Spread Has Been Activated.&lt;br /&gt;:chat2.ms.com 404 drcdetbkfr ##l## :You must have a registered nick (+r) to talk on this channel (##l##)&lt;br /&gt;:chat2.ms.com 404 drcdetbkfr ##l## :You must have a registered nick (+r) to talk on this channel (##l##)&lt;br /&gt;:zmqtlvgt!zmqtlvgt@B1CADB.3F468E44.D7B2BA0C.IP JOIN :##l##&lt;br /&gt;:ldsjwlel!ldsjwlel@0wn3d-5269B4BC.totbb.net JOIN :##l##&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;a href="http://gnulihd.110mb.com/bin/tools/cleanvpc.zip"&gt;&lt;strong&gt;Removal tool&lt;/strong&gt;&lt;/a&gt;&lt;span&gt; simply kills vpcrtf.exe ,remove two files windows\vpcrt.exe and  windows\img807.zip and the registry startup entry.&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35973745-3837493294368918750?l=matrixalaya.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://matrixalaya.blogspot.com/feeds/3837493294368918750/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=35973745&amp;postID=3837493294368918750' title='10 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/3837493294368918750'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/3837493294368918750'/><link rel='alternate' type='text/html' href='http://matrixalaya.blogspot.com/2007/08/img807zip-or-msnpoopy.html' title='Img807.zip or MsnPoopy'/><author><name>GNUlihd</name><uri>http://www.blogger.com/profile/05810387471599613365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>10</thr:total></entry><entry><id>tag:blogger.com,1999:blog-35973745.post-8867535714919438243</id><published>2007-07-04T06:18:00.000-07:00</published><updated>2007-07-04T06:31:57.843-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='hide file metadata'/><title type='text'>Hiding a file (a simple way)</title><content type='html'>&lt;span style="font-size:100%;"&gt;Go to command prompt and enter following command&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;C:\&gt;notepad visible.txt:hidden.txt&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Enter text in the new notepad window and save it.&lt;br /&gt;A new file &lt;span style="font-weight: bold;"&gt;visible.txt&lt;/span&gt; will be created but it will be &lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;blank&lt;/span&gt;!!&lt;br /&gt;You can not find ‘&lt;span style="font-style: italic;"&gt;C:\visible.txt:hidden.txt&lt;/span&gt;’ but its there along with its content you have just typed!!&lt;br /&gt;&lt;br /&gt;To prove it enter the same command&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;C:\&gt;notepad visible.txt:hidden.txt&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;Note:&lt;br /&gt;1)     You canchoose some secret filename after visible.txt: so others can’t guess.&lt;br /&gt;2)     You can add any number of hidden files corresponding to one visible file.&lt;br /&gt;   e.g.&lt;br /&gt;       visible.txt:hide&lt;br /&gt;       visible.txt:hello&lt;br /&gt;       visible.txt:secrete&lt;br /&gt;3) If file content of visible file is modified or deleted all the hidden files will be deleted :(.&lt;br /&gt;Well, that's a big problem. Simplicity comes with price anyways.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35973745-8867535714919438243?l=matrixalaya.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://matrixalaya.blogspot.com/feeds/8867535714919438243/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=35973745&amp;postID=8867535714919438243' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/8867535714919438243'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/8867535714919438243'/><link rel='alternate' type='text/html' href='http://matrixalaya.blogspot.com/2007/07/hiding-file-simple-way.html' title='Hiding a file (a simple way)'/><author><name>GNUlihd</name><uri>http://www.blogger.com/profile/05810387471599613365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-35973745.post-996551423438391774</id><published>2007-07-04T06:02:00.000-07:00</published><updated>2007-07-04T06:31:23.837-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='filename con aux nul'/><title type='text'>Filename con</title><content type='html'>&lt;p style="color: rgb(0, 0, 0);" class="MsoNormal"&gt;&lt;span style=";font-family:Verdana;font-size:100%;"  &gt;Can you rename any of your file or folder to filename &lt;b&gt;con&lt;/b&gt;?&lt;br /&gt;Try the same with filename &lt;b&gt;aux&lt;/b&gt; or &lt;b&gt;nul&lt;/b&gt;. Try saving this webpage as &lt;span style="font-weight: bold;"&gt;con.html&lt;/span&gt;.&lt;o:p&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;                &lt;p style="color: rgb(0, 0, 0);" class="MsoNormal"&gt;&lt;span style=";font-family:Verdana;font-size:100%;"  &gt;Quick googling will tell that these are the reserved filenames (character devices).&lt;br /&gt;Do you remember using ‘&lt;b&gt;copy con&lt;/b&gt;’ command in old DOS world as &lt;b&gt;copy con test.txt&lt;/b&gt;?&lt;br /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;span style="font-family:Verdana;"&gt;con&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=";font-family:Verdana;font-size:100%;"  &gt; is for &lt;b&gt;con&lt;/b&gt;sole and it simply copies ‘console input file’ to test.txt.&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;so,&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;br /&gt;&lt;b style="font-style: italic;"&gt;&lt;span style="font-family:Verdana;"&gt;copy test.txt con&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span style=";font-family:Verdana;font-size:100%;"  &gt;&lt;span style="font-style: italic;"&gt; &lt;/span&gt;&lt;br /&gt;is equivalent to &lt;b&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;type test.txt&lt;/span&gt;&lt;/b&gt;&lt;o:p&gt;&lt;span style="font-style: italic;"&gt; &lt;/span&gt;&lt;br /&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p style="color: rgb(0, 0, 0);" class="MsoNormal"&gt;&lt;span style=";font-family:Verdana;font-size:100%;"  &gt;Another filename &lt;b&gt;nul&lt;/b&gt; behaves like a file which is not.&lt;br /&gt;It’s like a black hole :-) It swallows everything and nothing comes out.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;        &lt;p style="color: rgb(0, 0, 0);" class="MsoNormal"&gt;&lt;span style=";font-family:Verdana;font-size:100%;"  &gt;e.g.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;dir&gt;nul&lt;br /&gt;type nul&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;copy con nul&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;type nul&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;          &lt;p class="MsoNormal" style="margin-left: 3.75pt; color: rgb(0, 0, 0);"&gt;&lt;span style=";font-family:Verdana;font-size:85%;"  &gt;List of reserved filenames from wiki:&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left: 3.75pt; color: rgb(0, 0, 0);"&gt;&lt;span style=";font-family:Verdana;font-size:85%;"  &gt;CON, PRN, AUX, CLOCK$, NUL&lt;br /&gt;COM0, COM1, COM2, COM3, COM4, COM5, COM6, COM7, COM8, COM9&lt;br /&gt;LPT0, LPT1, LPT2, LPT3, LPT4, LPT5, LPT6, LPT7, LPT8, and LPT9.&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35973745-996551423438391774?l=matrixalaya.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://matrixalaya.blogspot.com/feeds/996551423438391774/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=35973745&amp;postID=996551423438391774' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/996551423438391774'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/996551423438391774'/><link rel='alternate' type='text/html' href='http://matrixalaya.blogspot.com/2007/07/filename-con.html' title='Filename con'/><author><name>GNUlihd</name><uri>http://www.blogger.com/profile/05810387471599613365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-35973745.post-7704361958362569659</id><published>2007-04-06T04:41:00.000-07:00</published><updated>2007-10-05T01:55:02.779-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='tech ShowCert X.509 certificates'/><title type='text'>View Certificates</title><content type='html'>&lt;p class="MsoNormal"&gt;I have written a small tool &lt;a href="http://gnulihd.110mb.com/bin/my_utils/ShowCert.zip"&gt;ShowCert (88KB)&lt;/a&gt; to view certificate content without importing it in to the personal certificate store. Get it &lt;a href="http://gnulihd.110mb.com/bin/my_utils/ShowCert.zip"&gt;here &lt;/a&gt;.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;Currently it supports&lt;br /&gt;&lt;br /&gt; X.509 files (*.cer;*.crt)&lt;/p&gt;&lt;p class="MsoNormal"&gt;PKCS #7 files  (*.p7b)&lt;/p&gt;&lt;p class="MsoNormal"&gt;ASN raw certificate files (*.bin)&lt;/p&gt;&lt;p class="MsoNormal"&gt;and password protected PFX files.  (*.pfx,*.p12)&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;strong&gt;(Update Oct07)&lt;br /&gt;&lt;/strong&gt;&lt;/i&gt;&lt;i&gt;File open dialog box and&lt;br /&gt;Base64 encoded pfx/cer files (*.txt) support&lt;br /&gt;&lt;br /&gt;e.g. Save following text in a txt file and open with ShowCert.&lt;br /&gt;&lt;/i&gt;&lt;span style="font-family:courier new;"&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;-----BEGIN CERTIFICATE-----&lt;br /&gt;MIIDAjCCAmsCEB9CKF88iA+OPImzhLOrHxwwDQYJKoZIhvcNAQEFBQAwgcExCzAJ&lt;br /&gt;BgNVBAYTAlVTMRcwFQYDVQQKEw5WZXJpU2lnbiwgSW5jLjE8MDoGA1UECxMzQ2xh&lt;br /&gt;c3MgMiBQdWJsaWMgUHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEcy&lt;br /&gt;MTowOAYDVQQLEzEoYykgMTk5OCBWZXJpU2lnbiwgSW5jLiAtIEZvciBhdXRob3Jp&lt;br /&gt;emVkIHVzZSBvbmx5MR8wHQYDVQQLExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMB4X&lt;br /&gt;DTk4MDUxODAwMDAwMFoXDTE4MDUxODIzNTk1OVowgcExCzAJBgNVBAYTAlVTMRcw&lt;br /&gt;FQYDVQQKEw5WZXJpU2lnbiwgSW5jLjE8MDoGA1UECxMzQ2xhc3MgMiBQdWJsaWMg&lt;br /&gt;UHJpbWFyeSBDZXJ0aWZpY2F0aW9uIEF1dGhvcml0eSAtIEcyMTowOAYDVQQLEzEo&lt;br /&gt;YykgMTk5OCBWZXJpU2lnbiwgSW5jLiAtIEZvciBhdXRob3JpemVkIHVzZSBvbmx5&lt;br /&gt;MR8wHQYDVQQLExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMIGfMA0GCSqGSIb3DQEB&lt;br /&gt;AQUAA4GNADCBiQKBgQCniAEhdCznGgPwmOGXPA8hCPGc25fpmvzCBAYTvl9SyMwe&lt;br /&gt;LBJWLLgBaSzMmR+tsJaueQTyEznBe5i6CCzowoQTLKpp6Qn0x6kCpELCI09K2PAO&lt;br /&gt;ovsxbMnmb5knB/Xm9Ex4nm3rRob6uYbJVPKyxK/URhxayRUw/w1s9S0Obc5/dwID&lt;br /&gt;AQABMA0GCSqGSIb3DQEBBQUAA4GBABFFqKR/8eNzIMq97t/1hyORPY2sR0Ua3m3b&lt;br /&gt;VCHODoMO+NzlQ9XrLmGRI+JyADRV98TPETPdweQiI1xQUxn4ZOf3CQ9FUaBXK9+8&lt;br /&gt;Imb+MXB7JToPxYp+w7tyAczwvU1SgaQbWFhT1VM69Q5q2umvxOFY80JvVGJHrDGU&lt;br /&gt;0Q3O7x0x&lt;br /&gt;-----END CERTIFICATE-----&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;i&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/i&gt;&lt;i&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/i&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35973745-7704361958362569659?l=matrixalaya.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://matrixalaya.blogspot.com/feeds/7704361958362569659/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=35973745&amp;postID=7704361958362569659' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/7704361958362569659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/7704361958362569659'/><link rel='alternate' type='text/html' href='http://matrixalaya.blogspot.com/2007/04/view-certificates.html' title='View Certificates'/><author><name>GNUlihd</name><uri>http://www.blogger.com/profile/05810387471599613365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-35973745.post-1293581065566719994</id><published>2007-04-02T04:28:00.000-07:00</published><updated>2007-04-06T04:41:26.415-07:00</updated><title type='text'>Hacked By GNUlihd???</title><content type='html'>&lt;p class="MsoNormal"&gt;One day I was analyzing code of a simple worm “VBS/Solow-A” for educational purpose. I had explained to my friends that how it was exploiting the VB script host to spread itself from removable drive. I was surprised to be informed that same thing was modified to include my email address. I noticed that only when my brother’s friend informed me about that.&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;I told them not to worry as it simply modifies some common registry keys and nothing more. I am not that stupid to put my email address that way anyway. Who wants to help spammers ;-)&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;What it does.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;1)&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Copies itself (MFC32DLL.dll.vbs) to windows directory and all drives root path&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;i&gt;&lt;span style=""&gt;2)&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/i&gt;&lt;!--[endif]--&gt;Modifies registry value “&lt;i&gt;Window Title”&lt;/i&gt; at &lt;i&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\ &lt;/i&gt;with value &lt;i&gt;“Hacked by GNUl..@...”&lt;o:p&gt;&lt;/o:p&gt;&lt;/i&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;3)&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Adds registry entry “MS32DLL” at &lt;i&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\W indows\ CurrentVersion\Run\ &lt;/i&gt;with value “&lt;windowspath&gt;\MFC32DLL.dll.vbs” which is an autorun entry that executes the script each time windows starts.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Here is how to remove it. If you find following instructions difficult to understand you can read this one (http://www.icimod.org.np/icimodwiki/images/8/87/Mfc32dll.pdf). Thanks Anjesh. I gave a thought of writing a removal tool but the instructions are more educational.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;1)&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Open taskmanager and end process “wscript.exe”. “wscript.exe” is a Microsoft VB script host application which is running the script in the background. Mark’s ProcessExplorer is the best replacement of simple taskmanager.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;2)&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Delete “autorun.inf” and “MFC32DLL.dll.vbs” files from following directories. (you may need to check “Show hidden files and folders” and uncheck “Hide protected operating system files” at Folder Options-&gt;View which you can restore after removal)&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;a.&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;       &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;All Drives root paths. i.e. C:\autorun.inf; C:\ MFC32DLL.dll.vbs; D:\autorun.inf; D:\ MFC32DLL.dll.vbs etc.&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 1in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;b.&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Only “MFC32DLL.dll.vbs” from Windows directory. e.g. C:\Windows&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;3)&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Delete registry value “MS32DLL” from &lt;i&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run. &lt;/i&gt;(For those who don’t know: type “regedit.exe” at run and navigate to path &lt;i&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run &lt;/i&gt;&lt;span style=""&gt;to get the entry &lt;/span&gt;“MS32DLL” for deletion. There might be other entries too which are the autorun entries for each windows start.)&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-left: 0.5in; text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style=""&gt;4)&lt;span style="font-family: &amp;quot;Times New Roman&amp;quot;; font-style: normal; font-variant: normal; font-weight: normal; font-size: 7pt; line-height: normal; font-size-adjust: none; font-stretch: normal;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;This one is interesting one if you already don’t know. Navigate in regedit.exe to &lt;i&gt;HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main&lt;/i&gt; and find “Window Title” value in the other pane. Double click to edit its value to anything you like (“My IE” to “IE Sucks”). Re-Open internet explorer and enjoy. (No thing to do with &lt;a href="http://www.mozilla.com"&gt;Firefox&lt;/a&gt; fans like me)&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35973745-1293581065566719994?l=matrixalaya.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://matrixalaya.blogspot.com/feeds/1293581065566719994/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=35973745&amp;postID=1293581065566719994' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/1293581065566719994'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/1293581065566719994'/><link rel='alternate' type='text/html' href='http://matrixalaya.blogspot.com/2007/04/hacked-by-gnulihd.html' title='Hacked By GNUlihd???'/><author><name>GNUlihd</name><uri>http://www.blogger.com/profile/05810387471599613365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-35973745.post-8738780960807181883</id><published>2007-03-20T06:01:00.000-07:00</published><updated>2007-03-21T06:06:20.146-07:00</updated><title type='text'>Google privacy practice</title><content type='html'>&lt;span style="font-style: italic;"&gt;&lt;a href="http://googleblog.blogspot.com/2007/03/taking-steps-to-further-improve-our.html"&gt;http://googleblog.blogspot.com/2007/03/taking-steps-to-further-improve-our.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;"When you search on Google, we collect information about your search, such as the &lt;span style="color: rgb(255, 102, 102);"&gt;query itself, IP addresses and cookie details&lt;/span&gt;. Previously, we kept this data for as long as it was useful. Today we're pleased to report a change in our privacy policy: Unless we're legally required to retain log data for longer, we will anonymize our server logs after a limited period of time. When we implement this policy change in the coming months, we will continue to keep server log data (so that we can improve Google's services and protect them from security and other abuses)—but will make this data much more anonymous, so that it can no longer be identified with individual users, after &lt;span style="font-weight: bold;"&gt;18-24 months.&lt;/span&gt;"&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35973745-8738780960807181883?l=matrixalaya.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://matrixalaya.blogspot.com/feeds/8738780960807181883/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=35973745&amp;postID=8738780960807181883' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/8738780960807181883'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/8738780960807181883'/><link rel='alternate' type='text/html' href='http://matrixalaya.blogspot.com/2007/03/google-privacy-practice.html' title='Google privacy practice'/><author><name>GNUlihd</name><uri>http://www.blogger.com/profile/05810387471599613365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-35973745.post-116075768377960856</id><published>2006-10-13T09:30:00.000-07:00</published><updated>2006-10-13T09:41:23.786-07:00</updated><title type='text'></title><content type='html'>&lt;span style="font-style: italic;"&gt;Matrix + aalaya = Matrixalaya&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;(&lt;span style="font-style: italic;"&gt;Aalaya &lt;/span&gt;in &lt;span style="font-style: italic;"&gt;Sanskrit &lt;/span&gt;means home)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-style: italic;"&gt;&lt;a href="http://en.wikipedia.org/wiki/Himalaya"&gt;Himalaya&lt;/a&gt; &lt;/span&gt;is &lt;span style="font-style: italic;"&gt;Aalaya &lt;/span&gt;of &lt;span style="font-style: italic;"&gt;Him &lt;/span&gt;(Snow)&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/35973745-116075768377960856?l=matrixalaya.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://matrixalaya.blogspot.com/feeds/116075768377960856/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=35973745&amp;postID=116075768377960856' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/116075768377960856'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/35973745/posts/default/116075768377960856'/><link rel='alternate' type='text/html' href='http://matrixalaya.blogspot.com/2006/10/matrix-aalaya-matrixalaya-aalaya-in.html' title=''/><author><name>GNUlihd</name><uri>http://www.blogger.com/profile/05810387471599613365</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry></feed>
