<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>onHacks</title>
	<atom:link href="http://onhacks.org/lang/en/feed/" rel="self" type="application/rss+xml" />
	<link>http://onhacks.org</link>
	<description>On Hacking Across Boundaries</description>
	<lastBuildDate>Tue, 26 Jan 2010 18:26:00 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>OWASP Testing Guide V3 Chinese Version</title>
		<link>http://onhacks.org/lang/en/2010/01/27/owasp-testing-guide-v3-chinese</link>
		<comments>http://onhacks.org/lang/en/2010/01/27/owasp-testing-guide-v3-chinese#comments</comments>
		<pubDate>Tue, 26 Jan 2010 16:17:31 +0000</pubDate>
		<dc:creator>log0</dc:creator>
				<category><![CDATA[China]]></category>
		<category><![CDATA[Testing]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[Paper]]></category>

		<guid isPermaLink="false">http://onhacks.org/?p=786</guid>
		<description><![CDATA[OWASP Testing Guide V3 Chinese Version is finally published! You can download in the OWASP China-Mainland chapter page. If you are interested in web application security, it is highly encouraged to check it out. There will be things learnt.
OWASP China Research Group
To better facilitate the activities of OWASP in China for consistent and perpetual continuity, [...]]]></description>
			<content:encoded><![CDATA[<p><span lang="en"><a href="http://www.owasp.org/images/0/06/OWASP%E6%B5%8B%E8%AF%95%E6%8C%87%E5%8D%97%28%E4%B8%AD%E6%96%87%EF%BC%89.pdf" target="_blank">OWASP Testing Guide V3 Chinese Version</a></span><span lang="en"> is finally published! You can <a href="http://www.owasp.org/images/0/06/OWASP%E6%B5%8B%E8%AF%95%E6%8C%87%E5%8D%97%28%E4%B8%AD%E6%96%87%EF%BC%89.pdf" target="_blank">download</a> in the <a href="http://www.owasp.org/index.php/China-Mainland" target="_blank">OWASP China-Mainland chapter</a> page. If you are interested in web application security, it is highly encouraged to check it out. There will be things learnt.</span></p>
<blockquote><p><span lang="en">OWASP China Research Group</span></p>
<p><span lang="en">To better facilitate the activities of OWASP in China for consistent and perpetual continuity, OWASP China has formed regional groups mainly tasked to support the regional sharing and discussion. We welcome you to recommend an individual to take the lead. OWASP China Research Group currently aims to build upon and go into the depths of the foundation laid out by the OWASP Foundation, plus translation of the OWASP resources ectera. There will be activities such as training in different regions. OWASP China QQ Discussion Group 78238096<br />
</span></p>
<p><span lang="en"><em>(My translation above)</em><br />
</span></p></blockquote>
<p><span lang="en">I hope to improve China&#8217;s internet security. I succeeded Frank and Rip on the last iteration of this project, and that is why my December has been busy all along, and took much of my time.</span></p>
<p><span lang="en">Thanks a lot to the people below, and especially the many Microsoft people who worked so hard even during Christmas to produce this testing guide. Sorted from last name (Mandarin) :</span></p>
<ul>
<li><span lang="en">Aaron (DBAPPSECURITY)</span></li>
<li><span lang="en">Joanne Cheng (Microsoft)</span></li>
<li><span lang="en">Frank Fan (DBAPPSECURITY)</span></li>
<li><span lang="en">Karin He (Microsoft)</span></li>
<li><span lang="en">Adams Li (Microsoft)</span></li>
<li><span lang="en">RIP (OWASP China Chair)</span></li>
<li><span lang="en">Will Shen (Microsoft)</span></li>
<li><span lang="en">Chao Wang (Microsoft)</span></li>
<li><span lang="en">Wei Wei (Microsoft)</span></li>
<li><span lang="en">Pak Ming Cheung (Microsoft)</span></li>
<li><span lang="en">Eric Chio (Microsoft)</span></li>
</ul>
<p><span lang="en">Hope that readers of the guide will benefit much from it!</span></p>












]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2010/01/27/owasp-testing-guide-v3-chinese/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Recent Updates From Log0</title>
		<link>http://onhacks.org/lang/en/2010/01/18/recent-updates-from-log0</link>
		<comments>http://onhacks.org/lang/en/2010/01/18/recent-updates-from-log0#comments</comments>
		<pubDate>Mon, 18 Jan 2010 15:08:29 +0000</pubDate>
		<dc:creator>log0</dc:creator>
				<category><![CDATA[Random Chatter]]></category>

		<guid isPermaLink="false">http://onhacks.org/?p=784</guid>
		<description><![CDATA[Hi guys this is Log0, not that I&#8217;m dead, but I&#8217;m very well alive.
For the whole December and some January, I&#8217;ve been working for OWASP China on some projects &#8211; thus taking my full attention. And I have been busy on picking up some bits of life and my side project &#8211; yes! Working on [...]]]></description>
			<content:encoded><![CDATA[<p>Hi guys this is Log0, not that I&#8217;m dead, but I&#8217;m very well alive.</p>
<p>For the whole December and some January, I&#8217;ve been working for OWASP China on some projects &#8211; thus taking my full attention. And I have been busy on picking up some bits of life and my side project &#8211; yes! Working on it! It&#8217;s coming in this January!</p>
<p>The 2009 is a fantastic year! I am aiming well for 2010 and will aim to advance fully into my interests. More to that next time&#8230; meanwhile, stay tooned. =)</p>
]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2010/01/18/recent-updates-from-log0/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Caveats of MD5 Naming</title>
		<link>http://onhacks.org/lang/en/2010/01/18/caveats-of-md5-naming</link>
		<comments>http://onhacks.org/lang/en/2010/01/18/caveats-of-md5-naming#comments</comments>
		<pubDate>Mon, 18 Jan 2010 15:04:44 +0000</pubDate>
		<dc:creator>log0</dc:creator>
				<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://onhacks.org/?p=781</guid>
		<description><![CDATA[Brief note&#8230; 
You might have noticed that I used md5 as filenames in the previous (old!) post. In most cases, it is fine.
However, what if the malware depends on a file called hgz.dll? You can calculate hgz.dll as md5, then find the filename out, now put that in the VM again &#8211; fine. But you [...]]]></description>
			<content:encoded><![CDATA[<p><span lang="en">Brief note&#8230; </span></p>
<p><span lang="en">You might have noticed that I used md5 as filenames in the previous (old!) post. In most cases, it is fine.</span></p>
<p><span lang="en">However, what if the malware depends on a file called hgz.dll? You can calculate hgz.dll as md5, then find the filename out, now put that in the VM again &#8211; fine. But you see it is a troublesome process&#8230; that you can&#8217;t easily automate. There are other cases&#8230; of course.<br />
</span></p>
<p><span lang="en">Well, you get the point!</span></p>
]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2010/01/18/caveats-of-md5-naming/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Grouping Malware</title>
		<link>http://onhacks.org/lang/en/2009/12/11/grouping-malware</link>
		<comments>http://onhacks.org/lang/en/2009/12/11/grouping-malware#comments</comments>
		<pubDate>Fri, 11 Dec 2009 04:00:49 +0000</pubDate>
		<dc:creator>log0</dc:creator>
				<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://onhacks.org/?p=764</guid>
		<description><![CDATA[Grouping malware with similar binary structure saves time and effort. As a standalone part-time researcher, such productivity again is invaluable. When you collect malware, in time you will accumulate malware samples &#8211; many of them. Perhaps 2000 samples of malware. Processing all of them could be a costly operation. To save time and effort, we [...]]]></description>
			<content:encoded><![CDATA[<p><span lang="en">Grouping malware with similar binary structure saves time and effort. As a standalone part-time researcher, such productivity again is invaluable. When you collect malware, in time you will accumulate malware samples &#8211; many of them. Perhaps 2000 samples of malware. Processing all of them could be a costly operation. To save time and effort, we want to remove similar or duplicates of the same family. What can one do?</span></p>
<p><span lang="en">For this problem, we assume all the files are malicious as honeypots do not collect innocent software.</span></p>
<p><span lang="en">One way is to use virus scanners to scan and classify the files. After a scan, group together all the files that are detected as &#8220;Conficker.B&#8221; for example. As Conficker family is quite prevalent, such duplication identification can save a lot of time and effort. This way, just analyzing one or two of them is sufficient. However, the drawback is that all the undetected samples will be left as a big group which you must analyze one-by-one.</span></p>
<blockquote><p><span lang="en">Extract of a clamscan result&#8230;</span></p>
<p><span lang="en">/tmp/4c71b97435a24ffb8fd7fedd1b1790e1: OK<br />
/tmp/82dd3a3d386d4ea09870dcee4a75a531: OK<br />
/tmp/72bdd3bd37a0b5d1dd5f1be80cb29639.bin: OK<br />
/tmp/24bd1722b994f7daa193458348108bfc.bin: OK<br />
/tmp/39960c5ff1922466ded71a4a2799c295: Trojan.VanBot-366 FOUND<br />
/tmp/33f5f14c33bf2f71556204705407a885: W32.Virut-54 FOUND<br />
/tmp/880ce6df69aaeb1d3c57e756f53dd158.bin: Trojan.Delf-911 FOUND<br />
/tmp/7e0ce66bb299370010016f4522152969: Trojan.VanBot-366 FOUND<br />
/tmp/4f2d9f8129e7d7fd9b37f700aacdc9aa.bin: Trojan.Hupigon-25647 FOUND<br />
/tmp/5b69ff6f331ece36558516f66306f969: Trojan.Small-4287 FOUND<br />
/tmp/078aedb8630339487cf39d028b0156bd.bin: OK<br />
/tmp/417bdef0688996a845701da9dcf1b145: Trojan.VanBot-366 FOUND<br />
/tmp/eda3b7766c23dfffc0b85d0ba546b0c1: W32.Virut-54 FOUND<br />
/tmp/86f22ff53382dbb54e2c22560a3db373: Trojan.VanBot-366 FOUND<br />
/tmp/a4a41d2122c4d3552e3d59315f42d4e3: W32.Virut-54 FOUND</span></p></blockquote>
<p><span lang="en">In the above, without signatures, how can you tell if 4c71b97435a24ffb8fd7fedd1b1790e1 and 82dd3a3d386d4ea09870dcee4a75a531 is not the same family? How can you tell which malware is unique? You have to analyze them. Now scale the problem to perhaps 600, for yourself only.</span></p>
<p><span lang="en">The other way is to use ssdeep, a fuzzy hashing tool. It is used to match inputs that are similar, perhaps only some bytes and length. It will produce a hash signature like md5 but unlike md5, a single change of byte will not create a wildly different signature. The concept of ssdeep is to chop the files into many sections, and calculate the hash for each section.</span></p>
<p><span lang="en">Below I take a sample of an exe file (&#8220;file1.exe&#8221;). I copied the file and concatenates a byte after it (&#8220;file2.exe&#8221;), and computes the md5 sum of the two files.</span></p>
<blockquote><p><span lang="en">$ cp file1.exe file2.exe<br />
$ echo 1 &#62;&#62; file2.exe</span></p>
<p><span lang="en">$ md5sum file1.exe file2.exe<br />
72bdd3bd37a0b5d1dd5f1be80cb29639  file1.exe<br />
a626b78fa6ba13fdd9cfddb9f55ee7c6  file2.exe</span></p></blockquote>
<p><span lang="en">Just a difference in one byte, and the md5 hash is completely different. Let us do the ssdeep sum of the two files.</span></p>
<blockquote><p><span lang="en">(broken into lines for clarity)</span></p>
<p><span lang="en">$ ssdeep -b file1.exe file2.exe<br />
ssdeep,1.0&#8211;blocksize:hash:hash,filename<br />
</span><span style="color: #000000;" lang="en">768:<strong>my+qxlsz7yiV0+7YUaFhLFAtVI0xbM<br />
LvzEg1B1Ki8nJ78</strong>:<strong>R+qxlsHvGhLFyI0l8tC5J78</strong>,&#8221;file1.exe&#8221;<br />
768:<strong>my+qxlsz7yiV0+7YUaFhLFAtVI0xbM<br />
LvzEg1B1Ki8nJ7V</strong>:<strong>R+qxlsHvGhLFyI0l8tC5J7V</strong>,&#8221;file2.exe&#8221;</span></p></blockquote>
<p><span lang="en">Separated by colon, the first (768) is the blocksize, then two ssdeep hashes (my+qxlsz7yiV0+7YUaFhLFAtVI0xbMLvzEg1B1Ki8nJ7V and R+qxlsHvGhLFyI0l8tC5J7V) , then the last is the file path name (&#8220;file2.exe&#8221;). The main point are the two hashes &#8211; the signatures of the file. Both file hashes of the two files are really alike except for the last byte ( &#8220;8&#8243; vs &#8220;V&#8221; ).</span></p>
<p><span lang="en">If you have a large number of unidentified malware, antivirus scanners will not help to classify, but ssdeep can try. Below is extracted output of file matching with ssdeep. Each file name is the md5 of the file itself.</span></p>
<blockquote><p><span lang="en">$ ssdeep -dr .</span></p>
<p><span lang="en">&#8230;<br />
/tmp/72bdd3bd37a0b5d1dd5f1be80cb29639.bin matches /tmp/fa7c91b738e763eccf69676bd393925e.bin (88)<br />
/tmp/72bdd3bd37a0b5d1dd5f1be80cb29639.bin matches /tmp/ae142ce3b35cc04f5648a0c17c37ea30.bin (82)<br />
/tmp/72bdd3bd37a0b5d1dd5f1be80cb29639.bin matches /tmp/794b74fc4e833d245eb005e078dc21da.bin (82)<br />
/tmp/72bdd3bd37a0b5d1dd5f1be80cb29639.bin matches /tmp/46fb9678675df8dc83d38761a76c7950.bin (99)<br />
/tmp/72bdd3bd37a0b5d1dd5f1be80cb29639.bin matches /tmp/f412d41aacb4b16ded7b158b89fd3552.bin (90)<br />
/tmp/72bdd3bd37a0b5d1dd5f1be80cb29639.bin matches /tmp/4bfba885ed3dc4ba800446df49051af0.bin (82)<br />
/tmp/72bdd3bd37a0b5d1dd5f1be80cb29639.bin matches /tmp/13776c2b604290906305a56c4e7c61e5.bin (99)<br />
/tmp/72bdd3bd37a0b5d1dd5f1be80cb29639.bin matches /tmp/5a8424f4e1504b5823ca8742e2b1ce8d.bin (82)<br />
&#8230;</span></p></blockquote>
<p><span lang="en">In the above, all of them are undetected malware and gives wildly different md5 signature. Yet, ssdeep can relate them. For malware that does not match any other files, it can be assumed to be a unique malware in your collection, and you should pay more attention to it. Moreover, even packed executables (tested on UPX) still can be matched since packers are just compressors &#8211; the similar code will be compressed into a similar binary pattern.</span></p>
<p><span lang="en">There are a few culprits. First, remembering that ssdeep just does mini-hashes, if some bytes vary a little throughout the file ( by some obfuscation, etc, every 1 byte change at 100 byte intervals, i.e. no-ops) will cause the ssdeep to fail to identify matches. Then, for botnets credentials identification, similar files could contain very different login credentials and wrongly discarded due to highly similar binary structure. However, you can analyze the access control logic through such duplicated samples, then you can generalize the login credentials.</span></p>
<p><span lang="en">With ssdeep, you can now group duplicated undetected malware into groups for more efficient analysis.</span></p>
































<p>===</p>
<p>ssdeep &#8211; http://ssdeep.sourceforge.net/</p>
<p>UPX &#8211; http://upx.sourceforge.net/</p>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 3394px; width: 1px; height: 1px;">(为了清楚一点，分为数行)(为了清楚一点，分为数行)</div>
]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2009/12/11/grouping-malware/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Experience on Open Mail Relay Server for Honeypot</title>
		<link>http://onhacks.org/lang/en/2009/12/08/experience-on-open-mail-relay-server-for-honeypot</link>
		<comments>http://onhacks.org/lang/en/2009/12/08/experience-on-open-mail-relay-server-for-honeypot#comments</comments>
		<pubDate>Tue, 08 Dec 2009 07:06:39 +0000</pubDate>
		<dc:creator>.hac</dc:creator>
				<category><![CDATA[Email]]></category>
		<category><![CDATA[Honeypot]]></category>
		<category><![CDATA[Spampot]]></category>

		<guid isPermaLink="false">http://onhacks.org/lang/en/2009/12/08/760</guid>
		<description><![CDATA[This is a report more than discovery in spam collection. I was working on setting up a spampot using spampot.py which was written by Neale Pikett back to 2003. Although the result is not as my expectation, it does gives me more information about setting up a spampot.
Goal
The goal of running a spampot (honeypot which [...]]]></description>
			<content:encoded><![CDATA[<p>This is a report more than discovery in spam collection. I was working on setting up a spampot using <a id="micx" title="spampot.py" href="http://woozle.org/%7Eneale/src/python/spampot.py">spampot.py</a> which was written by Neale Pikett back to 2003. Although the result is not as my expectation, it does gives me more information about setting up a spampot.</p>
<p><span style="font-size: small;"><strong>Goal</strong></span></p>
<p>The goal of running a spampot (honeypot which only care about spam) is to collect spam and analysis the trend of them, hopefully we can find some interesting techniques that spammers/ hackers use in junk and phishing emails.</p>
<p><span style="font-size: small;"><strong>Approach</strong></span><br />
So far, there are at least two types of spampot hosting method that I know. The names of them are designed by me, if there are formal names for them, please let me know.<strong> </strong></p>
<blockquote><p><strong>Open Relay Spampot:</strong> This kind of honeypot is running as an open mail relay server. In case you are not familiar with, open relay means users can send message through the server anonymously.<strong></strong></p></blockquote>
<blockquote><p><strong>Close Relay Spampot:</strong> The spampot is running as a close mail relay server. To expose the server to spammers, you need to have your own domain binding to this server with email address(es) exposing to spammers/ hackers. For example, we can have onhacks.org binding to a spampot and spam@onhacks.org is one of the email address we want to expose to spammers. However, about the methods to increase the exposure of an email addresses is out of scope, we can discuss more on it later.</p></blockquote>
<p>In my setup, I decided to run spampot as <em>open mail relay server</em>.</p>
<p><span style="font-size: small;"><strong>Setup</strong></span><br />
I have VirtualBox installed on top of Windows 7. I am using Ubuntu as the guest OS, this is because it seems the implementation was done in *nix system. Since port 25 is the default port for SMTP service, we need to forward packets from host (Win7) to guest (Ubuntu) so that the spampot in guest OS can react to incoming connection at host port 25.</p>
<p>(Assuming that you are using NAT for VirtualBox)<br />
To enable port forwarding, you need to set the HostPort 25 forwarding to GuestPort 25. For more detail around port forwarding in VirtualBox, please refer to <a id="hipv" title="this" href="http://tombuntu.com/index.php/2008/12/17/configure-port-forwarding-to-a-virtualbox-guest-os/">this</a> article.</p>
<p>However, you will soon discover that it is not possible to perform port forwarding if the port is reserved (&#60; 1024). This can easily be resolved by running VirtualBox with admin credential (ie. Run As Administrator).</p>
<p>The spampot.py requires Sendmail being installed in Linux. Since sendmail actually is a service listening to port 25, I will do the follow to switch to spampot.py:</p>
<blockquote><p>sudo /etc/init.d/sendmail stop<br />
sudo spampot.py 0.0.0.0</p></blockquote>
<p>Surely you can set this automatically run when the system is started.</p>
<p>The last thing is to add a DNS record pointing to my machine. I have smtp.onhacks.org. pointing to it. Since it is still under experiment, the machine is running at home and IP is dynamic, I need to change it often.</p>
<p><span style="font-size: small;"><strong>Result</strong></span><br />
Currently, I got 0 message after running the spampot for few days. I have google around and looks like open relay spampot is not that popular anymore because many server admins aware that spammers were abusing open mail relay servers, they don&#8217;t allow open relay anymore. As a result, submitting spams to open relay servers is not efficient anymore.</p>
<p>I will continue running the spampot these days and see if we can get more spam through open relay honeypot. Afterward, I will work on close relay spampot.</p>
<p><strong><span style="font-size: small;">Reference</span></strong></p>
<ol>
<li><a id="j:td" title="Open mail relay - Wikipedia" href="http://en.wikipedia.org/wiki/Open_mail_relay">Open mail relay &#8211; Wikipedia</a></li>
<li><a id="gum0" title="spampot.py - written by Neale Pickett" href="http://woozle.org/%7Eneale/src/python/spampot.py">spampot.py &#8211; written by Neale Pickett</a></li>
<li><a id="x4ae" title="Configure Port Forwarding to a VirtualBox Guest OS - Tombuntu" href="http://tombuntu.com/index.php/2008/12/17/configure-port-forwarding-to-a-virtualbox-guest-os/">Configure Port Forwarding to a VirtualBox Guest OS &#8211; Tombuntu</a></li>
<li><a id="e9tb" title="SpamPots Project - Cert.org" href="http://www.cert.org/archive/pdf/SpamPots_CERTbe-Pub.pdf">SpamPots Project &#8211; Cert.org</a></li>
<li><a id="wzy0" title="Brazilian Honeypots Alliance" href="http://www.honeypots-alliance.org.br/">Brazilian Honeypots Alliance</a></li>
</ol>
]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2009/12/08/experience-on-open-mail-relay-server-for-honeypot/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>An interesting DoS attack story</title>
		<link>http://onhacks.org/lang/en/2009/11/29/an-interesting-dos-attack-story</link>
		<comments>http://onhacks.org/lang/en/2009/11/29/an-interesting-dos-attack-story#comments</comments>
		<pubDate>Sun, 29 Nov 2009 03:11:22 +0000</pubDate>
		<dc:creator>.hac</dc:creator>
				<category><![CDATA[Random Chatter]]></category>
		<category><![CDATA[DoS]]></category>

		<guid isPermaLink="false">http://onhacks.org/?p=752</guid>
		<description><![CDATA[Last night, I was waken by a call that a server was not working. This server is hosting an online judging system (similar to uva.onlinejudge.org, which has algorithmic problems that users can solve). I took a quick look at the compilation process and web pages, everything looked good except it always return &#8220;Compilation Error&#8221; no [...]]]></description>
			<content:encoded><![CDATA[<p>Last night, I was waken by a call that a server was not working. This server is hosting an online judging system (similar to <a href="http://uva.onlinejudge.org">uva.onlinejudge.org</a>, which has algorithmic problems that users can solve). I took a quick look at the compilation process and web pages, everything looked good except it always return &#8220;Compilation Error&#8221; no matter what was the content in source code (even a <a href="http://en.wikipedia.org/wiki/Hello_world_program">HelloWorld</a>!). By manually compiled the source code, the compilation error message gave more detail information about the root cause&#8230;Not enough space to link the object files! When I did a &#8220;df&#8221;, it said that the data partition was used 100%!!</p>
<p>After a deeper investigation, I discovered that one of the user was preparing questions on the machine, and generated a 12GB test data unexpectedly. Since this is a very old machine, it only has a 14GB hard disk for data storage and it already had 2GB data on it. This is kind of DoS attack since no one can submit sources to the judging system even though they can navigate to it.</p>
<p><strong>Lesson learned:</strong> We should have restriction on storage usage of each user instead of unlimited.</p>
<p>Any other suggestion to prevent this happen again?</p>
]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2009/11/29/an-interesting-dos-attack-story/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Google AppEngine is a part of Botnets</title>
		<link>http://onhacks.org/lang/en/2009/11/20/google-appengine-is-a-part-of-botnetsgoogle-appengine-%e6%88%90%e7%82%ba%e5%83%b5%e5%b1%8d%e7%b6%b2%e7%b5%a1%e7%9a%84%e4%b8%80%e9%83%a8%e4%bb%bdgoogle-appengine-%e6%88%90%e4%b8%ba%e5%83%b5%e5%b0%b8</link>
		<comments>http://onhacks.org/lang/en/2009/11/20/google-appengine-is-a-part-of-botnetsgoogle-appengine-%e6%88%90%e7%82%ba%e5%83%b5%e5%b1%8d%e7%b6%b2%e7%b5%a1%e7%9a%84%e4%b8%80%e9%83%a8%e4%bb%bdgoogle-appengine-%e6%88%90%e4%b8%ba%e5%83%b5%e5%b0%b8#comments</comments>
		<pubDate>Thu, 19 Nov 2009 16:01:48 +0000</pubDate>
		<dc:creator>log0</dc:creator>
				<category><![CDATA[Botnet]]></category>

		<guid isPermaLink="false">http://onhacks.org/?p=747</guid>
		<description><![CDATA[Details at Jose Nazario of Arbor Networks : http://asert.arbornetworks.com/2009/11/malicious-google-appengine-used-as-a-cnc/ .
Log0 is quite busy lately.
]]></description>
			<content:encoded><![CDATA[<p>Details at Jose Nazario of Arbor Networks : <a href="http://asert.arbornetworks.com/2009/11/malicious-google-appengine-used-as-a-cnc/" target="_blank">http://asert.arbornetworks.com/2009/11/malicious-google-appengine-used-as-a-cnc/</a> .</p>
<p>Log0 is quite busy lately.</p>
]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2009/11/20/google-appengine-is-a-part-of-botnetsgoogle-appengine-%e6%88%90%e7%82%ba%e5%83%b5%e5%b1%8d%e7%b6%b2%e7%b5%a1%e7%9a%84%e4%b8%80%e9%83%a8%e4%bb%bdgoogle-appengine-%e6%88%90%e4%b8%ba%e5%83%b5%e5%b0%b8/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BotHerder 0.1 Available for Download</title>
		<link>http://onhacks.org/lang/en/2009/11/16/botherder-0-1-available-for-download</link>
		<comments>http://onhacks.org/lang/en/2009/11/16/botherder-0-1-available-for-download#comments</comments>
		<pubDate>Mon, 16 Nov 2009 15:07:50 +0000</pubDate>
		<dc:creator>log0</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Source]]></category>

		<guid isPermaLink="false">http://onhacks.org/?p=733</guid>
		<description><![CDATA[BotHerder 0.1 is now available for download here, or at the source page. Help file included at README in the zip.
This tool was not to be released when I first built it, however it becomes more useful. It has a lot of functions to include in the future such as adopting general botnet communication, and [...]]]></description>
			<content:encoded><![CDATA[<p><span lang="en">BotHerder 0.1 is now available for download <a href="http://onhacks.org/get/botherder_0.1.tar.gz" target="_blank">here</a>, or at the source page. Help file included at README in the zip.</span></p>
<p><span lang="en">This tool was not to be released when I first built it, however it becomes more useful. It has a lot of functions to include in the future such as adopting general botnet communication, and making it easier to use and automate, and even scriptable.</span></p>




]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2009/11/16/botherder-0-1-available-for-download/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>A DIY Botnet Tracking System deck released</title>
		<link>http://onhacks.org/lang/en/2009/11/14/a-diy-botnet-tracking-system-deck</link>
		<comments>http://onhacks.org/lang/en/2009/11/14/a-diy-botnet-tracking-system-deck#comments</comments>
		<pubDate>Sat, 14 Nov 2009 14:06:19 +0000</pubDate>
		<dc:creator>log0</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Presentation]]></category>

		<guid isPermaLink="false">http://onhacks.org/?p=727</guid>
		<description><![CDATA[The deck of &#8220;A DIY Botnet Tracking System&#8221; is here : 
I will post the source code to the tool after updated with HELP document. Feel free to email me =)
BTW, hac.ka is my friend and the otherOnHacks teammate whom I mentioned during my final speech. He works on Email and DNS related items.







http://www.slideshare.net/log0/a-diy-botnet-tracking-system
]]></description>
			<content:encoded><![CDATA[<p><span lang="en">The deck of &#8220;A DIY Botnet Tracking System&#8221; is <a href="http://www.slideshare.net/log0/a-diy-botnet-tracking-system" target="_blank">here</a> : </span></p>
<p><span lang="en">I will post the source code to the tool after updated with HELP document. Feel free to email me =)</span></p>
<p><span lang="en">BTW, hac.ka is my friend and the otherOnHacks teammate whom I mentioned during my final speech. He works on Email and DNS related items.<br />
</span></p>






<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 37px; width: 1px; height: 1px;">http://www.slideshare.net/log0/a-diy-botnet-tracking-system</div>
]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2009/11/14/a-diy-botnet-tracking-system-deck/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Intelligence Report 7th</title>
		<link>http://onhacks.org/lang/en/2009/11/06/microsoft-security-intelligence-report-7th</link>
		<comments>http://onhacks.org/lang/en/2009/11/06/microsoft-security-intelligence-report-7th#comments</comments>
		<pubDate>Fri, 06 Nov 2009 15:44:10 +0000</pubDate>
		<dc:creator>log0</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Report]]></category>
		<category><![CDATA[SIR]]></category>

		<guid isPermaLink="false">http://onhacks.org/?p=724</guid>
		<description><![CDATA[Microsoft Security Intelligence Report 7th is out! Interested individuals should check it out. =)
http://www.microsoft.com/security/portal/Threat/SIR.aspxhttp://www.microsoft.com/security/portal/Threat/SIR.aspx
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.microsoft.com/security/portal/Threat/SIR.aspx" target="_blank">Microsoft Security Intelligence Report 7th</a> is out! Interested individuals should check it out. =)</p>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">http://www.microsoft.com/security/portal/Threat/SIR.aspxhttp://www.microsoft.com/security/portal/Threat/SIR.aspx</div>
]]></content:encoded>
			<wfw:commentRss>http://onhacks.org/lang/en/2009/11/06/microsoft-security-intelligence-report-7th/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
