<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>oneha&#124;f   Lab</title>
	<atom:link href="http://oneh.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://oneh.wordpress.com</link>
	<description>threat research</description>
	<lastBuildDate>Sun, 22 Mar 2009 15:14:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='oneh.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>oneha&#124;f   Lab</title>
		<link>http://oneh.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://oneh.wordpress.com/osd.xml" title="oneha&#124;f   Lab" />
	<atom:link rel='hub' href='http://oneh.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Virus group 29A disbanded &#8211; who’s next?</title>
		<link>http://oneh.wordpress.com/2009/03/22/virus-group-29a-disbanded-who%e2%80%99s-next/</link>
		<comments>http://oneh.wordpress.com/2009/03/22/virus-group-29a-disbanded-who%e2%80%99s-next/#comments</comments>
		<pubDate>Sun, 22 Mar 2009 15:13:30 +0000</pubDate>
		<dc:creator>oneh</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://oneh.wordpress.com/2009/03/22/virus-group-29a-disbanded-who%e2%80%99s-next/</guid>
		<description><![CDATA[Couple of weeks back, 29A officially shut down business. 29A’s published work was one of the best (IMHO) sources for cutting edge virus technologies. Their e-zines provided a sampling of what was happening in the Virus underground during that period. This was the last message posted by VirusBuster in their site: &#8221; I tried to contact ValleZ [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=36&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Couple of weeks back, <a title="29A site" href="http://www.29a.net/" target="_blank">29A</a> officially shut down business. 29A’s published work was one of the best (IMHO) sources for cutting edge virus technologies. Their e-zines provided a sampling of what was happening in the Virus underground during that period.</p>
<p>This was the last message posted by <em>VirusBuster</em> in their site:</p>
<p><em>&#8221; I tried to contact </em><strong><em>ValleZ</em></strong><em> for some time in order to take a decision together about the future of </em><strong><em>29A</em></strong><em> with no luck therefore I decided to take the decision alone. And my decision is that </em><strong><em>29A goes officially retired</em></strong><em>. I feel this is fair because I am kinda the alpha and the omega of the group. </em><strong><em>29A</em></strong><em> was born in </em><strong><em>Dark Node</em></strong><em>, my BBS, and I am the last active member of the group. My last words as 29A member are for all the people that worked hard to make of this group the best one: </em><strong><em>Thank you very much!</em></strong><em> Regards, </em><strong><em>VirusBuster/29A</em></strong></p>
<p><em><strong></strong></em></p>
<p><strong><em>29A has left the building! &#8220;</em></strong></p>
<p>Kind of sad.</p>
<p><strong><span style="font-weight:normal;">I came to know of 29A when I was in my 2nd year UG, around 1997. 29A was a new group then (If I am right, the group formed only in the mid of 1996). BTW, if you are wondering why they named it so, </span><em><span style="font-weight:normal;">29A </span></em><span style="font-weight:normal;">is the hex representation of </span><em><span style="font-weight:normal;">666 decimal</span></em><span style="font-weight:normal;">.</span></strong></p>
<p><strong></p>
<p><span style="font-weight:normal;">One of my (crazy, if you ask my wife now!) hobbies back then was collecting DOS/Windows virii source code. I was more interested in the source than the binary. I had close to 23K source files when I decided to move on to other things. There were umpteen number of sites even back then which listed for download many viruses, but most of them were distributed as either EXE or COM files. I used to take them, decompile/disassemble them using </span><em><a title="Classic tool!" href="http://www.tbc.net/~clive/vcomwinp.html" target="_blank"><span style="font-weight:normal;">SOURCER</span></a></em><span style="font-weight:normal;"> or </span><a title="Hmm...very nostalgic!!" href="http://en.wikipedia.org/wiki/DEBUG_(DOS_Command)" target="_blank"><em><span style="font-weight:normal;">debug.exe</span></em></a><em><span style="font-weight:normal;"> </span></em><span style="font-weight:normal;">(I had to use this only for a few files; Sourcer did a good job for the others.) and add to my virus database. I remember checking out a DB tool (</span><em><span style="font-weight:normal;">VirSort</span></em><span style="font-weight:normal;"> or </span><em><span style="font-weight:normal;">VirusBuster</span></em><span style="font-weight:normal;">??) for sometime, but resorted to maintaining them myself (that is, keeping them scattered through out my 4GB HDD</span><span style="font-weight:normal;"> ).</span></p>
<p><span style="font-weight:normal;">Apart from these, lots of VX tutors were there too. I remember some of the tutorials that were considered state-of-the-art (!?) then:</span></p>
<ul>
<li><span style="font-weight:normal;">Advanced Polymorphism Primer by DarkAngel</span></li>
<li><span style="font-weight:normal;">Calling the Windows API in Assembly Language by Qark</span></li>
<li><span style="font-weight:normal;">MCB Stealth by Darkman</span></li>
</ul>
<p><span style="font-weight:normal;">Particularly, I used to devour anything by </span><em><span style="font-weight:normal;">Dark Angel, Lord Julus &amp; VLAD. </span></em><span style="font-weight:normal;">How can I ever forget Lord Julus’s &#8220;Ring 0 Residency under Windows 95/98&#8243; article?? Classic!!</span></p>
<p style="text-align:center;"><img class="aligncenter" src="http://kannan.jumbledthoughts.com/wp-content/upload/2008/03/image1.png" border="0" alt="29A Magazine" width="404" height="207" /></p>
<p><span style="font-weight:normal;">When 29A started releasing their e-zines, it quickly became one of my favorites. I loved all their articles, especially by </span><em><span style="font-weight:normal;">MrSandman</span></em><span style="font-weight:normal;">, </span><em><span style="font-weight:normal;">Benny</span></em><span style="font-weight:normal;">, </span><em><span style="font-weight:normal;">VirusBuster, Jacky Qwerty, Vecna &amp; Rajaat </span></em><span style="font-weight:normal;">- they were my favorites. Issue #4 was, IMO, </span><span style="color:#800000;"><span style="font-weight:normal;">pure gold</span></span><span style="font-weight:normal;">!!</span></p>
<p><span style="font-weight:normal;">Later, when I came out of the college, I lost touch with the VX scene. </span><em><a title="29a quits" href="http://www.theregister.co.uk/2008/03/07/29a_rip/" target="_blank"><span style="font-weight:normal;">Register.co.uk</span></a></em><span style="font-weight:normal;"> &amp; F-Secure’s blog were the only VX news source for me. Though 29A published lots of new things, the following are considered notable accomplishments (?!):</span></p>
<ul>
<li><span style="font-weight:normal;">Cabir, which infected Symbian mobile phones</span></li>
<li><span style="font-weight:normal;">Duts, the first ever Pocket PC virus</span></li>
<li><span style="font-weight:normal;">Haiku, which generated Japanese-style poetry</span></li>
<li><span style="font-weight:normal;">Stream, which was the first virus to take advantage of NTFS Alternate Data Streams</span></li>
<li><span style="font-weight:normal;">Lindose, which infected both Windows and Linux computers</span></li>
<li><span style="font-weight:normal;">Donut a .NET aware Windows file infector</span></li>
</ul>
<p><span style="font-weight:normal;">I have given some links to the interviews (public/through email) of some 29A members below: I will be updating this with more as I find them in the net.</span></p>
<p></strong></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/oneh.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/oneh.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/oneh.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/oneh.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/oneh.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/oneh.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/oneh.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/oneh.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/oneh.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/oneh.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/oneh.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/oneh.wordpress.com/36/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/oneh.wordpress.com/36/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/oneh.wordpress.com/36/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=36&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://oneh.wordpress.com/2009/03/22/virus-group-29a-disbanded-who%e2%80%99s-next/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3e84a7667f87f6a2883afe5126b53245?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">oneh</media:title>
		</media:content>

		<media:content url="http://kannan.jumbledthoughts.com/wp-content/upload/2008/03/image1.png" medium="image">
			<media:title type="html">29A Magazine</media:title>
		</media:content>
	</item>
		<item>
		<title>automating the snort IDS in FreeBSD</title>
		<link>http://oneh.wordpress.com/2009/03/04/automating-the-snort-ids-in-freebsd/</link>
		<comments>http://oneh.wordpress.com/2009/03/04/automating-the-snort-ids-in-freebsd/#comments</comments>
		<pubDate>Wed, 04 Mar 2009 02:47:21 +0000</pubDate>
		<dc:creator>oneh</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://oneh.wordpress.com/?p=31</guid>
		<description><![CDATA[Currently I am into automating the process of installing and configuring snort in FreeBSD. I have developed a small script which installs and configures Snort, MySql, Apache, PHP, ADODB and Base console in FreeBSD. Currently I have written the following scripts: 1) start.sh -&#62; creates all necessary directories and users 2) deps.sh -&#62; installs dependencies [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=31&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p class="MsoNormal">Currently I am into automating the process of installing and configuring snort in FreeBSD. I have developed a small script which installs and configures Snort, MySql, Apache, PHP, ADODB and Base console in FreeBSD. Currently I have written the following scripts:</p>
<p><span>1) start.sh -&gt; creates all necessary directories and users</span></p>
<p><span>2) deps.sh -&gt; installs dependencies like libpcap, pcre, libxml2</span></p>
<p><span>3) mysql.sh -&gt; installs mysql</span></p>
<p><span>4) snort.sh -&gt; installs snort and updates the rules</span></p>
<p><span>5) create_snortdb.sh -&gt; creates snort db schema and confifures acl&#8217;s for accessing</span></p>
<p><span>6) apachephp.sh -&gt; installs apache, php and mod security</span></p>
<p><span> </span></p>
<p><span>right now I am into developing scripts for updating configuration files too.. like after you install all the above you need to manually modify snort.conf, httpd.conf;etc for settings.. </span></p>
<p><span>i am also developing a model to secure the entire ids by hardening FreeBSD, MySQL, Apache;etc and distributed IDS</span></p>
<p><span>will update soon !!!</span></p>
<p class="MsoNormal"><span> </span></p>
<p class="MsoNormal"> </p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/oneh.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/oneh.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/oneh.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/oneh.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/oneh.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/oneh.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/oneh.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/oneh.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/oneh.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/oneh.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/oneh.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/oneh.wordpress.com/31/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/oneh.wordpress.com/31/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/oneh.wordpress.com/31/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=31&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://oneh.wordpress.com/2009/03/04/automating-the-snort-ids-in-freebsd/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3e84a7667f87f6a2883afe5126b53245?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">oneh</media:title>
		</media:content>
	</item>
		<item>
		<title>spyware signature file</title>
		<link>http://oneh.wordpress.com/2008/09/24/spyware-signature-file/</link>
		<comments>http://oneh.wordpress.com/2008/09/24/spyware-signature-file/#comments</comments>
		<pubDate>Wed, 24 Sep 2008 05:28:58 +0000</pubDate>
		<dc:creator>oneh</dc:creator>
				<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://oneh.wordpress.com/?p=29</guid>
		<description><![CDATA[I am writing a small spyware removal software &#8230; I am writing this tool in VC++ and in ASM &#8230; currently I am writing a module to build the signature database and methods to retrieve informations from the DB &#8230; while doing this work I came across a good website which has excellent information about [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=29&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I am writing a small spyware removal software &#8230; I am writing this tool in VC++ and in ASM &#8230; currently I am writing a module to build the signature database and methods to retrieve informations from the DB &#8230; while doing this work I came across a good website which has excellent information about the spywares and it is www.spywaredb.com &#8230; it has lots of information about many spywares &#8230; I am totally using it and it&#8217;s very useful</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/oneh.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/oneh.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/oneh.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/oneh.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/oneh.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/oneh.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/oneh.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/oneh.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/oneh.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/oneh.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/oneh.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/oneh.wordpress.com/29/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/oneh.wordpress.com/29/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/oneh.wordpress.com/29/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=29&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://oneh.wordpress.com/2008/09/24/spyware-signature-file/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3e84a7667f87f6a2883afe5126b53245?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">oneh</media:title>
		</media:content>
	</item>
		<item>
		<title>hacker manifesto</title>
		<link>http://oneh.wordpress.com/2008/08/19/hacker-manifesto/</link>
		<comments>http://oneh.wordpress.com/2008/08/19/hacker-manifesto/#comments</comments>
		<pubDate>Tue, 19 Aug 2008 16:01:58 +0000</pubDate>
		<dc:creator>oneh</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[hacker manifesto]]></category>

		<guid isPermaLink="false">http://oneh.wordpress.com/?p=27</guid>
		<description><![CDATA[This is our world now&#8230; the world of the electron and the switch, the beauty of the baud. We explore&#8230; you call us criminals. We seek after knowledge&#8230; and you call us criminals. We exist without skin color, without nationality, without religious bias&#8230; and you call us criminals. You build atomic bombs, you wage wars, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=27&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;">This is our world now&#8230; the world of the electron and the switch, the beauty of the baud. We explore&#8230; you call us criminals. We seek after knowledge&#8230; and you call us criminals. We exist without skin color, without nationality, without religious bias&#8230; and you call us criminals. You build atomic bombs, you wage wars, you murder, cheat, and lie to us and try to make us believe it&#8217;s for our own good, yet we&#8217;re the criminals.</p>
<p style="text-align:center;">Yes, I am a criminal. My crime is that of curiosity. My crime is that of judging people by what they say and think, not what they look like.<br />
My crime is that of outsmarting you, something that you will never forgive me for.</p>
<p style="text-align:center;">I am a hacker, and this is my manifesto. You may stop this individual, but you can&#8217;t stop us all&#8230; after all, we&#8217;re all alike.</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/oneh.wordpress.com/27/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/oneh.wordpress.com/27/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/oneh.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/oneh.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/oneh.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/oneh.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/oneh.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/oneh.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/oneh.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/oneh.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/oneh.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/oneh.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/oneh.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/oneh.wordpress.com/27/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/oneh.wordpress.com/27/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/oneh.wordpress.com/27/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=27&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://oneh.wordpress.com/2008/08/19/hacker-manifesto/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3e84a7667f87f6a2883afe5126b53245?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">oneh</media:title>
		</media:content>
	</item>
		<item>
		<title>regmon</title>
		<link>http://oneh.wordpress.com/2008/08/17/regmon/</link>
		<comments>http://oneh.wordpress.com/2008/08/17/regmon/#comments</comments>
		<pubDate>Sun, 17 Aug 2008 05:36:00 +0000</pubDate>
		<dc:creator>oneh</dc:creator>
				<category><![CDATA[tools]]></category>
		<category><![CDATA[windows registry]]></category>

		<guid isPermaLink="false">http://oneh.wordpress.com/?p=17</guid>
		<description><![CDATA[regmon and filemon are the two important tools used in malware analysis. any malware, when it first infects the Windoze box, it infects the registry. the reason behind this is to make sure that the malware runs every time windoze boots up and to disable other security settings of windoze / av&#8217;s. regmon tool basically [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=17&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>regmon and filemon are the two important tools used in malware analysis.</p>
<p>any malware, when it first infects the Windoze box, it infects the registry. the reason behind this is to make sure that the malware runs every time windoze boots up and to disable other security settings of windoze / av&#8217;s.</p>
<p>regmon tool basically monitors any access to the registry. there are about 14 &#8211; 16 routines in the windoze kernel (also called virtual machine manager) which deals with all i/o operations on registry. the technique is like the dos TSR and IVT hooking one, where regmon hooks into these chain and anything accessing these routines will pass through regmon as well.</p>
<p>during DOS days all viruses will try to hook themselves into interrupt vector table and put themselves in TSR mode. the same applies in windoze with some fancy names. regmon&#8217;s heart is the regvxd.vxd code. this inserts or hooks itself into those 16 routines. regvxd.vxd is a Virtual Device Driver.</p>
<p>so before loading the malware, take a snapshot of the registry using regmon. then load the malware into the sandbox or the VM system and run the regmon. regmon clearly shows what all the key / values got changed ..</p>
<p>more coming &#8230;</p>
<p>get regmon from here <a href="http://technet.microsoft.com/en-us/sysinternals/bb896652.aspx">http://technet.microsoft.com/en-us/sysinternals/bb896652.aspx</a></p>
<p>from the oneha|f Lab<br />
(groups.google.com/group/onehalf)</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/oneh.wordpress.com/17/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/oneh.wordpress.com/17/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/oneh.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/oneh.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/oneh.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/oneh.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/oneh.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/oneh.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/oneh.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/oneh.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/oneh.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/oneh.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/oneh.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/oneh.wordpress.com/17/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/oneh.wordpress.com/17/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/oneh.wordpress.com/17/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=17&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://oneh.wordpress.com/2008/08/17/regmon/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3e84a7667f87f6a2883afe5126b53245?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">oneh</media:title>
		</media:content>
	</item>
		<item>
		<title>what is oneha&#124;f lab ?</title>
		<link>http://oneh.wordpress.com/2008/08/15/what-is-onehaf-lab/</link>
		<comments>http://oneh.wordpress.com/2008/08/15/what-is-onehaf-lab/#comments</comments>
		<pubDate>Fri, 15 Aug 2008 14:18:52 +0000</pubDate>
		<dc:creator>oneh</dc:creator>
				<category><![CDATA[announcements]]></category>
		<category><![CDATA[lab]]></category>

		<guid isPermaLink="false">http://oneh.wordpress.com/?p=11</guid>
		<description><![CDATA[so what is this oneha&#124;f group  ? a place for people to do malware research, malware code analysis, behaviour analysis, discuss about defending malwares, incident response and much more . I have chosen the name oneha&#124;f because, it was the first virus infected my system &#8230;.. I got very thrilled by knowing it’s infection technique [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=11&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>so what is this oneha|f group  ?</p>
<p>a place for people to do malware research, malware code analysis, behaviour analysis, discuss about defending malwares, incident response and much more .</p>
<p>I have chosen the name oneha|f because, it was the first virus infected my system &#8230;.. I got very thrilled by knowing it’s infection technique &#8230;..</p>
<p>onehalf’s payload is very interesting &#8230; it infects the hard disc by encrypting cylinders &#8230;.. the decryption happens on the fly, when this virus got loaded in the memory &#8230; if careful removal is not done, then the data is lost &#8230; since the virus will have the key to decrypt the data &#8230;..</p>
<p>focus will be more on code analysis, reverse engineering, assembly, worm techniques and what not &#8230;</p>
<p>come and join, if you are a person interested in malware research, love systems programming, hit your head in asm instructions, and what so ever related to depth of systems programming …</p>
<p>malware research is an interesting area &#8230; we will learn about extreme programming concepts, nice techniques, and depth about computer networks and computer itself &#8230;..</p>
<p>the main reason to create this group is to unite people in this arena … please no spammers, no script kiddies, no junkies … you can only join through people who are already in the group &#8230;..</p>
<p>the group is highly moderated &#8230;.. the reason is &#8230;.. we will share malware sample for discussion and research &#8230;.. we do not want to allow some one to come and sniff our messages, ask for tutorials, look for exploit codes &#8230; please do not bug us .. we are already busy ! &#8230;..</p>
<p>you can reach this group at <a href="http://groups.google.com/group/onehalf">http://groups.google.com/group/onehalf</a></p>
<p>and the web blog is at <a href="http://oneh.wordpress.com">http://oneh.wordpress.com</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/oneh.wordpress.com/11/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/oneh.wordpress.com/11/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/oneh.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/oneh.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/oneh.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/oneh.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/oneh.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/oneh.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/oneh.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/oneh.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/oneh.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/oneh.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/oneh.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/oneh.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/oneh.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/oneh.wordpress.com/11/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=11&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://oneh.wordpress.com/2008/08/15/what-is-onehaf-lab/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3e84a7667f87f6a2883afe5126b53245?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">oneh</media:title>
		</media:content>
	</item>
		<item>
		<title>first post</title>
		<link>http://oneh.wordpress.com/2008/08/15/first-post/</link>
		<comments>http://oneh.wordpress.com/2008/08/15/first-post/#comments</comments>
		<pubDate>Fri, 15 Aug 2008 05:27:44 +0000</pubDate>
		<dc:creator>oneh</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://oneh.wordpress.com/?p=3</guid>
		<description><![CDATA[Welcome to oneha&#124;f Lab, the malware research group this is the first post in this group. our primary focus is to study about malwares, techniques, malware defense and things like that . you can interact with our group at onehalf@googlegroups.com<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=3&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Welcome to oneha|f Lab, the malware research group</p>
<p>this is the first post in this group. our primary focus is to study about malwares, techniques, malware defense and things like that .</p>
<p>you can interact with our group at <a href="mailto:onehalf@googlegroups.com">onehalf@googlegroups.com</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/oneh.wordpress.com/3/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/oneh.wordpress.com/3/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/oneh.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/oneh.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/oneh.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/oneh.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/oneh.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/oneh.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/oneh.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/oneh.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/oneh.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/oneh.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/oneh.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/oneh.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/oneh.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/oneh.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=oneh.wordpress.com&amp;blog=4508962&amp;post=3&amp;subd=oneh&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://oneh.wordpress.com/2008/08/15/first-post/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/3e84a7667f87f6a2883afe5126b53245?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">oneh</media:title>
		</media:content>
	</item>
	</channel>
</rss>
