<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The FORWARD project blog &#187; javascript</title>
	<atom:link href="http://blogs.ict-forward.eu/forward/tag/javascript/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.ict-forward.eu/forward</link>
	<description>blogging on emerging and future threats</description>
	<lastBuildDate>Mon, 30 Jan 2012 09:09:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>New Linux OS REMnux Designed For Reverse Engineering Malware</title>
		<link>http://blogs.ict-forward.eu/forward/new-linux-os-remnux-designed-for-reverse-engineering-malware/</link>
		<comments>http://blogs.ict-forward.eu/forward/new-linux-os-remnux-designed-for-reverse-engineering-malware/#comments</comments>
		<pubDate>Tue, 20 Jul 2010 10:37:26 +0000</pubDate>
		<dc:creator>Edvin Vito</dc:creator>
				<category><![CDATA[security news]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[honeyd]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[malware-analysis]]></category>
		<category><![CDATA[network monitoring]]></category>
		<category><![CDATA[OS]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[wireshark]]></category>

		<guid isPermaLink="false">http://blogs.ict-forward.eu/forward/?p=948</guid>
		<description><![CDATA[A new OS called REMnux has been released from Lenny Zeltser, a security expert specializing on malware reverse engineering. REMnux is a lightweight version of Ubuntu originally distributed as a VMware virtual appliance, which can be booted via several VMware products or through X-Windows. The OS was also recently released as an ISO image of [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://threatpost.com/en_us/blogs/new-linux-os-remnux-designed-reverse-engineering-malware-070910" target="_blank">A new OS</a> called <a href="http://zeltser.com/remnux/" target="_blank">REMnux</a> has been released from <a href="http://zeltser.com/about/" target="_blank">Lenny Zeltser</a>, a security expert specializing on malware reverse engineering. REMnux is a lightweight version of Ubuntu originally distributed as a <a href="http://sourceforge.net/downloads/remnux/version1/" target="_blank">VMware</a> virtual appliance, which can be booted via several VMware products or through X-Windows. The OS was also recently released as an <a href="http://sourceforge.net/downloads/remnux/version1/" target="_blank">ISO image</a> of a Live CD.</p>
<p>The classical approach to analyze malware is to set up a virtual machine on a computer specifically designed for that purpose and then release the malware and monitor how it affects the system. The drawback of this protocol is that much of the malware&#8217;s behavior can remain hidden, while deeper analysis is not a convenient option.</p>
<p>REMnux comes as a solution to these disadvantages and offers an alternative approach for taking apart a malicious code. Typically, infection of another laboratory system with the malware sample is followed by direction of the potentially-malicious connections to the REMnux &#8220;monitoring&#8221; ports.</p>
<p>This approach combines a generous number of popular malware-analysis, reverse-engineering, network monitoring, and memory forensic tools. Amongst them, REMnux contains three tools for analyzing Flash-specific malware, namely SWF tools, Flasm, and Flare. Furthermore, it contains several applications for analyzing malicious PDFs, such as the <a href="http://blog.didierstevens.com/programs/pdf-tools/" target="_blank">Didier Steven&#8217;s</a> analysis tools. The OS also provides a lot of tools for de-obfucating JavaScript, including <a href="http://www.mozilla.org/rhino/debugger.html" target="_blank">Rhino debugger</a>, a NoScript-version of Firefox, JavaScript Deobfuscator and <a href="http://getfirebug.com/whatisfirebug" target="_blank">Firebug</a>, and Windows Script Decoder. In addition to the above analysis tools, a small Web server, an IRC server, and a pseudo-DNS server are also included. Further, several tools for network monitoring and interactions, such as the virtual honeypot server, <a href="http://www.honeyd.org/" target="_blank">HoneyD</a>, as well as <a href="http://www.wireshark.org/" target="_blank">Wireshark</a>, <a href="http://www.inetsim.org/" target="_blank">INetSim</a>, fakedns and fakesmtp scripts, and <a href="http://netcat.sourceforge.net/" target="_blank">NetCat</a> are also part of REMnux.</p>
<p>Behind the development of REMnux stands the idea of providing a useful set of tools for people interested in the field, rather than a be-all reverse-engineering environment. As Zeltser himself puts it: &#8220;This doesn&#8217;t have every tool in it, because I think people can get distracted with too many tools in there&#8221;. On the contrary, Zeltser states that this OS targets beginners or people that are not Linux experts. He also hopes that users&#8217; input and comments will aid in further development of REMnux to reach an improved version of the OS.</p>
<p>Any interested and adventurous potential developers, who would like to contribute to the improvement of REMnux,  are welcomed to <a href="http://zeltser.com/about/contact.html" target="_blank">contact</a> Lenny Zelter directly.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.ict-forward.eu/forward/new-linux-os-remnux-designed-for-reverse-engineering-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>When XXS met Reddit</title>
		<link>http://blogs.ict-forward.eu/forward/when-xxs-met-reddit/</link>
		<comments>http://blogs.ict-forward.eu/forward/when-xxs-met-reddit/#comments</comments>
		<pubDate>Wed, 07 Oct 2009 10:15:28 +0000</pubDate>
		<dc:creator>Thanasis Petsas</dc:creator>
				<category><![CDATA[security news]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[reddit]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://blogs.ict-forward.eu/forward/?p=329</guid>
		<description><![CDATA[The well-known social news website Reddit got hit from a very effective XSS (cross site scripting) attack on Sunday, September 27th. The attack was rested on the fact that Reddit was not filtering out JavaScript in specific instances while a user was moving the mouse over the text field of the comments. Furthermore, a user [...]]]></description>
			<content:encoded><![CDATA[<p>The well-known social news website <a href="http://www.reddit.com/">Reddit</a> got hit from a very effective <a href="http://en.wikipedia.org/wiki/Cross-site_scripting">XSS</a> (cross site scripting) attack on Sunday, September 27<sup>th</sup>.</p>
<p>The attack was rested on the fact that Reddit was not filtering out JavaScript in specific instances while a user was moving the mouse over the text field of the comments. <span id="more-329"></span>Furthermore, a user named “Empirical” made a piece of JavaScript code that its effect was to automatically reply to all comments of a Reddit page, if it was pasted into the browser address bar, as a Reddit thread reports. As a result, another user named “xssfinder” combined these two facts in order to create an XSS attack by exploiting this vulnerability.</p>
<p>Particularly, xssfinder posted a comment that was a link to malicious code on a popular thread called “Guy on a bike in New York ‘high fives’ people hailing cabs”. After that, things happened quickly. When a user tried to read this comment, or to post a reply to it, he or she was resulted in sending a vast number of spam comments onto other Reddit threads.</p>
<p>According to <a href="http://www.f-secure.com/weblog/archives/00001777.html">F-Secure</a>, Reddit administrators claim that all the holes that could lead to this type of attack have already been closed. Moreover, all the comments that were produced from this malicious code have been removed.</p>
<p>Besides, it is very common the fact that when a new XSS attack is created, a new wave of different variations follows in a short period of time. So, a solution to prevent such kind of attacks maybe is to turn off JavaScript, when someone try to access Reddit, using for example the <a href="https://addons.mozilla.org/el/firefox/addon/722">NoScript</a> extension of Firefox.</p>
<p>References: <a href="http://www.theregister.co.uk/2009/09/28/reddit_xss_worm/">The Register</a>, <a href="http://www.f-secure.com/weblog/archives/00001777.html">F-Secure</a>, <a href="http://www.h-online.com/security/Reddit-Attacked-by-XSS-Exploit--/news/114337">The H Security</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.ict-forward.eu/forward/when-xxs-met-reddit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

