<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>

<channel>
	<title>InfoSecPodcast.com &#187; Viruses &amp; Worms</title>
	<atom:link href="http://www.infosecpodcast.com/category/security/viruses-worms/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.infosecpodcast.com</link>
	<description>Information Security related news, opinions and ramblings</description>
	<pubDate>Tue, 11 Nov 2008 02:51:39 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Cell phone virus writer arrested in Spain</title>
		<link>http://www.infosecpodcast.com/2007/06/cell-phone-virus-writer-arrested-in-spain/</link>
		<comments>http://www.infosecpodcast.com/2007/06/cell-phone-virus-writer-arrested-in-spain/#comments</comments>
		<pubDate>Tue, 26 Jun 2007 13:30:35 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Viruses & Worms]]></category>
<category>cell phone</category><category>commwarrior</category><category>darwin</category><category>malware</category><category>viruses</category><category>virus cabir</category>
		<guid isPermaLink="false">http://www.infosecpodcast.com/viruses-worms/2007/06/cell-phone-virus-writer-arrested-in-spain/</guid>
		<description><![CDATA[Spanish police arrested a 28 year old man for writing several variants of the Cabir and Commwarrior viruses. These viruses targeted the Symbian operating system which is a popular cell phone OS. It was spread through Bluetooth connections. They are reporting that over 115,000 phones were infected. How did they catch him?
He put his fiance&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>Spanish police arrested a 28 year old man for writing several variants of the Cabir and Commwarrior viruses. These viruses targeted the Symbian operating system which is a popular cell phone OS. It was spread through Bluetooth connections. They are reporting that over 115,000 phones were infected. How did they catch him?</p>
<p>He put his fiance&#8217;s name in the source code. When will malware authors stop putting personally identifiable information in their malware? I hope never&#8230;..Darwin was right.</p>
<p><a href="http://www.whitedust.net/speaks/3905/Spanish%20police%20pinch%20cell%20phone%20hacker/" title="http://www.whitedust.net/speaks/3905/Spanish%20police%20pinch%20cell%20phone%20hacker/" target="_blank">www.whitedust.net/speaks/3905/Spanish%20police%20pinch%20cell%20phone%20hacker/</a></p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/cell+phone" rel="tag"> cell phone</a>, <a href="http://technorati.com/tag/virus" rel="tag"> virus</a>, <a href="http://technorati.com/tag/Cabir" rel="tag"> Cabir</a>, <a href="http://technorati.com/tag/Commwarroir" rel="tag"> Commwarroir</a>, <a href="http://technorati.com/tag/29a" rel="tag"> 29a</a>, <a href="http://technorati.com/tag/malware" rel="tag"> malware </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2007/06/cell-phone-virus-writer-arrested-in-spain/feed/</wfw:commentRss>
		</item>
		<item>
		<title>ESET&#8217;s NOD32 Antivirus</title>
		<link>http://www.infosecpodcast.com/2007/03/esets-nod32-antivirus/</link>
		<comments>http://www.infosecpodcast.com/2007/03/esets-nod32-antivirus/#comments</comments>
		<pubDate>Tue, 20 Mar 2007 02:10:23 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Viruses & Worms]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/viruses-worms/2007/03/esets-nod32-antivirus/</guid>
		<description><![CDATA[I try not to write about or endorse products as a rule. Every now and then I come across a product that warrants a post. I&#8217;ve been a long time Symantec antivirus user, much of it a holdover from the Symantec System Center days. The latest versions, from Symantec and others like Trend Micro,  [...]]]></description>
			<content:encoded><![CDATA[<p>I try not to write about or endorse products as a rule. Every now and then I come across a product that warrants a post. I&#8217;ve been a long time <a href="http://www.symantec.com" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.symantec.com');">Symantec</a> antivirus user, much of it a holdover from the Symantec System Center days. The latest versions, from Symantec and others like Trend Micro,  seem to have everything but the kitchen sink. Take a look at running processes and you will likely find several hogging more than their share of memory. They seem to be approaching bloatware status.</p>
<p>For a while now I have been using <a href="http://www.eset.com/products/index.php" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.eset.com');">NOD32</a> from <a href="http://www.eset.com" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.eset.com');">Eset</a>. A good friend who is Information Security Analyst at a local college here in NH turned me on to NOD32. It&#8217;s lightweight, fast and accurate.  They have scored 100% on the <a href="http://http://www.virusbtn.com/vb100/index" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.virusbtn.com');">Virus Bulletin</a> detection tests a total of 41 out of 43 times. The next closest competitor was Symantec at 35 out of 38 attempts.</p>
<p>If you are thinking about trying a different AV, give NOD32 a try. I&#8217;ve had great luck with it. You can get a free trial at <a href="http://www.eset.com/download/index.php" title="http://www.eset.com/download/index.php" target="_blank">www.eset.com/download/index.php</a></p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/Antivirus" rel="tag"> Antivirus</a>, <a href="http://technorati.com/tag/ESET" rel="tag"> ESET</a>, <a href="http://technorati.com/tag/NOD32" rel="tag"> NOD32  </a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2007/03/esets-nod32-antivirus/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Worm articles &#038; presentations</title>
		<link>http://www.infosecpodcast.com/2006/10/worm-articles-presentations/</link>
		<comments>http://www.infosecpodcast.com/2006/10/worm-articles-presentations/#comments</comments>
		<pubDate>Fri, 13 Oct 2006 15:45:16 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Viruses & Worms]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/viruses-worms/2006/10/worm-articles-presentations/</guid>
		<description><![CDATA[The JoatBlog posted links to conference materials from last years Workshop on Rapid Malcode (WORM).  A lot of great material  worms, bots and other nastys can be found here.
&#8211;Chris
Technorati Tags:  worm,  bot,  malcode 

  
]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://www.757.org/~joat/cgi-bin/blosxom.cgi" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.757.org');">JoatBlog</a> posted links to conference materials from last years <a href="http://www1.cs.columbia.edu/~angelos/worm05/worm-prog.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www1.cs.columbia.edu');">Workshop on Rapid Malcode</a> (WORM).  A lot of great material  worms, bots and other nastys can be found <a href="http://www.757.org/~joat/cgi-bin/blosxom.cgi/2006/08/27#wormshop.1" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.757.org');">here</a>.</p>
<p>&#8211;Chris</p>
<p>Technorati Tags: <a href="http://technorati.com/tag/worm" rel="tag"> worm</a>, <a href="http://technorati.com/tag/bot" rel="tag"> bot</a>, <a href="http://technorati.com/tag/malcode" rel="tag"> malcode </a></p><br />
<font><font face="arial,  helvetica" /></font></p>
<p><font> </font><font><font><font><font> </font></font></font></font></p>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2006/10/worm-articles-presentations/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Virus targets AntiVirus researchers, sort of.</title>
		<link>http://www.infosecpodcast.com/2006/07/virus-targets-antivirus-researchers-sort-of/</link>
		<comments>http://www.infosecpodcast.com/2006/07/virus-targets-antivirus-researchers-sort-of/#comments</comments>
		<pubDate>Thu, 13 Jul 2006 15:24:39 +0000</pubDate>
		<dc:creator>Chris Harrington</dc:creator>
		
		<category><![CDATA[Viruses & Worms]]></category>

		<guid isPermaLink="false">http://www.infosecpodcast.com/2006/07/13/virus-targets-antivirus-researchers-sort-of/</guid>
		<description><![CDATA[A new virus was detected in early July that reportedly targets AV researchers. The virus, know as Gatt / Gattaca, will scan an infected system for any files with the .idc extension and infect them. These .idc files are disassembler files used by Interactive Disassembler Pro, a very common tool used by AV researchers to [...]]]></description>
			<content:encoded><![CDATA[<p>A new virus was detected in early July that reportedly targets AV researchers. The virus, know as Gatt / Gattaca, will scan an infected system for any files with the .idc extension and infect them. These .idc files are disassembler files used by Interactive Disassembler Pro, a very common tool used by AV researchers to reverse engineer malware.</p>
<p>Why do I say this <strong><em>sort of</em></strong> targets AV researchers? The virus doesn&#8217;t do anything as there is <strong>no</strong> malicious payload. It just replicates it self to other .idc files. So why write something like this? I agree with Mikko from <a href="http://www.f-secure.com/weblog/" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.f-secure.com');">F-Secure</a>, &#8220;I think it  was written to just show off it can be done&#8221;. In typical hax0r tradition there is a hidden message / shout out in the file accoding to <a href="http://www.sophos.com/security/analyses/w32gattmana.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.sophos.com');">this Sophos</a> analysis. For the curious I&#8217;ve added links to several AV companies analyses of the virus.</p>
<p>And for the REALLY curious, pick up a copy of Ed Skoudis&#8217; book,  <a href="http://www.amazon.com/exec/obidos/redirect?tag=infosecpodcas-20%26link_code=xm2%26camp=2025%26creative=165953%26path=http://www.amazon.com/gp/redirect.html%253fASIN=0131014056%2526tag=infosecpodcas-20%2526lcode=xm2%2526cID=2025%2526ccmID=165953%2526location=/o/ASIN/0131014056%25253FSubscriptionId=0EMV44A9A5YT1RVDGZ82" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.amazon.com');">Malware: Fighting Malicious Code.</a> I am just finishing the book now and will post a review soon.</p>
<p>&#8211;Chris  <a target="_blank" href="http://www.symantec.com/avcenter/venc/data/w32.gatt.html" /></p>
<p><a href="http://www.symantec.com/avcenter/venc/data/w32.gatt.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.symantec.com');"> </a></p>
<table width="100%" cellspacing="2" cellpadding="2" border="0" style="text-align: left">
<tr>
<td>Links to W32.Gatt / W32.Gattaca / W32.Gattmann analysis<br />
<a href="http://www.symantec.com/avcenter/venc/data/w32.gatt.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.symantec.com');">Symantec</a> <a target="_blank" href="http://www.sophos.com/security/analyses/w32gattmana.html"><br />
Sophos</a> <a target="_blank" href="http://vil.nai.com/vil/content/v_140140.htm"><br />
McAfee</a> <a target="_blank" href="http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=PE%5FGATTMAN%2EA%2DO"><br />
Trend Micro</a></td>
<td>&nbsp;</td>
</tr>
</table>
<p><a href="http://www.symantec.com/avcenter/venc/data/w32.gatt.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.symantec.com');"> </a><a href="http://www.symantec.com/avcenter/venc/data/w32.gatt.html" target="_blank" onclick="javascript:pageTracker._trackPageview ('/outbound/www.symantec.com');"><p>Technorati Tags: <a href="http://technorati.com/tag/Virus" rel="tag">Virus</a>, <a href="http://technorati.com/tag/Malware" rel="tag"> Malware</a>, <a href="http://technorati.com/tag/Antivirus" rel="tag"> Antivirus</a></p></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.infosecpodcast.com/2006/07/virus-targets-antivirus-researchers-sort-of/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.892 seconds -->
