What is the art of ghosting?
Ghosting means to establish invisible presence, and gain invisible access, where you should not have access, getting information which you should not have, and trust, to make the environment, to work for you, without raising any suspicion, while being hidden where no one will ever look for you – in plain sight – in front of everyone’s eyes.
What is a ghost?
Ghost is a person who is skilled at social engineering, skilled in long term planning ahead of time, able to collect information and assemble the pieces of the puzzle using current line of events and circumstances as a layout to assemble the pieces of the puzzle.
What a ghost is capable of?
Well developed and well established ghost is capable of ALMOST anything at his will and convenience. Well ALMOST anything.
Наглеци се развиват в обществото ни и владеят обществото ни, защото ние им позволяваме да се развиват. ние ги храним, ние ги отглеждаме, ние им мълчим, ние им прощаваме, защото не им търсим сметка вина и отговорност. Докато това не се промени, наглеци винаги ще виреят в обществото и ще влаеят обществото!
Sunday, October 19, 2014
Saturday, October 18, 2014
Few useful tips how to increase the lifespan of an SSD
Few useful
tips how to increase the lifespan of an SSD
1. Do not
defragment your SSD. SSD does not suffer performance loss caused by
fragmentation. Defragmenting it, will
only fatigue it, but it will not increase it’s performance. You sacrifice it’s life
for nothing in return. Slowing down on an SSD, means the SSD is wearing out,
and it needs wear leveling. Slowing down of an SSD is caused down, because of
Error correction code being used, to try to correct not fully or not properly
read data, after multiple retries to make a good read. Self Healing and wear
leveling will fix this for some number of times, but ultimately, the SSD will
die.
Bicycle brakes - brake pads alignment
Bicycle
brakes - brake pads alignment
Bicycle
brakes evolved over time, increasing stopping power, from inadequate low – so
low, it is beyond useless, to insanely high – modern hydraulic disc brakes,
offer incredible amount of braking power, by gently squeezing them with one
finger. The biggest breakthrough came when engineers, realized 2 things:
1 That you
can create insanely strong brakes, but if braking pads are NOT properly aligned,
this braking power is lost. This is why adjustable brake pads were created,
with some free play designed into them in order to allow them to align
properly.
2. The brake
must have proper balance left-to-right, in order to distribute brakeforce
evenly.
Disc brake dynamics - The actual difference between mechanical disc brake and hydraulic disc brake
Disc brake dynamics - The actual difference
between mechanical disc brake and hydraulic disc brake
Regardless
how much engineers try to convince us, that modern high end mechanical disc
brakes, controlled by high-end braking cables and high-end cable housings, can
be real match to a hydraulic disc brake, the actual picture is quite different.
Mechanical brakes suffer from cable stretching, regardless of everything. Yes,
yes, I know the blah-blah-blah-blah that high-end cable in high-end cable
housing do not suffer that much as low-end cables in low-end housings… but at
the end of the day, the high-end cable also stretches. Even this combo has so
called slack, which appears and accumulates during long term use. This is the
reason for the brake to be inefficient, in most cases. Another issue is that
almost all mechanical disk brakes have only one moving piston, which moves only
one brake pad. In this case the static one must be set up properly a tiny hair
away from braking disk, in order to make it work at all. This is the reason for
50% of inefficiency, and the braking cable stretching is the other reason that
causes inefficiency.
Sunday, June 29, 2014
The nonsense of “Nothing to hide, nothing to fear”
Hello People of the Internet. I do not feel comfortable, being spyied upon, for some immature government’s happines? Are you happy with it?
Yes?
Then leave this blogpost, it is not for you, and you will find nothing of good use for you.
Then leave this blogpost, it is not for you, and you will find nothing of good use for you.
No?
This blogpost is for you.
This blogpost is for you.
I saw a video some time ago, presented by Mikko Hypponen, Chief Security Researcher of F-Secure company. In his Speech he said that if someone stranger asked Mikko Hypponen, if he is doing anything wrong, well he said he is not. Then he was asked why bother hiding, Mikko answered it is personal matter, and it is not your business or concern. HE IS RIGHT. My private life, my private chats, my private skype or phone cnvversations are NOT YOUR BUSINESS OR CONCERN! PERIOD! That the picture, and I do not care if you like it or not. Will I encrypt? HELL YEAH! And again I do not care if you like it or not. If you don’t – then you will bite the short end of the stick. The governments are using cheap excuses like child pornography, or terrorists attacks to try to mislead us, to justify, their violation of our rights. Do not allow them to do so. Internet People, you are the one with the ultimate power in your hands. Do not give that power to the governments, use it to defend yourselfs. Put the governments where they belong to – down in your legs, to know their place in future.
ENCRYPT ALL FOR CRYING OUT LOUD!
Here is a text I found, linked ot an initative picked up by F-Secure Company and Mikko Hypponen and David Hasselhoff:
Make your voice heard. Contribute to our manifesto for digital freedom!
It all has started at re:publica, Berlin, where F-Secure's Mikko Hyppönen, world-renowned security and privacy expert, discussed with Freedome Ambassador David Hasselhoff about the defining issues of today: digital freedom and privacy. Now you can join forces with them and contribute to the manifesto for digital freedom. We will provide the platform, but the manifesto itself will be licensed under creative commons. The goal of this crowdsourcing project is to raise awareness for #digitalfreedom and its fragile state in today's society. Together. With you.
Why Privacy Matters?
This manifesto is about digital freedom. It’s about the kind of world we want to live in. It’s about our privacy, now and in the future. Because our privacy is ours and it doesn't belong to anyone else. Privacy matters. Without privacy there can be no freedom. It is the most important part of democracy, freedom and human rights. You should be free to vote against politicians you don’t like without being afraid that they will find out who you are, without being intimidated, without being punished. Otherwise there can be no democracy. You should be free to be who you, to think your own thoughts, to discuss your own ideas in private, as well as in public, without fear, without persecution. Otherwise there is no freedom.
That’s why you have a right to keep your politics, your sexuality, your views, and your beliefs to yourself. And no government, or police force, or intelligence agency should ever have the right to breach those rights. But with mass surveillance security services around the world already did. Now they can follow everything about us without our permission. And they do it in secret.
Remember when secret police were scary, bad people? Now they’re supposed to be our friends, promising that they work behind the scenes to keep us safe. We've been told that we should trust them. The problem is that they already lied to us.
So we say our privacy is ours. My privacy is mine and your privacy is yours. It doesn't belong to anyone else. Private data of any sort should only ever be shared with consent. It should never, ever be taken.
Aside from the importance of privacy from the individual perspective, an argument can be made for the importance of privacy from a social perspective. Just as individual humans adapt and grow to survive in their environments, so do societies. It is worth noting that social environments are composed of other persons and that societal environments are composed of other societies. Whether at a societal, social or individual level, freedom to adapt and grow is ensured by privacy.
The ability to adapt or grow is founded on the identity of the adapting or growing thing. It comes down to a matter of harmony; if an identity is too broadly defined, it interferes with potential others and if too narrowly defined then it is not differentiated from potential others. So privacy, by disallowing elements from being interfered with by others and still leaving the same room for those others enables fruitful social growth.
In fact, the manner in which persons may contribute to this document illustrates this point. If the contributions were too restricted, so would the resultant document be too restricted and unrepresentative of the persons it applies to. If the contributions were not restricted enough, it would similarly be unrepresentative as some individuals would annihilate the work of others.
That’s why we need privacy. That’s why we need digital freedom. That’s why we've created this manifesto.
#Theme 1 Mass surveillance
We have stepped in the World of which Orwell warned us. It's sold "for our protection". It's used against us. It has to be stopped right here or ten years from now we are dreaming about "those days when technology wasn't used to spy on people without any right" or "of free network where you can find independent information".
A person's digital possessions should be afforded the same protection and respect as a persons physical belongings. Soon everything will be connected causing the lines between the digital and physical realms to blur. Before this happens the ground work needs to be laid otherwise all trust in technology will be lost.
The two great innovations of our time, the cell phone and the Internet, have been turned into surveillance tools to be used against us. And the problem with programs like PRISM is that they aren't just about doing surveillance on people suspected of crimes. They’re also about spying on people governments know are innocent. Everyone is targeted by mass surveillance of NSA. It is authorized by the current and ex presidents of United States, and should be considered as a crime. Surveillance is grown out of control, and even after Snowden leaks we know only know bits and pieces.
Some countries are in unique position to watch over the rest of the world. Just because their laws allow it and the rest of the world comes to use their services doesn't make it right to collect and store all the communication.
No one should be spied on merely because there is a way and a means available to spy on them.
Just because we have the technology we do not have to use it in a bad way. The fact that our devices offer an easy way to track and monitor your behavior does not mean that it should be used without your notice.
Digital citizens must get better information about what information is leaking out. Why not create a system like the TOC we have in the food industry.
People own data that they create or receive as part of private communication. This data is private and shall not be collected, searched or otherwise used by any other party. This protection shall affect data stored on people’s own devices, in cloud accounts and data in transfer. Authorities investigating crime and other real security threats shall target named suspects when collecting data of this kind.
Every such action shall be based on a warrant granted by a legal and transparently acting court of law and supported by a substantial suspicion. Bulk data collection by authorities is a gross violation of the United Nations’ Universal Declaration of Human Rights, Article 12. This article shall be revitalized in the digital world and enforced globally.
If we trade in privacy today, it will be gone tomorrow. The generations to come then won't have a choice anymore. This is kind of like working to save the environment. If we destroy the environment, it'll be gone for our children. The same goes here, I guess.
People should be educated to use Internet intelligently. A means to do so would be to create encryption and decryption tools. Such tools would be used off line to process messages. This should always be done for everything, creating such a demand in decryption time for any surveillance agency that would make the cost of spying everything we communicate online extremely costly. Of course, it would make internet usage slower, but it is worth thinking if one of our problems in this society is the obsession to have everything, including information, for yesterday.
People need to be aware of which of their data is actually precious, because sometimes, when we are talking about intangible things such as data, people are not really ascribing much value to it, until it's too late... When it has already been used against them.
We should not accept that others control our data. Data about us is our data, even if others generated and cumulated it into a new database. In particular 'open data' should only be processed with 'open algorithms'. The risks of discrimination in many big data analytics application are so high, that all big data algorithms should be open source and reviewable.
Metadata of all digital communications must be as private and protected by law as the content of the communication is.
It is not accepted that your government or service provider enters your house and follows everything you do. Why is it accepted that governments or companies like Google may access your private phone that you pay a decent amount of money for. This action allows them to follow your every step and all your communication?
Requests for data searches by legitimate law enforcement authorities should not be based on concepts derived from outdated and irrelevant technology. They should not presume the application of one country's code of law and conduct onto another country, but on a mutual framework that observes common human and property rights.
Intellectual property rights are used by artists, inventors and corporations to signify ownership of the objects and ideas they created. In the same vein, data property rights should be upheld that state that data produced by the individual belong to them, not to the companies that make use of the data.
Why should you allow mass surveillance and thus allow infringement of your rights as a free citizen?
In addition to having international treaties that oblige every signing nation to refrain from systematic mass surveillance, it is imperative that every single private company takes encrypting their customer data and data traffic seriously. The future demands that we have more local cloud storage services. Lets make that a thriving business!
Digital freedom must be secondary free Internet. You can't convert a Military ARPA based System to a free one. otherwise we "patch" the current Internet for Security Reasons.
All digital surveillance should be targeted, it is a clear violation of human rights to monitor everything in case someone is doing something bad. What happened to "innocent until proven guilty"? All permissions for targeted surveillance should go through legitimate courts, not some super secret court which has no responsibility on the consequences.
The Universal Declaration of Human Rights (Article 12) puts it in a clear and unambiguous manner:
"No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks."
#Theme 2 Digital persecution
Information gathered from mass surveillance should be one of those "inadmissible as evidence" kind of information. When we have lost our right to privacy, it's just as good as all of us walking around naked and speaking everything that comes to our minds. And we all know how well that works.
Semantic Web has good potential for doing good. As long as people have choice of leaving user and location data hidden.
Policy Aware Web promises to at least partially tackle the social and privacy related hurdles with the Semantic Web. On the other hand, defining the architecture for and implementing a rules engine layer on top of or underneath the current World Wide Web would be quite a daunting task and probably open massive opportunities for governmental and other players' online surveillance initiatives.
#Theme 3 Digital colonization
Technologies are fundamentally changing our world at a staggering speed. But just because something is technically possible doesn't mean that we should have to blindly accept it into our lives.
Just like colonized countries fought for their freedom back in 1800's and 1900's, we too must make the effort to break free from US-based services.
Countries in EU should invest in creating their own Gmail, Facebook etc. Russia for example has Vkontakte. Not hard.
At the same time it's important to recognize that several of the companies in the United States have revolutionized the way people use the Web, that the companies must sell personal data to cover operating costs and acquire revenue, and that the companies receive investments (directly or indirectly) from the NSA and CIA.
In competing with the industry in the United States to provide alternatives, the above situation must be addressed and real long-term investment is needed by governments outside the United States (and the European Parliament) if the aim of having our own Europe-based 'Silicon Valley' is to be realized.
Alternatives need to rise, and the software companies in the USA would need to feel that being in that country is a threat to their position. Perhaps they would also be willing to move and setup shop somewhere else. Again, to be in that position, the same governmental backing from EU members who care about security, privacy and human rights is required. Innovation and start-ups alone cannot achieve this.
Note that this is not the rest of worlds competition against USA, its more like basic human rights that they have also written in their country's constitutional documents. Starting from their very first amendment is stated freedom of expression that means nowadays communicating privately without someone looking trough all emails that someone sends or receives, this should apply on Digital world as well. This issue should have even more attention on the United States as it seems to be against their own constitution...
#Theme 4 Right of access, movement and expression
What we say and write in private should be of no interest to any governmental organization and we should fight for the freedom of access to platforms, movement and freedom of expression.
Having no digital privacy is no worse than having a permanent thought cloud on top of all our heads, broadcasting what we are all thinking. Because, let's face it, we ask Google first nowadays before we ask an expert.
Like everything else the internet can be used for the good or for the bad. It can help nurture education and democracy all over the planet, connect people from different backgrounds and initiate discussion and dialogue between them. Or it can be abused to undermine civil rights such as privacy or freedom of expression (maybe even: freedom of thought ?), to serve simply as a tool for an unjust minority to retain control. Let's make sure we as the people use it for right; that is, for society to advance and prosper instead of mankind being enslaved.
It's essential to have the freedom of expression for everyone. Every democracy is based on this idea. And nowadays a part of this freedom is to have access to social media platforms to publish his opinions.
The search for privacy is not a criminal act, it is a fundamental human right.
Governments collecting the emails of innocent people on a colossal scale is a violation of our human rights to privacy and freedom of expression. We should not allow our private messages to be intercepted and stored by those we elect to protect us. We must stand against email providers that work with the NSA and refuse to implement privacy options for users (technically: encryption, etc...).
We must protect the Internet from further segmentation. We are slowly seeing Internet separating to regions. All the regions able to access different content. Censorship is been implemented in countries like Australia, Russia, China, USA, Thailand etc. and even worse in Arabic countries. We are not far away from times that Internet as we know it exists.
It could be argued that protecting an individual person's access, movement and expression would require the ceasing of government monitoring of these activities. This would further fracture (in this case: governing and governed) so that enforcing this right for all instead requires us to decentralize it. In other words: we should seek to universalize the access, movement and expression rather than regarding it from either side of the one accessing, moving or expressing.
The nonsense of: “Nothing to hide, nothing to fear”
You may have read or heard the statement, “nothing to hide, nothing to fear” from some people, especially from people in authority. The problem is that it’s not true.
The statement is made with the implicit claim that the people who are watching you only have your best interests at heart; that they are fair, honest, and will never abuse their power. How can we know this? Even if it is true now, how can we be sure that the situation won’t change in the future? The answer is obvious: we can’t be sure of these things. The more secret they are, the less sure we can be. And the less we should trust them.
Governments change and so do their attitudes to freedom. The laws we allow now will last for a very long time – it is very difficult to undo a law, no matter how unfair. That is why we should make sure we limit the power governments, police, and security services have over our digital freedom. And we should do it now. What we lose today we may lose forever.
Why does this matter? The power to invade our digital freedom gives people the ability to discriminate against us without us ever knowing. They’ll never have to ask inappropriate, unfair, or illegal questions because they'll know the answers already.
In the supposedly free world we have our own fears. For example, imagine if you could never look for new jobs without your employer knowing. Imagine if you could never go to the doctor without an insurance company checking your results. Imagine if you could never have something that was yours alone.
What if you couldn't do a single thing without always worrying whether it would or could jeopardise your future in some unknown, unforeseeable way?
A world in which we are afraid of the people in power is a world we hoped we had left behind. In other countries people don’t have to imagine what they might have to fear. Their reality is that they can never vote against the government for fear of punishment and that they can never complain about the police for fear of a beating.
This is what supporters of “nothing to hide, nothing to fear” forget. It’s not about whether they can trust us, it’s about whether we can trust them.
Wednesday, March 26, 2014
Rules of Malware fight
Rules of Malware fight
1. Do not get cocky
Underestimating the level of threat, that malware poses, actually means you have no idea who your enemy is, what it is capable of.
2. Never say never
Never say, malware cannot infect you. There is no invulnerable OS, there is no impenetrable defense.
3. Never trust compromised OS
You can never trust malware to be honest. Once the system is broken It is no longer trustworthy.
4. Do not leave things halfway done
Malware always finds way to revive itself. Either finish it, do all the work fully and completely, or do not bother starting. Never leave malware executables left on the system, even if their autoruns are removed.
5. If it can be done, it is already done
Do not take Security as granted. Do you really know, which exploits your computer is vulnerable of? There are only two types of computers - These which are infected and these which will be infected.
6. Be prepared
Make sure you are familiar with the enemy, and you have the proper tools for the job, and the proper knowledge to use the tools properly. Each malware is it's own case, it requires it's own attention and knowledge and tools...
7. It has fangs and claws and it knows how to use them
Be very careful, be extremely careful. Treat malware with utmost care and respect. It is so easy to make a mistake and make the malware to backfire on you.
8. Copy me, I love to travel
When taking on malware, ALWAYS use read-only media with your tools, or bootable read-only media, created with updated tools. When cleaning thumb drives, do it from bootable read-only media, created with updated tools, while your main Hard Drive is PHYSICALLY DISCONNECTED!
9. Can you be absolutely sure, beyond any question, that your system is not compromised?
Wednesday, December 18, 2013
Цигански пазарлък за 2 стотинки
Тази карикатура е добро начало на този пост, имайки предвид контекста на карикатурата и на поста.
Цигански пазарлък за 2 стотинки
Днес стана една доста грозна сцена. До токова останах
отвратен от сцената, че реших да я сподея в блога си.
Днес след работа, ми се доядоха пържени картофки. Реших да
отида до близката бутка на пазара за бургери и хотдог, и да си поръчам пържени
каротфки. Видях на табелата цена от 99 стотинки за 100 грама. Реших да купя
повечко картофки да има за всички вкъщи. Купих 500 грама които според табелата са
4.95 лв. Питах продавача, колко стува една порция той каза 1 лев. Ок. Платих 5
лв, купих 5 порции – 500 грама да има за всички. Дали ми пука за тия 5 стотинки
разлика? Не. Изобщо. Аз даже често си поръчвам от него храна на вкъщи и като
има примерно някакво малко ресто примерно 40 – 50 стотинки, му ги оставям. Защо
ли? Защото:
1. По цял ден работи в тоя бутка, за да си изработи
някаква надница да си нахрани семейството
2. защото работи честно и почтено
3. защото винаги се старае клиента да е доволен, когато
си получи поръчката
4. защото при него всичко е винаги прясно, топло и
вкусно.
Докато чаках да се изпържат моите картофки, дойде една
жена на средна възраст, да си поръча и тя картофки. Чудесно. Картофките на
нашия готвач са хубави, и добре изпържени. Тя си поръча 200 грама. Попита човека
в буткатаколко струват, и той и казва една порция е 100 грама и струва 1 лев. При
което жената веднага си заби погледа в табелата, и вика ама на табелата пише 99
стотинки. След което започна да прави цигански пазарлък, буквално за 2
стотинки. Защото човека и казал 2 лв а не 1,98 лв.
Сцената ми
привлече вниманието, обърнах се и се заслушах, как тая малка злобна жена се пазареше за 2
стотинки, точко както се пазари някой циганин. Останах погнусен и отвратен от
тая сцена и си тръгнах с неприятното усещане, за човешката злоба и човешкото
падение. Стана ми тъжно, за човека от бутката, защото той виси там цял ден,
прави се на маймуна, за да угажда на претенциите на всички, точно за това му
оставям бакшиш, точноз а това ако имам примерно 40 – 50 стоники ресто при него
не си ги вземам, нека пие едно кафе с тях. Нека и той се почувства човек, той
нито е циркова маймуна нито е машина. За това останах и отвратен и погнусен от
тая малка злобна жена, дето така грозно му се пазареше, все едно той и е
някакъв роб дето и е длъжен и и е на подчинение.
Дали съм някой богаташ – не съм. Дали съм някой гъзар
дето има толкова пари че не ги цени - не съм. Аз съм същия като него. Същия като
човека от бутката. Работя в малка квартална бакалия. Колко изкарвам ли? Не изкарвам
много, достатъчно за да се издържам. Защо симпатизирам на човека от бутката ли?
Защото аз знам какво му коства, защото на мен ми коства същото. Защо изпитвам
погнуса и отвращение от такива малки злобни хора като тази малка злобна жена ли! Защото
всеки ден, имам вземане даване точно с такива малки злобни хора, изтъкани от
ежедневната злоба, с комплекси за малоценност, които си мислят че са мачкани от
живота. Не. Те не са мачкани от живота. Живота просто ги е избутал ей там в
канавката където им е мястото и повече не се занимава с такива. Те са мачкани
не от другите към които се отнасят със същата злоба, те са мачкани от собствената
си злоба, завист, с които тровят останките от душата си, и останалите хора около
тях мислейки си че като направят сцена и пазарлък на някой, вече са видиш ли
силните на деня. Не. Не са силните на деня. Те са жалката гротеска на деня.
Силните на деня са тези като човека от бутката, и като мен, които ежедневно трябва да се справяме с помията от злоба, завист и комплекси, които такива дребни злобни хора ни изсипват на главите, и въпреки всичката тази простащина, злоба, комплексарщина, оставаме на работното ни място и си завършваме работния ден.
Силните на деня са тези като човека от бутката, и като мен, които ежедневно трябва да се справяме с помията от злоба, завист и комплекси, които такива дребни злобни хора ни изсипват на главите, и въпреки всичката тази простащина, злоба, комплексарщина, оставаме на работното ни място и си завършваме работния ден.
Да, да си силен не значи да вдигаш шум и пушилка, да си
силен значи да знаеш кога да отстъпиш на такива малки и злобни хора, и да знаеш
как да се справиш с такива малки и злобни хора.
За хората и вирусите
За хората и вирусите
Напоследък се наслушах на разни твърдения за БИОС вирус,
с името BadBIOS и реших да видя каква е
тая нова щуротия, дето така е подпалила всички. Оказва се пълна щуротия, не
просто щуротия, а абсолютна щуротия.
Източника на тая щуротия, е Драгос Рую, ужким бил
секюрити рисърчър и основател, на конкурса
за пробиви и сигурност Pwn to own и
конференцията за сигурност и пробиви BlackHat. Общо
взето, твърдението гласи, че това е BIOS базиран
вирус който се разпространява чрез звук, и живее в BIOS и се стартира и почва да работи със стартирането на
компютъра и инициализирането на BIOS още ПРЕДИ да има
заредена операционна система. След това, твърдението гласи, че тоя вирус никога
не пипва и не помирисва операционната система на компютъра, и че си седи само в
БИОС и работи само от там, без да се опитва да се докопа до операционната
система.
Странно, защото разпространението чрез звук, макар да не е
невъзможно, е доста ненадеждна и бавна и капризна технология, която е зависима
от твърде много условия, които всичките трябва да са едновременно изпълнени перфектно
и коректно, и ако кое да е едно не се изпълни перфектно нещата пропадат.
Освен това BIOS е пряко обвързан с
платфорамата на която работи, няма такова нещо като универсален BIOS. Всеки BIOS е правен изцяло според платформата на която ще работи.
Няма начин, това да е, добра среда за разпространение. Всеки BIOS за всяка дънна платка е различен. Единственият шанс за
разпространение, е в много тясна група от BIOS и това са
всички дънни платки от една серия, модел, производител. Извън тази тясна група вируса
умира защото отива на различна платформа.
Tuesday, December 17, 2013
Горкия клетник, чак да го оплачеш
Горкия клетник, чак да го оплачеш. Те сигурно заради
такива изстрадали клетници като него са написали мюзикъла „Клетниците“.
На това му викам да нямаш късмет. Да се настроиш за
хубава измама, да си избереш мишена, да си поставиш цел и да откриеш че си
попаднал на грешната мишена, която да те изпържи, вместо ти нея. Те на това
викам да нямаш късмет. Ами какво да ви кажа. Има ги и такива баламурници. Както един
приятел вика баламургени. Баламурген значи баламурник, Баламургени, значи
баламурници, както същия приятел се майтапи с немска нотка в думата.
Мишената бях аз, целта беше да ми измъкне данните за
кредитната карта – хайде стига всички знаят че нямам такава, и че не вярвам на
тая система с картите, и че я смятам за прекалено незряла и недоразвита, за да
си доверя парите на нея, и за това всички знаят че скоро няма да си извадя
кредитна карта.
Та днес получавам странно телефонно обаждане. Да, новата
вълна предпразнични телефонн мошеници. Та реших че няма да го отсвиря, бързо
и категорично а ще се погавря с него,
докато му скъсам нервите.
Monday, December 2, 2013
Зевс, новият банков троянски кон
Говорейки за вируси, червеи, троянски коне, рууткити, определено бих се притеснил, ако създателите на тези изроди ми кажат:
Works as advertised, and delivers as promised.
Бих се притеснил двойно, ако това изречение ми го каже някой голям и сериозен секюрити рисърчър, например като Брус Шнайер, Стив Гибсън, Марк Русинович, Райндол Шварц, Брайън Кребс, или ако анализирам гадината и сам видя че наистина Works as advertised, and delivers as promised.
Така днес си грах с един троянски кон, исках да го анализирам, да го видя какво прави, как го прави и къде. Ето и резултатите от анализа ми. Това е гадина която ОПРЕДЕЛЕНО НЕ ЖЕЛАЕТЕ да ви се лепне на компютъра.
Когато получих мострата от Стив Гибсън от GRC.COM, Microsoft Secrity Essentials не го познаваше, докладваше го за чист. Пратих им копие на мострата, заедно с кратичко описанииче що е то в зип архива, признаха го, потвърдиха че е най-новия зевс, и ми отдадоха заслугата. 24 часа след като го пратих, ми казаха че са признали мострата и са направили дефиниция да го познава по мойта мостра.
поиграх си малко с него, и с инструментите на Марк Русинович Sysinternals tools и направих този кратък анализ.
Зевс е троянски кон, който се разпространява, с фишинг емайл, и поради тази причина създава и използва ботмрежа с името Zbot.
Троянският кон, използва рууткит, за да прикрие присъствието си – файлове, процеси, тредове, записи в регистри.
Рууткита, реагира късно да пази троянския кон, чак когато сте притеснително бизо до троянския кон – тоест ако не търсите троянския кон, рууткита няма да реагира за да не се издаде. Чак когато степритеснително близо до него, рууткита режава че не сте там случайно а с цел и реагира на ставащото.
Рууткита се прикрива като гугълска услуга, за да може, дори при неговото разкриване, да се опита да изглежда като нещо невинно. Камуфлаж.
Рууткита и троянският кон, са създадени, да работят на неадминистраторски акаунт, без права и привилегии, и притеснителното е че го правят, безупречно.
Троянският кон, се опитва да се отпише от системните защити на паметта – DEP – Data Execution Prevention, ASLR – Address Space Layout Randomization и SEHOP – Structured Exception Handler Overwrite Protection. Ако не успее, става още по-притеснително, използва нов пробив в системата за шрифтове, за да получи права на администратор и на системен процес на ядрото – kernel ring 0 с които тотално изключва споменатите защити.
Троянският кон, работи с папките на потребителя в потребителския профил, и в частите на регистри отнасящи се до текущият потребител. Тъй като се правят промени за текущият потребител, троянският кон няма нужда от администраторски права, за да зарази системата и да се запише за автоматично стартиране.
Троянският кон записва 2 файлана хард диска, единият от които е рууткита, който крие всичко, а другият е троянският кон, който бива скрит от рууткита.
Папката в която се записва рууткита е:
При 64 битова версия на уиндоус:
C:\program files x86\google\desktop\install\random named folder 1\random named folder 2\random named folder 3\googleupdate.exe
При 32 битова версия на уиндоус:
C:\program files\google\desktop\install\random named folder 1\random named folder 2\random named folder 3\googleupdate.exe
Където папките с имена random named folder всъщност са папки с произволни имена.
Папката в която се записва самият троянски кон е:
C:\users\current user folder\appdata\local\google\desktop\install\random named folder 1\random named folder 2\random named folder 3\randomfilename.exe
Където randomfilename значи произволно име на файла, и Където папките с имена random named folder всъщност са папки с произволни имена.
Имената на файла и на папките нарочно са произволни, и се създават за всеки заразен компютър произволни, за да може, да няма видими общи белези, между заразените компютри. Още една техника за прикриване на присъствието си.
При стартиране на заразеният компютър, операционната система зарежда рууткита, след като рууткита се стартира, заработи и се скрие, рууткита стартира троянския кон и го прикрива.
Рууткита се записва в регистри за автоматично стартиране в частта на регистри за текущият потребител:
HKEY_Current_User\Microsoft\Windows\Current_Version\Run
Интересното е че като система за пририване, това не успява да го направи. Опита му ма прикриване е белега който го издава. Записа на файла за автоматично стартиране бива прикрит с разместване на буквите в името на файла, и файла се вижда като:
exe.etadpuelgoog
но като наместите буквите правилно, се появява истинското име на файла:
googleupdate.exe
Това че всичко е разместено, привлича погледа. Обикновенов регистри всички имена са коректно споменати и няма опити за прикриван и завоалиране на имена, и за това така завоалирано името привлича внимание. единственото завоалирано има на фона на всички останали незавоалирани, за това по-горе казах че не успява и че опита за прикриване е това окето го издава.
Рууткита и троянският кон са маркирани като Safe Boot което означава, че уиндоус ги стартира при зареждане на компютъра в обичайния safe mode. Проблемът се утежнява, защото също бива зареден и в Safe mode with VGA и Safe Mode with Networking, защото в последният режим, троянският кон директно си се връзва в неговата бот мрежа и всичко работи на 100%
Хубавото, е че не се зарежда в най-минималистичния и най-орязаният режим – Safe mode with command prompt. Ех добрият стар дос, хората от старата школа, знаят за какво говоря. В този режим, не е проблем да навигирате с командите на дос, и да изтриете файловете на зевс и рууткита, и да използвате Autoruns sysinternals инструмента, за да премахнете записа за автоматично стартиране от регистри.
Веднъж троянският кон, стартиран от рууткита, и скрит от рууткита, веднага се закача за клавиатурата, и търпеливо анализира всичко което набирате от клавиатурата, за да види може ли да извади акаунти за електронно банкиране, данни за кредитни или дебитни карти, данни за банкови сметки.
Троянският кон, и рууткита, съществуват не като самостоятелни процеси, а като DLL тредове, под юриздикцията на services.exe което позволява, на троянският кон да следи клавиатурата, и на рууткита да го прикрива успeшно.
За да се свърже с неговата ботмрежа, троянският кон, стартира множество UDP връзки от локален порт 54946 на зарdзеният компютър, до отдалечен порт 16470 на произволно генерирани имена, физически пръснати по целия свят, откъдето вземат командите си от command & control или предава вече събраната информация от клавиатурата.
Subscribe to:
Posts (Atom)
