<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><id>tag:bogwitch.blog.co.uk,2009-11-08:/</id><title>Blogwitch</title><link rel="self" href="http://bogwitch.blog.co.uk/feed/atom/posts/"/><link rel="alternate" type="text/html" href="http://bogwitch.blog.co.uk/"/><generator version="1.0">MokoFeed</generator><updated>2009-11-08T02:30:19+01:00</updated><entry><id>tag:bogwitch.blog.co.uk,2006-10-04:/2006/10/04/usbdumper_analysis~1187123/</id><title>USBDumper - analysis</title><link rel="alternate" type="text/html" href="http://bogwitch.blog.co.uk/2006/10/04/usbdumper_analysis~1187123/"/><author><name>bogwitch</name></author><published>2006-10-04T14:05:01+02:00</published><updated>2006-10-04T14:05:01+02:00</updated><content type="html">	&lt;p&gt;Test platform MS Win2k.&lt;br&gt;
The executable is distributed with source code. I did not re-compile but gave the source a very cursory glance over. Nothing immeditately jumped out at me but remember, I am not a hugely experienced programmer.&lt;br&gt;
InCtrl5 listed no registry entries changed and no files added. The USBDumper executable is clearly visible in Task Manager.&lt;br&gt;
The process has not shown any signs thus far of attempting to access any network facilities.&lt;br&gt;
It does what it claims. In the directory from which it was executed, it creates a folder of todays date and copies the information from the USB memory device into it. If the folder exists the files from the key are copied into it.&lt;br&gt;
It does not always work. My Dell 16MB key - it always copies the data off. My 1GB key - no joy. Both are FAT formatted, I will need to find my NTFS formatted key before I can test.&lt;/p&gt;
	&lt;p&gt;Requires a little more investigation.&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/10/04/usbdumper_analysis~1187123/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</content></entry><entry><id>tag:bogwitch.blog.co.uk,2006-10-03:/2006/10/03/not_happy_with_mcafee~1184688/</id><title>Not happy with McAfee</title><link rel="alternate" type="text/html" href="http://bogwitch.blog.co.uk/2006/10/03/not_happy_with_mcafee~1184688/"/><author><name>bogwitch</name></author><published>2006-10-03T18:26:59+02:00</published><updated>2006-10-03T18:26:59+02:00</updated><content type="html">	&lt;p&gt;OK, McAfee has been detecting the 'psexec.exe' tool from Sysinternals (http://www.sysinternals.com) as 'Unwanted Programs' and as default, automatically deleting it. Since I am using a corporate license at work, I do not have a support contract number easily available to me so I emailed 'Customer Service' to explain that they were detecting (now) Microsoft software as malware. Apparently it is a job for technical support and they were unable, or more likely unwilling, to pass the information on.&lt;br&gt;
So, that will be the last time I contact McAfee directly and they will be removed from my malicious code submission list. I don't suppose they are bothered.&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/10/03/not_happy_with_mcafee~1184688/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</content></entry><entry><id>tag:bogwitch.blog.co.uk,2006-10-03:/2006/10/03/usbdumper~1184280/</id><title>USBDumper</title><link rel="alternate" type="text/html" href="http://bogwitch.blog.co.uk/2006/10/03/usbdumper~1184280/"/><author><name>bogwitch</name></author><published>2006-10-03T16:22:40+02:00</published><updated>2006-10-03T16:22:40+02:00</updated><content type="html">	&lt;p&gt;Not the easiest bit of software to find, I got it here: &lt;a href="http://www.secuobs.com/USBDumper.rar"&gt;http://www.secuobs.com/USBDumper.rar&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;I have not subjected it to my usual testing as my sandbox is not available to me right now, I'll get it tested hopefully by tomorrow. Until then, treat as highly suspicious!&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/10/03/usbdumper~1184280/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</content></entry><entry><id>tag:bogwitch.blog.co.uk,2006-09-12:/2006/09/12/infomation_assurance~1119758/</id><title>Infomation Assurance</title><link rel="alternate" type="text/html" href="http://bogwitch.blog.co.uk/2006/09/12/infomation_assurance~1119758/"/><author><name>bogwitch</name></author><published>2006-09-12T17:25:28+02:00</published><updated>2006-09-12T17:25:28+02:00</updated><content type="html">	&lt;p&gt;I am on an Information Assurance course this week so I doub't I'll see any new software this week.&lt;/p&gt;
	&lt;p&gt;I was pointed to Google mirror today.&lt;/p&gt;
	&lt;p&gt;&lt;a href="http://elgoog.rb-hosting.de/index.cgi"&gt;http://elgoog.rb-hosting.de/index.cgi&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;When I get back to work, I'd better check our content filter has this at least categorised and hopefully blocked!
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/09/12/infomation_assurance~1119758/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</content></entry><entry><id>tag:bogwitch.blog.co.uk,2006-09-07:/2006/09/07/hijackthis~1106741/</id><title>HIjackThis</title><link rel="alternate" type="text/html" href="http://bogwitch.blog.co.uk/2006/09/07/hijackthis~1106741/"/><author><name>bogwitch</name></author><published>2006-09-07T23:57:04+02:00</published><updated>2006-09-07T23:57:04+02:00</updated><content type="html">	&lt;p&gt;&lt;a href="http://www.merijn.org/files/hijackthis.zip"&gt;http://www.merijn.org/files/hijackthis.zip&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;HijackThis, don't forget ibprocman while you're there.
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/09/07/hijackthis~1106741/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</content></entry><entry><id>tag:bogwitch.blog.co.uk,2006-09-07:/2006/09/07/tiny_keylogger~1105168/</id><title>Tiny KeyLogger</title><link rel="alternate" type="text/html" href="http://bogwitch.blog.co.uk/2006/09/07/tiny_keylogger~1105168/"/><author><name>bogwitch</name></author><published>2006-09-07T14:58:11+02:00</published><updated>2006-09-07T14:58:11+02:00</updated><content type="html">	&lt;p&gt;&lt;a href="http://home.rochester.rr.com/artcfox/TinyKL/TinyKL.exe"&gt;http://home.rochester.rr.com/artcfox/TinyKL/TinyKL.exe&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Watch out! Make sure you have written consent for the installation of ANY keylogger. This one is great as it's: 1. free 2. small 3. can be easily renamed.&lt;/p&gt;
	&lt;p&gt;Downside is, some AV software identifies it as a virus/ malware.
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/09/07/tiny_keylogger~1105168/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</content></entry><entry><id>tag:bogwitch.blog.co.uk,2006-09-06:/2006/09/06/atguard_personal_firewall~1103580/</id><title>Atguard personal firewall</title><link rel="alternate" type="text/html" href="http://bogwitch.blog.co.uk/2006/09/06/atguard_personal_firewall~1103580/"/><author><name>bogwitch</name></author><published>2006-09-06T22:17:26+02:00</published><updated>2006-09-06T22:17:26+02:00</updated><content type="html">	&lt;p&gt;&lt;a href="http://www.es.embnet.org/Services/ftp/misc/Crypt/ftp.hacktic.nl/security/firewall/at_guard/atgd322.exe"&gt;http://www.es.embnet.org/Services/ftp/misc/Crypt/ftp.hacktic.nl/security/firewall/at_guard/atgd322.exe&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;NB AtGuard will probably seriously affect your http transfers with Windows2000 SP4 unless you copy the SP3 tcpip.sys over the SP4 versions. I've read that it loses the logging function under XP too but I'm not using XP so I don't care!
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/09/06/atguard_personal_firewall~1103580/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</content></entry><entry><id>tag:bogwitch.blog.co.uk,2006-09-06:/2006/09/06/inctrl5~1103533/</id><title>Inctrl5</title><link rel="alternate" type="text/html" href="http://bogwitch.blog.co.uk/2006/09/06/inctrl5~1103533/"/><author><name>bogwitch</name></author><published>2006-09-06T22:00:52+02:00</published><updated>2006-09-06T22:00:52+02:00</updated><content type="html">	&lt;p&gt;&lt;a href="http://www.devhood.com/tools/tool_details.aspx?tool_id=432"&gt;http://www.devhood.com/tools/tool_details.aspx?tool_id=432&lt;/a&gt;&lt;/p&gt;
	&lt;p&gt;Inctrl5 - system changes monitor.&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/09/06/inctrl5~1103533/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</content></entry><entry><id>tag:bogwitch.blog.co.uk,2006-09-06:/2006/09/06/why_am_i_trying_to_blog_again~1103515/</id><title>Why am I trying to blog again?</title><link rel="alternate" type="text/html" href="http://bogwitch.blog.co.uk/2006/09/06/why_am_i_trying_to_blog_again~1103515/"/><author><name>bogwitch</name></author><published>2006-09-06T21:53:37+02:00</published><updated>2006-09-06T21:53:37+02:00</updated><content type="html">	&lt;p&gt;Yes again. I started a blog before, updated it only a couple of times and now I can't even remember where it was!&lt;br&gt;
OK, so this time I'm planning to go for a security type blog. I'm not intending to publish this to anyone in particular but if you find the information helpful, so much the better.&lt;br&gt;
The real purpose of this will be to keep a record of stuff I need that I can access from wherever I am.
&lt;/p&gt;
&lt;p&gt; &lt;small&gt; &lt;a href="http://bogwitch.blog.co.uk/2006/09/06/why_am_i_trying_to_blog_again~1103515/#comments"&gt;Comments&lt;/a&gt; &lt;/small&gt; &lt;/p&gt;</content></entry></feed>
